CVE Feed

    Dashboard / CVE

    5.3
    Medium

    CVE-2024-33161

    Last Modified: 16 Apr 2025

    J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerability via the sql_filter parameter in the unallocatedList() function.

    Published: 7 May 2024
    6.5
    Medium

    CVE-2024-33780

    Last Modified: 16 Jun 2025

    MP-SPDZ v0.3.8 was discovered to contain a segmentation violation via the function osuCrypto::copyOut at /Tools/SilentPprf.cpp. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted message.

    Published: 7 May 2024
    7.5
    High

    CVE-2024-33781

    Last Modified: 16 Jun 2025

    MP-SPDZ v0.3.8 was discovered to contain a stack overflow via the function octetStream::get_bytes in /Tools/octetStream.cpp. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted message.

    Published: 7 May 2024
    7.5
    High

    CVE-2024-33782

    Last Modified: 16 Jun 2025

    MP-SPDZ v0.3.8 was discovered to contain a stack overflow via the function OTExtensionWithMatrix::extend in /OT/OTExtensionWithMatrix.cpp. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted message.

    Published: 7 May 2024
    6.5
    Medium

    CVE-2024-33783

    Last Modified: 16 Jun 2025

    MP-SPDZ v0.3.8 was discovered to contain a segmentation violation via the function osuCrypto::SilentMultiPprfReceiver::expand in /Tools/SilentPprf.cpp. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted message.

    Published: 7 May 2024
    9.6
    Critical

    CVE-2024-33857

    Last Modified: 18 Apr 2025

    An issue was discovered in Logpoint before 7.4.0. Due to a lack of input validation on URLs in threat intelligence, an attacker with low-level access to the system can trigger Server Side Request Forgery.

    Published: 7 May 2024
    5.3
    Medium

    CVE-2024-33856

    Last Modified: 18 Apr 2025

    An issue was discovered in Logpoint before 7.4.0. An attacker can enumerate a valid list of usernames by observing the response time at the Forgot Password endpoint.

    Published: 7 May 2024
    6.1
    Medium

    CVE-2024-33859

    Last Modified: 18 Apr 2025

    An issue was discovered in Logpoint before 7.4.0. HTML code sent through logs wasn't being escaped in the "Interesting Field" Web UI, leading to XSS.

    Published: 7 May 2024
    6.5
    Medium

    CVE-2024-33860

    Last Modified: 18 Apr 2025

    An issue was discovered in Logpoint before 7.4.0. It allows Local File Inclusion (LFI) when an arbitrary File Path is used within the File System Collector. The content of the file specified can be viewed in the incoming logs.

    Published: 7 May 2024
    7.5
    High

    CVE-2024-34315

    Last Modified: 14 Apr 2025

    CmsEasy v7.7.7.9 was discovered to contain a local file inclusion vunerability via the file_get_contents function in the fckedit_action method of /admin/template_admin.php. This vulnerability allows attackers to read arbitrary files.

    Published: 7 May 2024
    7.5
    High

    CVE-2024-34523

    Last Modified: 15 Apr 2026

    AChecker 1.5 allows remote attackers to read the contents of arbitrary files via the download.php path parameter by using Unauthenticated Path Traversal. This occurs through readfile in PHP. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.

    Published: 7 May 2024
    9.6
    Critical

    CVE-2024-4558

    Last Modified: 4 Nov 2025

    Use after free in ANGLE in Google Chrome prior to 124.0.6367.155 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

    Published: 7 May 2024
    9.8
    Critical

    CVE-2024-33434

    Last Modified: 15 Apr 2026

    An issue in tiagorlampert CHAOS v5.0.1 before 1b451cf62582295b7225caf5a7b506f0bad56f6b and 24c9e109b5be34df7b2bce8368eae669c481ed5e allows a remote attacker to execute arbitrary code via the unsafe concatenation of the `filename` argument into the `buildStr` string without any sanitization or filtering.

    Published: 7 May 2024
    5.2
    Medium

    CVE-2024-34397

    Last Modified: 12 May 2026

    An issue was discovered in GNOME GLib before 2.78.5, and 2.79.x and 2.80.x before 2.80.1. When a GDBus-based client subscribes to signals from a trusted system service such as NetworkManager on a shared computer, other users of the same computer can send spoofed D-Bus signals that the GDBus-based client will wrongly interpret as having been sent by the trusted system service. This could lead to the GDBus-based client behaving incorrectly, with an application-dependent impact.

    Published: 7 May 2024
    4.2
    Medium

    CVE-2023-42757

    Last Modified: 15 Apr 2026

    Process Explorer before 17.04 allows attackers to make it functionally unavailable (a denial of service for analysis) by renaming an executable file to a new extensionless 255-character name and launching it with NtCreateUserProcess. This can occur through an issue in wcscat_s error handling.

