CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2024-34506

    Last Modified: 4 Nov 2025

    An issue was discovered in includes/specials/SpecialMovePage.php in MediaWiki before 1.39.7, 1.40.x before 1.40.3, and 1.41.x before 1.41.1. If a user with the necessary rights to move the page opens Special:MovePage for a page with tens of thousands of subpages, then the page will exceed the maximum request time, leading to a denial of service.

    Published: 5 May 2024
    6.1
    Medium

    CVE-2024-34500

    Last Modified: 4 Nov 2025

    An issue was discovered in the UnlinkedWikibase extension in MediaWiki before 1.39.6, 1.40.x before 1.40.2, and 1.41.x before 1.41.1. XSS can occur through an interface message. Error messages (in the $err var) are not escaped before being passed to Html::rawElement() in the getError() function in the Hooks class.

    Published: 5 May 2024
    5.1
    Medium

    CVE-2024-34490

    Last Modified: 15 Apr 2026

    In Maxima through 5.47.0 before 51704c, the plotting facilities make use of predictable names under /tmp. Thus, the contents may be controlled by a local attacker who can create files in advance with these names. This affects, for example, plot2d.

    Published: 5 May 2024
    6.8
    Medium

    CVE-2024-34519

    Last Modified: 15 Apr 2026

    Avantra Server 24.x before 24.0.7 and 24.1.x before 24.1.1 mishandles the security of dashboards, aka XAN-5367. If a user can create a dashboard with an auto-login user, data disclosure may occur. Access control can be bypassed when there is a shared dashboard, and its auto-login user has privileges that a dashboard visitor should not have.

    Published: 5 May 2024
    7.5
    High

    CVE-2024-34489

    Last Modified: 15 Apr 2025

    OFPHello in parser.py in Faucet SDN Ryu 4.34 allows attackers to cause a denial of service (infinite loop) via length=0.

    Published: 5 May 2024
    8.8
    High

    CVE-2024-34515

    Last Modified: 15 Apr 2026

    image-optimizer before 1.7.3 allows PHAR deserialization, e.g., the phar:// protocol in arguments to file_exists().

    Published: 5 May 2024
    4.3
    Medium

    CVE-2024-34508

    Last Modified: 3 Nov 2025

    dcmnet in DCMTK before 3.6.9 has a segmentation fault via an invalid DIMSE message.

    Published: 5 May 2024
    5.3
    Medium

    CVE-2024-34509

    Last Modified: 3 Nov 2025

    dcmdata in DCMTK before 3.6.9 has a segmentation fault via an invalid DIMSE message.

    Published: 5 May 2024
    7.5
    High

    CVE-2024-34478

    Last Modified: 21 Aug 2025

    btcd before 0.24.0 does not correctly implement the consensus rules outlined in BIP 68 and BIP 112, making it susceptible to consensus failures. Specifically, it uses the transaction version as a signed integer when it is supposed to be treated as unsigned. There can be a chain split and loss of funds.

    Published: 5 May 2024
    7.5
    High

    CVE-2024-34483

    Last Modified: 15 Apr 2025

    OFPGroupDescStats in parser.py in Faucet SDN Ryu 4.34 allows attackers to cause a denial of service (infinite loop) via OFPBucket.len=0.

    Published: 5 May 2024
    5.3
    Medium

    CVE-2024-34484

    Last Modified: 15 Apr 2025

    OFPBucket in parser.py in Faucet SDN Ryu 4.34 allows attackers to cause a denial of service (infinite loop) via action.len=0.

    Published: 5 May 2024
    7.5
    High

    CVE-2024-34486

    Last Modified: 15 Apr 2025

    OFPPacketQueue in parser.py in Faucet SDN Ryu 4.34 allows attackers to cause a denial of service (infinite loop) via OFPQueueProp.len=0.

    Published: 5 May 2024
    7.5
    High

    CVE-2024-34487

    Last Modified: 15 Apr 2025

    OFPFlowStats in parser.py in Faucet SDN Ryu 4.34 allows attackers to cause a denial of service (infinite loop) via inst.length=0.

    Published: 5 May 2024
    7.5
    High

    CVE-2024-34488

    Last Modified: 15 Apr 2025

    OFPMultipartReply in parser.py in Faucet SDN Ryu 4.34 allows attackers to cause a denial of service (infinite loop) via b.length=0.

