CVE Feed

    Dashboard / CVE

    8
    High

    CVE-2024-25290

    Last Modified: 15 Apr 2026

    An issue in Casa Systems NL1901ACV R6B032 allows a remote attacker to execute arbitrary code via the userName parameter of the add function.

    Published: 2 May 2024
    6.2
    Medium

    CVE-2024-4418

    Last Modified: 15 Apr 2026

    A race condition leading to a stack use-after-free flaw was found in libvirt. Due to a bad assumption in the virNetClientIOEventLoop() method, the `data` pointer to a stack-allocated virNetClientIOEventData structure ended up being used in the virNetClientIOEventFD callback while the data pointer's stack frame was concurrently being "freed" when returning from virNetClientIOEventLoop(). The 'virtproxyd' daemon can be used to trigger requests. If libvirt is configured with fine-grained access control, this issue, in theory, allows a user to escape their otherwise limited access. This flaw allows a local, unprivileged user to access virtproxyd without authenticating. Remote users would need to authenticate before they could access it.

    Published: 2 May 2024
    8.8
    High

    CVE-2024-34145

    Last Modified: 10 Oct 2025

    A sandbox bypass vulnerability involving sandbox-defined classes that shadow specific non-sandbox-defined classes in Jenkins Script Security Plugin 1335.vf07d9ce377a_e and earlier allows attackers with permission to define and run sandboxed scripts, including Pipelines, to bypass the sandbox protection and execute arbitrary code in the context of the Jenkins controller JVM.

    Published: 2 May 2024
    7.5
    High

    CVE-2023-50685

    Last Modified: 15 Apr 2026

    An issue in Hipcam Cameras RealServer v.1.0 allows a remote attacker to cause a denial of service via a crafted script to the client_port parameter.

    Published: 2 May 2024
    6.5
    Medium

    CVE-2024-34146

    Last Modified: 10 Oct 2025

    Jenkins Git server Plugin 114.v068a_c7cc2574 and earlier does not perform a permission check for read access to a Git repository over SSH, allowing attackers with a previously configured SSH public key but lacking Overall/Read permission to access these repositories.

    Published: 2 May 2024
    9.8
    Critical

    CVE-2024-34144

    Last Modified: 10 Oct 2025

    A sandbox bypass vulnerability involving crafted constructor bodies in Jenkins Script Security Plugin 1335.vf07d9ce377a_e and earlier allows attackers with permission to define and run sandboxed scripts, including Pipelines, to bypass the sandbox protection and execute arbitrary code in the context of the Jenkins controller JVM.

    Published: 2 May 2024
    5.9
    Medium

    CVE-2024-33394

    Last Modified: 7 Jul 2025

    An issue in kubevirt kubevirt v1.2.0 and before allows a local attacker to execute arbitrary code via a crafted command to get the token component.

    Published: 2 May 2024
    8.4
    High

    CVE-2024-33396

    Last Modified: 15 Apr 2026

    An issue in karmada-io karmada v1.9.0 and before allows a local attacker to execute arbitrary code via a crafted command to get the token component.

    Published: 2 May 2024
    6.1
    Medium

    CVE-2024-33305

    Last Modified: 22 Apr 2025

    SourceCodester Laboratory Management System 1.0 is vulnerable to Cross Site Scripting (XSS) via "Middle Name" parameter in Create User.

    Published: 2 May 2024
    8.2
    High

    CVE-2024-33303

    Last Modified: 22 Apr 2025

    SourceCodester Product Show Room 1.0 is vulnerable to Cross Site Scripting (XSS) via "First Name" under Add Users.

    Published: 2 May 2024
    8.8
    High

    CVE-2024-33871

    Last Modified: 16 Apr 2025

    An issue was discovered in Artifex Ghostscript before 10.03.1. contrib/opvp/gdevopvp.c allows arbitrary code execution via a custom Driver library, exploitable via a crafted PostScript document. This occurs because the Driver parameter for opvp (and oprp) devices can have an arbitrary name for a dynamic library; this library is then loaded.

    Published: 2 May 2024
    7.5
    High

    CVE-2024-31964

    Last Modified: 15 Apr 2026

    A vulnerability on Mitel 6800 Series and 6900 Series SIP Phones through 6.3 SP3 HF4, 6900w Series SIP Phone through 6.3.3, and 6970 Conference Unit through 5.1.1 SP8 allows an unauthenticated attacker to conduct an authentication bypass attack due to improper authentication control. A successful exploit could allow an attacker to modify system configuration settings and potentially cause a denial of service.

