CVE Feed

    Dashboard / CVE

    4.4
    Medium

    CVE-2024-4031

    Last Modified: 15 Apr 2026

    Unquoted Search Path or Element vulnerability in Logitech MEVO WEBCAM APP on Windows allows Local Execution of Code.

    Published: 23 Apr 2024
    7.5
    High

    CVE-2024-2493

    Last Modified: 15 Apr 2026

    Session Hijacking vulnerability in Hitachi Ops Center Analyzer.This issue affects Hitachi Ops Center Analyzer: from 10.0.0-00 before 11.0.1-00.

    Published: 23 Apr 2024
    4.4
    Medium

    CVE-2023-6833

    Last Modified: 15 Apr 2026

    Insertion of Sensitive Information into Log File vulnerability in Hitachi Ops Center Administrator allows local users to gain sensitive information.This issue affects Hitachi Ops Center Administrator: before 11.0.1.

    Published: 23 Apr 2024
    6.4
    Medium

    CVE-2024-3889

    Last Modified: 8 Apr 2026

    The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Advanced Accordion widget in all versions up to, and including, 1.3.971 due to insufficient input sanitization and output escaping on user supplied attributes like 'accordion_title_tag'. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 23 Apr 2024
    6.4
    Medium

    CVE-2024-2798

    Last Modified: 8 Apr 2026

    The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's widget containers in all versions up to, and including, 1.3.971 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 23 Apr 2024
    6.4
    Medium

    CVE-2024-2799

    Last Modified: 8 Apr 2026

    The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Image Grid & Advanced Text widget HTML tags in all versions up to, and including, 1.3.96 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 23 Apr 2024
    5.3
    Medium

    CVE-2024-28890

    Last Modified: 4 Apr 2025

    Forminator prior to 1.29.0 contains an unrestricted upload of file with dangerous type vulnerability. If this vulnerability is exploited, a remote attacker may obtain sensitive information by accessing files on the server, alter the site that uses the plugin, and cause a denial-of-service (DoS) condition.

    Published: 23 Apr 2024
    7.2
    High

    CVE-2024-31077

    Last Modified: 4 Apr 2025

    Forminator prior to 1.29.3 contains a SQL injection vulnerability. If this vulnerability is exploited, a remote authenticated attacker with an administrative privilege may obtain and alter any information in the database and cause a denial-of-service (DoS) condition.

    Published: 23 Apr 2024
    5.4
    Medium

    CVE-2024-31857

    Last Modified: 4 Apr 2025

    Forminator prior to 1.15.4 contains a cross-site scripting vulnerability. If this vulnerability is exploited, a remote attacker may obtain user information etc. and alter the page contents on the user's web browser.

    Published: 23 Apr 2024
    5.5
    Medium

    CVE-2024-1241

    Last Modified: 15 Apr 2026

    Watchdog Antivirus v1.6.415 is vulnerable to a Denial of Service vulnerability by triggering the 0x80002014 IOCTL code of the wsdk-driver.sys driver.

    Published: 23 Apr 2024
    5.5
    Medium

    CVE-2024-2760

    Last Modified: 15 Apr 2026

    Bkav Home v7816, build 2403161130 is vulnerable to a Memory Information Leak vulnerability by triggering the 0x222240 IOCTL code of the BkavSDFlt.sys driver.

    Published: 23 Apr 2024
    8.8
    High

    CVE-2024-3293

    Last Modified: 15 Apr 2026

    The rtMedia for WordPress, BuddyPress and bbPress plugin for WordPress is vulnerable to blind SQL Injection via the rtmedia_gallery shortcode in all versions up to, and including, 4.6.18 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with contributor-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

    Published: 23 Apr 2024
    6.7
    Medium

    CVE-2024-31804

    Last Modified: 15 Apr 2026

    An unquoted service path vulnerability in Terratec DMX_6Fire USB v.1.23.0.02 allows a local attacker to escalate privileges via the Program.exe component.

    Published: 23 Apr 2024
    8.8
    High

    CVE-2024-31616

    Last Modified: 15 Apr 2026

    An issue discovered in RG-RSR10-01G-T(W)-S and RG-RSR10-01G-T(WA)-S routers with firmware version RSR10-01G-T-S_RSR_3.0(1)B9P2, Release(07150910) allows attackers to execute arbitrary code via the common_quick_config.lua file.

