Weekly Vulnerabilities Reports > July 22 to 28, 2024

Overview

284 new vulnerabilities reported during this period, including 46 critical vulnerabilities and 99 high severity vulnerabilities. This weekly summary report vulnerabilities in 192 products from 148 vendors including Totolink, Oretnom23, Tendacn, NI, and Apache. Vulnerabilities are notably categorized as "Cross-site Scripting", "Out-of-bounds Write", "OS Command Injection", "Missing Authorization", and "SQL Injection".

  • 248 reported vulnerabilities are remotely exploitables.
  • 79 reported vulnerabilities are related to weaknesses in OWASP Top Ten.
  • 138 reported vulnerabilities are exploitable by an anonymous user.
  • Totolink has the most reported vulnerabilities, with 11 reported vulnerabilities.
  • Opengeos has the most reported critical vulnerabilities, with 9 reported vulnerabilities.

TOTAL
VULNERABILITIES
CRITICAL RISK
VULNERABILITIES
HIGH RISK
VULNERABILITIES
MEDIUM RISK
VULNERABILITIES
LOW RISK
VULNERABILITIES
REMOTELY
EXPLOITABLE
LOCALLY
EXPLOITABLE
EXPLOIT
AVAILABLE
EXPLOITABLE
ANONYMOUSLY
AFFECTING
WEB APPLICATION

Vulnerability Details

The following table list reported vulnerabilities for the period covered by this report:

Expand/Hide

46 Critical Vulnerabilities

DATE CVE VENDOR VULNERABILITY CVSS
2024-07-28 CVE-2024-7164 Oretnom23 SQL Injection vulnerability in Oretnom23 School Fees Payment System 1.0

A vulnerability has been found in SourceCodester School Fees Payment System 1.0 and classified as critical.

9.8
2024-07-27 CVE-2024-7151 Tenda Out-of-bounds Write vulnerability in Tenda O3 Firmware 1.0.0.10(2478)

A vulnerability was found in Tenda O3 1.0.0.10(2478).

9.8
2024-07-26 CVE-2024-41114 Opengeos Unspecified vulnerability in Opengeos Streamlit-Geospatial

streamlit-geospatial is a streamlit multipage app for geospatial applications.

9.8
2024-07-26 CVE-2024-41115 Opengeos Unspecified vulnerability in Opengeos Streamlit-Geospatial

streamlit-geospatial is a streamlit multipage app for geospatial applications.

9.8
2024-07-26 CVE-2024-41116 Opengeos Unspecified vulnerability in Opengeos Streamlit-Geospatial

streamlit-geospatial is a streamlit multipage app for geospatial applications.

9.8
2024-07-26 CVE-2024-41117 Opengeos Unspecified vulnerability in Opengeos Streamlit-Geospatial

streamlit-geospatial is a streamlit multipage app for geospatial applications.

9.8
2024-07-26 CVE-2024-41118 Opengeos Server-Side Request Forgery (SSRF) vulnerability in Opengeos Streamlit-Geospatial

streamlit-geospatial is a streamlit multipage app for geospatial applications.

9.8
2024-07-26 CVE-2024-41119 Opengeos Unspecified vulnerability in Opengeos Streamlit-Geospatial

streamlit-geospatial is a streamlit multipage app for geospatial applications.

9.8
2024-07-26 CVE-2024-41120 Opengeos Server-Side Request Forgery (SSRF) vulnerability in Opengeos Streamlit-Geospatial

streamlit-geospatial is a streamlit multipage app for geospatial applications.

9.8
2024-07-26 CVE-2024-41112 Opengeos Unspecified vulnerability in Opengeos Streamlit-Geospatial

streamlit-geospatial is a streamlit multipage app for geospatial applications.

9.8
2024-07-26 CVE-2024-41113 Opengeos Unspecified vulnerability in Opengeos Streamlit-Geospatial

streamlit-geospatial is a streamlit multipage app for geospatial applications.

9.8
2024-07-26 CVE-2024-40689 IBM Unspecified vulnerability in IBM products

IBM InfoSphere Information Server 11.7 is vulnerable to SQL injection.

9.8
2024-07-26 CVE-2024-7120 Raisecom Unspecified vulnerability in Raisecom products

A vulnerability, which was classified as critical, was found in Raisecom MSG1200, MSG2100E, MSG2200 and MSG2300 3.90.

9.8
2024-07-25 CVE-2024-24621 Softaculous Incorrect Comparison vulnerability in Softaculous Webuzo

Softaculous Webuzo contains an authentication bypass vulnerability through the password reset functionality.

9.8
2024-07-25 CVE-2024-41468 Tendacn OS Command Injection vulnerability in Tendacn Fh1201 Firmware 1.2.0.14

Tenda FH1201 v1.2.0.14 was discovered to contain a command injection vulnerability via the cmdinput parameter at /goform/exeCommand

9.8
2024-07-25 CVE-2024-41473 Tendacn OS Command Injection vulnerability in Tendacn Fh1201 Firmware 1.2.0.14

Tenda FH1201 v1.2.0.14 was discovered to contain a command injection vulnerability via the mac parameter at ip/goform/WriteFacMac

9.8
2024-07-25 CVE-2024-38287 Rhubcom Weak Password Recovery Mechanism for Forgotten Password vulnerability in Rhubcom Turbomeeting

The password-reset mechanism in the Forgot Password functionality in R-HUB TurboMeeting through 8.x allows unauthenticated remote attackers to force the application into resetting the administrator's password to a random insecure 8-digit value.

9.8
2024-07-25 CVE-2024-38289 Rhubcom SQL Injection vulnerability in Rhubcom Turbomeeting

A boolean-based SQL injection issue in the Virtual Meeting Password (VMP) endpoint in R-HUB TurboMeeting through 8.x allows unauthenticated remote attackers to extract hashed passwords from the database, and authenticate to the application, via crafted SQL input.

9.8
2024-07-25 CVE-2024-7007 Positron Missing Authentication for Critical Function vulnerability in Positron Tra7005 Firmware 1.20

Positron Broadcast Signal Processor TRA7005 v1.20 is vulnerable to an authentication bypass exploit that could allow an attacker to have unauthorized access to protected areas of the application.

9.8
2024-07-24 CVE-2024-41459 Tendacn Out-of-bounds Write vulnerability in Tendacn Fh1201 Firmware 1.2.0.14

Tenda FH1201 v1.2.0.14 was discovered to contain a stack-based buffer overflow vulnerability via the PPPOEPassword parameter at ip/goform/QuickIndex.

9.8
2024-07-24 CVE-2024-41460 Tendacn Out-of-bounds Write vulnerability in Tendacn Fh1201 Firmware 1.2.0.14

Tenda FH1201 v1.2.0.14 was discovered to contain a stack-based buffer overflow vulnerability via the entrys parameter at ip/goform/RouteStatic.

9.8
2024-07-24 CVE-2024-41461 Tendacn Out-of-bounds Write vulnerability in Tendacn Fh1201 Firmware 1.2.0.14

Tenda FH1201 v1.2.0.14 was discovered to contain a stack-based buffer overflow vulnerability via the list1 parameter at ip/goform/DhcpListClient.

9.8
2024-07-24 CVE-2024-7081 Tailoring Management System Project Unspecified vulnerability in Tailoring Management System Project Tailoring Management System 1.0

A vulnerability was found in itsourcecode Tailoring Management System 1.0.

9.8
2024-07-24 CVE-2024-41551 Campcodes SQL Injection vulnerability in Campcodes Supplier Management System 1.0

CampCodes Supplier Management System v1.0 is vulnerable to SQL injection via Supply_Management_System/admin/view_order_items.php?id= .

9.8
2024-07-24 CVE-2023-45249 Acronis Improper Authentication vulnerability in Acronis Cyber Infrastructure

Remote command execution due to use of default passwords.

9.8
2024-07-24 CVE-2024-6096 Progress Unsafe Reflection vulnerability in Progress Telerik Reporting

In Progress® Telerik® Reporting versions prior to 18.1.24.709, a code execution attack is possible through object injection via an insecure type resolution vulnerability.

9.8
2024-07-24 CVE-2024-6327 Progress Deserialization of Untrusted Data vulnerability in Progress Telerik Report Server

In Progress® Telerik® Report Server versions prior to 2024 Q2 (10.1.24.709), a remote code execution attack is possible through an insecure deserialization vulnerability.

9.8
2024-07-24 CVE-2024-7066 F Logic Unspecified vulnerability in F-Logic Datacube3 Firmware

A vulnerability was found in F-logic DataCube3 1.0.

9.8
2024-07-23 CVE-2024-41319 Totolink Command Injection vulnerability in Totolink A6000R Firmware 1.0.1B20201211.2000

TOTOLINK A6000R V1.0.1-B20201211.2000 was discovered to contain a command injection vulnerability via the cmd parameter in the webcmd function.

9.8
2024-07-22 CVE-2024-6793 NI Deserialization of Untrusted Data vulnerability in NI Veristand

A deserialization of untrusted data vulnerability exists in NI VeriStand DataLogging Server that may result in remote code execution.

9.8
2024-07-22 CVE-2024-6794 NI Deserialization of Untrusted Data vulnerability in NI Veristand

A deserialization of untrusted data vulnerability exists in NI VeriStand Waveform Streaming Server that may result in remote code execution.

9.8
2024-07-22 CVE-2024-6805 NI Missing Authorization vulnerability in NI Veristand

The NI VeriStand Gateway is missing authorization checks when an actor attempts to access File Transfer resources.

9.8
2024-07-22 CVE-2024-6806 NI Missing Authorization vulnerability in NI Veristand

The NI VeriStand Gateway is missing authorization checks when an actor attempts to access Project resources.

