CVE Feed

    Dashboard / CVE

    6.5
    Medium

    CVE-2024-30445

    Last Modified: 28 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in GhozyLab, Inc. Web Icons allows Stored XSS.This issue affects Web Icons: from n/a through 1.0.0.10.

    Published: 29 Mar 2024
    6.5
    Medium

    CVE-2024-30446

    Last Modified: 28 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CRM Perks CRM Perks Forms allows Stored XSS.This issue affects CRM Perks Forms: from n/a through 1.1.4.

    Published: 29 Mar 2024
    7.1
    High

    CVE-2024-30447

    Last Modified: 28 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Creative Solutions Creative Image Slider – Responsive Slider Plugin allows Reflected XSS.This issue affects Creative Image Slider – Responsive Slider Plugin: from n/a through 2.1.3.

    Published: 29 Mar 2024
    5.9
    Medium

    CVE-2024-30448

    Last Modified: 28 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Supsystic Slider by Supsystic allows Stored XSS.This issue affects Slider by Supsystic: from n/a through 1.8.10.

    Published: 29 Mar 2024
    7.1
    High

    CVE-2024-30449

    Last Modified: 28 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Booking Activities Team Booking Activities allows Reflected XSS.This issue affects Booking Activities: from n/a through 1.15.19.

    Published: 29 Mar 2024
    6.5
    Medium

    CVE-2024-30450

    Last Modified: 28 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Step-Byte-Service GmbH OpenStreetMap for Gutenberg and WPBakery Page Builder (formerly Visual Composer) allows Stored XSS.This issue affects OpenStreetMap for Gutenberg and WPBakery Page Builder (formerly Visual Composer): from n/a through 1.1.1.

    Published: 29 Mar 2024
    6.5
    Medium

    CVE-2024-30451

    Last Modified: 28 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in INFINITUM FORM Geo Controller allows Stored XSS.This issue affects Geo Controller: from n/a through 8.6.4.

    Published: 29 Mar 2024
    5.9
    Medium

    CVE-2024-30452

    Last Modified: 28 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PluginOps Landing Page Builder allows Stored XSS.This issue affects Landing Page Builder: from n/a through 1.5.1.7.

    Published: 29 Mar 2024
    5.4
    Medium

    CVE-2024-30453

    Last Modified: 28 Apr 2026

    Server-Side Request Forgery (SSRF) vulnerability in Brave Brave Popup Builder.This issue affects Brave Popup Builder: from n/a through 0.6.5.

    Published: 29 Mar 2024
    4.3
    Medium

    CVE-2024-30455

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in GamiPress.This issue affects GamiPress: from n/a through 6.8.5.

    Published: 29 Mar 2024
    4.3
    Medium

    CVE-2024-30460

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Tumult Inc Tumult Hype Animations.This issue affects Tumult Hype Animations: from n/a through 1.9.11.

    Published: 29 Mar 2024
    4.3
    Medium

    CVE-2024-30454

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in VeronaLabs WP SMS.This issue affects WP SMS: from n/a through 6.6.2.

    Published: 29 Mar 2024
    5.7
    Medium

    CVE-2024-25944

    Last Modified: 4 Feb 2025

    Dell OpenManage Enterprise, v4.0 and prior, contain(s) a path traversal vulnerability. An unauthenticated remote attacker could potentially exploit this vulnerability, to gain unauthorized access to the files stored on the server filesystem, with the privileges of the running web application.

    Published: 29 Mar 2024
    4.3
    Medium

    CVE-2024-30462

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in realmag777 HUSKY – Products Filter for WooCommerce (formerly WOOF).This issue affects HUSKY – Products Filter for WooCommerce (formerly WOOF): from n/a through 1.3.5.1.

    Published: 29 Mar 2024
    4.3
    Medium

    CVE-2024-30463

    Last Modified: 28 Apr 2026

    Missing Authorization vulnerability in realmag777 BEAR.This issue affects BEAR: from n/a through 1.1.4.3.

