CVE Feed

    Dashboard / CVE

    5.3
    Medium

    CVE-2024-31617

    Last Modified: 5 Jun 2025

    OpenLiteSpeed before 1.8.1 mishandles chunked encoding.

    Published: 22 May 2024
    6.2
    Medium

    CVE-2024-29421

    Last Modified: 15 Apr 2026

    xmedcon 0.23.0 and fixed in v.0.24.0 is vulnerable to Buffer Overflow via libs/dicom/basic.c which allows an attacker to execute arbitrary code.

    Published: 22 May 2024
    6.1
    Medium

    CVE-2024-4563

    Last Modified: 8 Jan 2025

    The Progress MOVEit Automation configuration export function prior to 2024.0.0 uses a cryptographic method with insufficient bit length.

    Published: 22 May 2024
    5.8
    Medium

    CVE-2024-20293

    Last Modified: 11 Aug 2026

    A vulnerability in the activation of an access control list (ACL) on Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass the protection that is offered by a configured ACL on an affected device. This vulnerability is due to a logic error that occurs when an ACL changes from inactive to active in the running configuration of an affected device. An attacker could exploit this vulnerability by sending traffic through the affected device that should be denied by the configured ACL. The reverse condition is also true—traffic that should be permitted could be denied by the configured ACL. A successful exploit could allow the attacker to bypass configured ACL protections on the affected device, allowing the attacker to access trusted networks that the device might be protecting. Note: This vulnerability applies to both IPv4 and IPv6 traffic as well as dual-stack ACL configurations in which both IPv4 and IPv6 ACLs are configured on an interface.

    Published: 22 May 2024
    5
    Medium

    CVE-2024-20355

    Last Modified: 11 Aug 2026

    A vulnerability in the implementation of SAML 2.0 single sign-on (SSO) for remote access VPN services in Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, remote attacker to successfully establish a VPN session on an affected device. This vulnerability is due to improper separation of authorization domains when using SAML authentication. An attacker could exploit this vulnerability by using valid credentials to successfully authenticate using their designated connection profile (tunnel group), intercepting the SAML SSO token that is sent back from the Cisco ASA device, and then submitting the same SAML SSO token to a different tunnel group for authentication. A successful exploit could allow the attacker to establish a remote access VPN session using a connection profile that they are not authorized to use and connect to secured networks behind the affected device that they are not authorized to access. For successful exploitation, the attacker must have valid remote access VPN user credentials.

    Published: 22 May 2024
    5.8
    Medium

    CVE-2024-20361

    Last Modified: 7 Aug 2025

    A vulnerability in the Object Groups for Access Control Lists (ACLs) feature of Cisco Firepower Management Center (FMC) Software could allow an unauthenticated, remote attacker to bypass configured access controls on managed devices that are running Cisco Firepower Threat Defense (FTD) Software. This vulnerability is due to the incorrect deployment of the Object Groups for ACLs feature from Cisco FMC Software to managed FTD devices in high-availability setups. After an affected device is rebooted following Object Groups for ACLs deployment, an attacker can exploit this vulnerability by sending traffic through the affected device. A successful exploit could allow the attacker to bypass configured access controls and successfully send traffic to devices that are expected to be protected by the affected device.

    Published: 22 May 2024
    5.8
    Medium

    CVE-2024-20261

    Last Modified: 11 Aug 2026

    A vulnerability in the file policy feature that is used to inspect encrypted archive files of Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass a configured file policy to block an encrypted archive file. This vulnerability exists because of a logic error when a specific class of encrypted archive files is inspected. An attacker could exploit this vulnerability by sending a crafted, encrypted archive file through the affected device. A successful exploit could allow the attacker to send an encrypted archive file, which could contain malware and should have been blocked and dropped at the Cisco FTD device.

    Published: 22 May 2024
    5.8
    Medium

    CVE-2024-20363

    Last Modified: 11 Aug 2026

    Multiple Cisco products are affected by a vulnerability in the Snort Intrusion Prevention System (IPS) rule engine that could allow an unauthenticated, remote attacker to bypass the configured rules on an affected system. This vulnerability is due to incorrect HTTP packet handling. An attacker could exploit this vulnerability by sending crafted HTTP packets through an affected device. A successful exploit could allow the attacker to bypass configured IPS rules and allow uninspected traffic onto the network.

