CVE Feed

    Dashboard / CVE

    8.1
    High

    CVE-2023-44857

    Last Modified: 27 May 2025

    An issue in Cobham SAILOR VSAT Ku v.164B019, allows a remote attacker to execute arbitrary code via a crafted script to the sub_21D24 function in the acu_web component.

    Published: 12 Apr 2024
    7.5
    High

    CVE-2024-28869

    Last Modified: 26 Nov 2025

    Traefik is an HTTP reverse proxy and load balancer. In affected versions sending a GET request to any Traefik endpoint with the "Content-length" request header results in an indefinite hang with the default configuration. This vulnerability can be exploited by attackers to induce a denial of service. This vulnerability has been addressed in version 2.11.2 and 3.0.0-rc5. Users are advised to upgrade. For affected versions, this vulnerability can be mitigated by configuring the readTimeout option.

    Published: 12 Apr 2024
    6.2
    Medium

    CVE-2024-22734

    Last Modified: 17 Jun 2025

    An issue was discovered in AMCS Group Trux Waste Management Software before version 7.19.0018.26912, allows local attackers to obtain sensitive information via a static, hard-coded AES Key-IV pair in the TxUtilities.dll and TruxUser.cfg components.

    Published: 12 Apr 2024
    7.8
    High

    CVE-2024-25545

    Last Modified: 17 Jun 2025

    An issue in Weave Weave Desktop v.7.78.10 allows a local attacker to execute arbitrary code via a crafted script to the nwjs framework component.

    Published: 12 Apr 2024
    7.5
    High

    CVE-2024-29400

    Last Modified: 14 May 2025

    An issue was discovered in RuoYi v4.5.1, allows attackers to obtain sensitive information via the status parameter.

    Published: 12 Apr 2024
    6.3
    Medium

    CVE-2024-29461

    Last Modified: 27 May 2025

    An issue in Floodlight SDN OpenFlow Controller v.1.2 allows a remote attacker to cause a denial of service via the datapath id component.

    Published: 12 Apr 2024
    5.3
    Medium

    CVE-2024-30614

    Last Modified: 11 Apr 2025

    An issue in Ametys CMS v4.5.0 and before allows attackers to obtain sensitive information via exposed resources to the error scope.

    Published: 12 Apr 2024
    4.8
    Medium

    CVE-2024-31839

    Last Modified: 17 Jun 2025

    Cross Site Scripting vulnerability in tiagorlampert CHAOS v.5.0.1 allows a remote attacker to escalate privileges via the sendCommandHandler function in the handler.go component.

    Published: 12 Apr 2024
    —
    Unknown

    CVE-2024-32205

    Last Modified: 22 Apr 2024

    DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

    Published: 12 Apr 2024
    7.5
    High

    CVE-2024-2757

    Last Modified: 4 Nov 2025

    In PHP 8.3.* before 8.3.5, function mb_encode_mimeheader() runs endlessly for some inputs that contain long strings of non-space characters followed by a space. This could lead to a potential DoS attack if a hostile user sends data to an application that uses this function.

    Published: 12 Apr 2024
    8.8
    High

    CVE-2020-8006

    Last Modified: 4 Nov 2025

    The server in Circontrol Raption through 5.11.2 has a pre-authentication stack-based buffer overflow that can be exploited to gain run-time control of the device as root. The ocpp1.5 and pwrstudio binaries on the charging station do not use a number of common exploitation mitigations. In particular, there are no stack canaries and they do not use the Position Independent Executable (PIE) format.

    Published: 12 Apr 2024
    8
    High

    CVE-2023-49528

    Last Modified: 4 Nov 2025

    Buffer Overflow vulnerability in FFmpeg version n6.1-3-g466799d4f5, allows a local attacker to execute arbitrary code and cause a denial of service (DoS) via the af_dialoguenhance.c:261:5 in the de_stereo component.

    Published: 12 Apr 2024
    6.5
    Medium

    CVE-2024-2756

    Last Modified: 15 Apr 2026

    Due to an incomplete fix to CVE-2022-31629 https://github.com/advisories/GHSA-c43m-486j-j32p , network and same-site attackers can set a standard insecure cookie in the victim's browser which is treated as a __Host- or __Secure- cookie by PHP applications.

    Published: 12 Apr 2024
    6.5
    Medium

    CVE-2024-3096

    Last Modified: 4 Nov 2025

    In PHP  version 8.1.* before 8.1.28, 8.2.* before 8.2.18, 8.3.* before 8.3.5, if a password stored with password_hash() starts with a null byte (\x00), testing a blank string as the password via password_verify() will incorrectly return true.

