CVE Feed

    Dashboard / CVE

    6.5
    Medium

    CVE-2024-33649

    Last Modified: 28 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WpOpal Opal Widgets For Elementor allows Stored XSS.This issue affects Opal Widgets For Elementor: from n/a through 1.6.9.

    Published: 29 Apr 2024
    8.8
    High

    CVE-2024-4301

    Last Modified: 15 Apr 2026

    N-Reporter and N-Cloud, products of the N-Partner, have an OS Command Injection vulnerability. Remote attackers with normal user privilege can execute arbitrary system commands by manipulating user inputs on a specific page.

    Published: 29 Apr 2024
    9.8
    Critical

    CVE-2024-4300

    Last Modified: 15 Apr 2026

    E-WEBInformationCo. FS-EZViewer(Web) exposes sensitive information in the service. A remote attacker can obtain the database configuration file path through the webpage source code without login. Accessing this path allows attacker to obtain the database credential with the highest privilege and database host IP address. With this information, attackers can connect to the database and perform actions such as adding, modifying, or deleting database contents.

    Published: 29 Apr 2024
    7.2
    High

    CVE-2024-4299

    Last Modified: 26 Jan 2026

    The system configuration interface of HGiga iSherlock (including MailSherlock, SpamSherock, AuditSherlock) fails to filter special characters in certain function parameters, allowing remote attackers with administrative privileges to exploit this vulnerability for Command Injection attacks, enabling execution of arbitrary system commands.

    Published: 29 Apr 2024
    7.2
    High

    CVE-2024-4298

    Last Modified: 26 Jan 2026

    The email search interface of HGiga iSherlock (including MailSherlock, SpamSherock, AuditSherlock) fails to filter special characters in certain function parameters, allowing remote attackers with administrative privileges to exploit this vulnerability for Command Injection attacks, enabling execution of arbitrary system commands.

    Published: 29 Apr 2024
    4.9
    Medium

    CVE-2024-4297

    Last Modified: 26 Jan 2026

    The system configuration interface of HGiga iSherlock (including MailSherlock, SpamSherlock, AuditSherlock) fails to filter special characters in certain function parameters, allowing remote attackers with administrative privileges to exploit this vulnerability to download arbitrary system files.

    Published: 29 Apr 2024
    4.9
    Medium

    CVE-2024-4296

    Last Modified: 26 Jan 2026

    The account management interface of HGiga iSherlock (including MailSherlock, SpamSherlock, AuditSherlock) fails to filter special characters in certain function parameters, allowing remote attackers with administrative privileges to exploit this vulnerability to download arbitrary system files.

    Published: 29 Apr 2024
    7.5
    High

    CVE-2024-34046

    Last Modified: 24 Aug 2026

    The O-RAN E2T I-Release Prometheus metric Increment function can crash in sctpThread.cpp for message.peerInfo->sctpParams->e2tCounters[IN_SUCC][MSG_COUNTER][ProcedureCode_id_RICsubscription]->Increment().

    Published: 29 Apr 2024
    7.5
    High

    CVE-2024-34045

    Last Modified: 24 Aug 2026

    The O-RAN E2T I-Release Prometheus metric Increment function can crash in sctpThread.cpp for message.peerInfo->counters[IN_INITI][MSG_COUNTER][ProcedureCode_id_E2setup]->Increment().

    Published: 29 Apr 2024
    5.3
    Medium

    CVE-2024-34044

    Last Modified: 15 Apr 2026

    The O-RAN E2T I-Release buildPrometheusList function can have a NULL pointer dereference because peerInfo can be NULL.

    Published: 29 Apr 2024
    6.5
    Medium

    CVE-2024-34020

    Last Modified: 15 Apr 2026

    A stack-based buffer overflow was found in the putSDN() function of mail.c in hcode through 2.1.

    Published: 29 Apr 2024
    7
    High

    CVE-2024-33904

    Last Modified: 15 Apr 2026

    In plugins/HookSystem.cpp in Hyprland through 0.39.1 (before 28c8561), through a race condition, a local attacker can cause execution of arbitrary assembly code by writing to a predictable temporary file.

