CVE Feed

    Dashboard / CVE

    4.4
    Medium

    CVE-2024-3031

    Last Modified: 15 Apr 2026

    The Fluid Notification Bar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 3.2.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.

    Published: 4 Jun 2024
    5.3
    Medium

    CVE-2024-1718

    Last Modified: 15 Apr 2026

    The Claudio Sanches – Checkout Cielo for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to insufficient payment validation in the update_order_status() function in all versions up to, and including, 1.1.0. This makes it possible for unauthenticated attackers to update the status of orders to paid bypassing payment.

    Published: 4 Jun 2024
    7.5
    High

    CVE-2024-2019

    Last Modified: 15 Apr 2026

    The WP-DB-Table-Editor plugin for WordPress is vulnerable to unauthorized access of data, modification of data, and loss of data due to lack of a default capability requirement on the 'dbte_render' function in all versions up to, and including, 1.8.4. This makes it possible for authenticated attackers, with contributor access and above, to modify database tables that the theme has been configured to use the plugin to edit.

    Published: 4 Jun 2024
    7.2
    High

    CVE-2024-3555

    Last Modified: 15 Apr 2026

    The Social Link Pages: link-in-bio landing pages for your social media profiles plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the import_link_pages() function in all versions up to, and including, 1.6.9. This makes it possible for unauthenticated attackers to inject arbitrary pages and malicious web scripts.

    Published: 4 Jun 2024
    4.3
    Medium

    CVE-2024-1717

    Last Modified: 15 Apr 2026

    The Admin Notices Manager plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the handle_ajax_call() function in all versions up to, and including, 1.4.0. This makes it possible for authenticated attackers, with subscriber-level access and above, to retrieve a list of registered user emails.

    Published: 4 Jun 2024
    6.4
    Medium

    CVE-2024-3888

    Last Modified: 15 Apr 2026

    The tagDiv Composer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's button shortcode in all versions up to, and including, 4.8 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. NOTE: The vulnerable code in this plugin is specifically tied to the tagDiv Newspaper theme. If another theme is installed (e.g., NewsMag), this code may not be present.

    Published: 4 Jun 2024
    9.8
    Critical

    CVE-2024-4552

    Last Modified: 15 Apr 2026

    The Social Login Lite For WooCommerce plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 1.6.0. This is due to insufficient verification on the user being supplied during the social login through the plugin. This makes it possible for unauthenticated attackers to log in as any existing user on the site, such as an administrator, if they have access to the email.

    Published: 4 Jun 2024
    7.2
    High

    CVE-2024-4870

    Last Modified: 15 Apr 2026

    The Frontend Registration – Contact Form 7 plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 5.1 due to insufficient restriction on the '_cf7frr_' post meta. This makes it possible for authenticated attackers, with editor-level access and above, to modify the default user role in the registration form settings.

    Published: 4 Jun 2024
    5.4
    Medium

    CVE-2024-0757

    Last Modified: 21 May 2025

    The Insert or Embed Articulate Content into WordPress plugin through 4.3000000023 is not properly filtering which file extensions are allowed to be imported on the server, allowing the uploading of malicious code within zip files

    Published: 4 Jun 2024
    6.5
    Medium

    CVE-2024-29976

    Last Modified: 22 Jan 2025

    ** UNSUPPORTED WHEN ASSIGNED ** The improper privilege management vulnerability in the command “show_allsessions” in Zyxel NAS326 firmware versions before V5.21(AAZF.17)C0 and NAS542 firmware versions before V5.21(ABAG.14)C0 could allow an authenticated attacker to obtain a logged-in administrator’s session information containing cookies on an affected device.

    Published: 4 Jun 2024
    6.7
    Medium

    CVE-2024-29975

    Last Modified: 22 Jan 2025

    ** UNSUPPORTED WHEN ASSIGNED ** The improper privilege management vulnerability in the SUID executable binary in Zyxel NAS326 firmware versions before V5.21(AAZF.17)C0 and NAS542 firmware versions before V5.21(ABAG.14)C0 could allow an authenticated local attacker with administrator privileges to execute some system commands as the “root” user on a vulnerable device.

    Published: 4 Jun 2024
    9.8
    Critical

    CVE-2024-29974

    Last Modified: 22 Jan 2025

    ** UNSUPPORTED WHEN ASSIGNED ** The remote code execution vulnerability in the CGI program “file_upload-cgi” in Zyxel NAS326 firmware versions before V5.21(AAZF.17)C0 and NAS542 firmware versions before V5.21(ABAG.14)C0 could allow an unauthenticated attacker to execute arbitrary code by uploading a crafted configuration file to a vulnerable device.