    Published: 2 May 2024
    10
    Critical

    CVE-2024-32962

    Last Modified: 15 Apr 2026

    xml-crypto is an xml digital signature and encryption library for Node.js. In affected versions the default configuration does not check authorization of the signer, it only checks the validity of the signature per section 3.2.2 of the w3 xmldsig-core-20080610 spec. As such, without additional validation steps, the default configuration allows a malicious actor to re-sign an XML document, place the certificate in a `<KeyInfo />` element, and pass `xml-crypto` default validation checks. As a result `xml-crypto` trusts by default any certificate provided via digitally signed XML document's `<KeyInfo />`. `xml-crypto` prefers to use any certificate provided via digitally signed XML document's `<KeyInfo />` even if library was configured to use specific certificate (`publicCert`) for signature verification purposes. An attacker can spoof signature verification by modifying XML document and replacing existing signature with signature generated with malicious private key (created by attacker) and by attaching that private key's certificate to `<KeyInfo />` element. This vulnerability is combination of changes introduced to `4.0.0` on pull request 301 / commit `c2b83f98` and has been addressed in version 6.0.0 with pull request 445 / commit `21201723d`. Users are advised to upgrade. Users unable to upgrade may either check the certificate extracted via `getCertFromKeyInfo` against trusted certificates before accepting the results of the validation or set `xml-crypto's getCertFromKeyInfo` to `() => undefined` forcing `xml-crypto` to use an explicitly configured `publicCert` or `privateKey` for signature verification.

    Published: 2 May 2024
    7.7
    High

    CVE-2024-29309

    Last Modified: 15 Apr 2026

    An issue in Alfresco Content Services v.23.3.0.7 allows a remote attacker to execute arbitrary code via the Transfer Service.

    Published: 2 May 2024
    4.2
    Medium

    CVE-2024-31965

    Last Modified: 15 Apr 2026

    A vulnerability on Mitel 6800 Series and 6900 Series SIP Phones through 6.3 SP3 HF4, 6900w Series SIP Phone through 6.3.3, and 6970 Conference Unit through 5.1.1 SP8 allows an authenticated attacker with administrative privilege to conduct a path traversal attack due to insufficient input validation. A successful exploit could allow an attacker to access sensitive information.

    Published: 2 May 2024
    9.1
    Critical

    CVE-2024-31967

    Last Modified: 15 Apr 2026

    A vulnerability on Mitel 6800 Series and 6900 Series SIP Phones through 6.3 SP3 HF4, 6900w Series SIP Phone through 6.3.3, and 6970 Conference Unit through 5.1.1 SP8 allows an unauthenticated attacker to conduct an unauthorized access attack due to improper access control. A successful exploit could allow an attacker to gain unauthorized access to user information or the system configuration.

    Published: 2 May 2024
    6.9
    Medium

    CVE-2024-32359

    Last Modified: 15 Apr 2026

    An RBAC authorization risk in Carina v0.13.0 and earlier allows local attackers to execute arbitrary code through designed commands to obtain the secrets of the entire cluster and further take over the cluster.

    Published: 2 May 2024
    7.5
    High

    CVE-2024-30251

    Last Modified: 3 Nov 2025

    aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. In affected versions an attacker can send a specially crafted POST (multipart/form-data) request. When the aiohttp server processes it, the server will enter an infinite loop and be unable to process any further requests. An attacker can stop the application from serving requests after sending a single request. This issue has been addressed in version 3.9.4. Users are advised to upgrade. Users unable to upgrade may manually apply a patch to their systems. Please see the linked GHSA for instructions.

    Published: 2 May 2024
    5.3
    Medium

    CVE-2024-33302

    Last Modified: 22 Apr 2025

    SourceCodester Product Show Room 1.0 and before is vulnerable to Cross Site Scripting (XSS) via "Middle Name" under Add Users.

    Published: 2 May 2024
    6.8
    Medium

    CVE-2023-51631

    Last Modified: 7 Aug 2025

    D-Link DIR-X3260 prog.cgi SetUsersSettings Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DIR-X3260 routers. Authentication is required to exploit this vulnerability. The specific flaw exists within the prog.cgi binary, which handles HNAP requests made to the lighttpd webserver listening on TCP ports 80 and 443. The issue results from the lack of proper validation of a user-supplied string before copying it to a fixed-size stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-21675.

    Published: 1 May 2024
    9
    Critical

    CVE-2024-4142

    Last Modified: 15 Apr 2026

    An Improper input validation vulnerability that could potentially lead to privilege escalation was discovered in JFrog Artifactory. Due to this vulnerability, users with low privileges may gain administrative access to the system. This issue can also be exploited in Artifactory platforms with anonymous access enabled.