9.8
2024-07-22 CVE-2024-6912 Perkinelmer Use of Hard-coded Credentials vulnerability in Perkinelmer Processplus

Use of hard-coded MSSQL credentials in PerkinElmer ProcessPlus on Windows allows an attacker to login remove on all prone installations.This issue affects ProcessPlus: through 1.11.6507.0.

9.8
2024-07-22 CVE-2024-39685 Fish Audio OS Command Injection vulnerability in Fish.Audio Bert-Vits2

Bert-VITS2 is the VITS2 Backbone with multilingual bert.

9.8
2024-07-22 CVE-2024-39686 Fishaudio OS Command Injection vulnerability in Fishaudio Bert-Vits2

Bert-VITS2 is the VITS2 Backbone with multilingual bert.

9.8
2024-07-22 CVE-2024-41827 Jetbrains Insufficient Session Expiration vulnerability in Jetbrains Teamcity

In JetBrains TeamCity before 2024.07 access tokens could continue working after deletion or expiration

9.8
2024-07-22 CVE-2024-38759 WP Media Unspecified vulnerability in Wp-Media Search & Replace

Deserialization of Untrusted Data vulnerability in WP MEDIA SAS Search & Replace search-and-replace.This issue affects Search & Replace: from n/a through 3.2.2.

9.8
2024-07-22 CVE-2024-38773 Formlift SQL Injection vulnerability in Formlift for Infusionsoft web Forms

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Adrian Tobey FormLift for Infusionsoft Web Forms allows Blind SQL Injection.This issue affects FormLift for Infusionsoft Web Forms: from n/a through 7.5.17.

9.8
2024-07-22 CVE-2024-41703 Librechat Unspecified vulnerability in Librechat

LibreChat through 0.7.4-rc1 has incorrect access control for message updates.

9.8
2024-07-22 CVE-2024-41704 Librechat Path Traversal vulnerability in Librechat

LibreChat through 0.7.4-rc1 does not validate the normalized pathnames of images.

9.8
2024-07-22 CVE-2024-6970 Tailoring Management System Project Unspecified vulnerability in Tailoring Management System Project Tailoring Management System 1.0

A vulnerability classified as critical has been found in itsourcecode Tailoring Management System 1.0.

9.8
2024-07-22 CVE-2024-6966 Adonesevangelista Unspecified vulnerability in Adonesevangelista Online Blood Bank Management System 1.0

A vulnerability was found in itsourcecode Online Blood Bank Management System 1.0 and classified as critical.

9.8
2024-07-24 CVE-2024-41662 Vnote Project Cross-site Scripting vulnerability in Vnote Project Vnote

VNote is a note-taking platform.

9.6
2024-07-24 CVE-2024-40422 Stitionai Path Traversal vulnerability in Stitionai Devika 1.0

The snapshot_path parameter in the /api/get-browser-snapshot endpoint in stitionai devika v1 is susceptible to a path traversal attack.

9.1
2024-07-24 CVE-2024-41914 Arubanetworks Cross-site Scripting vulnerability in Arubanetworks Edgeconnect Sd-Wan Orchestrator

A vulnerability in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authenticated remote attacker to conduct a stored cross-site scripting (XSS) attack against an administrative user of the interface.

9.0

99 High Vulnerabilities

DATE CVE VENDOR VULNERABILITY CVSS
2024-07-28 CVE-2024-7171 Totolink OS Command Injection vulnerability in Totolink A3600R Firmware 4.1.2Cu.5182B20201102

A vulnerability classified as critical has been found in TOTOLINK A3600R 4.1.2cu.5182_B20201102.

8.8
2024-07-28 CVE-2024-7172 Totolink Unspecified vulnerability in Totolink A3600R Firmware 4.1.2Cu.5182B20201102

A vulnerability classified as critical was found in TOTOLINK A3600R 4.1.2cu.5182_B20201102.

8.8
2024-07-28 CVE-2024-7170 Totolink Use of Hard-coded Credentials vulnerability in Totolink A3000Ru Firmware 5.9C.5185B20201128

A vulnerability was found in TOTOLINK A3000RU 5.9c.5185.

8.8
2024-07-28 CVE-2024-7169 Oretnom23 Unspecified vulnerability in Oretnom23 School Fees Payment System 1.0

A vulnerability classified as problematic has been found in SourceCodester School Fees Payment System 1.0.

8.8
2024-07-28 CVE-2024-7167 Oretnom23 Unspecified vulnerability in Oretnom23 School Fees Payment System 1.0

A vulnerability was found in SourceCodester School Fees Payment System 1.0.

8.8
2024-07-28 CVE-2024-7168 Oretnom23 Unspecified vulnerability in Oretnom23 School Fees Payment System 1.0

A vulnerability was found in SourceCodester School Fees Payment System 1.0.

8.8
2024-07-28 CVE-2024-7165 Oretnom23 Unspecified vulnerability in Oretnom23 School Fees Payment System 1.0

A vulnerability was found in SourceCodester School Fees Payment System 1.0 and classified as critical.

8.8
2024-07-28 CVE-2024-7166 Oretnom23 Unspecified vulnerability in Oretnom23 School Fees Payment System 1.0

A vulnerability was found in SourceCodester School Fees Payment System 1.0.

8.8
2024-07-28 CVE-2024-7159 Totolink Unspecified vulnerability in Totolink A3600R Firmware 4.1.2Cu.5182B20201102

A vulnerability was found in TOTOLINK A3600R 4.1.2cu.5182_B20201102.

8.8
2024-07-28 CVE-2024-7160 Totolink Unspecified vulnerability in Totolink A3700R Firmware 9.1.2U.5822B20200513

A vulnerability classified as critical has been found in TOTOLINK A3700R 9.1.2u.5822_B20200513.

8.8
2024-07-28 CVE-2024-7158 Totolink Unspecified vulnerability in Totolink A3100R Firmware 4.1.2Cu.5050B20200504

A vulnerability was found in TOTOLINK A3100R 4.1.2cu.5050_B20200504.

8.8
2024-07-28 CVE-2024-7157 Totolink Unspecified vulnerability in Totolink A3100R Firmware 4.1.2Cu.5050B20200504

A vulnerability was found in TOTOLINK A3100R 4.1.2cu.5050_B20200504.

8.8
2024-07-27 CVE-2024-7152 Tenda Out-of-bounds Write vulnerability in Tenda O3 Firmware 1.0.0.10(2478)

A vulnerability was found in Tenda O3 1.0.0.10(2478).

8.8
2024-07-26 CVE-2024-38871 Zohocorp SQL Injection vulnerability in Zohocorp Manageengine Exchange Reporter Plus

Zohocorp ManageEngine Exchange Reporter Plus versions 5717 and below are vulnerable to the authenticated SQL injection in the reports module.

8.8
2024-07-26 CVE-2024-38872 Zohocorp SQL Injection vulnerability in Zohocorp Manageengine Exchange Reporter Plus

Zohocorp ManageEngine Exchange Reporter Plus versions 5717 and below are vulnerable to the authenticated SQL injection in the monitoring module.

8.8
2024-07-26 CVE-2024-39304 Churchcrm SQL Injection vulnerability in Churchcrm

ChurchCRM is an open-source church management system.

8.8
2024-07-26 CVE-2024-7119 Mdmafujulhasan Unspecified vulnerability in Mdmafujulhasan Online-Payroll-Management-System 20230911

A vulnerability, which was classified as critical, has been found in MD-MAFUJUL-HASAN Online-Payroll-Management-System up to 20230911.

8.8
2024-07-26 CVE-2024-7117 Mdmafujulhasan Unspecified vulnerability in Mdmafujulhasan Online-Payroll-Management-System 20230911

A vulnerability classified as critical has been found in MD-MAFUJUL-HASAN Online-Payroll-Management-System up to 20230911.

8.8
2024-07-26 CVE-2024-7118 Mdmafujulhasan Unspecified vulnerability in Mdmafujulhasan Online-Payroll-Management-System 20230911

A vulnerability classified as critical was found in MD-MAFUJUL-HASAN Online-Payroll-Management-System up to 20230911.

8.8
2024-07-26 CVE-2024-7116 Mdmafujulhasan Unspecified vulnerability in Mdmafujulhasan Online-Payroll-Management-System 20230911

A vulnerability was found in MD-MAFUJUL-HASAN Online-Payroll-Management-System up to 20230911.

8.8
2024-07-26 CVE-2024-7114 Tianchoy Unspecified vulnerability in Tianchoy Blog 1.8.8

A vulnerability was found in Tianchoy Blog up to 1.8.8.

8.8
2024-07-26 CVE-2024-7115 Mdmafujulhasan Unspecified vulnerability in Mdmafujulhasan Online-Payroll-Management-System 20230911

A vulnerability was found in MD-MAFUJUL-HASAN Online-Payroll-Management-System up to 20230911.

8.8
2024-07-25 CVE-2024-24622 Softaculous OS Command Injection vulnerability in Softaculous Webuzo

Softaculous Webuzo contains a command injection in the password reset functionality.

8.8
2024-07-25 CVE-2024-24623 Softaculous OS Command Injection vulnerability in Softaculous Webuzo

Softaculous Webuzo contains a command injection vulnerability in the FTP management functionality.

8.8
2024-07-25 CVE-2024-7105 Forip SQL Injection vulnerability in Forip Administracao Pabx

A vulnerability classified as critical has been found in ForIP Tecnologia Administração PABX 1.x.

8.8
2024-07-25 CVE-2024-7106 Denkgroot Unspecified vulnerability in Denkgroot Spina

A vulnerability classified as problematic was found in Spina CMS 2.18.0.

