CVE Feed

    Dashboard / CVE

    9.9
    Critical

    CVE-2024-3025

    Last Modified: 9 Jul 2025

    mintplex-labs/anything-llm is vulnerable to path traversal attacks due to insufficient validation of user-supplied input in the logo filename functionality. Attackers can exploit this vulnerability by manipulating the logo filename to reference files outside of the restricted directory. This can lead to unauthorized reading or deletion of files by utilizing the `/api/system/upload-logo` and `/api/system/logo` endpoints. The issue stems from the lack of filtering or validation on the logo filename, allowing attackers to target sensitive files such as the application's database.

    Published: 10 Apr 2024
    4.1
    Medium

    CVE-2024-3388

    Last Modified: 24 Jan 2025

    A vulnerability in the GlobalProtect Gateway in Palo Alto Networks PAN-OS software enables an authenticated attacker to impersonate another user and send network packets to internal assets. However, this vulnerability does not allow the attacker to receive response packets from those internal assets.

    Published: 10 Apr 2024
    5.3
    Medium

    CVE-2024-3387

    Last Modified: 30 Jan 2026

    A weak (low bit strength) device certificate in Palo Alto Networks Panorama software enables an attacker to perform a meddler-in-the-middle (MitM) attack to capture encrypted traffic between the Panorama management server and the firewalls it manages. With sufficient computing resources, the attacker could break encrypted communication and expose sensitive information that is shared between the management server and the firewalls.

    Published: 10 Apr 2024
    5.3
    Medium

    CVE-2024-3386

    Last Modified: 13 May 2026

    An incorrect string comparison vulnerability in Palo Alto Networks PAN-OS software prevents Predefined Decryption Exclusions from functioning as intended. This can cause traffic destined for domains that are not specified in Predefined Decryption Exclusions to be unintentionally excluded from decryption.

    Published: 10 Apr 2024
    7.5
    High

    CVE-2024-3385

    Last Modified: 13 May 2026

    A packet processing mechanism in Palo Alto Networks PAN-OS software enables a remote attacker to reboot hardware-based firewalls. Repeated attacks eventually cause the firewall to enter maintenance mode, which requires manual intervention to bring the firewall back online. This affects the following hardware firewall models: - PA-5400 Series firewalls - PA-7000 Series firewalls

    Published: 10 Apr 2024
    7.5
    High

    CVE-2024-3384

    Last Modified: 24 Jan 2025

    A vulnerability in Palo Alto Networks PAN-OS software enables a remote attacker to reboot PAN-OS firewalls when receiving Windows New Technology LAN Manager (NTLM) packets from Windows servers. Repeated attacks eventually cause the firewall to enter maintenance mode, which requires manual intervention to bring the firewall back online.

    Published: 10 Apr 2024
    7.4
    High

    CVE-2024-3383

    Last Modified: 24 Jan 2025

    A vulnerability in how Palo Alto Networks PAN-OS software processes data received from Cloud Identity Engine (CIE) agents enables modification of User-ID groups. This impacts user access to network resources where users may be inappropriately denied or allowed access to resources based on your existing Security Policy rules.

    Published: 10 Apr 2024
    7.5
    High

    CVE-2024-3382

    Last Modified: 13 May 2026

    A memory leak exists in Palo Alto Networks PAN-OS software that enables an attacker to send a burst of crafted packets through the firewall that eventually prevents the firewall from processing traffic. This issue applies only to PA-5400 Series devices that are running PAN-OS software with the SSL Forward Proxy feature enabled.

    Published: 10 Apr 2024
    7.1
    High

    CVE-2024-31299

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Reservation Diary ReDi Restaurant Reservation allows Cross-Site Scripting (XSS).This issue affects ReDi Restaurant Reservation: from n/a through 24.0128.

    Published: 10 Apr 2024
    8.5
    High

    CVE-2024-31355

    Last Modified: 28 Apr 2026

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Tribulant Slideshow Gallery.This issue affects Slideshow Gallery: from n/a through 1.7.8.

    Published: 10 Apr 2024
    7.6
    High

    CVE-2024-31356

    Last Modified: 28 Apr 2026

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Solwin Infotech User Activity Log.This issue affects User Activity Log: from n/a through 1.8.

    Published: 10 Apr 2024
    6.5
    Medium

    CVE-2024-31342

    Last Modified: 28 Apr 2026

    Missing Authorization vulnerability in WPcloudgallery WordPress Gallery Exporter.This issue affects WordPress Gallery Exporter: from n/a through 1.3.

