CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2023-47150

    Last Modified: 4 Feb 2026

    IBM Common Cryptographic Architecture (CCA) 7.0.0 through 7.5.36 could allow a remote user to cause a denial of service due to incorrect data handling for certain types of AES operations. IBM X-Force ID: 270602.

    Published: 26 Mar 2024
    8.8
    High

    CVE-2024-2891

    Last Modified: 22 Jan 2025

    A vulnerability, which was classified as critical, was found in Tenda AC7 15.03.06.44. Affected is the function formQuickIndex of the file /goform/QuickIndex. The manipulation of the argument PPPOEPassword leads to stack-based buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-257934 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 26 Mar 2024
    4.9
    Medium

    CVE-2024-29883

    Last Modified: 2 Jan 2026

    CreateWiki is Miraheze's MediaWiki extension for requesting & creating wikis. Suppression of wiki requests does not work as intended, and always restricts visibility to those with the `(createwiki)` user right regardless of the settings one sets on a given wiki request. This may expose information to users who are not supposed to be able to access it.

    Published: 26 Mar 2024
    4.3
    Medium

    CVE-2024-29881

    Last Modified: 2 Sept 2025

    TinyMCE is an open source rich text editor. A cross-site scripting (XSS) vulnerability was discovered in TinyMCE’s content loading and content inserting code. A SVG image could be loaded though an `object` or `embed` element and that image could potentially contain a XSS payload. This vulnerability is fixed in 6.8.1 and 7.0.0.

    Published: 26 Mar 2024
    4.3
    Medium

    CVE-2024-29203

    Last Modified: 2 Sept 2025

    TinyMCE is an open source rich text editor. A cross-site scripting (XSS) vulnerability was discovered in TinyMCE’s content insertion code. This allowed `iframe` elements containing malicious code to execute when inserted into the editor. These `iframe` elements are restricted in their permissions by same-origin browser protections, but could still trigger operations such as downloading of malicious assets. This vulnerability is fixed in 6.8.1.

    Published: 26 Mar 2024
    7.1
    High

    CVE-2024-1933

    Last Modified: 15 Apr 2026

    Insecure UNIX Symbolic Link (Symlink) Following in TeamViewer Remote Client prior Version 15.52 for macOS allows an attacker with unprivileged access, to potentially elevate privileges or conduct a denial-of-service-attack by overwriting the symlink.

    Published: 26 Mar 2024
    4.3
    Medium

    CVE-2023-52214

    Last Modified: 28 Apr 2026

    Missing Authorization vulnerability in voidCoders Void Contact Form 7 Widget For Elementor Page Builder.This issue affects Void Contact Form 7 Widget For Elementor Page Builder: from n/a through 2.3.

    Published: 26 Mar 2024
    6.5
    Medium

    CVE-2024-22156

    Last Modified: 28 Apr 2026

    Missing Authorization vulnerability in SNP Digital SalesKing.This issue affects SalesKing: from n/a through 1.6.15.

    Published: 26 Mar 2024
    6.5
    Medium

    CVE-2024-2906

    Last Modified: 28 Apr 2026

    Missing Authorization vulnerability in SoftLab Radio Player.This issue affects Radio Player: from n/a through 2.0.73.

    Published: 26 Mar 2024
    4.3
    Medium

    CVE-2024-30235

    Last Modified: 28 Apr 2026

    Missing Authorization vulnerability in Themeisle Multiple Page Generator Plugin – MPG.This issue affects Multiple Page Generator Plugin – MPG: from n/a through 3.4.0.

    Published: 26 Mar 2024
    6.5
    Medium

    CVE-2024-30234

    Last Modified: 28 Apr 2026

    Missing Authorization vulnerability in Wholesale Team WholesaleX.This issue affects WholesaleX: from n/a through 1.3.1.

    Published: 26 Mar 2024
    6.5
    Medium

    CVE-2024-30233

    Last Modified: 28 Apr 2026

    Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wholesale Team WholesaleX.This issue affects WholesaleX: from n/a through 1.3.1.

    Published: 26 Mar 2024
    6.5
    Medium

    CVE-2024-30232

    Last Modified: 28 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Exclusive Addons Exclusive Addons Elementor allows Stored XSS.This issue affects Exclusive Addons Elementor: from n/a through 2.6.9.

