CVE Feed

    Dashboard / CVE

    6.3
    Medium

    CVE-2024-5406

    Last Modified: 15 Apr 2026

    A vulnerability had been discovered in WinNMP 19.02 consisting of an XSS attack via index page in from, subject, text and hash parameters. This vulnerability could allow a remote user to send a specially crafted query to an authenticated user and steal their session details.

    Published: 27 May 2024
    6.3
    Medium

    CVE-2024-5405

    Last Modified: 15 Apr 2026

    A vulnerability had been discovered in WinNMP 19.02 consisting of an XSS attack via /tools/redis.php page in the k, hash, key and p parameters. This vulnerability could allow a remote user to submit a specially crafted JavaScript payload for an authenticated user to retrieve their session details.

    Published: 27 May 2024
    5.3
    Medium

    CVE-2024-36383

    Last Modified: 30 Jun 2025

    An issue was discovered in Logpoint SAML Authentication before 6.0.3. An attacker can place a crafted filename in the state field of a SAML SSO-URL response, and the file corresponding to this filename will ultimately be deleted. This can lead to a SAML Authentication login outage.

    Published: 27 May 2024
    8.8
    High

    CVE-2024-5035

    Last Modified: 15 Apr 2026

    The affected device expose a network service called "rftest" that is vulnerable to unauthenticated command injection on ports TCP/8888, TCP/8889, and TCP/8890. By successfully exploiting this flaw, remote unauthenticated attacker can gain arbitrary command execution on the device with elevated privileges.This issue affects Archer C4500X: through 1_1.1.6.

    Published: 27 May 2024
    2.4
    Low

    CVE-2024-27314

    Last Modified: 17 Jun 2025

    Zoho ManageEngine ServiceDesk Plus versions below 14730, ServiceDesk Plus MSP below 14720 and SupportCenter Plus below 14720 are vulnerable to stored XSS in the Custom Actions menu on the request details. This vulnerability can be exploited only by the SDAdmin role users.

    Published: 27 May 2024
    9.8
    Critical

    CVE-2024-26289

    Last Modified: 4 Apr 2025

    Deserialization of Untrusted Data vulnerability in PMB Services PMB allows Remote Code Inclusion.This issue affects PMB: from 7.5.1 before 7.5.6-2, from 7.4.1 before 7.4.9, from 7.3.1 before 7.3.18.

    Published: 27 May 2024
    7.2
    High

    CVE-2024-5403

    Last Modified: 15 Apr 2026

    ASKEY 5G NR Small Cell fails to properly filter user input for certain functionality, allowing remote attackers with administrator privilege to execute arbitrary system commands on the remote server.

    Published: 27 May 2024
    5.3
    Medium

    CVE-2024-3933

    Last Modified: 9 Jan 2025

    In Eclipse OpenJ9 release versions prior to 0.44.0 and after 0.13.0, when running with JVM option -Xgc:concurrentScavenge, the sequence generated for System.arrayCopy on the IBM Z platform with hardware and software support for guarded storage [1], could allow access to a buffer with an incorrect length value when executing an arraycopy sequence while the Concurrent Scavenge Garbage Collection cycle is active and the source and destination memory regions for arraycopy overlap. This allows read and write to addresses beyond the end of the array range.

    Published: 27 May 2024
    8.8
    High

    CVE-2024-4535

    Last Modified: 19 May 2025

    The KKProgressbar2 Free WordPress plugin through 1.1.4.2 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions via CSRF attacks

    Published: 27 May 2024
    6.1
    Medium

    CVE-2024-4534

    Last Modified: 19 May 2025

    The KKProgressbar2 Free WordPress plugin through 1.1.4.2 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack

    Published: 27 May 2024
    6.5
    Medium

    CVE-2024-4533

    Last Modified: 19 May 2025

    The KKProgressbar2 Free WordPress plugin through 1.1.4.2 does not sanitize and escape a parameter before using it in a SQL statement, allowing admin users to perform SQL injection attacks

    Published: 27 May 2024
    6.4
    Medium

    CVE-2024-4532

    Last Modified: 1 May 2025

    The Business Card WordPress plugin through 1.0.0 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions such as deleting cards via CSRF attacks

    Published: 27 May 2024
    7.1
    High

    CVE-2024-4531

    Last Modified: 1 May 2025

    The Business Card WordPress plugin through 1.0.0 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions such as editing cards via CSRF attacks

