Weekly Vulnerabilities Reports > July 22 to 28, 2024
Overview
284 new vulnerabilities reported during this period, including 46 critical vulnerabilities and 99 high severity vulnerabilities. This weekly summary report vulnerabilities in 192 products from 148 vendors including Totolink, Oretnom23, Tendacn, NI, and Apache. Vulnerabilities are notably categorized as "Cross-site Scripting", "Out-of-bounds Write", "OS Command Injection", "Missing Authorization", and "SQL Injection".
- 248 reported vulnerabilities are remotely exploitables.
- 79 reported vulnerabilities are related to weaknesses in OWASP Top Ten.
- 138 reported vulnerabilities are exploitable by an anonymous user.
- Totolink has the most reported vulnerabilities, with 11 reported vulnerabilities.
- Opengeos has the most reported critical vulnerabilities, with 9 reported vulnerabilities.
VULNERABILITIES
VULNERABILITIES
VULNERABILITIES
VULNERABILITIES
VULNERABILITIES
EXPLOITABLE
EXPLOITABLE
AVAILABLE
ANONYMOUSLY
WEB APPLICATION
Vulnerability Details
The following table list reported vulnerabilities for the period covered by this report:
46 Critical Vulnerabilities
DATE | CVE | VENDOR | VULNERABILITY | CVSS |
---|---|---|---|---|
2024-07-28 | CVE-2024-7164 | Oretnom23 | SQL Injection vulnerability in Oretnom23 School Fees Payment System 1.0 A vulnerability has been found in SourceCodester School Fees Payment System 1.0 and classified as critical. | 9.8 |
2024-07-27 | CVE-2024-7151 | Tenda | Out-of-bounds Write vulnerability in Tenda O3 Firmware 1.0.0.10(2478) A vulnerability was found in Tenda O3 1.0.0.10(2478). | 9.8 |
2024-07-26 | CVE-2024-41114 | Opengeos | Unspecified vulnerability in Opengeos Streamlit-Geospatial streamlit-geospatial is a streamlit multipage app for geospatial applications. | 9.8 |
2024-07-26 | CVE-2024-41115 | Opengeos | Unspecified vulnerability in Opengeos Streamlit-Geospatial streamlit-geospatial is a streamlit multipage app for geospatial applications. | 9.8 |
2024-07-26 | CVE-2024-41116 | Opengeos | Unspecified vulnerability in Opengeos Streamlit-Geospatial streamlit-geospatial is a streamlit multipage app for geospatial applications. | 9.8 |
2024-07-26 | CVE-2024-41117 | Opengeos | Unspecified vulnerability in Opengeos Streamlit-Geospatial streamlit-geospatial is a streamlit multipage app for geospatial applications. | 9.8 |
2024-07-26 | CVE-2024-41118 | Opengeos | Server-Side Request Forgery (SSRF) vulnerability in Opengeos Streamlit-Geospatial streamlit-geospatial is a streamlit multipage app for geospatial applications. | 9.8 |
2024-07-26 | CVE-2024-41119 | Opengeos | Unspecified vulnerability in Opengeos Streamlit-Geospatial streamlit-geospatial is a streamlit multipage app for geospatial applications. | 9.8 |
2024-07-26 | CVE-2024-41120 | Opengeos | Server-Side Request Forgery (SSRF) vulnerability in Opengeos Streamlit-Geospatial streamlit-geospatial is a streamlit multipage app for geospatial applications. | 9.8 |
2024-07-26 | CVE-2024-41112 | Opengeos | Unspecified vulnerability in Opengeos Streamlit-Geospatial streamlit-geospatial is a streamlit multipage app for geospatial applications. | 9.8 |
2024-07-26 | CVE-2024-41113 | Opengeos | Unspecified vulnerability in Opengeos Streamlit-Geospatial streamlit-geospatial is a streamlit multipage app for geospatial applications. | 9.8 |
2024-07-26 | CVE-2024-40689 | IBM | Unspecified vulnerability in IBM products IBM InfoSphere Information Server 11.7 is vulnerable to SQL injection. | 9.8 |
2024-07-26 | CVE-2024-7120 | Raisecom | Unspecified vulnerability in Raisecom products A vulnerability, which was classified as critical, was found in Raisecom MSG1200, MSG2100E, MSG2200 and MSG2300 3.90. | 9.8 |
2024-07-25 | CVE-2024-24621 | Softaculous | Incorrect Comparison vulnerability in Softaculous Webuzo Softaculous Webuzo contains an authentication bypass vulnerability through the password reset functionality. | 9.8 |
2024-07-25 | CVE-2024-41468 | Tendacn | OS Command Injection vulnerability in Tendacn Fh1201 Firmware 1.2.0.14 Tenda FH1201 v1.2.0.14 was discovered to contain a command injection vulnerability via the cmdinput parameter at /goform/exeCommand | 9.8 |
2024-07-25 | CVE-2024-41473 | Tendacn | OS Command Injection vulnerability in Tendacn Fh1201 Firmware 1.2.0.14 Tenda FH1201 v1.2.0.14 was discovered to contain a command injection vulnerability via the mac parameter at ip/goform/WriteFacMac | 9.8 |
2024-07-25 | CVE-2024-38287 | Rhubcom | Weak Password Recovery Mechanism for Forgotten Password vulnerability in Rhubcom Turbomeeting The password-reset mechanism in the Forgot Password functionality in R-HUB TurboMeeting through 8.x allows unauthenticated remote attackers to force the application into resetting the administrator's password to a random insecure 8-digit value. | 9.8 |
2024-07-25 | CVE-2024-38289 | Rhubcom | SQL Injection vulnerability in Rhubcom Turbomeeting A boolean-based SQL injection issue in the Virtual Meeting Password (VMP) endpoint in R-HUB TurboMeeting through 8.x allows unauthenticated remote attackers to extract hashed passwords from the database, and authenticate to the application, via crafted SQL input. | 9.8 |
2024-07-25 | CVE-2024-7007 | Positron | Missing Authentication for Critical Function vulnerability in Positron Tra7005 Firmware 1.20 Positron Broadcast Signal Processor TRA7005 v1.20 is vulnerable to an authentication bypass exploit that could allow an attacker to have unauthorized access to protected areas of the application. | 9.8 |
2024-07-24 | CVE-2024-41459 | Tendacn | Out-of-bounds Write vulnerability in Tendacn Fh1201 Firmware 1.2.0.14 Tenda FH1201 v1.2.0.14 was discovered to contain a stack-based buffer overflow vulnerability via the PPPOEPassword parameter at ip/goform/QuickIndex. | 9.8 |
2024-07-24 | CVE-2024-41460 | Tendacn | Out-of-bounds Write vulnerability in Tendacn Fh1201 Firmware 1.2.0.14 Tenda FH1201 v1.2.0.14 was discovered to contain a stack-based buffer overflow vulnerability via the entrys parameter at ip/goform/RouteStatic. | 9.8 |
2024-07-24 | CVE-2024-41461 | Tendacn | Out-of-bounds Write vulnerability in Tendacn Fh1201 Firmware 1.2.0.14 Tenda FH1201 v1.2.0.14 was discovered to contain a stack-based buffer overflow vulnerability via the list1 parameter at ip/goform/DhcpListClient. | 9.8 |
2024-07-24 | CVE-2024-7081 | Tailoring Management System Project | Unspecified vulnerability in Tailoring Management System Project Tailoring Management System 1.0 A vulnerability was found in itsourcecode Tailoring Management System 1.0. | 9.8 |
2024-07-24 | CVE-2024-41551 | Campcodes | SQL Injection vulnerability in Campcodes Supplier Management System 1.0 CampCodes Supplier Management System v1.0 is vulnerable to SQL injection via Supply_Management_System/admin/view_order_items.php?id= . | 9.8 |
2024-07-24 | CVE-2023-45249 | Acronis | Improper Authentication vulnerability in Acronis Cyber Infrastructure Remote command execution due to use of default passwords. | 9.8 |
2024-07-24 | CVE-2024-6096 | Progress | Unsafe Reflection vulnerability in Progress Telerik Reporting In Progress® Telerik® Reporting versions prior to 18.1.24.709, a code execution attack is possible through object injection via an insecure type resolution vulnerability. | 9.8 |
2024-07-24 | CVE-2024-6327 | Progress | Deserialization of Untrusted Data vulnerability in Progress Telerik Report Server In Progress® Telerik® Report Server versions prior to 2024 Q2 (10.1.24.709), a remote code execution attack is possible through an insecure deserialization vulnerability. | 9.8 |
2024-07-24 | CVE-2024-7066 | F Logic | Unspecified vulnerability in F-Logic Datacube3 Firmware A vulnerability was found in F-logic DataCube3 1.0. | 9.8 |
2024-07-23 | CVE-2024-41319 | Totolink | Command Injection vulnerability in Totolink A6000R Firmware 1.0.1B20201211.2000 TOTOLINK A6000R V1.0.1-B20201211.2000 was discovered to contain a command injection vulnerability via the cmd parameter in the webcmd function. | 9.8 |
2024-07-22 | CVE-2024-6793 | NI | Deserialization of Untrusted Data vulnerability in NI Veristand A deserialization of untrusted data vulnerability exists in NI VeriStand DataLogging Server that may result in remote code execution. | 9.8 |
2024-07-22 | CVE-2024-6794 | NI | Deserialization of Untrusted Data vulnerability in NI Veristand A deserialization of untrusted data vulnerability exists in NI VeriStand Waveform Streaming Server that may result in remote code execution. | 9.8 |
2024-07-22 | CVE-2024-6805 | NI | Missing Authorization vulnerability in NI Veristand The NI VeriStand Gateway is missing authorization checks when an actor attempts to access File Transfer resources. | 9.8 |
2024-07-22 | CVE-2024-6806 | NI | Missing Authorization vulnerability in NI Veristand The NI VeriStand Gateway is missing authorization checks when an actor attempts to access Project resources. | 9.8 |
2024-07-22 | CVE-2024-6912 | Perkinelmer | Use of Hard-coded Credentials vulnerability in Perkinelmer Processplus Use of hard-coded MSSQL credentials in PerkinElmer ProcessPlus on Windows allows an attacker to login remove on all prone installations.This issue affects ProcessPlus: through 1.11.6507.0. | 9.8 |
2024-07-22 | CVE-2024-39685 | Fish Audio | OS Command Injection vulnerability in Fish.Audio Bert-Vits2 Bert-VITS2 is the VITS2 Backbone with multilingual bert. | 9.8 |
