CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2024-29031

    Last Modified: 2 Sept 2025

    Meshery is an open source, cloud native manager that enables the design and management of Kubernetes-based infrastructure and applications. A SQL injection vulnerability in Meshery prior to version 0.7.17 allows a remote attacker to obtain sensitive information via the `order` parameter of `GetMeshSyncResources`. Version 0.7.17 contains a patch for this issue.

    Published: 21 Mar 2024
    8.8
    High

    CVE-2024-23975

    Last Modified: 5 Nov 2025

    SQL injection vulnerability exists in GetDIAE_slogListParameters.

    Published: 21 Mar 2024
    8.8
    High

    CVE-2024-28040

    Last Modified: 5 Nov 2025

    SQL injection vulnerability exists in GetDIAE_astListParameters.

    Published: 21 Mar 2024
    8.8
    High

    CVE-2024-25937

    Last Modified: 24 Jan 2025

    SQL injection vulnerability exists in the script DIAE_tagHandler.ashx.

    Published: 21 Mar 2024
    8.8
    High

    CVE-2024-28891

    Last Modified: 5 Nov 2025

    SQL injection vulnerability exists in the script Handler_CFG.ashx.

    Published: 21 Mar 2024
    8.8
    High

    CVE-2024-28029

    Last Modified: 21 Nov 2024

    Privileges are not fully verified server-side, which can be abused by a user with limited privileges to bypass authorization and access privileged functionality.

    Published: 21 Mar 2024
    8.8
    High

    CVE-2024-28119

    Last Modified: 2 Jan 2025

    Grav is an open-source, flat-file content management system. Prior to version 1.7.45, due to the unrestricted access to twig extension class from grav context, an attacker can redefine the escape function and execute arbitrary commands. Twig processing of static pages can be enabled in the front matter by any administrative user allowed to create or edit pages. As the Twig processor runs unsandboxed, this behavior can be used to gain arbitrary code execution and elevate privileges on the instance. Version 1.7.45 contains a patch for this issue.

    Published: 21 Mar 2024
    2.1
    Low

    CVE-2024-2769

    Last Modified: 30 Sept 2025

    A vulnerability was detected in Campcodes Complete Online Beauty Parlor Management System 1.0. The affected element is an unknown function of the file /admin/admin-profile.php. The manipulation of the argument adminname/email results in sql injection. The attack may be launched remotely. The exploit is now public and may be used.

    Published: 21 Mar 2024
    8.8
    High

    CVE-2024-28118

    Last Modified: 2 Jan 2025

    Grav is an open-source, flat-file content management system. Prior to version 1.7.45, due to the unrestricted access to twig extension class from Grav context, an attacker can redefine config variable. As a result, attacker can bypass a previous SSTI mitigation. Twig processing of static pages can be enabled in the front matter by any administrative user allowed to create or edit pages. As the Twig processor runs unsandboxed, this behavior can be used to gain arbitrary code execution and elevate privileges on the instance. Version 1.7.45 contains a fix for this issue.

    Published: 21 Mar 2024
    8.8
    High

    CVE-2024-28117

    Last Modified: 2 Jan 2025

    Grav is an open-source, flat-file content management system. Prior to version 1.7.45, Grav validates accessible functions through the Utils::isDangerousFunction function, but does not impose restrictions on twig functions like twig_array_map, allowing attackers to bypass the validation and execute arbitrary commands. Twig processing of static pages can be enabled in the front matter by any administrative user allowed to create or edit pages. As the Twig processor runs unsandboxed, this behavior can be used to gain arbitrary code execution and elevate privileges on the instance. Upgrading to patched version 1.7.45 can mitigate this issue.

    Published: 21 Mar 2024
    8.8
    High

    CVE-2024-28116

    Last Modified: 2 Jan 2025

    Grav is an open-source, flat-file content management system. Grav CMS prior to version 1.7.45 is vulnerable to a Server-Side Template Injection (SSTI), which allows any authenticated user (editor permissions are sufficient) to execute arbitrary code on the remote server bypassing the existing security sandbox. Version 1.7.45 contains a patch for this issue.