    Published: 4 Jun 2024
    9.8
    Critical

    CVE-2024-29973

    Last Modified: 22 Jan 2025

    ** UNSUPPORTED WHEN ASSIGNED ** The command injection vulnerability in the “setCookie” parameter in Zyxel NAS326 firmware versions before V5.21(AAZF.17)C0 and NAS542 firmware versions before V5.21(ABAG.14)C0 could allow an unauthenticated attacker to execute some operating system (OS) commands by sending a crafted HTTP POST request.

    Published: 4 Jun 2024
    9.8
    Critical

    CVE-2024-29972

    Last Modified: 22 Jan 2025

    ** UNSUPPORTED WHEN ASSIGNED ** The command injection vulnerability in the CGI program "remote_help-cgi" in Zyxel NAS326 firmware versions before V5.21(AAZF.17)C0 and NAS542 firmware versions before V5.21(ABAG.14)C0 could allow an unauthenticated attacker to execute some operating system (OS) commands by sending a crafted HTTP POST request.

    Published: 4 Jun 2024
    5.9
    Medium

    CVE-2023-1419

    Last Modified: 15 Apr 2026

    A script injection vulnerability was found in the Debezium database connector, where it does not properly sanitize some parameters. This flaw allows an attacker to send a malicious request to inject a parameter that may allow the viewing of unauthorized data.

    Published: 4 Jun 2024
    7.5
    High

    CVE-2024-34363

    Last Modified: 21 Nov 2024

    Envoy is a cloud-native, open source edge and service proxy. Due to how Envoy invoked the nlohmann JSON library, the library could throw an uncaught exception from downstream data if incomplete UTF-8 strings were serialized. The uncaught exception would cause Envoy to crash.

    Published: 4 Jun 2024
    5.5
    Medium

    CVE-2024-24789

    Last Modified: 13 Feb 2025

    The archive/zip package's handling of certain types of invalid zip files differs from the behavior of most zip implementations. This misalignment could be exploited to create an zip file with contents that vary depending on the implementation reading the file. The archive/zip package now rejects files containing these errors.

    Published: 4 Jun 2024
    9.8
    Critical

    CVE-2024-24790

    Last Modified: 13 Feb 2025

    The various Is methods (IsPrivate, IsLoopback, etc) did not work as expected for IPv4-mapped IPv6 addresses, returning false for addresses which would return true in their traditional IPv4 forms.

    Published: 4 Jun 2024
    5.9
    Medium

    CVE-2024-29152

    Last Modified: 27 Aug 2025

    An issue was discovered in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, Exynos 990, Exynos 1080, Exynos 2100, Exynos 2200, Exynos 1280, Exynos 1380, Exynos 1330, Exynos 2400, Exynos Modem 5123, and Exynos Modem 5300. The baseband software does not properly check states specified by the RRC (Radio Resource Control) Reconfiguration message. This can lead to disclosure of sensitive information.

    Published: 4 Jun 2024
    5.9
    Medium

    CVE-2024-23326

    Last Modified: 21 Nov 2024

    Envoy is a cloud-native, open source edge and service proxy. A theoretical request smuggling vulnerability exists through Envoy if a server can be tricked into adding an upgrade header into a response. Per RFC https://www.rfc-editor.org/rfc/rfc7230#section-6.7 a server sends 101 when switching protocols. Envoy incorrectly accepts a 200 response from a server when requesting a protocol upgrade, but 200 does not indicate protocol switch. This opens up the possibility of request smuggling through Envoy if the server can be tricked into adding the upgrade header to the response.

    Published: 4 Jun 2024
    5.4
    Medium

    CVE-2024-28103

    Last Modified: 6 Dec 2024

    Action Pack is a framework for handling and responding to web requests. Since 6.1.0, the application configurable Permissions-Policy is only served on responses with an HTML related Content-Type. This vulnerability is fixed in 6.1.7.8, 7.0.8.2, and 7.1.3.3.

    Published: 4 Jun 2024
    5.9
    Medium

    CVE-2024-32974

    Last Modified: 21 Nov 2024

    Envoy is a cloud-native, open source edge and service proxy. A crash was observed in `EnvoyQuicServerStream::OnInitialHeadersComplete()` with following call stack. It is a use-after-free caused by QUICHE continuing push request headers after `StopReading()` being called on the stream. As after `StopReading()`, the HCM's `ActiveStream` might have already be destroyed and any up calls from QUICHE could potentially cause use after free.

