CVE Feed

    Dashboard / CVE

    4.3
    Medium

    CVE-2024-4205

    Last Modified: 8 Apr 2026

    The Premium Addons for Elementor plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the get_template_content() function in all versions up to, and including, 4.10.31. This makes it possible for authenticated attackers, with subscriber-level access and above, to retrieve Elementor template data.

    Published: 31 May 2024
    7.2
    High

    CVE-2024-2793

    Last Modified: 15 Apr 2026

    The Visual Website Collaboration, Feedback & Project Management – Atarim plugin for WordPress is vulnerable to Stored Cross-Site Scripting via comments in all versions up to, and including, 3.30 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 31 May 2024
    6.4
    Medium

    CVE-2024-5418

    Last Modified: 8 Apr 2026

    The DethemeKit For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'slitems' attribute within the plugin's De Product Tab & Slide widget in all versions up to, and including, 2.1.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 31 May 2024
    8.8
    High

    CVE-2024-5345

    Last Modified: 15 Apr 2026

    The Responsive Owl Carousel for Elementor plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.2.0 via the layout parameter. This makes it possible for authenticated attackers, with Contributor-level access and above, to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where images and other “safe” file types can be uploaded and included. The inclusion is limited to PHP files.

    Published: 31 May 2024
    9.8
    Critical

    CVE-2024-32850

    Last Modified: 15 Apr 2026

    Improper neutralization of special elements used in a command ('Command Injection') exists in SkyBridge MB-A100/MB-A110 firmware Ver. 4.2.2 and earlier and SkyBridge BASIC MB-A130 firmware Ver. 1.5.5 and earlier. If the remote monitoring and control function is enabled on the product, an attacker with access to the product may execute an arbitrary command or login to the product with the administrator privilege.

    Published: 31 May 2024
    9.1
    Critical

    CVE-2024-37018

    Last Modified: 15 Apr 2026

    The OpenDaylight 0.15.3 controller allows topology poisoning via API requests because an application can manipulate the path that is taken by discovery packets.

    Published: 31 May 2024
    8.1
    High

    CVE-2024-5564

    Last Modified: 15 Apr 2026

    A vulnerability was found in libndp. This flaw allows a local malicious user to cause a buffer overflow in NetworkManager, triggered by sending a malformed IPv6 router advertisement packet. This issue occurred as libndp was not correctly validating the route length information.

    Published: 31 May 2024
    8.8
    High

    CVE-2024-37032

    Last Modified: 1 May 2025

    Ollama before 0.1.34 does not validate the format of the digest (sha256 with 64 hex digits) when getting the model path, and thus mishandles the TestGetBlobsPath test cases such as fewer than 64 hex digits, more than 64 hex digits, or an initial ../ substring.

    Published: 31 May 2024
    7.5
    High

    CVE-2024-36843

    Last Modified: 3 Nov 2025

    libmodbus v3.1.6 was discovered to contain a heap overflow via the modbus_mapping_free() function.

    Published: 31 May 2024
    8.1
    High

    CVE-2024-37017

    Last Modified: 15 Apr 2026

    asdcplib (aka AS-DCP Lib) 2.13.1 has a heap-based buffer over-read in ASDCP::TimedText::MXFReader::h__Reader::MD_to_TimedText_TDesc in AS_DCP_TimedText.cpp in libasdcp.so.

    Published: 30 May 2024
    8.8
    High

    CVE-2024-5499

    Last Modified: 13 Feb 2025

    Out of bounds write in Streams API in Google Chrome prior to 125.0.6422.141 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

    Published: 30 May 2024
    8.8
    High

    CVE-2024-5498

    Last Modified: 13 Feb 2025

    Use after free in Presentation API in Google Chrome prior to 125.0.6422.141 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

    Published: 30 May 2024
    8.8
    High

    CVE-2024-5497

    Last Modified: 13 Feb 2025

    Out of bounds memory access in Browser UI in Google Chrome prior to 125.0.6422.141 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

    Published: 30 May 2024
    8.8
    High

    CVE-2024-5496

    Last Modified: 13 Feb 2025

    Use after free in Media Session in Google Chrome prior to 125.0.6422.141 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

    Published: 30 May 2024
    8.8
    High

    CVE-2024-5495

    Last Modified: 13 Feb 2025

    Use after free in Dawn in Google Chrome prior to 125.0.6422.141 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