    Published: 29 Apr 2024
    9.8
    Critical

    CVE-2024-33266

    Last Modified: 15 Apr 2026

    SQL Injection vulnerability in Helloshop deliveryorderautoupdate v.2.8.1 and before allows an attacker to run arbitrary SQL commands via the DeliveryorderautoupdateOrdersModuleFrontController::initContent function.

    Published: 29 Apr 2024
    3.3
    Low

    CVE-2024-32268

    Last Modified: 15 Apr 2026

    An issue in Tuya Smart camera U6N v.3.2.5 allows a remote attacker to cause a denial of service via a crafted packet to the network connection component.

    Published: 29 Apr 2024
    7.5
    High

    CVE-2024-31801

    Last Modified: 15 Apr 2026

    Directory Traversal vulnerability in NEXSYS-ONE before v.Rev.15320 allows a remote attacker to obtain sensitive information via a crafted request.

    Published: 29 Apr 2024
    9.8
    Critical

    CVE-2024-31705

    Last Modified: 15 Apr 2026

    An issue in Infotel Conseil GLPI v.10.X.X and after allows a remote attacker to execute arbitrary code via the insufficient validation of user-supplied input.

    Published: 29 Apr 2024
    7.8
    High

    CVE-2024-27518

    Last Modified: 15 Apr 2026

    An issue in SUPERAntiSyware Professional X 10.0.1262 and 10.0.1264 allows unprivileged attackers to escalate privileges via a restore of a crafted DLL file into the C:\Program Files\SUPERAntiSpyware folder.

    Published: 29 Apr 2024
    6.1
    Medium

    CVE-2024-23995

    Last Modified: 15 Apr 2026

    Cross Site Scripting (XSS) in Beekeeper Studio 4.1.13 and earlier allows remote attackers to execute arbitrary code in the column name of a database table in tabulator-popup-container.

    Published: 29 Apr 2024
    7.7
    High

    CVE-2023-52080

    Last Modified: 15 Apr 2026

    IEIT NF5280M6 UEFI firmware through 8.4 has a pool overflow vulnerability, caused by improper use of the gRT->GetVariable() function. Attackers with access to local NVRAM variables can exploit this by modifying these variables on SPI Flash, resulting in memory data being tampered with. When critical data in memory data is tampered with,a crash may occur.

    Published: 29 Apr 2024
    4.2
    Medium

    CVE-2023-51710

    Last Modified: 15 Apr 2026

    EMS SQL Manager 3.6.2 (build 55333) for Oracle allows DLL hijacking: a user can trigger the execution of arbitrary code every time the product is executed.

    Published: 29 Apr 2024
    6.5
    Medium

    CVE-2023-50433

    Last Modified: 15 Apr 2026

    marshall in dhcp_packet.c in simple-dhcp-server through ec976d2 allows remote attackers to cause a denial of service by sending a malicious DHCP packet. The crash is caused by a type confusion bug that results in a large memory allocation; when this memory allocation fails the DHCP server will crash.

    Published: 29 Apr 2024
    5.3
    Medium

    CVE-2023-50432

    Last Modified: 15 Apr 2026

    simple-dhcp-server through ec976d2 allows remote attackers to cause a denial of service (daemon crash) by sending a DHCP packet without any option fields, which causes free_packet in dhcp_packet.c to dereference a NULL pointer.

    Published: 29 Apr 2024
    7.5
    High

    CVE-2023-46565

    Last Modified: 15 Apr 2026

    Buffer Overflow vulnerability in osrg gobgp commit 419c50dfac578daa4d11256904d0dc182f1a9b22 allows a remote attacker to cause a denial of service via the handlingError function in pkg/server/fsm.go.

    Published: 29 Apr 2024
    3.3
    Low

    CVE-2023-46270

    Last Modified: 15 Apr 2026

    MacPaw The Unarchiver before 4.3.6 contains vulnerability related to missing quarantine attributes for extracted items.

