CVE Feed

    Dashboard / CVE

    4.3
    Medium

    CVE-2024-0437

    Last Modified: 15 Apr 2026

    The Password Protected – Ultimate Plugin to Password Protect Your WordPress Content with Ease plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.6.6 via the API. This makes it possible for authenticated attackers, with subscriber access or higher, to extract post titles and content, thus bypassing the plugin's password protection.

    Published: 14 May 2024
    6.4
    Medium

    CVE-2024-4370

    Last Modified: 8 Apr 2026

    The WPZOOM Addons for Elementor (Templates, Widgets) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's widget Image Box in all versions up to, and including, 1.1.36 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 14 May 2024
    6.4
    Medium

    CVE-2024-4363

    Last Modified: 15 Apr 2026

    The Visual Portfolio, Photo Gallery & Post Grid plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘title_tag’ parameter in all versions up to, and including, 3.3.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 14 May 2024
    4.9
    Medium

    CVE-2024-31483

    Last Modified: 24 Jun 2025

    An authenticated sensitive information disclosure vulnerability exists in the CLI service accessed via the PAPI protocol. Successful exploitation of this vulnerability results in the ability to read arbitrary files in the underlying operating system.

    Published: 14 May 2024
    5.3
    Medium

    CVE-2024-31482

    Last Modified: 24 Jun 2025

    An unauthenticated Denial-of-Service (DoS) vulnerability exists in the ANSI escape code service accessed via the PAPI protocol. Successful exploitation of this vulnerability results in the ability to interrupt the normal operation of the affected Access Point.

    Published: 14 May 2024
    5.3
    Medium

    CVE-2024-31481

    Last Modified: 24 Jun 2025

    Unauthenticated Denial of Service (DoS) vulnerabilities exist in the CLI service accessed via the PAPI protocol. Successful exploitation of these vulnerabilities result in the ability to interrupt the normal operation of the affected service.

    Published: 14 May 2024
    5.3
    Medium

    CVE-2024-31480

    Last Modified: 24 Jun 2025

    Unauthenticated Denial of Service (DoS) vulnerabilities exist in the CLI service accessed via the PAPI protocol. Successful exploitation of these vulnerabilities result in the ability to interrupt the normal operation of the affected service.

    Published: 14 May 2024
    5.3
    Medium

    CVE-2024-31479

    Last Modified: 24 Jun 2025

    Unauthenticated Denial of Service (DoS) vulnerabilities exist in the Central Communications service accessed via the PAPI protocol. Successful exploitation of these vulnerabilities result in the ability to interrupt the normal operation of the affected service.

    Published: 14 May 2024
    5.3
    Medium

    CVE-2024-31478

    Last Modified: 24 Jun 2025

    Multiple unauthenticated Denial-of-Service (DoS) vulnerabilities exists in the Soft AP daemon accessed via the PAPI protocol. Successful exploitation of these vulnerabilites result in the ability to interrupt the normal operation of the affected Access Point.

    Published: 14 May 2024
    7.2
    High

    CVE-2024-31477

    Last Modified: 24 Jun 2025

    Multiple authenticated command injection vulnerabilities exist in the command line interface. Successful exploitation of these vulnerabilities result in the ability to execute arbitrary commands as a privileged user on the underlying operating system.

    Published: 14 May 2024
    6.4
    Medium

    CVE-2024-4666

    Last Modified: 8 Apr 2026

    The Borderless – Widgets, Elements, Templates and Toolkit for Elementor & Gutenberg plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple widgets in all versions up to, and including, 1.5.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 14 May 2024
    7.2
    High

    CVE-2024-31476

    Last Modified: 24 Jun 2025

    Multiple authenticated command injection vulnerabilities exist in the command line interface. Successful exploitation of these vulnerabilities result in the ability to execute arbitrary commands as a privileged user on the underlying operating system.

    Published: 14 May 2024
    8.2
    High

    CVE-2024-31475

    Last Modified: 24 Jun 2025

    There is an arbitrary file deletion vulnerability in the Central Communications service accessed by PAPI (Aruba's access point management protocol). Successful exploitation of this vulnerability results in the ability to delete arbitrary files on the underlying operating system, which could lead to the ability to interrupt normal operation and impact the integrity of the affected Access Point.

    Published: 14 May 2024
    8.2
    High

    CVE-2024-31474

    Last Modified: 24 Jun 2025

    There is an arbitrary file deletion vulnerability in the CLI service accessed by PAPI (Aruba's Access Point management protocol). Successful exploitation of this vulnerability results in the ability to delete arbitrary files on the underlying operating system, which could lead to the ability to interrupt normal operation and impact the integrity of the affected Access Point

    Published: 14 May 2024
    9.8
    Critical

    CVE-2024-31473

    Last Modified: 24 Jun 2025

    There is a command injection vulnerability in the underlying deauthentication service that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's Access Point management protocol) UDP port (8211). Successful exploitation of this vulnerability results in the ability to execute arbitrary code as a privileged user on the underlying operating system.

