CVE Feed

    Dashboard / CVE

    6.3
    Medium

    CVE-2024-2945

    Last Modified: 21 Feb 2025

    A vulnerability was found in Campcodes Online Examination System 1.0. It has been classified as critical. Affected is an unknown function of the file /adminpanel/admin/facebox_modal/updateExaminee.php. The manipulation of the argument id leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-258036.

    Published: 27 Mar 2024
    6.3
    Medium

    CVE-2024-2944

    Last Modified: 10 Apr 2025

    A vulnerability was found in Campcodes Online Examination System 1.0 and classified as critical. This issue affects some unknown processing of the file /adminpanel/admin/query/deleteCourseExe.php. The manipulation of the argument id leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-258035.

    Published: 27 Mar 2024
    6.3
    Medium

    CVE-2024-2943

    Last Modified: 21 Feb 2025

    A vulnerability has been found in Campcodes Online Examination System 1.0 and classified as critical. This vulnerability affects unknown code of the file /adminpanel/admin/query/deleteExamExe.php. The manipulation of the argument id leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-258034 is the identifier assigned to this vulnerability.

    Published: 27 Mar 2024
    7.5
    High

    CVE-2024-2097

    Last Modified: 15 Apr 2026

    An authenticated malicious client can send a special LINQ query to execute arbitrary code remotely (RCE) on the SCM server from List control, and execute the arbitrary code on the same system where SCMArchivedEventViewerTool is installed in the case of SCM Tools.

    Published: 27 Mar 2024
    7.5
    High

    CVE-2024-0400

    Last Modified: 15 Apr 2026

    SCM Software is a client and server application. An Authenticated System manager client can execute LINQ query in the SCM server, for customized filtering. An Authenticated malicious client can send a specially crafted code to skip the validation and execute arbitrary code (RCE) on the SCM Server remotely. Malicious clients can execute any command by using this RCE vulnerability.

    Published: 27 Mar 2024
    6.3
    Medium

    CVE-2024-2942

    Last Modified: 20 Feb 2025

    A vulnerability, which was classified as critical, was found in Campcodes Online Examination System 1.0. This affects an unknown part of the file /adminpanel/admin/query/deleteQuestionExe.php. The manipulation of the argument id leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-258033 was assigned to this vulnerability.

    Published: 27 Mar 2024
    6.3
    Medium

    CVE-2024-2941

    Last Modified: 20 Feb 2025

    A vulnerability, which was classified as critical, has been found in Campcodes Online Examination System 1.0. Affected by this issue is some unknown functionality of the file /adminpanel/admin/query/loginExe.php. The manipulation of the argument pass leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-258032.

    Published: 27 Mar 2024
    6.4
    Medium

    CVE-2024-2203

    Last Modified: 8 Apr 2026

    The The Plus Addons for Elementor plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 5.4.1 via the Clients widget. This makes it possible for authenticated attackers, with contributor-level access and above, to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where images and other “safe” file types can be uploaded and included.

    Published: 27 Mar 2024
    6.4
    Medium

    CVE-2024-2139

    Last Modified: 8 Apr 2026

    The Master Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Pricing Table widget in all versions up to, and including, 2.0.5.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 27 Mar 2024
    6.4
    Medium

    CVE-2024-2210

    Last Modified: 8 Apr 2026

    The The Plus Addons for Elementor plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 5.4.1 via the Team Member Listing widget. This makes it possible for authenticated attackers, with contributor-level access and above, to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where images and other “safe” file types can be uploaded and included.

    Published: 27 Mar 2024
    6.8
    Medium

    CVE-2024-1532

    Last Modified: 15 Apr 2026

    A vulnerability exists in the stb-language file handling that affects the RTU500 series product versions listed below. A malicious actor could enforce diagnostic texts being displayed as empty strings, if an authorized user uploads a specially crafted stb-language file.

    Published: 27 Mar 2024
    8.2
    High

    CVE-2024-1531

    Last Modified: 15 Apr 2026

    A vulnerability exists in the stb-language file handling that affects the RTU500 series product versions listed below. A malicious actor could print random memory content in the RTU500 system log, if an authorized user uploads a specially crafted stb-language file.

