CVE Feed

    Dashboard / CVE

    7.8
    High

    CVE-2024-24245

    Last Modified: 13 May 2025

    An issue in Canimaan Software LTD ClamXAV v3.1.2 through v3.6.1 and fixed in v.3.6.2 allows a local attacker to escalate privileges via the ClamXAV helper tool component.

    Published: 9 Apr 2024
    —
    Unknown

    CVE-2024-30681

    Last Modified: 27 May 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that there was not reasonable evidence to determine the existence of a vulnerability.

    Published: 9 Apr 2024
    —
    Unknown

    CVE-2024-30683

    Last Modified: 27 May 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that there was not reasonable evidence to determine the existence of a vulnerability.

    Published: 9 Apr 2024
    7.8
    High

    CVE-2024-26256

    Last Modified: 3 May 2025

    Libarchive Remote Code Execution Vulnerability

    Published: 9 Apr 2024
    —
    Unknown

    CVE-2024-30684

    Last Modified: 27 May 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that there was not reasonable evidence to determine the existence of a vulnerability.

    Published: 9 Apr 2024
    —
    Unknown

    CVE-2024-30686

    Last Modified: 27 May 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that there was not reasonable evidence to determine the existence of a vulnerability.

    Published: 9 Apr 2024
    —
    Unknown

    CVE-2024-30687

    Last Modified: 27 May 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that there was not reasonable evidence to determine the existence of a vulnerability.

    Published: 9 Apr 2024
    —
    Unknown

    CVE-2024-30688

    Last Modified: 27 May 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that there was not reasonable evidence to determine the existence of a vulnerability.

    Published: 9 Apr 2024
    —
    Unknown

    CVE-2024-30690

    Last Modified: 27 May 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that there was not reasonable evidence to determine the existence of a vulnerability.

    Published: 9 Apr 2024
    —
    Unknown

    CVE-2024-30691

    Last Modified: 27 May 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that there was not reasonable evidence to determine the existence of a vulnerability.

    Published: 9 Apr 2024
    —
    Unknown

    CVE-2024-30692

    Last Modified: 27 May 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that there was not reasonable evidence to determine the existence of a vulnerability.

    Published: 9 Apr 2024
    5.4
    Medium

    CVE-2024-27665

    Last Modified: 15 Apr 2026

    Unifiedtransform v2.X is vulnerable to Stored Cross-Site Scripting (XSS) via file upload feature in Syllabus module.

    Published: 9 Apr 2024
    —
    Unknown

    CVE-2024-30694

    Last Modified: 27 May 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that there was not reasonable evidence to determine the existence of a vulnerability.

    Published: 9 Apr 2024
    —
    Unknown

    CVE-2024-30695

    Last Modified: 27 May 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that there was not reasonable evidence to determine the existence of a vulnerability.

    Published: 9 Apr 2024
    —
    Unknown

    CVE-2024-30696

    Last Modified: 27 May 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that there was not reasonable evidence to determine the existence of a vulnerability.

    Published: 9 Apr 2024
    8.1
    High

    CVE-2024-27980

    Last Modified: 15 Apr 2026

    Due to the improper handling of batch files in child_process.spawn / child_process.spawnSync, a malicious command line argument can inject arbitrary commands and achieve code execution even if the shell option is not enabled.

    Published: 9 Apr 2024
    —
    Unknown

    CVE-2024-30697

    Last Modified: 27 May 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that there was not reasonable evidence to determine the existence of a vulnerability.

    Published: 9 Apr 2024
    —
    Unknown

    CVE-2024-30699

    Last Modified: 27 May 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that there was not reasonable evidence to determine the existence of a vulnerability.

    Published: 9 Apr 2024
    —
    Unknown

    CVE-2024-30676

    Last Modified: 27 May 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that there was not reasonable evidence to determine the existence of a vulnerability.

    Published: 9 Apr 2024
    —
    Unknown

    CVE-2024-30678

    Last Modified: 27 May 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that there was not reasonable evidence to determine the existence of a vulnerability.

    Published: 9 Apr 2024
    —
    Unknown

    CVE-2024-30679

    Last Modified: 27 May 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that there was not reasonable evidence to determine the existence of a vulnerability.

    Published: 9 Apr 2024
    —
    Unknown

    CVE-2024-30680

    Last Modified: 27 May 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that there was not reasonable evidence to determine the existence of a vulnerability.

    Published: 9 Apr 2024
    —
    Unknown

    CVE-2024-30701

    Last Modified: 27 May 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that there was not reasonable evidence to determine the existence of a vulnerability.

    Published: 9 Apr 2024
    —
    Unknown

    CVE-2024-30702

    Last Modified: 27 May 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that there was not reasonable evidence to determine the existence of a vulnerability.

    Published: 9 Apr 2024
    —
    Unknown

    CVE-2024-30703

    Last Modified: 27 May 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that there was not reasonable evidence to determine the existence of a vulnerability.

