CVE Feed

    Dashboard / CVE

    8.8
    High

    CVE-2024-23316

    Last Modified: 15 Apr 2026

    HTTP request desynchronization in Ping Identity PingAccess, all versions prior to 8.0.1 affected allows an attacker to send specially crafted http header requests to create a request smuggling condition for proxied requests.

    Published: 31 May 2024
    9.1
    Critical

    CVE-2024-31030

    Last Modified: 20 Jun 2025

    An issue in coap_msg.c in Keith Cullen's FreeCoAP v.0.7 allows remote attackers to cause a Denial of Service or potentially disclose information via a specially crafted packet.

    Published: 31 May 2024
    6.5
    Medium

    CVE-2021-44534

    Last Modified: 15 Apr 2026

    Insufficient user input filtering leads to arbitrary file read by non-authenticated attacker, which results in sensitive information disclosure.

    Published: 31 May 2024
    7.8
    High

    CVE-2023-38042

    Last Modified: 20 Jun 2025

    A local privilege escalation vulnerability in Ivanti Secure Access Client for Windows allows a low privileged user to execute code as SYSTEM.

    Published: 31 May 2024
    7.3
    High

    CVE-2023-46810

    Last Modified: 20 Jun 2025

    A local privilege escalation vulnerability in Ivanti Secure Access Client for Linux before 22.7R1, allows a low privileged user to execute code as root.

    Published: 31 May 2024
    8.8
    High

    CVE-2024-22059

    Last Modified: 30 Jun 2025

    A SQL injection vulnerability in web component of Ivanti Neurons for ITSM allows a remote authenticated user to read/modify/delete information in the underlying database. This may also lead to DoS.

    Published: 31 May 2024
    8.8
    High

    CVE-2024-29823

    Last Modified: 21 Nov 2024

    An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2022 SU5 and prior allows an unauthenticated attacker within the same network to execute arbitrary code.

    Published: 31 May 2024
    8.8
    High

    CVE-2024-29827

    Last Modified: 21 Nov 2024

    An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2022 SU5 and prior allows an unauthenticated attacker within the same network to execute arbitrary code.

    Published: 31 May 2024
    4.9
    Medium

    CVE-2024-22060

    Last Modified: 30 Jun 2025

    An unrestricted file upload vulnerability in web component of Ivanti Neurons for ITSM allows a remote, authenticated, high privileged user to write arbitrary files into sensitive directories of ITSM server.

    Published: 31 May 2024
    8.8
    High

    CVE-2024-29822

    Last Modified: 21 Nov 2024

    An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2022 SU5 and prior allows an unauthenticated attacker within the same network to execute arbitrary code.

    Published: 31 May 2024
    8.8
    High

    CVE-2024-29826

    Last Modified: 21 Nov 2024

    An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2022 SU5 and prior allows an unauthenticated attacker within the same network to execute arbitrary code.

    Published: 31 May 2024
    8
    High

    CVE-2024-29828

    Last Modified: 21 Nov 2024

    An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2022 SU5 and prior allows an authenticated attacker within the same network to execute arbitrary code.

    Published: 31 May 2024
    8
    High

    CVE-2024-29829

    Last Modified: 21 Nov 2024

    An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2022 SU5 and prior allows an authenticated attacker within the same network to execute arbitrary code.

    Published: 31 May 2024
    7.2
    High

    CVE-2024-29848

    Last Modified: 6 May 2025

    An unrestricted file upload vulnerability in web component of Ivanti Avalanche before 6.4.x allows an authenticated, privileged user to execute arbitrary commands as SYSTEM.

    Published: 31 May 2024
    8
    High

    CVE-2024-29846

    Last Modified: 21 Nov 2024

    An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2022 SU5 and prior allows an authenticated attacker within the same network to execute arbitrary code.

    Published: 31 May 2024
    8.2
    High

    CVE-2023-38551

    Last Modified: 15 Apr 2026

    A CRLF Injection vulnerability in Ivanti Connect Secure (9.x, 22.x) allows an authenticated high-privileged user to inject malicious code on a victim’s browser, thereby leading to cross-site scripting attack.

    Published: 31 May 2024
    8
    High

    CVE-2024-29830

    Last Modified: 21 Nov 2024

    An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2022 SU5 and prior allows an authenticated attacker within the same network to execute arbitrary code.

    Published: 31 May 2024
    7.8
    High

    CVE-2024-22058

    Last Modified: 20 Jun 2025

    A buffer overflow allows a low privilege user on the local machine that has the EPM Agent installed to execute arbitrary code with elevated permissions in Ivanti EPM 2021.1 and older.

    Published: 31 May 2024
    8.8
    High

    CVE-2024-29824

    Last Modified: 30 Oct 2025

    An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2022 SU5 and prior allows an unauthenticated attacker within the same network to execute arbitrary code.

    Published: 31 May 2024
    8.8
    High

    CVE-2024-29825

    Last Modified: 21 Nov 2024

    An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2022 SU5 and prior allows an unauthenticated attacker within the same network to execute arbitrary code.

