CVE Feed

    Dashboard / CVE

    6.1
    Medium

    CVE-2024-2299

    Last Modified: 9 Jul 2025

    A stored Cross-Site Scripting (XSS) vulnerability exists in the parisneo/lollms-webui application due to improper validation of uploaded files in the profile picture upload functionality. Attackers can exploit this vulnerability by uploading malicious HTML files containing JavaScript code, which is executed when the file is accessed. This vulnerability is remotely exploitable via Cross-Site Request Forgery (CSRF), allowing attackers to perform actions on behalf of authenticated users and potentially leading to unauthorized access to sensitive information within the Lollms-webui application.

    Published: 12 May 2024
    5.3
    Medium

    CVE-2024-4799

    Last Modified: 11 Feb 2025

    A vulnerability, which was classified as critical, was found in Kashipara College Management System 1.0. This affects an unknown part of the file view_each_faculty.php. The manipulation of the argument id leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-263919.

    Published: 12 May 2024
    5.3
    Medium

    CVE-2024-4798

    Last Modified: 11 Feb 2025

    A vulnerability, which was classified as critical, has been found in SourceCodester Online Computer and Laptop Store 1.0. Affected by this issue is some unknown functionality of the file /admin/maintenance/manage_brand.php. The manipulation of the argument id leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-263918 is the identifier assigned to this vulnerability.

    Published: 12 May 2024
    5.3
    Medium

    CVE-2024-4797

    Last Modified: 20 Feb 2025

    A vulnerability was found in Campcodes Online Laundry Management System 1.0. It has been declared as problematic. This vulnerability affects unknown code of the file /ajax.php. The manipulation of the argument name/customer_name/username leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-263896.

    Published: 12 May 2024
    5.3
    Medium

    CVE-2024-4796

    Last Modified: 20 Feb 2025

    A vulnerability was found in Campcodes Online Laundry Management System 1.0. It has been classified as critical. This affects an unknown part of the file /manage_inv.php. The manipulation of the argument id leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-263895.

    Published: 12 May 2024
    5.3
    Medium

    CVE-2024-4795

    Last Modified: 20 Feb 2025

    A vulnerability was found in Campcodes Online Laundry Management System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /manage_user.php. The manipulation of the argument id leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-263894 is the identifier assigned to this vulnerability.

    Published: 12 May 2024
    5.3
    Medium

    CVE-2024-4794

    Last Modified: 20 Feb 2025

    A vulnerability has been found in Campcodes Online Laundry Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /manage_receiving.php. The manipulation of the argument id leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-263893 was assigned to this vulnerability.

    Published: 12 May 2024
    5.3
    Medium

    CVE-2024-4793

    Last Modified: 20 Feb 2025

    A vulnerability, which was classified as critical, was found in Campcodes Online Laundry Management System 1.0. Affected is an unknown function of the file /manage_laundry.php. The manipulation of the argument id leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-263892.

    Published: 12 May 2024
    5.3
    Medium

    CVE-2024-4792

    Last Modified: 20 Feb 2025

    A vulnerability, which was classified as critical, has been found in Campcodes Online Laundry Management System 1.0. This issue affects some unknown processing of the file /admin_class.php. The manipulation of the argument id/delete_category/delete_inv/delete_laundry/delete_supply/delete_user/login/save_inv/save_user leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-263891.

    Published: 12 May 2024
    8.7
    High

    CVE-2024-4791

    Last Modified: 15 Apr 2026

    A vulnerability classified as critical was found in Contemporary Control System BASrouter BACnet BASRT-B 2.7.2. This vulnerability affects unknown code of the component Application Protocol Data Unit. The manipulation leads to denial of service. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-263890 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 12 May 2024
    5.3
    Medium

    CVE-2024-4790

    Last Modified: 4 Apr 2025

    A vulnerability classified as problematic has been found in DedeCMS 5.7.114. This affects an unknown part of the file /sys_verifies.php?action=view. The manipulation of the argument filename with the input ../../../../../etc/passwd leads to path traversal: '../filedir'. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-263889 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 11 May 2024
    2.7
    Low

    CVE-2023-47711

    Last Modified: 14 Jan 2025

    IBM Security Guardium 11.3, 11.4, 11.5, and 12.0 could allow an authenticated user to upload files that would cause a denial of service. IBM X-Force ID: 271526.

    Published: 11 May 2024
    7.8
    High

    CVE-2023-47712

    Last Modified: 14 Jan 2025

    IBM Security Guardium 11.3, 11.4, 11.5, and 12.0 could allow a local user to gain elevated privileges on the system due to improper permissions control. IBM X-Force ID: 271527.

    Published: 11 May 2024
    9.1
    Critical

    CVE-2023-47709

    Last Modified: 14 Jan 2025

    IBM Security Guardium 11.3, 11.4, 11.5, and 12.0 could allow a remote authenticated attacker to execute arbitrary commands on the system by sending a specially crafted request. IBM X-Force ID: 271524.