    Published: 9 Apr 2024
    —
    Unknown

    CVE-2024-30704

    Last Modified: 27 May 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that there was not reasonable evidence to determine the existence of a vulnerability.

    Published: 9 Apr 2024
    —
    Unknown

    CVE-2024-30706

    Last Modified: 27 May 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that there was not reasonable evidence to determine the existence of a vulnerability.

    Published: 9 Apr 2024
    6.6
    Medium

    CVE-2024-23584

    Last Modified: 15 Apr 2026

    The NMAP Importer service​ may expose data store credentials to authorized users of the Windows Registry.

    Published: 8 Apr 2024
    6.5
    Medium

    CVE-2024-0083

    Last Modified: 18 Sept 2025

    NVIDIA ChatRTX for Windows contains a vulnerability in the UI, where an attacker can cause a cross-site scripting error by network by running malicious scripts in users' browsers. A successful exploit of this vulnerability might lead to code execution, denial of service, and information disclosure.

    Published: 8 Apr 2024
    8.2
    High

    CVE-2024-0082

    Last Modified: 18 Sept 2025

    NVIDIA ChatRTX for Windows contains a vulnerability in the UI, where an attacker can cause improper privilege management by sending open file requests to the application. A successful exploit of this vulnerability might lead to local escalation of privileges, information disclosure, and data tampering

    Published: 8 Apr 2024
    5.5
    Medium

    CVE-2024-3466

    Last Modified: 16 Jan 2025

    A vulnerability was found in SourceCodester Laundry Management System 1.0. It has been declared as critical. Affected by this vulnerability is the function laporan_filter of the file /application/controller/Pengeluaran.php. The manipulation of the argument dari/sampai leads to sql injection. The associated identifier of this vulnerability is VDB-259747.

    Published: 8 Apr 2024
    6.3
    Medium

    CVE-2024-3465

    Last Modified: 17 Jan 2025

    A vulnerability was found in SourceCodester Laundry Management System 1.0. It has been classified as critical. Affected is the function laporan_filter of the file /application/controller/Transaki.php. The manipulation of the argument dari/sampai leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-259746 is the identifier assigned to this vulnerability.

    Published: 8 Apr 2024
    6.3
    Medium

    CVE-2024-3464

    Last Modified: 17 Jan 2025

    A vulnerability was found in SourceCodester Laundry Management System 1.0 and classified as critical. This issue affects the function laporan_filter of the file /application/controller/Pelanggan.php. The manipulation of the argument jeniskelamin leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-259745 was assigned to this vulnerability.

    Published: 8 Apr 2024
    3.5
    Low

    CVE-2024-3463

    Last Modified: 14 Jan 2025

    A vulnerability has been found in SourceCodester Laundry Management System 1.0 and classified as problematic. This vulnerability affects unknown code of the file /karyawan/edit. The manipulation of the argument karyawan leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-259744.

    Published: 8 Apr 2024
    6.3
    Medium

    CVE-2024-3458

    Last Modified: 6 Feb 2025

    A vulnerability classified as critical was found in Netentsec NS-ASG Application Security Gateway 6.3. This vulnerability affects unknown code of the file /admin/add_ikev2.php. The manipulation of the argument TunnelId leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-259714 is the identifier assigned to this vulnerability.

    Published: 8 Apr 2024
    6.3
    Medium

    CVE-2024-3457

    Last Modified: 6 Feb 2025

    A vulnerability classified as critical has been found in Netentsec NS-ASG Application Security Gateway 6.3. This affects an unknown part of the file /admin/config_ISCGroupNoCache.php. The manipulation of the argument GroupId leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-259713 was assigned to this vulnerability.

    Published: 8 Apr 2024
    7.5
    High

    CVE-2023-7164

    Last Modified: 11 Apr 2025

    The BackWPup WordPress plugin before 4.0.4 does not prevent Directory Listing in its temporary backup folder, allowing unauthenticated attackers to download backups of a site's database.

    Published: 8 Apr 2024
    6.3
    Medium

    CVE-2024-3456

    Last Modified: 7 Feb 2025

    A vulnerability was found in Netentsec NS-ASG Application Security Gateway 6.3. It has been rated as critical. Affected by this issue is some unknown functionality of the file /admin/config_Anticrack.php. The manipulation of the argument GroupId leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-259712.

    Published: 8 Apr 2024
    5.3
    Medium

    CVE-2024-31447

    Last Modified: 10 Sept 2025

    Shopware 6 is an open commerce platform based on Symfony Framework and Vue. Starting in version 6.3.5.0 and prior to versions 6.6.1.0 and 6.5.8.8, when a authenticated request is made to `POST /store-api/account/logout`, the cart will be cleared, but the User won't be logged out. This affects only the direct store-api usage, as the PHP Storefront listens additionally on `CustomerLogoutEvent` and invalidates the session additionally. The problem has been fixed in Shopware 6.6.1.0 and 6.5.8.8. Those who are unable to update can install the latest version of the Shopware Security Plugin as a workaround.

