CVE Feed

    Dashboard / CVE

    7.1
    High

    CVE-2024-29126

    Last Modified: 28 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jose Mortellaro Specific Content For Mobile – Customize the mobile version without redirections allows Reflected XSS.This issue affects Specific Content For Mobile – Customize the mobile version without redirections: from n/a through 0.1.9.5.

    Published: 19 Mar 2024
    7.1
    High

    CVE-2024-29127

    Last Modified: 28 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in AAM Advanced Access Manager allows Reflected XSS.This issue affects Advanced Access Manager: from n/a through 6.9.20.

    Published: 19 Mar 2024
    7.1
    High

    CVE-2024-29128

    Last Modified: 28 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Post SMTP POST SMTP allows Reflected XSS.This issue affects POST SMTP: from n/a through 2.8.6.

    Published: 19 Mar 2024
    7.1
    High

    CVE-2024-29129

    Last Modified: 28 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPLIT Pty Ltd OxyExtras allows Reflected XSS.This issue affects OxyExtras: from n/a through 1.4.4.

    Published: 19 Mar 2024
    7.1
    High

    CVE-2024-29130

    Last Modified: 28 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Scott Paterson Contact Form 7 – PayPal & Stripe Add-on allows Reflected XSS.This issue affects Contact Form 7 – PayPal & Stripe Add-on: from n/a through 2.0.

    Published: 19 Mar 2024
    6.5
    Medium

    CVE-2024-29134

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themefic Tourfic tourfic.This issue affects Tourfic: from n/a through <= 2.11.8.

    Published: 19 Mar 2024
    9.9
    Critical

    CVE-2024-29135

    Last Modified: 29 Apr 2026

    Unrestricted Upload of File with Dangerous Type vulnerability in Themefic Tourfic tourfic.This issue affects Tourfic: from n/a through <= 2.11.15.

    Published: 19 Mar 2024
    8.5
    High

    CVE-2024-29136

    Last Modified: 23 Apr 2026

    Deserialization of Untrusted Data vulnerability in Themefic Tourfic tourfic.This issue affects Tourfic: from n/a through <= 2.11.17.

    Published: 19 Mar 2024
    7.1
    High

    CVE-2024-29137

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themefic Tourfic tourfic.This issue affects Tourfic: from n/a through <= 2.11.7.

    Published: 19 Mar 2024
    7.1
    High

    CVE-2024-29138

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Joachim Jensen Restrict User Access – Membership Plugin with Force restrict-user-access.This issue affects Restrict User Access – Membership Plugin with Force: from n/a through <= 2.5.

    Published: 19 Mar 2024
    7.1
    High

    CVE-2024-29139

    Last Modified: 28 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Mark Tilly MyCurator Content Curation allows Reflected XSS.This issue affects MyCurator Content Curation: from n/a through 3.76.

    Published: 19 Mar 2024
    5.9
    Medium

    CVE-2024-29140

    Last Modified: 28 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Matt Manning MJM Clinic allows Stored XSS.This issue affects MJM Clinic: from n/a through 1.1.22.

    Published: 19 Mar 2024
    5.5
    Medium

    CVE-2024-29141

    Last Modified: 28 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PDF Embedder allows Stored XSS.This issue affects PDF Embedder: from n/a through 4.6.4.

    Published: 19 Mar 2024
    7.1
    High

    CVE-2024-29142

    Last Modified: 28 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WebberZone Better Search – Relevant search results for WordPress allows Stored XSS.This issue affects Better Search – Relevant search results for WordPress: from n/a through 3.3.0.

    Published: 19 Mar 2024
    6.5
    Medium

    CVE-2024-29143

    Last Modified: 28 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Cozmoslabs, sareiodata Passwordless Login passwordless-login allows Stored XSS.This issue affects Passwordless Login: from n/a through 1.1.2.

    Published: 19 Mar 2024
    9
    Critical

    CVE-2024-2636

    Last Modified: 15 Apr 2026

    An Unrestricted Upload of File vulnerability has been found on Cegid Meta4 HR, that allows an attacker to upload malicios files to the server via '/config/espanol/update_password.jsp' file. Modifying the 'M4_NEW_PASSWORD' parameter, an attacker could store a malicious JSP file inside the file directory, to be executed the the file is loaded in the application.

