CVE Feed

    Dashboard / CVE

    7.1
    High

    CVE-2024-28725

    Last Modified: 10 Jun 2025

    Cross Site Scripting (XSS) vulnerability in YzmCMS 7.0 allows attackers to run arbitrary code via Ads Management, Carousel Management, and System Settings.

    Published: 6 May 2024
    9.1
    Critical

    CVE-2024-33110

    Last Modified: 21 May 2025

    D-Link DIR-845L router v1.01KRb03 and before is vulnerable to Permission Bypass via the getcfg.php component.

    Published: 6 May 2024
    5.4
    Medium

    CVE-2024-34064

    Last Modified: 3 Nov 2025

    Jinja is an extensible templating engine. The `xmlattr` filter in affected versions of Jinja accepts keys containing non-attribute characters. XML/HTML attributes cannot contain spaces, `/`, `>`, or `=`, as each would then be interpreted as starting a separate attribute. If an application accepts keys (as opposed to only values) as user input, and renders these in pages that other users see as well, an attacker could use this to inject other attributes and perform XSS. The fix for CVE-2024-22195 only addressed spaces but not other characters. Accepting keys as user input is now explicitly considered an unintended use case of the `xmlattr` filter, and code that does so without otherwise validating the input should be flagged as insecure, regardless of Jinja version. Accepting _values_ as user input continues to be safe. This vulnerability is fixed in 3.1.4.

    Published: 6 May 2024
    7.5
    High

    CVE-2024-33112

    Last Modified: 21 May 2025

    D-Link DIR-845L router v1.01KRb03 and before is vulnerable to Command injection via the hnap_main()func.

    Published: 6 May 2024
    9.1
    Critical

    CVE-2024-33294

    Last Modified: 15 Apr 2026

    An issue in Library System using PHP/MySQli with Source Code V1.0 allows a remote attacker to execute arbitrary code via the _FAILE variable in the student_edit_photo.php component.

    Published: 6 May 2024
    9.8
    Critical

    CVE-2024-33403

    Last Modified: 25 Mar 2025

    A SQL injection vulnerability in /model/get_events.php in campcodes Complete Web-Based School Management System 1.0 allows attacker to execute arbitrary SQL commands via the event_id parameter.

    Published: 6 May 2024
    8.3
    High

    CVE-2024-33404

    Last Modified: 25 Mar 2025

    A SQL injection vulnerability in /model/add_student_first_payment.php in campcodes Complete Web-Based School Management System 1.0 allows attacker to execute arbitrary SQL commands via the index parameter.

    Published: 6 May 2024
    8.6
    High

    CVE-2024-33405

    Last Modified: 25 Mar 2025

    SQL injection vulnerability in add_friends.php in campcodes Complete Web-Based School Management System 1.0 allows attacker to execute arbitrary SQL commands via the friend_index parameter.

    Published: 6 May 2024
    7.3
    High

    CVE-2024-33406

    Last Modified: 25 Mar 2025

    SQL injection vulnerability in /model/delete_student_grade_subject.php in campcodes Complete Web-Based School Management System 1.0 allows attacker to execute arbitrary SQL commands via the index parameter.

    Published: 6 May 2024
    9.8
    Critical

    CVE-2024-33408

    Last Modified: 25 Mar 2025

    A SQL injection vulnerability in /model/get_classroom.php in campcodes Complete Web-Based School Management System 1.0 allows attacker to execute arbitrary SQL commands via the id parameter.

    Published: 6 May 2024
    9.8
    Critical

    CVE-2024-33409

    Last Modified: 25 Mar 2025

    SQL injection vulnerability in index.php in campcodes Complete Web-Based School Management System 1.0 allows attacker to execute arbitrary SQL commands via the name parameter.

    Published: 6 May 2024
    8.1
    High

    CVE-2024-33410

    Last Modified: 25 Mar 2025

    SQL injection vulnerability in /model/delete_range_grade.php in campcodes Complete Web-Based School Management System 1.0 allows attacker to execute arbitrary SQL commands via the id parameter.

    Published: 6 May 2024
    9.8
    Critical

    CVE-2024-33411

    Last Modified: 25 Mar 2025

    A SQL injection vulnerability in /model/get_admin_profile.php in Campcodes Complete Web-Based School Management System 1.0 allows attacker to execute arbitrary SQL commands via the my_index parameter.

