CVE Feed

    Dashboard / CVE

    3.5
    Low

    CVE-2024-3358

    Last Modified: 26 Feb 2025

    A vulnerability classified as problematic was found in SourceCodester Aplaya Beach Resort Online Reservation System 1.0. This vulnerability affects unknown code of the file /index.php. The manipulation of the argument to leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-259462 is the identifier assigned to this vulnerability.

    Published: 6 Apr 2024
    5.3
    Medium

    CVE-2024-2950

    Last Modified: 8 Apr 2026

    The BoldGrid Easy SEO – Simple and Effective SEO plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.6.14 via meta information (og:description) This makes it possible for unauthenticated attackers to view the first 130 characters of a password protected post which can contain sensitive information.

    Published: 6 Apr 2024
    5.3
    Medium

    CVE-2024-3216

    Last Modified: 8 Apr 2026

    The WooCommerce PDF Invoices, Packing Slips, Delivery Notes and Shipping Labels plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the wt_pklist_reset_settings() function in all versions up to, and including, 4.4.2. This makes it possible for unauthenticated attackers to reset all of the plugin's settings.

    Published: 6 Apr 2024
    7.1
    High

    CVE-2024-1385

    Last Modified: 8 Apr 2026

    The WP-Stateless – Google Cloud Storage plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the dismiss_notices() function in all versions up to, and including, 3.4.0. This makes it possible for authenticated attackers, with subscriber-level access and above, to update arbitrary option values to the current time, which may completely take a site offline.

    Published: 6 Apr 2024
    4.4
    Medium

    CVE-2024-2656

    Last Modified: 15 Apr 2026

    The Email Subscribers by Icegram Express – Email Marketing, Newsletters, Automation for WordPress & WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via a CSV import in all versions up to, and including, 5.7.14 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.

    Published: 6 Apr 2024
    6.4
    Medium

    CVE-2024-3245

    Last Modified: 8 Apr 2026

    The EmbedPress – Embed PDF, Google Docs, Vimeo, Wistia, Embed YouTube Videos, Audios, Maps & Embed Any Documents in Gutenberg & Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Youtube block in all versions up to, and including, 3.9.14 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 6 Apr 2024
    4.3
    Medium

    CVE-2024-1994

    Last Modified: 15 Apr 2026

    The Image Watermark plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the watermark_action_ajax() function in all versions up to, and including, 1.7.3. This makes it possible for authenticated attackers, with subscriber-level access and above, to apply and remove watermarks from images.

    Published: 6 Apr 2024
    5.2
    Medium

    CVE-2024-21506

    Last Modified: 5 Jun 2024

    Duplicate of CVE-2024-5629.

    Published: 6 Apr 2024
    7.5
    High

    CVE-2024-27620

    Last Modified: 15 Apr 2026

    An issue in Ladder v.0.0.1 thru v.0.0.21 allows a remote attacker to obtain sensitive information via a crafted request to the API.

    Published: 6 Apr 2024
    8.8
    High

    CVE-2024-28741

    Last Modified: 15 Apr 2026

    Cross Site Scripting vulnerability in EginDemirbilek NorthStar C2 v1 allows a remote attacker to execute arbitrary code via the login.php component.

    Published: 6 Apr 2024
    3.5
    Low

    CVE-2024-3357

    Last Modified: 11 Feb 2025

    A vulnerability classified as problematic has been found in SourceCodester Aplaya Beach Resort Online Reservation System 1.0. This affects an unknown part of the file admin/mod_reports/index.php. The manipulation of the argument end leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-259461 was assigned to this vulnerability.

    Published: 5 Apr 2024
    7.3
    High

    CVE-2024-3356

    Last Modified: 11 Feb 2025

    A vulnerability was found in SourceCodester Aplaya Beach Resort Online Reservation System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file admin/mod_settings/controller.php?action=add. The manipulation of the argument type leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-259460.

    Published: 5 Apr 2024
    7.5
    High

    CVE-2024-27912

    Last Modified: 15 Apr 2026

    A denial of service vulnerability was reported in some Lenovo Printers that could allow an attacker to cause the device to crash by sending crafted LPD packets.

