9.8
    Critical

    CVE-2024-25180

    Last Modified: 13 May 2025

    An issue discovered in pdfmake 0.2.9 allows remote attackers to run arbitrary code via crafted POST request to the /pdf endpoint. NOTE: this is disputed because the behavior of the /pdf endpoint is intentional. The /pdf endpoint is only available after installing a test framework (that lives outside of the pdfmake applicaton). Anyone installing this is responsible for ensuring that it is only available to authorized testers.

    Published:29 Feb 2024
    6.1
    Medium

    CVE-2024-25175

    Last Modified: 19 Sept 2025

    An issue in Kickdler before v1.107.0 allows attackers to provide an XSS payload via a HTTP response splitting attack.

    Published:25 Mar 2024
    9.1
    Critical

    CVE-2024-25170

    Last Modified: 28 Apr 2025

    An issue in Mezzanine v6.0.0 allows attackers to bypass access controls via manipulating the Host header.

    Published:28 Feb 2024
    9.8
    Critical

    CVE-2024-25169

    Last Modified: 28 Mar 2025

    An issue in Mezzanine v6.0.0 allows attackers to bypass access control mechanisms in the admin panel via a crafted request.

    Published:28 Feb 2024
    9.8
    Critical

    CVE-2024-25153

    Last Modified: 19 Sept 2025

    A directory traversal within the ‘ftpservlet’ of the FileCatalyst Workflow Web Portal allows files to be uploaded outside of the intended ‘uploadtemp’ directory with a specially crafted POST request. In situations where a file is successfully uploaded to web portal’s DocumentRoot, specially crafted JSP files could be used to execute code, including web shells.

    Published:13 Mar 2024
    10
    Critical

    CVE-2024-25096

    Last Modified: 28 Apr 2026

    Improper Control of Generation of Code ('Code Injection') vulnerability in Canto Inc. Canto allows Code Injection.This issue affects Canto: from n/a through 3.0.7.

    Published:3 Apr 2024
    8.8
    High

    CVE-2024-25092

    Last Modified: 21 Nov 2024

    Missing Authorization vulnerability in XLPlugins NextMove Lite.This issue affects NextMove Lite: from n/a through 2.17.0.

    Published:9 Jun 2024
    6.5
    Medium

    CVE-2024-25082

    Last Modified: 4 Nov 2025

    Splinefont in FontForge through 20230101 allows command injection via crafted archives or compressed files.

    Published:26 Feb 2024
    4.2
    Medium

    CVE-2024-25081

    Last Modified: 4 Nov 2025

    Splinefont in FontForge through 20230101 allows command injection via crafted filenames.

    Published:26 Feb 2024
    7.8
    High

    CVE-2024-25004

    Last Modified: 14 Mar 2024

    KiTTY versions 0.76.1.13 and before is vulnerable to a stack-based buffer overflow via the username, occurs due to insufficient bounds checking and input sanitization (at line 2600). This allows an attacker to overwrite adjacent memory, which leads to arbitrary code execution.

    Source:DEFCESCO
    Published:9 Feb 2024
    7.8
    High

    CVE-2024-25003

    Last Modified: 14 Mar 2024

    KiTTY versions 0.76.1.13 and before is vulnerable to a stack-based buffer overflow via the hostname, occurs due to insufficient bounds checking and input sanitization. This allows an attacker to overwrite adjacent memory, which leads to arbitrary code execution.

    Source:DEFCESCO
    Published:9 Feb 2024
    6.1
    Medium

    CVE-2024-24945

    Last Modified: 29 May 2025

    A stored cross-site scripting (XSS) vulnerability in Travel Journal Using PHP and MySQL with Source Code v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Share Your Moments parameter at /travel-journal/write-journal.php.

