CVE Feed

    Dashboard / CVE

    4.4
    Medium

    CVE-2023-52346

    Last Modified: 6 May 2025

    In modem driver, there is a possible system crash due to improper input validation. This could lead to local information disclosure with System execution privileges needed

    Published: 8 Apr 2024
    6
    Medium

    CVE-2023-52345

    Last Modified: 3 Dec 2024

    In modem driver, there is a possible system crash due to improper input validation. This could lead to local information disclosure with System execution privileges needed

    Published: 8 Apr 2024
    5.3
    Medium

    CVE-2023-52344

    Last Modified: 6 May 2025

    In modem-ps-nas-ngmm, there is a possible undefined behavior due to incorrect error handling. This could lead to remote information disclosure no additional execution privileges needed

    Published: 8 Apr 2024
    5.5
    Medium

    CVE-2023-52343

    Last Modified: 6 May 2025

    In SecurityCommand message after as security has been actived., there is a possible improper input validation. This could lead to remote information disclosure no additional execution privileges needed

    Published: 8 Apr 2024
    7.5
    High

    CVE-2023-52342

    Last Modified: 6 May 2025

    In modem-ps-nas-ngmm, there is a possible undefined behavior due to incorrect error handling. This could lead to remote information disclosure no additional execution privileges needed

    Published: 8 Apr 2024
    7.5
    High

    CVE-2023-52341

    Last Modified: 6 May 2025

    In Plaintext COUNTER CHECK message accepted before AS security activation, there is a possible missing permission check. This could lead to remote information disclosure no additional execution privileges needed

    Published: 8 Apr 2024
    6.1
    Medium

    CVE-2024-1752

    Last Modified: 28 May 2025

    The Font Farsi WordPress plugin through 1.6.6 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

    Published: 8 Apr 2024
    6.1
    Medium

    CVE-2024-1589

    Last Modified: 24 Mar 2025

    The SendPress Newsletters WordPress plugin through 1.23.11.6 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

    Published: 8 Apr 2024
    6.8
    Medium

    CVE-2024-1588

    Last Modified: 28 Mar 2025

    The SendPress Newsletters WordPress plugin through 1.23.11.6 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

    Published: 8 Apr 2024
    4.7
    Medium

    CVE-2024-1292

    Last Modified: 19 May 2025

    The WPB Show Core WordPress plugin before 2.7 does not sanitise and escape some parameters before outputting them back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

    Published: 8 Apr 2024
    8.8
    High

    CVE-2024-28744

    Last Modified: 15 Apr 2026

    The password is empty in the initial configuration of ACERA 9010-08 firmware v02.04 and earlier, and ACERA 9010-24 firmware v02.04 and earlier. An unauthenticated attacker may log in to the product with no password, and obtain and/or alter information such as network configuration and user information. The products are affected only when running in non MS mode with the initial configuration.

    Published: 8 Apr 2024
    6.9
    Medium

    CVE-2024-3437

    Last Modified: 10 Feb 2025

    A vulnerability was found in SourceCodester Prison Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /Admin/add-admin.php of the component Avatar Handler. The manipulation of the argument avatar leads to unrestricted upload. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-259631.

    Published: 8 Apr 2024
    7.5
    High

    CVE-2024-23084

    Last Modified: 9 Jul 2026

    Apfloat v1.10.1 was discovered to contain an ArrayIndexOutOfBoundsException via the component org.apfloat.internal.DoubleCRTMath::add(double[], double[]). NOTE: this is disputed by multiple third parties who believe there was not reasonable evidence to determine the existence of a vulnerability. The submission may have been based on a tool that is not sufficiently robust for vulnerability identification.

    Published: 8 Apr 2024
    9.1
    Critical

    CVE-2024-23078

    Last Modified: 9 Jul 2026

    JGraphT Core v1.5.2 was discovered to contain a NullPointerException via the component org.jgrapht.alg.util.ToleranceDoubleComparator::compare(Double, Double). NOTE: this is disputed by multiple third parties who believe there was not reasonable evidence to determine the existence of a vulnerability. The submission may have been based on a tool that is not sufficiently robust for vulnerability identification.