    Published: 21 Mar 2024
    8.8
    High

    CVE-2024-27921

    Last Modified: 10 Apr 2025

    Grav is an open-source, flat-file content management system. A file upload path traversal vulnerability has been identified in the application prior to version 1.7.45, enabling attackers to replace or create files with extensions like .json, .zip, .css, .gif, etc. This critical security flaw poses severe risks, that can allow attackers to inject arbitrary code on the server, undermine integrity of backup files by overwriting existing files or creating new ones, and exfiltrate sensitive data using CSS exfiltration techniques. Upgrading to patched version 1.7.45 can mitigate the issue.

    Published: 21 Mar 2024
    6.3
    Medium

    CVE-2024-2768

    Last Modified: 21 Feb 2025

    A vulnerability was found in Campcodes Complete Online Beauty Parlor Management System 1.0. It has been classified as critical. Affected is an unknown function of the file /admin/edit-services.php. The manipulation of the argument editid leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-257604.

    Published: 21 Mar 2024
    6.3
    Medium

    CVE-2024-2767

    Last Modified: 21 Feb 2025

    A vulnerability was found in Campcodes Complete Online Beauty Parlor Management System 1.0 and classified as critical. This issue affects some unknown processing of the file /admin/forgot-password.php. The manipulation of the argument email leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-257603.

    Published: 21 Mar 2024
    6.3
    Medium

    CVE-2024-2766

    Last Modified: 21 Feb 2025

    A vulnerability has been found in Campcodes Complete Online Beauty Parlor Management System 1.0 and classified as critical. This vulnerability affects unknown code of the file /admin/index.php. The manipulation of the argument username leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-257602 is the identifier assigned to this vulnerability.

    Published: 21 Mar 2024
    8.8
    High

    CVE-2024-2764

    Last Modified: 12 Dec 2024

    A vulnerability, which was classified as critical, was found in Tenda AC10U 15.03.06.48. This affects the function formSetPPTPServer of the file /goform/SetPptpServerCfg. The manipulation of the argument endIP leads to stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-257601 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 21 Mar 2024
    8.8
    High

    CVE-2024-2763

    Last Modified: 12 Dec 2024

    A vulnerability, which was classified as critical, has been found in Tenda AC10U 15.03.06.48. Affected by this issue is the function formSetCfm of the file goform/setcfm. The manipulation of the argument funcpara1 leads to stack-based buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-257600. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 21 Mar 2024
    —
    Unknown

    CVE-2024-2802

    Last Modified: 26 Mar 2024

    ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2024-1166. Reason: This candidate is a reservation duplicate of CVE-2024-1166. Notes: All CVE users should reference CVE-2024-1166 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage.

    Published: 21 Mar 2024
    4.3
    Medium

    CVE-2024-24883

    Last Modified: 28 Apr 2026

    Missing Authorization vulnerability in BdThemes Prime Slider – Addons For Elementor.This issue affects Prime Slider – Addons For Elementor: from n/a through 3.11.10.

    Published: 21 Mar 2024
    5.4
    Medium

    CVE-2024-25907

    Last Modified: 28 Apr 2026

    Missing Authorization vulnerability in JoomUnited WP Media folder.This issue affects WP Media folder: from n/a through 5.7.2.

    Published: 21 Mar 2024
    5.3
    Medium

    CVE-2024-24850

    Last Modified: 28 Apr 2026

    Missing Authorization vulnerability in Mark Stockton Quicksand Post Filter jQuery Plugin.This issue affects Quicksand Post Filter jQuery Plugin: from n/a through 3.1.1.

    Published: 21 Mar 2024
    6.5
    Medium

    CVE-2022-44633

    Last Modified: 28 Apr 2026

    Missing Authorization vulnerability in YITH YITH WooCommerce Gift Cards Premium.This issue affects YITH WooCommerce Gift Cards Premium: from n/a through 3.23.1.

