CVE Feed

    Dashboard / CVE

    6.2
    Medium

    CVE-2023-45913

    Last Modified: 4 Nov 2025

    Mesa v23.0.4 was discovered to contain a NULL pointer dereference via the function dri2GetGlxDrawableFromXDrawableId(). This vulnerability is triggered when the X11 server sends an DRI2_BufferSwapComplete event unexpectedly when the application is using DRI3. NOTE: this is disputed because there is no scenario in which the vulnerability was demonstrated.

    Published: 27 Mar 2024
    4.2
    Medium

    CVE-2023-45920

    Last Modified: 4 Nov 2025

    Xfig v3.2.8 was discovered to contain a NULL pointer dereference when calling XGetWMHints(). NOTE: this is disputed because it is not expected that an X application should continue to run when there is arbitrary anomalous behavior from the X server or window manager.

    Published: 27 Mar 2024
    4.3
    Medium

    CVE-2023-45922

    Last Modified: 4 Nov 2025

    glx_pbuffer.c in Mesa 23.0.4 was discovered to contain a segmentation violation when calling __glXGetDrawableAttribute(). NOTE: this is disputed because there are no common situations in which users require uninterrupted operation with an attacker-controller server.

    Published: 27 Mar 2024
    —
    Unknown

    CVE-2023-45925

    Last Modified: 15 Apr 2026

    GNU Midnight Commander 4.8.29-146-g299d9a2fb was discovered to contain a NULL pointer dereference via the function x_error_handler() at tty/x11conn.c. NOTE: this is disputed because it should be categorized as a usability problem (an X operation silently fails).

    Published: 27 Mar 2024
    7.5
    High

    CVE-2023-45931

    Last Modified: 4 Nov 2025

    Mesa 23.0.4 was discovered to contain a NULL pointer dereference in check_xshm() for the has_error state. NOTE: this is disputed because there is no scenario in which the vulnerability was demonstrated.

    Published: 27 Mar 2024
    4.2
    Medium

    CVE-2023-45935

    Last Modified: 15 Apr 2026

    Qt 6 through 6.6 was discovered to contain a NULL pointer dereference via the function QXcbConnection::initializeAllAtoms(). NOTE: this is disputed because it is not expected that an X application should continue to run when there is arbitrary anomalous behavior from the X server.

    Published: 27 Mar 2024
    7.3
    High

    CVE-2023-46047

    Last Modified: 4 Nov 2025

    An issue in Sane 1.2.1 allows a local attacker to execute arbitrary code via a crafted file to the sanei_configure_attach() function. NOTE: this is disputed because there is no expectation that the product should be starting with an attacker-controlled configuration file.

    Published: 27 Mar 2024
    7.1
    High

    CVE-2023-46052

    Last Modified: 4 Nov 2025

    Sane 1.2.1 heap bounds overwrite in init_options() from backend/test.c via a long init_mode string in a configuration file. NOTE: this is disputed because there is no expectation that test.c code should be executed with an attacker-controlled configuration file.

    Published: 27 Mar 2024
    8.4
    High

    CVE-2024-24335

    Last Modified: 4 Nov 2025

    A heap buffer overflow occurs in the dfs_v2 romfs filesystem RT-Thread through 5.0.2.

    Published: 27 Mar 2024
    8.4
    High

    CVE-2024-25388

    Last Modified: 4 Nov 2025

    drivers/wlan/wlan_mgmt,c in RT-Thread through 5.0.2 has an integer signedness error and resultant buffer overflow.

    Published: 27 Mar 2024
    7.5
    High

    CVE-2024-25389

    Last Modified: 4 Nov 2025

    RT-Thread through 5.0.2 generates random numbers with a weak algorithm of "seed = 214013L * seed + 2531011L; return (seed >> 16) & 0x7FFF;" in calc_random in drivers/misc/rt_random.c.

    Published: 27 Mar 2024
    8.4
    High

    CVE-2024-25390

    Last Modified: 4 Nov 2025

    A heap buffer overflow occurs in finsh/msh_file.c and finsh/msh.c in RT-Thread through 5.0.2.

