5.3
    Medium

    CVE-2024-30255

    Last Modified: 4 Nov 2025

    Envoy is a cloud-native, open source edge and service proxy. The HTTP/2 protocol stack in Envoy versions prior to 1.29.3, 1.28.2, 1.27.4, and 1.26.8 are vulnerable to CPU exhaustion due to flood of CONTINUATION frames. Envoy's HTTP/2 codec allows the client to send an unlimited number of CONTINUATION frames even after exceeding Envoy's header map limits. This allows an attacker to send a sequence of CONTINUATION frames without the END_HEADERS bit set causing CPU utilization, consuming approximately 1 core per 300Mbit/s of traffic and culminating in denial of service through CPU exhaustion. Users should upgrade to version 1.29.3, 1.28.2, 1.27.4, or 1.26.8 to mitigate the effects of the CONTINUATION flood. As a workaround, disable HTTP/2 protocol for downstream connections.

    Published:3 Apr 2024
    7
    High

    CVE-2024-30212

    Last Modified: 15 Apr 2026

    If a SCSI READ(10) command is initiated via USB using the largest LBA (0xFFFFFFFF) with it's default block size of 512 and a count of 1, the first 512 byte of the 0x80000000 memory area is returned to the user. If the block count is increased, the full RAM can be exposed. The same method works to write to this memory area. If RAM contains pointers, those can be - depending on the application - overwritten to return data from any other offset including Progam and Boot Flash.

    Published:28 May 2024
    6.3
    Medium

    CVE-2024-30167

    Last Modified: 29 Apr 2026

    /cgi-bin/time.cgi in Atlona AT-OME-MS42 Matrix Switcher 1.1.2 allow remote authenticated users to execute arbitrary commands as root via a POST request that carries a serverName parameter.

    Source:rizzziom
    Published:8 May 2026
    7
    High

    CVE-2024-30090

    Last Modified: 20 Jul 2026

    Microsoft Streaming Service Elevation of Privilege Vulnerability

    Published:11 Jun 2024
    7
    High

    CVE-2024-30088

    Last Modified: 17 Dec 2025

    Windows Kernel Elevation of Privilege Vulnerability

    Published:11 Jun 2024
    7.8
    High

    CVE-2024-30085

    Last Modified: 17 Dec 2025

    Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability

    Published:11 Jun 2024
    7.1
    High

    CVE-2024-30056

    Last Modified: 3 May 2025

    Microsoft Edge (Chromium-based) Information Disclosure Vulnerability

    Published:25 May 2024
    4.7
    Medium

    CVE-2024-30052

    Last Modified: 17 Dec 2025

    Visual Studio Remote Code Execution Vulnerability

    Published:11 Jun 2024
    7.8
    High

    CVE-2024-30051

    Last Modified: 28 Oct 2025

    Windows DWM Core Library Elevation of Privilege Vulnerability

    Published:14 May 2024
    6.5
    Medium

    CVE-2024-30043

    Last Modified: 3 May 2025

    Microsoft SharePoint Server Information Disclosure Vulnerability

    Published:14 May 2024
    8.8
    High

    CVE-2024-29988

    Last Modified: 28 Oct 2025

    SmartScreen Prompt Security Feature Bypass Vulnerability

    Published:9 Apr 2024
    9.8
    Critical

    CVE-2024-29973

    Last Modified: 22 Jan 2025

    ** UNSUPPORTED WHEN ASSIGNED ** The command injection vulnerability in the “setCookie” parameter in Zyxel NAS326 firmware versions before V5.21(AAZF.17)C0 and NAS542 firmware versions before V5.21(ABAG.14)C0 could allow an unauthenticated attacker to execute some operating system (OS) commands by sending a crafted HTTP POST request.

    Published:4 Jun 2024
    9.8
    Critical

    CVE-2024-29972

    Last Modified: 22 Jan 2025

    ** UNSUPPORTED WHEN ASSIGNED ** The command injection vulnerability in the CGI program "remote_help-cgi" in Zyxel NAS326 firmware versions before V5.21(AAZF.17)C0 and NAS542 firmware versions before V5.21(ABAG.14)C0 could allow an unauthenticated attacker to execute some operating system (OS) commands by sending a crafted HTTP POST request.

