CVE Feed

    Dashboard / CVE

    5.7
    Medium

    CVE-2024-3059

    Last Modified: 7 May 2025

    The ENL Newsletter WordPress plugin through 1.0.1 does not have CSRF checks in some places, which could allow attackers to make logged in admins delete arbitrary Campaigns via a CSRF attack

    Published: 26 Apr 2024
    5.4
    Medium

    CVE-2024-3058

    Last Modified: 7 May 2025

    The ENL Newsletter WordPress plugin through 1.0.1 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack

    Published: 26 Apr 2024
    5.5
    Medium

    CVE-2024-3048

    Last Modified: 14 May 2025

    The Bannerlid WordPress plugin through 1.1.0 does not escape generated URLs before outputting them in attributes, leading to Reflected Cross-Site Scripting which could be used against high privilege users such as administrators

    Published: 26 Apr 2024
    4.3
    Medium

    CVE-2024-2908

    Last Modified: 8 May 2025

    The Call Now Button WordPress plugin before 1.4.7 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

    Published: 26 Apr 2024
    5.4
    Medium

    CVE-2024-2837

    Last Modified: 14 Apr 2025

    The WP Chat App WordPress plugin before 3.6.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admins to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed

    Published: 26 Apr 2024
    6.3
    Medium

    CVE-2024-2603

    Last Modified: 18 Apr 2025

    The Salon booking system WordPress plugin through 9.6.5 does not sanitise and escape some of its settings, which could allow high privilege users such as admin (or editor depending on Salon booking system WordPress plugin through 9.6.5 configuration) to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

    Published: 26 Apr 2024
    4.8
    Medium

    CVE-2024-2439

    Last Modified: 14 Apr 2025

    The Salon booking system WordPress plugin through 9.6.5 does not sanitise and escape some of its settings, which could allow high privilege users such as Editor to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

    Published: 26 Apr 2024
    4.3
    Medium

    CVE-2024-2429

    Last Modified: 14 Apr 2025

    The Salon booking system WordPress plugin through 9.6.5 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack

    Published: 26 Apr 2024
    5.9
    Medium

    CVE-2024-2310

    Last Modified: 8 May 2025

    The WP Google Review Slider WordPress plugin before 13.6 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

    Published: 26 Apr 2024
    4.7
    Medium

    CVE-2024-2159

    Last Modified: 8 May 2025

    The Social Sharing Plugin WordPress plugin before 3.3.61 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

    Published: 26 Apr 2024
    8
    High

    CVE-2024-4163

    Last Modified: 15 Apr 2026

    The Skylab IGX IIoT Gateway allowed users to connect to it via a limited shell terminal (IGX). However, it was discovered that the process was running under root privileges. This allowed the attacker to read, write, and modify any file in the operating system by utilizing the limited shell file exec and download functions. By replacing the /etc/passwd file with a new root user entry, the attacker was able to breakout from the limited shell and login to a unrestricted shell with root access. With the root access, the attacker will be able take full control of the IIoT Gateway.

    Published: 26 Apr 2024
    6.3
    Medium

    CVE-2024-0905

    Last Modified: 8 May 2025

    The Fancy Product Designer WordPress plugin before 6.1.8 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against unauthenticated and admin-level users

    Published: 26 Apr 2024
    9.1
    Critical

    CVE-2024-33668

    Last Modified: 16 Sept 2026

    An issue was discovered in Zammad before 6.3.0. The Zammad Upload Cache uses insecure, partially guessable FormIDs to identify content. An attacker could try to brute force them to upload malicious content to article drafts they have no access to.

    Published: 26 Apr 2024
    6.1
    Medium

    CVE-2024-33665

    Last Modified: 15 Apr 2026

    angular-translate through 2.19.1 allows XSS via a crafted key that is used by the translate directive. NOTE: the vendor indicates that there is no documentation indicating that a key is supposed to be safe against XSS attacks.

