CVE Feed

    Dashboard / CVE

    6.4
    Medium

    CVE-2024-1768

    Last Modified: 8 Apr 2026

    The Clever Fox plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's info box block in all versions up to, and including, 25.2.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 7 Jun 2024
    7.6
    High

    CVE-2023-32475

    Last Modified: 21 Nov 2024

    Dell BIOS contains a missing support for integrity check vulnerability. An attacker with physical access to the system could potentially bypass security mechanisms to run arbitrary code on the system.

    Published: 7 Jun 2024
    5.4
    Medium

    CVE-2023-6876

    Last Modified: 8 Apr 2026

    The Clever Fox – One Click Website Importer by Nayra Themes plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'clever-fox-activate-theme' function in all versions up to, and including, 25.2.0. This makes it possible for authenticated attackers, with subscriber access and above, to modify the active theme, including to an invalid value which can take down the site.

    Published: 7 Jun 2024
    4.3
    Medium

    CVE-2024-1689

    Last Modified: 8 Apr 2026

    The WooCommerce Tools plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the woocommerce_tool_toggle_module() function in all versions up to, and including, 1.2.9. This makes it possible for authenticated attackers, with subscriber-level access and above, to deactivate arbitrary plugin modules.

    Published: 7 Jun 2024
    6.5
    Medium

    CVE-2022-4968

    Last Modified: 21 Nov 2024

    netplan leaks the private key of wireguard to local users. Versions after 1.0 are not affected.

    Published: 7 Jun 2024
    7.2
    High

    CVE-2024-30162

    Last Modified: 15 Apr 2026

    Invision Community through 4.7.16 allows remote code execution via the applications/core/modules/admin/editor/toolbar.php IPS\core\modules\admin\editor\_toolbar::addPlugin() method. This method handles uploaded ZIP files that are extracted into the applications/core/interface/ckeditor/ckeditor/plugins/ directory without properly verifying their content. This can be exploited by admin users (with the toolbar_manage permission) to write arbitrary PHP files into that directory, leading to execution of arbitrary PHP code in the context of the web server user.

    Published: 7 Jun 2024
    9.8
    Critical

    CVE-2024-4577

    Last Modified: 3 Nov 2025

    In PHP versions 8.1.* before 8.1.29, 8.2.* before 8.2.20, 8.3.* before 8.3.8, when using Apache and PHP-CGI on Windows, if the system is set up to use certain code pages, Windows may use "Best-Fit" behavior to replace characters in command line given to Win32 API functions. PHP CGI module may misinterpret those characters as PHP options, which may allow a malicious user to pass options to PHP binary being run, and thus reveal the source code of scripts, run arbitrary PHP code on the server, etc.

    Published: 7 Jun 2024
    7.8
    High

    CVE-2024-4610

    Last Modified: 23 Oct 2025

    Use After Free vulnerability in Arm Ltd Bifrost GPU Kernel Driver, Arm Ltd Valhall GPU Kernel Driver allows a local non-privileged user to make improper GPU memory processing operations to gain access to already freed memory.This issue affects Bifrost GPU Kernel Driver: from r34p0 through r40p0; Valhall GPU Kernel Driver: from r34p0 through r40p0.

    Published: 7 Jun 2024
    6.8
    Medium

    CVE-2024-31958

    Last Modified: 26 Jun 2025

    An issue was discovered in Samsung Mobile Processor EExynos 2200, Exynos 1480, Exynos 2400. It lacks a check for the validation of native handles, which can result in an Out-of-Bounds Write.

    Published: 7 Jun 2024
    8.8
    High

    CVE-2023-49223

    Last Modified: 15 Apr 2026

    Precor touchscreen console P62, P80, and P82 could allow a remote attacker to obtain sensitive information because the root password is stored in /etc/passwd. An attacker could exploit this to extract files and obtain sensitive information.

    Published: 7 Jun 2024
    8.8
    High

    CVE-2024-0444

    Last Modified: 17 Mar 2026

    GStreamer AV1 Video Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to exploit this vulnerability but attack vectors may vary depending on the implementation. The specific flaw exists within the parsing of tile list data within AV1-encoded video files. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-22873.

    Published: 7 Jun 2024
    6.1
    Medium

    CVE-2024-37383

    Last Modified: 31 Oct 2025

    Roundcube Webmail before 1.5.7 and 1.6.x before 1.6.7 allows XSS via SVG animate attributes.

    Published: 7 Jun 2024
    9.8
    Critical

    CVE-2024-30163

    Last Modified: 19 Mar 2025

    Invision Community before 4.7.16 allow SQL injection via the applications/nexus/modules/front/store/store.php IPS\nexus\modules\front\store\_store::_categoryView() method, where user input passed through the filter request parameter is not properly sanitized before being used to execute SQL queries. This can be exploited by unauthenticated attackers to carry out Blind SQL Injection attacks.