    Published: 30 May 2024
    8.8
    High

    CVE-2024-5494

    Last Modified: 13 Feb 2025

    Use after free in Dawn in Google Chrome prior to 125.0.6422.141 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

    Published: 30 May 2024
    8.8
    High

    CVE-2024-5493

    Last Modified: 13 Feb 2025

    Heap buffer overflow in WebRTC in Google Chrome prior to 125.0.6422.141 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

    Published: 30 May 2024
    1.8
    Low

    CVE-2024-36119

    Last Modified: 15 Apr 2026

    Statamic is a, Laravel + Git powered CMS designed for building websites. In affected versions users registering via the `user:register_form` tag will have their password confirmation stored in plain text in their user file. This only affects sites matching **all** of the following conditions: 1. Running Statamic versions between 5.3.0 and 5.6.1. (This version range represents only one calendar week), 2. Using the `user:register_form` tag. 3. Using file-based user accounts. (Does not affect users stored in a database.), 4. Has users that have registered during that time period. (Existing users are not affected.). Additionally passwords are only visible to users that have access to read user yaml files, typically developers of the application itself. This issue has been patched in version 5.6.2, however any users registered during that time period and using the affected version range will still have the the `password_confirmation` value in their yaml files. We recommend that affected users have their password reset. System administrators are advised to upgrade their deployments. There are no known workarounds for this vulnerability. Anyone who commits their files to a public git repo, may consider clearing the sensitive data from the git history as it is likely that passwords were uploaded.

    Published: 30 May 2024
    6
    Medium

    CVE-2024-1298

    Last Modified: 15 Apr 2026

    EDK2 contains a vulnerability when S3 sleep is activated where an Attacker may cause a Division-By-Zero due to a UNIT32 overflow via local access. A successful exploit of this vulnerability may lead to a loss of Availability.

    Published: 30 May 2024
    8.5
    High

    CVE-2024-34171

    Last Modified: 30 Jul 2025

    Fuji Electric Monitouch V-SFT is vulnerable to a stack-based buffer overflow, which could allow an attacker to execute arbitrary code.

    Published: 30 May 2024
    8.5
    High

    CVE-2024-5271

    Last Modified: 30 Jul 2025

    Fuji Electric Monitouch V-SFT is vulnerable to an out-of-bounds write because of a type confusion, which could result in arbitrary code execution.

    Published: 30 May 2024
    4.2
    Medium

    CVE-2024-32877

    Last Modified: 22 Sept 2025

    Yii 2 is a PHP application framework. During internal penetration testing of a product based on Yii2, users discovered a Cross-site Scripting (XSS) vulnerability within the framework itself. This issue is relevant for the latest version of Yii2 (2.0.49.3). This issue lies in the mechanism for displaying function argument values in the stack trace. The vulnerability manifests when an argument's value exceeds 32 characters. For convenience, argument values exceeding this limit are truncated and displayed with an added "...". The full argument value becomes visible when hovering over it with the mouse, as it is displayed in the title attribute of a span tag. However, the use of a double quote (") allows an attacker to break out of the title attribute's value context and inject their own attributes into the span tag, including malicious JavaScript code through event handlers such as onmousemove. This vulnerability allows an attacker to execute arbitrary JavaScript code in the security context of the victim's site via a specially crafted link. This could lead to the theft of cookies (including httpOnly cookies, which are accessible on the page), content substitution, or complete takeover of user accounts. This issue has been addressed in version 2.0.50. Users are advised to upgrade. There are no known workarounds for this vulnerability.

    Published: 30 May 2024
    6.5
    Medium

    CVE-2024-35189

    Last Modified: 20 Oct 2025

    Fides is an open-source privacy engineering platform. The Fides webserver has a number of endpoints that retrieve `ConnectionConfiguration` records and their associated `secrets` which _can_ contain sensitive data (e.g. passwords, private keys, etc.). These `secrets` are stored encrypted at rest (in the application database), and the associated endpoints are not meant to expose that sensitive data in plaintext to API clients, as it could be compromising. Fides's developers have available to them a Pydantic field-attribute (`sensitive`) that they can annotate as `True` to indicate that a given secret field should not be exposed via the API. The application has an internal function that uses `sensitive` annotations to mask the sensitive fields with a `"**********"` placeholder value. This vulnerability is due to a bug in that function, which prevented `sensitive` API model fields that were _nested_ below the root-level of a `secrets` object from being masked appropriately. Only the `BigQuery` connection configuration secrets meets these criteria: the secrets schema has a nested sensitive `keyfile_creds.private_key` property that is exposed in plaintext via the APIs. Connection types other than `BigQuery` with sensitive fields at the root-level that are not nested are properly masked with the placeholder and are not affected by this vulnerability. This vulnerability has been patched in Fides version 2.37.0. Users are advised to upgrade to this version or later to secure their systems against this threat. Users are also advised to rotate any Google Cloud secrets used for BigQuery integrations in their Fides deployments. There are no known workarounds for this vulnerability.

