CVE Feed

    Dashboard / CVE

    4.8
    Medium

    CVE-2023-5971

    Last Modified: 9 Jan 2026

    The Save as PDF Plugin by Pdfcrowd WordPress plugin before 3.2.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

    Published: 9 May 2024
    7.5
    High

    CVE-2024-29857

    Last Modified: 15 Apr 2026

    An issue was discovered in ECCurve.java and ECCurve.cs in Bouncy Castle Java (BC Java) before 1.78, BC Java LTS before 2.73.6, BC-FJA before 1.0.2.5, and BC C# .Net before 2.3.1. Importing an EC certificate with crafted F2m parameters can lead to excessive CPU consumption during the evaluation of the curve parameters.

    Published: 9 May 2024
    5.3
    Medium

    CVE-2024-4672

    Last Modified: 19 Feb 2025

    A vulnerability classified as problematic was found in Campcodes Complete Web-Based School Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /view/show_student_subject.php. The manipulation of the argument id leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-263593 was assigned to this vulnerability.

    Published: 9 May 2024
    6.5
    Medium

    CVE-2023-6682

    Last Modified: 12 Dec 2024

    An issue has been discovered in GitLab CE/EE affecting all versions starting from 16.9 prior to 16.9.7, starting from 16.10 prior to 16.10.5, and starting from 16.11 prior to 16.11.2. A problem with the processing logic for Discord Integrations Chat Messages can lead to a regular expression DoS attack on the server.

    Published: 9 May 2024
    6.5
    Medium

    CVE-2023-6688

    Last Modified: 12 Dec 2024

    An issue has been discovered in GitLab CE/EE affecting all versions starting from 16.11 prior to 16.11.2. A problem with the processing logic for Google Chat Messages integration may lead to a regular expression DoS attack on the server.

    Published: 9 May 2024
    6.5
    Medium

    CVE-2024-2454

    Last Modified: 12 Dec 2024

    An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.11 prior to 16.9.7, starting from 16.10 prior to 16.10.5, and starting from 16.11 prior to 16.11.2. The pins endpoint is susceptible to DoS through a crafted request.

    Published: 9 May 2024
    6.5
    Medium

    CVE-2024-2651

    Last Modified: 12 Dec 2024

    An issue has been discovered in GitLab CE/EE affecting all versions before 16.9.7, all versions starting from 16.10 before 16.10.5, all versions starting from 16.11 before 16.11.2. It was possible for an attacker to cause a denial of service using maliciously crafted markdown content.

    Published: 9 May 2024
    4.3
    Medium

    CVE-2024-4539

    Last Modified: 13 Dec 2024

    An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.4 prior to 16.9.7, starting from 16.10 prior to 16.10.5, and starting from 16.11 prior to 16.11.2 where abusing the API to filter branch and tags could lead to Denial of Service.

    Published: 9 May 2024
    5.7
    Medium

    CVE-2024-4597

    Last Modified: 13 Dec 2024

    An issue has been discovered in GitLab EE affecting all versions from 16.7 before 16.9.7, all versions starting from 16.10 before 16.10.5, all versions starting from 16.11 before 16.11.2. An attacker could force a user with an active SAML session to approve an MR via CSRF.

    Published: 9 May 2024
    7.5
    High

    CVE-2024-33655

    Last Modified: 15 Apr 2026

    The DNS protocol in RFC 1035 and updates allows remote attackers to cause a denial of service (resource consumption) by arranging for DNS queries to be accumulated for seconds, such that responses are later sent in a pulsing burst (which can be considered traffic amplification in some cases), aka the "DNSBomb" issue.

    Published: 9 May 2024
    6.5
    Medium

    CVE-2024-3744

    Last Modified: 15 Apr 2026

    A security issue was discovered in azure-file-csi-driver where an actor with access to the driver logs could observe service account tokens. These tokens could then potentially be exchanged with external cloud providers to access secrets stored in cloud vault solutions. Tokens are only logged when TokenRequests is configured in the CSIDriver object and the driver is set to run at log level 2 or greater via the -v flag.

    Published: 9 May 2024
    7.5
    High

    CVE-2024-30172

    Last Modified: 15 Apr 2026

    An issue was discovered in Bouncy Castle Java Cryptography APIs before 1.78. An Ed25519 verification code infinite loop can occur via a crafted signature and public key.

