CVE Feed

    Dashboard / CVE

    4.7
    Medium

    CVE-2024-2262

    Last Modified: 13 May 2025

    Themify WordPress plugin before 1.4.4 does not have CSRF check in its bulk action, which could allow attackers to make logged in users delete arbitrary filters via CSRF attack, granted they know the related filter slugs

    Published: 1 Apr 2024
    6.3
    Medium

    CVE-2024-20055

    Last Modified: 23 Apr 2025

    In imgsys, there is a possible information disclosure due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is needed for exploitation Patch ID: ALPS08518692; Issue ID: MSV-1012.

    Published: 1 Apr 2024
    6.6
    Medium

    CVE-2024-20054

    Last Modified: 23 Apr 2025

    In gnss, there is a possible escalation of privilege due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08580200; Issue ID: ALPS08580200.

    Published: 1 Apr 2024
    8.4
    High

    CVE-2024-20053

    Last Modified: 23 Apr 2025

    In flashc, there is a possible out of bounds write due to an uncaught exception. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08541757; Issue ID: ALPS08541764.

    Published: 1 Apr 2024
    4.4
    Medium

    CVE-2024-20052

    Last Modified: 23 Apr 2025

    In flashc, there is a possible information disclosure due to an uncaught exception. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08541757; Issue ID: ALPS08541761.

    Published: 1 Apr 2024
    2.3
    Low

    CVE-2024-20051

    Last Modified: 23 Apr 2025

    In flashc, there is a possible system crash due to an uncaught exception. This could lead to local denial of service with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08541757; Issue ID: ALPS08541758.

    Published: 1 Apr 2024
    4.4
    Medium

    CVE-2024-20050

    Last Modified: 23 Apr 2025

    In flashc, there is a possible information disclosure due to an uncaught exception. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08541757; Issue ID: ALPS08541757.

    Published: 1 Apr 2024
    4.4
    Medium

    CVE-2024-20049

    Last Modified: 23 Apr 2025

    In flashc, there is a possible information disclosure due to an uncaught exception. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08541765; Issue ID: ALPS08541765.

    Published: 1 Apr 2024
    6.2
    Medium

    CVE-2024-20048

    Last Modified: 23 Apr 2025

    In flashc, there is a possible information disclosure due to an uncaught exception. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08541769; Issue ID: ALPS08541769.

    Published: 1 Apr 2024
    5.4
    Medium

    CVE-2024-20047

    Last Modified: 23 Apr 2025

    In battery, there is a possible out of bounds read due to an integer overflow. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08587865; Issue ID: ALPS08486807.

    Published: 1 Apr 2024
    6.6
    Medium

    CVE-2024-20046

    Last Modified: 23 Apr 2025

    In battery, there is a possible escalation of privilege due to an integer overflow. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08485622; Issue ID: ALPS08485622.

    Published: 1 Apr 2024
    2.3
    Low

    CVE-2024-20045

    Last Modified: 23 Apr 2025

    In audio, there is a possible out of bounds read due to an incorrect calculation of buffer size. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08024748; Issue ID: ALPS08029526.

    Published: 1 Apr 2024
    6.6
    Medium

    CVE-2024-20044

    Last Modified: 23 Apr 2025

    In da, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08541784; Issue ID: ALPS08541784.

    Published: 1 Apr 2024
    6.6
    Medium

    CVE-2024-20043

    Last Modified: 23 Apr 2025

    In da, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08541781; Issue ID: ALPS08541781.

    Published: 1 Apr 2024
    6.6
    Medium

    CVE-2024-20042

    Last Modified: 23 Apr 2025

    In da, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08541780; Issue ID: ALPS08541780.

    Published: 1 Apr 2024
    4.4
    Medium

    CVE-2024-20041

    Last Modified: 23 Apr 2025

    In da, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08541746; Issue ID: ALPS08541746.

    Published: 1 Apr 2024
    8.8
    High

    CVE-2024-20040

    Last Modified: 23 Apr 2025

    In wlan firmware, there is a possible out of bounds write due to improper input validation. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08360153 (for MT6XXX chipsets) / WCNCR00363530 (for MT79XX chipsets); Issue ID: MSV-979.

    Published: 1 Apr 2024
    8.8
    High

    CVE-2024-20039

    Last Modified: 23 Apr 2025

    In modem protocol, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01240012; Issue ID: MSV-1215.

    Published: 1 Apr 2024
    5.3
    Medium

    CVE-2024-1526

    Last Modified: 10 Jun 2025

    The Hubbub Lite WordPress plugin before 1.33.1 does not ensure that user have access to password protected post before displaying its content in a meta tag.

    Published: 1 Apr 2024
    6.1
    Medium

    CVE-2024-28895

    Last Modified: 15 Apr 2026

    'Yahoo! JAPAN' App for Android v2.3.1 to v3.161.1 and 'Yahoo! JAPAN' App for iOS v3.2.2 to v4.109.0 contain a cross-site scripting vulnerability. If this vulnerability is exploited, an arbitrary script may be executed on the WebView of 'Yahoo! JAPAN' App via other app installed on the user's device.

