8.8
    High

    CVE-2024-51442

    Last Modified: 15 Apr 2026

    Command Injection in Minidlna version v1.3.3 and before allows an attacker to execute arbitrary OS commands via a specially crafted minidlna.conf configuration file.

    Published:8 Jan 2025
    Unknown

    CVE-2024-51435

    https://github.com/bevennyamande/CVE-2024-51435

    6.4
    Medium

    CVE-2024-51430

    Last Modified: 15 Apr 2026

    Cross Site Scripting vulnerability in online diagnostic lab management system using php v.1.0 allows a remote attacker to execute arbitrary code via the Test Name parameter on the diagnostic/add-test.php component.

    Published:31 Oct 2024
    7.5
    High

    CVE-2024-51428

    Last Modified: 14 Jan 2026

    An issue in Espressif Esp idf v5.3.0 allows attackers to cause a Denial of Service (DoS) via a crafted data channel packet.

    Published:7 Nov 2024
    10
    Critical

    CVE-2024-51378

    Last Modified: 13 Apr 2025

    getresetstatus in dns/views.py and ftp/views.py in CyberPanel (aka Cyber Panel) before 1c0c6cb allows remote attackers to bypass authentication and execute arbitrary commands via /dns/getresetstatus or /ftp/getresetstatus by bypassing secMiddleware (which is only for a POST request) and using shell metacharacters in the statusfile property, as exploited in the wild in October 2024 by PSAUX. Versions through 2.3.6 and (unpatched) 2.3.7 are affected.

    Source:Luka Petrovic (refr4g)
    Published:29 Oct 2024
    9.8
    Critical

    CVE-2024-51358

    Last Modified: 15 Apr 2026

    An issue in Linux Server Heimdall v.2.6.1 allows a remote attacker to execute arbitrary code via a crafted script to the Add new application.

    Published:5 Nov 2024
    3.8
    Low

    CVE-2024-51324

    Last Modified: 15 Apr 2026

    An issue in the BdApiUtil driver of Baidu Antivirus v5.2.3.116083 allows attackers to terminate arbitrary process via executing a BYOVD (Bring Your Own Vulnerable Driver) attack.

    Published:11 Feb 2025
    7.5
    High

    CVE-2024-51179

    Last Modified: 29 Sept 2025

    An issue in Open 5GS v.2.7.1 allows a remote attacker to cause a denial of service via the Network Function Virtualizations (NFVs) such as the User Plane Function (UPF) and the Session Management Function (SMF), The Packet Data Unit (PDU) session establishment process.

    Published:12 Nov 2024
    9.8
    Critical

    CVE-2024-51132

    Last Modified: 15 Apr 2026

    An XML External Entity (XXE) vulnerability in HAPI FHIR before v6.4.0 allows attackers to access sensitive information or execute arbitrary code via supplying a crafted request containing malicious XML entities.

    Published:5 Nov 2024
    5.4
    Medium

    CVE-2024-51032

    Last Modified: 21 Nov 2024

    A Cross-site Scripting (XSS) vulnerability in manage_recipient.php of Sourcecodester Toll Tax Management System 1.0 allows remote authenticated users to inject arbitrary web scripts via the "owner" input field.

    Published:8 Nov 2024
    5.4
    Medium

    CVE-2024-51031

    Last Modified: 21 Nov 2024

    A Cross-site Scripting (XSS) vulnerability in manage_account.php in Sourcecodester Cab Management System 1.0 allows remote authenticated users to inject arbitrary web scripts via the "First Name," "Middle Name," and "Last Name" fields.

    Published:8 Nov 2024
    6.5
    Medium

    CVE-2024-51030

    Last Modified: 21 Nov 2024

    A SQL injection vulnerability in manage_client.php and view_cab.php of Sourcecodester Cab Management System 1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter, leading to unauthorized access and potential compromise of sensitive data within the database.

    Published:8 Nov 2024
    5.4
    Medium

    CVE-2024-51026

    Last Modified: 15 Apr 2026

    The NetAdmin IAM system (version 4.0.30319) has a Cross Site Scripting (XSS) vulnerability in the /BalloonSave.ashx endpoint, where it is possible to inject a malicious payload into the Content= field.