    Published: 9 May 2024
    3.1
    Low

    CVE-2024-4317

    Last Modified: 28 Mar 2025

    Missing authorization in PostgreSQL built-in views pg_stats_ext and pg_stats_ext_exprs allows an unprivileged database user to read most common values and other statistics from CREATE STATISTICS commands of other users. The most common values may reveal column values the eavesdropper could not otherwise read or results of functions they cannot execute. Installing an unaffected version only fixes fresh PostgreSQL installations, namely those that are created with the initdb utility after installing that version. Current PostgreSQL installations will remain vulnerable until they follow the instructions in the release notes. Within major versions 14-16, minor versions before PostgreSQL 16.3, 15.7, and 14.12 are affected. Versions before PostgreSQL 14 are unaffected.

    Published: 9 May 2024
    8.3
    High

    CVE-2024-3727

    Last Modified: 25 Apr 2026

    A flaw was found in the github.com/containers/image library. This flaw allows attackers to trigger unexpected authenticated registry accesses on behalf of a victim user, causing resource exhaustion, local path traversal, and other attacks.

    Published: 9 May 2024
    7.8
    High

    CVE-2024-27793

    Last Modified: 2 Apr 2026

    The issue was addressed with improved checks. This issue is fixed in iTunes 12.13.2 for Windows. Parsing a file may lead to an unexpected app termination or arbitrary code execution.

    Published: 8 May 2024
    8.8
    High

    CVE-2024-34196

    Last Modified: 18 Jun 2025

    Totolink AC1200 Wireless Dual Band Gigabit Router A3002RU_V3 Firmware V3.0.0-B20230809.1615 is vulnerable to Buffer Overflow. The "boa" program allows attackers to modify the value of the "vwlan_idx" field via "formMultiAP". This can lead to a stack overflow through the "formWlEncrypt" CGI function by constructing malicious HTTP requests and passing a WLAN SSID value exceeding the expected length, potentially resulting in command execution or denial of service attacks.

    Published: 8 May 2024
    9.1
    Critical

    CVE-2024-26517

    Last Modified: 18 Jun 2025

    SQL Injection vulnerability in School Task Manager v.1.0 allows a remote attacker to obtain sensitive information via a crafted payload to the delete-task.php component.

    Published: 8 May 2024
    8.8
    High

    CVE-2024-34308

    Last Modified: 4 Apr 2025

    TOTOLINK LR350 V9.3.5u.6369_B20220309 was discovered to contain a stack overflow via the password parameter in the function urldecode.

    Published: 8 May 2024
    4.3
    Medium

    CVE-2024-28759

    Last Modified: 15 Apr 2026

    A crafted network packet may cause a buffer overrun in Wind River VxWorks 7 through 23.09.

    Published: 8 May 2024
    2.2
    Low

    CVE-2024-22460

    Last Modified: 4 Feb 2025

    Dell PowerProtect DM5500 version 5.15.0.0 and prior contains an insecure deserialization Vulnerability. A remote attacker with high privileges could potentially exploit this vulnerability, leading to arbitrary code execution on the vulnerable application.

    Published: 8 May 2024
    6.5
    Medium

    CVE-2024-24908

    Last Modified: 4 Feb 2025

    Dell PowerProtect DM5500 version 5.15.0.0 and prior contain an Arbitrary File Delete via Path Traversal vulnerability. A remote attacker with high privileges could potentially exploit this vulnerability to deletion of arbitrary files stored on the server filesystem.

    Published: 8 May 2024
    3.5
    Low

    CVE-2024-28971

    Last Modified: 27 Jan 2025

    Dell Update Manager Plugin, versions 1.4.0 through 1.5.0, contains a Plain-text Password Storage Vulnerability in Log file. A remote high privileged attacker could potentially exploit this vulnerability, leading to the disclosure of certain user credentials. The attacker may be able to use the exposed credentials to access the vulnerable application with privileges of the compromised account.

    Published: 8 May 2024
    6.4
    Medium

    CVE-2024-24787

    Last Modified: 15 Apr 2026

    On Darwin, building a Go module which contains CGO can trigger arbitrary code execution when using the Apple version of ld, due to usage of the -lto_library flag in a "#cgo LDFLAGS" directive.

