CVE Feed

    Dashboard / CVE

    8.1
    High

    CVE-2022-48629

    Last Modified: 4 Aug 2026

    In the Linux kernel, the following vulnerability has been resolved: crypto: qcom-rng - ensure buffer for generate is completely filled The generate function in struct rng_alg expects that the destination buffer is completely filled if the function returns 0. qcom_rng_read() can run into a situation where the buffer is partially filled with randomness and the remaining part of the buffer is zeroed since qcom_rng_generate() doesn't check the return value. This issue can be reproduced by running the following from libkcapi: kcapi-rng -b 9000000 > OUTFILE The generated OUTFILE will have three huge sections that contain all zeros, and this is caused by the code where the test 'val & PRNG_STATUS_DATA_AVAIL' fails. Let's fix this issue by ensuring that qcom_rng_read() always returns with a full buffer if the function returns success. Let's also have qcom_rng_generate() return the correct value. Here's some statistics from the ent project (https://www.fourmilab.ch/random/) that shows information about the quality of the generated numbers: $ ent -c qcom-random-before Value Char Occurrences Fraction 0 606748 0.067416 1 33104 0.003678 2 33001 0.003667 ... 253 � 32883 0.003654 254 � 33035 0.003671 255 � 33239 0.003693 Total: 9000000 1.000000 Entropy = 7.811590 bits per byte. Optimum compression would reduce the size of this 9000000 byte file by 2 percent. Chi square distribution for 9000000 samples is 9329962.81, and randomly would exceed this value less than 0.01 percent of the times. Arithmetic mean value of data bytes is 119.3731 (127.5 = random). Monte Carlo value for Pi is 3.197293333 (error 1.77 percent). Serial correlation coefficient is 0.159130 (totally uncorrelated = 0.0). Without this patch, the results of the chi-square test is 0.01%, and the numbers are certainly not random according to ent's project page. The results improve with this patch: $ ent -c qcom-random-after Value Char Occurrences Fraction 0 35432 0.003937 1 35127 0.003903 2 35424 0.003936 ... 253 � 35201 0.003911 254 � 34835 0.003871 255 � 35368 0.003930 Total: 9000000 1.000000 Entropy = 7.999979 bits per byte. Optimum compression would reduce the size of this 9000000 byte file by 0 percent. Chi square distribution for 9000000 samples is 258.77, and randomly would exceed this value 42.24 percent of the times. Arithmetic mean value of data bytes is 127.5006 (127.5 = random). Monte Carlo value for Pi is 3.141277333 (error 0.01 percent). Serial correlation coefficient is 0.000468 (totally uncorrelated = 0.0). This change was tested on a Nexus 5 phone (msm8974 SoC).

    Published: 5 Mar 2024
    5.4
    Medium

    CVE-2024-24785

    Last Modified: 15 Apr 2026

    If errors returned from MarshalJSON methods contain user controlled data, they may be used to break the contextual auto-escaping behavior of the html/template package, allowing for subsequent actions to inject unexpected content into templates.

    Published: 5 Mar 2024
    7.5
    High

    CVE-2024-24784

    Last Modified: 15 Apr 2026

    The ParseAddressList function incorrectly handles comments (text within parentheses) within display names. Since this is a misalignment with conforming address parsers, it can result in different trust decisions being made by programs using different parsers.

    Published: 5 Mar 2024
    5.9
    Medium

    CVE-2024-24783

    Last Modified: 15 Apr 2026

    Verifying a certificate chain which contains a certificate with an unknown public key algorithm will cause Certificate.Verify to panic. This affects all crypto/tls clients, and servers that set Config.ClientAuth to VerifyClientCertIfGiven or RequireAndVerifyClientCert. The default behavior is for TLS servers to not verify client certificates.

    Published: 5 Mar 2024
    5.8
    Medium

    CVE-2024-27564

    Last Modified: 20 Mar 2025

    pictureproxy.php in the dirk1983 mm1.ltd source code f9f4bbc allows SSRF via the url parameter. NOTE: the references section has an archived copy of pictureproxy.php from its original GitHub location, but the repository name might later change because it is misleading.

    Published: 5 Mar 2024
    8.4
    High

    CVE-2024-25858

    Last Modified: 23 May 2025

    In Foxit PDF Reader before 2024.1 and PDF Editor before 2024.1, code execution via JavaScript could occur because of an unoptimized prompt message for users to review parameters of commands.

    Published: 5 Mar 2024
    7.5
    High

    CVE-2023-5685

    Last Modified: 15 Apr 2026

    A flaw was found in XNIO. The XNIO NotifierState that can cause a Stack Overflow Exception when the chain of notifier states becomes problematically large can lead to uncontrolled resource management and a possible denial of service (DoS).

