CVE Feed

    Dashboard / CVE

    7.8
    High

    CVE-2024-20064

    Last Modified: 29 Mar 2025

    In wlan service, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08572601; Issue ID: MSV-1229.

    Published: 6 May 2024
    5.9
    Medium

    CVE-2024-20060

    Last Modified: 30 Apr 2025

    In da, there is a possible escalation of privilege due to an incorrect status check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08541749; Issue ID: ALPS08541754.

    Published: 6 May 2024
    6.7
    Medium

    CVE-2024-20059

    Last Modified: 30 Apr 2025

    In da, there is a possible escalation of privilege due to an incorrect status check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08541749; Issue ID: ALPS08541749.

    Published: 6 May 2024
    4.4
    Medium

    CVE-2024-20058

    Last Modified: 30 Apr 2025

    In keyInstall, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08580204; Issue ID: ALPS08580204.

    Published: 6 May 2024
    5.3
    Medium

    CVE-2023-32871

    Last Modified: 5 May 2025

    In DA, there is a possible permission bypass due to an incorrect status check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08355514; Issue ID: ALPS08355514.

    Published: 6 May 2024
    6.7
    Medium

    CVE-2023-32873

    Last Modified: 13 Mar 2025

    In keyInstall, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08583919; Issue ID: ALPS08304227.

    Published: 6 May 2024
    7.2
    High

    CVE-2024-20057

    Last Modified: 30 Apr 2025

    In keyInstall, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08587881; Issue ID: ALPS08587881.

    Published: 6 May 2024
    6.7
    Medium

    CVE-2024-20056

    Last Modified: 30 Apr 2025

    In preloader, there is a possible escalation of privilege due to an insecure default value. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08528185; Issue ID: ALPS08528185.

    Published: 6 May 2024
    3.5
    Low

    CVE-2024-4516

    Last Modified: 19 Feb 2025

    A vulnerability was found in Campcodes Complete Web-Based School Management System 1.0 and classified as problematic. Affected by this issue is some unknown functionality of the file /view/timetable.php. The manipulation of the argument grade leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-263120.

    Published: 6 May 2024
    3.5
    Low

    CVE-2024-4515

    Last Modified: 19 Feb 2025

    A vulnerability has been found in Campcodes Complete Web-Based School Management System 1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /view/timetable_grade_wise.php. The manipulation of the argument grade leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-263119.

    Published: 6 May 2024
    3.5
    Low

    CVE-2024-4514

    Last Modified: 19 Feb 2025

    A vulnerability, which was classified as problematic, was found in Campcodes Complete Web-Based School Management System 1.0. Affected is an unknown function of the file /view/timetable_insert_form.php. The manipulation of the argument grade leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-263118 is the identifier assigned to this vulnerability.

    Published: 6 May 2024
    5.9
    Medium

    CVE-2024-0904

    Last Modified: 8 May 2025

    The Fancy Product Designer WordPress plugin before 6.1.81 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

    Published: 6 May 2024
    3.5
    Low

    CVE-2024-4513

    Last Modified: 19 Feb 2025

    A vulnerability, which was classified as problematic, has been found in Campcodes Complete Web-Based School Management System 1.0. This issue affects some unknown processing of the file /view/timetable_update_form.php. The manipulation of the argument grade leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-263117 was assigned to this vulnerability.

    Published: 6 May 2024
    3.5
    Low

    CVE-2024-4512

    Last Modified: 10 Feb 2025

    A vulnerability classified as problematic was found in SourceCodester Prison Management System 1.0. This vulnerability affects unknown code of the file /Employee/edit-profile.php. The manipulation of the argument txtfullname/txtdob/txtaddress/txtqualification/cmddept/cmdemployeetype/txtappointment leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-263116.