2024-07-22 | CVE-2024-39686 | Fishaudio | OS Command Injection vulnerability in Fishaudio Bert-Vits2 Bert-VITS2 is the VITS2 Backbone with multilingual bert. | 9.8 |
2024-07-22 | CVE-2024-41827 | Jetbrains | Insufficient Session Expiration vulnerability in Jetbrains Teamcity In JetBrains TeamCity before 2024.07 access tokens could continue working after deletion or expiration | 9.8 |
2024-07-22 | CVE-2024-38759 | WP Media | Unspecified vulnerability in Wp-Media Search & Replace Deserialization of Untrusted Data vulnerability in WP MEDIA SAS Search & Replace search-and-replace.This issue affects Search & Replace: from n/a through 3.2.2. | 9.8 |
2024-07-22 | CVE-2024-38773 | Formlift | SQL Injection vulnerability in Formlift for Infusionsoft web Forms Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Adrian Tobey FormLift for Infusionsoft Web Forms allows Blind SQL Injection.This issue affects FormLift for Infusionsoft Web Forms: from n/a through 7.5.17. | 9.8 |
2024-07-22 | CVE-2024-41703 | Librechat | Unspecified vulnerability in Librechat LibreChat through 0.7.4-rc1 has incorrect access control for message updates. | 9.8 |
2024-07-22 | CVE-2024-41704 | Librechat | Path Traversal vulnerability in Librechat LibreChat through 0.7.4-rc1 does not validate the normalized pathnames of images. | 9.8 |
2024-07-22 | CVE-2024-6970 | Tailoring Management System Project | Unspecified vulnerability in Tailoring Management System Project Tailoring Management System 1.0 A vulnerability classified as critical has been found in itsourcecode Tailoring Management System 1.0. | 9.8 |
2024-07-22 | CVE-2024-6966 | Adonesevangelista | Unspecified vulnerability in Adonesevangelista Online Blood Bank Management System 1.0 A vulnerability was found in itsourcecode Online Blood Bank Management System 1.0 and classified as critical. | 9.8 |
2024-07-24 | CVE-2024-41662 | Vnote Project | Cross-site Scripting vulnerability in Vnote Project Vnote VNote is a note-taking platform. | 9.6 |
2024-07-24 | CVE-2024-40422 | Stitionai | Path Traversal vulnerability in Stitionai Devika 1.0 The snapshot_path parameter in the /api/get-browser-snapshot endpoint in stitionai devika v1 is susceptible to a path traversal attack. | 9.1 |
2024-07-24 | CVE-2024-41914 | Arubanetworks | Cross-site Scripting vulnerability in Arubanetworks Edgeconnect Sd-Wan Orchestrator A vulnerability in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authenticated remote attacker to conduct a stored cross-site scripting (XSS) attack against an administrative user of the interface. | 9.0 |
99 High Vulnerabilities
DATE | CVE | VENDOR | VULNERABILITY | CVSS |
---|---|---|---|---|
2024-07-28 | CVE-2024-7171 | Totolink | OS Command Injection vulnerability in Totolink A3600R Firmware 4.1.2Cu.5182B20201102 A vulnerability classified as critical has been found in TOTOLINK A3600R 4.1.2cu.5182_B20201102. | 8.8 |
2024-07-28 | CVE-2024-7172 | Totolink | Unspecified vulnerability in Totolink A3600R Firmware 4.1.2Cu.5182B20201102 A vulnerability classified as critical was found in TOTOLINK A3600R 4.1.2cu.5182_B20201102. | 8.8 |
2024-07-28 | CVE-2024-7170 | Totolink | Use of Hard-coded Credentials vulnerability in Totolink A3000Ru Firmware 5.9C.5185B20201128 A vulnerability was found in TOTOLINK A3000RU 5.9c.5185. | 8.8 |
2024-07-28 | CVE-2024-7169 | Oretnom23 | Unspecified vulnerability in Oretnom23 School Fees Payment System 1.0 A vulnerability classified as problematic has been found in SourceCodester School Fees Payment System 1.0. | 8.8 |
2024-07-28 | CVE-2024-7167 | Oretnom23 | Unspecified vulnerability in Oretnom23 School Fees Payment System 1.0 A vulnerability was found in SourceCodester School Fees Payment System 1.0. | 8.8 |
2024-07-28 | CVE-2024-7168 | Oretnom23 | Unspecified vulnerability in Oretnom23 School Fees Payment System 1.0 A vulnerability was found in SourceCodester School Fees Payment System 1.0. | 8.8 |
2024-07-28 | CVE-2024-7165 | Oretnom23 | Unspecified vulnerability in Oretnom23 School Fees Payment System 1.0 A vulnerability was found in SourceCodester School Fees Payment System 1.0 and classified as critical. | 8.8 |
2024-07-28 | CVE-2024-7166 | Oretnom23 | Unspecified vulnerability in Oretnom23 School Fees Payment System 1.0 A vulnerability was found in SourceCodester School Fees Payment System 1.0. | 8.8 |
2024-07-28 | CVE-2024-7159 | Totolink | Unspecified vulnerability in Totolink A3600R Firmware 4.1.2Cu.5182B20201102 A vulnerability was found in TOTOLINK A3600R 4.1.2cu.5182_B20201102. | 8.8 |
2024-07-28 | CVE-2024-7160 | Totolink | Unspecified vulnerability in Totolink A3700R Firmware 9.1.2U.5822B20200513 A vulnerability classified as critical has been found in TOTOLINK A3700R 9.1.2u.5822_B20200513. | 8.8 |
2024-07-28 | CVE-2024-7158 | Totolink | Unspecified vulnerability in Totolink A3100R Firmware 4.1.2Cu.5050B20200504 A vulnerability was found in TOTOLINK A3100R 4.1.2cu.5050_B20200504. | 8.8 |
2024-07-28 | CVE-2024-7157 | Totolink | Unspecified vulnerability in Totolink A3100R Firmware 4.1.2Cu.5050B20200504 A vulnerability was found in TOTOLINK A3100R 4.1.2cu.5050_B20200504. | 8.8 |
2024-07-27 | CVE-2024-7152 | Tenda | Out-of-bounds Write vulnerability in Tenda O3 Firmware 1.0.0.10(2478) A vulnerability was found in Tenda O3 1.0.0.10(2478). | 8.8 |
2024-07-26 | CVE-2024-38871 | Zohocorp | SQL Injection vulnerability in Zohocorp Manageengine Exchange Reporter Plus Zohocorp ManageEngine Exchange Reporter Plus versions 5717 and below are vulnerable to the authenticated SQL injection in the reports module. | 8.8 |
2024-07-26 | CVE-2024-38872 | Zohocorp | SQL Injection vulnerability in Zohocorp Manageengine Exchange Reporter Plus Zohocorp ManageEngine Exchange Reporter Plus versions 5717 and below are vulnerable to the authenticated SQL injection in the monitoring module. | 8.8 |
2024-07-26 | CVE-2024-39304 | Churchcrm | SQL Injection vulnerability in Churchcrm ChurchCRM is an open-source church management system. | 8.8 |
2024-07-26 | CVE-2024-7119 | Mdmafujulhasan | Unspecified vulnerability in Mdmafujulhasan Online-Payroll-Management-System 20230911 A vulnerability, which was classified as critical, has been found in MD-MAFUJUL-HASAN Online-Payroll-Management-System up to 20230911. | 8.8 |
2024-07-26 | CVE-2024-7117 | Mdmafujulhasan | Unspecified vulnerability in Mdmafujulhasan Online-Payroll-Management-System 20230911 A vulnerability classified as critical has been found in MD-MAFUJUL-HASAN Online-Payroll-Management-System up to 20230911. | 8.8 |
2024-07-26 | CVE-2024-7118 | Mdmafujulhasan | Unspecified vulnerability in Mdmafujulhasan Online-Payroll-Management-System 20230911 A vulnerability classified as critical was found in MD-MAFUJUL-HASAN Online-Payroll-Management-System up to 20230911. | 8.8 |
2024-07-26 | CVE-2024-7116 | Mdmafujulhasan | Unspecified vulnerability in Mdmafujulhasan Online-Payroll-Management-System 20230911 A vulnerability was found in MD-MAFUJUL-HASAN Online-Payroll-Management-System up to 20230911. | 8.8 |
2024-07-26 | CVE-2024-7114 | Tianchoy | Unspecified vulnerability in Tianchoy Blog 1.8.8 A vulnerability was found in Tianchoy Blog up to 1.8.8. | 8.8 |
2024-07-26 | CVE-2024-7115 | Mdmafujulhasan | Unspecified vulnerability in Mdmafujulhasan Online-Payroll-Management-System 20230911 A vulnerability was found in MD-MAFUJUL-HASAN Online-Payroll-Management-System up to 20230911. | 8.8 |
2024-07-25 | CVE-2024-24622 | Softaculous | OS Command Injection vulnerability in Softaculous Webuzo Softaculous Webuzo contains a command injection in the password reset functionality. | 8.8 |
2024-07-25 | CVE-2024-24623 | Softaculous | OS Command Injection vulnerability in Softaculous Webuzo Softaculous Webuzo contains a command injection vulnerability in the FTP management functionality. | 8.8 |
2024-07-25 | CVE-2024-7105 | Forip | SQL Injection vulnerability in Forip Administracao Pabx A vulnerability classified as critical has been found in ForIP Tecnologia Administração PABX 1.x. | 8.8 |
2024-07-25 | CVE-2024-7106 | Denkgroot | Unspecified vulnerability in Denkgroot Spina A vulnerability classified as problematic was found in Spina CMS 2.18.0. | 8.8 |
2024-07-25 | CVE-2024-37084 | Vmware | Unspecified vulnerability in VMWare Spring Cloud Data Flow 2.11.0/2.11.1/2.11.2 In Spring Cloud Data Flow versions prior to 2.11.4, a malicious user who has access to the Skipper server api can use a crafted upload request to write an arbitrary file to any location on the file system which could lead to compromising the server | 8.8 |
2024-07-24 | CVE-2024-41136 | Arubanetworks | OS Command Injection vulnerability in Arubanetworks Edgeconnect Sd-Wan Orchestrator An authenticated command injection vulnerability exists in the HPE Aruba Networking EdgeConnect SD-WAN gateways Command Line Interface. | 8.8 |
2024-07-24 | CVE-2024-31970 | Adtran | Unspecified vulnerability in Adtran SDG Smartos AdTran SRG 834-5 HDC17600021F1 devices (with SmartOS 11.1.1.1 and fixed in Version 12.1.3.1) have SSH enabled by default, accessible both over the LAN and the Internet. | 8.8 |
2024-07-24 | CVE-2024-36541 | Kube Logging | Incorrect Default Permissions vulnerability in Kube-Logging Logging-Operator 4.6.0 Insecure permissions in logging-operator v4.6.0 allows attackers to access sensitive data and escalate privileges by obtaining the service account's token. | 8.8 |
