CVE Feed

    Dashboard / CVE

    6.3
    Medium

    CVE-2024-2812

    Last Modified: 21 Nov 2024

    A vulnerability was found in Tenda AC15 15.03.05.18/15.03.20_multi. It has been classified as critical. This affects the function formWriteFacMac of the file /goform/WriteFacMac. The manipulation of the argument mac leads to os command injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-257667. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 22 Mar 2024
    3.8
    Low

    CVE-2024-1742

    Last Modified: 4 Dec 2024

    Invocation of the sqlplus command with sensitive information in the command line in the mk_oracle Checkmk agent plugin before Checkmk 2.3.0b4 (beta), 2.2.0p24, 2.1.0p41 and 2.0.0 (EOL) allows the extraction of this information from the process list.

    Published: 22 Mar 2024
    8.2
    High

    CVE-2024-0638

    Last Modified: 4 Dec 2024

    Least privilege violation in the Checkmk agent plugins mk_oracle, mk_oracle.ps1, and mk_oracle_crs before Checkmk 2.3.0b4 (beta), 2.2.0p24, 2.1.0p41 and 2.0.0 (EOL) allows local users to escalate privileges.

    Published: 22 Mar 2024
    8.8
    High

    CVE-2024-2811

    Last Modified: 21 Nov 2024

    A vulnerability was found in Tenda AC15 15.03.20_multi and classified as critical. Affected by this issue is the function formWifiWpsStart of the file /goform/WifiWpsStart. The manipulation of the argument index leads to stack-based buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-257666 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 22 Mar 2024
    8.8
    High

    CVE-2024-2810

    Last Modified: 21 Nov 2024

    A vulnerability has been found in Tenda AC15 15.03.05.18/15.03.20_multi and classified as critical. Affected by this vulnerability is the function formWifiWpsOOB of the file /goform/WifiWpsOOB. The manipulation of the argument index leads to stack-based buffer overflow. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-257665 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 22 Mar 2024
    8.8
    High

    CVE-2024-2809

    Last Modified: 21 Nov 2024

    A vulnerability, which was classified as critical, was found in Tenda AC15 15.03.05.18/15.03.20_multi. Affected is the function formSetFirewallCfg of the file /goform/SetFirewallCfg. The manipulation of the argument firewallEn leads to stack-based buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-257664. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 22 Mar 2024
    8.8
    High

    CVE-2024-2808

    Last Modified: 21 Nov 2024

    A vulnerability, which was classified as critical, has been found in Tenda AC15 15.03.05.18/15.03.20_multi. This issue affects the function formQuickIndex of the file /goform/QuickIndex. The manipulation of the argument PPPOEPassword leads to stack-based buffer overflow. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-257663. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 22 Mar 2024
    8.8
    High

    CVE-2024-2807

    Last Modified: 10 Apr 2025

    A vulnerability classified as critical was found in Tenda AC15 15.03.05.18/15.03.20_multi. This vulnerability affects the function formExpandDlnaFile of the file /goform/expandDlnaFile. The manipulation of the argument filePath leads to stack-based buffer overflow. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-257662 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 22 Mar 2024
    8.8
    High

    CVE-2024-2806

    Last Modified: 21 Nov 2024

    A vulnerability classified as critical has been found in Tenda AC15 15.03.05.18/15.03.20_multi. This affects the function addWifiMacFilter of the file /goform/addWifiMacFilter. The manipulation of the argument deviceId/deviceMac leads to stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-257661 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 22 Mar 2024
    8.8
    High

    CVE-2024-2805

    Last Modified: 24 Jan 2025

    A vulnerability was found in Tenda AC15 15.03.05.18/15.03.20_multi. It has been rated as critical. Affected by this issue is the function formSetSpeedWan of the file /goform/SetSpeedWan. The manipulation of the argument speed_dir leads to stack-based buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-257660. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 22 Mar 2024
    6.1
    Medium

    CVE-2024-0957

    Last Modified: 8 Apr 2026

    The WooCommerce PDF Invoices, Packing Slips, Delivery Notes and Shipping Labels plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Customer Notes field in all versions up to, and including, 4.4.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected invoice for printing.

