Unknown

    CVE-2024-55182

    https://github.com/MernJsb/CVE-2024-55182

    9.8
    Critical

    CVE-2024-55099

    Last Modified: 3 Apr 2025

    A SQL Injection vulnerability was found in /admin/index.php in phpgurukul Online Nurse Hiring System v1.0, which allows remote attackers to execute arbitrary SQL commands to get unauthorized database access via the username parameter.

    Published:12 Dec 2024
    6.1
    Medium

    CVE-2024-55060

    Last Modified: 3 Apr 2025

    A cross-site scripting (XSS) vulnerability in the component index.php of Rafed CMS Website v1.44 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.

    Published:13 Mar 2025
    6.1
    Medium

    CVE-2024-55040

    Last Modified: 7 Aug 2025

    Cross Site Scripting vulnerability in Sensaphone WEB600 Monitoring System v.1.6.5.H and before allows a remote attacker to execute arbitrary code via a crafted GET requests to /@.xml, placing payloads in the g7200, g7300, g4601, and g1F02 parameters.

    Published:21 Jul 2025
    5.4
    Medium

    CVE-2024-54951

    Last Modified: 14 Aug 2025

    Monica 4.1.2 is vulnerable to Cross Site Scripting (XSS). A malicious user can create a malformed contact and use that contact in the "HOW YOU MET" customization options to trigger the XSS.

    Published:13 Feb 2025
    6.8
    Medium

    CVE-2024-54916

    Last Modified: 15 Apr 2026

    An issue in the SharedConfig class of Telegram Android APK v.11.7.0 allows a physically proximate attacker to bypass authentication and escalate privileges by manipulating the return value of the checkPasscode method.

    Published:11 Feb 2025
    4.7
    Medium

    CVE-2024-54910

    Last Modified: 15 Apr 2026

    Hasleo Backup Suite Free v4.9.4 and before is vulnerable to Insecure Permissions via the File recovery function.

    Published:10 Jan 2025
    8
    High

    CVE-2024-54887

    Last Modified: 20 Jun 2025

    TP-Link TL-WR940N V3 and V4 with firmware 3.16.9 and earlier contain a buffer overflow via the dnsserver1 and dnsserver2 parameters at /userRpm/Wan6to4TunnelCfgRpm.htm. This vulnerability allows an authenticated attacker to execute arbitrary code on the remote device in the context of the root user.

    Published:9 Jan 2025
    9.1
    Critical

    CVE-2024-54880

    Last Modified: 28 Mar 2025

    SeaCMS V13.1 is vulnerable to Incorrect Access Control. A logic flaw can be exploited by an attacker to allow any user to register accounts in bulk.

    Published:6 Jan 2025
    9.1
    Critical

    CVE-2024-54879

    Last Modified: 28 Mar 2025

    SeaCMS V13.1 is vulnerable to Incorrect Access Control. A logic flaw can be exploited by an attacker to allow any user to recharge members indefinitely.

    Published:6 Jan 2025
    9.8
    Critical

    CVE-2024-54820

    Last Modified: 15 Apr 2026

    XOne Web Monitor v02.10.2024.530 framework 1.0.4.9 was discovered to contain a SQL injection vulnerability in the login page. This vulnerability allows attackers to extract all usernames and passwords via a crafted input.

    Published:24 Feb 2025
    9.1
    Critical

    CVE-2024-54819

    Last Modified: 15 Apr 2026

    I, Librarian before and including 5.11.1 is vulnerable to Server-Side Request Forgery (SSRF) due to improper input validation in classes/security/validation.php

    Published:7 Jan 2025
    5.4
    Medium

    CVE-2024-54795

    Last Modified: 17 Oct 2025

    SpagoBI v3.5.1 contains multiple Stored Cross-Site Scripting (XSS) vulnerabilities in the create/edit forms of the worksheet designer function.

    Published:21 Jan 2025
    9.1
    Critical

    CVE-2024-54794

    Last Modified: 17 Oct 2025

    The script input feature of SpagoBI 3.5.1 allows arbitrary code execution.

