CVE Feed

    Dashboard / CVE

    8.6
    High

    CVE-2024-0081

    Last Modified: 10 Oct 2025

    NVIDIA NeMo framework for Ubuntu contains a vulnerability in tools/asr_webapp where an attacker may cause an allocation of resources without limits or throttling. A successful exploit of this vulnerability may lead to a server-side denial of service.

    Published: 5 Apr 2024
    10
    Critical

    CVE-2024-22004

    Last Modified: 24 Jul 2025

    Due to length check, an attacker with privilege access on a Linux Nonsecure operating system can trigger a vulnerability and leak the secure memory from the Trusted Application

    Published: 5 Apr 2024
    7.3
    High

    CVE-2024-3351

    Last Modified: 11 Feb 2025

    A vulnerability, which was classified as critical, was found in SourceCodester Aplaya Beach Resort Online Reservation System 1.0. This affects an unknown part of the file admin/mod_roomtype/index.php. The manipulation of the argument id leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-259455.

    Published: 5 Apr 2024
    2.8
    Low

    CVE-2024-0080

    Last Modified: 15 Apr 2026

    NVIDIA nvTIFF Library for Windows and Linux contains a vulnerability where improper input validation might enable an attacker to use a specially crafted input file. A successful exploit of this vulnerability might lead to a partial denial of service.

    Published: 5 Apr 2024
    3.3
    Low

    CVE-2024-0076

    Last Modified: 18 Sept 2025

    NVIDIA CUDA toolkit for all platforms contains a vulnerability in cuobjdump and nvdisasm where an attacker may cause a crash by tricking a user into reading a malformed ELF file. A successful exploit of this vulnerability may lead to a partial denial of service.

    Published: 5 Apr 2024
    3.3
    Low

    CVE-2024-0072

    Last Modified: 18 Sept 2025

    NVIDIA CUDA toolkit for all platforms contains a vulnerability in cuobjdump and nvdisasm where an attacker may cause a crash by tricking a user into reading a malformed ELF file. A successful exploit of this vulnerability may lead to a partial denial of service.

    Published: 5 Apr 2024
    2.8
    Low

    CVE-2023-31028

    Last Modified: 15 Apr 2026

    NVIDIA nvJPEG2000 Library for Windows and Linux contains a vulnerability where improper input validation might enable an attacker to use a specially crafted input file. A successful exploit of this vulnerability might lead to a partial denial of service.

    Published: 5 Apr 2024
    8.6
    High

    CVE-2024-31851

    Last Modified: 15 Apr 2026

    A path traversal vulnerability exists in the Java version of CData Sync < 23.4.8843 when running using the embedded Jetty server, which could allow an unauthenticated remote attacker to gain access to sensitive information and perform limited actions.

    Published: 5 Apr 2024
    8.6
    High

    CVE-2024-31850

    Last Modified: 15 Apr 2026

    A path traversal vulnerability exists in the Java version of CData Arc < 23.4.8839 when running using the embedded Jetty server, which could allow an unauthenticated remote attacker to gain access to sensitive information and perform limited actions.

    Published: 5 Apr 2024
    9.8
    Critical

    CVE-2024-31849

    Last Modified: 15 Apr 2026

    A path traversal vulnerability exists in the Java version of CData Connect < 23.4.8846 when running using the embedded Jetty server, which could allow an unauthenticated remote attacker to gain complete administrative access to the application.

    Published: 5 Apr 2024
    9.8
    Critical

    CVE-2024-31848

    Last Modified: 15 Apr 2026

    A path traversal vulnerability exists in the Java version of CData API Server < 23.4.8844 when running using the embedded Jetty server, which could allow an unauthenticated remote attacker to gain complete administrative access to the application.

    Published: 5 Apr 2024
    7.3
    High

    CVE-2024-3350

    Last Modified: 11 Feb 2025

    A vulnerability, which was classified as critical, has been found in SourceCodester Aplaya Beach Resort Online Reservation System 1.0. Affected by this issue is some unknown functionality of the file admin/mod_room/index.php. The manipulation of the argument id leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-259454 is the identifier assigned to this vulnerability.

