CVE Feed

    Dashboard / CVE

    6.7
    Medium

    CVE-2023-43544

    Last Modified: 27 Jan 2025

    Memory corruption when IPC callback handle is used after it has been released during register callback by another thread.

    Published: 3 Jun 2024
    6.7
    Medium

    CVE-2023-43543

    Last Modified: 27 Jan 2025

    Memory corruption in Audio during a playback or a recording due to race condition between allocation and deallocation of graph object.

    Published: 3 Jun 2024
    7.8
    High

    CVE-2023-43542

    Last Modified: 11 Aug 2025

    Memory corruption while copying a keyblob`s material when the key material`s size is not accurately checked.

    Published: 3 Jun 2024
    9.3
    Critical

    CVE-2023-43538

    Last Modified: 27 Jan 2025

    Memory corruption in TZ Secure OS while Tunnel Invoke Manager initialization.

    Published: 3 Jun 2024
    6.5
    Medium

    CVE-2023-43537

    Last Modified: 11 Aug 2025

    Information disclosure while handling T2LM Action Frame in WLAN Host.

    Published: 3 Jun 2024
    4.4
    Medium

    CVE-2024-35633

    Last Modified: 23 Apr 2026

    Server-Side Request Forgery (SSRF) vulnerability in Creative Themes Blocksy Companion blocksy-companion.This issue affects Blocksy Companion: from n/a through <= 2.0.42.

    Published: 3 Jun 2024
    4.4
    Medium

    CVE-2024-35635

    Last Modified: 3 Apr 2025

    Server-Side Request Forgery (SSRF) vulnerability in WPManageNinja LLC Ninja Tables.This issue affects Ninja Tables: from n/a through 5.0.9.

    Published: 3 Jun 2024
    5.9
    Medium

    CVE-2024-23665

    Last Modified: 17 Dec 2024

    Multiple improper authorization vulnerabilities [CWE-285] in FortiWeb version 7.4.2 and below, version 7.2.7 and below, version 7.0.10 and below, version 6.4.3 and below, version 6.3.23 and below may allow an authenticated attacker to perform unauthorized ADOM operations via crafted requests.

    Published: 3 Jun 2024
    6.1
    Medium

    CVE-2024-23664

    Last Modified: 21 Jan 2025

    A URL redirection to untrusted site ('open redirect') in Fortinet FortiAuthenticator version 6.6.0, version 6.5.3 and below, version 6.4.9 and below may allow an attacker to to redirect users to an arbitrary website via a crafted URL.

    Published: 3 Jun 2024
    7.8
    High

    CVE-2024-23667

    Last Modified: 8 Jul 2026

    An improper authorization in Fortinet FortiWebManager 7.2.0, FortiWebManager 7.0.0 through 7.0.4, FortiWebManager 6.3.0, FortiWebManager 6.2.3 through 6.2.4, FortiWebManager 6.0.2 allows attacker to execute unauthorized code or commands via HTTP requests or CLI.

    Published: 3 Jun 2024
    8.8
    High

    CVE-2024-23668

    Last Modified: 8 Jul 2026

    An improper authorization in Fortinet FortiWebManager 7.2.0, FortiWebManager 7.0.0 through 7.0.4, FortiWebManager 6.3.0, FortiWebManager 6.2.3 through 6.2.4, FortiWebManager 6.0.2 allows attacker to execute unauthorized code or commands via HTTP requests or CLI.

    Published: 3 Jun 2024
    7.8
    High

    CVE-2024-23670

    Last Modified: 8 Jul 2026

    An improper authorization in Fortinet FortiWebManager 7.2.0, FortiWebManager 7.0.0 through 7.0.4, FortiWebManager 6.3.0, FortiWebManager 6.2.3 through 6.2.4, FortiWebManager 6.0.2 allows attacker to execute unauthorized code or commands via HTTP requests or CLI.

    Published: 3 Jun 2024
    9.8
    Critical

    CVE-2024-5404

    Last Modified: 15 Apr 2026

    An unauthenticated remote attacker can change the admin password in a moneo appliance due to weak password recovery mechanism.

    Published: 3 Jun 2024
    4.4
    Medium

    CVE-2024-35637

    Last Modified: 23 Apr 2026

    Server-Side Request Forgery (SSRF) vulnerability in andy_moyle Church Admin church-admin.This issue affects Church Admin: from n/a through <= 4.3.6.