    Published: 21 Mar 2024
    4.3
    Medium

    CVE-2022-47604

    Last Modified: 28 Apr 2026

    Missing Authorization vulnerability in junkcoder, ristoniinemets AJAX Thumbnail Rebuild.This issue affects AJAX Thumbnail Rebuild: from n/a through 1.13.

    Published: 21 Mar 2024
    4.3
    Medium

    CVE-2024-25908

    Last Modified: 28 Apr 2026

    Missing Authorization vulnerability in JoomUnited WP Media folder.This issue affects WP Media folder: from n/a through 5.7.2.

    Published: 21 Mar 2024
    9.8
    Critical

    CVE-2024-25912

    Last Modified: 28 Apr 2026

    Missing Authorization vulnerability in Skymoonlabs MoveTo.This issue affects MoveTo: from n/a through 6.2.

    Published: 21 Mar 2024
    5.4
    Medium

    CVE-2024-25922

    Last Modified: 28 Apr 2026

    Missing Authorization vulnerability in Peach Payments Peach Payments Gateway.This issue affects Peach Payments Gateway: from n/a through 3.1.9.

    Published: 21 Mar 2024
    4.3
    Medium

    CVE-2024-25935

    Last Modified: 28 Apr 2026

    Missing Authorization vulnerability in Metagauss RegistrationMagic.This issue affects RegistrationMagic: from n/a through 5.2.5.9.

    Published: 21 Mar 2024
    7.5
    High

    CVE-2023-51672

    Last Modified: 28 Apr 2026

    Missing Authorization vulnerability in FunnelKit FunnelKit Checkout.This issue affects FunnelKit Checkout: from n/a through 3.10.3.

    Published: 21 Mar 2024
    5.4
    Medium

    CVE-2023-27607

    Last Modified: 28 Apr 2026

    Missing Authorization vulnerability in WP Swings Points and Rewards for WooCommerce.This issue affects Points and Rewards for WooCommerce: from n/a through 1.5.0.

    Published: 21 Mar 2024
    5.3
    Medium

    CVE-2022-44595

    Last Modified: 28 Apr 2026

    Improper Authentication vulnerability in Melapress WP 2FA allows Authentication Bypass.This issue affects WP 2FA: from n/a through 2.2.0.

    Published: 21 Mar 2024
    6.2
    Medium

    CVE-2024-27277

    Last Modified: 14 Feb 2025

    The private key for the IBM Storage Protect Plus Server 10.1.0 through 10.1.16 certificate can be disclosed, undermining the security of the certificate. IBM X-Force ID: 285205.

    Published: 21 Mar 2024
    6.5
    Medium

    CVE-2023-49837

    Last Modified: 28 Apr 2026

    Uncontrolled Resource Consumption vulnerability in David Artiss Code Embed.This issue affects Code Embed: from n/a through 2.3.6.

    Published: 21 Mar 2024
    4.3
    Medium

    CVE-2024-27190

    Last Modified: 28 Apr 2026

    Missing Authorization vulnerability in Jean-David Daviet Download Media.This issue affects Download Media: from n/a through 1.4.2.

    Published: 21 Mar 2024
    9.9
    Critical

    CVE-2024-27956

    Last Modified: 28 Apr 2026

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ValvePress Automatic allows SQL Injection.This issue affects Automatic: from n/a through 3.92.0.

    Published: 21 Mar 2024
    7.1
    High

    CVE-2024-27968

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Optimole Super Page Cache for Cloudflare allows Stored XSS.This issue affects Super Page Cache for Cloudflare: from n/a through 4.7.5.

    Published: 21 Mar 2024
    5.9
    Medium

    CVE-2024-2578

    Last Modified: 28 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPCoder WP Coder allows Stored XSS.This issue affects WP Coder: from n/a through 3.5.

    Published: 21 Mar 2024
    5.9
    Medium

    CVE-2024-2579

    Last Modified: 28 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Data443 Tracking Code Manager.This issue affects Tracking Code Manager: from n/a through 2.0.16.

    Published: 21 Mar 2024
    6.5
    Medium

    CVE-2024-2580

    Last Modified: 28 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in FunnelKit Automation By Autonami allows Stored XSS.This issue affects Automation By Autonami: from n/a through 2.8.2.