    Published: 5 Mar 2024
    8.8
    High

    CVE-2023-43318

    Last Modified: 4 Nov 2025

    TP-Link JetStream Smart Switch TL-SG2210P 5.0 Build 20211201 allows attackers to escalate privileges via modification of the 'tid' and 'usrlvl' values in GET requests.

    Published: 5 Mar 2024
    8.1
    High

    CVE-2024-27561

    Last Modified: 21 Jan 2025

    A Server-Side Request Forgery (SSRF) in the installUpdateThemePluginAction function of WonderCMS v3.1.3 allows attackers to force the application to make arbitrary requests via injection of crafted URLs into the installThemePlugin parameter.

    Published: 5 Mar 2024
    7.8
    High

    CVE-2024-24098

    Last Modified: 23 Oct 2025

    Code-projects Scholars Tracking System 1.0 is vulnerable to SQL Injection via the News Feed.

    Published: 5 Mar 2024
    7.5
    High

    CVE-2024-24786

    Last Modified: 23 Sept 2026

    The protojson.Unmarshal function can enter an infinite loop when unmarshaling certain forms of invalid JSON. This condition can occur when unmarshaling into a message which contains a google.protobuf.Any value, or when the UnmarshalOptions.DiscardUnknown option is set.

    Published: 5 Mar 2024
    5.5
    Medium

    CVE-2022-48630

    Last Modified: 4 May 2025

    In the Linux kernel, the following vulnerability has been resolved: crypto: qcom-rng - fix infinite loop on requests not multiple of WORD_SZ The commit referenced in the Fixes tag removed the 'break' from the else branch in qcom_rng_read(), causing an infinite loop whenever 'max' is not a multiple of WORD_SZ. This can be reproduced e.g. by running: kcapi-rng -b 67 >/dev/null There are many ways to fix this without adding back the 'break', but they all seem more awkward than simply adding it back, so do just that. Tested on a machine with Qualcomm Amberwing processor.

    Published: 5 Mar 2024
    5.3
    Medium

    CVE-2024-27563

    Last Modified: 21 Jan 2025

    A Server-Side Request Forgery (SSRF) in the getFileFromRepo function of WonderCMS v3.1.3 allows attackers to force the application to make arbitrary requests via injection of crafted URLs into the pluginThemeUrl parameter.

    Published: 5 Mar 2024
    6.1
    Medium

    CVE-2022-46088

    Last Modified: 8 Jan 2025

    Online Flight Booking Management System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the feedback form.

    Published: 5 Mar 2024
    9.6
    Critical

    CVE-2024-24276

    Last Modified: 27 Mar 2025

    Cross Site Scripting (XSS) vulnerability in Teamwire Windows desktop client v.2.0.1 through v.2.4.0 allows a remote attacker to obtain sensitive information via a crafted payload to the chat name, message preview, username and group name components.

    Published: 5 Mar 2024
    9.1
    Critical

    CVE-2024-26339

    Last Modified: 1 Apr 2025

    swftools v0.9.2 was discovered to contain a strcpy parameter overlap via /home/swftools/src/swfc+0x48318a.

    Published: 5 Mar 2024
    4.3
    Medium

    CVE-2023-45289

    Last Modified: 15 Apr 2026

    When following an HTTP redirect to a domain which is not a subdomain match or exact match of the initial domain, an http.Client does not forward sensitive headers such as "Authorization" or "Cookie". For example, a redirect from foo.com to www.foo.com will forward the Authorization header, but a redirect to bar.com will not. A maliciously crafted HTTP redirect could cause sensitive headers to be unexpectedly forwarded.

    Published: 5 Mar 2024
    6.5
    Medium

    CVE-2023-45290

    Last Modified: 15 Apr 2026

    When parsing a multipart form (either explicitly with Request.ParseMultipartForm or implicitly with Request.FormValue, Request.PostFormValue, or Request.FormFile), limits on the total size of the parsed form were not applied to the memory consumed while reading a single form line. This permits a maliciously crafted input containing very long lines to cause allocation of arbitrarily large amounts of memory, potentially leading to memory exhaustion. With fix, the ParseMultipartForm function now correctly limits the maximum size of form lines.

    Published: 5 Mar 2024
    6.1
    Medium

    CVE-2023-48644

    Last Modified: 3 Jun 2025

    An issue was discovered in the Archibus app 4.0.3 for iOS. There is an XSS vulnerability in the create work request feature of the maintenance module, via the description field. This allows an attacker to perform an action on behalf of the user, exfiltrate data, and so on.