    Published: 3 Jun 2024
    4.3
    Medium

    CVE-2024-35638

    Last Modified: 15 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in JumpDEMAND Inc. ActiveDEMAND.This issue affects ActiveDEMAND: from n/a through 0.2.43.

    Published: 3 Jun 2024
    5.9
    Medium

    CVE-2024-35639

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Webliberty Simple Spoiler simple-spoiler.This issue affects Simple Spoiler: from n/a through <= 1.2.

    Published: 3 Jun 2024
    4.3
    Medium

    CVE-2023-48789

    Last Modified: 2 Jan 2025

    A client-side enforcement of server-side security in Fortinet FortiPortal version 6.0.0 through 6.0.14 allows attacker to improper access control via crafted HTTP requests.

    Published: 3 Jun 2024
    6.5
    Medium

    CVE-2024-31493

    Last Modified: 21 Jan 2025

    An improper removal of sensitive information before storage or transfer vulnerability [CWE-212] in FortiSOAR version 7.3.0, version 7.2.2 and below, version 7.0.3 and below may allow an authenticated low privileged user to read Connector passwords in plain-text via HTTP responses.

    Published: 3 Jun 2024
    5.5
    Medium

    CVE-2024-23107

    Last Modified: 17 Dec 2024

    An exposure of sensitive information to an unauthorized actor vulnerability [CWE-200] in FortiWeb version 7.4.0, version 7.2.4 and below, version 7.0.8 and below, 6.3 all versions may allow an authenticated attacker to read password hashes of other administrators via CLI commands.

    Published: 3 Jun 2024
    5.9
    Medium

    CVE-2024-35640

    Last Modified: 28 Apr 2026

    Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Tomas Cordero Safety Exit allows Stored XSS.This issue affects Safety Exit: from n/a through 1.7.0.

    Published: 3 Jun 2024
    5.9
    Medium

    CVE-2024-35641

    Last Modified: 15 Apr 2026

    Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in GregRoss Just Writing Statistics allows Stored XSS.This issue affects Just Writing Statistics: from n/a through 4.5.

    Published: 3 Jun 2024
    5.9
    Medium

    CVE-2024-35642

    Last Modified: 15 Apr 2026

    Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Bryan Hadaway Site Favicon allows Stored XSS.This issue affects Site Favicon: from n/a through 0.2.

    Published: 3 Jun 2024
    5.9
    Medium

    CVE-2024-35643

    Last Modified: 15 Apr 2026

    Cross Site Scripting (XSS) vulnerability in Xabier Miranda WP Back Button allows Stored XSS.This issue affects WP Back Button: from n/a through 1.1.3.

    Published: 3 Jun 2024
    9.8
    Critical

    CVE-2024-5311

    Last Modified: 15 Apr 2026

    DigiWin EasyFlow .NET lacks validation for certain input parameters. An unauthenticated remote attacker can inject arbitrary SQL commands to read, modify, and delete database records.

    Published: 3 Jun 2024
    6.1
    Medium

    CVE-2024-37031

    Last Modified: 15 Apr 2026

    The Active Admin (aka activeadmin) framework before 3.2.2 for Ruby on Rails allows stored XSS in certain situations where users can create entities (to be later edited in forms) with arbitrary names, aka a "dynamic form legends" issue. 4.0.0.beta7 is also a fixed version.

    Published: 3 Jun 2024
    9.8
    Critical

    CVE-2024-36042

    Last Modified: 29 May 2025

    Silverpeas before 6.3.5 allows authentication bypass by omitting the Password field to AuthenticationServlet, often providing an unauthenticated user with superadmin access.

    Published: 3 Jun 2024
    5.9
    Medium

    CVE-2023-51436

    Last Modified: 15 Apr 2026

    Cross-site scripting vulnerability exists in UNIVERSAL PASSPORT RX versions 1.0.0 to 1.0.8, which may allow a remote authenticated attacker with an administrative privilege to execute an arbitrary script on the web browser of the user who is using the product.

    Published: 3 Jun 2024
    6.5
    Medium

    CVE-2023-42427

    Last Modified: 15 Apr 2026

    Cross-site scripting vulnerability exists in UNIVERSAL PASSPORT RX versions 1.0.0 to 1.0.7, which may allow a remote authenticated attacker to execute an arbitrary script on the web browser of the user who is using the product.

    Published: 3 Jun 2024
    6.7
    Medium

    CVE-2024-20075

    Last Modified: 13 Mar 2025

    In eemgpu, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08713302; Issue ID: MSV-1393.

