CVE Feed

    Dashboard / CVE

    7.1
    High

    CVE-2024-33465

    Last Modified: 15 Apr 2026

    Cross Site Scripting vulnerability in MajorDoMo before v.0662e5e allows an attacker to escalate privileges via the the thumb/thumb.php component.

    Published: 30 Apr 2024
    5.3
    Medium

    CVE-2024-33436

    Last Modified: 18 Jun 2025

    An issue in CSS Exfil Protection v.1.1.0 allows a remote attacker to obtain sensitive information due to missing support for CSS variables

    Published: 30 Apr 2024
    6.1
    Medium

    CVE-2024-33371

    Last Modified: 1 Apr 2025

    Cross Site Scripting vulnerability in DedeCMS v.5.7.113 allows a remote attacker to execute arbitrary code via the typeid parameter in the makehtml_list_action.php component.

    Published: 30 Apr 2024
    7.5
    High

    CVE-2024-33332

    Last Modified: 3 Jun 2025

    An issue discovered in SpringBlade 3.7.1 allows attackers to obtain sensitive information via crafted GET request to api/blade-system/tenant.

    Published: 30 Apr 2024
    7.5
    High

    CVE-2024-34088

    Last Modified: 1 May 2025

    In FRRouting (FRR) through 9.1, it is possible for the get_edge() function in ospf_te.c in the OSPF daemon to return a NULL pointer. In cases where calling functions do not handle the returned NULL value, the OSPF daemon crashes, leading to denial of service.

    Published: 30 Apr 2024
    5.6
    Medium

    CVE-2019-19751

    Last Modified: 15 Apr 2026

    easyMINE before 2019-12-05 ships with SSH host keys baked into the installation image, which allows man-in-the-middle attacks and makes identification of all public IPv4 nodes trivial with Shodan.io.

    Published: 30 Apr 2024
    9.1
    Critical

    CVE-2019-19753

    Last Modified: 15 Apr 2026

    SimpleMiningOS through v1259 ships with SSH host keys baked into the installation image, which allows man-in-the-middle attacks and makes identification of all public IPv4 nodes trivial with Shodan.io. NOTE: the vendor indicated that they have no plans to fix this, and discourage deployment using public IPv4.

    Published: 30 Apr 2024
    9.1
    Critical

    CVE-2019-19755

    Last Modified: 15 Apr 2026

    ethOS through 1.3.3 ships with SSH host keys baked into the installation image, which allows man-in-the-middle attacks and makes identification of all public IPv4 nodes trivial with Shodan.io. NOTE: as of 2019-12-01, the vendor indicated that they plan to fix this.

    Published: 30 Apr 2024
    6.7
    Medium

    CVE-2023-50914

    Last Modified: 15 Apr 2026

    A Privilege Escalation issue in the inter-process communication procedure from GOG Galaxy (Beta) 2.0.67.2 through v2.0.71.2 allows authentictaed users to change the DACL of arbitrary system directories to include Everyone full control permissions by modifying the FixDirectoryPrivileges instruction parameters sent from GalaxyClient.exe to GalaxyClientService.exe.

    Published: 30 Apr 2024
    9.8
    Critical

    CVE-2024-33267

    Last Modified: 15 Apr 2026

    SQL Injection vulnerability in Hero hfheropayment v.1.2.5 and before allows an attacker to escalate privileges via the HfHeropaymentGatewayBackModuleFrontController::initContent() function.

    Published: 30 Apr 2024
    7.5
    High

    CVE-2024-33437

    Last Modified: 18 Jun 2025

    An issue in CSS Exfil Protection v.1.1.0 allows a remote attacker to obtain sensitive information due to missing support for CSS Style Rules.

    Published: 30 Apr 2024
    7.5
    High

    CVE-2024-28716

    Last Modified: 15 Apr 2026

    An issue in OpenStack Storlets yoga-eom allows a remote attacker to execute arbitrary code via the gateway.py component.

    Published: 30 Apr 2024
    6.1
    Medium

    CVE-2024-33101

    Last Modified: 23 Apr 2025

    A stored cross-site scripting (XSS) vulnerability in the component /action/anti.php of ThinkSAAS v3.7.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the word parameter.

    Published: 30 Apr 2024
    5.4
    Medium

    CVE-2024-33102

    Last Modified: 23 Apr 2025

    A stored cross-site scripting (XSS) vulnerability in the component /pubs/counter.php of ThinkSAAS v3.7.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the code parameter.