    Published: 14 May 2024
    9.8
    Critical

    CVE-2024-31472

    Last Modified: 24 Jun 2025

    There are command injection vulnerabilities in the underlying Soft AP Daemon service that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's Access Point management protocol) UDP port (8211). Successful exploitation of these vulnerabilities result in the ability to execute arbitrary code as a privileged user on the underlying operating system.

    Published: 14 May 2024
    9.8
    Critical

    CVE-2024-31471

    Last Modified: 24 Jun 2025

    There is a command injection vulnerability in the underlying Central Communications service that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's Access Point management protocol) UDP port (8211). Successful exploitation of this vulnerability results in the ability to execute arbitrary code as a privileged user on the underlying operating system.

    Published: 14 May 2024
    9.8
    Critical

    CVE-2024-31470

    Last Modified: 24 Jun 2025

    There is a buffer overflow vulnerability in the underlying SAE (Simultaneous Authentication of Equals) service that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's Access Point management protocol) UDP port (8211). Successful exploitation of this vulnerability results in the ability to execute arbitrary code as a privileged user on the underlying operating system.

    Published: 14 May 2024
    9.8
    Critical

    CVE-2024-31469

    Last Modified: 24 Jun 2025

    There are buffer overflow vulnerabilities in the underlying Central Communications service that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's Access Point management protocol) UDP port (8211). Successful exploitation of these vulnerabilities result in the ability to execute arbitrary code as a privileged user on the underlying operating system.

    Published: 14 May 2024
    9.8
    Critical

    CVE-2024-31468

    Last Modified: 24 Jun 2025

    There are buffer overflow vulnerabilities in the underlying Central Communications service that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's Access Point management protocol) UDP port (8211). Successful exploitation of these vulnerabilities result in the ability to execute arbitrary code as a privileged user on the underlying operating system.

    Published: 14 May 2024
    9.8
    Critical

    CVE-2024-31467

    Last Modified: 24 Jun 2025

    There are buffer overflow vulnerabilities in the underlying CLI service that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's Access Point management protocol) UDP port (8211). Successful exploitation of these vulnerabilities result in the ability to execute arbitrary code as a privileged user on the underlying operating system.

    Published: 14 May 2024
    5.3
    Medium

    CVE-2024-35175

    Last Modified: 15 Apr 2026

    sshpiper is a reverse proxy for sshd. Starting in version 1.0.50 and prior to version 1.3.0, the way the proxy protocol listener is implemented in sshpiper can allow an attacker to forge their connecting address. Commit 2ddd69876a1e1119059debc59fe869cb4e754430 added the proxy protocol listener as the only listener in sshpiper, with no option to toggle this functionality off. This means that any connection that sshpiper is directly (or in some cases indirectly) exposed to can use proxy protocol to forge its source address. Any users of sshpiper who need logs from it for whitelisting/rate limiting/security investigations could have them become much less useful if an attacker is sending a spoofed source address. Version 1.3.0 contains a patch for the issue.

    Published: 14 May 2024
    9.8
    Critical

    CVE-2024-31466

    Last Modified: 24 Jun 2025

    There are buffer overflow vulnerabilities in the underlying CLI service that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's Access Point management protocol) UDP port (8211). Successful exploitation of these vulnerabilities result in the ability to execute arbitrary code as a privileged user on the underlying operating system.

    Published: 14 May 2024
    8.8
    High

    CVE-2023-33327

    Last Modified: 15 Apr 2026

    Improper Privilege Management vulnerability in Teplitsa of social technologies Leyka allows Privilege Escalation.This issue affects Leyka: from n/a through 3.30.2.

    Published: 14 May 2024
    5.4
    Medium

    CVE-2024-4562

    Last Modified: 9 Dec 2024

    In WhatsUp Gold versions released before 2023.1.2 , an SSRF vulnerability exists in Whatsup Gold's Issue exists in the HTTP Monitoring functionality.  Due to the lack of proper authorization, any authenticated user can access the HTTP monitoring functionality, what leads to the Server Side Request Forgery.

    Published: 14 May 2024
    4.2
    Medium

    CVE-2024-4561

    Last Modified: 9 Dec 2024

    In WhatsUp Gold versions released before 2023.1.2 , a blind SSRF vulnerability exists in Whatsup Gold's FaviconController that allows an attacker to send arbitrary HTTP requests on behalf of the vulnerable server.