    Published: 29 Mar 2024
    4.3
    Medium

    CVE-2024-30468

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in All In One WP Security & Firewall Team All In One WP Security & Firewall.This issue affects All In One WP Security & Firewall: from n/a through 5.2.6.

    Published: 29 Mar 2024
    5.3
    Medium

    CVE-2024-30477

    Last Modified: 28 Apr 2026

    Missing Authorization vulnerability in Klarna Klarna Payments for WooCommerce.This issue affects Klarna Payments for WooCommerce: from n/a through 3.2.4.

    Published: 29 Mar 2024
    4.3
    Medium

    CVE-2024-30482

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Brice CAPOBIANCO Simple Revisions Delete.This issue affects Simple Revisions Delete: from n/a through 1.5.3.

    Published: 29 Mar 2024
    10
    Critical

    CVE-2024-30247

    Last Modified: 7 May 2025

    NextcloudPi is a ready to use image for Virtual Machines, Raspberry Pi, Odroid HC1, Rock64 and other boards. A command injection vulnerability in NextCloudPi allows command execution as the root user via the NextCloudPi web-panel. Due to a security misconfiguration this can be used by anyone with access to NextCloudPi web-panel, no authentication is required. It is recommended that the NextCloudPi is upgraded to 1.53.1.

    Published: 29 Mar 2024
    4.3
    Medium

    CVE-2024-30518

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in ThemeLocation Custom WooCommerce Checkout Fields Editor.This issue affects Custom WooCommerce Checkout Fields Editor: from n/a through 1.3.0.

    Published: 29 Mar 2024
    5.4
    Medium

    CVE-2024-30521

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Landingi Landingi Landing Pages.This issue affects Landingi Landing Pages: from n/a through 3.1.1.

    Published: 29 Mar 2024
    7.6
    High

    CVE-2024-30246

    Last Modified: 10 Jul 2025

    Tuleap is an Open Source Suite to improve management of software developments and collaboration. A malicious user could exploit this issue on purpose to delete information on the instance or possibly gain access to restricted artifacts. It is however not possible to control exactly which information is deleted. Information from theDate, File, Float, Int, List, OpenList, Text, and Permissions on artifact (this one can lead to the disclosure of restricted information) fields can be impacted. This vulnerability is fixed in Tuleap Community Edition version 15.7.99.6 and Tuleap Enterprise Edition 15.7-2, 15.6-5, 15.5-6, 15.4-8, 15.3-6, 15.2-5, 15.1-9, 15.0-9, and 14.12-6.

    Published: 29 Mar 2024
    6.5
    Medium

    CVE-2024-30513

    Last Modified: 28 Apr 2026

    Authorization Bypass Through User-Controlled Key vulnerability in Metagauss ProfileGrid.This issue affects ProfileGrid : from n/a through 5.7.2.

    Published: 29 Mar 2024
    5.3
    Medium

    CVE-2024-30469

    Last Modified: 28 Apr 2026

    Missing Authorization vulnerability in WPExperts Wholesale For WooCommerce.This issue affects Wholesale For WooCommerce: from n/a through 2.3.0.

    Published: 29 Mar 2024
    5.3
    Medium

    CVE-2024-30511

    Last Modified: 28 Apr 2026

    Insertion of Sensitive Information into Log File vulnerability in Frédéric GILLES FG PrestaShop to WooCommerce.This issue affects FG PrestaShop to WooCommerce: from n/a through 4.45.1.

    Published: 29 Mar 2024
    5.3
    Medium

    CVE-2024-30514

    Last Modified: 28 Apr 2026

    Insertion of Sensitive Information into Log File vulnerability in Paid Memberships Pro Paid Memberships Pro – Payfast Gateway Add On.This issue affects Paid Memberships Pro – Payfast Gateway Add On: from n/a through 1.4.1.

    Published: 29 Mar 2024
    4.3
    Medium

    CVE-2024-30492

    Last Modified: 28 Apr 2026

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in WebToffee Import Export WordPress Users.This issue affects Import Export WordPress Users: from n/a through 2.5.2.

