CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2023-52716

    Last Modified: 13 Mar 2025

    Vulnerability of starting activities in the background in the ActivityManagerService (AMS) module. Impact: Successful exploitation of this vulnerability will affect availability.

    Published: 7 Apr 2024
    7.5
    High

    CVE-2023-52715

    Last Modified: 28 Mar 2025

    The SystemUI module has a vulnerability in permission management. Impact: Successful exploitation of this vulnerability may affect availability.

    Published: 7 Apr 2024
    5.3
    Medium

    CVE-2021-4438

    Last Modified: 21 Mar 2025

    A vulnerability, which was classified as critical, has been found in kyivstarteam react-native-sms-user-consent up to 1.1.4 on Android. Affected by this issue is the function registerReceiver of the file android/src/main/java/ua/kyivstar/reactnativesmsuserconsent/SmsUserConsentModule.kt. The manipulation leads to improper export of android application components. Attacking locally is a requirement. Upgrading to version 1.1.5 is able to address this issue. The name of the patch is 5423dcb0cd3e4d573b5520a71fa08aa279e4c3c7. It is recommended to upgrade the affected component. The identifier of this vulnerability is VDB-259508.

    Published: 7 Apr 2024
    —
    Unknown

    CVE-2023-52382

    Last Modified: 17 Apr 2024

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

    Published: 7 Apr 2024
    7.5
    High

    CVE-2023-52714

    Last Modified: 13 Mar 2025

    Vulnerability of defects introduced in the design process in the hwnff module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

    Published: 7 Apr 2024
    7.7
    High

    CVE-2023-52713

    Last Modified: 13 Mar 2025

    Vulnerability of improper permission control in the window management module. Impact: Successful exploitation of this vulnerability will affect availability and confidentiality.

    Published: 7 Apr 2024
    7.5
    High

    CVE-2024-30418

    Last Modified: 13 Mar 2025

    Vulnerability of insufficient permission verification in the app management module. Impact: Successful exploitation of this vulnerability will affect availability.

    Published: 7 Apr 2024
    7.5
    High

    CVE-2024-30417

    Last Modified: 29 Mar 2025

    Path traversal vulnerability in the Bluetooth-based sharing module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

    Published: 7 Apr 2024
    7.5
    High

    CVE-2024-30416

    Last Modified: 13 Mar 2025

    Use After Free (UAF) vulnerability in the underlying driver module. Impact: Successful exploitation of this vulnerability will affect availability.

    Published: 7 Apr 2024
    9.1
    Critical

    CVE-2024-30415

    Last Modified: 13 Mar 2025

    Vulnerability of improper permission control in the window management module. Impact: Successful exploitation of this vulnerability will affect availability.

    Published: 7 Apr 2024
    7.5
    High

    CVE-2024-30414

    Last Modified: 13 Mar 2025

    Command injection vulnerability in the AccountManager module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

    Published: 7 Apr 2024
    7.5
    High

    CVE-2024-30413

    Last Modified: 28 Mar 2025

    Vulnerability of improper permission control in the window management module. Impact: Successful exploitation of this vulnerability will affect availability.

    Published: 7 Apr 2024
    6.3
    Medium

    CVE-2024-3417

    Last Modified: 17 Jan 2025

    A vulnerability, which was classified as critical, has been found in SourceCodester Online Courseware 1.0. This issue affects some unknown processing of the file admin/saveeditt.php. The manipulation of the argument contact leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-259589 was assigned to this vulnerability.

    Published: 7 Apr 2024
    6.3
    Medium

    CVE-2024-3416

    Last Modified: 17 Jan 2025

    A vulnerability classified as critical was found in SourceCodester Online Courseware 1.0. This vulnerability affects unknown code of the file admin/editt.php. The manipulation of the argument id leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-259588.

