9.4
    Critical

    CVE-2024-34226

    Last Modified: 22 Apr 2025

    SQL injection vulnerability in /php-sqlite-vms/?page=manage_visitor&id=1 in SourceCodester Visitor Management System 1.0 allow attackers to execute arbitrary SQL commands via the id parameters.

    Published:13 May 2024
    6.1
    Medium

    CVE-2024-34225

    Last Modified: 16 Apr 2025

    Cross Site Scripting vulnerability in php-lms/admin/?page=system_info in Computer Laboratory Management System using PHP and MySQL 1.0 allow remote attackers to inject arbitrary web script or HTML via the name, shortname parameters.

    Published:13 May 2024
    7.3
    High

    CVE-2024-34224

    Last Modified: 16 Apr 2025

    Cross Site Scripting vulnerability in /php-lms/classes/Users.php?f=save in Computer Laboratory Management System using PHP and MySQL 1.0 allow remote attackers to inject arbitrary web script or HTML via the firstname, middlename, lastname parameters.

    Published:13 May 2024
    4.3
    Medium

    CVE-2024-34223

    Last Modified: 18 Apr 2025

    Insecure permission vulnerability in /hrm/leaverequest.php in SourceCodester Human Resource Management System 1.0 allow attackers to approve or reject leave ticket.

    Published:13 May 2024
    5.9
    Medium

    CVE-2024-34222

    Last Modified: 18 Apr 2025

    Sourcecodester Human Resource Management System 1.0 is vulnerable to SQL Injection via the searccountry parameter.

    Published:13 May 2024
    8.8
    High

    CVE-2024-34221

    Last Modified: 18 Apr 2025

    Sourcecodester Human Resource Management System 1.0 is vulnerable to Insecure Permissions resulting in privilege escalation.

    Published:13 May 2024
    7.5
    High

    CVE-2024-34220

    Last Modified: 18 Apr 2025

    Sourcecodester Human Resource Management System 1.0 is vulnerable to SQL Injection via the 'leave' parameter.

    Published:9 May 2024
    9.8
    Critical

    CVE-2024-34144

    Last Modified: 10 Oct 2025

    A sandbox bypass vulnerability involving crafted constructor bodies in Jenkins Script Security Plugin 1335.vf07d9ce377a_e and earlier allows attackers with permission to define and run sandboxed scripts, including Pipelines, to bypass the sandbox protection and execute arbitrary code in the context of the Jenkins controller JVM.

    Published:2 May 2024
    9.8
    Critical

    CVE-2024-34102

    Last Modified: 23 Oct 2025

    Adobe Commerce versions 2.4.7, 2.4.6-p5, 2.4.5-p7, 2.4.4-p8 and earlier are affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability that could result in arbitrary code execution. An attacker could exploit this vulnerability by sending a crafted XML document that references external entities. Exploitation of this issue does not require user interaction.

    Published:13 Jun 2024
    9.7
    Critical

    CVE-2024-34070

    Last Modified: 15 Apr 2026

    Froxlor is open source server administration software. Prior to 2.1.9, a Stored Blind Cross-Site Scripting (XSS) vulnerability was identified in the Failed Login Attempts Logging Feature of the Froxlor Application. An unauthenticated User can inject malicious scripts in the loginname parameter on the Login attempt, which will then be executed when viewed by the Administrator in the System Logs. By exploiting this vulnerability, the attacker can perform various malicious actions such as forcing the Administrator to execute actions without their knowledge or consent. For instance, the attacker can force the Administrator to add a new administrator controlled by the attacker, thereby giving the attacker full control over the application. This vulnerability is fixed in 2.1.9.

    Published:10 May 2024
    5.4
    Medium

    CVE-2024-34064

    Last Modified: 3 Nov 2025

    Jinja is an extensible templating engine. The `xmlattr` filter in affected versions of Jinja accepts keys containing non-attribute characters. XML/HTML attributes cannot contain spaces, `/`, `>`, or `=`, as each would then be interpreted as starting a separate attribute. If an application accepts keys (as opposed to only values) as user input, and renders these in pages that other users see as well, an attacker could use this to inject other attributes and perform XSS. The fix for CVE-2024-22195 only addressed spaces but not other characters. Accepting keys as user input is now explicitly considered an unintended use case of the `xmlattr` filter, and code that does so without otherwise validating the input should be flagged as insecure, regardless of Jinja version. Accepting _values_ as user input continues to be safe. This vulnerability is fixed in 3.1.4.

