CVE Feed

    Dashboard / CVE

    6.5
    Medium

    CVE-2024-27989

    Last Modified: 28 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in I Thirteen Web Solution WP Responsive Tabs horizontal vertical and accordion Tabs allows Stored XSS.This issue affects WP Responsive Tabs horizontal vertical and accordion Tabs: from n/a through 1.1.17.

    Published: 21 Mar 2024
    6.5
    Medium

    CVE-2024-27990

    Last Modified: 28 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in The Moneytizer allows Stored XSS.This issue affects The Moneytizer: from n/a through 9.5.20.

    Published: 21 Mar 2024
    6.5
    Medium

    CVE-2024-27991

    Last Modified: 28 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in SupportCandy allows Stored XSS.This issue affects SupportCandy: from n/a through 3.2.3.

    Published: 21 Mar 2024
    7.1
    High

    CVE-2024-27992

    Last Modified: 28 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Link Whisper Link Whisper Free allows Reflected XSS.This issue affects Link Whisper Free: from n/a through 0.6.8.

    Published: 21 Mar 2024
    7.1
    High

    CVE-2024-27993

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in typps Calendarista Basic Edition calendarista-basic-edition.This issue affects Calendarista Basic Edition: from n/a through <= 3.0.2.

    Published: 21 Mar 2024
    7.1
    High

    CVE-2024-27994

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in YITHEMES YITH WooCommerce Product Add-Ons yith-woocommerce-product-add-ons.This issue affects YITH WooCommerce Product Add-Ons: from n/a through <= 4.5.0.

    Published: 21 Mar 2024
    5.9
    Medium

    CVE-2024-27995

    Last Modified: 28 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Repute Infosystems ARMember – Membership Plugin, Content Restriction, Member Levels, User Profile & User signup allows Stored XSS.This issue affects ARMember – Membership Plugin, Content Restriction, Member Levels, User Profile & User signup: from n/a through 4.0.23.

    Published: 21 Mar 2024
    7.1
    High

    CVE-2024-2465

    Last Modified: 17 Jun 2025

    Open redirection vulnerability in CDeX application allows to redirect users to arbitrary websites via a specially crafted URL.This issue affects CDeX application versions through 5.7.1.

    Published: 21 Mar 2024
    6.3
    Medium

    CVE-2024-2464

    Last Modified: 17 Jun 2025

    This issue occurs during password recovery, where a difference in messages could allow an attacker to determine if the user is valid or not, enabling a brute force attack with valid users.This issue affects CDeX application versions through 5.7.1.

    Published: 21 Mar 2024
    8
    High

    CVE-2024-2463

    Last Modified: 17 Jun 2025

    Weak password recovery mechanism in CDeX application allows to retrieve password reset token.This issue affects CDeX application versions through 5.7.1.

    Published: 21 Mar 2024
    4.3
    Medium

    CVE-2023-47715

    Last Modified: 21 Nov 2024

    IBM Storage Protect Plus Server 10.1.0 through 10.1.16 could allow an authenticated user with read-only permissions to add or delete entries from an existing HyperVisor configuration. IBM X-Force ID: 271538.

    Published: 21 Mar 2024
    4.2
    Medium

    CVE-2024-29880

    Last Modified: 16 Dec 2024

    In JetBrains TeamCity before 2023.11 users with access to the agent machine might obtain permissions of the user running the agent process

    Published: 21 Mar 2024
    7.1
    High

    CVE-2024-29879

    Last Modified: 24 Jan 2025

    Cross-Site Scripting (XSS) vulnerability in Sentrifugo 3.2, through  /sentrifugo/index.php/index/getdepartments/format/html, 'business_id' parameter. The exploitation of this vulnerability could allow a remote user to send a specially crafted URL to the victim and steal their session data.

    Published: 21 Mar 2024
    7.1
    High

    CVE-2024-29878

    Last Modified: 24 Jan 2025

    Cross-Site Scripting (XSS) vulnerability in Sentrifugo 3.2, through  /sentrifugo/index.php/sitepreference/add, 'description' parameter. The exploitation of this vulnerability could allow a remote user to send a specially crafted URL to the victim and steal their session data.

    Published: 21 Mar 2024
    7.1
    High

    CVE-2024-29877

    Last Modified: 24 Jan 2025

    Cross-Site Scripting (XSS) vulnerability in Sentrifugo 3.2, through  /sentrifugo/index.php/expenses/expensecategories/edit, 'expense_category_name' parameter. The exploitation of this vulnerability could allow a remote user to send a specially crafted URL to the victim and steal their session data.

