CVE Feed

    Dashboard / CVE

    4.7
    Medium

    CVE-2024-3440

    Last Modified: 10 Feb 2025

    A vulnerability was found in SourceCodester Prison Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /Admin/edit_profile.php. The manipulation leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-259693 was assigned to this vulnerability.

    Published: 8 Apr 2024
    3.5
    Low

    CVE-2014-125111

    Last Modified: 15 Apr 2026

    A vulnerability was found in namithjawahar Wp-Insert up to 2.0.8 and classified as problematic. Affected by this issue is some unknown functionality. The manipulation leads to cross site scripting. The attack may be launched remotely. Upgrading to version 2.0.9 is able to address this issue. The name of the patch is a07b7b08084b9b85859f3968ce7fde0fd1fcbba3. It is recommended to upgrade the affected component. The identifier of this vulnerability is VDB-259628.

    Published: 8 Apr 2024
    3.5
    Low

    CVE-2011-10006

    Last Modified: 11 Apr 2025

    A vulnerability was found in GamerZ WP-PostRatings up to 1.64. It has been classified as problematic. This affects an unknown part of the file wp-postratings.php. The manipulation leads to cross site scripting. It is possible to initiate the attack remotely. Upgrading to version 1.65 is able to address this issue. The identifier of the patch is 6182a5682b12369ced0becd3b505439ce2eb8132. It is recommended to upgrade the affected component. The identifier VDB-259629 was assigned to this vulnerability.

    Published: 8 Apr 2024
    8.7
    High

    CVE-2024-2834

    Last Modified: 15 Apr 2026

    A Stored Cross-Site Scripting (XSS) vulnerability has been identified in OpenText ArcSight Management Center and ArcSight Platform. The vulnerability could be remotely exploited.

    Published: 8 Apr 2024
    7.3
    High

    CVE-2024-3439

    Last Modified: 10 Feb 2025

    A vulnerability was found in SourceCodester Prison Management System 1.0. It has been classified as critical. Affected is an unknown function of the file /Account/login.php. The manipulation leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-259692.

    Published: 8 Apr 2024
    7.3
    High

    CVE-2024-3438

    Last Modified: 10 Feb 2025

    A vulnerability was found in SourceCodester Prison Management System 1.0 and classified as critical. This issue affects some unknown processing of the file /Admin/login.php. The manipulation leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-259691.

    Published: 8 Apr 2024
    —
    Unknown

    CVE-2024-3449

    Last Modified: 11 Feb 2025

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

    Published: 8 Apr 2024
    7.5
    High

    CVE-2024-27897

    Last Modified: 13 Mar 2025

    Input verification vulnerability in the call module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

    Published: 8 Apr 2024
    7.5
    High

    CVE-2024-27896

    Last Modified: 13 Mar 2025

    Input verification vulnerability in the log module. Impact: Successful exploitation of this vulnerability can affect integrity.

    Published: 8 Apr 2024
    7.5
    High

    CVE-2024-27895

    Last Modified: 28 Mar 2025

    Vulnerability of permission control in the window module. Successful exploitation of this vulnerability may affect confidentiality.

    Published: 8 Apr 2024
    6.3
    Medium

    CVE-2023-52364

    Last Modified: 13 Mar 2025

    Vulnerability of input parameters being not strictly verified in the RSMC module. Impact: Successful exploitation of this vulnerability may cause out-of-bounds write.

    Published: 8 Apr 2024
    7.5
    High

    CVE-2023-52386

    Last Modified: 27 Mar 2025

    Out-of-bounds write vulnerability in the RSMC module. Impact: Successful exploitation of this vulnerability will affect availability.

    Published: 8 Apr 2024
    6.2
    Medium

    CVE-2023-52385

    Last Modified: 13 Mar 2025

    Out-of-bounds write vulnerability in the RSMC module. Impact: Successful exploitation of this vulnerability will affect availability.

    Published: 8 Apr 2024
    6.5
    Medium

    CVE-2023-52554

    Last Modified: 13 Mar 2025

    Permission control vulnerability in the Bluetooth module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

    Published: 8 Apr 2024
    7.4
    High

    CVE-2023-52553

    Last Modified: 13 Mar 2025

    Race condition vulnerability in the Wi-Fi module. Impact: Successful exploitation of this vulnerability will affect availability.

