CVE Feed

    Dashboard / CVE

    6.1
    Medium

    CVE-2024-23559

    Last Modified: 11 Apr 2025

    HCL DevOps Deploy / Launch is generating an obsolete HTTP header.

    Published: 15 Apr 2024
    4.1
    Medium

    CVE-2023-45808

    Last Modified: 6 Feb 2025

    iTop is an IT service management platform. When creating or updating an object, extkey values aren't checked to be in the current user silo. In other words, by forging an http request, the user can create objects pointing to out of silo objects (for example a UserRequest in an out of scope Organization). Fixed in iTop 2.7.10, 3.0.4, 3.1.1, and 3.2.0.

    Published: 15 Apr 2024
    6.8
    Medium

    CVE-2023-44396

    Last Modified: 6 Feb 2025

    iTop is an IT service management platform. Dashlet edits ajax endpoints can be used to produce XSS. Fixed in iTop 2.7.10, 3.0.4, and 3.1.1.

    Published: 15 Apr 2024
    5.7
    Medium

    CVE-2023-43790

    Last Modified: 6 Feb 2025

    iTop is an IT service management platform. By manipulating HTTP queries, a user can inject malicious content in the fields used for the object friendlyname value. This vulnerability is fixed in 3.1.1 and 3.2.0.

    Published: 15 Apr 2024
    5
    Medium

    CVE-2023-38511

    Last Modified: 6 Feb 2025

    iTop is an IT service management platform. Dashboard editor : can load multiple files and URL, and full path disclosure on dashboard config file. This vulnerability is fixed in 3.0.4 and 3.1.1.

    Published: 15 Apr 2024
    6.3
    Medium

    CVE-2024-3797

    Last Modified: 10 Feb 2025

    A vulnerability was found in SourceCodester QR Code Bookmark System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /endpoint/delete-bookmark.php?bookmark=1. The manipulation of the argument bookmark leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-260764.

    Published: 15 Apr 2024
    4.8
    Medium

    CVE-2024-3796

    Last Modified: 10 Apr 2025

    Vulnerability in WBSAirback 21.02.04, which consists of a stored Cross-Site Scripting (XSS) through /admin/BackupSchedule, description field. Exploitation of this vulnerability could allow a remote user to send a specially crafted URL to the victim and steal their session data.

    Published: 15 Apr 2024
    4.8
    Medium

    CVE-2024-3795

    Last Modified: 10 Apr 2025

    Vulnerability in WBSAirback 21.02.04, which consists of a stored Cross-Site Scripting (XSS) through /admin/BackupTemplate, name / description fields. Exploitation of this vulnerability could allow a remote user to send a specially crafted URL to the victim and steal their session data.

    Published: 15 Apr 2024
    4.8
    Medium

    CVE-2024-3794

    Last Modified: 10 Apr 2025

    Vulnerability in WBSAirback 21.02.04, which consists of a stored Cross-Site Scripting (XSS) through /admin/AdvancedSystem, description field, all parameters. Exploitation of this vulnerability could allow a remote user to send a specially crafted URL to the victim and steal their session data.

    Published: 15 Apr 2024
    4.8
    Medium

    CVE-2024-3793

    Last Modified: 10 Apr 2025

    Vulnerability in WBSAirback 21.02.04, which consists of a stored Cross-Site Scripting (XSS) through /admin/CloudAccounts, account name / user password / server fields, all parameters. Exploitation of this vulnerability could allow a remote user to send a specially crafted URL to the victim and steal their session data.

    Published: 15 Apr 2024
    4.8
    Medium

    CVE-2024-3792

    Last Modified: 10 Apr 2025

    Vulnerability in WBSAirback 21.02.04, which consists of a stored Cross-Site Scripting (XSS) through /admin/DeviceReplication, execution range field, all parameters. Exploitation of this vulnerability could allow a remote user to send a specially crafted URL to the victim and steal their session data.

