CVE Feed

    Dashboard / CVE

    4.3
    Medium

    CVE-2023-46171

    Last Modified: 11 Mar 2025

    IBM DS8900F HMC 89.21.19.0, 89.21.31.0, 89.30.68.0, 89.32.40.0, and 89.33.48.0 could allow an authenticated user to view sensitive log information after enumerating filenames. IBM X-Force ID: 269408.

    Published: 7 Mar 2024
    4.3
    Medium

    CVE-2024-26167

    Last Modified: 3 May 2025

    Microsoft Edge for Android Spoofing Vulnerability

    Published: 7 Mar 2024
    6.4
    Medium

    CVE-2024-2127

    Last Modified: 8 Apr 2026

    The Page Builder: Pagelayer – Drag and Drop website builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via custom attributes in all versions up to, and including, 1.8.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 7 Mar 2024
    6.4
    Medium

    CVE-2024-2128

    Last Modified: 8 Apr 2026

    The EmbedPress – Embed PDF, Google Docs, Vimeo, Wistia, Embed YouTube Videos, Audios, Maps & Embed Any Documents in Gutenberg & Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's embed widget in all versions up to, and including, 3.9.10 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 7 Mar 2024
    8.8
    High

    CVE-2024-1773

    Last Modified: 8 Apr 2026

    The PDF Invoices and Packing Slips For WooCommerce plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.3.7 via deserialization of untrusted input via the order_id parameter. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject a PHP Object. No known POP chain is present in the vulnerable plugin. If a POP chain is present via an additional plugin or theme installed on the target system, it could allow the attacker to delete arbitrary files, retrieve sensitive data, or execute code.

    Published: 7 Mar 2024
    8.8
    High

    CVE-2024-0203

    Last Modified: 21 Jan 2025

    The Digits plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 8.4.1. This is due to missing nonce validation in the 'digits_save_settings' function. This makes it possible for unauthenticated attackers to modify the default role of registered users to elevate user privileges via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

    Published: 7 Mar 2024
    7.2
    High

    CVE-2023-48725

    Last Modified: 4 Nov 2025

    A stack-based buffer overflow vulnerability exists in the JSON Parsing getblockschedule() functionality of Netgear RAX30 1.0.11.96 and 1.0.7.78. A specially crafted HTTP request can lead to code execution. An attacker can make an authenticated HTTP request to trigger this vulnerability.

    Published: 7 Mar 2024
    6.6
    Medium

    CVE-2023-42509

    Last Modified: 11 Mar 2025

    JFrog Artifactory later than version 7.17.4 but prior to version 7.77.0 is vulnerable to an issue whereby a sequence of improperly handled exceptions in repository configuration initialization steps may lead to exposure of sensitive data.

    Published: 7 Mar 2024
    7.2
    High

    CVE-2023-42661

    Last Modified: 11 Mar 2025

    JFrog Artifactory prior to version 7.76.2 is vulnerable to Arbitrary File Write of untrusted data, which may lead to DoS or Remote Code Execution when a specially crafted series of requests is sent by an authenticated user. This is due to insufficient validation of artifacts.

    Published: 7 Mar 2024
    —
    Unknown

    CVE-2023-47691

    Last Modified: 20 Mar 2024

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

    Published: 7 Mar 2024
    6.3
    Medium

    CVE-2024-2241

    Last Modified: 27 Jun 2025

    Improper access control in the user interface in Devolutions Workspace 2024.1.0 and earlier allows an authenticated user to perform unintended actions via specific permissions

    Published: 7 Mar 2024
    5.4
    Medium

    CVE-2024-2245

    Last Modified: 13 Jul 2025

    Cross-Site Scripting vulnerability in moziloCMS version 2.0. By sending a POST request to the '/install.php' endpoint, a JavaScript payload could be executed in the 'username' parameter.