    Published: 21 Mar 2024
    9.8
    Critical

    CVE-2024-29876

    Last Modified: 24 Jan 2025

    SQL injection vulnerability in Sentrifugo 3.2, through  /sentrifugo/index.php/reports/activitylogreport, 'sortby' parameter. The exploitation of this vulnerability could allow a remote user to send a specially crafted query to the server and extract all the data from it.

    Published: 21 Mar 2024
    9.8
    Critical

    CVE-2024-29875

    Last Modified: 24 Jan 2025

    SQL injection vulnerability in Sentrifugo 3.2, through  /sentrifugo/index.php/default/reports/exportactiveuserrpt, 'sort_name' parameter. The exploitation of this vulnerability could allow a remote user to send a specially crafted query to the server and extract all the data from it.

    Published: 21 Mar 2024
    9.8
    Critical

    CVE-2024-29874

    Last Modified: 24 Jan 2025

    SQL injection vulnerability in Sentrifugo 3.2, through /sentrifugo/index.php/default/reports/activeuserrptpdf, 'sort_name' parameter. The exploitation of this vulnerability could allow a remote user to send a specially crafted query to the server and extract all the data from it.

    Published: 21 Mar 2024
    9.8
    Critical

    CVE-2024-29873

    Last Modified: 10 Apr 2025

    SQL injection vulnerability in Sentrifugo 3.2, through /sentrifugo/index.php/reports/businessunits/format/html, 'bunitname' parameter. The exploitation of this vulnerability could allow a remote user to send a specially crafted query to the server and extract all the data from it.

    Published: 21 Mar 2024
    9.8
    Critical

    CVE-2024-29872

    Last Modified: 24 Jan 2025

    SQL injection vulnerability in Sentrifugo 3.2, through /sentrifugo/index.php/empscreening/add, 'agencyids' parameter. The exploitation of this vulnerability could allow a remote user to send a specially crafted query to the server and extract all the data from it.

    Published: 21 Mar 2024
    9.8
    Critical

    CVE-2024-29871

    Last Modified: 24 Jan 2025

    SQL injection vulnerability in Sentrifugo 3.2, through /sentrifugo/index.php/index/getdepartments/sentrifugo/index.php/index/updatecontactnumber, 'id' parameter. The exploitation of this vulnerability could allow a remote user to send a specially crafted query to the server and extract all the data from it.

    Published: 21 Mar 2024
    9.8
    Critical

    CVE-2024-29870

    Last Modified: 24 Jan 2025

    SQL injection vulnerability in Sentrifugo 3.2, through /sentrifugo/index.php/index/getdepartments/format/html, 'business_id' parameter./sentrifugo/index.php/index/getdepartments/format/html, 'business_id' parameter. The exploitation of this vulnerability could allow a remote user to send a specially crafted query to the server and extract all the data from it.

    Published: 21 Mar 2024
    6.4
    Medium

    CVE-2024-2742

    Last Modified: 15 Apr 2026

    Operating system command injection vulnerability in Planet IGS-4215-16T2S, affecting firmware version 1.305b210528. An authenticated attacker could execute arbitrary code on the remote host by exploiting IP address functionality.

    Published: 21 Mar 2024
    7.1
    High

    CVE-2024-2741

    Last Modified: 15 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Planet IGS-4215-16T2S, affecting firmware version 1.305b210528. This vulnerability could allow a remote attacker to trick some authenticated users into performing actions in their session, such as adding or updating accounts through the Switch web interface.

    Published: 21 Mar 2024
    7.7
    High

    CVE-2024-2740

    Last Modified: 15 Apr 2026

    Information exposure vulnerability in Planet IGS-4215-16T2S, affecting firmware version 1.305b210528. This vulnerability could allow a remote attacker to access some administrative resources due to lack of proper management of the Switch web interface.

    Published: 21 Mar 2024
    9.8
    Critical

    CVE-2024-29732

    Last Modified: 15 Apr 2026

    A SQL Injection has been found on SCAN_VISIO eDocument Suite Web Viewer of Abast. This vulnerability allows an unauthenticated user to retrieve, update and delete all the information of database. This vulnerability was found on login page via "user" parameter.

    Published: 21 Mar 2024
    9.8
    Critical

    CVE-2024-27438

    Last Modified: 17 Jun 2025

    Download of Code Without Integrity Check vulnerability in Apache Doris. The jdbc driver files used for JDBC catalog is not checked and may resulting in remote command execution. Once the attacker is authorized to create a JDBC catalog, he/she can use arbitrary driver jar file with unchecked code snippet. This code snippet will be run when catalog is initializing without any check. This issue affects Apache Doris: from 1.2.0 through 2.0.4. Users are recommended to upgrade to version 2.0.5 or 2.1.x, which fixes the issue.