    Published: 19 Mar 2024
    7.3
    High

    CVE-2024-2635

    Last Modified: 15 Apr 2026

    The configuration pages available are not intended to be placed on an Internet facing web server, as they expose file paths to the client, who can be an attacker. Instead of rewriting these pages to avoid this vulnerability, they will be dismissed from future releases of Cegid Meta4 HR, as they do not offer product functionality

    Published: 19 Mar 2024
    6.1
    Medium

    CVE-2024-2634

    Last Modified: 15 Apr 2026

    A Cross-Site Scripting Vulnerability has been found on Meta4 HR affecting version 819.001.022 and earlier. The endpoint '/sse_generico/generico_login.jsp' is vulnerable to XSS attack via 'lang' query, i.e. '/sse_generico/generico_login.jsp?lang=%27%3balert(%27BLEUSS%27)%2f%2f&params='.

    Published: 19 Mar 2024
    6.1
    Medium

    CVE-2024-2633

    Last Modified: 15 Apr 2026

    A Cross-Site Scripting Vulnerability has been found on Meta4 HR affecting version 819.001.022 and earlier. The endpoint '/sitetest/english/dumpenv.jsp' is vulnerable to XSS attack by 'lang' query, i.e. '/sitetest/english/dumpenv.jsp?snoop=yes&lang=%27%3Cimg%20src/onerror=alert(1)%3E&params'.

    Published: 19 Mar 2024
    9.8
    Critical

    CVE-2024-2615

    Last Modified: 14 Mar 2025

    Memory safety bugs present in Firefox 123. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 124.

    Published: 19 Mar 2024
    7.5
    High

    CVE-2024-2613

    Last Modified: 25 Feb 2025

    Data was not properly sanitized when decoding a QUIC ACK frame; this could have led to unrestricted memory consumption and a crash. This vulnerability affects Firefox < 124.

    Published: 19 Mar 2024
    6.1
    Medium

    CVE-2024-2609

    Last Modified: 14 Mar 2025

    The permission prompt input delay could expire while the window is not in focus. This makes it vulnerable to clickjacking by malicious websites. This vulnerability affects Firefox < 124, Firefox ESR < 115.10, and Thunderbird < 115.10.

    Published: 19 Mar 2024
    3.7
    Low

    CVE-2024-2606

    Last Modified: 1 Apr 2025

    Passing invalid data could have led to invalid wasm values being created, such as arbitrary integers turning into pointer values. This vulnerability affects Firefox < 124.

    Published: 19 Mar 2024
    7.5
    High

    CVE-2024-2632

    Last Modified: 15 Apr 2026

    A Information Exposure Vulnerability has been found on Meta4 HR. This vulnerability allows an attacker to obtain a lot of information about the application such as the variables set in the process, the Tomcat versions, library versions and underlying operation system via HTTP GET '/sitetest/english/dumpenv.jsp'.

    Published: 19 Mar 2024
    5.8
    Medium

    CVE-2024-1146

    Last Modified: 15 Oct 2025

    Cross-Site Scripting vulnerability in Devklan's Alma Blog that affects versions 2.1.10 and earlier. This vulnerability could allow an attacker to store a malicious JavaScript payload within the application by adding the payload to 'Community Description' or 'Community Rules'.

    Published: 19 Mar 2024
    5.3
    Medium

    CVE-2024-1145

    Last Modified: 15 Oct 2025

    User enumeration vulnerability in Devklan's Alma Blog that affects versions 2.1.10 and earlier. This vulnerability could allow a remote user to retrieve all valid users registered in the application just by looking at the request response.

    Published: 19 Mar 2024
    6.5
    Medium

    CVE-2024-1144

    Last Modified: 15 Oct 2025

    Improper access control vulnerability in Devklan's Alma Blog that affects versions 2.1.10 and earlier. This vulnerability could allow an unauthenticated user to access the application's functionalities without the need for credentials.