    Published: 26 Mar 2024
    9.1
    Critical

    CVE-2024-30231

    Last Modified: 28 Apr 2026

    Unrestricted Upload of File with Dangerous Type vulnerability in WebToffee Product Import Export for WooCommerce.This issue affects Product Import Export for WooCommerce: from n/a through 2.4.1.

    Published: 26 Mar 2024
    4.3
    Medium

    CVE-2024-23520

    Last Modified: 28 Apr 2026

    Missing Authorization vulnerability in AccessAlly PopupAlly.This issue affects PopupAlly: from n/a through 2.1.0.

    Published: 26 Mar 2024
    4.3
    Medium

    CVE-2024-24711

    Last Modified: 28 Apr 2026

    Missing Authorization vulnerability in weDevs WooCommerce Conversion Tracking.This issue affects WooCommerce Conversion Tracking: from n/a through 2.0.11.

    Published: 26 Mar 2024
    4.3
    Medium

    CVE-2024-24718

    Last Modified: 28 Apr 2026

    Missing Authorization vulnerability in PropertyHive.This issue affects PropertyHive: from n/a through 2.0.6.

    Published: 26 Mar 2024
    4.3
    Medium

    CVE-2024-24719

    Last Modified: 28 Apr 2026

    Missing Authorization vulnerability in Uriahs Victor Location Picker at Checkout for WooCommerce.This issue affects Location Picker at Checkout for WooCommerce: from n/a through 1.8.9.

    Published: 26 Mar 2024
    6.5
    Medium

    CVE-2024-24799

    Last Modified: 28 Apr 2026

    Missing Authorization vulnerability in WooCommerce WooCommerce Box Office.This issue affects WooCommerce Box Office: from n/a through 1.2.2.

    Published: 26 Mar 2024
    5.9
    Medium

    CVE-2024-1455

    Last Modified: 30 Jul 2025

    A vulnerability in the langchain-ai/langchain repository allows for a Billion Laughs Attack, a type of XML External Entity (XXE) exploitation. By nesting multiple layers of entities within an XML document, an attacker can cause the XML parser to consume excessive CPU and memory resources, leading to a denial of service (DoS).

    Published: 26 Mar 2024
    6.1
    Medium

    CVE-2024-28126

    Last Modified: 15 Apr 2026

    Cross-site scripting vulnerability exists in 0ch BBS Script ver.4.00. An arbitrary script may be executed on the web browser of the user accessing the website that uses the product. Note that the developer was unreachable, therefore, users should consider stop using 0ch BBS Script ver.4.00.

    Published: 26 Mar 2024
    4.3
    Medium

    CVE-2024-2904

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Extend Themes Calliope.This issue affects Calliope: from n/a through 1.0.33.

    Published: 26 Mar 2024
    9.8
    Critical

    CVE-2024-28048

    Last Modified: 15 Apr 2026

    OS command injection vulnerability exists in ffBull ver.4.11, which may allow a remote unauthenticated attacker to execute an arbitrary OS command with the privilege of the running web server. Note that the developer was unreachable, therefore, users should consider stop using ffBull ver.4.11.

    Published: 26 Mar 2024
    5.4
    Medium

    CVE-2024-28034

    Last Modified: 15 Apr 2026

    Cross-site scripting vulnerability exists in Mini Thread Version 3.33βi. An arbitrary script may be executed on the web browser of the user accessing the website that uses the product. Note that the developer was unreachable, therefore, users should consider stop using Mini Thread Version 3.33βi.

    Published: 26 Mar 2024
    7.3
    High

    CVE-2024-28033

    Last Modified: 15 Apr 2026

    OS command injection vulnerability exists in WebProxy 1.7.8 and 1.7.9, which may allow a remote unauthenticated attacker to execute an arbitrary OS command with the privilege of the running web server. Note that the developer was unreachable, therefore, users should consider stop using WebProxy 1.7.8 and 1.7.9.

    Published: 26 Mar 2024
    6.1
    Medium

    CVE-2024-26018

    Last Modified: 15 Apr 2026

    Cross-site scripting vulnerability exists in TvRock 0.9t8a. An arbitrary script may be executed on the web browser of the user accessing the website that uses the product. Note that the developer was unreachable, therefore, users should consider stop using TvRock 0.9t8a.

    Published: 26 Mar 2024
    7.8
    High

    CVE-2024-28131

    Last Modified: 15 Apr 2026

    EasyRange Ver 1.41 contains an issue with the executable file search path when displaying an extracted file on Explorer, which may lead to loading an executable file resides in the same folder where the extracted file is placed. If this vulnerability is exploited, arbitrary code may be executed with the privilege of the running program. Note that the developer was unreachable, therefore, users should consider stop using EasyRange Ver 1.41.