    Published: 7 Jun 2024
    8.4
    High

    CVE-2024-31959

    Last Modified: 26 Jun 2025

    An issue was discovered in Samsung Mobile Processor Exynos 2200, Exynos 1480, Exynos 2400. It lacks a check for the validation of native handles, which can result in code execution.

    Published: 7 Jun 2024
    —
    Unknown

    CVE-2024-36811

    Last Modified: 28 Oct 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2024-37295. Reason: This candidate is a reservation duplicate of CVE-2024-37295. Notes: All CVE users should reference CVE-2024-37295 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage.

    Published: 7 Jun 2024
    7.5
    High

    CVE-2024-36827

    Last Modified: 28 Mar 2025

    An XML External Entity (XXE) vulnerability in the ebookmeta.get_metadata function of ebookmeta before v1.2.8 allows attackers to access sensitive information or cause a Denial of Service (DoS) via crafted XML input.

    Published: 7 Jun 2024
    4.9
    Medium

    CVE-2024-37280

    Last Modified: 21 Nov 2024

    A flaw was discovered in Elasticsearch, affecting document ingestion when an index template contains a dynamic field mapping of “passthrough” type. Under certain circumstances, ingesting documents in this index would cause a StackOverflow exception to be thrown and ultimately lead to a Denial of Service. Note that passthrough fields is an experimental feature.

    Published: 7 Jun 2024
    6.1
    Medium

    CVE-2024-37384

    Last Modified: 1 May 2025

    Roundcube Webmail before 1.5.7 and 1.6.x before 1.6.7 allows XSS via list columns from user preferences.

    Published: 7 Jun 2024
    9.1
    Critical

    CVE-2024-37388

    Last Modified: 21 Nov 2024

    An XML External Entity (XXE) vulnerability in the ebookmeta.get_metadata function of lxml before v4.9.1 allows attackers to access sensitive information or cause a Denial of Service (DoS) via crafted XML input.

    Published: 7 Jun 2024
    7.7
    High

    CVE-2024-5585

    Last Modified: 13 Feb 2025

    In PHP versions 8.1.* before 8.1.29, 8.2.* before 8.2.20, 8.3.* before 8.3.8, the fix for CVE-2024-1874 does not work if the command name includes trailing spaces. Original issue: when using proc_open() command with array syntax, due to insufficient escaping, if the arguments of the executed command are controlled by a malicious user, the user can supply arguments that would execute arbitrary commands in Windows shell.

    Published: 7 Jun 2024
    5.9
    Medium

    CVE-2024-2408

    Last Modified: 21 Mar 2025

    The openssl_private_decrypt function in PHP, when using PKCS1 padding (OPENSSL_PKCS1_PADDING, which is the default), is vulnerable to the Marvin Attack unless it is used with an OpenSSL version that includes the changes from this pull request: https://github.com/openssl/openssl/pull/13817 (rsa_pkcs1_implicit_rejection). These changes are part of OpenSSL 3.2 and have also been backported to stable versions of various Linux distributions, as well as to the PHP builds provided for Windows since the previous release. All distributors and builders should ensure that this version is used to prevent PHP from being vulnerable. PHP Windows builds for the versions 8.1.29, 8.2.20 and 8.3.8 and above include OpenSSL patches that fix the vulnerability.

    Published: 7 Jun 2024
    8.4
    High

    CVE-2024-32502

    Last Modified: 27 Aug 2025

    An issue was discovered in Samsung Mobile Processor and Wearable Processor Exynos 850, Exynos 1080, Exynos 2100, Exynos 1280, Exynos 1380, Exynos 1330, Exynos W920, Exynos W930. The mobile processor lacks proper reference count checking, which can result in a UAF (Use-After-Free) vulnerability.

    Published: 7 Jun 2024
    7.8
    High

    CVE-2023-49221

    Last Modified: 15 Apr 2026

    Precor touchscreen console P62, P80, and P82 could allow a remote attacker (within the local network) to bypass security restrictions, and access the service menu, because there is a hard-coded service code.

    Published: 7 Jun 2024
    8.8
    High

    CVE-2023-49222

    Last Modified: 15 Apr 2026

    Precor touchscreen console P82 contains a private SSH key that corresponds to a default public key. A remote attacker could exploit this to gain root privileges.

    Published: 7 Jun 2024
    8
    High

    CVE-2023-49224

    Last Modified: 15 Apr 2026

    Precor touchscreen console P62, P80, and P82 contains a default SSH public key in the authorized_keys file. A remote attacker could use this key to gain root privileges.

    Published: 7 Jun 2024
    8.4
    High

    CVE-2023-37539

    Last Modified: 21 Nov 2024

    The Domino Catalog template is susceptible to a Stored Cross-Site Scripting (XSS) vulnerability. An attacker with the ability to edit documents in the catalog application/database created from this template can embed a cross site scripting attack. The attack would be activated by an end user clicking it.