    Published: 6 May 2024
    6.3
    Medium

    CVE-2024-4511

    Last Modified: 15 Apr 2026

    A vulnerability classified as critical has been found in Shanghai Sunfull Automation BACnet Server HMI1002-ARM 2.0.4. This affects an unknown part of the component Message Handler. The manipulation leads to buffer overflow. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-263115. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 6 May 2024
    4.7
    Medium

    CVE-2024-4510

    Last Modified: 21 Aug 2025

    A vulnerability was found in Ruijie RG-UAC up to 20240428. It has been rated as critical. Affected by this issue is some unknown functionality of the file /view/networkConfig/ArpTable/arp_add_commit.php. The manipulation of the argument text_ip_addr/text_mac_addr leads to os command injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-263114 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 6 May 2024
    4.7
    Medium

    CVE-2024-4509

    Last Modified: 21 Aug 2025

    A vulnerability was found in Ruijie RG-UAC up to 20240428. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /view/IPV6/naborTable/add_commit.php. The manipulation of the argument ip_addr/mac_addr leads to os command injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-263113 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 6 May 2024
    4.7
    Medium

    CVE-2024-4508

    Last Modified: 21 Aug 2025

    A vulnerability was found in Ruijie RG-UAC up to 20240428. It has been classified as critical. Affected is an unknown function of the file /view/IPV6/ipv6StaticRoute/static_route_edit_ipv6.php. The manipulation of the argument oldipmask/oldgateway/olddevname leads to os command injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-263112. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 6 May 2024
    5.5
    Medium

    CVE-2024-4840

    Last Modified: 15 Apr 2026

    An flaw was found in the OpenStack Platform (RHOSP) director, a toolset for installing and managing a complete RHOSP environment. Plaintext passwords may be stored in log files, which can expose sensitive information to anyone with access to the logs.

    Published: 6 May 2024
    7.5
    High

    CVE-2024-4438

    Last Modified: 15 Apr 2026

    The etcd package distributed with the Red Hat OpenStack platform has an incomplete fix for CVE-2023-39325/CVE-2023-44487, known as Rapid Reset. This issue occurs because the etcd package in the Red Hat OpenStack platform is using http://golang.org/x/net/http2 instead of the one provided by Red Hat Enterprise Linux versions, meaning it should be updated at compile time instead.

    Published: 6 May 2024
    7.5
    High

    CVE-2024-4437

    Last Modified: 15 Apr 2026

    The etcd package distributed with the Red Hat OpenStack platform has an incomplete fix for CVE-2021-44716. This issue occurs because the etcd package in the Red Hat OpenStack platform is using http://golang.org/x/net/http2 instead of the one provided by Red Hat Enterprise Linux versions, meaning it should be updated at compile time instead.

    Published: 6 May 2024
    7.5
    High

    CVE-2024-34538

    Last Modified: 15 Apr 2026

    Mateso PasswordSafe through 8.13.9.26689 has Weak Cryptography.

    Published: 6 May 2024
    7.3
    High

    CVE-2024-34533

    Last Modified: 15 Apr 2026

    A SQL injection vulnerability in ZI PT Solusi Usaha Mudah Analytic Data Query module (aka izi_data) 11.0 through 17.x before 17.0.3 allows a remote attacker to gain privileges via a query to IZITools::query_check, IZITools::query_fetch, or IZITools::query_execute.

    Published: 6 May 2024
    8.8
    High

    CVE-2024-30973

    Last Modified: 15 Apr 2026

    An issue in V-SOL G/EPON ONU HG323AC-B with firmware version V2.0.08-210715 allows an attacker to execute arbtirary code and obtain sensitive information via crafted POST request to /boaform/getASPdata/formFirewall, /boaform/getASPdata/formAcc.

    Published: 6 May 2024
    6.8
    Medium

    CVE-2023-33548

    Last Modified: 15 Apr 2026

    Cross Site Scripting (XSS) vulnerability in ASUS RT-AC51U with firmware versions up to and including 3.0.0.4.380.8591 allows attackers to run arbitrary code via the WPA Pre-Shared Key field.

    Published: 6 May 2024
    5.4
    Medium

    CVE-2024-33111

    Last Modified: 21 May 2025

    D-Link DIR-845L router <=v1.01KRb03 is vulnerable to Cross Site Scripting (XSS) via /htdocs/webinc/js/bsc_sms_inbox.php.

