CVE Feed

    Dashboard / CVE

    5.4
    Medium

    CVE-2024-0881

    Last Modified: 9 May 2025

    The Post Grid, Form Maker, Popup Maker, WooCommerce Blocks, Post Blocks, Post Carousel WordPress plugin before 2.2.76 does not have proper authorization, resulting in password protected posts to be displayed in the result of some unauthenticated AJAX actions, allowing unauthenticated users to read such posts

    Published: 11 Apr 2024
    6.4
    Medium

    CVE-2024-3344

    Last Modified: 8 Apr 2026

    The Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG file upload in all versions up to, and including, 2.6.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 11 Apr 2024
    6.4
    Medium

    CVE-2024-3343

    Last Modified: 8 Apr 2026

    The Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's block attributes in all versions up to, and including, 2.6.8 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 11 Apr 2024
    7.8
    High

    CVE-2024-20797

    Last Modified: 4 Dec 2024

    Animate versions 23.0.4, 24.0.1 and earlier are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this vulnerability to execute code in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 11 Apr 2024
    5.5
    Medium

    CVE-2024-20794

    Last Modified: 5 Dec 2024

    Animate versions 23.0.4, 24.0.1 and earlier are affected by a NULL Pointer Dereference vulnerability that could lead to an application denial-of-service. An attacker could leverage this vulnerability to cause a system crash, resulting in a denial of service. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 11 Apr 2024
    5.5
    Medium

    CVE-2024-20796

    Last Modified: 4 Dec 2024

    Animate versions 23.0.4, 24.0.1 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 11 Apr 2024
    7.8
    High

    CVE-2024-20795

    Last Modified: 4 Dec 2024

    Animate versions 23.0.4, 24.0.1 and earlier are affected by an Integer Overflow or Wraparound vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 11 Apr 2024
    4.6
    Medium

    CVE-2023-32228

    Last Modified: 15 Apr 2026

    A firmware bug which may lead to misinterpretation of data in the AMC2-4WCF and AMC2-2WCF allowing an adversary to grant access to the last authorized user.

    Published: 11 Apr 2024
    5.9
    Medium

    CVE-2024-32080

    Last Modified: 28 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Nick Pelton Search Keyword Redirect allows Stored XSS.This issue affects Search Keyword Redirect: from n/a through 1.0.

    Published: 11 Apr 2024
    —
    Unknown

    CVE-2024-31861

    Last Modified: 21 Jun 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

    Published: 11 Apr 2024
    5.5
    Medium

    CVE-2024-20798

    Last Modified: 5 Dec 2024

    Illustrator versions 28.3, 27.9.2 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 11 Apr 2024
    5.5
    Medium

    CVE-2024-20771

    Last Modified: 5 Dec 2024

    Bridge versions 13.0.6, 14.0.2 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 11 Apr 2024
    5.3
    Medium

    CVE-2024-2966

    Last Modified: 8 Apr 2026

    The Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 5.5.6 via the element_pack_ajax_search function. This makes it possible for unauthenticated attackers to extract sensitive data including password protected post details.

    Published: 11 Apr 2024
    6.4
    Medium

    CVE-2024-3285

    Last Modified: 8 Apr 2026

    The Slider, Gallery, and Carousel by MetaSlider – Responsive WordPress Slideshows plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'metaslider' shortcode in all versions up to, and including, 3.70.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 11 Apr 2024
    4.3
    Medium

    CVE-2023-6257

    Last Modified: 9 May 2025

    The Inline Related Posts WordPress plugin before 3.6.0 is missing authorization in an AJAX action to ensure that users are allowed to see the content of the posts displayed, allowing any authenticated user, such as subscriber to retrieve the content of password protected posts

    Published: 11 Apr 2024
    4.7
    Medium

    CVE-2024-3621

    Last Modified: 30 Jan 2025

    A vulnerability was found in SourceCodester Kortex Lite Advocate Office Management System 1.0. It has been classified as critical. This affects an unknown part of the file /control/register_case.php. The manipulation of the argument title/case_no/client_name/court/case_type/case_stage/legel_acts/description/filling_date/hearing_date/opposite_lawyer/total_fees/unpaid leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-260277 was assigned to this vulnerability.

    Published: 11 Apr 2024
    4.7
    Medium

    CVE-2024-3620

    Last Modified: 28 Jan 2025

    A vulnerability was found in SourceCodester Kortex Lite Advocate Office Management System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /control/adds.php. The manipulation of the argument name/gender/dob/email/mobile/address leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-260276.

    Published: 11 Apr 2024
    4.7
    Medium

    CVE-2024-3619

    Last Modified: 28 Jan 2025

    A vulnerability has been found in SourceCodester Kortex Lite Advocate Office Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /control/addcase_stage.php. The manipulation of the argument cname leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-260275.

