CVE Feed

    Dashboard / CVE

    4.3
    Medium

    CVE-2024-4220

    Last Modified: 21 Nov 2024

    Prior to 23.1, an information disclosure vulnerability exists within BeyondInsight which can allow an attacker to enumerate usernames.

    Published: 4 Jun 2024
    4.8
    Medium

    CVE-2024-4219

    Last Modified: 21 Nov 2024

    Prior to 23.2, it is possible to perform arbitrary Server-Side requests via HTTP-based connectors within BeyondInsight, resulting in a server-side request forgery vulnerability.

    Published: 4 Jun 2024
    6.1
    Medium

    CVE-2024-32464

    Last Modified: 21 Nov 2024

    Action Text brings rich text content and editing to Rails. Instances of ActionText::Attachable::ContentAttachment included within a rich_text_area tag could potentially contain unsanitized HTML. This vulnerability is fixed in 7.1.3.4 and 7.2.0.beta2.

    Published: 4 Jun 2024
    7.5
    High

    CVE-2024-4520

    Last Modified: 15 Oct 2025

    An improper access control vulnerability exists in the gaizhenbiao/chuanhuchatgpt application, specifically in version 20240410. This vulnerability allows any user on the server to access the chat history of any other user without requiring any form of interaction between the users. Exploitation of this vulnerability could lead to data breaches, including the exposure of sensitive personal details, financial data, or confidential conversations. Additionally, it could facilitate identity theft and manipulation or fraud through the unauthorized access to users' chat histories. This issue is due to insufficient access control mechanisms in the application's handling of chat history data.

    Published: 4 Jun 2024
    5.3
    Medium

    CVE-2024-30525

    Last Modified: 21 Nov 2024

    Missing Authorization vulnerability in moveaddons Move Addons for Elementor.This issue affects Move Addons for Elementor: from n/a through 1.2.9.

    Published: 4 Jun 2024
    5.4
    Medium

    CVE-2024-30528

    Last Modified: 21 Nov 2024

    Missing Authorization vulnerability in Spiffy Plugins Spiffy Calendar.This issue affects Spiffy Calendar: from n/a through 4.9.10.

    Published: 4 Jun 2024
    4.3
    Medium

    CVE-2024-30484

    Last Modified: 21 Nov 2024

    Missing Authorization vulnerability in RT Easy Builder – Advanced addons for Elementor.This issue affects RT Easy Builder – Advanced addons for Elementor: from n/a through 2.0.

    Published: 4 Jun 2024
    5.3
    Medium

    CVE-2024-35670

    Last Modified: 21 Nov 2024

    Broken Authentication vulnerability in SoftLab Integrate Google Drive.This issue affects Integrate Google Drive: from n/a through 1.3.93.

    Published: 4 Jun 2024
    6.5
    Medium

    CVE-2024-34759

    Last Modified: 21 Nov 2024

    Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in VideoWhisper Picture Gallery allows Stored XSS.This issue affects Picture Gallery: from n/a through 1.5.11.

    Published: 4 Jun 2024
    7.5
    High

    CVE-2024-35672

    Last Modified: 21 Nov 2024

    Missing Authorization vulnerability in Netgsm.This issue affects Netgsm: from n/a through 2.9.19.

    Published: 4 Jun 2024
    7.5
    High

    CVE-2024-25095

    Last Modified: 21 Nov 2024

    Insertion of Sensitive Information into Log File vulnerability in Code Parrots Easy Forms for Mailchimp.This issue affects Easy Forms for Mailchimp: from n/a through 6.9.0.

    Published: 4 Jun 2024
    9.8
    Critical

    CVE-2024-37273

    Last Modified: 13 Feb 2025

    An arbitrary file upload vulnerability in the /v1/app/appendFileSync interface of Jan v0.4.12 allows attackers to execute arbitrary code via uploading a crafted file.

    Published: 4 Jun 2024
    9.8
    Critical

    CVE-2024-36858

    Last Modified: 13 Feb 2025

    An arbitrary file upload vulnerability in the /v1/app/writeFileSync interface of Jan v0.4.12 allows attackers to execute arbitrary code via uploading a crafted file.

    Published: 4 Jun 2024
    7.5
    High

    CVE-2024-36857

    Last Modified: 13 Feb 2025

    Jan v0.4.12 was discovered to contain an arbitrary file read vulnerability via the /v1/app/readFileSync interface.

    Published: 4 Jun 2024
    9.8
    Critical

    CVE-2024-36604

    Last Modified: 13 Feb 2025

    Tenda O3V2 v1.0.0.12(3880) was discovered to contain a Blind Command Injection via stpEn parameter in the SetStp function. This vulnerability allows attackers to execute arbitrary commands with root privileges.

    Published: 4 Jun 2024
    7.1
    High

    CVE-2024-29004

    Last Modified: 21 Nov 2024

    The SolarWinds Platform was determined to be affected by a stored cross-site scripting vulnerability affecting the web console. A high-privileged user and user interaction is required to exploit this vulnerability.