    Published: 7 Mar 2024
    8.8
    High

    CVE-2024-1351

    Last Modified: 11 Mar 2025

    Under certain configurations of --tlsCAFile and tls.CAFile, MongoDB Server may skip peer certificate validation which may result in untrusted connections to succeed. This may effectively reduce the security guarantees provided by TLS and open connections that should have been closed due to failing certificate validation. This issue affects MongoDB Server v7.0 versions prior to and including 7.0.5, MongoDB Server v6.0 versions prior to and including 6.0.13, MongoDB Server v5.0 versions prior to and including 5.0.24 and MongoDB Server v4.4 versions prior to and including 4.4.28. Required Configuration : A server process will allow incoming connections to skip peer certificate validation if the server process was started with TLS enabled (net.tls.mode set to allowTLS, preferTLS, or requireTLS) and without a net.tls.CAFile configured.

    Published: 7 Mar 2024
    6.5
    Medium

    CVE-2024-28230

    Last Modified: 16 Dec 2024

    In JetBrains YouTrack before 2024.1.25893 attaching/detaching workflow to a project was possible without project admin permissions

    Published: 7 Mar 2024
    6.5
    Medium

    CVE-2024-28229

    Last Modified: 16 Apr 2025

    In JetBrains YouTrack before 2024.1.25893 user without appropriate permissions could restore issues and articles

    Published: 7 Mar 2024
    5.3
    Medium

    CVE-2024-28228

    Last Modified: 16 Dec 2024

    In JetBrains YouTrack before 2024.1.25893 creation comments on behalf of an arbitrary user in HelpDesk was possible

    Published: 7 Mar 2024
    7.5
    High

    CVE-2024-1169

    Last Modified: 8 Apr 2026

    The Post Form – Registration Form – Profile Form for User Profiles – Frontend Content Forms for User Submissions (UGC) plugin for WordPress is vulnerable to unauthorized media upload due to a missing capability check on the buddyforms_upload_handle_dropped_media function in all versions up to, and including, 2.8.7. This makes it possible for unauthenticated attackers to upload media files.

    Published: 7 Mar 2024
    8.2
    High

    CVE-2024-1170

    Last Modified: 8 Apr 2026

    The Post Form – Registration Form – Profile Form for User Profiles – Frontend Content Forms for User Submissions (UGC) plugin for WordPress is vulnerable to unauthorized media file deletion due to a missing capability check on the handle_deleted_media function in all versions up to, and including, 2.8.7. This makes it possible for unauthenticated attackers to delete arbitrary media files.

    Published: 7 Mar 2024
    4.3
    Medium

    CVE-2024-22256

    Last Modified: 27 Mar 2025

    VMware Cloud Director contains a partial information disclosure vulnerability. A malicious actor can potentially gather information about organization names based on the behavior of the instance.

    Published: 7 Mar 2024
    6.4
    Medium

    CVE-2024-1534

    Last Modified: 8 Apr 2026

    The Booster for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 7.1.7 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 7 Mar 2024
    9.1
    Critical

    CVE-2024-0818

    Last Modified: 13 Feb 2025

    Arbitrary File Overwrite Via Path Traversal in paddlepaddle/paddle before 2.6

    Published: 7 Mar 2024
    8.8
    High

    CVE-2024-1382

    Last Modified: 8 Apr 2026

    The Restaurant Reservations plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.9 via the nd_rst_layout attribute of the nd_rst_search shortcode. This makes it possible for authenticated attackers, with contributor-level access and above, to include and execute arbitrary PHP files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where an uploaded PHP file may not be directly accessible.

    Published: 7 Mar 2024
    6.4
    Medium

    CVE-2024-2136

    Last Modified: 8 Apr 2026

    The WPKoi Templates for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Advanced Heading widget in all versions up to, and including, 2.5.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 7 Mar 2024
    9.3
    Critical

    CVE-2023-42662

    Last Modified: 11 Mar 2025

    JFrog Artifactory versions 7.59 and above, but below 7.59.18, 7.63.18, 7.68.19, 7.71.8 are vulnerable to an issue whereby user interaction with specially crafted URLs could lead to exposure of user access tokens due to improper handling of the CLI / IDE browser based SSO integration.

