CVE Feed

    Dashboard / CVE

    9.8
    Critical

    CVE-2023-49232

    Last Modified: 15 Apr 2026

    An authentication bypass vulnerability was found in Stilog Visual Planning 8. It allows an unauthenticated attacker to brute-force the password reset PINs of administrative users.

    Published: 29 Mar 2024
    6.3
    Medium

    CVE-2023-49234

    Last Modified: 15 Apr 2026

    An XML external entity (XXE) vulnerability was found in Stilog Visual Planning 8. It allows an authenticated attacker to access local server files and exfiltrate data to an external server.

    Published: 29 Mar 2024
    —
    Unknown

    CVE-2024-3069

    Last Modified: 11 Feb 2025

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

    Published: 28 Mar 2024
    7.2
    High

    CVE-2024-25955

    Last Modified: 27 Jan 2025

    Dell vApp Manager, versions prior to 9.2.4.9 contain a Command Injection Vulnerability. An authorized attacker could potentially exploit this vulnerability leading to an execution of an inserted command. Dell recommends customers to upgrade at the earliest opportunity.

    Published: 28 Mar 2024
    7.2
    High

    CVE-2024-25946

    Last Modified: 25 Mar 2025

    Dell vApp Manager, versions prior to 9.2.4.9 contain a Command Injection Vulnerability. An authorized attacker could potentially exploit this vulnerability leading to an execution of an inserted command. Dell recommends customers to upgrade at the earliest opportunity.

    Published: 28 Mar 2024
    5.5
    Medium

    CVE-2024-25971

    Last Modified: 27 Jan 2025

    Dell PowerProtect Data Manager, version 19.15, contains an XML External Entity Injection vulnerability. A remote high privileged attacker could potentially exploit this vulnerability, leading to information disclosure, denial-of-service.

    Published: 28 Mar 2024
    5.3
    Medium

    CVE-2024-25954

    Last Modified: 20 Feb 2026

    Dell PowerScale OneFS, versions 9.5.0.x through 9.7.0.x, contain an insufficient session expiration vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability, leading to denial of service.

    Published: 28 Mar 2024
    5.9
    Medium

    CVE-2024-25963

    Last Modified: 20 Feb 2026

    Dell PowerScale OneFS, versions 8.2.2.x through 9.5.0.x contains a use of a broken cryptographic algorithm vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability, leading to information disclosure.

    Published: 28 Mar 2024
    6
    Medium

    CVE-2024-25953

    Last Modified: 20 Feb 2026

    Dell PowerScale OneFS versions 9.4.0.x through 9.7.0.x contains an UNIX symbolic link (symlink) following vulnerability. A local high privileged attacker could potentially exploit this vulnerability, leading to denial of service, information tampering.

    Published: 28 Mar 2024
    6
    Medium

    CVE-2024-25952

    Last Modified: 20 Feb 2026

    Dell PowerScale OneFS versions 8.2.2.x through 9.7.0.x contains an UNIX symbolic link (symlink) following vulnerability. A local high privileged attacker could potentially exploit this vulnerability, leading to denial of service, information tampering.

    Published: 28 Mar 2024
    7.3
    High

    CVE-2024-25960

    Last Modified: 20 Feb 2026

    Dell PowerScale OneFS versions 8.2.2.x through 9.7.0.x contains a cleartext transmission of sensitive information vulnerability. A local low privileged attacker could potentially exploit this vulnerability, leading to escalation of privileges.

    Published: 28 Mar 2024
    6
    Medium

    CVE-2024-25961

    Last Modified: 20 Feb 2026

    Dell PowerScale OneFS versions 8.2.2.x through 9.7.0.x contains an improper privilege management vulnerability. A local high privileged attacker could potentially exploit this vulnerability, leading to escalation of privileges.

    Published: 28 Mar 2024
    7.9
    High

    CVE-2024-25959

    Last Modified: 20 Feb 2026

    Dell PowerScale OneFS versions 9.4.0.x through 9.7.0.x contains an insertion of sensitive information into log file vulnerability. A low privileged local attacker could potentially exploit this vulnerability, leading to sensitive information disclosure, escalation of privileges.