    Published: 15 Apr 2024
    4.8
    Medium

    CVE-2024-3791

    Last Modified: 10 Apr 2025

    Vulnerability in WBSAirback 21.02.04, which consists of a stored Cross-Site Scripting (XSS) through /admin/SystemConfiguration, name / free memory limit fields , type / password parameters. Exploitation of this vulnerability could allow a remote user to send a specially crafted URL to the victim and steal their session data.

    Published: 15 Apr 2024
    4.8
    Medium

    CVE-2024-3790

    Last Modified: 10 Apr 2025

    Vulnerability in WBSAirback 21.02.04, which consists of a stored Cross-Site Scripting (XSS) through /admin/SystemUsers, login / description fields, passwd1/ passwd2 parameters. Exploitation of this vulnerability could allow a remote user to send a specially crafted URL to the victim and steal their session data.

    Published: 15 Apr 2024
    6.5
    Medium

    CVE-2024-3789

    Last Modified: 10 Apr 2025

    Uncontrolled resource consumption vulnerability in White Bear Solutions WBSAirback, version 21.02.04. This vulnerability could allow an attacker to send multiple command injection payloads to influence the amount of resources consumed.

    Published: 15 Apr 2024
    6.6
    Medium

    CVE-2024-3788

    Last Modified: 10 Apr 2025

    Vulnerability in WBSAirback 21.02.04, which involves improper neutralisation of Server-Side Includes (SSI), through License (/admin/CDPUsers). Exploitation of this vulnerability could allow a remote user to execute arbitrary code.

    Published: 15 Apr 2024
    6.6
    Medium

    CVE-2024-3787

    Last Modified: 27 Mar 2025

    Vulnerability in WBSAirback 21.02.04, which involves improper neutralisation of Server-Side Includes (SSI), through S3 disks (/admin/DeviceS3). Exploitation of this vulnerability could allow a remote user to execute arbitrary code.

    Published: 15 Apr 2024
    6.6
    Medium

    CVE-2024-3786

    Last Modified: 10 Apr 2025

    Vulnerability in WBSAirback 21.02.04, which involves improper neutralisation of Server-Side Includes (SSI), through Device Synchronizations (/admin/DeviceReplication). Exploitation of this vulnerability could allow a remote user to execute arbitrary code.

    Published: 15 Apr 2024
    6.6
    Medium

    CVE-2024-3785

    Last Modified: 10 Apr 2025

    Vulnerability in WBSAirback 21.02.04, which involves improper neutralisation of Server-Side Includes (SSI), through Device NAS shared section (/admin/DeviceNAS). Exploitation of this vulnerability could allow a remote user to execute arbitrary code.

    Published: 15 Apr 2024
    6.6
    Medium

    CVE-2024-3784

    Last Modified: 27 Feb 2025

    Vulnerability in WBSAirback 21.02.04, which involves improper neutralisation of Server-Side Includes (SSI), through S3 Accounts (/admin/CloudAccounts). Exploitation of this vulnerability could allow a remote user to execute arbitrary code.

    Published: 15 Apr 2024
    7.7
    High

    CVE-2024-3783

    Last Modified: 10 Apr 2025

    The Backup Agents section in WBSAirback 21.02.04 is affected by a Path Traversal vulnerability, allowing a user with low privileges to download files from the system.

    Published: 15 Apr 2024
    8.8
    High

    CVE-2024-3782

    Last Modified: 10 Apr 2025

    Cross-Site Request Forgery vulnerability in WBSAirback 21.02.04, which could allow an attacker to create a manipulated HTML form to perform privileged actions once it is executed by a privileged user.

    Published: 15 Apr 2024
    9.1
    Critical

    CVE-2024-3781

    Last Modified: 10 Apr 2025

    Command injection vulnerability in the operating system. Improper neutralisation of special elements in Active Directory integration allows the intended command to be modified when sent to a downstream component in WBSAirback 21.02.04.

