CVE Feed

    Dashboard / CVE

    —
    Unknown

    CVE-2024-2396

    Last Modified: 11 Feb 2025

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

    Published: 12 Mar 2024
    6.2
    Medium

    CVE-2024-2371

    Last Modified: 15 Apr 2026

    Information exposure vulnerability in Korenix JetI/O 6550 affecting firmware version F208 Build:0817. The SNMP protocol uses plaintext to transfer data, allowing an attacker to intercept traffic and retrieve credentials.

    Published: 12 Mar 2024
    5.3
    Medium

    CVE-2024-0906

    Last Modified: 8 Apr 2026

    The f(x) Private Site plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.2.1 via the API. This makes it possible for unauthenticated attackers to obtain page and post contents of a site protected with this plugin.

    Published: 12 Mar 2024
    6.4
    Medium

    CVE-2024-1328

    Last Modified: 8 Apr 2026

    The Newsletter2Go plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘style’ parameter in all versions up to, and including, 4.0.14 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 12 Mar 2024
    6.5
    Medium

    CVE-2024-27279

    Last Modified: 13 May 2025

    Directory traversal vulnerability exists in a-blog cms Ver.3.1.x series Ver.3.1.9 and earlier, Ver.3.0.x series Ver.3.0.30 and earlier, Ver.2.11.x series Ver.2.11.59 and earlier, Ver.2.10.x series Ver.2.10.51 and earlier, and Ver.2.9 and earlier versions. If this vulnerability is exploited, a user with editor or higher privilege who can login to the product may obtain arbitrary files on the server including password files.

    Published: 12 Mar 2024
    8.7
    High

    CVE-2024-26288

    Last Modified: 23 Jan 2025

    An unauthenticated remote attacker can influence the communication due to the lack of encryption of sensitive data via a MITM. Charging is not affected.

    Published: 12 Mar 2024
    4.8
    Medium

    CVE-2024-26005

    Last Modified: 23 Jan 2025

    An unauthenticated remote attacker can gain service level privileges through an incomplete cleanup during service restart after a DoS. 

    Published: 12 Mar 2024
    7.5
    High

    CVE-2024-26004

    Last Modified: 23 Jan 2025

    An unauthenticated remote attacker can DoS a control agent due to access of a uninitialized pointer which may prevent or disrupt the charging functionality.

    Published: 12 Mar 2024
    7.5
    High

    CVE-2024-26003

    Last Modified: 23 Jan 2025

    An unauthenticated remote attacker can DoS the control agent due to a out-of-bounds read which may prevent or disrupt the charging functionality. 

    Published: 12 Mar 2024
    7.8
    High

    CVE-2024-26002

    Last Modified: 23 Jan 2025

    An improper input validation in the Qualcom plctool allows a local attacker with low privileges to gain root access by changing the ownership of specific files.

    Published: 12 Mar 2024
    7.4
    High

    CVE-2024-26001

    Last Modified: 24 Jan 2025

    An unauthenticated remote attacker can write memory out of bounds due to improper input validation in the MQTT stack. The brute force attack is not always successful because of memory randomization.

    Published: 12 Mar 2024
    5.9
    Medium

    CVE-2024-26000

    Last Modified: 16 Apr 2025

    An unauthenticated remote attacker can read memory out of bounds due to improper input validation in the MQTT stack. The brute force attack is not always successful because of memory randomization.

    Published: 12 Mar 2024
    8.4
    High

    CVE-2024-25999

    Last Modified: 23 Jan 2025

    An unauthenticated local attacker can perform a privilege escalation due to improper input validation in the OCPP agent service. 

    Published: 12 Mar 2024
    7.3
    High

    CVE-2024-25998

    Last Modified: 24 Jan 2025

    An unauthenticated remote attacker can perform a command injection in the OCPP Service with limited privileges due to improper input validation.