    Published:1 Feb 2024
    7.5
    High

    CVE-2024-24926

    Last Modified: 28 Apr 2026

    Deserialization of Untrusted Data vulnerability in UnitedThemes Brooklyn | Creative Multi-Purpose Responsive WordPress Theme.This issue affects Brooklyn | Creative Multi-Purpose Responsive WordPress Theme: from n/a through 4.9.7.6.

    Published:12 Feb 2024
    8.6
    High

    CVE-2024-24919

    Last Modified: 24 Oct 2025

    Potentially allowing an attacker to read certain information on Check Point Security Gateways once connected to the internet and enabled with remote Access VPN or Mobile Access Software Blades. A Security fix that mitigates this vulnerability is available.

    Published:28 May 2024
    8.8
    High

    CVE-2024-24824

    Last Modified: 17 Jun 2025

    Graylog is a free and open log management platform. Starting in version 2.0.0 and prior to versions 5.1.11 and 5.2.4, arbitrary classes can be loaded and instantiated using a HTTP PUT request to the `/api/system/cluster_config/` endpoint. Graylog's cluster config system uses fully qualified class names as config keys. To validate the existence of the requested class before using them, Graylog loads the class using the class loader. If a user with the appropriate permissions performs the request, arbitrary classes with 1-arg String constructors can be instantiated. This will execute arbitrary code that is run during class instantiation. In the specific use case of `java.io.File`, the behavior of the internal web-server stack will lead to information exposure by including the entire file content in the response to the REST request. Versions 5.1.11 and 5.2.4 contain a fix for this issue.

    Published:7 Feb 2024
    6.1
    Medium

    CVE-2024-24816

    Last Modified: 21 Nov 2024

    CKEditor4 is an open source what-you-see-is-what-you-get HTML editor. A cross-site scripting vulnerability vulnerability has been discovered in versions prior to 4.24.0-lts in samples that use the `preview` feature. All integrators that use these samples in the production code can be affected. The vulnerability allows an attacker to execute JavaScript code by abusing the misconfigured preview feature. It affects all users using the CKEditor 4 at version < 4.24.0-lts with affected samples used in a production environment. A fix is available in version 4.24.0-lts.

    Published:7 Feb 2024
    8.5
    High

    CVE-2024-24809

    Last Modified: 15 Apr 2026

    Traccar is an open source GPS tracking system. Versions prior to 6.0 are vulnerable to path traversal and unrestricted upload of file with dangerous type. Since the system allows registration by default, attackers can acquire ordinary user permissions by registering an account and exploit this vulnerability to upload files with the prefix `device.` under any folder. Attackers can use this vulnerability for phishing, cross-site scripting attacks, and potentially execute arbitrary commands on the server. Version 6.0 contains a patch for the issue.

    Published:10 Apr 2024
    6.4
    Medium

    CVE-2024-24787

    Last Modified: 15 Apr 2026

    On Darwin, building a Go module which contains CGO can trigger arbitrary code execution when using the Apple version of ld, due to usage of the -lto_library flag in a "#cgo LDFLAGS" directive.

    Published:8 May 2024
    8.8
    High

    CVE-2024-24760

    Last Modified: 15 May 2025

    mailcow is a dockerized email package, with multiple containers linked in one bridged network. A security vulnerability has been identified in mailcow affecting versions < 2024-01c. This vulnerability potentially allows attackers on the same subnet to connect to exposed ports of a Docker container, even when the port is bound to 127.0.0.1. The vulnerability has been addressed by implementing additional iptables/nftables rules. These rules drop packets for Docker containers on ports 3306, 6379, 8983, and 12345, where the input interface is not `br-mailcow` and the output interface is `br-mailcow`.

    Published:2 Feb 2024
    8.8
    High

    CVE-2024-24747

    Last Modified: 12 Apr 2024

    MinIO is a High Performance Object Storage. When someone creates an access key, it inherits the permissions of the parent key. Not only for `s3:*` actions, but also `admin:*` actions. Which means unless somewhere above in the access-key hierarchy, the `admin` rights are denied, access keys will be able to simply override their own `s3` permissions to something more permissive. The vulnerability is fixed in RELEASE.2024-01-31T20-20-33Z.