    Published:11 Nov 2024
    7.3
    High

    CVE-2024-50986

    Last Modified: 7 Jul 2025

    An issue in Clementine v.1.3.1 allows a local attacker to execute arbitrary code via a crafted DLL file.

    Published:15 Nov 2024
    6.5
    Medium

    CVE-2024-50972

    Last Modified: 18 Nov 2024

    A SQL injection vulnerability in printtool.php of Itsourcecode Construction Management System 1.0 allows remote attackers to execute arbitrary SQL commands via the borrow_id parameter.

    Published:13 Nov 2024
    6.5
    Medium

    CVE-2024-50971

    Last Modified: 18 Nov 2024

    A SQL injection vulnerability in print.php of Itsourcecode Construction Management System 1.0 allows remote attackers to execute arbitrary SQL commands via the map_id parameter.

    Published:13 Nov 2024
    6.5
    Medium

    CVE-2024-50970

    Last Modified: 18 Nov 2024

    A SQL injection vulnerability in orderview1.php of Itsourcecode Online Furniture Shopping Project 1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Published:13 Nov 2024
    6.1
    Medium

    CVE-2024-50969

    Last Modified: 21 Nov 2024

    A Reflected cross-site scripting (XSS) vulnerability in browse.php of Code-projects Jonnys Liquor 1.0 allows remote attackers to inject arbitrary web scripts or HTML via the search parameter.

    Published:13 Nov 2024
    7.5
    High

    CVE-2024-50968

    Last Modified: 20 Nov 2024

    A business logic vulnerability exists in the Add to Cart function of itsourcecode Agri-Trading Online Shopping System 1.0, which allows remote attackers to manipulate the quant parameter when adding a product to the cart. By setting the quantity value to -0, an attacker can exploit a flaw in the application's total price calculation logic. This vulnerability causes the total price to be reduced to zero, allowing the attacker to add items to the cart and proceed to checkout.

    Published:14 Nov 2024
    6.5
    Medium

    CVE-2024-50967

    Last Modified: 15 Apr 2026

    The /rest/rights/ REST API endpoint in Becon DATAGerry through 2.2.0 contains an Incorrect Access Control vulnerability. An attacker can remotely access this endpoint without authentication, leading to unauthorized disclosure of sensitive information.

    Published:17 Jan 2025
    Unknown

    CVE-2024-50964

    https://github.com/fdzdev/CVE-2024-50964

    Unknown

    CVE-2024-50962

    https://github.com/fdzdev/CVE-2024-50962

    Unknown

    CVE-2024-50961

    https://github.com/fdzdev/CVE-2024-50961

    7.5
    High

    CVE-2024-50945

    Last Modified: 15 Apr 2026

    An improper access control vulnerability exists in SimplCommerce at commit 230310c8d7a0408569b292c5a805c459d47a1d8f, allowing users to submit reviews without verifying if they have purchased the product.

    Published:27 Dec 2024
    9.8
    Critical

    CVE-2024-50944

    Last Modified: 15 Apr 2026

    Integer overflow vulnerability exists in SimplCommerce at commit 230310c8d7a0408569b292c5a805c459d47a1d8f in the shopping cart functionality. The issue lies in the quantity parameter in the CartController's AddToCart method.

    Published:27 Dec 2024
    6.1
    Medium

    CVE-2024-50861

    Last Modified: 14 Apr 2025

    The ip_mod_dns_key_form.cgi request in GestioIP v3.5.7 is vulnerable to Stored XSS. An attacker can inject malicious code into the "TSIG Key" field, which is saved in the database and triggers XSS when viewed, enabling data exfiltration and CSRF attacks.

    Source:Maximiliano Belino
    Published:14 Jan 2025
    4.8
    Medium

    CVE-2024-50859

    Last Modified: 14 Apr 2025

    The ip_import_acl_csv request in GestioIP v3.5.7 is vulnerable to Reflected XSS. When a user uploads an improperly formatted file, the content may be reflected in the HTML response, allowing the attacker to execute malicious scripts or exfiltrate data.

