CVE Feed

    Dashboard / CVE

    5.3
    Medium

    CVE-2024-5351

    Last Modified: 1 Mar 2025

    A vulnerability was found in anji-plus AJ-Report up to 1.4.1. It has been declared as critical. Affected by this vulnerability is the function getValueFromJs of the component Javascript Handler. The manipulation leads to deserialization. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-266263.

    Published: 26 May 2024
    5.3
    Medium

    CVE-2024-5350

    Last Modified: 1 Mar 2025

    A vulnerability was found in anji-plus AJ-Report up to 1.4.1. It has been classified as critical. Affected is the function pageList of the file /pageList. The manipulation of the argument p leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-266262 is the identifier assigned to this vulnerability.

    Published: 25 May 2024
    5.1
    Medium

    CVE-2024-5340

    Last Modified: 21 Aug 2025

    A vulnerability was found in Ruijie RG-UAC up to 20240516. It has been rated as critical. Affected by this issue is some unknown functionality of the file /view/vpn/autovpn/sub_commit.php. The manipulation of the argument key leads to os command injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-266246 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 25 May 2024
    —
    Unknown

    CVE-2024-5388

    Last Modified: 3 Jun 2024

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

    Published: 25 May 2024
    —
    Unknown

    CVE-2024-5387

    Last Modified: 3 Jun 2024

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

    Published: 25 May 2024
    7.1
    High

    CVE-2024-30056

    Last Modified: 3 May 2025

    Microsoft Edge (Chromium-based) Information Disclosure Vulnerability

    Published: 25 May 2024
    5.1
    Medium

    CVE-2024-5339

    Last Modified: 21 Aug 2025

    A vulnerability was found in Ruijie RG-UAC up to 20240516. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /view/vpn/autovpn/online_check.php. The manipulation of the argument peernode leads to os command injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-266245 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 25 May 2024
    5.1
    Medium

    CVE-2024-5338

    Last Modified: 21 Aug 2025

    A vulnerability was found in Ruijie RG-UAC up to 20240516. It has been classified as critical. Affected is an unknown function of the file /view/vpn/autovpn/online.php. The manipulation of the argument peernode leads to os command injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-266244. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 25 May 2024
    5.1
    Medium

    CVE-2024-5337

    Last Modified: 21 Aug 2025

    A vulnerability was found in Ruijie RG-UAC up to 20240516 and classified as critical. This issue affects some unknown processing of the file /view/systemConfig/sys_user/user_commit.php. The manipulation of the argument email2/user_name leads to os command injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-266243. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 25 May 2024
    5.1
    Medium

    CVE-2024-5336

    Last Modified: 21 Aug 2025

    A vulnerability has been found in Ruijie RG-UAC up to 20240516 and classified as critical. This vulnerability affects the function addVlan of the file /view/networkConfig/vlan/vlan_add_commit.php. The manipulation of the argument phyport leads to os command injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-266242 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 25 May 2024
    6.4
    Medium

    CVE-2024-4045

    Last Modified: 8 Apr 2026

    The Popup Builder by OptinMonster – WordPress Popups for Optins, Email Newsletters and Lead Generation plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘campaign_id’ parameter in versions up to, and including, 2.16.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 25 May 2024
    6.4
    Medium

    CVE-2024-5218

    Last Modified: 15 Apr 2026

    The Reviews and Rating – Google Reviews plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's file upload feature in all versions up to, and including, 5.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 25 May 2024
    5.3
    Medium

    CVE-2024-4858

    Last Modified: 8 Apr 2026

    The Testimonial Carousel For Elementor plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'save_testimonials_option_callback' function in versions up to, and including, 10.2.0. This makes it possible for unauthenticated attackers to update the OpenAI API key, disabling the feature.

    Published: 25 May 2024
    6.4
    Medium

    CVE-2024-5229

    Last Modified: 8 Apr 2026

    The Primary Addon for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Pricing Table widget in all versions up to, and including, 1.5.5 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 25 May 2024
    6.4
    Medium

    CVE-2024-5220

    Last Modified: 8 Apr 2026

    The ND Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's upload feature in all versions up to, and including, 7.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 25 May 2024
    6.5
    Medium

    CVE-2024-36079

    Last Modified: 15 Apr 2026

    An issue was discovered in Vaultize 21.07.27. When uploading files, there is no check that the filename parameter is correct. As a result, a temporary file will be created outside the specified directory when the file is downloaded. To exploit this, an authenticated user would upload a file with an incorrect file name, and then download it.

    Published: 24 May 2024
    3.7
    Low

    CVE-2024-35232

    Last Modified: 15 Apr 2026

    github.com/huandu/facebook is a Go package that fully supports the Facebook Graph API with file upload, batch request and marketing API. access_token can be exposed in error message on fail in HTTP request. This issue has been patched in version 2.7.2.

    Published: 24 May 2024
    9.8
    Critical

    CVE-2024-35374

    Last Modified: 10 Jun 2025

    Mocodo Mocodo Online 4.2.6 and below does not properly sanitize the sql_case input field in /web/generate.php, allowing remote attackers to execute arbitrary commands and potentially command injection, leading to remote code execution (RCE) under certain conditions.

