Unknown

    CVE-2024-1642470

    https://github.com/Symbolexe/CVE-2024-1642470

    Unknown

    CVE-2024-415770

    https://github.com/muhmad-umair/CVE-2024-415770-ssrf-rce

    Unknown

    CVE-2024-99001

    https://github.com/gduma-phData/patch-CVE-2024-99001

    Unknown

    CVE-2024-88555

    https://github.com/gduma-phData/patch-CVE-2024-88555

    Unknown

    CVE-2024-77200

    https://github.com/gduma-phData/patch-CVE-2024-77200

    Unknown

    CVE-2024-66001

    https://github.com/gduma-phData/patch-CVE-2024-66001

    9.3
    Critical

    CVE-2024-58290

    Last Modified: 15 Apr 2026

    Xhibiter NFT Marketplace 1.10.2 contains a SQL injection vulnerability in the collections endpoint that allows attackers to manipulate database queries through the 'id' parameter. Attackers can exploit boolean-based, time-based, and UNION-based SQL injection techniques to potentially extract or manipulate database information by sending crafted payloads to the collections page.

    Published:11 Dec 2025
    7.2
    High

    CVE-2024-58258

    Last Modified: 16 Jul 2025

    SugarCRM before 13.0.4 and 14.x before 14.0.1 allows SSRF in the API module because a limited type of code injection can occur.

    Source:Egidio Romano
    Published:13 Jul 2025
    8.2
    High

    CVE-2024-58239

    Last Modified: 4 Aug 2026

    In the Linux kernel, the following vulnerability has been resolved: tls: stop recv() if initial process_rx_list gave us non-DATA If we have a non-DATA record on the rx_list and another record of the same type still on the queue, we will end up merging them: - process_rx_list copies the non-DATA record - we start the loop and process the first available record since it's of the same type - we break out of the loop since the record was not DATA Just check the record type and jump to the end in case process_rx_list did some work.

    Published:22 Aug 2025
    6.5
    Medium

    CVE-2024-57972

    Last Modified: 15 Apr 2026

    The pairing API request handler in Microsoft HoloLens 1 (Windows Holographic) through 10.0.17763.3046 and HoloLens 2 (Windows Holographic) through 10.0.22621.1244 allows remote attackers to cause a Denial of Service (resource consumption and device unusability) by sending many requests through the Device Portal framework.

    Published:6 Mar 2025
    4.9
    Medium

    CVE-2024-57785

    Last Modified: 15 Apr 2026

    Zenitel AlphaWeb XE v11.2.3.10 was discovered to contain a local file inclusion vulnerability via the component amc_uploads.php.

    Published:16 Jan 2025
    5.5
    Medium

    CVE-2024-57784

    Last Modified: 15 Apr 2026

    An issue in the component /php/script_uploads.php of Zenitel AlphaWeb XE v11.2.3.10 allows attackers to execute a directory traversal.

    Published:16 Jan 2025
    8.8
    High

    CVE-2024-57778

    Last Modified: 15 Apr 2026

    An issue in Orbe ONetView Roeador Onet-1200 Orbe 1680210096 allows a remote attacker to escalate privileges via the servers response from status code 500 to status code 200.

    Published:14 Feb 2025
    9.1
    Critical

    CVE-2024-57727

    Last Modified: 26 Feb 2026

    SimpleHelp remote support software v5.5.7 and before is vulnerable to multiple path traversal vulnerabilities that enable unauthenticated remote attackers to download arbitrary files from the SimpleHelp host via crafted HTTP requests. These files include server configuration files containing various secrets and hashed user passwords.

    Published:15 Jan 2025
    6.5
    Medium

    CVE-2024-57725

    Last Modified: 15 Apr 2026

    An issue in the Arcadyan Livebox Fibra PRV3399B_B_LT allows a remote or local attacker to modify the GPON link value without authentication, causing an internet service disruption via the /firstconnection.cgi endpoint.

    Published:14 Feb 2025
    5.7
    Medium

    CVE-2024-57708

    Last Modified: 26 Jun 2025

    An issue in OneTrust SDK v.6.33.0 allows a local attacker to cause a denial of service via the Object.setPrototypeOf, __proto__, and Object.assign components. NOTE: this is disputed by the Supplier who does not agree it is a prototype pollution vulnerability.

    Source:Alameen Karim Merali
    Published:25 Jun 2025
    7.5
    High

    CVE-2024-57698

    Last Modified: 28 May 2025

    An issue in modernwms v.1.0 allows an attacker view the MD5 hash of the administrator password and other attributes without authentication, even after initial configuration and password change. This happens due to excessive exposure of information and the lack of adequate access control on the /user/list?culture=en-us endpoint.

