CVE Feed

    Dashboard / CVE

    8.8
    High

    CVE-2024-35102

    Last Modified: 15 Apr 2026

    Insecure Permissions vulnerability in VITEC AvediaServer (Model avsrv-m8105) 8.6.2-1 allows a remote attacker to escalate privileges via a crafted script.

    Published: 15 May 2024
    6.5
    Medium

    CVE-2024-3182

    Last Modified: 15 Apr 2026

    Install-type password disclosure vulnerability in Universal Installer including the Silent Installer in TIBCO Hawk versions 6.2.0, 6.2.1, 6.2.2 and 6.2.3 allows user's Enterprise Message Service (EMS) password to be exposed outside of the hawkagent.cfg and hawkevent.cfg config files.

    Published: 15 May 2024
    4.8
    Medium

    CVE-2024-20383

    Last Modified: 8 Aug 2025

    A vulnerability in the web-based management interface of Cisco AsyncOS Software for Cisco Secure Email and Web Manager could allow an authenticated, remote attacker to conduct an XSS attack against a user of the interface. This vulnerability is due to insufficient validation of user input. An attacker could exploit this vulnerability by persuading a user of an affected interface to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information.

    Published: 15 May 2024
    4.8
    Medium

    CVE-2024-20257

    Last Modified: 6 Aug 2025

    A vulnerability in the web-based management interface of Cisco AsyncOS Software for Cisco Secure Email Gateway could allow an authenticated, remote attacker to conduct an XSS attack against a user of the interface.r This vulnerability is due to insufficient validation of user input. An attacker could exploit this vulnerability by persuading a user of an affected interface to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information.

    Published: 15 May 2024
    4.8
    Medium

    CVE-2024-20256

    Last Modified: 7 Aug 2025

    A vulnerability in the web-based management interface of Cisco AsyncOS Software for Cisco Secure Email and Web Manager and Secure Web Appliance could allow an authenticated, remote attacker to conduct an XSS attack against a user of the interface. This vulnerability is due to insufficient validation of user input. An attacker could exploit this vulnerability by persuading a user of an affected interface to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information.

    Published: 15 May 2024
    6.1
    Medium

    CVE-2024-20258

    Last Modified: 31 Jul 2025

    A vulnerability in the web-based management interface of Cisco AsyncOS Software for Cisco Secure Email and Web Manager and Secure Email Gateway could allow an unauthenticated, remote attacker to conduct an XSS attack against a user of the interface. This vulnerability is due to insufficient validation of user input. An attacker could exploit this vulnerability by persuading a user of an affected interface to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information.

    Published: 15 May 2024
    5.3
    Medium

    CVE-2024-4905

    Last Modified: 11 Feb 2025

    A vulnerability classified as critical has been found in Kashipara College Management System 1.0. Affected is an unknown function of the file view_students_each_detail.php. The manipulation of the argument id leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-264438 is the identifier assigned to this vulnerability.

    Published: 15 May 2024
    7.8
    High

    CVE-2024-20366

    Last Modified: 25 Mar 2025

    A vulnerability in the Tail-f High Availability Cluster Communications (HCC) function pack of Cisco Crosswork Network Services Orchestrator (NSO) could allow an authenticated, local attacker to elevate privileges to root on an affected device. This vulnerability exists because a user-controlled search path is used to locate executable files. An attacker could exploit this vulnerability by configuring the application in a way that causes a malicious file to be executed. A successful exploit could allow the attacker to execute arbitrary code on an affected device as the root user. To exploit this vulnerability, the attacker would need valid credentials on an affected device.

    Published: 15 May 2024
    6.8
    Medium

    CVE-2024-20391

    Last Modified: 22 Jul 2025

    A vulnerability in the Network Access Manager (NAM) module of Cisco Secure Client could allow an unauthenticated attacker with physical access to an affected device to elevate privileges to SYSTEM. This vulnerability is due to a lack of authentication on a specific function. A successful exploit could allow the attacker to execute arbitrary code with SYSTEM privileges on an affected device.

    Published: 15 May 2024
    4.7
    Medium

    CVE-2024-20369

    Last Modified: 25 Mar 2025

    A vulnerability in the web-based management interface of Cisco Crosswork Network Services Orchestrator (NSO) could allow an unauthenticated, remote attacker to redirect a user to a malicious web page. This vulnerability is due to improper input validation of a parameter in an HTTP request. An attacker could exploit this vulnerability by persuading a user to click a crafted link. A successful exploit could allow the attacker to redirect a user to a malicious website.