    Published: 7 Mar 2024
    6.4
    Medium

    CVE-2024-1419

    Last Modified: 8 Apr 2026

    The The Plus Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘_id’ attribute of the Header Meta Content widget in all versions up to, and including, 5.4.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 7 Mar 2024
    6.4
    Medium

    CVE-2024-1506

    Last Modified: 8 Apr 2026

    The Prime Slider – Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'title_tags' attribute of the Fiestar widget in all versions up to, and including, 3.13.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 7 Mar 2024
    6.4
    Medium

    CVE-2024-1377

    Last Modified: 8 Apr 2026

    The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘author_meta_tag’ attribute of the Author Meta widget in all versions up to, and including, 3.10.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 7 Mar 2024
    5.4
    Medium

    CVE-2024-1500

    Last Modified: 8 Apr 2026

    The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Logo Widget in all versions up to, and including, 1.3.91 due to insufficient input sanitization and output escaping on user supplied URLs. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 7 Mar 2024
    4.7
    Medium

    CVE-2024-1720

    Last Modified: 8 Apr 2026

    The User Registration – Custom Registration Form, Login Form, and User Profile WordPress Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Display Name' parameter in all versions up to, and including, 3.1.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This vulnerability requires social engineering to successfully exploit, and the impact would be very limited due to the attacker requiring a user to login as the user with the injected payload for execution.

    Published: 7 Mar 2024
    6.4
    Medium

    CVE-2024-1366

    Last Modified: 8 Apr 2026

    The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘archive_title_tag’ attribute of the Archive Title widget in all versions up to, and including, 3.10.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 7 Mar 2024
    8.8
    High

    CVE-2023-51395

    Last Modified: 15 Apr 2026

    The vulnerability described by CVE-2023-0972 has been additionally discovered in Silicon Labs Z-Wave end devices. This vulnerability may allow an unauthenticated attacker within Z-Wave range to overflow a stack buffer, leading to arbitrary code execution.

    Published: 7 Mar 2024
    5.4
    Medium

    CVE-2024-28216

    Last Modified: 7 May 2025

    nGrinder before 3.5.9 allows an attacker to obtain the results of webhook requests due to lack of access control, which could be the cause of information disclosure and limited Server-Side Request Forgery.

    Published: 7 Mar 2024
    7.5
    High

    CVE-2024-28215

    Last Modified: 7 May 2025

    nGrinder before 3.5.9 allows an attacker to create or update webhook configuration due to lack of access control, which could be the cause of information disclosure and limited Server-Side Request Forgery.

    Published: 7 Mar 2024
    2.7
    Low

    CVE-2024-28214

    Last Modified: 7 May 2025

    nGrinder before 3.5.9 allows to set delay without limitation, which could be the cause of Denial of Service by remote attacker.

    Published: 7 Mar 2024
    9.8
    Critical

    CVE-2024-28213

    Last Modified: 7 May 2025

    nGrinder before 3.5.9 allows to accept serialized Java objects from unauthenticated users, which could allow remote attacker to execute arbitrary code via unsafe Java objects deserialization.

    Published: 7 Mar 2024
    9.8
    Critical

    CVE-2024-28212

    Last Modified: 7 May 2025

    nGrinder before 3.5.9 uses old version of SnakeYAML, which could allow remote attacker to execute arbitrary code via unsafe deserialization.

    Published: 7 Mar 2024
    9.8
    Critical

    CVE-2024-28211

    Last Modified: 7 May 2025

    nGrinder before 3.5.9 allows connection to malicious JMX/RMI server by default, which could be the cause of executing arbitrary code via RMI registry by remote attacker.