    Published: 10 Apr 2024
    7.5
    High

    CVE-2024-31343

    Last Modified: 28 Apr 2026

    Missing Authorization vulnerability in Sonaar Music MP3 Audio Player for Music, Radio & Podcast by Sonaar.This issue affects MP3 Audio Player for Music, Radio & Podcast by Sonaar: from n/a through 4.10.1.

    Published: 10 Apr 2024
    6.5
    Medium

    CVE-2024-31287

    Last Modified: 28 Apr 2026

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Max Foundry Media Library Folders.This issue affects Media Library Folders: from n/a through 8.1.8.

    Published: 10 Apr 2024
    7.7
    High

    CVE-2024-31240

    Last Modified: 28 Apr 2026

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in InfoTheme WP Poll Maker.This issue affects WP Poll Maker: from n/a through 3.1.

    Published: 10 Apr 2024
    6.2
    Medium

    CVE-2024-31874

    Last Modified: 3 Nov 2025

    IBM Security Verify Access Appliance 10.0.0 through 10.0.7 uses uninitialized variables when deploying that could allow a local user to cause a denial of service. IBM X-Force ID: 287318.

    Published: 10 Apr 2024
    7.5
    High

    CVE-2024-31297

    Last Modified: 28 Apr 2026

    Missing Authorization vulnerability in WPExperts Wholesale For WooCommerce.This issue affects Wholesale For WooCommerce: from n/a through 2.3.0.

    Published: 10 Apr 2024
    7.5
    High

    CVE-2024-31873

    Last Modified: 3 Nov 2025

    IBM Security Verify Access Appliance 10.0.0 through 10.0.7 contains hard-coded credentials which it uses for its own inbound authentication that could be obtained by a malicious actor. IBM X-Force ID: 287317.

    Published: 10 Apr 2024
    7.5
    High

    CVE-2024-31358

    Last Modified: 28 Apr 2026

    Missing Authorization vulnerability in Saleswonder Team: Tobias 5 Stars Rating Funnel 5-stars-rating-funnel.This issue affects 5 Stars Rating Funnel: from n/a through <= 1.2.67.

    Published: 10 Apr 2024
    8.2
    High

    CVE-2024-0218

    Last Modified: 15 Apr 2026

    A Denial of Service (Dos) vulnerability in Nozomi Networks Guardian, caused by improper input validation in certain fields used in the Radius parsing functionality of our IDS, allows an unauthenticated attacker sending specially crafted malformed network packets to cause the IDS module to stop updating nodes, links, and assets. Network traffic may not be analyzed until the IDS module is restarted.

    Published: 10 Apr 2024
    7.5
    High

    CVE-2024-31871

    Last Modified: 3 Nov 2025

    IBM Security Verify Access Appliance 10.0.0 through 10.0.7 could allow a malicious actor to conduct a man in the middle attack when deploying Python scripts due to improper certificate validation. IBM X-Force ID: 287306.

    Published: 10 Apr 2024
    5.3
    Medium

    CVE-2024-31245

    Last Modified: 12 Aug 2026

    Insertion of Sensitive Information into Log File vulnerability in ConvertKit.This issue affects ConvertKit: from n/a through 2.4.5.

    Published: 10 Apr 2024
    7.5
    High

    CVE-2024-31872

    Last Modified: 3 Nov 2025

    IBM Security Verify Access Appliance 10.0.0 through 10.0.7 could allow a malicious actor to conduct a man in the middle attack when deploying Open Source scripts due to missing certificate validation. IBM X-Force ID: 287316.

    Published: 10 Apr 2024
    5.3
    Medium

    CVE-2024-31247

    Last Modified: 28 Apr 2026

    Insertion of Sensitive Information into Log File vulnerability in Frédéric GILLES FG Drupal to WordPress.This issue affects FG Drupal to WordPress: from n/a through 3.70.3.

    Published: 10 Apr 2024
    7.5
    High

    CVE-2023-6916

    Last Modified: 15 Apr 2026

    Audit records for OpenAPI requests may include sensitive information. This could lead to unauthorized accesses and privilege escalation.

    Published: 10 Apr 2024
    5.3
    Medium

    CVE-2024-31249

    Last Modified: 12 Aug 2026

    Insertion of Sensitive Information into Log File vulnerability in WPKube Subscribe To Comments Reloaded.This issue affects Subscribe To Comments Reloaded: from n/a through 220725.

    Published: 10 Apr 2024
    3.7
    Low

    CVE-2024-31254

    Last Modified: 28 Apr 2026

    Insertion of Sensitive Information into Log File vulnerability in WebToffee WordPress Backup & Migration.This issue affects WordPress Backup & Migration: from n/a through 1.4.7.

