6.4
    Medium

    CVE-2024-1234

    Last Modified: 5 Apr 2025

    The Exclusive Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via data attribute in all versions up to, and including, 2.6.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor access or higher, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Source:Al Baradi Joy
    Published:13 Mar 2024
    10
    Critical

    CVE-2024-1212

    Last Modified: 26 Feb 2026

    Unauthenticated remote attackers can access the system through the LoadMaster management interface, enabling arbitrary system command execution.

    Published:21 Feb 2024
    5.3
    Medium

    CVE-2024-1209

    Last Modified: 8 Apr 2026

    The LearnDash LMS plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.10.1 via direct file access due to insufficient protection of uploaded assignments. This makes it possible for unauthenticated attackers to obtain those uploads.

    Published:5 Feb 2024
    5.3
    Medium

    CVE-2024-1208

    Last Modified: 8 Apr 2026

    The LearnDash LMS plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.10.2 via API. This makes it possible for unauthenticated attackers to obtain access to quiz questions.

    Published:5 Feb 2024
    9.8
    Critical

    CVE-2024-1207

    Last Modified: 8 Apr 2026

    The WP Booking Calendar plugin for WordPress is vulnerable to SQL Injection via the 'calendar_request_params[dates_ddmmyy_csv]' parameter in all versions up to, and including, 9.9 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

    Published:8 Feb 2024
    7.3
    High

    CVE-2024-1112

    Last Modified: 29 May 2025

    Heap-based buffer overflow vulnerability in Resource Hacker, developed by Angus Johnson, affecting version 3.6.0.92. This vulnerability could allow an attacker to execute arbitrary code via a long filename argument.

    Published:31 Jan 2024
    7.8
    High

    CVE-2024-1086

    Last Modified: 7 Aug 2026

    A use-after-free vulnerability in the Linux kernel's netfilter: nf_tables component can be exploited to achieve local privilege escalation. The nft_verdict_init() function allows positive values as drop error within the hook verdict, and hence the nf_hook_slow() function can cause a double free vulnerability when NF_DROP is issued with a drop error which resembles NF_ACCEPT. We recommend upgrading past commit f342de4e2f33e0e39165d8639387aa6c19dff660.

    Published:31 Jan 2024
    9.8
    Critical

    CVE-2024-1071

    Last Modified: 15 Apr 2025

    The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to SQL Injection via the 'sorting' parameter in versions 2.1.3 to 2.8.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

    Published:13 Mar 2024
    5.9
    Medium

    CVE-2024-1065

    Last Modified: 27 Mar 2025

    Use After Free vulnerability in Arm Ltd Bifrost GPU Kernel Driver, Arm Ltd Valhall GPU Kernel Driver, Arm Ltd Arm 5th Gen GPU Architecture Kernel Driver allows a local non-privileged user to make improper GPU memory processing operations to gain access to already freed memory.This issue affects Bifrost GPU Kernel Driver: from r45p0 through r48p0; Valhall GPU Kernel Driver: from r45p0 through r48p0; Arm 5th Gen GPU Architecture Kernel Driver: from r45p0 through r48p0.

    Published:19 Apr 2024
    4.7
    Medium

    CVE-2024-0986

    Last Modified: 29 May 2025

    A vulnerability was found in Issabel PBX 4.0.0. It has been rated as critical. This issue affects some unknown processing of the file /index.php?menu=asterisk_cli of the component Asterisk-Cli. The manipulation of the argument Command leads to os command injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-252251. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

    Published:28 Jan 2024
    Unknown

    CVE-2024-835

    https://github.com/melmathari/dockerCVE-2024-835

    6.3
    Medium

    CVE-2024-0783

    Last Modified: 30 May 2025

    A vulnerability was found in Project Worlds Online Admission System 1.0 and classified as critical. This issue affects some unknown processing of the file documents.php. The manipulation leads to unrestricted upload. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-251699.

    Published:22 Jan 2024
    7.5
    High

    CVE-2024-0762

    Last Modified: 29 Sept 2025

    Potential buffer overflow in unsafe UEFI variable handling in Phoenix SecureCore™ for select Intel platforms This issue affects: Phoenix SecureCore™ for Intel Kaby Lake: from 4.0.1.1 before 4.0.1.998; Phoenix SecureCore™ for Intel Coffee Lake: from 4.1.0.1 before 4.1.0.562; Phoenix SecureCore™ for Intel Ice Lake: from 4.2.0.1 before 4.2.0.323; Phoenix SecureCore™ for Intel Comet Lake: from 4.2.1.1 before 4.2.1.287; Phoenix SecureCore™ for Intel Tiger Lake: from 4.3.0.1 before 4.3.0.236; Phoenix SecureCore™ for Intel Jasper Lake: from 4.3.1.1 before 4.3.1.184; Phoenix SecureCore™ for Intel Alder Lake: from 4.4.0.1 before 4.4.0.269; Phoenix SecureCore™ for Intel Raptor Lake: from 4.5.0.1 before 4.5.0.218; Phoenix SecureCore™ for Intel Meteor Lake: from 4.5.1.1 before 4.5.1.15.