8.8
2024-07-25 CVE-2024-37084 Vmware Unspecified vulnerability in VMWare Spring Cloud Data Flow 2.11.0/2.11.1/2.11.2

In Spring Cloud Data Flow versions prior to 2.11.4,  a malicious user who has access to the Skipper server api can use a crafted upload request to write an arbitrary file to any location on the file system which could lead to compromising the server

8.8
2024-07-24 CVE-2024-41136 Arubanetworks OS Command Injection vulnerability in Arubanetworks Edgeconnect Sd-Wan Orchestrator

An authenticated command injection vulnerability exists in the HPE Aruba Networking EdgeConnect SD-WAN gateways Command Line Interface.

8.8
2024-07-24 CVE-2024-31970 Adtran Unspecified vulnerability in Adtran SDG Smartos

AdTran SRG 834-5 HDC17600021F1 devices (with SmartOS 11.1.1.1 and fixed in Version 12.1.3.1) have SSH enabled by default, accessible both over the LAN and the Internet.

8.8
2024-07-24 CVE-2024-36541 Kube Logging Incorrect Default Permissions vulnerability in Kube-Logging Logging-Operator 4.6.0

Insecure permissions in logging-operator v4.6.0 allows attackers to access sensitive data and escalate privileges by obtaining the service account's token.

8.8
2024-07-24 CVE-2024-22443 Arubanetworks Unspecified vulnerability in Arubanetworks Edgeconnect Sd-Wan Orchestrator

A vulnerability in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authenticated remote attacker to conduct a server-side prototype pollution attack.

8.8
2024-07-24 CVE-2024-31977 Adtran OS Command Injection vulnerability in Adtran 834-5 Firmware and SDG Smartos

Adtran 834-5 11.1.0.101-202106231430, and fixed as of SmartOS Version 12.6.3.1, devices allow OS Command Injection via shell metacharacters to the Ping or Traceroute utility.

8.8
2024-07-24 CVE-2024-7067 Shuttur Unspecified vulnerability in Shuttur Ecommerce-Laravel-Bootstrap

A vulnerability was found in kirilkirkov Ecommerce-Laravel-Bootstrap up to 1f1097a3448ce8ec53e034ea0f70b8e2a0e64a87.

8.8
2024-07-24 CVE-2023-48362 Apache Unspecified vulnerability in Apache Drill

XXE in the XML Format Plugin in Apache Drill version 1.19.0 and greater allows a user to read any file on a remote file system or execute commands via a malicious XML file. Users are recommended to upgrade to version 1.21.2, which fixes this issue.

8.8
2024-07-23 CVE-2024-38164 Microsoft Unspecified vulnerability in Microsoft Groupme

An improper access control vulnerability in GroupMe allows an a unauthenticated attacker to elevate privileges over a network by convincing a user to click on a malicious link.

8.8
2024-07-22 CVE-2024-6913 Perkinelmer Unspecified vulnerability in Perkinelmer Processplus

Execution with unnecessary privileges in PerkinElmer ProcessPlus allows an attacker to spawn a remote shell on the windows system.This issue affects ProcessPlus: through 1.11.6507.0.

8.8
2024-07-22 CVE-2024-26020 Ankiweb Unspecified vulnerability in Ankiweb Anki 24.04

An arbitrary script execution vulnerability exists in the MPV functionality of Ankitects Anki 24.04.

8.8
2024-07-22 CVE-2024-38701 Kodezen Unspecified vulnerability in Kodezen Academy LMS

Authorization Bypass Through User-Controlled Key vulnerability in Academy LMS.This issue affects Academy LMS: from n/a through 2.0.4.

8.8
2024-07-22 CVE-2024-38708 Ukrsolution Unspecified vulnerability in Ukrsolution Barcode Scanner and Inventory Manager

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in UkrSolution Barcode Scanner with Inventory & Order Manager allows SQL Injection.This issue affects Barcode Scanner with Inventory & Order Manager: from n/a through 1.6.1.

8.8
2024-07-22 CVE-2024-38755 Designinvento Unspecified vulnerability in Designinvento Directorypress

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Designinvento DirectoryPress allows SQL Injection.This issue affects DirectoryPress: from n/a through 3.6.10.

8.8
2024-07-22 CVE-2024-23321 Apache Unspecified vulnerability in Apache Rocketmq

For RocketMQ versions 5.2.0 and below, under certain conditions, there is a risk of exposure of sensitive Information to an unauthorized actor even if RocketMQ is enabled with authentication and authorization functions. An attacker, possessing regular user privileges or listed in the IP whitelist, could potentially acquire the administrator's account and password through specific interfaces.

8.8
2024-07-22 CVE-2024-5973 Stylemixthemes Unspecified vulnerability in Stylemixthemes Masterstudy LMS

The MasterStudy LMS WordPress Plugin WordPress plugin before 3.3.24 does not prevent students from creating instructor accounts, which could be used to get access to functionalities they shouldn't have.

8.8
2024-07-22 CVE-2024-6244 Projectzealous Cross-Site Request Forgery (CSRF) vulnerability in Projectzealous PZ Frontend Manager

The PZ Frontend Manager WordPress plugin before 1.0.6 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions via CSRF attacks

8.8
2024-07-22 CVE-2024-6964 Tenda Out-of-bounds Write vulnerability in Tenda O3 Firmware1.0.0.10(2478)

A vulnerability, which was classified as critical, was found in Tenda O3 1.0.0.10.

8.8
2024-07-22 CVE-2024-6965 Tenda Out-of-bounds Write vulnerability in Tenda O3 Firmware1.0.0.10(2478)

A vulnerability has been found in Tenda O3 1.0.0.10 and classified as critical.

8.8
2024-07-22 CVE-2024-6962 Tenda Out-of-bounds Write vulnerability in Tenda O3 Firmware1.0.0.10(2478)

A vulnerability classified as critical was found in Tenda O3 1.0.0.10.

8.8
2024-07-22 CVE-2024-6963 Tenda Out-of-bounds Write vulnerability in Tenda O3 Firmware1.0.0.10(2478)

A vulnerability, which was classified as critical, has been found in Tenda O3 1.0.0.10.

8.8
2024-07-26 CVE-2024-35296 Apache Unspecified vulnerability in Apache Traffic Server

Invalid Accept-Encoding header can cause Apache Traffic Server to fail cache lookup and force forwarding requests. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.10, from 9.0.0 through 9.2.4. Users are recommended to upgrade to version 8.1.11 or 9.2.5, which fixes the issue.

8.2
2024-07-25 CVE-2024-1724 Canonical Incorrect Permission Assignment for Critical Resource vulnerability in Canonical Snapd

In snapd versions prior to 2.62, when using AppArmor for enforcement of sandbox permissions, snapd failed to restrict writes to the $HOME/bin path.

8.2
2024-07-22 CVE-2024-32484 Ankitects Cross-site Scripting vulnerability in Ankitects Anki 24.04

An reflected XSS vulnerability exists in the handling of invalid paths in the Flask server in Ankitects Anki 24.04.

8.2
2024-07-23 CVE-2024-38176 Microsoft Unspecified vulnerability in Microsoft Groupme

An improper restriction of excessive authentication attempts in GroupMe allows a unauthenticated attacker to elevate privileges over a network.

8.1
2024-07-28 CVE-2024-42052 Splashtop Unspecified vulnerability in Splashtop Streamer 3.3.8.0/3.5.0.0/3.5.6.0

The MSI installer for Splashtop Streamer for Windows before 3.5.8.0 uses a temporary folder with weak permissions during installation.

7.8
2024-07-26 CVE-2024-7062 Mikekazakov Incorrect Authorization vulnerability in Mikekazakov Nimble Commander

Nimble Commander suffers from a privilege escalation vulnerability due to the server (info.filesmanager.Files.PrivilegedIOHelperV2) performing improper/insufficient validation of a client’s authorization before executing an operation.

7.8
2024-07-23 CVE-2024-4079 NI Out-of-bounds Read vulnerability in NI Labview

An out of bounds read due to a missing bounds check in LabVIEW may disclose information or result in arbitrary code execution.

7.8
2024-07-23 CVE-2024-4080 NI Out-of-bounds Write vulnerability in NI Labview

A memory corruption issue due to an improper length check in LabVIEW tdcore.dll may disclose information or result in arbitrary code execution.

7.8
2024-07-23 CVE-2024-4081 NI Out-of-bounds Write vulnerability in NI Labview

A memory corruption issue due to an improper length check in NI LabVIEW may disclose information or result in arbitrary code execution.

7.8
2024-07-22 CVE-2024-6791 NI Path Traversal vulnerability in NI Veristand

A directory path traversal vulnerability exists when loading a vsmodel file in NI VeriStand that may result in remote code execution.

7.8
2024-07-22 CVE-2024-6121 NI Unspecified vulnerability in NI Flexlogger and Systemlink

An out-of-date version of Redis shipped with NI SystemLink Server is susceptible to multiple vulnerabilities, including CVE-2022-24834.

7.8
2024-07-22 CVE-2024-37391 Proton Unspecified vulnerability in Proton Protonvpn

ProtonVPN before 3.2.10 on Windows mishandles the drive installer path, which should use this: '"' + ExpandConstant('{autopf}\Proton\Drive') + '"' in Setup/setup.iss.

7.8
2024-07-28 CVE-2024-7156 Totolink Unspecified vulnerability in Totolink A3700R Firmware 9.1.2U.5822B20200513

A vulnerability was found in TOTOLINK A3700R 9.1.2u.5822_B20200513 and classified as problematic.

7.5
2024-07-28 CVE-2024-7154 Totolink Missing Authentication for Critical Function vulnerability in Totolink A3700R Firmware 9.1.2U.5822B20200513

A vulnerability, which was classified as problematic, was found in TOTOLINK A3700R 9.1.2u.5822_B20200513.