    Published: 6 Jun 2024
    5.4
    Medium

    CVE-2024-36775

    Last Modified: 13 Feb 2025

    A cross-site scripting (XSS) vulnerability in Monstra CMS v3.0.4 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the About Me parameter in the Edit Profile page.

    Published: 6 Jun 2024
    7.2
    High

    CVE-2024-36774

    Last Modified: 13 Feb 2025

    An arbitrary file upload vulnerability in Monstra CMS v3.0.4 allows attackers to execute arbitrary code via uploading a crafted PHP file.

    Published: 6 Jun 2024
    5.6
    Medium

    CVE-2024-4013

    Last Modified: 15 Apr 2026

    A bug exists in the API, mesh_node_power_off(), which fails to copy the contents of the Replay Protection List (RPL) from RAM to NVM before powering down, resulting in the ability to replay unsaved messages. Note that as of June 2024, the Gecko SDK was renamed to the Simplicity SDK, and the versioning scheme was changed from Gecko SDK vX.Y.Z to Simplicity SDK YYYY.MM.Patch#.

    Published: 6 Jun 2024
    7.5
    High

    CVE-2023-51847

    Last Modified: 15 Apr 2026

    An issue in obgm and Libcoap v.a3ed466 allows a remote attacker to cause a denial of service via thecoap_context_t function in the src/coap_threadsafe.c:297:3 component.

    Published: 6 Jun 2024
    5.5
    Medium

    CVE-2024-22525

    Last Modified: 18 Mar 2025

    dnspod-sr 0dfbd37 contains a SEGV.

    Published: 6 Jun 2024
    5.5
    Medium

    CVE-2024-22524

    Last Modified: 27 Mar 2025

    dnspod-sr 0dfbd37 is vulnerable to buffer overflow.

    Published: 6 Jun 2024
    7.5
    High

    CVE-2024-24199

    Last Modified: 13 Mar 2025

    smartdns commit 54b4dc was discovered to contain a misaligned address at smartdns/src/dns.c.

    Published: 6 Jun 2024
    7.5
    High

    CVE-2024-24198

    Last Modified: 13 Feb 2025

    smartdns commit 54b4dc was discovered to contain a misaligned address at smartdns/src/util.c.

    Published: 6 Jun 2024
    7.5
    High

    CVE-2024-24195

    Last Modified: 13 Feb 2025

    robdns commit d76d2e6 was discovered to contain a misaligned address at /src/zonefile-insertion.c.

    Published: 6 Jun 2024
    7.5
    High

    CVE-2024-24194

    Last Modified: 15 Apr 2026

    robdns commit d76d2e6 was discovered to contain a NULL pointer dereference via the item->tokens component at /src/conf-parse.c.

    Published: 6 Jun 2024
    9.1
    Critical

    CVE-2024-24192

    Last Modified: 13 Feb 2025

    robdns commit d76d2e6 was discovered to contain a heap overflow via the component block->filename at /src/zonefile-insertion.c.

    Published: 6 Jun 2024
    7.5
    High

    CVE-2024-36823

    Last Modified: 25 Mar 2025

    The encrypt() function of Ninja Core v7.0.0 was discovered to use a weak cryptographic algorithm, leading to a possible leakage of sensitive information.

    Published: 6 Jun 2024
    8.8
    High

    CVE-2024-32752

    Last Modified: 15 Apr 2026

    The iSTAR door controllers running firmware prior to version 6.6.B, does not support authenticated communications with ICU, which may allow an attacker to gain unauthorized access

    Published: 6 Jun 2024
    4
    Medium

    CVE-2024-36795

    Last Modified: 29 May 2025

    Insecure permissions in Netgear WNR614 JNR1010V2/N300-V1.1.0.54_1.0.1 allows attackers to access URLs and directories embedded within the firmware via unspecified vectors.

    Published: 6 Jun 2024
    9.8
    Critical

    CVE-2024-22074

    Last Modified: 18 Mar 2025

    Dynamsoft Service 1.8.1025 through 1.8.2013, 1.7.0330 through 1.7.2531, 1.6.0428 through 1.6.1112, 1.5.0625 through 1.5.3116, 1.4.0618 through 1.4.1230, and 1.0.516 through 1.3.0115 has Incorrect Access Control. This is fixed in 1.8.2014, 1.7.4212, 1.6.3212, 1.5.31212, 1.4.3212, and 1.3.3212.

    Published: 6 Jun 2024
    7.5
    High

    CVE-2024-36730

    Last Modified: 14 Mar 2025

    Improper input validation in OneFlow-Inc. Oneflow v0.9.1 allows attackers to cause a Denial of Service (DoS) via inputting negative values into the oneflow.zeros/ones parameter.

