CVE Feed

    Dashboard / CVE

    6.8
    Medium

    CVE-2024-30004

    Last Modified: 3 May 2025

    Windows Mobile Broadband Driver Remote Code Execution Vulnerability

    Published: 14 May 2024
    6.8
    Medium

    CVE-2024-30003

    Last Modified: 3 May 2025

    Windows Mobile Broadband Driver Remote Code Execution Vulnerability

    Published: 14 May 2024
    6.8
    Medium

    CVE-2024-30002

    Last Modified: 3 May 2025

    Windows Mobile Broadband Driver Remote Code Execution Vulnerability

    Published: 14 May 2024
    6.8
    Medium

    CVE-2024-30001

    Last Modified: 3 May 2025

    Windows Mobile Broadband Driver Remote Code Execution Vulnerability

    Published: 14 May 2024
    6.8
    Medium

    CVE-2024-30000

    Last Modified: 3 May 2025

    Windows Mobile Broadband Driver Remote Code Execution Vulnerability

    Published: 14 May 2024
    6.8
    Medium

    CVE-2024-29999

    Last Modified: 3 May 2025

    Windows Mobile Broadband Driver Remote Code Execution Vulnerability

    Published: 14 May 2024
    6.8
    Medium

    CVE-2024-29998

    Last Modified: 3 May 2025

    Windows Mobile Broadband Driver Remote Code Execution Vulnerability

    Published: 14 May 2024
    6.8
    Medium

    CVE-2024-29997

    Last Modified: 3 May 2025

    Windows Mobile Broadband Driver Remote Code Execution Vulnerability

    Published: 14 May 2024
    7.8
    High

    CVE-2024-29996

    Last Modified: 3 May 2025

    Windows Common Log File System Driver Elevation of Privilege Vulnerability

    Published: 14 May 2024
    7.7
    High

    CVE-2024-1630

    Last Modified: 15 Apr 2026

    Path traversal vulnerability in “getAllFolderContents” function of Common Service Desktop, a GE HealthCare ultrasound device component

    Published: 14 May 2024
    6.2
    Medium

    CVE-2024-1629

    Last Modified: 15 Apr 2026

    Path traversal vulnerability in “deleteFiles” function of Common Service Desktop, a GE HealthCare ultrasound device component

    Published: 14 May 2024
    5.4
    Medium

    CVE-2023-24204

    Last Modified: 23 Apr 2025

    SQL injection vulnerability in SourceCodester Simple Customer Relationship Management System v1.0 allows attacker to execute arbitrary code via the name parameter in get-quote.php.

    Published: 14 May 2024
    6.7
    Medium

    CVE-2023-36640

    Last Modified: 12 Jun 2026

    A use of externally-controlled format string vulnerability in Fortinet FortiOS 7.4.0, FortiOS 7.2.0 through 7.2.5, FortiOS 7.0 all versions, FortiOS 6.4 all versions, FortiOS 6.2 all versions, FortiOS 6.0.0 through 6.0.16, FortiPAM 1.1.0, FortiPAM 1.0 all versions, FortiProxy 7.2.0 through 7.2.5, FortiProxy 7.0.0 through 7.0.11, FortiProxy 2.0 all versions, FortiProxy 1.2 all versions, FortiProxy 1.1 all versions, FortiProxy 1.0 all versions allows attacker to execute unauthorized code or commands via specially crafted commands

    Published: 14 May 2024
    6.7
    Medium

    CVE-2023-45583

    Last Modified: 12 Jun 2026

    A use of externally-controlled format string vulnerability in Fortinet FortiOS 7.4.0, FortiOS 7.2.0 through 7.2.5, FortiOS 7.0 all versions, FortiOS 6.4 all versions, FortiOS 6.2 all versions, FortiOS 6.0.0 through 6.0.16, FortiPAM 1.1.0, FortiPAM 1.0 all versions, FortiProxy 7.2.0 through 7.2.5, FortiProxy 7.0.0 through 7.0.11, FortiProxy 2.0 all versions, FortiProxy 1.2 all versions, FortiProxy 1.1 all versions, FortiProxy 1.0 all versions, FortiSwitchManager 7.2.0 through 7.2.2, FortiSwitchManager 7.0.0 through 7.0.2 allows attacker to execute unauthorized code or commands via specially crafted cli commands and http requests.