    Published: 5 Apr 2024
    7.3
    High

    CVE-2024-3349

    Last Modified: 11 Feb 2025

    A vulnerability classified as critical was found in SourceCodester Aplaya Beach Resort Online Reservation System 1.0. Affected by this vulnerability is an unknown functionality of the file admin/login.php. The manipulation of the argument email leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-259453 was assigned to this vulnerability.

    Published: 5 Apr 2024
    7.3
    High

    CVE-2024-3348

    Last Modified: 11 Feb 2025

    A vulnerability classified as critical has been found in SourceCodester Aplaya Beach Resort Online Reservation System 1.0. Affected is an unknown function of the file booking/index.php. The manipulation of the argument log_email/log_pword leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-259452.

    Published: 5 Apr 2024
    7.3
    High

    CVE-2024-3347

    Last Modified: 27 Feb 2025

    A vulnerability was found in SourceCodester Airline Ticket Reservation System 1.0. It has been rated as critical. This issue affects some unknown processing of the file activate_jet_details_form_handler.php. The manipulation of the argument jet_id leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-259451.

    Published: 5 Apr 2024
    —
    Unknown

    CVE-2024-3381

    Last Modified: 27 May 2024

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

    Published: 5 Apr 2024
    —
    Unknown

    CVE-2024-3380

    Last Modified: 7 Jun 2024

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

    Published: 5 Apr 2024
    6.3
    Medium

    CVE-2024-3346

    Last Modified: 15 Apr 2026

    A vulnerability was found in Byzoro Smart S80 up to 20240328. It has been declared as critical. This vulnerability affects unknown code of the file /log/webmailattach.php. The manipulation of the argument mail_file_path leads to os command injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-259450 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 5 Apr 2024
    10
    Critical

    CVE-2023-48426

    Last Modified: 24 Jul 2025

    u-boot bug that allows for u-boot shell and interrupt over UART

    Published: 5 Apr 2024
    7.3
    High

    CVE-2024-31220

    Last Modified: 11 Sept 2025

    Sunshine is a self-hosted game stream host for Moonlight. Starting in version 0.16.0 and prior to version 0.18.0, an attacker may be able to remotely read arbitrary files without authentication due to a path traversal vulnerability. Users who exposed the Sunshine configuration web user interface outside of localhost may be affected, depending on firewall configuration. To exploit vulnerability, attacker could make an http/s request to the `node_modules` endpoint if user exposed Sunshine config web server to internet or attacker is on the LAN. Version 0.18.0 contains a patch for this issue. As a workaround, one may block access to Sunshine via firewall.

    Published: 5 Apr 2024
    9.8
    Critical

    CVE-2024-31218

    Last Modified: 15 Apr 2026

    Webhood is a self-hosted URL scanner used analyzing phishing and malicious sites. Webhood's backend container images in versions 0.9.0 and earlier are subject to Missing Authentication for Critical Function vulnerability. This vulnerability allows an unauthenticated attacker to send a HTTP request to the database (Pocketbase) admin API to create an admin account. The Pocketbase admin API does not check for authentication/authorization when creating an admin account when no admin accounts have been added. In its default deployment, Webhood does not create a database admin account. Therefore, unless users have manually created an admin account in the database, an admin account will not exist in the deployment and the deployment is vulnerable. Versions starting from 0.9.1 are patched. The patch creates a randomly generated admin account if admin accounts have not already been created i.e. the vulnerability is exploitable in the deployment. As a workaround, users can disable access to URL path starting with `/api/admins` entirely. With this workaround, the vulnerability is not exploitable via network.

    Published: 5 Apr 2024
    3.5
    Low

    CVE-2024-31213

    Last Modified: 17 Jan 2025

    InstantCMS is a free and open source content management system. An open redirect was found in the ICMS2 application version 2.16.2 when being redirected after modifying one's own user profile. An attacker could trick a victim into visiting their web application, thinking they are still present on the ICMS2 application. They could then host a website stating "To update your profile, please enter your password," upon which the user may type their password and send it to the attacker. As of time of publication, a patched version is not available.

    Published: 5 Apr 2024
    4.6
    Medium

    CVE-2024-2380

    Last Modified: 4 Dec 2024

    Stored XSS in graph rendering in Checkmk <2.3.0b4.