    Published: 26 Apr 2024
    5.5
    Medium

    CVE-2024-32887

    Last Modified: 15 Apr 2026

    Sidekiq is simple, efficient background processing for Ruby. Sidekiq is reflected XSS vulnerability. The value of substr parameter is reflected in the response without any encoding, allowing an attacker to inject Javascript code into the response of the application. An attacker could exploit it to target users of the Sidekiq Web UI. Moreover, if other applications are deployed on the same domain or website as Sidekiq, users of those applications could also be affected, leading to a broader scope of compromise. Potentially compromising their accounts, forcing the users to perform sensitive actions, stealing sensitive data, performing CORS attacks, defacement of the web application, etc. This issue has been patched in version 7.2.4.

    Published: 26 Apr 2024
    8.4
    High

    CVE-2024-28327

    Last Modified: 15 Apr 2026

    Asus RT-N12+ B1 router stores user passwords in plaintext, which could allow local attackers to obtain unauthorized access and modify router settings.

    Published: 26 Apr 2024
    7.6
    High

    CVE-2024-31755

    Last Modified: 30 Jun 2025

    cJSON v1.7.17 was discovered to contain a segmentation violation, which can trigger through the second parameter of function cJSON_SetValuestring at cJSON.c.

    Published: 26 Apr 2024
    6
    Medium

    CVE-2024-32404

    Last Modified: 30 Jun 2025

    Server-Side Template Injection (SSTI) vulnerability in inducer relate before v.2024.1, allows remote attackers to execute arbitrary code via a crafted payload to the Markup Sandbox feature.

    Published: 26 Apr 2024
    6.1
    Medium

    CVE-2024-33669

    Last Modified: 18 Jun 2025

    An issue was discovered in Passbolt Browser Extension before 4.6.2. It can send multiple requests to HaveIBeenPwned while a password is being typed, which results in an information leak. This allows an attacker capable of observing Passbolt's HTTPS queries to the Pwned Password API to more easily brute force passwords that are manually typed by the user.

    Published: 26 Apr 2024
    9.8
    Critical

    CVE-2024-28322

    Last Modified: 14 May 2025

    SQL Injection vulnerability in /event-management-master/backend/register.php in PuneethReddyHC Event Management 1.0 allows attackers to run arbitrary SQL commands via the event_id parameter in a crafted POST request.

    Published: 26 Apr 2024
    5.9
    Medium

    CVE-2023-26603

    Last Modified: 15 Apr 2026

    JumpCloud Agent before 1.178.0 Creates a Temporary File in a Directory with Insecure Permissions. This allows privilege escalation to SYSTEM via a repair action in the installer.

    Published: 26 Apr 2024
    5.5
    Medium

    CVE-2024-33259

    Last Modified: 22 Sept 2025

    Jerryscript commit cefd391 was discovered to contain a segmentation violation via the component scanner_seek at jerry-core/parser/js/js-scanner-util.c.

    Published: 26 Apr 2024
    5.1
    Medium

    CVE-2024-33260

    Last Modified: 22 Sept 2025

    Jerryscript commit cefd391 was discovered to contain a segmentation violation via the component parser_parse_class at jerry-core/parser/js/js-parser-expr.c

    Published: 26 Apr 2024
    6.2
    Medium

    CVE-2024-33255

    Last Modified: 22 Sept 2025

    Jerryscript commit cefd391 was discovered to contain an Assertion Failure via ECMA_STRING_IS_REF_EQUALS_TO_ONE (string_p) in ecma_free_string_list.

    Published: 26 Apr 2024
    7.1
    High

    CVE-2024-33258

    Last Modified: 22 Sept 2025

    Jerryscript commit ff9ff8f was discovered to contain a segmentation violation via the component vm_loop at jerry-core/vm/vm.c.

    Published: 26 Apr 2024
    4
    Medium

    CVE-2024-33263

    Last Modified: 22 Sept 2025

    QuickJS commit 3b45d15 was discovered to contain an Assertion Failure via JS_FreeRuntime(JSRuntime *) at quickjs.c.