    Published: 6 Jun 2024
    5.3
    Medium

    CVE-2024-37154

    Last Modified: 21 Nov 2024

    Evmos is the Ethereum Virtual Machine (EVM) Hub on the Cosmos Network. Users are able to delegate tokens that have not yet been vested. This affects employees and grantees who have funds managed via `ClawbackVestingAccount`. This affects 18.1.0 and earlier.

    Published: 6 Jun 2024
    9.8
    Critical

    CVE-2024-2359

    Last Modified: 21 Nov 2024

    A vulnerability in the parisneo/lollms-webui version 9.3 allows attackers to bypass intended access restrictions and execute arbitrary code. The issue arises from the application's handling of the `/execute_code` endpoint, which is intended to be blocked from external access by default. However, attackers can exploit the `/update_setting` endpoint, which lacks proper access control, to modify the `host` configuration at runtime. By changing the `host` setting to an attacker-controlled value, the restriction on the `/execute_code` endpoint can be bypassed, leading to remote code execution. This vulnerability is due to improper neutralization of special elements used in an OS command (`Improper Neutralization of Special Elements used in an OS Command`).

    Published: 6 Jun 2024
    9.8
    Critical

    CVE-2024-2360

    Last Modified: 21 Nov 2024

    parisneo/lollms-webui is vulnerable to path traversal attacks that can lead to remote code execution due to insufficient sanitization of user-supplied input in the 'Database path' and 'PDF LaTeX path' settings. An attacker can exploit this vulnerability by manipulating these settings to execute arbitrary code on the targeted server. The issue affects the latest version of the software. The vulnerability stems from the application's handling of the 'discussion_db_name' and 'pdf_latex_path' parameters, which do not properly validate file paths, allowing for directory traversal. This vulnerability can also lead to further file exposure and other attack vectors by manipulating the 'discussion_db_name' parameter.

    Published: 6 Jun 2024
    9.8
    Critical

    CVE-2024-3408

    Last Modified: 21 Nov 2024

    man-group/dtale version 3.10.0 is vulnerable to an authentication bypass and remote code execution (RCE) due to improper input validation. The vulnerability arises from a hardcoded `SECRET_KEY` in the flask configuration, allowing attackers to forge a session cookie if authentication is enabled. Additionally, the application fails to properly restrict custom filter queries, enabling attackers to execute arbitrary code on the server by bypassing the restriction on the `/update-settings` endpoint, even when `enable_custom_filters` is not enabled. This vulnerability allows attackers to bypass authentication mechanisms and execute remote code on the server.

    Published: 6 Jun 2024
    7.5
    High

    CVE-2024-5124

    Last Modified: 20 May 2025

    A timing attack vulnerability exists in the gaizhenbiao/chuanhuchatgpt repository, specifically within the password comparison logic. The vulnerability is present in version 20240310 of the software, where passwords are compared using the '=' operator in Python. This method of comparison allows an attacker to guess passwords based on the timing of each character's comparison. The issue arises from the code segment that checks a password for a particular username, which can lead to the exposure of sensitive information to an unauthorized actor. An attacker exploiting this vulnerability could potentially guess user passwords, compromising the security of the system.

    Published: 6 Jun 2024
    9.3
    Critical

    CVE-2024-5328

    Last Modified: 21 Nov 2024

    A Server-Side Request Forgery (SSRF) vulnerability exists in the lunary-ai/lunary application, specifically within the endpoint '/auth/saml/tto/download-idp-xml'. The vulnerability arises due to the application's failure to validate user-supplied URLs before using them in server-side requests. An attacker can exploit this vulnerability by sending a specially crafted request to the affected endpoint, allowing them to make unauthorized requests to internal or external resources. This could lead to the disclosure of sensitive information, service disruption, or further attacks against the network infrastructure. The issue affects the latest version of the application as of the report.

    Published: 6 Jun 2024
    8.8
    High

    CVE-2024-3150

    Last Modified: 9 Jan 2025

    In mintplex-labs/anything-llm, a vulnerability exists in the thread update process that allows users with Default or Manager roles to escalate their privileges to Administrator. The issue arises from improper input validation when handling HTTP POST requests to the endpoint `/workspace/:slug/thread/:threadSlug/update`. Specifically, the application fails to validate or check user input before passing it to the `workspace_thread` Prisma model for execution. This oversight allows attackers to craft a Prisma relation query operation that manipulates the `users` model to change a user's role to admin. Successful exploitation grants attackers the highest level of user privileges, enabling them to see and perform all actions within the system.

    Published: 6 Jun 2024
    7.5
    High

    CVE-2024-36732

    Last Modified: 2 May 2025

    An issue in OneFlow-Inc. Oneflow v0.9.1 allows attackers to cause a Denial of Service (DoS) when an empty array is processed with oneflow.tensordot.

    Published: 6 Jun 2024