CVE Feed

    Dashboard / CVE

    6.2
    Medium

    CVE-2024-35312

    Last Modified: 15 Apr 2026

    In Tor Arti before 1.2.3, STUB circuits incorrectly have a length of 2 (with lite vanguards), aka TROVE-2024-003.

    Published: 17 May 2024
    5.3
    Medium

    CVE-2024-5069

    Last Modified: 11 Feb 2025

    A vulnerability, which was classified as critical, has been found in SourceCodester Simple Online Mens Salon Management System 1.0. Affected by this issue is some unknown functionality of the file view_service.php. The manipulation of the argument id leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-264926 is the identifier assigned to this vulnerability.

    Published: 17 May 2024
    5.3
    Medium

    CVE-2024-5066

    Last Modified: 3 Mar 2025

    A vulnerability classified as critical was found in PHPGurukul Online Course Registration System 3.1. Affected by this vulnerability is an unknown functionality of the file /pincode-verification.php. The manipulation of the argument pincode leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-264925 was assigned to this vulnerability.

    Published: 17 May 2024
    6.9
    Medium

    CVE-2024-5065

    Last Modified: 3 Mar 2025

    A vulnerability classified as critical has been found in PHPGurukul Online Course Registration System 3.1. Affected is an unknown function of the file /onlinecourse/. The manipulation of the argument regno leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-264924.

    Published: 17 May 2024
    5.5
    Medium

    CVE-2024-34959

    Last Modified: 1 Apr 2025

    DedeCMS V5.7.113 is vulnerable to Cross Site Scripting (XSS) via sys_data_replace.php.

    Published: 17 May 2024
    4.4
    Medium

    CVE-2024-5022

    Last Modified: 4 Apr 2025

    The file scheme of URLs would be hidden, resulting in potential spoofing of a website's address in the location bar This vulnerability affects Focus for iOS < 126.

    Published: 17 May 2024
    7.2
    High

    CVE-2021-22508

    Last Modified: 15 Apr 2026

    A potential vulnerability has been identified for OpenText Operations Bridge Reporter. The vulnerability could be exploited to inject malicious SQL queries. An attack requires to be an authenticated administrator of OBR with network access to the OBR web application.

    Published: 17 May 2024
    6.9
    Medium

    CVE-2024-5064

    Last Modified: 3 Mar 2025

    A vulnerability was found in PHPGurukul Online Course Registration System 3.1. It has been rated as critical. This issue affects some unknown processing of the file news-details.php. The manipulation of the argument nid leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-264923.

    Published: 17 May 2024
    6.9
    Medium

    CVE-2024-5063

    Last Modified: 12 Jul 2025

    A vulnerability was found in PHPGurukul Online Course Registration System 3.1. It has been declared as critical. This vulnerability affects unknown code of the file /admin/index.php. The manipulation of the argument username/password leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-264922 is the identifier assigned to this vulnerability.

    Published: 17 May 2024
    8.2
    High

    CVE-2024-3292

    Last Modified: 15 Apr 2026

    A race condition vulnerability exists where an authenticated, local attacker on a Windows Nessus Agent host could modify installation parameters at installation time, which could lead to the execution of arbitrary code on the Nessus host. - CVE-2024-3292

    Published: 17 May 2024
    7.8
    High

    CVE-2024-3291

    Last Modified: 15 Apr 2026

    When installing Nessus Agent to a directory outside of the default location on a Windows host, Nessus Agent versions prior to 10.6.4 did not enforce secure permissions for sub-directories. This could allow for local privilege escalation if users had not secured the directories in the non-default installation location.

    Published: 17 May 2024
    5.8
    Medium

    CVE-2024-35190

    Last Modified: 26 Aug 2025

    Asterisk is an open source private branch exchange and telephony toolkit. After upgrade to 18.23.0, ALL unauthorized SIP requests are identified as PJSIP Endpoint of local asterisk server. This vulnerability is fixed in 18.23.1, 20.8.1, and 21.3.1.