    Published: 14 May 2024
    8.1
    High

    CVE-2020-26312

    Last Modified: 15 Apr 2026

    Dotmesh is a git-like command-line interface for capturing, organizing and sharing application states. In versions 0.8.1 and prior, the unsafe handling of symbolic links in an unpacking routine may enable attackers to read and/or write to arbitrary locations outside the designated target folder. The routine `untarFile` attempts to guard against creating symbolic links that point outside the directory a tar archive is extracted to. However, a malicious tarball first linking `subdir/parent` to `..` (allowed, because `subdir/..` falls within the archive root) and then linking `subdir/parent/escapes` to `..` results in a symbolic link pointing to the tarball’s parent directory, contrary to the routine’s goals. This issue may lead to arbitrary file write (with same permissions as the program running the unpack operation) if the attacker can control the archive file. Additionally, if the attacker has read access to the unpacked files, they may be able to read arbitrary system files the parent process has permissions to read. As of time of publication, no patch for this issue is available.

    Published: 14 May 2024
    7.2
    High

    CVE-2022-28132

    Last Modified: 15 Apr 2026

    The T-Soft E-Commerce 4 web application is susceptible to SQL injection (SQLi) attacks when authenticated as an admin or privileged user. This vulnerability allows attackers to access and manipulate the database through crafted requests. By exploiting this flaw, attackers can bypass authentication mechanisms, view sensitive information stored in the database, and potentially exfiltrate data.

    Published: 14 May 2024
    7.8
    High

    CVE-2024-31556

    Last Modified: 15 Apr 2026

    An issue in Reportico Web before v.8.1.0 allows a local attacker to execute arbitrary code and obtain sensitive information via the sessionid function.

    Published: 14 May 2024
    7.2
    High

    CVE-2021-22280

    Last Modified: 19 Dec 2025

    Improper DLL loading algorithms in B&R Automation Studio versions >=4.0 and <4.12 may allow an authenticated local attacker to execute code in the context of the product.

    Published: 14 May 2024
    7.5
    High

    CVE-2024-3676

    Last Modified: 15 Apr 2026

    The Proofpoint Encryption endpoint of Proofpoint Enterprise Protection contains an Improper Input Validation vulnerability that allows an unauthenticated remote attacker with a specially crafted HTTP request to create additional Encryption user accounts under the attacker's control.  These accounts are able to send spoofed email to any users within the domains configured by the Administrator.

    Published: 14 May 2024
    5
    Medium

    CVE-2024-0862

    Last Modified: 15 Apr 2026

    The Proofpoint Encryption endpoint of Proofpoint Enterprise Protection contains a Server-Side Request Forgery vulnerability that allows an authenticated user to relay HTTP requests from the Protection server to otherwise private network addresses.

    Published: 14 May 2024
    7.2
    High

    CVE-2024-2637

    Last Modified: 15 Apr 2026

    An Uncontrolled Search Path Element vulnerability in B&R Industrial Automation Scene Viewer, B&R Industrial Automation Automation Runtime, B&R Industrial Automation mapp Vision, B&R Industrial Automation mapp View, B&R Industrial Automation mapp Cockpit, B&R Industrial Automation mapp Safety, B&R Industrial Automation VC4, B&R Industrial Automation APROL, B&R Industrial Automation CAN Driver, B&R Industrial Automation CAN Driver CC770, B&R Industrial Automation CAN Driver SJA1000, B&R Industrial Automation Tou0ch Lock, B&R Industrial Automation B&R Single-Touch Driver, B&R Industrial Automation Serial User Mode Touch Driver, B&R Industrial Automation Windows Settings Changer (LTSC), B&R Industrial Automation Windows Settings Changer (2019 LTSC), B&R Industrial Automation Windows 10 Recovery Solution, B&R Industrial Automation ADI driver universal, B&R Industrial Automation ADI Development Kit, B&R Industrial Automation ADI .NET SDK, B&R Industrial Automation SRAM driver, B&R Industrial Automation HMI Service Center, B&R Industrial Automation HMI Service Center Maintenance, B&R Industrial Automation Windows 10 IoT Enterprise 2019 LTSC, B&R Industrial Automation KCF Editor could allow an authenticated local attacker to execute malicious code by placing specially crafted files in the loading search path..This issue affects Scene Viewer: before 4.4.0; Automation Runtime: before J4.93; mapp Vision: before 5.26.1; mapp View: before 5.24.2; mapp Cockpit: before 5.24.2; mapp Safety: before 5.24.2; VC4: before 4.73.2; APROL: before 4.4-01; CAN Driver: before 1.1.0; CAN Driver CC770: before 3.3.0; CAN Driver SJA1000: before 1.3.0; Tou0ch Lock: before 2.1.0; B&R Single-Touch Driver: before 2.0.0; Serial User Mode Touch Driver: before 1.7.1; Windows Settings Changer (LTSC): before 3.2.0; Windows Settings Changer (2019 LTSC): before 2.2.0; Windows 10 Recovery Solution: before 3.2.0; ADI driver universal: before 3.2.0; ADI Development Kit: before 5.5.0; ADI .NET SDK: before 4.1.0; SRAM driver: before 1.2.0; HMI Service Center: before 3.1.0; HMI Service Center Maintenance: before 2.1.0; Windows 10 IoT Enterprise 2019 LTSC: through 1.1; KCF Editor: before 1.1.0.