    Published: 30 May 2024
    5.5
    Medium

    CVE-2024-35228

    Last Modified: 15 Apr 2026

    Wagtail is an open source content management system built on Django. Due to an improperly applied permission check in the `wagtail.contrib.settings` module, a user with access to the Wagtail admin and knowledge of the URL of the edit view for a settings model can access and update that setting, even when they have not been granted permission over the model. The vulnerability is not exploitable by an ordinary site visitor without access to the Wagtail admin. Patched versions have been released as Wagtail 6.0.5 and 6.1.2. Wagtail releases prior to 6.0 are unaffected. Users are advised to upgrade. Site owners who are unable to upgrade to a patched version can avoid the vulnerability in `ModelViewSet` by registering the model as a snippet instead. No workaround is available for `wagtail.contrib.settings`.

    Published: 30 May 2024
    9.3
    Critical

    CVE-2024-2422

    Last Modified: 2 Feb 2026

    LenelS2 NetBox access control and event monitoring system was discovered to contain an authenticated RCE in versions prior to and including 5.6.1, which allows an attacker to execute malicious commands.

    Published: 30 May 2024
    9.3
    Critical

    CVE-2024-2421

    Last Modified: 2 Feb 2026

    LenelS2 NetBox access control and event monitoring system was discovered to contain an unauthenticated RCE in versions prior to and including 5.6.1, which allows an attacker to execute malicious commands with elevated permissions.

    Published: 30 May 2024
    8.8
    High

    CVE-2024-2420

    Last Modified: 2 Feb 2026

    LenelS2 NetBox access control and event monitoring system was discovered to contain Hardcoded Credentials in versions prior to and including 5.6.1 which allows an attacker to bypass authentication requirements.

    Published: 30 May 2024
    9.8
    Critical

    CVE-2024-35469

    Last Modified: 11 Apr 2025

    A SQL injection vulnerability in /hrm/user/ in SourceCodester Human Resource Management System 1.0 allows attackers to execute arbitrary SQL commands via the password parameter.

    Published: 30 May 2024
    5.4
    Medium

    CVE-2024-35468

    Last Modified: 11 Apr 2025

    A SQL injection vulnerability in /hrm/index.php in SourceCodester Human Resource Management System 1.0 allows attackers to execute arbitrary SQL commands via the password parameter.

    Published: 30 May 2024
    8.1
    High

    CVE-2024-35433

    Last Modified: 17 Jun 2025

    ZKTeco ZKBio CVSecurity 6.1.1 is vulnerable to Incorrect Access Control. An authenticated user, without the permissions of managing users, can create a new admin user.

    Published: 30 May 2024
    7.1
    High

    CVE-2024-35428

    Last Modified: 13 Mar 2025

    ZKTeco ZKBio CVSecurity 6.1.1 is vulnerable to Directory Traversal via BaseMediaFile. An authenticated user can delete local files from the server which can lead to DoS.

    Published: 30 May 2024
    3.5
    Low

    CVE-2024-36118

    Last Modified: 21 Nov 2024

    MeterSphere is a test management and interface testing tool. In affected versions users without workspace permissions can view functional test cases of other workspaces beyond their authority. This issue has been addressed in version 2.10.15-lts. Users of MeterSphere are advised to upgrade. There are no known workarounds for this vulnerability.

    Published: 30 May 2024
    —
    Unknown

    CVE-2024-36998

    Last Modified: 22 Jan 2026

    ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. The CVE was never used.

    Published: 30 May 2024
    —
    Unknown

    CVE-2024-36988

    Last Modified: 22 Jan 2026

    ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. The CVE was never used.

    Published: 30 May 2024
    —
    Unknown

    CVE-2024-5538

    Last Modified: 31 May 2024

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

    Published: 30 May 2024
    —
    Unknown

    CVE-2024-5537

    Last Modified: 31 May 2024

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

    Published: 30 May 2024
    6.5
    Medium

    CVE-2024-35429

    Last Modified: 13 Feb 2025

    ZKTeco ZKBio CVSecurity 6.1.1 is vulnerable to Directory Traversal via eventRecord.