    Published: 5 Apr 2024
    6.4
    Medium

    CVE-2024-2499

    Last Modified: 15 Apr 2026

    The Squelch Tabs and Accordions Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'accordions' shortcode in all versions up to, and including, 0.4.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 5 Apr 2024
    5.3
    Medium

    CVE-2023-5692

    Last Modified: 15 Apr 2026

    WordPress Core is vulnerable to Sensitive Information Exposure in versions up to, and including, 6.4.3 via the redirect_guess_404_permalink function. This can allow unauthenticated attackers to expose the slug of a custom post whose 'publicly_queryable' post status has been set to 'false'.

    Published: 5 Apr 2024
    8.8
    High

    CVE-2023-6523

    Last Modified: 20 May 2026

    Authorization Bypass Through User-Controlled Key vulnerability in ExtremePacs Extreme XDS allows Authentication Abuse. This issue affects Extreme XDS: before 3914.

    Published: 5 Apr 2024
    7.2
    High

    CVE-2023-6522

    Last Modified: 20 May 2026

    Incorrect Use of Privileged APIs vulnerability in ExtremePacs Extreme XDS allows Collect Data as Provided by Users. This issue affects Extreme XDS: before 3914.

    Published: 5 Apr 2024
    6.5
    Medium

    CVE-2024-2447

    Last Modified: 13 Dec 2024

    Mattermost versions 8.1.x before 8.1.11, 9.3.x before 9.3.3, 9.4.x before 9.4.4, and 9.5.x before 9.5.2 fail to authenticate the source of certain types of post actions, allowing an authenticated attacker to create posts as other users via a crafted post action.

    Published: 5 Apr 2024
    4.7
    Medium

    CVE-2024-29221

    Last Modified: 13 Dec 2024

    Improper Access Control in Mattermost Server versions 9.5.x before 9.5.2, 9.4.x before 9.4.4, 9.3.x before 9.3.3, 8.1.x before 8.1.11 lacked proper access control in the `/api/v4/users/me/teams` endpoint allowing a team admin to get the invite ID of their team, thus allowing them to invite users, even if the "Add Members" permission was explicitly removed from team admins.

    Published: 5 Apr 2024
    4.3
    Medium

    CVE-2024-28949

    Last Modified: 12 Dec 2024

    Mattermost Server versions 9.5.x before 9.5.2, 9.4.x before 9.4.4, 9.3.x before 9.3.3, 8.1.x before 8.1.11 don't limit the number of user preferences which allows an attacker to send a large number of user preferences potentially causing denial of service.

    Published: 5 Apr 2024
    3.1
    Low

    CVE-2024-21848

    Last Modified: 27 Feb 2025

    Improper Access Control in Mattermost Server versions 8.1.x before 8.1.11 allows an attacker that is in a channel with an active call to keep participating in the call even if they are removed from the channel

    Published: 5 Apr 2024
    8.8
    High

    CVE-2024-2115

    Last Modified: 8 Apr 2026

    The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.0.0. This is due to missing or incorrect nonce validation on the filter_users functions. This makes it possible for unauthenticated attackers to elevate their privileges to that of a teacher via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

    Published: 5 Apr 2024
    8.8
    High

    CVE-2024-3217

    Last Modified: 8 Apr 2026

    The WP Directory Kit plugin for WordPress is vulnerable to SQL Injection via the 'attribute_value' and 'attribute_id' parameters in all versions up to, and including, 1.3.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with subscriber-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

    Published: 5 Apr 2024
    —
    Unknown

    CVE-2024-31625

    Last Modified: 5 Jun 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that there was not reasonable evidence to determine the existence of a vulnerability.

    Published: 5 Apr 2024
    —
    Unknown

    CVE-2024-31626

    Last Modified: 5 Jun 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that there was not reasonable evidence to determine the existence of a vulnerability.

    Published: 5 Apr 2024
    —
    Unknown

    CVE-2024-31627

    Last Modified: 5 Jun 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that there was not reasonable evidence to determine the existence of a vulnerability.

    Published: 5 Apr 2024
    —
    Unknown

    CVE-2024-31628

    Last Modified: 5 Jun 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that there was not reasonable evidence to determine the existence of a vulnerability.

    Published: 5 Apr 2024
    —
    Unknown

    CVE-2024-31629

    Last Modified: 5 Jun 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that there was not reasonable evidence to determine the existence of a vulnerability.

    Published: 5 Apr 2024
    —
    Unknown

    CVE-2024-31630

    Last Modified: 5 Jun 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that there was not reasonable evidence to determine the existence of a vulnerability.

