CVE Feed

    Dashboard / CVE

    6.7
    Medium

    CVE-2023-52162

    Last Modified: 15 Apr 2026

    Mercusys MW325R EU V3 (Firmware MW325R(EU)_V3_1.11.0 Build 221019) is vulnerable to a stack-based buffer overflow, which could allow an attacker to execute arbitrary code. Exploiting the vulnerability requires authentication.

    Published: 3 Jun 2024
    4.6
    Medium

    CVE-2024-34051

    Last Modified: 15 Apr 2026

    A Reflected Cross-site scripting (XSS) vulnerability located in htdocs/compta/paiement/card.php of Dolibarr before 19.0.2 allows remote attackers to inject arbitrary web script or HTML via a crafted payload injected into the facid parameter.

    Published: 3 Jun 2024
    9.8
    Critical

    CVE-2024-31682

    Last Modified: 15 Apr 2026

    Incorrect access control in the fingerprint authentication mechanism of Phone Cleaner: Boost & Clean v2.2.0 allows attackers to bypass fingerprint authentication due to the use of a deprecated API.

    Published: 3 Jun 2024
    3.5
    Low

    CVE-2024-31684

    Last Modified: 15 Apr 2026

    Incorrect access control in the fingerprint authentication mechanism of Bitdefender Mobile Security v4.11.3-gms allows attackers to bypass fingerprint authentication due to the use of a deprecated API.

    Published: 3 Jun 2024
    7.8
    High

    CVE-2022-1242

    Last Modified: 22 Aug 2025

    Apport can be tricked into connecting to arbitrary sockets as the root user

    Published: 3 Jun 2024
    7.8
    High

    CVE-2021-3899

    Last Modified: 26 Aug 2025

    There is a race condition in the 'replaced executable' detection that, with the correct local configuration, allow an attacker to execute arbitrary code as root.

    Published: 3 Jun 2024
    8.4
    High

    CVE-2022-0555

    Last Modified: 26 Aug 2025

    Subiquity Shows Guided Storage Passphrase in Plaintext with Read-all Permissions

    Published: 3 Jun 2024
    9.8
    Critical

    CVE-2024-37019

    Last Modified: 15 Apr 2026

    Northern.tech Mender Enterprise before 3.6.4 and 3.7.x before 3.7.4 has Weak Authentication.

    Published: 3 Jun 2024
    9.3
    Critical

    CVE-2024-4332

    Last Modified: 15 Apr 2026

    An authentication bypass vulnerability has been identified in the REST and SOAP API components of Tripwire Enterprise (TE) 9.1.0 when TE is configured to use LDAP/Active Directory SAML authentication and its optional "Auto-synchronize LDAP Users, Roles, and Groups" feature is enabled. This vulnerability allows unauthenticated attackers to bypass authentication if a valid username is known. Exploitation of this vulnerability could allow remote attackers to gain privileged access to the APIs and lead to unauthorized information disclosure or modification.

    Published: 3 Jun 2024
    6.1
    Medium

    CVE-2024-36674

    Last Modified: 17 Jun 2025

    LyLme_spage v1.9.5 is vulnerable to Cross Site Scripting (XSS) via admin/link.php.

    Published: 3 Jun 2024
    8.2
    High

    CVE-2024-32983

    Last Modified: 25 Nov 2025

    Misskey is an open source, decentralized microblogging platform. Misskey doesn't perform proper normalization on the JSON structures of incoming signed ActivityPub activity objects before processing them, allowing threat actors to spoof the contents of signed activities and impersonate the authors of the original activities. This vulnerability is fixed in 2024.5.0.

    Published: 3 Jun 2024
    7.5
    High

    CVE-2024-36128

    Last Modified: 3 Jan 2025

    Directus is a real-time API and App dashboard for managing SQL database content. Prior to 10.11.2, providing a non-numeric length value to the random string generation utility will create a memory issue breaking the capability to generate random strings platform wide. This creates a denial of service situation where logged in sessions can no longer be refreshed as sessions depend on the capability to generate a random session ID. This vulnerability is fixed in 10.11.2.

    Published: 3 Jun 2024
    7.5
    High

    CVE-2024-36127

    Last Modified: 15 Apr 2026

    apko is an apk-based OCI image builder. apko exposures HTTP basic auth credentials from repository and keyring URLs in log output. This vulnerability is fixed in v0.14.5.

    Published: 3 Jun 2024
    5.3
    Medium

    CVE-2024-36124

    Last Modified: 12 Jul 2025

    iq80 Snappy is a compression/decompression library. When uncompressing certain data, Snappy tries to read outside the bounds of the given byte arrays. Because Snappy uses the JDK class `sun.misc.Unsafe` to speed up memory access, no additional bounds checks are performed and this has similar security consequences as out-of-bounds access in C or C++, namely it can lead to non-deterministic behavior or crash the JVM. iq80 Snappy is not actively maintained anymore. As quick fix users can upgrade to version 0.5.