    Published:14 May 2024
    7.5
    High

    CVE-2024-0760

    Last Modified: 15 Apr 2026

    A malicious client can send many DNS messages over TCP, potentially causing the server to become unstable while the attack is in progress. The server may recover after the attack ceases. Use of ACLs will not mitigate the attack. This issue affects BIND 9 versions 9.18.1 through 9.18.27, 9.19.0 through 9.19.24, and 9.18.11-S1 through 9.18.27-S1.

    Published:23 Jul 2024
    5.4
    Medium

    CVE-2024-0757

    Last Modified: 21 May 2025

    The Insert or Embed Articulate Content into WordPress plugin through 4.3000000023 is not properly filtering which file extensions are allowed to be imported on the server, allowing the uploading of malicious code within zip files

    Published:4 Jun 2024
    6.5
    Medium

    CVE-2024-0741

    Last Modified: 30 May 2025

    An out of bounds write in ANGLE could have allowed an attacker to corrupt memory leading to a potentially exploitable crash. This vulnerability affects Firefox < 122, Firefox ESR < 115.7, and Thunderbird < 115.7.

    Published:22 Jan 2024
    5.3
    Medium

    CVE-2024-0737

    Last Modified: 28 Jul 2025

    A vulnerability classified as problematic was found in Xlightftpd Xlight FTP Server 1.1. This vulnerability affects unknown code of the component Login. The manipulation of the argument user leads to denial of service. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-251560.

    Source:Fernando Mengali
    Published:19 Jan 2024
    5.3
    Medium

    CVE-2024-0725

    Last Modified: 9 Jun 2025

    A vulnerability was found in ProSSHD 1.2 on Windows. It has been declared as problematic. This vulnerability affects unknown code. The manipulation leads to denial of service. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-251548.

    Source:Fernando Mengali
    Published:19 Jan 2024
    5.3
    Medium

    CVE-2024-0723

    Last Modified: 26 Jun 2025

    A vulnerability was found in freeSSHd 1.0.9 on Windows. It has been classified as problematic. This affects an unknown part. The manipulation leads to denial of service. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-251547.

    Source:Fernando Mengali
    Published:19 Jan 2024
    Low

    CVE-2024-0713

    Last Modified: 25 Apr 2024

    ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2020-28871. Reason: This candidate is a reservation duplicate of CVE-2020-28871. Notes: All CVE users should reference CVE-2020-28871 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage.

    Published:19 Jan 2024
    5.3
    Medium

    CVE-2024-0710

    Last Modified: 15 Apr 2026

    The GP Unique ID plugin for WordPress is vulnerable to Unique ID Modification in all versions up to, and including, 1.5.5. This is due to insufficient input validation. This makes it possible for unauthenticated attackers to tamper with the generation of a unique ID on a form submission and replace the generated unique ID with a user-controlled one, leading to a loss of integrity in cases where the ID's uniqueness is relied upon in a security-specific context.

    Published:2 May 2024
    8.8
    High

    CVE-2024-0692

    Last Modified: 16 Apr 2025

    The SolarWinds Security Event Manager was susceptible to Remote Code Execution Vulnerability. This vulnerability allows an unauthenticated user to abuse SolarWinds’ service, resulting in remote code execution.

    Published:1 Mar 2024
    5.5
    Medium

    CVE-2024-0684

    Last Modified: 4 Nov 2025

    A flaw was found in the GNU coreutils "split" program. A heap overflow with user-controlled data of multiple hundred bytes in length could occur in the line_bytes_split() function, potentially leading to an application crash and denial of service.

    Published:18 Jan 2024
    7.3
    High

    CVE-2024-0683

    Last Modified: 8 Apr 2026

    The Bulgarisation for WooCommerce plugin for WordPress is vulnerable to unauthorized access due to missing capability checks on several functions in all versions up to, and including, 3.0.14. This makes it possible for unauthenticated and authenticated attackers, with subscriber-level access and above, to generate and delete labels.