    Published: 8 May 2024
    9.8
    Critical

    CVE-2024-26579

    Last Modified: 28 Mar 2025

    Deserialization of Untrusted Data vulnerability in Apache InLong.This issue affects Apache InLong: from 1.7.0 through 1.11.0,  the attackers can bypass using malicious parameters. Users are advised to upgrade to Apache InLong's 1.12.0 or cherry-pick [1], [2] to solve it. [1] https://github.com/apache/inlong/pull/9694 [2]  https://github.com/apache/inlong/pull/9707

    Published: 8 May 2024
    6.5
    Medium

    CVE-2024-32761

    Last Modified: 4 Feb 2026

    Under certain conditions, a data leak may occur in the Traffic Management Microkernels (TMMs) of BIG-IP tenants running on VELOS and rSeries platforms. This leak occurs randomly and cannot be deliberately triggered. If it occurs, it may leak up to 64 bytes of non-contiguous randomized bytes. Under rare conditions, this may lead to a TMM restart, affecting availability.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated

    Published: 8 May 2024
    7.5
    High

    CVE-2024-26026

    Last Modified: 19 Sept 2025

    An SQL injection vulnerability exists in the BIG-IP Next Central Manager API (URI).  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated

    Published: 8 May 2024
    7.5
    High

    CVE-2024-21793

    Last Modified: 19 Sept 2025

    An OData injection vulnerability exists in the BIG-IP Next Central Manager API (URI).  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

    Published: 8 May 2024
    6.8
    Medium

    CVE-2024-33612

    Last Modified: 16 Dec 2025

    An improper certificate validation vulnerability exists in BIG-IP Next Central Manager and may allow an attacker to impersonate an Instance Provider system.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

    Published: 8 May 2024
    8
    High

    CVE-2024-31156

    Last Modified: 16 Dec 2025

    A stored cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Configuration utility that allows an attacker to run JavaScript in the context of the currently logged-in user.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

    Published: 8 May 2024
    6.1
    Medium

    CVE-2024-33604

    Last Modified: 21 Oct 2025

    A reflected cross-site scripting (XSS) vulnerability exist in undisclosed page of the BIG-IP Configuration utility that allows an attacker to run JavaScript in the context of the currently logged-in user.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated

    Published: 8 May 2024
    4.4
    Medium

    CVE-2024-28132

    Last Modified: 6 Aug 2025

    Exposure of Sensitive Information vulnerability exists in the GSLB container, which may allow an authenticated attacker with local access to view sensitive information.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

    Published: 8 May 2024
    5.9
    Medium

    CVE-2024-28889

    Last Modified: 21 Oct 2025

    When an SSL profile with alert timeout is configured with a non-default value on a virtual server, undisclosed traffic along with conditions beyond the attacker's control can cause the Traffic Management Microkernel (TMM) to terminate.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

    Published: 8 May 2024
    7.4
    High

    CVE-2024-32049

    Last Modified: 12 Dec 2024

    BIG-IP Next Central Manager (CM) may allow an unauthenticated, remote attacker to obtain the BIG-IP Next LTM/WAF instance credentials.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

    Published: 8 May 2024
    4.7
    Medium

    CVE-2024-27202

    Last Modified: 21 Oct 2025

    A DOM-based cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Configuration utility that allows an attacker to run JavaScript in the context of the currently logged-in user.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

    Published: 8 May 2024
    7.5
    High

    CVE-2024-25560

    Last Modified: 21 Oct 2025

    When BIG-IP AFM is licensed and provisioned, undisclosed DNS traffic can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

    Published: 8 May 2024
    7.5
    High

    CVE-2024-33608

    Last Modified: 21 Oct 2025

    When IPsec is configured on a virtual server, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

    Published: 8 May 2024
    7.4
    High

    CVE-2024-28883

    Last Modified: 6 Aug 2025

    An origin validation vulnerability exists in BIG-IP APM browser network access VPN client for Windows, macOS and Linux which may allow an attacker to bypass F5 endpoint inspection. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

    Published: 8 May 2024
    6.3
    Medium

    CVE-2024-4654

    Last Modified: 13 Nov 2025

    A vulnerability was found in BlueNet Technology Clinical Browsing System 1.2.1. It has been classified as critical. This affects an unknown part of the file /xds/cloudInterface.php. The manipulation of the argument INSTI_CODE leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-263499.

    Published: 8 May 2024
    9.8
    Critical

    CVE-2024-32113

    Last Modified: 23 Oct 2025

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache OFBiz.This issue affects Apache OFBiz: before 18.12.13. Users are recommended to upgrade to version 18.12.13, which fixes the issue.

