CVE Feed

    Dashboard / CVE

    9.8
    Critical

    CVE-2024-31750

    Last Modified: 10 Jun 2025

    SQL injection vulnerability in f-logic datacube3 v.1.0 allows a remote attacker to obtain sensitive information via the req_id parameter.

    Published: 18 Apr 2024
    2.4
    Low

    CVE-2024-32325

    Last Modified: 13 May 2025

    TOTOLINK EX200 V4.0.3c.7646_B20201211 contains a Cross-site scripting (XSS) vulnerability through the ssid parameter in the setWiFiExtenderConfig function.

    Published: 18 Apr 2024
    6.8
    Medium

    CVE-2024-32326

    Last Modified: 7 Apr 2025

    TOTOLINK EX200 V4.0.3c.7646_B20201211 contains a Cross-site scripting (XSS) vulnerability through the key parameter in the setWiFiExtenderConfig function.

    Published: 18 Apr 2024
    5.5
    Medium

    CVE-2024-32327

    Last Modified: 3 Apr 2025

    TOTOLINK N300RT V2.1.8-B20201030.1539 contains a Store Cross-site scripting (XSS) vulnerability in Port Forwarding under the Firewall Page.

    Published: 18 Apr 2024
    4.3
    Medium

    CVE-2024-32333

    Last Modified: 3 Apr 2025

    TOTOLINK N300RT V2.1.8-B20201030.1539 contains a Store Cross-site scripting (XSS) vulnerability in MAC Filtering under the Firewall Page.

    Published: 18 Apr 2024
    6.5
    Medium

    CVE-2024-32334

    Last Modified: 3 Apr 2025

    TOTOLINK N300RT V2.1.8-B20201030.1539 contains a Store Cross-site scripting (XSS) vulnerability in IP/Port Filtering under the Firewall Page.

    Published: 18 Apr 2024
    5.4
    Medium

    CVE-2024-32335

    Last Modified: 3 Apr 2025

    TOTOLINK N300RT V2.1.8-B20201030.1539 contains a Store Cross-site scripting (XSS) vulnerability in Access Control under the Wireless Page.

    Published: 18 Apr 2024
    6.1
    Medium

    CVE-2024-27306

    Last Modified: 3 Nov 2025

    aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. A XSS vulnerability exists on index pages for static file handling. This vulnerability is fixed in 3.9.4. We have always recommended using a reverse proxy server (e.g. nginx) for serving static files. Users following the recommendation are unaffected. Other users can disable `show_index` if unable to upgrade.

    Published: 18 Apr 2024
    7.4
    High

    CVE-2024-30920

    Last Modified: 4 Nov 2025

    Cross Site Scripting vulnerability in DerbyNet v9.0 and below allows a remote attacker to execute arbitrary code via the render-document.php component.

    Published: 18 Apr 2024
    9.8
    Critical

    CVE-2024-30922

    Last Modified: 4 Nov 2025

    SQL Injection vulnerability in DerbyNet v9.0 allows a remote attacker to execute arbitrary code via the where Clause in Award Document Rendering.

    Published: 18 Apr 2024
    9.8
    Critical

    CVE-2024-30923

    Last Modified: 4 Nov 2025

    SQL Injection vulnerability in DerbyNet v9.0 and below allows a remote attacker to execute arbitrary code via the where Clause in Racer Document Rendering

    Published: 18 Apr 2024
    6.5
    Medium

    CVE-2024-30925

    Last Modified: 4 Nov 2025

    Cross Site Scripting vulnerability in DerbyNet v9.0 and below allows attackers to execute arbitrary code via the photo-thumbs.php component.

    Published: 18 Apr 2024
    6.3
    Medium

    CVE-2024-30927

    Last Modified: 4 Nov 2025

    Cross Site Scripting vulnerability in DerbyNet v9.0 and below allows attackers to execute arbitrary code via the racer-results.php component.

    Published: 18 Apr 2024
    8
    High

    CVE-2024-30929

    Last Modified: 4 Nov 2025

    Cross Site Scripting vulnerability in DerbyNet v9.0 and below allows attackers to execute arbitrary code via the 'back' Parameter in playlist.php

    Published: 18 Apr 2024
    5.9
    Medium

    CVE-2024-30171

    Last Modified: 15 Apr 2026

    An issue was discovered in Bouncy Castle Java TLS API and JSSE Provider before 1.78. Timing-based leakage may occur in RSA based handshakes because of exception processing.

    Published: 18 Apr 2024
    4.3
    Medium

    CVE-2024-3928

    Last Modified: 15 Apr 2026

    A vulnerability was found in Dromara open-capacity-platform 2.0.1. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /actuator/heapdump of the component auth-server. The manipulation leads to information disclosure. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-261367.