    Published: 5 May 2024
    9.8
    Critical

    CVE-2024-34502

    Last Modified: 4 Nov 2025

    An issue was discovered in WikibaseLexeme in MediaWiki before 1.39.6, 1.40.x before 1.40.2, and 1.41.x before 1.41.1. Loading Special:MergeLexemes will (attempt to) make an edit that merges the from-id to the to-id, even if the request was not a POST request, and even if it does not contain an edit token.

    Published: 5 May 2024
    7.4
    High

    CVE-2024-34507

    Last Modified: 4 Nov 2025

    An issue was discovered in includes/CommentFormatter/CommentParser.php in MediaWiki before 1.39.7, 1.40.x before 1.40.3, and 1.41.x before 1.41.1. XSS can occur because of mishandling of the 0x1b character, as demonstrated by Special:RecentChanges#%1b0000000.

    Published: 5 May 2024
    7.5
    High

    CVE-2024-34510

    Last Modified: 17 Jun 2025

    Gradio before 4.20 allows credential leakage on Windows.

    Published: 5 May 2024
    —
    Unknown

    CVE-2024-34511

    Last Modified: 14 May 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2024-1561. Reason: This candidate is a duplicate of CVE-2024-1561. Notes: All CVE users should reference CVE-2024-1561 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage.

    Published: 5 May 2024
    4.8
    Medium

    CVE-2024-34529

    Last Modified: 15 Apr 2026

    Nebari through 2024.4.1 prints the temporary Keycloak root password.

    Published: 5 May 2024
    7.7
    High

    CVE-2024-34528

    Last Modified: 15 Apr 2026

    WordOps through 3.20.0 has a wo/cli/plugins/stack_pref.py TOCTOU race condition because the conf_path os.open does not use a mode parameter during file creation.

    Published: 5 May 2024
    8.8
    High

    CVE-2024-4491

    Last Modified: 27 Jan 2025

    A vulnerability classified as critical was found in Tenda i21 1.0.0.14(4656). This vulnerability affects the function formGetDiagnoseInfo. The manipulation of the argument cmdinput leads to stack-based buffer overflow. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-263080. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 4 May 2024
    5.3
    Medium

    CVE-2023-27283

    Last Modified: 7 Jan 2025

    IBM Aspera Orchestrator 4.0.1 could allow a remote attacker to enumerate usernames due to observable response discrepancies. IBM X-Force ID: 248545.

    Published: 4 May 2024
    4.3
    Medium

    CVE-2024-1050

    Last Modified: 15 Apr 2026

    The Import and export users and customers plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the ajax_force_reset_password_delete_metas() function in all versions up to, and including, 1.26.5. This makes it possible for authenticated attackers, with subscriber-level access and above, to delete all forced password resets. CVE-2024-34815 is a duplicate of this issue.

    Published: 4 May 2024
    5.4
    Medium

    CVE-2023-7065

    Last Modified: 15 Apr 2026

    The Stop Spammers Security | Block Spam Users, Comments, Forms plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2024.4. This is due to missing or incorrect nonce validation on the sfs_process AJAX action. This makes it possible for unauthenticated attackers to add arbitrary IPs to the plugin's allowlist and blocklist via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

    Published: 4 May 2024
    8.8
    High

    CVE-2024-3240

    Last Modified: 15 Apr 2026

    The ConvertPlug plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.5.25 via deserialization of untrusted input from the 'settings_encoded' attribute of the 'smile_info_bar' shortcode. This makes it possible for authenticated attackers, with contributor-level access and above, to inject a PHP Object. No POP chain is present in the vulnerable plugin. If a POP chain is present via an additional plugin or theme installed on the target system, it could allow the attacker to delete arbitrary files, retrieve sensitive data, or execute code.

    Published: 4 May 2024
    5.4
    Medium

    CVE-2024-3237

    Last Modified: 15 Apr 2026

    The ConvertPlug plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the cp_dismiss_notice() function in all versions up to, and including, 3.5.25. This makes it possible for authenticated attackers, with subscriber-level access and above, to update arbitrary option values to true.