    Published: 31 May 2024
    9.4
    Critical

    CVE-2024-5176

    Last Modified: 15 Apr 2026

    Insufficiently Protected Credentials vulnerability in Baxter Welch Allyn Configuration Tool may allow Remote Services with Stolen Credentials.This issue affects Welch Allyn Configuration Tool: versions 1.9.4.1 and prior.

    Published: 31 May 2024
    2
    Low

    CVE-2024-35196

    Last Modified: 15 Apr 2026

    Sentry is a developer-first error tracking and performance monitoring platform. Sentry's Slack integration incorrectly records the incoming request body in logs. This request data can contain sensitive information, including the deprecated Slack verification token. With this verification token, it is possible under specific configurations, an attacker can forge requests and act as the Slack integration. The request body is leaked in log entries matching `event == "slack.*" && name == "sentry.integrations.slack" && request_data == *`. The deprecated slack verification token, will be found in the `request_data.token` key. **SaaS users** do not need to take any action. **Self-hosted users** should upgrade to version 24.5.0 or higher, rotate their Slack verification token, and use the Slack Signing Secret instead of the verification token. For users only using the `slack.signing-secret` in their self-hosted configuration, the legacy verification token is not used to verify the webhook payload. It is ignored. Users unable to upgrade should either set the `slack.signing-secret` instead of `slack.verification-token`. The signing secret is Slack's recommended way of authenticating webhooks. By having `slack.singing-secret` set, Sentry self-hosted will no longer use the verification token for authentication of the webhooks, regardless of whether `slack.verification-token` is set or not. Alternatively if the self-hosted instance is unable to be upgraded or re-configured to use the `slack.signing-secret`, the logging configuration can be adjusted to not generate logs from the integration. The default logging configuration can be found in `src/sentry/conf/server.py`. **Services should be restarted once the configuration change is saved.**

    Published: 31 May 2024
    9.1
    Critical

    CVE-2024-1275

    Last Modified: 15 Apr 2026

    Use of Default Cryptographic Key vulnerability in Baxter Welch Allyn Connex Spot Monitor may allow Configuration/Environment Manipulation.This issue affects Welch Allyn Connex Spot Monitor in all versions prior to 1.52.

    Published: 31 May 2024
    8.4
    High

    CVE-2024-35142

    Last Modified: 3 Nov 2025

    IBM Security Verify Access Docker 10.0.0 through 10.0.6 could allow a local user to escalate their privileges due to execution of unnecessary privileges. IBM X-Force ID: 292418.

    Published: 31 May 2024
    7.7
    High

    CVE-2024-35140

    Last Modified: 3 Nov 2025

    IBM Security Verify Access Docker 10.0.0 through 10.0.6 could allow a local user to escalate their privileges due to improper certificate validation. IBM X-Force ID: 292416.

    Published: 31 May 2024
    8.1
    High

    CVE-2024-36120

    Last Modified: 21 Nov 2024

    javascript-deobfuscator removes common JavaScript obfuscation techniques. In affected versions crafted payloads targeting expression simplification can lead to code execution. This issue has been patched in version 1.1.0. Users are advised to update. Users unable to upgrade should disable the expression simplification feature.

    Published: 31 May 2024
    5.4
    Medium

    CVE-2022-25037

    Last Modified: 15 Apr 2026

    An issue in wanEditor v4.7.11 and fixed in v.4.7.12 and v.5 was discovered to contain a cross-site scripting (XSS) vulnerability via the image upload function.

    Published: 31 May 2024
    6.1
    Medium

    CVE-2022-25038

    Last Modified: 15 Apr 2026

    wanEditor v4.7.11 was discovered to contain a cross-site scripting (XSS) vulnerability via the video upload function.

    Published: 31 May 2024
    7.1
    High

    CVE-2024-28736

    Last Modified: 15 Apr 2026

    An issue in Debezium Community debezium-ui v.2.5 allows a local attacker to execute arbitrary code via the refresh page function.

    Published: 31 May 2024
    9.8
    Critical

    CVE-2024-36108

    Last Modified: 15 Apr 2026

    casgate is an Open Source Identity and Access Management system. In affected versions `casgate` allows remote unauthenticated attacker to obtain sensitive information via GET request to an API endpoint. This issue has been addressed in PR #201 which is pending merge. An attacker could use `id` parameter of GET requests with value `anonymous/ anonymous` to bypass authorization on certain API endpoints. Successful exploitation of the vulnerability could lead to account takeover, privilege escalation or provide attacker with credential to other services. Users are advised to upgrade. There are no known workarounds for this vulnerability.

    Published: 31 May 2024
    6.4
    Medium

    CVE-2023-7073

    Last Modified: 15 Apr 2026

    The Auto Featured Image (Auto Post Thumbnail) plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 4.1.7 via the upload_to_library AJAX action. This makes it possible for authenticated attackers, with author-level access and above, to make web requests to arbitrary locations originating from the web application and can be used to query and modify information from internal services.

    Published: 31 May 2024
    8.1
    High

    CVE-2024-5565

    Last Modified: 15 Apr 2026

    The Vanna library uses a prompt function to present the user with visualized results, it is possible to alter the prompt using prompt injection and run arbitrary Python code instead of the intended visualization code. Specifically - allowing external input to the library’s “ask” method with "visualize" set to True (default behavior) leads to remote code execution.