    Published:29 Apr 2025
    7.5
    High

    CVE-2024-57610

    Last Modified: 19 Sept 2025

    A rate limiting issue in Sylius v2.0.2 allows a remote attacker to perform unrestricted brute-force attacks on user accounts, significantly increasing the risk of account compromise and denial of service for legitimate users. The Supplier's position is that the Sylius core software is not intended to address brute-force attacks; instead, customers deploying a Sylius-based system are supposed to use "firewalls, rate-limiting middleware, or authentication providers" for that functionality.

    Published:6 Feb 2025
    8.6
    High

    CVE-2024-57609

    Last Modified: 15 Apr 2026

    An issue in Kanaries Inc Pygwalker before v.0.4.9.9 allows a remote attacker to obtain sensitive information and execute arbitrary code via the redirect_path parameter of the login redirection function.

    Published:6 Feb 2025
    Unknown

    CVE-2024-57551

    https://github.com/amanbahiniya/cve-disclosures

    4.5
    Medium

    CVE-2024-57523

    Last Modified: 22 Apr 2025

    Cross Site Request Forgery (CSRF) in Users.php in SourceCodester Packers and Movers Management System 1.0 allows attackers to create unauthorized admin accounts via crafted requests sent to an authenticated admin user.

    Published:6 Feb 2025
    6.4
    Medium

    CVE-2024-57522

    Last Modified: 22 Apr 2025

    SourceCodester Packers and Movers Management System v1.0 is vulnerable to Cross Site Scripting (XSS) in Users.php. An attacker can inject a malicious script into the username or name field during user creation.

    Published:3 Feb 2025
    10
    Critical

    CVE-2024-57521

    Last Modified: 6 Jan 2026

    SQL Injection vulnerability in RuoYi v.4.7.9 and before allows a remote attacker to execute arbitrary code via the createTable function in SqlUtil.java.

    Published:23 Dec 2025
    4.8
    Medium

    CVE-2024-57514

    Last Modified: 15 Apr 2026

    The TP-Link Archer A20 v3 router is vulnerable to Cross-site Scripting (XSS) due to improper handling of directory listing paths in the web interface. When a specially crafted URL is visited, the router's web page renders the directory listing and executes arbitrary JavaScript embedded in the URL. This allows the attacker to inject malicious code into the page, executing JavaScript on the victim's browser, which could then be used for further malicious actions. The vulnerability was identified in the 1.0.6 Build 20231011 rel.85717(5553) version.

    Published:28 Jan 2025
    6.5
    Medium

    CVE-2024-57487

    Last Modified: 3 Apr 2025

    In Code-Projects Online Car Rental System 1.0, the file upload feature does not validate file extensions or MIME types allowing an attacker to upload a PHP shell without any restrictions and execute commands on the server.

    Published:13 Jan 2025
    Unknown

    CVE-2024-57484

    https://github.com/yogeswaran6383/CVE-2024-57484

    9.8
    Critical

    CVE-2024-57430

    Last Modified: 24 Jun 2025

    An SQL injection vulnerability in the pjActionGetUser function of PHPJabbers Cinema Booking System v2.0 allows attackers to manipulate database queries via the column parameter. Exploiting this flaw can lead to unauthorized information disclosure, privilege escalation, or database manipulation.

    Published:6 Feb 2025
    5.4
    Medium

    CVE-2024-57429

    Last Modified: 24 Jun 2025

    A cross-site request forgery (CSRF) vulnerability in the pjActionUpdate function of PHPJabbers Cinema Booking System v2.0 allows remote attackers to escalate privileges by tricking an authenticated admin into submitting an unauthorized request.

    Published:6 Feb 2025
    9.3
    Critical

    CVE-2024-57428

    Last Modified: 24 Jun 2025

    A stored cross-site scripting (XSS) vulnerability in PHPJabbers Cinema Booking System v2.0 exists due to unsanitized input in file upload fields (event_img, seat_maps) and seat number configurations (number[new_X] in pjActionCreate). Attackers can inject persistent JavaScript, leading to phishing, malware injection, and session hijacking.

    Published:6 Feb 2025
    6.1
    Medium

    CVE-2024-57427

    Last Modified: 24 Jun 2025

    PHPJabbers Cinema Booking System v2.0 is vulnerable to reflected cross-site scripting (XSS). Multiple endpoints improperly handle user input, allowing malicious scripts to execute in a victim’s browser. Attackers can craft malicious links to steal session cookies or conduct phishing attacks.