    Published: 7 Mar 2024
    6.4
    Medium

    CVE-2024-1761

    Last Modified: 8 Apr 2026

    The WP Chat App plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's widget/block in all versions up to, and including, 3.6.1 due to insufficient input sanitization and output escaping on user supplied attributes such as 'buttonColor' and 'phoneNumber'. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 7 Mar 2024
    9.8
    Critical

    CVE-2024-0917

    Last Modified: 13 Feb 2025

    remote code execution in paddlepaddle/paddle 2.6.0

    Published: 7 Mar 2024
    7.3
    High

    CVE-2024-28097

    Last Modified: 5 Feb 2025

    Calendar functionality in Schoolbox application before version 23.1.3 is vulnerable to stored cross-site scripting allowing authenticated attacker to perform security actions in the context of the affected users.

    Published: 7 Mar 2024
    7.3
    High

    CVE-2024-28096

    Last Modified: 5 Feb 2025

    Class functionality in Schoolbox application before version 23.1.3 is vulnerable to stored cross-site scripting allowing authenticated attacker to perform security actions in the context of the affected users.

    Published: 7 Mar 2024
    7.3
    High

    CVE-2024-28095

    Last Modified: 5 Feb 2025

    News functionality in Schoolbox application before version 23.1.3 is vulnerable to stored cross-site scripting allowing authenticated attacker to perform security actions in the context of the affected users.

    Published: 7 Mar 2024
    8.8
    High

    CVE-2024-28094

    Last Modified: 5 Feb 2025

    Chat functionality in Schoolbox application before version 23.1.3 is vulnerable to blind SQL Injection enabling the authenticated attackers to read, modify, and delete database records.

    Published: 7 Mar 2024
    5.6
    Medium

    CVE-2024-1460

    Last Modified: 14 Oct 2025

    MSI Afterburner v4.6.5.16370 is vulnerable to a Kernel Memory Leak vulnerability by triggering the 0x80002040 IOCTL code of the RTCore64.sys driver. The handle to the driver can only be obtained from a high integrity process.

    Published: 7 Mar 2024
    4.4
    Medium

    CVE-2024-1443

    Last Modified: 14 Oct 2025

    MSI Afterburner v4.6.5.16370 is vulnerable to a Denial of Service vulnerability by triggering the 0x80002000 IOCTL code of the RTCore64.sys driver. The handle to the driver can only be obtained from a high integrity process.

    Published: 7 Mar 2024
    8.2
    High

    CVE-2024-26566

    Last Modified: 9 Jul 2026

    An issue in Cute Http File Server v.3.1 allows a remote attacker to escalate privileges via the password verification component.

    Published: 7 Mar 2024
    7.5
    High

    CVE-2023-47415

    Last Modified: 5 Jul 2026

    Cypress Solutions CTM-200 v2.7.1.5600 and below was discovered to contain an OS command injection vulnerability via the cli_text parameter.

    Published: 7 Mar 2024
    7.7
    High

    CVE-2024-27733

    Last Modified: 15 Apr 2026

    File Upload vulnerability in Byzro Network Smart s42 Management Platform v.S42 allows a local attacker to execute arbitrary code via the useratte/userattestation.php component.

    Published: 7 Mar 2024
    9.8
    Critical

    CVE-2024-22857

    Last Modified: 15 Apr 2026

    Heap based buffer flow in zlog v1.1.0 to v1.2.17 in zlog_rule_new().The size of record_name is MAXLEN_PATH(1024) + 1 but file_path may have data upto MAXLEN_CFG_LINE(MAXLEN_PATH*4) + 1. So a check was missing in zlog_rule_new() while copying the record_name from file_path + 1 which caused the buffer overflow. An attacker can exploit this vulnerability to overwrite the zlog_record_fn record_func function pointer to get arbitrary code execution or potentially cause remote code execution (RCE).

    Published: 7 Mar 2024
    8.1
    High

    CVE-2024-22752

    Last Modified: 15 Apr 2026

    Insecure permissions issue in EaseUS MobiMover 6.0.5 Build 21620 allows attackers to gain escalated privileges via use of crafted executable launched from the application installation directory.

    Published: 7 Mar 2024