    Published: 31 May 2024
    5.4
    Medium

    CVE-2024-31907

    Last Modified: 8 Jan 2025

    IBM Planning Analytics Local 2.0 and 2.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 289889.

    Published: 31 May 2024
    6.4
    Medium

    CVE-2024-31908

    Last Modified: 8 Jan 2025

    IBM Planning Analytics Local 2.0 and 2.1 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 289890.

    Published: 31 May 2024
    5.4
    Medium

    CVE-2024-31889

    Last Modified: 8 Jan 2025

    IBM Planning Analytics Local 2.0 and 2.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 288136.

    Published: 31 May 2024
    4
    Medium

    CVE-2024-22338

    Last Modified: 14 Aug 2025

    IBM Security Verify Access OIDC Provider 22.09 through 23.03 could disclose sensitive information to a local user due to hazardous input validation. IBM X-Force ID: 279978.

    Published: 31 May 2024
    9.8
    Critical

    CVE-2024-23692

    Last Modified: 22 Nov 2025

    Rejetto HTTP File Server, up to and including version 2.3m, is vulnerable to a template injection vulnerability. This vulnerability allows a remote, unauthenticated attacker to execute arbitrary commands on the affected system by sending a specially crafted HTTP request. As of the CVE assignment date, Rejetto HFS 2.3m is no longer supported.

    Published: 31 May 2024
    6.4
    Medium

    CVE-2024-5041

    Last Modified: 8 Apr 2026

    The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘ha-ia-content-button’ parameter in all versions up to, and including, 3.10.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 31 May 2024
    6.4
    Medium

    CVE-2024-4160

    Last Modified: 8 Apr 2026

    The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wpdm-all-packages' shortcode in all versions up to, and including, 3.2.90 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 31 May 2024
    6.4
    Medium

    CVE-2024-5347

    Last Modified: 8 Apr 2026

    The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'arrow' attribute within the plugin's Post Navigation widget in all versions up to, and including, 3.10.9 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 31 May 2024
    7.3
    High

    CVE-2024-5436

    Last Modified: 22 Jul 2025

    Type confusion in Snapchat LensCore could lead to denial of service or arbitrary code execution prior to version 12.88. We recommend upgrading to version 12.88 or above.

    Published: 31 May 2024
    8.3
    High

    CVE-2024-5525

    Last Modified: 23 Oct 2025

    Improper privilege management vulnerability in Astrotalks affecting version 10/03/2023. This vulnerability allows a local user to access the application as an administrator without any provided credentials, allowing the attacker to perform administrative actions.

    Published: 31 May 2024
    5.3
    Medium

    CVE-2024-5524

    Last Modified: 23 Oct 2025

    Information exposure vulnerability in Astrotalks affecting version 10/03/2023. This vulnerability allows unregistered users to access all internal links of the application without providing any credentials.

    Published: 31 May 2024
    8.8
    High

    CVE-2024-5523

    Last Modified: 23 Oct 2025

    SQL injection vulnerability in Astrotalks affecting version 10/03/2023. This vulnerability could allow an authenticated local user to send a specially crafted SQL query to the 'searchString' parameter and retrieve all information stored in the database.

    Published: 31 May 2024
    6.4
    Medium

    CVE-2024-5427

    Last Modified: 8 Apr 2026

    The WPCafe – Online Food Ordering, Restaurant Menu, Delivery, and Reservations for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Reservation Form shortcode in all versions up to, and including, 2.2.24 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 31 May 2024
    9.8
    Critical

    CVE-2024-36246

    Last Modified: 15 Apr 2026

    Missing authorization vulnerability exists in Unifier and Unifier Cast. If this vulnerability is exploited, arbitrary code may be executed with LocalSystem privilege. As a result, a malicious program may be installed, data may be altered or deleted.

    Published: 31 May 2024
    5.9
    Medium

    CVE-2024-23847

    Last Modified: 15 Apr 2026

    Incorrect default permissions issue exists in Unifier and Unifier Cast. If this vulnerability is exploited, arbitrary code may be executed with LocalSystem privilege. As a result, a malicious program may be installed, data may be altered or deleted.

    Published: 31 May 2024
    7.5
    High

    CVE-2024-4469

    Last Modified: 21 May 2025

    The WP STAGING WordPress Backup Plugin WordPress plugin before 3.5.0 does not prevent users with the administrator role from pinging conducting SSRF attacks, which may be a problem in multisite configurations.

    Published: 31 May 2024
    5.4
    Medium

    CVE-2024-4379

    Last Modified: 8 Apr 2026

    The Premium Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Global Tooltip widget in all versions up to, and including, 4.10.31 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 31 May 2024
    6.4
    Medium

    CVE-2024-4376

    Last Modified: 8 Apr 2026

    The Premium Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Fancy Text widget in all versions up to, and including, 4.10.31 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. While 4.10.32 is patched, it is recommended to update to 4.10.33 because 4.10.32 caused a fatal error.

    Published: 31 May 2024