    Published: 15 Apr 2024
    6
    Medium

    CVE-2024-24898

    Last Modified: 15 Apr 2026

    Exposure of Sensitive Information to an Unauthorized Actor vulnerability in openEuler kernel on Linux allows Resource Leak Exposure. This vulnerability is associated with program files https://gitee.Com/openeuler/kernel/blob/openEuler-1.0-LTS/drivers/staging/gmjstcm/tcm.C. This issue affects kernel: from 4.19.90-2109.1.0.0108 before 4.19.90-2403.4.0.0244.

    Published: 15 Apr 2024
    6
    Medium

    CVE-2024-24891

    Last Modified: 15 Apr 2026

    Exposure of Sensitive Information to an Unauthorized Actor vulnerability in openEuler kernel on Linux allows Resource Leak Exposure. This vulnerability is associated with program files https://gitee.Com/openeuler/kernel/blob/openEuler-1.0-LTS/drivers/staging/gmjstcm/tcm.C. This issue affects kernel: from 4.19.90-2109.1.0.0108 before 4.19.90-2403.4.0.0244.

    Published: 15 Apr 2024
    7.8
    High

    CVE-2024-3780

    Last Modified: 15 Apr 2026

    A vulnerability of Information Exposure has been found on Technicolor CGA2121 affecting the version 1.01, this vulnerability allows a local attacker to obtain sensitive information stored on the device such as wifi network's SSID and their respective passwords.

    Published: 15 Apr 2024
    —
    Unknown

    CVE-2024-3802

    Last Modified: 4 Jun 2024

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

    Published: 15 Apr 2024
    4.2
    Medium

    CVE-2024-26023

    Last Modified: 30 Jun 2025

    OS command injection vulnerability in BUFFALO wireless LAN routers allows a logged-in user to execute arbitrary OS commands.

    Published: 15 Apr 2024
    9.8
    Critical

    CVE-2024-23486

    Last Modified: 30 Jun 2025

    Plaintext storage of a password issue exists in BUFFALO wireless LAN routers, which may allow a network-adjacent unauthenticated attacker with access to the product's login page may obtain configured credentials.

    Published: 15 Apr 2024
    5.3
    Medium

    CVE-2024-28957

    Last Modified: 30 Jun 2025

    Generation of predictable identifiers issue exists in Cente middleware TCP/IP Network Series. If this vulnerability is exploited, a remote unauthenticated attacker may interfere communications by predicting some packet header IDs of the device.

    Published: 15 Apr 2024
    5.3
    Medium

    CVE-2024-28894

    Last Modified: 30 Jun 2025

    Out-of-bounds read vulnerability caused by improper checking of the option length values in IPv6 headers exists in Cente middleware TCP/IP Network Series, which may allow an unauthenticated attacker to stop the device operations by sending a specially crafted packet.

    Published: 15 Apr 2024
    7.5
    High

    CVE-2024-23911

    Last Modified: 30 Jun 2025

    Out-of-bounds read vulnerability caused by improper checking of the option length values in IPv6 NDP packets exists in Cente middleware TCP/IP Network Series, which may allow an unauthenticated attacker to stop the device operations by sending a specially crafted packet.

    Published: 15 Apr 2024
    8.8
    High

    CVE-2024-30220

    Last Modified: 27 Aug 2025

    Command injection vulnerability in PLANEX COMMUNICATIONS wireless LAN routers allows a network-adjacent unauthenticated attacker to execute an arbitrary command by sending a specially crafted request to a certain port. Note that MZK-MF300N is no longer supported, therefore the update for this product is not provided.

    Published: 15 Apr 2024
    6.8
    Medium

    CVE-2024-30219

    Last Modified: 27 Aug 2025

    Active debug code vulnerability exists in PLANEX COMMUNICATIONS wireless LAN routers. If a logged-in user who knows how to use the debug function accesses the device's management page, an unintended operation may be performed. Note that MZK-MF300N is no longer supported, therefore the update for this product is not provided.

    Published: 15 Apr 2024
    7.8
    High

    CVE-2024-29219

    Last Modified: 19 Sept 2025

    Out-of-bounds read vulnerability exists in KV STUDIO Ver.11.64 and earlier and KV REPLAY VIEWER Ver.2.64 and earlier, and VT5-WX15/WX12 Ver.6.02 and earlier, which may lead to information disclosure or arbitrary code execution by having a user of the affected product open a specially crafted file.