    Published: 7 Apr 2024
    6.4
    Medium

    CVE-2023-6877

    Last Modified: 8 Apr 2026

    The RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 4.3.3 due to insufficient input sanitization and output escaping on the Content-Type field of error messages when retrieving an invalid RSS feed. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 7 Apr 2024
    7.5
    High

    CVE-2020-36829

    Last Modified: 15 Apr 2026

    The Mojolicious module before 8.65 for Perl is vulnerable to secure_compare timing attacks that allow an attacker to guess the length of a secret string. Only versions after 1.74 are affected.

    Published: 7 Apr 2024
    6.5
    Medium

    CVE-2024-31948

    Last Modified: 4 Nov 2025

    In FRRouting (FRR) through 9.1, an attacker using a malformed Prefix SID attribute in a BGP UPDATE packet can cause the bgpd daemon to crash.

    Published: 7 Apr 2024
    6.5
    Medium

    CVE-2024-31951

    Last Modified: 1 May 2025

    In the Opaque LSA Extended Link parser in FRRouting (FRR) through 9.1, there can be a buffer overflow and daemon crash in ospf_te_parse_ext_link for OSPF LSA packets during an attempt to read Segment Routing Adjacency SID subTLVs (lengths are not validated).

    Published: 7 Apr 2024
    4.3
    Medium

    CVE-2021-47208

    Last Modified: 5 May 2025

    The Mojolicious module before 9.11 for Perl has a bug in format detection that can potentially be exploited for denial of service.

    Published: 7 Apr 2024
    6.5
    Medium

    CVE-2024-31949

    Last Modified: 4 Nov 2025

    In FRRouting (FRR) through 9.1, an infinite loop can occur when receiving a MP/GR capability as a dynamic capability because malformed data results in a pointer not advancing.

    Published: 7 Apr 2024
    6.5
    Medium

    CVE-2024-31950

    Last Modified: 1 May 2025

    In FRRouting (FRR) through 9.1, there can be a buffer overflow and daemon crash in ospf_te_parse_ri for OSPF LSA packets during an attempt to read Segment Routing subTLVs (their size is not validated).

    Published: 7 Apr 2024
    3.5
    Low

    CVE-2024-3415

    Last Modified: 11 Feb 2025

    A vulnerability was found in SourceCodester Human Resource Information System 1.0. It has been classified as problematic. Affected is an unknown function of the file Superadmin_Dashboard/process/addbranches_process.php. The manipulation of the argument branches_name leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-259584.

    Published: 6 Apr 2024
    3.5
    Low

    CVE-2024-3414

    Last Modified: 26 Feb 2025

    A vulnerability was found in SourceCodester Human Resource Information System 1.0 and classified as problematic. This issue affects some unknown processing of the file Superadmin_Dashboard/process/addcorporate_process.php. The manipulation of the argument corporate_name leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-259583.

    Published: 6 Apr 2024
    7.3
    High

    CVE-2024-3413

    Last Modified: 10 Feb 2025

    A vulnerability has been found in SourceCodester Human Resource Information System 1.0 and classified as critical. This vulnerability affects unknown code of the file initialize/login_process.php. The manipulation of the argument hr_email/hr_password leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-259582 is the identifier assigned to this vulnerability.

    Published: 6 Apr 2024
    8.8
    High

    CVE-2024-3159

    Last Modified: 4 Nov 2025

    Out of bounds memory access in V8 in Google Chrome prior to 123.0.6312.105 allowed a remote attacker to perform arbitrary read/write via a crafted HTML page. (Chromium security severity: High)

    Published: 6 Apr 2024
    8.8
    High

    CVE-2024-3158

    Last Modified: 4 Nov 2025

    Use after free in Bookmarks in Google Chrome prior to 123.0.6312.105 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

    Published: 6 Apr 2024
    8.8
    High

    CVE-2024-3156

    Last Modified: 4 Nov 2025

    Inappropriate implementation in V8 in Google Chrome prior to 123.0.6312.105 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High)

    Published: 6 Apr 2024
    4.3
    Medium

    CVE-2024-3378

    Last Modified: 21 Nov 2024

    A vulnerability has been found in iboss Secure Web Gateway up to 10.1 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /login of the component Login Portal. The manipulation of the argument redirectUrl leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 10.2.0.160 is able to address this issue. It is recommended to upgrade the affected component. The identifier VDB-259501 was assigned to this vulnerability.