    Published: 12 Mar 2024
    5.3
    Medium

    CVE-2024-25997

    Last Modified: 23 Jan 2025

    An unauthenticated remote attacker can perform a log injection due to improper input validation. Only a certain log file is affected.

    Published: 12 Mar 2024
    5.3
    Medium

    CVE-2024-25996

    Last Modified: 23 Jan 2025

    An unauthenticated remote attacker can perform a remote code execution due to an origin validation error. The access is limited to the service user.

    Published: 12 Mar 2024
    9.8
    Critical

    CVE-2024-25995

    Last Modified: 30 Jan 2025

    An unauthenticated remote attacker can modify configurations to perform a remote code execution, gain root rights or perform an DoS due to improper input validation.

    Published: 12 Mar 2024
    5.3
    Medium

    CVE-2024-25994

    Last Modified: 24 Jan 2025

    An unauthenticated remote attacker can upload a arbitrary script file due to improper input validation. The upload destination is fixed and is write only.

    Published: 12 Mar 2024
    7.2
    High

    CVE-2024-27121

    Last Modified: 15 Apr 2026

    Path traversal vulnerability exists in Machine Automation Controller NJ Series and Machine Automation Controller NX Series. An arbitrary file in the affected product may be accessed or arbitrary code may be executed by processing a specially crafted request sent from a remote attacker with an administrative privilege. As for the details of the affected product names/versions, see the information provided by the vendor under [References] section.

    Published: 12 Mar 2024
    6.1
    Medium

    CVE-2024-21584

    Last Modified: 13 Mar 2025

    Pleasanter 1.3.49.0 and earlier contains a cross-site scripting vulnerability. If an attacker tricks the user to access the product with a specially crafted URL and perform a specific operation, an arbitrary script may be executed on the web browser of the user.

    Published: 12 Mar 2024
    6.3
    Medium

    CVE-2024-24964

    Last Modified: 23 May 2025

    Improper access control vulnerability exists in the resident process of SKYSEA Client View versions from Ver.11.220 prior to Ver.19.2. If this vulnerability is exploited, an arbitrary process may be executed with SYSTEM privilege by a user who can log in to the PC where the product's Windows client is installed.

    Published: 12 Mar 2024
    7.8
    High

    CVE-2024-21805

    Last Modified: 23 May 2025

    Improper access control vulnerability exists in the specific folder of SKYSEA Client View versions from Ver.16.100 prior to Ver.19.2. If this vulnerability is exploited, an arbitrary file may be placed in the specific folder by a user who can log in to the PC where the product's Windows client is installed. In case the file is a specially crafted DLL file, arbitrary code may be executed with SYSTEM privilege.

    Published: 12 Mar 2024
    5.6
    Medium

    CVE-2023-6814

    Last Modified: 15 Apr 2026

    Insertion of Sensitive Information into Log File vulnerability in Hitachi Cosminexus Component Container allows local users to gain sensitive information.This issue affects Cosminexus Component Container: from 11-30 before 11-30-05, from 11-20 before 11-20-07, from 11-10 before 11-10-10, from 11-00 before 11-00-12, All versions of V8 and V9.

    Published: 12 Mar 2024
    5.3
    Medium

    CVE-2024-25645

    Last Modified: 7 Feb 2025

    Under certain condition SAP NetWeaver (Enterprise Portal) - version 7.50 allows an attacker to access information which would otherwise be restricted causing low impact on confidentiality of the application and with no impact on Integrity and Availability of the application.

    Published: 12 Mar 2024
    5.3
    Medium

    CVE-2024-28163

    Last Modified: 7 Feb 2025

    Under certain conditions, Support Web Pages of SAP NetWeaver Process Integration (PI) - versions 7.50, allows an attacker to access information which would otherwise be restricted, causing low impact on Confidentiality with no impact on Integrity and Availability of the application.

