CVE Feed

    Dashboard / CVE

    4.3
    Medium

    CVE-2024-2033

    Last Modified: 15 Apr 2026

    The Video Conferencing with Zoom plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.4.5 via the get_assign_host_id AJAX action. This makes it possible for authenticated attackers, with subscriber access or higher, to enumerate usernames, emails and IDs of all users on a site.

    Published: 9 Apr 2024
    5.3
    Medium

    CVE-2024-2302

    Last Modified: 8 Apr 2026

    The Easy Digital Downloads – Sell Digital Files & Subscriptions (eCommerce Store + Payments Made Easy) plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.2.9. This makes it possible for unauthenticated attackers to download the debug log via Directory Listing. This file may include PII.

    Published: 9 Apr 2024
    6.4
    Medium

    CVE-2024-2185

    Last Modified: 8 Apr 2026

    The Beaver Builder Addons by WPZOOM plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Image Box widget in all versions up to, and including, 1.3.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 9 Apr 2024
    7.2
    High

    CVE-2024-1852

    Last Modified: 8 Apr 2026

    The WP-Members Membership Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the X-Forwarded-For header in all versions up to, and including, 3.4.9.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page which is the edit users page. This vulnerability was partially patched in version 3.4.9.2, and was fully patched in 3.4.9.3.

    Published: 9 Apr 2024
    6.4
    Medium

    CVE-2024-2187

    Last Modified: 8 Apr 2026

    The Beaver Builder Addons by WPZOOM plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Testimonials widget in all versions up to, and including, 1.3.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 9 Apr 2024
    3.6
    Low

    CVE-2024-2918

    Last Modified: 28 Mar 2025

    Improper input validation in PAM JIT elevation feature in Devolutions Server 2024.1.6 and earlier allows an attacker with access to the PAM JIT elevation feature to forge the displayed group in the PAM JIT elevation checkout request via a specially crafted request.

    Published: 9 Apr 2024
    7.7
    High

    CVE-2024-31457

    Last Modified: 15 Apr 2026

    gin-vue-admin is a backstage management system based on vue and gin, which separates the front and rear of the full stack. gin-vue-admin pseudoversion 0.0.0-20240407133540-7bc7c3051067, corresponding to version 2.6.1, has a code injection vulnerability in the backend. In the Plugin System -> Plugin Template feature, an attacker can perform directory traversal by manipulating the `plugName` parameter. They can create specific folders such as `api`, `config`, `global`, `model`, `router`, `service`, and `main.go` function within the specified traversal directory. Moreover, the Go files within these folders can have arbitrary code inserted based on a specific PoC parameter. The main reason for the existence of this vulnerability is the controllability of the PlugName field within the struct. Pseudoversion 0.0.0-20240409100909-b1b7427c6ea6, corresponding to commit b1b7427c6ea6c7a027fa188c6be557f3795e732b, contains a patch for the issue. As a workaround, one may manually use a filtering method available in the GitHub Security Advisory to rectify the directory traversal problem.

    Published: 9 Apr 2024
    5.5
    Medium

    CVE-2024-25116

    Last Modified: 15 Apr 2026

    RedisBloom adds a set of probabilistic data structures to Redis. Starting in version 2.0.0 and prior to version 2.4.7 and 2.6.10, authenticated users can use the `CF.RESERVE` command to trigger a runtime assertion and termination of the Redis server process. The problem is fixed in RedisBloom 2.4.7 and 2.6.10.

    Published: 9 Apr 2024
    7
    High

    CVE-2024-25115

    Last Modified: 15 Apr 2026

    RedisBloom adds a set of probabilistic data structures to Redis. Starting in version 2.0.0 and prior to version 2.4.7 and 2.6.10, specially crafted `CF.LOADCHUNK` commands may be used by authenticated users to perform heap overflow, which may lead to remote code execution. The problem is fixed in RedisBloom 2.4.7 and 2.6.10.

    Published: 9 Apr 2024
    8.3
    High

    CVE-2024-22423

    Last Modified: 5 Jan 2026

    yt-dlp is a youtube-dl fork with additional features and fixes. The patch that addressed CVE-2023-40581 attempted to prevent RCE when using `--exec` with `%q` by replacing double quotes with two double quotes. However, this escaping is not sufficient, and still allows expansion of environment variables. Support for output template expansion in `--exec`, along with this vulnerable behavior, was added to `yt-dlp` in version 2021.04.11. yt-dlp version 2024.04.09 fixes this issue by properly escaping `%`. It replaces them with `%%cd:~,%`, a variable that expands to nothing, leaving only the leading percent. It is recommended to upgrade yt-dlp to version 2024.04.09 as soon as possible. Also, always be careful when using `--exec`, because while this specific vulnerability has been patched, using unvalidated input in shell commands is inherently dangerous. For Windows users who are not able to upgrade, avoid using any output template expansion in `--exec` other than `{}` (filepath); if expansion in `--exec` is needed, verify the fields you are using do not contain `"`, `|` or `&`; and/or instead of using `--exec`, write the info json and load the fields from it instead.