    Published: 24 May 2024
    9.8
    Critical

    CVE-2024-35373

    Last Modified: 10 Jun 2025

    Mocodo Mocodo Online 4.2.6 and below is vulnerable to Remote Code Execution via /web/rewrite.php.

    Published: 24 May 2024
    7.2
    High

    CVE-2024-33471

    Last Modified: 15 Apr 2026

    An issue in the Sensor Settings of AVTECH Room Alert 4E v4.4.0 allows attackers to gain access to SMTP credentials in plaintext via a crafted AJAX request. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.

    Published: 24 May 2024
    8.8
    High

    CVE-2024-35388

    Last Modified: 30 May 2025

    TOTOLINK NR1800X v9.1.0u.6681_B20230703 was discovered to contain a stack overflow via the password parameter in the function urldecode

    Published: 24 May 2024
    9.8
    Critical

    CVE-2024-35387

    Last Modified: 4 Apr 2025

    TOTOLINK LR350 V9.3.5u.6369_B20220309 was discovered to contain a stack overflow via the http_host parameter in the function loginAuth.

    Published: 24 May 2024
    6.5
    Medium

    CVE-2024-36049

    Last Modified: 15 Apr 2026

    Aptos Wisal payroll accounting before 7.1.6 uses hardcoded credentials in the Windows client to fetch the complete list of usernames and passwords from the database server, using an unencrypted connection. This allows attackers in a machine-in-the-middle position read and write access to personally identifiable information (PII) and especially payroll data and the ability to impersonate legitimate users with respect to the audit log.

    Published: 24 May 2024
    4.3
    Medium

    CVE-2023-46442

    Last Modified: 15 Apr 2026

    An infinite loop in the retrieveActiveBody function of Soot before v4.4.1 under Java 8 allows attackers to cause a Denial of Service (DoS).

    Published: 24 May 2024
    4.3
    Medium

    CVE-2024-34995

    Last Modified: 15 Apr 2026

    svnWebUI v1.8.3 was discovered to contain an arbitrary file deletion vulnerability via the dirTemps parameter under com.cym.controller.UserController#importOver. This vulnerability allows attackers to delete arbitrary files via a crafted POST request.

    Published: 24 May 2024
    8.8
    High

    CVE-2024-35395

    Last Modified: 3 Apr 2025

    TOTOLINK CP900L v4.1.5cu.798_B20221228 was discovered to contain a hardcoded password vulnerability in /etc/shadow.sample, which allows attackers to log in as root.

    Published: 24 May 2024
    9.8
    Critical

    CVE-2024-35396

    Last Modified: 3 Apr 2025

    TOTOLINK CP900L v4.1.5cu.798_B20221228 was discovered to contain a hardcoded password for telnet in /web_cste/cgi-bin/product.ini, which allows attackers to log in as root.

    Published: 24 May 2024
    4.9
    Medium

    CVE-2024-33470

    Last Modified: 15 Apr 2026

    An issue in the SMTP Email Settings of AVTECH Room Alert 4E v4.4.0 allows attackers to gain access to credentials in plaintext via a passback attack. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.

    Published: 24 May 2024
    6.5
    Medium

    CVE-2024-22588

    Last Modified: 15 Apr 2026

    Kwik commit 745fd4e2 does not discard unused encryption keys.

    Published: 24 May 2024
    6.5
    Medium

    CVE-2024-33809

    Last Modified: 10 Jun 2025

    PingCAP TiDB v7.5.1 was discovered to contain a buffer overflow vulnerability, which could lead to database crashes and denial of service attacks.

    Published: 24 May 2024
    8.6
    High

    CVE-2024-35340

    Last Modified: 9 Apr 2025

    Tenda FH1206 V1.2.0.8(8155) was discovered to contain a command injection vulnerability via the cmdinput parameter at ip/goform/formexeCommand.

    Published: 24 May 2024
    7.5
    High

    CVE-2024-35618

    Last Modified: 10 Jun 2025

    PingCAP TiDB v7.5.1 was discovered to contain a NULL pointer dereference via the component SortedRowContainer.

    Published: 24 May 2024
    9.8
    Critical

    CVE-2024-35339

    Last Modified: 9 Apr 2025

    Tenda FH1206 V1.2.0.8(8155) was discovered to contain a command injection vulnerability via the mac parameter at ip/goform/WriteFacMac.

    Published: 24 May 2024
    9.6
    Critical

    CVE-2024-35592

    Last Modified: 15 Apr 2026

    An arbitrary file upload vulnerability in the Upload function of Box-IM v2.0 allows attackers to execute arbitrary code via uploading a crafted PDF file.

    Published: 24 May 2024
    5.4
    Medium

    CVE-2024-35591

    Last Modified: 30 Sept 2025

    An arbitrary file upload vulnerability in O2OA v8.3.8 allows attackers to execute arbitrary code via uploading a crafted PDF file.