2024-07-24 | CVE-2024-22443 | Arubanetworks | Unspecified vulnerability in Arubanetworks Edgeconnect Sd-Wan Orchestrator A vulnerability in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authenticated remote attacker to conduct a server-side prototype pollution attack. | 8.8 |
2024-07-24 | CVE-2024-31977 | Adtran | OS Command Injection vulnerability in Adtran 834-5 Firmware and SDG Smartos Adtran 834-5 11.1.0.101-202106231430, and fixed as of SmartOS Version 12.6.3.1, devices allow OS Command Injection via shell metacharacters to the Ping or Traceroute utility. | 8.8 |
2024-07-24 | CVE-2024-7067 | Shuttur | Unspecified vulnerability in Shuttur Ecommerce-Laravel-Bootstrap A vulnerability was found in kirilkirkov Ecommerce-Laravel-Bootstrap up to 1f1097a3448ce8ec53e034ea0f70b8e2a0e64a87. | 8.8 |
2024-07-24 | CVE-2023-48362 | Apache | Unspecified vulnerability in Apache Drill XXE in the XML Format Plugin in Apache Drill version 1.19.0 and greater allows a user to read any file on a remote file system or execute commands via a malicious XML file. Users are recommended to upgrade to version 1.21.2, which fixes this issue. | 8.8 |
2024-07-23 | CVE-2024-38164 | Microsoft | Unspecified vulnerability in Microsoft Groupme An improper access control vulnerability in GroupMe allows an a unauthenticated attacker to elevate privileges over a network by convincing a user to click on a malicious link. | 8.8 |
2024-07-22 | CVE-2024-6913 | Perkinelmer | Unspecified vulnerability in Perkinelmer Processplus Execution with unnecessary privileges in PerkinElmer ProcessPlus allows an attacker to spawn a remote shell on the windows system.This issue affects ProcessPlus: through 1.11.6507.0. | 8.8 |
2024-07-22 | CVE-2024-26020 | Ankiweb | Unspecified vulnerability in Ankiweb Anki 24.04 An arbitrary script execution vulnerability exists in the MPV functionality of Ankitects Anki 24.04. | 8.8 |
2024-07-22 | CVE-2024-38701 | Kodezen | Unspecified vulnerability in Kodezen Academy LMS Authorization Bypass Through User-Controlled Key vulnerability in Academy LMS.This issue affects Academy LMS: from n/a through 2.0.4. | 8.8 |
2024-07-22 | CVE-2024-38708 | Ukrsolution | Unspecified vulnerability in Ukrsolution Barcode Scanner and Inventory Manager Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in UkrSolution Barcode Scanner with Inventory & Order Manager allows SQL Injection.This issue affects Barcode Scanner with Inventory & Order Manager: from n/a through 1.6.1. | 8.8 |
2024-07-22 | CVE-2024-38755 | Designinvento | Unspecified vulnerability in Designinvento Directorypress Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Designinvento DirectoryPress allows SQL Injection.This issue affects DirectoryPress: from n/a through 3.6.10. | 8.8 |
2024-07-22 | CVE-2024-23321 | Apache | Unspecified vulnerability in Apache Rocketmq For RocketMQ versions 5.2.0 and below, under certain conditions, there is a risk of exposure of sensitive Information to an unauthorized actor even if RocketMQ is enabled with authentication and authorization functions. An attacker, possessing regular user privileges or listed in the IP whitelist, could potentially acquire the administrator's account and password through specific interfaces. | 8.8 |
2024-07-22 | CVE-2024-5973 | Stylemixthemes | Unspecified vulnerability in Stylemixthemes Masterstudy LMS The MasterStudy LMS WordPress Plugin WordPress plugin before 3.3.24 does not prevent students from creating instructor accounts, which could be used to get access to functionalities they shouldn't have. | 8.8 |
2024-07-22 | CVE-2024-6244 | Projectzealous | Cross-Site Request Forgery (CSRF) vulnerability in Projectzealous PZ Frontend Manager The PZ Frontend Manager WordPress plugin before 1.0.6 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions via CSRF attacks | 8.8 |
2024-07-22 | CVE-2024-6964 | Tenda | Out-of-bounds Write vulnerability in Tenda O3 Firmware1.0.0.10(2478) A vulnerability, which was classified as critical, was found in Tenda O3 1.0.0.10. | 8.8 |
2024-07-22 | CVE-2024-6965 | Tenda | Out-of-bounds Write vulnerability in Tenda O3 Firmware1.0.0.10(2478) A vulnerability has been found in Tenda O3 1.0.0.10 and classified as critical. | 8.8 |
2024-07-22 | CVE-2024-6962 | Tenda | Out-of-bounds Write vulnerability in Tenda O3 Firmware1.0.0.10(2478) A vulnerability classified as critical was found in Tenda O3 1.0.0.10. | 8.8 |
2024-07-22 | CVE-2024-6963 | Tenda | Out-of-bounds Write vulnerability in Tenda O3 Firmware1.0.0.10(2478) A vulnerability, which was classified as critical, has been found in Tenda O3 1.0.0.10. | 8.8 |
2024-07-26 | CVE-2024-35296 | Apache | Unspecified vulnerability in Apache Traffic Server Invalid Accept-Encoding header can cause Apache Traffic Server to fail cache lookup and force forwarding requests. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.10, from 9.0.0 through 9.2.4. Users are recommended to upgrade to version 8.1.11 or 9.2.5, which fixes the issue. | 8.2 |
2024-07-25 | CVE-2024-1724 | Canonical | Incorrect Permission Assignment for Critical Resource vulnerability in Canonical Snapd In snapd versions prior to 2.62, when using AppArmor for enforcement of sandbox permissions, snapd failed to restrict writes to the $HOME/bin path. | 8.2 |
2024-07-22 | CVE-2024-32484 | Ankitects | Cross-site Scripting vulnerability in Ankitects Anki 24.04 An reflected XSS vulnerability exists in the handling of invalid paths in the Flask server in Ankitects Anki 24.04. | 8.2 |
2024-07-23 | CVE-2024-38176 | Microsoft | Unspecified vulnerability in Microsoft Groupme An improper restriction of excessive authentication attempts in GroupMe allows a unauthenticated attacker to elevate privileges over a network. | 8.1 |
2024-07-28 | CVE-2024-42052 | Splashtop | Unspecified vulnerability in Splashtop Streamer 3.3.8.0/3.5.0.0/3.5.6.0 The MSI installer for Splashtop Streamer for Windows before 3.5.8.0 uses a temporary folder with weak permissions during installation. | 7.8 |
2024-07-26 | CVE-2024-7062 | Mikekazakov | Incorrect Authorization vulnerability in Mikekazakov Nimble Commander Nimble Commander suffers from a privilege escalation vulnerability due to the server (info.filesmanager.Files.PrivilegedIOHelperV2) performing improper/insufficient validation of a client’s authorization before executing an operation. | 7.8 |
2024-07-23 | CVE-2024-4079 | NI | Out-of-bounds Read vulnerability in NI Labview An out of bounds read due to a missing bounds check in LabVIEW may disclose information or result in arbitrary code execution. | 7.8 |
2024-07-23 | CVE-2024-4080 | NI | Out-of-bounds Write vulnerability in NI Labview A memory corruption issue due to an improper length check in LabVIEW tdcore.dll may disclose information or result in arbitrary code execution. | 7.8 |
2024-07-23 | CVE-2024-4081 | NI | Out-of-bounds Write vulnerability in NI Labview A memory corruption issue due to an improper length check in NI LabVIEW may disclose information or result in arbitrary code execution. | 7.8 |
2024-07-22 | CVE-2024-6791 | NI | Path Traversal vulnerability in NI Veristand A directory path traversal vulnerability exists when loading a vsmodel file in NI VeriStand that may result in remote code execution. | 7.8 |
2024-07-22 | CVE-2024-6121 | NI | Unspecified vulnerability in NI Flexlogger and Systemlink An out-of-date version of Redis shipped with NI SystemLink Server is susceptible to multiple vulnerabilities, including CVE-2022-24834. | 7.8 |
2024-07-22 | CVE-2024-37391 | Proton | Unspecified vulnerability in Proton Protonvpn ProtonVPN before 3.2.10 on Windows mishandles the drive installer path, which should use this: '"' + ExpandConstant('{autopf}\Proton\Drive') + '"' in Setup/setup.iss. | 7.8 |
2024-07-28 | CVE-2024-7156 | Totolink | Unspecified vulnerability in Totolink A3700R Firmware 9.1.2U.5822B20200513 A vulnerability was found in TOTOLINK A3700R 9.1.2u.5822_B20200513 and classified as problematic. | 7.5 |
2024-07-28 | CVE-2024-7154 | Totolink | Missing Authentication for Critical Function vulnerability in Totolink A3700R Firmware 9.1.2U.5822B20200513 A vulnerability, which was classified as problematic, was found in TOTOLINK A3700R 9.1.2u.5822_B20200513. | 7.5 |
2024-07-26 | CVE-2024-41812 | Txtdot | Server-Side Request Forgery (SSRF) vulnerability in Txtdot txtdot is an HTTP proxy that parses only text, links, and pictures from pages, removing ads and heavy scripts. | 7.5 |
2024-07-26 | CVE-2024-41813 | Txtdot | Server-Side Request Forgery (SSRF) vulnerability in Txtdot txtdot is an HTTP proxy that parses only text, links, and pictures from pages, removing ads and heavy scripts. | 7.5 |
2024-07-26 | CVE-2024-41685 | Syrotech | Incorrect Permission Assignment for Critical Resource vulnerability in Syrotech Sy-Gpon-1110-Wdont Firmware 3.1.02231102 This vulnerability exists in SyroTech SY-GPON-1110-WDONT Router due to missing HTTPOnly flag for the session cookies associated with the router's web management interface. | 7.5 |
2024-07-26 | CVE-2024-41687 | Syrotech | Cleartext Transmission of Sensitive Information vulnerability in Syrotech Sy-Gpon-1110-Wdont Firmware 3.1.02231102 This vulnerability exists in SyroTech SY-GPON-1110-WDONT Router due to transmission of password in plain text. | 7.5 |
2024-07-26 | CVE-2023-38522 | Apache | Unspecified vulnerability in Apache Traffic Server Apache Traffic Server accepts characters that are not allowed for HTTP field names and forwards malformed requests to origin servers. | 7.5 |
