CVE Feed

    Dashboard / CVE

    8.8
    High

    CVE-2024-36077

    Last Modified: 15 Apr 2026

    Qlik Sense Enterprise for Windows before 14.187.4 allows a remote attacker to elevate their privilege due to improper validation. The attacker can elevate their privilege to the internal system role, which allows them to execute commands on the server. This affects February 2024 Patch 3 (14.173.3 through 14.173.7), November 2023 Patch 8 (14.159.4 through 14.159.13), August 2023 Patch 13 (14.139.3 through 14.139.20), May 2023 Patch 15 (14.129.3 through 14.129.22), February 2023 Patch 13 (14.113.1 through 14.113.18), November 2022 Patch 13 (14.97.2 through 14.97.18), August 2022 Patch 16 (14.78.3 through 14.78.23), and May 2022 Patch 17 (14.67.7 through 14.67.31). This has been fixed in May 2024 (14.187.4), February 2024 Patch 4 (14.173.8), November 2023 Patch 9 (14.159.14), August 2023 Patch 14 (14.139.21), May 2023 Patch 16 (14.129.23), February 2023 Patch 14 (14.113.19), November 2022 Patch 14 (14.97.19), August 2022 Patch 17 (14.78.25), and May 2022 Patch 18 (14.67.34).

    Published: 22 May 2024
    6.5
    Medium

    CVE-2024-5166

    Last Modified: 22 Jul 2025

    An Insecure Direct Object Reference in Google Cloud's Looker allowed metadata exposure across authenticated Looker users sharing the same LookML model.

    Published: 22 May 2024
    8.8
    High

    CVE-2024-34448

    Last Modified: 18 Apr 2025

    Ghost before 5.82.0 allows CSV Injection during a member CSV export.

    Published: 22 May 2024
    5.4
    Medium

    CVE-2024-29392

    Last Modified: 23 Apr 2025

    Silverpeas Core 6.3 is vulnerable to Cross Site Scripting (XSS) via ClipboardSessionController.

    Published: 22 May 2024
    5.4
    Medium

    CVE-2024-35362

    Last Modified: 28 Apr 2025

    Ecshop 3.6 is vulnerable to Cross Site Scripting (XSS) via ecshop/article_cat.php.

    Published: 22 May 2024
    8.4
    High

    CVE-2024-33228

    Last Modified: 15 Apr 2026

    An issue in the component segwindrvx64.sys of Insyde Software Corp SEG Windows Driver v100.00.07.02 allows attackers to escalate privileges and execute arbitrary code via sending crafted IOCTL requests.

    Published: 22 May 2024
    8.8
    High

    CVE-2024-33227

    Last Modified: 15 Apr 2026

    An issue in the component ddcdrv.sys of Nicomsoft WinI2C/DDC v3.7.4.0 allows attackers to escalate privileges and execute arbitrary code via sending crafted IOCTL requests.

    Published: 22 May 2024
    9.9
    Critical

    CVE-2024-33226

    Last Modified: 15 Apr 2026

    An issue in the component Access64.sys of Wistron Corporation TBT Force Power Control v1.0.0.0 allows attackers to escalate privileges and execute arbitrary code via sending crafted IOCTL requests.

    Published: 22 May 2024
    7.8
    High

    CVE-2024-33225

    Last Modified: 15 Apr 2026

    An issue in the component RTKVHD64.sys of Realtek Semiconductor Corp Realtek(r) High Definition Audio Function Driver v6.0.9549.1 allows attackers to escalate privileges and execute arbitrary code via sending crafted IOCTL requests.

    Published: 22 May 2024
    8.4
    High

    CVE-2024-33224

    Last Modified: 15 Apr 2026

    An issue in the component rtkio64.sys of Realtek Semiconductor Corp Realtek lO Driver v1.008.0823.2017 allows attackers to escalate privileges and execute arbitrary code via sending crafted IOCTL requests.

    Published: 22 May 2024
    8.8
    High

    CVE-2024-5160

    Last Modified: 13 Feb 2025

    Heap buffer overflow in Dawn in Google Chrome prior to 125.0.6422.76 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: High)

    Published: 22 May 2024
    8.8
    High

    CVE-2024-5159

    Last Modified: 13 Feb 2025

    Heap buffer overflow in ANGLE in Google Chrome prior to 125.0.6422.76 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: High)

    Published: 22 May 2024
    8.1
    High

    CVE-2024-5158

    Last Modified: 13 Feb 2025

    Type Confusion in V8 in Google Chrome prior to 125.0.6422.76 allowed a remote attacker to potentially perform arbitrary read/write via a crafted HTML page. (Chromium security severity: High)

    Published: 22 May 2024
    8.8
    High

    CVE-2024-5157

    Last Modified: 27 Mar 2025

    Use after free in Scheduling in Google Chrome prior to 125.0.6422.76 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

    Published: 22 May 2024
    8.8
    High

    CVE-2024-33223

    Last Modified: 15 Apr 2026

    An issue in the component IOMap64.sys of ASUSTeK Computer Inc ASUS GPU TweakII v1.4.5.2 allows attackers to escalate privileges and execute arbitrary code via sending crafted IOCTL requests.