    Published: 4 Jun 2024
    7.5
    High

    CVE-2024-32976

    Last Modified: 21 Nov 2024

    Envoy is a cloud-native, open source edge and service proxy. Envoyproxy with a Brotli filter can get into an endless loop during decompression of Brotli data with extra input.

    Published: 4 Jun 2024
    5.9
    Medium

    CVE-2024-34362

    Last Modified: 21 Nov 2024

    Envoy is a cloud-native, open source edge and service proxy. There is a use-after-free in `HttpConnectionManager` (HCM) with `EnvoyQuicServerStream` that can crash Envoy. An attacker can exploit this vulnerability by sending a request without `FIN`, then a `RESET_STREAM` frame, and then after receiving the response, closing the connection.

    Published: 4 Jun 2024
    5.7
    Medium

    CVE-2024-34364

    Last Modified: 21 Nov 2024

    Envoy is a cloud-native, open source edge and service proxy. Envoy exposed an out-of-memory (OOM) vector from the mirror response, since async HTTP client will buffer the response with an unbounded buffer.

    Published: 4 Jun 2024
    5.9
    Medium

    CVE-2024-32975

    Last Modified: 21 Nov 2024

    Envoy is a cloud-native, open source edge and service proxy. There is a crash at `QuicheDataReader::PeekVarInt62Length()`. It is caused by integer underflow in the `QuicStreamSequencerBuffer::PeekRegion()` implementation.

    Published: 4 Jun 2024
    4.3
    Medium

    CVE-2023-28492

    Last Modified: 15 Apr 2026

    Missing Authorization vulnerability in CodePeople CP Multi View Event Calendar allows Functionality Misuse.This issue affects CP Multi View Event Calendar: from n/a through 1.4.10.

    Published: 3 Jun 2024
    4.3
    Medium

    CVE-2023-27460

    Last Modified: 12 Jul 2025

    Missing Authorization vulnerability in CodePeople, paypaldev CP Contact Form with Paypal allows Functionality Misuse.This issue affects CP Contact Form with Paypal: from n/a through 1.3.34.

    Published: 3 Jun 2024
    3.7
    Low

    CVE-2023-27437

    Last Modified: 15 Apr 2026

    Missing Authorization vulnerability in Event Espresso Event Espresso 4 Decaf allows Functionality Misuse.This issue affects Event Espresso 4 Decaf: from n/a through 4.10.44.Decaf.

    Published: 3 Jun 2024
    4.3
    Medium

    CVE-2023-26523

    Last Modified: 21 Nov 2024

    Missing Authorization vulnerability in CodePeople Calculated Fields Form allows Functionality Misuse.This issue affects Calculated Fields Form: from n/a through 1.1.120.

    Published: 3 Jun 2024
    4.3
    Medium

    CVE-2023-26521

    Last Modified: 15 Apr 2026

    Missing Authorization vulnerability in CodePeople Search in Place allows Functionality Misuse.This issue affects Search in Place: from n/a through 1.0.104.

    Published: 3 Jun 2024
    3.7
    Low

    CVE-2023-24373

    Last Modified: 28 Apr 2026

    External Control of Assumed-Immutable Web Parameter vulnerability in WpDevArt Booking calendar, Appointment Booking System allows Manipulating Hidden Fields.This issue affects Booking calendar, Appointment Booking System: from n/a through 3.2.3.

    Published: 3 Jun 2024
    5.3
    Medium

    CVE-2023-23738

    Last Modified: 28 Apr 2026

    Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') vulnerability in Brainstorm Force Spectra allows Content Spoofing, Phishing.This issue affects Spectra: from n/a through 2.3.0.

    Published: 3 Jun 2024
    5.3
    Medium

    CVE-2023-23735

    Last Modified: 1 Mar 2025

    Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Brainstorm Force Spectra allows Code Injection.This issue affects Spectra: from n/a through 2.3.0.

    Published: 3 Jun 2024
    5.3
    Medium

    CVE-2023-23730

    Last Modified: 10 Apr 2025

    Improper Restriction of Excessive Authentication Attempts vulnerability in Brainstorm Force Spectra allows Functionality Bypass.This issue affects Spectra: from n/a through 2.3.0.