    Published: 30 Apr 2024
    8.1
    High

    CVE-2023-46304

    Last Modified: 22 Apr 2025

    modules/Users/models/Module.php in Vtiger CRM 7.5.0 allows a remote authenticated attacker to run arbitrary PHP code because an unprotected endpoint allows them to write this code to the config.inc.php file (executed on every page load).

    Published: 30 Apr 2024
    7.8
    High

    CVE-2024-23773

    Last Modified: 15 Apr 2026

    An issue was discovered in Quest KACE Agent for Windows 12.0.38 and 13.1.23.0. An Arbitrary file delete vulnerability exists in the KSchedulerSvc.exe component. Local attackers can delete any file of their choice with NT Authority\SYSTEM privileges.

    Published: 30 Apr 2024
    6.4
    Medium

    CVE-2024-22546

    Last Modified: 1 Apr 2025

    TRENDnet TEW-815DAP 1.0.2.0 is vulnerable to Command Injection via the do_setNTP function. An authenticated attacker with administrator privileges can leverage this vulnerability over the network via a malicious POST request.

    Published: 30 Apr 2024
    6.6
    Medium

    CVE-2024-23772

    Last Modified: 15 Apr 2026

    An issue was discovered in Quest KACE Agent for Windows 12.0.38 and 13.1.23.0. An Arbitrary file create vulnerability exists in the KSchedulerSvc.exe, KUserAlert.exe, and Runkbot.exe components. This allows local attackers to create any file of their choice with NT Authority\SYSTEM privileges.

    Published: 30 Apr 2024
    7.5
    High

    CVE-2024-26331

    Last Modified: 15 Apr 2026

    ReCrystallize Server 5.10.0.0 uses a authorization mechanism that relies on the value of a cookie, but it does not bind the cookie value to a session ID. Attackers can easily modify the cookie value, within a browser or by implementing client-side code outside of a browser. Attackers can bypass the authentication mechanism by modifying the cookie to contain an expected value.

    Published: 30 Apr 2024
    8.1
    High

    CVE-2024-29320

    Last Modified: 3 Jun 2025

    Wallos before 1.15.3 is vulnerable to SQL Injection via the category and payment parameters to /subscriptions/get.php.

    Published: 30 Apr 2024
    7.5
    High

    CVE-2024-29384

    Last Modified: 18 Jun 2025

    An issue in CSS Exfil Protection v.1.1.0 allows a remote attacker to obtain sensitive information via the content.js and parseCSSRules functions.

    Published: 30 Apr 2024
    8.8
    High

    CVE-2024-29466

    Last Modified: 15 Apr 2026

    Directory Traversal vulnerability in lsgwr spring boot online exam v.0.9 allows an attacker to execute arbitrary code via the FileTransUtil.java component.

    Published: 30 Apr 2024
    9.8
    Critical

    CVE-2024-33273

    Last Modified: 15 Apr 2026

    SQL injection vulnerability in shipup before v.3.3.0 allows a remote attacker to escalate privileges via the getShopID function.

    Published: 30 Apr 2024
    6.7
    Medium

    CVE-2024-33522

    Last Modified: 15 Apr 2026

    In vulnerable versions of Calico (v3.27.2 and below), Calico Enterprise (v3.19.0-1, v3.18.1, v3.17.3 and below), and Calico Cloud (v19.2.0 and below), an attacker who has local access to the Kubernetes node, can escalate their privileges by exploiting a vulnerability in the Calico CNI install binary. The issue arises from an incorrect SUID (Set User ID) bit configuration in the binary, combined with the ability to control the input binary, allowing an attacker to execute an arbitrary binary with elevated privileges.

    Published: 29 Apr 2024
    8.8
    High

    CVE-2024-0840

    Last Modified: 15 Apr 2026

    The Grandstream UCM Series IP PBX before firmware version 1.0.20.52 is affected by a parameter injection vulnerability in the HTTP interface. A remote and authenticated attacker can execute arbitrary code by sending a crafted HTTP request. Authentication may be possible using a default user and password. Affected models are the UCM6202, UCM6204, UCM6208, and UCM6510.

    Published: 29 Apr 2024
    6.8
    Medium

    CVE-2024-34011

    Last Modified: 15 Apr 2026

    Local privilege escalation due to insecure folder permissions. The following products are affected: Acronis Cyber Protect Cloud Agent (Windows) before build 37758.