    Published: 9 Apr 2024
    6.5
    Medium

    CVE-2024-31454

    Last Modified: 15 Apr 2026

    PsiTransfer is an open source, self-hosted file sharing solution. Prior to version 2.2.0, the absence of restrictions on the endpoint, which is designed for uploading files, allows an attacker who received the id of a file distribution to change the files that are in this distribution. The vulnerability allows an attacker to influence those users who come to the file distribution after them and slip the victim files with a malicious or phishing signature. Version 2.2.0 contains a patch for this issue. CVE-2024-31454 allows users to violate the integrity of a file that is uploaded by another user. In this case, additional files are not loaded into the file bucket. Violation of integrity at the level of individual files. While the vulnerability with the number CVE-2024-31453 allows users to violate the integrity of a file bucket without violating the integrity of files uploaded by other users. Thus, vulnerabilities are reproduced differently, require different security recommendations and affect different objects of the application’s business logic.

    Published: 9 Apr 2024
    4.1
    Medium

    CVE-2024-27242

    Last Modified: 31 Jul 2025

    Cross site scripting in Zoom Desktop Client for Linux before version 5.17.10 may allow an authenticated user to conduct a denial of service via network access.

    Published: 9 Apr 2024
    5.5
    Medium

    CVE-2024-27247

    Last Modified: 31 Jul 2025

    Improper privilege management in the installer for Zoom Desktop Client for macOS before version 5.17.10 may allow a privileged user to conduct an escalation of privilege via local access.

    Published: 9 Apr 2024
    5.9
    Medium

    CVE-2024-24694

    Last Modified: 31 Jul 2025

    Improper privilege management in the installer for Zoom Desktop Client for Windows before version 5.17.10 may allow an authenticated user to conduct an escalation of privilege via local access.

    Published: 9 Apr 2024
    6.5
    Medium

    CVE-2024-31453

    Last Modified: 15 Apr 2026

    PsiTransfer is an open source, self-hosted file sharing solution. Prior to version 2.2.0, the absence of restrictions on the endpoint, which allows users to create a path for uploading a file in a file distribution, allows an attacker to add arbitrary files to the distribution. The vulnerability allows an attacker to influence those users who come to the file distribution after them and slip the victim files with a malicious or phishing signature. Version 2.2.0 contains a patch for the issue. CVE-2024-31453 allows users to violate the integrity of a file bucket and upload new files there, while the vulnerability with the number CVE-2024-31454 allows users to violate the integrity of a single file that is uploaded by another user by writing data there and not allows you to upload new files to the bucket. Thus, vulnerabilities are reproduced differently, require different security recommendations and affect different objects of the application’s business logic.

