CVE Feed

    Dashboard / CVE

    9.3
    Critical

    CVE-2024-22252

    Last Modified: 27 Mar 2025

    VMware ESXi, Workstation, and Fusion contain a use-after-free vulnerability in the XHCI USB controller. A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute code as the virtual machine's VMX process running on the host. On ESXi, the exploitation is contained within the VMX sandbox whereas, on Workstation and Fusion, this may lead to code execution on the machine where Workstation or Fusion is installed.

    Published: 5 Mar 2024
    7.6
    High

    CVE-2024-1764

    Last Modified: 28 Mar 2025

    Improper privilege management in Just-in-time (JIT) elevation module in Devolutions Server 2023.3.14.0 and earlier allows a user to continue using the elevated privilege even after the expiration under specific circumstances

    Published: 5 Mar 2024
    5.8
    Medium

    CVE-2024-27931

    Last Modified: 3 Jan 2025

    Deno is a JavaScript, TypeScript, and WebAssembly runtime with secure defaults. Insufficient validation of parameters in `Deno.makeTemp*` APIs would allow for creation of files outside of the allowed directories. This may allow the user to overwrite important files on the system that may affect other systems. A user may provide a prefix or suffix to a `Deno.makeTemp*` API containing path traversal characters. This is fixed in Deno 1.41.1.

    Published: 5 Mar 2024
    7.1
    High

    CVE-2024-27929

    Last Modified: 21 Jan 2025

    ImageSharp is a managed, cross-platform, 2D graphics library. A heap-use-after-free flaw was found in ImageSharp's InitializeImage() function of PngDecoderCore.cs file. This vulnerability is triggered when an attacker passes a specially crafted PNG image file to ImageSharp for conversion, potentially leading to information disclosure. This issue has been patched in versions 3.1.3 and 2.1.7.

    Published: 5 Mar 2024
    7.2
    High

    CVE-2024-1356

    Last Modified: 28 Jul 2025

    Authenticated command injection vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of these vulnerabilities result in the ability to execute arbitrary commands as a privileged user on the underlying operating system.

    Published: 5 Mar 2024
    9.8
    Critical

    CVE-2024-1202

    Last Modified: 3 Jun 2026

    Authentication Bypass by Primary Weakness vulnerability in XPodas Octopod allows Authentication Bypass. This issue affects Octopod: before v1.  NOTE: The vendor was contacted and it was learned that the product is not supported.

    Published: 5 Mar 2024
    9.8
    Critical

    CVE-2023-7103

    Last Modified: 20 May 2026

    Authentication Bypass by Primary Weakness vulnerability in ZKSoftware Biometric Security Solutions UFace 5 allows Authentication Bypass. This issue affects UFace 5: through 12022024.

    Published: 5 Mar 2024
    6.1
    Medium

    CVE-2024-2188

    Last Modified: 12 Jul 2025

    Cross-Site Scripting (XSS) vulnerability stored in TP-Link Archer AX50 affecting firmware version 1.0.11 build 2022052. This vulnerability could allow an unauthenticated attacker to create a port mapping rule via a SOAP request and store a malicious JavaScript payload within that rule, which could result in an execution of the JavaScript payload when the rule is loaded.

    Published: 5 Mar 2024
    5.6
    Medium

    CVE-2023-45600

    Last Modified: 23 Apr 2025

    A CWE-613 “Insufficient Session Expiration” vulnerability in the web application, due to the session cookie “sessionid” lasting two weeks, facilitates session hijacking attacks against victims. This issue affects: AiLux imx6 bundle below version imx6_1.0.7-2.

    Published: 5 Mar 2024
    5.5
    Medium

    CVE-2023-45599

    Last Modified: 12 Jul 2025

    A CWE-646 “Reliance on File Name or Extension of Externally-Supplied File” vulnerability in the “iec61850” functionality of the web application allows a remote authenticated attacker to upload any arbitrary type of file into the device. This issue affects: AiLux imx6 bundle below version imx6_1.0.7-2.

    Published: 5 Mar 2024
    5.3
    Medium

    CVE-2023-45598

    Last Modified: 10 Apr 2025

    A CWE-425 “Direct Request ('Forced Browsing')” vulnerability in the “measure” functionality of the web application allows a remote unauthenticated attacker to access confidential measure information. This issue affects: AiLux imx6 bundle below version imx6_1.0.7-2.

    Published: 5 Mar 2024
    5.9
    Medium

    CVE-2023-45597

    Last Modified: 10 Apr 2025

    A CWE-1236 “Improper Neutralization of Formula Elements in a CSV File” vulnerability in the “file_configuration” functionality of the web application (concerning the function “export_file”) allows a remote authenticated attacker to inject arbitrary formulas inside generated CSV files. This issue affects: AiLux imx6 bundle below version imx6_1.0.7-2.