    Published: 19 Mar 2024
    4.8
    Medium

    CVE-2024-1401

    Last Modified: 5 May 2025

    The Profile Box Shortcode And Widget WordPress plugin before 1.2.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

    Published: 19 Mar 2024
    6.5
    Medium

    CVE-2024-24683

    Last Modified: 15 Jul 2025

    Improper Input Validation vulnerability in Apache Hop Engine.This issue affects Apache Hop Engine: before 2.8.0. Users are recommended to upgrade to version 2.8.0, which fixes the issue. When Hop Server writes links to the PrepareExecutionPipelineServlet page one of the parameters provided to the user was not properly escaped. The variable not properly escaped is the "id", which is not directly accessible by users creating pipelines making the risk of exploiting this low. This issue only affects users using the Hop Server component and does not directly affect the client.

    Published: 19 Mar 2024
    4.4
    Medium

    CVE-2024-25942

    Last Modified: 4 Feb 2025

    Dell PowerEdge Server BIOS contains an Improper SMM communication buffer verification vulnerability. A physical high privileged attacker could potentially exploit this vulnerability leading to arbitrary writes to SMRAM.

    Published: 19 Mar 2024
    7.2
    High

    CVE-2024-22453

    Last Modified: 4 Feb 2025

    Dell PowerEdge Server BIOS contains a heap-based buffer overflow vulnerability. A local high privileged attacker could potentially exploit this vulnerability to write to otherwise unauthorized memory.

    Published: 19 Mar 2024
    6.5
    Medium

    CVE-2024-0055

    Last Modified: 13 Jan 2026

    Sandro Poppi, member of the AXIS OS Bug Bounty Program, has found that the VAPIX APIs mediaclip.cgi and playclip.cgi was vulnerable for file globbing which could lead to a resource exhaustion attack. Axis has released patched AXIS OS versions for the highlighted flaw. Please refer to the Axis security advisory for more information and solution.

    Published: 19 Mar 2024
    6.5
    Medium

    CVE-2024-0054

    Last Modified: 15 Apr 2026

    Sandro Poppi, member of the AXIS OS Bug Bounty Program, has found that the VAPIX APIs local_list.cgi, create_overlay.cgi and irissetup.cgi was vulnerable for file globbing which could lead to a resource exhaustion attack. Axis has released patched AXIS OS versions for the highlighted flaw. Please refer to the Axis security advisory for more information and solution.

    Published: 19 Mar 2024
    6.1
    Medium

    CVE-2024-21504

    Last Modified: 21 Nov 2024

    Versions of the package livewire/livewire from 3.3.5 and before 3.4.9 are vulnerable to Cross-site Scripting (XSS) when a page uses [Url] for a property. An attacker can inject HTML code in the context of the user's browser session by crafting a malicious link and convincing the user to click on it.

    Published: 19 Mar 2024
    6.3
    Medium

    CVE-2024-2622

    Last Modified: 21 Nov 2024

    A vulnerability was found in Fujian Kelixin Communication Command and Dispatch Platform up to 20240318. It has been classified as critical. This affects an unknown part of the file /api/client/editemedia.php. The manipulation of the argument number/enterprise_uuid leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-257199.

    Published: 19 Mar 2024
    6.3
    Medium

    CVE-2024-2621

    Last Modified: 21 Nov 2024

    A vulnerability was found in Fujian Kelixin Communication Command and Dispatch Platform up to 20240318 and classified as critical. Affected by this issue is some unknown functionality of the file api/client/user/pwd_update.php. The manipulation of the argument uuid leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-257198 is the identifier assigned to this vulnerability.

    Published: 19 Mar 2024
    6.3
    Medium

    CVE-2024-2620

    Last Modified: 21 Nov 2024

    A vulnerability has been found in Fujian Kelixin Communication Command and Dispatch Platform up to 20240318 and classified as critical. Affected by this vulnerability is an unknown functionality of the file api/client/down_file.php. The manipulation of the argument uuid leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-257197 was assigned to this vulnerability.

    Published: 19 Mar 2024
    9.8
    Critical

    CVE-2024-28303

    Last Modified: 15 Apr 2026

    Open Source Medicine Ordering System v1.0 was discovered to contain a SQL injection vulnerability via the date parameter at /admin/reports/index.php.