    Published: 27 May 2024
    6.3
    Medium

    CVE-2024-4530

    Last Modified: 1 May 2025

    The Business Card WordPress plugin through 1.0.0 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions such as editing card categories via CSRF attacks

    Published: 27 May 2024
    5
    Medium

    CVE-2024-4529

    Last Modified: 1 May 2025

    The Business Card WordPress plugin through 1.0.0 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions such as deleting card categories via CSRF attacks

    Published: 27 May 2024
    5.4
    Medium

    CVE-2024-3939

    Last Modified: 21 May 2025

    The Ditty WordPress plugin before 3.1.36 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

    Published: 27 May 2024
    8.8
    High

    CVE-2024-5400

    Last Modified: 26 Jan 2026

    Openfind Mail2000 does not properly filter parameters of specific CGI. Remote attackers with regular privileges can exploit this vulnerability to execute arbitrary system commands on the remote server.

    Published: 27 May 2024
    4.7
    Medium

    CVE-2024-35297

    Last Modified: 15 Apr 2026

    Cross-site scripting vulnerability exists in WP Booking versions prior to 2.4.5. If this vulnerability is exploited, an arbitrary script may be executed on the web browser of the user who is accessing the web site using the product.

    Published: 27 May 2024
    6.1
    Medium

    CVE-2024-35291

    Last Modified: 15 Apr 2026

    Cross-site scripting vulnerability exists in Splunk Config Explorer versions prior to 1.7.16. If this vulnerability is exploited, an arbitrary script may be executed on the web browser of the user who is using the product.

    Published: 27 May 2024
    6.1
    Medium

    CVE-2024-36384

    Last Modified: 15 Apr 2026

    Pointsharp Cryptshare Server before 7.0.0 has an XSS issue that is related to notification messages.

    Published: 27 May 2024
    7.2
    High

    CVE-2024-5399

    Last Modified: 26 Jan 2026

    Openfind Mail2000 does not properly filter parameters of specific API. Remote attackers with administrative privileges can exploit this vulnerability to execute arbitrary system commands on the remote server.

    Published: 27 May 2024
    5.3
    Medium

    CVE-2024-5397

    Last Modified: 10 Feb 2025

    A vulnerability classified as critical was found in itsourcecode Online Student Enrollment System 1.0. Affected by this vulnerability is an unknown functionality of the file instructorSubjects.php. The manipulation of the argument instructorId leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-266311.

    Published: 27 May 2024
    5.3
    Medium

    CVE-2024-5396

    Last Modified: 10 Feb 2025

    A vulnerability classified as critical has been found in itsourcecode Online Student Enrollment System 1.0. Affected is an unknown function of the file newfaculty.php. The manipulation of the argument name leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-266310 is the identifier assigned to this vulnerability.

    Published: 27 May 2024
    5.3
    Medium

    CVE-2024-5395

    Last Modified: 10 Feb 2025

    A vulnerability was found in itsourcecode Online Student Enrollment System 1.0. It has been rated as critical. This issue affects some unknown processing of the file listofinstructor.php. The manipulation of the argument FullName leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-266309 was assigned to this vulnerability.

    Published: 27 May 2024
    5.3
    Medium

    CVE-2024-5394

    Last Modified: 10 Feb 2025

    A vulnerability was found in itsourcecode Online Student Enrollment System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file newDept.php. The manipulation of the argument deptname leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-266308.

    Published: 27 May 2024
    5.3
    Medium

    CVE-2024-5393

    Last Modified: 10 Feb 2025

    A vulnerability was found in itsourcecode Online Student Enrollment System 1.0. It has been classified as critical. This affects an unknown part of the file listofcourse.php. The manipulation of the argument idno leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-266307.

    Published: 27 May 2024
    5.3
    Medium

    CVE-2024-5392

    Last Modified: 10 Feb 2025

    A vulnerability was found in itsourcecode Online Student Enrollment System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file editSubject.php. The manipulation of the argument id leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-266306 is the identifier assigned to this vulnerability.

    Published: 27 May 2024
    5.3
    Medium

    CVE-2024-5391

    Last Modified: 10 Feb 2025

    A vulnerability has been found in itsourcecode Online Student Enrollment System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file listofsubject.php. The manipulation of the argument subjcode leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-266305 was assigned to this vulnerability.