    Published: 27 Mar 2024
    3.5
    Low

    CVE-2024-2940

    Last Modified: 19 Feb 2025

    A vulnerability classified as problematic was found in Campcodes Online Examination System 1.0. Affected by this vulnerability is an unknown functionality of the file /adminpanel/admin/facebox_modal/updateCourse.php. The manipulation of the argument id leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-258031.

    Published: 27 Mar 2024
    5.3
    Medium

    CVE-2024-2244

    Last Modified: 15 Apr 2026

    REST service authentication anomaly with “valid username/no password” credential combination for batch job processing resulting in successful service invocation. The anomaly doesn’t exist with other credential combinations.

    Published: 27 Mar 2024
    3.5
    Low

    CVE-2024-2939

    Last Modified: 19 Feb 2025

    A vulnerability classified as problematic has been found in Campcodes Online Examination System 1.0. Affected is an unknown function of the file /adminpanel/admin/facebox_modal/updateExaminee.php. The manipulation of the argument id leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-258030 is the identifier assigned to this vulnerability.

    Published: 27 Mar 2024
    6.3
    Medium

    CVE-2024-2938

    Last Modified: 20 Feb 2025

    A vulnerability was found in Campcodes Online Examination System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /adminpanel/admin/facebox_modal/updateCourse.php. The manipulation of the argument id leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-258029 was assigned to this vulnerability.

    Published: 27 Mar 2024
    5.3
    Medium

    CVE-2024-2935

    Last Modified: 18 Feb 2025

    A vulnerability, which was classified as problematic, has been found in SourceCodester Todo List in Kanban Board 1.0. Affected by this issue is some unknown functionality of the component Add ToDo. The manipulation of the argument Todo leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

    Published: 27 Mar 2024
    6.3
    Medium

    CVE-2024-2934

    Last Modified: 18 Feb 2025

    A vulnerability classified as critical was found in SourceCodester Todo List in Kanban Board 1.0. Affected by this vulnerability is an unknown functionality of the file /endpoint/delete-todo.php. The manipulation of the argument list leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-258013 was assigned to this vulnerability.

    Published: 27 Mar 2024
    6.5
    Medium

    CVE-2024-2206

    Last Modified: 29 Jul 2025

    An SSRF vulnerability exists in the gradio-app/gradio due to insufficient validation of user-supplied URLs in the `/proxy` route. Attackers can exploit this vulnerability by manipulating the `self.replica_urls` set through the `X-Direct-Url` header in requests to the `/` and `/config` routes, allowing the addition of arbitrary URLs for proxying. This flaw enables unauthorized proxying of requests and potential access to internal endpoints within the Hugging Face space. The issue arises from the application's inadequate checking of safe URLs in the `build_proxy_request` function.

    Published: 27 Mar 2024
    6.3
    Medium

    CVE-2024-2932

    Last Modified: 18 Feb 2025

    A vulnerability classified as critical has been found in SourceCodester Online Chatting System 1.0. Affected is an unknown function of the file admin/update_room.php. The manipulation of the argument id leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-258012.

    Published: 27 Mar 2024
    3.3
    Low

    CVE-2024-28085

    Last Modified: 14 Jul 2026

    wall in util-linux through 2.40, often installed with setgid tty permissions, allows escape sequences to be sent to other users' terminals through argv. (Specifically, escape sequences received from stdin are blocked, but escape sequences received from argv are not blocked.) There may be plausible scenarios where this leads to account takeover.

    Published: 27 Mar 2024
    9.1
    Critical

    CVE-2024-28335

    Last Modified: 15 Apr 2026

    Lektor before 3.3.11 does not sanitize DB path traversal. Thus, shell commands might be executed via a file that is added to the templates directory, if the victim's web browser accesses an untrusted website that uses JavaScript to send requests to localhost port 5000, and the web browser is running on the same machine as the "lektor server" command.

    Published: 27 Mar 2024
    3.3
    Low

    CVE-2023-46051

    Last Modified: 15 Apr 2026

    TeX Live 944e257 allows a NULL pointer dereference in texk/web2c/pdftexdir/tounicode.c. NOTE: this is disputed because it should be categorized as a usability problem.

    Published: 27 Mar 2024
    5.3
    Medium

    CVE-2023-46049

    Last Modified: 15 Apr 2026

    LLVM 15.0.0 has a NULL pointer dereference in the parseOneMetadata() function via a crafted pdflatex.fmt file (or perhaps a crafted .o file) to llvm-lto. NOTE: this is disputed because the relationship between pdflatex.fmt and any LLVM language front end is not explained, and because a crash of the llvm-lto application should be categorized as a usability problem.

