CVE Feed

    Dashboard / CVE

    6.5
    Medium

    CVE-2024-23533

    Last Modified: 6 May 2025

    An out-of-bounds read vulnerability in WLAvalancheService component of Ivanti Avalanche before 6.4.3, in certain conditions can allow an authenticated remote attacker to read sensitive information in memory.

    Published: 19 Apr 2024
    7.5
    High

    CVE-2024-23531

    Last Modified: 6 May 2025

    An Integer Overflow vulnerability in WLInfoRailService component of Ivanti Avalanche before 6.4.3 allows an unauthenticated remote attacker to perform denial of service attacks. In certain rare conditions this could also lead to reading content from memory.

    Published: 19 Apr 2024
    7.5
    High

    CVE-2024-23530

    Last Modified: 6 May 2025

    An out-of-bounds read vulnerability in WLAvalancheService component of Ivanti Avalanche before 6.4.3, in certain conditions can allow an unauthenticated remote attacker to read sensitive information in memory.

    Published: 19 Apr 2024
    8.8
    High

    CVE-2024-27976

    Last Modified: 16 Dec 2025

    A Path Traversal vulnerability in web component of Ivanti Avalanche before 6.4.3 allows a remote authenticated attacker to execute arbitrary commands as SYSTEM.

    Published: 19 Apr 2024
    9.8
    Critical

    CVE-2024-29204

    Last Modified: 16 Dec 2025

    A Heap Overflow vulnerability in WLAvalancheService component of Ivanti Avalanche before 6.4.3 allows a remote unauthenticated attacker to execute arbitrary commands

    Published: 19 Apr 2024
    8.8
    High

    CVE-2024-27975

    Last Modified: 16 Dec 2025

    An Use-after-free vulnerability in WLAvalancheService component of Ivanti Avalanche before 6.4.3 allows a remote authenticated attacker to execute arbitrary commands as SYSTEM.

    Published: 19 Apr 2024
    7.1
    High

    CVE-2024-27984

    Last Modified: 6 May 2025

    A Path Traversal vulnerability in web component of Ivanti Avalanche before 6.4.3 allows a remote authenticated attacker to delete specific type of files and/or cause denial of service.

    Published: 19 Apr 2024
    3.3
    Low

    CVE-2023-51792

    Last Modified: 15 Apr 2026

    Buffer Overflow vulnerability in libde265 v1.0.12 allows a local attacker to cause a denial of service via the allocation size exceeding the maximum supported size of 0x10000000000.

    Published: 19 Apr 2024
    8.8
    High

    CVE-2023-49963

    Last Modified: 15 Apr 2026

    DYMO LabelWriter Print Server through 2.366 contains a backdoor hard-coded password that could allow an attacker to take control.

    Published: 19 Apr 2024
    7.8
    High

    CVE-2023-51798

    Last Modified: 7 Jan 2026

    Buffer Overflow vulnerability in Ffmpeg v.N113007-g8d24a28d06 allows a local attacker to execute arbitrary code via a floating point exception (FPE) error at libavfilter/vf_minterpolate.c:1078:60 in interpolate.

    Published: 19 Apr 2024
    7.3
    High

    CVE-2024-30974

    Last Modified: 23 Sept 2025

    SQL Injection vulnerability in autoexpress v.1.3.0 allows attackers to run arbitrary SQL commands via the carId parameter.

    Published: 19 Apr 2024
    9.8
    Critical

    CVE-2023-47435

    Last Modified: 15 Apr 2026

    An issue in the verifyPassword function of hexo-theme-matery v2.0.0 allows attackers to bypass authentication and access password protected pages.

    Published: 19 Apr 2024
    4
    Medium

    CVE-2023-50007

    Last Modified: 6 Jun 2025

    FFmpeg v.n6.1-3-g466799d4f5 allows an attacker to trigger use of a parameter of negative size in the av_samples_set_silence function in thelibavutil/samplefmt.c:260:9 component.