    Published: 3 Jun 2024
    6.6
    Medium

    CVE-2024-20074

    Last Modified: 25 Apr 2025

    In dmc, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08668110; Issue ID: MSV-1333.

    Published: 3 Jun 2024
    6.6
    Medium

    CVE-2024-20073

    Last Modified: 25 Apr 2025

    In wlan service, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00367704; Issue ID: MSV-1411.

    Published: 3 Jun 2024
    6.6
    Medium

    CVE-2024-20072

    Last Modified: 25 Apr 2025

    In wlan driver, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00364732; Issue ID: MSV-1332.

    Published: 3 Jun 2024
    4.4
    Medium

    CVE-2024-20071

    Last Modified: 25 Apr 2025

    In wlan driver, there is a possible out of bounds read due to improper input validation. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00364733; Issue ID: MSV-1331.

    Published: 3 Jun 2024
    5.1
    Medium

    CVE-2024-20070

    Last Modified: 25 Apr 2025

    In modem, there is a possible information disclosure due to using risky cryptographic algorithm during connection establishment negotiation. This could lead to remote information disclosure, when weak encryption algorithm is used, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY00942482; Issue ID: MSV-1469.

    Published: 3 Jun 2024
    6.5
    Medium

    CVE-2024-20069

    Last Modified: 25 Apr 2025

    In modem, there is a possible selection of less-secure algorithm during the VoWiFi IKE due to a missing DH downgrade check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01286330; Issue ID: MSV-1430.

    Published: 3 Jun 2024
    5.9
    Medium

    CVE-2024-20068

    Last Modified: 25 Apr 2025

    In modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service with no additional execution privileges needed. User interaction is no needed for exploitation. Patch ID: MOLY01270721; Issue ID: MSV-1479.

    Published: 3 Jun 2024
    9.8
    Critical

    CVE-2024-20067

    Last Modified: 25 Apr 2025

    In modem, there is a possible out of bounds write due to improper input invalidation. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01267285; Issue ID: MSV-1462.

    Published: 3 Jun 2024
    7.5
    High

    CVE-2024-20066

    Last Modified: 27 Mar 2025

    In modem, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is no needed for exploitation. Patch ID: MOLY01267281; Issue ID: MSV-1477.

    Published: 3 Jun 2024
    4
    Medium

    CVE-2024-20065

    Last Modified: 25 Apr 2025

    In telephony, there is a possible information disclosure due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08698617; Issue ID: MSV-1394.

    Published: 3 Jun 2024
    5.3
    Medium

    CVE-2024-5590

    Last Modified: 7 Feb 2025

    A vulnerability was found in Netentsec NS-ASG Application Security Gateway 6.3. It has been declared as critical. This vulnerability affects unknown code of the file /protocol/iscuser/uploadiscuser.php of the component JSON Content Handler. The manipulation of the argument messagecontent leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-266848. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 3 Jun 2024
    5.3
    Medium

    CVE-2024-5589

    Last Modified: 7 Feb 2025

    A vulnerability was found in Netentsec NS-ASG Application Security Gateway 6.3. It has been classified as critical. This affects an unknown part of the file /admin/config_MT.php?action=delete. The manipulation of the argument Mid leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-266847. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 3 Jun 2024
    4.9
    Medium

    CVE-2025-0620

    Last Modified: 29 Jun 2026

    A flaw was found in Samba. The smbd service daemon does not pick up group membership changes when re-authenticating an expired SMB session. This issue can expose file shares until clients disconnect and then connect again.

    Published: 3 Jun 2024
    7.5
    High

    CVE-2024-36962

    Last Modified: 4 Aug 2026

    In the Linux kernel, the following vulnerability has been resolved: net: ks8851: Queue RX packets in IRQ handler instead of disabling BHs Currently the driver uses local_bh_disable()/local_bh_enable() in its IRQ handler to avoid triggering net_rx_action() softirq on exit from netif_rx(). The net_rx_action() could trigger this driver .start_xmit callback, which is protected by the same lock as the IRQ handler, so calling the .start_xmit from netif_rx() from the IRQ handler critical section protected by the lock could lead to an attempt to claim the already claimed lock, and a hang. The local_bh_disable()/local_bh_enable() approach works only in case the IRQ handler is protected by a spinlock, but does not work if the IRQ handler is protected by mutex, i.e. this works for KS8851 with Parallel bus interface, but not for KS8851 with SPI bus interface. Remove the BH manipulation and instead of calling netif_rx() inside the IRQ handler code protected by the lock, queue all the received SKBs in the IRQ handler into a queue first, and once the IRQ handler exits the critical section protected by the lock, dequeue all the queued SKBs and push them all into netif_rx(). At this point, it is safe to trigger the net_rx_action() softirq, since the netif_rx() call is outside of the lock that protects the IRQ handler.