    Published: 27 Mar 2024
    6.2
    Medium

    CVE-2023-46048

    Last Modified: 15 Apr 2026

    Tex Live 944e257 has a NULL pointer dereference in texk/web2c/pdftexdir/writet1.c. NOTE: this is disputed because it should be categorized as a usability problem.

    Published: 27 Mar 2024
    5.5
    Medium

    CVE-2023-46046

    Last Modified: 15 Apr 2026

    An issue in MiniZinc before 2.8.0 allows a NULL pointer dereference via ti_expr in a crafted .mzn file. NOTE: this is disputed because there is no common libminizinc use case in which an unattended process is supposed to run forever to process a series of atttacker-controlled .mzn files.

    Published: 27 Mar 2024
    9.8
    Critical

    CVE-2023-45924

    Last Modified: 15 Apr 2026

    libglxproto.c in OpenGL libglvnd bb06db5a was discovered to contain a segmentation violation via the function glXGetDrawableScreen(). NOTE: this is disputed because there are no common situations in which users require uninterrupted operation with an attacker-controller server.

    Published: 27 Mar 2024
    —
    Unknown

    CVE-2023-31854

    Last Modified: 15 Apr 2026

    std::bad_alloc is mishandled in Precomp 0.4.8. NOTE: this is disputed because it should be categorized as a usability problem.

    Published: 27 Mar 2024
    4.9
    Medium

    CVE-2024-23450

    Last Modified: 13 Feb 2025

    A flaw was discovered in Elasticsearch, where processing a document in a deeply nested pipeline on an ingest node could cause the Elasticsearch node to crash.

    Published: 27 Mar 2024
    6.5
    Medium

    CVE-2023-47438

    Last Modified: 15 Apr 2026

    SQL Injection vulnerability in Reportico Till 8.1.0 allows attackers to obtain sensitive information or other system information via the project parameter.

    Published: 27 Mar 2024
    9.1
    Critical

    CVE-2023-45929

    Last Modified: 30 May 2025

    S-Lang 2.3.2 was discovered to contain a segmentation fault via the function fixup_tgetstr().

    Published: 27 Mar 2024
    3.5
    Low

    CVE-2024-2004

    Last Modified: 30 Jul 2025

    When a protocol selection parameter option disables all protocols without adding any then the default set of protocols would remain in the allowed set due to an error in the logic for removing protocols. The below command would perform a request to curl.se with a plaintext protocol which has been explicitly disabled. curl --proto -all,-http http://curl.se The flaw is only present if the set of selected protocols disables the entire set of available protocols, in itself a command with no practical use and therefore unlikely to be encountered in real situations. The curl security team has thus assessed this to be low severity bug.

    Published: 27 Mar 2024
    6.3
    Medium

    CVE-2024-2379

    Last Modified: 30 Jul 2025

    libcurl skips the certificate verification for a QUIC connection under certain conditions, when built to use wolfSSL. If told to use an unknown/bad cipher or curve, the error path accidentally skips the verification and returns OK, thus ignoring any certificate problems.

    Published: 27 Mar 2024
    6.5
    Medium

    CVE-2024-2466

    Last Modified: 30 Jul 2025

    libcurl did not check the server certificate of TLS connections done to a host specified as an IP address, when built to use mbedTLS. libcurl would wrongly avoid using the set hostname function when the specified hostname was given as an IP address, therefore completely skipping the certificate check. This affects all uses of TLS protocols (HTTPS, FTPS, IMAPS, POPS3, SMTPS, etc).

    Published: 27 Mar 2024
    9.8
    Critical

    CVE-2023-31634

    Last Modified: 28 May 2025

    In TeslaMate before 1.27.2, there is unauthorized access to port 4000 for remote viewing and operation of user data. After accessing the IP address for the TeslaMate instance, an attacker can switch the port to 3000 to enter Grafana for remote operations. At that time, the default username and password can be used to enter the Grafana management console without logging in, a related issue to CVE-2022-23126.

