CVE Feed

    Dashboard / CVE

    8.8
    High

    CVE-2023-50260

    Last Modified: 9 Jan 2025

    Wazuh is a free and open source platform used for threat prevention, detection, and response. A wrong validation in the `host_deny` script allows to write any string in the `hosts.deny` file, which can end in an arbitrary command execution on the target system. This vulnerability is part of the active response feature, which can automatically triggers actions in response to alerts. By default, active responses are limited to a set of pre defined executables. This is enforced by only allowing executables stored under `/var/ossec/active-response/bin` to be run as an active response. However, the `/var/ossec/active-response/bin/host_deny` can be exploited. `host_deny` is used to add IP address to the `/etc/hosts.deny` file to block incoming connections on a service level by using TCP wrappers. Attacker can inject arbitrary command into the `/etc/hosts.deny` file and execute arbitrary command by using the spawn directive. The active response can be triggered by writing events either to the local `execd` queue on server or to the `ar` queue which forwards the events to agents. So, it can leads to LPE on server as root and RCE on agent as root. This vulnerability is fixed in 4.7.2.

    Published: 19 Apr 2024
    8
    High

    CVE-2024-3684

    Last Modified: 2 Sept 2025

    A server side request forgery vulnerability was identified in GitHub Enterprise Server that allowed an attacker with an editor role in the Management Console to gain admin access to the appliance when configuring the Artifacts & Logs and Migrations Storage. Exploitation of this vulnerability required access to the GitHub Enterprise Server instance and access to the Management Console with the editor role. This vulnerability affected all versions of GitHub Enterprise Server prior to 3.12 and was fixed in versions 3.12.2, 3.11.8, 3.10.10, and 3.9.13. This vulnerability was reported via the GitHub Bug Bounty program.

    Published: 19 Apr 2024
    6.5
    Medium

    CVE-2023-49275

    Last Modified: 9 Jan 2025

    Wazuh is a free and open source platform used for threat prevention, detection, and response. A NULL pointer dereference was detected during fuzzing of the analysis engine, allowing malicious clients to DoS the analysis engine. The bug occurs when `analysisd` receives a syscollector message with the `hotfix` `msg_type` but lacking a `timestamp`. It uses `cJSON_GetObjectItem()` to get the `timestamp` object item and dereferences it without checking for a `NULL` value. A malicious client can DoS the analysis engine. This vulnerability is fixed in 4.7.1.

    Published: 19 Apr 2024
    8
    High

    CVE-2024-3646

    Last Modified: 2 Sept 2025

    A command injection vulnerability was identified in GitHub Enterprise Server that allowed an attacker with an editor role in the Management Console to gain admin SSH access to the instance when configuring the chat integration. Exploitation of this vulnerability required access to the GitHub Enterprise Server instance and access to the Management Console with the editor role. This vulnerability affected all versions of GitHub Enterprise Server prior to 3.12 and was fixed in versions 3.12.2, 3.11.8, 3.10.10, and 3.9.13. This vulnerability was reported via the GitHub Bug Bounty program.

    Published: 19 Apr 2024
    5.9
    Medium

    CVE-2024-3470

    Last Modified: 2 Sept 2025

    An Improper Privilege Management vulnerability was identified in GitHub Enterprise Server that allowed an attacker to use a deploy key pertaining to an organization to bypass an organization ruleset. An attacker would require access to a valid deploy key for a repository in the organization as well as repository administrator access. This vulnerability affected versions of GitHub Enterprise Server 3.11 to 3.12 and was fixed in versions 3.11.8 and 3.12.2. This vulnerability was reported via the GitHub Bug Bounty program.

    Published: 19 Apr 2024
    7.8
    High

    CVE-2023-37400

    Last Modified: 19 Dec 2024

    IBM Aspera Faspex 5.0.0 through 5.0.7 could allow a local user to escalate their privileges due to insecure credential storage. IBM X-Force ID: 259677.

    Published: 19 Apr 2024
    6.3
    Medium

    CVE-2024-3654

    Last Modified: 15 Apr 2026

    An XSS vulnerability has been found in Teimas Global's Teixo, version 1.42.42-stable. This vulnerability could allow an attacker to send a specially crafted JavaScript payload via the "seconds" parameter in the program's URL, resulting in a possible takeover of a registered user's session.

    Published: 19 Apr 2024
    5.3
    Medium

    CVE-2024-32683

    Last Modified: 28 Apr 2026

    Authorization Bypass Through User-Controlled Key vulnerability in Wpmet Wp Ultimate Review.This issue affects Wp Ultimate Review: from n/a through 2.2.5.