    Published: 22 May 2024
    —
    Unknown

    CVE-2023-20239

    Last Modified: 13 Feb 2025

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

    Published: 22 May 2024
    8.8
    High

    CVE-2024-36077

    Last Modified: 15 Apr 2026

    Qlik Sense Enterprise for Windows before 14.187.4 allows a remote attacker to elevate their privilege due to improper validation. The attacker can elevate their privilege to the internal system role, which allows them to execute commands on the server. This affects February 2024 Patch 3 (14.173.3 through 14.173.7), November 2023 Patch 8 (14.159.4 through 14.159.13), August 2023 Patch 13 (14.139.3 through 14.139.20), May 2023 Patch 15 (14.129.3 through 14.129.22), February 2023 Patch 13 (14.113.1 through 14.113.18), November 2022 Patch 13 (14.97.2 through 14.97.18), August 2022 Patch 16 (14.78.3 through 14.78.23), and May 2022 Patch 17 (14.67.7 through 14.67.31). This has been fixed in May 2024 (14.187.4), February 2024 Patch 4 (14.173.8), November 2023 Patch 9 (14.159.14), August 2023 Patch 14 (14.139.21), May 2023 Patch 16 (14.129.23), February 2023 Patch 14 (14.113.19), November 2022 Patch 14 (14.97.19), August 2022 Patch 17 (14.78.25), and May 2022 Patch 18 (14.67.34).

    Published: 22 May 2024
    6.5
    Medium

    CVE-2024-5166

    Last Modified: 22 Jul 2025

    An Insecure Direct Object Reference in Google Cloud's Looker allowed metadata exposure across authenticated Looker users sharing the same LookML model.

    Published: 22 May 2024
    8.8
    High

    CVE-2024-34448

    Last Modified: 18 Apr 2025

    Ghost before 5.82.0 allows CSV Injection during a member CSV export.

    Published: 22 May 2024
    5.4
    Medium

    CVE-2024-29392

    Last Modified: 23 Apr 2025

    Silverpeas Core 6.3 is vulnerable to Cross Site Scripting (XSS) via ClipboardSessionController.

    Published: 22 May 2024
    5.4
    Medium

    CVE-2024-35362

    Last Modified: 28 Apr 2025

    Ecshop 3.6 is vulnerable to Cross Site Scripting (XSS) via ecshop/article_cat.php.

    Published: 22 May 2024
    8.4
    High

    CVE-2024-33228

    Last Modified: 15 Apr 2026

    An issue in the component segwindrvx64.sys of Insyde Software Corp SEG Windows Driver v100.00.07.02 allows attackers to escalate privileges and execute arbitrary code via sending crafted IOCTL requests.

    Published: 22 May 2024
    8.8
    High

    CVE-2024-33227

    Last Modified: 15 Apr 2026

    An issue in the component ddcdrv.sys of Nicomsoft WinI2C/DDC v3.7.4.0 allows attackers to escalate privileges and execute arbitrary code via sending crafted IOCTL requests.

    Published: 22 May 2024
    9.9
    Critical

    CVE-2024-33226

    Last Modified: 15 Apr 2026

    An issue in the component Access64.sys of Wistron Corporation TBT Force Power Control v1.0.0.0 allows attackers to escalate privileges and execute arbitrary code via sending crafted IOCTL requests.

    Published: 22 May 2024
    7.8
    High

    CVE-2024-33225

    Last Modified: 15 Apr 2026

    An issue in the component RTKVHD64.sys of Realtek Semiconductor Corp Realtek(r) High Definition Audio Function Driver v6.0.9549.1 allows attackers to escalate privileges and execute arbitrary code via sending crafted IOCTL requests.

    Published: 22 May 2024
    8.4
    High

    CVE-2024-33224

    Last Modified: 15 Apr 2026

    An issue in the component rtkio64.sys of Realtek Semiconductor Corp Realtek lO Driver v1.008.0823.2017 allows attackers to escalate privileges and execute arbitrary code via sending crafted IOCTL requests.

