CVE Feed

    Dashboard / CVE

    6.7
    Medium

    CVE-2023-32633

    Last Modified: 15 Apr 2026

    Improper input validation in the Intel(R) CSME installer software before version 2328.5.5.0 may allow an authenticated user to potentially enable escalation of privilege via local access.

    Published: 14 Mar 2024
    6.7
    Medium

    CVE-2023-28389

    Last Modified: 15 Apr 2026

    Incorrect default permissions in some Intel(R) CSME installer software before version 2328.5.5.0 may allow an authenticated user to potentially enable escalation of privilege via local access.

    Published: 14 Mar 2024
    6.8
    Medium

    CVE-2023-35191

    Last Modified: 15 Apr 2026

    Uncontrolled resource consumption for some Intel(R) SPS firmware versions may allow a privileged user to potentially enable denial of service via network access.

    Published: 14 Mar 2024
    7.2
    High

    CVE-2023-32282

    Last Modified: 15 Apr 2026

    Race condition in BIOS firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via local access.

    Published: 14 Mar 2024
    7.2
    High

    CVE-2023-32666

    Last Modified: 15 Apr 2026

    On-chip debug and test interface with improper access control in some 4th Generation Intel(R) Xeon(R) Processors when using Intel(R) SGX or Intel(R) TDX may allow a privileged user to potentially enable escalation of privilege via local access.

    Published: 14 Mar 2024
    7.2
    High

    CVE-2024-1713

    Last Modified: 23 Jan 2025

    A user who can create objects in a database with plv8 3.2.1 installed is able to cause deferred triggers to execute as the Superuser during autovacuum.

    Published: 14 Mar 2024
    7.7
    High

    CVE-2023-50168

    Last Modified: 10 Mar 2025

    Pega Platform from 6.x to 8.8.4 is affected by an XXE issue with PDF Generation.

    Published: 14 Mar 2024
    6.5
    Medium

    CVE-2024-25156

    Last Modified: 23 Jan 2025

    A path traversal vulnerability exists in GoAnywhere MFT prior to 7.4.2 which allows attackers to circumvent endpoint-specific permission checks in the GoAnywhere Admin and Web Clients.

    Published: 14 Mar 2024
    5.5
    Medium

    CVE-2024-0313

    Last Modified: 15 Apr 2026

    A malicious insider exploiting this vulnerability can circumvent existing security controls put in place by the organization. On the contrary, if the victim is legitimately using the temporary bypass to reach out to the Internet for retrieving application and system updates, a remote device could target it and undo the bypass, thereby denying the victim access to the update service, causing it to fail.

    Published: 14 Mar 2024
    5.5
    Medium

    CVE-2024-0312

    Last Modified: 15 Apr 2026

    A malicious insider can uninstall Skyhigh Client Proxy without a valid uninstall password.

    Published: 14 Mar 2024
    5.5
    Medium

    CVE-2024-0311

    Last Modified: 15 Apr 2026

    A malicious insider can bypass the existing policy of Skyhigh Client Proxy without a valid release code.

    Published: 14 Mar 2024
    7.7
    High

    CVE-2024-1623

    Last Modified: 23 Jan 2025

    Insufficient session timeout vulnerability in the FAST3686 V2 Vodafone router from Sagemcom. This vulnerability could allow a local attacker to access the administration panel without requiring login credentials. This vulnerability is possible because the 'Login.asp and logout.asp' files do not handle session details correctly.

    Published: 14 Mar 2024
    8.1
    High

    CVE-2024-28746

    Last Modified: 20 Mar 2025

    Apache Airflow, versions 2.8.0 through 2.8.2, has a vulnerability that allows an authenticated user with limited permissions to access resources such as variables, connections, etc from the UI which they do not have permission to access.  Users of Apache Airflow are recommended to upgrade to version 2.8.3 or newer to mitigate the risk associated with this vulnerability

    Published: 14 Mar 2024
    6.5
    Medium

    CVE-2024-27986

    Last Modified: 28 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Livemesh Elementor Addons by Livemesh allows Stored XSS.This issue affects Elementor Addons by Livemesh: from n/a through 8.3.5.