    Published: 7 May 2024
    6.5
    Medium

    CVE-2024-2913

    Last Modified: 9 Jul 2025

    A race condition vulnerability exists in the mintplex-labs/anything-llm repository, specifically within the user invite acceptance process. Attackers can exploit this vulnerability by sending multiple concurrent requests to accept a single user invite, allowing the creation of multiple user accounts from a single invite link intended for only one user. This bypasses the intended security mechanism that restricts invite acceptance to a single user, leading to unauthorized user creation without detection in the invite tab. The issue is due to the lack of validation for concurrent requests in the backend.

    Published: 6 May 2024
    —
    Unknown

    CVE-2024-4579

    Last Modified: 14 May 2024

    ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2024-4295. Reason: This candidate is a reservation duplicate of CVE-2024-4295. Notes: All CVE users should reference CVE-2024-4295 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage.

    Published: 6 May 2024
    8
    High

    CVE-2024-29941

    Last Modified: 15 Apr 2026

    Insecure storage of the ICT MIFARE and DESFire encryption keys in the firmware binary allows malicious actors to create credentials for any site code and card number that is using the default ICT encryption.

    Published: 6 May 2024
    5.7
    Medium

    CVE-2024-1695

    Last Modified: 15 Apr 2026

    A potential security vulnerability has been identified in the HP Application Enabling Software Driver for certain HP PC products, which might allow escalation of privilege. HP is releasing software updates to mitigate this potential vulnerability.

    Published: 6 May 2024
    5.9
    Medium

    CVE-2024-34413

    Last Modified: 28 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in SliceWP allows Stored XSS.This issue affects SliceWP: from n/a through 1.1.10.

    Published: 6 May 2024
    —
    Unknown

    CVE-2024-4572

    Last Modified: 14 May 2024

    ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All references and descriptions in this candidate have been removed to prevent accidental usage.

    Published: 6 May 2024
    —
    Unknown

    CVE-2024-4571

    Last Modified: 14 May 2024

    ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All references and descriptions in this candidate have been removed to prevent accidental usage.

    Published: 6 May 2024
    4.3
    Medium

    CVE-2024-33570

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in Roxnor Metform metform.This issue affects Metform: from n/a through <= 3.8.3.

    Published: 6 May 2024
    6.5
    Medium

    CVE-2024-33576

    Last Modified: 28 Apr 2026

    Missing Authorization vulnerability in Ollybach WPPizza.This issue affects WPPizza: from n/a through 3.18.10.

    Published: 6 May 2024
    5.3
    Medium

    CVE-2024-33907

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in Michael Nelson Print My Blog print-my-blog.This issue affects Print My Blog: from n/a through <= 3.26.2.

    Published: 6 May 2024
    5.3
    Medium

    CVE-2024-33908

    Last Modified: 28 Apr 2026

    Missing Authorization vulnerability in Themesgrove WidgetKit.This issue affects WidgetKit: from n/a through 2.5.0.

    Published: 6 May 2024
    5.3
    Medium

    CVE-2024-33910

    Last Modified: 28 Apr 2026

    Missing Authorization vulnerability in Supsystic Digital Publications by Supsystic.This issue affects Digital Publications by Supsystic: from n/a through 1.7.7.

    Published: 6 May 2024
    7.1
    High

    CVE-2024-33912

    Last Modified: 28 Apr 2026

    Missing Authorization vulnerability in Academy LMS.This issue affects Academy LMS: from n/a through 1.9.16.

    Published: 6 May 2024
    4.3
    Medium

    CVE-2024-34371

    Last Modified: 28 Apr 2026

    Missing Authorization vulnerability in Hamid Alinia Login with phone number login-with-phone-number.This issue affects Login with phone number: from n/a through <= 1.7.18.

    Published: 6 May 2024
    5.3
    Medium

    CVE-2024-34372

    Last Modified: 28 Apr 2026

    Missing Authorization vulnerability in AddonMaster Post Grid Master.This issue affects Post Grid Master: from n/a through 3.4.7.

    Published: 6 May 2024
    4.3
    Medium

    CVE-2024-34377

    Last Modified: 28 Apr 2026

    Missing Authorization vulnerability in A WP Life Video Gallery – Api Gallery, YouTube and Vimeo, Link Gallery.This issue affects Video Gallery – Api Gallery, YouTube and Vimeo, Link Gallery: from n/a through 1.5.3.

    Published: 6 May 2024
    8.6
    High

    CVE-2024-34378

    Last Modified: 28 Apr 2026

    Missing Authorization vulnerability in LeadConnector.This issue affects LeadConnector: from n/a through 1.7.