    Published: 22 May 2024
    8.8
    High

    CVE-2024-5160

    Last Modified: 13 Feb 2025

    Heap buffer overflow in Dawn in Google Chrome prior to 125.0.6422.76 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: High)

    Published: 22 May 2024
    8.8
    High

    CVE-2024-5159

    Last Modified: 13 Feb 2025

    Heap buffer overflow in ANGLE in Google Chrome prior to 125.0.6422.76 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: High)

    Published: 22 May 2024
    8.1
    High

    CVE-2024-5158

    Last Modified: 13 Feb 2025

    Type Confusion in V8 in Google Chrome prior to 125.0.6422.76 allowed a remote attacker to potentially perform arbitrary read/write via a crafted HTML page. (Chromium security severity: High)

    Published: 22 May 2024
    8.8
    High

    CVE-2024-5157

    Last Modified: 27 Mar 2025

    Use after free in Scheduling in Google Chrome prior to 125.0.6422.76 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

    Published: 22 May 2024
    8.8
    High

    CVE-2024-33223

    Last Modified: 15 Apr 2026

    An issue in the component IOMap64.sys of ASUSTeK Computer Inc ASUS GPU TweakII v1.4.5.2 allows attackers to escalate privileges and execute arbitrary code via sending crafted IOCTL requests.

    Published: 22 May 2024
    8.4
    High

    CVE-2024-33222

    Last Modified: 15 Apr 2026

    An issue in the component ATSZIO64.sys of ASUSTeK Computer Inc ASUS ATSZIO Driver v0.2.1.7 allows attackers to escalate privileges and execute arbitrary code via sending crafted IOCTL requests.

    Published: 22 May 2024
    7.8
    High

    CVE-2024-33221

    Last Modified: 15 Apr 2026

    An issue in the component AsusBSItf.sys of ASUSTeK Computer Inc ASUS BIOS Flash Driver v3.2.12.0 allows attackers to escalate privileges and execute arbitrary code via sending crafted IOCTL requests.

    Published: 22 May 2024
    8.8
    High

    CVE-2024-33220

    Last Modified: 18 Apr 2025

    An issue in the component AslO3_64.sys of ASUSTeK Computer Inc AISuite3 v3.03.36 3.03.36 allows attackers to escalate privileges and execute arbitrary code via sending crafted IOCTL requests.

    Published: 22 May 2024
    7.8
    High

    CVE-2024-33219

    Last Modified: 18 Apr 2025

    An issue in the component AsIO64.sys of ASUSTeK Computer Inc ASUS SABERTOOTH X99 Driver v1.0.1.0 allows attackers to escalate privileges and execute arbitrary code via sending crafted IOCTL requests.

    Published: 22 May 2024
    7.8
    High

    CVE-2024-33218

    Last Modified: 15 Apr 2026

    An issue in the component AsUpIO64.sys of ASUSTeK Computer Inc ASUS USB 3.0 Boost Storage Driver 5.30.20.0 allows attackers to escalate privileges and execute arbitrary code via sending crafted IOCTL requests.

    Published: 22 May 2024
    6.4
    Medium

    CVE-2024-3926

    Last Modified: 8 Apr 2026

    The Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the custom_attributes value in widgets in all versions up to, and including, 5.6.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 22 May 2024
    9.8
    Critical

    CVE-2024-35409

    Last Modified: 28 May 2025

    WeBid 1.1.2 is vulnerable to SQL Injection via admin/tax.php.

    Published: 22 May 2024
    6.4
    Medium

    CVE-2024-35475

    Last Modified: 12 Nov 2025

    A Cross-Site Request Forgery (CSRF) vulnerability was discovered in OpenKM Community Edition on or before version 6.3.12. The vulnerability exists in /admin/DatabaseQuery, which allows an attacker to manipulate a victim with administrative privileges to execute arbitrary SQL commands.

    Published: 22 May 2024
    5.4
    Medium

    CVE-2024-35561

    Last Modified: 9 Apr 2025

    idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/ca_deal.php?mudi=add&nohrefStr=close.

    Published: 22 May 2024
    4.3
    Medium

    CVE-2024-35560

    Last Modified: 9 Apr 2025

    idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/ca_deal.php?mudi=del&dataType=&dataTypeCN.