    Published: 15 May 2024
    6.1
    Medium

    CVE-2024-20392

    Last Modified: 6 Aug 2025

    A vulnerability in the web-based management API of Cisco AsyncOS Software for Cisco Secure Email Gateway could allow an unauthenticated, remote attacker to conduct an HTTP response splitting attack. This vulnerability is due to insufficient input validation of some parameters that are passed to the web-based management API of the affected system. An attacker could exploit this vulnerability by persuading a user of an affected interface to click a crafted link. A successful exploit could allow the attacker to perform cross-site scripting (XSS) attacks, resulting in the execution of arbitrary script code in the browser of the targeted user, or could allow the attacker to access sensitive, browser-based information.

    Published: 15 May 2024
    5.5
    Medium

    CVE-2024-20394

    Last Modified: 4 Aug 2025

    A vulnerability in Cisco AppDynamics Network Visibility Agent could allow an unauthenticated, local attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to the inability to handle unexpected input. An attacker who has local device access could exploit this vulnerability by sending an HTTP request to the targeted service. A successful exploit could allow the attacker to cause a DoS condition by stopping the Network Agent Service on the local device.

    Published: 15 May 2024
    5.3
    Medium

    CVE-2024-4837

    Last Modified: 16 Jan 2025

    In Progress Telerik Report Server, version 2024 Q1 (10.0.24.305) or earlier, on IIS, an unauthenticated attacker can gain access to Telerik Report Server restricted functionality via a trust boundary violation vulnerability.

    Published: 15 May 2024
    6.5
    Medium

    CVE-2024-4357

    Last Modified: 16 Jan 2025

    An information disclosure vulnerability exists in Progress Telerik Report Server, version 2024 Q1 (10.0.24.305) or earlier, allows low-privilege attacker to read systems file via XML External Entity Processing.

    Published: 15 May 2024
    7.7
    High

    CVE-2024-4200

    Last Modified: 16 Jan 2025

    In Progress® Telerik® Reporting versions prior to 2024 Q2 (18.1.24.2.514), a code execution attack is possible by a local threat actor through an insecure deserialization vulnerability.

    Published: 15 May 2024
    8.3
    High

    CVE-2024-4622

    Last Modified: 15 Apr 2026

    If misconfigured, alpitronic Hypercharger EV charging devices can expose a web interface protected by authentication. If the default credentials are not changed, an attacker can use public knowledge to access the device as an administrator.

    Published: 15 May 2024
    7.7
    High

    CVE-2024-4202

    Last Modified: 16 Jan 2025

    In Progress® Telerik® Reporting versions prior to 2024 Q2 (18.1.24.514), a code execution attack is possible through an insecure instantiation vulnerability.

    Published: 15 May 2024
    5.6
    Medium

    CVE-2024-3488

    Last Modified: 21 Jan 2025

    File Upload vulnerability in unauthenticated session found in OpenText™ iManager 3.2.6.0200. The vulnerability could allow ant attacker to upload a file without authentication.

    Published: 15 May 2024
    3.5
    Low

    CVE-2024-3487

    Last Modified: 21 Jan 2025

    Broken Authentication vulnerability discovered in OpenText™ iManager 3.2.6.0200. This vulnerability allows an attacker to manipulate certain parameters to bypass authentication.

    Published: 15 May 2024
    7.8
    High

    CVE-2024-3486

    Last Modified: 21 Jan 2025

    XML External Entity injection vulnerability found in OpenText™ iManager 3.2.6.0200. This could lead to information disclosure and remote code execution.

    Published: 15 May 2024
    5.3
    Medium

    CVE-2024-3485

    Last Modified: 21 Jan 2025

    Server Side Request Forgery vulnerability has been discovered in OpenText™ iManager 3.2.6.0200. This could lead to senstive information disclosure.

    Published: 15 May 2024
    5.7
    Medium

    CVE-2024-3484

    Last Modified: 21 Jan 2025

    Path Traversal found in OpenText™ iManager 3.2.6.0200. This can lead to privilege escalation or file disclosure.

    Published: 15 May 2024
    8.6
    High

    CVE-2024-28042

    Last Modified: 15 Apr 2026

    SUBNET Solutions Inc. has identified vulnerabilities in third-party components used in PowerSYSTEM Center.

    Published: 15 May 2024
    7.8
    High

    CVE-2024-3483

    Last Modified: 21 Jan 2025

    Remote Code Execution has been discovered in OpenText™ iManager 3.2.6.0200. The vulnerability can trigger command injection and insecure deserialization issues.

    Published: 15 May 2024
    7.2
    High

    CVE-2024-3892

    Last Modified: 3 Jul 2025

    A local code execution vulnerability is possible in Telerik UI for WinForms beginning in v2021.1.122 but prior to v2024.2.514. This vulnerability could allow an untrusted theme assembly to execute arbitrary code on the local Windows system.