    Published: 6 May 2024
    5.3
    Medium

    CVE-2024-33113

    Last Modified: 21 May 2025

    D-LINK DIR-845L <=v1.01KRb03 is vulnerable to Information disclosurey via bsc_sms_inbox.php.

    Published: 6 May 2024
    5.3
    Medium

    CVE-2024-33117

    Last Modified: 11 Jun 2025

    crmeb_java v1.3.4 was discovered to contain a Server-Side Request Forgery (SSRF) via the mergeList method in class com.zbkj.front.pub.ImageMergeController.

    Published: 6 May 2024
    7.5
    High

    CVE-2024-33118

    Last Modified: 10 Jun 2025

    LuckyFrameWeb v3.5.2 was discovered to contain an arbitrary read vulnerability via the fileDownload method in class com.luckyframe.project.common.CommonController.

    Published: 6 May 2024
    6.3
    Medium

    CVE-2024-33121

    Last Modified: 17 Jun 2025

    Roothub v2.6 was discovered to contain a SQL injection vulnerability via the 's' parameter in the search() function.

    Published: 6 May 2024
    5.9
    Medium

    CVE-2024-33407

    Last Modified: 25 Mar 2025

    SQL injection vulnerability in /model/delete_record.php in campcodes Complete Web-Based School Management System 1.0 allows attacker to execute arbitrary SQL commands via the id parameter.

    Published: 6 May 2024
    6.3
    Medium

    CVE-2024-33752

    Last Modified: 11 Jun 2025

    An arbitrary file upload vulnerability exists in emlog pro 2.3.0 and pro 2.3.2 at admin/views/plugin.php that could be exploited by a remote attacker to submit a special request to upload a malicious file to execute arbitrary code.

    Published: 6 May 2024
    7.3
    High

    CVE-2024-34089

    Last Modified: 28 Mar 2025

    An issue was discovered in Archer Platform 6 before 2024.04. There is a stored cross-site scripting (XSS) vulnerability. A remote authenticated malicious Archer user could potentially exploit this vulnerability to store malicious HTML or JavaScript code in a trusted application data store. When victim users access the data store through their browsers, the malicious code gets executed by the web browser in the context of the vulnerable application. 6.14 P3 (6.14.0.3) is also a fixed release.

    Published: 6 May 2024
    6.2
    Medium

    CVE-2024-34250

    Last Modified: 13 Jun 2025

    A heap buffer overflow vulnerability was discovered in Bytecode Alliance wasm-micro-runtime v2.0.0 which allows a remote attacker to cause at least a denial of service via the "wasm_loader_check_br" function in core/iwasm/interpreter/wasm_loader.c.

    Published: 6 May 2024
    7.5
    High

    CVE-2024-34251

    Last Modified: 13 Jun 2025

    An out-of-bound memory read vulnerability was discovered in Bytecode Alliance wasm-micro-runtime v2.0.0 which allows a remote attacker to cause a denial of service via the "block_type_get_arity" function in core/iwasm/interpreter/wasm.h.

    Published: 6 May 2024
    8.6
    High

    CVE-2024-34470

    Last Modified: 17 Jun 2025

    An issue was discovered in HSC Mailinspector 5.2.17-3 through v.5.2.18. An Unauthenticated Path Traversal vulnerability exists in the /public/loader.php file. The path parameter does not properly filter whether the file and directory passed are part of the webroot, allowing an attacker to read arbitrary files on the server.

    Published: 6 May 2024
    4.3
    Medium

    CVE-2024-26312

    Last Modified: 18 Mar 2025

    Archer Platform 6 before 2024.03 contains a sensitive information disclosure vulnerability. An authenticated attacker could potentially obtain access to sensitive information via a popup warning message.

    Published: 6 May 2024
    7.1
    High

    CVE-2024-28725

    Last Modified: 10 Jun 2025

    Cross Site Scripting (XSS) vulnerability in YzmCMS 7.0 allows attackers to run arbitrary code via Ads Management, Carousel Management, and System Settings.