    Published: 15 Apr 2024
    8.8
    High

    CVE-2024-29218

    Last Modified: 30 Jun 2025

    Out-of-bounds write vulnerability exists in KV STUDIO Ver.11.64 and earlier, KV REPLAY VIEWER Ver.2.64 and earlier, and VT5-WX15/WX12 Ver.6.02 and earlier, which may lead to information disclosure or arbitrary code execution by having a user of the affected product open a specially crafted file.

    Published: 15 Apr 2024
    4.7
    Medium

    CVE-2024-32129

    Last Modified: 28 Apr 2026

    URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Freshworks Freshdesk (official).This issue affects Freshdesk (official): from n/a through 2.3.6.

    Published: 15 Apr 2024
    7.8
    High

    CVE-2024-28099

    Last Modified: 30 Jun 2025

    VT STUDIO Ver.8.32 and earlier contains an issue with the DLL search path, which may lead to insecurely loading Dynamic Link Libraries. As a result, arbitrary code may be executed with the privileges of the running application.

    Published: 15 Apr 2024
    4.3
    Medium

    CVE-2024-30546

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Pixelite Login With Ajax.This issue affects Login With Ajax: from n/a through 4.1.

    Published: 15 Apr 2024
    5.4
    Medium

    CVE-2024-31373

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in E2Pdf e2pdf e2pdf.This issue affects e2pdf: from n/a through <= 1.20.27.

    Published: 15 Apr 2024
    4.3
    Medium

    CVE-2024-31374

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Scott Bolinger AppPresser apppresser allows Cross Site Request Forgery.This issue affects AppPresser: from n/a through <= 4.3.0.

    Published: 15 Apr 2024
    4.3
    Medium

    CVE-2024-31376

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Andrew Dashboard To-Do List dashboard-to-do-list.This issue affects Dashboard To-Do List: from n/a through <= 1.3.1.

    Published: 15 Apr 2024
    5.4
    Medium

    CVE-2024-31378

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in MailMunch MailChimp Forms by MailMunch.This issue affects MailChimp Forms by MailMunch: from n/a through 3.2.1.

    Published: 15 Apr 2024
    4.3
    Medium

    CVE-2024-31379

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Smash Balloon Smash Balloon Social Post Feed.This issue affects Smash Balloon Social Post Feed: from n/a through 4.2.1.

    Published: 15 Apr 2024
    4.3
    Medium

    CVE-2024-31381

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in RebelCode Spotlight Social Media Feeds.This issue affects Spotlight Social Media Feeds: from n/a through 1.6.10.

    Published: 15 Apr 2024
    4.3
    Medium

    CVE-2024-31382

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in creativethemeshq Blocksy blocksy.This issue affects Blocksy: from n/a through <= 2.0.22.

    Published: 15 Apr 2024
    4.3
    Medium

    CVE-2024-31383

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Pagelayer PopularFX.This issue affects PopularFX: from n/a through 1.2.4.

    Published: 15 Apr 2024
    4.3
    Medium

    CVE-2024-31384

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Rara Theme Spa and Salon.This issue affects Spa and Salon: from n/a through 1.2.7.

    Published: 15 Apr 2024
    4.3
    Medium

    CVE-2024-31385

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Reservation Diary ReDi Restaurant Reservation.This issue affects ReDi Restaurant Reservation: from n/a through 24.0128.

    Published: 15 Apr 2024
    4.3
    Medium

    CVE-2024-31388

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Pauple Table & Contact Form 7 Database – Tablesome.This issue affects Table & Contact Form 7 Database – Tablesome: from n/a through 1.0.25.

    Published: 15 Apr 2024
    5.4
    Medium

    CVE-2024-31389

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Ertano MihanPanel.This issue affects MihanPanel: from n/a before 12.7.

    Published: 15 Apr 2024