    Published: 28 Mar 2024
    5.5
    Medium

    CVE-2023-42936

    Last Modified: 4 Nov 2025

    This issue was addressed with improved redaction of sensitive information. This issue is fixed in macOS Monterey 12.7.2, macOS Ventura 13.6.3, iOS 17.2 and iPadOS 17.2, tvOS 17.2, watchOS 10.2, macOS Sonoma 14.2. An app may be able to access user-sensitive data.

    Published: 28 Mar 2024
    7.8
    High

    CVE-2023-42931

    Last Modified: 4 Nov 2025

    The issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.6.3, macOS Sonoma 14.2, macOS Monterey 12.7.2. A process may gain admin privileges without proper authentication.

    Published: 28 Mar 2024
    8.6
    High

    CVE-2023-42947

    Last Modified: 4 Nov 2025

    A path handling issue was addressed with improved validation. This issue is fixed in macOS Monterey 12.7.2, macOS Ventura 13.6.3, iOS 17.2 and iPadOS 17.2, tvOS 17.2, watchOS 10.2, macOS Sonoma 14.2. An app may be able to break out of its sandbox.

    Published: 28 Mar 2024
    5.5
    Medium

    CVE-2023-42896

    Last Modified: 2 Mar 2026

    An issue was addressed with improved handling of temporary files. This issue is fixed in macOS Monterey 12.7.2, macOS Ventura 13.6.3, iOS 17.2 and iPadOS 17.2, iOS 16.7.3 and iPadOS 16.7.3, macOS Sonoma 14.2. An app may be able to modify protected parts of the file system.

    Published: 28 Mar 2024
    5.5
    Medium

    CVE-2023-42930

    Last Modified: 4 Nov 2025

    This issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.6.3, macOS Sonoma 14.2, macOS Monterey 12.7.2. An app may be able to modify protected parts of the file system.

    Published: 28 Mar 2024
    8.8
    High

    CVE-2023-42913

    Last Modified: 4 Nov 2025

    This issue was addressed through improved state management. This issue is fixed in macOS Sonoma 14.2. Remote Login sessions may be able to obtain full disk access permissions.

    Published: 28 Mar 2024
    5.5
    Medium

    CVE-2023-40390

    Last Modified: 4 Nov 2025

    A privacy issue was addressed by moving sensitive data to a protected location. This issue is fixed in macOS Sonoma 14.2. An app may be able to access user-sensitive data.

    Published: 28 Mar 2024
    5.5
    Medium

    CVE-2023-42893

    Last Modified: 4 Nov 2025

    A permissions issue was addressed by removing vulnerable code and adding additional checks. This issue is fixed in macOS Monterey 12.7.2, macOS Ventura 13.6.3, iOS 17.2 and iPadOS 17.2, iOS 16.7.3 and iPadOS 16.7.3, tvOS 17.2, watchOS 10.2, macOS Sonoma 14.2. An app may be able to access protected user data.

    Published: 28 Mar 2024
    7
    High

    CVE-2023-42974

    Last Modified: 4 Nov 2025

    A race condition was addressed with improved state handling. This issue is fixed in macOS Monterey 12.7.2, macOS Ventura 13.6.3, iOS 17.2 and iPadOS 17.2, iOS 16.7.3 and iPadOS 16.7.3, macOS Sonoma 14.2. An app may be able to execute arbitrary code with kernel privileges.

    Published: 28 Mar 2024
    7.5
    High

    CVE-2023-42962

    Last Modified: 4 Nov 2025

    This issue was addressed with improved checks This issue is fixed in iOS 17.2 and iPadOS 17.2, iOS 16.7.3 and iPadOS 16.7.3. A remote attacker may be able to cause a denial-of-service.

    Published: 28 Mar 2024
    7.8
    High

    CVE-2023-42892

    Last Modified: 4 Nov 2025

    A use-after-free issue was addressed with improved memory management. This issue is fixed in macOS Ventura 13.6.3, macOS Sonoma 14.2, macOS Monterey 12.7.2. A local attacker may be able to elevate their privileges.