    Published: 27 Mar 2024
    6.5
    Medium

    CVE-2023-40285

    Last Modified: 17 Jun 2025

    An issue was discovered on Supermicro X11SSM-F, X11SAE-F, and X11SSE-F 1.66 devices. An attacker could exploit an XSS issue.

    Published: 27 Mar 2024
    8.3
    High

    CVE-2023-40286

    Last Modified: 18 Jun 2025

    An issue was discovered on Supermicro X11SSM-F, X11SAE-F, and X11SSE-F 1.66 devices. An attacker could exploit an XSS issue.

    Published: 27 Mar 2024
    8.3
    High

    CVE-2023-40287

    Last Modified: 18 Jun 2025

    An issue was discovered on Supermicro X11SSM-F, X11SAE-F, and X11SSE-F 1.66 devices. An attacker could exploit an XSS issue.

    Published: 27 Mar 2024
    8.3
    High

    CVE-2023-40288

    Last Modified: 18 Jun 2025

    An issue was discovered on Supermicro X11SSM-F, X11SAE-F, and X11SSE-F 1.66 devices. An attacker could exploit an XSS issue.

    Published: 27 Mar 2024
    7.2
    High

    CVE-2023-40289

    Last Modified: 18 Jun 2025

    A command injection issue was discovered on Supermicro X11SSM-F, X11SAE-F, and X11SSE-F 1.66 devices. An attacker can exploit this to elevate privileges from a user with BMC administrative privileges.

    Published: 27 Mar 2024
    7.5
    High

    CVE-2023-43768

    Last Modified: 23 Apr 2025

    An issue was discovered in Couchbase Server 6.6.x through 7.2.0, before 7.1.5 and 7.2.1. Unauthenticated users may cause memcached to run out of memory via large commands.

    Published: 27 Mar 2024
    5.3
    Medium

    CVE-2023-45919

    Last Modified: 4 Nov 2025

    Mesa 23.0.4 was discovered to contain a buffer over-read in glXQueryServerString(). NOTE: this is disputed because there are no common situations in which users require uninterrupted operation with an attacker-controller server.

    Published: 27 Mar 2024
    9.1
    Critical

    CVE-2023-45927

    Last Modified: 4 Nov 2025

    S-Lang 2.3.2 was discovered to contain an arithmetic exception via the function tt_sprintf().

    Published: 27 Mar 2024
    8.6
    High

    CVE-2024-2398

    Last Modified: 30 Jul 2025

    When an application tells libcurl it wants to allow HTTP/2 server push, and the amount of received headers for the push surpasses the maximum allowed limit (1000), libcurl aborts the server push. When aborting, libcurl inadvertently does not free all the previously allocated headers and instead leaks the memory. Further, this error condition fails silently and is therefore not easily detected by an application.

    Published: 27 Mar 2024
    8.4
    High

    CVE-2024-24334

    Last Modified: 30 Apr 2025

    A heap buffer overflow occurs in dfs_v2 dfs_file in RT-Thread through 5.0.2.

    Published: 27 Mar 2024
    7.5
    High

    CVE-2024-25354

    Last Modified: 15 Apr 2026

    RegEx Denial of Service in domain-suffix 1.0.8 allows attackers to crash the application via crafted input to the parse function.

    Published: 27 Mar 2024
    9.8
    Critical

    CVE-2024-25393

    Last Modified: 4 Nov 2025

    A stack buffer overflow occurs in net/at/src/at_server.c in RT-Thread through 5.0.2.

    Published: 27 Mar 2024
    8.4
    High

    CVE-2024-25391

    Last Modified: 4 Nov 2025

    A stack buffer overflow occurs in libc/posix/ipc/mqueue.c in RT-Thread through 5.0.2.

    Published: 27 Mar 2024
    9.1
    Critical

    CVE-2024-25735

    Last Modified: 4 Nov 2025

    An issue was discovered on WyreStorm Apollo VX20 devices before 1.3.58. Remote attackers can discover cleartext passwords via a SoftAP /device/config GET request.

    Published: 27 Mar 2024
    9.8
    Critical

    CVE-2024-28815

    Last Modified: 15 Apr 2026

    A vulnerability in the BluStar component of Mitel InAttend 2.6 SP4 through 2.7 and CMG 8.5 SP4 through 8.6 could allow access to sensitive information, changes to the system configuration, or execution of arbitrary commands within the context of the system.

    Published: 27 Mar 2024