8.1
    High

    CVE-2024-22983

    Last Modified: 2 May 2025

    SQL injection vulnerability in Projectworlds Visitor Management System in PHP v.1.0 allows a remote attacker to escalate privileges via the name parameter in the myform.php endpoint.

    Published:28 Feb 2024
    8.8
    High

    CVE-2024-22939

    Last Modified: 16 Jan 2025

    Cross Site Request Forgery vulnerability in FlyCms v.1.0 allows a remote attacker to execute arbitrary code via the system/article/category_edit component.

    Published:1 Feb 2024
    9.8
    Critical

    CVE-2024-22922

    Last Modified: 23 Jan 2026

    An issue in Projectworlds Vistor Management Systemin PHP v.1.0 allows a remtoe attacker to escalate privileges via a crafted script to the login page in the POST/index.php

    Published:25 Jan 2024
    Unknown

    CVE-2024-22909

    https://github.com/BurakSevben/CVE-2024-22909

    8.8
    High

    CVE-2024-22899

    Last Modified: 4 Nov 2025

    Vinchin Backup & Recovery v7.2 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the syncNtpTime function.

    Published:2 Feb 2024
    6.8
    Medium

    CVE-2024-22894

    Last Modified: 21 Nov 2024

    An issue fixed in AIT-Deutschland Alpha Innotec Heatpumps V2.88.3 or later, V3.89.0 or later, V4.81.3 or later and Novelan Heatpumps V2.88.3 or later, V3.89.0 or later, V4.81.3 or later, allows remote attackers to execute arbitrary code via the password component in the shadow file.

    Published:30 Jan 2024
    9.8
    Critical

    CVE-2024-22891

    Last Modified: 13 May 2025

    Nteract v.0.28.0 was discovered to contain a remote code execution (RCE) vulnerability via the Markdown link.

    Published:1 Mar 2024
    Unknown

    CVE-2024-22890

    https://github.com/BurakSevben/CVE-2024-22890

    5.5
    Medium

    CVE-2024-22889

    Last Modified: 21 Jan 2025

    Due to incorrect access control in Plone version v6.0.9, remote attackers can view and list all files hosted on the website via sending a crafted request.

    Published:5 Mar 2024
    Unknown

    CVE-2024-22867

    https://github.com/brandon-t-elliott/CVE-2024-22867

    9.8
    Critical

    CVE-2024-22853

    Last Modified: 20 Jun 2025

    D-LINK Go-RT-AC750 GORTAC750_A1_FW_v101b03 has a hardcoded password for the Alphanetworks account, which allows remote attackers to obtain root access via a telnet session.

    Published:6 Feb 2024
    9.8
    Critical

    CVE-2024-22836

    Last Modified: 10 Mar 2024

    An OS command injection vulnerability exists in Akaunting v3.1.3 and earlier. An attacker can manipulate the company locale when installing an app to execute system commands on the hosting server.

    Source:u32i
    Published:8 Feb 2024
    7.8
    High

    CVE-2024-22774

    Last Modified: 15 Apr 2026

    An issue in Panoramic Corporation Digital Imaging Software v.9.1.2.7600 allows a local attacker to escalate privileges via the ccsservice.exe component.

    Published:13 May 2024
    8.1
    High

    CVE-2024-22752

    Last Modified: 15 Apr 2026

    Insecure permissions issue in EaseUS MobiMover 6.0.5 Build 21620 allows attackers to gain escalated privileges via use of crafted executable launched from the application installation directory.

    Published:7 Mar 2024
    6.2
    Medium

    CVE-2024-22734

    Last Modified: 17 Jun 2025

    An issue was discovered in AMCS Group Trux Waste Management Software before version 7.19.0018.26912, allows local attackers to obtain sensitive information via a static, hard-coded AES Key-IV pair in the TxUtilities.dll and TruxUser.cfg components.

    Published:12 Apr 2024
    7.2
    High

    CVE-2024-22722

    Last Modified: 8 Apr 2025

    Server Side Template Injection (SSTI) vulnerability in Form Tools 3.1.1 allows attackers to run arbitrary commands via the Group Name field under the add forms section of the application.

    Published:11 Apr 2024
    7.5
    High

    CVE-2024-22641

    Last Modified: 3 Nov 2025

    TCPDF version 6.6.5 and before is vulnerable to ReDoS (Regular Expression Denial of Service) if parsing an untrusted SVG file.