    Published: 4 Jun 2024
    6.4
    Medium

    CVE-2024-28999

    Last Modified: 21 Nov 2024

    The SolarWinds Platform was determined to be affected by a Race Condition Vulnerability affecting the web console.

    Published: 4 Jun 2024
    7.5
    High

    CVE-2024-28996

    Last Modified: 21 Nov 2024

    The SolarWinds Platform was determined to be affected by a SWQL Injection Vulnerability. Attack complexity is high for this vulnerability.  

    Published: 4 Jun 2024
    8.8
    High

    CVE-2024-36550

    Last Modified: 13 Feb 2025

    idccms V1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via /admin/vpsCompany_deal.php?mudi=add&nohrefStr=close

    Published: 4 Jun 2024
    8.8
    High

    CVE-2024-36549

    Last Modified: 13 Feb 2025

    idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via /admin/vpsCompany_deal.php?mudi=rev&nohrefStr=close

    Published: 4 Jun 2024
    8.8
    High

    CVE-2024-36548

    Last Modified: 13 Feb 2025

    idccms V1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via admin/vpsCompany_deal.php?mudi=del

    Published: 4 Jun 2024
    8.8
    High

    CVE-2024-36547

    Last Modified: 13 Feb 2025

    idccms V1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component admin/vpsClass_deal.php?mudi=add

    Published: 4 Jun 2024
    7.5
    High

    CVE-2024-32871

    Last Modified: 21 Nov 2024

    Pimcore is an Open Source Data & Experience Management Platform. The Pimcore thumbnail generation can be used to flood the server with large files. By changing the file extension or scaling factor of the requested thumbnail, attackers can create files that are much larger in file size than the original. This vulnerability is fixed in 11.2.4.

    Published: 4 Jun 2024
    5.4
    Medium

    CVE-2024-0756

    Last Modified: 3 Mar 2026

    The Insert or Embed Articulate Content into WordPress plugin through 4.3000000023 lacks validation of URLs when adding iframes, allowing attackers to inject an iFrame in the page and thus load arbitrary content from any page.

    Published: 4 Jun 2024
    6.5
    Medium

    CVE-2024-35649

    Last Modified: 28 Apr 2026

    Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Pdfcrowd Save as PDF plugin by Pdfcrowd allows Stored XSS.This issue affects Save as PDF plugin by Pdfcrowd: from n/a through 3.2.3.

    Published: 4 Jun 2024
    6.5
    Medium

    CVE-2024-35651

    Last Modified: 21 Nov 2024

    Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Spiffy Plugins WP Flow Plus allows Stored XSS.This issue affects WP Flow Plus: from n/a through 5.2.2.

    Published: 4 Jun 2024
    7.1
    High

    CVE-2024-35652

    Last Modified: 28 Apr 2026

    Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Saso Nikolov Event Tickets with Ticket Scanner allows Reflected XSS.This issue affects Event Tickets with Ticket Scanner: from n/a through 2.3.1.

    Published: 4 Jun 2024
    9.4
    Critical

    CVE-2024-36400

    Last Modified: 21 Nov 2024

    nano-id is a unique string ID generator for Rust. Affected versions of the nano-id crate incorrectly generated IDs using a reduced character set in the `nano_id::base62` and `nano_id::base58` functions. Specifically, the `base62` function used a character set of 32 symbols instead of the intended 62 symbols, and the `base58` function used a character set of 16 symbols instead of the intended 58 symbols. Additionally, the `nano_id::gen` macro is also affected when a custom character set that is not a power of 2 in size is specified. It should be noted that `nano_id::base64` is not affected by this vulnerability. This can result in a significant reduction in entropy, making the generated IDs predictable and vulnerable to brute-force attacks when the IDs are used in security-sensitive contexts such as session tokens or unique identifiers. The vulnerability is fixed in 0.4.0.

    Published: 4 Jun 2024
    6.5
    Medium

    CVE-2024-35653

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Visual Composer Visual Composer Website Builder visualcomposer.This issue affects Visual Composer Website Builder: from n/a through <= 45.8.0.

    Published: 4 Jun 2024
    6.5
    Medium

    CVE-2024-35654

    Last Modified: 21 Nov 2024

    Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in CyberChimps Responsive allows Stored XSS.This issue affects Responsive: from n/a through 5.0.3.

    Published: 4 Jun 2024
    5.9
    Medium

    CVE-2024-35655

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Brave Brave brave-popup-builder allows DOM-Based XSS.This issue affects Brave: from n/a through <= 0.6.9.

    Published: 4 Jun 2024
    7.1
    High

    CVE-2024-35664

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpvividplugins WPvivid Backup for MainWP wpvivid-backup-mainwp allows Reflected XSS.This issue affects WPvivid Backup for MainWP: from n/a through <= 0.9.32.

