9.8
    Critical

    CVE-2024-36042

    Last Modified: 29 May 2025

    Silverpeas before 6.3.5 allows authentication bypass by omitting the Password field to AuthenticationServlet, often providing an unauthenticated user with superadmin access.

    Published:3 Jun 2024
    6.3
    Medium

    CVE-2024-36039

    Last Modified: 15 Apr 2026

    PyMySQL through 1.1.0 allows SQL injection if used with untrusted JSON input because keys are not escaped by escape_dict.

    Published:21 May 2024
    8.8
    High

    CVE-2024-35584

    Last Modified: 17 Jul 2025

    SQL injection vulnerabilities were discovered in Ajax.php, ForWindow.php, ForExport.php, Modules.php, functions/HackingLogFnc.php in OpenSis Community Edition 9.1 to 8.0, and possibly earlier versions. It is possible for an authenticated user to perform SQL Injection due to the lack to sanitisation. The application takes arbitrary value from "X-Forwarded-For" header and appends it to a SQL INSERT statement directly, leading to SQL Injection.

    Published:15 Oct 2024
    7.6
    High

    CVE-2024-35540

    Last Modified: 13 Apr 2025

    A stored cross-site scripting (XSS) vulnerability in Typecho v1.3.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.

    Source:cyberaz0r
    Published:20 Aug 2024
    6.5
    Medium

    CVE-2024-35539

    Last Modified: 13 Apr 2025

    Typecho v1.3.0 was discovered to contain a race condition vulnerability in the post commenting function. This vulnerability allows attackers to post several comments before the spam protection checks if the comments are posted too frequently.

    Source:cyberaz0r
    Published:19 Aug 2024
    5.3
    Medium

    CVE-2024-35538

    Last Modified: 28 Apr 2025

    Typecho v1.3.0 was discovered to contain a Client IP Spoofing vulnerability, which allows attackers to falsify their IP addresses by specifying an arbitrary IP as value of X-Forwarded-For or Client-Ip headers while performing HTTP requests.

    Published:19 Aug 2024
    4.7
    Medium

    CVE-2024-35511

    Last Modified: 3 Apr 2025

    phpgurukul Men Salon Management System v2.0 is vulnerable to SQL Injection via the "username" parameter of /msms/admin/index.php.

    Published:28 May 2024
    6.4
    Medium

    CVE-2024-35475

    Last Modified: 12 Nov 2025

    A Cross-Site Request Forgery (CSRF) vulnerability was discovered in OpenKM Community Edition on or before version 6.3.12. The vulnerability exists in /admin/DatabaseQuery, which allows an attacker to manipulate a victim with administrative privileges to execute arbitrary SQL commands.

    Published:22 May 2024
    9.8
    Critical

    CVE-2024-35469

    Last Modified: 11 Apr 2025

    A SQL injection vulnerability in /hrm/user/ in SourceCodester Human Resource Management System 1.0 allows attackers to execute arbitrary SQL commands via the password parameter.

    Published:30 May 2024
    5.4
    Medium

    CVE-2024-35468

    Last Modified: 11 Apr 2025

    A SQL injection vulnerability in /hrm/index.php in SourceCodester Human Resource Management System 1.0 allows attackers to execute arbitrary SQL commands via the password parameter.

    Published:30 May 2024
    9.8
    Critical

    CVE-2024-35374

    Last Modified: 10 Jun 2025

    Mocodo Mocodo Online 4.2.6 and below does not properly sanitize the sql_case input field in /web/generate.php, allowing remote attackers to execute arbitrary commands and potentially command injection, leading to remote code execution (RCE) under certain conditions.

    Published:24 May 2024
    8.4
    High

    CVE-2024-35333

    Last Modified: 15 Apr 2026

    A stack-buffer-overflow vulnerability exists in the read_charset_decl function of html2xhtml 1.3. This vulnerability occurs due to improper bounds checking when copying data into a fixed-size stack buffer. An attacker can exploit this vulnerability by providing a specially crafted input to the vulnerable function, causing a buffer overflow and potentially leading to arbitrary code execution, denial of service, or data corruption.

    Published:29 May 2024
    5.6
    Medium

    CVE-2024-35315

    Last Modified: 7 Jul 2025

    A vulnerability in the Desktop Client of Mitel MiCollab through 9.7.1.110, and MiVoice Business Solution Virtual Instance (MiVB SVI) 1.0.0.25, could allow an authenticated attacker to conduct a privilege escalation attack due to improper file validation. A successful exploit could allow an attacker to run arbitrary code with elevated privileges.