    Published: 19 Apr 2024
    7.5
    High

    CVE-2024-29969

    Last Modified: 4 Feb 2025

    When a Brocade SANnav installation is upgraded from Brocade SANnav v2.2.2 to Brocade SANnav 2.3.0, TLS/SSL weak message authentication code ciphers are added by default for port 18082.

    Published: 19 Apr 2024
    7.7
    High

    CVE-2024-29968

    Last Modified: 4 Feb 2025

    An information disclosure vulnerability exists in Brocade SANnav before v2.3.1 and v2.3.0a when Brocade SANnav instances are configured in disaster recovery mode. SQL Table names, column names, and SQL queries are collected in DR standby Supportsave. This could allow authenticated users to access the database structure and its contents.

    Published: 19 Apr 2024
    4.4
    Medium

    CVE-2024-29967

    Last Modified: 4 Feb 2025

    In Brocade SANnav before Brocade SANnav v2.31 and v2.3.0a, it was observed that Docker instances inside the appliance have insecure mount points, allowing reading and writing access to sensitive files. The vulnerability could allow a sudo privileged user on the host OS to read and write access to these files.

    Published: 19 Apr 2024
    6.8
    Medium

    CVE-2024-2761

    Last Modified: 30 May 2025

    The Genesis Blocks WordPress plugin before 3.1.3 does not properly escape data input provided to some of its blocks, allowing using with at least contributor privileges to conduct Stored XSS attacks.

    Published: 19 Apr 2024
    7.5
    High

    CVE-2024-29966

    Last Modified: 4 Feb 2025

    Brocade SANnav OVA before v2.3.1 and v2.3.0a contain hard-coded credentials in the documentation that appear as the appliance's root password. The vulnerability could allow an unauthenticated attacker full access to the Brocade SANnav appliance.

    Published: 19 Apr 2024
    5.9
    Medium

    CVE-2024-1065

    Last Modified: 27 Mar 2025

    Use After Free vulnerability in Arm Ltd Bifrost GPU Kernel Driver, Arm Ltd Valhall GPU Kernel Driver, Arm Ltd Arm 5th Gen GPU Architecture Kernel Driver allows a local non-privileged user to make improper GPU memory processing operations to gain access to already freed memory.This issue affects Bifrost GPU Kernel Driver: from r45p0 through r48p0; Valhall GPU Kernel Driver: from r45p0 through r48p0; Arm 5th Gen GPU Architecture Kernel Driver: from r45p0 through r48p0.

    Published: 19 Apr 2024
    6.8
    Medium

    CVE-2024-0671

    Last Modified: 27 Mar 2025

    Use After Free vulnerability in Arm Ltd Midgard GPU Kernel Driver, Arm Ltd Bifrost GPU Kernel Driver, Arm Ltd Valhall GPU Kernel Driver, Arm Ltd Arm 5th Gen GPU Architecture Kernel Driver allows a local non-privileged user to make improper GPU memory processing operations to gain access to already freed memory.This issue affects Midgard GPU Kernel Driver: from r19p0 through r32p0; Bifrost GPU Kernel Driver: from r7p0 through r48p0; Valhall GPU Kernel Driver: from r19p0 through r48p0; Arm 5th Gen GPU Architecture Kernel Driver: from r41p0 through r48p0.

    Published: 19 Apr 2024
    6.8
    Medium

    CVE-2024-29965

    Last Modified: 4 Feb 2025

    In Brocade SANnav before v2.3.1, and v2.3.0a, it is possible to back up the appliance from the web interface or the command line interface ("SSH"). The resulting backups are world-readable. A local attacker can recover backup files, restore them to a new malicious appliance, and retrieve the passwords of all the switches.

    Published: 19 Apr 2024
    5.7
    Medium

    CVE-2024-29964

    Last Modified: 4 Feb 2025

    Brocade SANnav versions before v2.3.0a do not correctly set permissions on files, including docker files. An unprivileged attacker who gains access to the server can read sensitive information from these files.

    Published: 19 Apr 2024
    5.5
    Medium

    CVE-2024-29962

    Last Modified: 4 Feb 2025

    Brocade SANnav OVA before v2.3.1 and v2.3.0a have an insecure file permission setting that makes files world-readable. This could allow a local user without the required privileges to access sensitive information or a Java binary.

    Published: 19 Apr 2024
    1.9
    Low

    CVE-2024-29963

    Last Modified: 4 Feb 2025

    Brocade SANnav OVA before v2.3.1, and v2.3.0a, contain hardcoded TLS keys used by Docker. Note: Brocade SANnav doesn't have access to remote Docker registries.