    Published: 21 Mar 2024
    5.3
    Medium

    CVE-2024-26307

    Last Modified: 17 Jun 2025

    Possible race condition vulnerability in Apache Doris. Some of code using `chmod()` method. This method run the risk of someone renaming the file out from under user and chmodding the wrong file. This could theoretically happen, but the impact would be minimal. This issue affects Apache Doris: before 1.2.8, before 2.0.4. Users are recommended to upgrade to version 2.0.4, which fixes the issue.

    Published: 21 Mar 2024
    9.8
    Critical

    CVE-2024-1148

    Last Modified: 15 Apr 2026

    Weak access control in OpenText PVCS Version Manager allows potential bypassing of authentication and uploading of files.

    Published: 21 Mar 2024
    9.8
    Critical

    CVE-2024-1147

    Last Modified: 15 Apr 2026

    Weak access control in OpenText PVCS Version Manager allows potential bypassing of authentication and download of files.

    Published: 21 Mar 2024
    4.7
    Medium

    CVE-2024-2754

    Last Modified: 18 Feb 2025

    A vulnerability classified as critical has been found in SourceCodester Complete E-Commerce Site 1.0. Affected is an unknown function of the file /admin/users_photo.php. The manipulation of the argument photo leads to unrestricted upload. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-257544.

    Published: 21 Mar 2024
    8.8
    High

    CVE-2024-2162

    Last Modified: 15 Apr 2026

    An OS Command Injection vulnerability in Kiloview NDI allows a low-privileged user to execute arbitrary code remotely on the device with high privileges. This issue affects Kiloview NDI N3, N3-s, N4, N20, N30, N40 and was fixed in Firmware version 2.02.0227 .

    Published: 21 Mar 2024
    9.8
    Critical

    CVE-2024-2161

    Last Modified: 15 Apr 2026

    Use of Hard-coded Credentials in Kiloview NDI allows un-authenticated users to bypass authenticationThis issue affects Kiloview NDI N3, N3-s, N4, N20, N30, N40 and was fixed in Firmware version 2.02.0227 .

    Published: 21 Mar 2024
    8.8
    High

    CVE-2024-1538

    Last Modified: 8 Apr 2026

    The File Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 7.2.4. This is due to missing or incorrect nonce validation on the wp_file_manager page that includes files through the 'lang' parameter. This makes it possible for unauthenticated attackers to include local JavaScript files that can be leveraged to achieve RCE via a forged request granted they can trick a site administrator into performing an action such as clicking on a link. This issue was partially patched in version 7.2.4, and fully patched in 7.2.5.

    Published: 21 Mar 2024
    7.8
    High

    CVE-2024-26642

    Last Modified: 4 Aug 2026

    In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: disallow anonymous set with timeout flag Anonymous sets are never used with timeout from userspace, reject this. Exception to this rule is NFT_SET_EVAL to ensure legacy meters still work.

    Published: 21 Mar 2024
    7.8
    High

    CVE-2023-52620

    Last Modified: 4 Aug 2026

    In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: disallow timeout for anonymous sets Never used from userspace, disallow these parameters.

    Published: 21 Mar 2024
    5.6
    Medium

    CVE-2024-29916

    Last Modified: 15 Apr 2026

    The dormakaba Saflok system before the November 2023 software update allows an attacker to unlock arbitrary doors at a property via forged keycards, if the attacker has obtained one active or expired keycard for the specific property, aka the "Unsaflok" issue. This occurs, in part, because the key derivation function relies only on a UID. This affects, for example, Saflok MT, and the Confidant, Quantum, RT, and Saffire series.

    Published: 21 Mar 2024
    5
    Medium

    CVE-2024-28835

    Last Modified: 15 Apr 2026

    A flaw has been discovered in GnuTLS where an application crash can be induced when attempting to verify a specially crafted .pem bundle using the "certtool --verify-chain" command.

    Published: 21 Mar 2024
    5.3
    Medium

    CVE-2024-28834

    Last Modified: 15 Apr 2026

    A flaw was found in GnuTLS. The Minerva attack is a cryptographic vulnerability that exploits deterministic behavior in systems like GnuTLS, leading to side-channel leaks. In specific scenarios, such as when using the GNUTLS_PRIVKEY_FLAG_REPRODUCIBLE flag, it can result in a noticeable step in nonce size from 513 to 512 bits, exposing a potential timing side-channel.

    Published: 21 Mar 2024
    4.5
    Medium

    CVE-2024-27281

    Last Modified: 15 Apr 2026

    An issue was discovered in RDoc 6.3.3 through 6.6.2, as distributed in Ruby 3.x through 3.3.0. When parsing .rdoc_options (used for configuration in RDoc) as a YAML file, object injection and resultant remote code execution are possible because there are no restrictions on the classes that can be restored. (When loading the documentation cache, object injection and resultant remote code execution are also possible if there were a crafted cache.) The main fixed version is 6.6.3.1. For Ruby 3.0 users, a fixed version is rdoc 6.3.4.1. For Ruby 3.1 users, a fixed version is rdoc 6.4.1.1. For Ruby 3.2 users, a fixed version is rdoc 6.5.1.1.

