CVE Feed

    Dashboard / CVE

    5.3
    Medium

    CVE-2024-34383

    Last Modified: 28 Apr 2026

    Authorization Bypass Through User-Controlled Key vulnerability in The SEO Guys at SEOPress SEOPress.This issue affects SEOPress: from n/a through 7.7.1.

    Published: 6 May 2024
    7.5
    High

    CVE-2024-34388

    Last Modified: 28 Apr 2026

    Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Scribit GDPR Compliance.This issue affects GDPR Compliance: from n/a through 1.2.5.

    Published: 6 May 2024
    8.5
    High

    CVE-2024-32807

    Last Modified: 15 Apr 2026

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Brevo Sendinblue for WooCommerce allows Relative Path Traversal, Manipulating Web Input to File System Calls.This issue affects Sendinblue for WooCommerce: from n/a through 4.0.17.

    Published: 6 May 2024
    6.1
    Medium

    CVE-2024-34078

    Last Modified: 15 Apr 2026

    html-sanitizer is an allowlist-based HTML cleaner. If using `keep_typographic_whitespace=False` (which is the default), the sanitizer normalizes unicode to the NFKC form at the end. Some unicode characters normalize to chevrons; this allows specially crafted HTML to escape sanitization. The problem has been fixed in 2.4.2.

    Published: 6 May 2024
    8.2
    High

    CVE-2024-32982

    Last Modified: 15 Apr 2026

    Litestar and Starlite is an Asynchronous Server Gateway Interface (ASGI) framework. Prior to 2.8.3, 2.7.2, and 2.6.4, a Local File Inclusion (LFI) vulnerability has been discovered in the static file serving component of LiteStar. This vulnerability allows attackers to exploit path traversal flaws, enabling unauthorized access to sensitive files outside the designated directories. Such access can lead to the disclosure of sensitive information or potentially compromise the server. The vulnerability is located in the file path handling mechanism within the static content serving function, specifically at `litestar/static_files/base.py`. This vulnerability is fixed in versions 2.8.3, 2.7.2, and 2.6.4.

    Published: 6 May 2024
    8.4
    High

    CVE-2024-23354

    Last Modified: 11 Aug 2025

    Memory corruption when the IOCTL call is interrupted by a signal.

    Published: 6 May 2024
    8.4
    High

    CVE-2024-23351

    Last Modified: 16 Dec 2025

    Memory corruption as GPU registers beyond the last protected range can be accessed through LPAC submissions.

    Published: 6 May 2024
    7.3
    High

    CVE-2024-21480

    Last Modified: 11 Aug 2025

    Memory corruption while playing audio file having large-sized input buffer.

    Published: 6 May 2024
    7.5
    High

    CVE-2024-21477

    Last Modified: 15 Jan 2025

    Transient DOS while parsing a protected 802.11az Fine Time Measurement (FTM) frame.

    Published: 6 May 2024
    7.8
    High

    CVE-2024-21476

    Last Modified: 16 Dec 2025

    Memory corruption when the channel ID passed by user is not validated and further used.

    Published: 6 May 2024
    7.8
    High

    CVE-2024-21475

    Last Modified: 11 Aug 2025

    Memory corruption when the payload received from firmware is not as per the expected protocol size.

    Published: 6 May 2024
    8.4
    High

    CVE-2024-21474

    Last Modified: 15 Jan 2025

    Memory corruption when size of buffer from previous call is used without validation or re-initialization.

    Published: 6 May 2024
    8.4
    High

    CVE-2024-21471

    Last Modified: 11 Aug 2025

    Memory corruption when IOMMU unmap of a GPU buffer fails in Linux.

    Published: 6 May 2024
    8.4
    High

    CVE-2023-43531

    Last Modified: 11 Aug 2025

    Memory corruption while verifying the serialized header when the key pairs are generated.

    Published: 6 May 2024
    5.9
    Medium

    CVE-2023-43530

    Last Modified: 11 Aug 2025

    Memory corruption in HLOS while checking for the storage type.

    Published: 6 May 2024
    7.5
    High

    CVE-2023-43529

    Last Modified: 11 Aug 2025

    Transient DOS while processing IKEv2 Informational request messages, when a malformed fragment packet is received.

    Published: 6 May 2024
    6.1
    Medium

    CVE-2023-43528

    Last Modified: 11 Aug 2025

    Information disclosure when the ADSP payload size received in HLOS in response to Audio Stream Manager matrix session is less than this expected size.

    Published: 6 May 2024
    6.8
    Medium

    CVE-2023-43527

    Last Modified: 11 Aug 2025

    Information disclosure while parsing dts header atom in Video.

    Published: 6 May 2024
    6.7
    Medium

    CVE-2023-43526

    Last Modified: 15 Jan 2025

    Memory corruption while querying module parameters from Listen Sound model client in kernel from user space.

    Published: 6 May 2024
    6.7
    Medium

    CVE-2023-43525

    Last Modified: 16 Dec 2025

    Memory corruption while copying the sound model data from user to kernel buffer during sound model register.