    Published: 28 Mar 2024
    4.1
    Medium

    CVE-2024-31140

    Last Modified: 16 Dec 2024

    In JetBrains TeamCity before 2024.03 server administrators could remove arbitrary files from the server by installing tools

    Published: 28 Mar 2024
    5.9
    Medium

    CVE-2024-31139

    Last Modified: 16 Dec 2024

    In JetBrains TeamCity before 2024.03 xXE was possible in the Maven build steps detector

    Published: 28 Mar 2024
    4.6
    Medium

    CVE-2024-31138

    Last Modified: 21 Nov 2024

    In JetBrains TeamCity before 2024.03 xSS was possible via Agent Distribution settings

    Published: 28 Mar 2024
    6.8
    Medium

    CVE-2024-31137

    Last Modified: 21 Nov 2024

    In JetBrains TeamCity before 2024.03 reflected XSS was possible via Space connection configuration

    Published: 28 Mar 2024
    7.4
    High

    CVE-2024-31136

    Last Modified: 16 Dec 2024

    In JetBrains TeamCity before 2024.03 2FA could be bypassed by providing a special URL parameter

    Published: 28 Mar 2024
    6.1
    Medium

    CVE-2024-31135

    Last Modified: 21 Nov 2024

    In JetBrains TeamCity before 2024.03 open redirect was possible on the login page

    Published: 28 Mar 2024
    6.5
    Medium

    CVE-2024-31134

    Last Modified: 16 Dec 2024

    In JetBrains TeamCity before 2024.03 authenticated users without administrative permissions could register other users when self-registration was disabled

    Published: 28 Mar 2024
    6.3
    Medium

    CVE-2024-3042

    Last Modified: 21 Feb 2025

    A vulnerability was found in SourceCodester Simple Subscription Website 1.0 and classified as critical. This issue affects some unknown processing of the file manage_user.php. The manipulation of the argument id leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-258431.

    Published: 28 Mar 2024
    6.3
    Medium

    CVE-2024-3041

    Last Modified: 10 Feb 2025

    A vulnerability has been found in Netentsec NS-ASG Application Security Gateway 6.3 and classified as critical. This vulnerability affects unknown code of the file /protocol/log/listloginfo.php. The manipulation leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-258430 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 28 Mar 2024
    6.3
    Medium

    CVE-2024-3040

    Last Modified: 10 Feb 2025

    A vulnerability, which was classified as critical, was found in Netentsec NS-ASG Application Security Gateway 6.3. This affects an unknown part of the file /admin/list_crl_conf. The manipulation of the argument CRLId leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-258429 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 28 Mar 2024
    6.3
    Medium

    CVE-2024-3039

    Last Modified: 25 Mar 2025

    A vulnerability classified as critical has been found in Shanghai Brad Technology BladeX 3.4.0. Affected is an unknown function of the file /api/blade-user/export-user of the component API. The manipulation with the input updatexml(1,concat(0x3f,md5(123456),0x3f),1)=1 leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-258426 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 28 Mar 2024
    3.5
    Low

    CVE-2023-45715

    Last Modified: 8 Jan 2026

    The console may experience a service interruption when processing file names with invalid characters.

    Published: 28 Mar 2024
    2
    Low

    CVE-2023-45706

    Last Modified: 8 Jan 2026

    An administrative user of WebReports may perform a Cross Site Scripting (XSS) and/or Man in the Middle (MITM) exploit through SAML configuration.

    Published: 28 Mar 2024
    3.5
    Low

    CVE-2023-45705

    Last Modified: 28 Mar 2025

    An administrative user of WebReports may perform a Server Side Request Forgery (SSRF) exploit through SMTP configuration options.

    Published: 28 Mar 2024
    4.9
    Medium

    CVE-2024-29898

    Last Modified: 8 Jan 2026

    CreateWiki is Miraheze's MediaWiki extension for requesting & creating wikis. An oversight during the writing of the patch for CVE-2024-29897 may have exposed suppressed wiki requests to private wikis that added Special:RequestWikiQueue to the read whitelist to users without the `(read)` permission. This vulnerability is fixed in 8f8442ed5299510ea3e58416004b9334134c149c.

    Published: 28 Mar 2024
    4.9
    Medium

    CVE-2024-29897

    Last Modified: 15 Apr 2026

    CreateWiki is Miraheze's MediaWiki extension for requesting & creating wikis. It is possible for users with (delete) or (suppressrevision) on any wiki in the farm to access suppressed wiki requests by going to the request's entry on Special:RequestWikiQueue on the wiki where they have these rights. The same vulnerability was present briefly on the REST API before being quickly corrected in commit `6bc0685`. To our knowledge, the vulnerable commits of the REST API are not running in production anywhere. This vulnerability is fixed in 23415c17ffb4832667c06abcf1eadadefd4c8937.