    Published: 4 Jun 2024
    6.5
    Medium

    CVE-2024-35666

    Last Modified: 21 Nov 2024

    Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Themesflat Themesflat Addons For Elementor allows Stored XSS.This issue affects Themesflat Addons For Elementor: from n/a through 2.1.2.

    Published: 4 Jun 2024
    7.1
    High

    CVE-2024-35668

    Last Modified: 21 Nov 2024

    Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Brevo Newsletter, SMTP, Email marketing and Subscribe forms by Sendinblue allows Reflected XSS.This issue affects Newsletter, SMTP, Email marketing and Subscribe forms by Sendinblue: from n/a through 3.1.77.

    Published: 4 Jun 2024
    6.5
    Medium

    CVE-2024-35782

    Last Modified: 28 Apr 2026

    Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Codeless Cowidgets – Elementor Addons allows Stored XSS.This issue affects Cowidgets – Elementor Addons: from n/a through 1.1.1.

    Published: 4 Jun 2024
    9.8
    Critical

    CVE-2024-35700

    Last Modified: 23 Apr 2026

    Incorrect Privilege Assignment vulnerability in DeluxeThemes Userpro userpro.This issue affects Userpro: from n/a through <= 5.1.8.

    Published: 4 Jun 2024
    4.9
    Medium

    CVE-2024-35634

    Last Modified: 21 Nov 2024

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Wow-Company Woocommerce – Recent Purchases allows PHP Local File Inclusion.This issue affects Woocommerce – Recent Purchases: from n/a through 1.0.1.

    Published: 4 Jun 2024
    9.6
    Critical

    CVE-2024-35629

    Last Modified: 21 Nov 2024

    Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Wow-Company Easy Digital Downloads – Recent Purchases allows PHP Remote File Inclusion.This issue affects Easy Digital Downloads – Recent Purchases: from n/a through 1.0.2.

    Published: 4 Jun 2024
    9.1
    Critical

    CVE-2024-34792

    Last Modified: 21 Nov 2024

    Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in dexta Dextaz Ping allows Command Injection.This issue affects Dextaz Ping: from n/a through 0.65.

    Published: 4 Jun 2024
    8.5
    High

    CVE-2024-34554

    Last Modified: 28 Apr 2026

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Select-Themes Stockholm Core allows PHP Local File Inclusion.This issue affects Stockholm Core: from n/a through 2.4.1.

    Published: 4 Jun 2024
    8.5
    High

    CVE-2024-34552

    Last Modified: 21 Nov 2024

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Select-Themes Stockholm allows PHP Local File Inclusion.This issue affects Stockholm: from n/a through 9.6.

    Published: 4 Jun 2024
    9
    Critical

    CVE-2024-34551

    Last Modified: 21 Nov 2024

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Select-Themes Stockholm allows PHP Local File Inclusion.This issue affects Stockholm: from n/a through 9.6.

    Published: 4 Jun 2024
    6.5
    Medium

    CVE-2024-34384

    Last Modified: 21 Nov 2024

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in SinaExtra Sina Extension for Elementor allows PHP Local File Inclusion.This issue affects Sina Extension for Elementor: from n/a through 3.5.1.

    Published: 4 Jun 2024
    8.8
    High

    CVE-2024-33628

    Last Modified: 15 Apr 2026

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in XforWooCommerce allows PHP Local File Inclusion.This issue affects XforWooCommerce: from n/a through 2.0.2.

    Published: 4 Jun 2024
    8.5
    High

    CVE-2024-33568

    Last Modified: 28 Apr 2026

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'), Deserialization of Untrusted Data vulnerability in BdThemes Element Pack Pro allows Path Traversal, Object Injection.This issue affects Element Pack Pro: from n/a before 7.19.3.

    Published: 4 Jun 2024
    9
    Critical

    CVE-2024-33560

    Last Modified: 15 Apr 2026

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in 8theme XStore allows PHP Local File Inclusion.This issue affects XStore: from n/a through 9.3.8.

    Published: 4 Jun 2024
    8.5
    High

    CVE-2024-33557

    Last Modified: 26 Feb 2025

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in 8theme XStore Core allows PHP Local File Inclusion.This issue affects XStore Core: from n/a through 5.3.8.

    Published: 4 Jun 2024
    6.5
    Medium

    CVE-2024-33541

    Last Modified: 21 Nov 2024

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in BetterAddons Better Elementor Addons allows PHP Local File Inclusion.This issue affects Better Elementor Addons: from n/a through 1.4.1.

    Published: 4 Jun 2024
    10
    Critical

    CVE-2024-25600

    Last Modified: 15 Apr 2026

    Improper Control of Generation of Code ('Code Injection') vulnerability in Codeer Limited Bricks Builder allows Code Injection.This issue affects Bricks Builder: from n/a through 1.9.6.

    Published: 4 Jun 2024
    7.5
    High

    CVE-2024-36800

    Last Modified: 3 Apr 2025

    A SQL injection vulnerability in SEMCMS v.4.8, allows a remote attacker to obtain sensitive information via the ID parameter in Download.php.

    Published: 4 Jun 2024