    Published: 12 Mar 2024
    5.4
    Medium

    CVE-2024-27902

    Last Modified: 26 Feb 2025

    Applications based on SAP GUI for HTML in SAP NetWeaver AS ABAP - versions 7.89, 7.93, do not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability. A successful attack can allow a malicious attacker to access and modify data through their ability to execute code in a user’s browser. There is no impact on the availability of the system

    Published: 12 Mar 2024
    4.3
    Medium

    CVE-2024-27900

    Last Modified: 16 Apr 2025

    Due to missing authorization check, attacker with business user account in SAP ABAP Platform - version 758, 795, can change the privacy setting of job templates from shared to private. As a result, the selected template would only be accessible to the owner.

    Published: 12 Mar 2024
    5.3
    Medium

    CVE-2024-25644

    Last Modified: 10 Apr 2025

    Under certain conditions SAP NetWeaver WSRM - version 7.50, allows an attacker to access information which would otherwise be restricted, causing low impact on Confidentiality with no impact on Integrity and Availability of the application.

    Published: 12 Mar 2024
    4.6
    Medium

    CVE-2024-22133

    Last Modified: 26 Feb 2025

    SAP Fiori Front End Server - version 605, allows altering of approver details on the read-only field when sending leave request information. This could lead to creation of request with incorrect approver causing low impact on Confidentiality and Integrity with no impact on Availability of the application.

    Published: 12 Mar 2024
    9.1
    Critical

    CVE-2024-22127

    Last Modified: 7 Feb 2025

    SAP NetWeaver Administrator AS Java (Administrator Log Viewer plug-in) - version 7.50, allows an attacker with high privileges to upload potentially dangerous files which leads to command injection vulnerability. This would enable the attacker to run commands which can cause high impact on confidentiality, integrity and availability of the application.

    Published: 12 Mar 2024
    8.4
    High

    CVE-2024-27758

    Last Modified: 15 Apr 2026

    In RPyC before 6.0.0, when a server exposes a method that calls the attribute named __array__ for a client-provided netref (e.g., np.array(client_netref)), a remote attacker can craft a class that results in remote code execution.

    Published: 12 Mar 2024
    4.8
    Medium

    CVE-2024-26521

    Last Modified: 15 Apr 2026

    HTML Injection vulnerability in CE Phoenix v1.0.8.20 and before allows a remote attacker to execute arbitrary code, escalate privileges, and obtain sensitive information via a crafted payload to the english.php component.

    Published: 12 Mar 2024
    5.9
    Medium

    CVE-2024-2467

    Last Modified: 15 Apr 2026

    A timing-based side-channel flaw exists in the perl-Crypt-OpenSSL-RSA package, which could be sufficient to recover plaintext across a network in a Bleichenbacher-style attack. To achieve successful decryption, an attacker would have to be able to send a large number of trial messages. The vulnerability affects the legacy PKCS#1v1.5 RSA encryption padding mode.

    Published: 12 Mar 2024
    6.1
    Medium

    CVE-2023-22655

    Last Modified: 15 Apr 2026

    Protection mechanism failure in some 3rd and 4th Generation Intel(R) Xeon(R) Processors when using Intel(R) SGX or Intel(R) TDX may allow a privileged user to potentially enable escalation of privilege via local access.

    Published: 12 Mar 2024
    6.5
    Medium

    CVE-2024-2182

    Last Modified: 15 Apr 2026

    A flaw was found in the Open Virtual Network (OVN). In OVN clusters where BFD is used between hypervisors for high availability, an attacker can inject specially crafted BFD packets from inside unprivileged workloads, including virtual machines or containers, that can trigger a denial of service.

    Published: 12 Mar 2024
    7.5
    High

    CVE-2024-28340

    Last Modified: 27 May 2025

    An information leak in the currentsetting.htm component of Netgear CBR40 2.5.0.28, Netgear CBK40 2.5.0.28, and Netgear CBK43 2.5.0.28 allows attackers to obtain sensitive information without any authentication required.

