CVE Feed

    Dashboard / CVE

    —
    Unknown

    CVE-2019-25172

    Last Modified: 16 Sept 2025

    ** REJECT ** DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was in a CNA pool that was not assigned to any issues during 2019. Notes: none.

    Published: 26 Feb 2024
    —
    Unknown

    CVE-2019-25173

    Last Modified: 16 Sept 2025

    ** REJECT ** DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was in a CNA pool that was not assigned to any issues during 2019. Notes: none.

    Published: 26 Feb 2024
    —
    Unknown

    CVE-2019-25174

    Last Modified: 16 Sept 2025

    ** REJECT ** DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was in a CNA pool that was not assigned to any issues during 2019. Notes: none.

    Published: 26 Feb 2024
    —
    Unknown

    CVE-2019-25175

    Last Modified: 16 Sept 2025

    ** REJECT ** DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was in a CNA pool that was not assigned to any issues during 2019. Notes: none.

    Published: 26 Feb 2024
    —
    Unknown

    CVE-2019-25176

    Last Modified: 16 Sept 2025

    ** REJECT ** DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was in a CNA pool that was not assigned to any issues during 2019. Notes: none.

    Published: 26 Feb 2024
    —
    Unknown

    CVE-2019-25177

    Last Modified: 16 Sept 2025

    ** REJECT ** DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was in a CNA pool that was not assigned to any issues during 2019. Notes: none.

    Published: 26 Feb 2024
    —
    Unknown

    CVE-2019-25178

    Last Modified: 16 Sept 2025

    ** REJECT ** DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was in a CNA pool that was not assigned to any issues during 2019. Notes: none.

    Published: 26 Feb 2024
    —
    Unknown

    CVE-2019-25179

    Last Modified: 16 Sept 2025

    ** REJECT ** DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was in a CNA pool that was not assigned to any issues during 2019. Notes: none.

    Published: 26 Feb 2024
    —
    Unknown

    CVE-2019-25164

    Last Modified: 16 Sept 2025

    ** REJECT ** DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was in a CNA pool that was not assigned to any issues during 2019. Notes: none.

    Published: 26 Feb 2024
    —
    Unknown

    CVE-2019-25165

    Last Modified: 16 Sept 2025

    ** REJECT ** DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was in a CNA pool that was not assigned to any issues during 2019. Notes: none.

    Published: 26 Feb 2024
    —
    Unknown

    CVE-2019-25166

    Last Modified: 16 Sept 2025

    ** REJECT ** DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was in a CNA pool that was not assigned to any issues during 2019. Notes: none.

    Published: 26 Feb 2024
    —
    Unknown

    CVE-2019-25167

    Last Modified: 16 Sept 2025

    ** REJECT ** DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was in a CNA pool that was not assigned to any issues during 2019. Notes: none.

    Published: 26 Feb 2024
    —
    Unknown

    CVE-2019-25168

    Last Modified: 16 Sept 2025

    ** REJECT ** DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was in a CNA pool that was not assigned to any issues during 2019. Notes: none.

    Published: 26 Feb 2024
    —
    Unknown

    CVE-2019-25169

    Last Modified: 16 Sept 2025

    ** REJECT ** DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was in a CNA pool that was not assigned to any issues during 2019. Notes: none.

    Published: 26 Feb 2024
    —
    Unknown

    CVE-2019-25170

    Last Modified: 16 Sept 2025

    ** REJECT ** DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was in a CNA pool that was not assigned to any issues during 2019. Notes: none.

    Published: 26 Feb 2024
    —
    Unknown

    CVE-2019-25171

    Last Modified: 16 Sept 2025

    ** REJECT ** DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was in a CNA pool that was not assigned to any issues during 2019. Notes: none.

    Published: 26 Feb 2024
    —
    Unknown

    CVE-2019-25163

    Last Modified: 16 Sept 2025

    ** REJECT ** DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was in a CNA pool that was not assigned to any issues during 2019. Notes: none.

    Published: 26 Feb 2024
    0
    Low

    CVE-2024-27088

    Last Modified: 5 Feb 2025

    es5-ext contains ECMAScript 5 extensions. Passing functions with very long names or complex default argument names into `function#copy` or `function#toStringTokens` may cause the script to stall. The vulnerability is patched in v0.10.63.