    Published: 9 Apr 2024
    8.8
    High

    CVE-2024-29993

    Last Modified: 3 May 2025

    Azure CycleCloud Elevation of Privilege Vulnerability

    Published: 9 Apr 2024
    5.5
    Medium

    CVE-2024-29992

    Last Modified: 24 Sept 2026

    Azure Identity Library for .NET Information Disclosure Vulnerability

    Published: 9 Apr 2024
    8.4
    High

    CVE-2024-29989

    Last Modified: 3 May 2025

    Azure Monitor Agent Elevation of Privilege Vulnerability

    Published: 9 Apr 2024
    8.8
    High

    CVE-2024-29985

    Last Modified: 3 May 2025

    Microsoft OLE DB Driver for SQL Server Remote Code Execution Vulnerability

    Published: 9 Apr 2024
    8.8
    High

    CVE-2024-29984

    Last Modified: 3 May 2025

    Microsoft OLE DB Driver for SQL Server Remote Code Execution Vulnerability

    Published: 9 Apr 2024
    8.8
    High

    CVE-2024-29983

    Last Modified: 3 May 2025

    Microsoft OLE DB Driver for SQL Server Remote Code Execution Vulnerability

    Published: 9 Apr 2024
    8.8
    High

    CVE-2024-29982

    Last Modified: 3 May 2025

    Microsoft OLE DB Driver for SQL Server Remote Code Execution Vulnerability

    Published: 9 Apr 2024
    8.1
    High

    CVE-2024-20670

    Last Modified: 3 May 2025

    Outlook for Windows Spoofing Vulnerability

    Published: 9 Apr 2024
    7.1
    High

    CVE-2024-29062

    Last Modified: 3 May 2025

    Secure Boot Security Feature Bypass Vulnerability

    Published: 9 Apr 2024
    7.8
    High

    CVE-2024-29061

    Last Modified: 3 May 2025

    Secure Boot Security Feature Bypass Vulnerability

    Published: 9 Apr 2024
    4.3
    Medium

    CVE-2024-29056

    Last Modified: 3 May 2025

    Windows Authentication Elevation of Privilege Vulnerability

    Published: 9 Apr 2024
    7.2
    High

    CVE-2024-29054

    Last Modified: 3 May 2025

    Microsoft Defender for IoT Elevation of Privilege Vulnerability

    Published: 9 Apr 2024
    7.2
    High

    CVE-2024-29055

    Last Modified: 3 May 2025

    Microsoft Defender for IoT Elevation of Privilege Vulnerability

    Published: 9 Apr 2024
    8.8
    High

    CVE-2024-29053

    Last Modified: 3 May 2025

    Microsoft Defender for IoT Remote Code Execution Vulnerability

    Published: 9 Apr 2024
    7.8
    High

    CVE-2024-29052

    Last Modified: 27 Aug 2025

    Windows Storage Elevation of Privilege Vulnerability

    Published: 9 Apr 2024
    8.8
    High

    CVE-2024-29048

    Last Modified: 3 May 2025

    Microsoft OLE DB Driver for SQL Server Remote Code Execution Vulnerability

    Published: 9 Apr 2024
    8.8
    High

    CVE-2024-29046

    Last Modified: 3 May 2025

    Microsoft OLE DB Driver for SQL Server Remote Code Execution Vulnerability

    Published: 9 Apr 2024
    8.8
    High

    CVE-2024-29044

    Last Modified: 3 May 2025

    Microsoft OLE DB Driver for SQL Server Remote Code Execution Vulnerability

    Published: 9 Apr 2024
    8.8
    High

    CVE-2024-28944

    Last Modified: 3 May 2025

    Microsoft OLE DB Driver for SQL Server Remote Code Execution Vulnerability

    Published: 9 Apr 2024
    8.8
    High

    CVE-2024-28943

    Last Modified: 3 May 2025

    Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability

    Published: 9 Apr 2024
    8.8
    High

    CVE-2024-28941

    Last Modified: 3 May 2025

    Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability

    Published: 9 Apr 2024
    8.8
    High

    CVE-2024-28940

    Last Modified: 3 May 2025

    Microsoft OLE DB Driver for SQL Server Remote Code Execution Vulnerability

    Published: 9 Apr 2024
    8.8
    High

    CVE-2024-28938

    Last Modified: 3 May 2025

    Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability

    Published: 9 Apr 2024
    8.8
    High

    CVE-2024-28937

    Last Modified: 3 May 2025

    Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability

    Published: 9 Apr 2024
    8.8
    High

    CVE-2024-28935

    Last Modified: 3 May 2025

    Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability

    Published: 9 Apr 2024
    8.8
    High

    CVE-2024-28934

    Last Modified: 3 May 2025

    Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability

    Published: 9 Apr 2024
    8.8
    High

    CVE-2024-28933

    Last Modified: 3 May 2025

    Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability

    Published: 9 Apr 2024
    8.8
    High

    CVE-2024-28930

    Last Modified: 3 May 2025

    Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability

    Published: 9 Apr 2024
    8.8
    High

    CVE-2024-28927

    Last Modified: 3 May 2025

    Microsoft OLE DB Driver for SQL Server Remote Code Execution Vulnerability

    Published: 9 Apr 2024
    8.8
    High

    CVE-2024-28926

    Last Modified: 3 May 2025

    Microsoft OLE DB Driver for SQL Server Remote Code Execution Vulnerability

    Published: 9 Apr 2024
    6.2
    Medium

    CVE-2024-28917

    Last Modified: 3 May 2025

    Azure Arc-enabled Kubernetes Extension Cluster-Scope Elevation of Privilege Vulnerability

    Published: 9 Apr 2024
    7.8
    High

    CVE-2024-28907

    Last Modified: 3 May 2025

    Microsoft Brokering File System Elevation of Privilege Vulnerability

    Published: 9 Apr 2024
    7.8
    High

    CVE-2024-28904

    Last Modified: 3 May 2025

    Microsoft Brokering File System Elevation of Privilege Vulnerability

    Published: 9 Apr 2024
    5.5
    Medium

    CVE-2024-28900

    Last Modified: 3 May 2025

    Windows Remote Access Connection Manager Information Disclosure Vulnerability

    Published: 9 Apr 2024
    6.8
    Medium

    CVE-2024-28897

    Last Modified: 3 May 2025

    Secure Boot Security Feature Bypass Vulnerability

    Published: 9 Apr 2024