    Published: 4 May 2024
    5.4
    Medium

    CVE-2024-3868

    Last Modified: 15 Apr 2026

    The Folders Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via a user's First Name and Last Name in all versions up to, and including, 3.0.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 4 May 2024
    5.3
    Medium

    CVE-2024-34473

    Last Modified: 15 Apr 2026

    An issue was discovered in appmgr in O-RAN Near-RT RIC I-Release. An attacker could register an unintended RMR message type during xApp registration to disrupt other service components.

    Published: 4 May 2024
    9.8
    Critical

    CVE-2024-34461

    Last Modified: 15 Apr 2026

    Zenario before 9.5.60437 uses Twig filters insecurely in the Twig Snippet plugin, and in the site-wide HEAD and BODY elements, enabling code execution by a designer or an administrator.

    Published: 4 May 2024
    6.5
    Medium

    CVE-2024-34460

    Last Modified: 15 Apr 2026

    The Tree Explorer tool from Organizer in Zenario before 9.5.60602 is affected by XSS. (This component was removed in 9.5.60602.)

    Published: 4 May 2024
    6.1
    Medium

    CVE-2024-34468

    Last Modified: 17 Jun 2025

    Rukovoditel before 3.5.3 allows XSS via user_photo to My Page.

    Published: 4 May 2024
    6.1
    Medium

    CVE-2024-34462

    Last Modified: 10 Jun 2025

    Alinto SOGo through 5.10.0 allows XSS during attachment preview.

    Published: 4 May 2024
    —
    Unknown

    CVE-2024-34466

    Last Modified: 6 May 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2024-34467. Reason: This candidate is a reservation duplicate of CVE-2024-34467. Notes: All CVE users should reference CVE-2024-34467 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage.

    Published: 4 May 2024
    6.1
    Medium

    CVE-2024-34467

    Last Modified: 17 Jun 2025

    ThinkPHP 8.0.3 allows remote attackers to exploit XSS due to inadequate filtering of function argument values in think_exception.tpl.

    Published: 4 May 2024
    7.1
    High

    CVE-2024-34469

    Last Modified: 17 Jun 2025

    Rukovoditel before 3.5.3 allows XSS via user_photo to index.php?module=users/registration&action=save.

    Published: 4 May 2024
    7.5
    High

    CVE-2024-34475

    Last Modified: 22 Apr 2025

    Open5GS before 2.7.1 is vulnerable to a reachable assertion that can cause an AMF crash via NAS messages from a UE: gmm_state_authentication in amf/gmm-sm.c for != OGS_ERROR.

    Published: 4 May 2024
    5.3
    Medium

    CVE-2024-34476

    Last Modified: 22 Apr 2025

    Open5GS before 2.7.1 is vulnerable to a reachable assertion that can cause an AMF crash via NAS messages from a UE: ogs_nas_encrypt in lib/nas/common/security.c for pkbuf->len.

    Published: 4 May 2024
    7.5
    High

    CVE-2023-52729

    Last Modified: 15 Apr 2026

    TCPServer.cpp in SimpleNetwork through 29bc615 has an off-by-one error that causes a buffer overflow when trying to add '\0' to the end of long msg data. It can be exploited via crafted TCP packets.

    Published: 4 May 2024
    6.3
    Medium

    CVE-2023-40695

    Last Modified: 7 Jan 2025

    IBM Cognos Controller 10.4.1, 10.4.2, and 11.0.0 does not invalidate session after logout which could allow an authenticated user to impersonate another user on the system. IBM X-Force ID: 264938.

    Published: 3 May 2024
    6
    Medium

    CVE-2021-20451

    Last Modified: 7 Jan 2025

    IBM Cognos Controller 10.4.1, 10.4.2, and 11.0.0 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 196643.

    Published: 3 May 2024
    5.3
    Medium

    CVE-2022-22364

    Last Modified: 7 Jan 2025

    IBM Cognos Controller 10.4.1, 10.4.2, and 11.0.0 is vulnerable to external service interaction attack, caused by improper validation of user-supplied input. A remote attacker could exploit this vulnerability to induce the application to perform server-side DNS lookups or HTTP requests to arbitrary domain names. By submitting suitable payloads, an attacker can cause the application server to attack other systems that it can interact with. IBM X-Force ID: 220903.