    Published: 23 Apr 2024
    7.5
    High

    CVE-2024-28627

    Last Modified: 15 Apr 2026

    An issue in Flipsnack v.18/03/2024 allows a local attacker to obtain sensitive information via the reader.gz.js file.

    Published: 23 Apr 2024
    6.6
    Medium

    CVE-2024-27282

    Last Modified: 15 Apr 2026

    An issue was discovered in Ruby 3.x through 3.3.0. If attacker-supplied data is provided to the Ruby regex compiler, it is possible to extract arbitrary heap data relative to the start of the text, including pointers and sensitive strings. The fixed versions are 3.0.7, 3.1.5, 3.2.4, and 3.3.1.

    Published: 23 Apr 2024
    8.1
    High

    CVE-2024-33599

    Last Modified: 12 May 2026

    nscd: Stack-based buffer overflow in netgroup cache If the Name Service Cache Daemon's (nscd) fixed size cache is exhausted by client requests then a subsequent client request for netgroup data may result in a stack-based buffer overflow. This flaw was introduced in glibc 2.15 when the cache was added to nscd. This vulnerability is only present in the nscd binary.

    Published: 23 Apr 2024
    3.9
    Low

    CVE-2023-48184

    Last Modified: 15 Oct 2025

    QuickJS before 7414e5f has a quickjs.h JS_FreeValueRT use-after-free because of incorrect garbage collection of async functions with closures.

    Published: 23 Apr 2024
    9.8
    Critical

    CVE-2024-33215

    Last Modified: 17 Mar 2025

    Tenda FH1206 V1.2.0.8(8155)_EN was discovered to contain a stack-based buffer overflow vulnerability via the mitInterface parameter in ip/goform/addressNat.

    Published: 23 Apr 2024
    7.5
    High

    CVE-2024-33217

    Last Modified: 17 Mar 2025

    Tenda FH1206 V1.2.0.8(8155)_EN was discovered to contain a stack-based buffer overflow vulnerability via the page parameter in ip/goform/addressNat.

    Published: 23 Apr 2024
    7.5
    High

    CVE-2024-33214

    Last Modified: 17 Mar 2025

    Tenda FH1206 V1.2.0.8(8155)_EN was discovered to contain a stack-based buffer overflow vulnerability via the entrys parameter in ip/goform/RouteStatic.

    Published: 23 Apr 2024
    7.5
    High

    CVE-2024-32661

    Last Modified: 3 Nov 2025

    FreeRDP is a free implementation of the Remote Desktop Protocol. FreeRDP based clients prior to version 3.5.1 are vulnerable to a possible `NULL` access and crash. Version 3.5.1 contains a patch for the issue. No known workarounds are available.

    Published: 23 Apr 2024
    9.8
    Critical

    CVE-2024-21511

    Last Modified: 15 Apr 2026

    Versions of the package mysql2 before 3.9.7 are vulnerable to Arbitrary Code Injection due to improper sanitization of the timezone parameter in the readCodeFor function by calling a native MySQL Server date/time function.

    Published: 23 Apr 2024
    7.8
    High

    CVE-2024-26922

    Last Modified: 4 Aug 2026

    In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: validate the parameters of bo mapping operations more clearly Verify the parameters of amdgpu_vm_bo_(map/replace_map/clearing_mappings) in one common place.

    Published: 23 Apr 2024
    5.6
    Medium

    CVE-2024-30800

    Last Modified: 30 Jun 2025

    PX4 Autopilot v.1.14 allows an attacker to fly the drone into no-fly zones by breaching the geofence using flaws in the function.

    Published: 23 Apr 2024
    5.4
    Medium

    CVE-2024-30886

    Last Modified: 21 May 2025

    A stored cross-site scripting (XSS) vulnerability in the remotelink function of HadSky v7.6.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the url parameter.

    Published: 23 Apr 2024
    8.8
    High

    CVE-2024-32258

    Last Modified: 15 Apr 2026

    The network server of fceux 2.7.0 has a path traversal vulnerability, allowing attackers to overwrite any files on the server without authentication by fake ROM.

    Published: 23 Apr 2024
    9.8
    Critical

    CVE-2024-32658

    Last Modified: 3 Nov 2025

    FreeRDP is a free implementation of the Remote Desktop Protocol. FreeRDP based clients prior to version 3.5.1 are vulnerable to out-of-bounds read. Version 3.5.1 contains a patch for the issue. No known workarounds are available.