    Published: 5 Apr 2024
    —
    Unknown

    CVE-2024-31631

    Last Modified: 5 Jun 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that there was not reasonable evidence to determine the existence of a vulnerability.

    Published: 5 Apr 2024
    —
    Unknown

    CVE-2024-31622

    Last Modified: 5 Jun 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that there was not reasonable evidence to determine the existence of a vulnerability.

    Published: 5 Apr 2024
    —
    Unknown

    CVE-2024-31623

    Last Modified: 5 Jun 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that there was not reasonable evidence to determine the existence of a vulnerability.

    Published: 5 Apr 2024
    —
    Unknown

    CVE-2024-31624

    Last Modified: 5 Jun 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that there was not reasonable evidence to determine the existence of a vulnerability.

    Published: 5 Apr 2024
    6.5
    Medium

    CVE-2024-2509

    Last Modified: 13 May 2025

    The Gutenberg Blocks by Kadence Blocks WordPress plugin before 3.2.26 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

    Published: 5 Apr 2024
    4.3
    Medium

    CVE-2023-5973

    Last Modified: 13 Feb 2025

    Brocade Web Interface in Brocade Fabric OS v9.x and before v9.2.0 does not properly represent the portName to the user if the portName contains reserved characters. This could allow an authenticated user to alter the UI of the Brocade Switch and change ports display.

    Published: 5 Apr 2024
    3.5
    Low

    CVE-2024-3321

    Last Modified: 18 Feb 2025

    A vulnerability classified as problematic has been found in SourceCodester eLearning System 1.0. This affects an unknown part of the component Maintenance Module. The manipulation of the argument Subject Code/Description leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-259389 was assigned to this vulnerability.

    Published: 5 Apr 2024
    3.5
    Low

    CVE-2024-3320

    Last Modified: 18 Feb 2025

    A vulnerability was found in SourceCodester eLearning System 1.0. It has been rated as problematic. Affected by this issue is some unknown functionality. The manipulation of the argument page leads to cross site scripting. The attack may be launched remotely. The identifier of this vulnerability is VDB-259388.

    Published: 5 Apr 2024
    7.8
    High

    CVE-2024-26812

    Last Modified: 4 Aug 2026

    In the Linux kernel, the following vulnerability has been resolved: vfio/pci: Create persistent INTx handler A vulnerability exists where the eventfd for INTx signaling can be deconfigured, which unregisters the IRQ handler but still allows eventfds to be signaled with a NULL context through the SET_IRQS ioctl or through unmask irqfd if the device interrupt is pending. Ideally this could be solved with some additional locking; the igate mutex serializes the ioctl and config space accesses, and the interrupt handler is unregistered relative to the trigger, but the irqfd path runs asynchronous to those. The igate mutex cannot be acquired from the atomic context of the eventfd wake function. Disabling the irqfd relative to the eventfd registration is potentially incompatible with existing userspace. As a result, the solution implemented here moves configuration of the INTx interrupt handler to track the lifetime of the INTx context object and irq_type configuration, rather than registration of a particular trigger eventfd. Synchronization is added between the ioctl path and eventfd_signal() wrapper such that the eventfd trigger can be dynamically updated relative to in-flight interrupts or irqfd callbacks.

    Published: 5 Apr 2024
    7.8
    High

    CVE-2024-26810

    Last Modified: 4 Aug 2026

    In the Linux kernel, the following vulnerability has been resolved: vfio/pci: Lock external INTx masking ops Mask operations through config space changes to DisINTx may race INTx configuration changes via ioctl. Create wrappers that add locking for paths outside of the core interrupt code. In particular, irq_type is updated holding igate, therefore testing is_intx() requires holding igate. For example clearing DisINTx from config space can otherwise race changes of the interrupt configuration. This aligns interfaces which may trigger the INTx eventfd into two camps, one side serialized by igate and the other only enabled while INTx is configured. A subsequent patch introduces synchronization for the latter flows.

    Published: 5 Apr 2024
    7.8
    High

    CVE-2024-30977

    Last Modified: 15 Apr 2026

    An issue in Secnet Security Network Intelligent AC Management System v.1.02.040 allows a local attacker to escalate privileges via the password component.

    Published: 5 Apr 2024