    Published: 29 Apr 2024
    5.5
    Medium

    CVE-2023-31889

    Last Modified: 15 Apr 2026

    An issue discovered in httpd in ASUS RT-AC51U with firmware version up to and including 3.0.0.4.380.8591 allows local attackers to cause a denial of service via crafted GET request.

    Published: 29 Apr 2024
    6.5
    Medium

    CVE-2023-52726

    Last Modified: 14 Jul 2025

    Open Networking Foundation SD-RAN ONOS onos-ric-sdk-go 0.8.12 allows infinite repetition of the processing of an error (in the Subscribe function implementation for the subscribed indication stream).

    Published: 29 Apr 2024
    7.5
    High

    CVE-2024-34050

    Last Modified: 27 Jun 2025

    Open Networking Foundation SD-RAN Rimedo rimedo-ts 0.1.1 has a slice bounds out-of-range panic in "return uint64(b[2])<<16 | uint64(b[1])<<8 | uint64(b[0])" in reader.go.

    Published: 29 Apr 2024
    7.5
    High

    CVE-2024-34049

    Last Modified: 27 May 2025

    Open Networking Foundation SD-RAN Rimedo rimedo-ts 0.1.1 has a slice bounds out-of-range panic in "return plmnIdString[0:3], plmnIdString[3:]" in reader.go.

    Published: 29 Apr 2024
    9.8
    Critical

    CVE-2024-34048

    Last Modified: 27 May 2025

    O-RAN RIC I-Release e2mgr lacks array size checks in E2nodeConfigUpdateNotificationHandler.

    Published: 29 Apr 2024
    4.3
    Medium

    CVE-2024-34047

    Last Modified: 27 May 2025

    O-RAN RIC I-Release e2mgr lacks array size checks in RicServiceUpdateHandler.

    Published: 29 Apr 2024
    5.3
    Medium

    CVE-2024-34043

    Last Modified: 14 Jul 2025

    O-RAN RICAPP kpimon-go I-Release has a segmentation violation via a certain E2AP-PDU message.

    Published: 29 Apr 2024
    4.6
    Medium

    CVE-2024-33905

    Last Modified: 15 Apr 2026

    In Telegram WebK before 2.0.0 (488), a crafted Mini Web App allows XSS via the postMessage web_app_open_link event type.

    Published: 29 Apr 2024
    5.9
    Medium

    CVE-2024-33903

    Last Modified: 15 Apr 2026

    In CARLA through 0.9.15.2, the collision sensor mishandles some situations involving pedestrians or bicycles, in part because the collision sensor function is not exposed to the Blueprint library.

    Published: 29 Apr 2024
    9.8
    Critical

    CVE-2024-33445

    Last Modified: 22 Sept 2025

    An issue in hisiphp v2.0.111 allows a remote attacker to execute arbitrary code via a crafted script to the SystemPlugins::mkInfo parameter in the SystemPlugins.php component.

    Published: 29 Apr 2024
    2.1
    Low

    CVE-2024-31747

    Last Modified: 30 Jul 2025

    An issue in Yealink VP59 Microsoft Teams Phone firmware 91.15.0.118 (fixed in 122.15.0.142) allows a physically proximate attacker to disable the phone lock via the Walkie Talkie menu option.

    Published: 29 Apr 2024
    9.8
    Critical

    CVE-2024-31820

    Last Modified: 23 Sept 2025

    An issue in Ecommerce-CodeIgniter-Bootstrap commit v. d22b54e8915f167a135046ceb857caaf8479c4da allows a remote attacker to execute arbitrary code via the getLangFolderForEdit method of the Languages.php component.

    Published: 29 Apr 2024
    9.8
    Critical

    CVE-2024-31822

    Last Modified: 23 Sept 2025

    An issue in Ecommerce-CodeIgniter-Bootstrap commit v. d22b54e8915f167a135046ceb857caaf8479c4da allows a remote attacker to execute arbitrary code via the saveLanguageFiles method of the Languages.php component.