    Published: 21 Mar 2024
    7.1
    High

    CVE-2024-27962

    Last Modified: 28 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Florian 'fkrauthan' Krauthan allows Reflected XSS.This issue affects wp-mpdf: from n/a through 3.7.1.

    Published: 21 Mar 2024
    6.5
    Medium

    CVE-2024-27963

    Last Modified: 28 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crisp allows Stored XSS.This issue affects Crisp: from n/a through 0.44.

    Published: 21 Mar 2024
    8.8
    High

    CVE-2024-27964

    Last Modified: 28 Apr 2026

    Unrestricted Upload of File with Dangerous Type vulnerability in Gesundheit Bewegt GmbH Zippy.This issue affects Zippy: from n/a through 1.6.9.

    Published: 21 Mar 2024
    5.9
    Medium

    CVE-2024-27965

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPFunnels WPFunnels wpfunnels.This issue affects WPFunnels: from n/a through <= 3.0.6.

    Published: 21 Mar 2024
    4.3
    Medium

    CVE-2024-1727

    Last Modified: 30 Jul 2025

    A Cross-Site Request Forgery (CSRF) vulnerability in gradio-app/gradio allows attackers to upload multiple large files to a victim's system if they are running Gradio locally. By crafting a malicious HTML page that triggers an unauthorized file upload to the victim's server, an attacker can deplete the system's disk space, potentially leading to a denial of service. This issue affects the file upload functionality as implemented in gradio/routes.py.

    Published: 21 Mar 2024
    8.1
    High

    CVE-2024-29019

    Last Modified: 15 Apr 2026

    ESPHome is a system to control microcontrollers remotely through Home Automation systems. API endpoints in dashboard component of ESPHome version 2023.12.9 (command line installation) are vulnerable to Cross-Site Request Forgery (CSRF) allowing remote attackers to carry out attacks against a logged user of the dashboard to perform operations on configuration files (create, edit, delete). It is possible for a malicious actor to create a specifically crafted web page that triggers a cross site request against ESPHome, this allows bypassing the authentication for API calls on the platform. This vulnerability allows bypassing authentication on API calls accessing configuration file operations on the behalf of a logged user. In order to trigger the vulnerability, the victim must visit a weaponized page. In addition to this, it is possible to chain this vulnerability with GHSA-9p43-hj5j-96h5/ CVE-2024-27287 to obtain a complete takeover of the user account. Version 2024.3.0 contains a patch for this issue.

    Published: 21 Mar 2024
    5.9
    Medium

    CVE-2024-27966

    Last Modified: 28 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ExpressTech Quiz And Survey Master allows Stored XSS.This issue affects Quiz And Survey Master: from n/a through 8.2.2.

    Published: 21 Mar 2024
    4.3
    Medium

    CVE-2024-27967

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Michael Leithold DSGVO All in one for WP.This issue affects DSGVO All in one for WP: from n/a through 4.3.

    Published: 21 Mar 2024
    6.5
    Medium

    CVE-2024-27969

    Last Modified: 28 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Enhanced Free Downloads WooCommerce allows Stored XSS.This issue affects Free Downloads WooCommerce: from n/a through 3.5.8.2.

    Published: 21 Mar 2024
    5.4
    Medium

    CVE-2024-27970

    Last Modified: 28 Apr 2026

    Missing Authorization vulnerability in BogdanFix WP SendFox.This issue affects WP SendFox: from n/a through 1.3.0.

    Published: 21 Mar 2024
    5.4
    Medium

    CVE-2024-27985

    Last Modified: 28 Apr 2026

    Deserialization of Untrusted Data vulnerability in PropertyHive.This issue affects PropertyHive: from n/a through 2.0.9.

    Published: 21 Mar 2024
    6.5
    Medium

    CVE-2024-27988

    Last Modified: 28 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WEN Themes WEN Responsive Columns allows Stored XSS.This issue affects WEN Responsive Columns: from n/a through 1.3.2.

    Published: 21 Mar 2024