    Published:21 Oct 2024
    9.8
    Critical

    CVE-2024-35286

    Last Modified: 7 Jul 2025

    A vulnerability in NuPoint Messenger (NPM) of Mitel MiCollab through 9.8.0.33 allows an unauthenticated attacker to conduct a SQL injection attack due to insufficient sanitization of user input. A successful exploit could allow an attacker to access sensitive information and execute arbitrary database and management operations.

    Published:21 Oct 2024
    7.8
    High

    CVE-2024-35250

    Last Modified: 20 Jul 2026

    Windows Kernel-Mode Driver Elevation of Privilege Vulnerability

    Published:11 Jun 2024
    8.8
    High

    CVE-2024-35242

    Last Modified: 15 Apr 2026

    Composer is a dependency manager for PHP. On the 2.x branch prior to versions 2.2.24 and 2.7.7, the `composer install` command running inside a git/hg repository which has specially crafted branch names can lead to command injection. This requires cloning untrusted repositories. Patches are available in version 2.2.24 for 2.2 LTS or 2.7.7 for mainline. As a workaround, avoid cloning potentially compromised repositories.

    Published:10 Jun 2024
    7.8
    High

    CVE-2024-35205

    Last Modified: 15 Apr 2026

    The WPS Office (aka cn.wps.moffice_eng) application before 17.0.0 for Android fails to properly sanitize file names before processing them through external application interactions, leading to a form of path traversal. This potentially enables any application to dispatch a crafted library file, aiming to overwrite an existing native library utilized by WPS Office. Successful exploitation could result in the execution of arbitrary commands under the guise of WPS Office's application ID.

    Published:13 May 2024
    5.3
    Medium

    CVE-2024-35176

    Last Modified: 3 Nov 2025

    REXML is an XML toolkit for Ruby. The REXML gem before 3.2.6 has a denial of service vulnerability when it parses an XML that has many `<`s in an attribute value. Those who need to parse untrusted XMLs may be impacted to this vulnerability. The REXML gem 3.2.7 or later include the patch to fix this vulnerability. As a workaround, don't parse untrusted XMLs.

    Published:16 May 2024
    6.8
    Medium

    CVE-2024-35133

    Last Modified: 13 Apr 2025

    IBM Security Verify Access 10.0.0 through 10.0.8 OIDC Provider could allow a remote authenticated attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially crafted Web site, a remote attacker could exploit this vulnerability to spoof the URL displayed to redirect a user to a malicious Web site that would appear to be trusted. This could allow the attacker to obtain highly sensitive information or conduct further attacks against the victim.

    Source:Giulio Garzia
    Published:29 Aug 2024
    4.6
    Medium

    CVE-2024-35106

    Last Modified: 15 Apr 2026

    NEXTU FLETA AX1500 WIFI6 v1.0.3 was discovered to contain a buffer overflow at /boafrm/formIpQoS. This vulnerability allows attackers to cause a Denial of Service (DoS) or potentially arbitrary code execution via a crafted POST request.

    Published:7 Feb 2025
    6.5
    Medium

    CVE-2024-34958

    Last Modified: 15 Apr 2025

    idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component admin/banner_deal.php?mudi=add

    Published:16 May 2024
    9.8
    Critical

    CVE-2024-34833

    Last Modified: 30 Apr 2025

    Sourcecodester Payroll Management System v1.0 is vulnerable to File Upload. Users can upload images via the "save_settings" page. An unauthenticated attacker can leverage this functionality to upload a malicious PHP file instead. Successful exploitation of this vulnerability results in the ability to execute arbitrary code as the user running the web server.

    Published:17 Jun 2024
    9.8
    Critical

    CVE-2024-34832

    Last Modified: 13 Feb 2025

    Directory Traversal vulnerability in CubeCart v.6.5.5 and before allows an attacker to execute arbitrary code via a crafted file uploaded to the _g and node parameters.

    Published:6 Jun 2024
    6.1
    Medium

    CVE-2024-34831

    Last Modified: 17 Jul 2025

    cross-site scripting (XSS) vulnerability in Gibbon Core v26.0.00 allows an attacker to execute arbitrary code via the imageLink parameter in the library_manage_catalog_editProcess.php component.