    Published: 26 Feb 2024
    4.6
    Medium

    CVE-2024-27087

    Last Modified: 31 Dec 2024

    Kirby is a content management system. The new link field introduced in Kirby 4 allows several different link types that each validate the entered link to the relevant URL format. It also includes a "Custom" link type for advanced use cases that don't fit any of the pre-defined link formats. As the "Custom" link type is meant to be flexible, it also allows the javascript: URL scheme. In some use cases this can be intended, but it can also be misused by attackers to execute arbitrary JavaScript code when a user or visitor clicks on a link that is generated from the contents of the link field. This vulnerability is patched in 4.1.1.

    Published: 26 Feb 2024
    7.2
    High

    CVE-2024-27081

    Last Modified: 7 Feb 2025

    ESPHome is a system to control your ESP8266/ESP32. A security misconfiguration in the edit configuration file API in the dashboard component of ESPHome version 2023.12.9 (command line installation) allows authenticated remote attackers to read and write arbitrary files under the configuration directory rendering remote code execution possible. This vulnerability is patched in 2024.2.1.

    Published: 26 Feb 2024
    7.5
    High

    CVE-2024-23837

    Last Modified: 3 Nov 2025

    LibHTP is a security-aware parser for the HTTP protocol. Crafted traffic can cause excessive processing time of HTTP headers, leading to denial of service. This issue is addressed in 0.5.46.

    Published: 26 Feb 2024
    8.8
    High

    CVE-2024-21825

    Last Modified: 27 Apr 2026

    A heap-based buffer overflow vulnerability exists in the GGUF library GGUF_TYPE_ARRAY/GGUF_TYPE_STRING parsing functionality of llama.cpp Commit 18c2e17. A specially crafted .gguf file can lead to code execution. An attacker can provide a malicious file to trigger this vulnerability.

    Published: 26 Feb 2024
    8.8
    High

    CVE-2024-23496

    Last Modified: 27 Apr 2026

    A heap-based buffer overflow vulnerability exists in the GGUF library gguf_fread_str functionality of llama.cpp Commit 18c2e17. A specially crafted .gguf file can lead to code execution. An attacker can provide a malicious file to trigger this vulnerability.

    Published: 26 Feb 2024
    8.8
    High

    CVE-2024-21802

    Last Modified: 27 Apr 2026

    A heap-based buffer overflow vulnerability exists in the GGUF library info->ne functionality of llama.cpp Commit 18c2e17. A specially crafted .gguf file can lead to code execution. An attacker can provide a malicious file to trigger this vulnerability.

    Published: 26 Feb 2024
    8.8
    High

    CVE-2024-21836

    Last Modified: 27 Apr 2026

    A heap-based buffer overflow vulnerability exists in the GGUF library header.n_tensors functionality of llama.cpp Commit 18c2e17. A specially crafted .gguf file can lead to code execution. An attacker can provide a malicious file to trigger this vulnerability.

    Published: 26 Feb 2024
    8.8
    High

    CVE-2024-23605

    Last Modified: 27 Apr 2026

    A heap-based buffer overflow vulnerability exists in the GGUF library header.n_kv functionality of llama.cpp Commit 18c2e17. A specially crafted .gguf file can lead to code execution. An attacker can provide a malicious file to trigger this vulnerability.

    Published: 26 Feb 2024
    5.3
    Medium

    CVE-2024-1436

    Last Modified: 28 Apr 2026

    Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wiloke WooCommerce Coupon Popup, SmartBar, Slide In | MyShopKit.This issue affects WooCommerce Coupon Popup, SmartBar, Slide In | MyShopKit: from n/a through 1.0.9.

    Published: 26 Feb 2024
    5.3
    Medium

    CVE-2024-24568

    Last Modified: 13 Feb 2025

    Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to 7.0.3, the rules inspecting HTTP2 headers can get bypassed by crafted traffic. The vulnerability has been patched in 7.0.3.

    Published: 26 Feb 2024
    7.1
    High

    CVE-2024-23839

    Last Modified: 13 Feb 2025

    Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to 7.0.3, specially crafted traffic can cause a heap use after free if the ruleset uses the http.request_header or http.response_header keyword. The vulnerability has been patched in 7.0.3. To work around the vulnerability, avoid the http.request_header and http.response_header keywords.

