CVE Feed

    Dashboard / CVE

    6.5
    Medium

    CVE-2024-27930

    Last Modified: 2 Jan 2025

    GLPI is a Free Asset and IT Management Software package, Data center management, ITIL Service Desk, licenses tracking and software auditing. An authenticated user can access sensitive fields data from items on which he has read access. This issue has been patched in version 10.0.13.

    Published: 18 Mar 2024
    6.5
    Medium

    CVE-2024-27937

    Last Modified: 2 Jan 2025

    GLPI is a Free Asset and IT Management Software package, Data center management, ITIL Service Desk, licenses tracking and software auditing. An authenticated user can obtain the email address of all GLPI users. This issue has been patched in version 10.0.13.

    Published: 18 Mar 2024
    4.8
    Medium

    CVE-2024-0951

    Last Modified: 27 Mar 2025

    The Advanced Social Feeds Widget & Shortcode WordPress plugin through 1.7 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

    Published: 18 Mar 2024
    6.1
    Medium

    CVE-2024-0711

    Last Modified: 13 May 2025

    The Buttons Shortcode and Widget WordPress plugin through 1.16 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

    Published: 18 Mar 2024
    8.8
    High

    CVE-2024-0858

    Last Modified: 5 May 2025

    The Innovs HR WordPress plugin through 1.0.3.4 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions via CSRF attacks such as adding them as employees.

    Published: 18 Mar 2024
    6.1
    Medium

    CVE-2024-0973

    Last Modified: 5 May 2025

    The Widget for Social Page Feeds WordPress plugin before 6.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

    Published: 18 Mar 2024
    5.4
    Medium

    CVE-2024-0820

    Last Modified: 28 Mar 2025

    The Jobs for WordPress plugin before 2.7.4 does not sanitise and escape some parameters, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks

    Published: 18 Mar 2024
    5.4
    Medium

    CVE-2024-0719

    Last Modified: 13 May 2025

    The Tabs Shortcode and Widget WordPress plugin through 1.17 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

    Published: 18 Mar 2024
    6.5
    Medium

    CVE-2024-0365

    Last Modified: 5 May 2025

    The Fancy Product Designer WordPress plugin before 6.1.5 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by adminstrators.

    Published: 18 Mar 2024
    8.8
    High

    CVE-2024-0779

    Last Modified: 5 May 2025

    The Enjoy Social Feed plugin for WordPress website WordPress plugin through 6.2.2 does not have authorisation and CSRF in various function hooked to admin_init, allowing unauthenticated users to call them and unlink arbitrary users Instagram Account for example

    Published: 18 Mar 2024
    8.8
    High

    CVE-2024-0780

    Last Modified: 14 Mar 2025

    The Enjoy Social Feed plugin for WordPress website WordPress plugin through 6.2.2 does not have authorisation when resetting its database, allowing any authenticated users, such as subscriber to perform such action

    Published: 18 Mar 2024
    7.8
    High

    CVE-2024-20746

    Last Modified: 4 Dec 2024

    Premiere Pro versions 24.1, 23.6.2 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 18 Mar 2024
    7.8
    High

    CVE-2024-20745

    Last Modified: 4 Dec 2024

    Premiere Pro versions 24.1, 23.6.2 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 18 Mar 2024
    9.9
    Critical

    CVE-2024-2599

    Last Modified: 17 Apr 2025

    File upload restriction evasion vulnerability in AMSS++ version 4.31. This vulnerability could allow an authenticated user to potentially obtain RCE through webshell, compromising the entire infrastructure.

    Published: 18 Mar 2024
    7.1
    High

    CVE-2024-2598

    Last Modified: 17 Apr 2025

    Vulnerability in AMSS++ version 4.31, which does not sufficiently encode user-controlled input, resulting in a Cross-Site Scripting (XSS) vulnerability through /amssplus/modules/book/main/select_send_2.php, in multiple parameters. This vulnerability could allow a remote attacker to send a specially crafted URL to an authenticated user and steal their session cookie credentials.

    Published: 18 Mar 2024
    7.1
    High

    CVE-2024-2597

    Last Modified: 17 Apr 2025

    Vulnerability in AMSS++ version 4.31, which does not sufficiently encode user-controlled input, resulting in a Cross-Site Scripting (XSS) vulnerability through /amssplus/modules/book/main/bookdetail_school_person.php, in the 'b_id' parameter. This vulnerability could allow a remote attacker to send a specially crafted URL to an authenticated user and steal their session cookie credentials.