    Published: 22 Mar 2024
    6.4
    Medium

    CVE-2024-2392

    Last Modified: 8 Apr 2026

    The Blocksy Companion plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Newsletter widget in all versions up to, and including, 2.0.31 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 22 Mar 2024
    6.4
    Medium

    CVE-2024-2500

    Last Modified: 15 Apr 2026

    The ColorMag theme for WordPress is vulnerable to Stored Cross-Site Scripting via a user's Display Name in all versions up to, and including, 3.1.6 due to insufficient input sanitization and output escaping. This makes it possible for authentciated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 22 Mar 2024
    4.3
    Medium

    CVE-2024-2080

    Last Modified: 15 Apr 2026

    The LiquidPoll – Polls, Surveys, NPS and Feedback Reviews plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.3.76 via the poller_list shortcode. This makes it possible for authenticated attackers, with contributor-level access and above, to extract information from polls that may be private.

    Published: 22 Mar 2024
    3.5
    Low

    CVE-2024-2780

    Last Modified: 20 Feb 2025

    A vulnerability was found in Campcodes Online Marriage Registration System 1.0. It has been declared as problematic. This vulnerability affects unknown code of the file /admin/admin-profile.php. The manipulation of the argument adminname leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-257614 is the identifier assigned to this vulnerability.

    Published: 22 Mar 2024
    3.5
    Low

    CVE-2024-2779

    Last Modified: 20 Feb 2025

    A vulnerability was found in Campcodes Online Marriage Registration System 1.0. It has been classified as problematic. This affects an unknown part of the file /admin/application-bwdates-reports-details.php. The manipulation of the argument fromdate leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-257613 was assigned to this vulnerability.

    Published: 22 Mar 2024
    3.5
    Low

    CVE-2024-2778

    Last Modified: 20 Feb 2025

    A vulnerability was found in Campcodes Online Marriage Registration System 1.0 and classified as problematic. Affected by this issue is some unknown functionality of the file /admin/search.php. The manipulation of the argument searchdata leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-257612.

    Published: 22 Mar 2024
    5.3
    Medium

    CVE-2024-2777

    Last Modified: 30 Sept 2025

    A vulnerability has been found in Campcodes/PHPGurukul Online Marriage Registration System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /admin/application-bwdates-reports-details.php. The manipulation of the argument fromdate leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

    Published: 22 Mar 2024
    6.3
    Medium

    CVE-2024-2824

    Last Modified: 15 Apr 2026

    A vulnerability was found in Matthias-Wandel jhead 3.08 and classified as critical. This issue affects the function PrintFormatNumber of the file exif.c. The manipulation leads to heap-based buffer overflow. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-257711.

    Published: 22 Mar 2024
    9.8
    Critical

    CVE-2024-29943

    Last Modified: 1 Apr 2025

    An attacker was able to perform an out-of-bounds read or write on a JavaScript object by fooling range-based bounds check elimination. This vulnerability affects Firefox < 124.0.1.

    Published: 22 Mar 2024
    8.8
    High

    CVE-2024-28559

    Last Modified: 28 May 2025

    SQL injection vulnerability in Niushop B2B2C v.5.3.3 and before allows an attacker to escalate privileges via the setPrice() function of the Goodsbatchset.php component.

    Published: 22 Mar 2024
    5.4
    Medium

    CVE-2024-29865

    Last Modified: 16 Apr 2025

    Logpoint before 7.1.0 allows Self-XSS on the LDAP authentication page via the username to the LDAP login form.

    Published: 22 Mar 2024
    8.4
    High

    CVE-2024-29944

    Last Modified: 1 Apr 2025

    An attacker was able to inject an event handler into a privileged object that would allow arbitrary JavaScript execution in the parent process. Note: This vulnerability affects Desktop Firefox only, it does not affect mobile versions of Firefox. This vulnerability affects Firefox < 124.0.1 and Firefox ESR < 115.9.1.