    Published: 1 May 2024
    —
    Unknown

    CVE-2024-34157

    Last Modified: 13 Feb 2026

    reserved but not needed

    Published: 1 May 2024
    —
    Unknown

    CVE-2024-34154

    Last Modified: 13 Feb 2026

    reserved but not needed

    Published: 1 May 2024
    7.5
    High

    CVE-2024-29011

    Last Modified: 15 Apr 2026

    Use of hard-coded password in the GMS ECM endpoint leading to authentication bypass vulnerability. This issue affects GMS: 9.3.4 and earlier versions.

    Published: 1 May 2024
    7.1
    High

    CVE-2024-29010

    Last Modified: 15 Apr 2026

    The XML document processed in the GMS ECM URL endpoint is vulnerable to XML external entity (XXE) injection, potentially resulting in the disclosure of sensitive information. This issue affects GMS: 9.3.4 and earlier versions.

    Published: 1 May 2024
    7.9
    High

    CVE-2023-7241

    Last Modified: 15 Apr 2026

    Privilege Escalation in WRSA.EXE in Webroot Antivirus 8.0.1X- 9.0.35.12 on Windows64 bit and 32 bit allows malicious software to abuse WRSA.EXE to delete arbitrary and protected files.

    Published: 1 May 2024
    7.5
    High

    CVE-2024-20376

    Last Modified: 5 Jan 2026

    A vulnerability in the web-based management interface of Cisco IP Phone firmware could allow an unauthenticated, remote attacker to cause an affected device to reload, resulting in a DoS condition. This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by sending a crafted request to the web-based management interface of an affected device. A successful exploit could allow the attacker to cause the affected device to reload.

    Published: 1 May 2024
    7.5
    High

    CVE-2024-20378

    Last Modified: 5 Jan 2026

    A vulnerability in the web-based management interface of Cisco IP Phone firmware could allow an unauthenticated, remote attacker to retrieve sensitive information from an affected device. This vulnerability is due to a lack of authentication for specific endpoints of the web-based management interface on an affected device. An attacker could exploit this vulnerability by connecting to the affected device. A successful exploit could allow the attacker to gain unauthorized access to the device, enabling the recording of user credentials and traffic to and from the affected device, including VoIP calls that could be replayed.

    Published: 1 May 2024
    5.9
    Medium

    CVE-2024-20357

    Last Modified: 5 Jan 2026

    A vulnerability in the XML service of Cisco IP Phone firmware could allow an unauthenticated, remote attacker to initiate phone calls on an affected device. This vulnerability exists because bounds-checking does not occur while parsing XML requests. An attacker could exploit this vulnerability by sending a crafted XML request to an affected device. A successful exploit could allow the attacker to initiate calls or play sounds on the device.

    Published: 1 May 2024
    6.5
    Medium

    CVE-2024-28764

    Last Modified: 11 Apr 2025

    IBM WebSphere Automation 1.7.0 could allow an attacker with privileged access to the network to conduct a CSV injection. An attacker could execute arbitrary commands on the system, caused by improper validation of csv file contents. IBM X-Force ID: 285623.

    Published: 1 May 2024
    5.3
    Medium

    CVE-2024-33518

    Last Modified: 25 Jul 2025

    An unauthenticated Denial-of-Service (DoS) vulnerability exists in the Radio Frequency Manager service accessed via the PAPI protocol. Successful exploitation of this vulnerability results in the ability to interrupt the normal operation of the affected service.

    Published: 1 May 2024
    5.3
    Medium

    CVE-2024-33517

    Last Modified: 28 Jul 2025

    An unauthenticated Denial-of-Service (DoS) vulnerability exists in the Radio Frequency Manager service accessed via the PAPI protocol. Successful exploitation of this vulnerability results in the ability to interrupt the normal operation of the affected service.

    Published: 1 May 2024
    5.3
    Medium

    CVE-2024-33516

    Last Modified: 28 Jul 2025

    An unauthenticated Denial of Service (DoS) vulnerability exists in the Auth service accessed via the PAPI protocol provided by ArubaOS. Successful exploitation of this vulnerability results in the ability to interrupt the normal operation of the controller.

    Published: 1 May 2024
    5.3
    Medium

    CVE-2024-33515

    Last Modified: 28 Jul 2025

    Unauthenticated Denial-of-Service (DoS) vulnerabilities exist in the AP Management service accessed via the PAPI protocol. Successful exploitation of these vulnerabilities results in the ability to interrupt the normal operation of the affected service.

    Published: 1 May 2024
    7.5
    High

    CVE-2024-23480

    Last Modified: 17 Feb 2026

    A fallback mechanism in code sign checking on macOS may allow arbitrary code execution. This issue affects Zscaler Client Connector on MacOS prior to 4.2.

    Published: 1 May 2024
    5.3
    Medium

    CVE-2024-33514

    Last Modified: 28 Jul 2025

    Unauthenticated Denial-of-Service (DoS) vulnerabilities exist in the AP Management service accessed via the PAPI protocol. Successful exploitation of these vulnerabilities results in the ability to interrupt the normal operation of the affected service.