    Published: 14 May 2024
    7.5
    High

    CVE-2024-23105

    Last Modified: 21 Nov 2024

    A Use Of Less Trusted Source [CWE-348] vulnerability in Fortinet FortiPortal version 7.0.0 through 7.0.6 and version 7.2.0 through 7.2.1 allows an unauthenticated attack to bypass IP protection through crafted HTTP or HTTPS packets.

    Published: 14 May 2024
    5.5
    Medium

    CVE-2023-50180

    Last Modified: 21 Nov 2024

    An exposure of sensitive system information to an unauthorized control sphere vulnerability [CWE-497] in FortiADC version 7.4.1 and below, version 7.2.3 and below, version 7.1.4 and below, version 7.0.5 and below, version 6.2.6 and below may allow a read-only admin to view data pertaining to other admins.

    Published: 14 May 2024
    7.2
    High

    CVE-2023-46714

    Last Modified: 21 Nov 2024

    A stack-based buffer overflow [CWE-121] vulnerability in Fortinet FortiOS version 7.2.1 through 7.2.6 and version 7.4.0 through 7.4.1 allows a privileged attacker over the administrative interface to execute arbitrary code or commands via crafted HTTP or HTTPs requests.

    Published: 14 May 2024
    6.6
    Medium

    CVE-2023-44247

    Last Modified: 14 Jan 2026

    A double free vulnerability [CWE-415] vulnerability in Fortinet FortiOS 6.4 all versions may allow a privileged attacker to execute code or commands via crafted HTTP or HTTPs requests.

    Published: 14 May 2024
    7.1
    High

    CVE-2023-40720

    Last Modified: 21 Nov 2024

    An authorization bypass through user-controlled key vulnerability [CWE-639] in FortiVoiceEntreprise version 7.0.0 through 7.0.1 and before 6.4.8 allows an authenticated attacker to read the SIP configuration of other users via crafted HTTP or HTTPS requests.

    Published: 14 May 2024
    5
    Medium

    CVE-2023-45586

    Last Modified: 21 Nov 2024

    An insufficient verification of data authenticity vulnerability [CWE-345] in Fortinet FortiOS SSL-VPN tunnel mode version 7.4.0 through 7.4.1, version 7.2.0 through 7.2.7 and before 7.0.12 & FortiProxy SSL-VPN tunnel mode version 7.4.0 through 7.4.1, version 7.2.0 through 7.2.7 and before 7.0.13 allows an authenticated VPN user to send (but not receive) packets spoofing the IP of another user via crafted network packets.

    Published: 14 May 2024
    5.3
    Medium

    CVE-2024-26007

    Last Modified: 11 Dec 2024

    An improper check or handling of exceptional conditions vulnerability [CWE-703] in Fortinet FortiOS version 7.4.1 allows an unauthenticated attacker to provoke a denial of service on the administrative interface via crafted HTTP requests.

    Published: 14 May 2024
    6.8
    Medium

    CVE-2024-31488

    Last Modified: 16 Dec 2025

    An improper neutralization of inputs during web page generation vulnerability [CWE-79] in FortiNAC version 9.4.0 through 9.4.4, 9.2.0 through 9.2.8, 9.1.0 through 9.1.10, 8.8.0 through 8.8.11, 8.7.0 through 8.7.6, 7.2.0 through 7.2.3 may allow a remote authenticated attacker to perform stored and reflected cross site scripting (XSS) attack via crafted HTTP requests.

    Published: 14 May 2024
    8.8
    High

    CVE-2024-31491

    Last Modified: 14 Jan 2026

    A client-side enforcement of server-side security vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.4, FortiSandbox 4.2.1 through 4.2.6 allows attacker to execute unauthorized code or commands via HTTP requests.