    Published: 14 Mar 2024
    4.9
    Medium

    CVE-2024-22398

    Last Modified: 15 Apr 2026

    An improper Limitation of a Pathname to a Restricted Directory (Path Traversal) vulnerability in SonicWall Email Security Appliance could allow a remote attacker with administrative privileges to conduct a directory traversal attack and delete arbitrary files from the appliance file system.

    Published: 14 Mar 2024
    8.3
    High

    CVE-2024-22397

    Last Modified: 15 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in the SonicOS SSLVPN portal allows a remote authenticated attacker as a firewall 'admin' user to store and execute arbitrary JavaScript code.

    Published: 14 Mar 2024
    5.3
    Medium

    CVE-2024-22396

    Last Modified: 15 Apr 2026

    An Integer-based buffer overflow vulnerability in the SonicOS via IPSec allows a remote attacker in specific conditions to cause Denial of Service (DoS) and potentially execute arbitrary code by sending a specially crafted IKEv2 payload.

    Published: 14 Mar 2024
    6.5
    Medium

    CVE-2024-1884

    Last Modified: 23 Jan 2025

    This is a Server-Side Request Forgery (SSRF) vulnerability in the PaperCut NG/MF server-side module that allows an attacker to induce the server-side application to make HTTP requests to an arbitrary domain of the attacker's choosing.

    Published: 14 Mar 2024
    6.3
    Medium

    CVE-2024-1883

    Last Modified: 23 Jan 2025

    This is a reflected cross site scripting vulnerability in the PaperCut NG/MF application server. An attacker can exploit this weakness by crafting a malicious URL that contains a script. When an unsuspecting user clicks on this malicious link, it could potentially lead to limited loss of confidentiality, integrity or availability.

    Published: 14 Mar 2024
    7.2
    High

    CVE-2024-1882

    Last Modified: 23 Jan 2025

    This vulnerability allows an already authenticated admin user to create a malicious payload that could be leveraged for remote code execution on the server hosting the PaperCut NG/MF application server.

    Published: 14 Mar 2024
    5.5
    Medium

    CVE-2024-26475

    Last Modified: 27 Mar 2025

    An issue in radareorg radare2 v.0.9.7 through v.5.8.6 and fixed in v.5.8.8 allows a local attacker to cause a denial of service via the grub_sfs_read_extent function.

    Published: 14 Mar 2024
    9.8
    Critical

    CVE-2024-28391

    Last Modified: 10 Jun 2025

    SQL injection vulnerability in FME Modules quickproducttable module for PrestaShop v.1.2.1 and before, allows a remote attacker to escalate privileges and obtain information via the readCsv(), displayAjaxProductChangeAttr, displayAjaxProductAddToCart, getSearchProducts, and displayAjaxProductSku methods.

    Published: 14 Mar 2024
    9.3
    Critical

    CVE-2024-28752

    Last Modified: 27 Jun 2025

    A SSRF vulnerability using the Aegis DataBinding in versions of Apache CXF before 4.0.4, 3.6.3 and 3.5.8 allows an attacker to perform SSRF style attacks on webservices that take at least one parameter of any type. Users of other data bindings (including the default databinding) are not impacted.

    Published: 14 Mar 2024
    9.8
    Critical

    CVE-2024-28388

    Last Modified: 18 Sept 2025

    SQL injection vulnerability in SunnyToo stproductcomments module for PrestaShop v.1.0.5 and before, allows a remote attacker to escalate privileges and obtain sensitive information via the StProductCommentClass::getListcomments method.

    Published: 14 Mar 2024
    9.8
    Critical

    CVE-2024-28423

    Last Modified: 18 Sept 2025

    Airflow-Diagrams v2.1.0 was discovered to contain an arbitrary file upload vulnerability in the unsafe_load function at cli.py. This vulnerability allows attackers to execute arbitrary code via uploading a crafted YML file.

    Published: 14 Mar 2024
    9.8
    Critical

    CVE-2023-42286

    Last Modified: 16 Apr 2025

    There is a PHP file inclusion vulnerability in the template configuration of eyoucms v1.6.4, allowing attackers to execute code or system commands through a carefully crafted malicious payload.

    Published: 14 Mar 2024
    8.8
    High

    CVE-2023-50677

    Last Modified: 28 Jul 2025

    An issue in NETGEAR-DGND4000 v.1.1.00.15_1.00.15 allows a remote attacker to escalate privileges via the next_file parameter to the /setup.cgi component.