    Published: 6 May 2024
    8.2
    High

    CVE-2024-33753

    Last Modified: 15 Apr 2026

    Section Camera V2.5.5.3116-S50-SMA-B20160811 and earlier versions allow the accounts and passwords of administrators and users to be changed without authorization.

    Published: 6 May 2024
    9.1
    Critical

    CVE-2024-33749

    Last Modified: 1 Apr 2025

    DedeCMS V5.7.114 is vulnerable to deletion of any file via mail_file_manage.php.

    Published: 6 May 2024
    8
    High

    CVE-2024-33788

    Last Modified: 11 Jun 2025

    Linksys E5600 v1.1.0.26 was discovered to contain a command injection vulnerability via the PinCode parameter at /API/info form endpoint.

    Published: 6 May 2024
    5.4
    Medium

    CVE-2024-33829

    Last Modified: 15 Apr 2025

    idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/readDeal.php?mudi=updateWebCache.

    Published: 6 May 2024
    8.1
    High

    CVE-2024-33830

    Last Modified: 15 Apr 2025

    idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/readDeal.php?mudi=clearWebCache.

    Published: 6 May 2024
    7.3
    High

    CVE-2024-34090

    Last Modified: 18 Mar 2025

    An issue was discovered in Archer Platform 6 before 2024.04. There is a stored cross-site scripting (XSS) vulnerability. The login banner in the Archer Control Panel (ACP) did not previously escape content appropriately. 6.14 P3 (6.14.0.3) is also a fixed release.

    Published: 6 May 2024
    7.3
    High

    CVE-2024-34091

    Last Modified: 18 Mar 2025

    An issue was discovered in Archer Platform 6 before 2024.04. There is a stored cross-site scripting (XSS) vulnerability. A remote authenticated malicious Archer user could potentially exploit this vulnerability to store malicious HTML or JavaScript code in a trusted application data store. When victim users access the data store through their browsers, the malicious code gets executed in the background of the application and renders content inaccessible. 6.14 P3 (6.14.0.3) is also a fixed release.

    Published: 6 May 2024
    8.8
    High

    CVE-2024-34092

    Last Modified: 25 Mar 2025

    An issue was discovered in Archer Platform 6 before 2024.04. Authentication was mishandled because lock did not terminate an existing session. 6.14 P3 (6.14.0.3) is also a fixed release.

    Published: 6 May 2024
    5.3
    Medium

    CVE-2024-34093

    Last Modified: 18 Mar 2025

    An issue was discovered in Archer Platform 6 before 2024.03. There is an X-Forwarded-For Header Bypass vulnerability. An unauthenticated attacker could potentially bypass intended whitelisting when X-Forwarded-For header is enabled.

    Published: 6 May 2024
    7.5
    High

    CVE-2024-34246

    Last Modified: 16 Apr 2025

    wasm3 v0.5.0 was discovered to contain an out-of-bound memory read which leads to segmentation fault via the function "main" in wasm3/platforms/app/main.c.

    Published: 6 May 2024
    9.8
    Critical

    CVE-2024-34249

    Last Modified: 16 Apr 2025

    wasm3 v0.5.0 was discovered to contain a heap buffer overflow which leads to segmentation fault via the function "DeallocateSlot" in wasm3/source/m3_compile.c.

    Published: 6 May 2024
    7.5
    High

    CVE-2024-34252

    Last Modified: 16 Apr 2025

    wasm3 v0.5.0 was discovered to contain a global buffer overflow which leads to segmentation fault via the function "PreserveRegisterIfOccupied" in wasm3/source/m3_compile.c.

    Published: 6 May 2024
    5.4
    Medium

    CVE-2024-34471

    Last Modified: 17 Jun 2025

    An issue was discovered in HSC Mailinspector 5.2.17-3. A Path Traversal vulnerability (resulting in file deletion) exists in the mliRealtimeEmails.php file. The filename parameter in the export HTML functionality does not properly validate the file location, allowing an attacker to read and delete arbitrary files on the server. This was observed when the mliRealtimeEmails.php file itself was read and subsequently deleted, resulting in a 404 error for the file and disruption of email information loading.