    Published: 5 Mar 2024
    5.3
    Medium

    CVE-2023-45596

    Last Modified: 23 Apr 2025

    A CWE-425 “Direct Request ('Forced Browsing')” vulnerability in the “file_configuration” functionality of the web application allows a remote unauthenticated attacker to access confidential configuration files. This issue affects: AiLux imx6 bundle below version imx6_1.0.7-2.

    Published: 5 Mar 2024
    5.9
    Medium

    CVE-2023-45595

    Last Modified: 11 Apr 2025

    A CWE-434 “Unrestricted Upload of File with Dangerous Type” vulnerability in the “file_configuration” functionality of the web application allows a remote authenticated attacker to upload any arbitrary type of file into the device. This issue affects: AiLux imx6 bundle below version imx6_1.0.7-2.

    Published: 5 Mar 2024
    6.8
    Medium

    CVE-2023-45594

    Last Modified: 9 Apr 2025

    A CWE-552 “Files or Directories Accessible to External Parties” vulnerability in the embedded Chromium browser allows a physical attacker to arbitrarily download/upload files to/from the file system, with unspecified impacts to the confidentiality, integrity, and availability of the device. This issue affects: AiLux imx6 bundle below version imx6_1.0.7-2.

    Published: 5 Mar 2024
    6.8
    Medium

    CVE-2023-45593

    Last Modified: 10 Apr 2025

    A CWE-184 “Incomplete List of Disallowed Inputs” vulnerability in the embedded Chromium browser (concerning the handling of alternative URLs, other than “ http://localhost” ) allows a physical attacker to read arbitrary files on the file system, alter the configuration of the embedded browser, and have other unspecified impacts to the confidentiality, integrity, and availability of the device. This issue affects: AiLux imx6 bundle below version imx6_1.0.7-2.

    Published: 5 Mar 2024
    6.8
    Medium

    CVE-2023-45592

    Last Modified: 10 Apr 2025

    A CWE-250 “Execution with Unnecessary Privileges” vulnerability in the embedded Chromium browser (due to the binary being executed with the “--no-sandbox” option and with root privileges) exacerbates the impacts of successful attacks executed against the browser. This issue affects: AiLux imx6 bundle below version imx6_1.0.7-2.

    Published: 5 Mar 2024
    7.5
    High

    CVE-2023-45591

    Last Modified: 10 Apr 2025

    A CWE-122 “Heap-based Buffer Overflow” vulnerability in the “logger_generic” function of the “Ax_rtu” binary allows a remote authenticated attacker to trigger a memory corruption in the context of the binary. This may result in a Denial-of-Service (DoS) condition, possibly in the execution of arbitrary code with the same privileges of the process (root), or have other unspecified impacts on the device. This issue affects: AiLux imx6 bundle below version imx6_1.0.7-2.

    Published: 5 Mar 2024
    7.5
    High

    CVE-2023-5457

    Last Modified: 9 Apr 2025

    A CWE-1269 “Product Released in Non-Release Configuration” vulnerability in the Django web framework used by the web application (due to the “debug” configuration parameter set to “True”) allows a remote unauthenticated attacker to access critical information and have other unspecified impacts to the confidentiality, integrity, and availability of the application. This issue affects: AiLux imx6 bundle below version imx6_1.0.7-2.

    Published: 5 Mar 2024
    8.1
    High

    CVE-2023-5456

    Last Modified: 10 Apr 2025

    A CWE-798 “Use of Hard-coded Credentials” vulnerability in the MariaDB database of the web application allows a remote unauthenticated attacker to access the database service and all included data with the same privileges of the web application. This issue affects: AiLux imx6 bundle below version imx6_1.0.7-2.

    Published: 5 Mar 2024
    4.1
    Medium

    CVE-2024-20833

    Last Modified: 10 Feb 2025

    Use after free vulnerability in pub_crypto_recv_msg prior to SMR Mar-2024 Release 1 due to race condition allows local attackers with system privilege to cause memory corruption.

    Published: 5 Mar 2024
    3.8
    Low

    CVE-2023-42419

    Last Modified: 15 Apr 2026

    Maintenance Server, in Cybellum's QCOW air-gapped distribution (China Edition), versions 2.15.5 through 2.27, was compiled with a hard-coded private cryptographic key. An attacker with administrative privileges & access to the air-gapped server could potentially use this key to run commands on the server. The issue was resolved in version 2.28. Earlier versions, including all Cybellum 1.x versions, and distributions for the rest of the world remain unaffected.

    Published: 5 Mar 2024
    5.1
    Medium

    CVE-2024-20841

    Last Modified: 14 Feb 2025

    Improper Handling of Insufficient Privileges in Samsung Account prior to version 14.8.00.3 allows local attackers to access data.