    Published: 22 May 2024
    8.8
    High

    CVE-2024-35559

    Last Modified: 9 Apr 2025

    idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/infoMove_deal.php?mudi=rev&nohrefStr=close.

    Published: 22 May 2024
    8.8
    High

    CVE-2024-35558

    Last Modified: 9 Apr 2025

    idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/ca_deal.php?mudi=rev&nohrefStr=close.

    Published: 22 May 2024
    5.5
    Medium

    CVE-2024-35557

    Last Modified: 9 Apr 2025

    idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/vpsApi_deal.php?mudi=rev&nohrefStr=close.

    Published: 22 May 2024
    6.3
    Medium

    CVE-2024-35555

    Last Modified: 9 Apr 2025

    idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/share_switch.php?mudi=switch&dataType=newsWeb&fieldName=state&fieldName2=state&tabName=infoWeb&dataID=40.

    Published: 22 May 2024
    8.8
    High

    CVE-2024-35556

    Last Modified: 9 Apr 2025

    idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/vpsSys_deal.php?mudi=infoSet.

    Published: 22 May 2024
    5.4
    Medium

    CVE-2024-35554

    Last Modified: 9 Apr 2025

    idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/infoWeb_deal.php?mudi=del&dataType=newsWeb&dataTypeCN.

    Published: 22 May 2024
    8.3
    High

    CVE-2024-35553

    Last Modified: 9 Apr 2025

    idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/infoMove_deal.php?mudi=add&nohrefStr=close.

    Published: 22 May 2024
    8.8
    High

    CVE-2024-35552

    Last Modified: 9 Apr 2025

    idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/infoMove_deal.php?mudi=del&dataType=logo&dataTypeCN.

    Published: 22 May 2024
    4.3
    Medium

    CVE-2024-35551

    Last Modified: 9 Apr 2025

    idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/infoWeb_deal.php?mudi=add.

    Published: 22 May 2024
    6.3
    Medium

    CVE-2024-35550

    Last Modified: 9 Apr 2025

    idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/infoWeb_deal.php?mudi=rev.

    Published: 22 May 2024
    5.4
    Medium

    CVE-2024-4261

    Last Modified: 15 Apr 2026

    The Responsive Contact Form Builder & Lead Generation Plugin plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 1.9.1. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for authenticated attackers, with subscriber-level access and above, to execute arbitrary shortcodes.

    Published: 22 May 2024
    5.1
    Medium

    CVE-2024-5196

    Last Modified: 14 Oct 2025

    A vulnerability classified as critical has been found in Arris VAP2500 08.50. This affects an unknown part of the file /tools_command.php. The manipulation of the argument cmb_header/txt_command leads to command injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-265833 was assigned to this vulnerability.

    Published: 22 May 2024
    5.1
    Medium

    CVE-2024-5195

    Last Modified: 14 Oct 2025

    A vulnerability was found in Arris VAP2500 08.50. It has been rated as critical. Affected by this issue is some unknown functionality of the file /diag_s.php. The manipulation of the argument customer_info leads to command injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-265832.

    Published: 22 May 2024
    5.1
    Medium

    CVE-2024-5194

    Last Modified: 14 Oct 2025

    A vulnerability was found in Arris VAP2500 08.50. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /assoc_table.php. The manipulation of the argument id leads to command injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-265831.

    Published: 22 May 2024
    5.5
    Medium

    CVE-2024-5193

    Last Modified: 5 Jan 2026

    A security vulnerability has been detected in Ritlabs TinyWeb Server 1.94. This vulnerability affects unknown code of the component Request Handler. The manipulation with the input %0D%0A leads to crlf injection. It is possible to initiate the attack remotely. The exploit has been disclosed publicly and may be used. Upgrading to version 1.99 is able to resolve this issue. The identifier of the patch is d49c3da6a97e950975b18626878f3ee1f082358e. It is suggested to upgrade the affected component. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 22 May 2024
    6.4
    Medium

    CVE-2024-4262

    Last Modified: 15 Apr 2026

    The Piotnet Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple widgets in all versions up to, and including, 2.4.28 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 22 May 2024