    Published: 28 Mar 2024
    7.2
    High

    CVE-2024-29882

    Last Modified: 8 Jan 2026

    SRS is a simple, high-efficiency, real-time video server. SRS's `/api/v1/vhosts/vid-<id>?callback=<payload>` endpoint didn't filter the callback function name which led to injecting malicious javascript payloads and executing XSS ( Cross-Site Scripting). This vulnerability is fixed in 5.0.210 and 6.0.121.

    Published: 28 Mar 2024
    6.8
    Medium

    CVE-2024-29200

    Last Modified: 10 Oct 2025

    Kimai is a web-based multi-user time-tracking application. The permission `view_other_timesheet` performs differently for the Kimai UI and the API, thus returning unexpected data through the API. When setting the `view_other_timesheet` permission to true, on the frontend, users can only see timesheet entries for teams they are a part of. When requesting all timesheets from the API, however, all timesheet entries are returned, regardless of whether the user shares team permissions or not. This vulnerability is fixed in 2.13.0.

    Published: 28 Mar 2024
    8.1
    High

    CVE-2024-28109

    Last Modified: 15 Apr 2026

    veraPDF-library is a PDF/A validation library. Executing policy checks using custom schematron files invokes an XSL transformation that could lead to a remote code execution (RCE) vulnerability. This vulnerability is fixed in 1.24.2.

    Published: 28 Mar 2024
    9.8
    Critical

    CVE-2023-6437

    Last Modified: 20 May 2026

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in TP-Link TP-Link EX20v AX1800, Tp-Link Archer C5v AC1200, Tp-Link TD-W9970, Tp-Link TD-W9970v3, TP-Link VX220-G2u, TP-Link VN020-G2u allows authenticated OS Command Injection. This issue affects TP-Link EX20v AX1800, Tp-Link Archer C5v AC1200, Tp-Link TD-W9970, Tp-Link TD-W9970v3 : through 20240328. Also  the vulnerability continues in the TP-Link VX220-G2u and TP-Link VN020-G2u models due to the products not being produced and supported.

    Published: 28 Mar 2024
    7.5
    High

    CVE-2024-29896

    Last Modified: 19 Sept 2025

    Astro-Shield is a library to compute the subresource integrity hashes for your JS scripts and CSS stylesheets. When automated CSP headers generation for SSR content is enabled and the web application serves content that can be partially controlled by external users, then it is possible that the CSP headers generation feature might be "allow-listing" malicious injected resources like inlined JS, or references to external malicious scripts. The fix is available in version 1.3.0.

    Published: 28 Mar 2024
    7.2
    High

    CVE-2024-27775

    Last Modified: 15 Apr 2026

    SysAid before version 23.2.14 b18 - CWE-918: Server-Side Request Forgery (SSRF) may allow exposing the local OS user's NTLMv2 hash

    Published: 28 Mar 2024
    7.3
    High

    CVE-2024-0259

    Last Modified: 9 Apr 2025

    Fortra's Robot Schedule Enterprise Agent for Windows prior to version 3.04 is susceptible to privilege escalation. A low-privileged user can overwrite the service executable. When the service is restarted, the replaced binary runs with local system privileges, allowing a low-privileged user to gain elevated privileges.

    Published: 28 Mar 2024
    6.5
    Medium

    CVE-2024-30422

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPVibes Elementor Addon Elements addon-elements-for-elementor-page-builder.This issue affects Elementor Addon Elements: from n/a through <= 1.13.1.

    Published: 28 Mar 2024
    4.3
    Medium

    CVE-2024-30421

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Pixelite Events Manager.This issue affects Events Manager: from n/a through 6.4.7.1.

    Published: 28 Mar 2024
    8.7
    High

    CVE-2023-6371

    Last Modified: 23 May 2025

    An issue has been discovered in GitLab CE/EE affecting all versions before 16.8.5, all versions starting from 16.9 before 16.9.3, all versions starting from 16.10 before 16.10.1. A wiki page with a crafted payload may lead to a Stored XSS, allowing attackers to perform arbitrary actions on behalf of victims.

    Published: 28 Mar 2024