    Published: 17 Apr 2024
    4.3
    Medium

    CVE-2023-4509

    Last Modified: 2 Jul 2025

    It is possible for an API key to be logged in clear text in the audit log file after an invalid login attempt.

    Published: 17 Apr 2024
    8.1
    High

    CVE-2023-4235

    Last Modified: 4 Nov 2025

    A flaw was found in ofono, an Open Source Telephony on Linux. A stack overflow bug is triggered within the decode_deliver_report() function during the SMS decoding. It is assumed that the attack scenario is accessible from a compromised modem, a malicious base station, or just SMS. There is a bound check for this memcpy length in decode_submit(), but it was forgotten in decode_deliver_report().

    Published: 17 Apr 2024
    8.1
    High

    CVE-2023-4234

    Last Modified: 4 Nov 2025

    A flaw was found in ofono, an Open Source Telephony on Linux. A stack overflow bug is triggered within the decode_submit_report() function during the SMS decoding. It is assumed that the attack scenario is accessible from a compromised modem, a malicious base station, or just SMS. There is a bound check for this memcpy length in decode_submit(), but it was forgotten in decode_submit_report().

    Published: 17 Apr 2024
    8.1
    High

    CVE-2023-4233

    Last Modified: 4 Nov 2025

    A flaw was found in ofono, an Open Source Telephony on Linux. A stack overflow bug is triggered within the sms_decode_address_field() function during the SMS PDU decoding. It is assumed that the attack scenario is accessible from a compromised modem, a malicious base station, or just SMS.

    Published: 17 Apr 2024
    8.1
    High

    CVE-2023-4232

    Last Modified: 4 Nov 2025

    A flaw was found in ofono, an Open Source Telephony on Linux. A stack overflow bug is triggered within the decode_status_report() function during the SMS decoding. It is assumed that the attack scenario is accessible from a compromised modem, a malicious base station, or just SMS. There is a bound check for this memcpy length in decode_submit(), but it was forgotten in decode_status_report().

    Published: 17 Apr 2024
    5
    Medium

    CVE-2024-29955

    Last Modified: 4 Feb 2025

    A vulnerability in Brocade SANnav before v2.3.1 and v2.3.0a could allow a privileged user to print the SANnav encrypted key in PostgreSQL startup logs. This could provide attackers with an additional, less-protected path to acquiring the encryption key.

    Published: 17 Apr 2024
    5.5
    Medium

    CVE-2024-29952

    Last Modified: 4 Feb 2025

    A vulnerability in Brocade SANnav before v2.3.1 and v2.3.0a could allow an authenticated user to print the Auth, Priv, and SSL key store passwords in unencrypted logs by manipulating command variables.

    Published: 17 Apr 2024
    6.1
    Medium

    CVE-2024-32472

    Last Modified: 15 Apr 2026

    excalidraw is an open source virtual hand-drawn style whiteboard. A stored XSS vulnerability in Excalidraw's web embeddable component. This allows arbitrary JavaScript to be run in the context of the domain where the editor is hosted. There were two vectors. One rendering untrusted string as iframe's `srcdoc` without properly sanitizing against HTML injection. Second by improperly sanitizing against attribute HTML injection. This in conjunction with allowing `allow-same-origin` sandbox flag (necessary for several embeds) resulted in the XSS. This vulnerability is fixed in 0.17.6 and 0.16.4.

    Published: 17 Apr 2024
    3.3
    Low

    CVE-2024-0257

    Last Modified: 15 Apr 2026

    RoboDK v5.5.4 is vulnerable to heap-based buffer overflow while processing a specific project file. The resulting memory corruption may crash the application.

    Published: 17 Apr 2024
    9.8
    Critical

    CVE-2024-3817

    Last Modified: 11 Dec 2025

    HashiCorp’s go-getter library is vulnerable to argument injection when executing Git to discover remote branches. This vulnerability does not affect the go-getter/v2 branch and package.

    Published: 17 Apr 2024
    5.4
    Medium

    CVE-2024-21990

    Last Modified: 10 Feb 2025

    ONTAP Select Deploy administration utility versions 9.12.1.x, 9.13.1.x and 9.14.1.x contain hard-coded credentials that could allow an attacker to view Deploy configuration information and modify the account credentials.

    Published: 17 Apr 2024
    8.1
    High

    CVE-2024-21989

    Last Modified: 10 Feb 2025

    ONTAP Select Deploy administration utility versions 9.12.1.x, 9.13.1.x and 9.14.1.x are susceptible to a vulnerability which when successfully exploited could allow a read-only user to escalate their privileges.