    Published: 8 May 2024
    7.1
    High

    CVE-2024-3951

    Last Modified: 15 Apr 2026

    PTC Codebeamer is vulnerable to a cross site scripting vulnerability that could allow an attacker to inject and execute malicious code.

    Published: 8 May 2024
    9.1
    Critical

    CVE-2024-32980

    Last Modified: 15 Apr 2026

    Spin is the developer tool for building and running serverless applications powered by WebAssembly. Prior to 2.4.3, some specifically configured Spin applications that use `self` requests without a specified URL authority can be induced to make requests to arbitrary hosts via the `Host` HTTP header. The following conditions need to be met for an application to be vulnerable: 1. The environment Spin is deployed in routes requests to the Spin runtime based on the request URL instead of the `Host` header, and leaves the `Host` header set to its original value; 2. The Spin application's component handling the incoming request is configured with an `allow_outbound_hosts` list containing `"self"`; and 3. In reaction to an incoming request, the component makes an outbound request whose URL doesn't include the hostname/port. Spin 2.4.3 has been released to fix this issue.

    Published: 8 May 2024
    6.3
    Medium

    CVE-2024-4653

    Last Modified: 10 Oct 2025

    A vulnerability was found in BlueNet Technology Clinical Browsing System 1.2.1 and classified as critical. Affected by this issue is some unknown functionality of the file /xds/outIndex.php. The manipulation of the argument name leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-263498 is the identifier assigned to this vulnerability.

    Published: 8 May 2024
    8.3
    High

    CVE-2024-34347

    Last Modified: 15 Apr 2026

    @hoppscotch/cli is a CLI to run Hoppscotch Test Scripts in CI environments. Prior to 0.8.0, the @hoppscotch/js-sandbox package provides a Javascript sandbox that uses the Node.js vm module. However, the vm module is not safe for sandboxing untrusted Javascript code. This is because code inside the vm context can break out if it can get a hold of any reference to an object created outside of the vm. In the case of @hoppscotch/js-sandbox, multiple references to external objects are passed into the vm context to allow pre-request scripts interactions with environment variables and more. But this also allows the pre-request script to escape the sandbox. This vulnerability is fixed in 0.8.0.

    Published: 8 May 2024
    4.9
    Medium

    CVE-2024-32886

    Last Modified: 15 Apr 2026

    Vitess is a database clustering system for horizontal scaling of MySQL. When executing the following simple query, the `vtgate` will go into an endless loop that also keeps consuming memory and eventually will run out of memory. This vulnerability is fixed in 19.0.4, 18.0.5, and 17.0.7.

    Published: 8 May 2024
    3.5
    Low

    CVE-2024-4652

    Last Modified: 19 Feb 2025

    A vulnerability, which was classified as problematic, was found in Campcodes Complete Web-Based School Management System 1.0. Affected is an unknown function of the file /view/show_teacher2.php. The manipulation of the argument month leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-263496.

    Published: 8 May 2024
    3.5
    Low

    CVE-2024-4651

    Last Modified: 19 Feb 2025

    A vulnerability, which was classified as problematic, has been found in Campcodes Complete Web-Based School Management System 1.0. This issue affects some unknown processing of the file /view/student_attendance_history1.php. The manipulation of the argument year leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-263495.

    Published: 8 May 2024
    4.3
    Medium

    CVE-2024-33573

    Last Modified: 28 Apr 2026

    Missing Authorization vulnerability in EPROLO EPROLO Dropshipping.This issue affects EPROLO Dropshipping: from n/a through 1.7.1.

    Published: 8 May 2024
    4.3
    Medium

    CVE-2024-33574

    Last Modified: 28 Apr 2026

    Missing Authorization vulnerability in appsbd Vitepos.This issue affects Vitepos: from n/a through 3.0.1.

    Published: 8 May 2024
    3.5
    Low

    CVE-2024-4650

    Last Modified: 19 Feb 2025

    A vulnerability classified as problematic was found in Campcodes Complete Web-Based School Management System 1.0. This vulnerability affects unknown code of the file /view/student_due_payment.php. The manipulation of the argument due_month leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-263494 is the identifier assigned to this vulnerability.

    Published: 8 May 2024
    3.5
    Low

    CVE-2024-4649

    Last Modified: 19 Feb 2025

    A vulnerability classified as problematic has been found in Campcodes Complete Web-Based School Management System 1.0. This affects an unknown part of the file /view/student_exam_mark_insert_form1.php. The manipulation of the argument page leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-263493 was assigned to this vulnerability.

    Published: 8 May 2024