2024-07-26 | CVE-2024-35161 | Apache | Unspecified vulnerability in Apache Traffic Server Apache Traffic Server forwards malformed HTTP chunked trailer section to origin servers. | 7.5 |
2024-07-25 | CVE-2022-32759 | IBM | Unspecified vulnerability in IBM products IBM Security Directory Integrator 7.2.0 and IBM Security Verify Directory Integrator 10.0.0 uses insufficient session expiration which could allow an unauthorized user to obtain sensitive information. | 7.5 |
2024-07-25 | CVE-2024-41800 | Craftcms | Improper Authentication vulnerability in Craftcms Craft CMS Craft is a content management system (CMS). | 7.5 |
2024-07-24 | CVE-2024-41462 | Tendacn | Out-of-bounds Write vulnerability in Tendacn Fh1201 Firmware 1.2.0.14 Tenda FH1201 v1.2.0.14 was discovered to contain a stack-based buffer overflow vulnerability via the page parameter at ip/goform/DhcpListClient. | 7.5 |
2024-07-24 | CVE-2024-41463 | Tendacn | Out-of-bounds Write vulnerability in Tendacn Fh1201 Firmware 1.2.0.14 Tenda FH1201 v1.2.0.14 was discovered to contain a stack-based buffer overflow vulnerability via the entrys parameter at ip/goform/addressNat. | 7.5 |
2024-07-24 | CVE-2024-41464 | Tendacn | Out-of-bounds Write vulnerability in Tendacn Fh1201 Firmware 1.2.0.14 Tenda FH1201 v1.2.0.14 was discovered to contain a stack-based buffer overflow vulnerability via the mitInterface parameter in ip/goform/RouteStatic | 7.5 |
2024-07-24 | CVE-2024-41465 | Tendacn | Out-of-bounds Write vulnerability in Tendacn Fh1201 Firmware 1.2.0.14 Tenda FH1201 v1.2.0.14 was discovered to contain a stack-based buffer overflow vulnerability via the funcpara1 parameter at ip/goform/setcfm. | 7.5 |
2024-07-24 | CVE-2024-41466 | Tendacn | Out-of-bounds Write vulnerability in Tendacn Fh1201 Firmware 1.2.0.14 Tenda FH1201 v1.2.0.14 was discovered to contain a stack-based buffer overflow vulnerability via the page parameter at ip/goform/NatStaticSetting. | 7.5 |
2024-07-24 | CVE-2024-7080 | Insurance Management System Project | Path Traversal vulnerability in Insurance Management System Project Insurance Management System 1.0 A vulnerability was found in SourceCodester Insurance Management System 1.0. | 7.5 |
2024-07-24 | CVE-2024-41672 | Duckdb | Unspecified vulnerability in Duckdb DuckDB is a SQL database management system. | 7.5 |
2024-07-24 | CVE-2024-7069 | Oretnom23 | Unspecified vulnerability in Oretnom23 Employee and Visitor Gate Pass Logging System 1.0 A vulnerability, which was classified as critical, has been found in SourceCodester Employee and Visitor Gate Pass Logging System 1.0. | 7.5 |
2024-07-24 | CVE-2024-39676 | Apache | Unspecified vulnerability in Apache Pinot Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Pinot. This issue affects Apache Pinot: from 0.1 before 1.0.0. Users are recommended to upgrade to version 1.0.0 and configure RBAC, which fixes the issue. Details: When using a request to path “/appconfigs” to the controller, it can lead to the disclosure of sensitive information such as system information (e.g. | 7.5 |
2024-07-24 | CVE-2024-6197 | Haxx | Unspecified vulnerability in Haxx Libcurl libcurl's ASN1 parser has this utf8asn1str() function used for parsing an ASN.1 UTF-8 string. | 7.5 |
2024-07-24 | CVE-2024-6750 | Wpwebinfotech | Missing Authorization vulnerability in Wpwebinfotech Social Auto Poster The Social Auto Poster plugin for WordPress is vulnerable to unauthorized access, modification, and loss of data due to a missing capability check on multiple functions in all versions up to, and including, 5.3.14. | 7.5 |
2024-07-23 | CVE-2024-40060 | Wcharczuk | Infinite Loop vulnerability in Wcharczuk Go-Chart go-chart v2.1.1 was discovered to contain an infinite loop via the drawCanvas() function. | 7.5 |
2024-07-22 | CVE-2024-6911 | Perkinelmer | Files or Directories Accessible to External Parties vulnerability in Perkinelmer Processplus Files on the Windows system are accessible without authentication to external parties due to a local file inclusion in PerkinElmer ProcessPlus.This issue affects ProcessPlus: through 1.11.6507.0. | 7.5 |
2024-07-22 | CVE-2024-40051 | IP Guard | Path Traversal vulnerability in Ip-Guard 4.81.0307.0 IP Guard v4.81.0307.0 was discovered to contain an arbitrary file read vulnerability via the file name parameter. | 7.5 |
2024-07-22 | CVE-2024-41131 | Sixlabors | Out-of-bounds Write vulnerability in Sixlabors Imagesharp ImageSharp is a 2D graphics API. | 7.5 |
2024-07-22 | CVE-2024-41132 | Sixlabors | Allocation of Resources Without Limits or Throttling vulnerability in Sixlabors Imagesharp ImageSharp is a 2D graphics API. | 7.5 |
2024-07-22 | CVE-2024-41829 | Jetbrains | Improper Authentication vulnerability in Jetbrains Teamcity In JetBrains TeamCity before 2024.07 an OAuth code for JetBrains Space could be stolen via Space Application connection | 7.5 |
2024-07-22 | CVE-2024-6969 | Oretnom23 | Unspecified vulnerability in Oretnom23 Clinic'S Patient Management System 1.0 A vulnerability was found in SourceCodester Clinics Patient Management System 1.0. | 7.5 |
2024-07-22 | CVE-2024-6967 | Oretnom23 | Unspecified vulnerability in Oretnom23 Employee and Visitor Gate Pass Logging System 1.0 A vulnerability was found in SourceCodester Employee and Visitor Gate Pass Logging System 1.0. | 7.5 |
2024-07-22 | CVE-2024-6968 | Oretnom23 | Unspecified vulnerability in Oretnom23 Clinic'S Patient Management System 1.0 A vulnerability was found in SourceCodester Clinics Patient Management System 1.0. | 7.5 |
2024-07-25 | CVE-2024-29069 | Canonical | Link Following vulnerability in Canonical Snapd In snapd versions prior to 2.62, snapd failed to properly check the destination of symbolic links when extracting a snap. | 7.3 |
2024-07-25 | CVE-2024-38288 | Rhubcom | Command Injection vulnerability in Rhubcom Turbomeeting A command-injection issue in the Certificate Signing Request (CSR) functionality in R-HUB TurboMeeting through 8.x allows authenticated attackers with administrator privileges to execute arbitrary commands on the underlying server as root. | 7.2 |
2024-07-25 | CVE-2024-40318 | Webkul | Unrestricted Upload of File with Dangerous Type vulnerability in Webkul Qloapps 1.6.0 An arbitrary file upload vulnerability in Webkul Qloapps v1.6.0.0 allows attackers to execute arbitrary code via uploading a crafted file. | 7.2 |
2024-07-24 | CVE-2024-39345 | Adtran | OS Command Injection vulnerability in Adtran SDG Smartos AdTran 834-5 HDC17600021F1 (SmartOS 11.1.1.1) devices enable the SSH service by default and have a hidden, undocumented, hard-coded support account whose password is based on the devices MAC address. | 7.2 |
2024-07-22 | CVE-2024-37942 | Berqier | Unspecified vulnerability in Berqier Berqwp Server-Side Request Forgery (SSRF) vulnerability in Berqier Ltd BerqWP.This issue affects BerqWP: from n/a through 1.7.5. | 7.2 |
2024-07-22 | CVE-2024-38692 | Spiffyplugins | Unspecified vulnerability in Spiffyplugins Spiffy Calendar Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Spiffy Plugins Spiffy Calendar allows SQL Injection.This issue affects Spiffy Calendar: from n/a through 4.9.11. | 7.2 |
2024-07-22 | CVE-2024-38788 | Uipress | Unspecified vulnerability in Uipress Lite Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in B?i Admin 2020 UiPress lite allows SQL Injection.This issue affects UiPress lite: from n/a through 3.4.06. | 7.2 |
2024-07-25 | CVE-2024-39672 | Huawei | Unspecified vulnerability in Huawei Emui and Harmonyos Memory request logic vulnerability in the memory module. Impact: Successful exploitation of this vulnerability will affect integrity and availability. | 7.1 |
2024-07-25 | CVE-2024-39673 | Huawei | Unspecified vulnerability in Huawei Emui and Harmonyos Vulnerability of serialisation/deserialisation mismatch in the iAware module. | 7.1 |
2024-07-26 | CVE-2024-41815 | Starship | OS Command Injection vulnerability in Starship Starship is a cross-shell prompt. | 7.0 |
134 Medium Vulnerabilities
DATE | CVE | VENDOR | VULNERABILITY | CVSS |
---|---|---|---|---|
2024-07-26 | CVE-2024-40897 | Gstreamer | Out-of-bounds Write vulnerability in Gstreamer ORC Stack-based buffer overflow vulnerability exists in orcparse.c of ORC versions prior to 0.4.39. | 6.7 |
2024-07-25 | CVE-2024-29068 | Canonical | Unspecified vulnerability in Canonical Snapd In snapd versions prior to 2.62, snapd failed to properly check the file type when extracting a snap. | 6.6 |
2024-07-28 | CVE-2024-7161 | Seacms | Unspecified vulnerability in Seacms 13.0 A vulnerability classified as problematic was found in SeaCMS 13.0. | 6.5 |
2024-07-26 | CVE-2023-49921 | Elastic | Information Exposure Through Log Files vulnerability in Elastic Elasticsearch An issue was discovered by Elastic whereby Watcher search input logged the search query results on DEBUG log level. | 6.5 |
2024-07-24 | CVE-2024-7060 | Gitlab | Unspecified vulnerability in Gitlab An information disclosure vulnerability in GitLab CE/EE in project/group exports affecting all versions from 15.4 prior to 17.0.5, 17.1 prior to 17.1.3, and 17.2 prior to 17.2.1 allows unauthorized users to view the resultant export. | 6.5 |
2024-07-24 | CVE-2024-3297 | CSA IOT | Unspecified vulnerability in Csa-Iot Matter An issue in the Certificate Authenticated Session Establishment (CASE) protocol for establishing secure sessions between two devices, as implemented in the Matter protocol versions before Matter 1.1 allows an attacker to replay manipulated CASE Sigma1 messages to make the device unresponsive until the device is power-cycled. | 6.5 |