7.5
2024-07-26 CVE-2024-41812 Txtdot Server-Side Request Forgery (SSRF) vulnerability in Txtdot

txtdot is an HTTP proxy that parses only text, links, and pictures from pages, removing ads and heavy scripts.

7.5
2024-07-26 CVE-2024-41813 Txtdot Server-Side Request Forgery (SSRF) vulnerability in Txtdot

txtdot is an HTTP proxy that parses only text, links, and pictures from pages, removing ads and heavy scripts.

7.5
2024-07-26 CVE-2024-41685 Syrotech Incorrect Permission Assignment for Critical Resource vulnerability in Syrotech Sy-Gpon-1110-Wdont Firmware 3.1.02231102

This vulnerability exists in SyroTech SY-GPON-1110-WDONT Router due to missing HTTPOnly flag for the session cookies associated with the router's web management interface.

7.5
2024-07-26 CVE-2024-41687 Syrotech Cleartext Transmission of Sensitive Information vulnerability in Syrotech Sy-Gpon-1110-Wdont Firmware 3.1.02231102

This vulnerability exists in SyroTech SY-GPON-1110-WDONT Router due to transmission of password in plain text.

7.5
2024-07-26 CVE-2023-38522 Apache Unspecified vulnerability in Apache Traffic Server

Apache Traffic Server accepts characters that are not allowed for HTTP field names and forwards malformed requests to origin servers.

7.5
2024-07-26 CVE-2024-35161 Apache Unspecified vulnerability in Apache Traffic Server

Apache Traffic Server forwards malformed HTTP chunked trailer section to origin servers.

7.5
2024-07-25 CVE-2022-32759 IBM Unspecified vulnerability in IBM products

IBM Security Directory Integrator 7.2.0 and IBM Security Verify Directory Integrator 10.0.0 uses insufficient session expiration which could allow an unauthorized user to obtain sensitive information.

7.5
2024-07-25 CVE-2024-41800 Craftcms Improper Authentication vulnerability in Craftcms Craft CMS

Craft is a content management system (CMS).

7.5
2024-07-24 CVE-2024-41462 Tendacn Out-of-bounds Write vulnerability in Tendacn Fh1201 Firmware 1.2.0.14

Tenda FH1201 v1.2.0.14 was discovered to contain a stack-based buffer overflow vulnerability via the page parameter at ip/goform/DhcpListClient.

7.5
2024-07-24 CVE-2024-41463 Tendacn Out-of-bounds Write vulnerability in Tendacn Fh1201 Firmware 1.2.0.14

Tenda FH1201 v1.2.0.14 was discovered to contain a stack-based buffer overflow vulnerability via the entrys parameter at ip/goform/addressNat.

7.5
2024-07-24 CVE-2024-41464 Tendacn Out-of-bounds Write vulnerability in Tendacn Fh1201 Firmware 1.2.0.14

Tenda FH1201 v1.2.0.14 was discovered to contain a stack-based buffer overflow vulnerability via the mitInterface parameter in ip/goform/RouteStatic

7.5
2024-07-24 CVE-2024-41465 Tendacn Out-of-bounds Write vulnerability in Tendacn Fh1201 Firmware 1.2.0.14

Tenda FH1201 v1.2.0.14 was discovered to contain a stack-based buffer overflow vulnerability via the funcpara1 parameter at ip/goform/setcfm.

7.5
2024-07-24 CVE-2024-41466 Tendacn Out-of-bounds Write vulnerability in Tendacn Fh1201 Firmware 1.2.0.14

Tenda FH1201 v1.2.0.14 was discovered to contain a stack-based buffer overflow vulnerability via the page parameter at ip/goform/NatStaticSetting.

7.5
2024-07-24 CVE-2024-7080 Insurance Management System Project Path Traversal vulnerability in Insurance Management System Project Insurance Management System 1.0

A vulnerability was found in SourceCodester Insurance Management System 1.0.

7.5
2024-07-24 CVE-2024-41672 Duckdb Unspecified vulnerability in Duckdb

DuckDB is a SQL database management system.

7.5
2024-07-24 CVE-2024-7069 Oretnom23 Unspecified vulnerability in Oretnom23 Employee and Visitor Gate Pass Logging System 1.0

A vulnerability, which was classified as critical, has been found in SourceCodester Employee and Visitor Gate Pass Logging System 1.0.

7.5
2024-07-24 CVE-2024-39676 Apache Unspecified vulnerability in Apache Pinot

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Pinot. This issue affects Apache Pinot: from 0.1 before 1.0.0. Users are recommended to upgrade to version 1.0.0 and configure RBAC, which fixes the issue. Details:  When using a request to path “/appconfigs” to the controller, it can lead to the disclosure of sensitive information such as system information (e.g.

7.5
2024-07-24 CVE-2024-6197 Haxx Unspecified vulnerability in Haxx Libcurl

libcurl's ASN1 parser has this utf8asn1str() function used for parsing an ASN.1 UTF-8 string.

7.5
2024-07-24 CVE-2024-6750 Wpwebinfotech Missing Authorization vulnerability in Wpwebinfotech Social Auto Poster

The Social Auto Poster plugin for WordPress is vulnerable to unauthorized access, modification, and loss of data due to a missing capability check on multiple functions in all versions up to, and including, 5.3.14.

7.5
2024-07-23 CVE-2024-40060 Wcharczuk Infinite Loop vulnerability in Wcharczuk Go-Chart

go-chart v2.1.1 was discovered to contain an infinite loop via the drawCanvas() function.

7.5
2024-07-22 CVE-2024-6911 Perkinelmer Files or Directories Accessible to External Parties vulnerability in Perkinelmer Processplus

Files on the Windows system are accessible without authentication to external parties due to a local file inclusion in PerkinElmer ProcessPlus.This issue affects ProcessPlus: through 1.11.6507.0.

7.5
2024-07-22 CVE-2024-40051 IP Guard Path Traversal vulnerability in Ip-Guard 4.81.0307.0

IP Guard v4.81.0307.0 was discovered to contain an arbitrary file read vulnerability via the file name parameter.

7.5
2024-07-22 CVE-2024-41131 Sixlabors Out-of-bounds Write vulnerability in Sixlabors Imagesharp

ImageSharp is a 2D graphics API.

7.5
2024-07-22 CVE-2024-41132 Sixlabors Allocation of Resources Without Limits or Throttling vulnerability in Sixlabors Imagesharp

ImageSharp is a 2D graphics API.

7.5
2024-07-22 CVE-2024-41829 Jetbrains Improper Authentication vulnerability in Jetbrains Teamcity

In JetBrains TeamCity before 2024.07 an OAuth code for JetBrains Space could be stolen via Space Application connection

7.5
2024-07-22 CVE-2024-6969 Oretnom23 Unspecified vulnerability in Oretnom23 Clinic'S Patient Management System 1.0

A vulnerability was found in SourceCodester Clinics Patient Management System 1.0.

7.5
2024-07-22 CVE-2024-6967 Oretnom23 Unspecified vulnerability in Oretnom23 Employee and Visitor Gate Pass Logging System 1.0

A vulnerability was found in SourceCodester Employee and Visitor Gate Pass Logging System 1.0.

7.5
2024-07-22 CVE-2024-6968 Oretnom23 Unspecified vulnerability in Oretnom23 Clinic'S Patient Management System 1.0

A vulnerability was found in SourceCodester Clinics Patient Management System 1.0.

7.5
2024-07-25 CVE-2024-29069 Canonical Link Following vulnerability in Canonical Snapd

In snapd versions prior to 2.62, snapd failed to properly check the destination of symbolic links when extracting a snap.

7.3
2024-07-25 CVE-2024-38288 Rhubcom Command Injection vulnerability in Rhubcom Turbomeeting

A command-injection issue in the Certificate Signing Request (CSR) functionality in R-HUB TurboMeeting through 8.x allows authenticated attackers with administrator privileges to execute arbitrary commands on the underlying server as root.

7.2
2024-07-25 CVE-2024-40318 Webkul Unrestricted Upload of File with Dangerous Type vulnerability in Webkul Qloapps 1.6.0

An arbitrary file upload vulnerability in Webkul Qloapps v1.6.0.0 allows attackers to execute arbitrary code via uploading a crafted file.

7.2
2024-07-24 CVE-2024-39345 Adtran OS Command Injection vulnerability in Adtran SDG Smartos

AdTran 834-5 HDC17600021F1 (SmartOS 11.1.1.1) devices enable the SSH service by default and have a hidden, undocumented, hard-coded support account whose password is based on the devices MAC address.

7.2
2024-07-22 CVE-2024-37942 Berqier Unspecified vulnerability in Berqier Berqwp

Server-Side Request Forgery (SSRF) vulnerability in Berqier Ltd BerqWP.This issue affects BerqWP: from n/a through 1.7.5.

7.2
2024-07-22 CVE-2024-38692 Spiffyplugins Unspecified vulnerability in Spiffyplugins Spiffy Calendar

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Spiffy Plugins Spiffy Calendar allows SQL Injection.This issue affects Spiffy Calendar: from n/a through 4.9.11.

7.2
2024-07-22 CVE-2024-38788 Uipress Unspecified vulnerability in Uipress Lite

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in B?i Admin 2020 UiPress lite allows SQL Injection.This issue affects UiPress lite: from n/a through 3.4.06.

7.2
2024-07-25 CVE-2024-39672 Huawei Unspecified vulnerability in Huawei Emui and Harmonyos

Memory request logic vulnerability in the memory module. Impact: Successful exploitation of this vulnerability will affect integrity and availability.

7.1
2024-07-25 CVE-2024-39673 Huawei Unspecified vulnerability in Huawei Emui and Harmonyos

Vulnerability of serialisation/deserialisation mismatch in the iAware module.

7.1
2024-07-26 CVE-2024-41815 Starship OS Command Injection vulnerability in Starship

Starship is a cross-shell prompt.