    Published:6 May 2024
    7.6
    High

    CVE-2024-33911

    Last Modified: 28 Apr 2026

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Weblizar School Management Pro.This issue affects School Management Pro: from n/a through 10.3.4.

    Published:2 May 2024
    6.5
    Medium

    CVE-2024-33901

    Last Modified: 13 Jun 2025

    Issue in KeePassXC 2.7.7 allows an attacker (who has the privileges of the victim) to recover some passwords stored in the .kdbx database via a memory dump. NOTE: the vendor disputes this because memory-management constraints make this unavoidable in the current design and other realistic designs.

    Published:20 May 2024
    7.2
    High

    CVE-2024-33896

    Last Modified: 13 Apr 2025

    Cosy+ devices running a firmware 21.x below 21.2s10 or a firmware 22.x below 22.1s3 are vulnerable to code injection due to improper parameter blacklisting. This is fixed in version 21.2s10 and 22.1s3.

    Source:CodeB0ss
    Published:2 Aug 2024
    4
    Medium

    CVE-2024-33883

    Last Modified: 15 Apr 2026

    The ejs (aka Embedded JavaScript templates) package before 3.1.10 for Node.js lacks certain pollution protection.

    Published:28 Apr 2024
    8.8
    High

    CVE-2024-33775

    Last Modified: 24 Aug 2026

    An issue with the Autodiscover component in Nagios XI 2024R1.01 allows a remote attacker to escalate privileges via a crafted Dashlet.

    Published:1 May 2024
    6.3
    Medium

    CVE-2024-33722

    Last Modified: 12 May 2026

    SOPlanning 1.52.00 is vulnerable to SQL Injection by an authenticated user via projets.php with statut[].

    Published:8 May 2026
    Unknown

    CVE-2024-33676

    https://github.com/dersecure/CVE-2024-33676

    6.5
    Medium

    CVE-2024-33648

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Kemory Grubb Recencio Book Reviews recencio-book-reviews allows DOM-Based XSS.This issue affects Recencio Book Reviews: from n/a through <= 1.66.0.

    Published:29 Apr 2024
    9.9
    Critical

    CVE-2024-33644

    Last Modified: 15 Apr 2026

    Improper Control of Generation of Code ('Code Injection') vulnerability in WPCustomify Customify Site Library allows Code Injection.This issue affects Customify Site Library: from n/a through 0.0.9.

    Published:17 May 2024
    9.3
    Critical

    CVE-2024-33559

    Last Modified: 19 May 2024

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in 8theme XStore allows SQL Injection.This issue affects XStore: from n/a through 9.3.5.

    Source:Abdualhadi khalifa
    Published:29 Apr 2024
    8.1
    High

    CVE-2024-33453

    Last Modified: 31 Dec 2025

    Buffer Overflow vulnerability in esp-idf v.5.1 allows a remote attacker to obtain sensitive information via the externalId component.

    Published:17 Oct 2024
    8
    High

    CVE-2024-33438

    Last Modified: 16 Apr 2025

    File Upload vulnerability in CubeCart before 6.5.5 allows an authenticated user to execute arbitrary code via a crafted .phar file.

    Published:29 Apr 2024
    Unknown

    CVE-2024-33421

    https://github.com/sp624/CVE-2024-33421

    Unknown

    CVE-2024-33352

    https://github.com/mmiszczyk/CVE-2024-33352

    4.7
    Medium

    CVE-2024-33299

    Last Modified: 3 Jul 2025

    Cross Site Scripting vulnerability in Microweber v.2.0.9 allows a remote attacker to execute arbitrary code via the First Name and Last Name parameters in the endpoint /admin/module/view?type=users

    Published:10 Jan 2025
    6.1
    Medium

    CVE-2024-33298

    Last Modified: 3 Jul 2025

    Microweber Cross Site Scripting vulnerability in Microweber v.2.0.9 allows a remote attacker to execute arbitrary code via the create new backup function in the endpoint /admin/module/view?type=admin__backup

    Published:10 Jan 2025
    4.7
    Medium

    CVE-2024-33297

    Last Modified: 3 Jul 2025

    Cross Site Scripting vulnerability in Microweber v.2.0.9 allows a remote attacker to execute arbitrary code via the campaign Name (Internal Name) field in the Add new campaign function

    Published:10 Jan 2025
    6.1
    Medium

    CVE-2024-33231

    Last Modified: 15 Apr 2026

    Cross Site Scripting vulnerability in Ferozo Email version 1.1 allows a local attacker to execute arbitrary code via a crafted payload to the PDF preview component.

