CVE Feed

    Dashboard / CVE

    7.3
    High

    CVE-2024-35226

    Last Modified: 15 Apr 2026

    Smarty is a template engine for PHP, facilitating the separation of presentation (HTML/CSS) from application logic. In affected versions template authors could inject php code by choosing a malicious file name for an extends-tag. Sites that cannot fully trust template authors should update asap. All users are advised to update. There is no patch for users on the v3 branch. There are no known workarounds for this vulnerability.

    Published: 28 May 2024
    4.7
    Medium

    CVE-2024-35511

    Last Modified: 3 Apr 2025

    phpgurukul Men Salon Management System v2.0 is vulnerable to SQL Injection via the "username" parameter of /msms/admin/index.php.

    Published: 28 May 2024
    5.4
    Medium

    CVE-2024-35548

    Last Modified: 15 Apr 2026

    A SQL injection vulnerability in Mybatis plus versions below 3.5.6 allows remote attackers to obtain database information via a Boolean blind injection. NOTE: the vendor's position is that this can only occur in a misconfigured application; the documentation discusses how to develop applications that avoid SQL injection.

    Published: 28 May 2024
    7.5
    High

    CVE-2024-22641

    Last Modified: 3 Nov 2025

    TCPDF version 6.6.5 and before is vulnerable to ReDoS (Regular Expression Denial of Service) if parsing an untrusted SVG file.

    Published: 28 May 2024
    5.4
    Medium

    CVE-2024-35240

    Last Modified: 15 Apr 2026

    Umbraco Commerce is an open source dotnet ecommerce solution. In affected versions there exists a stored Cross-site scripting (XSS) issue which would enable attackers to inject malicious code into Print Functionality. This issue has been addressed in versions 12.1.4, and 10.0.5. Users are advised to upgrade. There are no known workarounds for this vulnerability.

    Published: 28 May 2024
    2.7
    Low

    CVE-2024-35239

    Last Modified: 5 Jan 2026

    Umbraco Commerce is an open source dotnet web forms solution. In affected versions an authenticated user that has access to edit Forms may inject unsafe code into Forms components. This issue can be mitigated by configuring TitleAndDescription:AllowUnsafeHtmlRendering after upgrading to one of the patched versions (13.0.1, 12.2.2, 10.5.3, 8.13.13).

    Published: 28 May 2024
    7.5
    High

    CVE-2023-30313

    Last Modified: 15 Apr 2026

    An issue discovered in Wavlink QUANTUM D2G routers allows attackers to hijack TCP sessions which could lead to a denial of service.

    Published: 28 May 2024
    7.3
    High

    CVE-2024-28060

    Last Modified: 15 Apr 2026

    An issue was discovered in Apiris Kafeo 6.4.4. It permits DLL hijacking, allowing a user to trigger the execution of arbitrary code every time the product is executed.

    Published: 28 May 2024
    4.3
    Medium

    CVE-2023-30306

    Last Modified: 15 Apr 2026

    An issue discovered in Mercury x30g, Mercury YR1800XG routers allows attackers to hijack TCP sessions which could lead to a denial of service.

    Published: 28 May 2024
    7.5
    High

    CVE-2023-30310

    Last Modified: 15 Apr 2026

    An issue discovered in Comfast Comfast CF-616AC routers allows attackers to hijack TCP sessions which could lead to a denial of service.

    Published: 28 May 2024
    6.1
    Medium

    CVE-2024-35583

    Last Modified: 11 Apr 2025

    A cross-site scripting (XSS) vulnerability in Sourcecodester Laboratory Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Remarks input field.

    Published: 28 May 2024
    6.1
    Medium

    CVE-2024-35581

    Last Modified: 11 Apr 2025

    A cross-site scripting (XSS) vulnerability in Sourcecodester Laboratory Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Borrower Name input field.

    Published: 28 May 2024
    5.7
    Medium

    CVE-2023-30309

    Last Modified: 30 May 2025

    An issue discovered in D-Link DI-7003GV2 routers allows attackers to hijack TCP sessions which could lead to a denial of service.

    Published: 28 May 2024
    6.1
    Medium

    CVE-2024-35582

    Last Modified: 11 Apr 2025

    A cross-site scripting (XSS) vulnerability in Sourcecodester Laboratory Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Department input field.