    Published: 1 May 2024
    7.8
    High

    CVE-2024-23457

    Last Modified: 2 Mar 2026

    The anti-tampering functionality of the Zscaler Client Connector can be disabled under certain conditions when an uninstall password is enforced. This affects Zscaler Client Connector on Windows prior to 4.2.0.209

    Published: 1 May 2024
    7.5
    High

    CVE-2024-25015

    Last Modified: 21 Aug 2025

    IBM MQ 9.2 LTS, 9.3 LTS, and 9.3 CD Internet Pass-Thru could allow a remote user to cause a denial of service by sending HTTP requests that would consume all available resources. IBM X-Force ID: 281278.

    Published: 1 May 2024
    5.9
    Medium

    CVE-2024-33513

    Last Modified: 27 Aug 2025

    Unauthenticated Denial-of-Service (DoS) vulnerabilities exist in the AP Management service accessed via the PAPI protocol. Successful exploitation of these vulnerabilities results in the ability to interrupt the normal operation of the affected service.

    Published: 1 May 2024
    7.7
    High

    CVE-2024-28893

    Last Modified: 14 Jan 2026

    Certain HP software packages (SoftPaqs) are potentially vulnerable to arbitrary code execution when the SoftPaq configuration file has been modified after extraction. HP has released updated software packages (SoftPaqs).

    Published: 1 May 2024
    9.8
    Critical

    CVE-2023-47212

    Last Modified: 4 Nov 2025

    A heap-based buffer overflow vulnerability exists in the comment functionality of stb _vorbis.c v1.22. A specially crafted .ogg file can lead to an out-of-bounds write. An attacker can provide a malicious file to trigger this vulnerability.

    Published: 1 May 2024
    8.8
    High

    CVE-2023-47166

    Last Modified: 4 Nov 2025

    A firmware update vulnerability exists in the luci2-io file-import functionality of Milesight UR32L v32.3.0.7-r2. A specially crafted network request can lead to arbitrary firmware update. An attacker can send a network request to trigger this vulnerability.

    Published: 1 May 2024
    9.8
    Critical

    CVE-2023-49606

    Last Modified: 4 Nov 2025

    A use-after-free vulnerability exists in the HTTP Connection Headers parsing in Tinyproxy 1.11.1 and Tinyproxy 1.10.0. A specially crafted HTTP header can trigger reuse of previously freed memory, which leads to memory corruption and could lead to remote code execution. An attacker needs to make an unauthenticated HTTP request to trigger this vulnerability.

    Published: 1 May 2024
    —
    Unknown

    CVE-2023-40533

    Last Modified: 8 May 2024

    This CVE ID is a duplicate of CVE-2022-40468

    Published: 1 May 2024
    9.8
    Critical

    CVE-2024-33512

    Last Modified: 15 Apr 2026

    There is a buffer overflow vulnerability in the underlying Local User Authentication Database service that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's access point management protocol) UDP port (8211). Successful exploitation of this vulnerability results in the ability to execute arbitrary code as a privileged user on the underlying operating system.

    Published: 1 May 2024
    9.8
    Critical

    CVE-2024-33511

    Last Modified: 15 Apr 2026

    There is a buffer overflow vulnerability in the underlying Automatic Reporting service that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's access point management protocol) UDP port (8211). Successful exploitation of this vulnerability results in the ability to execute arbitrary code as a privileged user on the underlying operating system.

    Published: 1 May 2024
    9.8
    Critical

    CVE-2024-26305

    Last Modified: 22 Sept 2026

    There is a buffer overflow vulnerability in the underlying Utility daemon that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's access point management protocol) UDP port (8211). Successful exploitation of this vulnerability results in the ability to execute arbitrary code as a privileged user on the underlying operating system.

    Published: 1 May 2024
    9.8
    Critical

    CVE-2024-26304

    Last Modified: 15 Apr 2026

    There is a buffer overflow vulnerability in the underlying L2/L3 Management service that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's access point management protocol) UDP port (8211). Successful exploitation of this vulnerability results in the ability to execute arbitrary code as a privileged user on the underlying operating system.

    Published: 1 May 2024
    —
    Unknown

    CVE-2024-4387

    Last Modified: 11 Jun 2024

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

    Published: 1 May 2024
    6.7
    Medium

    CVE-2024-24912

    Last Modified: 26 Aug 2025

    A local privilege escalation vulnerability has been identified in Harmony Endpoint Security Client for Windows versions E88.10 and below. To exploit this vulnerability, an attacker must first obtain the ability to execute local privileged code on the target system.

    Published: 1 May 2024