    Published: 3 Jun 2024
    9.8
    Critical

    CVE-2024-36782

    Last Modified: 30 May 2025

    TOTOLINK CP300 V2.0.4-B20201102 was discovered to contain a hardcoded password vulnerability in /etc/shadow.sample, which allows attackers to log in as root.

    Published: 3 Jun 2024
    —
    Unknown

    CVE-2024-5610

    Last Modified: 8 Jan 2025

    loading template...

    Published: 3 Jun 2024
    9.8
    Critical

    CVE-2024-36783

    Last Modified: 4 Apr 2025

    TOTOLINK LR350 V9.3.5u.6369_B20220309 was discovered to contain a command injection via the host_time parameter in the NTPSyncWithHost function.

    Published: 3 Jun 2024
    —
    Unknown

    CVE-2024-5609

    Last Modified: 6 Jun 2024

    ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2023-6966. Reason: This candidate is a reservation duplicate of CVE-2023-6966. Notes: All CVE users should reference CVE-2023-6966 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage.

    Published: 3 Jun 2024
    6.7
    Medium

    CVE-2023-52162

    Last Modified: 15 Apr 2026

    Mercusys MW325R EU V3 (Firmware MW325R(EU)_V3_1.11.0 Build 221019) is vulnerable to a stack-based buffer overflow, which could allow an attacker to execute arbitrary code. Exploiting the vulnerability requires authentication.

    Published: 3 Jun 2024
    4.6
    Medium

    CVE-2024-34051

    Last Modified: 15 Apr 2026

    A Reflected Cross-site scripting (XSS) vulnerability located in htdocs/compta/paiement/card.php of Dolibarr before 19.0.2 allows remote attackers to inject arbitrary web script or HTML via a crafted payload injected into the facid parameter.

    Published: 3 Jun 2024
    9.8
    Critical

    CVE-2024-31682

    Last Modified: 15 Apr 2026

    Incorrect access control in the fingerprint authentication mechanism of Phone Cleaner: Boost & Clean v2.2.0 allows attackers to bypass fingerprint authentication due to the use of a deprecated API.

    Published: 3 Jun 2024
    3.5
    Low

    CVE-2024-31684

    Last Modified: 15 Apr 2026

    Incorrect access control in the fingerprint authentication mechanism of Bitdefender Mobile Security v4.11.3-gms allows attackers to bypass fingerprint authentication due to the use of a deprecated API.

    Published: 3 Jun 2024
    7.8
    High

    CVE-2022-1242

    Last Modified: 22 Aug 2025

    Apport can be tricked into connecting to arbitrary sockets as the root user

    Published: 3 Jun 2024
    7.8
    High

    CVE-2021-3899

    Last Modified: 26 Aug 2025

    There is a race condition in the 'replaced executable' detection that, with the correct local configuration, allow an attacker to execute arbitrary code as root.

    Published: 3 Jun 2024
    8.4
    High

    CVE-2022-0555

    Last Modified: 26 Aug 2025

    Subiquity Shows Guided Storage Passphrase in Plaintext with Read-all Permissions

    Published: 3 Jun 2024
    9.8
    Critical

    CVE-2024-37019

    Last Modified: 15 Apr 2026

    Northern.tech Mender Enterprise before 3.6.4 and 3.7.x before 3.7.4 has Weak Authentication.

    Published: 3 Jun 2024
    9.3
    Critical

    CVE-2024-4332

    Last Modified: 15 Apr 2026

    An authentication bypass vulnerability has been identified in the REST and SOAP API components of Tripwire Enterprise (TE) 9.1.0 when TE is configured to use LDAP/Active Directory SAML authentication and its optional "Auto-synchronize LDAP Users, Roles, and Groups" feature is enabled. This vulnerability allows unauthenticated attackers to bypass authentication if a valid username is known. Exploitation of this vulnerability could allow remote attackers to gain privileged access to the APIs and lead to unauthorized information disclosure or modification.

    Published: 3 Jun 2024
    6.1
    Medium

    CVE-2024-36674

    Last Modified: 17 Jun 2025

    LyLme_spage v1.9.5 is vulnerable to Cross Site Scripting (XSS) via admin/link.php.

    Published: 3 Jun 2024
    8.2
    High

    CVE-2024-32983

    Last Modified: 25 Nov 2025

    Misskey is an open source, decentralized microblogging platform. Misskey doesn't perform proper normalization on the JSON structures of incoming signed ActivityPub activity objects before processing them, allowing threat actors to spoof the contents of signed activities and impersonate the authors of the original activities. This vulnerability is fixed in 2024.5.0.

    Published: 3 Jun 2024