    Published: 5 Mar 2024
    5.7
    Medium

    CVE-2024-20840

    Last Modified: 14 Feb 2025

    Improper access control in Samsung Voice Recorder prior to versions 21.5.16.01 in Android 12 and Android 13, 21.4.51.02 in Android 14 allows physical attackers using hardware keyboard to use VoiceRecorder on the lock screen.

    Published: 5 Mar 2024
    4.6
    Medium

    CVE-2024-20839

    Last Modified: 23 Dec 2024

    Improper access control in Samsung Voice Recorder prior to versions 21.5.16.01 in Android 12 and Android 13, 21.4.51.02 in Android 14 allows physical attackers to access recording files on the lock screen.

    Published: 5 Mar 2024
    6.8
    Medium

    CVE-2024-20838

    Last Modified: 23 Dec 2024

    Improper validation vulnerability in Samsung Internet prior to version 24.0.3.2 allows local attackers to execute arbitrary code.

    Published: 5 Mar 2024
    5.3
    Medium

    CVE-2024-20837

    Last Modified: 23 Dec 2024

    Improper handling of granting permission for Trusted Web Activities in Samsung Internet prior to version 24.0.0.41 allows local attackers to grant permission to their own TWA WebApps without user interaction.

    Published: 5 Mar 2024
    3.3
    Low

    CVE-2024-20836

    Last Modified: 10 Feb 2025

    Out of bounds Read vulnerability in ssmis_get_frm in libsubextractor.so prior to SMR Mar-2024 Release 1 allows local attackers to read out of bounds memory.

    Published: 5 Mar 2024
    4
    Medium

    CVE-2024-20835

    Last Modified: 10 Feb 2025

    Improper access control vulnerability in CustomFrequencyManagerService prior to SMR Mar-2024 Release 1 allows local attackers to execute privileged behaviors.

    Published: 5 Mar 2024
    3.3
    Low

    CVE-2024-20834

    Last Modified: 10 Feb 2025

    The sensitive information exposure vulnerability in WlanTest prior to SMR Mar-2024 Release 1 allows local attackers to access MAC address without proper permission.

    Published: 5 Mar 2024
    6.4
    Medium

    CVE-2024-20832

    Last Modified: 16 Apr 2025

    Heap overflow in Little Kernel in bootloader prior to SMR Mar-2024 Release 1 allows local privileged attackers to execute arbitrary code.

    Published: 5 Mar 2024
    6.4
    Medium

    CVE-2024-20831

    Last Modified: 10 Feb 2025

    Stack overflow in Little Kernel in bootloader prior to SMR Mar-2024 Release 1 allows local privileged attackers to execute arbitrary code.

    Published: 5 Mar 2024
    5.3
    Medium

    CVE-2024-20830

    Last Modified: 10 Feb 2025

    Incorrect default permission in AppLock prior to SMR MAr-2024 Release 1 allows local attackers to configure AppLock settings.

    Published: 5 Mar 2024
    5.4
    Medium

    CVE-2024-20829

    Last Modified: 14 Feb 2025

    Missing proper interaction for opening deeplink in Samsung Internet prior to version v24.0.0.0 allows remote attackers to open an application without proper interaction.

    Published: 5 Mar 2024
    5.9
    Medium

    CVE-2023-52432

    Last Modified: 10 Feb 2025

    Improper input validation in IpcTxSndSetLoopbackCtrl in libsec-ril prior to SMR Sep-2023 Release 1 allows local attackers to write out-of-bounds memory.

    Published: 5 Mar 2024
    6.2
    Medium

    CVE-2024-22383

    Last Modified: 15 Apr 2026

    Missing release of resource after effective lifetime (CWE-772) in the Controller 7000 resulted in HBUS connected T-Series readers to not automatically recover after coming under attack over the RS-485 interface, resulting in a persistent denial of service. This issue affects: All variants of the Gallagher Controller 7000 9.00 prior to vCR9.00.231204b (distributed in 9.00.1507(MR1)), 8.90 prior to vCR8.90.240209b (distributed in 8.90.1751 (MR3)), 8.80 prior to vCR8.80.240209a (distributed in 8.80.1526 (MR4)), 8.70 prior to vCR8.70.240209a (distributed in 8.70.2526 (MR6)).

    Published: 5 Mar 2024
    6.8
    Medium

    CVE-2024-21838

    Last Modified: 10 Feb 2025

    Improper neutralization of special elements in output (CWE-74) used by the email generation feature of the Command Centre Server could lead to HTML code injection in emails generated by Command Centre. This issue affects: Gallagher Command Centre 9.00 prior to vEL9.00.1774 (MR2), 8.90 prior to vEL8.90.1751 (MR3), 8.80 prior to vEL8.80.1526 (MR4), 8.70 prior to vEL8.70.2526 (MR6),  all version of 8.60 and prior.