    Published: 5 Apr 2024
    7.5
    High

    CVE-2024-27911

    Last Modified: 15 Apr 2026

    A vulnerability was reported in some Lenovo Printers that could allow an unauthenticated attacker to obtain the administrator password.

    Published: 5 Apr 2024
    5.3
    Medium

    CVE-2024-27910

    Last Modified: 15 Apr 2026

    A vulnerability was reported in some Lenovo Printers that could allow an unauthenticated attacker to reboot the printer without authentication.

    Published: 5 Apr 2024
    4.9
    Medium

    CVE-2024-27909

    Last Modified: 15 Apr 2026

    A denial of service vulnerability was reported in the HTTPS service of some Lenovo Printers that could result in a system reboot.

    Published: 5 Apr 2024
    4.9
    Medium

    CVE-2024-27908

    Last Modified: 15 Apr 2026

    A buffer overflow vulnerability was reported in the HTTPS service of some Lenovo Printers that could result in denial of service.

    Published: 5 Apr 2024
    6.3
    Medium

    CVE-2024-23592

    Last Modified: 15 Apr 2026

    An authentication bypass vulnerability was reported in Lenovo devices with Synaptics fingerprint readers that could allow an attacker with physical access to replay fingerprints and bypass Windows Hello authentication.

    Published: 5 Apr 2024
    6.7
    Medium

    CVE-2023-25494

    Last Modified: 15 Apr 2026

    A potential vulnerability were reported in the BIOS of some Desktop, Smart Edge, and ThinkStation products that could allow a local attacker with elevated privileges to write to NVRAM variables.

    Published: 5 Apr 2024
    6.7
    Medium

    CVE-2023-25493

    Last Modified: 15 Apr 2026

    A potential vulnerability was reported in the BIOS update tool driver for some Desktop, Smart Edge, Smart Office, and ThinkStation products that could allow a local user with elevated privileges to execute arbitrary code.

    Published: 5 Apr 2024
    6.7
    Medium

    CVE-2023-5912

    Last Modified: 15 Apr 2026

    A potential memory leakage vulnerability was reported in some Lenovo Notebook products that may allow a local attacker with elevated privileges to write to NVRAM variables.

    Published: 5 Apr 2024
    6.5
    Medium

    CVE-2023-4605

    Last Modified: 15 Apr 2026

    A valid authenticated Lenovo XClarity Administrator (LXCA) user can potentially leverage an unauthenticated API endpoint to retrieve system event information.

    Published: 5 Apr 2024
    7.3
    High

    CVE-2024-3355

    Last Modified: 11 Feb 2025

    A vulnerability was found in SourceCodester Aplaya Beach Resort Online Reservation System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file admin/mod_users/controller.php?action=add. The manipulation of the argument name leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-259459.

    Published: 5 Apr 2024
    6.7
    Medium

    CVE-2024-29783

    Last Modified: 17 Jun 2025

    In tmu_get_tr_thresholds, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 5 Apr 2024
    5.5
    Medium

    CVE-2024-29782

    Last Modified: 17 Jun 2025

    In tmu_get_tr_num_thresholds of tmu.c, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 5 Apr 2024
    7.3
    High

    CVE-2024-29757

    Last Modified: 17 Jun 2025

    there is a possible permission bypass due to Debug certs being allowlisted. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 5 Apr 2024
    9.8
    Critical

    CVE-2024-29756

    Last Modified: 17 Jun 2025

    In afe_callback of q6afe.c, there is a possible out of bounds write due to a buffer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 5 Apr 2024
    4.4
    Medium

    CVE-2024-29755

    Last Modified: 17 Jun 2025

    In tmu_get_pi of tmu.c, there is a possible out of bounds read due to improper input validation. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 5 Apr 2024
    6.2
    Medium

    CVE-2024-29754

    Last Modified: 17 Jun 2025

    In TMU_IPC_GET_TABLE, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 5 Apr 2024
    7.7
    High

    CVE-2024-29753

    Last Modified: 17 Jun 2025

    In tmu_set_control_temp_step of tmu.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 5 Apr 2024
    7.8
    High