    Published:28 May 2024
    7.5
    High

    CVE-2024-22640

    Last Modified: 4 Nov 2025

    TCPDF version <=6.6.5 is vulnerable to ReDoS (Regular Expression Denial of Service) if parsing an untrusted HTML page with a crafted color.

    Published:19 Apr 2024
    Unknown

    CVE-2024-22534

    https://github.com/austino2000/CVE-2024-22534

    6.5
    Medium

    CVE-2024-22532

    Last Modified: 13 May 2025

    Buffer Overflow vulnerability in XNSoft NConvert 7.163 (for Windows x86) allows attackers to cause a denial of service via crafted xwd file.

    Published:28 Feb 2024
    5.5
    Medium

    CVE-2024-22526

    Last Modified: 17 Jun 2025

    Buffer Overflow vulnerability in bandisoft bandiview v7.0, allows local attackers to cause a denial of service (DoS) via exr image file.

    Published:12 Apr 2024
    8.8
    High

    CVE-2024-22515

    Last Modified: 8 May 2025

    Unrestricted File Upload vulnerability in iSpyConnect.com Agent DVR 5.1.6.0 allows attackers to upload arbitrary files via the upload audio component.

    Published:6 Feb 2024
    8.8
    High

    CVE-2024-22514

    Last Modified: 21 Nov 2024

    An issue discovered in iSpyConnect.com Agent DVR 5.1.6.0 allows attackers to run arbitrary files by restoring a crafted backup file.

    Published:6 Feb 2024
    5.5
    Medium

    CVE-2024-22513

    Last Modified: 15 Apr 2024

    djangorestframework-simplejwt version 5.3.1 and before is vulnerable to information disclosure. A user can access web application resources even after their account has been disabled due to missing user validation checks via the for_user method.

    Source:Dhrumil Mistry
    Published:16 Mar 2024
    9.7
    Critical

    CVE-2024-22416

    Last Modified: 17 Jun 2025

    pyLoad is a free and open-source Download Manager written in pure Python. The `pyload` API allows any API call to be made using GET requests. Since the session cookie is not set to `SameSite: strict`, this opens the library up to severe attack possibilities via a Cross-Site Request Forgery (CSRF) attack. As a result any API call can be made via a CSRF attack by an unauthenticated user. This issue has been addressed in release `0.5.0b3.dev78`. All users are advised to upgrade.

    Published:17 Jan 2024
    6.5
    Medium

    CVE-2024-22411

    Last Modified: 2 Jun 2025

    Avo is a framework to create admin panels for Ruby on Rails apps. In Avo 3 pre12, any HTML inside text that is passed to `error` or `succeed` in an `Avo::BaseAction` subclass will be rendered directly without sanitization in the toast/notification that appears in the UI on Action completion. A malicious user could exploit this vulnerability to trigger a cross site scripting attack on an unsuspecting user. This issue has been addressed in the 3.3.0 and 2.47.0 releases of Avo. Users are advised to upgrade.

    Published:16 Jan 2024
    9.1
    Critical

    CVE-2024-22393

    Last Modified: 5 May 2025

    Unrestricted Upload of File with Dangerous Type vulnerability in Apache Answer.This issue affects Apache Answer: through 1.2.1. Pixel Flood Attack by uploading large pixel files will cause server out of memory. A logged-in user can cause such an attack by uploading an image when posting content. Users are recommended to upgrade to version [1.2.5], which fixes the issue.

    Published:22 Feb 2024
    2.9
    Low

    CVE-2024-22371

    Last Modified: 25 Apr 2025

    Exposure of sensitive data by by crafting a malicious EventFactory and providing a custom ExchangeCreatedEvent that exposes sensitive data. Vulnerability in Apache Camel.This issue affects Apache Camel: from 3.21.X through 3.21.3, from 3.22.X through 3.22.0, from 4.0.X through 4.0.3, from 4.X through 4.3.0. Users are recommended to upgrade to version 3.21.4, 3.22.1, 4.0.4 or 4.4.0, which fixes the issue.