    Published: 18 Mar 2024
    7.1
    High

    CVE-2024-2596

    Last Modified: 17 Apr 2025

    Vulnerability in AMSS++ version 4.31, which does not sufficiently encode user-controlled input, resulting in a Cross-Site Scripting (XSS) vulnerability through /amssplus/modules/mail/main/select_send.php, in multiple parameters. This vulnerability could allow a remote attacker to send a specially crafted URL to an authenticated user and steal their session cookie credentials.

    Published: 18 Mar 2024
    7.1
    High

    CVE-2024-2595

    Last Modified: 17 Apr 2025

    Vulnerability in AMSS++ version 4.31, which does not sufficiently encode user-controlled input, resulting in a Cross-Site Scripting (XSS) vulnerability through /amssplus/modules/book/main/bookdetail_khet_person.php, in the 'b_id' parameter. This vulnerability could allow a remote attacker to send a specially crafted URL to an authenticated user and steal their session cookie credentials.

    Published: 18 Mar 2024
    7.1
    High

    CVE-2024-2594

    Last Modified: 17 Apr 2025

    Vulnerability in AMSS++ version 4.31, which does not sufficiently encode user-controlled input, resulting in a Cross-Site Scripting (XSS) vulnerability through /amssplus/admin/index.php, in multiple parameters. This vulnerability could allow a remote attacker to send a specially crafted URL to an authenticated user and steal their session cookie credentials.

    Published: 18 Mar 2024
    7.1
    High

    CVE-2024-2593

    Last Modified: 17 Apr 2025

    Vulnerability in AMSS++ version 4.31, which does not sufficiently encode user-controlled input, resulting in a Cross-Site Scripting (XSS) vulnerability through /amssplus/modules/book/main/bookdetail_group.php, in the 'b_id' parameter. This vulnerability could allow a remote attacker to send a specially crafted URL to an authenticated user and steal their session cookie credentials.

    Published: 18 Mar 2024
    8.2
    High

    CVE-2024-2592

    Last Modified: 17 Apr 2025

    Vulnerability in AMSS++ version 4.31 that allows SQL injection through /amssplus/modules/person/pic_show.php, in the 'person_id' parameter. This vulnerability could allow a remote attacker to send a specially crafted SQL query to the server and retrieve all the information stored in the DB.

    Published: 18 Mar 2024
    8.2
    High

    CVE-2024-2591

    Last Modified: 17 Apr 2025

    Vulnerability in AMSS++ version 4.31 that allows SQL injection through /amssplus/modules/book/main/bookdetail_group.php, in multiple parameters. This vulnerability could allow a remote attacker to send a specially crafted SQL query to the server and retrieve all the information stored in the DB.

    Published: 18 Mar 2024
    8.2
    High

    CVE-2024-2590

    Last Modified: 17 Apr 2025

    Vulnerability in AMSS++ version 4.31 that allows SQL injection through /amssplus/modules/mail/main/select_send.php, in the 'sd_index' parameter. This vulnerability could allow a remote attacker to send a specially crafted SQL query to the server and retrieve all the information stored in the DB.

    Published: 18 Mar 2024
    8.2
    High

    CVE-2024-2589

    Last Modified: 17 Apr 2025

    Vulnerability in AMSS++ version 4.31 that allows SQL injection through /amssplus/modules/book/main/bookdetail_school_person.php, in multiple parameters. This vulnerability could allow a remote attacker to send a specially crafted SQL query to the server and retrieve all the information stored in the DB.

    Published: 18 Mar 2024
    8.2
    High

    CVE-2024-2588

    Last Modified: 16 Apr 2025

    Vulnerability in AMSS++ version 4.31 that allows SQL injection through /amssplus/admin/index.php, in the 'id' parameter. This vulnerability could allow a remote attacker to send a specially crafted SQL query to the server and retrieve all the information stored in the DB.