    Published:21 Jan 2025
    6.1
    Medium

    CVE-2024-54792

    Last Modified: 17 Oct 2025

    A Cross-Site Request Forgery (CSRF) vulnerability has been found in SpagoBI v3.5.1 in the user administration panel. An authenticated user can lead another user into executing unwanted actions inside the application they are logged in, like adding, editing or deleting users.

    Published:21 Jan 2025
    5.4
    Medium

    CVE-2024-54772

    Last Modified: 30 Jun 2025

    An issue was discovered in the Winbox service of MikroTik RouterOS long-term release v6.43.13 through v6.49.13 and stable v6.43 through v7.17.2. A patch is available in the stable release v6.49.18. A discrepancy in response size between connection attempts made with a valid username and those with an invalid username allows attackers to enumerate for valid accounts.

    Published:11 Feb 2025
    6.3
    Medium

    CVE-2024-54761

    Last Modified: 18 Aug 2025

    BigAnt Office Messenger 5.6.06 is vulnerable to SQL Injection via the 'dev_code' parameter.

    Source:Nicat Abbasov
    Published:9 Jan 2025
    9.8
    Critical

    CVE-2024-54756

    Last Modified: 15 Apr 2026

    A remote code execution (RCE) vulnerability in the ZScript function of ZDoom Team GZDoom v4.13.1 allows attackers to execute arbitrary code via supplying a crafted PK3 file containing a malicious ZScript source file.

    Published:20 Feb 2025
    4.3
    Medium

    CVE-2024-54679

    Last Modified: 5 Sept 2025

    CyberPanel (aka Cyber Panel) before 6778ad1 does not require the FilemanagerAdmin capability for restartMySQL actions.

    Published:5 Dec 2024
    9.1
    Critical

    CVE-2024-54507

    Last Modified: 2 Apr 2026

    A type confusion issue was addressed with improved memory handling. This issue is fixed in iOS 18.2 and iPadOS 18.2, macOS Sequoia 15.2. An attacker with user privileges may be able to read kernel memory.

    Published:27 Jan 2025
    8.8
    High

    CVE-2024-54498

    Last Modified: 2 Apr 2026

    A path handling issue was addressed with improved validation. This issue is fixed in macOS Sequoia 15.2, macOS Sonoma 14.7.2, macOS Ventura 13.7.2. An app may be able to break out of its sandbox.

    Published:11 Dec 2024
    7.2
    High

    CVE-2024-54385

    Last Modified: 23 Apr 2026

    Server-Side Request Forgery (SSRF) vulnerability in princeahmed Radio Player radio-player allows Server Side Request Forgery.This issue affects Radio Player: from n/a through <= 2.0.83.

    Published:16 Dec 2024
    9.8
    Critical

    CVE-2024-54383

    Last Modified: 23 Apr 2026

    Incorrect Privilege Assignment vulnerability in wpweb WooCommerce PDF Vouchers woocommerce-pdf-vouchers allows Privilege Escalation.This issue affects WooCommerce PDF Vouchers: from n/a through < 4.9.9.

    Published:18 Dec 2024
    8.8
    High

    CVE-2024-54379

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in blokhauswp Minterpress minterpress allows Privilege Escalation.This issue affects Minterpress: from n/a through <= 1.0.5.

    Published:16 Dec 2024
    8.8
    High

    CVE-2024-54378

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in Quietly Quietly Insights quietly-insights allows Privilege Escalation.This issue affects Quietly Insights: from n/a through <= 1.2.2.

    Published:16 Dec 2024
    7.5
    High

    CVE-2024-54374

    Last Modified: 23 Apr 2026

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Sabri Sogrid sogrid allows PHP Local File Inclusion.This issue affects Sogrid: from n/a through <= 1.5.6.

    Published:16 Dec 2024
    9.1
    Critical

    CVE-2024-54369

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in ThemeHunk Zita Site Builder ai-site-builder allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Zita Site Builder: from n/a through <= 1.0.2.