    Published: 6 May 2024
    9.1
    Critical

    CVE-2024-33110

    Last Modified: 21 May 2025

    D-Link DIR-845L router v1.01KRb03 and before is vulnerable to Permission Bypass via the getcfg.php component.

    Published: 6 May 2024
    5.4
    Medium

    CVE-2024-34064

    Last Modified: 3 Nov 2025

    Jinja is an extensible templating engine. The `xmlattr` filter in affected versions of Jinja accepts keys containing non-attribute characters. XML/HTML attributes cannot contain spaces, `/`, `>`, or `=`, as each would then be interpreted as starting a separate attribute. If an application accepts keys (as opposed to only values) as user input, and renders these in pages that other users see as well, an attacker could use this to inject other attributes and perform XSS. The fix for CVE-2024-22195 only addressed spaces but not other characters. Accepting keys as user input is now explicitly considered an unintended use case of the `xmlattr` filter, and code that does so without otherwise validating the input should be flagged as insecure, regardless of Jinja version. Accepting _values_ as user input continues to be safe. This vulnerability is fixed in 3.1.4.

    Published: 6 May 2024
    7.5
    High

    CVE-2024-33112

    Last Modified: 21 May 2025

    D-Link DIR-845L router v1.01KRb03 and before is vulnerable to Command injection via the hnap_main()func.

    Published: 6 May 2024
    9.1
    Critical

    CVE-2024-33294

    Last Modified: 15 Apr 2026

    An issue in Library System using PHP/MySQli with Source Code V1.0 allows a remote attacker to execute arbitrary code via the _FAILE variable in the student_edit_photo.php component.

    Published: 6 May 2024
    9.8
    Critical

    CVE-2024-33403

    Last Modified: 25 Mar 2025

    A SQL injection vulnerability in /model/get_events.php in campcodes Complete Web-Based School Management System 1.0 allows attacker to execute arbitrary SQL commands via the event_id parameter.

    Published: 6 May 2024
    8.3
    High

    CVE-2024-33404

    Last Modified: 25 Mar 2025

    A SQL injection vulnerability in /model/add_student_first_payment.php in campcodes Complete Web-Based School Management System 1.0 allows attacker to execute arbitrary SQL commands via the index parameter.

    Published: 6 May 2024
    8.6
    High

    CVE-2024-33405

    Last Modified: 25 Mar 2025

    SQL injection vulnerability in add_friends.php in campcodes Complete Web-Based School Management System 1.0 allows attacker to execute arbitrary SQL commands via the friend_index parameter.

    Published: 6 May 2024
    7.3
    High

    CVE-2024-33406

    Last Modified: 25 Mar 2025

    SQL injection vulnerability in /model/delete_student_grade_subject.php in campcodes Complete Web-Based School Management System 1.0 allows attacker to execute arbitrary SQL commands via the index parameter.

    Published: 6 May 2024
    9.8
    Critical

    CVE-2024-33408

    Last Modified: 25 Mar 2025

    A SQL injection vulnerability in /model/get_classroom.php in campcodes Complete Web-Based School Management System 1.0 allows attacker to execute arbitrary SQL commands via the id parameter.

    Published: 6 May 2024
    9.8
    Critical

    CVE-2024-33409

    Last Modified: 25 Mar 2025

    SQL injection vulnerability in index.php in campcodes Complete Web-Based School Management System 1.0 allows attacker to execute arbitrary SQL commands via the name parameter.

    Published: 6 May 2024
    8.1
    High

    CVE-2024-33410

    Last Modified: 25 Mar 2025

    SQL injection vulnerability in /model/delete_range_grade.php in campcodes Complete Web-Based School Management System 1.0 allows attacker to execute arbitrary SQL commands via the id parameter.

    Published: 6 May 2024
    9.8
    Critical

    CVE-2024-33411

    Last Modified: 25 Mar 2025

    A SQL injection vulnerability in /model/get_admin_profile.php in Campcodes Complete Web-Based School Management System 1.0 allows attacker to execute arbitrary SQL commands via the my_index parameter.

    Published: 6 May 2024