    Published: 10 Apr 2024
    7.5
    High

    CVE-2024-31259

    Last Modified: 28 Apr 2026

    Insertion of Sensitive Information into Log File vulnerability in Searchiq SearchIQ.This issue affects SearchIQ: from n/a through 4.5.

    Published: 10 Apr 2024
    4.3
    Medium

    CVE-2024-31278

    Last Modified: 28 Apr 2026

    Insertion of Sensitive Information Into Sent Data vulnerability in Leap13 Premium Addons for Elementor premium-addons-for-elementor.This issue affects Premium Addons for Elementor: from n/a through <= 4.10.22.

    Published: 10 Apr 2024
    5.3
    Medium

    CVE-2024-31298

    Last Modified: 28 Apr 2026

    Insertion of Sensitive Information into Log File vulnerability in Joel Hardi User Spam Remover.This issue affects User Spam Remover: from n/a through 1.0.

    Published: 10 Apr 2024
    5.3
    Medium

    CVE-2024-31302

    Last Modified: 28 Apr 2026

    Exposure of Sensitive Information to an Unauthorized Actor vulnerability in CodePeople Contact Form Email.This issue affects Contact Form Email: from n/a through 1.3.44.

    Published: 10 Apr 2024
    5.3
    Medium

    CVE-2024-31353

    Last Modified: 28 Apr 2026

    Insertion of Sensitive Information into Log File vulnerability in Tribulant Slideshow Gallery.This issue affects Slideshow Gallery: from n/a through 1.7.8.

    Published: 10 Apr 2024
    4.7
    Medium

    CVE-2024-31253

    Last Modified: 28 Apr 2026

    URL Redirection to Untrusted Site ('Open Redirect') vulnerability in WP OAuth Server OAuth Server.This issue affects OAuth Server: from n/a through 4.3.3.

    Published: 10 Apr 2024
    4.7
    Medium

    CVE-2024-31282

    Last Modified: 28 Apr 2026

    URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Appcheap.Io App Builder.This issue affects App Builder: from n/a through 3.8.7.

    Published: 10 Apr 2024
    9.8
    Critical

    CVE-2024-3566

    Last Modified: 15 May 2026

    A command inject vulnerability allows an attacker to perform command injection on Windows applications that indirectly depend on the CreateProcess function when the specific conditions are satisfied.

    Published: 10 Apr 2024
    8.5
    High

    CVE-2024-24809

    Last Modified: 15 Apr 2026

    Traccar is an open source GPS tracking system. Versions prior to 6.0 are vulnerable to path traversal and unrestricted upload of file with dangerous type. Since the system allows registration by default, attackers can acquire ordinary user permissions by registering an account and exploit this vulnerability to upload files with the prefix `device.` under any folder. Attackers can use this vulnerability for phishing, cross-site scripting attacks, and potentially execute arbitrary commands on the server. Version 6.0 contains a patch for the issue.

    Published: 10 Apr 2024
    5
    Medium

    CVE-2024-3448

    Last Modified: 15 Apr 2026

    Users with low privileges can perform certain AJAX actions. In this vulnerability instance, improper access to ajax?action=plugin:focus:checkIframeAvailability leads to a Server-Side Request Forgery by analyzing the error messages returned from the back-end. Allowing an attacker to perform a port scan in the back-end. At the time of publication of the CVE no patch is available.

    Published: 10 Apr 2024
    5.4
    Medium

    CVE-2024-2731

    Last Modified: 15 Apr 2026

    Users with low privileges (all permissions deselected in the administrator permissions settings) can view certain pages that expose sensitive information such as company names, users' names and surnames, stage names, and monitoring campaigns and their descriptions. In addition, unprivileged users can see and edit the descriptions of tags. At the time of publication of the CVE no patch is available.

    Published: 10 Apr 2024
    5.3
    Medium

    CVE-2024-2730

    Last Modified: 15 Apr 2026

    Mautic uses predictable page indices for unpublished landing pages, their content can be accessed by unauthenticated users under public preview URLs which could expose sensitive data. At the time of publication of the CVE no patch is available

    Published: 10 Apr 2024
    8.2
    High

    CVE-2024-31492

    Last Modified: 23 Jan 2025

    An external control of file name or path vulnerability [CWE-73] in FortiClientMac version 7.2.3 and below, version 7.0.10 and below installer may allow a local attacker to execute arbitrary code or commands via writing a malicious configuration file in /tmp before starting the installation process.