    Published: 30 May 2024
    9.8
    Critical

    CVE-2024-35349

    Last Modified: 13 Feb 2025

    A vulnerability has been discovered in Diño Physics School Assistant version 2.3. The vulnerability impacts an unidentified code within the file /admin/category/view_category.php. Manipulating the argument id can result in SQL injection.

    Published: 30 May 2024
    9.8
    Critical

    CVE-2024-35350

    Last Modified: 11 Apr 2025

    A vulnerability has been discovered in Diño Physics School Assistant version 2.3. The vulnerability impacts an unidentified code within the file /admin/?page=borrow/view_borrow. Manipulating the argument id can result in SQL injection.

    Published: 30 May 2024
    5.4
    Medium

    CVE-2024-35351

    Last Modified: 11 Apr 2025

    A vulnerability has been discovered in Diño Physics School Assistant version 2.3. This vulnerability impacts unidentified code within the file /classes/SystemSettings.php?f=update_settings. Manipulating the parameter name results in cross-site scripting.

    Published: 30 May 2024
    9.8
    Critical

    CVE-2024-35359

    Last Modified: 13 Feb 2025

    A vulnerability has been discovered in Diño Physics School Assistant version 2.3. The vulnerability impacts an unidentified code within the file /classes/Master.php?f=view_item. Manipulating the argument id can result in SQL injection.

    Published: 30 May 2024
    7.5
    High

    CVE-2024-35431

    Last Modified: 17 Jun 2025

    ZKTeco ZKBio CVSecurity 6.1.1 is vulnerable to Directory Traversal via photoBase64. An unauthenticated user can download local files from the server. NOTE: Third parties have indicated other versions are also vulnerable including up to 6.4.1.

    Published: 30 May 2024
    6.1
    Medium

    CVE-2024-35352

    Last Modified: 11 Apr 2025

    A vulnerability has been discovered in Diño Physics School Assistant version 2.3. This vulnerability impacts unidentified code within the file /classes/Users.php?f=save. Manipulating the parameter middlename results in cross-site scripting.

    Published: 30 May 2024
    9.8
    Critical

    CVE-2024-35353

    Last Modified: 11 Apr 2025

    A vulnerability has been discovered in Diño Physics School Assistant version 2.3. The vulnerability impacts an unidentified code within the file /classes/Users.php?f=save. Manipulating the argument id can result in improper authorization.

    Published: 30 May 2024
    6.1
    Medium

    CVE-2024-35432

    Last Modified: 17 Jun 2025

    ZKTeco ZKBio CVSecurity 6.1.1 is vulnerable to Cross Site Scripting (XSS) via an Audio File. An authenticated user can injection malicious JavaScript code to trigger a Cross Site Scripting.

    Published: 30 May 2024
    9.8
    Critical

    CVE-2024-35354

    Last Modified: 11 Apr 2025

    A vulnerability has been discovered in Diño Physics School Assistant version 2.3. The vulnerability impacts an unidentified code within the file /classes/Master.php?f=save_category. Manipulating the argument id can result in SQL injection.

    Published: 30 May 2024
    9.8
    Critical

    CVE-2024-35355

    Last Modified: 11 Apr 2025

    A vulnerability has been discovered in Diño Physics School Assistant version 2.3. The vulnerability impacts an unidentified code within the file /classes/Master.php?f=delete_category. Manipulating the argument id can result in SQL injection.

    Published: 30 May 2024
    6.3
    Medium

    CVE-2024-35356

    Last Modified: 11 Apr 2025

    A vulnerability has been discovered in Diño Physics School Assistant version 2.3. The vulnerability impacts an unidentified code within the file /classes/Master.php?f=save_item. Manipulating the argument id can result in SQL injection.

    Published: 30 May 2024
    5.3
    Medium

    CVE-2024-35357

    Last Modified: 11 Apr 2025

    A vulnerability has been discovered in Diño Physics School Assistant version 2.3. The vulnerability impacts an unidentified code within the file /classes/Master.php?f=delete_item. Manipulating the argument id can result in SQL injection.

    Published: 30 May 2024
    5.4
    Medium

    CVE-2024-35345

    Last Modified: 11 Apr 2025

    A vulnerability has been discovered in Diño Physics School Assistant version 2.3. The vulnerability impacts unidentified code within the file /classes/Users.php. Manipulating the argument id results in cross-site scripting.

    Published: 30 May 2024