    Published: 8 Apr 2024
    9.8
    Critical

    CVE-2024-26811

    Last Modified: 4 Aug 2026

    In the Linux kernel, the following vulnerability has been resolved: ksmbd: validate payload size in ipc response If installing malicious ksmbd-tools, ksmbd.mountd can return invalid ipc response to ksmbd kernel server. ksmbd should validate payload size of ipc response from ksmbd.mountd to avoid memory overrun or slab-out-of-bounds. This patch validate 3 ipc response that has payload.

    Published: 8 Apr 2024
    8.1
    High

    CVE-2024-28270

    Last Modified: 15 Apr 2026

    An issue discovered in web-flash v3.0 allows attackers to reset passwords for arbitrary users via crafted POST request to /prod-api/user/resetPassword.

    Published: 8 Apr 2024
    5.9
    Medium

    CVE-2024-2511

    Last Modified: 12 May 2026

    Issue summary: Some non-default TLS server configurations can cause unbounded memory growth when processing TLSv1.3 sessions Impact summary: An attacker may exploit certain server configurations to trigger unbounded memory growth that would lead to a Denial of Service This problem can occur in TLSv1.3 if the non-default SSL_OP_NO_TICKET option is being used (but not if early_data support is also configured and the default anti-replay protection is in use). In this case, under certain conditions, the session cache can get into an incorrect state and it will fail to flush properly as it fills. The session cache will continue to grow in an unbounded manner. A malicious client could deliberately create the scenario for this failure to force a Denial of Service. It may also happen by accident in normal operation. This issue only affects TLS servers supporting TLSv1.3. It does not affect TLS clients. The FIPS modules in 3.2, 3.1 and 3.0 are not affected by this issue. OpenSSL 1.0.2 is also not affected by this issue.

    Published: 8 Apr 2024
    5.5
    Medium

    CVE-2024-3567

    Last Modified: 8 Nov 2025

    A flaw was found in QEMU. An assertion failure was present in the update_sctp_checksum() function in hw/net/net_tx_pkt.c when trying to calculate the checksum of a short-sized fragmented packet. This flaw allows a malicious guest to crash QEMU and cause a denial of service condition.

    Published: 8 Apr 2024
    7.5
    High

    CVE-2024-31816

    Last Modified: 18 Mar 2025

    In TOTOLINK EX200 V4.0.3c.7646_B20201211, an attacker can obtain sensitive information without authorization through the function getEasyWizardCfg.

    Published: 8 Apr 2024
    8.8
    High

    CVE-2024-31814

    Last Modified: 18 Mar 2025

    TOTOLINK EX200 V4.0.3c.7646_B20201211 allows attackers to bypass login through the Form_Login function.

    Published: 8 Apr 2024
    8
    High

    CVE-2024-31811

    Last Modified: 18 Mar 2025

    TOTOLINK EX200 V4.0.3c.7646_B20201211 was discovered to contain a remote code execution (RCE) vulnerability via the langType parameter in the setLanguageCfg function.

    Published: 8 Apr 2024
    9.8
    Critical

    CVE-2024-31807

    Last Modified: 18 Mar 2025

    TOTOLINK EX200 V4.0.3c.7646_B20201211 was discovered to contain a remote code execution (RCE) vulnerability via the hostTime parameter in the NTPSyncWithHost function.

    Published: 8 Apr 2024
    6.5
    Medium

    CVE-2024-31806

    Last Modified: 18 Mar 2025

    TOTOLINK EX200 V4.0.3c.7646_B20201211 was discovered to contain a Denial-of-Service (DoS) vulnerability in the RebootSystem function which can reboot the system without authorization.

    Published: 8 Apr 2024
    9.1
    Critical

    CVE-2022-43216

    Last Modified: 20 Jun 2025

    AbrhilSoft Employee's Portal before v5.6.2 was discovered to contain a SQL injection vulnerability in the login page.

    Published: 8 Apr 2024
    8.8
    High

    CVE-2024-31809

    Last Modified: 18 Mar 2025

    TOTOLINK EX200 V4.0.3c.7646_B20201211 was discovered to contain a remote code execution (RCE) vulnerability via the FileName parameter in the setUpgradeFW function.