    Source:Jenson Zhao
    Published:31 Jan 2024
    8.8
    High

    CVE-2024-24725

    Last Modified: 29 Jul 2025

    Gibbon through 26.0.00 allows remote authenticated users to conduct PHP deserialization attacks via columnOrder in a POST request to the modules/System%20Admin/import_run.php&type=externalAssessment&step=4 URI.

    Published:23 Mar 2024
    9.8
    Critical

    CVE-2024-24724

    Last Modified: 2 Apr 2024

    Gibbon through 26.0.00 allows /modules/School%20Admin/messengerSettings.php Server Side Template Injection leading to Remote Code Execution because input is passed to the Twig template engine (messengerSettings.php) without sanitization.

    Source:Ali Maharramli_Fikrat Guliev_Islam Rzayev
    Published:3 Apr 2024
    7.8
    High

    CVE-2024-24686

    Last Modified: 13 Feb 2025

    Multiple stack-based buffer overflow vulnerabilities exist in the readOFF functionality of libigl v2.5.0. A specially crafted .off file can lead to stack-based buffer overflow. An attacker can provide a malicious file to trigger this vulnerability.This vulnerability concerns the parsing of comments within the faces section of an `.off` file processed via the `readOFF` function.

    Published:28 May 2024
    7.8
    High

    CVE-2024-24685

    Last Modified: 13 Feb 2025

    Multiple stack-based buffer overflow vulnerabilities exist in the readOFF functionality of libigl v2.5.0. A specially crafted .off file can lead to stack-based buffer overflow. An attacker can provide a malicious file to trigger this vulnerability.This vulnerability concerns the parsing of comments within the vertex section of an `.off` file processed via the `readOFF` function.

    Published:28 May 2024
    7.8
    High

    CVE-2024-24684

    Last Modified: 13 Feb 2025

    Multiple stack-based buffer overflow vulnerabilities exist in the readOFF functionality of libigl v2.5.0. A specially crafted .off file can lead to stack-based buffer overflow. An attacker can provide a malicious file to trigger this vulnerability.This vulnerability concerns the header parsing occuring while processing an `.off` file via the `readOFF` function. We can see above that at [0] a stack-based buffer called `comment` is defined with an hardcoded size of `1000 bytes`. The call to `fscanf` at [1] is unsafe and if the first line of the header of the `.off` files is longer than 1000 bytes it will overflow the `header` buffer.

    Published:28 May 2024
    8
    High

    CVE-2024-24590

    Last Modified: 17 Jun 2025

    Deserialization of untrusted data can occur in versions 0.17.0 to 1.14.2 of the client SDK of Allegro AI’s ClearML platform, enabling a maliciously uploaded artifact to run arbitrary code on an end user’s system when interacted with.

    Published:6 Feb 2024
    10
    Critical

    CVE-2024-24576

    Last Modified: 5 Jan 2026

    Rust is a programming language. The Rust Security Response WG was notified that the Rust standard library prior to version 1.77.2 did not properly escape arguments when invoking batch files (with the `bat` and `cmd` extensions) on Windows using the `Command`. An attacker able to control the arguments passed to the spawned process could execute arbitrary shell commands by bypassing the escaping. The severity of this vulnerability is critical for those who invoke batch files on Windows with untrusted arguments. No other platform or use is affected. The `Command::arg` and `Command::args` APIs state in their documentation that the arguments will be passed to the spawned process as-is, regardless of the content of the arguments, and will not be evaluated by a shell. This means it should be safe to pass untrusted input as an argument. On Windows, the implementation of this is more complex than other platforms, because the Windows API only provides a single string containing all the arguments to the spawned process, and it's up to the spawned process to split them. Most programs use the standard C run-time argv, which in practice results in a mostly consistent way arguments are splitted. One exception though is `cmd.exe` (used among other things to execute batch files), which has its own argument splitting logic. That forces the standard library to implement custom escaping for arguments passed to batch files. Unfortunately it was reported that our escaping logic was not thorough enough, and it was possible to pass malicious arguments that would result in arbitrary shell execution. Due to the complexity of `cmd.exe`, we didn't identify a solution that would correctly escape arguments in all cases. To maintain our API guarantees, we improved the robustness of the escaping code, and changed the `Command` API to return an `InvalidInput` error when it cannot safely escape an argument. This error will be emitted when spawning the process. The fix is included in Rust 1.77.2. Note that the new escaping logic for batch files errs on the conservative side, and could reject valid arguments. Those who implement the escaping themselves or only handle trusted inputs on Windows can also use the `CommandExt::raw_arg` method to bypass the standard library's escaping logic.