2024-07-24 | CVE-2024-40767 | Openstack | Unspecified vulnerability in Openstack Nova In OpenStack Nova before 27.4.1, 28 before 28.2.1, and 29 before 29.1.1, by supplying a raw format image that is actually a crafted QCOW2 image with a backing file path or VMDK flat image with a descriptor file path, an authenticated user may convince systems to return a copy of the referenced file's contents from the server, resulting in unauthorized access to potentially sensitive data. | 6.5 |
2024-07-24 | CVE-2024-5861 | Wpeasypay | Missing Authorization vulnerability in Wpeasypay WP Easypay The WP EasyPay – Square for WordPress plugin for WordPress is vulnerable to unauthorized modification of datadue to a missing capability check on the wpep_square_disconnect() function in all versions up to, and including, 4.2.3. | 6.5 |
2024-07-24 | CVE-2024-6751 | Wpwebinfotech | Cross-Site Request Forgery (CSRF) vulnerability in Wpwebinfotech Social Auto Poster The Social Auto Poster plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.3.14. | 6.5 |
2024-07-22 | CVE-2024-39688 | Fish Audio | Path Traversal vulnerability in Fish.Audio Bert-Vits2 Bert-VITS2 is the VITS2 Backbone with multilingual bert. | 6.5 |
2024-07-22 | CVE-2024-29073 | Ankiweb | Inclusion of Functionality from Untrusted Control Sphere vulnerability in Ankiweb Anki 24.04 An vulnerability in the handling of Latex exists in Ankitects Anki 24.04. | 6.5 |
2024-07-22 | CVE-2024-41824 | Jetbrains | Information Exposure Through Log Files vulnerability in Jetbrains Teamcity In JetBrains TeamCity before 2024.07 parameters of the "password" type could leak into the build log in some specific cases | 6.5 |
2024-07-22 | CVE-2024-41828 | Jetbrains | Unspecified vulnerability in Jetbrains Teamcity In JetBrains TeamCity before 2024.07 comparison of authorization tokens took non-constant time | 6.5 |
2024-07-22 | CVE-2024-34457 | Apache | Unspecified vulnerability in Apache Streampark On versions before 2.1.4, after a regular user successfully logs in, they can manually make a request using the authorization token to view everyone's user flink information, including executeSQL and config. Mitigation: all users should upgrade to 2.1.4 | 6.5 |
2024-07-22 | CVE-2024-6542 | Checkmk | Unspecified vulnerability in Checkmk 2.0.0/2.1.0/2.2.0 Improper neutralization of livestatus command delimiters in mknotifyd in Checkmk <= 2.0.0p39, < 2.1.0p47, < 2.2.0p32 and < 2.3.0p11 allows arbitrary livestatus command execution. | 6.5 |
2024-07-22 | CVE-2024-38723 | Json Content Importer | Unspecified vulnerability in Json-Content-Importer Json Content Importer Server-Side Request Forgery (SSRF) vulnerability in Bernhard Kux JSON Content Importer.This issue affects JSON Content Importer: from n/a through 1.5.6. | 6.4 |
2024-07-22 | CVE-2024-38728 | S Sols | Unspecified vulnerability in S-Sols Seraphinite Post .Docx Source Server-Side Request Forgery (SSRF) vulnerability in Seraphinite Solutions Seraphinite Post .DOCX Source.This issue affects Seraphinite Post .DOCX Source: from n/a through 2.16.9. | 6.4 |
2024-07-22 | CVE-2024-38730 | Wpthemespace | Unspecified vulnerability in Wpthemespace Magical Addons for Elementor Server-Side Request Forgery (SSRF) vulnerability in Noor alam Magical Addons For Elementor.This issue affects Magical Addons For Elementor: from n/a through 1.1.41. | 6.4 |
2024-07-23 | CVE-2024-41012 | Linux | Use After Free vulnerability in Linux Kernel In the Linux kernel, the following vulnerability has been resolved: filelock: Remove locks reliably when fcntl/close race is detected When fcntl_setlk() races with close(), it removes the created lock with do_lock_file_wait(). However, LSMs can allow the first do_lock_file_wait() that created the lock while denying the second do_lock_file_wait() that tries to remove the lock. Separately, posix_lock_file() could also fail to remove a lock due to GFP_KERNEL allocation failure (when splitting a range in the middle). After the bug has been triggered, use-after-free reads will occur in lock_get_status() when userspace reads /proc/locks. | 6.3 |
2024-07-28 | CVE-2024-7163 | Seacms | Unspecified vulnerability in Seacms 12.9 A vulnerability, which was classified as problematic, was found in SeaCMS 12.9. | 6.1 |
2024-07-25 | CVE-2024-3938 | Dotcms | Cross-site Scripting vulnerability in Dotcms The "reset password" login page accepted an HTML injection via URL parameters. This has already been rectified via patch, and as such it cannot be demonstrated via Demo site link. | 6.1 |
2024-07-25 | CVE-2024-41809 | Openobserve | Cross-site Scripting vulnerability in Openobserve OpenObserve is an open-source observability platform. | 6.1 |
2024-07-25 | CVE-2024-6558 | HMS Networks | Unspecified vulnerability in Hms-Networks products HMS Industrial Networks Anybus-CompactCom 30 products are vulnerable to a XSS attack caused by the lack of input sanitation checks. | 6.1 |
2024-07-25 | CVE-2024-41801 | Openproject | Open Redirect vulnerability in Openproject OpenProject is open source project management software. | 6.1 |
2024-07-24 | CVE-2024-22444 | Arubanetworks | Cross-site Scripting vulnerability in Arubanetworks Edgeconnect Sd-Wan Orchestrator A vulnerability within the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow a remote attacker to conduct a reflected cross-site scripting (XSS) attack against a user of the interface. | 6.1 |
2024-07-24 | CVE-2024-6753 | Wpwebinfotech | Cross-site Scripting vulnerability in Wpwebinfotech Social Auto Poster The Social Auto Poster plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘mapTypes’ parameter in the 'wpw_auto_poster_map_wordpress_post_type' AJAX function in all versions up to, and including, 5.3.14 due to insufficient input sanitization and output escaping. | 6.1 |
2024-07-22 | CVE-2024-24507 | ACT ON | Cross-site Scripting vulnerability in Act-On 2023 Cross Site Scripting vulnerability in Act-On 2023 allows a remote attacker to execute arbitrary code via the newUser parameter in the login.jsp component. | 6.1 |
2024-07-22 | CVE-2024-35656 | Elementor | Unspecified vulnerability in Elementor PRO 3.0.5/3.11.6/3.11.7 Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Elementor Elementor Pro allows Reflected XSS.This issue affects Elementor Pro: from n/a through 3.21.2. | 6.1 |
2024-07-22 | CVE-2024-37097 | Unitedthemes | Cross-site Scripting vulnerability in Unitedthemes Shortcodes Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in UnitedThemes Shortcodes by United Themes allows Reflected XSS.This issue affects Shortcodes by United Themes: from n/a before 5.0.5. | 6.1 |
2024-07-22 | CVE-2024-37117 | Uncannyowl | Unspecified vulnerability in Uncannyowl Uncanny Automator Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Uncanny Owl Uncanny Automator Pro allows Reflected XSS.This issue affects Uncanny Automator Pro: from n/a through 5.3. | 6.1 |
2024-07-22 | CVE-2024-37199 | Kriesi | Unspecified vulnerability in Kriesi Enfold Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Kriesi.At Enfold allows Reflected XSS.This issue affects Enfold: from n/a through 5.6.9. | 6.1 |
2024-07-22 | CVE-2024-37206 | Theme4Press | Cross-site Scripting vulnerability in Theme4Press Demo Awesome 1.0.0/1.0.1 Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Theme4Press Demo Awesome allows Reflected XSS.This issue affects Demo Awesome: from n/a through 1.0.1. | 6.1 |
2024-07-22 | CVE-2024-37211 | Ali2Woo | Unspecified vulnerability in Ali2Woo Aliexpress Dropshipping With Alinext Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Ali2Woo Team Ali2Woo Lite allows Reflected XSS.This issue affects Ali2Woo Lite: from n/a through 3.3.5. | 6.1 |
2024-07-22 | CVE-2024-37245 | Vsourz | Unspecified vulnerability in Vsourz ALL in ONE Redirection Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Vsourz Digital All In One Redirection allows Reflected XSS.This issue affects All In One Redirection: from n/a through 2.2.0. | 6.1 |
2024-07-22 | CVE-2024-37257 | Permalink Manager Lite Project | Unspecified vulnerability in Permalink Manager Lite Project Permalink Manager Lite Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Maciej Bis Permalink Manager Lite allows Reflected XSS.This issue affects Permalink Manager Lite: from n/a through 2.4.3.3. | 6.1 |
2024-07-22 | CVE-2024-37258 | Wpsocialrocket | Unspecified vulnerability in Wpsocialrocket Social Rocket Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Social Rocket allows Reflected XSS.This issue affects Social Rocket: from n/a through 1.3.3. | 6.1 |
2024-07-22 | CVE-2024-37259 | Wpextended | Unspecified vulnerability in Wpextended WP Extended Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WP Extended The Ultimate WordPress Toolkit – WP Extended allows Reflected XSS.This issue affects The Ultimate WordPress Toolkit – WP Extended: from n/a through 2.4.7. | 6.1 |
2024-07-22 | CVE-2024-37261 | Wplab | Unspecified vulnerability in Wplab Wp-Lister Lite for Amazon Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WP Lab WP-Lister Lite for Amazon allows Reflected XSS.This issue affects WP-Lister Lite for Amazon: from n/a through 2.6.16. | 6.1 |