    Published: 14 May 2024
    —
    Unknown

    CVE-2024-4880

    Last Modified: 11 Feb 2025

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

    Published: 14 May 2024
    9.8
    Critical

    CVE-2024-33485

    Last Modified: 15 Apr 2026

    SQL Injection vulnerability in CASAP Automated Enrollment System using PHP/MySQLi with Source Code V1.0 allows a remote attacker to obtain sensitive information via a crafted payload to the login.php component

    Published: 14 May 2024
    —
    Unknown

    CVE-2024-4878

    Last Modified: 19 May 2025

    Unused CVE record, incorrectly reserved

    Published: 14 May 2024
    9.8
    Critical

    CVE-2024-4778

    Last Modified: 4 Apr 2025

    Memory safety bugs present in Firefox 125. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 126.

    Published: 14 May 2024
    8.2
    High

    CVE-2024-4776

    Last Modified: 1 Apr 2025

    A file dialog shown while in full-screen mode could have resulted in the window remaining disabled. This vulnerability affects Firefox < 126.

    Published: 14 May 2024
    5.9
    Medium

    CVE-2024-4775

    Last Modified: 1 Apr 2025

    An iterator stop condition was missing when handling WASM code in the built-in profiler, potentially leading to invalid memory access and undefined behavior. *Note:* This issue only affects the application when the profiler is running. This vulnerability affects Firefox < 126.

    Published: 14 May 2024
    6.5
    Medium

    CVE-2024-4774

    Last Modified: 28 Mar 2025

    The `ShmemCharMapHashEntry()` code was susceptible to potentially undefined behavior by bypassing the move semantics for one of its data members. This vulnerability affects Firefox < 126.

    Published: 14 May 2024
    7.5
    High

    CVE-2024-4773

    Last Modified: 4 Apr 2025

    When a network error occurred during page load, the prior content could have remained in view with a blank URL bar. This could have been used to obfuscate a spoofed web site. This vulnerability affects Firefox < 126.

    Published: 14 May 2024
    5.9
    Medium

    CVE-2024-4772

    Last Modified: 1 Apr 2025

    An HTTP digest authentication nonce value was generated using `rand()` which could lead to predictable values. This vulnerability affects Firefox < 126.

    Published: 14 May 2024
    8.6
    High

    CVE-2024-4771

    Last Modified: 1 Apr 2025

    A memory allocation check was missing which would lead to a use-after-free if the allocation failed. This could have triggered a crash or potentially be leveraged to achieve code execution. This vulnerability affects Firefox < 126.

    Published: 14 May 2024
    4.3
    Medium

    CVE-2024-4766

    Last Modified: 4 Apr 2025

    Different techniques existed to obscure the fullscreen notification in Firefox for Android. These could have led to potential user confusion and spoofing attacks. *This bug only affects Firefox for Android. Other versions of Firefox are unaffected.* This vulnerability affects Firefox < 126.

    Published: 14 May 2024
    8.1
    High

    CVE-2024-4765

    Last Modified: 4 Apr 2025

    Web application manifests were stored by using an insecure MD5 hash which allowed for a hash collision to overwrite another application's manifest. This could have been exploited to run arbitrary code in another application's context. *This issue only affects Firefox for Android. Other versions of Firefox are unaffected.* This vulnerability affects Firefox < 126.

    Published: 14 May 2024
    9.8
    Critical

    CVE-2024-4764

    Last Modified: 1 Apr 2025

    Multiple WebRTC threads could have claimed a newly connected audio input leading to use-after-free. This vulnerability affects Firefox < 126.

    Published: 14 May 2024
    8.4
    High

    CVE-2024-27110

    Last Modified: 15 Apr 2026

    Elevation of privilege vulnerability in GE HealthCare EchoPAC products

    Published: 14 May 2024
    7.6
    High

    CVE-2024-27109

    Last Modified: 15 Apr 2026

    Insufficiently protected credentials in GE HealthCare EchoPAC products

    Published: 14 May 2024
    6.8
    Medium

    CVE-2024-27108

    Last Modified: 15 Apr 2026

    Non privileged access to critical file vulnerability in GE HealthCare EchoPAC products

    Published: 14 May 2024
    9.6
    Critical

    CVE-2024-27107

    Last Modified: 15 Apr 2026

    Weak account password in GE HealthCare EchoPAC products

    Published: 14 May 2024