    Published: 12 Apr 2024
    7.5
    High

    CVE-2024-3651

    Last Modified: 4 Nov 2025

    A vulnerability was identified in the kjd/idna library, specifically within the `idna.encode()` function, affecting version 3.6. The issue arises from the function's handling of crafted input strings, which can lead to quadratic complexity and consequently, a denial of service condition. This vulnerability is triggered by a crafted input that causes the `idna.encode()` function to process the input with considerable computational load, significantly increasing the processing time in a quadratic manner relative to the input size.

    Published: 12 Apr 2024
    —
    Unknown

    CVE-2024-30850

    Last Modified: 3 Apr 2026

    DO NOT USE THIS CVE RECORD. ConsultIDs: CVE-2024-33434. Reason: This record is a duplicate of CVE-2024-33434. Notes: All CVE users should reference CVE-2024-33434 instead of this record. All references and descriptions in this record have been removed to prevent accidental usage.

    Published: 12 Apr 2024
    6.2
    Medium

    CVE-2024-2397

    Last Modified: 15 Apr 2026

    Due to a bug in packet data buffers management, the PPP printer in tcpdump can enter an infinite loop when reading a crafted DLT_PPP_SERIAL .pcap savefile. This problem does not affect any tcpdump release, but it affected the git master branch from 2023-06-05 to 2024-03-21.

    Published: 12 Apr 2024
    7.4
    High

    CVE-2023-5394

    Last Modified: 15 Apr 2026

    Server receiving a malformed message that where the GCL message hostname may be too large which may cause a stack overflow; resulting in possible remote code execution. Honeywell recommends updating to the most recent version of the product. See Honeywell Security Notification for recommendations on upgrading and versioning.

    Published: 11 Apr 2024
    7.4
    High

    CVE-2023-5393

    Last Modified: 15 Apr 2026

    Server receiving a malformed message that causes a disconnect to a hostname may causing a stack overflow resulting in possible remote code execution. Honeywell recommends updating to the most recent version of the product. See Honeywell Security Notification for recommendations on upgrading and versioning.

    Published: 11 Apr 2024
    7.5
    High

    CVE-2023-5392

    Last Modified: 15 Apr 2026

    C300 information leak due to an analysis feature which allows extracting more memory over the network than required by the function. Honeywell recommends updating to the most recent version of the product. See Honeywell Security Notification for recommendations on upgrading and versioning.

    Published: 11 Apr 2024
    7.8
    High

    CVE-2024-30271

    Last Modified: 4 Dec 2024

    Illustrator versions 28.3, 27.9.2 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 11 Apr 2024
    7.8
    High

    CVE-2024-30272

    Last Modified: 4 Dec 2024

    Illustrator versions 28.3, 27.9.2 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 11 Apr 2024
    7.8
    High

    CVE-2024-30273

    Last Modified: 4 Dec 2024

    Illustrator versions 28.3, 27.9.2 and earlier are affected by a Stack-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 11 Apr 2024
    5.9
    Medium

    CVE-2023-50949

    Last Modified: 21 Nov 2024

    IBM QRadar SIEM 7.5 could allow an unauthorized user to perform unauthorized actions due to improper certificate validation. IBM X-Force ID: 275706.

    Published: 11 Apr 2024
    4.3
    Medium

    CVE-2024-32105

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in ELEXtensions ELEX WooCommerce Dynamic Pricing and Discounts.This issue affects ELEX WooCommerce Dynamic Pricing and Discounts: from n/a through 2.1.2.

    Published: 11 Apr 2024
    4.3
    Medium

    CVE-2024-32106

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in WP Compress WP Compress – Image Optimizer [All-In-One].This issue affects WP Compress – Image Optimizer [All-In-One]: from n/a through 6.10.35.

    Published: 11 Apr 2024
    4.3
    Medium

    CVE-2024-32107

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in XLPlugins Finale Lite.This issue affects Finale Lite: from n/a through 2.18.0.

    Published: 11 Apr 2024
    4.3
    Medium

    CVE-2024-32108

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Stephanie Leary Convert Post Types.This issue affects Convert Post Types: from n/a through 1.4.

    Published: 11 Apr 2024
    4.3
    Medium

    CVE-2024-32109

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Julien Berthelot / MPEmbed.Com WP Matterport Shortcode allows Cross Site Request Forgery.This issue affects WP Matterport Shortcode: from n/a through 2.1.9.

    Published: 11 Apr 2024
    5.9
    Medium

    CVE-2024-32083

    Last Modified: 28 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Varun Kumar Easy Logo allows Stored XSS.This issue affects Easy Logo: from n/a through 1.9.3.

    Published: 11 Apr 2024
    5.9
    Medium

    CVE-2024-31361

    Last Modified: 28 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in bunny.Net allows Stored XSS.This issue affects bunny.Net: from n/a through 2.0.1.