    Published: 3 Jun 2024
    6.5
    Medium

    CVE-2024-36123

    Last Modified: 22 Aug 2025

    Citizen is a MediaWiki skin that makes extensions part of the cohesive experience. The page `MediaWiki:Tagline` has its contents used unescaped, so custom HTML (including Javascript) can be injected by someone with the ability to edit the MediaWiki namespace (typically those with the `editinterface` permission, or sysops). This vulnerability is fixed in 2.16.0.

    Published: 3 Jun 2024
    9.4
    Critical

    CVE-2024-0336

    Last Modified: 3 Jun 2026

    Missing Authentication for Critical Function vulnerability in EMTA Grup PDKS allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects PDKS: from V3.04 before 20240603. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 3 Jun 2024
    8.1
    High

    CVE-2024-36728

    Last Modified: 1 Apr 2025

    TRENDnet TEW-827DRU devices through 2.06B04 contain a stack-based buffer overflow in the ssi binary. The overflow allows an authenticated user to execute arbitrary code by POSTing to apply.cgi via the action vlan_setting with a sufficiently long dns1 or dns 2 key.

    Published: 3 Jun 2024
    6.3
    Medium

    CVE-2024-36729

    Last Modified: 1 Apr 2025

    TRENDnet TEW-827DRU devices through 2.06B04 contain a stack-based buffer overflow in the ssi binary. The overflow allows an authenticated user to execute arbitrary code by POSTing to apply.cgi via the action wizard_ipv6 with a sufficiently long reboot_type key.

    Published: 3 Jun 2024
    5.9
    Medium

    CVE-2024-5197

    Last Modified: 22 Jul 2025

    There exists interger overflows in libvpx in versions prior to 1.14.1. Calling vpx_img_alloc() with a large value of the d_w, d_h, or align parameter may result in integer overflows in the calculations of buffer sizes and offsets and some fields of the returned vpx_image_t struct may be invalid. Calling vpx_img_wrap() with a large value of the d_w, d_h, or stride_align parameter may result in integer overflows in the calculations of buffer sizes and offsets and some fields of the returned vpx_image_t struct may be invalid. We recommend upgrading to version 1.14.1 or beyond

    Published: 3 Jun 2024
    8.1
    High

    CVE-2024-36569

    Last Modified: 11 Apr 2025

    Sourcecodester Gas Agency Management System v1.0 is vulnerable to arbitrary code execution via editClientImage.php.

    Published: 3 Jun 2024
    9.8
    Critical

    CVE-2024-36568

    Last Modified: 11 Apr 2025

    Sourcecodester Gas Agency Management System v1.0 is vulnerable to SQL Injection via /gasmark/editbrand.php?id=.

    Published: 3 Jun 2024
    4.3
    Medium

    CVE-2024-35632

    Last Modified: 15 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in CRM Perks. Integration for Contact Form 7 and Constant Contact.This issue affects Integration for Contact Form 7 and Constant Contact: from n/a through 1.1.5.

    Published: 3 Jun 2024
    5.9
    Medium

    CVE-2024-34385

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in YITHEMES YITH WooCommerce Wishlist yith-woocommerce-wishlist.This issue affects YITH WooCommerce Wishlist: from n/a through <= 3.32.0.

    Published: 3 Jun 2024
    —
    Unknown

    CVE-2024-34764

    Last Modified: 2 Feb 2026

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. Collision with another CVE ID.

    Published: 3 Jun 2024
    6.5
    Medium

    CVE-2024-34766

    Last Modified: 15 Apr 2026

    Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Automattic ChaosTheory allows Stored XSS.This issue affects ChaosTheory: from n/a through 1.3.

    Published: 3 Jun 2024
    6.5
    Medium

    CVE-2024-34767

    Last Modified: 25 Nov 2025

    Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in HasThemes ShopLentor allows Stored XSS.This issue affects ShopLentor: from n/a through 2.8.7.

    Published: 3 Jun 2024
    6.5
    Medium

    CVE-2024-34769

    Last Modified: 15 Apr 2026

    Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in cyclonetheme Elegant Blocks allows Stored XSS.This issue affects Elegant Blocks: from n/a through 1.7.

    Published: 3 Jun 2024
    6.5
    Medium

    CVE-2024-34770

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Popup Maker Popup Maker WP popup-maker-wp allows Stored XSS.This issue affects Popup Maker WP: from n/a through <= 1.3.6.

    Published: 3 Jun 2024
    6.5
    Medium

    CVE-2024-34789

    Last Modified: 15 Apr 2026

    Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WP Hait Post Grid Elementor Addon allows Stored XSS.This issue affects Post Grid Elementor Addon: from n/a through 2.0.16.

    Published: 3 Jun 2024
    5.9
    Medium

    CVE-2024-34790

    Last Modified: 28 Apr 2026

    Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Hans van Eijsden,niwreg ImageMagick Sharpen Resized Images allows Stored XSS.This issue affects ImageMagick Sharpen Resized Images: from n/a through 1.1.7.

    Published: 3 Jun 2024
    6.5
    Medium

    CVE-2024-34791

    Last Modified: 26 Feb 2025

    Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in wpbean WPB Elementor Addons allows Stored XSS.This issue affects WPB Elementor Addons: from n/a through 1.0.9.