    Published: 19 Apr 2024
    7.8
    High

    CVE-2023-50008

    Last Modified: 10 Jun 2025

    FFmpeg v.n6.1-3-g466799d4f5 allows memory consumption when using the colorcorrect filter, in the av_malloc function in libavutil/mem.c:105:9 component.

    Published: 19 Apr 2024
    8
    High

    CVE-2023-50009

    Last Modified: 9 Jun 2025

    FFmpeg v.n6.1-3-g466799d4f5 allows a heap-based buffer overflow via the ff_gaussian_blur_8 function in libavfilter/edge_template.c:116:5 component.

    Published: 19 Apr 2024
    7.8
    High

    CVE-2023-50010

    Last Modified: 9 Jun 2025

    FFmpeg v.n6.1-3-g466799d4f5 allows a buffer over-read at ff_gradfun_blur_line_movdqa_sse2, as demonstrated by a call to the set_encoder_id function in /fftools/ffmpeg_enc.c component.

    Published: 19 Apr 2024
    8
    High

    CVE-2023-51795

    Last Modified: 7 Jan 2026

    Buffer Overflow vulnerability in Ffmpeg v.N113007-g8d24a28d06 allows a local attacker to execute arbitrary code via the libavfilter/avf_showspectrum.c:1789:52 component in showspectrumpic_request_frame

    Published: 19 Apr 2024
    7.5
    High

    CVE-2024-22640

    Last Modified: 4 Nov 2025

    TCPDF version <=6.6.5 is vulnerable to ReDoS (Regular Expression Denial of Service) if parsing an untrusted HTML page with a crafted color.

    Published: 19 Apr 2024
    7
    High

    CVE-2024-22905

    Last Modified: 15 Sept 2025

    Buffer Overflow vulnerability in ARM mbed-os v.6.17.0 allows a remote attacker to execute arbitrary code via a crafted script to the hciTrSerialRxIncoming function.

    Published: 19 Apr 2024
    5.4
    Medium

    CVE-2024-27752

    Last Modified: 21 May 2025

    Cross Site Scripting vulnerability in CSZ CMS v.1.3.0 allows a remote attacker to execute arbitrary code via the Default Keyword field in the settings function.

    Published: 19 Apr 2024
    7.1
    High

    CVE-2024-31552

    Last Modified: 15 Apr 2026

    CuteHttpFileServer v.3.1 version has an arbitrary file download vulnerability, which allows attackers to download arbitrary files on the server and obtain sensitive information.

    Published: 19 Apr 2024
    9.8
    Critical

    CVE-2024-31546

    Last Modified: 14 Apr 2025

    Computer Laboratory Management System v1.0 is vulnerable to SQL Injection via the "id" parameter of /admin/damage/view_damage.php.

    Published: 19 Apr 2024
    9.1
    Critical

    CVE-2024-31547

    Last Modified: 14 Apr 2025

    Computer Laboratory Management System v1.0 is vulnerable to SQL Injection via the "id" parameter of /admin/item/view_item.php.

    Published: 19 Apr 2024
    6.5
    Medium

    CVE-2024-31587

    Last Modified: 15 Apr 2026

    SecuSTATION Camera V2.5.5.3116-S50-SMA-B20160811A and lower allows an unauthenticated attacker to download device configuration files via a crafted request.

    Published: 19 Apr 2024
    5.5
    Medium

    CVE-2024-31584

    Last Modified: 3 Jun 2025

    Pytorch before v2.2.0 has an Out-of-bounds Read vulnerability via the component torch/csrc/jit/mobile/flatbuffer_loader.cpp.

    Published: 19 Apr 2024
    7.5
    High

    CVE-2024-31744

    Last Modified: 15 Apr 2026

    In Jasper 4.2.2, the jpc_streamlist_remove function in src/libjasper/jpc/jpc_dec.c:2407 has an assertion failure vulnerability, allowing attackers to cause a denial of service attack through a specific image file.

    Published: 19 Apr 2024
    8.8
    High

    CVE-2023-49502

    Last Modified: 4 Nov 2025

    Buffer Overflow vulnerability in Ffmpeg v.n6.1-3-g466799d4f5 allows a local attacker to execute arbitrary code via the ff_bwdif_filter_intra_c function in the libavfilter/bwdifdsp.c:125:5 component.