    Published: 6 May 2024
    7.3
    High

    CVE-2024-34534

    Last Modified: 15 Apr 2026

    A SQL injection vulnerability in Cybrosys Techno Solutions Text Commander module (aka text_commander) 16.0 through 16.0.1 allows a remote attacker to gain privileges via the data parameter to models/ir_model.py:IrModel::chech_model.

    Published: 6 May 2024
    2.9
    Low

    CVE-2024-4568

    Last Modified: 29 Jan 2025

    In Xpdf 4.05 (and earlier), a PDF object loop in the PDF resources leads to infinite recursion and a stack overflow.

    Published: 6 May 2024
    7.5
    High

    CVE-2024-34069

    Last Modified: 3 Dec 2025

    Werkzeug is a comprehensive WSGI web application library. The debugger in affected versions of Werkzeug can allow an attacker to execute code on a developer's machine under some circumstances. This requires the attacker to get the developer to interact with a domain and subdomain they control, and enter the debugger PIN, but if they are successful it allows access to the debugger even if it is only running on localhost. This also requires the attacker to guess a URL in the developer's application that will trigger the debugger. This vulnerability is fixed in 3.0.3.

    Published: 6 May 2024
    7.5
    High

    CVE-2024-4436

    Last Modified: 15 Apr 2026

    The etcd package distributed with the Red Hat OpenStack platform has an incomplete fix for CVE-2022-41723. This issue occurs because the etcd package in the Red Hat OpenStack platform is using http://golang.org/x/net/http2 instead of the one provided by Red Hat Enterprise Linux versions, meaning it should be updated at compile time instead.

    Published: 6 May 2024
    5.5
    Medium

    CVE-2024-34472

    Last Modified: 25 Nov 2025

    An issue was discovered in HSC Mailinspector 5.2.17-3 through v.5.2.18. An authenticated blind SQL injection vulnerability exists in the mliRealtimeEmails.php file. The ordemGrid parameter in a POST request to /mailinspector/mliRealtimeEmails.php does not properly sanitize input, allowing an authenticated attacker to execute arbitrary SQL commands, leading to the potential disclosure of the entire application database.

    Published: 6 May 2024
    9.8
    Critical

    CVE-2024-34532

    Last Modified: 15 Apr 2026

    A SQL injection vulnerability in Yvan Dotet PostgreSQL Query Deluxe module (aka query_deluxe) 17.x before 17.0.0.4 allows a remote attacker to gain privileges via the query parameter to models/querydeluxe.py:QueryDeluxe::get_result_from_query.

    Published: 6 May 2024
    4.7
    Medium

    CVE-2024-4507

    Last Modified: 21 Aug 2025

    A vulnerability was found in Ruijie RG-UAC up to 20240428 and classified as critical. This issue affects some unknown processing of the file /view/IPV6/ipv6StaticRoute/static_route_add_ipv6.php. The manipulation of the argument text_prefixlen/text_gateway/devname leads to os command injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-263111. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 5 May 2024
    4.7
    Medium

    CVE-2024-4506

    Last Modified: 21 Aug 2025

    A vulnerability has been found in Ruijie RG-UAC up to 20240428 and classified as critical. This vulnerability affects unknown code of the file /view/IPV6/ipv6Addr/ip_addr_edit_commit.php. The manipulation of the argument text_ip_addr/orgprelen/orgname leads to os command injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-263110 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 5 May 2024
    4.7
    Medium

    CVE-2024-4505

    Last Modified: 21 Aug 2025

    A vulnerability, which was classified as critical, was found in Ruijie RG-UAC up to 20240428. This affects an unknown part of the file /view/IPV6/ipv6Addr/ip_addr_add_commit.php. The manipulation of the argument prelen/ethname leads to os command injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-263109 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 5 May 2024
    4.7
    Medium

    CVE-2024-4504

    Last Modified: 21 Aug 2025

    A vulnerability, which was classified as critical, has been found in Ruijie RG-UAC up to 20240428. Affected by this issue is some unknown functionality of the file /view/HAconfig/baseConfig/commit.php. The manipulation of the argument peer_ip/local_ip leads to os command injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-263108. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 5 May 2024
    4.7
    Medium