    Published: 1 Apr 2024
    6.8
    Medium

    CVE-2024-31033

    Last Modified: 15 Apr 2026

    JJWT (aka Java JWT) through 0.12.5 ignores certain characters and thus a user might falsely conclude that they have a strong key. The impacted code is the setSigningKey() method within the DefaultJwtParser class and the signWith() method within the DefaultJwtBuilder class. NOTE: the vendor disputes this because the "ignores" behavior cannot occur (in any version) unless there is a user error in how JJWT is used, and because the version that was actually tested must have been more than six years out of date.

    Published: 1 Apr 2024
    4.3
    Medium

    CVE-2023-48906

    Last Modified: 15 Apr 2026

    Stack Overflow vulnerability in Btstack 1.6 and earlier allows attackers to cause a denial of service via crafted input to the char_for_nibble function.

    Published: 1 Apr 2024
    5.3
    Medium

    CVE-2024-30861

    Last Modified: 4 Apr 2025

    netentsec NS-ASG 6.3 is vulnerable to SQL Injection via /admin/configguide/ipsec_guide_1.php.

    Published: 1 Apr 2024
    7.8
    High

    CVE-2024-26654

    Last Modified: 4 Aug 2026

    In the Linux kernel, the following vulnerability has been resolved: ALSA: sh: aica: reorder cleanup operations to avoid UAF bugs The dreamcastcard->timer could schedule the spu_dma_work and the spu_dma_work could also arm the dreamcastcard->timer. When the snd_pcm_substream is closing, the aica_channel will be deallocated. But it could still be dereferenced in the worker thread. The reason is that del_timer() will return directly regardless of whether the timer handler is running or not and the worker could be rescheduled in the timer handler. As a result, the UAF bug will happen. The racy situation is shown below: (Thread 1) | (Thread 2) snd_aicapcm_pcm_close() | ... | run_spu_dma() //worker | mod_timer() flush_work() | del_timer() | aica_period_elapsed() //timer kfree(dreamcastcard->channel) | schedule_work() | run_spu_dma() //worker ... | dreamcastcard->channel-> //USE In order to mitigate this bug and other possible corner cases, call mod_timer() conditionally in run_spu_dma(), then implement PCM sync_stop op to cancel both the timer and worker. The sync_stop op will be called from PCM core appropriately when needed.

    Published: 1 Apr 2024
    4.7
    Medium

    CVE-2024-25080

    Last Modified: 15 Apr 2026

    WebMail in Axigen 10.x before 10.3.3.62 allows XSS via the image attachment viewer.

    Published: 1 Apr 2024
    7.8
    High

    CVE-2024-26653

    Last Modified: 4 May 2025

    In the Linux kernel, the following vulnerability has been resolved: usb: misc: ljca: Fix double free in error handling path When auxiliary_device_add() returns error and then calls auxiliary_device_uninit(), callback function ljca_auxdev_release calls kfree(auxdev->dev.platform_data) to free the parameter data of the function ljca_new_client_device. The callers of ljca_new_client_device shouldn't call kfree() again in the error handling path to free the platform data. Fix this by cleaning up the redundant kfree() in all callers and adding kfree() the passed in platform_data on errors which happen before auxiliary_device_init() succeeds .

    Published: 1 Apr 2024
    9.8
    Critical

    CVE-2024-29433

    Last Modified: 7 May 2025

    A deserialization vulnerability in the FASTJSON component of Alldata v0.4.6 allows attackers to execute arbitrary commands via supplying crafted data.

    Published: 1 Apr 2024
    4.1
    Medium

    CVE-2024-29435

    Last Modified: 7 May 2025

    An issue discovered in Alldata v0.4.6 allows attacker to run arbitrary commands via the processId parameter.

    Published: 1 Apr 2024
    9.8
    Critical

    CVE-2024-30858

    Last Modified: 4 Apr 2025

    netentsec NS-ASG 6.3 is vulnerable to SQL Injection via /admin/edit_fire_wall.php.

    Published: 1 Apr 2024
    8.8
    High

    CVE-2024-30859

    Last Modified: 4 Apr 2025

    netentsec NS-ASG 6.3 is vulnerable to SQL Injection via /admin/config_ISCGroupSSLCert.php.

    Published: 1 Apr 2024
    8.8
    High

    CVE-2024-30860

    Last Modified: 4 Apr 2025

    netentsec NS-ASG 6.3 is vulnerable to SQL Injection via /admin/export_excel_user.php.

    Published: 1 Apr 2024
    8.8
    High

    CVE-2024-30862

    Last Modified: 4 Apr 2025

    netentsec NS-ASG 6.3 is vulnerable to SQL Injection via /3g/index.php.