    Published: 14 Mar 2024
    10
    Critical

    CVE-2024-25139

    Last Modified: 18 Sept 2025

    In TP-Link Omada er605 1.0.1 through (v2.6) 2.2.3, a cloud-brd binary is susceptible to an integer overflow that leads to a heap-based buffer overflow. After heap shaping, an attacker can achieve code execution in the context of the cloud-brd binary that runs at the root level. This is fixed in ER605(UN)_v2_2.2.4 Build 020240119.

    Published: 14 Mar 2024
    6.7
    Medium

    CVE-2024-25649

    Last Modified: 13 Nov 2025

    In Delinea PAM Secret Server 11.4, it is possible for an attacker (with Administrator access to the Secret Server machine) to read the following data from a memory dump: the decrypted master key, database credentials (when SQL Server Authentication is enabled), the encryption key of RabbitMQ queue messages, and session cookies.

    Published: 14 Mar 2024
    9.1
    Critical

    CVE-2024-26503

    Last Modified: 10 Jun 2025

    Unrestricted File Upload vulnerability in Greek Universities Network Open eClass v.3.15 and earlier allows attackers to run arbitrary code via upload of crafted file to certbadge.php endpoint.

    Published: 14 Mar 2024
    6.5
    Medium

    CVE-2024-28323

    Last Modified: 1 Apr 2025

    The bwdates-report-result.php file in Phpgurukul User Registration & Login and User Management System 3.1 contains a potential security vulnerability related to user input validation. The script retrieves user-provided date inputs without proper validation, making it susceptible to SQL injection attacks.

    Published: 14 Mar 2024
    9.8
    Critical

    CVE-2024-28383

    Last Modified: 13 Mar 2025

    Tenda AX12 v1.0 v22.03.01.16 was discovered to contain a stack overflow via the ssid parameter in the sub_431CF0 function.

    Published: 14 Mar 2024
    6.3
    Medium

    CVE-2024-28417

    Last Modified: 30 Apr 2025

    Webedition CMS 9.2.2.0 has a Stored XSS vulnerability via /webEdition/we_cmd.php.

    Published: 14 Mar 2024
    6.5
    Medium

    CVE-2024-28418

    Last Modified: 30 Apr 2025

    Webedition CMS 9.2.2.0 has a File upload vulnerability via /webEdition/we_cmd.php

    Published: 14 Mar 2024
    7.5
    High

    CVE-2024-28425

    Last Modified: 18 Sept 2025

    greykite v1.0.0 was discovered to contain an arbitrary file upload vulnerability in the load_obj function at /templates/pickle_utils.py. This vulnerability allows attackers to execute arbitrary code via uploading a crafted file.

    Published: 14 Mar 2024
    8.8
    High

    CVE-2024-28424

    Last Modified: 5 May 2025

    zenml v0.55.4 was discovered to contain an arbitrary file upload vulnerability in the load function at /materializers/cloudpickle_materializer.py. This vulnerability allows attackers to execute arbitrary code via uploading a crafted file.

    Published: 14 Mar 2024
    6.5
    Medium

    CVE-2024-28849

    Last Modified: 5 Dec 2025

    follow-redirects is an open source, drop-in replacement for Node's `http` and `https` modules that automatically follows redirects. In affected versions follow-redirects only clears authorization header during cross-domain redirect, but keep the proxy-authentication header which contains credentials too. This vulnerability may lead to credentials leak, but has been addressed in version 1.15.6. Users are advised to upgrade. There are no known workarounds for this vulnerability.

    Published: 14 Mar 2024
    6.5
    Medium

    CVE-2024-29156

    Last Modified: 25 Mar 2025

    In OpenStack Murano through 16.0.0, when YAQL before 3.0.0 is used, the Murano service's MuranoPL extension to the YAQL language fails to sanitize the supplied environment, leading to potential leakage of sensitive service account information.

    Published: 14 Mar 2024
    8.8
    High

    CVE-2024-25228

    Last Modified: 4 Nov 2025

    Vinchin Backup and Recovery 7.2 and Earlier is vulnerable to Authenticated Remote Code Execution (RCE) via the getVerifydiyResult function in ManoeuvreHandler.class.php.

