5.3
    Medium

    CVE-2024-7928

    Last Modified: 13 Sept 2024

    A vulnerability, which was classified as problematic, has been found in FastAdmin up to 1.3.3.20220121. Affected by this issue is some unknown functionality of the file /index/ajax/lang. The manipulation of the argument lang leads to path traversal. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 1.3.4.20220530 is able to address this issue. It is recommended to upgrade the affected component.

    Published:19 Aug 2024
    8.1
    High

    CVE-2024-7856

    Last Modified: 8 Apr 2026

    The MP3 Audio Player – Music Player, Podcast Player & Radio by Sonaar plugin for WordPress is vulnerable to unauthorized arbitrary file deletion due to a missing capability check on the removeTempFiles() function and insufficient path validation on the 'file' parameter in all versions up to, and including, 5.7.0.1. This makes it possible for authenticated attackers, with subscriber-level access and above, to delete arbitrary files which can make remote code execution possible when wp-config.php is deleted.

    Published:29 Aug 2024
    10
    Critical

    CVE-2024-7854

    Last Modified: 8 Apr 2026

    The Woo Inquiry plugin for WordPress is vulnerable to SQL Injection in all versions up to, and including, 0.1 due to insufficient escaping on the user supplied parameter 'dbid' and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

    Published:21 Aug 2024
    5.1
    Medium

    CVE-2024-7815

    Last Modified: 13 Apr 2025

    A vulnerability has been found in CodeAstro Online Railway Reservation System 1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /admin/admin-update-employee.php of the component Update Employee Page. The manipulation of the argument emp_fname /emp_lname /emp_nat_idno/emp_addr leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

    Source:Raj Nandi
    Published:15 Aug 2024
    6.9
    Medium

    CVE-2024-7808

    Last Modified: 23 Oct 2025

    A vulnerability was found in code-projects Job Portal 1.0. It has been classified as critical. Affected is an unknown function of the file logindbc.php. The manipulation of the argument email leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

    Published:15 Aug 2024
    2.6
    Low

    CVE-2024-7804

    Last Modified: 20 Jun 2025

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

    Published:20 Mar 2025
    6.3
    Medium

    CVE-2024-7801

    Last Modified: 13 Apr 2025

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Microchip TimeProvider 4100 (Data plot modules) allows SQL Injection.This issue affects TimeProvider 4100: from 1.0 before 2.4.7.

    Source:Armando Huesca Prida
    Published:4 Oct 2024
    6.4
    Medium

    CVE-2024-7703

    Last Modified: 15 Apr 2026

    The ARMember – Membership Plugin, Content Restriction, Member Levels, User Profile & User signup plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 4.0.37 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses the SVG file.

    Published:17 Aug 2024
    8.8
    High

    CVE-2024-7646

    Last Modified: 15 Apr 2026

    A security issue was discovered in ingress-nginx where an actor with permission to create Ingress objects (in the `networking.k8s.io` or `extensions` API group) can bypass annotation validation to inject arbitrary commands and obtain the credentials of the ingress-nginx controller. In the default configuration, that credential has access to all secrets in the cluster.

    Published:16 Aug 2024
    8.1
    High

    CVE-2024-7627

    Last Modified: 11 Sept 2024

    The Bit File Manager plugin for WordPress is vulnerable to Remote Code Execution in versions 6.0 to 6.5.5 via the 'checkSyntax' function. This is due to writing a temporary file to a publicly accessible directory before performing file validation. This makes it possible for unauthenticated attackers to execute code on the server if an administrator has allowed Guest User read permissions.

    Published:5 Sept 2024
    5.3
    Medium

    CVE-2024-7595

    Last Modified: 3 Nov 2025

    GRE and GRE6 Protocols (RFC2784) do not validate or verify the source of a network packet allowing an attacker to spoof and route arbitrary traffic via an exposed network interface that can lead to spoofing, access control bypass, and other unexpected network behaviors. This can be considered similar to CVE-2020-10136.

    Published:14 Jan 2025
    9.8
    Critical

    CVE-2024-7593

    Last Modified: 14 May 2026

    Incorrect implementation of an authentication algorithm in Ivanti vTM other than versions 22.2R1 or 22.7R2 allows a remote unauthenticated attacker to bypass authentication of the admin panel.