    Published: 12 Mar 2024
    8.4
    High

    CVE-2024-27317

    Last Modified: 13 Feb 2025

    In Pulsar Functions Worker, authenticated users can upload functions in jar or nar files. These files, essentially zip files, are extracted by the Functions Worker. However, if a malicious file is uploaded, it could exploit a directory traversal vulnerability. This occurs when the filenames in the zip files, which aren't properly validated, contain special elements like "..", altering the directory path. This could allow an attacker to create or modify files outside of the designated extraction directory, potentially influencing system behavior. This vulnerability also applies to the Pulsar Broker when it is configured with "functionsWorkerEnabled=true". This issue affects Apache Pulsar versions from 2.4.0 to 2.10.5, from 2.11.0 to 2.11.3, from 3.0.0 to 3.0.2, from 3.1.0 to 3.1.2, and 3.2.0. 2.10 Pulsar Function Worker users should upgrade to at least 2.10.6. 2.11 Pulsar Function Worker users should upgrade to at least 2.11.4. 3.0 Pulsar Function Worker users should upgrade to at least 3.0.3. 3.1 Pulsar Function Worker users should upgrade to at least 3.1.3. 3.2 Pulsar Function Worker users should upgrade to at least 3.2.1. Users operating versions prior to those listed above should upgrade to the aforementioned patched versions or newer versions.

    Published: 12 Mar 2024
    7.1
    High

    CVE-2024-25325

    Last Modified: 12 May 2025

    SQL injection vulnerability in Employee Management System v.1.0 allows a local attacker to obtain sensitive information via a crafted payload to the txtemail parameter in the login.php.

    Published: 12 Mar 2024
    8.5
    High

    CVE-2024-27135

    Last Modified: 13 Feb 2025

    Improper input validation in the Pulsar Function Worker allows a malicious authenticated user to execute arbitrary Java code on the Pulsar Function worker, outside of the sandboxes designated for running user-provided functions. This vulnerability also applies to the Pulsar Broker when it is configured with "functionsWorkerEnabled=true". This issue affects Apache Pulsar versions from 2.4.0 to 2.10.5, from 2.11.0 to 2.11.3, from 3.0.0 to 3.0.2, from 3.1.0 to 3.1.2, and 3.2.0. 2.10 Pulsar Function Worker users should upgrade to at least 2.10.6. 2.11 Pulsar Function Worker users should upgrade to at least 2.11.4. 3.0 Pulsar Function Worker users should upgrade to at least 3.0.3. 3.1 Pulsar Function Worker users should upgrade to at least 3.1.3. 3.2 Pulsar Function Worker users should upgrade to at least 3.2.1. Users operating versions prior to those listed above should upgrade to the aforementioned patched versions or newer versions.

    Published: 12 Mar 2024
    8.5
    High

    CVE-2024-27894

    Last Modified: 13 Feb 2025

    The Pulsar Functions Worker includes a capability that permits authenticated users to create functions where the function's implementation is referenced by a URL. The supported URL schemes include "file", "http", and "https". When a function is created using this method, the Functions Worker will retrieve the implementation from the URL provided by the user. However, this feature introduces a vulnerability that can be exploited by an attacker to gain unauthorized access to any file that the Pulsar Functions Worker process has permissions to read. This includes reading the process environment which potentially includes sensitive information, such as secrets. Furthermore, an attacker could leverage this vulnerability to use the Pulsar Functions Worker as a proxy to access the content of remote HTTP and HTTPS endpoint URLs. This could also be used to carry out denial of service attacks. This vulnerability also applies to the Pulsar Broker when it is configured with "functionsWorkerEnabled=true". This issue affects Apache Pulsar versions from 2.4.0 to 2.10.5, from 2.11.0 to 2.11.3, from 3.0.0 to 3.0.2, from 3.1.0 to 3.1.2, and 3.2.0. 2.10 Pulsar Function Worker users should upgrade to at least 2.10.6. 2.11 Pulsar Function Worker users should upgrade to at least 2.11.4. 3.0 Pulsar Function Worker users should upgrade to at least 3.0.3. 3.1 Pulsar Function Worker users should upgrade to at least 3.1.3. 3.2 Pulsar Function Worker users should upgrade to at least 3.2.1. Users operating versions prior to those listed above should upgrade to the aforementioned patched versions or newer versions. The updated versions of Pulsar Functions Worker will, by default, impose restrictions on the creation of functions using URLs. For users who rely on this functionality, the Function Worker configuration provides two configuration keys: "additionalEnabledConnectorUrlPatterns" and "additionalEnabledFunctionsUrlPatterns". These keys allow users to specify a set of URL patterns that are permitted, enabling the creation of functions using URLs that match the defined patterns. This approach ensures that the feature remains available to those who require it, while limiting the potential for unauthorized access and exploitation.