    Published: 29 Apr 2024
    8.2
    High

    CVE-2024-34010

    Last Modified: 15 Apr 2026

    Local privilege escalation due to unquoted search path vulnerability. The following products are affected: Acronis Cyber Protect Cloud Agent (Windows) before build 37758, Acronis Cyber Protect 16 (Windows) before build 38690, Acronis True Image (Windows) before build 42386, Acronis True Image OEM (Windows) before build 42575.

    Published: 29 Apr 2024
    7.1
    High

    CVE-2023-48684

    Last Modified: 15 Apr 2026

    Sensitive information disclosure and manipulation due to missing authorization. The following products are affected: Acronis Cyber Protect Cloud Agent (Linux, macOS, Windows) before build 37758, Acronis Cyber Protect 17 (Linux, macOS, Windows) before build 41186.

    Published: 29 Apr 2024
    7.1
    High

    CVE-2023-48683

    Last Modified: 15 Apr 2026

    Sensitive information disclosure and manipulation due to missing authorization. The following products are affected: Acronis Cyber Protect Cloud Agent (Linux, macOS, Windows) before build 37758, Acronis Cyber Protect 16 (Linux, macOS, Windows) before build 39169.

    Published: 29 Apr 2024
    8.2
    High

    CVE-2024-1969

    Last Modified: 15 Apr 2026

    Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in Secomea GateManager (webserver modules) allows crash of GateManager.This issue affects GateManager: from 9.7 before 11.2.624095033.

    Published: 29 Apr 2024
    8.1
    High

    CVE-2024-1579

    Last Modified: 15 Apr 2026

    Incorrect Usage of Seeds in Pseudo-Random Number Generator (PRNG) vulnerability in Secomea GateManager (Webserver modules) allows Session Hijacking.This issue affects GateManager: before 11.2.624071020.

    Published: 29 Apr 2024
    8.8
    High

    CVE-2024-27322

    Last Modified: 15 Apr 2026

    Deserialization of untrusted data can occur in the R statistical programming language, on any version starting at 1.4.0 up to and not including 4.4.0, enabling a maliciously crafted RDS (R Data Serialization) formatted file or R package to run arbitrary code on an end user’s system when interacted with.

    Published: 29 Apr 2024
    4.3
    Medium

    CVE-2024-33585

    Last Modified: 28 Apr 2026

    Missing Authorization vulnerability in Tyche Softwares Payment Gateway Based Fees and Discounts for WooCommerce.This issue affects Payment Gateway Based Fees and Discounts for WooCommerce: from n/a through 2.12.1.

    Published: 29 Apr 2024
    5.3
    Medium

    CVE-2024-33586

    Last Modified: 28 Apr 2026

    Missing Authorization vulnerability in Photo Gallery Team Photo Gallery by 10Web.This issue affects Photo Gallery by 10Web: from n/a through 1.8.20.

    Published: 29 Apr 2024
    5.3
    Medium

    CVE-2024-33587

    Last Modified: 28 Apr 2026

    Missing Authorization vulnerability in Copy Content Protection Team Secure Copy Content Protection and Content Locking.This issue affects Secure Copy Content Protection and Content Locking: from n/a through 3.9.0.

    Published: 29 Apr 2024
    5.4
    Medium

    CVE-2024-33588

    Last Modified: 28 Apr 2026

    Missing Authorization vulnerability in codeSavory Knowledge Base documentation & wiki plugin – BasePress.This issue affects Knowledge Base documentation & wiki plugin – BasePress: from n/a through 2.16.1.

    Published: 29 Apr 2024
    6.3
    Medium

    CVE-2024-4310

    Last Modified: 23 Apr 2025

    Cross-site Scripting (XSS) vulnerability in HubBank affecting version 1.0.2. This vulnerability allows an attacker to send a specially crafted JavaScript payload to registration and profile forms and trigger the payload when any authenticated user loads the page, resulting in a session takeover.

    Published: 29 Apr 2024
    8.1
    High

    CVE-2024-4309

    Last Modified: 23 Apr 2025

    SQL injection vulnerability in HubBank affecting version 1.0.2. This vulnerability could allow an attacker to send a specially crafted SQL query to the database through different endpoints (/user/transaction.php?id=1, /user/credit-debit_transaction.php?id=1,/user/view_transaction. php?id=1 and /user/viewloantrans.php?id=1, id parameter) and retrieve the information stored in the database.