    Published:23 Feb 2024
    7.8
    High

    CVE-2024-22369

    Last Modified: 2 Apr 2025

    Deserialization of Untrusted Data vulnerability in Apache Camel SQL ComponentThis issue affects Apache Camel: from 3.0.0 before 3.21.4, from 3.22.0 before 3.22.1, from 4.0.0 before 4.0.4, from 4.1.0 before 4.4.0. Users are recommended to upgrade to version 4.4.0, which fixes the issue. If users are on the 4.0.x LTS releases stream, then they are suggested to upgrade to 4.0.4. If users are on 3.x, they are suggested to move to 3.21.4 or 3.22.1

    Published:19 Feb 2024
    7.5
    High

    CVE-2024-22363

    Last Modified: 15 Apr 2026

    SheetJS Community Edition before 0.20.2 is vulnerable.to Regular Expression Denial of Service (ReDoS).

    Published:5 Apr 2024
    5.1
    Medium

    CVE-2024-22318

    Last Modified: 26 Feb 2024

    IBM i Access Client Solutions (ACS) 1.1.2 through 1.1.4 and 1.1.4.3 through 1.1.9.4 is vulnerable to NT LAN Manager (NTLM) hash disclosure by an attacker modifying UNC capable paths within ACS configuration files to point to a hostile server. If NTLM is enabled, the Windows operating system will try to authenticate using the current user's session. The hostile server could capture the NTLM hash information to obtain the user's credentials. IBM X-Force ID: 279091.

    Source:hyp3rlinx
    Published:9 Feb 2024
    4.9
    Medium

    CVE-2024-22275

    Last Modified: 27 Jun 2025

    The vCenter Server contains a partial file read vulnerability. A malicious actor with administrative privileges on the vCenter appliance shell may exploit this issue to partially read arbitrary files containing sensitive data.

    Published:21 May 2024
    7.2
    High

    CVE-2024-22274

    Last Modified: 27 Jun 2025

    The vCenter Server contains an authenticated remote code execution vulnerability. A malicious actor with administrative privileges on the vCenter appliance shell may exploit this issue to run arbitrary commands on the underlying operating system.

    Published:21 May 2024
    8.8
    High

    CVE-2024-22263

    Last Modified: 15 Apr 2026

    Spring Cloud Data Flow is a microservices-based Streaming and Batch data processing in Cloud Foundry and Kubernetes. The Skipper server has the ability to receive upload package requests. However, due to improper sanitization for upload path, a malicious user who has access to skipper server api can use a crafted upload request to write arbitrary file to any location on file system, may even compromises the server.

    Published:19 Jun 2024
    8.1
    High

    CVE-2024-22262

    Last Modified: 15 Apr 2026

    Applications that use UriComponentsBuilder to parse an externally provided URL (e.g. through a query parameter) AND perform validation checks on the host of the parsed URL may be vulnerable to a open redirect https://cwe.mitre.org/data/definitions/601.html  attack or to a SSRF attack if the URL is used after passing validation checks. This is the same as CVE-2024-22259 https://spring.io/security/cve-2024-22259  and CVE-2024-22243 https://spring.io/security/cve-2024-22243 , but with different input.

    Published:16 Apr 2024
    8.1
    High

    CVE-2024-22243

    Last Modified: 15 Apr 2026

    Applications that use UriComponentsBuilder to parse an externally provided URL (e.g. through a query parameter) AND perform validation checks on the host of the parsed URL may be vulnerable to a open redirect https://cwe.mitre.org/data/definitions/601.html  attack or to a SSRF attack if the URL is used after passing validation checks.

    Published:21 Feb 2024
    7.1
    High

    CVE-2024-22198

    Last Modified: 21 Nov 2024

    Nginx-UI is a web interface to manage Nginx configurations. It is vulnerable to arbitrary command execution by abusing the configuration settings. The `Home > Preference` page exposes a list of system settings such as `Run Mode`, `Jwt Secret`, `Node Secret` and `Terminal Start Command`. While the UI doesn't allow users to modify the `Terminal Start Command` setting, it is possible to do so by sending a request to the API. This issue may lead to authenticated remote code execution, privilege escalation, and information disclosure. This vulnerability has been patched in version 2.0.0.beta.9.

    Published:11 Jan 2024
    8.8
    High

    CVE-2024-22145

    Last Modified: 23 Apr 2026

    Incorrect Privilege Assignment vulnerability in InstaWP InstaWP Connect instawp-connect.This issue affects InstaWP Connect: from n/a through <= 0.1.0.8.