7.0

134 Medium Vulnerabilities

DATE CVE VENDOR VULNERABILITY CVSS
2024-07-26 CVE-2024-40897 Gstreamer Out-of-bounds Write vulnerability in Gstreamer ORC

Stack-based buffer overflow vulnerability exists in orcparse.c of ORC versions prior to 0.4.39.

6.7
2024-07-25 CVE-2024-29068 Canonical Unspecified vulnerability in Canonical Snapd

In snapd versions prior to 2.62, snapd failed to properly check the file type when extracting a snap.

6.6
2024-07-28 CVE-2024-7161 Seacms Unspecified vulnerability in Seacms 13.0

A vulnerability classified as problematic was found in SeaCMS 13.0.

6.5
2024-07-26 CVE-2023-49921 Elastic Information Exposure Through Log Files vulnerability in Elastic Elasticsearch

An issue was discovered by Elastic whereby Watcher search input logged the search query results on DEBUG log level.

6.5
2024-07-24 CVE-2024-7060 Gitlab Unspecified vulnerability in Gitlab

An information disclosure vulnerability in GitLab CE/EE in project/group exports affecting all versions from 15.4 prior to 17.0.5, 17.1 prior to 17.1.3, and 17.2 prior to 17.2.1 allows unauthorized users to view the resultant export.

6.5
2024-07-24 CVE-2024-3297 CSA IOT Unspecified vulnerability in Csa-Iot Matter

An issue in the Certificate Authenticated Session Establishment (CASE) protocol for establishing secure sessions between two devices, as implemented in the Matter protocol versions before Matter 1.1 allows an attacker to replay manipulated CASE Sigma1 messages to make the device unresponsive until the device is power-cycled.

6.5
2024-07-24 CVE-2024-40767 Openstack Unspecified vulnerability in Openstack Nova

In OpenStack Nova before 27.4.1, 28 before 28.2.1, and 29 before 29.1.1, by supplying a raw format image that is actually a crafted QCOW2 image with a backing file path or VMDK flat image with a descriptor file path, an authenticated user may convince systems to return a copy of the referenced file's contents from the server, resulting in unauthorized access to potentially sensitive data.

6.5
2024-07-24 CVE-2024-5861 Wpeasypay Missing Authorization vulnerability in Wpeasypay WP Easypay

The WP EasyPay – Square for WordPress plugin for WordPress is vulnerable to unauthorized modification of datadue to a missing capability check on the wpep_square_disconnect() function in all versions up to, and including, 4.2.3.

6.5
2024-07-24 CVE-2024-6751 Wpwebinfotech Cross-Site Request Forgery (CSRF) vulnerability in Wpwebinfotech Social Auto Poster

The Social Auto Poster plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.3.14.

6.5
2024-07-22 CVE-2024-39688 Fish Audio Path Traversal vulnerability in Fish.Audio Bert-Vits2

Bert-VITS2 is the VITS2 Backbone with multilingual bert.

6.5
2024-07-22 CVE-2024-29073 Ankiweb Inclusion of Functionality from Untrusted Control Sphere vulnerability in Ankiweb Anki 24.04

An vulnerability in the handling of Latex exists in Ankitects Anki 24.04.

6.5
2024-07-22 CVE-2024-41824 Jetbrains Information Exposure Through Log Files vulnerability in Jetbrains Teamcity

In JetBrains TeamCity before 2024.07 parameters of the "password" type could leak into the build log in some specific cases

6.5
2024-07-22 CVE-2024-41828 Jetbrains Unspecified vulnerability in Jetbrains Teamcity

In JetBrains TeamCity before 2024.07 comparison of authorization tokens took non-constant time

6.5
2024-07-22 CVE-2024-34457 Apache Unspecified vulnerability in Apache Streampark

On versions before 2.1.4, after a regular user successfully logs in, they can manually make a request using the authorization token to view everyone's user flink information, including executeSQL and config. Mitigation: all users should upgrade to 2.1.4

6.5
2024-07-22 CVE-2024-6542 Checkmk Unspecified vulnerability in Checkmk 2.0.0/2.1.0/2.2.0

Improper neutralization of livestatus command delimiters in mknotifyd in Checkmk <= 2.0.0p39, < 2.1.0p47, < 2.2.0p32 and < 2.3.0p11 allows arbitrary livestatus command execution.

6.5
2024-07-22 CVE-2024-38723 Json Content Importer Unspecified vulnerability in Json-Content-Importer Json Content Importer

Server-Side Request Forgery (SSRF) vulnerability in Bernhard Kux JSON Content Importer.This issue affects JSON Content Importer: from n/a through 1.5.6.

6.4
2024-07-22 CVE-2024-38728 S Sols Unspecified vulnerability in S-Sols Seraphinite Post .Docx Source

Server-Side Request Forgery (SSRF) vulnerability in Seraphinite Solutions Seraphinite Post .DOCX Source.This issue affects Seraphinite Post .DOCX Source: from n/a through 2.16.9.

6.4
2024-07-22 CVE-2024-38730 Wpthemespace Unspecified vulnerability in Wpthemespace Magical Addons for Elementor

Server-Side Request Forgery (SSRF) vulnerability in Noor alam Magical Addons For Elementor.This issue affects Magical Addons For Elementor: from n/a through 1.1.41.

6.4
2024-07-23 CVE-2024-41012 Linux Use After Free vulnerability in Linux Kernel

In the Linux kernel, the following vulnerability has been resolved: filelock: Remove locks reliably when fcntl/close race is detected When fcntl_setlk() races with close(), it removes the created lock with do_lock_file_wait(). However, LSMs can allow the first do_lock_file_wait() that created the lock while denying the second do_lock_file_wait() that tries to remove the lock. Separately, posix_lock_file() could also fail to remove a lock due to GFP_KERNEL allocation failure (when splitting a range in the middle). After the bug has been triggered, use-after-free reads will occur in lock_get_status() when userspace reads /proc/locks.

6.3
2024-07-28 CVE-2024-7163 Seacms Unspecified vulnerability in Seacms 12.9

A vulnerability, which was classified as problematic, was found in SeaCMS 12.9.

6.1
2024-07-25 CVE-2024-3938 Dotcms Cross-site Scripting vulnerability in Dotcms

The "reset password" login page accepted an HTML injection via URL parameters. This has already been rectified via patch, and as such it cannot be demonstrated via Demo site link.

6.1
2024-07-25 CVE-2024-41809 Openobserve Cross-site Scripting vulnerability in Openobserve

OpenObserve is an open-source observability platform.

6.1
2024-07-25 CVE-2024-6558 HMS Networks Unspecified vulnerability in Hms-Networks products

HMS Industrial Networks Anybus-CompactCom 30 products are vulnerable to a XSS attack caused by the lack of input sanitation checks.

6.1
2024-07-25 CVE-2024-41801 Openproject Open Redirect vulnerability in Openproject

OpenProject is open source project management software.

6.1
2024-07-24 CVE-2024-22444 Arubanetworks Cross-site Scripting vulnerability in Arubanetworks Edgeconnect Sd-Wan Orchestrator

A vulnerability within the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow a remote attacker to conduct a reflected cross-site scripting (XSS) attack against a user of the interface.

6.1
2024-07-24 CVE-2024-6753 Wpwebinfotech Cross-site Scripting vulnerability in Wpwebinfotech Social Auto Poster

The Social Auto Poster plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘mapTypes’ parameter in the 'wpw_auto_poster_map_wordpress_post_type' AJAX function in all versions up to, and including, 5.3.14 due to insufficient input sanitization and output escaping.

6.1
2024-07-22 CVE-2024-24507 ACT ON Cross-site Scripting vulnerability in Act-On 2023

Cross Site Scripting vulnerability in Act-On 2023 allows a remote attacker to execute arbitrary code via the newUser parameter in the login.jsp component.

6.1
2024-07-22 CVE-2024-35656 Elementor Unspecified vulnerability in Elementor PRO 3.0.5/3.11.6/3.11.7

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Elementor Elementor Pro allows Reflected XSS.This issue affects Elementor Pro: from n/a through 3.21.2.

6.1
2024-07-22 CVE-2024-37097 Unitedthemes Cross-site Scripting vulnerability in Unitedthemes Shortcodes

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in UnitedThemes Shortcodes by United Themes allows Reflected XSS.This issue affects Shortcodes by United Themes: from n/a before 5.0.5.

6.1
2024-07-22 CVE-2024-37117 Uncannyowl Unspecified vulnerability in Uncannyowl Uncanny Automator

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Uncanny Owl Uncanny Automator Pro allows Reflected XSS.This issue affects Uncanny Automator Pro: from n/a through 5.3.

6.1
2024-07-22 CVE-2024-37199 Kriesi Unspecified vulnerability in Kriesi Enfold

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Kriesi.At Enfold allows Reflected XSS.This issue affects Enfold: from n/a through 5.6.9.

6.1
2024-07-22 CVE-2024-37206 Theme4Press Cross-site Scripting vulnerability in Theme4Press Demo Awesome 1.0.0/1.0.1

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Theme4Press Demo Awesome allows Reflected XSS.This issue affects Demo Awesome: from n/a through 1.0.1.

6.1
2024-07-22 CVE-2024-37211 Ali2Woo Unspecified vulnerability in Ali2Woo Aliexpress Dropshipping With Alinext

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Ali2Woo Team Ali2Woo Lite allows Reflected XSS.This issue affects Ali2Woo Lite: from n/a through 3.3.5.

6.1
2024-07-22 CVE-2024-37245 Vsourz Unspecified vulnerability in Vsourz ALL in ONE Redirection

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Vsourz Digital All In One Redirection allows Reflected XSS.This issue affects All In One Redirection: from n/a through 2.2.0.