    Published: 18 Mar 2024
    8.2
    High

    CVE-2024-2587

    Last Modified: 16 Apr 2025

    Vulnerability in AMSS++ version 4.31 that allows SQL injection through /amssplus/modules/book/main/bookdetail_khet_person.php, in multiple parameters. This vulnerability could allow a remote attacker to send a specially crafted SQL query to the server and retrieve all the information stored in the DB.

    Published: 18 Mar 2024
    8.2
    High

    CVE-2024-2586

    Last Modified: 11 Apr 2025

    Vulnerability in AMSS++ version 4.31 that allows SQL injection through /amssplus/index.php, in the 'username' parameter. This vulnerability could allow a remote attacker to send a specially crafted SQL query to the server and retrieve all the information stored in the DB.

    Published: 18 Mar 2024
    8.2
    High

    CVE-2024-2585

    Last Modified: 10 Apr 2025

    Vulnerability in AMSS++ version 4.31 that allows SQL injection through /amssplus/modules/book/main/select_send_2.php, in the 'sd_index' parameter. This vulnerability could allow a remote attacker to send a specially crafted SQL query to the server and retrieve all the information stored in the DB.

    Published: 18 Mar 2024
    8.2
    High

    CVE-2024-2584

    Last Modified: 11 Apr 2025

    Vulnerability in AMSS++ version 4.31 that allows SQL injection through /amssplus/modules/book/main/select_send.php, in the 'sd_index' parameter. This vulnerability could allow a remote attacker to send a specially crafted SQL query to the server and retrieve all the information stored in the DB.

    Published: 18 Mar 2024
    7.5
    High

    CVE-2024-27774

    Last Modified: 10 Mar 2025

    Unitronics Unistream Unilogic – Versions prior to 1.35.227 - CWE-259: Use of Hard-coded Password may allow disclosing Sensitive Information Embedded inside Device's Firmware

    Published: 18 Mar 2024
    8.8
    High

    CVE-2024-27773

    Last Modified: 10 Mar 2025

    Unitronics Unistream Unilogic – Versions prior to 1.35.227 - CWE-348: Use of Less Trusted Source may allow RCE

    Published: 18 Mar 2024
    8.8
    High

    CVE-2024-27772

    Last Modified: 10 Mar 2025

    Unitronics Unistream Unilogic – Versions prior to 1.35.227 - CWE-78: 'OS Command Injection' may allow RCE

    Published: 18 Mar 2024
    8.8
    High

    CVE-2024-27771

    Last Modified: 10 Mar 2025

    Unitronics Unistream Unilogic – Versions prior to 1.35.227 - CWE-22: 'Path Traversal' may allow RCE

    Published: 18 Mar 2024
    8.8
    High

    CVE-2024-27770

    Last Modified: 10 Mar 2025

    Unitronics Unistream Unilogic – Versions prior to 1.35.227 - CWE-23: Relative Path Traversal

    Published: 18 Mar 2024
    8.8
    High

    CVE-2024-27769

    Last Modified: 10 Apr 2025

    Unitronics Unistream Unilogic – Versions prior to 1.35.227 - CWE-200: Exposure of Sensitive Information to an Unauthorized Actor may allow Taking Ownership Over Devices

    Published: 18 Mar 2024
    9.8
    Critical

    CVE-2024-27768

    Last Modified: 10 Mar 2025

    Unitronics Unistream Unilogic – Versions prior to 1.35.227 - CWE-22: 'Path Traversal' may allow RCE

    Published: 18 Mar 2024
    10
    Critical

    CVE-2024-27767

    Last Modified: 10 Mar 2025

    CWE-287: Improper Authentication may allow Authentication Bypass

    Published: 18 Mar 2024
    7.4
    High

    CVE-2024-20767

    Last Modified: 23 Oct 2025

    ColdFusion versions 2023.6, 2021.12 and earlier are affected by an Improper Access Control vulnerability that could result in arbitrary file system read. An attacker could leverage this vulnerability to access or modify restricted files. Exploitation of this issue does not require user interaction. Exploitation of this issue requires the admin panel be exposed to the internet.

