Low

    CVE-2024-27088

    Last Modified: 5 Feb 2025

    es5-ext contains ECMAScript 5 extensions. Passing functions with very long names or complex default argument names into `function#copy` or `function#toStringTokens` may cause the script to stall. The vulnerability is patched in v0.10.63.

    Published:26 Feb 2024
    5.5
    Medium

    CVE-2024-26817

    Last Modified: 4 Nov 2025

    In the Linux kernel, the following vulnerability has been resolved: amdkfd: use calloc instead of kzalloc to avoid integer overflow This uses calloc instead of doing the multiplication which might overflow.

    Published:13 Apr 2024
    7.8
    High

    CVE-2024-26581

    Last Modified: 1 Oct 2025

    In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_set_rbtree: skip end interval element from gc rbtree lazy gc on insert might collect an end interval element that has been just added in this transactions, skip end interval elements that are not yet active.

    Published:20 Feb 2024
    7.8
    High

    CVE-2024-26574

    Last Modified: 28 Mar 2025

    Insecure Permissions vulnerability in Wondershare Filmora v.13.0.51 allows a local attacker to execute arbitrary code via a crafted script to the WSNativePushService.exe

    Published:8 Apr 2024
    Unknown

    CVE-2024-26560

    https://github.com/sajaljat/CVE-2024-26560

    Unknown

    CVE-2024-26535

    https://github.com/sajaljat/CVE-2024-26535

    Unknown

    CVE-2024-26534

    https://github.com/sajaljat/CVE-2024-26534

    4.8
    Medium

    CVE-2024-26521

    Last Modified: 15 Apr 2026

    HTML Injection vulnerability in CE Phoenix v1.0.8.20 and before allows a remote attacker to execute arbitrary code, escalate privileges, and obtain sensitive information via a crafted payload to the english.php component.

    Published:12 Mar 2024
    9.1
    Critical

    CVE-2024-26503

    Last Modified: 10 Jun 2025

    Unrestricted File Upload vulnerability in Greek Universities Network Open eClass v.3.15 and earlier allows attackers to run arbitrary code via upload of crafted file to certbadge.php endpoint.

    Published:14 Mar 2024
    5.5
    Medium

    CVE-2024-26475

    Last Modified: 27 Mar 2025

    An issue in radareorg radare2 v.0.9.7 through v.5.8.6 and fixed in v.5.8.8 allows a local attacker to cause a denial of service via the grub_sfs_read_extent function.

    Published:14 Mar 2024
    5.5
    Medium

    CVE-2024-26308

    Last Modified: 27 Mar 2025

    Allocation of Resources Without Limits or Throttling vulnerability in Apache Commons Compress.This issue affects Apache Commons Compress: from 1.21 before 1.26. Users are recommended to upgrade to version 1.26, which fixes the issue.

    Published:19 Feb 2024
    9.8
    Critical

    CVE-2024-26304

    Last Modified: 15 Apr 2026

    There is a buffer overflow vulnerability in the underlying L2/L3 Management service that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's access point management protocol) UDP port (8211). Successful exploitation of this vulnerability results in the ability to execute arbitrary code as a privileged user on the underlying operating system.

    Published:1 May 2024
    7.8
    High

    CVE-2024-26230

    Last Modified: 3 May 2025

    Windows Telephony Server Elevation of Privilege Vulnerability

    Published:9 Apr 2024
    7.8
    High

    CVE-2024-26229

    Last Modified: 3 May 2025

    Windows CSC Service Elevation of Privilege Vulnerability

    Published:9 Apr 2024
    7.8
    High

    CVE-2024-26218

    Last Modified: 3 May 2025

    Windows Kernel Elevation of Privilege Vulnerability

    Published:9 Apr 2024
    7.8
    High

    CVE-2024-26170

    Last Modified: 3 May 2025

    Windows Composite Image File System (CimFS) Elevation of Privilege Vulnerability

    Published:12 Mar 2024
    7.8
    High

    CVE-2024-26169

    Last Modified: 28 Oct 2025

    Windows Error Reporting Service Elevation of Privilege Vulnerability

    Published:12 Mar 2024
    5.5
    Medium

    CVE-2024-26160

    Last Modified: 3 May 2025

    Windows Cloud Files Mini Filter Driver Information Disclosure Vulnerability

    Published:12 Mar 2024
    5.3
    Medium

    CVE-2024-26144

    Last Modified: 14 Feb 2025

    Rails is a web-application framework. Starting with version 5.2.0, there is a possible sensitive session information leak in Active Storage. By default, Active Storage sends a Set-Cookie header along with the user's session cookie when serving blobs. It also sets Cache-Control to public. Certain proxies may cache the Set-Cookie, leading to an information leak. The vulnerability is fixed in 7.0.8.1 and 6.1.7.7.