    Published: 19 Mar 2024
    8.8
    High

    CVE-2024-28715

    Last Modified: 24 Jun 2025

    Cross Site Scripting vulnerability in DOraCMS v.2.18 and before allows a remote attacker to execute arbitrary code via the markdown0 function in the /app/public/apidoc/oas3/wrap-components/markdown.jsx endpoint.

    Published: 19 Mar 2024
    6.1
    Medium

    CVE-2024-2610

    Last Modified: 1 Apr 2025

    Using a markup injection an attacker could have stolen nonce values. This could have been used to bypass strict content security policies. This vulnerability affects Firefox < 124, Firefox ESR < 115.9, and Thunderbird < 115.9.

    Published: 19 Mar 2024
    9.8
    Critical

    CVE-2024-28394

    Last Modified: 15 Apr 2026

    An issue in Advanced Plugins reportsstatistics v1.3.20 and before allows a remote attacker to execute arbitrary code via the Sales Reports, Statistics, Custom Fields & Export module.

    Published: 19 Mar 2024
    6.1
    Medium

    CVE-2023-40277

    Last Modified: 14 Apr 2025

    An issue was discovered in OpenClinic GA 5.247.01. A Reflected Cross-Site Scripting (XSS) vulnerability has been discovered in the login.jsp message parameter.

    Published: 19 Mar 2024
    9.1
    Critical

    CVE-2023-40275

    Last Modified: 14 Apr 2025

    An issue was discovered in OpenClinic GA 5.247.01. It allows retrieval of patient lists via queries such as findFirstname= to _common/search/searchByAjax/patientslistShow.jsp.

    Published: 19 Mar 2024
    9.1
    Critical

    CVE-2023-40276

    Last Modified: 14 Apr 2025

    An issue was discovered in OpenClinic GA 5.247.01. An Unauthenticated File Download vulnerability has been discovered in pharmacy/exportFile.jsp.

    Published: 19 Mar 2024
    7.5
    High

    CVE-2023-40279

    Last Modified: 14 Apr 2025

    An issue was discovered in OpenClinic GA 5.247.01. An attacker can perform a directory path traversal via the Page parameter in a GET request to main.do.

    Published: 19 Mar 2024
    7.5
    High

    CVE-2023-40280

    Last Modified: 14 Apr 2025

    An issue was discovered in OpenClinic GA 5.247.01. An attacker can perform a directory path traversal via the Page parameter in a GET request to popup.jsp.

    Published: 19 Mar 2024
    6.5
    Medium

    CVE-2023-50811

    Last Modified: 27 Mar 2025

    An issue discovered in SELESTA Visual Access Manager 4.38.6 allows attackers to modify the “computer” POST parameter related to the ID of a specific reception by POST HTTP request interception. Iterating that parameter, it has been possible to access to the application and take control of many other receptions in addition the assigned one.

    Published: 19 Mar 2024
    5.3
    Medium

    CVE-2023-50966

    Last Modified: 15 Apr 2026

    erlang-jose (aka JOSE for Erlang and Elixir) through 1.11.6 allow attackers to cause a denial of service (CPU consumption) via a large p2c (aka PBES2 Count) value in a JOSE header.

    Published: 19 Mar 2024
    5.3
    Medium

    CVE-2024-21503

    Last Modified: 15 Apr 2026

    Versions of the package black before 24.3.0 are vulnerable to Regular Expression Denial of Service (ReDoS) via the lines_with_leading_tabs_expanded function in the strings.py file. An attacker could exploit this vulnerability by crafting a malicious input that causes a denial of service. Exploiting this vulnerability is possible when running Black on untrusted input, or if you habitually put thousands of leading tab characters in your docstrings.

    Published: 19 Mar 2024
    6.5
    Medium

    CVE-2024-22025

    Last Modified: 15 Apr 2026

    A vulnerability in Node.js has been identified, allowing for a Denial of Service (DoS) attack through resource exhaustion when using the fetch() function to retrieve content from an untrusted URL. The vulnerability stems from the fact that the fetch() function in Node.js always decodes Brotli, making it possible for an attacker to cause resource exhaustion when fetching content from an untrusted URL. An attacker controlling the URL passed into fetch() can exploit this vulnerability to exhaust memory, potentially leading to process termination, depending on the system configuration.

    Published: 19 Mar 2024