    Published:13 Aug 2024
    10
    Critical

    CVE-2024-7591

    Last Modified: 18 Feb 2025

    Improper Input Validation vulnerability in Progress LoadMaster allows OS Command Injection.This issue affects: * LoadMaster: 7.2.40.0 and above * ECS: All versions * Multi-Tenancy: 7.1.35.4 and above

    Published:5 Sept 2024
    6.5
    Medium

    CVE-2024-7514

    Last Modified: 15 Apr 2026

    The WordPress Comments Import & Export plugin for WordPress is vulnerable to to arbitrary file read due to insufficient file path validation during the comments import process, in versions up to, and including, 2.3.7. This makes it possible for authenticated attackers, with Author-level access and above, to read the contents of arbitrary files on the server, which can contain sensitive information. The issue was partially fixed in version 2.3.8 and fully fixed in 2.3.9

    Published:11 Oct 2024
    8.8
    High

    CVE-2024-7479

    Last Modified: 15 Apr 2026

    Improper verification of cryptographic signature during installation of a VPN driver via the TeamViewer_service.exe component of TeamViewer Remote Clients prior version 15.58.4 for Windows allows an attacker with local unprivileged access on a Windows system to elevate their privileges and install drivers.

    Published:25 Sept 2024
    9.8
    Critical

    CVE-2024-7456

    Last Modified: 6 Nov 2024

    A SQL injection vulnerability exists in the `/api/v1/external-users` route of lunary-ai/lunary version v1.4.2. The `order by` clause of the SQL query uses `sql.unsafe` without prior sanitization, allowing for SQL injection. The `orderByClause` variable is constructed without server-side validation or sanitization, enabling an attacker to execute arbitrary SQL commands. Successful exploitation can lead to complete data loss, modification, or corruption.

    Published:1 Nov 2024
    8.8
    High

    CVE-2024-7399

    Last Modified: 25 Apr 2026

    Improper limitation of a pathname to a restricted directory vulnerability in Samsung MagicINFO 9 Server version before 21.1050 allows attackers to write arbitrary file as system authority.

    Published:9 Aug 2024
    9.1
    Critical

    CVE-2024-7387

    Last Modified: 11 Aug 2026

    A flaw was found in openshift/builder. This vulnerability allows command injection via path traversal, where a malicious user can execute arbitrary commands on the OpenShift node running the builder container. When using the “Docker” strategy, executable files inside the privileged build container can be overridden using the `spec.source.secrets.secret.destinationDir` attribute of the `BuildConfig` definition. An attacker running code in a privileged container could escalate their permissions on the node running the container.

    Published:16 Sept 2024
    8.2
    High

    CVE-2024-7344

    Last Modified: 15 Sept 2025

    Howyar UEFI Application "Reloader" (32-bit and 64-bit) is vulnerable to execution of unsigned software in a hardcoded path.

    Published:14 Jan 2025
    6.9
    Medium

    CVE-2024-7339

    Last Modified: 20 Dec 2024

    A vulnerability has been found in TVT DVR TD-2104TS-CL, DVR TD-2108TS-HP, Provision-ISR DVR SH-4050A5-5L(MM) and AVISION DVR AV108T and classified as problematic. This vulnerability affects unknown code of the file /queryDevInfo. The manipulation leads to information disclosure. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-273262 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

    Published:1 Aug 2024
    6.1
    Medium

    CVE-2024-7313

    Last Modified: 17 May 2025

    The Shield Security WordPress plugin before 20.0.6 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

    Published:26 Aug 2024
    6.5
    Medium

    CVE-2024-7135

    Last Modified: 8 Apr 2026

    The Tainacan plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'get_file' function in all versions up to, and including, 0.21.7. The function is also vulnerable to directory traversal. This makes it possible for authenticated attackers, with Subscriber-level access and above, to read the contents of arbitrary files on the server, which can contain sensitive information.

    Published:31 Jul 2024
    5.3
    Medium

    CVE-2024-7124

    Last Modified: 15 Apr 2026

    Improper Neutralization of Input During Web Page Generation vulnerability in DInGO dLibra software in the parameter 'filter' in the endpoint 'indexsearch' allows a Reflected Cross-Site Scripting (XSS). An attacker might trick somebody into using a crafted URL, which will cause a script to be run in user's browser. This issue affects DInGO dLibra software in versions from 6.0 before 6.3.20.

    Published:14 Nov 2024
    5.3
    Medium

    CVE-2024-7120

    Last Modified: 21 Nov 2024

    A vulnerability, which was classified as critical, was found in Raisecom MSG1200, MSG2100E, MSG2200 and MSG2300 3.90. This affects an unknown part of the file list_base_config.php of the component Web Interface. The manipulation of the argument template leads to os command injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-272451.