    Published: 11 May 2024
    4.3
    Medium

    CVE-2024-28760

    Last Modified: 7 Jan 2025

    IBM App Connect Enterprise 11.0.0.1 through 11.0.0.25 and 12.0.1.0 through 12.0.12.0 dashboard is vulnerable to a denial of service due to improper restrictions of resource allocation. IBM X-Force ID: 285244.

    Published: 11 May 2024
    5.4
    Medium

    CVE-2024-28761

    Last Modified: 13 Mar 2025

    IBM App Connect Enterprise 11.0.0.1 through 11.0.0.25 and 12.0.1.0 through 12.0.12.0 is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the victim's Web browser within the security context of the hosting site. IBM X-Force ID: 285245.

    Published: 11 May 2024
    6.2
    Medium

    CVE-2023-52721

    Last Modified: 9 Dec 2024

    The WindowManager module has a vulnerability in permission control. Impact: Successful exploitation of this vulnerability may affect confidentiality.

    Published: 11 May 2024
    6.4
    Medium

    CVE-2024-4046

    Last Modified: 9 Dec 2024

    Cracking vulnerability in the OS security module Impact: Successful exploitation of this vulnerability will affect availability.

    Published: 11 May 2024
    6.8
    Medium

    CVE-2024-32999

    Last Modified: 9 Dec 2024

    Cracking vulnerability in the OS security module Impact: Successful exploitation of this vulnerability will affect availability.

    Published: 11 May 2024
    5.9
    Medium

    CVE-2024-32998

    Last Modified: 9 Dec 2024

    NULL pointer access vulnerability in the clock module Impact: Successful exploitation of this vulnerability will affect availability.

    Published: 11 May 2024
    4.1
    Medium

    CVE-2023-52720

    Last Modified: 9 Dec 2024

    Race condition vulnerability in the soundtrigger module Impact: Successful exploitation of this vulnerability will affect availability.

    Published: 11 May 2024
    8.4
    High

    CVE-2024-32997

    Last Modified: 9 Dec 2024

    Race condition vulnerability in the binder driver module Impact: Successful exploitation of this vulnerability will affect availability.

    Published: 11 May 2024
    6.2
    Medium

    CVE-2024-32996

    Last Modified: 9 Dec 2024

    Privilege escalation vulnerability in the account module Impact: Successful exploitation of this vulnerability will affect availability.

    Published: 11 May 2024
    6.2
    Medium

    CVE-2024-32995

    Last Modified: 11 Dec 2024

    Denial of service (DoS) vulnerability in the AMS module Impact: Successful exploitation of this vulnerability will affect availability.

    Published: 11 May 2024
    7.1
    High

    CVE-2023-52719

    Last Modified: 9 Dec 2024

    Privilege escalation vulnerability in the PMS module Impact: Successful exploitation of this vulnerability may affect service confidentiality.

    Published: 11 May 2024
    5.6
    Medium

    CVE-2024-32993

    Last Modified: 11 Dec 2024

    Out-of-bounds access vulnerability in the memory module Impact: Successful exploitation of this vulnerability will affect availability.

    Published: 11 May 2024
    4.7
    Medium

    CVE-2023-52384

    Last Modified: 9 Dec 2024

    Double-free vulnerability in the RSMC module Impact: Successful exploitation of this vulnerability will affect availability.

    Published: 11 May 2024
    4.7
    Medium

    CVE-2023-52383

    Last Modified: 9 Dec 2024

    Double-free vulnerability in the RSMC module Impact: Successful exploitation of this vulnerability will affect availability.

    Published: 11 May 2024
    7.5
    High

    CVE-2024-32992

    Last Modified: 11 Dec 2024

    Insufficient verification vulnerability in the baseband module Impact: Successful exploitation of this vulnerability will affect availability.

    Published: 11 May 2024
    7.5
    High

    CVE-2024-32991

    Last Modified: 11 Dec 2024

    Permission verification vulnerability in the wpa_supplicant module Impact: Successful exploitation of this vulnerability will affect availability.

    Published: 11 May 2024
    6.1
    Medium

    CVE-2024-32990

    Last Modified: 11 Dec 2024

    Permission verification vulnerability in the system sharing pop-up module Impact: Successful exploitation of this vulnerability will affect availability.

    Published: 11 May 2024
    3.3
    Low

    CVE-2024-32989

    Last Modified: 11 Dec 2024

    Insufficient verification vulnerability in the system sharing pop-up module Impact: Successful exploitation of this vulnerability will affect availability.