    Published: 27 Mar 2024
    5.9
    Medium

    CVE-2024-25392

    Last Modified: 4 Nov 2025

    An out-of-bounds access occurs in utilities/var_export/var_export.c in RT-Thread through 5.0.2.

    Published: 27 Mar 2024
    8.8
    High

    CVE-2024-25395

    Last Modified: 4 Nov 2025

    A buffer overflow occurs in utilities/rt-link/src/rtlink.c in RT-Thread through 5.0.2.

    Published: 27 Mar 2024
    7.5
    High

    CVE-2024-25734

    Last Modified: 4 Nov 2025

    An issue was discovered on WyreStorm Apollo VX20 devices before 1.3.58. The TELNET service prompts for a password only after a valid username is entered, which might make it easier for remote attackers to enumerate user accounts.

    Published: 27 Mar 2024
    7.5
    High

    CVE-2024-25736

    Last Modified: 4 Nov 2025

    An issue was discovered on WyreStorm Apollo VX20 devices before 1.3.58. Remote attackers can restart the device via a /device/reboot GET request.

    Published: 27 Mar 2024
    8.8
    High

    CVE-2024-3019

    Last Modified: 15 Apr 2026

    A flaw was found in PCP. The default pmproxy configuration exposes the Redis server backend to the local network, allowing remote command execution with the privileges of the Redis user. This issue can only be exploited when pmproxy is running. By default, pmproxy is not running and needs to be started manually. The pmproxy service is usually started from the 'Metrics settings' page of the Cockpit web interface. This flaw affects PCP versions 4.3.4 and newer.

    Published: 27 Mar 2024
    8.3
    High

    CVE-2023-40284

    Last Modified: 17 Jun 2025

    An issue was discovered on Supermicro X11SSM-F, X11SAE-F, and X11SSE-F 1.66 devices. An attacker could exploit an XSS issue.

    Published: 27 Mar 2024
    8.3
    High

    CVE-2023-40290

    Last Modified: 18 Jun 2025

    An issue was discovered on Supermicro X11SSM-F, X11SAE-F, and X11SSE-F 1.66 devices. An attacker could exploit an XSS issue that affects Internet Explorer 11 on Windows.

    Published: 27 Mar 2024
    7.3
    High

    CVE-2024-2947

    Last Modified: 15 Apr 2026

    A flaw was found in Cockpit. Deleting a sosreport with a crafted name via the Cockpit web interface can lead to a command injection vulnerability, resulting in privilege escalation. This issue affects Cockpit versions 270 and newer.

    Published: 27 Mar 2024
    4.4
    Medium

    CVE-2024-23451

    Last Modified: 4 Feb 2025

    Incorrect Authorization issue exists in the API key based security model for Remote Cluster Security, which is currently in Beta, in Elasticsearch 8.10.0 and before 8.13.0. This allows a malicious user with a valid API key for a remote cluster configured to use the new Remote Cluster Security to read arbitrary documents from any index on the remote cluster, and only if they use the Elasticsearch custom transport protocol to issue requests with the target index ID, the shard ID and the document ID. None of Elasticsearch REST API endpoints are affected by this issue.

    Published: 27 Mar 2024
    4.3
    Medium

    CVE-2024-25394

    Last Modified: 4 Nov 2025

    A buffer overflow occurs in utilities/ymodem/ry_sy.c in RT-Thread through 5.0.2 because of an incorrect sprintf call or a missing '\0' character.

    Published: 27 Mar 2024
    4.1
    Medium

    CVE-2024-26652

    Last Modified: 4 May 2025

    In the Linux kernel, the following vulnerability has been resolved: net: pds_core: Fix possible double free in error handling path When auxiliary_device_add() returns error and then calls auxiliary_device_uninit(), Callback function pdsc_auxbus_dev_release calls kfree(padev) to free memory. We shouldn't call kfree(padev) again in the error handling path. Fix this by cleaning up the redundant kfree() and putting the error handling back to where the errors happened.

    Published: 27 Mar 2024
    5.5
    Medium

    CVE-2024-26651

    Last Modified: 12 May 2026

    In the Linux kernel, the following vulnerability has been resolved: sr9800: Add check for usbnet_get_endpoints Add check for usbnet_get_endpoints() and return the error if it fails in order to transfer the error.