    Published: 8 Apr 2024
    8.8
    High

    CVE-2024-31442

    Last Modified: 7 Jan 2026

    Redon Hub is a Roblox Product Delivery Bot, also known as a Hub. In all hubs before version 1.0.2, all commands are capable of being ran by all users, including admin commands. This allows users to receive products for free and delete/create/update products/tags/etc. The only non-affected command is `/products admin clear` as this was already programmed for bot owners only. All users should upgrade to version 1.0.2 to receive a patch.

    Published: 8 Apr 2024
    6.3
    Medium

    CVE-2024-3455

    Last Modified: 7 Feb 2025

    A vulnerability was found in Netentsec NS-ASG Application Security Gateway 6.3. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /admin/add_postlogin.php. The manipulation of the argument SingleLoginId leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-259711.

    Published: 8 Apr 2024
    6.3
    Medium

    CVE-2024-3445

    Last Modified: 17 Jan 2025

    A vulnerability was found in SourceCodester Laundry Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /karyawan/laporan_filter. The manipulation of the argument data_karyawan leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-259702 is the identifier assigned to this vulnerability.

    Published: 8 Apr 2024
    9.8
    Critical

    CVE-2024-31224

    Last Modified: 4 Nov 2025

    GPT Academic provides interactive interfaces for large language models. A vulnerability was found in gpt_academic versions 3.64 through 3.73. The server deserializes untrustworthy data from the client, which may risk remote code execution. Any device that exposes the GPT Academic service to the Internet is vulnerable. Version 3.74 contains a patch for the issue. There are no known workarounds aside from upgrading to a patched version.

    Published: 8 Apr 2024
    5.9
    Medium

    CVE-2024-31221

    Last Modified: 11 Sept 2025

    Sunshine is a self-hosted game stream host for Moonlight. Starting in version 0.10.0 and prior to version 0.23.0, after unpairing all devices in the web UI interface and then pairing only one device, all of the previously devices will be temporarily paired. Version 0.23.0 contains a patch for the issue. As a workaround, restarting Sunshine after unpairing all devices prevents the vulnerability.

    Published: 8 Apr 2024
    4.7
    Medium

    CVE-2024-3444

    Last Modified: 15 Apr 2026

    A vulnerability was found in Wangshen SecGate 3600 up to 20240408. It has been classified as critical. This affects an unknown part of the file /?g=net_pro_keyword_import_save. The manipulation of the argument reqfile leads to unrestricted upload. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-259701 was assigned to this vulnerability.

    Published: 8 Apr 2024
    3.5
    Low

    CVE-2024-3443

    Last Modified: 10 Feb 2025

    A vulnerability classified as problematic was found in SourceCodester Prison Management System 1.0. This vulnerability affects unknown code of the file /Employee/apply_leave.php. The manipulation of the argument txtstart_date/txtend_date leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-259696.

    Published: 8 Apr 2024
    6.3
    Medium

    CVE-2024-3442

    Last Modified: 10 Feb 2025

    A vulnerability classified as critical has been found in SourceCodester Prison Management System 1.0. This affects an unknown part of the file /Employee/delete_leave.php. The manipulation leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-259695.

    Published: 8 Apr 2024
    4.2
    Medium

    CVE-2024-31205

    Last Modified: 7 Jan 2026

    Saleor is an e-commerce platform. Starting in version 3.10.0 and prior to versions 3.14.64, 3.15.39, 3.16.39, 3.17.35, 3.18.31, and 3.19.19, an attacker may bypass cross-set request forgery (CSRF) validation when calling refresh token mutation with empty string. When a user provides an empty string in `refreshToken` mutation, while the token persists in `JWT_REFRESH_TOKEN_COOKIE_NAME` cookie, application omits validation against CSRF token and returns valid access token. Versions 3.14.64, 3.15.39, 3.16.39, 3.17.35, 3.18.31, and 3.19.19 contain a patch for the issue. As a workaround, one may replace `saleor.graphql.account.mutations.authentication.refresh_token.py.get_refresh_token`. This will fix the issue, but be aware, that it returns `JWT_MISSING_TOKEN` instead of `JWT_INVALID_TOKEN`.

    Published: 8 Apr 2024
    5.3
    Medium

    CVE-2024-30269

    Last Modified: 12 Feb 2025

    DataEase, an open source data visualization and analysis tool, has a database configuration information exposure vulnerability prior to version 2.5.0. Visiting the `/de2api/engine/getEngine;.js` path via a browser reveals that the platform's database configuration is returned. The vulnerability has been fixed in v2.5.0. No known workarounds are available aside from upgrading.

    Published: 8 Apr 2024
    6.3
    Medium

    CVE-2024-3441

    Last Modified: 10 Feb 2025

    A vulnerability was found in SourceCodester Prison Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /Employee/edit-profile.php. The manipulation leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-259694 is the identifier assigned to this vulnerability.

    Published: 8 Apr 2024