    Published: 8 Apr 2024
    5.4
    Medium

    CVE-2024-31375

    Last Modified: 28 Apr 2026

    Missing Authorization vulnerability in Saleswonder Team: Tobias WP2LEADS wp2leads.This issue affects WP2LEADS: from n/a through <= 3.2.7.

    Published: 8 Apr 2024
    7.5
    High

    CVE-2023-52552

    Last Modified: 13 Mar 2025

    Input verification vulnerability in the power module. Impact: Successful exploitation of this vulnerability will affect availability.

    Published: 8 Apr 2024
    5.3
    Medium

    CVE-2023-52551

    Last Modified: 13 Mar 2025

    Vulnerability of data verification errors in the kernel module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

    Published: 8 Apr 2024
    7.5
    High

    CVE-2023-52550

    Last Modified: 13 Mar 2025

    Vulnerability of data verification errors in the kernel module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

    Published: 8 Apr 2024
    7.5
    High

    CVE-2023-52549

    Last Modified: 13 Mar 2025

    Vulnerability of data verification errors in the kernel module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

    Published: 8 Apr 2024
    7.5
    High

    CVE-2023-52546

    Last Modified: 28 Mar 2025

    Vulnerability of package name verification being bypassed in the Calendar app. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

    Published: 8 Apr 2024
    7.5
    High

    CVE-2023-52545

    Last Modified: 13 Mar 2025

    Vulnerability of undefined permissions in the Calendar app. Impact: Successful exploitation of this vulnerability will affect availability.

    Published: 8 Apr 2024
    4.3
    Medium

    CVE-2023-52544

    Last Modified: 13 Mar 2025

    Vulnerability of file path verification being bypassed in the email module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

    Published: 8 Apr 2024
    6.5
    Medium

    CVE-2024-31357

    Last Modified: 28 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in BdThemes Ultimate Store Kit Elementor Addons allows Stored XSS.This issue affects Ultimate Store Kit Elementor Addons: from n/a through 1.5.2.

    Published: 8 Apr 2024
    7.5
    High

    CVE-2023-52359

    Last Modified: 27 Mar 2025

    Vulnerability of permission verification in some APIs in the ActivityTaskManagerService module. Impact: Successful exploitation of this vulnerability will affect availability.

    Published: 8 Apr 2024
    6.2
    Medium

    CVE-2023-52543

    Last Modified: 13 Mar 2025

    Permission verification vulnerability in the system module. Impact: Successful exploitation of this vulnerability will affect availability.

    Published: 8 Apr 2024
    6.5
    Medium

    CVE-2023-52542

    Last Modified: 13 Mar 2025

    Permission verification vulnerability in the system module. Impact: Successful exploitation of this vulnerability will affect availability.

    Published: 8 Apr 2024
    7.5
    High

    CVE-2023-52541

    Last Modified: 13 Mar 2025

    Authentication vulnerability in the API for app pre-loading. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

    Published: 8 Apr 2024
    7.5
    High

    CVE-2023-52540

    Last Modified: 28 Mar 2025

    Vulnerability of improper authentication in the Iaware module. Impact: Successful exploitation of this vulnerability will affect availability.

    Published: 8 Apr 2024
    7.5
    High

    CVE-2023-52539

    Last Modified: 13 Mar 2025

    Permission verification vulnerability in the Settings module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

    Published: 8 Apr 2024
    9.1
    Critical

    CVE-2023-52538

    Last Modified: 25 Mar 2025

    Vulnerability of package name verification being bypassed in the HwIms module. Impact: Successful exploitation of this vulnerability will affect availability.

    Published: 8 Apr 2024
    7.5
    High

    CVE-2023-52537

    Last Modified: 13 Mar 2025

    Vulnerability of package name verification being bypassed in the HwIms module. Impact: Successful exploitation of this vulnerability will affect availability.

    Published: 8 Apr 2024
    7.5
    High

    CVE-2023-52388

    Last Modified: 13 Mar 2025

    Permission control vulnerability in the clock module. Impact: Successful exploitation of this vulnerability will affect availability.

    Published: 8 Apr 2024
    6.1
    Medium

    CVE-2024-23192

    Last Modified: 15 Apr 2026

    RSS feeds that contain malicious data- attributes could be abused to inject script code to a users browser session when reading compromised RSS feeds or successfully luring users to compromised accounts. Attackers could perform malicious API requests or extract information from the users account. Please deploy the provided updates and patch releases. Potentially malicious attributes now get removed from external RSS content. No publicly available exploits are known.