    Published:26 Jul 2024
    9.8
    Critical

    CVE-2024-7094

    Last Modified: 15 Apr 2026

    The JS Help Desk – The Ultimate Help Desk & Support Plugin plugin for WordPress is vulnerable to PHP Code Injection leading to Remote Code Execution in all versions up to, and including, 2.8.6 via the 'storeTheme' function. This is due to a lack of sanitization on user-supplied values, which replace values in the style.php file, along with missing capability checks. This makes it possible for unauthenticated attackers to execute code on the server. This issue was partially patched in 2.8.6 when the code injection issue was resolved, and fully patched in 2.8.7 when the missing authorization and cross-site request forgery protection was added. CVE-2024-43274 is likely a duplicate of this issue.

    Published:13 Aug 2024
    8.7
    High

    CVE-2024-7029

    Last Modified: 9 Jan 2025

    Commands can be injected over the network and executed without authentication.

    Published:2 Aug 2024
    7.1
    High

    CVE-2024-7014

    Last Modified: 9 Feb 2026

    EvilVideo vulnerability allows sending malicious apps disguised as videos in Telegram for Android application affecting versions 10.14.4 and older.

    Published:23 Jul 2024
    4.8
    Medium

    CVE-2024-6783

    Last Modified: 15 Apr 2026

    A vulnerability has been discovered in Vue, that allows an attacker to perform XSS via prototype pollution. The attacker could change the prototype chain of some properties such as `Object.prototype.staticClass` or `Object.prototype.staticStyle` to execute arbitrary JavaScript code.

    Published:23 Jul 2024
    9.8
    Critical

    CVE-2024-6782

    Last Modified: 15 Apr 2026

    Improper access control in Calibre 6.9.0 ~ 7.14.0 allow unauthenticated attackers to achieve remote code execution.

    Published:6 Aug 2024
    7.5
    High

    CVE-2024-6778

    Last Modified: 26 Dec 2024

    Race in DevTools in Google Chrome prior to 126.0.6478.182 allowed an attacker who convinced a user to install a malicious extension to inject scripts or HTML into a privileged page via a crafted Chrome Extension. (Chromium security severity: High)

    Published:16 Jul 2024
    8.4
    High

    CVE-2024-6769

    Last Modified: 15 Apr 2026

    A DLL Hijacking caused by drive remapping combined with a poisoning of the activation cache in Microsoft Windows 10, Windows 11, Windows Server 2016, Windows Server 2019, and Windows Server 2022 allows a malicious authenticated attacker to elevate from a medium integrity process to a high integrity process without the intervention of a UAC prompt.

    Published:26 Sept 2024
    6.8
    Medium

    CVE-2024-6768

    Last Modified: 15 Apr 2026

    A Denial of Service in CLFS.sys in Microsoft Windows 10, Windows 11, Windows Server 2016, Windows Server 2019, and Windows Server 2022 allows a malicious authenticated low-privilege user to cause a Blue Screen of Death via a forced call to the KeBugCheckEx function.

    Published:12 Aug 2024
    9.9
    Critical

    CVE-2024-6678

    Last Modified: 21 Nov 2024

    An issue was discovered in GitLab CE/EE affecting all versions starting from 8.14 prior to 17.1.7, starting from 17.2 prior to 17.2.5, and starting from 17.3 prior to 17.3.2, which allows an attacker to trigger a pipeline as an arbitrary user under certain circumstances.

    Published:12 Sept 2024
    9.8
    Critical

    CVE-2024-6670

    Last Modified: 31 Oct 2025

    In WhatsUp Gold versions released before 2024.0.0, a SQL Injection vulnerability allows an unauthenticated attacker to retrieve the users encrypted password.

    Published:29 Aug 2024
    6.1
    Medium

    CVE-2024-6651

    Last Modified: 11 Apr 2025

    The WordPress File Upload WordPress plugin before 4.24.8 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

    Published:6 Aug 2024
    8.7
    High

    CVE-2024-6648

    Last Modified: 13 May 2025

    Absolute Path Traversal vulnerability in AP Page Builder versions prior to 4.0.0 could allow an unauthenticated remote user to modify the 'product_item_path' within the 'config' JSON file, allowing them to read any file on the system.

    Published:8 May 2025
    9.8
    Critical

    CVE-2024-6624

    Last Modified: 8 Apr 2026

    The JSON API User plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 3.9.3. This is due to improper controls on custom user meta fields. This makes it possible for unauthenticated attackers to register as administrators on the site. The plugin requires the JSON API plugin to also be installed.