    CVE-2024-29752

    Last Modified: 17 Jun 2025

    In tmu_set_tr_num_thresholds of tmu.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 5 Apr 2024
    5.5
    Medium

    CVE-2024-29751

    Last Modified: 17 Jun 2025

    In asn1_ec_pkey_parse_p384 of asn1_common.c, there is a possible OOB Read due to a missing null check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 5 Apr 2024
    5.5
    Medium

    CVE-2024-29750

    Last Modified: 17 Jun 2025

    In km_exp_did_inner of kmv.c, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 5 Apr 2024
    8.4
    High

    CVE-2024-29749

    Last Modified: 17 Jun 2025

    In tmu_set_tr_thresholds of tmu.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 5 Apr 2024
    7.8
    High

    CVE-2024-29748

    Last Modified: 24 Oct 2025

    there is a possible way to bypass due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.

    Published: 5 Apr 2024
    5.9
    Medium

    CVE-2024-29747

    Last Modified: 17 Jun 2025

    In _dvfs_get_lv of dvfs.c, there is a possible out of bounds read due to a missing null check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 5 Apr 2024
    8.4
    High

    CVE-2024-29746

    Last Modified: 17 Jun 2025

    In lpm_req_handler of lpm.c, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 5 Apr 2024
    5.5
    Medium

    CVE-2024-29745

    Last Modified: 24 Oct 2025

    there is a possible Information Disclosure due to uninitialized data. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 5 Apr 2024
    5.5
    Medium

    CVE-2024-29744

    Last Modified: 17 Jun 2025

    In tmu_get_gov_time_windows, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 5 Apr 2024
    7.7
    High

    CVE-2024-29743

    Last Modified: 17 Jun 2025

    In tmu_set_temp_lut of tmu.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 5 Apr 2024
    5.5
    Medium

    CVE-2024-29742

    Last Modified: 17 Jun 2025

    In apply_minlock_constraint of dvfs.c, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 5 Apr 2024
    7.8
    High

    CVE-2024-29741

    Last Modified: 28 Feb 2026

    In pblS2mpuResume of s2mpu.c, there is a possible mitigation bypass due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 5 Apr 2024
    7.4
    High

    CVE-2024-29740

    Last Modified: 17 Jun 2025

    In tmu_set_table of tmu.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 5 Apr 2024
    5.5
    Medium

    CVE-2024-29739

    Last Modified: 17 Jun 2025

    In tmu_get_temp_lut of tmu.c, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 5 Apr 2024
    5.5
    Medium

    CVE-2024-29738

    Last Modified: 17 Jun 2025

    In gov_init, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 5 Apr 2024
    5.5
    Medium

    CVE-2024-27232

    Last Modified: 17 Jun 2025

    In asn1_ec_pkey_parse of asn1_common.c, there is a possible OOB read due to a missing null check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 5 Apr 2024
    5.9
    Medium

    CVE-2024-27231

    Last Modified: 17 Jun 2025

    In tmu_get_tr_stats of tmu.c, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 5 Apr 2024
    7.3
    High

    CVE-2024-3354

    Last Modified: 11 Feb 2025

    A vulnerability was found in SourceCodester Aplaya Beach Resort Online Reservation System 1.0. It has been classified as critical. Affected is an unknown function of the file admin/mod_users/index.php. The manipulation of the argument id leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-259458 is the identifier assigned to this vulnerability.

    Published: 5 Apr 2024
    7.3
    High

    CVE-2024-3353

    Last Modified: 14 May 2025

    A vulnerability was found in SourceCodester Aplaya Beach Resort Online Reservation System 1.0 and classified as critical. This issue affects some unknown processing of the file admin/mod_reports/index.php. The manipulation of the argument categ/end leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-259457 was assigned to this vulnerability.

    Published: 5 Apr 2024
    7.3
    High

    CVE-2024-3352

    Last Modified: 11 Feb 2025

    A vulnerability has been found in SourceCodester Aplaya Beach Resort Online Reservation System 1.0 and classified as critical. This vulnerability affects unknown code of the file admin/mod_comments/index.php. The manipulation of the argument id leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-259456.

    Published: 5 Apr 2024