    Published: 17 Apr 2024
    5.7
    Medium

    CVE-2024-29951

    Last Modified: 4 Feb 2025

    Brocade SANnav before v2.3.1 and v2.3.0a uses the SHA-1 hash in internal SSH ports that are not open to remote connection.

    Published: 17 Apr 2024
    8.3
    High

    CVE-2024-3323

    Last Modified: 15 Apr 2026

    Cross Site Scripting in UI Request/Response Validation in TIBCO JasperReports Server 8.0.4 and 8.2.0 allows allows for the injection of malicious executable scripts into the code of a trusted application that may lead to stealing the user's active session cookie via sending malicious link, enticing the user to interact.

    Published: 17 Apr 2024
    7.5
    High

    CVE-2024-29950

    Last Modified: 4 Feb 2025

    The class FileTransfer implemented in Brocade SANnav before v2.3.1, v2.3.0a, uses the ssh-rsa signature scheme, which has a SHA-1 hash. The vulnerability could allow a remote, unauthenticated attacker to perform a man-in-the-middle attack.

    Published: 17 Apr 2024
    6.5
    Medium

    CVE-2024-3914

    Last Modified: 13 Feb 2025

    Use after free in V8 in Google Chrome prior to 124.0.6367.60 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

    Published: 17 Apr 2024
    8.4
    High

    CVE-2024-28073

    Last Modified: 10 Feb 2025

    SolarWinds Serv-U was found to be susceptible to a Directory Traversal Remote Code Vulnerability. This vulnerability requires a highly privileged account to be exploited.

    Published: 17 Apr 2024
    5.9
    Medium

    CVE-2023-5407

    Last Modified: 15 Apr 2026

    Controller denial of service due to improper handling of a specially crafted message received by the controller. See Honeywell Security Notification for recommendations on upgrading and versioning.

    Published: 17 Apr 2024
    5.9
    Medium

    CVE-2023-5406

    Last Modified: 15 Apr 2026

    Server communication with a controller can lead to remote code execution using a specially crafted message from the controller. See Honeywell Security Notification for recommendations on upgrading and versioning.

    Published: 17 Apr 2024
    5.9
    Medium

    CVE-2023-5405

    Last Modified: 15 Apr 2026

    Server information leak for the CDA Server process memory can occur when an error is generated in response to a specially crafted message. See Honeywell Security Notification for recommendations on upgrading and versioning.

    Published: 17 Apr 2024
    8.1
    High

    CVE-2023-5404

    Last Modified: 15 Apr 2026

    Server receiving a malformed message can cause a pointer to be overwritten which can result in a remote code execution or failure. See Honeywell Security Notification for recommendations on upgrading and versioning.

    Published: 17 Apr 2024
    8.1
    High

    CVE-2023-5403

    Last Modified: 15 Apr 2026

    Server hostname translation to IP address manipulation which could lead to an attacker performing remote code execution or causing a failure. See Honeywell Security Notification for recommendations on upgrading and versioning.

    Published: 17 Apr 2024
    8.1
    High

    CVE-2023-5401

    Last Modified: 15 Apr 2026

    Server receiving a malformed message based on a using the specified key values can cause a stack overflow vulnerability which could lead to an attacker performing remote code execution or causing a failure. See Honeywell Security Notification for recommendations on upgrading and versioning.

    Published: 17 Apr 2024
    8.1
    High

    CVE-2023-5400

    Last Modified: 15 Apr 2026

    Server receiving a malformed message based on a using the specified key values can cause a heap overflow vulnerability which could lead to an attacker performing remote code execution or causing a failure.  See Honeywell Security Notification for recommendations on upgrading and versioning.

    Published: 17 Apr 2024
    5.9
    Medium

    CVE-2023-5398

    Last Modified: 15 Apr 2026

    Server receiving a malformed message based on a list of IPs resulting in heap corruption causing a denial of service. See Honeywell Security Notification for recommendations on upgrading and versioning.

    Published: 17 Apr 2024
    8.1
    High

    CVE-2023-5397

    Last Modified: 15 Apr 2026

    Server receiving a malformed message to create a new connection could lead to an attacker performing remote code execution or causing a failure. See Honeywell Security Notification for recommendations on upgrading and versioning.

    Published: 17 Apr 2024
    7.4
    High

    CVE-2023-5396

    Last Modified: 15 Apr 2026

    Server receiving a malformed message creates connection for a hostname that may cause a stack overflow resulting in possible remote code execution. See Honeywell Security Notification for recommendations on upgrading and versioning.