    Published: 28 May 2024
    6.5
    Medium

    CVE-2023-30308

    Last Modified: 13 Aug 2025

    An issue discovered in Ruijie EG210G-P, Ruijie EG105G-V2, Ruijie NBR, and Ruijie EG105G routers allows attackers to hijack TCP sessions which could lead to a denial of service.

    Published: 28 May 2024
    6.3
    Medium

    CVE-2024-28061

    Last Modified: 15 Apr 2026

    An issue was discovered in Apiris Kafeo 6.4.4. It permits a bypass, of the protection in place, to access to the data stored in the embedded database file.

    Published: 28 May 2024
    9.8
    Critical

    CVE-2024-35510

    Last Modified: 1 Apr 2025

    An arbitrary file upload vulnerability in /dede/file_manage_control.php of DedeCMS v5.7.114 allows attackers to execute arbitrary code via uploading a crafted file.

    Published: 28 May 2024
    5.3
    Medium

    CVE-2023-30307

    Last Modified: 15 Apr 2026

    An issue discovered in TP-LINK TL-R473GP-AC, TP-LINK XDR6020, TP-LINK TL-R479GP-AC, TP-LINK TL-R4239G, TP-LINK TL-WAR1200L, and TP-LINK TL-R476G routers allows attackers to hijack TCP sessions which could lead to a denial of service.

    Published: 28 May 2024
    8.8
    High

    CVE-2022-45171

    Last Modified: 13 Feb 2025

    An issue was discovered in LIVEBOX Collaboration vDesk through v018. An Unrestricted Upload of a File with a Dangerous Type can occur under the vShare web site section. A remote user, authenticated to the product, can arbitrarily upload potentially dangerous files without restrictions.

    Published: 28 May 2024
    8.1
    High

    CVE-2023-46694

    Last Modified: 15 Apr 2026

    Vtenext 21.02 allows an authenticated attacker to upload arbitrary files, potentially enabling them to execute remote commands. This flaw exists due to the application's failure to enforce proper authentication controls when accessing the Ckeditor file manager functionality.

    Published: 28 May 2024
    7.5
    High

    CVE-2023-30305

    Last Modified: 10 Jun 2025

    An issue discovered in Linksys E5600 routers allows attackers to hijack TCP sessions which could lead to a denial of service.

    Published: 28 May 2024
    7.5
    High

    CVE-2023-30311

    Last Modified: 15 Apr 2026

    An issue discovered in H3C Magic R365 and H3C Magic R100 routers allows attackers to hijack TCP sessions which could lead to a denial of service.

    Published: 28 May 2024
    7.5
    High

    CVE-2024-33450

    Last Modified: 15 Apr 2026

    SQL Injection in Finereport v.8.0 allows a remote attacker to obtain sensitive information

    Published: 28 May 2024
    6.9
    Medium

    CVE-2024-5434

    Last Modified: 15 Apr 2026

    The Campbell Scientific CSI Web Server stores web authentication credentials in a file with a specific file name. Passwords within that file are stored in a weakly encoded format. There is no known way to remotely access the file unless it has been manually renamed. However, if an attacker were to gain access to the file, passwords could be decoded and reused to gain access.

    Published: 28 May 2024
    7.6
    High

    CVE-2024-36109

    Last Modified: 15 Apr 2026

    CoCalc is web-based software that enables collaboration in research, teaching, and scientific publishing. In affected versions the markdown parser allows `<script>` tags to be included which execute when published. This issue has been addressed in commit `419862a9c9879c`. Users are advised to upgrade. There are no known workarounds for this vulnerability.

    Published: 28 May 2024
    5.3
    Medium

    CVE-2024-5433

    Last Modified: 15 Apr 2026

    The Campbell Scientific CSI Web Server supports a command that will return the most recent file that matches a given expression. A specially crafted expression can lead to a path traversal vulnerability. This command combined with a specially crafted expression allows anonymous, unauthenticated access (allowed by default) by an attacker to files and directories outside of the webserver root directory they should be restricted to.

    Published: 28 May 2024
    8.2
    High

    CVE-2024-36110

    Last Modified: 15 Apr 2026

    ansibleguy-webui is an open source WebUI for using Ansible. Multiple forms in versions < 0.0.21 allowed injection of HTML elements. These are returned to the user after executing job actions and thus evaluated by the browser. These issues have been addressed in version 0.0.21 (0.0.21.post2 on pypi). Users are advised to upgrade. There are no known workarounds for these issues.