    Published:4 Jun 2024
    9.8
    Critical

    CVE-2024-29943

    Last Modified: 1 Apr 2025

    An attacker was able to perform an out-of-bounds read or write on a JavaScript object by fooling range-based bounds check elimination. This vulnerability affects Firefox < 124.0.1.

    Published:22 Mar 2024
    10
    Critical

    CVE-2024-29895

    Last Modified: 15 Apr 2026

    Cacti provides an operational monitoring and fault management framework. A command injection vulnerability on the 1.3.x DEV branch allows any unauthenticated user to execute arbitrary command on the server when `register_argc_argv` option of PHP is `On`. In `cmd_realtime.php` line 119, the `$poller_id` used as part of the command execution is sourced from `$_SERVER['argv']`, which can be controlled by URL when `register_argc_argv` option of PHP is `On`. And this option is `On` by default in many environments such as the main PHP Docker image for PHP. Commit 53e8014d1f082034e0646edc6286cde3800c683d contains a patch for the issue, but this commit was reverted in commit 99633903cad0de5ace636249de16f77e57a3c8fc.

    Published:13 May 2024
    9.1
    Critical

    CVE-2024-29868

    Last Modified: 15 Jul 2025

    Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG) vulnerability in Apache StreamPipes user self-registration and password recovery mechanism. This allows an attacker to guess the recovery token in a reasonable time and thereby to take over the attacked user's account. This issue affects Apache StreamPipes: from 0.69.0 through 0.93.0. Users are recommended to upgrade to version 0.95.0, which fixes the issue.

    Published:24 Jun 2024
    7.8
    High

    CVE-2024-29863

    Last Modified: 15 Apr 2026

    A race condition in the installer executable in Qlik Qlikview before versions May 2022 SR3 (12.70.20300) and May 2023 SR2 (12,80.20200) may allow an existing lower privileged user to cause code to be executed in the context of a Windows Administrator.

    Published:5 Apr 2024
    9
    Critical

    CVE-2024-29855

    Last Modified: 14 Jul 2025

    Hard-coded JWT secret allows authentication bypass in Veeam Recovery Orchestrator

    Published:11 Jun 2024
    9.8
    Critical

    CVE-2024-29849

    Last Modified: 3 Jul 2025

    Veeam Backup Enterprise Manager allows unauthenticated users to log in as any user to enterprise manager web interface.

    Published:22 May 2024
    9.8
    Critical

    CVE-2024-29847

    Last Modified: 17 Sept 2024

    Deserialization of untrusted data in the agent portal of Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote unauthenticated attacker to achieve remote code execution.

    Published:12 Sept 2024
    8.8
    High

    CVE-2024-29824

    Last Modified: 30 Oct 2025

    An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2022 SU5 and prior allows an unauthenticated attacker within the same network to execute arbitrary code.

    Published:31 May 2024
    9.8
    Critical

    CVE-2024-29671

    Last Modified: 15 Apr 2026

    Buffer Overflow vulnerability in NEXTU FLATA AX1500 Router v.1.0.2 allows a remote attacker to execute arbitrary code via the POST request handler component.

    Published:16 Dec 2024
    6.3
    Medium

    CVE-2024-29510

    Last Modified: 28 Apr 2025

    Artifex Ghostscript before 10.03.1 allows memory corruption, and SAFER sandbox bypass, via format string injection with a uniprint device.

    Published:16 May 2024
    8.1
    High

    CVE-2024-29415

    Last Modified: 15 Apr 2026

    The ip package through 2.0.1 for Node.js might allow SSRF because some IP addresses (such as 127.1, 01200034567, 012.1.2.3, 000:0:0000::01, and ::fFFf:127.0.0.1) are improperly categorized as globally routable via isPublic. NOTE: this issue exists because of an incomplete fix for CVE-2023-42282.