    Published: 8 Apr 2024
    7.5
    High

    CVE-2024-31817

    Last Modified: 24 Mar 2025

    In TOTOLINK EX200 V4.0.3c.7646_B20201211, an attacker can obtain sensitive information without authorization through the function getSysStatusCfg.

    Published: 8 Apr 2024
    9.1
    Critical

    CVE-2024-22949

    Last Modified: 27 May 2025

    JFreeChart v1.5.4 was discovered to contain a NullPointerException via the component /chart/annotations/CategoryLineAnnotation. NOTE: this is disputed by multiple third parties who believe there was not reasonable evidence to determine the existence of a vulnerability. The submission may have been based on a tool that is not sufficiently robust for vulnerability identification.

    Published: 8 Apr 2024
    3.3
    Low

    CVE-2024-31047

    Last Modified: 13 Aug 2025

    An issue in Academy Software Foundation openexr v.3.2.3 and before allows a local attacker to cause a denial of service (DoS) via the convert function of exrmultipart.cpp.

    Published: 8 Apr 2024
    8.8
    High

    CVE-2024-31808

    Last Modified: 18 Mar 2025

    TOTOLINK EX200 V4.0.3c.7646_B20201211 was discovered to contain a remote code execution (RCE) vulnerability via the webWlanIdx parameter in the setWebWlanIdx function.

    Published: 8 Apr 2024
    6.5
    Medium

    CVE-2024-31812

    Last Modified: 18 Mar 2025

    In TOTOLINK EX200 V4.0.3c.7646_B20201211, an attacker can obtain sensitive information without authorization through the function getWiFiExtenderConfig.

    Published: 8 Apr 2024
    8.4
    High

    CVE-2024-31813

    Last Modified: 18 Mar 2025

    TOTOLINK EX200 V4.0.3c.7646_B20201211 does not contain an authentication mechanism by default.

    Published: 8 Apr 2024
    9.1
    Critical

    CVE-2024-31815

    Last Modified: 17 Jun 2025

    In TOTOLINK EX200 V4.0.3c.7314_B20191204, an attacker can obtain the configuration file without authorization through /cgi-bin/ExportSettings.sh

    Published: 8 Apr 2024
    7.8
    High

    CVE-2024-26574

    Last Modified: 28 Mar 2025

    Insecure Permissions vulnerability in Wondershare Filmora v.13.0.51 allows a local attacker to execute arbitrary code via a crafted script to the WSNativePushService.exe

    Published: 8 Apr 2024
    8.8
    High

    CVE-2024-28066

    Last Modified: 18 Jun 2025

    In Unify CP IP Phone firmware 1.10.4.3, Weak Credentials are used (a hardcoded root password).

    Published: 8 Apr 2024
    6.2
    Medium

    CVE-2024-23079

    Last Modified: 15 Apr 2026

    JGraphT Core v1.5.2 was discovered to contain a NullPointerException via the component org.jgrapht.alg.util.ToleranceDoubleComparator::compare(Double, Double). NOTE: this is disputed by multiple third parties who believe there was not reasonable evidence to determine the existence of a vulnerability. The submission may have been based on a tool that is not sufficiently robust for vulnerability identification.

    Published: 8 Apr 2024
    3.3
    Low

    CVE-2024-23081

    Last Modified: 21 Nov 2024

    ThreeTen Backport v1.6.8 was discovered to contain a NullPointerException via the component org.threeten.bp.LocalDate::compareTo(ChronoLocalDate). NOTE: this is disputed by multiple third parties who believe there was not reasonable evidence to determine the existence of a vulnerability. The submission may have been based on a tool that is not sufficiently robust for vulnerability identification.

    Published: 8 Apr 2024
    —
    Unknown

    CVE-2024-23082

    Last Modified: 5 Jul 2026

    ThreeTen Backport v1.6.8 was discovered to contain an integer overflow via the component org.threeten.bp.format.DateTimeFormatter::parse(CharSequence, ParsePosition). NOTE: this is disputed by multiple third parties who believe there was not reasonable evidence to determine the existence of a vulnerability. The submission may have been based on a tool that is not sufficiently robust for vulnerability identification.