    Published:10 Sept 2024
    7.8
    High

    CVE-2024-34741

    Last Modified: 17 Dec 2024

    In setForceHideNonSystemOverlayWindowIfNeeded of WindowState.java, there is a possible way for message content to be visible on the screensaver while lock screen visibility settings are restricted by the user due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published:15 Aug 2024
    7.7
    High

    CVE-2024-34740

    Last Modified: 17 Dec 2024

    In attributeBytesBase64 and attributeBytesHex of BinaryXmlSerializer.java, there is a possible arbitrary XML injection due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published:15 Aug 2024
    7.8
    High

    CVE-2024-34739

    Last Modified: 29 Sept 2025

    In shouldRestrictOverlayActivities of UsbProfileGroupSettingsManager.java, there is a possible escape from SUW due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.

    Published:15 Aug 2024
    9.7
    Critical

    CVE-2024-34716

    Last Modified: 21 Jan 2025

    PrestaShop is an open source e-commerce web application. A cross-site scripting (XSS) vulnerability that only affects PrestaShops with customer-thread feature flag enabled is present starting from PrestaShop 8.1.0 and prior to PrestaShop 8.1.6. When the customer thread feature flag is enabled through the front-office contact form, a hacker can upload a malicious file containing an XSS that will be executed when an admin opens the attached file in back office. The script injected can access the session and the security token, which allows it to perform any authenticated action in the scope of the administrator's right. This vulnerability is patched in 8.1.6. A workaround is to disable the customer-thread feature-flag.

    Published:14 May 2024
    6.8
    Medium

    CVE-2024-34693

    Last Modified: 21 Feb 2025

    Improper Input Validation vulnerability in Apache Superset, allows for an authenticated attacker to create a MariaDB connection with local_infile enabled. If both the MariaDB server (off by default) and the local mysql client on the web server are set to allow for local infile, it's possible for the attacker to execute a specific MySQL/MariaDB SQL command that is able to read files from the server and insert their content on a MariaDB database table.This issue affects Apache Superset: before 3.1.3 and version 4.0.0 Users are recommended to upgrade to version 4.0.1 or 3.1.3, which fixes the issue.

    Published:20 Jun 2024
    6.1
    Medium

    CVE-2024-34582

    Last Modified: 15 Apr 2026

    Sunhillo SureLine through 8.10.0 on RICI 5000 devices allows cgi/usrPasswd.cgi userid_change XSS within the Forgot Password feature.

    Published:16 May 2024
    5.9
    Medium

    CVE-2024-34568

    Last Modified: 28 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themeqx LetterPress allows Stored XSS.This issue affects LetterPress: from n/a through 1.2.1.

    Published:8 May 2024
    7.8
    High

    CVE-2024-34474

    Last Modified: 15 Apr 2026

    Clario through 2024-04-11 for Desktop has weak permissions for %PROGRAMDATA%\Clario and tries to load DLLs from there as SYSTEM.

    Published:5 May 2024
    5.5
    Medium

    CVE-2024-34472

    Last Modified: 25 Nov 2025

    An issue was discovered in HSC Mailinspector 5.2.17-3 through v.5.2.18. An authenticated blind SQL injection vulnerability exists in the mliRealtimeEmails.php file. The ordemGrid parameter in a POST request to /mailinspector/mliRealtimeEmails.php does not properly sanitize input, allowing an authenticated attacker to execute arbitrary SQL commands, leading to the potential disclosure of the entire application database.

    Published:6 May 2024
    5.4
    Medium

    CVE-2024-34471

    Last Modified: 17 Jun 2025

    An issue was discovered in HSC Mailinspector 5.2.17-3. A Path Traversal vulnerability (resulting in file deletion) exists in the mliRealtimeEmails.php file. The filename parameter in the export HTML functionality does not properly validate the file location, allowing an attacker to read and delete arbitrary files on the server. This was observed when the mliRealtimeEmails.php file itself was read and subsequently deleted, resulting in a 404 error for the file and disruption of email information loading.

    Published:6 May 2024
    8.6
    High

    CVE-2024-34470

    Last Modified: 17 Jun 2025

    An issue was discovered in HSC Mailinspector 5.2.17-3 through v.5.2.18. An Unauthenticated Path Traversal vulnerability exists in the /public/loader.php file. The path parameter does not properly filter whether the file and directory passed are part of the webroot, allowing an attacker to read arbitrary files on the server.

    Published:6 May 2024
    7.1
    High

    CVE-2024-34469

    Last Modified: 17 Jun 2025

    Rukovoditel before 3.5.3 allows XSS via user_photo to index.php?module=users/registration&action=save.

    Published:4 May 2024
    5.1
    Medium

    CVE-2024-34463

    Last Modified: 15 Apr 2026

    BPL Personal Weighing Scale PWS-01BT IND/09/18/599 devices send sensitive information in unencrypted BLE packets. (The packet data also lacks authentication and integrity protection.)