    Published:20 Feb 2024
    Unknown

    CVE-2024-29410

    https://www.exploit-db.com/exploits/51943

    7.8
    High

    CVE-2024-29404

    Last Modified: 15 Apr 2026

    An issue in Razer Synapse 3 v.3.9.131.20813 and Synapse 3 App v.20240213 allows a local attacker to execute arbitrary code via the export parameter of the Chroma Effects function in the Profiles component.

    Published:3 Dec 2024
    7.6
    High

    CVE-2024-29399

    Last Modified: 17 Jun 2025

    An issue was discovered in GNU Savane v.3.13 and before, allows a remote attacker to execute arbitrary code and escalate privileges via a crafted file to the upload.php component.

    Published:11 Apr 2024
    9.8
    Critical

    CVE-2024-29375

    Last Modified: 15 Apr 2026

    CSV Injection vulnerability in Addactis IBNRS v.3.10.3.107 allows a remote attacker to execute arbitrary code via a crafted .ibnrs file to the Project Description, Identifiers, Custom Triangle Name (inside Input Triangles) and Yield Curve Name parameters.

    Published:4 Apr 2024
    5.3
    Medium

    CVE-2024-29296

    Last Modified: 9 Jul 2026

    A user enumeration vulnerability was found in Portainer CE 2.19.4. This issue occurs during user authentication process, where a difference in response time could allow a remote unauthenticated user to determine if a username is valid or not.

    Published:10 Apr 2024
    Low

    CVE-2024-29291

    Last Modified: 21 Apr 2024

    An issue in Laravel Framework 8 through 11 might allow a remote attacker to discover database credentials in storage/logs/laravel.log. NOTE: this is disputed by multiple third parties because the owner of a Laravel Framework installation can choose to have debugging logs, but needs to set the access control appropriately for the type of data that may be logged.

    Source:Huseein Amer
    Published:16 Apr 2024
    6.5
    Medium

    CVE-2024-29278

    Last Modified: 15 Apr 2026

    funboot v1.1 is vulnerable to Cross Site Scripting (XSS) via the title field in "create a message ."

    Published:30 Mar 2024
    9.8
    Critical

    CVE-2024-29275

    Last Modified: 28 Mar 2025

    SQL injection vulnerability in SeaCMS version 12.9, allows remote unauthenticated attackers to execute arbitrary code and obtain sensitive information via the id parameter in class.php.

    Published:22 Mar 2024
    6.5
    Medium

    CVE-2024-29272

    Last Modified: 28 May 2025

    Arbitrary File Upload vulnerability in VvvebJs before version 1.7.5, allows unauthenticated remote attackers to execute arbitrary code and obtain sensitive information via the sanitizeFileName parameter in save.php.

    Published:22 Mar 2024
    8.8
    High

    CVE-2024-29269

    Last Modified: 17 Jun 2025

    An issue discovered in Telesquare TLR-2005Ksh 1.0.0 and 1.1.4 allows attackers to run arbitrary system commands via the Cmd parameter.

    Published:10 Apr 2024
    7.5
    High

    CVE-2024-29059

    Last Modified: 28 Oct 2025

    .NET Framework Information Disclosure Vulnerability

    Published:22 Mar 2024
    8.4
    High

    CVE-2024-29050

    Last Modified: 3 May 2025

    Windows Cryptographic Services Remote Code Execution Vulnerability

    Published:9 Apr 2024
    6.4
    Medium

    CVE-2024-28999

    Last Modified: 26 Jun 2024

    The SolarWinds Platform was determined to be affected by a Race Condition Vulnerability affecting the web console.

    Source:Elhussain Fathy
    Published:4 Jun 2024
    8.6
    High

    CVE-2024-28995

    Last Modified: 29 May 2025

    SolarWinds Serv-U was susceptible to a directory transversal vulnerability that would allow access to read sensitive files on the host machine.

    Source:İbrahimsql
    Published:6 Jun 2024
    9.1
    Critical

    CVE-2024-28987

    Last Modified: 27 Oct 2025

    The SolarWinds Web Help Desk (WHD) software is affected by a hardcoded credential vulnerability, allowing remote unauthenticated user to access internal functionality and modify data.

    Published:21 Aug 2024
    5.4
    Medium

    CVE-2024-28784

    Last Modified: 10 Apr 2025

    IBM QRadar SIEM 7.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 285893.