    Published: 26 Apr 2024
    3.1
    Low

    CVE-2024-22091

    Last Modified: 12 May 2025

    Mattermost versions 8.1.x <= 8.1.10, 9.6.x <= 9.6.0, 9.5.x <= 9.5.2 and 8.1.x <= 8.1.11 fail to limit the size of a request path that includes user inputs which allows an attacker to cause excessive resource consumption, possibly leading to a DoS via sending large request paths

    Published: 26 Apr 2024
    9.8
    Critical

    CVE-2024-22633

    Last Modified: 15 Apr 2026

    Setor Informatica Sistema Inteligente para Laboratorios (S.I.L.) 388 was discovered to contain a remote code execution (RCE) vulnerability via the hprinter parameter. This vulnerability is triggered via a crafted POST request.

    Published: 26 Apr 2024
    9.1
    Critical

    CVE-2024-25343

    Last Modified: 30 Jun 2025

    Tenda N300 F3 router vulnerability allows users to bypass intended security policy and create weak passwords.

    Published: 26 Apr 2024
    5.4
    Medium

    CVE-2024-28328

    Last Modified: 15 Apr 2026

    CSV Injection vulnerability in the Asus RT-N12+ router allows administrator users to inject arbitrary commands or formulas in the client name parameter which can be triggered and executed in a different user session upon exporting to CSV format.

    Published: 26 Apr 2024
    6.8
    Medium

    CVE-2024-28326

    Last Modified: 15 Apr 2026

    Incorrect Access Control in ASUS RT-N12+ B1 and RT-N12 D1 routers allows local attackers to obtain root terminal access via the the UART interface.

    Published: 26 Apr 2024
    9.8
    Critical

    CVE-2024-30804

    Last Modified: 15 Apr 2026

    An issue discovered in the DeviceIoControl component in ASUS Fan_Xpert before v.10013 allows an attacker to execute arbitrary code via crafted IOCTL requests.

    Published: 26 Apr 2024
    8.1
    High

    CVE-2024-31502

    Last Modified: 15 Apr 2026

    An issue in Insurance Management System v.1.0.0 and before allows a remote attacker to escalate privileges via a crafted POST request to /admin/core/new_staff.

    Published: 26 Apr 2024
    7.5
    High

    CVE-2024-31551

    Last Modified: 14 Apr 2025

    Directory Traversal vulnerability in lib/admin/image.admin.php in cmseasy v7.7.7.9 20240105 allows attackers to delete arbitrary files via crafted GET request.

    Published: 26 Apr 2024
    9.8
    Critical

    CVE-2024-31601

    Last Modified: 15 Apr 2026

    An issue in Beijing Panabit Network Software Co., Ltd Panalog big data analysis platform v. 20240323 and before allows attackers to execute arbitrary code via the exportpdf.php component.

    Published: 26 Apr 2024
    6.1
    Medium

    CVE-2024-31741

    Last Modified: 18 Apr 2025

    Cross Site Scripting vulnerability in MiniCMS v.1.11 allows a remote attacker to run arbitrary code via crafted string in the URL after login.

    Published: 26 Apr 2024
    6.1
    Medium

    CVE-2024-31828

    Last Modified: 24 Aug 2026

    Cross Site Scripting vulnerability in Lavalite CMS v.10.1.0 allows attackers to execute arbitrary code and obtain sensitive information via a crafted payload to the URL.

    Published: 26 Apr 2024
    4.3
    Medium

    CVE-2024-32046

    Last Modified: 12 May 2025

    Mattermost versions 9.6.x <= 9.6.0, 9.5.x <= 9.5.2, 9.4.x <= 9.4.4 and 8.1.x <= 8.1.11 fail to remove detailed error messages in API requests even if the developer mode is off which allows an attacker to get information about the server such as the full path were files are stored

    Published: 26 Apr 2024
    7.5
    High

    CVE-2024-32406

    Last Modified: 17 Dec 2025

    Server-Side Template Injection (SSTI) vulnerability in inducer relate before v.2024.1 allows a remote attacker to execute arbitrary code via a crafted payload to the Batch-Issue Exam Tickets function.