    Published:11 Jul 2024
    9.3
    Critical

    CVE-2024-6592

    Last Modified: 7 Aug 2026

    An incorrect authorization vulnerability in the protocol communication between the WatchGuard Authentication Gateway (aka Single Sign-On Agent) on Windows and the WatchGuard Single Sign-On Client on Windows and MacOS allows an attacker with network access to forge communications to affected components. In the event an attacker has already gained network access, they could exploit this vulnerability to retrieve authenticated usernames and group memberships from the Single Sign-On Agent or send arbitrary account and group information to the Single Sign-On Agent for their host. This vulnerability cannot be used by an attacker to gain access to user credentials.

    Published:25 Sept 2024
    5.4
    Medium

    CVE-2024-6536

    Last Modified: 10 Jun 2025

    The Zephyr Project Manager WordPress plugin before 3.3.99 does not sanitise and escape some of its settings, which could allow high privilege users such as editors and admins to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

    Published:30 Jul 2024
    7.1
    High

    CVE-2024-6529

    Last Modified: 10 Apr 2025

    The Ultimate Classified Listings WordPress plugin before 1.4 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

    Published:1 Aug 2024
    9.3
    Critical

    CVE-2024-6516

    Last Modified: 15 Apr 2025

    Cross Site Scripting vulnerabilities where found providing a potential for malicious scripts to be injected into a client browser.  Affected products: ABB ASPECT - Enterprise v3.08.02; NEXUS Series v3.08.02; MATRIX Series v3.08.02

    Source:LiquidWorm
    Published:5 Dec 2024
    6.4
    Medium

    CVE-2024-6485

    Last Modified: 15 Apr 2026

    A security vulnerability has been discovered in bootstrap that could enable Cross-Site Scripting (XSS) attacks. The vulnerability is associated with the data-loading-text attribute within the button plugin. This vulnerability can be exploited by injecting malicious JavaScript code into the attribute, which would then be executed when the button's loading state is triggered.

    Published:11 Jul 2024
    8.4
    High

    CVE-2024-6473

    Last Modified: 5 Sept 2024

    Yandex Browser for Desktop before 24.7.1.380 has a DLL Hijacking Vulnerability because an untrusted search path is used.

    Published:3 Sept 2024
    9.8
    Critical

    CVE-2024-6460

    Last Modified: 27 May 2025

    The Grow by Tradedoubler WordPress plugin through 2.0.21 is vulnerable to Local File Inclusion via the component parameter. This makes it possible for attackers to include and execute PHP files on the server, allowing the execution of any PHP code in those files.

    Published:16 Aug 2024
    8.1
    High

    CVE-2024-6387

    Last Modified: 22 Apr 2025

    A security regression (CVE-2006-5051) was discovered in OpenSSH's server (sshd). There is a race condition which can lead sshd to handle some signals in an unsafe manner. An unauthenticated, remote attacker may be able to trigger it by failing to authenticate within a set time period.

    Source:Milad karimi
    Published:1 Jul 2024
    9.9
    Critical

    CVE-2024-6386

    Last Modified: 8 Apr 2026

    The WPML plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 4.6.12 via Twig Server-Side Template Injection. This is due to missing input validation and sanitization on the render function. This makes it possible for authenticated attackers, with Contributor-level access and above, to execute code on the server.

    Published:21 Aug 2024
    9.1
    Critical

    CVE-2024-6366

    Last Modified: 30 May 2025

    The User Profile Builder WordPress plugin before 3.11.8 does not have proper authorisation, allowing unauthenticated users to upload media files via the async upload functionality of WP.

    Published:29 Jul 2024
    7.2
    High

    CVE-2024-6333

    Last Modified: 15 Apr 2026

    Authenticated Remote Code Execution in Altalink, Versalink & WorkCentre Products.

    Published:17 Oct 2024
    9.8
    Critical

    CVE-2024-6330

    Last Modified: 27 May 2025

    The GEO my WP WordPress plugin before 4.5.0.2 does not prevent unauthenticated attackers from including arbitrary files in PHP's execution context, which leads to Remote Code Execution.

    Published:19 Aug 2024
    9.4
    Critical

    CVE-2024-6298

    Last Modified: 13 Apr 2025

    Unauthorized file access in WEB Server in ABB ASPECT - Enterprise v3.08.01; NEXUS Series v3.08.01 ; MATRIX Series v3.08.01 allows Attacker to execute arbitrary code remotely

    Source:LiquidWorm
    Published:5 Jul 2024