    Published:18 Nov 2024
    5.4
    Medium

    CVE-2024-33210

    Last Modified: 3 Jul 2025

    A cross-site scripting (XSS) vulnerability has been identified in Flatpress 1.3. This vulnerability allows an attacker to inject malicious scripts into web pages viewed by other users.

    Published:2 Oct 2024
    5.4
    Medium

    CVE-2024-33209

    Last Modified: 14 Mar 2025

    FlatPress v1.3 is vulnerable to Cross Site Scripting (XSS). An attacker can inject malicious JavaScript code into the "Add New Entry" section, which allows them to execute arbitrary code in the context of a victim's web browser.

    Published:2 Oct 2024
    5.3
    Medium

    CVE-2024-33113

    Last Modified: 21 May 2025

    D-LINK DIR-845L <=v1.01KRb03 is vulnerable to Information disclosurey via bsc_sms_inbox.php.

    Published:6 May 2024
    5.4
    Medium

    CVE-2024-33111

    Last Modified: 21 May 2025

    D-Link DIR-845L router <=v1.01KRb03 is vulnerable to Cross Site Scripting (XSS) via /htdocs/webinc/js/bsc_sms_inbox.php.

    Published:6 May 2024
    10
    Critical

    CVE-2024-32962

    Last Modified: 15 Apr 2026

    xml-crypto is an xml digital signature and encryption library for Node.js. In affected versions the default configuration does not check authorization of the signer, it only checks the validity of the signature per section 3.2.2 of the w3 xmldsig-core-20080610 spec. As such, without additional validation steps, the default configuration allows a malicious actor to re-sign an XML document, place the certificate in a `<KeyInfo />` element, and pass `xml-crypto` default validation checks. As a result `xml-crypto` trusts by default any certificate provided via digitally signed XML document's `<KeyInfo />`. `xml-crypto` prefers to use any certificate provided via digitally signed XML document's `<KeyInfo />` even if library was configured to use specific certificate (`publicCert`) for signature verification purposes. An attacker can spoof signature verification by modifying XML document and replacing existing signature with signature generated with malicious private key (created by attacker) and by attaching that private key's certificate to `<KeyInfo />` element. This vulnerability is combination of changes introduced to `4.0.0` on pull request 301 / commit `c2b83f98` and has been addressed in version 6.0.0 with pull request 445 / commit `21201723d`. Users are advised to upgrade. Users unable to upgrade may either check the certificate extracted via `getCertFromKeyInfo` against trusted certificates before accepting the results of the validation or set `xml-crypto's getCertFromKeyInfo` to `() => undefined` forcing `xml-crypto` to use an explicitly configured `publicCert` or `privateKey` for signature verification.

    Published:2 May 2024
    8.6
    High

    CVE-2024-32830

    Last Modified: 25 Nov 2025

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in ThemeKraft BuddyForms allows Server Side Request Forgery, Relative Path Traversal.This issue affects BuddyForms: from n/a through 2.8.8.

    Published:17 May 2024
    9.3
    Critical

    CVE-2024-32709

    Last Modified: 28 Apr 2026

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Plechev Andrey WP-Recall.This issue affects WP-Recall: from n/a through 16.26.5.

    Published:24 Apr 2024
    10
    Critical

    CVE-2024-32700

    Last Modified: 28 Apr 2026

    Unrestricted Upload of File with Dangerous Type vulnerability in Kognetiks Kognetiks Chatbot for WordPress.This issue affects Kognetiks Chatbot for WordPress: from n/a through 2.0.0.

    Published:13 May 2024
    10
    Critical

    CVE-2024-32651

    Last Modified: 15 Apr 2026

    changedetection.io is an open source web page change detection, website watcher, restock monitor and notification service. There is a Server Side Template Injection (SSTI) in Jinja2 that allows Remote Command Execution on the server host. Attackers can run any system command without any restriction and they could use a reverse shell. The impact is critical as the attacker can completely takeover the server machine. This can be reduced if changedetection is behind a login page, but this isn't required by the application (not by default and not enforced).

    Published:25 Apr 2024
    9.8
    Critical

    CVE-2024-32640

    Last Modified: 15 Apr 2026

    MASA CMS is an Enterprise Content Management platform based on open source technology. Versions prior to 7.4.5, 7.3.12, and 7.2.7 contain a SQL injection vulnerability in the `processAsyncObject` method that can result in remote code execution. Versions 7.4.5, 7.3.12, and 7.2.7 contain a fix for the issue.