    Published:27 Mar 2024
    7.5
    High

    CVE-2024-28757

    Last Modified: 4 Nov 2025

    libexpat through 2.6.1 allows an XML Entity Expansion attack when there is isolated use of external parsers (created via XML_ExternalEntityParserCreate).

    Published:10 Mar 2024
    9.3
    Critical

    CVE-2024-28752

    Last Modified: 27 Jun 2025

    A SSRF vulnerability using the Aegis DataBinding in versions of Apache CXF before 4.0.4, 3.6.3 and 3.5.8 allows an attacker to perform SSRF style attacks on webservices that take at least one parameter of any type. Users of other data bindings (including the default databinding) are not impacted.

    Published:14 Mar 2024
    8.8
    High

    CVE-2024-28741

    Last Modified: 15 Apr 2026

    Cross Site Scripting vulnerability in EginDemirbilek NorthStar C2 v1 allows a remote attacker to execute arbitrary code via the login.php component.

    Published:6 Apr 2024
    8.8
    High

    CVE-2024-28715

    Last Modified: 24 Jun 2025

    Cross Site Scripting vulnerability in DOraCMS v.2.18 and before allows a remote attacker to execute arbitrary code via the markdown0 function in the /app/public/apidoc/oas3/wrap-components/markdown.jsx endpoint.

    Published:19 Mar 2024
    6.1
    Medium

    CVE-2024-28623

    Last Modified: 18 Aug 2025

    RiteCMS v3.0.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the component main_menu/edit_section.

    Source:Gurjot Singh
    Published:13 Mar 2024
    9.8
    Critical

    CVE-2024-28595

    Last Modified: 20 Mar 2024

    SQL Injection vulnerability in Employee Management System v1.0 allows attackers to run arbitrary SQL commands via the admin_id parameter in update-admin.php.

    Source:Shubham Pandey
    Published:19 Mar 2024
    6.7
    Medium

    CVE-2024-28589

    Last Modified: 15 Apr 2026

    An issue was discovered in Axigen Mail Server for Windows versions 10.5.18 and before, allows local low-privileged attackers to execute arbitrary code and escalate privileges via insecure DLL loading from a world-writable directory during service initialization.

    Published:3 Apr 2024
    9.8
    Critical

    CVE-2024-28515

    Last Modified: 15 Apr 2026

    Buffer Overflow vulnerability in CSAPP_Lab CSAPP Lab3 15-213 Fall 20xx allows a remote attacker to execute arbitrary code via the lab3 of csapp,lab3/buflab-update.pl component.

    Published:3 Apr 2024
    5.3
    Medium

    CVE-2024-28397

    Last Modified: 30 Apr 2026

    An issue in the component js2py.disable_pyimport() of js2py up to v0.74 allows attackers to execute arbitrary code via a crafted API call.

    Source:alisunbul
    Published:20 Jun 2024
    9.8
    Critical

    CVE-2024-28255

    Last Modified: 4 Sept 2025

    OpenMetadata is a unified platform for discovery, observability, and governance powered by a central metadata repository, in-depth lineage, and seamless team collaboration. The `JwtFilter` handles the API authentication by requiring and verifying JWT tokens. When a new request comes in, the request's path is checked against this list. When the request's path contains any of the excluded endpoints the filter returns without validating the JWT. Unfortunately, an attacker may use Path Parameters to make any path contain any arbitrary strings. For example, a request to `GET /api/v1;v1%2fusers%2flogin/events/subscriptions/validation/condition/111` will match the excluded endpoint condition and therefore will be processed with no JWT validation allowing an attacker to bypass the authentication mechanism and reach any arbitrary endpoint, including the ones listed above that lead to arbitrary SpEL expression injection. This bypass will not work when the endpoint uses the `SecurityContext.getUserPrincipal()` since it will return `null` and will throw an NPE. This issue may lead to authentication bypass and has been addressed in version 1.2.4. Users are advised to upgrade. There are no known workarounds for this vulnerability. This issue is also tracked as `GHSL-2023-237`.

    Published:15 Mar 2024
    Items Per Page