    Published: 14 May 2024
    5.4
    Medium

    CVE-2023-24203

    Last Modified: 23 Apr 2025

    Cross Site Scripting vulnerability in SourceCodester Simple Customer Relationship Management System v1.0 allows attacker to execute arbitary code via the company or query parameter(s).

    Published: 14 May 2024
    6.1
    Medium

    CVE-2024-26367

    Last Modified: 15 Apr 2026

    Cross Site Scripting vulnerability in Evertz microsystems MViP-II Firmware 8.6.5, XPS-EDGE-* Build 1467, evEDGE-EO-* Build 0029, MMA10G-* Build 0498, 570IPG-X19-10G Build 0691 allows a remote attacker to execute arbitrary code via a crafted payload to the login parameters.

    Published: 14 May 2024
    8.4
    High

    CVE-2024-1628

    Last Modified: 15 Apr 2026

    OS command injection vulnerabilities in GE HealthCare ultrasound devices

    Published: 14 May 2024
    8
    High

    CVE-2024-32355

    Last Modified: 4 Apr 2025

    TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain a command injection vulnerability via the 'password' parameter in the setSSServer function.

    Published: 14 May 2024
    6
    Medium

    CVE-2024-32354

    Last Modified: 4 Apr 2025

    TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain a command injection vulnerability via the 'timeout' parameter in the setSSServer function at /cgi-bin/cstecgi.cgi.

    Published: 14 May 2024
    9.8
    Critical

    CVE-2024-32353

    Last Modified: 4 Apr 2025

    TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain a command injection vulnerability via the 'port' parameter in the setSSServer function at /cgi-bin/cstecgi.cgi.

    Published: 14 May 2024
    8.8
    High

    CVE-2024-32352

    Last Modified: 4 Apr 2025

    TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an authenticated remote command execution (RCE) vulnerability via the "ipsecL2tpEnable" parameter in the "cstecgi.cgi" binary.

    Published: 14 May 2024
    8.8
    High

    CVE-2024-32351

    Last Modified: 4 Apr 2025

    TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an authenticated remote command execution (RCE) vulnerability via the "mru" parameter in the "cstecgi.cgi" binary.

    Published: 14 May 2024
    8.8
    High

    CVE-2024-32350

    Last Modified: 4 Apr 2025

    TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an authenticated remote command execution (RCE) vulnerability via the "ipsecPsk" parameter in the "cstecgi.cgi" binary.

    Published: 14 May 2024
    6
    Medium

    CVE-2024-32349

    Last Modified: 4 Apr 2025

    TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an authenticated remote command execution (RCE) vulnerability via the "mtu" parameters in the "cstecgi.cgi" binary.

    Published: 14 May 2024
    5.3
    Medium

    CVE-2024-34717

    Last Modified: 21 Jan 2025

    PrestaShop is an open source e-commerce web application. In PrestaShop 8.1.5, any invoice can be downloaded from front-office in anonymous mode, by supplying a random secure_key parameter in the url. This issue is patched in version 8.1.6. No known workarounds are available.

    Published: 14 May 2024
    9.6
    Critical

    CVE-2024-34716

    Last Modified: 21 Jan 2025

    PrestaShop is an open source e-commerce web application. A cross-site scripting (XSS) vulnerability that only affects PrestaShops with customer-thread feature flag enabled is present starting from PrestaShop 8.1.0 and prior to PrestaShop 8.1.6. When the customer thread feature flag is enabled through the front-office contact form, a hacker can upload a malicious file containing an XSS that will be executed when an admin opens the attached file in back office. The script injected can access the session and the security token, which allows it to perform any authenticated action in the scope of the administrator's right. This vulnerability is patched in 8.1.6. A workaround is to disable the customer-thread feature-flag.