    Published: 6 Apr 2024
    4.3
    Medium

    CVE-2024-3377

    Last Modified: 17 Jan 2025

    A vulnerability classified as problematic was found in SourceCodester Computer Laboratory Management System 1.0. This vulnerability affects unknown code of the file /classes/SystemSettings.php?f=update_settings. The manipulation of the argument name leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-259498 is the identifier assigned to this vulnerability.

    Published: 6 Apr 2024
    7.5
    High

    CVE-2024-24746

    Last Modified: 17 Jun 2025

    Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in Apache NimBLE.  Specially crafted GATT operation can cause infinite loop in GATT server leading to denial of service in Bluetooth stack or device. This issue affects Apache NimBLE: through 1.6.0. Users are recommended to upgrade to version 1.7.0, which fixes the issue.

    Published: 6 Apr 2024
    9
    Critical

    CVE-2024-25029

    Last Modified: 7 May 2025

    IBM Personal Communications 14.0.6 through 15.0.1 includes a Windows service that is vulnerable to remote code execution (RCE) and local privilege escalation (LPE). The vulnerability allows any unprivileged user with network access to a target computer to run commands with full privileges in the context of NT AUTHORITY\SYSTEM. This allows for a low privileged attacker to move laterally to affected systems and to escalate their privileges. IBM X-Force ID: 281619.

    Published: 6 Apr 2024
    7.5
    High

    CVE-2024-22328

    Last Modified: 14 Jan 2025

    IBM Maximo Application Suite 8.10 and 8.11 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system. IBM X-Force ID: 279950.

    Published: 6 Apr 2024
    7.3
    High

    CVE-2024-3376

    Last Modified: 26 Feb 2025

    A vulnerability classified as critical has been found in SourceCodester Computer Laboratory Management System 1.0. This affects an unknown part of the file config.php. The manipulation of the argument url leads to execution after redirect. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-259497 was assigned to this vulnerability.

    Published: 6 Apr 2024
    6.3
    Medium

    CVE-2024-3369

    Last Modified: 25 Apr 2025

    A vulnerability, which was classified as critical, has been found in code-projects Car Rental 1.0. Affected by this issue is some unknown functionality of the file add-vehicle.php. The manipulation of the argument Upload Image leads to unrestricted upload. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-259490 is the identifier assigned to this vulnerability.

    Published: 6 Apr 2024
    3.5
    Low

    CVE-2024-3366

    Last Modified: 18 Jul 2025

    A vulnerability classified as problematic was found in Xuxueli xxl-job up to 2.4.1. This vulnerability affects the function deserialize of the file com/xxl/job/core/util/JdkSerializeTool.java of the component Template Handler. The manipulation leads to injection. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-259480.

    Published: 6 Apr 2024
    3.5
    Low

    CVE-2024-3365

    Last Modified: 10 Feb 2025

    A vulnerability was found in SourceCodester Online Library System 1.0. It has been rated as problematic. This issue affects some unknown processing of the file admin/users/controller.php. The manipulation of the argument user_name leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-259469 was assigned to this vulnerability.

    Published: 6 Apr 2024
    3.5
    Low

    CVE-2024-3364

    Last Modified: 10 Feb 2025

    A vulnerability was found in SourceCodester Online Library System 1.0. It has been declared as problematic. This vulnerability affects unknown code of the file admin/books/index.php. The manipulation of the argument id leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-259468.