    Published: 6 May 2024
    6.7
    Medium

    CVE-2023-43524

    Last Modified: 15 Jan 2025

    Memory corruption when the bandpass filter order received from AHAL is not within the expected range.

    Published: 6 May 2024
    6.7
    Medium

    CVE-2023-43521

    Last Modified: 11 Aug 2025

    Memory corruption when multiple listeners are being registered with the same file descriptor.

    Published: 6 May 2024
    8.4
    High

    CVE-2023-33119

    Last Modified: 16 Dec 2025

    Memory corruption while loading a VM from a signed VM image that is not coherent in the processor cache.

    Published: 6 May 2024
    7.5
    High

    CVE-2024-32972

    Last Modified: 15 Apr 2026

    go-ethereum (geth) is a golang execution layer implementation of the Ethereum protocol. Prior to 1.13.15, a vulnerable node can be made to consume very large amounts of memory when handling specially crafted p2p messages sent from an attacker node. The fix has been included in geth version `1.13.15` and onwards.

    Published: 6 May 2024
    7.5
    High

    CVE-2024-4549

    Last Modified: 17 Jun 2025

    A denial of service vulnerability exists in Delta Electronics DIAEnergie v1.10.1.8610 and prior. When processing an 'ICS Restart!' message, CEBC.exe restarts the system.

    Published: 6 May 2024
    9.8
    Critical

    CVE-2024-4548

    Last Modified: 27 Jun 2025

    An SQLi vulnerability exists in Delta Electronics DIAEnergie v1.10.1.8610 and prior when CEBC.exe processes a 'RecalculateHDMWYC' message, which is split into 4 fields using the '~' character as the separator. An unauthenticated remote attacker can perform SQLi via the fourth field.

    Published: 6 May 2024
    9.8
    Critical

    CVE-2024-4547

    Last Modified: 27 Jun 2025

    A SQLi vulnerability exists in Delta Electronics DIAEnergie v1.10.1.8610 and prior when CEBC.exe processes a 'RecalculateScript' message, which is splitted into 4 fields using the '~' character as the separator. An unauthenticated remote attacker can perform SQLi via the fourth field

    Published: 6 May 2024
    8.3
    High

    CVE-2024-3576

    Last Modified: 15 Apr 2026

    The NPort 5100A Series firmware version v1.6 and prior versions are affected by web server XSS vulnerability. The vulnerability is caused by not correctly neutralizing user-controllable input before placing it in output. Malicious users may use the vulnerability to get sensitive information and escalate privileges.

    Published: 6 May 2024
    5.5
    Medium

    CVE-2023-49676

    Last Modified: 15 Apr 2026

    An unauthenticated local attacker may trick a user to open corrupted project files to crash the system due to use after free vulnerability.

    Published: 6 May 2024
    7.8
    High

    CVE-2023-49675

    Last Modified: 15 Apr 2026

    An unauthenticated local attacker may trick a user to open corrupted project files to execute arbitrary code or crash the system due to an out-of-bounds write vulnerability.

    Published: 6 May 2024
    6.4
    Medium

    CVE-2023-6854

    Last Modified: 15 Apr 2026

    The Breakdance plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's custom postmeta output in all versions up to, and including, 1.7.0 due to insufficient input sanitization and output escaping on user supplied post meta fields. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 6 May 2024
    5.3
    Medium

    CVE-2024-23193

    Last Modified: 10 Apr 2025

    E-Mails exported as PDF were stored in a cache that did not consider specific session information for the related user account. Users of the same service node could access other users E-Mails in case they were exported as PDF for a brief moment until caches were cleared. Successful exploitation requires good timing and modification of multiple request parameters. Please deploy the provided updates and patch releases. The cache for PDF exports now takes user session information into consideration when performing authorization decisions. No publicly available exploits are known.

    Published: 6 May 2024
    6.5
    Medium

    CVE-2024-23188

    Last Modified: 15 Apr 2026

    Maliciously crafted E-Mail attachment names could be used to temporarily execute script code in the context of the users browser session. Common user interaction is required for the vulnerability to trigger. Attackers could perform malicious API requests or extract information from the users account. Please deploy the provided updates and patch releases. We now use safer methods of handling external content when embedding attachment information to the web interface. No publicly available exploits are known.

    Published: 6 May 2024
    6.5
    Medium

    CVE-2024-23187

    Last Modified: 13 Feb 2025

    Content-ID based embedding of resources in E-Mails could be abused to trigger client-side script code when using the "show more" option. Attackers could perform malicious API requests or extract information from the users account. Exploiting the vulnerability requires user interaction. Please deploy the provided updates and patch releases. CID replacement has been hardened to omit invalid identifiers. No publicly available exploits are known.

    Published: 6 May 2024
    6.5
    Medium

    CVE-2024-23186

    Last Modified: 13 Feb 2025

    E-Mail containing malicious display-name information could trigger client-side script execution when using specific mobile devices. Attackers could perform malicious API requests or extract information from the users account. Please deploy the provided updates and patch releases. We now use safer methods of handling external content when embedding displayname information to the web interface. No publicly available exploits are known.