    Published: 5 Mar 2024
    7.2
    High

    CVE-2024-22188

    Last Modified: 15 Sept 2025

    TYPO3 before 13.0.1 allows an authenticated admin user (with system maintainer privileges) to execute arbitrary shell commands (with the privileges of the web server) via a command injection vulnerability in form fields of the Install Tool. The fixed versions are 8.7.57 ELTS, 9.5.46 ELTS, 10.4.43 ELTS, 11.5.35 LTS, 12.4.11 LTS, and 13.0.1.

    Published: 5 Mar 2024
    7.5
    High

    CVE-2024-22889

    Last Modified: 21 Jan 2025

    Due to incorrect access control in Plone version v6.0.9, remote attackers can view and list all files hosted on the website via sending a crafted request.

    Published: 5 Mar 2024
    9.6
    Critical

    CVE-2024-24275

    Last Modified: 27 Mar 2025

    Cross Site Scripting vulnerability in Teamwire Windows desktop client v.2.0.1 through v.2.4.0 allows a remote attacker to obtain sensitive information via a crafted payload to the global search function.

    Published: 5 Mar 2024
    7.5
    High

    CVE-2024-24278

    Last Modified: 23 May 2025

    An issue in Teamwire Windows desktop client v.2.0.1 through v.2.4.0 allows a remote attacker to obtain sensitive information via a crafted payload to the message function.

    Published: 5 Mar 2024
    7.5
    High

    CVE-2024-25269

    Last Modified: 16 Apr 2025

    libheif <= 1.17.6 contains a memory leak in the function JpegEncoder::Encode. This flaw allows an attacker to cause a denial of service attack.

    Published: 5 Mar 2024
    7.8
    High

    CVE-2024-25817

    Last Modified: 15 Jan 2025

    Buffer Overflow vulnerability in eza before version 0.18.2, allows local attackers to execute arbitrary code via the .git/HEAD, .git/refs, and .git/objects components.

    Published: 5 Mar 2024
    4.3
    Medium

    CVE-2024-26337

    Last Modified: 1 Apr 2025

    swftools v0.9.2 was discovered to contain a segmentation violation via the function s_font at swftools/src/swfc.c.

    Published: 5 Mar 2024
    5.5
    Medium

    CVE-2024-26333

    Last Modified: 1 Apr 2025

    swftools v0.9.2 was discovered to contain a segmentation violation via the function free_lines at swftools/lib/modules/swfshape.c.

    Published: 5 Mar 2024
    6.2
    Medium

    CVE-2024-26334

    Last Modified: 1 Apr 2025

    swftools v0.9.2 was discovered to contain a segmentation violation via the function compileSWFActionCode at swftools/lib/action/actioncompiler.c.

    Published: 5 Mar 2024
    5.5
    Medium

    CVE-2024-26335

    Last Modified: 1 Apr 2025

    swftools v0.9.2 was discovered to contain a segmentation violation via the function state_free at swftools/src/swfc-history.c.

    Published: 5 Mar 2024
    9.8
    Critical

    CVE-2024-27565

    Last Modified: 21 Jan 2025

    A Server-Side Request Forgery (SSRF) in weixin.php of ChatGPT-wechat-personal commit a0857f6 allows attackers to force the application to make arbitrary requests.

    Published: 5 Mar 2024
    6.1
    Medium

    CVE-2024-27627

    Last Modified: 15 Apr 2026

    A reflected cross-site scripting (XSS) vulnerability exists in SuperCali version 1.1.0, allowing remote attackers to execute arbitrary JavaScript code via the email parameter in the bad_password.php page.

    Published: 5 Mar 2024
    5.9
    Medium

    CVE-2024-27623

    Last Modified: 17 Dec 2025

    CMS Made Simple version 2.2.19 is vulnerable to Server-Side Template Injection (SSTI). The vulnerability exists within the Design Manager, particularly when editing the Breadcrumbs.

    Published: 5 Mar 2024
    7.2
    High

    CVE-2024-27622

    Last Modified: 28 Mar 2025

    A remote code execution vulnerability has been identified in the User Defined Tags module of CMS Made Simple version 2.2.19 / 2.2.21. This vulnerability arises from inadequate sanitization of user-supplied input in the 'Code' section of the module. As a result, authenticated users with administrative privileges can inject and execute arbitrary PHP code.

    Published: 5 Mar 2024
    4.8
    Medium

    CVE-2024-27625

    Last Modified: 28 Mar 2025

    CMS Made Simple Version 2.2.19 is vulnerable to Cross Site Scripting (XSS). This vulnerability resides in the File Manager module of the admin panel. Specifically, the issue arises due to inadequate sanitization of user input in the "New directory" field.

    Published: 5 Mar 2024
    6.1
    Medium

    CVE-2024-27626

    Last Modified: 17 Jun 2025

    A Reflected Cross-Site Scripting (XSS) vulnerability has been identified in Dotclear version 2.29. The flaw exists within the Search functionality of the Admin Panel.