    Published: 26 Mar 2024
    5.3
    Medium

    CVE-2024-24805

    Last Modified: 28 Apr 2026

    Missing Authorization vulnerability in Deepak anand WP Dummy Content Generator.This issue affects WP Dummy Content Generator: from n/a through 3.1.2.

    Published: 26 Mar 2024
    7.6
    High

    CVE-2023-23991

    Last Modified: 28 Apr 2026

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WPdevelop / Oplugins Booking Calendar allows SQL Injection.This issue affects Booking Calendar: from n/a through 9.4.3.

    Published: 26 Mar 2024
    5.4
    Medium

    CVE-2023-32237

    Last Modified: 28 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CodexThemes TheGem (Elementor), CodexThemes TheGem (WPBakery) allows Stored XSS.This issue affects TheGem (Elementor): from n/a before 5.8.1.1; TheGem (WPBakery): from n/a before 5.8.1.1.

    Published: 26 Mar 2024
    7.1
    High

    CVE-2023-33322

    Last Modified: 28 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Etoile Web Design Front End Users allows Reflected XSS.This issue affects Front End Users: from n/a before 3.2.25.

    Published: 26 Mar 2024
    6.5
    Medium

    CVE-2023-7251

    Last Modified: 28 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jeff Starr User Submitted Posts allows Stored XSS.This issue affects User Submitted Posts: from n/a through 20230901.

    Published: 26 Mar 2024
    —
    Unknown

    CVE-2023-41696

    Last Modified: 26 Mar 2024

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

    Published: 26 Mar 2024
    7.1
    High

    CVE-2023-45771

    Last Modified: 28 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Contact Form With Captcha allows Reflected XSS.This issue affects Contact Form With Captcha: from n/a through 1.6.8.

    Published: 26 Mar 2024
    4.3
    Medium

    CVE-2023-49838

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in KlbTheme Clotya theme, KlbTheme Cosmetsy theme, KlbTheme Furnob theme, KlbTheme Bacola theme, KlbTheme Partdo theme, KlbTheme Medibazar theme, KlbTheme Machic theme.This issue affects Clotya theme: from n/a through 1.1.6; Cosmetsy theme: from n/a through 1.7.7; Furnob theme: from n/a through 1.2.2; Bacola theme: from n/a through 1.3.3; Partdo theme: from n/a through 1.1.1; Medibazar theme: from n/a through 1.8.6; Machic theme: from n/a through 1.2.8.

    Published: 26 Mar 2024
    7.1
    High

    CVE-2023-49839

    Last Modified: 28 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in KlbTheme Cosmetsy theme (core plugin), KlbTheme Partdo theme (core plugin), KlbTheme Bacola theme (core plugin), KlbTheme Medibazar theme (core plugin), KlbTheme Furnob theme (core plugin), KlbTheme Clotya theme (core plugin) allows Reflected XSS.This issue affects Cosmetsy theme (core plugin): from n/a through 1.3.0; Partdo theme (core plugin): from n/a through 1.0.9; Bacola theme (core plugin): from n/a through 1.3.3; Medibazar theme (core plugin): from n/a through 1.2.3; Furnob theme (core plugin): from n/a through 1.1.7; Clotya theme (core plugin): from n/a through 1.1.5.

    Published: 26 Mar 2024
    6.5
    Medium

    CVE-2023-51416

    Last Modified: 15 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in EnvialoSimple EnvíaloSimple.This issue affects EnvíaloSimple: from n/a through 2.2.

    Published: 26 Mar 2024
    5.9
    Medium

    CVE-2024-2889

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Lab WP-Lister Lite for Amazon wp-lister-for-amazon.This issue affects WP-Lister Lite for Amazon: from n/a through <= 2.6.11.

    Published: 26 Mar 2024
    6.5
    Medium

    CVE-2024-2888

    Last Modified: 28 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in BoldGrid Post and Page Builder by BoldGrid – Visual Drag and Drop Editor allows Stored XSS.This issue affects Post and Page Builder by BoldGrid – Visual Drag and Drop Editor: from n/a through 1.26.2.