    Published: 3 Jun 2024
    7.8
    High

    CVE-2024-36961

    Last Modified: 4 Aug 2026

    In the Linux kernel, the following vulnerability has been resolved: thermal/debugfs: Fix two locking issues with thermal zone debug With the current thermal zone locking arrangement in the debugfs code, user space can open the "mitigations" file for a thermal zone before the zone's debugfs pointer is set which will result in a NULL pointer dereference in tze_seq_start(). Moreover, thermal_debug_tz_remove() is not called under the thermal zone lock, so it can run in parallel with the other functions accessing the thermal zone's struct thermal_debugfs object. Then, it may clear tz->debugfs after one of those functions has checked it and the struct thermal_debugfs object may be freed prematurely. To address the first problem, pass a pointer to the thermal zone's struct thermal_debugfs object to debugfs_create_file() in thermal_debug_tz_add() and make tze_seq_start(), tze_seq_next(), tze_seq_stop(), and tze_seq_show() retrieve it from s->private instead of a pointer to the thermal zone object. This will ensure that tz_debugfs will be valid across the "mitigations" file accesses until thermal_debugfs_remove_id() called by thermal_debug_tz_remove() removes that file. To address the second problem, use tz->lock in thermal_debug_tz_remove() around the tz->debugfs value check (in case the same thermal zone is removed at the same time in two different threads) and its reset to NULL. Cc :6.8+ <[email protected]> # 6.8+

    Published: 3 Jun 2024
    7.5
    High

    CVE-2024-4540

    Last Modified: 15 Apr 2026

    A flaw was found in Keycloak in OAuth 2.0 Pushed Authorization Requests (PAR). Client-provided parameters were found to be included in plain text in the KC_RESTART cookie returned by the authorization server's HTTP response to a `request_uri` authorization request, possibly leading to an information disclosure vulnerability.

    Published: 3 Jun 2024
    8.8
    High

    CVE-2024-25131

    Last Modified: 15 Apr 2026

    A flaw was found in the MustGather.managed.openshift.io Custom Defined Resource (CRD) of OpenShift Dedicated. A non-privileged user on the cluster can create a MustGather object with a specially crafted file and set the most privileged service account to run the job. This can allow a standard developer user to escalate their privileges to a cluster administrator and pivot to the AWS environment.

    Published: 3 Jun 2024
    8.8
    High

    CVE-2024-36964

    Last Modified: 4 Aug 2026

    In the Linux kernel, the following vulnerability has been resolved: fs/9p: only translate RWX permissions for plain 9P2000 Garbage in plain 9P2000's perm bits is allowed through, which causes it to be able to set (among others) the suid bit. This was presumably not the intent since the unix extended bits are handled explicitly and conditionally on .u.

    Published: 3 Jun 2024
    9.6
    Critical

    CVE-2023-51219

    Last Modified: 15 Apr 2026

    A deep link validation issue in KakaoTalk 10.4.3 allowed a remote adversary to direct users to run any attacker-controlled JavaScript within a WebView. The impact was further escalated by triggering another WebView that leaked its access token in a HTTP request header. Ultimately, this access token could be used to take over another user's account and read her/his chat messages.

    Published: 3 Jun 2024
    9.1
    Critical

    CVE-2024-34987

    Last Modified: 3 Apr 2025

    A SQL Injection vulnerability exists in the `ofrs/admin/index.php` script of PHPGurukul Online Fire Reporting System 1.2. The vulnerability allows attackers to bypass authentication and gain unauthorized access by injecting SQL commands into the username input field during the login process.

    Published: 3 Jun 2024
    7.1
    High

    CVE-2024-36960

    Last Modified: 4 May 2025

    In the Linux kernel, the following vulnerability has been resolved: drm/vmwgfx: Fix invalid reads in fence signaled events Correctly set the length of the drm_event to the size of the structure that's actually used. The length of the drm_event was set to the parent structure instead of to the drm_vmw_event_fence which is supposed to be read. drm_read uses the length parameter to copy the event to the user space thus resuling in oob reads.

    Published: 3 Jun 2024