    Published: 14 May 2024
    6.5
    Medium

    CVE-2024-34191

    Last Modified: 20 Aug 2025

    htmly v2.9.6 was discovered to contain an arbitrary file deletion vulnerability via the delete_post() function at admin.php. This vulnerability allows attackers to delete arbitrary files via a crafted request.

    Published: 14 May 2024
    7.5
    High

    CVE-2024-34950

    Last Modified: 21 May 2025

    D-Link DIR-822+ v1.0.5 was discovered to contain a stack-based buffer overflow vulnerability in the SetNetworkTomographySettings module.

    Published: 14 May 2024
    5.4
    Medium

    CVE-2024-34243

    Last Modified: 13 Jun 2025

    Konga v0.14.9 is vulnerable to Cross Site Scripting (XSS) via the username parameter.

    Published: 14 May 2024
    5.3
    Medium

    CVE-2024-34914

    Last Modified: 15 Apr 2026

    php-censor v2.1.4 and fixed in v.2.1.5 was discovered to utilize a weak hashing algorithm for its remember_key value. This allows attackers to bruteforce to bruteforce the remember_key value to gain access to accounts that have checked "remember me" when logging in.

    Published: 14 May 2024
    7.4
    High

    CVE-2024-1486

    Last Modified: 15 Apr 2026

    Elevation of privileges via misconfigured access control list in GE HealthCare ultrasound devices

    Published: 14 May 2024
    7.5
    High

    CVE-2024-1598

    Last Modified: 25 Sept 2025

    Potential buffer overflow in unsafe UEFI variable handling in Phoenix SecureCore™ for Intel Gemini Lake.This issue affects: SecureCore™ for Intel Gemini Lake: from 4.1.0.1 before 4.1.0.567.

    Published: 14 May 2024
    7.5
    High

    CVE-2024-0762

    Last Modified: 29 Sept 2025

    Potential buffer overflow in unsafe UEFI variable handling in Phoenix SecureCore™ for select Intel platforms This issue affects: Phoenix SecureCore™ for Intel Kaby Lake: from 4.0.1.1 before 4.0.1.998; Phoenix SecureCore™ for Intel Coffee Lake: from 4.1.0.1 before 4.1.0.562; Phoenix SecureCore™ for Intel Ice Lake: from 4.2.0.1 before 4.2.0.323; Phoenix SecureCore™ for Intel Comet Lake: from 4.2.1.1 before 4.2.1.287; Phoenix SecureCore™ for Intel Tiger Lake: from 4.3.0.1 before 4.3.0.236; Phoenix SecureCore™ for Intel Jasper Lake: from 4.3.1.1 before 4.3.1.184; Phoenix SecureCore™ for Intel Alder Lake: from 4.4.0.1 before 4.4.0.269; Phoenix SecureCore™ for Intel Raptor Lake: from 4.5.0.1 before 4.5.0.218; Phoenix SecureCore™ for Intel Meteor Lake: from 4.5.1.1 before 4.5.1.15.

    Published: 14 May 2024
    7.8
    High

    CVE-2023-35841

    Last Modified: 25 Sept 2025

    Exposed IOCTL with Insufficient Access Control in Phoenix WinFlash Driver on Windows allows Privilege Escalation which allows for modification of system firmware.This issue affects WinFlash Driver: before 4.5.0.0.

    Published: 14 May 2024
    7.6
    High

    CVE-2024-34714

    Last Modified: 15 Apr 2026

    The Hoppscotch Browser Extension is a browser extension for Hoppscotch, a community-driven end-to-end open-source API development ecosystem. Due to an oversight during a change made to the extension in the commit d4e8e4830326f46ba17acd1307977ecd32a85b58, a critical check for the origin list was missed and allowed for messages to be sent to the extension which the extension gladly processed and responded back with the results of, while this wasn't supposed to happen and be blocked by the origin not being present in the origin list. This vulnerability exposes Hoppscotch Extension users to sites which call into Hoppscotch Extension APIs internally. This fundamentally allows any site running on the browser with the extension installed to bypass CORS restrictions if the user is running extensions with the given version. This security hole was patched in the commit 7e364b928ab722dc682d0fcad713a96cc38477d6 which was released along with the extension version `0.35`. As a workaround, Chrome users can use the Extensions Settings to disable the extension access to only the origins that you want. Firefox doesn't have an alternative to upgrading to a fixed version.