    Source:Maximiliano Belino
    Published:14 Jan 2025
    8.8
    High

    CVE-2024-50858

    Last Modified: 14 Apr 2025

    Multiple endpoints in GestioIP v3.5.7 are vulnerable to Cross-Site Request Forgery (CSRF). An attacker can execute actions via the admin's browser by hosting a malicious URL, leading to data modification, deletion, or exfiltration.

    Source:Maximiliano Belino
    Published:14 Jan 2025
    4.8
    Medium

    CVE-2024-50857

    Last Modified: 14 Apr 2025

    The ip_do_job request in GestioIP v3.5.7 is vulnerable to Cross-Site Scripting (XSS). It allows data exfiltration and enables CSRF attacks. The vulnerability requires specific user permissions within the application to exploit successfully.

    Source:Maximiliano Belino
    Published:14 Jan 2025
    4.8
    Medium

    CVE-2024-50849

    Last Modified: 20 Oct 2025

    A Stored Cross-Site Scripting (XSS) vulnerability in the "Rules" functionality of WorldServer v11.8.2 allows a remote authenticated attacker to execute arbitrary JavaScript code.

    Published:18 Nov 2024
    6.5
    Medium

    CVE-2024-50848

    Last Modified: 20 Oct 2025

    An XML External Entity (XXE) vulnerability in the Import object and Translation Memory import functionalities of WorldServer v11.8.2 to access sensitive information and execute arbitrary commands via supplying a crafted .tmx file.

    Published:18 Nov 2024
    7.8
    High

    CVE-2024-50804

    Last Modified: 15 Apr 2026

    Insecure Permissions vulnerability in Micro-star International MSI Center Pro 2.1.37.0 allows a local attacker to execute arbitrary code via the Device_DeviceID.dat.bak file within the C:\ProgramData\MSI\One Dragon Center\Data folder

    Published:18 Nov 2024
    6.1
    Medium

    CVE-2024-50803

    Last Modified: 13 Jun 2025

    The mediapool feature of the Redaxo Core CMS application v 5.17.1 is vulnerable to Cross Site Scripting(XSS) which allows a remote attacker to escalate privileges

    Published:19 Nov 2024
    6.1
    Medium

    CVE-2024-50677

    Last Modified: 13 Jun 2025

    A cross-site scripting (XSS) vulnerability in OroPlatform CMS v5.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Search parameter.

    Published:6 Dec 2024
    9.8
    Critical

    CVE-2024-50672

    Last Modified: 15 Apr 2025

    A NoSQL injection vulnerability in Adapt Learning Adapt Authoring Tool <= 0.11.3 allows unauthenticated attackers to reset user and administrator account passwords via the "Reset password" feature. The vulnerability occurs due to insufficient validation of user input, which is used as a query in Mongoose's find() function. This makes it possible for attackers to perform a full takeover of the administrator account. Attackers can then use the newly gained administrative privileges to upload a custom plugin to perform remote code execution (RCE) on the server hosting the web application.

    Source:Eui Chul Chung
    Published:25 Nov 2024
    6.8
    Medium

    CVE-2024-50657

    Last Modified: 15 Apr 2026

    An issue in Owncloud android apk v.4.3.1 allows a physically proximate attacker to escalate privileges via the PassCodeViewModel class, specifically in the checkPassCodeIsValid method

    Published:22 Nov 2024
    Low

    CVE-2024-50633

    Last Modified: 19 Sept 2025

    A Broken Object Level Authorization (BOLA) vulnerability in Indico through 3.3.5 allows attackers to read information by sending a crafted POST request to the component /api/principals. NOTE: this is disputed by the Supplier because the product intentionally lets all users retrieve certain information about other user accounts (this functionality is, in the current design, not restricted to any privileged roles such as event organizer).

    Published:16 Jan 2025
    5.3
    Medium

    CVE-2024-50629

    Last Modified: 17 Nov 2025

    Improper encoding or escaping of output vulnerability in the webapi component in Synology BeeStation OS (BSM) before 1.1-65374 and Synology DiskStation Manager (DSM) before 7.1.1-42962-7, 7.2-64570-4, 7.2.1-69057-6 and 7.2.2-72806-1 allow remote attackers to read limited files via unspecified vectors.