    Published: 27 Mar 2024
    6.1
    Medium

    CVE-2023-25364

    Last Modified: 15 Apr 2026

    Opswat Metadefender Core before 5.2.1 does not properly defend against potential HTML injection and XSS attacks.

    Published: 27 Mar 2024
    8.6
    High

    CVE-2023-29134

    Last Modified: 15 Apr 2026

    An issue was discovered in the Cargo extension for MediaWiki through 1.39.3. There is mishandling of backticks to smartSplit.

    Published: 27 Mar 2024
    6.3
    Medium

    CVE-2024-2209

    Last Modified: 20 Feb 2026

    A user with administrative privileges can create a compromised dll file of the same name as the original dll within the HP printer’s Firmware Update Utility (FUU) bundle and place it in the Microsoft Windows default downloads directory which can lead to potential arbitrary code execution.

    Published: 26 Mar 2024
    7.3
    High

    CVE-2024-2930

    Last Modified: 18 Feb 2025

    A vulnerability was found in SourceCodester Music Gallery Site 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file classes/Master.php?f=save_music. The manipulation leads to unrestricted upload. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-258001 was assigned to this vulnerability.

    Published: 26 Mar 2024
    6.5
    Medium

    CVE-2024-25138

    Last Modified: 15 Apr 2026

    In AutomationDirect C-MORE EA9 HMI, credentials used by the platform are stored as plain text on the device.

    Published: 26 Mar 2024
    7.3
    High

    CVE-2024-2927

    Last Modified: 20 Feb 2025

    A vulnerability was found in code-projects Mobile Shop 1.0. It has been classified as critical. Affected is an unknown function of the file Details.php of the component Login Page. The manipulation of the argument id leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-258000.

    Published: 26 Mar 2024
    5.4
    Medium

    CVE-2024-2917

    Last Modified: 20 Feb 2025

    A vulnerability was found in Campcodes House Rental Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file index.php. The manipulation of the argument page leads to file inclusion. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-257983.

    Published: 26 Mar 2024
    4.3
    Medium

    CVE-2024-25137

    Last Modified: 15 Apr 2026

    In AutomationDirect C-MORE EA9 HMI there is a program that copies a buffer of a size controlled by the user into a limited sized buffer on the stack which may lead to a stack overflow. The result of this stack-based buffer overflow can lead to denial-of-service conditions.

    Published: 26 Mar 2024
    7.5
    High

    CVE-2024-25136

    Last Modified: 15 Apr 2026

    There is a function in AutomationDirect C-MORE EA9 HMI that allows an attacker to send a relative path in the URL without proper sanitizing of the content.

    Published: 26 Mar 2024
    7.3
    High

    CVE-2024-2916

    Last Modified: 20 Feb 2025

    A vulnerability was found in Campcodes House Rental Management System 1.0. It has been classified as critical. Affected is an unknown function of the file ajax.php. The manipulation of the argument username leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-257982 is the identifier assigned to this vulnerability.

    Published: 26 Mar 2024
    6.9
    Medium

    CVE-2024-2911

    Last Modified: 21 Aug 2025

    A vulnerability, which was classified as problematic, was found in Tianjin PubliCMS 4.0.202302.e. This affects an unknown part. The manipulation leads to cross-site request forgery. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 26 Mar 2024
    6.3
    Medium

    CVE-2024-2910

    Last Modified: 3 Nov 2025

    A vulnerability, which was classified as critical, has been found in Ruijie RG-EG350 up to 20240318. Affected by this issue is the function vpnAction of the file /itbox_pi/vpn_quickset_service.php?a=set_vpn of the component HTTP POST Request Handler. The manipulation of the argument ip/port/user/pass/dns/startIp leads to os command injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-257978 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 26 Mar 2024
    8.8
    High

    CVE-2024-2909

    Last Modified: 3 Nov 2025

    A vulnerability classified as critical was found in Ruijie RG-EG350 up to 20240318. Affected by this vulnerability is the function setAction of the file /itbox_pi/networksafe.php?a=set of the component HTTP POST Request Handler. The manipulation of the argument bandwidth leads to os command injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-257977 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 26 Mar 2024
    9.9
    Critical

    CVE-2023-48777

    Last Modified: 28 Apr 2026

    Unrestricted Upload of File with Dangerous Type vulnerability in Elementor.Com Elementor Website Builder.This issue affects Elementor Website Builder: from 3.3.0 through 3.18.1.