    Published: 22 May 2024
    8.4
    High

    CVE-2024-33222

    Last Modified: 15 Apr 2026

    An issue in the component ATSZIO64.sys of ASUSTeK Computer Inc ASUS ATSZIO Driver v0.2.1.7 allows attackers to escalate privileges and execute arbitrary code via sending crafted IOCTL requests.

    Published: 22 May 2024
    7.8
    High

    CVE-2024-33221

    Last Modified: 15 Apr 2026

    An issue in the component AsusBSItf.sys of ASUSTeK Computer Inc ASUS BIOS Flash Driver v3.2.12.0 allows attackers to escalate privileges and execute arbitrary code via sending crafted IOCTL requests.

    Published: 22 May 2024
    8.8
    High

    CVE-2024-33220

    Last Modified: 18 Apr 2025

    An issue in the component AslO3_64.sys of ASUSTeK Computer Inc AISuite3 v3.03.36 3.03.36 allows attackers to escalate privileges and execute arbitrary code via sending crafted IOCTL requests.

    Published: 22 May 2024
    7.8
    High

    CVE-2024-33219

    Last Modified: 18 Apr 2025

    An issue in the component AsIO64.sys of ASUSTeK Computer Inc ASUS SABERTOOTH X99 Driver v1.0.1.0 allows attackers to escalate privileges and execute arbitrary code via sending crafted IOCTL requests.

    Published: 22 May 2024
    7.8
    High

    CVE-2024-33218

    Last Modified: 15 Apr 2026

    An issue in the component AsUpIO64.sys of ASUSTeK Computer Inc ASUS USB 3.0 Boost Storage Driver 5.30.20.0 allows attackers to escalate privileges and execute arbitrary code via sending crafted IOCTL requests.

    Published: 22 May 2024
    6.4
    Medium

    CVE-2024-3926

    Last Modified: 8 Apr 2026

    The Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the custom_attributes value in widgets in all versions up to, and including, 5.6.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 22 May 2024
    9.8
    Critical

    CVE-2024-35409

    Last Modified: 28 May 2025

    WeBid 1.1.2 is vulnerable to SQL Injection via admin/tax.php.

    Published: 22 May 2024
    6.4
    Medium

    CVE-2024-35475

    Last Modified: 12 Nov 2025

    A Cross-Site Request Forgery (CSRF) vulnerability was discovered in OpenKM Community Edition on or before version 6.3.12. The vulnerability exists in /admin/DatabaseQuery, which allows an attacker to manipulate a victim with administrative privileges to execute arbitrary SQL commands.

    Published: 22 May 2024
    5.4
    Medium

    CVE-2024-35561

    Last Modified: 9 Apr 2025

    idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/ca_deal.php?mudi=add&nohrefStr=close.

    Published: 22 May 2024
    4.3
    Medium

    CVE-2024-35560

    Last Modified: 9 Apr 2025

    idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/ca_deal.php?mudi=del&dataType=&dataTypeCN.

    Published: 22 May 2024
    8.8
    High

    CVE-2024-35559

    Last Modified: 9 Apr 2025

    idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/infoMove_deal.php?mudi=rev&nohrefStr=close.

    Published: 22 May 2024
    8.8
    High

    CVE-2024-35558

    Last Modified: 9 Apr 2025

    idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/ca_deal.php?mudi=rev&nohrefStr=close.

    Published: 22 May 2024
    5.5
    Medium

    CVE-2024-35557

    Last Modified: 9 Apr 2025

    idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/vpsApi_deal.php?mudi=rev&nohrefStr=close.

    Published: 22 May 2024
    6.3
    Medium

    CVE-2024-35555

    Last Modified: 9 Apr 2025

    idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/share_switch.php?mudi=switch&dataType=newsWeb&fieldName=state&fieldName2=state&tabName=infoWeb&dataID=40.

    Published: 22 May 2024
    8.8
    High

    CVE-2024-35556

    Last Modified: 9 Apr 2025

    idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/vpsSys_deal.php?mudi=infoSet.

    Published: 22 May 2024
    5.4
    Medium

    CVE-2024-35554

    Last Modified: 9 Apr 2025

    idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/infoWeb_deal.php?mudi=del&dataType=newsWeb&dataTypeCN.

    Published: 22 May 2024
    8.3
    High

    CVE-2024-35553

    Last Modified: 9 Apr 2025

    idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/infoMove_deal.php?mudi=add&nohrefStr=close.

    Published: 22 May 2024
    8.8
    High

    CVE-2024-35552

    Last Modified: 9 Apr 2025

    idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/infoMove_deal.php?mudi=del&dataType=logo&dataTypeCN.