    Published: 23 Apr 2024
    7.5
    High

    CVE-2024-32662

    Last Modified: 13 Feb 2025

    FreeRDP is a free implementation of the Remote Desktop Protocol. FreeRDP based clients prior to version 3.5.1 are vulnerable to out-of-bounds read. This occurs when `WCHAR` string is read with twice the size it has and converted to `UTF-8`, `base64` decoded. The string is only used to compare against the redirection server certificate. Version 3.5.1 contains a patch for the issue. No known workarounds are available.

    Published: 23 Apr 2024
    9.8
    Critical

    CVE-2024-32659

    Last Modified: 3 Nov 2025

    FreeRDP is a free implementation of the Remote Desktop Protocol. FreeRDP based clients prior to version 3.5.1 are vulnerable to out-of-bounds read if `((nWidth == 0) and (nHeight == 0))`. Version 3.5.1 contains a patch for the issue. No known workarounds are available.

    Published: 23 Apr 2024
    7.3
    High

    CVE-2024-33211

    Last Modified: 17 Mar 2025

    Tenda FH1206 V1.2.0.8(8155)_EN was discovered to contain a stack-based buffer overflow vulnerability via the PPPOEPassword parameter in ip/goform/QuickIndex.

    Published: 23 Apr 2024
    8.8
    High

    CVE-2024-33212

    Last Modified: 17 Mar 2025

    Tenda FH1206 V1.2.0.8(8155)_EN was discovered to contain a stack-based buffer overflow vulnerability via the funcpara1 parameter in ip/goform/setcfm.

    Published: 23 Apr 2024
    6.5
    Medium

    CVE-2024-33213

    Last Modified: 17 Mar 2025

    Tenda FH1206 V1.2.0.8(8155)_EN was discovered to contain a stack-based buffer overflow vulnerability via the mitInterface parameter in ip/goform/RouteStatic.

    Published: 23 Apr 2024
    —
    Unknown

    CVE-2024-33339

    Last Modified: 29 Apr 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

    Published: 23 Apr 2024
    —
    Unknown

    CVE-2024-33331

    Last Modified: 28 Apr 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2024-33891. Reason: This candidate is a reservation duplicate of CVE-2024-33891. Notes: All CVE users should reference CVE-2024-33891 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage.

    Published: 23 Apr 2024
    —
    Unknown

    CVE-2024-33386

    Last Modified: 13 Feb 2025

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

    Published: 23 Apr 2024
    7.5
    High

    CVE-2024-32660

    Last Modified: 3 Nov 2025

    FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.5.1, a malicious server can crash the FreeRDP client by sending invalid huge allocation size. Version 3.5.1 contains a patch for the issue. No known workarounds are available.

    Published: 23 Apr 2024
    7.5
    High

    CVE-2023-48183

    Last Modified: 15 Oct 2025

    QuickJS before c4cdd61 has a build_for_in_iterator NULL pointer dereference because of an erroneous lexical scope of "this" with eval.

    Published: 23 Apr 2024
    4.6
    Medium

    CVE-2024-32657

    Last Modified: 22 Sept 2025

    Hydra is a Continuous Integration service for Nix based projects. Attackers can execute arbitrary code in the browser context of Hydra and execute authenticated HTTP requests. The abused feature allows Nix builds to specify files that Hydra serves to clients. One use of this functionality is serving NixOS `.iso` files. The issue is only with html files served by Hydra. The issue has been patched on https://hydra.nixos.org around 2024-04-21 14:30 UTC. The nixpkgs package were fixed in unstable and 23.11. Users with custom Hydra packages can apply the fix commit to their local installations. The vulnerability is only triggered when opening HTML build artifacts, so not opening them until the vulnerability is fixed works around the issue.

    Published: 22 Apr 2024
    7.8
    High

    CVE-2024-32656

    Last Modified: 15 Apr 2026

    Ant Media Server is live streaming engine software. A local privilege escalation vulnerability in present in versions 2.6.0 through 2.8.2 allows any unprivileged operating system user account to escalate privileges to the root user account on the system. This vulnerability arises from Ant Media Server running with Java Management Extensions (JMX) enabled and authentication disabled on localhost on port 5599/TCP. This vulnerability is nearly identical to the local privilege escalation vulnerability CVE-2023-26269 identified in Apache James. Any unprivileged operating system user can connect to the JMX service running on port 5599/TCP on localhost and leverage the MLet Bean within JMX to load a remote MBean from an attacker-controlled server. This allows an attacker to execute arbitrary code within the Java process run by Ant Media Server and execute code within the context of the `antmedia` service account on the system. Version 2.9.0 contains a patch for the issue. As a workaround, one may remove certain parameters from the `antmedia.service` file.