    Published: 29 Apr 2024
    8.1
    High

    CVE-2024-4307

    Last Modified: 23 Apr 2025

    SQL injection vulnerability in HubBank affecting version 1.0.2. This vulnerability could allow an attacker to send a specially crafted SQL query to the database through different endpoints (/accounts/activities.php?id=1, /accounts/view-deposit.php?id=1, /accounts/view_cards. php?id=1, /accounts/wire-transfer.php?id=1 and /accounts/wiretransfer-pending.php?id=1, id parameter) and retrieve the information stored in the database.

    Published: 29 Apr 2024
    8.1
    High

    CVE-2024-4308

    Last Modified: 26 Sept 2025

    SQL injection vulnerability in HubBank affecting version 1.0.2. This vulnerability could allow an attacker to send a specially crafted SQL query to the database through different endpoints (/admin/view_users.php?id=1,/admin/viewloan-trans.php?id=1,/admin/view-deposit.php?id=1,/admin/view-domtrans.php?id=1, /admin/delete_cards.php?id=1,/admin/view_cards.php?id=1 and /admin/view_users.php?id=1, id parameter) and retrieve the information stored in the database.

    Published: 29 Apr 2024
    9.9
    Critical

    CVE-2024-4306

    Last Modified: 23 Apr 2025

    Critical unrestricted file upload vulnerability in HubBank affecting version 1.0.2. This vulnerability allows a registered user to upload malicious PHP files via upload document fields, resulting in webshell execution.

    Published: 29 Apr 2024
    5.4
    Medium

    CVE-2024-4304

    Last Modified: 15 Apr 2026

    A Cross-Site Scripting XSS vulnerability has been detected on GT3 Soluciones SWAL. This vulnerability consists in a reflected XSS in the Titular parameter inside Gestion 'Documental > Seguimiento de Expedientes > Alta de Expedientes'.

    Published: 29 Apr 2024
    6.5
    Medium

    CVE-2024-33589

    Last Modified: 28 Apr 2026

    Missing Authorization vulnerability in WPOmnia KB Support.This issue affects KB Support: from n/a through 1.6.0.

    Published: 29 Apr 2024
    5
    Medium

    CVE-2024-33590

    Last Modified: 28 Apr 2026

    Server-Side Request Forgery (SSRF) vulnerability in codeSavory Knowledge Base documentation & wiki plugin – BasePress.This issue affects Knowledge Base documentation & wiki plugin – BasePress: from n/a through 2.16.1.

    Published: 29 Apr 2024
    7.5
    High

    CVE-2024-33591

    Last Modified: 28 Apr 2026

    Missing Authorization vulnerability in Tips and Tricks HQ Easy Accept Payments.This issue affects Easy Accept Payments: from n/a through 4.9.10.

    Published: 29 Apr 2024
    4.3
    Medium

    CVE-2024-33593

    Last Modified: 28 Apr 2026

    Missing Authorization vulnerability in RedNao Smart Forms.This issue affects Smart Forms: from n/a through 2.6.91.

    Published: 29 Apr 2024
    7.5
    High

    CVE-2024-33594

    Last Modified: 28 Apr 2026

    Missing Authorization vulnerability in Leaky Paywall.This issue affects Leaky Paywall: from n/a through 4.20.8.

    Published: 29 Apr 2024
    4.3
    Medium

    CVE-2024-33595

    Last Modified: 28 Apr 2026

    Missing Authorization vulnerability in Jewel Theme Master Addons for Elementor.This issue affects Master Addons for Elementor: from n/a through 2.0.5.4.1.

    Published: 29 Apr 2024
    9.4
    Critical

    CVE-2024-3375

    Last Modified: 3 Jun 2026

    Incorrect Permission Assignment for Critical Resource vulnerability in Havelsan Inc. Dialogue allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Dialogue: from v1.83 before v1.83.1 or v1.84.

    Published: 29 Apr 2024
    5.3
    Medium

    CVE-2024-33596

    Last Modified: 28 Apr 2026

    Missing Authorization vulnerability in Five Star Plugins Five Star Restaurant Reservations.This issue affects Five Star Restaurant Reservations: from n/a through 2.6.16.

    Published: 29 Apr 2024