    Published: 19 Apr 2024
    7.5
    High

    CVE-2024-31841

    Last Modified: 21 May 2025

    An issue was discovered in Italtel Embrace 1.6.4. The web server fails to sanitize input data, allowing remote unauthenticated attackers to read arbitrary files on the filesystem.

    Published: 19 Apr 2024
    7.5
    High

    CVE-2024-31846

    Last Modified: 21 May 2025

    An issue was discovered in Italtel Embrace 1.6.4. The web application does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

    Published: 19 Apr 2024
    8.8
    High

    CVE-2024-32166

    Last Modified: 3 Jun 2025

    Webid v1.2.1 suffers from an Insecure Direct Object Reference (IDOR) - Broken Access Control vulnerability, allowing attackers to buy now an auction that is suspended (horizontal privilege escalation).

    Published: 19 Apr 2024
    4.6
    Medium

    CVE-2024-32206

    Last Modified: 5 May 2025

    A stored cross-site scripting (XSS) vulnerability in the component \affiche\admin\index.php of WUZHICMS v4.1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the $formdata parameter.

    Published: 19 Apr 2024
    7.3
    High

    CVE-2024-32391

    Last Modified: 30 Apr 2025

    Cross Site Scripting vulnerability in MacCMS v.10 v.2024.1000.3000 allows a remote attacker to execute arbitrary code via a crafted payload.

    Published: 19 Apr 2024
    4.5
    Medium

    CVE-2024-32392

    Last Modified: 14 Apr 2025

    Cross Site Scripting vulnerability in CmSimple v.5.15 allows a remote attacker to execute arbitrary code via the functions.php component.

    Published: 19 Apr 2024
    7.1
    High

    CVE-2024-32409

    Last Modified: 4 Apr 2025

    An issue in SEMCMS v.4.8 allows a remote attacker to execute arbitrary code via a crafted script.

    Published: 19 Apr 2024
    8
    High

    CVE-2023-49501

    Last Modified: 4 Nov 2025

    Buffer Overflow vulnerability in Ffmpeg v.n6.1-3-g466799d4f5 allows a local attacker to execute arbitrary code via the config_eq_output function in the libavfilter/asrc_afirsrc.c:495:30 component.

    Published: 19 Apr 2024
    7.8
    High

    CVE-2023-51791

    Last Modified: 7 Jan 2026

    Buffer Overflow vulenrability in Ffmpeg v.N113007-g8d24a28d06 allows a local attacker to execute arbitrary code via the libavcodec/jpegxl_parser.c in gen_alias_map.

    Published: 19 Apr 2024
    7.8
    High

    CVE-2023-51793

    Last Modified: 7 Jan 2026

    Buffer Overflow vulnerability in Ffmpeg v.N113007-g8d24a28d06 allows a local attacker to execute arbitrary code via the libavutil/imgutils.c:353:9 in image_copy_plane.

    Published: 19 Apr 2024
    3.6
    Low

    CVE-2023-51796

    Last Modified: 7 Jan 2026

    Buffer Overflow vulnerability in Ffmpeg v.N113007-g8d24a28d06 allows a local attacker to execute arbitrary code via the libavfilter/f_reverse.c:269:26 in areverse_request_frame.

    Published: 19 Apr 2024
    6.7
    Medium

    CVE-2023-51797

    Last Modified: 7 Jan 2026

    Buffer Overflow vulnerability in Ffmpeg v.N113007-g8d24a28d06 allows a local attacker to execute arbitrary code via the libavfilter/avf_showwaves.c:722:24 in showwaves_filter_frame

    Published: 19 Apr 2024
    8.7
    High

    CVE-2024-3742

    Last Modified: 15 Apr 2026

    Electrolink transmitters store credentials in clear-text. Use of these credentials could allow an attacker to access the system.