    Published: 21 Mar 2024
    9.8
    Critical

    CVE-2024-27280

    Last Modified: 15 Apr 2026

    A buffer-overread issue was discovered in StringIO 3.0.1, as distributed in Ruby 3.0.x through 3.0.6 and 3.1.x through 3.1.4. The ungetbyte and ungetc methods on a StringIO can read past the end of a string, and a subsequent call to StringIO.gets may return the memory value. 3.0.3 is the main fixed version; however, for Ruby 3.0 users, a fixed version is stringio 3.0.1.1, and for Ruby 3.1 users, a fixed version is stringio 3.0.1.2.

    Published: 21 Mar 2024
    6.2
    Medium

    CVE-2024-2494

    Last Modified: 15 Apr 2026

    A flaw was found in the RPC library APIs of libvirt. The RPC server deserialization code allocates memory for arrays before the non-negative length check is performed by the C API entry points. Passing a negative length to the g_new0 function results in a crash due to the negative length being treated as a huge positive number. This flaw allows a local, unprivileged user to perform a denial of service attack by causing the libvirt daemon to crash.

    Published: 21 Mar 2024
    7.8
    High

    CVE-2024-26643

    Last Modified: 4 Aug 2026

    In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: mark set as dead when unbinding anonymous set with timeout While the rhashtable set gc runs asynchronously, a race allows it to collect elements from anonymous sets with timeouts while it is being released from the commit path. Mingi Cho originally reported this issue in a different path in 6.1.x with a pipapo set with low timeouts which is not possible upstream since 7395dfacfff6 ("netfilter: nf_tables: use timestamp to check for set element timeout"). Fix this by setting on the dead flag for anonymous sets to skip async gc in this case. According to 08e4c8c5919f ("netfilter: nf_tables: mark newset as dead on transaction abort"), Florian plans to accelerate abort path by releasing objects via workqueue, therefore, this sets on the dead flag for abort path too.

    Published: 21 Mar 2024
    6.1
    Medium

    CVE-2024-28635

    Last Modified: 17 Jun 2025

    Cross Site Scripting (XSS) vulnerability in SurveyJS Survey Creator v.1.9.132 and before, allows attackers to execute arbitrary code and obtain sensitive information via the title parameter in form.

    Published: 21 Mar 2024
    6.1
    Medium

    CVE-2024-29374

    Last Modified: 1 May 2025

    A Cross-Site Scripting (XSS) vulnerability exists in the way MOODLE 3.10.9 handles user input within the "GET /?lang=" URL parameter.

    Published: 21 Mar 2024
    5.9
    Medium

    CVE-2024-28402

    Last Modified: 8 Apr 2025

    TOTOLINK X2000R before V1.0.0-B20231213.1013 contains a Stored Cross-site scripting (XSS) vulnerability in IP/Port Filtering under the Firewall Page.

    Published: 21 Mar 2024
    6.5
    Medium

    CVE-2024-28863

    Last Modified: 16 Dec 2025

    node-tar is a Tar for Node.js. node-tar prior to version 6.2.1 has no limit on the number of sub-folders created in the folder creation process. An attacker who generates a large number of sub-folders can consume memory on the system running node-tar and even crash the Node.js client within few seconds of running it using a path with too many sub-folders inside. Version 6.2.1 fixes this issue by preventing extraction in excessively deep sub-folders.

    Published: 21 Mar 2024
    5.3
    Medium

    CVE-2024-29244

    Last Modified: 17 Jun 2025

    Shenzhen Libituo Technology Co., Ltd LBT-T300-mini v1.2.9 was discovered to contain a buffer overflow via the pin_code_3g parameter at /apply.cgi.

    Published: 21 Mar 2024
    9.8
    Critical

    CVE-2023-48901

    Last Modified: 19 May 2025

    A SQL injection vulnerability in tramyardg Autoexpress version 1.3.0, allows remote unauthenticated attackers to execute arbitrary SQL commands via the parameter "id" within the getPhotosByCarId function call in details.php.

    Published: 21 Mar 2024
    9.8
    Critical

    CVE-2023-48902

    Last Modified: 19 May 2025

    An issue was discovered in tramyardg autoexpress version 1.3.0, allows unauthenticated remote attackers to escalate privileges, update car data, delete vehicles, and upload car images via authentication bypass in uploadCarImages.php.

    Published: 21 Mar 2024