    Published: 28 May 2024
    8.6
    High

    CVE-2024-24919

    Last Modified: 24 Oct 2025

    Potentially allowing an attacker to read certain information on Check Point Security Gateways once connected to the internet and enabled with remote Access VPN or Mobile Access Software Blades. A Security fix that mitigates this vulnerability is available.

    Published: 28 May 2024
    6.5
    Medium

    CVE-2023-43850

    Last Modified: 30 May 2025

    Improper input validation in the user management function of web interface in Aten PE6208 2.3.228 and 2.4.232 allows remote authenticated users to cause a partial DoS of web interface via HTTP POST request.

    Published: 28 May 2024
    6.5
    Medium

    CVE-2023-43849

    Last Modified: 30 May 2025

    Incorrect access control in firmware upgrade function of web interface in Aten PE6208 2.3.228 and 2.4.232 allows remote authenticated users to submit a firmware image via HTTP POST requests. This may result in DoS or remote code execution.

    Published: 28 May 2024
    8
    High

    CVE-2023-43848

    Last Modified: 30 May 2025

    Incorrect access control in the firewall management function of web interface in Aten PE6208 2.3.228 and 2.4.232 allows remote authenticated users to alter local firewall settings of the device as if they were the administrator via HTTP POST request.

    Published: 28 May 2024
    5.3
    Medium

    CVE-2023-43847

    Last Modified: 30 May 2025

    Incorrect access control in the outlet control function of web interface in Aten PE6208 2.3.228 and 2.4.232 allows remote authenticated users to control all the outlets as if they were the administrator via HTTP POST requests.

    Published: 28 May 2024
    5.3
    Medium

    CVE-2023-43846

    Last Modified: 30 May 2025

    Incorrect access control in logs management function of web interface in Aten PE6208 2.3.228 and 2.4.232 allows remote attackers to get the device logs via HTTP GET request. The logs contain such information as user names and IP addresses used in the infrastructure. This information may help the attackers to conduct further attacks in the infrastructure.

    Published: 28 May 2024
    9.8
    Critical

    CVE-2023-43845

    Last Modified: 30 May 2025

    Aten PE6208 2.3.228 and 2.4.232 have default credentials for the privileged telnet account. The user is not asked to change the credentials after first login. If not changed, attackers can log in to the telnet console and gain administrator privileges.

    Published: 28 May 2024
    8
    High

    CVE-2023-43844

    Last Modified: 30 May 2025

    Aten PE6208 2.3.228 and 2.4.232 have default credentials for the privileged web interface account. The user is not asked to change the credentials after first login. If not changed, attackers can log in to the web interface and gain administrator privileges.

    Published: 28 May 2024
    7.3
    High

    CVE-2023-43843

    Last Modified: 3 Jun 2025

    Incorrect access control in the account management function of web interface in Aten PE6208 2.3.228 and 2.4.232 allows remote authenticated users to read user and administrator accounts passwords via HTTP GET request.

    Published: 28 May 2024
    7.3
    High

    CVE-2023-43842

    Last Modified: 3 Jun 2025

    Incorrect access control in the account management function of web interface in Aten PE6208 2.3.228 and 2.4.232 allows remote authenticated users to alter user and administrator accounts credentials via HTTP POST request.

    Published: 28 May 2024
    8.1
    High

    CVE-2024-33402

    Last Modified: 25 Mar 2025

    A SQL injection vulnerability in /model/approve_petty_cash.php in campcodes Complete Web-Based School Management System 1.0 allows attacker to execute arbitrary SQL commands via the id parameter.

    Published: 28 May 2024
    9.9
    Critical

    CVE-2024-35344

    Last Modified: 15 Apr 2026

    Certain Anpviz products contain a hardcoded cryptographic key stored in the firmware of the device. This affects IPC-D250, IPC-D260, IPC-B850, IPC-D850, IPC-D350, IPC-D3150, IPC-D4250, IPC-D380, IPC-D880, IPC-D280, IPC-D3180, MC800N, YM500L, YM800N_N2, YMF50B, YM800SV2, YM500L8, and YM200E10 firmware v3.2.2.2 and lower and possibly more vendors/models of IP camera.