    Published:6 Feb 2025
    8.8
    High

    CVE-2024-57394

    Last Modified: 23 Jun 2025

    The quarantine - restore function in Qi-ANXIN Tianqing Endpoint Security Management System v10.0 allows user to restore a malicious file to an arbitrary file path. Attackers can write malicious DLL to system path and perform privilege escalation by leveraging Windows DLL hijacking vulnerabilities.

    Published:21 Apr 2025
    7.3
    High

    CVE-2024-57378

    Last Modified: 15 Apr 2026

    Wazuh SIEM version 4.8.2 is affected by a broken access control vulnerability. This issue allows the unauthorized creation of internal users without assigning any existing user role, potentially leading to privilege escalation or unauthorized access to sensitive resources.

    Published:13 Feb 2025
    8.8
    High

    CVE-2024-57376

    Last Modified: 1 Jul 2025

    Buffer Overflow vulnerability in D-Link DSR-150, DSR-150N, DSR-250, DSR-250N, DSR-500N, DSR-1000N from 3.13 to 3.17B901C allows unauthenticated users to execute remote code execution.

    Published:28 Jan 2025
    8.1
    High

    CVE-2024-57373

    Last Modified: 15 Apr 2026

    Cross Site Request Forgery (CSRF) vulnerability in LifestyleStore v1.0 allows a remote attacker to execute unauthorized actions on behalf of an authenticated user, potentially leading to account modifications or data compromise.

    Published:27 Jan 2025
    Unknown

    CVE-2024-57366

    https://github.com/h4ckusaur/CVE-2024-57366

    6.5
    Medium

    CVE-2024-57241

    Last Modified: 1 Apr 2025

    Dedecms 5.71sp1 and earlier is vulnerable to URL redirect. In the web application, a logic error does not judge the input GET request resulting in URL redirection.

    Published:11 Feb 2025
    5.4
    Medium

    CVE-2024-57175

    Last Modified: 28 Mar 2025

    A Stored Cross-Site Scripting (XSS) vulnerability was identified in the PHPGURUKUL Online Birth Certificate System v1.0 via the profile name to /user/certificate-form.php.

    Published:3 Feb 2025
    9.8
    Critical

    CVE-2024-57040

    Last Modified: 22 Apr 2026

    TP-Link TL-WR845N devices with firmware TL-WR845N(UN)_V4_200909 and TL-WR845N(UN)_V4_190219 was discovered to contain a hardcoded password for the root account which can be obtained by analyzing downloaded firmware or via a brute force attack through physical access to the router. NOTE: The supplier has stated that this issue was fixed in firmware versions 250401 or later.

    Published:26 Feb 2025
    7.3
    High

    CVE-2024-56924

    Last Modified: 4 Aug 2025

    A Cross Site Request Forgery (CSRF) vulnerability in Code Astro Internet banking system 2.0.0 allows remote attackers to execute arbitrary JavaScript on the admin page (pages_account), potentially leading to unauthorized actions such as changing account settings or stealing sensitive user information. This vulnerability occurs due to improper validation of user requests, which enables attackers to exploit the system by tricking the admin user into executing malicious scripts.

    Published:22 Jan 2025
    8.1
    High

    CVE-2024-56903

    Last Modified: 15 Apr 2026

    Geovision GV-ASWeb with the version 6.1.1.0 or less allows attackers to modify POST request method with the GET against critical functionalities, such as account management. This vulnerability is used in chain with CVE-2024-56901 for a successful CSRF attack.

    Published:3 Feb 2025
    7.5
    High

    CVE-2024-56902

    Last Modified: 8 Apr 2025

    Information disclosure vulnerability in Geovision GV-ASManager web application with the version v6.1.0.0 or less, which discloses account information, including cleartext password.

    Source:Giorgi Dograshvili
    Published:3 Feb 2025
    8.8
    High

    CVE-2024-56901

    Last Modified: 11 Apr 2025

    A Cross-Site Request Forgery (CSRF) vulnerability in Geovision GV-ASWeb application with the version 6.1.1.0 or less that allows attackers to arbitrarily create Administrator accounts via a crafted GET request method. This vulnerability is used in chain with CVE-2024-56903 for a successful CSRF attack.

    Source:Giorgi Dograshvili
    Published:3 Feb 2025
    8.8
    High

    CVE-2024-56898

    Last Modified: 11 Apr 2025

    Broken access control vulnerability in Geovision GV-ASWeb with version v6.1.0.0 or less. This vulnerability allows low privilege users perform actions that they aren't authorized to, which can be leveraged to escalate privileges, create, modify or delete accounts.