    Published: 15 May 2024
    8.5
    High

    CVE-2024-34082

    Last Modified: 2 Jan 2025

    Grav is a file-based Web platform. Prior to version 1.7.46, a low privilege user account with page edit privilege can read any server files using Twig Syntax. This includes Grav user account files - `/grav/user/accounts/*.yaml`. This file stores hashed user password, 2FA secret, and the password reset token. This can allow an adversary to compromise any registered account and read any file in the web server by resetting a password for a user to get access to the password reset token from the file or by cracking the hashed password. A low privileged user may also perform a full account takeover of other registered users including Administrators. Version 1.7.46 contains a patch.

    Published: 15 May 2024
    7.6
    High

    CVE-2024-3967

    Last Modified: 21 Jan 2025

    Remote Code Execution has been discovered in OpenText™ iManager 3.2.6.0200. The vulnerability can trigger remote code execution unisng unsafe java object deserialization.

    Published: 15 May 2024
    7.8
    High

    CVE-2024-3968

    Last Modified: 21 Jan 2025

    Remote Code Execution has been discovered in OpenText™ iManager 3.2.6.0200. The vulnerability can trigger remote code execution using custom file upload task.

    Published: 15 May 2024
    5.3
    Medium

    CVE-2024-3970

    Last Modified: 21 Jan 2025

    Server Side Request Forgery vulnerability has been discovered in OpenText™ iManager 3.2.6.0200. This could lead to senstive information disclosure by directory traversal.

    Published: 15 May 2024
    5.4
    Medium

    CVE-2024-27593

    Last Modified: 15 Apr 2026

    A stored cross-site scripting (XSS) vulnerability in the Filter function of Eramba Version 3.22.3 Community Edition allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the filter name field. This vulnerability has been fixed in version 3.23.0.

    Published: 15 May 2024
    4.8
    Medium

    CVE-2023-7258

    Last Modified: 22 Jul 2025

    A denial of service exists in Gvisor Sandbox where a bug in reference counting code in mount point tracking could lead to a panic, making it possible for an attacker running as root and with permission to mount volumes to kill the sandbox. We recommend upgrading past commit 6a112c60a257dadac59962e0bc9e9b5aee70b5b6

    Published: 15 May 2024
    8.9
    High

    CVE-2023-5938

    Last Modified: 15 Apr 2026

    Multiple functions use archives without properly validating the filenames therein, rendering the application vulnerable to path traversal via 'zip slip' attacks. An administrator able to provide tampered archives to be processed by the affected versions of Arc may be able to have arbitrary files extracted to arbitrary filesystem locations. Leveraging this issue, an attacker may be able to overwrite arbitrary files on the target filesystem and cause critical impacts on the system (e.g., arbitrary command execution on the victim’s machine).

    Published: 15 May 2024
    5.2
    Medium

    CVE-2023-5937

    Last Modified: 15 Apr 2026

    On Windows systems, the Arc configuration files resulted to be world-readable. This can lead to information disclosure by local attackers, via exfiltration of sensitive data from configuration files.

    Published: 15 May 2024
    7.3
    High

    CVE-2023-5936

    Last Modified: 15 Apr 2026

    On Unix systems (Linux, MacOS), Arc uses a temporary file with unsafe privileges. By tampering with such file, a malicious local user in the system may be able to trigger arbitrary code execution with root privileges.

    Published: 15 May 2024
    7.3
    High

    CVE-2023-5935

    Last Modified: 15 Apr 2026

    When configuring Arc (e.g. during the first setup), a local web interface is provided to ease the configuration process. Such web interface lacks authentication and may thus be abused by a local attacker or malware running on the machine itself. A malicious local user or process, during a window of opportunity when the local web interface is active, may be able to extract sensitive information or change Arc's configuration. This could also lead to arbitrary code execution if a malicious update package is installed.

    Published: 15 May 2024
    6.8
    Medium

    CVE-2024-35179

    Last Modified: 15 Apr 2026

    Stalwart Mail Server is an open-source mail server. Prior to version 0.8.0, when using `RUN_AS_USER`, the specified user (and therefore, web interface admins) can read arbitrary files as root. This issue affects admins who have set up to run stalwart with `RUN_AS_USER` who handed out admin credentials to the mail server but expect these to only grant access according to the `RUN_AS_USER` and are attacked where the attackers managed to achieve Arbitrary Code Execution using another vulnerability. Version 0.8.0 contains a patch for the issue.