    Published: 11 Apr 2024
    5.9
    Medium

    CVE-2024-31387

    Last Modified: 28 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Popup LikeBox Team Popup Like box allows Stored XSS.This issue affects Popup Like box: from n/a through 3.7.2.

    Published: 11 Apr 2024
    5.9
    Medium

    CVE-2024-31925

    Last Modified: 28 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in FAKTOR VIER F4 Improvements allows Stored XSS.This issue affects F4 Improvements: from n/a through 1.8.0.

    Published: 11 Apr 2024
    5.9
    Medium

    CVE-2024-31926

    Last Modified: 28 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in BracketSpace Advanced Cron Manager – debug & control allows Stored XSS.This issue affects Advanced Cron Manager – debug & control: from n/a through 2.5.2.

    Published: 11 Apr 2024
    5.9
    Medium

    CVE-2024-31927

    Last Modified: 28 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Aminur Islam WP Login and Logout Redirect allows Stored XSS.This issue affects WP Login and Logout Redirect: from n/a through 1.2.

    Published: 11 Apr 2024
    5.9
    Medium

    CVE-2024-31928

    Last Modified: 28 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Darko Top Bar allows Stored XSS.This issue affects Top Bar: from n/a through 3.0.5.

    Published: 11 Apr 2024
    5.9
    Medium

    CVE-2024-31929

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Iain Poulson Intagrate Lite instagrate-to-wordpress.This issue affects Intagrate Lite: from n/a through <= 1.3.7.

    Published: 11 Apr 2024
    5.9
    Medium

    CVE-2024-31930

    Last Modified: 28 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Pdfcrowd Save as PDF plugin by Pdfcrowd allows Stored XSS.This issue affects Save as PDF plugin by Pdfcrowd: from n/a through 3.2.1 .

    Published: 11 Apr 2024
    5.9
    Medium

    CVE-2024-31931

    Last Modified: 28 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Save as Image plugin by Pdfcrowd allows Stored XSS.This issue affects Save as Image plugin by Pdfcrowd: from n/a through 3.2.1 .

    Published: 11 Apr 2024
    5.4
    Medium

    CVE-2024-31932

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in CreativeThemes Blocksy Companion.This issue affects Blocksy Companion: from n/a through 2.0.28.

    Published: 11 Apr 2024
    4.3
    Medium

    CVE-2024-31934

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Link Whisper Link Whisper Free.This issue affects Link Whisper Free: from n/a through 0.6.9.

    Published: 11 Apr 2024
    4.3
    Medium

    CVE-2024-31935

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in BracketSpace Simple Post Notes.This issue affects Simple Post Notes: from n/a through 1.7.6.

    Published: 11 Apr 2024
    5.4
    Medium

    CVE-2024-31936

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in AyeCode Ltd UsersWP.This issue affects UsersWP: from n/a before 1.2.6.

    Published: 11 Apr 2024
    5.9
    Medium

    CVE-2024-31937

    Last Modified: 28 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Visitor Analytics TWIPLA (Visitor Analytics IO) allows Stored XSS.This issue affects TWIPLA (Visitor Analytics IO): from n/a through 1.2.0.

    Published: 11 Apr 2024
    7.1
    High

    CVE-2024-31285

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Tooltip WordPress Tooltips allows Stored XSS.This issue affects WordPress Tooltips: from n/a through 9.5.3.

    Published: 11 Apr 2024
    4.3
    Medium

    CVE-2024-32112

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Leadinfo leadinfo. The patch was released under the same version which was reported as vulnerable. We consider the current version as vulnerable.This issue affects Leadinfo: from n/a through 1.0.

    Published: 11 Apr 2024
    6.3
    Medium

    CVE-2023-32295

    Last Modified: 17 Jun 2025

    Missing Authorization vulnerability in Alex Tselegidis Easy!Appointments.This issue affects Easy!Appointments: from n/a through 1.3.3.

    Published: 11 Apr 2024
    5.4
    Medium

    CVE-2024-0881

    Last Modified: 9 May 2025

    The Post Grid, Form Maker, Popup Maker, WooCommerce Blocks, Post Blocks, Post Carousel WordPress plugin before 2.2.76 does not have proper authorization, resulting in password protected posts to be displayed in the result of some unauthenticated AJAX actions, allowing unauthenticated users to read such posts

    Published: 11 Apr 2024
    6.4
    Medium

    CVE-2024-3344

    Last Modified: 8 Apr 2026

    The Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG file upload in all versions up to, and including, 2.6.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 11 Apr 2024
    6.4
    Medium

    CVE-2024-3343

    Last Modified: 8 Apr 2026

    The Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's block attributes in all versions up to, and including, 2.6.8 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 11 Apr 2024