    Published: 12 Mar 2024
    6.1
    Medium

    CVE-2023-42307

    Last Modified: 20 Mar 2025

    Cross Site Scripting (XSS) vulnerability in Code-Projects Exam Form Submission 1.0 allows attackers to run arbitrary code via "Subject Name" and "Subject Code" section.

    Published: 12 Mar 2024
    6.1
    Medium

    CVE-2023-42308

    Last Modified: 3 Apr 2025

    Cross Site Scripting (XSS) vulnerability in Manage Fastrack Subjects in Code-Projects Exam Form Submission 1.0 allows attackers to run arbitrary code via the "Subject Name" and "Subject Code" Section.

    Published: 12 Mar 2024
    6.1
    Medium

    CVE-2023-43292

    Last Modified: 7 Jul 2025

    Cross Site Scripting vulnerability in My Food Recipe Using PHP with Source Code v.1.0 allows a local attacker to execute arbitrary code via a crafted payload to the Recipe Name, Procedure, and ingredients parameters.

    Published: 12 Mar 2024
    6.1
    Medium

    CVE-2023-49453

    Last Modified: 29 Sept 2025

    Reflected cross-site scripting (XSS) vulnerability in Racktables v0.22.0 and before, allows local attackers to execute arbitrary code and obtain sensitive information via the search component in index.php.

    Published: 12 Mar 2024
    5.7
    Medium

    CVE-2024-2193

    Last Modified: 15 Apr 2026

    A Speculative Race Condition (SRC) vulnerability that impacts modern CPU architectures supporting speculative execution (related to Spectre V1) has been disclosed. An unauthenticated attacker can exploit this vulnerability to disclose arbitrary data from the CPU using race conditions to access the speculative executable code paths.

    Published: 12 Mar 2024
    7.8
    High

    CVE-2024-24092

    Last Modified: 3 Apr 2025

    SQL Injection vulnerability in Code-projects.org Scholars Tracking System 1.0 allows attackers to run arbitrary code via login.php.

    Published: 12 Mar 2024
    9.8
    Critical

    CVE-2024-24093

    Last Modified: 3 Apr 2025

    SQL Injection vulnerability in Code-projects Scholars Tracking System 1.0 allows attackers to run arbitrary code via Personal Information Update information.

    Published: 12 Mar 2024
    5.4
    Medium

    CVE-2024-24097

    Last Modified: 3 Apr 2025

    Cross Site Scripting (XSS) vulnerability in Code-projects Scholars Tracking System 1.0 allows attackers to run arbitrary code via the News Feed.

    Published: 12 Mar 2024
    9.8
    Critical

    CVE-2024-24101

    Last Modified: 13 Mar 2025

    Code-projects Scholars Tracking System 1.0 is vulnerable to SQL Injection under Eligibility Information Update.

    Published: 12 Mar 2024
    9.3
    Critical

    CVE-2024-25331

    Last Modified: 15 Apr 2026

    DIR-822 Rev. B Firmware v2.02KRB09 and DIR-822-CA Rev. B Firmware v2.03WWb01 suffer from a LAN-Side Unauthenticated Remote Code Execution (RCE) vulnerability elevated from HNAP Stack-Based Buffer Overflow.

    Published: 12 Mar 2024