    Published: 29 Mar 2024
    7.5
    High

    CVE-2024-29904

    Last Modified: 7 May 2025

    CodeIgniter is a PHP full-stack web framework A vulnerability was found in the Language class that allowed DoS attacks. This vulnerability can be exploited by an attacker to consume a large amount of memory on the server. Upgrade to v4.4.7 or later.

    Published: 29 Mar 2024
    4.8
    Medium

    CVE-2024-29901

    Last Modified: 11 Dec 2025

    The AuthKit library for Next.js provides helpers for authentication and session management using WorkOS & AuthKit with Next.js. A user can reuse an expired session by controlling the `x-workos-session` header. The vulnerability is patched in v0.4.2.

    Published: 29 Mar 2024
    7.5
    High

    CVE-2024-29900

    Last Modified: 7 May 2025

    Electron Packager bundles Electron-based application source code with a renamed Electron executable and supporting files into folders ready for distribution. A random segment of ~1-10kb of Node.js heap memory allocated either side of a known buffer will be leaked into the final executable. This memory _could_ contain sensitive information such as environment variables, secrets files, etc. This issue is patched in 18.3.1.

    Published: 29 Mar 2024
    8.8
    High

    CVE-2024-29890

    Last Modified: 15 Apr 2026

    DataLens is a business intelligence and data visualization system. A specifically crafted request allowed the creation of a special chart type with the ability to pass custom javascript code that would later be executed in an unprotected sandbox on subsequent requests to that chart. The problem was fixed in the datalens-ui version `0.1449.0`. Restricting access to the API for creating or modifying charts (`/charts/api/charts/v1/`) would mitigate the issue.

    Published: 29 Mar 2024
    9.9
    Critical

    CVE-2024-29202

    Last Modified: 25 Mar 2025

    JumpServer is an open source bastion host and an operation and maintenance security audit system. Attackers can exploit a Jinja2 template injection vulnerability in JumpServer's Ansible to execute arbitrary code within the Celery container. Since the Celery container runs with root privileges and has database access, attackers could steal sensitive information from all hosts or manipulate the database. This vulnerability is fixed in v3.10.7.

    Published: 29 Mar 2024
    9.9
    Critical

    CVE-2024-29201

    Last Modified: 25 Mar 2025

    JumpServer is an open source bastion host and an operation and maintenance security audit system. Attackers can bypass the input validation mechanism in JumpServer's Ansible to execute arbitrary code within the Celery container. Since the Celery container runs with root privileges and has database access, attackers could steal sensitive information from all hosts or manipulate the database. This vulnerability is fixed in v3.10.7.

    Published: 29 Mar 2024
    4.6
    Medium

    CVE-2024-29020

    Last Modified: 9 Jan 2025

    JumpServer is an open source bastion host and an operation and maintenance security audit system. An authorized attacker can obtain sensitive information contained within playbook files if they manage to learn the playbook_id of another user. This breach of confidentiality can lead to information disclosure and exposing sensitive data. This vulnerability is fixed in v3.10.6.

    Published: 29 Mar 2024
    4.6
    Medium

    CVE-2024-29024

    Last Modified: 9 Jan 2025

    JumpServer is an open source bastion host and an operation and maintenance security audit system. An authenticated user can exploit the Insecure Direct Object Reference (IDOR) vulnerability in the file manager's bulk transfer by manipulating job IDs to upload malicious files, potentially compromising the integrity and security of the system. This vulnerability is fixed in v3.10.6.

    Published: 29 Mar 2024
    8.4
    High

    CVE-2024-23537

    Last Modified: 13 Feb 2025

    Improper Privilege Management vulnerability in Apache Fineract.This issue affects Apache Fineract: <1.8.5. Users are recommended to upgrade to version 1.9.0, which fixes the issue.

    Published: 29 Mar 2024
    9.9
    Critical

    CVE-2024-23538

    Last Modified: 13 Feb 2025

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Fineract.This issue affects Apache Fineract: <1.8.5. Users are recommended to upgrade to version 1.8.5 or 1.9.0, which fix the issue.