    Published: 19 Apr 2024
    8.2
    High

    CVE-2024-29961

    Last Modified: 4 Feb 2025

    A vulnerability affects Brocade SANnav before v2.3.1 and v2.3.0a. It allows a Brocade SANnav service to send ping commands in the background at regular intervals to gridgain.com to check if updates are available for the Component. This could make an unauthenticated, remote attacker aware of the behavior and launch a supply-chain attack against a Brocade SANnav appliance.

    Published: 19 Apr 2024
    6.8
    Medium

    CVE-2024-29960

    Last Modified: 4 Feb 2025

    In Brocade SANnav server before v2.3.1 and v2.3.0a, the SSH keys inside the OVA image are identical in the VM every time SANnav is installed. Any Brocade SAnnav VM based on the official OVA images is vulnerable to MITM over SSH. An attacker can decrypt and compromise the SSH traffic to the SANnav.

    Published: 19 Apr 2024
    8.6
    High

    CVE-2024-29959

    Last Modified: 4 Feb 2025

    A vulnerability in Brocade SANnav before v2.3.1 and v2.3.0a prints Brocade Fabric OS switch encrypted passwords in the Brocade SANnav Standby node's support save.

    Published: 19 Apr 2024
    7.5
    High

    CVE-2024-29958

    Last Modified: 4 Feb 2025

    A vulnerability in Brocade SANnav before v2.3.1 and v2.3.0a prints the encryption key in the console when a privileged user executes the script to replace the Brocade SANnav Management Portal standby node. This could provide attackers an additional, less protected path to acquiring the encryption key.

    Published: 19 Apr 2024
    7.5
    High

    CVE-2024-29957

    Last Modified: 4 Feb 2025

    When Brocade SANnav before v2.3.1 and v2.3.0a servers are configured in Disaster Recovery mode, the encryption key is stored in the DR log files. This could provide attackers with an additional, less-protected path to acquiring the encryption key.

    Published: 19 Apr 2024
    7.2
    High

    CVE-2024-3600

    Last Modified: 8 Apr 2026

    The Poll Maker – Best WordPress Poll Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting due to a missing capability check on the ays_poll_maker_quick_start AJAX action in addition to insufficient escaping and sanitization in all versions up to, and including, 5.1.8. This makes it possible for unauthenticated attackers to create quizzes and inject malicious web scripts into them that execute when a user visits the page.

    Published: 19 Apr 2024
    6.1
    Medium

    CVE-2024-3731

    Last Modified: 8 Apr 2026

    The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 's' parameter in all versions up to, and including, 5.47.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

    Published: 19 Apr 2024
    5.4
    Medium

    CVE-2024-3818

    Last Modified: 8 Apr 2026

    The Essential Blocks – Page Builder Gutenberg Blocks, Patterns & Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's "Social Icons" block in all versions up to, and including, 4.5.9 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 19 Apr 2024
    6.1
    Medium

    CVE-2024-3615

    Last Modified: 8 Apr 2026

    The Media Library Folders plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 's' parameter in all versions up to, and including, 8.2.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

    Published: 19 Apr 2024
    —
    Unknown

    CVE-2024-3975

    Last Modified: 11 Feb 2025

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

    Published: 19 Apr 2024
    6.4
    Medium

    CVE-2024-3598

    Last Modified: 8 Apr 2026

    The ElementsKit Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Creative Button widget in all versions up to, and including, 3.6.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 19 Apr 2024
    6.4
    Medium

    CVE-2024-3560

    Last Modified: 8 Apr 2026

    The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the _id value in all versions up to, and including, 4.2.6.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 19 Apr 2024
    7.5
    High

    CVE-2024-23526

    Last Modified: 6 May 2025

    An out-of-bounds read vulnerability in WLAvalancheService component of Ivanti Avalanche before 6.4.3, in certain conditions can allow an unauthenticated remote attacker to read sensitive information in memory.

    Published: 19 Apr 2024
    9.8
    Critical

    CVE-2024-22061

    Last Modified: 6 May 2025

    A Heap Overflow vulnerability in WLInfoRailService component of Ivanti Avalanche before 6.4.3 allows a remote unauthenticated attacker to execute arbitrary commands

    Published: 19 Apr 2024
    7.5
    High

    CVE-2024-23529

    Last Modified: 6 May 2025

    An out-of-bounds read vulnerability in WLAvalancheService component of Ivanti Avalanche before 6.4.3, in certain conditions can allow an unauthenticated remote attacker to read sensitive information in memory.

    Published: 19 Apr 2024
    7.5
    High

    CVE-2024-23528

    Last Modified: 6 May 2025

    An out-of-bounds read vulnerability in WLAvalancheService component of Ivanti Avalanche before 6.4.3, in certain conditions can allow an unauthenticated remote attacker to read sensitive information in memory.