    Published: 3 Jun 2024
    5.9
    Medium

    CVE-2024-34793

    Last Modified: 15 Apr 2026

    Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Kharim Tomlinson WP Next Post Navi allows Stored XSS.This issue affects WP Next Post Navi: from n/a through 1.8.3.

    Published: 3 Jun 2024
    7.1
    High

    CVE-2024-34794

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in tainacan Tainacan tainacan.This issue affects Tainacan: from n/a through <= 0.21.3.

    Published: 3 Jun 2024
    6.5
    Medium

    CVE-2024-34795

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in tainacan Tainacan tainacan.This issue affects Tainacan: from n/a through <= 0.21.3.

    Published: 3 Jun 2024
    5.9
    Medium

    CVE-2024-34796

    Last Modified: 3 Apr 2025

    Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in AccessAlly PopupAlly allows Stored XSS.This issue affects PopupAlly: from n/a through 2.1.1.

    Published: 3 Jun 2024
    5.9
    Medium

    CVE-2024-34797

    Last Modified: 15 Apr 2026

    Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Benoit Mercusot Simple Popup Manager allows Stored XSS.This issue affects Simple Popup Manager: from n/a through 1.3.5.

    Published: 3 Jun 2024
    6.5
    Medium

    CVE-2024-34801

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Mervin Praison Praison SEO WordPress seo-wordpress allows DOM-Based XSS.This issue affects Praison SEO WordPress: from n/a through <= 4.0.15.

    Published: 3 Jun 2024
    7.1
    High

    CVE-2024-35631

    Last Modified: 15 Apr 2026

    Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Foliovision FV Flowplayer Video Player allows Reflected XSS.This issue affects FV Flowplayer Video Player: from n/a through 7.5.45.7212.

    Published: 3 Jun 2024
    7.6
    High

    CVE-2024-35630

    Last Modified: 15 Apr 2026

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in LJ Apps WP TripAdvisor Review Slider allows Blind SQL Injection.This issue affects WP TripAdvisor Review Slider: from n/a through 12.6.

    Published: 3 Jun 2024
    5.3
    Medium

    CVE-2024-34754

    Last Modified: 15 Apr 2026

    Exposure of Sensitive Information to an Unauthorized Actor vulnerability in A WP Life Contact Form Widget.This issue affects Contact Form Widget: from n/a through 1.3.9.

    Published: 3 Jun 2024
    5.3
    Medium

    CVE-2024-34798

    Last Modified: 15 Apr 2026

    Insertion of Sensitive Information into Log File vulnerability in Lukman Nakib Debug Log – Manger Tool.This issue affects Debug Log – Manger Tool: from n/a through 1.4.5.

    Published: 3 Jun 2024
    4.3
    Medium

    CVE-2024-34803

    Last Modified: 15 Apr 2026

    Missing Authorization vulnerability in Fastly.This issue affects Fastly: from n/a through 1.2.25.

    Published: 3 Jun 2024
    9.1
    Critical

    CVE-2024-3829

    Last Modified: 15 Oct 2025

    qdrant/qdrant version 1.9.0-dev is vulnerable to arbitrary file read and write during the snapshot recovery process. Attackers can exploit this vulnerability by manipulating snapshot files to include symlinks, leading to arbitrary file read by adding a symlink that points to a desired file on the filesystem and arbitrary file write by including a symlink and a payload file in the snapshot's directory structure. This vulnerability allows for the reading and writing of arbitrary files on the server, which could potentially lead to a full takeover of the system. The issue is fixed in version v1.9.0.

    Published: 3 Jun 2024
    7.5
    High

    CVE-2024-23363

    Last Modified: 9 Jan 2025

    Transient DOS while processing an improperly formatted Fine Time Measurement (FTM) management frame.

    Published: 3 Jun 2024
    8.4
    High

    CVE-2024-23360

    Last Modified: 9 Jan 2025

    Memory corruption while creating a LPAC client as LPAC engine was allowed to access GPU registers.

    Published: 3 Jun 2024
    6.2
    Medium

    CVE-2024-21478

    Last Modified: 27 Jan 2025

    transient DOS when setting up a fence callback to free a KGSL memory entry object during DMA.

    Published: 3 Jun 2024
    9.3
    Critical

    CVE-2023-43556

    Last Modified: 11 Aug 2025

    Memory corruption in Hypervisor when platform information mentioned is not aligned.

    Published: 3 Jun 2024
    8.2
    High

    CVE-2023-43555

    Last Modified: 11 Aug 2025

    Information disclosure in Video while parsing mp2 clip with invalid section length.

    Published: 3 Jun 2024
    9.1
    Critical

    CVE-2023-43551

    Last Modified: 11 Aug 2025

    Cryptographic issue while performing attach with a LTE network, a rogue base station can skip the authentication phase and immediately send the Security Mode Command.

    Published: 3 Jun 2024
    6.7
    Medium

    CVE-2023-43545

    Last Modified: 27 Jan 2025

    Memory corruption when more scan frequency list or channels are sent from the user space.

    Published: 3 Jun 2024