    Published: 22 Mar 2024
    7.8
    High

    CVE-2023-41099

    Last Modified: 17 Jun 2025

    In the Windows installer in Atos Eviden CardOS API before 5.5.5.2811, Local Privilege Escalation can occur.(from a regular user to SYSTEM).

    Published: 22 Mar 2024
    6.3
    Medium

    CVE-2024-25168

    Last Modified: 28 May 2025

    SQL injection vulnerability in snow snow v.2.0.0 allows a remote attacker to execute arbitrary code via the dataScope parameter of the system/role/list interface.

    Published: 22 Mar 2024
    6.1
    Medium

    CVE-2024-25807

    Last Modified: 28 May 2025

    Cross Site Scripting (XSS) vulnerability in Lychee 3.1.6, allows remote attackers to execute arbitrary code and obtain sensitive information via the title parameter when creating an album.

    Published: 22 Mar 2024
    8.3
    High

    CVE-2024-25808

    Last Modified: 28 May 2025

    Cross-site Request Forgery (CSRF) vulnerability in Lychee version 3.1.6, allows remote attackers to execute arbitrary code via the create new album function.

    Published: 22 Mar 2024
    5.4
    Medium

    CVE-2024-26557

    Last Modified: 28 May 2025

    Codiad v2.8.4 allows reflected XSS via the components/market/dialog.php type parameter.

    Published: 22 Mar 2024
    9.8
    Critical

    CVE-2024-28441

    Last Modified: 17 Jun 2025

    File Upload vulnerability in magicflue v.7.0 and before allows a remote attacker to execute arbitrary code via a crafted request to the messageid parameter of the mail/mailupdate.jsp endpoint.

    Published: 22 Mar 2024
    5.4
    Medium

    CVE-2024-28560

    Last Modified: 28 May 2025

    SQL injection vulnerability in Niushop B2B2C v.5.3.3 and before allows an attacker to escalate privileges via the deleteArea() function of the Address.php component.

    Published: 22 Mar 2024
    5.4
    Medium

    CVE-2024-28593

    Last Modified: 1 May 2025

    The Chat activity in Moodle 4.3.3 allows students to insert a potentially unwanted HTML A element or IMG element, or HTML content that leads to a performance degradation. NOTE: the vendor's Using_Chat page says "If you know some HTML code, you can use it in your text to do things like insert images, play sounds or create different coloured and sized text." This page also says "Chat is due to be removed from standard Moodle."

    Published: 22 Mar 2024
    2.4
    Low

    CVE-2024-29338

    Last Modified: 28 Mar 2025

    Anchor CMS v0.12.7 was discovered to contain a Cross-Site Request Forgery (CSRF) via /anchor/admin/categories/delete/2.

    Published: 22 Mar 2024
    6.1
    Medium

    CVE-2024-29271

    Last Modified: 28 May 2025

    Reflected Cross-Site Scripting (XSS) vulnerability in VvvebJs before version 1.7.7, allows remote attackers to execute arbitrary code and obtain sensitive information via the action parameter in save.php.

    Published: 22 Mar 2024
    6.5
    Medium

    CVE-2024-29272

    Last Modified: 28 May 2025

    Arbitrary File Upload vulnerability in VvvebJs before version 1.7.5, allows unauthenticated remote attackers to execute arbitrary code and obtain sensitive information via the sanitizeFileName parameter in save.php.

    Published: 22 Mar 2024
    6.1
    Medium

    CVE-2024-29273

    Last Modified: 17 Jun 2025

    There is Stored Cross-Site Scripting (XSS) in dzzoffice 2.02.1 SC UTF8 in uploadfile to index.php, with the XSS payload in an SVG document.

    Published: 22 Mar 2024
    9.8
    Critical

    CVE-2024-29275

    Last Modified: 28 Mar 2025

    SQL injection vulnerability in SeaCMS version 12.9, allows remote unauthenticated attackers to execute arbitrary code and obtain sensitive information via the id parameter in class.php.