    Published: 5 Mar 2024
    9.1
    Critical

    CVE-2024-21815

    Last Modified: 10 Feb 2025

    Insufficiently protected credentials (CWE-522) for third party DVR integrations to the Command Centre Server are accessible to authenticated but unprivileged users. This issue affects: Gallagher Command Centre 9.00 prior to vEL9.00.1774 (MR2), 8.90 prior to vEL8.90.1751 (MR3), 8.80 prior to vEL8.80.1526 (MR4), 8.70 prior to vEL8.70.2526 (MR6),  all version of 8.60 and prior.

    Published: 5 Mar 2024
    5.3
    Medium

    CVE-2024-1093

    Last Modified: 8 Apr 2026

    The Change Memory Limit plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the admin_logic() function hooked via admin_init in all versions up to, and including, 1.0. This makes it possible for unauthenticated attackers to update the memory limit.

    Published: 5 Mar 2024
    5.3
    Medium

    CVE-2024-1769

    Last Modified: 8 Apr 2026

    The JM Twitter Cards plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 14 via the meta description data. This makes it possible for unauthenticated attackers to view password protected post content when viewing the page source.

    Published: 5 Mar 2024
    6.5
    Medium

    CVE-2024-1381

    Last Modified: 8 Apr 2026

    The Page Builder Sandwich – Front End WordPress Page Builder Plugin plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 5.1.0. This makes it possible for authenticated attackers, with subscriber access and higher, to extract sensitive user or configuration data.

    Published: 5 Mar 2024
    8.8
    High

    CVE-2024-0825

    Last Modified: 8 Apr 2026

    The Vimeography: Vimeo Video Gallery WordPress Plugin plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.3.2 via deserialization of untrusted input via the vimeography_duplicate_gallery_serialized in the duplicate_gallery function. This makes it possible for authenticated attackers attackers, with contributor access or higher, to inject a PHP Object. No POP chain is present in the vulnerable plugin. If a POP chain is present via an additional plugin or theme installed on the target system, it could allow the attacker to delete arbitrary files, retrieve sensitive data, or execute code.

    Published: 5 Mar 2024
    5.3
    Medium

    CVE-2024-1088

    Last Modified: 8 Apr 2026

    The Password Protected Store for WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.2 via the REST API. This makes it possible for unauthenticated attackers to extract sensitive data including post titles and content.

    Published: 5 Mar 2024
    6.5
    Medium

    CVE-2024-1285

    Last Modified: 8 Apr 2026

    The Page Builder Sandwich – Front End WordPress Page Builder Plugin plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'gambit_builder_save_content' function in all versions up to, and including, 5.1.0. This makes it possible for authenticated attackers, with subscriber access and above, to insert arbitrary content into existing posts.

    Published: 5 Mar 2024
    8.8
    High

    CVE-2024-1731

    Last Modified: 8 Apr 2026

    The Auto Refresh Single Page plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.1 via deserialization of untrusted input from the arsp_options post meta option. This makes it possible for authenticated attackers, with contributor-level access and above, to inject a PHP Object. No known POP chain is present in the vulnerable plugin. If a POP chain is present via an additional plugin or theme installed on the target system, it could allow the attacker to delete arbitrary files, retrieve sensitive data, or execute code.

    Published: 5 Mar 2024
    6.4
    Medium

    CVE-2024-0698

    Last Modified: 8 Apr 2026

    The Easy!Appointments plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'easyappointments' shortcode in all versions up to, and including, 1.3.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 5 Mar 2024
    5.3
    Medium

    CVE-2024-1095

    Last Modified: 8 Apr 2026

    The Build & Control Block Patterns – Boost up Gutenberg Editor plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the settings_export() function in all versions up to, and including, 1.3.5.4. This makes it possible for unauthenticated attackers to export the plugin's settings.

    Published: 5 Mar 2024
    5.3
    Medium

    CVE-2024-1478

    Last Modified: 8 Apr 2026

    The Maintenance Mode plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.0.1 via the REST API. This makes it possible for unauthenticated attackers to obtain post and page content via API thus bypassing the content protection provided by the plugin.

    Published: 5 Mar 2024
    6.1
    Medium

    CVE-2024-1782

    Last Modified: 8 Apr 2026

    The Blue Triad EZAnalytics plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'bt_webid' parameter in all versions up to, and including, 1.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

    Published: 5 Mar 2024
    5.3
    Medium

    CVE-2024-1178

    Last Modified: 8 Apr 2026

    The SportsPress – Sports Club & League Manager plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the settings_save() function in all versions up to, and including, 2.7.17. This makes it possible for unauthenticated attackers to update the permalink structure for the clubs

    Published: 5 Mar 2024