    Published: 17 Apr 2024
    8.1
    High

    CVE-2023-5395

    Last Modified: 15 Apr 2026

    Server receiving a malformed message that uses the hostname in an internal table may cause a stack overflow resulting in possible remote code execution. See Honeywell Security Notification for recommendations on upgrading and versioning.

    Published: 17 Apr 2024
    7.1
    High

    CVE-2024-32463

    Last Modified: 15 Apr 2026

    phlex is an open source framework for building object-oriented views in Ruby. There is a potential cross-site scripting (XSS) vulnerability that can be exploited via maliciously crafted user data. The filter to detect and prevent the use of the `javascript:` URL scheme in the `href` attribute of an `<a>` tag could be bypassed with tab `\t` or newline `\n` characters between the characters of the protocol, e.g. `java\tscript:`. This vulnerability is fixed in 1.10.1, 1.9.2, 1.8.3, 1.7.2, 1.6.3, 1.5.3, and 1.4.2. Configuring a Content Security Policy that does not allow `unsafe-inline` would effectively prevent this vulnerability from being exploited.

    Published: 17 Apr 2024
    7.5
    High

    CVE-2024-30253

    Last Modified: 15 Apr 2026

    @solana/web3.js is the Solana JavaScript SDK. Using particular inputs with `@solana/web3.js` will result in memory exhaustion (OOM). If you have a server, client, mobile, or desktop product that accepts untrusted input for use with `@solana/web3.js`, your application/service may crash, resulting in a loss of availability. This vulnerability is fixed in 1.0.1, 1.10.2, 1.11.1, 1.12.1, 1.1.2, 1.13.1, 1.14.1, 1.15.1, 1.16.2, 1.17.1, 1.18.1, 1.19.1, 1.20.3, 1.21.1, 1.22.1, 1.23.1, 1.24.3, 1.25.1, 1.26.1, 1.27.1, 1.28.1, 1.2.8, 1.29.4, 1.30.3, 1.31.1, 1.3.1, 1.32.3, 1.33.1, 1.34.1, 1.35.2, 1.36.1, 1.37.3, 1.38.1, 1.39.2, 1.40.2, 1.41.11, 1.4.1, 1.42.1, 1.43.7, 1.44.4, 1.45.1, 1.46.1, 1.47.5, 1.48.1, 1.49.1, 1.50.2, 1.51.1, 1.5.1, 1.52.1, 1.53.1, 1.54.2, 1.55.1, 1.56.3, 1.57.1, 1.58.1, 1.59.2, 1.60.1, 1.61.2, 1.6.1, 1.62.2, 1.63.2, 1.64.1, 1.65.1, 1.66.6, 1.67.3, 1.68.2, 1.69.1, 1.70.4, 1.71.1, 1.72.1, 1.7.2, 1.73.5, 1.74.1, 1.75.1, 1.76.1, 1.77.4, 1.78.8, 1.79.1, 1.80.1, 1.81.1, 1.8.1, 1.82.1, 1.83.1, 1.84.1, 1.85.1, 1.86.1, 1.87.7, 1.88.1, 1.89.2, 1.90.2, 1.9.2, and 1.91.3.

    Published: 17 Apr 2024
    4.3
    Medium

    CVE-2024-3825

    Last Modified: 15 Apr 2026

    Versions of the BlazeMeter Jenkins plugin prior to 4.22 contain a flaw which results in credential enumeration

    Published: 17 Apr 2024
    4.1
    Medium

    CVE-2024-29035

    Last Modified: 12 Feb 2025

    Umbraco is an ASP.NET CMS. Failing webhooks logs are available when solution is not in debug mode. Those logs can contain information that is critical. This vulnerability is fixed in 13.1.1.

    Published: 17 Apr 2024
    5.3
    Medium

    CVE-2023-43491

    Last Modified: 4 Nov 2025

    An information disclosure vulnerability exists in the web interface /cgi-bin/debug_dump.cgi functionality of Peplink Smart Reader v1.2.0 (in QEMU). A specially crafted HTTP request can lead to a disclosure of sensitive information. An attacker can make an unauthenticated HTTP request to trigger this vulnerability.

    Published: 17 Apr 2024
    5.3
    Medium

    CVE-2023-45209

    Last Modified: 4 Nov 2025

    An information disclosure vulnerability exists in the web interface /cgi-bin/download_config.cgi functionality of Peplink Smart Reader v1.2.0 (in QEMU). A specially crafted HTTP request can lead to a disclosure of sensitive information. An attacker can make an unauthenticated HTTP request to trigger this vulnerability.

    Published: 17 Apr 2024