2024-07-22 | CVE-2024-37262 | Vcita | Unspecified vulnerability in Vcita Online Booking & Scheduling Calendar for Wordpress BY Vcita Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in vCita.Com Online Booking & Scheduling Calendar for WordPress by vcita allows Reflected XSS.This issue affects Online Booking & Scheduling Calendar for WordPress by vcita: from n/a through 4.4.2. | 6.1 |
2024-07-22 | CVE-2024-37264 | Groundhogg | Unspecified vulnerability in Groundhogg Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Groundhogg Inc. | 6.1 |
2024-07-22 | CVE-2024-37267 | Kaptinlin | Unspecified vulnerability in Kaptinlin Striking Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in kaptinlin Striking allows Reflected XSS.This issue affects Striking: from n/a through 2.3.4. | 6.1 |
2024-07-22 | CVE-2024-37275 | Nextscripts | Unspecified vulnerability in Nextscripts Social Networks Auto Poster Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in NextScripts allows Reflected XSS.This issue affects NextScripts: from n/a through 4.4.6. | 6.1 |
2024-07-22 | CVE-2024-37416 | Wppa | Cross-site Scripting vulnerability in Wppa WP Photo Album Plus Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in J.N. | 6.1 |
2024-07-22 | CVE-2024-37432 | Themegrill | Unspecified vulnerability in Themegrill Esteem Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in ThemeGrill Esteem allows Stored XSS.This issue affects Esteem: from n/a through 1.5.0. | 6.1 |
2024-07-22 | CVE-2024-37433 | Mailster | Unspecified vulnerability in Mailster Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in EverPress Mailster allows Reflected XSS.This issue affects Mailster: from n/a through 4.0.9. | 6.1 |
2024-07-24 | CVE-2023-32471 | Dell | Unspecified vulnerability in Dell products Dell Edge Gateway BIOS, versions 3200 and 5200, contains an out-of-bounds read vulnerability. | 6.0 |
2024-07-26 | CVE-2024-37034 | Couchbase | Inadequate Encryption Strength vulnerability in Couchbase Server An issue was discovered in Couchbase Server before 7.2.5 and 7.6.0 before 7.6.1. | 5.9 |
2024-07-25 | CVE-2024-38103 | Microsoft | Unspecified vulnerability in Microsoft Edge Microsoft Edge (Chromium-based) Information Disclosure Vulnerability | 5.9 |
2024-07-24 | CVE-2023-32466 | Dell | Unspecified vulnerability in Dell Edge Gateway 3200 Firmware Dell Edge Gateway BIOS, versions 3200 and 5200, contains an out-of-bounds write vulnerability. | 5.7 |
2024-07-25 | CVE-2023-7271 | Huawei | Unspecified vulnerability in Huawei Emui and Harmonyos Privilege escalation vulnerability in the NMS module Impact: Successful exploitation of this vulnerability will affect availability. | 5.5 |
2024-07-25 | CVE-2024-39670 | Huawei | Unspecified vulnerability in Huawei Emui and Harmonyos Privilege escalation vulnerability in the account synchronisation module. Impact: Successful exploitation of this vulnerability will affect availability. | 5.5 |
2024-07-25 | CVE-2024-39671 | Huawei | Unspecified vulnerability in Huawei Emui and Harmonyos Access control vulnerability in the security verification module. Impact: Successful exploitation of this vulnerability may affect service confidentiality. | 5.5 |
2024-07-25 | CVE-2024-39674 | Huawei | Unspecified vulnerability in Huawei Emui and Harmonyos Plaintext vulnerability in the Gallery search module. Impact: Successful exploitation of this vulnerability will affect availability. | 5.5 |
2024-07-24 | CVE-2024-40575 | Huawei | Unspecified vulnerability in Huawei Opengauss 7.3.0 An issue in Huawei Technologies opengauss (openGauss 5.0.0 build) v.7.3.0 allows a local attacker to cause a denial of service via the modification of table attributes | 5.5 |
2024-07-23 | CVE-2024-41836 | Adobe | NULL Pointer Dereference vulnerability in Adobe Indesign InDesign Desktop versions ID18.5.2, ID19.3 and earlier are affected by a NULL Pointer Dereference vulnerability that could lead to an application denial-of-service (DoS) condition. | 5.5 |
2024-07-22 | CVE-2024-6122 | NI | Incorrect Default Permissions vulnerability in NI Flexlogger and Systemlink An incorrect permission in the installation directory for the shared NI SystemLink Server KeyValueDatabase service may result in information disclosure via local access. | 5.5 |
2024-07-28 | CVE-2024-7162 | Seacms | Unspecified vulnerability in Seacms 12.9/13.0 A vulnerability, which was classified as problematic, has been found in SeaCMS 12.9/13.0. | 5.4 |
2024-07-28 | CVE-2024-42054 | Cervantessec | Unrestricted Upload of File with Dangerous Type vulnerability in Cervantessec Cervantes 0.3/0.4/0.5 Cervantes through 0.5-alpha accepts insecure file uploads. | 5.4 |
2024-07-28 | CVE-2024-42055 | Cervantessec | Cross-site Scripting vulnerability in Cervantessec Cervantes 0.3/0.4/0.5 Cervantes through 0.5-alpha allows stored XSS. | 5.4 |
2024-07-26 | CVE-2024-25090 | Apache | Unspecified vulnerability in Apache Roller Insufficient input validation and sanitation in Profile name & screenname, Bookmark name & description and blogroll name features in all versions of Apache Roller on all platforms allows an authenticated user to perform an XSS attack. | 5.4 |
2024-07-25 | CVE-2024-40324 | Datex Soft | Injection vulnerability in Datex-Soft E-Staff 5.1 A CRLF injection vulnerability in E-Staff v5.1 allows attackers to insert Carriage Return (CR) and Line Feed (LF) characters into input fields, leading to HTTP response splitting and header manipulation. | 5.4 |
2024-07-25 | CVE-2024-41808 | Openobserve | Cross-site Scripting vulnerability in Openobserve The OpenObserve open-source observability platform provides the ability to filter logs in a dashboard by the values uploaded in a given log. | 5.4 |
2024-07-25 | CVE-2024-28772 | IBM | Unspecified vulnerability in IBM products IBM Security Directory Integrator 7.2.0 and IBM Security Verify Directory Integrator 10.0.0 is vulnerable to stored cross-site scripting. | 5.4 |
2024-07-25 | CVE-2024-41705 | Archerirm | Cross-site Scripting vulnerability in Archerirm Archer A stored XSS issue was discovered in Archer Platform 6.8 before 2024.06. | 5.4 |
2024-07-25 | CVE-2024-41706 | Archerirm | Cross-site Scripting vulnerability in Archerirm Archer A stored XSS issue was discovered in Archer Platform 6 before version 2024.06. | 5.4 |
2024-07-25 | CVE-2024-41707 | Archerirm | Cross-site Scripting vulnerability in Archerirm Archer An issue was discovered in Archer Platform 6 before 2024.06. | 5.4 |
2024-07-25 | CVE-2024-7047 | Gitlab | Cross-site Scripting vulnerability in Gitlab A cross site scripting vulnerability exists in GitLab CE/EE affecting all versions from 16.6 prior to 17.0.5, 17.1 prior to 17.1.3, 17.2 prior to 17.2.1 allowing an attacker to execute arbitrary scripts under the context of the current logged in user. | 5.4 |
2024-07-24 | CVE-2024-3896 | Robogallery | Cross-site Scripting vulnerability in Robogallery Robo Gallery The Photo Gallery, Images, Slider in Rbs Image Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the the Gallery title field in all versions up to, and including, 3.2.19 due to insufficient input sanitization and output escaping. | 5.4 |
2024-07-24 | CVE-2024-5818 | Royal Elementor Addons | Cross-site Scripting vulnerability in Royal-Elementor-Addons Royal Elementor Addons The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored DOM-based Cross-Site Scripting via the plugin's Magazine Grid/Slider widget in all versions up to, and including, 1.3.980 due to insufficient input sanitization and output escaping on user supplied attributes. | 5.4 |
2024-07-24 | CVE-2024-6896 | Ampforwp | Cross-site Scripting vulnerability in Ampforwp Accelerated Mobile Pages The AMP for WP – Accelerated Mobile Pages plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.0.96.1 due to insufficient input sanitization and output escaping. | 5.4 |
2024-07-24 | CVE-2024-6930 | Wpbookingcalendar | Cross-site Scripting vulnerability in Wpbookingcalendar Booking Calendar The WP Booking Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'type' attribute within the plugin's bookingform shortcode in all versions up to, and including, 10.2.1 due to insufficient input sanitization and output escaping on user supplied attributes. | 5.4 |
2024-07-24 | CVE-2024-6629 | Plugins360 | Cross-site Scripting vulnerability in Plugins360 All-In-One Video Gallery The All-in-One Video Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Video shortcode in all versions up to, and including, 3.7.1 due to insufficient input sanitization and output escaping on user supplied attributes. | 5.4 |
2024-07-24 | CVE-2024-3246 | Litespeedtech | Cross-Site Request Forgery (CSRF) vulnerability in Litespeedtech Litespeed Cache The LiteSpeed Cache plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 6.2.0.1. | 5.4 |
2024-07-24 | CVE-2024-6752 | Wpwebinfotech | Cross-site Scripting vulnerability in Wpwebinfotech Social Auto Poster The Social Auto Poster plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘wp_name’ parameter in the 'wpw_auto_poster_map_wordpress_post_type' AJAX function in all versions up to, and including, 5.3.14 due to insufficient input sanitization and output escaping. | 5.4 |
2024-07-22 | CVE-2024-41825 | Jetbrains | Cross-site Scripting vulnerability in Jetbrains Teamcity In JetBrains TeamCity before 2024.07 stored XSS was possible on the Code Inspection tab | 5.4 |