    Published:16 Dec 2024
    9.8
    Critical

    CVE-2024-54363

    Last Modified: 23 Apr 2026

    Incorrect Privilege Assignment vulnerability in saiful.total Wp NssUser Register wp-nssuser-register allows Privilege Escalation.This issue affects Wp NssUser Register: from n/a through <= 1.0.0.

    Published:16 Dec 2024
    7.2
    High

    CVE-2024-54330

    Last Modified: 23 Apr 2026

    Server-Side Request Forgery (SSRF) vulnerability in hurraki Hurrakify hurrakify allows Server Side Request Forgery.This issue affects Hurrakify: from n/a through <= 2.4.

    Published:13 Dec 2024
    9.3
    Critical

    CVE-2024-54292

    Last Modified: 23 Apr 2026

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in appsplate Appsplate appsplate allows SQL Injection.This issue affects Appsplate: from n/a through <= 2.1.3.

    Published:13 Dec 2024
    9.9
    Critical

    CVE-2024-54262

    Last Modified: 23 Apr 2026

    Unrestricted Upload of File with Dangerous Type vulnerability in sidngr Import Export For WooCommerce import-export-for-woocommerce allows Upload a Web Shell to a Web Server.This issue affects Import Export For WooCommerce: from n/a through <= 1.6.2.

    Published:13 Dec 2024
    9.8
    Critical

    CVE-2024-54239

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in dugudlabs Eyewear prescription form eyewear-prescription-form allows Privilege Escalation.This issue affects Eyewear prescription form: from n/a through <= 4.0.18.

    Published:13 Dec 2024
    6.4
    Medium

    CVE-2024-54160

    Last Modified: 15 Apr 2026

    dashboards-reporting (aka Dashboards Reports) before 2.19.0.0, as shipped in OpenSearch before 2.19, allows XSS because Markdown is not sanitized when previewing a header or footer.

    Published:12 Feb 2025
    9.3
    Critical

    CVE-2024-54152

    Last Modified: 15 Apr 2026

    Angular Expressions provides expressions for the Angular.JS web framework as a standalone module. Prior to version 1.4.3, an attacker can write a malicious expression that escapes the sandbox to execute arbitrary code on the system. With a more complex (undisclosed) payload, one can get full access to Arbitrary code execution on the system. The problem has been patched in version 1.4.3 of Angular Expressions. Two possible workarounds are available. One may either disable access to `__proto__` globally or make sure that one uses the function with just one argument.

    Published:10 Dec 2024
    10
    Critical

    CVE-2024-54085

    Last Modified: 26 Feb 2026

    AMI’s SPx contains a vulnerability in the BMC where an Attacker may bypass authentication remotely through the Redfish Host Interface. A successful exploitation of this vulnerability may lead to a loss of confidentiality, integrity, and/or availability.

    Published:11 Mar 2025
    9.8
    Critical

    CVE-2024-53924

    Last Modified: 11 Jul 2025

    Pycel through 1.0b30, when operating on an untrusted spreadsheet, allows code execution via a crafted formula in a cell, such as one beginning with the =IF(A1=200, eval("__import__('os').system( substring.

    Published:17 Apr 2025
    9.1
    Critical

    CVE-2024-53900

    Last Modified: 1 Oct 2025

    Mongoose before 8.8.3 can improperly use $where in match, leading to search injection.

    Published:2 Dec 2024
    8.2
    High

    CVE-2024-53704

    Last Modified: 26 Feb 2026

    An Improper Authentication vulnerability in the SSLVPN authentication mechanism allows a remote attacker to bypass authentication.

    Published:9 Jan 2025
    8.1
    High

    CVE-2024-53703

    Last Modified: 4 Nov 2025

    A vulnerability in the SonicWall SMA100 SSLVPN firmware 10.2.1.13-72sv and earlier versions mod_httprp library loaded by the Apache web server allows remote attackers to cause Stack-based buffer overflow and potentially lead to code execution.