    Published: 17 May 2024
    5.4
    Medium

    CVE-2023-5597

    Last Modified: 15 Apr 2026

    A stored Cross-site Scripting (XSS) vulnerability affecting 3DDashboard in 3DSwymer from Release 3DEXPERIENCE R2023x through Release 3DEXPERIENCE R2024x allows an attacker to execute arbitrary script code.

    Published: 17 May 2024
    8.2
    High

    CVE-2024-3290

    Last Modified: 15 Apr 2026

    A race condition vulnerability exists where an authenticated, local attacker on a Windows Nessus host could modify installation parameters at installation time, which could lead to the execution of arbitrary code on the Nessus host

    Published: 17 May 2024
    7.8
    High

    CVE-2024-3289

    Last Modified: 15 Apr 2026

    When installing Nessus to a directory outside of the default location on a Windows host, Nessus versions prior to 10.7.3 did not enforce secure permissions for sub-directories. This could allow for local privilege escalation if users had not secured the directories in the non-default installation location.

    Published: 17 May 2024
    6.3
    Medium

    CVE-2024-31974

    Last Modified: 15 Apr 2026

    The com.solarized.firedown (aka Solarized FireDown Browser & Downloader) application 1.0.76 for Android allows a remote attacker to execute arbitrary JavaScript code via a crafted intent. com.solarized.firedown.IntentActivity uses a WebView component to display web content and doesn't adequately sanitize the URI or any extra data passed in the intent by any installed application (with no permissions).

    Published: 17 May 2024
    7.5
    High

    CVE-2024-22429

    Last Modified: 30 Jan 2025

    Dell BIOS contains an Improper Input Validation vulnerability. A local authenticated malicious user with admin privileges could potentially exploit this vulnerability, leading to arbitrary code execution.

    Published: 17 May 2024
    6.5
    Medium

    CVE-2024-5072

    Last Modified: 28 Mar 2025

    Improper input validation in PAM JIT elevation feature in Devolutions Server 2024.1.11.0 and earlier allows an authenticated user with access to the PAM JIT elevation feature to manipulate the LDAP filter query via a specially crafted request.

    Published: 17 May 2024
    4.8
    Medium

    CVE-2024-34241

    Last Modified: 13 May 2025

    A cross-site scripting (XSS) vulnerability in Rocketsoft Rocket LMS 1.9 allows an administrator to store a JavaScript payload using the admin web interface when creating new courses and new course notifications.

    Published: 17 May 2024
    5.3
    Medium

    CVE-2024-5051

    Last Modified: 10 Feb 2025

    A vulnerability has been found in SourceCodester Gas Agency Management System 1.0 and classified as critical. This vulnerability affects unknown code of the file edituser.php. The manipulation of the argument id leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-264748.

    Published: 17 May 2024
    5.3
    Medium

    CVE-2024-5050

    Last Modified: 15 Apr 2026

    A vulnerability, which was classified as critical, was found in Wangshen SecGate 3600 up to 20240516. This affects an unknown part of the file /?g=log_import_save. The manipulation of the argument reqfile leads to unrestricted upload. It is possible to initiate the attack remotely. The associated identifier of this vulnerability is VDB-264747.

    Published: 17 May 2024
    5.3
    Medium

    CVE-2024-5049

    Last Modified: 13 Jul 2025

    A vulnerability, which was classified as critical, has been found in Codezips E-Commerce Site 1.0. Affected by this issue is some unknown functionality of the file admin/editproduct.php. The manipulation of the argument profilepic leads to unrestricted upload. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-264746 is the identifier assigned to this vulnerability.

    Published: 17 May 2024
    9.8
    Critical

    CVE-2024-34919

    Last Modified: 15 Apr 2026

    An arbitrary file upload vulnerability in the component \modstudent\controller.php of Pisay Online E-Learning System using PHP/MySQL v1.0 allows attackers to execute arbitrary code via uploading a crafted file.