    Published: 26 Mar 2024
    6.4
    Medium

    CVE-2024-2303

    Last Modified: 15 Apr 2026

    The Easy Textillate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'textillate' shortcode in all versions up to, and including, 2.01 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 26 Mar 2024
    5.3
    Medium

    CVE-2023-7232

    Last Modified: 7 May 2025

    The Backup and Restore WordPress WordPress plugin through 1.45 does not protect some log files containing sensitive information such as site configuration etc, allowing unauthenticated users to access such data

    Published: 26 Mar 2024
    6.4
    Medium

    CVE-2024-2170

    Last Modified: 8 Apr 2026

    The VK All in One Expansion Unit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the child page index widget in all versions up to, and including, 9.96.0.1 due to insufficient input sanitization and output escaping on user supplied attributes such as 'className.' This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 26 Mar 2024
    3.7
    Low

    CVE-2024-29199

    Last Modified: 26 Aug 2025

    Nautobot is a Network Source of Truth and Network Automation Platform. A number of Nautobot URL endpoints were found to be improperly accessible to unauthenticated (anonymous) users. These endpoints will not disclose any Nautobot data to an unauthenticated user unless the Nautobot configuration variable EXEMPT_VIEW_PERMISSIONS is changed from its default value (an empty list) to permit access to specific data by unauthenticated users. This vulnerability is fixed in 1.6.16 and 2.1.9.

    Published: 26 Mar 2024
    8.1
    High

    CVE-2024-0866

    Last Modified: 15 Apr 2026

    The Check & Log Email plugin for WordPress is vulnerable to Unauthenticated Hook Injection in all versions up to, and including, 1.0.9 via the check_nonce function. This makes it possible for unauthenticated attackers to execute actions with hooks in WordPress under certain circumstances. The action the attacker wishes to execute needs to have a nonce check, and the nonce needs to be known to the attacker. Furthermore, the absence of a capability check is a requirement.

    Published: 26 Mar 2024
    3.8
    Low

    CVE-2024-29196

    Last Modified: 9 Jan 2025

    phpMyFAQ is an open source FAQ web application for PHP 8.1+ and MySQL, PostgreSQL and other databases. There is a Path Traversal vulnerability in Attachments that allows attackers with admin rights to upload malicious files to other locations of the web root. This vulnerability is fixed in 3.2.6.

    Published: 26 Mar 2024
    6
    Medium

    CVE-2024-29195

    Last Modified: 15 Dec 2025

    The azure-c-shared-utility is a C library for AMQP/MQTT communication to Azure Cloud Services. This library may be used by the Azure IoT C SDK for communication between IoT Hub and IoT Hub devices. An attacker can cause an integer wraparound or under-allocation or heap buffer overflow due to vulnerabilities in parameter checking mechanism, by exploiting the buffer length parameter in Azure C SDK, which may lead to remote code execution. Requirements for RCE are 1. Compromised Azure account allowing malformed payloads to be sent to the device via IoT Hub service, 2. By passing IoT hub service max message payload limit of 128KB, and 3. Ability to overwrite code space with remote code. Fixed in commit https://github.com/Azure/azure-c-shared-utility/commit/1129147c38ac02ad974c4c701a1e01b2141b9fe2.

    Published: 26 Mar 2024
    7.4
    High

    CVE-2024-29189

    Last Modified: 15 Dec 2025

    PyAnsys Geometry is a Python client library for the Ansys Geometry service and other CAD Ansys products. On file src/ansys/geometry/core/connection/product_instance.py, upon calling this method _start_program directly, users could exploit its usage to perform malicious operations on the current machine where the script is ran. This vulnerability is fixed in 0.3.3 and 0.4.12.

    Published: 26 Mar 2024
    5.4
    Medium

    CVE-2024-2732

    Last Modified: 8 Apr 2026

    The Themify Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'themify_post_slider shortcode in all versions up to, and including, 2.0.8 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 26 Mar 2024
    4.3
    Medium

    CVE-2024-1745

    Last Modified: 7 May 2025

    The Testimonial Slider WordPress plugin before 2.3.7 does not properly ensure that a user has the necessary capabilities to edit certain sensitive Testimonial Slider WordPress plugin before 2.3.7 settings, making it possible for users with at least the Author role to edit them.

    Published: 26 Mar 2024
    8
    High

    CVE-2023-51148

    Last Modified: 5 Jul 2026

    An issue in TRENDnet Trendnet AC1200 Dual Band PoE Indoor Wireless Access Point TEW-821DAP v.3.00b06 allows an attacker to execute arbitrary code via the 'mycli' command-line interface component.

    Published: 26 Mar 2024