    Published: 22 Mar 2024
    8.8
    High

    CVE-2024-29366

    Last Modified: 17 Jun 2025

    A command injection vulnerability exists in the cgibin binary in DIR-845L router firmware <= v1.01KRb03.

    Published: 22 Mar 2024
    9
    Critical

    CVE-2024-29385

    Last Modified: 17 Jun 2025

    DIR-845L router <= v1.01KRb03 has an Unauthenticated remote code execution vulnerability in the cgibin binary via soapcgi_main function.

    Published: 22 Mar 2024
    7.4
    High

    CVE-2024-29499

    Last Modified: 28 Mar 2025

    Anchor CMS v0.12.7 was discovered to contain a Cross-Site Request Forgery (CSRF) via /anchor/admin/users/delete/2.

    Published: 22 Mar 2024
    6.3
    Medium

    CVE-2024-2776

    Last Modified: 21 Feb 2025

    A vulnerability, which was classified as critical, was found in Campcodes Online Marriage Registration System 1.0. Affected is an unknown function of the file /admin/search.php. The manipulation of the argument searchdata leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-257610 is the identifier assigned to this vulnerability.

    Published: 21 Mar 2024
    3.5
    Low

    CVE-2024-2775

    Last Modified: 20 Feb 2025

    A vulnerability, which was classified as problematic, has been found in Campcodes Online Marriage Registration System 1.0. This issue affects some unknown processing of the file /user/user-profile.php. The manipulation of the argument lname leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-257609 was assigned to this vulnerability.

    Published: 21 Mar 2024
    6.3
    Medium

    CVE-2024-2774

    Last Modified: 21 Feb 2025

    A vulnerability classified as critical was found in Campcodes Online Marriage Registration System 1.0. This vulnerability affects unknown code of the file /user/search.php. The manipulation of the argument searchdata leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-257608.

    Published: 21 Mar 2024
    6.4
    Medium

    CVE-2024-2453

    Last Modified: 15 Apr 2026

    There is an SQL injection vulnerability in Advantech WebAccess/SCADA software that allows an authenticated attacker to remotely inject SQL code in the database. Successful exploitation of this vulnerability could allow an attacker to read or modify data on the remote database.

    Published: 21 Mar 2024
    3.5
    Low

    CVE-2024-2773

    Last Modified: 10 Apr 2025

    A vulnerability classified as problematic has been found in Campcodes Online Marriage Registration System 1.0. This affects an unknown part of the file /user/search.php. The manipulation of the argument searchdata leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-257607.

    Published: 21 Mar 2024
    6.3
    Medium

    CVE-2024-2770

    Last Modified: 21 Feb 2025

    A vulnerability was found in Campcodes Complete Online Beauty Parlor Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /admin/contact-us.php. The manipulation of the argument email leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-257606 is the identifier assigned to this vulnerability.

    Published: 21 Mar 2024
    4.9
    Medium

    CVE-2023-42954

    Last Modified: 9 Dec 2024

    A privilege escalation issue existed in FileMaker Server, potentially exposing sensitive information to front-end websites when signed in to the Admin Console with an administrator role. This issue has been fixed in FileMaker Server 20.3.1 by reducing the information sent in requests.

    Published: 21 Mar 2024
    4.6
    Medium

    CVE-2024-28045

    Last Modified: 5 Nov 2025

    Improper neutralization of input within the affected product could lead to cross-site scripting.

    Published: 21 Mar 2024
    8.1
    High

    CVE-2024-25567

    Last Modified: 5 Nov 2025

    Path traversal attack is possible and write outside of the intended directory and may access sensitive information. If a file name is specified that already exists on the file system, then the original file will be overwritten.

    Published: 21 Mar 2024
    8.1
    High

    CVE-2024-28171

    Last Modified: 5 Nov 2025

    It is possible to perform a path traversal attack and write outside of the intended directory. If a file name is specified that already exists on the file system, then the original file will be overwritten.

    Published: 21 Mar 2024
    8.8
    High

    CVE-2024-23494

    Last Modified: 5 Nov 2025

    SQL injection vulnerability exists in GetDIAE_unListParameters.

    Published: 21 Mar 2024