    Published: 17 May 2024
    9.8
    Critical

    CVE-2024-34982

    Last Modified: 17 Jun 2025

    An arbitrary file upload vulnerability in the component /include/file.php of lylme_spage v1.9.5 allows attackers to execute arbitrary code via uploading a crafted file.

    Published: 17 May 2024
    5.3
    Medium

    CVE-2024-5048

    Last Modified: 3 Mar 2025

    A vulnerability classified as critical was found in code-projects Budget Management 1.0. Affected by this vulnerability is an unknown functionality of the file /index.php. The manipulation of the argument edit leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-264745 was assigned to this vulnerability.

    Published: 17 May 2024
    6.9
    Medium

    CVE-2024-5047

    Last Modified: 10 Feb 2025

    A vulnerability classified as critical has been found in SourceCodester Student Management System 1.0. Affected is an unknown function of the file /student/controller.php. The manipulation of the argument photo leads to unrestricted upload. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-264744.

    Published: 17 May 2024
    6.9
    Medium

    CVE-2024-5046

    Last Modified: 10 Feb 2025

    A vulnerability was found in SourceCodester Online Examination System 1.0. It has been rated as critical. This issue affects some unknown processing of the file registeracc.php. The manipulation of the argument email leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-264743.

    Published: 17 May 2024
    6.9
    Medium

    CVE-2024-5045

    Last Modified: 10 Feb 2025

    A vulnerability was found in SourceCodester Online Birth Certificate Management System 1.0. It has been declared as problematic. This vulnerability affects unknown code of the file /admin. The manipulation leads to files or directories accessible. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-264742 is the identifier assigned to this vulnerability.

    Published: 17 May 2024
    7.5
    High

    CVE-2024-5055

    Last Modified: 15 Apr 2026

    Uncontrolled resource consumption vulnerability in XAMPP Windows, versions 7.3.2 and earlier. This vulnerability exists when XAMPP attempts to process many incomplete HTTP requests, resulting in resource consumption and system crashes.

    Published: 17 May 2024
    6.3
    Medium

    CVE-2024-5044

    Last Modified: 5 Mar 2025

    A vulnerability was found in Emlog Pro 2.3.4. It has been classified as problematic. This affects an unknown part of the component Cookie Handler. The manipulation of the argument AuthCookie leads to improper authentication. It is possible to initiate the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used. The identifier VDB-264741 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 17 May 2024
    5.1
    Medium

    CVE-2024-5043

    Last Modified: 5 Mar 2025

    A vulnerability was found in Emlog Pro 2.3.4 and classified as critical. Affected by this issue is some unknown functionality of the file admin/setting.php. The manipulation leads to unrestricted upload. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-264740. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 17 May 2024
    —
    Unknown

    CVE-2024-35173

    Last Modified: 12 Mar 2025

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

    Published: 17 May 2024
    5.3
    Medium

    CVE-2024-35174

    Last Modified: 15 Apr 2026

    Missing Authorization vulnerability in Flothemes Flo Forms.This issue affects Flo Forms: from n/a through 1.0.42.

    Published: 17 May 2024
    9.1
    Critical

    CVE-2024-22120

    Last Modified: 8 Oct 2025

    Zabbix server can perform command execution for configured scripts. After command is executed, audit entry is added to "Audit Log". Due to "clientip" field is not sanitized, it is possible to injection SQL into "clientip" and exploit time based blind SQL injection.

    Published: 17 May 2024
    4.3
    Medium

    CVE-2024-34755

    Last Modified: 15 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in CRM Perks Integration for Contact Form 7 and Salesforce.This issue affects Integration for Contact Form 7 and Salesforce: from n/a through 1.3.9.

    Published: 17 May 2024
    4.3
    Medium

    CVE-2024-34756

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in CRM Perks Integration for Contact Form 7 HubSpot.This issue affects Integration for Contact Form 7 HubSpot: from n/a through 1.3.1.

    Published: 17 May 2024
    4.3
    Medium

    CVE-2024-34806

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Creative Motion Clearfy Cache.This issue affects Clearfy Cache: from n/a through 2.2.1.