    Published: 11 Apr 2024
    4.7
    Medium

    CVE-2024-3618

    Last Modified: 28 Jan 2025

    A vulnerability, which was classified as critical, was found in SourceCodester Kortex Lite Advocate Office Management System 1.0. Affected is an unknown function of the file /control/activate_case.php. The manipulation of the argument id leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-260274 is the identifier assigned to this vulnerability.

    Published: 11 Apr 2024
    8.8
    High

    CVE-2024-25572

    Last Modified: 8 Apr 2025

    Cross-site request forgery (CSRF) vulnerability exists in Ninja Forms prior to 3.4.31. If a website administrator views a malicious page while logging in, unintended operations may be performed.

    Published: 11 Apr 2024
    5.4
    Medium

    CVE-2024-26019

    Last Modified: 8 Apr 2025

    Ninja Forms prior to 3.8.1 contains a cross-site scripting vulnerability in submit processing. If this vulnerability is exploited, an arbitrary script may be executed on the web browser of the user who is accessing to the website using the product.

    Published: 11 Apr 2024
    6.1
    Medium

    CVE-2024-29220

    Last Modified: 8 Apr 2025

    Ninja Forms prior to 3.8.1 contains a cross-site scripting vulnerability in custom fields for labels. If this vulnerability is exploited, an arbitrary script may be executed on the web browser of the user who is accessing to the website using the product.

    Published: 11 Apr 2024
    4.7
    Medium

    CVE-2024-3617

    Last Modified: 28 Jan 2025

    A vulnerability, which was classified as critical, has been found in SourceCodester Kortex Lite Advocate Office Management System 1.0. This issue affects some unknown processing of the file /control/deactivate_case.php. The manipulation of the argument id leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-260273 was assigned to this vulnerability.

    Published: 11 Apr 2024
    7.2
    High

    CVE-2023-6811

    Last Modified: 15 Apr 2026

    The Language Translate Widget for WordPress – ConveyThis plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'api_key’ parameter in all versions up to, and including, 223 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 11 Apr 2024
    6.5
    Medium

    CVE-2024-3652

    Last Modified: 27 Feb 2026

    The Libreswan Project was notified of an issue causing libreswan to restart when using IKEv1 without specifying an esp= line. When the peer requests AES-GMAC, libreswan's default proposal handler causes an assertion failure and crashes and restarts. IKEv2 connections are not affected.

    Published: 11 Apr 2024
    3.5
    Low

    CVE-2024-3616

    Last Modified: 10 Feb 2025

    A vulnerability classified as problematic was found in SourceCodester Warehouse Management System 1.0. This vulnerability affects unknown code of the file pengguna.php. The manipulation of the argument admin_user/admin_nama/admin_alamat/admin_telepon leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-260272.

    Published: 11 Apr 2024
    3.5
    Low

    CVE-2024-3614

    Last Modified: 18 Feb 2025

    A vulnerability classified as problematic has been found in SourceCodester Warehouse Management System 1.0. This affects an unknown part of the file customer.php. The manipulation of the argument nama_customer/alamat_customer/notelp_customer leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-260271.

    Published: 11 Apr 2024
    3.5
    Low

    CVE-2024-3613

    Last Modified: 18 Feb 2025

    A vulnerability was found in SourceCodester Warehouse Management System 1.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the file supplier.php. The manipulation of the argument nama_supplier/alamat_supplier/notelp_supplier leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-260270 is the identifier assigned to this vulnerability.

    Published: 11 Apr 2024
    8.2
    High

    CVE-2025-3528

    Last Modified: 15 Apr 2026

    A flaw was found in the Mirror Registry. The quay-app container shipped as part of the Mirror Registry for OpenShift has write access to the `/etc/passwd`. This flaw allows a malicious actor with access to the container to modify the passwd file and elevate their privileges to the root user within that pod.

    Published: 11 Apr 2024
    9.8
    Critical

    CVE-2024-21508

    Last Modified: 15 Apr 2026

    Versions of the package mysql2 before 3.9.4 are vulnerable to Remote Code Execution (RCE) via the readCodeFor function due to improper validation of the supportBigNumbers and bigNumberStrings values.

    Published: 11 Apr 2024
    4.7
    Medium

    CVE-2024-30883

    Last Modified: 11 Apr 2025

    Reflected Cross Site Scripting (XSS) vulnerability in RageFrame2 v2.6.43, allows remote attackers to execute arbitrary web scripts or HTML and obtain sensitive information via a crafted payload injected into the aspectRatio parameter in the image cropping function.

    Published: 11 Apr 2024
    4.3
    Medium

    CVE-2024-30915

    Last Modified: 17 Jun 2025

    An issue was discovered in OpenDDS commit b1c534032bb62ad4ae32609778de6b8d6c823a66, allows a local attacker to cause a denial of service and obtain sensitive information via the max_samples parameter within the DataReaderQoS component.