    Published: 24 May 2024
    4.3
    Medium

    CVE-2024-5273

    Last Modified: 10 Oct 2025

    Jenkins Report Info Plugin 1.2 and earlier does not perform path validation of the workspace directory while serving report files, allowing attackers with Item/Configure permission to retrieve Surefire failures, PMD violations, Findbugs bugs, and Checkstyle errors on the controller file system by editing the workspace path.

    Published: 24 May 2024
    5.5
    Medium

    CVE-2024-35593

    Last Modified: 15 Apr 2026

    An arbitrary file upload vulnerability in the File preview function of Raingad IM v4.1.4 allows attackers to execute arbitrary code via uploading a crafted PDF file.

    Published: 24 May 2024
    6.1
    Medium

    CVE-2024-35595

    Last Modified: 15 Apr 2026

    An arbitrary file upload vulnerability in the File Preview function of Xintongda OA v2023.12.30.1 allows attackers to execute arbitrary code via uploading a crafted PDF file.

    Published: 24 May 2024
    4
    Medium

    CVE-2024-5318

    Last Modified: 13 Dec 2024

    An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.11 prior to 16.10.6, starting from 16.11 prior to 16.11.3, and starting from 17.0 prior to 17.0.1. A Guest user can view dependency lists of private projects through job artifacts.

    Published: 24 May 2024
    7.1
    High

    CVE-2023-49575

    Last Modified: 21 May 2025

    A vulnerability has been discovered in VX Search Enterprise affecting version 10.2.14, in Sync Breeze Enterprise Server 10.4.18 version, and in Disk Pulse Enterprise 10.4.18 version, that could allow an attacker to execute persistent XSS through /setup_smtp in smtp_server, smtp_user, smtp_password and smtp_email_address parameters. This vulnerability could allow an attacker to store malicious JavaScript payloads on the system to be triggered when the page loads.

    Published: 24 May 2024
    7.1
    High

    CVE-2023-49574

    Last Modified: 4 Mar 2025

    A vulnerability has been discovered in VX Search Enterprise affecting version 10.2.14 that could allow an attacker to execute persistent XSS through /add_job in job_name. This vulnerability could allow an attacker to store malicious JavaScript payloads on the system to be triggered when the page loads.

    Published: 24 May 2024
    7.1
    High

    CVE-2023-49573

    Last Modified: 4 Mar 2025

    A vulnerability has been discovered in VX Search Enterprise affecting version 10.2.14 that could allow an attacker to execute persistent XSS through /add_command_action in action_value. This vulnerability could allow an attacker to store malicious JavaScript payloads on the system to be triggered when the page loads.

    Published: 24 May 2024
    7.1
    High

    CVE-2023-49572

    Last Modified: 21 May 2025

    A vulnerability has been discovered in VX Search Enterprise affecting version 10.2.14, and in Disk Pulse Enterprise 10.4.18 version, that could allow an attacker to execute persistent XSS through /setup_odbc in odbc_data_source, odbc_user and odbc_password parameters. This vulnerability could allow an attacker to store malicious JavaScript payloads on the system to be triggered when the page loads.

    Published: 24 May 2024
    5.4
    Medium

    CVE-2023-47710

    Last Modified: 8 Jan 2025

    IBM Security Guardium 11.4, 11.5, and 12.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 271525.

    Published: 24 May 2024
    7.2
    High

    CVE-2024-4455

    Last Modified: 8 Apr 2026

    The YITH WooCommerce Ajax Search plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘item’ parameter in versions up to, and including, 2.4.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 24 May 2024
    6.3
    Medium

    CVE-2024-5312

    Last Modified: 15 Apr 2026

    PHP Server Monitor, version 3.2.0, is vulnerable to an XSS via the /phpservermon-3.2.0/vendor/phpmailer/phpmailer/test_script/index.php page in all visible parameters. An attacker could create a specially crafted URL, send it to a victim and retrieve their session details.

    Published: 24 May 2024
    9.1
    Critical

    CVE-2024-5315

    Last Modified: 10 Apr 2025

    Vulnerabilities in Dolibarr ERP - CRM that affect version 9.0.1 and allow SQL injection. These vulnerabilities could allow a remote attacker to send a specially crafted SQL query to the system and retrieve all the information stored in the database through the parameters viewstatut in /dolibarr/commande/list.php.

    Published: 24 May 2024
    9.1
    Critical

    CVE-2024-5314

    Last Modified: 10 Apr 2025

    Vulnerabilities in Dolibarr ERP - CRM that affect version 9.0.1 and allow SQL injection. These vulnerabilities could allow a remote attacker to send a specially crafted SQL query to the system and retrieve all the information stored in the database through the parameters sortorder y sortfield in /dolibarr/admin/dict.php.

    Published: 24 May 2024
    5.1
    Medium

    CVE-2024-5310

    Last Modified: 5 Jun 2025

    A vulnerability classified as problematic has been found in JFinalCMS up to 20221020. This affects an unknown part of the file /admin/content. The manipulation of the argument Title leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-266121 was assigned to this vulnerability.

    Published: 24 May 2024
    6.5
    Medium

    CVE-2024-4037

    Last Modified: 8 Apr 2026

    The WP Photo Album Plus plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 8.7.02.003. This is due to the plugin allowing unauthenticated users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes.

    Published: 24 May 2024