6.1
2024-07-22 CVE-2024-37257 Permalink Manager Lite Project Unspecified vulnerability in Permalink Manager Lite Project Permalink Manager Lite

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Maciej Bis Permalink Manager Lite allows Reflected XSS.This issue affects Permalink Manager Lite: from n/a through 2.4.3.3.

6.1
2024-07-22 CVE-2024-37258 Wpsocialrocket Unspecified vulnerability in Wpsocialrocket Social Rocket

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Social Rocket allows Reflected XSS.This issue affects Social Rocket: from n/a through 1.3.3.

6.1
2024-07-22 CVE-2024-37259 Wpextended Unspecified vulnerability in Wpextended WP Extended

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WP Extended The Ultimate WordPress Toolkit – WP Extended allows Reflected XSS.This issue affects The Ultimate WordPress Toolkit – WP Extended: from n/a through 2.4.7.

6.1
2024-07-22 CVE-2024-37261 Wplab Unspecified vulnerability in Wplab Wp-Lister Lite for Amazon

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WP Lab WP-Lister Lite for Amazon allows Reflected XSS.This issue affects WP-Lister Lite for Amazon: from n/a through 2.6.16.

6.1
2024-07-22 CVE-2024-37262 Vcita Unspecified vulnerability in Vcita Online Booking & Scheduling Calendar for Wordpress BY Vcita

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in vCita.Com Online Booking & Scheduling Calendar for WordPress by vcita allows Reflected XSS.This issue affects Online Booking & Scheduling Calendar for WordPress by vcita: from n/a through 4.4.2.

6.1
2024-07-22 CVE-2024-37264 Groundhogg Unspecified vulnerability in Groundhogg

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Groundhogg Inc.

6.1
2024-07-22 CVE-2024-37267 Kaptinlin Unspecified vulnerability in Kaptinlin Striking

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in kaptinlin Striking allows Reflected XSS.This issue affects Striking: from n/a through 2.3.4.

6.1
2024-07-22 CVE-2024-37275 Nextscripts Unspecified vulnerability in Nextscripts Social Networks Auto Poster

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in NextScripts allows Reflected XSS.This issue affects NextScripts: from n/a through 4.4.6.

6.1
2024-07-22 CVE-2024-37416 Wppa Cross-site Scripting vulnerability in Wppa WP Photo Album Plus

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in J.N.

6.1
2024-07-22 CVE-2024-37432 Themegrill Unspecified vulnerability in Themegrill Esteem

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in ThemeGrill Esteem allows Stored XSS.This issue affects Esteem: from n/a through 1.5.0.

6.1
2024-07-22 CVE-2024-37433 Mailster Unspecified vulnerability in Mailster

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in EverPress Mailster allows Reflected XSS.This issue affects Mailster: from n/a through 4.0.9.

6.1
2024-07-24 CVE-2023-32471 Dell Unspecified vulnerability in Dell products

Dell Edge Gateway BIOS, versions 3200 and 5200, contains an out-of-bounds read vulnerability.

6.0
2024-07-26 CVE-2024-37034 Couchbase Inadequate Encryption Strength vulnerability in Couchbase Server

An issue was discovered in Couchbase Server before 7.2.5 and 7.6.0 before 7.6.1.

5.9
2024-07-25 CVE-2024-38103 Microsoft Unspecified vulnerability in Microsoft Edge

Microsoft Edge (Chromium-based) Information Disclosure Vulnerability

5.9
2024-07-24 CVE-2023-32466 Dell Unspecified vulnerability in Dell Edge Gateway 3200 Firmware

Dell Edge Gateway BIOS, versions 3200 and 5200, contains an out-of-bounds write vulnerability.

5.7
2024-07-25 CVE-2023-7271 Huawei Unspecified vulnerability in Huawei Emui and Harmonyos

Privilege escalation vulnerability in the NMS module Impact: Successful exploitation of this vulnerability will affect availability.

5.5
2024-07-25 CVE-2024-39670 Huawei Unspecified vulnerability in Huawei Emui and Harmonyos

Privilege escalation vulnerability in the account synchronisation module. Impact: Successful exploitation of this vulnerability will affect availability.

5.5
2024-07-25 CVE-2024-39671 Huawei Unspecified vulnerability in Huawei Emui and Harmonyos

Access control vulnerability in the security verification module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

5.5
2024-07-25 CVE-2024-39674 Huawei Unspecified vulnerability in Huawei Emui and Harmonyos

Plaintext vulnerability in the Gallery search module. Impact: Successful exploitation of this vulnerability will affect availability.

5.5
2024-07-24 CVE-2024-40575 Huawei Unspecified vulnerability in Huawei Opengauss 7.3.0

An issue in Huawei Technologies opengauss (openGauss 5.0.0 build) v.7.3.0 allows a local attacker to cause a denial of service via the modification of table attributes

5.5
2024-07-23 CVE-2024-41836 Adobe NULL Pointer Dereference vulnerability in Adobe Indesign

InDesign Desktop versions ID18.5.2, ID19.3 and earlier are affected by a NULL Pointer Dereference vulnerability that could lead to an application denial-of-service (DoS) condition.

5.5
2024-07-22 CVE-2024-6122 NI Incorrect Default Permissions vulnerability in NI Flexlogger and Systemlink

An incorrect permission in the installation directory for the shared NI SystemLink Server KeyValueDatabase service may result in information disclosure via local access.

5.5
2024-07-28 CVE-2024-7162 Seacms Unspecified vulnerability in Seacms 12.9/13.0

A vulnerability, which was classified as problematic, has been found in SeaCMS 12.9/13.0.

5.4
2024-07-28 CVE-2024-42054 Cervantessec Unrestricted Upload of File with Dangerous Type vulnerability in Cervantessec Cervantes 0.3/0.4/0.5

Cervantes through 0.5-alpha accepts insecure file uploads.

5.4
2024-07-28 CVE-2024-42055 Cervantessec Cross-site Scripting vulnerability in Cervantessec Cervantes 0.3/0.4/0.5

Cervantes through 0.5-alpha allows stored XSS.

5.4
2024-07-26 CVE-2024-25090 Apache Unspecified vulnerability in Apache Roller

Insufficient input validation and sanitation in Profile name & screenname, Bookmark name & description and blogroll name features in all versions of Apache Roller on all platforms allows an authenticated user to perform an XSS attack.

5.4
2024-07-25 CVE-2024-40324 Datex Soft Injection vulnerability in Datex-Soft E-Staff 5.1

A CRLF injection vulnerability in E-Staff v5.1 allows attackers to insert Carriage Return (CR) and Line Feed (LF) characters into input fields, leading to HTTP response splitting and header manipulation.

5.4
2024-07-25 CVE-2024-41808 Openobserve Cross-site Scripting vulnerability in Openobserve

The OpenObserve open-source observability platform provides the ability to filter logs in a dashboard by the values uploaded in a given log.

5.4
2024-07-25 CVE-2024-28772 IBM Unspecified vulnerability in IBM products

IBM Security Directory Integrator 7.2.0 and IBM Security Verify Directory Integrator 10.0.0 is vulnerable to stored cross-site scripting.

5.4
2024-07-25 CVE-2024-41705 Archerirm Cross-site Scripting vulnerability in Archerirm Archer

A stored XSS issue was discovered in Archer Platform 6.8 before 2024.06.

5.4
2024-07-25 CVE-2024-41706 Archerirm Cross-site Scripting vulnerability in Archerirm Archer

A stored XSS issue was discovered in Archer Platform 6 before version 2024.06.

5.4
2024-07-25 CVE-2024-41707 Archerirm Cross-site Scripting vulnerability in Archerirm Archer

An issue was discovered in Archer Platform 6 before 2024.06.

5.4
2024-07-25 CVE-2024-7047 Gitlab Cross-site Scripting vulnerability in Gitlab

A cross site scripting vulnerability exists in GitLab CE/EE affecting all versions from 16.6 prior to 17.0.5, 17.1 prior to 17.1.3, 17.2 prior to 17.2.1 allowing an attacker to execute arbitrary scripts under the context of the current logged in user.

5.4
2024-07-24 CVE-2024-3896 Robogallery Cross-site Scripting vulnerability in Robogallery Robo Gallery

The Photo Gallery, Images, Slider in Rbs Image Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the the Gallery title field in all versions up to, and including, 3.2.19 due to insufficient input sanitization and output escaping.

5.4
2024-07-24 CVE-2024-5818 Royal Elementor Addons Cross-site Scripting vulnerability in Royal-Elementor-Addons Royal Elementor Addons

The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored DOM-based Cross-Site Scripting via the plugin's Magazine Grid/Slider widget in all versions up to, and including, 1.3.980 due to insufficient input sanitization and output escaping on user supplied attributes.

5.4
2024-07-24 CVE-2024-6896 Ampforwp Cross-site Scripting vulnerability in Ampforwp Accelerated Mobile Pages

The AMP for WP – Accelerated Mobile Pages plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.0.96.1 due to insufficient input sanitization and output escaping.

5.4
2024-07-24 CVE-2024-6930 Wpbookingcalendar Cross-site Scripting vulnerability in Wpbookingcalendar Booking Calendar

The WP Booking Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'type' attribute within the plugin's bookingform shortcode in all versions up to, and including, 10.2.1 due to insufficient input sanitization and output escaping on user supplied attributes.

5.4
2024-07-24 CVE-2024-6629 Plugins360 Cross-site Scripting vulnerability in Plugins360 All-In-One Video Gallery

The All-in-One Video Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Video shortcode in all versions up to, and including, 3.7.1 due to insufficient input sanitization and output escaping on user supplied attributes.