    Published:5 Dec 2024
    8.7
    High

    CVE-2024-53691

    Last Modified: 23 Sept 2025

    A link following vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have gained user access to traverse the file system to unintended locations. We have already fixed the vulnerability in the following versions: QTS 5.1.8.2823 build 20240712 and later QTS 5.2.0.2802 build 20240620 and later QuTS hero h5.1.8.2823 build 20240712 and later QuTS hero h5.2.0.2802 build 20240620 and later

    Published:6 Dec 2024
    9.5
    Critical

    CVE-2024-53677

    Last Modified: 15 Jul 2025

    File upload logic in Apache Struts is flawed. An attacker can manipulate file upload params to enable paths traversal and under some circumstances this can lead to uploading a malicious file which can be used to perform Remote Code Execution. This issue affects Apache Struts: from 2.0.0 before 6.4.0. Users are recommended to upgrade to version 6.4.0 at least and migrate to the new file upload mechanism https://struts.apache.org/core-developers/file-upload . If you are not using an old file upload logic based on FileuploadInterceptor your application is safe. You can find more details in  https://cwiki.apache.org/confluence/display/WW/S2-067

    Published:11 Dec 2024
    Unknown

    CVE-2024-53667

    https://github.com/baburkin/struts-uploader-vulnerability

    4.8
    Medium

    CVE-2024-53617

    Last Modified: 15 Apr 2026

    A Cross Site Scripting vulnerability in LibrePhotos before commit 32237 allows attackers to takeover any account via uploading an HTML file on behalf of the admin user using IDOR in file upload.

    Published:2 Dec 2024
    6.5
    Medium

    CVE-2024-53615

    Last Modified: 15 Apr 2026

    A command injection vulnerability in the video thumbnail rendering component of Karl Ward's files.gallery v0.3.0 through 0.11.0 allows remote attackers to execute arbitrary code via a crafted video file.

    Published:30 Jan 2025
    9.8
    Critical

    CVE-2024-53591

    Last Modified: 23 Jun 2025

    An issue in the login page of Seclore v3.27.5.0 allows attackers to bypass authentication via a brute force attack.

    Published:18 Apr 2025
    5.3
    Medium

    CVE-2024-53586

    Last Modified: 11 Apr 2025

    An issue in the relPath parameter of WebFileSys version 2.31.0 allows attackers to perform directory traversal via a crafted HTTP request. By injecting traversal payloads into the parameter, attackers can manipulate file paths and gain unauthorized access to sensitive files, potentially exposing data outside the intended directory.

    Source:Korn Chaisuwan_ Charanin Thongudom_ Pongtorn Angsuchotmetee
    Published:6 Feb 2025
    9.8
    Critical

    CVE-2024-53584

    Last Modified: 14 Apr 2025

    OpenPanel v0.3.4 was discovered to contain an OS command injection vulnerability via the timezone parameter.

    Source:Korn Chaisuwan_ Charanin Thongudom_ Pongtorn Angsuchotmetee
    Published:31 Jan 2025
    7.5
    High

    CVE-2024-53582

    Last Modified: 14 Apr 2025

    An issue found in the Copy and View functions in the File Manager component of OpenPanel v0.3.4 allows attackers to execute a directory traversal via a crafted HTTP request.

    Source:Korn Chaisuwan_ Charanin Thongudom_ Pongtorn Angsuchotmetee
    Published:31 Jan 2025
    9.1
    Critical

    CVE-2024-53537

    Last Modified: 14 Apr 2025

    An issue in OpenPanel v0.3.4 to v0.2.1 allows attackers to execute a directory traversal in File Actions of File Manager.

    Source:Korn Chaisuwan_ Charanin Thongudom_ Pongtorn Angsuchotmetee
    Published:31 Jan 2025
    7.5
    High

    CVE-2024-53522

    Last Modified: 15 Apr 2026

    Bangkok Medical Software HOSxP XE v4.64.11.3 was discovered to contain a hardcoded IDEA Key-IV pair in the HOSxPXE4.exe and HOS-WIN32.INI components. This allows attackers to access sensitive information.

    Published:7 Jan 2025
    Items Per Page