    Published: 26 Mar 2024
    8
    High

    CVE-2023-48275

    Last Modified: 28 Apr 2026

    Unrestricted Upload of File with Dangerous Type vulnerability in Trustindex.Io Widgets for Google Reviews.This issue affects Widgets for Google Reviews: from n/a through 11.0.2.

    Published: 26 Mar 2024
    8.5
    High

    CVE-2023-39307

    Last Modified: 28 Apr 2026

    Unrestricted Upload of File with Dangerous Type vulnerability in ThemeFusion Avada.This issue affects Avada: from n/a through 7.11.1.

    Published: 26 Mar 2024
    9
    Critical

    CVE-2023-38388

    Last Modified: 28 Apr 2026

    Unrestricted Upload of File with Dangerous Type vulnerability in Artbees JupiterX Core.This issue affects JupiterX Core: from n/a through 3.3.5.

    Published: 26 Mar 2024
    9.1
    Critical

    CVE-2023-47873

    Last Modified: 28 Apr 2026

    Unrestricted Upload of File with Dangerous Type vulnerability in WEN Solutions WP Child Theme Generator.This issue affects WP Child Theme Generator: from n/a through 1.0.9.

    Published: 26 Mar 2024
    9.1
    Critical

    CVE-2023-47846

    Last Modified: 28 Apr 2026

    Unrestricted Upload of File with Dangerous Type vulnerability in Terry Lin WP Githuber MD.This issue affects WP Githuber MD: from n/a through 1.16.2.

    Published: 26 Mar 2024
    8.8
    High

    CVE-2024-2903

    Last Modified: 22 Jan 2025

    A vulnerability was found in Tenda AC7 15.03.06.44. It has been classified as critical. Affected is the function GetParentControlInfo of the file /goform/GetParentControlInfo. The manipulation of the argument mac leads to stack-based buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-257946 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 26 Mar 2024
    9.1
    Critical

    CVE-2023-47842

    Last Modified: 28 Apr 2026

    Unrestricted Upload of File with Dangerous Type vulnerability in Zachary Segal CataBlog.This issue affects CataBlog: from n/a through 1.7.0.

    Published: 26 Mar 2024
    9.1
    Critical

    CVE-2023-29386

    Last Modified: 28 Apr 2026

    Unrestricted Upload of File with Dangerous Type vulnerability in Julien Crego Manager for Icomoon.This issue affects Manager for Icomoon: from n/a through 2.0.

    Published: 26 Mar 2024
    4.9
    Medium

    CVE-2024-26303

    Last Modified: 15 Apr 2026

    Authenticated Denial of Service Vulnerability in ArubaOS-Switch SSH Daemon

    Published: 26 Mar 2024
    9.3
    Critical

    CVE-2023-28787

    Last Modified: 28 Apr 2026

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ExpressTech Quiz And Survey Master.This issue affects Quiz And Survey Master: from n/a through 8.1.4.

    Published: 26 Mar 2024
    7.1
    High

    CVE-2023-28687

    Last Modified: 28 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in perfectwpthemes Glaze Blog Lite, themebeez Fascinate, themebeez Cream Blog, themebeez Cream Magazine allows Reflected XSS.This issue affects Glaze Blog Lite: from n/a through <= 1.1.4; Fascinate: from n/a through 1.0.8; Cream Blog: from n/a through 2.1.3; Cream Magazine: from n/a through 2.1.4.

    Published: 26 Mar 2024
    7.7
    High

    CVE-2024-2887

    Last Modified: 28 Mar 2025

    Type Confusion in WebAssembly in Google Chrome prior to 123.0.6312.86 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)

    Published: 26 Mar 2024