    Published: 15 May 2024
    6.5
    Medium

    CVE-2024-3317

    Last Modified: 15 Apr 2026

    An improper access control was identified in the Identity Security Cloud (ISC) message server API that allowed an authenticated user to exfiltrate job processing metadata (opaque messageIDs, work queue depth and counts) for other tenants.

    Published: 15 May 2024
    5.1
    Medium

    CVE-2024-31216

    Last Modified: 15 Apr 2026

    The source-controller is a Kubernetes operator, specialised in artifacts acquisition from external sources such as Git, OCI, Helm repositories and S3-compatible buckets. The source-controller implements the source.toolkit.fluxcd.io API and is a core component of the GitOps toolkit. Prior to version 1.2.5, when source-controller was configured to use an Azure SAS token when connecting to Azure Blob Storage, the token was logged along with the Azure URL when the controller encountered a connection error. An attacker with access to the source-controller logs could use the token to gain access to the Azure Blob Storage until the token expires. This vulnerability was fixed in source-controller v1.2.5. There is no workaround for this vulnerability except for using a different auth mechanism such as Azure Workload Identity.

    Published: 15 May 2024
    4.2
    Medium

    CVE-2024-3318

    Last Modified: 15 Apr 2026

    A file path traversal vulnerability was identified in the DelimitedFileConnector Cloud Connector that allowed an authenticated administrator to set arbitrary connector attributes, including the “file“ attribute, which in turn allowed the user to access files uploaded for other sources.

    Published: 15 May 2024
    9.1
    Critical

    CVE-2024-3319

    Last Modified: 15 Apr 2026

    An issue was identified in the Identity Security Cloud (ISC) Transform preview and IdentityProfile preview API endpoints that allowed an authenticated administrator to execute user-defined templates as part of attribute transforms which could allow remote code execution on the host.

    Published: 15 May 2024
    5.3
    Medium

    CVE-2024-4903

    Last Modified: 15 Apr 2026

    A vulnerability was found in Tongda OA 2017. It has been declared as critical. This vulnerability affects unknown code of the file /general/meeting/manage/delete.php. The manipulation of the argument M_ID_STR leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-264436. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 15 May 2024
    —
    Unknown

    CVE-2024-4952

    Last Modified: 11 Feb 2025

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

    Published: 15 May 2024
    —
    Unknown

    CVE-2024-4951

    Last Modified: 11 Feb 2025

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

    Published: 15 May 2024
    7.4
    High

    CVE-2024-25079

    Last Modified: 4 Aug 2025

    A memory corruption vulnerability in HddPassword in Insyde InsydeH2O kernel 5.2 before 05.29.09, kernel 5.3 before 05.38.09, kernel 5.4 before 05.46.09, kernel 5.5 before 05.54.09, and kernel 5.6 before 05.61.09 could lead to escalating privileges in SMM.

    Published: 15 May 2024
    7.4
    High

    CVE-2024-27353

    Last Modified: 15 Apr 2026

    A memory corruption vulnerability in SdHost and SdMmcDevice in Insyde InsydeH2O kernel 5.2 before 05.29.09, kernel 5.3 before 05.38.09, kernel 5.4 before 05.46.09, kernel 5.5 before 05.54.09, and kernel 5.6 before 05.61.09 could lead to escalating privileges in SMM.

    Published: 15 May 2024
    9.8
    Critical

    CVE-2024-34955

    Last Modified: 4 Apr 2025

    Code-projects Budget Management 1.0 is vulnerable to SQL Injection via the delete parameter.

    Published: 15 May 2024
    6.1
    Medium

    CVE-2024-34954

    Last Modified: 4 Apr 2025

    Code-projects Budget Management 1.0 is vulnerable to Cross Site Scripting (XSS) via the budget parameter.

    Published: 15 May 2024
    7.4
    High

    CVE-2024-25078

    Last Modified: 29 Jul 2025

    A memory corruption vulnerability in StorageSecurityCommandDxe in Insyde InsydeH2O before kernel 5.2: IB19130163 in 05.29.07, kernel 5.3: IB19130163 in 05.38.07, kernel 5.4: IB19130163 in 05.46.07, kernel 5.5: IB19130163 in 05.54.07, and kernel 5.6: IB19130163 in 05.61.07 could lead to escalating privileges in SMM.

    Published: 15 May 2024
    —
    Unknown

    CVE-2024-4938

    Last Modified: 5 Jul 2025

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

    Published: 15 May 2024
    6.4
    Medium

    CVE-2024-2248

    Last Modified: 15 Apr 2026

    A Header Injection vulnerability in the JFrog platform in versions below 7.85.0 (SaaS) and 7.84.7 (Self-Hosted) may allow threat actors to take over the end user's account when clicking on a specially crafted URL sent to the victim’s user email.

    Published: 15 May 2024