    Published:19 Mar 2025
    9.8
    Critical

    CVE-2024-50623

    Last Modified: 5 Nov 2025

    In Cleo Harmony before 5.8.0.21, VLTrader before 5.8.0.21, and LexiCom before 5.8.0.21, there is an unrestricted file upload and download that could lead to remote code execution.

    Published:27 Oct 2024
    10
    Critical

    CVE-2024-50603

    Last Modified: 5 Nov 2025

    An issue was discovered in Aviatrix Controller before 7.1.4191 and 7.2.x before 7.2.4996. Due to the improper neutralization of special elements used in an OS command, an unauthenticated attacker is able to execute arbitrary code. Shell metacharacters can be sent to /v1/api in cloud_type for list_flightpath_destination_instances, or src_cloud_type for flightpath_connection_test.

    Published:8 Jan 2025
    5.9
    Medium

    CVE-2024-50602

    Last Modified: 15 Oct 2025

    An issue was discovered in libexpat before 2.6.4. There is a crash within the XML_ResumeParser function because XML_StopParser can stop/suspend an unstarted parser.

    Published:27 Oct 2024
    4.4
    Medium

    CVE-2024-50562

    Last Modified: 20 Jun 2025

    An Insufficient Session Expiration vulnerability [CWE-613] in FortiOS SSL-VPN version 7.6.0, version 7.4.6 and below, version 7.2.10 and below, 7.0 all versions, 6.4 all versions may allow an attacker in possession of a cookie used to log in the SSL-VPN portal to log in again, although the session has expired or was logged out.

    Source:Shahid Hakim
    Published:10 Jun 2025
    10
    Critical

    CVE-2024-50526

    Last Modified: 23 Apr 2026

    Unrestricted Upload of File with Dangerous Type vulnerability in Lindeni Mahlalela Multi Purpose Mail Form multi-purpose-mail-form allows Upload a Web Shell to a Web Server.This issue affects Multi Purpose Mail Form: from n/a through <= 1.0.2.

    Published:4 Nov 2024
    10
    Critical

    CVE-2024-50510

    Last Modified: 23 Apr 2026

    Unrestricted Upload of File with Dangerous Type vulnerability in webandprint AR For Woocommerce ar-for-woocommerce allows Upload a Web Shell to a Web Server.This issue affects AR For Woocommerce: from n/a through <= 6.3.

    Published:30 Oct 2024
    8.6
    High

    CVE-2024-50509

    Last Modified: 23 Apr 2026

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Chetan Khandla Woocommerce Product Design woo-product-design allows Path Traversal.This issue affects Woocommerce Product Design: from n/a through <= 1.0.0.

    Published:30 Oct 2024
    7.5
    High

    CVE-2024-50508

    Last Modified: 23 Apr 2026

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Chetan Khandla Woocommerce Product Design woo-product-design allows Path Traversal.This issue affects Woocommerce Product Design: from n/a through <= 1.0.0.

    Published:30 Oct 2024
    9.8
    Critical

    CVE-2024-50507

    Last Modified: 23 Apr 2026

    Deserialization of Untrusted Data vulnerability in Daschmi DS.DownloadList dsdownloadlist allows Object Injection.This issue affects DS.DownloadList: from n/a through <= 1.3.

    Published:30 Oct 2024
    10
    Critical

    CVE-2024-50498

    Last Modified: 23 Apr 2026

    Improper Control of Generation of Code ('Code Injection') vulnerability in Ajit Bohra WP Query Console wp-query-console allows Code Injection.This issue affects WP Query Console: from n/a through <= 1.0.

    Published:28 Oct 2024
    10
    Critical

    CVE-2024-50493

    Last Modified: 23 Apr 2026

    Unrestricted Upload of File with Dangerous Type vulnerability in masterhomepage Automatic Translation automatic-translation allows Upload a Web Shell to a Web Server.This issue affects Automatic Translation: from n/a through <= 1.0.4.

    Published:29 Oct 2024
    8.3
    High

    CVE-2024-50492

    Last Modified: 23 Apr 2026

    Improper Control of Generation of Code ('Code Injection') vulnerability in Scott Paterson ScottCart scottcart allows Code Injection.This issue affects ScottCart: from n/a through <= 1.1.

    Published:28 Oct 2024
    Items Per Page