    Published: 6 May 2024
    2.4
    Low

    CVE-2024-4528

    Last Modified: 10 Feb 2025

    A vulnerability was found in SourceCodester Prison Management System 1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /Admin/user-record.php. The manipulation of the argument txtfullname leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-263131.

    Published: 6 May 2024
    3.5
    Low

    CVE-2024-4527

    Last Modified: 19 Feb 2025

    A vulnerability was found in Campcodes Complete Web-Based School Management System 1.0. It has been classified as problematic. Affected is an unknown function of the file /view/student_payment_details2.php. The manipulation of the argument index leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-263130 is the identifier assigned to this vulnerability.

    Published: 6 May 2024
    3.5
    Low

    CVE-2024-4526

    Last Modified: 19 Feb 2025

    A vulnerability was found in Campcodes Complete Web-Based School Management System 1.0 and classified as problematic. This issue affects some unknown processing of the file /view/student_payment_details3.php. The manipulation of the argument month leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-263129 was assigned to this vulnerability.

    Published: 6 May 2024
    7.5
    High

    CVE-2024-3756

    Last Modified: 18 Apr 2025

    The MF Gig Calendar WordPress plugin through 1.2.1 does not have CSRF checks in some places, which could allow attackers to make logged in Contributors and above delete arbitrary events via a CSRF attack

    Published: 6 May 2024
    5.4
    Medium

    CVE-2024-3755

    Last Modified: 18 Apr 2025

    The MF Gig Calendar WordPress plugin through 1.2.1 does not sanitise and escape some of its settings, which could allow high privilege users such as editor to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

    Published: 6 May 2024
    5.4
    Medium

    CVE-2024-3752

    Last Modified: 8 May 2025

    The Crelly Slider WordPress plugin through 1.4.5 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

    Published: 6 May 2024
    3.5
    Low

    CVE-2024-4525

    Last Modified: 19 Feb 2025

    A vulnerability has been found in Campcodes Complete Web-Based School Management System 1.0 and classified as problematic. This vulnerability affects unknown code of the file /view/student_payment_details4.php. The manipulation of the argument index leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-263128.

    Published: 6 May 2024
    3.5
    Low

    CVE-2024-4524

    Last Modified: 19 Feb 2025

    A vulnerability, which was classified as problematic, was found in Campcodes Complete Web-Based School Management System 1.0. This affects an unknown part of the file /view/student_payment_invoice.php. The manipulation of the argument desc leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-263127.

    Published: 6 May 2024
    3.5
    Low

    CVE-2024-4523

    Last Modified: 19 Feb 2025

    A vulnerability, which was classified as problematic, has been found in Campcodes Complete Web-Based School Management System 1.0. Affected by this issue is some unknown functionality of the file /view/teacher_attendance_history1.php. The manipulation of the argument year leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-263126 is the identifier assigned to this vulnerability.

    Published: 6 May 2024
    3.5
    Low

    CVE-2024-4522

    Last Modified: 19 Feb 2025

    A vulnerability classified as problematic was found in Campcodes Complete Web-Based School Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /view/teacher_salary_details.php. The manipulation of the argument index leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-263125 was assigned to this vulnerability.

    Published: 6 May 2024
    3.5
    Low

    CVE-2024-4521

    Last Modified: 19 Feb 2025

    A vulnerability classified as problematic has been found in Campcodes Complete Web-Based School Management System 1.0. Affected is an unknown function of the file /view/teacher_salary_details2.php. The manipulation of the argument index leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-263124.

    Published: 6 May 2024
    3.5
    Low

    CVE-2024-4519

    Last Modified: 19 Feb 2025

    A vulnerability was found in Campcodes Complete Web-Based School Management System 1.0. It has been rated as problematic. This issue affects some unknown processing of the file /view/teacher_salary_details3.php. The manipulation of the argument month leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-263123.

    Published: 6 May 2024
    3.5
    Low

    CVE-2024-4518

    Last Modified: 19 Feb 2025

    A vulnerability was found in Campcodes Complete Web-Based School Management System 1.0. It has been declared as problematic. This vulnerability affects unknown code of the file /view/teacher_salary_invoice.php. The manipulation of the argument desc leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-263122 is the identifier assigned to this vulnerability.

    Published: 6 May 2024
    3.5
    Low

    CVE-2024-4517

    Last Modified: 19 Feb 2025

    A vulnerability was found in Campcodes Complete Web-Based School Management System 1.0. It has been classified as problematic. This affects an unknown part of the file /view/teacher_salary_invoice1.php. The manipulation of the argument date leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-263121 was assigned to this vulnerability.

    Published: 6 May 2024
    6.7
    Medium

    CVE-2024-20021

    Last Modified: 30 Apr 2025

    In atf spm, there is a possible way to remap physical memory to virtual memory due to a logic error. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08584568; Issue ID: MSV-1249.

    Published: 6 May 2024