    Published: 8 Apr 2024
    5.4
    Medium

    CVE-2024-23191

    Last Modified: 15 Apr 2026

    Upsell advertisement information of an account can be manipulated to execute script code in the context of the users browser session. To exploit this an attacker would require temporary access to a users account or an successful social engineering attack to lure users to maliciously configured accounts. Attackers could perform malicious API requests or extract information from the users account. Please deploy the provided updates and patch releases. Sanitization of user-defined upsell content has been improved. No publicly available exploits are known.

    Published: 8 Apr 2024
    5.4
    Medium

    CVE-2024-23190

    Last Modified: 15 Apr 2026

    Upsell shop information of an account can be manipulated to execute script code in the context of the users browser session. To exploit this an attacker would require temporary access to a users account or an successful social engineering attack to lure users to maliciously configured accounts. Attackers could perform malicious API requests or extract information from the users account. Please deploy the provided updates and patch releases. Sanitization of user-defined upsell content has been improved. No publicly available exploits are known.

    Published: 8 Apr 2024
    5.4
    Medium

    CVE-2024-23189

    Last Modified: 15 Apr 2026

    Embedded content references at tasks could be used to temporarily execute script code in the context of the users browser session. To exploit this an attacker would require temporary access to the users account, access to another account within the same context or an successful social engineering attack to make users import external content. Attackers could perform malicious API requests or extract information from the users account. Please deploy the provided updates and patch releases. Sanitization of user-generated content has been improved. No publicly available exploits are known.

    Published: 8 Apr 2024
    4.8
    Medium

    CVE-2024-1958

    Last Modified: 19 May 2025

    The WPB Show Core WordPress plugin before 2.7 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin or unauthenticated users

    Published: 8 Apr 2024
    6.1
    Medium

    CVE-2024-1956

    Last Modified: 19 May 2025

    The wpb-show-core WordPress plugin before 2.7 does not sanitise and escape the parameters before outputting it back in the response of an unauthenticated request, leading to a Reflected Cross-Site Scripting

    Published: 8 Apr 2024
    4.4
    Medium

    CVE-2023-52536

    Last Modified: 26 Mar 2025

    In faceid service, there is a possible out of bounds read due to a missing bounds check. This could lead to local denial of service with System execution privileges needed

    Published: 8 Apr 2024
    4.4
    Medium

    CVE-2023-52535

    Last Modified: 6 May 2025

    In vsp driver, there is a possible missing verification incorrect input. This could lead to local denial of service with no additional execution privileges needed

    Published: 8 Apr 2024
    5.9
    Medium

    CVE-2023-52534

    Last Modified: 6 May 2025

    In ngmm, there is a possible undefined behavior due to incorrect error handling. This could lead to remote denial of service with no additional execution privileges needed

    Published: 8 Apr 2024
    5.3
    Medium

    CVE-2023-52533

    Last Modified: 6 May 2025

    In modem-ps-nas-ngmm, there is a possible undefined behavior due to incorrect error handling. This could lead to remote information disclosure no additional execution privileges needed

    Published: 8 Apr 2024
    4.4
    Medium

    CVE-2024-23658

    Last Modified: 6 May 2025

    In camera driver, there is a possible use after free due to a logic error. This could lead to local denial of service with System execution privileges needed

    Published: 8 Apr 2024
    5.5
    Medium

    CVE-2023-52352

    Last Modified: 28 Mar 2025

    In Network Adapter Service, there is a possible missing permission check. This could lead to local denial of service with no additional execution privileges needed

    Published: 8 Apr 2024
    7.8
    High

    CVE-2023-52351

    Last Modified: 6 May 2025

    In ril service, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service with System execution privileges needed

    Published: 8 Apr 2024
    4.4
    Medium

    CVE-2023-52350

    Last Modified: 27 Mar 2025

    In ril service, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service with System execution privileges needed

    Published: 8 Apr 2024
    4.4
    Medium

    CVE-2023-52349

    Last Modified: 28 Mar 2025

    In ril service, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service with System execution privileges needed

    Published: 8 Apr 2024
    4.4
    Medium

    CVE-2023-52348

    Last Modified: 6 May 2025

    In ril service, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service with System execution privileges needed

    Published: 8 Apr 2024
    5.5
    Medium

    CVE-2023-52347

    Last Modified: 6 May 2025

    In ril service, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service with System execution privileges needed

    Published: 8 Apr 2024