    Published: 14 May 2024
    9.8
    Critical

    CVE-2024-34256

    Last Modified: 3 Jun 2025

    OFCMS V1.1.2 is vulnerable to SQL Injection via the new table function.

    Published: 14 May 2024
    3.5
    Low

    CVE-2024-34713

    Last Modified: 15 Apr 2026

    sshproxy is used on a gateway to transparently proxy a user SSH connection on the gateway to an internal host via SSH. Prior to version 1.6.3, any user authorized to connect to a ssh server using `sshproxy` can inject options to the `ssh` command executed by `sshproxy`. All versions of `sshproxy` are impacted. The problem is patched starting in version 1.6.3. The only workaround is to use the `force_command` option in `sshproxy.yaml`, but it's rarely relevant.

    Published: 14 May 2024
    6.5
    Medium

    CVE-2024-34712

    Last Modified: 15 Apr 2026

    Oceanic is a NodeJS library for interfacing with Discord. Prior to version 1.10.4, input to functions such as `Client.rest.channels.removeBan` is not url-encoded, resulting in specially crafted input such as `../../../channels/{id}` being normalized into the url `/api/v10/channels/{id}`, and deleting a channel rather than removing a ban. Version 1.10.4 fixes this issue. Some workarounds are available. One may sanitize user input, ensuring strings are valid for the purpose they are being used for. One may also encode input with `encodeURIComponent` before providing it to the library.

    Published: 14 May 2024
    5.3
    Medium

    CVE-2024-34358

    Last Modified: 3 Sept 2025

    TYPO3 is an enterprise content management system. Starting in version 9.0.0 and prior to versions 9.5.48 ELTS, 10.4.45 ELTS, 11.5.37 LTS, 12.4.15 LTS, and 13.1.1, the `ShowImageController` (`_eID tx_cms_showpic_`) lacks a cryptographic HMAC-signature on the `frame` HTTP query parameter (e.g. `/index.php?eID=tx_cms_showpic?file=3&...&frame=12345`). This allows adversaries to instruct the system to produce an arbitrary number of thumbnail images on the server side. TYPO3 versions 9.5.48 ELTS, 10.4.45 ELTS, 11.5.37 LTS, 12.4.15 LTS, 13.1.1 fix the problem described.

    Published: 14 May 2024
    5.4
    Medium

    CVE-2024-34357

    Last Modified: 3 Sept 2025

    TYPO3 is an enterprise content management system. Starting in version 9.0.0 and prior to versions 9.5.48 ELTS, 10.4.45 ELTS, 11.5.37 LTS, 12.4.15 LTS, and 13.1.1, failing to properly encode user-controlled values in file entities, the `ShowImageController` (`_eID tx_cms_showpic_`) is vulnerable to cross-site scripting. Exploiting this vulnerability requires a valid backend user account with access to file entities. TYPO3 versions 9.5.48 ELTS, 10.4.45 ELTS, 11.5.37 LTS, 12.4.15 LTS, 13.1.1 fix the problem described.

    Published: 14 May 2024
    5.4
    Medium

    CVE-2024-34356

    Last Modified: 3 Sept 2025

    TYPO3 is an enterprise content management system. Starting in version 9.0.0 and prior to versions 9.5.48 ELTS, 10.4.45 ELTS, 11.5.37 LTS, 12.4.15 LTS, and 13.1.1, the form manager backend module is vulnerable to cross-site scripting. Exploiting this vulnerability requires a valid backend user account with access to the form module. TYPO3 versions 9.5.48 ELTS, 10.4.45 ELTS, 11.5.37 LTS, 12.4.15 LTS, and 13.1.1 fix the problem described.

    Published: 14 May 2024