2024-07-22 | CVE-2024-33933 | Brainstormforce | Unspecified vulnerability in Brainstormforce Elementor - Header, Footer & Blocks Template Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Brainstorm Force, Nikhil Chavan Elementor – Header, Footer & Blocks Template allows DOM-Based XSS.This issue affects Elementor – Header, Footer & Blocks Template: from n/a through 1.6.35. | 5.4 |
2024-07-22 | CVE-2024-37100 | Threeroutesmedia | Unspecified vulnerability in Threeroutesmedia Elegant Themes Icons Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Mayur Somani, threeroutes media Elegant Themes Icons allows Stored XSS.This issue affects Elegant Themes Icons: from n/a through 1.3. | 5.4 |
2024-07-22 | CVE-2024-37101 | Afthemes | Unspecified vulnerability in Afthemes WP Post Author Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in AF themes WP Post Author allows Stored XSS.This issue affects WP Post Author: from n/a through 3.6.7. | 5.4 |
2024-07-22 | CVE-2024-37114 | Takashimatsuyama | Unspecified vulnerability in Takashimatsuyama MY Favorites Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Takashi Matsuyama My Favorites allows Stored XSS.This issue affects My Favorites: from n/a through 1.4.1. | 5.4 |
2024-07-22 | CVE-2024-37116 | Sinatrateam | Unspecified vulnerability in Sinatrateam Sinatra Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in sinatrateam Sinatra allows Stored XSS.This issue affects Sinatra: from n/a through 1.3. | 5.4 |
2024-07-22 | CVE-2024-37215 | Creativeinteractivemedia | Unspecified vulnerability in Creativeinteractivemedia Transition Slider Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in creativeinteractivemedia Transition Slider – Responsive Image Slider and Gallery allows Stored XSS.This issue affects Transition Slider – Responsive Image Slider and Gallery: from n/a through 2.20.3. | 5.4 |
2024-07-22 | CVE-2024-37216 | Generatewp | Unspecified vulnerability in Generatewp Sketchfab Embed Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Rami Yushuvaev Sketchfab Embed allows Stored XSS.This issue affects Sketchfab Embed: from n/a through 1.5. | 5.4 |
2024-07-22 | CVE-2024-37217 | Prowcplugins | Unspecified vulnerability in Prowcplugins Empty Cart Button for Woocommerce 1.3.8 Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in ProWCPlugins Empty Cart Button for WooCommerce allows Stored XSS.This issue affects Empty Cart Button for WooCommerce: from n/a through 1.3.8. | 5.4 |
2024-07-22 | CVE-2024-37219 | Pagebuildersandwich | Unspecified vulnerability in Pagebuildersandwich Page Builder Sandwich Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in PBN Hosting SL Page Builder Sandwich – Front-End Page Builder allows Stored XSS.This issue affects Page Builder Sandwich – Front-End Page Builder: from n/a through 5.1.0. | 5.4 |
2024-07-22 | CVE-2024-37221 | Kimili | Unspecified vulnerability in Kimili Flash Embed Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Michael Bester Kimili Flash Embed allows Stored XSS.This issue affects Kimili Flash Embed: from n/a through 2.5.3. | 5.4 |
2024-07-22 | CVE-2024-37223 | Nicdarkthemes | Unspecified vulnerability in Nicdarkthemes Restaurant Food 2.0 Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Nicdark Restaurant Reservations allows Stored XSS.This issue affects Restaurant Reservations: from n/a through 2.0. | 5.4 |
2024-07-22 | CVE-2024-37229 | Auburnforest | Unspecified vulnerability in Auburnforest Blogmentor Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in AuburnForest Blogmentor – Blog Layouts for Elementor allows Stored XSS.This issue affects Blogmentor – Blog Layouts for Elementor: from n/a through 1.5. | 5.4 |
2024-07-22 | CVE-2024-37244 | Ninjabeaveraddon | Unspecified vulnerability in Ninjabeaveraddon Ninja Beaver Add-Ons for Beaver Builder Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Ninja Team Ninja Beaver Add-ons for Beaver Builder allows Stored XSS.This issue affects Ninja Beaver Add-ons for Beaver Builder: from n/a through 2.4.5. | 5.4 |
2024-07-22 | CVE-2024-38503 | Apache | Unspecified vulnerability in Apache Syncope When editing a user, group or any object in the Syncope Console, HTML tags could be added to any text field and could lead to potential exploits. The same vulnerability was found in the Syncope Enduser, when editing “Personal Information” or “User Requests”. Users are recommended to upgrade to version 3.0.8, which fixes this issue. | 5.4 |
2024-07-22 | CVE-2024-37246 | Gallery Slideshow Project | Unspecified vulnerability in Gallery Slideshow Project Gallery Slideshow Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Jethin Gallery Slideshow allows Stored XSS.This issue affects Gallery Slideshow: from n/a through 1.4.1. | 5.4 |
2024-07-22 | CVE-2024-37263 | Themelooks | Cross-site Scripting vulnerability in Themelooks Enter Addons Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in ThemeLooks Enter Addons enteraddons allows Stored XSS.This issue affects Enter Addons: from n/a through 2.1.6. | 5.4 |
2024-07-22 | CVE-2024-37265 | Northernbeacheswebsites | Unspecified vulnerability in Northernbeacheswebsites Ideapush Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Martin Gibson IdeaPush allows Stored XSS.This issue affects IdeaPush: from n/a through 8.60. | 5.4 |
2024-07-22 | CVE-2024-37278 | Brainstormforce | Unspecified vulnerability in Brainstormforce Cards for Beaver Builder Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Pratik Chaskar Cards for Beaver Builder.This issue affects Cards for Beaver Builder: from n/a through 1.1.4. | 5.4 |
2024-07-22 | CVE-2024-37409 | Wpbeaveraddons | Unspecified vulnerability in Wpbeaveraddons Powerpack Lite for Beaver Builder Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Beaver Addons PowerPack Lite for Beaver Builder allows Stored XSS.This issue affects PowerPack Lite for Beaver Builder: from n/a through 1.3.0.4. | 5.4 |
2024-07-22 | CVE-2024-37414 | Depicter | Unspecified vulnerability in Depicter Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Depicter Slider and Popup by Averta Depicter Slider allows Stored XSS.This issue affects Depicter Slider: from n/a through 3.0.2. | 5.4 |
2024-07-22 | CVE-2024-37422 | Emiliaprojects | Unspecified vulnerability in Emiliaprojects Progress Planner Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Team Emilia Projects Progress Planner allows Stored XSS.This issue affects Progress Planner: from n/a through 0.9.2. | 5.4 |
2024-07-22 | CVE-2024-37428 | Themesgrove | Unspecified vulnerability in Themesgrove All-In-One Addons for Elementor Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Themesgrove WidgetKit allows Stored XSS.This issue affects WidgetKit: from n/a through 2.5.0. | 5.4 |
2024-07-22 | CVE-2024-37445 | Bplugins | Unspecified vulnerability in Bplugins Html5 Audio Player Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in bPlugins Html5 Audio Player allows Stored XSS.This issue affects Html5 Audio Player: from n/a through 2.2.23. | 5.4 |
2024-07-22 | CVE-2024-6271 | Community Events Project | Cross-Site Request Forgery (CSRF) vulnerability in Community Events Project Community Events The Community Events WordPress plugin before 1.5 does not have CSRF check in place when deleting events, which could allow attackers to make a logged in admin delete arbitrary events via a CSRF attack | 5.4 |
2024-07-27 | CVE-2024-1798 | Themeum | Missing Authorization vulnerability in Themeum Tutor LMS - Migration Tool The Tutor LMS – Migration Tool plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the tutor_lp_export_xml function in all versions up to, and including, 2.2.0. | 5.3 |
2024-07-26 | CVE-2024-41684 | Syrotech | Unspecified vulnerability in Syrotech Sy-Gpon-1110-Wdont Firmware 3.1.02231102 This vulnerability exists in SyroTech SY-GPON-1110-WDONT Router due to missing secure flag for the session cookies associated with the router's web management interface. | 5.3 |
2024-07-24 | CVE-2024-6755 | Wpwebinfotech | Missing Authorization vulnerability in Wpwebinfotech Social Auto Poster The Social Auto Poster plugin for WordPress is vulnerable to unauthorized modification and loss of data due to a missing capability check on the ‘wpw_auto_poster_quick_delete_multiple’ function in all versions up to, and including, 5.3.14. | 5.3 |
2024-07-24 | CVE-2024-7091 | Gitlab | Unspecified vulnerability in Gitlab An issue was discovered in GitLab CE/EE affecting all versions starting from 15.6 prior to 17.0.5, starting from 17.1 prior to 17.1.3, and starting from 17.2 prior to 17.2.1 where it was possible to disclose limited information of an exported group or project to another user. | 5.0 |
2024-07-24 | CVE-2024-5067 | Gitlab | Unspecified vulnerability in Gitlab An issue was discovered in GitLab EE affecting all versions starting from 16.11 prior to 17.0.5, starting from 17.1 prior to 17.1.3, and starting from 17.2 prior to 17.2.1 where certain project-level analytics settings could be leaked in DOM to group members with Developer or higher roles. | 4.9 |
2024-07-27 | CVE-2024-6518 | Fluentforms | Cross-site Scripting vulnerability in Fluentforms Contact Form The Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 5.1.19 due to insufficient input sanitization and output escaping. | 4.8 |
2024-07-27 | CVE-2024-6520 | Fluentforms | Cross-site Scripting vulnerability in Fluentforms Contact Form The Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 5.1.19 due to insufficient input sanitization and output escaping. | 4.8 |