    Published: 5 Mar 2024
    9.8
    Critical

    CVE-2024-27764

    Last Modified: 21 Jan 2025

    An issue in Jeewms v.3.7 and before allows a remote attacker to escalate privileges via the AuthInterceptor component.

    Published: 5 Mar 2024
    7.5
    High

    CVE-2024-27765

    Last Modified: 21 Jan 2025

    Directory Traversal vulnerability in Jeewms v.3.7 and before allows a remote attacker to obtain sensitive information via the cgformTemplateController component.

    Published: 5 Mar 2024
    9.8
    Critical

    CVE-2023-38944

    Last Modified: 4 Nov 2025

    An issue in Multilaser RE160V firmware v12.03.01.09_pt and Multilaser RE163V firmware v12.03.01.10_pt allows attackers to bypass the access control and gain complete access to the application via modifying a HTTP header.

    Published: 5 Mar 2024
    5
    Medium

    CVE-2023-41829

    Last Modified: 15 Apr 2026

    An improper export vulnerability was reported in the Motorola Carrier Services application that could allow a malicious, local application to read files without authorization.

    Published: 4 Mar 2024
    5.1
    Medium

    CVE-2023-41827

    Last Modified: 15 Apr 2026

    An improper export vulnerability was reported in the Motorola OTA update application, that could allow a malicious, local application to inject an HTML-based message on screen UI.

    Published: 4 Mar 2024
    4.7
    Medium

    CVE-2024-2168

    Last Modified: 18 Feb 2025

    A vulnerability was found in SourceCodester Online Tours & Travels Management System 1.0. It has been classified as critical. Affected is an unknown function of the file /admin/operations/expense_category.php of the component HTTP POST Request Handler. The manipulation of the argument status leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-255678 is the identifier assigned to this vulnerability.

    Published: 4 Mar 2024
    8.1
    High

    CVE-2024-2048

    Last Modified: 13 Nov 2025

    Vault and Vault Enterprise (“Vault”) TLS certificate auth method did not correctly validate client certificates when configured with a non-CA certificate as trusted certificate. In this configuration, an attacker may be able to craft a malicious certificate that could be used to bypass authentication. Fixed in Vault 1.15.5 and 1.14.10.

    Published: 4 Mar 2024
    3.1
    Low

    CVE-2023-6068

    Last Modified: 18 Dec 2025

    On affected 7130 Series FPGA platforms running MOS and recent versions of the MultiAccess FPGA, application of ACL’s may result in incorrect operation of the configured ACL for a port resulting in some packets that should be denied being permitted and some

    Published: 4 Mar 2024
    8.8
    High

    CVE-2024-27889

    Last Modified: 22 Oct 2025

    Multiple SQL Injection vulnerabilities exist in the reporting application of the Arista Edge Threat Management - Arista NG Firewall (NGFW). A user with advanced report application access rights can exploit the SQL injection, allowing them to execute commands on the underlying operating system with elevated privileges.

    Published: 4 Mar 2024
    7.5
    High

    CVE-2023-32331

    Last Modified: 31 Jan 2025

    IBM Connect:Express for UNIX 1.5.0 is vulnerable to a buffer overflow that could allow a remote attacker to cause a denial of service through its browser UI. IBM X-Force ID: 254979.

    Published: 4 Mar 2024
    6.1
    Medium

    CVE-2023-38360

    Last Modified: 7 Jan 2025

    IBM CICS TX Advanced 10.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 260769.

    Published: 4 Mar 2024
    7.3
    High

    CVE-2024-27199

    Last Modified: 21 Apr 2026

    In JetBrains TeamCity before 2023.11.4 path traversal allowing to perform limited admin actions was possible

    Published: 4 Mar 2024
    9.8
    Critical

    CVE-2024-27198

    Last Modified: 24 Oct 2025

    In JetBrains TeamCity before 2023.11.4 authentication bypass allowing to perform admin actions was possible

    Published: 4 Mar 2024
    6.5
    Medium

    CVE-2024-1316

    Last Modified: 27 Jun 2025

    The Event Tickets and Registration WordPress plugin before 5.8.1, Events Tickets Plus WordPress plugin before 5.9.1 does not prevent users with at least the contributor role from leaking the existence of certain events they shouldn't have access to. (e.g. draft, private, pending review, pw-protected, and trashed events).

    Published: 4 Mar 2024
    4.3
    Medium

    CVE-2024-1319

    Last Modified: 24 Apr 2025

    The Events Tickets Plus WordPress plugin before 5.9.1 does not prevent users with at least the contributor role from leaking the attendees list on any post type regardless of status. (e.g. draft, private, pending review, password-protected, and trashed posts).

    Published: 4 Mar 2024