    Published: 11 Apr 2024
    6.5
    Medium

    CVE-2023-48865

    Last Modified: 17 Jun 2025

    An issue discovered in Reportico Till 8.1.0 allows attackers to obtain sensitive information via execute_mode parameter of the URL.

    Published: 11 Apr 2024
    8.1
    High

    CVE-2024-22719

    Last Modified: 8 Apr 2025

    SQL Injection vulnerability in Form Tools 3.1.1 allows attackers to run arbitrary SQL commands via the 'keyword' when searching for a client.

    Published: 11 Apr 2024
    6.1
    Medium

    CVE-2024-22717

    Last Modified: 8 Apr 2025

    Cross Site Scripting (XSS) vulnerability in Form Tools 3.1.1 allows attackers to run arbitrary code via the First Name field in the application.

    Published: 11 Apr 2024
    9.6
    Critical

    CVE-2024-22718

    Last Modified: 8 Apr 2025

    Cross Site Scripting (XSS) vulnerability in Form Tools 3.1.1 allows attackers to run arbitrary code via the client_id parameter in the application URL.

    Published: 11 Apr 2024
    7.2
    High

    CVE-2024-22722

    Last Modified: 8 Apr 2025

    Server Side Template Injection (SSTI) vulnerability in Form Tools 3.1.1 allows attackers to run arbitrary commands via the Group Name field under the add forms section of the application.

    Published: 11 Apr 2024
    6.3
    Medium

    CVE-2024-22721

    Last Modified: 8 Apr 2025

    Cross Site Request Forgery (CSRF) vulnerability in Form Tools 3.1.1 allows attackers to manipulate sensitive user data via crafted link.

    Published: 11 Apr 2024
    7.8
    High

    CVE-2024-25376

    Last Modified: 17 Jun 2025

    An issue discovered in Thesycon Software Solutions Gmbh & Co. KG TUSBAudio MSI-based installers before 5.68.0 allows a local attacker to execute arbitrary code via the msiexec.exe repair mode.

    Published: 11 Apr 2024
    8.8
    High

    CVE-2024-25852

    Last Modified: 17 Jun 2025

    Linksys RE7000 v2.0.9, v2.0.11, and v2.0.15 have a command execution vulnerability in the "AccessControlList" parameter of the access control function point. An attacker can use the vulnerability to obtain device administrator rights.

    Published: 11 Apr 2024
    4.3
    Medium

    CVE-2024-27592

    Last Modified: 17 Jun 2025

    Open Redirect vulnerability in Corezoid Process Engine v6.5.0 allows attackers to redirect to arbitrary websites via appending a crafted link to /login/ in the login page URL.

    Published: 11 Apr 2024
    7.5
    High

    CVE-2024-28458

    Last Modified: 10 Jun 2025

    Null Pointer Dereference vulnerability in swfdump in swftools 0.9.2 allows attackers to crash the appliation via the function compileSWFActionCode in action/actioncompiler.c.

    Published: 11 Apr 2024
    7.6
    High

    CVE-2024-29399

    Last Modified: 17 Jun 2025

    An issue was discovered in GNU Savane v.3.13 and before, allows a remote attacker to execute arbitrary code and escalate privileges via a crafted file to the upload.php component.

    Published: 11 Apr 2024
    —
    Unknown

    CVE-2024-29448

    Last Modified: 27 May 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that there was not reasonable evidence to determine the existence of a vulnerability.

    Published: 11 Apr 2024
    —
    Unknown

    CVE-2024-29449

    Last Modified: 27 May 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that there was not reasonable evidence to determine the existence of a vulnerability.

    Published: 11 Apr 2024
    —
    Unknown

    CVE-2024-29450

    Last Modified: 27 May 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that there was not reasonable evidence to determine the existence of a vulnerability.

    Published: 11 Apr 2024
    —
    Unknown

    CVE-2024-29452

    Last Modified: 27 May 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that there was not reasonable evidence to determine the existence of a vulnerability.

    Published: 11 Apr 2024
    —
    Unknown

    CVE-2024-29454

    Last Modified: 27 May 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that there was not reasonable evidence to determine the existence of a vulnerability.

    Published: 11 Apr 2024
    —
    Unknown

    CVE-2024-29455

    Last Modified: 27 May 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that there was not reasonable evidence to determine the existence of a vulnerability.

    Published: 11 Apr 2024
    6.1
    Medium

    CVE-2024-30878

    Last Modified: 11 Apr 2025

    A cross-site scripting (XSS) vulnerability in RageFrame2 v2.6.43, allows remote attackers to execute arbitrary web scripts or HTML and obtain sensitive information via a crafted payload injected into the upload_drive parameter.

    Published: 11 Apr 2024