    Published: 28 May 2024
    7.5
    High

    CVE-2024-35341

    Last Modified: 15 Apr 2026

    Certain Anpviz products allow unauthenticated users to download the running configuration of the device via a HTTP GET request to /ConfigFile.ini or /config.xml URIs. This configuration file contains usernames and encrypted passwords (encrypted with a hardcoded key common to all devices). This affects IPC-D250, IPC-D260, IPC-B850, IPC-D850, IPC-D350, IPC-D3150, IPC-D4250, IPC-D380, IPC-D880, IPC-D280, IPC-D3180, MC800N, YM500L, YM800N_N2, YMF50B, YM800SV2, YM500L8, and YM200E10 firmware v3.2.2.2 and lower and possibly more vendors/models of IP camera.

    Published: 28 May 2024
    4.6
    Medium

    CVE-2024-35342

    Last Modified: 15 Apr 2026

    Certain Anpviz products allow unauthenticated users to modify or disable camera related settings such as microphone volume, speaker volume, LED lighting, NTP, motion detection, etc. This affects IPC-D250, IPC-D260, IPC-B850, IPC-D850, IPC-D350, IPC-D3150, IPC-D4250, IPC-D380, IPC-D880, IPC-D280, IPC-D3180, MC800N, YM500L, YM800N_N2, YMF50B, YM800SV2, YM500L8, and YM200E10 firmware v3.2.2.2 and lower and possibly more vendors/models of IP camera.

    Published: 28 May 2024
    9.8
    Critical

    CVE-2024-35343

    Last Modified: 15 Apr 2026

    Certain Anpviz products allow unauthenticated users to download arbitrary files from the device's filesystem via a HTTP GET request to the /playback/ URI. This affects IPC-D250, IPC-D260, IPC-B850, IPC-D850, IPC-D350, IPC-D3150, IPC-D4250, IPC-D380, IPC-D880, IPC-D280, IPC-D3180, MC800N, YM500L, YM800N_N2, YMF50B, YM800SV2, YM500L8, and YM200E10 (IP Cameras) firmware v3.2.2.2 and lower and possibly more vendors/models of IP camera.

    Published: 28 May 2024
    7.1
    High

    CVE-2024-30165

    Last Modified: 15 Apr 2026

    Amazon AWS Client VPN before 3.9.1 on macOS has a buffer overflow that could potentially allow a local actor to execute arbitrary commands with elevated permissions, a different vulnerability than CVE-2024-30164.

    Published: 28 May 2024
    6.7
    Medium

    CVE-2024-30164

    Last Modified: 15 Apr 2026

    Amazon AWS Client VPN has a buffer overflow that could potentially allow a local actor to execute arbitrary commands with elevated permissions. This is resolved in 3.11.1 on Windows, 3.9.1 on macOS, and 3.12.1 on Linux. NOTE: although the macOS resolution is the same as for CVE-2024-30165, this vulnerability on macOS is not the same as CVE-2024-30165.

    Published: 28 May 2024
    9.8
    Critical

    CVE-2024-35563

    Last Modified: 15 Apr 2026

    CDG-Server-V5.6.2.126.139 and earlier was discovered to contain a SQL injection vulnerability via the permissionId parameter in CDGTempPermissions.

    Published: 28 May 2024
    8.6
    High

    CVE-2024-26024

    Last Modified: 15 Apr 2026

    SUBNET Solutions Inc. has identified vulnerabilities in third-party components used in Substation Server.

    Published: 28 May 2024
    9.8
    Critical

    CVE-2024-34854

    Last Modified: 10 Jun 2025

    F-logic DataCube3 v1.0 is vulnerable to File Upload via `/admin/transceiver_schedule.php.`

    Published: 28 May 2024
    6.3
    Medium

    CVE-2024-34852

    Last Modified: 10 Jun 2025

    F-logic DataCube3 v1.0 is affected by command injection due to improper string filtering at the command execution point in the ./admin/transceiver_schedule.php file. An unauthenticated remote attacker can exploit this vulnerability by sending a file name containing command injection. Successful exploitation of this vulnerability may allow the attacker to execute system commands.

    Published: 28 May 2024
    5.9
    Medium

    CVE-2024-35401

    Last Modified: 3 Apr 2025

    TOTOLINK CP900L v4.1.5cu.798_B20221228 was discovered to contain a command injection vulnerability via the FileName parameter in the UploadFirmwareFile function.

    Published: 28 May 2024
    2.7
    Low

    CVE-2024-35403

    Last Modified: 3 Apr 2025

    TOTOLINK CP900L v4.1.5cu.798_B20221228 was discovered to contain a stack overflow via the desc parameter in the function setIpPortFilterRules

    Published: 28 May 2024