    Published: 8 Apr 2024
    7.5
    High

    CVE-2024-23085

    Last Modified: 18 Jun 2025

    Apfloat v1.10.1 was discovered to contain a NullPointerException via the component org.apfloat.internal.DoubleScramble::scramble(double[], int, int[]). NOTE: this is disputed by multiple third parties who believe there was not reasonable evidence to determine the existence of a vulnerability. The submission may have been based on a tool that is not sufficiently robust for vulnerability identification.

    Published: 8 Apr 2024
    9.8
    Critical

    CVE-2024-23086

    Last Modified: 18 Jun 2025

    Apfloat v1.10.1 was discovered to contain a stack overflow via the component org.apfloat.internal.DoubleModMath::modPow(double. NOTE: this is disputed by multiple third parties who believe there was not reasonable evidence to determine the existence of a vulnerability. The submission may have been based on a tool that is not sufficiently robust for vulnerability identification.

    Published: 8 Apr 2024
    8.8
    High

    CVE-2024-24279

    Last Modified: 17 Jun 2025

    An issue in secdiskapp 1.5.1 (management program for NewQ Fingerprint Encryption Super Speed Flash Disk) allows attackers to gain escalated privileges via vsVerifyPassword and vsSetFingerPrintPower functions.

    Published: 8 Apr 2024
    9.8
    Critical

    CVE-2024-27488

    Last Modified: 15 Apr 2026

    Incorrect Access Control vulnerability in ZLMediaKit versions 1.0 through 8.0, allows remote attackers to escalate privileges and obtain sensitive information. The application system enables the http API interface by default and uses the secret parameter method to authenticate the http restful api interface, but the secret is hardcoded by default.

    Published: 8 Apr 2024
    7.5
    High

    CVE-2024-27630

    Last Modified: 2 Sept 2025

    Insecure Direct Object Reference (IDOR) in GNU Savane v.3.12 and before allows a remote attacker to delete arbitrary files via crafted input to the trackers_data_delete_file function.

    Published: 8 Apr 2024
    6
    Medium

    CVE-2024-27631

    Last Modified: 2 Sept 2025

    Cross Site Request Forgery vulnerability in GNU Savane v.3.12 and before allows a remote attacker to escalate privileges via siteadmin/usergroup.php

    Published: 8 Apr 2024
    8.8
    High

    CVE-2024-27632

    Last Modified: 2 Sept 2025

    An issue in GNU Savane v.3.12 and before allows a remote attacker to escalate privileges via the form_id in the form_header() function.

    Published: 8 Apr 2024
    6.6
    Medium

    CVE-2024-28224

    Last Modified: 13 May 2025

    Ollama before 0.1.29 has a DNS rebinding vulnerability that can inadvertently allow remote access to the full API, thereby letting an unauthorized user chat with a large language model, delete a model, or cause a denial of service (resource exhaustion).

    Published: 8 Apr 2024
    7.5
    High

    CVE-2024-28732

    Last Modified: 15 Apr 2025

    An issue was discovered in OFPMatch in parser.py in Faucet SDN Ryu version 4.34, allows remote attackers to cause a denial of service (DoS) (infinite loop).

    Published: 8 Apr 2024
    —
    Unknown

    CVE-2024-30667

    Last Modified: 27 May 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that there was not reasonable evidence to determine the existence of a vulnerability.

    Published: 8 Apr 2024
    —
    Unknown

    CVE-2024-30659

    Last Modified: 27 May 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that there was not reasonable evidence to determine the existence of a vulnerability.

    Published: 8 Apr 2024
    —
    Unknown

    CVE-2024-30661

    Last Modified: 27 May 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that there was not reasonable evidence to determine the existence of a vulnerability.

    Published: 8 Apr 2024
    —
    Unknown

    CVE-2024-30662

    Last Modified: 27 May 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that there was not reasonable evidence to determine the existence of a vulnerability.

    Published: 8 Apr 2024