    Published:25 Feb 2024
    7.5
    High

    CVE-2024-26026

    Last Modified: 19 Sept 2025

    An SQL injection vulnerability exists in the BIG-IP Next Central Manager API (URI).  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated

    Published:8 May 2024
    9.8
    Critical

    CVE-2024-25897

    Last Modified: 22 Apr 2025

    ChurchCRM 5.5.0 FRCatalog.php is vulnerable to Blind SQL Injection (Time-based) via the CurrentFundraiser GET parameter.

    Published:21 Feb 2024
    8.8
    High

    CVE-2024-25832

    Last Modified: 10 Mar 2024

    F-logic DataCube3 v1.0 is vulnerable to unrestricted file upload, which could allow an authenticated malicious actor to upload a file of dangerous type by manipulating the filename extension.

    Source:Samy Younsi - NS Labs
    Published:28 Feb 2024
    9.8
    Critical

    CVE-2024-25830

    Last Modified: 10 Mar 2024

    F-logic DataCube3 v1.0 is vulnerable to Incorrect Access Control due to an improper directory access restriction. An unauthenticated, remote attacker can exploit this, by sending a URI that contains the path of the configuration file. A successful exploit could allow the attacker to extract the root and admin password.

    Source:Samy Younsi - NS Labs
    Published:28 Feb 2024
    Unknown

    CVE-2024-25809

    https://github.com/sajaljat/CVE-2024-25809

    7.5
    High

    CVE-2024-25736

    Last Modified: 26 Feb 2024

    An issue was discovered on WyreStorm Apollo VX20 devices before 1.3.58. Remote attackers can restart the device via a /device/reboot GET request.

    Source:hyp3rlinx
    Published:27 Mar 2024
    9.1
    Critical

    CVE-2024-25735

    Last Modified: 26 Feb 2024

    An issue was discovered on WyreStorm Apollo VX20 devices before 1.3.58. Remote attackers can discover cleartext passwords via a SoftAP /device/config GET request.

    Source:hyp3rlinx
    Published:27 Mar 2024
    7.5
    High

    CVE-2024-25734

    Last Modified: 26 Feb 2024

    An issue was discovered on WyreStorm Apollo VX20 devices before 1.3.58. The TELNET service prompts for a password only after a valid username is entered, which might make it easier for remote attackers to enumerate user accounts.

    Source:hyp3rlinx
    Published:27 Mar 2024
    Unknown

    CVE-2024-25733

    https://github.com/hackintoanetwork/ARC-Browser-Address-Bar-Spoofing-PoC

    7.5
    High

    CVE-2024-25731

    Last Modified: 26 Mar 2025

    The Elink Smart eSmartCam (com.cn.dq.ipc) application 2.1.5 for Android contains hardcoded AES encryption keys that can be extracted from a binary file. Thus, encryption can be defeated by an attacker who can observe packet data (e.g., over Wi-Fi).

    Published:4 Mar 2024
    8.8
    High

    CVE-2024-25723

    Last Modified: 12 May 2025

    ZenML Server in the ZenML machine learning package before 0.46.7 for Python allows remote privilege escalation because the /api/v1/users/{user_name_or_id}/activate REST API endpoint allows access on the basis of a valid username along with a new password in the request body. These are also patched versions: 0.44.4, 0.43.1, and 0.42.2.

    Published:27 Feb 2024
    9.1
    Critical

    CVE-2024-25641

    Last Modified: 15 Apr 2025

    Cacti provides an operational monitoring and fault management framework. Prior to version 1.2.27, an arbitrary file write vulnerability, exploitable through the "Package Import" feature, allows authenticated users having the "Import Templates" permission to execute arbitrary PHP code on the web server. The vulnerability is located within the `import_package()` function defined into the `/lib/import.php` script. The function blindly trusts the filename and file content provided within the XML data, and writes such files into the Cacti base path (or even outside, since path traversal sequences are not filtered). This can be exploited to write or overwrite arbitrary files on the web server, leading to execution of arbitrary PHP code or other security impacts. Version 1.2.27 contains a patch for this issue.