2024-07-27 | CVE-2024-6521 | Fluentforms | Cross-site Scripting vulnerability in Fluentforms Contact Form The Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 5.1.19 due to insufficient input sanitization and output escaping. | 4.8 |
2024-07-24 | CVE-2024-31971 | Adtran | Cross-site Scripting vulnerability in Adtran Netvanta 3120 Firmware 18.01.01.00.E Multiple stored cross-site scripting (XSS) vulnerabilities on AdTran NetVanta 3120 18.01.01.00.E devices allow remote attackers to inject arbitrary JavaScript, as demonstrated by /mainPassword.html, /processIdentity.html, /public.html, /dhcp.html, /private.html, /hostname.html, /connectivity.html, /NetworkMonitor.html, /trafficMonitoringConfig.html, and /wizardMain.html. | 4.8 |
2024-07-24 | CVE-2024-6094 | Technowich | Cross-site Scripting vulnerability in Technowich WP Ulike The WP ULike WordPress plugin before 4.7.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). | 4.8 |
2024-07-22 | CVE-2024-41826 | Jetbrains | Cross-site Scripting vulnerability in Jetbrains Teamcity In JetBrains TeamCity before 2024.07 stored XSS was possible on Show Connection page | 4.8 |
2024-07-22 | CVE-2024-37120 | Oxilab | Unspecified vulnerability in Oxilab Responsive Tabs Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Biplob Adhikari Tabs allows Stored XSS.This issue affects Tabs: from n/a through 4.0.6. | 4.8 |
2024-07-22 | CVE-2024-37121 | Oxilab | Unspecified vulnerability in Oxilab Shortcode Addons Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in biplob018 Shortcode Addons allows Stored XSS.This issue affects Shortcode Addons: from n/a through 3.2.5. | 4.8 |
2024-07-22 | CVE-2024-37122 | Oxilab | Unspecified vulnerability in Oxilab Accordions Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Biplob Adhikari Accordions allows Stored XSS.This issue affects Accordions: from n/a through 2.3.5. | 4.8 |
2024-07-22 | CVE-2024-37239 | Wpmudev | Cross-site Scripting vulnerability in Wpmudev Branda Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WPMU DEV Branda allows Stored XSS.This issue affects Branda: from n/a through 3.4.17. | 4.8 |
2024-07-22 | CVE-2024-37271 | Print MY Blog Project | Unspecified vulnerability in Print MY Blog Project Print MY Blog Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Michael Nelson Print My Blog allows Stored XSS.This issue affects Print My Blog: from n/a through 3.27.0. | 4.8 |
2024-07-22 | CVE-2024-37429 | Idehweb | Unspecified vulnerability in Idehweb Login With Phone Number Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Hamid Alinia – idehweb Login with phone number allows Stored XSS.This issue affects Login with phone number: from n/a through 1.7.35. | 4.8 |
2024-07-22 | CVE-2024-37434 | Atarim | Unspecified vulnerability in Atarim Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Atarim allows Stored XSS.This issue affects Atarim: from n/a through 3.31. | 4.8 |
2024-07-22 | CVE-2024-41709 | Backdropcms | Cross-site Scripting vulnerability in Backdropcms Backdrop Backdrop CMS before 1.27.3 and 1.28.x before 1.28.2 does not sufficiently sanitize field labels before they are displayed in certain places. | 4.8 |
2024-07-22 | CVE-2024-5004 | Cminds | Cross-site Scripting vulnerability in Cminds CM Popup The CM Popup Plugin for WordPress WordPress plugin before 1.6.6 does not sanitise and escape some of the campaign settings, which could allow high privilege users such as contributor to perform Stored Cross-Site Scripting attacks | 4.8 |
2024-07-22 | CVE-2024-5529 | Holoborodko | Cross-site Scripting vulnerability in Holoborodko WP Quicklatex The WP QuickLaTeX WordPress plugin before 3.8.8 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). | 4.8 |
2024-07-22 | CVE-2024-6243 | Ibericode | Cross-site Scripting vulnerability in Ibericode Html Forms The HTML Forms WordPress plugin before 1.3.33 does not sanitize and escape the form message inputs, allowing high-privilege users, such as administrators, to perform Stored Cross-Site Scripting (XSS) attacks even when the unfiltered_html capability is disabled. | 4.8 |
2024-07-28 | CVE-2024-7155 | Totolink | Use of Hard-coded Credentials vulnerability in Totolink A3300R Firmware 17.0.0Cu.557B20221024 A vulnerability has been found in TOTOLINK A3300R 17.0.0cu.557_B20221024 and classified as problematic. | 4.7 |
2024-07-26 | CVE-2024-41688 | Syrotech | Cleartext Storage of Sensitive Information vulnerability in Syrotech Sy-Gpon-1110-Wdont Firmware 3.1.02231102 This vulnerability exists in SyroTech SY-GPON-1110-WDONT Router due lack of encryption in storing of usernames and passwords within the router's firmware/ database. | 4.6 |
2024-07-26 | CVE-2024-41689 | Syrotech | Cleartext Storage of Sensitive Information vulnerability in Syrotech Sy-Gpon-1110-Wdont Firmware 3.1.02231102 This vulnerability exists in SyroTech SY-GPON-1110-WDONT Router due to unencrypted storing of WPA/ WPS credentials within the router's firmware/ database. | 4.6 |
2024-07-26 | CVE-2024-41690 | Syrotech | Cleartext Storage of Sensitive Information vulnerability in Syrotech Sy-Gpon-1110-Wdont Firmware 3.1.02231102 This vulnerability exists in SyroTech SY-GPON-1110-WDONT Router due to storing of default username and password credentials in plaintext within the router's firmware/ database. | 4.6 |
2024-07-26 | CVE-2024-41691 | Syrotech | Cleartext Storage of Sensitive Information vulnerability in Syrotech Sy-Gpon-1110-Wdont Firmware 3.1.02231102 This vulnerability exists in SyroTech SY-GPON-1110-WDONT Router due to storing of FTP credentials in plaintext within the SquashFS-root filesystem associated with the router's firmware. | 4.6 |
2024-07-24 | CVE-2024-37533 | IBM | Unspecified vulnerability in IBM Infosphere Information Server 11.7 IBM InfoSphere Information Server 11.7 could disclose sensitive user information to another user with physical access to the machine. | 4.6 |
2024-07-24 | CVE-2024-7068 | Insurance Management System Project | Cross-site Scripting vulnerability in Insurance Management System Project Insurance Management System 1.0 A vulnerability classified as problematic has been found in SourceCodester Insurance Management System 1.0. | 4.6 |
2024-07-27 | CVE-2024-1804 | Themeum | Missing Authorization vulnerability in Themeum Tutor LMS - Migration Tool The Tutor LMS – Migration Tool plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the tutor_import_from_xml function in all versions up to, and including, 2.2.0. | 4.3 |
2024-07-25 | CVE-2024-7057 | Gitlab | Unspecified vulnerability in Gitlab An information disclosure vulnerability in GitLab CE/EE affecting all versions starting from 16.7 prior to 17.0.5, starting from 17.1 prior to 17.1.3, and starting from 17.2 prior to 17.2.1 where job artifacts can be inappropriately exposed to users lacking the proper authorization level. | 4.3 |
2024-07-24 | CVE-2024-7065 | Denkgroot | Unspecified vulnerability in Denkgroot Spina A vulnerability was found in Spina CMS up to 2.18.0. | 4.3 |
2024-07-24 | CVE-2024-6874 | Haxx | Out-of-bounds Read vulnerability in Haxx Libcurl 8.8.0 libcurl's URL API function [curl_url_get()](https://curl.se/libcurl/c/curl_url_get.html) offers punycode conversions, to and from IDN. | 4.3 |
2024-07-24 | CVE-2024-6754 | Wpwebinfotech | Missing Authorization vulnerability in Wpwebinfotech Social Auto Poster The Social Auto Poster plugin for WordPress is vulnerable to unauthorized modification of data to a missing capability check on the ‘wpw_auto_poster_update_tweet_template’ function in all versions up to, and including, 5.3.14. | 4.3 |
2024-07-22 | CVE-2024-32152 | Ankitects | Unspecified vulnerability in Ankitects Anki 24.04 A blocklist bypass vulnerability exists in the LaTeX functionality of Ankitects Anki 24.04. | 4.3 |
5 Low Vulnerabilities
DATE | CVE | VENDOR | VULNERABILITY | CVSS |
---|---|---|---|---|
2024-07-24 | CVE-2024-3454 | CSA IOT | Unspecified vulnerability in Csa-Iot Matter An implementation issue in the Connectivity Standards Alliance Matter 1.2 protocol as used in the connectedhomeip SDK allows a third party to disclose information about devices part of the same fabric (footprinting), even though the protocol is designed to prevent access to such information. | 3.5 |
2024-07-23 | CVE-2024-41839 | Adobe | Unspecified vulnerability in Adobe Experience Manager Adobe Experience Manager versions 6.5.20 and earlier are affected by an Improper Input Validation vulnerability that could lead to a security feature bypass. | 3.5 |
2024-07-25 | CVE-2024-40873 | Absolute | Cross-site Scripting vulnerability in Absolute Secure Access There is a cross-site scripting vulnerability in the Secure Access administrative console of Absolute Secure Access prior to version 13.07. Attackers with system administrator permissions can interfere with another system administrator’s use of the publishing UI when the administrators are editing the same management object. | 3.4 |
2024-07-26 | CVE-2024-41686 | Syrotech | Unspecified vulnerability in Syrotech Sy-Gpon-1110-Wdont Firmware 3.1.02231102 This vulnerability exists in SyroTech SY-GPON-1110-WDONT Router due to improper implementation of password policies. | 3.3 |
2024-07-24 | CVE-2024-0231 | Gitlab | Injection vulnerability in Gitlab A resource misdirection vulnerability in GitLab CE/EE versions 12.0 prior to 17.0.5, 17.1 prior to 17.1.3, and 17.2 prior to 17.2.1 allows an attacker to craft a repository import in such a way as to misdirect commits. | 2.7 |