    Published: 1 Apr 2024
    6.3
    Medium

    CVE-2024-30863

    Last Modified: 4 Apr 2025

    netentsec NS-ASG 6.3 is vulnerable to SQL Injection via /WebPages/history.php.

    Published: 1 Apr 2024
    6.3
    Medium

    CVE-2024-30864

    Last Modified: 4 Apr 2025

    netentsec NS-ASG 6.3 is vulnerable to SQL Injection via /admin/config_ISCGroupTimePolicy.php.

    Published: 1 Apr 2024
    9.8
    Critical

    CVE-2024-30865

    Last Modified: 4 Apr 2025

    netentsec NS-ASG 6.3 is vulnerable to SQL Injection via /admin/edit_user_login.php.

    Published: 1 Apr 2024
    5.4
    Medium

    CVE-2024-30866

    Last Modified: 4 Apr 2025

    netentsec NS-ASG 6.3 is vulnerable to SQL Injection via /3g/menu.php.

    Published: 1 Apr 2024
    9.8
    Critical

    CVE-2024-30867

    Last Modified: 4 Apr 2025

    netentsec NS-ASG 6.3 is vulnerable to SQL Injection via /admin/edit_virtual_site_info.php.

    Published: 1 Apr 2024
    9.8
    Critical

    CVE-2024-30868

    Last Modified: 4 Apr 2025

    netentsec NS-ASG 6.3 is vulnerable to SQL Injection via /admin/add_getlogin.php.

    Published: 1 Apr 2024
    8.8
    High

    CVE-2024-30870

    Last Modified: 4 Apr 2025

    netentsec NS-ASG 6.3 is vulnerable to SQL Injection via /admin/address_interpret.php.

    Published: 1 Apr 2024
    8.8
    High

    CVE-2024-30871

    Last Modified: 4 Apr 2025

    netentsec NS-ASG 6.3 is vulnerable to SQL Injection via /WebPages/applyhardware.php.

    Published: 1 Apr 2024
    5.1
    Medium

    CVE-2024-30872

    Last Modified: 4 Apr 2025

    netentsec NS-ASG 6.3 is vulnerable to SQL Injection via /include/authrp.php.

    Published: 1 Apr 2024
    6.7
    Medium

    CVE-2024-28219

    Last Modified: 4 Nov 2025

    In _imagingcms.c in Pillow before 10.3.0, a buffer overflow exists because strcpy is used instead of strncpy.

    Published: 1 Apr 2024
    5.5
    Medium

    CVE-2024-26655

    Last Modified: 17 Mar 2026

    In the Linux kernel, the following vulnerability has been resolved: Fix memory leak in posix_clock_open() If the clk ops.open() function returns an error, we don't release the pccontext we allocated for this clock. Re-organize the code slightly to make it all more obvious.

    Published: 1 Apr 2024
    3.5
    Low

    CVE-2014-125110

    Last Modified: 15 Apr 2026

    A vulnerability has been found in wp-file-upload Plugin up to 2.4.3 on WordPress and classified as problematic. Affected by this vulnerability is the function wfu_ajax_action_callback of the file lib/wfu_ajaxactions.php. The manipulation leads to cross site scripting. The attack can be launched remotely. Upgrading to version 2.4.4 is able to address this issue. The identifier of the patch is c846327df030a0a97da036a2f07c769ab9284ddb. It is recommended to upgrade the affected component. The identifier VDB-258781 was assigned to this vulnerability.

    Published: 31 Mar 2024
    6.5
    Medium

    CVE-2024-30524

    Last Modified: 28 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in RedLettuce Plugins PDF Viewer for Elementor allows Stored XSS.This issue affects PDF Viewer for Elementor: from n/a through 2.9.3.

    Published: 31 Mar 2024
    6.5
    Medium

    CVE-2024-30530

    Last Modified: 28 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Sonaar Music MP3 Audio Player for Music, Radio & Podcast by Sonaar allows Stored XSS.This issue affects MP3 Audio Player for Music, Radio & Podcast by Sonaar: from n/a through 5.1.

    Published: 31 Mar 2024
    5.9
    Medium

    CVE-2024-30548

    Last Modified: 28 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Noah Kagan underConstruction allows Stored XSS.This issue affects underConstruction: from n/a through 1.21.

    Published: 31 Mar 2024
    5.9
    Medium

    CVE-2024-30549

    Last Modified: 28 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in cimatti Contact Forms by Cimatti contact-forms.This issue affects Contact Forms by Cimatti: from n/a through <= 1.8.0.

    Published: 31 Mar 2024
    7.1
    High

    CVE-2024-30550

    Last Modified: 28 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpdevart Responsive Image Gallery, Gallery Album allows Reflected XSS.This issue affects Responsive Image Gallery, Gallery Album: from n/a through 2.0.3.

    Published: 31 Mar 2024
    7.1
    High

    CVE-2024-30551

    Last Modified: 28 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Toast Plugins Sticky Anything.This issue affects Sticky Anything: from n/a through 2.1.5.

    Published: 31 Mar 2024