    Published: 27 May 2024
    5.3
    Medium

    CVE-2024-5390

    Last Modified: 10 Feb 2025

    A vulnerability, which was classified as critical, was found in itsourcecode Online Student Enrollment System 1.0. Affected is an unknown function of the file listofstudent.php. The manipulation of the argument lname leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-266304.

    Published: 27 May 2024
    5.1
    Medium

    CVE-2024-5385

    Last Modified: 30 Jul 2025

    A vulnerability, which was classified as problematic, has been found in oretnom23 Online Car Wash Booking System 1.0. This issue affects some unknown processing of the file /admin/?page=user/list. The manipulation of the argument First Name/Last Name with the input <script>confirm (document.cookie)</script> leads to cross site scripting. The attack may be initiated remotely. The associated identifier of this vulnerability is VDB-266303.

    Published: 27 May 2024
    7.5
    High

    CVE-2024-36426

    Last Modified: 15 Apr 2026

    In TARGIT Decision Suite 23.2.15007.0 before Autumn 2023, the session token is part of the URL and may be sent in a cleartext HTTP session.

    Published: 27 May 2024
    5.9
    Medium

    CVE-2024-3049

    Last Modified: 17 Mar 2026

    A flaw was found in Booth, a cluster ticket manager. If a specially-crafted hash is passed to gcry_md_get_algo_dlen(), it may allow an invalid HMAC to be accepted by the Booth server.

    Published: 27 May 2024
    8.3
    High

    CVE-2024-35219

    Last Modified: 15 Apr 2026

    OpenAPI Generator allows generation of API client libraries (SDK generation), server stubs, documentation and configuration automatically given an OpenAPI Spec. Prior to version 7.6.0, attackers can exploit a path traversal vulnerability to read and delete files and folders from an arbitrary, writable directory as anyone can set the output folder when submitting the request via the `outputFolder` option. The issue was fixed in version 7.6.0 by removing the usage of the `outputFolder` option. No known workarounds are available.

    Published: 27 May 2024
    5.7
    Medium

    CVE-2023-6349

    Last Modified: 22 Jul 2025

    A heap overflow vulnerability exists in libvpx - Encoding a frame that has larger dimensions than the originally configured size with VP9 may result in a heap overflow in libvpx. We recommend upgrading to version 1.13.1 or above

    Published: 27 May 2024
    6.9
    Medium

    CVE-2024-5384

    Last Modified: 11 Feb 2025

    A vulnerability classified as critical was found in SourceCodester Facebook News Feed Like 1.0. This vulnerability affects unknown code of the file index.php. The manipulation of the argument page leads to sql injection. The attack can be initiated remotely. VDB-266302 is the identifier assigned to this vulnerability.

    Published: 26 May 2024
    5.3
    Medium

    CVE-2024-5383

    Last Modified: 21 Aug 2025

    A vulnerability classified as problematic has been found in lakernote EasyAdmin up to 20240324. This affects an unknown part of the file /sys/file/upload. The manipulation of the argument file leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. This product takes the approach of rolling releases to provide continious delivery. Therefore, version details for affected and updated releases are not available. The identifier of the patch is 9c8a836ace17a93c45e5ad52a2340788b7795030. It is recommended to apply a patch to fix this issue. The identifier VDB-266301 was assigned to this vulnerability.

    Published: 26 May 2024
    5.4
    Medium

    CVE-2024-36056

    Last Modified: 15 Apr 2026

    Hw64.sys in Marvin Test HW.exe before 5.0.5.0 allows unprivileged user-mode processes to arbitrarily map physical memory via IOCTL 0x9c406490 (for IoAllocateMdl, MmBuildMdlForNonPagedPool, and MmMapLockedPages), leading to NT AUTHORITY\SYSTEM privilege escalation.

    Published: 26 May 2024
    5.5
    Medium

    CVE-2024-36055

    Last Modified: 15 Apr 2026

    Hw64.sys in Marvin Test HW.exe before 5.0.5.0 allows unprivileged user-mode processes to arbitrarily map physical memory with read/write access via the MmMapIoSpace API (IOCTL 0x9c40a4f8, 0x9c40a4e8, 0x9c40a4c0, 0x9c40a4c4, 0x9c40a4ec, and seven others), leading to a denial of service (BSOD).