    Published: 6 Apr 2024
    5.5
    Medium

    CVE-2024-2296

    Last Modified: 8 Apr 2026

    The Photo Gallery by 10Web – Mobile-Friendly Image Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG file uploads in all versions up to, and including, 1.8.21 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled. CVE-2024-29833 appears to be a duplicate of this issue.

    Published: 6 Apr 2024
    6.4
    Medium

    CVE-2024-2132

    Last Modified: 8 Apr 2026

    The Ultimate Bootstrap Elements for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Image Widget in all versions up to, and including, 1.4.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 6 Apr 2024
    7.3
    High

    CVE-2024-3363

    Last Modified: 18 Feb 2025

    A vulnerability was found in SourceCodester Online Library System 1.0. It has been classified as critical. This affects an unknown part of the file admin/borrowed/index.php. The manipulation of the argument BookPublisher/BookTitle leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-259467.

    Published: 6 Apr 2024
    6.4
    Medium

    CVE-2024-2458

    Last Modified: 8 Apr 2026

    The Powerkit – Supercharge your WordPress Site plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in all versions up to, and including, 2.9.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 6 Apr 2024
    6.4
    Medium

    CVE-2024-0837

    Last Modified: 8 Apr 2026

    The Element Pack Elementor Addons (Header Footer, Free Template Library, Grid, Carousel, Table, Parallax Animation, Register Form, Twitter Grid) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the image URL parameter in all versions up to, and including, 5.3.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 6 Apr 2024
    6.4
    Medium

    CVE-2024-1428

    Last Modified: 8 Apr 2026

    The Element Pack Elementor Addons (Header Footer, Free Template Library, Grid, Carousel, Table, Parallax Animation, Register Form, Twitter Grid) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘element_pack_wrapper_link’ attribute of the Trailer Box widget in all versions up to, and including, 5.5.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 6 Apr 2024
    6.4
    Medium

    CVE-2024-2949

    Last Modified: 8 Apr 2026

    The Carousel, Slider, Gallery by WP Carousel – Image Carousel & Photo Gallery, Post Carousel & Post Grid, Product Carousel & Product Grid for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the carousel widget in all versions up to, and including, 2.6.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 6 Apr 2024
    7.3
    High

    CVE-2024-3362

    Last Modified: 10 Feb 2025

    A vulnerability was found in SourceCodester Online Library System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file admin/books/controller.php. The manipulation of the argument IBSN leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-259466 is the identifier assigned to this vulnerability.

    Published: 6 Apr 2024
    6.4
    Medium

    CVE-2024-2471

    Last Modified: 8 Apr 2026

    The FooGallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via image attachment fields (such as 'Title', 'Alt Text', 'Custom URL', 'Custom Class', and 'Override Type') in all versions up to, and including, 2.4.14 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 6 Apr 2024
    7.3
    High

    CVE-2024-3361

    Last Modified: 10 Feb 2025

    A vulnerability has been found in SourceCodester Online Library System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file admin/books/deweydecimal.php. The manipulation of the argument category leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-259465 was assigned to this vulnerability.

    Published: 6 Apr 2024
    4.8
    Medium

    CVE-2024-2444

    Last Modified: 8 May 2025

    The Inline Related Posts WordPress plugin before 3.5.0 does not sanitise and escape some of its settings, which could allow high privilege users such as Admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed

    Published: 6 Apr 2024
    7.3
    High

    CVE-2024-3360

    Last Modified: 10 Feb 2025

    A vulnerability, which was classified as critical, was found in SourceCodester Online Library System 1.0. Affected is an unknown function of the file admin/books/index.php. The manipulation of the argument id leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-259464.

    Published: 6 Apr 2024
    7.3
    High

    CVE-2024-3359

    Last Modified: 10 Feb 2025

    A vulnerability, which was classified as critical, has been found in SourceCodester Online Library System 1.0. This issue affects some unknown processing of the file admin/login.php. The manipulation of the argument user_email leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-259463.

    Published: 6 Apr 2024