    Published: 11 May 2024
    6.4
    Medium

    CVE-2024-4487

    Last Modified: 8 Apr 2026

    The Blocksy Companion plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG uploads in versions up to, and including, 2.0.45 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 11 May 2024
    6.4
    Medium

    CVE-2024-4329

    Last Modified: 15 Apr 2026

    The Thim Elementor Kit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘id’ parameter in all versions up to, and including, 1.1.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 11 May 2024
    9.8
    Critical

    CVE-2024-4560

    Last Modified: 15 Apr 2026

    The Kognetiks Chatbot for WordPress plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the chatbot_chatgpt_upload_file_to_assistant function in all versions up to, and including, 1.9.9. This makes it possible for unauthenticated attackers, with to upload arbitrary files on the affected site's server which may make remote code execution possible.

    Published: 11 May 2024
    6.4
    Medium

    CVE-2024-4630

    Last Modified: 15 Apr 2026

    The Starter Templates — Elementor, WordPress & Beaver Builder Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘custom_upload_mimes’ function in versions up to, and including, 4.2.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 11 May 2024
    5.5
    Medium

    CVE-2023-5447

    Last Modified: 15 Apr 2026

    Missing lock check in SynHsaService may create a use-after-free condition which causes abnormal termination of the service, resulting in denial of service for the Synaptics Hardware Support App.

    Published: 11 May 2024
    6.4
    Medium

    CVE-2024-4209

    Last Modified: 8 Apr 2026

    The Gutenberg Blocks with AI by Kadence WP – Page Builder Features plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the countdown timer in all versions up to, and including, 3.2.36 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 11 May 2024
    6.4
    Medium

    CVE-2024-4574

    Last Modified: 15 Apr 2026

    The Graphina – Elementor Charts and Graphs plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple widgets in all versions up to, and including, 1.8.9 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 10 May 2024
    8.8
    High

    CVE-2024-3055

    Last Modified: 8 Apr 2026

    The Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin for WordPress is vulnerable to time-based SQL Injection via the ‘id’ parameter in all versions up to, and including, 1.5.102 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with contributor access or higher, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

    Published: 10 May 2024
    6.4
    Medium

    CVE-2024-4430

    Last Modified: 8 Apr 2026

    The Beaver Builder – WordPress Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the photo widget crop attribute in all versions up to, and including, 2.8.1.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor access or higher, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 10 May 2024
    4.4
    Medium

    CVE-2024-4417

    Last Modified: 15 Apr 2026

    The Falang multilanguage for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.3.49 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.

    Published: 10 May 2024
    5.3
    Medium

    CVE-2024-4213

    Last Modified: 15 Apr 2026

    The Shopping Cart & eCommerce Store plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 5.6.4 via the order report functionality. This makes it possible for unauthenticated attackers to extract sensitive data including order details such as payment details, addresses and other PII.

    Published: 10 May 2024
    9.8
    Critical

    CVE-2024-4413

    Last Modified: 15 Apr 2026

    The Hotel Booking Lite plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 4.11.1 via deserialization of untrusted input. This makes it possible for unauthenticated attackers to inject a PHP Object. No known POP chain is present in the vulnerable plugin. If a POP chain is present via an additional plugin or theme installed on the target system, it could allow the attacker to delete arbitrary files, retrieve sensitive data, or execute code.

    Published: 10 May 2024
    5.3
    Medium

    CVE-2024-4738

    Last Modified: 19 Feb 2025

    A vulnerability was found in Campcodes Legal Case Management System 1.0. It has been declared as problematic. This vulnerability affects unknown code. The manipulation of the argument new_client leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-263824.

    Published: 10 May 2024
    5.3
    Medium

    CVE-2024-4737

    Last Modified: 19 Feb 2025

    A vulnerability was found in Campcodes Legal Case Management System 1.0. It has been classified as problematic. This affects an unknown part of the file /admin/vendor. The manipulation of the argument company_name/mobile leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-263823.

    Published: 10 May 2024
    5.3
    Medium

    CVE-2024-4736

    Last Modified: 19 Feb 2025

    A vulnerability was found in Campcodes Legal Case Management System 1.0 and classified as problematic. Affected by this issue is some unknown functionality of the file /admin/tax. The manipulation of the argument name leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-263822 is the identifier assigned to this vulnerability.

    Published: 10 May 2024
    6.7
    Medium

    CVE-2024-27460

    Last Modified: 21 Jan 2026

    A privilege escalation exists in the updater for Plantronics Hub 3.25.1 and below.

    Published: 10 May 2024
    5.3
    Medium

    CVE-2024-4735

    Last Modified: 19 Feb 2025

    A vulnerability has been found in Campcodes Legal Case Management System 1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /admin/tasks. The manipulation of the argument task_subject leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-263821 was assigned to this vulnerability.

    Published: 10 May 2024
    5.3
    Medium

    CVE-2024-4732

    Last Modified: 19 Feb 2025

    A vulnerability, which was classified as problematic, has been found in Campcodes Legal Case Management System 1.0. Affected by this issue is some unknown functionality of the file /admin/service. The manipulation of the argument name leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-263810 is the identifier assigned to this vulnerability.

    Published: 10 May 2024