    Published: 18 Mar 2024
    5.4
    Medium

    CVE-2024-1658

    Last Modified: 5 May 2025

    The Grid Shortcodes WordPress plugin before 1.1.1 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

    Published: 18 Mar 2024
    5.4
    Medium

    CVE-2024-1333

    Last Modified: 5 May 2025

    The Responsive Pricing Table WordPress plugin before 5.1.11 does not validate and escape some of its Pricing Table options before outputting them back in a page/post where the related shortcode is embed, which could allow users with the author role and above to perform Stored Cross-Site Scripting attacks

    Published: 18 Mar 2024
    6.1
    Medium

    CVE-2024-1331

    Last Modified: 5 May 2025

    The Team Members WordPress plugin before 5.3.2 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the author role and above to perform Stored Cross-Site Scripting attacks.

    Published: 18 Mar 2024
    5.8
    Medium

    CVE-2024-28039

    Last Modified: 15 Apr 2026

    Improper restriction of XML external entity references vulnerability exists in FitNesse all releases, which allows a remote unauthenticated attacker to obtain sensitive information, alter data, or cause a denial-of-service (DoS) condition.

    Published: 18 Mar 2024
    6.1
    Medium

    CVE-2024-22475

    Last Modified: 15 Apr 2026

    Cross-site request forgery vulnerability in multiple printers and scanners which implement Web Based Management provided by BROTHER INDUSTRIES, LTD. allows a remote unauthenticated attacker to perform unintended operations on the affected product. As for the details of affected product names, model numbers, and versions, refer to the information provided by the respective vendors listed under [References].

    Published: 18 Mar 2024
    5.3
    Medium

    CVE-2024-21824

    Last Modified: 15 Apr 2026

    Improper authentication vulnerability in exists in multiple printers and scanners which implement Web Based Management provided by BROTHER INDUSTRIES, LTD. If this vulnerability is exploited, a network-adjacent user who can access the product may impersonate an administrative user. As for the details of affected product names, model numbers, and versions, refer to the information provided by the respective vendors listed under [References].

    Published: 18 Mar 2024
    6.3
    Medium

    CVE-2024-27974

    Last Modified: 15 Apr 2026

    Cross-site request forgery vulnerability in FUJIFILM printers which implement CentreWare Internet Services or Internet Services allows a remote unauthenticated attacker to alter user information. In the case the user is an administrator, the settings such as the administrator's ID, password, etc. may be altered. As for the details of affected product names, model numbers, and versions, refer to the information provided by the vendor listed under [References].

    Published: 18 Mar 2024
    6.1
    Medium

    CVE-2024-28128

    Last Modified: 20 Mar 2025

    Cross-site scripting vulnerability exists in FitNesse releases prior to 20220319, which may allow a remote unauthenticated attacker to execute an arbitrary script on the web browser of the user who is using the product and accessing a link with a specially crafted certain parameter.

    Published: 18 Mar 2024
    9.8
    Critical

    CVE-2024-28125

    Last Modified: 15 Apr 2026

    FitNesse all releases allows a remote authenticated attacker to execute arbitrary OS commands. Note: A contributor of FitNesse has claimed that this is not a vulnerability but a product specification and this is currently under further investigation.

    Published: 18 Mar 2024
    6.1
    Medium

    CVE-2024-23604

    Last Modified: 27 Mar 2025

    Cross-site scripting vulnerability exists in FitNesse all releases, which may allow a remote unauthenticated attacker to execute an arbitrary script on the web browser of the user who is using the product and accessing a link with specially crafted multiple parameters.

    Published: 18 Mar 2024
    4.6
    Medium

    CVE-2024-1606

    Last Modified: 12 Jul 2025

    Lack of input sanitization in BMC Control-M branches 9.0.20 and 9.0.21 allows logged-in users for manipulation of generated web pages via injection of HTML code. This might lead to a successful phishing attack for example by tricking users into using a hyperlink pointing to a website controlled by an attacker. Fix for 9.0.20 branch was released in version 9.0.20.238. Fix for 9.0.21 branch was released in version 9.0.21.200.

    Published: 18 Mar 2024
    6.6
    Medium

    CVE-2024-1605

    Last Modified: 12 Jul 2025

    BMC Control-M branches 9.0.20 and 9.0.21 upon user login load all Dynamic Link Libraries (DLL) from a directory that grants Write and Read permissions to all users. Leveraging it leads to loading of a potentially malicious libraries, which will execute with the application's privileges. Fix for 9.0.20 branch was released in version 9.0.20.238. Fix for 9.0.21 branch was released in version 9.0.21.201.

    Published: 18 Mar 2024