    Published:13 Mar 2024
    6.5
    Medium

    CVE-2024-0679

    Last Modified: 8 Apr 2026

    The ColorMag theme for WordPress is vulnerable to unauthorized access due to a missing capability check on the plugin_action_callback() function in all versions up to, and including, 3.1.2. This makes it possible for authenticated attackers, with subscriber-level access and above, to install and activate arbitrary plugins.

    Published:20 Jan 2024
    8.8
    High

    CVE-2024-0670

    Last Modified: 13 Feb 2025

    Privilege escalation in windows agent plugin in Checkmk before 2.2.0p23, 2.1.0p40 and 2.0.0 (EOL) allows local user to escalate privileges

    Published:11 Mar 2024
    5.3
    Medium

    CVE-2024-0624

    Last Modified: 8 Apr 2026

    The Paid Memberships Pro – Content Restriction, User Registration, & Paid Subscriptions plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.12.7. This is due to missing or incorrect nonce validation on the pmpro_update_level_order() function. This makes it possible for unauthenticated attackers to update the order of levels via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

    Published:25 Jan 2024
    4.3
    Medium

    CVE-2024-0623

    Last Modified: 8 Apr 2026

    The VK Block Patterns plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.31.1.1. This is due to missing or incorrect nonce validation on the vbp_clear_patterns_cache() function. This makes it possible for unauthenticated attackers to clear the patterns cache via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

    Published:20 Jan 2024
    6.1
    Medium

    CVE-2024-0590

    Last Modified: 8 Apr 2026

    The Microsoft Clarity plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 0.9.3. This is due to missing nonce validation on the edit_clarity_project_id() function. This makes it possible for unauthenticated attackers to change the project id and add malicious JavaScript via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

    Published:20 Feb 2024
    4.3
    Medium

    CVE-2024-0588

    Last Modified: 8 Apr 2026

    The Paid Memberships Pro – Content Restriction, User Registration, & Paid Subscriptions plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.12.10. This is due to missing nonce validation on the pmpro_lifter_save_streamline_option() function. This makes it possible for unauthenticated attackers to enable the streamline setting with Lifter LMS via a forged request granted they can trick a site administrator into performing an action such as clicking on a link. CVE-2024-32793 and CVE-2024-32794 appear to be a duplicate of this issue.

    Published:9 Apr 2024
    7.8
    High

    CVE-2024-0582

    Last Modified: 20 Nov 2025

    A memory leak flaw was found in the Linux kernel’s io_uring functionality in how a user registers a buffer ring with IORING_REGISTER_PBUF_RING, mmap() it, and then frees it. This flaw allows a local user to crash or potentially escalate their privileges on the system.

    Published:8 Jan 2024
    7.2
    High

    CVE-2024-0566

    Last Modified: 16 Apr 2025

    The Smart Manager WordPress plugin before 8.28.0 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by high privilege users such as admin.

    Source:Ivan Spiridonov
    Published:12 Feb 2024
    8.8
    High

    CVE-2024-0520

    Last Modified: 15 Oct 2025

    A vulnerability in mlflow/mlflow version 8.2.1 allows for remote code execution due to improper neutralization of special elements used in an OS command ('Command Injection') within the `mlflow.data.http_dataset_source.py` module. Specifically, when loading a dataset from a source URL with an HTTP scheme, the filename extracted from the `Content-Disposition` header or the URL path is used to generate the final file path without proper sanitization. This flaw enables an attacker to control the file path fully by utilizing path traversal or absolute path techniques, such as '../../tmp/poc.txt' or '/tmp/poc.txt', leading to arbitrary file write. Exploiting this vulnerability could allow a malicious user to execute commands on the vulnerable machine, potentially gaining access to data and model information. The issue is fixed in version 2.9.0.

    Published:6 Jun 2024
    8.8
    High

    CVE-2024-0519

    Last Modified: 24 Oct 2025

    Out of bounds memory access in V8 in Google Chrome prior to 120.0.6099.224 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

    Published:16 Jan 2024
    6.1
    Medium

    CVE-2024-0509

    Last Modified: 8 Apr 2026

    The WP 404 Auto Redirect to Similar Post plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘request’ parameter in all versions up to, and including, 1.0.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

    Published:5 Feb 2024
    6.5
    Medium

    CVE-2024-0507

    Last Modified: 21 Nov 2024

    An attacker with access to a Management Console user account with the editor role could escalate privileges through a command injection vulnerability in the Management Console. This vulnerability affected all versions of GitHub Enterprise Server and was fixed in versions 3.11.3, 3.10.5, 3.9.8, and 3.8.13 This vulnerability was reported via the GitHub Bug Bounty program.