    Published: 29 Apr 2024
    7.5
    High

    CVE-2023-46566

    Last Modified: 15 Apr 2026

    Buffer Overflow vulnerability in msoulier tftpy commit 467017b844bf6e31745138a30e2509145b0c529c allows a remote attacker to cause a denial of service via the parse function in the TftpPacketFactory class.

    Published: 29 Apr 2024
    8.6
    High

    CVE-2023-46960

    Last Modified: 15 Apr 2026

    Buffer Overflow vulnerability in PyPXE v.1.8.4 allows a remote attacker to cause a denial of service via the handle function in the tftp module.

    Published: 29 Apr 2024
    9.8
    Critical

    CVE-2023-50434

    Last Modified: 15 Apr 2026

    emdns_resolve_raw in emdns.c in emdns through fbd1eef calls strlen with an input that may not be '\0' terminated, leading to a stack-based buffer over-read. This can be triggered by a remote adversary that can send DNS requests to the emdns server. The impact could vary depending on the system libraries, compiler, and processor architecture. Code before be565c3 is unaffected.

    Published: 29 Apr 2024
    6.1
    Medium

    CVE-2023-51254

    Last Modified: 23 Apr 2025

    Cross Site Scripting vulnerability in Jfinalcms v.5.0.0 allows a remote attacker to execute arbitrary code via a crafted script to the friendship link component.

    Published: 29 Apr 2024
    7.1
    High

    CVE-2023-52723

    Last Modified: 15 Apr 2026

    In KDE libksieve before 23.03.80, kmanagesieve/session.cpp places a cleartext password in server logs because a username variable is accidentally given a password value.

    Published: 29 Apr 2024
    8.1
    High

    CVE-2023-52724

    Last Modified: 14 Jul 2025

    Open Networking Foundation SD-RAN onos-kpimon 0.4.7 allows out-of-bounds array access in the processIndicationFormat1 function.

    Published: 29 Apr 2024
    6.5
    Medium

    CVE-2023-52725

    Last Modified: 14 Jul 2025

    Open Networking Foundation SD-RAN ONOS onos-kpimon 0.4.7 allows blocking of the errCh channel within the Start function of the monitoring package.

    Published: 29 Apr 2024
    8.1
    High

    CVE-2023-52727

    Last Modified: 14 Jul 2025

    Open Networking Foundation SD-RAN ONOS onos-lib-go 0.10.25 allows an index out-of-range condition in parseAlignBits.

    Published: 29 Apr 2024
    5.5
    Medium

    CVE-2023-52728

    Last Modified: 14 Jul 2025

    Open Networking Foundation SD-RAN ONOS onos-lib-go 0.10.25 allows an index out-of-range condition in putBitString.

    Published: 29 Apr 2024
    6.5
    Medium

    CVE-2024-28294

    Last Modified: 17 Jun 2025

    Limbas up to v5.2.14 was discovered to contain a SQL injection vulnerability via the ftid parameter.

    Published: 29 Apr 2024
    7.6
    High

    CVE-2024-28320

    Last Modified: 1 Apr 2025

    Insecure Direct Object References (IDOR) vulnerability in Hospital Management System 1.0 allows attackers to manipulate user parameters for unauthorized access and modifications via crafted POST request to /patient/edit-user.php.

    Published: 29 Apr 2024
    7.6
    High

    CVE-2024-31621

    Last Modified: 27 May 2025

    An issue in FlowiseAI Inc Flowise v.1.6.2 and before allows a remote attacker to execute arbitrary code via a crafted script to the api/v1 component.

    Published: 29 Apr 2024
    9.8
    Critical

    CVE-2024-31823

    Last Modified: 24 Aug 2026

    An issue in Ecommerce-CodeIgniter-Bootstrap commit v. d22b54e8915f167a135046ceb857caaf8479c4da allows a remote attacker to execute arbitrary code via the removeSecondaryImage method of the Publish.php component.

    Published: 29 Apr 2024