    Published: 22 May 2024
    4.3
    Medium

    CVE-2024-35551

    Last Modified: 9 Apr 2025

    idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/infoWeb_deal.php?mudi=add.

    Published: 22 May 2024
    6.3
    Medium

    CVE-2024-35550

    Last Modified: 9 Apr 2025

    idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/infoWeb_deal.php?mudi=rev.

    Published: 22 May 2024
    5.4
    Medium

    CVE-2024-4261

    Last Modified: 15 Apr 2026

    The Responsive Contact Form Builder & Lead Generation Plugin plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 1.9.1. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for authenticated attackers, with subscriber-level access and above, to execute arbitrary shortcodes.

    Published: 22 May 2024
    5.1
    Medium

    CVE-2024-5196

    Last Modified: 14 Oct 2025

    A vulnerability classified as critical has been found in Arris VAP2500 08.50. This affects an unknown part of the file /tools_command.php. The manipulation of the argument cmb_header/txt_command leads to command injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-265833 was assigned to this vulnerability.

    Published: 22 May 2024
    5.1
    Medium

    CVE-2024-5195

    Last Modified: 14 Oct 2025

    A vulnerability was found in Arris VAP2500 08.50. It has been rated as critical. Affected by this issue is some unknown functionality of the file /diag_s.php. The manipulation of the argument customer_info leads to command injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-265832.

    Published: 22 May 2024
    5.1
    Medium

    CVE-2024-5194

    Last Modified: 14 Oct 2025

    A vulnerability was found in Arris VAP2500 08.50. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /assoc_table.php. The manipulation of the argument id leads to command injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-265831.

    Published: 22 May 2024
    5.5
    Medium

    CVE-2024-5193

    Last Modified: 5 Jan 2026

    A security vulnerability has been detected in Ritlabs TinyWeb Server 1.94. This vulnerability affects unknown code of the component Request Handler. The manipulation with the input %0D%0A leads to crlf injection. It is possible to initiate the attack remotely. The exploit has been disclosed publicly and may be used. Upgrading to version 1.99 is able to resolve this issue. The identifier of the patch is d49c3da6a97e950975b18626878f3ee1f082358e. It is suggested to upgrade the affected component. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 22 May 2024
    6.4
    Medium

    CVE-2024-4262

    Last Modified: 15 Apr 2026

    The Piotnet Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple widgets in all versions up to, and including, 2.4.28 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 22 May 2024
    —
    Unknown

    CVE-2024-4153

    Last Modified: 7 Jun 2024

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

    Published: 22 May 2024
    6.4
    Medium

    CVE-2024-5025

    Last Modified: 8 Apr 2026

    The Memberpress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘arglist’ parameter in all versions up to, and including, 1.11.29 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 22 May 2024
    6.4
    Medium

    CVE-2024-4362

    Last Modified: 8 Apr 2026

    The SiteOrigin Widgets Bundle plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'siteorigin_widget' shortcode in all versions up to, and including, 1.60.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 22 May 2024
    8.5
    High

    CVE-2024-5031

    Last Modified: 8 Apr 2026

    The Memberpress plugin for WordPress is vulnerable to Blind Server-Side Request Forgery in all versions up to, and including, 1.11.29 via the 'mepr-user-file' shortcode. This makes it possible for authenticated attackers, with Contributor-level access and above, to make web requests to arbitrary locations originating from the web application and can be used to query and modify information from internal services.

    Published: 22 May 2024
    4.3
    Medium

    CVE-2024-2036

    Last Modified: 15 Apr 2026

    The ApplyOnline – Application Form Builder and Manager plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the aol_modal_box AJAX action in all versions up to, and including, 2.6.2. This makes it possible for authenticated attackers, with subscriber access or higher, to view Application submissions.

    Published: 22 May 2024
    9.8
    Critical

    CVE-2024-3495

    Last Modified: 15 Apr 2026

    The Country State City Dropdown CF7 plugin for WordPress is vulnerable to SQL Injection via the ‘cnt’ and 'sid' parameters in versions up to, and including, 2.7.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

    Published: 22 May 2024
    6.4
    Medium

    CVE-2024-4896

    Last Modified: 8 Apr 2026

    The WPB Elementor Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘url’ parameter in all versions up to, and including, 1.0.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 22 May 2024
    7.5
    High

    CVE-2024-32988

    Last Modified: 15 Apr 2026

    'OfferBox' App for Android versions 2.0.0 to 2.3.17 and 'OfferBox' App for iOS versions 2.1.7 to 2.6.14 use a hard-coded secret key for JWT. Secret key for JWT may be retrieved if the application binary is reverse-engineered.

    Published: 22 May 2024
    9.8
    Critical

    CVE-2024-5147

    Last Modified: 8 Apr 2026

    The WPZOOM Addons for Elementor (Templates, Widgets) plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.1.37 via the 'grid_style' parameter. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where images and other “safe” file types can be uploaded and included.

    Published: 22 May 2024