    Published: 14 Mar 2024
    7.6
    High

    CVE-2024-25652

    Last Modified: 10 Oct 2025

    In Delinea PAM Secret Server 11.4, it is possible for a user assigned "Administer Reports" permission and/or with access to Report functionality via UNLIMITED ADMIN MODE (with access to the Report functionality) to gain unauthorized access to remote sessions created by legitimate users through information obtained from the Custom Legacy Report functionality.

    Published: 14 Mar 2024
    9.8
    Critical

    CVE-2024-28390

    Last Modified: 19 Nov 2025

    An issue in Advanced Plugins ultimateimagetool module for PrestaShop before v.2.2.01, allows a remote attacker to escalate privileges and obtain sensitive information via Improper Access Control.

    Published: 14 Mar 2024
    5.9
    Medium

    CVE-2024-25650

    Last Modified: 10 Oct 2025

    Insecure key exchange between Delinea PAM Secret Server 11.4 and the Distributed Engine 8.4.3 allows a PAM administrator to obtain the Symmetric Key (used to encrypt RabbitMQ messages) via crafted payloads to the /pre-authenticate, /authenticate, and /execute-and-respond REST API endpoints. This makes it possible for a PAM administrator to impersonate the Engine and exfiltrate sensitive information from the messages published in the RabbitMQ exchanges, without being audited in the application.

    Published: 14 Mar 2024
    5.3
    Medium

    CVE-2024-25651

    Last Modified: 14 Oct 2025

    User enumeration can occur in the Authentication REST API in Delinea PAM Secret Server 11.4. This allows a remote attacker to determine whether a user is valid because of a difference in responses from the /oauth2/token endpoint.

    Published: 14 Mar 2024
    4.3
    Medium

    CVE-2024-25653

    Last Modified: 14 Oct 2025

    Broken Access Control in the Report functionality of Delinea PAM Secret Server 11.4 allows unprivileged users, when Unlimited Admin Mode is enabled, to view system reports and modify custom reports via the Report functionality in the Web UI.

    Published: 14 Mar 2024
    5.6
    Medium

    CVE-2024-28251

    Last Modified: 4 Sept 2025

    Querybook is a Big Data Querying UI, combining collocated table metadata and a simple notebook interface. Querybook's datadocs functionality works by using a Websocket Server. The client talks to this WSS whenever updating/deleting/reading any cells as well as for watching the live status of query executions. Currently the CORS setting allows all origins, which could result in cross-site websocket hijacking and allow attackers to read/edit/remove datadocs of the user. This issue has been addressed in version 3.32.0. Users are advised to upgrade. There are no known workarounds for this vulnerability.

    Published: 13 Mar 2024
    7.2
    High

    CVE-2024-1654

    Last Modified: 23 Jan 2025

    This vulnerability potentially allows unauthorized write operations which may lead to remote code execution. An attacker must already have authenticated admin access and knowledge of both an internal system identifier and details of another valid user to exploit this.

    Published: 13 Mar 2024
    4.8
    Medium

    CVE-2024-1223

    Last Modified: 23 Jan 2025

    This vulnerability potentially allows unauthorized enumeration of information from the embedded device APIs. An attacker must already have existing knowledge of some combination of valid usernames, device names and an internal system key. For such an attack to be successful the system must be in a specific runtime state.

    Published: 13 Mar 2024
    8.6
    High

    CVE-2024-1222

    Last Modified: 23 Jan 2025

    This allows attackers to use a maliciously formed API request to gain access to an API authorization level with elevated privileges. This applies to a small subset of PaperCut NG/MF API calls.

    Published: 13 Mar 2024
    3.1
    Low

    CVE-2024-1221

    Last Modified: 23 Jan 2025

    This vulnerability potentially allows files on a PaperCut NG/MF server to be exposed using a specifically formed payload against the impacted API endpoint. The attacker must carry out some reconnaissance to gain knowledge of a system token. This CVE only affects Linux and macOS PaperCut NG/MF servers.

    Published: 13 Mar 2024
    6.1
    Medium

    CVE-2024-2242

    Last Modified: 8 Apr 2026

    The Contact Form 7 plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘active-tab’ parameter in all versions up to, and including, 5.9 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

    Published: 13 Mar 2024