    Published: 22 Apr 2024
    6.1
    Medium

    CVE-2024-32653

    Last Modified: 15 Apr 2026

    jadx is a Dex to Java decompiler. Prior to version 1.5.0, the package name is not filtered before concatenation. This can be exploited to inject arbitrary code into the package name. The vulnerability allows an attacker to execute commands with shell privileges. Version 1.5.0 contains a patch for the vulnerability.

    Published: 22 Apr 2024
    7.2
    High

    CVE-2024-32480

    Last Modified: 2 Jan 2025

    LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system. Versions prior to 24.4.0 are vulnerable to SQL injection. The `order` parameter is obtained from `$request`. After performing a string check, the value is directly incorporated into an SQL statement and concatenated, resulting in a SQL injection vulnerability. An attacker may extract a whole database this way. Version 24.4.0 fixes the issue.

    Published: 22 Apr 2024
    7.1
    High

    CVE-2024-32479

    Last Modified: 2 Jan 2025

    LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system. Prior to version 24.4.0, there is improper sanitization on the `Service` template name, which can lead to stored Cross-site Scripting. Version 24.4.0 fixes this vulnerability.

    Published: 22 Apr 2024
    7.1
    High

    CVE-2024-32461

    Last Modified: 2 Jan 2025

    LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system. A SQL injection vulnerability in POST /search/search=packages in LibreNMS prior to version 24.4.0 allows a user with global read privileges to execute SQL commands via the package parameter. With this vulnerability, an attacker can exploit a SQL injection time based vulnerability to extract all data from the database, such as administrator credentials. Version 24.4.0 contains a patch for the vulnerability.

    Published: 22 Apr 2024
    9.8
    Critical

    CVE-2024-4040

    Last Modified: 26 Feb 2026

    A server side template injection vulnerability in CrushFTP in all versions before 10.7.1 and 11.1.0 on all platforms allows unauthenticated remote attackers to read files from the filesystem outside of the VFS Sandbox, bypass authentication to gain administrative access, and perform remote code execution on the server.

    Published: 22 Apr 2024
    7.2
    High

    CVE-2024-3154

    Last Modified: 24 Aug 2026

    A flaw was found in cri-o, where an arbitrary systemd property can be injected via a Pod annotation. Any user who can create a pod with an arbitrary annotation may perform an arbitrary action on the host system.

    Published: 22 Apr 2024
    9.1
    Critical

    CVE-2024-27349

    Last Modified: 21 Aug 2025

    Authentication Bypass by Spoofing vulnerability in Apache HugeGraph-Server.This issue affects Apache HugeGraph-Server: from 1.0.0 before 1.3.0. Users are recommended to upgrade to version 1.3.0, which fixes the issue.

    Published: 22 Apr 2024
    9.8
    Critical

    CVE-2024-27348

    Last Modified: 23 Oct 2025

    RCE-Remote Command Execution vulnerability in Apache HugeGraph-Server.This issue affects Apache HugeGraph-Server: from 1.0.0 before 1.3.0 in Java8 & Java11 Users are recommended to upgrade to version 1.3.0 with Java11 & enable the Auth system, which fixes the issue.

    Published: 22 Apr 2024
    5.3
    Medium

    CVE-2024-27347

    Last Modified: 30 Jun 2025

    Server-Side Request Forgery (SSRF) vulnerability in Apache HugeGraph-Hubble.This issue affects Apache HugeGraph-Hubble: from 1.0.0 before 1.3.0. Users are recommended to upgrade to version 1.3.0, which fixes the issue.

    Published: 22 Apr 2024
    6.4
    Medium

    CVE-2024-3645

    Last Modified: 8 Apr 2026

    The Essential Addons for Elementor Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Counter widget in all versions up to, and including, 5.8.11 due to insufficient input sanitization and output escaping on user supplied attributes such as 'title_html_tag'. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 22 Apr 2024