    Published:11 Aug 2025
    8.1
    High

    CVE-2024-32523

    Last Modified: 23 Apr 2026

    Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in EverPress Mailster mailster.This issue affects Mailster: from n/a through <= 4.0.6.

    Published:17 May 2024
    8.4
    High

    CVE-2024-32462

    Last Modified: 16 Dec 2025

    Flatpak is a system for building, distributing, and running sandboxed desktop applications on Linux. in versions before 1.10.9, 1.12.9, 1.14.6, and 1.15.8, a malicious or compromised Flatpak app could execute arbitrary code outside its sandbox. Normally, the `--command` argument of `flatpak run` expects to be given a command to run in the specified Flatpak app, optionally along with some arguments. However it is possible to instead pass `bwrap` arguments to `--command=`, such as `--bind`. It's possible to pass an arbitrary `commandline` to the portal interface `org.freedesktop.portal.Background.RequestBackground` from within a Flatpak app. When this is converted into a `--command` and arguments, it achieves the same effect of passing arguments directly to `bwrap`, and thus can be used for a sandbox escape. The solution is to pass the `--` argument to `bwrap`, which makes it stop processing options. This has been supported since bubblewrap 0.3.0. All supported versions of Flatpak require at least that version of bubblewrap. xdg-desktop-portal version 1.18.4 will mitigate this vulnerability by only allowing Flatpak apps to create .desktop files for commands that do not start with --. The vulnerability is patched in 1.15.8, 1.10.9, 1.12.9, and 1.14.6.

    Published:18 Apr 2024
    9.8
    Critical

    CVE-2024-32459

    Last Modified: 3 Nov 2025

    FreeRDP is a free implementation of the Remote Desktop Protocol. FreeRDP based clients and servers that use a version of FreeRDP prior to 3.5.0 or 2.11.6 are vulnerable to out-of-bounds read. Versions 3.5.0 and 2.11.6 patch the issue. No known workarounds are available.

    Published:22 Apr 2024
    9.8
    Critical

    CVE-2024-32444

    Last Modified: 23 Apr 2026

    Incorrect Privilege Assignment vulnerability in InspiryThemes RealHomes realhomes allows Privilege Escalation.This issue affects RealHomes: from n/a through <= 4.3.6.

    Published:3 Sept 2025
    7.6
    High

    CVE-2024-32399

    Last Modified: 15 Apr 2026

    Directory Traversal vulnerability in RaidenMAILD Mail Server v.4.9.4 and before allows a remote attacker to obtain sensitive information via the /webeditor/ component.

    Published:22 Apr 2024
    7.5
    High

    CVE-2024-32371

    Last Modified: 17 Jun 2025

    An issue in HSC Cybersecurity HC Mailinspector 5.2.17-3 through 5.2.18 allows a regular user account to escalate their privileges and gain administrative access by changing the type parameter from 1 to 0.

    Published:7 May 2024
    9.8
    Critical

    CVE-2024-32370

    Last Modified: 17 Jun 2025

    An issue in HSC Cybersecurity HC Mailinspector 5.2.17-3 through 5.2.18 allows a remote attacker to obtain sensitive information via a crafted payload to the id parameter in the mliSystemUsers.php component.

    Published:7 May 2024
    4.3
    Medium

    CVE-2024-32369

    Last Modified: 17 Jun 2025

    SQL Injection vulnerability in HSC Cybersecurity HC Mailinspector 5.2.17-3 through 5.2.18 allows a remote attacker to obtain sensitive information via a crafted payload to the start and limit parameter in the mliWhiteList.php component.

    Published:7 May 2024
    8.8
    High

    CVE-2024-32258

    Last Modified: 15 Apr 2026

    The network server of fceux 2.7.0 has a path traversal vulnerability, allowing attackers to overwrite any files on the server without authentication by fake ROM.

    Published:23 Apr 2024
    9.8
    Critical

    CVE-2024-32238

    Last Modified: 15 Apr 2026

    H3C ER8300G2-X is vulnerable to Incorrect Access Control. The password for the router's management system can be accessed via the management system page login interface.

    Published:22 Apr 2024
    Low

    CVE-2024-32205

    Last Modified: 22 Apr 2024

    DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

    Published:12 Apr 2024
    Items Per Page