5.4
2024-07-24 CVE-2024-3246 Litespeedtech Cross-Site Request Forgery (CSRF) vulnerability in Litespeedtech Litespeed Cache

The LiteSpeed Cache plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 6.2.0.1.

5.4
2024-07-24 CVE-2024-6752 Wpwebinfotech Cross-site Scripting vulnerability in Wpwebinfotech Social Auto Poster

The Social Auto Poster plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘wp_name’ parameter in the 'wpw_auto_poster_map_wordpress_post_type' AJAX function in all versions up to, and including, 5.3.14 due to insufficient input sanitization and output escaping.

5.4
2024-07-22 CVE-2024-41825 Jetbrains Cross-site Scripting vulnerability in Jetbrains Teamcity

In JetBrains TeamCity before 2024.07 stored XSS was possible on the Code Inspection tab

5.4
2024-07-22 CVE-2024-33933 Brainstormforce Unspecified vulnerability in Brainstormforce Elementor - Header, Footer & Blocks Template

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Brainstorm Force, Nikhil Chavan Elementor – Header, Footer & Blocks Template allows DOM-Based XSS.This issue affects Elementor – Header, Footer & Blocks Template: from n/a through 1.6.35.

5.4
2024-07-22 CVE-2024-37100 Threeroutesmedia Unspecified vulnerability in Threeroutesmedia Elegant Themes Icons

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Mayur Somani, threeroutes media Elegant Themes Icons allows Stored XSS.This issue affects Elegant Themes Icons: from n/a through 1.3.

5.4
2024-07-22 CVE-2024-37101 Afthemes Unspecified vulnerability in Afthemes WP Post Author

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in AF themes WP Post Author allows Stored XSS.This issue affects WP Post Author: from n/a through 3.6.7.

5.4
2024-07-22 CVE-2024-37114 Takashimatsuyama Unspecified vulnerability in Takashimatsuyama MY Favorites

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Takashi Matsuyama My Favorites allows Stored XSS.This issue affects My Favorites: from n/a through 1.4.1.

5.4
2024-07-22 CVE-2024-37116 Sinatrateam Unspecified vulnerability in Sinatrateam Sinatra

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in sinatrateam Sinatra allows Stored XSS.This issue affects Sinatra: from n/a through 1.3.

5.4
2024-07-22 CVE-2024-37215 Creativeinteractivemedia Unspecified vulnerability in Creativeinteractivemedia Transition Slider

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in creativeinteractivemedia Transition Slider – Responsive Image Slider and Gallery allows Stored XSS.This issue affects Transition Slider – Responsive Image Slider and Gallery: from n/a through 2.20.3.

5.4
2024-07-22 CVE-2024-37216 Generatewp Unspecified vulnerability in Generatewp Sketchfab Embed

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Rami Yushuvaev Sketchfab Embed allows Stored XSS.This issue affects Sketchfab Embed: from n/a through 1.5.

5.4
2024-07-22 CVE-2024-37217 Prowcplugins Unspecified vulnerability in Prowcplugins Empty Cart Button for Woocommerce 1.3.8

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in ProWCPlugins Empty Cart Button for WooCommerce allows Stored XSS.This issue affects Empty Cart Button for WooCommerce: from n/a through 1.3.8.

5.4
2024-07-22 CVE-2024-37219 Pagebuildersandwich Unspecified vulnerability in Pagebuildersandwich Page Builder Sandwich

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in PBN Hosting SL Page Builder Sandwich – Front-End Page Builder allows Stored XSS.This issue affects Page Builder Sandwich – Front-End Page Builder: from n/a through 5.1.0.

5.4
2024-07-22 CVE-2024-37221 Kimili Unspecified vulnerability in Kimili Flash Embed

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Michael Bester Kimili Flash Embed allows Stored XSS.This issue affects Kimili Flash Embed: from n/a through 2.5.3.

5.4
2024-07-22 CVE-2024-37223 Nicdarkthemes Unspecified vulnerability in Nicdarkthemes Restaurant Food 2.0

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Nicdark Restaurant Reservations allows Stored XSS.This issue affects Restaurant Reservations: from n/a through 2.0.

5.4
2024-07-22 CVE-2024-37229 Auburnforest Unspecified vulnerability in Auburnforest Blogmentor

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in AuburnForest Blogmentor – Blog Layouts for Elementor allows Stored XSS.This issue affects Blogmentor – Blog Layouts for Elementor: from n/a through 1.5.

5.4
2024-07-22 CVE-2024-37244 Ninjabeaveraddon Unspecified vulnerability in Ninjabeaveraddon Ninja Beaver Add-Ons for Beaver Builder

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Ninja Team Ninja Beaver Add-ons for Beaver Builder allows Stored XSS.This issue affects Ninja Beaver Add-ons for Beaver Builder: from n/a through 2.4.5.

5.4
2024-07-22 CVE-2024-38503 Apache Unspecified vulnerability in Apache Syncope

When editing a user, group or any object in the Syncope Console, HTML tags could be added to any text field and could lead to potential exploits. The same vulnerability was found in the Syncope Enduser, when editing “Personal Information” or “User Requests”. Users are recommended to upgrade to version 3.0.8, which fixes this issue.

5.4
2024-07-22 CVE-2024-37246 Gallery Slideshow Project Unspecified vulnerability in Gallery Slideshow Project Gallery Slideshow

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Jethin Gallery Slideshow allows Stored XSS.This issue affects Gallery Slideshow: from n/a through 1.4.1.

5.4
2024-07-22 CVE-2024-37263 Themelooks Cross-site Scripting vulnerability in Themelooks Enter Addons

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in ThemeLooks Enter Addons enteraddons allows Stored XSS.This issue affects Enter Addons: from n/a through 2.1.6.

5.4
2024-07-22 CVE-2024-37265 Northernbeacheswebsites Unspecified vulnerability in Northernbeacheswebsites Ideapush

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Martin Gibson IdeaPush allows Stored XSS.This issue affects IdeaPush: from n/a through 8.60.

5.4
2024-07-22 CVE-2024-37278 Brainstormforce Unspecified vulnerability in Brainstormforce Cards for Beaver Builder

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Pratik Chaskar Cards for Beaver Builder.This issue affects Cards for Beaver Builder: from n/a through 1.1.4.

5.4
2024-07-22 CVE-2024-37409 Wpbeaveraddons Unspecified vulnerability in Wpbeaveraddons Powerpack Lite for Beaver Builder

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Beaver Addons PowerPack Lite for Beaver Builder allows Stored XSS.This issue affects PowerPack Lite for Beaver Builder: from n/a through 1.3.0.4.

5.4
2024-07-22 CVE-2024-37414 Depicter Unspecified vulnerability in Depicter

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Depicter Slider and Popup by Averta Depicter Slider allows Stored XSS.This issue affects Depicter Slider: from n/a through 3.0.2.

5.4
2024-07-22 CVE-2024-37422 Emiliaprojects Unspecified vulnerability in Emiliaprojects Progress Planner

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Team Emilia Projects Progress Planner allows Stored XSS.This issue affects Progress Planner: from n/a through 0.9.2.

5.4
2024-07-22 CVE-2024-37428 Themesgrove Unspecified vulnerability in Themesgrove All-In-One Addons for Elementor

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Themesgrove WidgetKit allows Stored XSS.This issue affects WidgetKit: from n/a through 2.5.0.

5.4
2024-07-22 CVE-2024-37445 Bplugins Unspecified vulnerability in Bplugins Html5 Audio Player

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in bPlugins Html5 Audio Player allows Stored XSS.This issue affects Html5 Audio Player: from n/a through 2.2.23.

5.4
2024-07-22 CVE-2024-6271 Community Events Project Cross-Site Request Forgery (CSRF) vulnerability in Community Events Project Community Events

The Community Events WordPress plugin before 1.5 does not have CSRF check in place when deleting events, which could allow attackers to make a logged in admin delete arbitrary events via a CSRF attack

5.4
2024-07-27 CVE-2024-1798 Themeum Missing Authorization vulnerability in Themeum Tutor LMS - Migration Tool

The Tutor LMS – Migration Tool plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the tutor_lp_export_xml function in all versions up to, and including, 2.2.0.

5.3
2024-07-26 CVE-2024-41684 Syrotech Unspecified vulnerability in Syrotech Sy-Gpon-1110-Wdont Firmware 3.1.02231102

This vulnerability exists in SyroTech SY-GPON-1110-WDONT Router due to missing secure flag for the session cookies associated with the router's web management interface.

5.3
2024-07-24 CVE-2024-6755 Wpwebinfotech Missing Authorization vulnerability in Wpwebinfotech Social Auto Poster

The Social Auto Poster plugin for WordPress is vulnerable to unauthorized modification and loss of data due to a missing capability check on the ‘wpw_auto_poster_quick_delete_multiple’ function in all versions up to, and including, 5.3.14.

5.3
2024-07-24 CVE-2024-7091 Gitlab Unspecified vulnerability in Gitlab

An issue was discovered in GitLab CE/EE affecting all versions starting from 15.6 prior to 17.0.5, starting from 17.1 prior to 17.1.3, and starting from 17.2 prior to 17.2.1 where it was possible to disclose limited information of an exported group or project to another user.

5.0
2024-07-24 CVE-2024-5067 Gitlab Unspecified vulnerability in Gitlab

An issue was discovered in GitLab EE affecting all versions starting from 16.11 prior to 17.0.5, starting from 17.1 prior to 17.1.3, and starting from 17.2 prior to 17.2.1 where certain project-level analytics settings could be leaked in DOM to group members with Developer or higher roles.

4.9
2024-07-27 CVE-2024-6518 Fluentforms Cross-site Scripting vulnerability in Fluentforms Contact Form

The Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 5.1.19 due to insufficient input sanitization and output escaping.