    Published: 10 Apr 2024
    9.1
    Critical

    CVE-2024-1740

    Last Modified: 10 Jan 2025

    In lunary-ai/lunary version 1.0.1, a vulnerability exists where a user removed from an organization can still read, create, modify, and delete logs by re-using an old authorization token. The lunary web application communicates with the server using an 'Authorization' token in the browser, which does not properly invalidate upon the user's removal from the organization. This allows the removed user to perform unauthorized actions on logs and access project and external user details without valid permissions.

    Published: 10 Apr 2024
    9.1
    Critical

    CVE-2024-1741

    Last Modified: 31 Jan 2025

    lunary-ai/lunary version 1.0.1 is vulnerable to improper authorization, allowing removed members to read, create, modify, and delete prompt templates using an old authorization token. Despite being removed from an organization, these members can still perform operations on prompt templates by sending HTTP requests with their previously captured authorization token. This issue exposes organizations to unauthorized access and manipulation of sensitive template data.

    Published: 10 Apr 2024
    6.1
    Medium

    CVE-2024-1602

    Last Modified: 9 Jul 2025

    parisneo/lollms-webui is vulnerable to stored Cross-Site Scripting (XSS) that leads to Remote Code Execution (RCE). The vulnerability arises due to inadequate sanitization and validation of model output data, allowing an attacker to inject malicious JavaScript code. This code can be executed within the user's browser context, enabling the attacker to send a request to the `/execute_code` endpoint and establish a reverse shell to the attacker's host. The issue affects various components of the application, including the handling of user input and model output.

    Published: 10 Apr 2024
    9.8
    Critical

    CVE-2024-1520

    Last Modified: 9 Jul 2025

    An OS Command Injection vulnerability exists in the '/open_code_folder' endpoint of the parisneo/lollms-webui application, due to improper validation of user-supplied input in the 'discussion_id' parameter. Attackers can exploit this vulnerability by injecting malicious OS commands, leading to unauthorized command execution on the underlying operating system. This could result in unauthorized access, data leakage, or complete system compromise.

    Published: 10 Apr 2024
    9.8
    Critical

    CVE-2024-1511

    Last Modified: 9 Jul 2025

    The parisneo/lollms-webui repository is susceptible to a path traversal vulnerability due to inadequate validation of user-supplied file paths. This flaw allows an unauthenticated attacker to read, write, and in certain configurations execute arbitrary files on the server by exploiting various endpoints. The vulnerability can be exploited even when the service is bound to localhost, through cross-site requests facilitated by malicious HTML/JS pages.

    Published: 10 Apr 2024
    —
    Unknown

    CVE-2024-1599

    Last Modified: 7 Jun 2024

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

    Published: 10 Apr 2024
    9.3
    Critical

    CVE-2024-1600

    Last Modified: 9 Jul 2025

    A Local File Inclusion (LFI) vulnerability exists in the parisneo/lollms-webui application, specifically within the `/personalities` route. An attacker can exploit this vulnerability by crafting a URL that includes directory traversal sequences (`../../`) followed by the desired system file path, URL encoded. Successful exploitation allows the attacker to read any file on the filesystem accessible by the web server. This issue arises due to improper control of filename for include/require statement in the application.

    Published: 10 Apr 2024
    7.5
    High

    CVE-2024-1728

    Last Modified: 30 Jul 2025

    gradio-app/gradio is vulnerable to a local file inclusion vulnerability due to improper validation of user-supplied input in the UploadButton component. Attackers can exploit this vulnerability to read arbitrary files on the filesystem, such as private SSH keys, by manipulating the file path in the request to the `/queue/join` endpoint. This issue could potentially lead to remote code execution. The vulnerability is present in the handling of file upload paths, allowing attackers to redirect file uploads to unintended locations on the server.

    Published: 10 Apr 2024
    6.5
    Medium

    CVE-2024-1625

    Last Modified: 30 Jan 2025

    An Insecure Direct Object Reference (IDOR) vulnerability exists in the lunary-ai/lunary application version 0.3.0, allowing unauthorized deletion of any organization's project. The vulnerability is due to insufficient authorization checks in the project deletion endpoint, where the endpoint fails to verify if the project ID provided in the request belongs to the requesting user's organization. As a result, an attacker can delete projects belonging to any organization by sending a crafted DELETE request with the target project's ID. This issue affects the project deletion functionality implemented in the projects.delete route.

    Published: 10 Apr 2024
    7.8
    High

    CVE-2024-20772

    Last Modified: 5 Dec 2024

    Media Encoder versions 24.2.1, 23.6.4 and earlier are affected by a Stack-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 10 Apr 2024