    Source:Giorgi Dograshvili
    Published:3 Feb 2025
    7.5
    High

    CVE-2024-56889

    Last Modified: 18 Apr 2025

    Incorrect access control in the endpoint /admin/m_delete.php of CodeAstro Complaint Management System v1.0 allows unauthorized attackers to arbitrarily delete complaints via modification of the id parameter.

    Published:6 Feb 2025
    8.1
    High

    CVE-2024-56883

    Last Modified: 25 Sept 2025

    Sage DPW before 2024_12_001 is vulnerable to Incorrect Access Control. The implemented role-based access controls are not always enforced on the server side. Low-privileged Sage users with employee role privileges can create external courses for other employees, even though they do not have the option to do so in the user interface. To do this, a valid request to create a course simply needs to be modified, so that the current user ID in the "id" parameter is replaced with the ID of another user.

    Published:18 Feb 2025
    5.4
    Medium

    CVE-2024-56882

    Last Modified: 1 Oct 2025

    Sage DPW before 2024_12_000 is vulnerable to Cross Site Scripting (XSS). Low-privileged Sage users with employee role privileges can permanently store JavaScript code in the Kurstitel and Kurzinfo input fields. The injected payload is executed for each authenticated user who views and interacts with the modified data elements.

    Published:18 Feb 2025
    6.9
    Medium

    CVE-2024-56801

    Last Modified: 7 Feb 2025

    Tasklists provides plugin tasklists for GLPI. Versions prior to 2.0.4 have a blind SQL injection vulnerability. Version 2.0.4 contains a patch for the vulnerability.

    Published:30 Dec 2024
    7.4
    High

    CVE-2024-56800

    Last Modified: 15 Apr 2026

    Firecrawl is a web scraper that allows users to extract the content of a webpage for a large language model. Versions prior to 1.1.1 contain a server-side request forgery (SSRF) vulnerability. The scraping engine could be exploited by crafting a malicious site that redirects to a local IP address. This allowed exfiltration of local network resources through the API. The cloud service was patched on December 27th, 2024, and the maintainers have checked that no user data was exposed by this vulnerability. Scraping engines used in the open sourced version of Firecrawl were patched on December 29th, 2024, except for the playwright services which the maintainers have determined to be un-patchable. All users of open-source software (OSS) Firecrawl should upgrade to v1.1.1. As a workaround, OSS Firecrawl users should supply the playwright services with a secure proxy. A proxy can be specified through the `PROXY_SERVER` env in the environment variables. Please refer to the documentation for instructions. Ensure that the proxy server one is using is setup to block all traffic going to link-local IP addresses.

    Published:30 Dec 2024
    2.1
    Low

    CVE-2024-56512

    Last Modified: 11 Feb 2025

    Apache NiFi 1.10.0 through 2.0.0 are missing fine-grained authorization checking for Parameter Contexts, referenced Controller Services, and referenced Parameter Providers, when creating new Process Groups. Creating a new Process Group can include binding to a Parameter Context, but in cases where the Process Group did not reference any Parameter values, the framework did not check user authorization for the bound Parameter Context. Missing authorization for a bound Parameter Context enabled clients to download non-sensitive Parameter values after creating the Process Group. Creating a new Process Group can also include referencing existing Controller Services or Parameter Providers. The framework did not check user authorization for referenced Controller Services or Parameter Providers, enabling clients to create Process Groups and use these components that were otherwise unauthorized. This vulnerability is limited in scope to authenticated users authorized to create Process Groups. The scope is further limited to deployments with component-based authorization policies. Upgrading to Apache NiFi 2.1.0 is the recommended mitigation, which includes authorization checking for Parameter and Controller Service references on Process Group creation.

    Published:28 Dec 2024
    3.6
    Low

    CVE-2024-56433

    Last Modified: 15 Apr 2026

    shadow-utils (aka shadow) 4.4 through 4.17.0 establishes a default /etc/subuid behavior (e.g., uid 100000 through 165535 for the first user account) that can realistically conflict with the uids of users defined on locally administered networks, potentially leading to account takeover, e.g., by leveraging newuidmap for access to an NFS home directory (or same-host resources in the case of remote logins by these local network users). NOTE: it may also be argued that system administrators should not have assigned uids, within local networks, that are within the range that can occur in /etc/subuid.

    Published:26 Dec 2024
    Items Per Page