    Published:3 Sept 2024
    6.1
    Medium

    CVE-2024-34452

    Last Modified: 11 Apr 2025

    CMSimple_XH 1.7.6 allows XSS by uploading a crafted SVG document.

    Published:21 Jun 2024
    7.1
    High

    CVE-2024-34444

    Last Modified: 28 Apr 2026

    Missing Authorization vulnerability in ThemePunch OHG Slider Revolution.This issue affects Slider Revolution: from n/a before 6.7.0.

    Published:19 Jun 2024
    7.2
    High

    CVE-2024-34370

    Last Modified: 28 Apr 2026

    Improper Privilege Management vulnerability in WPFactory EAN for WooCommerce allows Privilege Escalation.This issue affects EAN for WooCommerce: from n/a through 4.8.9.

    Published:17 May 2024
    8.6
    High

    CVE-2024-34361

    Last Modified: 2 Oct 2025

    Pi-hole is a DNS sinkhole that protects devices from unwanted content without installing any client-side software. A vulnerability in versions prior to 5.18.3 allows an authenticated user to make internal requests to the server via the `gravity_DownloadBlocklistFromUrl()` function. Depending on some circumstances, the vulnerability could lead to remote command execution. Version 5.18.3 contains a patch for this issue.

    Published:5 Jul 2024
    7.5
    High

    CVE-2024-34351

    Last Modified: 10 Sept 2025

    Next.js is a React framework that can provide building blocks to create web applications. A Server-Side Request Forgery (SSRF) vulnerability was identified in Next.js Server Actions. If the `Host` header is modified, and the below conditions are also met, an attacker may be able to make requests that appear to be originating from the Next.js application server itself. The required conditions are 1) Next.js is running in a self-hosted manner; 2) the Next.js application makes use of Server Actions; and 3) the Server Action performs a redirect to a relative path which starts with a `/`. This vulnerability was fixed in Next.js `14.1.1`.

    Published:9 May 2024
    7.5
    High

    CVE-2024-34350

    Last Modified: 10 Sept 2025

    Next.js is a React framework that can provide building blocks to create web applications. Prior to 13.5.1, an inconsistent interpretation of a crafted HTTP request meant that requests are treated as both a single request, and two separate requests by Next.js, leading to desynchronized responses. This led to a response queue poisoning vulnerability in the affected Next.js versions. For a request to be exploitable, the affected route also had to be making use of the [rewrites](https://nextjs.org/docs/app/api-reference/next-config-js/rewrites) feature in Next.js. The vulnerability is resolved in Next.js `13.5.1` and newer.

    Published:9 May 2024
    8.4
    High

    CVE-2024-34329

    Last Modified: 15 Apr 2026

    Insecure permissions in Entrust Datacard XPS Card Printer Driver 8.5 and earlier without the dxp1-patch-E24-004 patch allows unauthenticated attackers to execute arbitrary code as SYSTEM via a crafted DLL payload.

    Published:22 Jul 2024
    6.3
    Medium

    CVE-2024-34328

    Last Modified: 15 Apr 2026

    An open redirect in Sielox AnyWare v2.1.2 allows attackers to execute a man-in-the-middle attack via a crafted URL.

    Published:31 Jul 2025
    6.5
    Medium

    CVE-2024-34327

    Last Modified: 6 Aug 2025

    Sielox AnyWare v2.1.2 was discovered to contain a SQL injection vulnerability via the email address field of the password reset form.

    Published:31 Jul 2025
    9.8
    Critical

    CVE-2024-34313

    Last Modified: 15 Apr 2026

    An issue in VPL Jail System up to v4.0.2 allows attackers to execute a directory traversal via a crafted request to a public endpoint.

    Published:24 Jun 2024
    6.1
    Medium

    CVE-2024-34312

    Last Modified: 25 Mar 2025

    Virtual Programming Lab for Moodle up to v4.2.3 was discovered to contain a cross-site scripting (XSS) vulnerability via the component vplide.js.

    Published:24 Jun 2024
    8.8
    High

    CVE-2024-34310

    Last Modified: 15 Apr 2026

    Jin Fang Times Content Management System v3.2.3 was discovered to contain a SQL injection vulnerability via the id parameter.

    Published:10 May 2024
    4.8
    Medium

    CVE-2024-34241

    Last Modified: 19 May 2024

    A cross-site scripting (XSS) vulnerability in Rocketsoft Rocket LMS 1.9 allows an administrator to store a JavaScript payload using the admin web interface when creating new courses and new course notifications.

    Source:Sergio Medeiros
    Published:17 May 2024
    Items Per Page