    Published: 6 May 2024
    4.3
    Medium

    CVE-2024-34387

    Last Modified: 28 Apr 2026

    Missing Authorization vulnerability in AF themes WP Post Author.This issue affects WP Post Author: from n/a through 3.6.4.

    Published: 6 May 2024
    4.3
    Medium

    CVE-2024-34389

    Last Modified: 28 Apr 2026

    Missing Authorization vulnerability in AF themes WP Post Author.This issue affects WP Post Author: from n/a through 3.6.4.

    Published: 6 May 2024
    5.9
    Medium

    CVE-2024-34366

    Last Modified: 28 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in AltText.Ai Download Alt Text AI allows Stored XSS.This issue affects Download Alt Text AI: from n/a through 1.3.4.

    Published: 6 May 2024
    7.1
    High

    CVE-2024-34369

    Last Modified: 28 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Webpushr Web Push Notifications Webpushr allows Reflected XSS.This issue affects Webpushr: from n/a through 4.35.0.

    Published: 6 May 2024
    7.6
    High

    CVE-2024-3661

    Last Modified: 15 Jan 2025

    DHCP can add routes to a client’s routing table via the classless static route option (121). VPN-based security solutions that rely on routes to redirect traffic can be forced to leak traffic over the physical interface. An attacker on the same local network can read, disrupt, or possibly modify network traffic that was expected to be protected by the VPN.

    Published: 6 May 2024
    6.5
    Medium

    CVE-2024-34373

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in POSIMYTH The Plus Addons for Elementor Page Builder Lite the-plus-addons-for-elementor-page-builder.This issue affects The Plus Addons for Elementor Page Builder Lite: from n/a through <= 5.4.2.

    Published: 6 May 2024
    6.5
    Medium

    CVE-2024-34374

    Last Modified: 28 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in QuomodoSoft ElementsReady Addons for Elementor allows Stored XSS.This issue affects ElementsReady Addons for Elementor: from n/a through 5.8.0.

    Published: 6 May 2024
    5.9
    Medium

    CVE-2024-34375

    Last Modified: 28 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPPOOL Sheets To WP Table Live Sync allows Stored XSS.This issue affects Sheets To WP Table Live Sync: from n/a through 3.7.0.

    Published: 6 May 2024
    6.5
    Medium

    CVE-2024-34376

    Last Modified: 28 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Theme Freesia Edge allows Stored XSS.This issue affects Edge: from n/a through 2.0.9.

    Published: 6 May 2024
    6.5
    Medium

    CVE-2024-34380

    Last Modified: 28 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in QuantumCloud Conversational Forms for ChatBot allows Stored XSS.This issue affects Conversational Forms for ChatBot: from n/a through 1.2.0.

    Published: 6 May 2024
    6.5
    Medium

    CVE-2024-34381

    Last Modified: 28 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PropertyHive allows Stored XSS.This issue affects PropertyHive: from n/a through 2.0.10.

    Published: 6 May 2024
    6.5
    Medium

    CVE-2024-34390

    Last Modified: 28 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in AddonMaster Post Grid Master allows Stored XSS.This issue affects Post Grid Master: from n/a through 3.4.8.

    Published: 6 May 2024
    4.3
    Medium

    CVE-2024-34379

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Rara Theme Restaurant and Cafe.This issue affects Restaurant and Cafe: from n/a through 1.2.1.

    Published: 6 May 2024
    7.1
    High

    CVE-2024-34367

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Popup Box Team Popup box allows Cross-Site Scripting (XSS).This issue affects Popup box: from n/a through 4.1.2.

    Published: 6 May 2024
    7.6
    High

    CVE-2024-34386

    Last Modified: 28 Apr 2026

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Lucian Apostol Auto Affiliate Links.This issue affects Auto Affiliate Links: from n/a through 6.4.3.1.

    Published: 6 May 2024
    8.5
    High

    CVE-2024-34412

    Last Modified: 28 Apr 2026

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Parcel Panel ParcelPanel.This issue affects ParcelPanel: from n/a through 3.8.1.

    Published: 6 May 2024
    5.3
    Medium

    CVE-2024-34368

    Last Modified: 28 Apr 2026

    Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Mooberry Dreams Mooberry Book Manager.This issue affects Mooberry Book Manager: from n/a through 4.15.12.

    Published: 6 May 2024
    5.3
    Medium

    CVE-2024-34382

    Last Modified: 28 Apr 2026

    Exposure of Sensitive Information to an Unauthorized Actor vulnerability in RoboSoft Robo Gallery.This issue affects Robo Gallery: from n/a through 3.2.18.

    Published: 6 May 2024