    Published:9 Apr 2024
    7.5
    High

    CVE-2024-24549

    Last Modified: 29 Oct 2025

    Denial of Service due to improper input validation vulnerability for HTTP/2 requests in Apache Tomcat. When processing an HTTP/2 request, if the request exceeded any of the configured limits for headers, the associated HTTP/2 stream was not reset until after all of the headers had been processed.This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.0-M16, from 10.1.0-M1 through 10.1.18, from 9.0.0-M1 through 9.0.85, from 8.5.0 through 8.5.98. Other, older, EOL versions may also be affected. Users are recommended to upgrade to version 11.0.0-M17, 10.1.19, 9.0.86 or 8.5.99 which fix the issue.

    Published:13 Mar 2024
    Low

    CVE-2024-24499

    Last Modified: 2 Apr 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2024-1007. Reason: This candidate is a duplicate of CVE-2024-1007. Notes: All CVE users should reference CVE-2024-1007 instead of this candidate.

    Source:Yevhenii Butenko
    Published:25 Jan 2024
    Low

    CVE-2024-24497

    Last Modified: 2 Apr 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2024-1009. Reason: This candidate is a duplicate of CVE-2024-1009. Notes: All CVE users should reference CVE-2024-1009 instead of this candidate.

    Source:Yevhenii Butenko
    Published:25 Jan 2024
    9.8
    Critical

    CVE-2024-24496

    Last Modified: 2 Apr 2024

    An issue in Daily Habit Tracker v.1.0 allows a remote attacker to manipulate trackers via the home.php, add-tracker.php, delete-tracker.php, update-tracker.php components.

    Source:Yevhenii Butenko
    Published:8 Feb 2024
    9.8
    Critical

    CVE-2024-24495

    Last Modified: 2 Apr 2024

    SQL Injection vulnerability in delete-tracker.php in Daily Habit Tracker v.1.0 allows a remote attacker to execute arbitrary code via crafted GET request.

    Source:Yevhenii Butenko
    Published:8 Feb 2024
    6.1
    Medium

    CVE-2024-24494

    Last Modified: 2 Apr 2024

    Cross Site Scripting vulnerability in Daily Habit Tracker v.1.0 allows a remote attacker to execute arbitrary code via the day, exercise, pray, read_book, vitamins, laundry, alcohol and meat parameters in the add-tracker.php and update-tracker.php components.

    Source:Yevhenii Butenko
    Published:8 Feb 2024
    5.5
    Medium

    CVE-2024-24488

    Last Modified: 5 Jun 2025

    An issue in Shenzen Tenda Technology CP3V2.0 V11.10.00.2311090948 allows a local attacker to obtain sensitive information via the password component.

    Published:7 Feb 2024
    7.5
    High

    CVE-2024-24451

    Last Modified: 15 Apr 2026

    A stack overflow in the sctp_server::sctp_receiver_thread component of OpenAirInterface CN5G AMF (oai-cn5g-amf) up to v2.0.0 allows attackers to cause a Denial of Service (DoS) by repeatedly establishing SCTP connections with the N2 interface.