    Published: 26 Apr 2024
    7.5
    High

    CVE-2024-33342

    Last Modified: 21 May 2025

    D-Link DIR-822+ V1.0.5 was found to contain a command injection in SetPlcNetworkpwd function of prog.cgi, which allows remote attackers to execute arbitrary commands via shell.

    Published: 26 Apr 2024
    8.8
    High

    CVE-2024-33343

    Last Modified: 21 May 2025

    D-Link DIR-822+ V1.0.5 was found to contain a command injection in ChgSambaUserSettings function of prog.cgi, which allows remote attackers to execute arbitrary commands via shell.

    Published: 26 Apr 2024
    9.8
    Critical

    CVE-2024-33344

    Last Modified: 21 May 2025

    D-Link DIR-822+ V1.0.5 was found to contain a command injection in ftext function of upload_firmware.cgi, which allows remote attackers to execute arbitrary commands via shell.

    Published: 26 Apr 2024
    8.6
    High

    CVE-2024-33666

    Last Modified: 15 Apr 2025

    An issue was discovered in Zammad before 6.3.0. Users with customer access to a ticket could have accessed time accounting details of this ticket via the API. This data should be available only to agents.

    Published: 26 Apr 2024
    6.5
    Medium

    CVE-2024-33667

    Last Modified: 15 Apr 2025

    An issue was discovered in Zammad before 6.3.0. An authenticated agent could perform a remote Denial of Service attack by calling an endpoint that accepts a generic method name, which was not properly sanitized against an allowlist.

    Published: 26 Apr 2024
    4.3
    Medium

    CVE-2024-33670

    Last Modified: 18 Jun 2025

    Passbolt API before 4.6.2 allows HTML injection in a URL parameter, resulting in custom content being displayed when a user visits the crafted URL. Although the injected content is not executed as JavaScript due to Content Security Policy (CSP) restrictions, it may still impact the appearance and user interaction of the page.

    Published: 26 Apr 2024
    7.7
    High

    CVE-2024-33671

    Last Modified: 30 Jun 2025

    An issue was discovered in Veritas Backup Exec before 22.2 HotFix 917391. The Backup Exec Deduplication Multi-threaded Streaming Agent can be leveraged to perform arbitrary file deletion on protected files.

    Published: 26 Apr 2024
    7.7
    High

    CVE-2024-33672

    Last Modified: 10 Jun 2025

    An issue was discovered in Veritas NetBackup before 10.4. The Multi-Threaded Agent used in NetBackup can be leveraged to perform arbitrary file deletion on protected files.

    Published: 26 Apr 2024
    7.8
    High

    CVE-2024-33673

    Last Modified: 30 Jun 2025

    An issue was discovered in Veritas Backup Exec before 22.2 HotFix 917391. Improper access controls allow for DLL Hijacking in the Windows DLL Search path.

    Published: 26 Apr 2024
    4.3
    Medium

    CVE-2024-4182

    Last Modified: 12 May 2025

    Mattermost versions 9.6.0, 9.5.x before 9.5.3, 9.4.x before 9.4.5, and 8.1.x before 8.1.12 fail to handle JSON parsing errors in custom status values, which allows an authenticated attacker to crash other users' web clients via a malformed custom status.

    Published: 26 Apr 2024
    4.3
    Medium

    CVE-2024-4183

    Last Modified: 12 May 2025

    Mattermost versions 8.1.x before 8.1.12, 9.6.x before 9.6.1, 9.5.x before 9.5.3, 9.4.x before 9.4.5 fail to limit the number of active sessions, which allows an authenticated attacker to crash the server via repeated requests to the getSessions API after flooding the sessions table.

    Published: 26 Apr 2024