    Published: 18 Apr 2024
    8.7
    High

    CVE-2024-1491

    Last Modified: 15 Apr 2026

    The devices allow access to an unprotected endpoint that allows MPFS file system binary image upload without authentication. The MPFS2 file system module provides a light-weight read-only file system that can be stored in external EEPROM, external serial flash, or internal flash program memory. This file system serves as the basis for the HTTP2 web server module, but is also used by the SNMP module and is available to other applications that require basic read-only storage capabilities. This can be exploited to overwrite the flash program memory that holds the web server's main interfaces and execute arbitrary code.

    Published: 18 Apr 2024
    6.9
    Medium

    CVE-2024-21846

    Last Modified: 15 Apr 2026

    An unauthenticated attacker can reset the board and stop transmitter operations by sending a specially-crafted GET request to the command.cgi gateway, resulting in a denial-of-service scenario.

    Published: 18 Apr 2024
    8.7
    High

    CVE-2024-21872

    Last Modified: 15 Apr 2026

    The device allows an unauthenticated attacker to bypass authentication and modify the cookie to reveal hidden pages that allows more critical operations to the transmitter.

    Published: 18 Apr 2024
    8.7
    High

    CVE-2024-22186

    Last Modified: 15 Apr 2026

    The application suffers from a privilege escalation vulnerability. An attacker logged in as guest can escalate his privileges by poisoning the cookie to become administrator.

    Published: 18 Apr 2024
    8.7
    High

    CVE-2024-22179

    Last Modified: 15 Apr 2026

    The application is vulnerable to an unauthenticated parameter manipulation that allows an attacker to set the credentials to blank giving her access to the admin panel. Also vulnerable to account takeover and arbitrary password change.

    Published: 18 Apr 2024
    8.7
    High

    CVE-2024-3741

    Last Modified: 15 Apr 2026

    Electrolink transmitters are vulnerable to an authentication bypass vulnerability affecting the login cookie. An attacker can set an arbitrary value except 'NO' to the login cookie and have full system access.

    Published: 18 Apr 2024
    3.5
    Low

    CVE-2024-30107

    Last Modified: 29 Oct 2025

    HCL Connections contains a broken access control vulnerability that may expose sensitive information to unauthorized users in certain scenarios.

    Published: 18 Apr 2024
    7.7
    High

    CVE-2024-32477

    Last Modified: 4 Sept 2025

    Deno is a JavaScript, TypeScript, and WebAssembly runtime with secure defaults. By using ANSI escape sequences and a race between `libc::tcflush(0, libc::TCIFLUSH)` and reading standard input, it's possible to manipulate the permission prompt and force it to allow an unsafe action regardless of the user input. Some ANSI escape sequences act as a info request to the master terminal emulator and the terminal emulator sends back the reply in the PTY channel. standard streams also use this channel to send and get data. For example the `\033[6n` sequence requests the current cursor position. These sequences allow us to append data to the standard input of Deno. This vulnerability allows an attacker to bypass Deno permission policy. This vulnerability is fixed in 1.42.2.

    Published: 18 Apr 2024
    7.3
    High

    CVE-2024-32474

    Last Modified: 15 Sept 2025

    Sentry is an error tracking and performance monitoring platform. Prior to 24.4.1, when authenticating as a superuser to Sentry with a username and password, the password is leaked as cleartext in logs under the _event_: `auth-index.validate_superuser`. An attacker with access to the log data could use these leaked credentials to login to the Sentry system as superuser. Self-hosted users on affected versions should upgrade to 24.4.1 or later. Users can configure the logging level to exclude logs of the `INFO` level and only generate logs for levels at `WARNING` or more.

    Published: 18 Apr 2024
    7.5
    High

    CVE-2024-20380

    Last Modified: 23 Jul 2025

    A vulnerability in the HTML parser of ClamAV could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to an issue in the C to Rust foreign function interface. An attacker could exploit this vulnerability by submitting a crafted file containing HTML content to be scanned by ClamAV on an affected device. An exploit could allow the attacker to cause the ClamAV scanning process to terminate, resulting in a DoS condition on the affected software.

    Published: 18 Apr 2024