    Published: 29 Mar 2024
    8.3
    High

    CVE-2024-23539

    Last Modified: 13 Feb 2025

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Fineract.This issue affects Apache Fineract: <1.8.5. Users are recommended to upgrade to version 1.8.5 or 1.9.0, which fix the issue.

    Published: 29 Mar 2024
    3.5
    Low

    CVE-2024-3081

    Last Modified: 29 Apr 2025

    A vulnerability was found in EasyCorp EasyAdmin up to 4.8.9. It has been declared as problematic. Affected by this vulnerability is the function Autocomplete of the file assets/js/autocomplete.js of the component Autocomplete. The manipulation of the argument item leads to cross site scripting. The attack can be launched remotely. Upgrading to version 4.8.10 is able to address this issue. The identifier of the patch is 127436e4c3f56276d548070f99e61b7234200a11. It is recommended to upgrade the affected component. The identifier VDB-258613 was assigned to this vulnerability.

    Published: 29 Mar 2024
    5.9
    Medium

    CVE-2024-28867

    Last Modified: 13 Jan 2026

    Swift Prometheus is a Swift client for the Prometheus monitoring system, supporting counters, gauges and histograms. In code which applies _un-sanitized string values into metric names or labels_, an attacker could make use of this and send a `?lang` query parameter containing newlines, `}` or similar characters which can lead to the attacker taking over the exported format -- including creating unbounded numbers of stored metrics, inflating server memory usage, or causing "bogus" metrics. This vulnerability is fixed in2.0.0-alpha.2.

    Published: 29 Mar 2024
    6.5
    Medium

    CVE-2024-30508

    Last Modified: 28 Apr 2026

    Missing Authorization vulnerability in ThimPress WP Hotel Booking.This issue affects WP Hotel Booking: from n/a through 2.0.9.2.

    Published: 29 Mar 2024
    2.7
    Low

    CVE-2024-30507

    Last Modified: 28 Apr 2026

    Authorization Bypass Through User-Controlled Key vulnerability in Molongui.This issue affects Molongui: from n/a through 4.7.7.

    Published: 29 Mar 2024
    7.1
    High

    CVE-2024-30506

    Last Modified: 28 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Vsourz Digital All In One Redirection allows Stored XSS.This issue affects All In One Redirection: from n/a through 2.2.0.

    Published: 29 Mar 2024
    6.5
    Medium

    CVE-2024-30505

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in andy_moyle Church Admin church-admin.This issue affects Church Admin: from n/a through <= 4.1.18.

    Published: 29 Mar 2024
    7.6
    High

    CVE-2024-30504

    Last Modified: 28 Apr 2026

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WP Travel Engine.This issue affects WP Travel Engine: from n/a through 5.7.9.

    Published: 29 Mar 2024
    9.3
    Critical

    CVE-2024-30502

    Last Modified: 28 Apr 2026

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WP Travel Engine.This issue affects WP Travel Engine: from n/a through 5.7.9.

    Published: 29 Mar 2024
    7.6
    High

    CVE-2024-30501

    Last Modified: 28 Apr 2026

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WPChill Download Monitor.This issue affects Download Monitor: from n/a through 4.9.4.

    Published: 29 Mar 2024
    8.5
    High

    CVE-2024-30499

    Last Modified: 28 Apr 2026

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in CRM Perks CRM Perks Forms.This issue affects CRM Perks Forms: from n/a through 1.1.4.

    Published: 29 Mar 2024
    9.3
    Critical

    CVE-2024-30498

    Last Modified: 28 Apr 2026

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in CRM Perks CRM Perks Forms.This issue affects CRM Perks Forms: from n/a through 1.1.4.

    Published: 29 Mar 2024
    8.5
    High

    CVE-2024-30497

    Last Modified: 28 Apr 2026

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in I Thirteen Web Solution WP Responsive Tabs horizontal vertical and accordion Tabs.This issue affects WP Responsive Tabs horizontal vertical and accordion Tabs: from n/a through 1.1.17.

    Published: 29 Mar 2024