    Published: 3 May 2024
    6.2
    Medium

    CVE-2024-34075

    Last Modified: 15 Apr 2026

    kurwov is a fast, dependency-free library for creating Markov Chains. An unsafe sanitization of dataset contents on the `MarkovData#getNext` method used in `Markov#generate` and `Markov#choose` allows a maliciously crafted string on the dataset to throw and stop the function from running properly. If a string contains a forbidden substring (i.e. `__proto__`) followed by a space character, the code will access a special property in `MarkovData#finalData` by removing the last character of the string, bypassing the dataset sanitization (as it is supposed to be already sanitized before this function is called). Any dataset can be contaminated with the substring making it unable to properly generate anything in some cases. This issue has been addressed in version 3.2.5 and all users are advised to upgrade. There are no known workarounds for this vulnerability.

    Published: 3 May 2024
    8.4
    High

    CVE-2024-34066

    Last Modified: 21 Feb 2025

    Pterodactyl wings is the server control plane for Pterodactyl Panel. If the Wings token is leaked either by viewing the node configuration or posting it accidentally somewhere, an attacker can use it to gain arbitrary file write and read access on the node the token is associated to. This issue has been addressed in version 1.11.12 and users are advised to upgrade. Users unable to upgrade may enable the `ignore_panel_config_updates` option as a workaround.

    Published: 3 May 2024
    5.3
    Medium

    CVE-2023-28952

    Last Modified: 7 Jan 2025

    IBM Cognos Controller 10.4.1, 10.4.2, and 11.0.0 is vulnerable to injection attacks in application logging by not sanitizing user provided data. IBM X-Force ID: 251463.

    Published: 3 May 2024
    6.1
    Medium

    CVE-2024-34067

    Last Modified: 6 Jun 2025

    Pterodactyl is a free, open-source game server management panel built with PHP, React, and Go. Importing a malicious egg or gaining access to wings instance could lead to cross site scripting (XSS) on the panel, which could be used to gain an administrator account on the panel. Specifically, the following things are impacted: Egg Docker images and Egg variables: Name, Environment variable, Default value, Description, Validation rules. Additionally, certain fields would reflect malicious input, but it would require the user knowingly entering such input to have an impact. To iterate, this would require an administrator to perform actions and can't be triggered by a normal panel user. This issue has has been addressed in version 1.11.6 and users are advised to upgrade. No workaround is available other than updating to the latest version of the panel.

    Published: 3 May 2024
    6.3
    Medium

    CVE-2023-38724

    Last Modified: 14 Jan 2025

    IBM Cognos Controller 10.4.1, 10.4.2, and 11.0.0 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 262183.

    Published: 3 May 2024
    5.9
    Medium

    CVE-2023-40696

    Last Modified: 7 Jan 2025

    IBM Cognos Controller 10.4.1, 10.4.2, and 11.0.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 264939.

    Published: 3 May 2024
    6.4
    Medium

    CVE-2024-34068

    Last Modified: 21 Feb 2025

    Pterodactyl wings is the server control plane for Pterodactyl Panel. An authenticated user who has access to a game server is able to bypass the previously implemented access control (GHSA-6rg3-8h8x-5xfv) that prevents accessing internal endpoints of the node hosting Wings in the pull endpoint. This would allow malicious users to potentially access resources on local networks that would otherwise be inaccessible. This issue has been addressed in version 1.11.2 and users are advised to upgrade. Users unable to upgrade may enable the `api.disable_remote_download` option as a workaround.

    Published: 3 May 2024
    5.3
    Medium

    CVE-2021-20556

    Last Modified: 7 Jan 2025

    IBM Cognos Controller 10.4.1, 10.4.2, and 11.0.0 could allow a remote user to enumerate usernames due to differentiating error messages on existing usernames. IBM X-Force ID: 199181.

    Published: 3 May 2024
    3.7
    Low

    CVE-2023-23474

    Last Modified: 7 Jan 2025

    IBM Cognos Controller 10.4.1, 10.4.2, and 11.0.0 could allow a remote attacker to obtain sensitive information when a stack trace is returned in the browser. IBM X-Force ID: 245403.

    Published: 3 May 2024