4.8
2024-07-27 CVE-2024-6520 Fluentforms Cross-site Scripting vulnerability in Fluentforms Contact Form

The Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 5.1.19 due to insufficient input sanitization and output escaping.

4.8
2024-07-27 CVE-2024-6521 Fluentforms Cross-site Scripting vulnerability in Fluentforms Contact Form

The Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 5.1.19 due to insufficient input sanitization and output escaping.

4.8
2024-07-24 CVE-2024-31971 Adtran Cross-site Scripting vulnerability in Adtran Netvanta 3120 Firmware 18.01.01.00.E

Multiple stored cross-site scripting (XSS) vulnerabilities on AdTran NetVanta 3120 18.01.01.00.E devices allow remote attackers to inject arbitrary JavaScript, as demonstrated by /mainPassword.html, /processIdentity.html, /public.html, /dhcp.html, /private.html, /hostname.html, /connectivity.html, /NetworkMonitor.html, /trafficMonitoringConfig.html, and /wizardMain.html.

4.8
2024-07-24 CVE-2024-6094 Technowich Cross-site Scripting vulnerability in Technowich WP Ulike

The WP ULike WordPress plugin before 4.7.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

4.8
2024-07-22 CVE-2024-41826 Jetbrains Cross-site Scripting vulnerability in Jetbrains Teamcity

In JetBrains TeamCity before 2024.07 stored XSS was possible on Show Connection page

4.8
2024-07-22 CVE-2024-37120 Oxilab Unspecified vulnerability in Oxilab Responsive Tabs

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Biplob Adhikari Tabs allows Stored XSS.This issue affects Tabs: from n/a through 4.0.6.

4.8
2024-07-22 CVE-2024-37121 Oxilab Unspecified vulnerability in Oxilab Shortcode Addons

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in biplob018 Shortcode Addons allows Stored XSS.This issue affects Shortcode Addons: from n/a through 3.2.5.

4.8
2024-07-22 CVE-2024-37122 Oxilab Unspecified vulnerability in Oxilab Accordions

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Biplob Adhikari Accordions allows Stored XSS.This issue affects Accordions: from n/a through 2.3.5.

4.8
2024-07-22 CVE-2024-37239 Wpmudev Cross-site Scripting vulnerability in Wpmudev Branda

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WPMU DEV Branda allows Stored XSS.This issue affects Branda: from n/a through 3.4.17.

4.8
2024-07-22 CVE-2024-37271 Print MY Blog Project Unspecified vulnerability in Print MY Blog Project Print MY Blog

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Michael Nelson Print My Blog allows Stored XSS.This issue affects Print My Blog: from n/a through 3.27.0.

4.8
2024-07-22 CVE-2024-37429 Idehweb Unspecified vulnerability in Idehweb Login With Phone Number

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Hamid Alinia – idehweb Login with phone number allows Stored XSS.This issue affects Login with phone number: from n/a through 1.7.35.

4.8
2024-07-22 CVE-2024-37434 Atarim Unspecified vulnerability in Atarim

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Atarim allows Stored XSS.This issue affects Atarim: from n/a through 3.31.

4.8
2024-07-22 CVE-2024-41709 Backdropcms Cross-site Scripting vulnerability in Backdropcms Backdrop

Backdrop CMS before 1.27.3 and 1.28.x before 1.28.2 does not sufficiently sanitize field labels before they are displayed in certain places.

4.8
2024-07-22 CVE-2024-5004 Cminds Cross-site Scripting vulnerability in Cminds CM Popup

The CM Popup Plugin for WordPress WordPress plugin before 1.6.6 does not sanitise and escape some of the campaign settings, which could allow high privilege users such as contributor to perform Stored Cross-Site Scripting attacks

4.8
2024-07-22 CVE-2024-5529 Holoborodko Cross-site Scripting vulnerability in Holoborodko WP Quicklatex

The WP QuickLaTeX WordPress plugin before 3.8.8 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

4.8
2024-07-22 CVE-2024-6243 Ibericode Cross-site Scripting vulnerability in Ibericode Html Forms

The HTML Forms WordPress plugin before 1.3.33 does not sanitize and escape the form message inputs, allowing high-privilege users, such as administrators, to perform Stored Cross-Site Scripting (XSS) attacks even when the unfiltered_html capability is disabled.

4.8
2024-07-28 CVE-2024-7155 Totolink Use of Hard-coded Credentials vulnerability in Totolink A3300R Firmware 17.0.0Cu.557B20221024

A vulnerability has been found in TOTOLINK A3300R 17.0.0cu.557_B20221024 and classified as problematic.

4.7
2024-07-26 CVE-2024-41688 Syrotech Cleartext Storage of Sensitive Information vulnerability in Syrotech Sy-Gpon-1110-Wdont Firmware 3.1.02231102

This vulnerability exists in SyroTech SY-GPON-1110-WDONT Router due lack of encryption in storing of usernames and passwords within the router's firmware/ database.

4.6
2024-07-26 CVE-2024-41689 Syrotech Cleartext Storage of Sensitive Information vulnerability in Syrotech Sy-Gpon-1110-Wdont Firmware 3.1.02231102

This vulnerability exists in SyroTech SY-GPON-1110-WDONT Router due to unencrypted storing of WPA/ WPS credentials within the router's firmware/ database.

4.6
2024-07-26 CVE-2024-41690 Syrotech Cleartext Storage of Sensitive Information vulnerability in Syrotech Sy-Gpon-1110-Wdont Firmware 3.1.02231102

This vulnerability exists in SyroTech SY-GPON-1110-WDONT Router due to storing of default username and password credentials in plaintext within the router's firmware/ database.

4.6
2024-07-26 CVE-2024-41691 Syrotech Cleartext Storage of Sensitive Information vulnerability in Syrotech Sy-Gpon-1110-Wdont Firmware 3.1.02231102

This vulnerability exists in SyroTech SY-GPON-1110-WDONT Router due to storing of FTP credentials in plaintext within the SquashFS-root filesystem associated with the router's firmware.

4.6
2024-07-24 CVE-2024-37533 IBM Unspecified vulnerability in IBM Infosphere Information Server 11.7

IBM InfoSphere Information Server 11.7 could disclose sensitive user information to another user with physical access to the machine.

4.6
2024-07-24 CVE-2024-7068 Insurance Management System Project Cross-site Scripting vulnerability in Insurance Management System Project Insurance Management System 1.0

A vulnerability classified as problematic has been found in SourceCodester Insurance Management System 1.0.

4.6
2024-07-27 CVE-2024-1804 Themeum Missing Authorization vulnerability in Themeum Tutor LMS - Migration Tool

The Tutor LMS – Migration Tool plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the tutor_import_from_xml function in all versions up to, and including, 2.2.0.

4.3
2024-07-25 CVE-2024-7057 Gitlab Unspecified vulnerability in Gitlab

An information disclosure vulnerability in GitLab CE/EE affecting all versions starting from 16.7 prior to 17.0.5, starting from 17.1 prior to 17.1.3, and starting from 17.2 prior to 17.2.1 where job artifacts can be inappropriately exposed to users lacking the proper authorization level.

4.3
2024-07-24 CVE-2024-7065 Denkgroot Unspecified vulnerability in Denkgroot Spina

A vulnerability was found in Spina CMS up to 2.18.0.

4.3
2024-07-24 CVE-2024-6874 Haxx Out-of-bounds Read vulnerability in Haxx Libcurl 8.8.0

libcurl's URL API function [curl_url_get()](https://curl.se/libcurl/c/curl_url_get.html) offers punycode conversions, to and from IDN.

4.3
2024-07-24 CVE-2024-6754 Wpwebinfotech Missing Authorization vulnerability in Wpwebinfotech Social Auto Poster

The Social Auto Poster plugin for WordPress is vulnerable to unauthorized modification of data to a missing capability check on the ‘wpw_auto_poster_update_tweet_template’ function in all versions up to, and including, 5.3.14.

4.3
2024-07-22 CVE-2024-32152 Ankitects Unspecified vulnerability in Ankitects Anki 24.04

A blocklist bypass vulnerability exists in the LaTeX functionality of Ankitects Anki 24.04.

4.3

5 Low Vulnerabilities

DATE CVE VENDOR VULNERABILITY CVSS
2024-07-24 CVE-2024-3454 CSA IOT Unspecified vulnerability in Csa-Iot Matter

An implementation issue in the Connectivity Standards Alliance Matter 1.2 protocol as used in the connectedhomeip SDK allows a third party to disclose information about devices part of the same fabric (footprinting), even though the protocol is designed to prevent access to such information.

3.5
2024-07-23 CVE-2024-41839 Adobe Unspecified vulnerability in Adobe Experience Manager

Adobe Experience Manager versions 6.5.20 and earlier are affected by an Improper Input Validation vulnerability that could lead to a security feature bypass.

3.5
2024-07-25 CVE-2024-40873 Absolute Cross-site Scripting vulnerability in Absolute Secure Access

There is a cross-site scripting vulnerability in the Secure Access administrative console of Absolute Secure Access prior to version 13.07. Attackers with system administrator permissions can interfere with another system administrator’s use of the publishing UI when the administrators are editing the same management object.

3.4
2024-07-26 CVE-2024-41686 Syrotech Unspecified vulnerability in Syrotech Sy-Gpon-1110-Wdont Firmware 3.1.02231102

This vulnerability exists in SyroTech SY-GPON-1110-WDONT Router due to improper implementation of password policies.

3.3
2024-07-24 CVE-2024-0231 Gitlab Injection vulnerability in Gitlab

A resource misdirection vulnerability in GitLab CE/EE versions 12.0 prior to 17.0.5, 17.1 prior to 17.1.3, and 17.2 prior to 17.2.1 allows an attacker to craft a repository import in such a way as to misdirect commits.

2.7