    Published:21 Jan 2025
    5.3
    Medium

    CVE-2024-24450

    Last Modified: 15 Apr 2026

    Stack-based memcpy buffer overflow in the ngap_handle_pdu_session_resource_setup_response routine in OpenAirInterface CN5G AMF <= 2.0.0 allows a remote attacker with access to the N2 interface to carry out denial of service against the AMF and potentially execute code by sending a PDU Session Resource Setup Response with a suffciently large FailedToSetupList IE.

    Published:15 Nov 2024
    8.8
    High

    CVE-2024-24409

    Last Modified: 9 Apr 2025

    Zohocorp ManageEngine ADManager Plus versions 7203 and prior are vulnerable to Privilege Escalation in the Modify Computers option.

    Source:Metin Yunus Kandemir
    Published:8 Nov 2024
    9.8
    Critical

    CVE-2024-24402

    Last Modified: 24 Mar 2025

    An issue in Nagios XI 2024R1.01 allows a remote attacker to escalate privileges via a crafted script to the /usr/local/nagios/bin/npcd component.

    Published:26 Feb 2024
    9.8
    Critical

    CVE-2024-24401

    Last Modified: 27 Jun 2025

    SQL Injection vulnerability in Nagios XI 2024R1.01 allows a remote attacker to execute arbitrary code via a crafted payload to the monitoringwizard.php component.

    Published:26 Feb 2024
    9.8
    Critical

    CVE-2024-24398

    Last Modified: 15 May 2025

    Directory Traversal vulnerability in Stimulsoft GmbH Stimulsoft Dashboard.JS before v.2024.1.2 allows a remote attacker to execute arbitrary code via a crafted payload to the fileName parameter of the Save function.

    Published:6 Feb 2024
    5.4
    Medium

    CVE-2024-24397

    Last Modified: 15 May 2025

    Cross Site Scripting vulnerability in Stimulsoft GmbH Stimulsoft Dashboard.JS before v.2024.1.2 allows a remote attacker to execute arbitrary code via a crafted payload to the ReportName field.

    Published:5 Feb 2024
    6.1
    Medium

    CVE-2024-24396

    Last Modified: 21 Nov 2024

    Cross Site Scripting vulnerability in Stimulsoft GmbH Stimulsoft Dashboard.JS before v.2024.1.2 allows a remote attacker to execute arbitrary code via a crafted payload to the search bar component.

    Published:5 Feb 2024
    7.2
    High

    CVE-2024-24386

    Last Modified: 18 Sept 2025

    An issue in VitalPBX v.3.2.4-5 allows an attacker to execute arbitrary code via a crafted payload to the /var/lib/vitalpbx/scripts folder.

    Published:15 Feb 2024
    Unknown

    CVE-2024-24210

    https://github.com/ha6ker-hu/CVE-2024-24210

    9.8
    Critical

    CVE-2024-24142

    Last Modified: 9 May 2025

    Sourcecodester School Task Manager 1.0 allows SQL Injection via the 'subject' parameter.

    Published:13 Feb 2024
    9.8
    Critical

    CVE-2024-24141

    Last Modified: 21 Nov 2024

    Sourcecodester School Task Manager App 1.0 allows SQL Injection via the 'task' parameter.

    Published:29 Jan 2024
    7.2
    High

    CVE-2024-24140

    Last Modified: 29 May 2025

    Sourcecodester Daily Habit Tracker App 1.0 allows SQL Injection via the parameter 'tracker.'

    Published:29 Jan 2024
    7.2
    High

    CVE-2024-24139

    Last Modified: 21 Nov 2024

    Sourcecodester Login System with Email Verification 1.0 allows SQL Injection via the 'user' parameter.

    Published:29 Jan 2024
    Unknown

    CVE-2024-24138

    https://github.com/BurakSevben/CVE-2024-24138

    Unknown

    CVE-2024-24137

    https://github.com/BurakSevben/CVE-2024-24137

    Items Per Page