    CVE-2024-4503

    Last Modified: 21 Aug 2025

    A vulnerability classified as critical was found in Ruijie RG-UAC up to 20240428. Affected by this vulnerability is an unknown functionality of the file /view/dhcp/dhcpConfig/dhcp_relay_commit.php. The manipulation of the argument interface_from leads to os command injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-263107. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 5 May 2024
    4.7
    Medium

    CVE-2024-4502

    Last Modified: 21 Aug 2025

    A vulnerability classified as critical has been found in Ruijie RG-UAC up to 20240428. Affected is an unknown function of the file /view/dhcp/dhcpClient/dhcp_client_commit.php. The manipulation of the argument ifName leads to os command injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-263106 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 5 May 2024
    4.7
    Medium

    CVE-2024-4501

    Last Modified: 21 Aug 2025

    A vulnerability was found in Ruijie RG-UAC up to 20240428. It has been rated as critical. This issue affects some unknown processing of the file /view/bugSolve/captureData/commit.php. The manipulation of the argument tcpDump leads to os command injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-263105 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 5 May 2024
    6.3
    Medium

    CVE-2024-4500

    Last Modified: 10 Feb 2025

    A vulnerability was found in SourceCodester Prison Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /Employee/edit-photo.php. The manipulation of the argument userImage leads to unrestricted upload. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-263104.

    Published: 5 May 2024
    8.8
    High

    CVE-2024-4497

    Last Modified: 27 Jan 2025

    A vulnerability was found in Tenda i21 1.0.0.14(4656). It has been declared as critical. This vulnerability affects the function formexeCommand. The manipulation of the argument cmdinput leads to stack-based buffer overflow. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-263086 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 5 May 2024
    8.8
    High

    CVE-2024-4496

    Last Modified: 27 Jan 2025

    A vulnerability was found in Tenda i21 1.0.0.14(4656). It has been classified as critical. This affects the function formWifiMacFilterSet. The manipulation of the argument ssidIndex leads to stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-263085 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 5 May 2024
    8.8
    High

    CVE-2024-4495

    Last Modified: 27 Jan 2025

    A vulnerability was found in Tenda i21 1.0.0.14(4656) and classified as critical. Affected by this issue is the function formWifiMacFilterGet. The manipulation of the argument index leads to stack-based buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-263084. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 5 May 2024
    8.8
    High

    CVE-2024-4494

    Last Modified: 27 Jan 2025

    A vulnerability has been found in Tenda i21 1.0.0.14(4656) and classified as critical. Affected by this vulnerability is the function formSetUplinkInfo of the file /goform/setUplinkInfo. The manipulation of the argument pingHostIp2 leads to stack-based buffer overflow. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-263083. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 5 May 2024
    8.8
    High

    CVE-2024-4493

    Last Modified: 27 Jan 2025

    A vulnerability, which was classified as critical, was found in Tenda i21 1.0.0.14(4656). Affected is the function formSetAutoPing. The manipulation of the argument ping1/ping2 leads to stack-based buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-263082 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 5 May 2024
    8.8
    High

    CVE-2024-4492

    Last Modified: 27 Jan 2025

    A vulnerability, which was classified as critical, has been found in Tenda i21 1.0.0.14(4656). This issue affects the function formOfflineSet of the file /goform/setStaOffline. The manipulation of the argument GO/ssidIndex leads to stack-based buffer overflow. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-263081 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 5 May 2024
    7.5
    High

    CVE-2024-34527

    Last Modified: 15 Apr 2026

    spaces_plugin/app.py in SolidUI 0.4.0 has an unnecessary print statement for an OpenAI key. The printed string might be logged.

    Published: 5 May 2024
    9.1
    Critical

    CVE-2024-34524

    Last Modified: 15 Apr 2026

    In XLANG OpenAgents through fe73ac4, the allowed_file protection mechanism can be bypassed by using an incorrect file extension for the nature of the file content.

    Published: 5 May 2024
    7.8
    High

    CVE-2024-34474

    Last Modified: 15 Apr 2026

    Clario through 2024-04-11 for Desktop has weak permissions for %PROGRAMDATA%\Clario and tries to load DLLs from there as SYSTEM.

    Published: 5 May 2024
    5.3
    Medium

    CVE-2024-34525

    Last Modified: 25 Nov 2025

    FileCodeBox 2.0 stores a OneDrive password and AWS key in a cleartext env file.

    Published: 5 May 2024