    Published:16 Jan 2024
    Unknown

    CVE-2024-436

    https://github.com/Julian-gmz/CVE-2024-436_Exploit

    6.1
    Medium

    CVE-2024-0406

    Last Modified: 20 Nov 2025

    A flaw was discovered in the mholt/archiver package. This flaw allows an attacker to create a specially crafted tar file, which, when unpacked, may allow access to restricted files or directories. This issue can allow the creation or overwriting of files with the user's or application's privileges using the library.

    Published:31 Jan 2024
    9.9
    Critical

    CVE-2024-0402

    Last Modified: 23 Apr 2026

    An issue has been discovered in GitLab CE/EE affecting all versions from 16.0 prior to 16.6.6, 16.7 prior to 16.7.4, and 16.8 prior to 16.8.1 which allows an authenticated user to write files to arbitrary locations on the GitLab server while creating a workspace.

    Published:26 Jan 2024
    8.1
    High

    CVE-2024-0399

    Last Modified: 16 Apr 2025

    The WooCommerce Customers Manager WordPress plugin before 29.7 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to an SQL injection exploitable by Subscriber+ role.

    Source:Ivan Spiridonov
    Published:15 Apr 2024
    4.3
    Medium

    CVE-2024-0379

    Last Modified: 8 Apr 2026

    The Custom Twitter Feeds – A Tweets Widget or X Feed Widget plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.2.1. This is due to missing or incorrect nonce validation on the ctf_auto_save_tokens function. This makes it possible for unauthenticated attackers to update the site's twitter API token and secret via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

    Published:20 Feb 2024
    8.6
    High

    CVE-2024-0368

    Last Modified: 8 Apr 2026

    The Hustle – Email Marketing, Lead Generation, Optins, Popups plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 7.8.3 via hardcoded API Keys. This makes it possible for unauthenticated attackers to extract sensitive data including PII.

    Published:13 Mar 2024
    7.3
    High

    CVE-2024-0352

    Last Modified: 3 Jun 2025

    A vulnerability classified as critical was found in Likeshop up to 2.5.7.20210311. This vulnerability affects the function FileServer::userFormImage of the file server/application/api/controller/File.php of the component HTTP POST Request Handler. The manipulation of the argument file leads to unrestricted upload. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-250120.

    Published:9 Jan 2024
    Unknown

    CVE-2024-340

    https://github.com/SimoesCTT/-CTT-PAN-OS-EXPLOIT-CVE-2024-340

    8.2
    High

    CVE-2024-0324

    Last Modified: 8 Apr 2026

    The User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'wppb_two_factor_authentication_settings_update' function in all versions up to, and including, 3.10.8. This makes it possible for unauthenticated attackers to enable or disable the 2FA functionality present in the Premium version of the plugin for arbitrary user roles.

    Published:5 Feb 2024
    5.5
    Medium

    CVE-2024-0311

    Last Modified: 15 Apr 2026

    A malicious insider can bypass the existing policy of Skyhigh Client Proxy without a valid release code.

    Published:14 Mar 2024
    5.3
    Medium

    CVE-2024-0305

    Last Modified: 21 Nov 2024

    A vulnerability was found in Guangzhou Yingke Electronic Technology Ncast up to 2017 and classified as problematic. Affected by this issue is some unknown functionality of the file /manage/IPSetup.php of the component Guest Login. The manipulation leads to information disclosure. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-249872.

    Published:8 Jan 2024
    8.2
    High

    CVE-2024-0258

    Last Modified: 2 Apr 2026

    The issue was addressed with improved memory handling. This issue is fixed in iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4, tvOS 17.4, watchOS 10.4. An app may be able to execute arbitrary code out of its sandbox or with certain elevated privileges.

    Published:8 Mar 2024
    5.3
    Medium

    CVE-2024-0235

    Last Modified: 20 Jun 2025

    The EventON WordPress plugin before 4.5.5, EventON WordPress plugin before 2.2.7 do not have authorisation in an AJAX action, allowing unauthenticated users to retrieve email addresses of any users on the blog

    Published:16 Jan 2024
    2.4
    Low

    CVE-2024-0230

    Last Modified: 2 Apr 2026

    A session management issue was addressed with improved checks. This issue is fixed in Magic Keyboard Firmware Update 2.0.6. An attacker with physical access to the accessory may be able to extract its Bluetooth pairing key and monitor Bluetooth traffic.

    Published:12 Jan 2024