    Published: 17 May 2024
    4.3
    Medium

    CVE-2024-34807

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in CodeBard Fast Custom Social Share by CodeBard fast-custom-social-share-by-codebard.This issue affects Fast Custom Social Share by CodeBard: from n/a through <= 1.1.2.

    Published: 17 May 2024
    4.3
    Medium

    CVE-2024-34809

    Last Modified: 7 Jan 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Extend Themes EmpowerWP.This issue affects EmpowerWP: from n/a through 1.0.21.

    Published: 17 May 2024
    8.8
    High

    CVE-2024-32960

    Last Modified: 15 Apr 2026

    Improper Privilege Management vulnerability in Booking Ultra Pro allows Privilege Escalation.This issue affects Booking Ultra Pro: from n/a through 1.1.12.

    Published: 17 May 2024
    8.8
    High

    CVE-2024-32959

    Last Modified: 23 Apr 2026

    Incorrect Privilege Assignment vulnerability in Sirv CDN and Image Hosting Sirv sirv.This issue affects Sirv: from n/a through <= 7.2.2.

    Published: 17 May 2024
    8.6
    High

    CVE-2024-32830

    Last Modified: 25 Nov 2025

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in ThemeKraft BuddyForms allows Server Side Request Forgery, Relative Path Traversal.This issue affects BuddyForms: from n/a through 2.8.8.

    Published: 17 May 2024
    7.5
    High

    CVE-2024-5052

    Last Modified: 15 Apr 2026

    Denial of Service (DoS) vulnerability for Cerberus Enterprise 8.0.10.3 web administration. The vulnerability exists when the web server, default port 10001, attempts to process a large number of incomplete HTTP requests.

    Published: 17 May 2024
    5.3
    Medium

    CVE-2024-32827

    Last Modified: 15 Apr 2026

    Authentication Bypass by Spoofing vulnerability in RafflePress Giveaways and Contests allows Functionality Bypass.This issue affects Giveaways and Contests: from n/a through 1.12.7.

    Published: 17 May 2024
    10
    Critical

    CVE-2024-32809

    Last Modified: 15 Apr 2026

    Unrestricted Upload of File with Dangerous Type vulnerability in JumpDEMAND Inc. ActiveDEMAND allows Using Malicious Files.This issue affects ActiveDEMAND: from n/a through 0.2.41.

    Published: 17 May 2024
    5.3
    Medium

    CVE-2024-32802

    Last Modified: 15 Apr 2026

    Missing Authorization vulnerability in WordPlus BP Better Messages allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects BP Better Messages: from n/a through 2.4.32.

    Published: 17 May 2024
    5.3
    Medium

    CVE-2024-32786

    Last Modified: 21 Nov 2024

    Authentication Bypass by Spoofing vulnerability in WP Royal Royal Elementor Addons allows Functionality Bypass.This issue affects Royal Elementor Addons: from n/a through 1.3.93.

    Published: 17 May 2024
    4.3
    Medium

    CVE-2024-32774

    Last Modified: 3 Feb 2025

    Improper Restriction of Excessive Authentication Attempts vulnerability in Metagauss ProfileGrid allows Removing Important Client Functionality.This issue affects ProfileGrid : from n/a through 5.8.2.

    Published: 17 May 2024
    5.3
    Medium

    CVE-2024-32720

    Last Modified: 15 Apr 2026

    Improper Restriction of Excessive Authentication Attempts vulnerability in CodePeople Appointment Hour Booking allows Removing Important Client Functionality.This issue affects Appointment Hour Booking: from n/a through 1.4.56.

    Published: 17 May 2024
    3.7
    Low

    CVE-2024-32708

    Last Modified: 28 Apr 2026

    Authentication Bypass by Spoofing vulnerability in helderk Maintenance Mode allows Functionality Bypass.This issue affects Maintenance Mode: from n/a through 3.0.1.

    Published: 17 May 2024