    Published: 19 Apr 2024
    8.8
    High

    CVE-2024-25000

    Last Modified: 16 Dec 2025

    A Path Traversal vulnerability in web component of Ivanti Avalanche before 6.4.3 allows a remote authenticated attacker to execute arbitrary commands as SYSTEM.

    Published: 19 Apr 2024
    8.1
    High

    CVE-2024-27977

    Last Modified: 6 May 2025

    A Path Traversal vulnerability in web component of Ivanti Avalanche before 6.4.3 allows a remote authenticated attacker to delete arbitrary files, thereby leading to Denial-of-Service.

    Published: 19 Apr 2024
    8.8
    High

    CVE-2024-24992

    Last Modified: 6 May 2025

    A Path Traversal vulnerability in web component of Ivanti Avalanche before 6.4.3 allows a remote authenticated attacker to execute arbitrary commands as SYSTEM.

    Published: 19 Apr 2024
    7.5
    High

    CVE-2024-23532

    Last Modified: 6 May 2025

    An out-of-bounds Read vulnerability in WLAvalancheService component of Ivanti Avalanche before 6.4.3 allows an authenticated remote attacker to perform denial of service attacks. In certain conditions this could also lead to remote code execution.

    Published: 19 Apr 2024
    8.8
    High

    CVE-2024-23535

    Last Modified: 16 Dec 2025

    A Path Traversal vulnerability in web component of Ivanti Avalanche before 6.4.3 allows a remote authenticated attacker to execute arbitrary commands as SYSTEM.

    Published: 19 Apr 2024
    8.8
    High

    CVE-2024-24998

    Last Modified: 6 May 2025

    A Path Traversal vulnerability in web component of Ivanti Avalanche before 6.4.3 allows a remote authenticated attacker to execute arbitrary commands as SYSTEM.

    Published: 19 Apr 2024
    7.5
    High

    CVE-2024-24995

    Last Modified: 16 Dec 2025

    A Race Condition (TOCTOU) vulnerability in web component of Ivanti Avalanche before 6.4.3 allows a remote authenticated attacker to execute arbitrary commands as SYSTEM.

    Published: 19 Apr 2024
    7.5
    High

    CVE-2024-24993

    Last Modified: 6 May 2025

    A Race Condition (TOCTOU) vulnerability in web component of Ivanti Avalanche before 6.4.3 allows a remote authenticated attacker to execute arbitrary commands as SYSTEM.

    Published: 19 Apr 2024
    8.8
    High

    CVE-2024-24999

    Last Modified: 16 Dec 2025

    A Path Traversal vulnerability in web component of Ivanti Avalanche before 6.4.3 allows a remote authenticated attacker to execute arbitrary commands as SYSTEM.

    Published: 19 Apr 2024
    6.5
    Medium

    CVE-2024-24991

    Last Modified: 6 May 2025

    A Null Pointer Dereference vulnerability in WLAvalancheService component of Ivanti Avalanche before 6.4.3 allows an authenticated remote attacker to perform denial of service attacks.

    Published: 19 Apr 2024
    8.8
    High

    CVE-2024-24997

    Last Modified: 16 Dec 2025

    A Path Traversal vulnerability in web component of Ivanti Avalanche before 6.4.3 allows a remote authenticated attacker to execute arbitrary commands as SYSTEM.

    Published: 19 Apr 2024
    6.5
    Medium

    CVE-2024-27978

    Last Modified: 6 May 2025

    A Null Pointer Dereference vulnerability in WLAvalancheService component of Ivanti Avalanche before 6.4.3 allows an authenticated remote attacker to perform denial of service attacks.

    Published: 19 Apr 2024
    8.8
    High

    CVE-2024-24994

    Last Modified: 6 May 2025

    A Path Traversal vulnerability in web component of Ivanti Avalanche before 6.4.3 allows a remote authenticated attacker to execute arbitrary commands as SYSTEM.

    Published: 19 Apr 2024
    9.8
    Critical

    CVE-2024-24996

    Last Modified: 6 May 2025

    A Heap overflow vulnerability in WLInfoRailService component of Ivanti Avalanche before 6.4.3 allows an unauthenticated remote attacker to execute arbitrary commands.

    Published: 19 Apr 2024
    8.8
    High

    CVE-2024-23534

    Last Modified: 16 Dec 2025

    An Unrestricted File-upload vulnerability in web component of Ivanti Avalanche before 6.4.3 allows a remote authenticated attacker to execute arbitrary commands as SYSTEM.

    Published: 19 Apr 2024