    Published:17 May 2024
    9.1
    Critical

    CVE-2024-22127

    Last Modified: 7 Feb 2025

    SAP NetWeaver Administrator AS Java (Administrator Log Viewer plug-in) - version 7.50, allows an attacker with high privileges to upload potentially dangerous files which leads to command injection vulnerability. This would enable the attacker to run commands which can cause high impact on confidentiality, integrity and availability of the application.

    Published:12 Mar 2024
    9.1
    Critical

    CVE-2024-22120

    Last Modified: 8 Oct 2025

    Zabbix server can perform command execution for configured scripts. After command is executed, audit entry is added to "Audit Log". Due to "clientip" field is not sanitized, it is possible to injection SQL into "clientip" and exploit time based blind SQL injection.

    Published:17 May 2024
    6.7
    Medium

    CVE-2024-22026

    Last Modified: 13 Mar 2025

    A local privilege escalation vulnerability in EPMM before 12.1.0.0 allows an authenticated local user to bypass shell restriction and execute arbitrary commands on the appliance.

    Published:22 May 2024
    8.3
    High

    CVE-2024-22024

    Last Modified: 31 Oct 2025

    An XML external entity or XXE vulnerability in the SAML component of Ivanti Connect Secure (9.x, 22.x), Ivanti Policy Secure (9.x, 22.x) and ZTA gateways which allows an attacker to access certain restricted resources without authentication.

    Published:13 Feb 2024
    7.5
    High

    CVE-2024-22019

    Last Modified: 4 Nov 2025

    A vulnerability in Node.js HTTP servers allows an attacker to send a specially crafted HTTP request with chunked encoding, leading to resource exhaustion and denial of service (DoS). The server reads an unbounded number of bytes from a single connection, exploiting the lack of limitations on chunk extension bytes. The issue can cause CPU and network bandwidth exhaustion, bypassing standard safeguards like timeouts and body size limits.

    Published:16 Feb 2024
    7.3
    High

    CVE-2024-22017

    Last Modified: 15 Apr 2026

    setuid() does not affect libuv's internal io_uring operations if initialized before the call to setuid(). This allows the process to perform privileged operations despite presumably having dropped such privileges through a call to setuid(). This vulnerability affects all users using version greater or equal than Node.js 18.18.0, Node.js 20.4.0 and Node.js 21.

    Published:19 Feb 2024
    7.8
    High

    CVE-2024-22002

    Last Modified: 15 Apr 2026

    CORSAIR iCUE 5.9.105 with iCUE Murals on Windows allows unprivileged users to insert DLL files in the cuepkg-1.2.6 subdirectory of the installation directory.

    Published:18 Jun 2024
    7.9
    High

    CVE-2024-21980

    Last Modified: 26 Nov 2024

    Improper restriction of write operations in SNP firmware could allow a malicious hypervisor to potentially overwrite a guest's memory or UMC seed resulting in loss of confidentiality and integrity.

    Published:5 Aug 2024
    6
    Medium

    CVE-2024-21978

    Last Modified: 26 Nov 2024

    Improper input validation in SEV-SNP could allow a malicious hypervisor to read or overwrite guest memory potentially leading to data leakage or data corruption.

    Published:5 Aug 2024
    7.5
    High

    CVE-2024-21907

    Last Modified: 28 Nov 2025

    Newtonsoft.Json before version 13.0.1 is affected by a mishandling of exceptional conditions vulnerability. Crafted data that is passed to the JsonConvert.DeserializeObject method may trigger a StackOverflow exception resulting in denial of service. Depending on the usage of the library, an unauthenticated and remote attacker may be able to cause the denial of service condition.

    Published:3 Jan 2024
    8.2
    High

    CVE-2024-21893

    Last Modified: 30 Oct 2025

    A server-side request forgery vulnerability in the SAML component of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) and Ivanti Neurons for ZTA allows an attacker to access certain restricted resources without authentication.

    Published:31 Jan 2024
    9.1
    Critical

    CVE-2024-21887

    Last Modified: 31 Oct 2025

    A command injection vulnerability in web components of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) allows an authenticated administrator to send specially crafted requests and execute arbitrary commands on the appliance.

    Published:12 Jan 2024
    Items Per Page