    Source:D3Ext
    Published:13 May 2024
    10
    Critical

    CVE-2024-25600

    Last Modified: 7 Jul 2026

    Improper Control of Generation of Code ('Code Injection') vulnerability in Codeer Limited Bricks Builder allows Code Injection.This issue affects Bricks Builder: from n/a through 1.9.6.

    Source:Jared Brits
    Published:4 Jun 2024
    4.7
    Medium

    CVE-2024-25503

    Last Modified: 15 Apr 2026

    Cross Site Scripting (XSS) vulnerability in Advanced REST Client v.17.0.9 allows a remote attacker to execute arbitrary code and obtain sensitive information via a crafted script to the edit details parameter of the New Project function.

    Published:4 Apr 2024
    7.8
    High

    CVE-2024-25466

    Last Modified: 27 Mar 2025

    Directory Traversal vulnerability in React Native Document Picker before v.9.1.1 and fixed in v.9.1.1 allows a local attacker to execute arbitrary code via a crafted script to the Android library component.

    Published:16 Feb 2024
    7
    High

    CVE-2024-25423

    Last Modified: 28 May 2025

    An issue in MAXON CINEMA 4D R2024.2.0 allows a local attacker to execute arbitrary code via a crafted c4d_base.xdl64 file.

    Published:22 Feb 2024
    9.8
    Critical

    CVE-2024-25422

    Last Modified: 29 Mar 2025

    SQL Injection vulnerability in SEMCMS v.4.8 allows a remote attacker to execute arbitrary code and obtain sensitive information via the SEMCMS_Menu.php component.

    Published:28 Feb 2024
    4.6
    Medium

    CVE-2024-25412

    Last Modified: 13 Mar 2025

    A cross-site scripting (XSS) vulnerability in Flatpress v1.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the email field.

    Published:27 Sept 2024
    6.1
    Medium

    CVE-2024-25411

    Last Modified: 10 Jul 2025

    A cross-site scripting (XSS) vulnerability in Flatpress v1.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the username parameter in setup.php.

    Published:27 Sept 2024
    6.1
    Medium

    CVE-2024-25381

    Last Modified: 6 May 2025

    There is a Stored XSS Vulnerability in Emlog Pro 2.2.8 Article Publishing, due to non-filtering of quoted content.

    Published:21 Feb 2024
    7.8
    High

    CVE-2024-25376

    Last Modified: 17 Jun 2025

    An issue discovered in Thesycon Software Solutions Gmbh & Co. KG TUSBAudio MSI-based installers before 5.68.0 allows a local attacker to execute arbitrary code via the msiexec.exe repair mode.

    Published:11 Apr 2024
    9.3
    Critical

    CVE-2024-25293

    Last Modified: 13 May 2025

    mjml-app versions 3.0.4 and 3.1.0-beta were discovered to contain a remote code execution (RCE) via the href attribute.

    Published:1 Mar 2024
    9.6
    Critical

    CVE-2024-25292

    Last Modified: 27 Mar 2025

    Cross-site scripting (XSS) vulnerability in RenderTune v1.1.4 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Upload Title parameter.

    Published:29 Feb 2024
    9.8
    Critical

    CVE-2024-25291

    Last Modified: 22 Apr 2025

    Deskfiler v1.2.3 allows attackers to execute arbitrary code via uploading a crafted plugin.

    Published:29 Feb 2024
    Unknown

    CVE-2024-25281

    https://github.com/sajaljat/CVE-2024-25281

    Unknown

    CVE-2024-25280

    https://github.com/sajaljat/CVE-2024-25280

    Unknown

    CVE-2024-25279

    https://github.com/sajaljat/CVE-2024-25279

    Unknown

    CVE-2024-25278

    https://github.com/sajaljat/CVE-2024-25278

    Unknown

    CVE-2024-25277

    https://github.com/maen08/CVE-2024-25277

    6.5
    Medium

    CVE-2024-25227

    Last Modified: 26 Mar 2025

    SQL Injection vulnerability in ABO.CMS version 5.8, allows remote attackers to execute arbitrary code, cause a denial of service (DoS), escalate privileges, and obtain sensitive information via the tb_login parameter in admin login page.

    Published:15 Mar 2024
    6.1
    Medium

    CVE-2024-25202

    Last Modified: 22 Apr 2025

    Cross Site Scripting vulnerability in Phpgurukul User Registration & Login and User Management System 1.0 allows attackers to run arbitrary code via the search bar.

    Published:28 Feb 2024
    Items Per Page