    Published: 26 May 2024
    7.4
    High

    CVE-2024-36054

    Last Modified: 15 Apr 2026

    Hw64.sys in Marvin Test HW.exe before 5.0.5.0 allows unprivileged user-mode processes to arbitrarily read kernel memory (and consequently gain all privileges) via IOCTL 0x9c4064b8 (via MmMapIoSpace) and IOCTL 0x9c406490 (via ZwMapViewOfSection).

    Published: 26 May 2024
    5.3
    Medium

    CVE-2024-5381

    Last Modified: 11 Feb 2025

    A vulnerability classified as critical was found in itsourcecode Student Information Management System 1.0. Affected by this vulnerability is an unknown functionality of the file view.php. The manipulation of the argument studentId leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-266293 was assigned to this vulnerability.

    Published: 26 May 2024
    5.3
    Medium

    CVE-2024-5380

    Last Modified: 15 Apr 2026

    A vulnerability classified as problematic has been found in jsy-1 short-url 1.0.0. Affected is an unknown function of the file admin.php. The manipulation of the argument url leads to cross site scripting. It is possible to launch the attack remotely. Upgrading to version 2.0.0 is able to address this issue. The name of the patch is 35c790897d6979392bc6f60707fc32da13a98b63. It is recommended to upgrade the affected component. The identifier of this vulnerability is VDB-266292.

    Published: 26 May 2024
    4.9
    Medium

    CVE-2024-4286

    Last Modified: 15 Apr 2026

    Mintplex-Labs' anything-llm application is vulnerable to improper neutralization of special elements used in an expression language statement, identified in the commit id `57984fa85c31988b2eff429adfc654c46e0c342a`. The vulnerability arises from the application's handling of user modifications by managers or admins, allowing for the modification of all existing attributes of the `user` database entity without proper checks or sanitization. This flaw can be exploited to delete user threads, denying users access to their previously submitted data, or to inject fake threads and/or chat history for social engineering attacks.

    Published: 26 May 2024
    5.3
    Medium

    CVE-2024-5379

    Last Modified: 5 Jun 2025

    A vulnerability was found in JFinalCMS up to 20240111. It has been rated as problematic. This issue affects some unknown processing of the file /admin/template. The manipulation of the argument directory leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-266291.

    Published: 26 May 2024
    7.4
    High

    CVE-2024-34454

    Last Modified: 15 Apr 2026

    Nintendo Wii U OS 5.5.5 allows man-in-the-middle attackers to forge SSL certificates as though they came from a Root CA, because there is a secondary verification mechanism that only checks whether a CA is known and ignores the CA details and signature (and because * is accepted as a Common Name).

    Published: 26 May 2024
    5.3
    Medium

    CVE-2024-5378

    Last Modified: 10 Feb 2025

    A vulnerability was found in SourceCodester School Intramurals Student Attendance Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /manage_sy.php. The manipulation of the argument id leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-266290 is the identifier assigned to this vulnerability.

    Published: 26 May 2024
    6.9
    Medium

    CVE-2024-5377

    Last Modified: 10 Feb 2025

    A vulnerability was found in SourceCodester Vehicle Management System 1.0. It has been classified as critical. This affects an unknown part of the file /newvehicle.php. The manipulation of the argument file leads to unrestricted upload. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-266289 was assigned to this vulnerability.

    Published: 26 May 2024
    5.3
    Medium

    CVE-2024-5376

    Last Modified: 11 Feb 2025

    A vulnerability was found in Kashipara College Management System 1.0 and classified as problematic. Affected by this issue is some unknown functionality of the file view_each_faculty.php. The manipulation of the argument id leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-266288.

    Published: 26 May 2024
    5.3
    Medium

    CVE-2024-5375

    Last Modified: 11 Feb 2025

    A vulnerability has been found in Kashipara College Management System 1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file submit_student.php. The manipulation of the argument address leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-266287.

    Published: 26 May 2024
    5.3
    Medium

    CVE-2024-5374

    Last Modified: 11 Feb 2025

    A vulnerability, which was classified as problematic, was found in Kashipara College Management System 1.0. Affected is an unknown function of the file submit_new_faculty.php. The manipulation of the argument address leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-266286 is the identifier assigned to this vulnerability.

    Published: 26 May 2024
    5.3
    Medium

    CVE-2024-5373

    Last Modified: 11 Feb 2025

    A vulnerability, which was classified as problematic, has been found in Kashipara College Management System 1.0. This issue affects some unknown processing of the file submit_login.php. The manipulation of the argument usertype leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-266285 was assigned to this vulnerability.

    Published: 26 May 2024