    Published: 26 Feb 2024
    7.5
    High

    CVE-2024-23836

    Last Modified: 13 Feb 2025

    Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to versions 6.0.16 and 7.0.3, an attacker can craft traffic to cause Suricata to use far more CPU and memory for processing the traffic than needed, which can lead to extreme slow downs and denial of service. This vulnerability is patched in 6.0.16 or 7.0.3. Workarounds include disabling the affected protocol app-layer parser in the yaml and reducing the `stream.reassembly.depth` value helps reduce the severity of the issue.

    Published: 26 Feb 2024
    7.2
    High

    CVE-2024-24714

    Last Modified: 28 Apr 2026

    Unrestricted Upload of File with Dangerous Type vulnerability in bPlugins LLC Icons Font Loader.This issue affects Icons Font Loader: from n/a through 1.1.4.

    Published: 26 Feb 2024
    7.5
    High

    CVE-2024-23835

    Last Modified: 13 Feb 2025

    Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to version 7.0.3, excessive memory use during pgsql parsing could lead to OOM-related crashes. This vulnerability is patched in 7.0.3. As workaround, users can disable the pgsql app layer parser.

    Published: 26 Feb 2024
    9.9
    Critical

    CVE-2024-25909

    Last Modified: 28 Apr 2026

    Unrestricted Upload of File with Dangerous Type vulnerability in JoomUnited WP Media folder.This issue affects WP Media folder: from n/a through 5.7.2.

    Published: 26 Feb 2024
    10
    Critical

    CVE-2024-25913

    Last Modified: 28 Apr 2026

    Unrestricted Upload of File with Dangerous Type vulnerability in Skymoonlabs MoveTo.This issue affects MoveTo: from n/a through 6.2.

    Published: 26 Feb 2024
    10
    Critical

    CVE-2024-25925

    Last Modified: 28 Apr 2026

    Unrestricted Upload of File with Dangerous Type vulnerability in SYSBASICS WooCommerce Easy Checkout Field Editor, Fees & Discounts.This issue affects WooCommerce Easy Checkout Field Editor, Fees & Discounts: from n/a through 3.5.12.

    Published: 26 Feb 2024
    6.4
    Medium

    CVE-2024-1890

    Last Modified: 11 Mar 2025

    Vulnerability whereby an attacker could send a malicious link to an authenticated operator, which could allow remote attackers to perform a clickjacking attack on Sunny WebBox firmware version 1.6.1 and earlier.

    Published: 26 Feb 2024
    8.8
    High

    CVE-2024-1889

    Last Modified: 11 Mar 2025

    Cross-Site Request Forgery vulnerability in SMA Cluster Controller, affecting version 01.05.01.R. This vulnerability could allow an attacker to send a malicious link to an authenticated user to perform actions with these user permissions on the affected device.

    Published: 26 Feb 2024
    6.7
    Medium

    CVE-2023-49114

    Last Modified: 25 Apr 2025

    A DLL hijacking vulnerability was identified in the Qognify VMS Client Viewer version 7.1 or higher, which allows local users to execute arbitrary code and obtain higher privileges via careful placement of a malicious DLL, if some specific pre-conditions are met.

    Published: 26 Feb 2024
    7.5
    High

    CVE-2024-1622

    Last Modified: 27 Feb 2025

    Due to a mistake in error checking, Routinator will terminate when an incoming RTR connection is reset by the peer too quickly after opening.

    Published: 26 Feb 2024
    6.5
    Medium

    CVE-2024-0387

    Last Modified: 25 Feb 2025

    The EDS-4000/G4000 Series prior to version 3.2 includes IP forwarding capabilities that users cannot deactivate. An attacker may be able to send requests to the product and have it forwarded to the target. An attacker can bypass access controls or hide the source of malicious requests.

    Published: 26 Feb 2024
    3
    Low

    CVE-2024-1886

    Last Modified: 21 Nov 2024

    This vulnerability allows remote attackers to traverse the directory on the affected webOS of LG Signage.

    Published: 26 Feb 2024
    6.3
    Medium

    CVE-2024-1885

    Last Modified: 21 Nov 2024

    This vulnerability allows remote attackers to execute arbitrary code on the affected webOS of LG Signage.

    Published: 26 Feb 2024
    9.1
    Critical

    CVE-2024-1735

    Last Modified: 26 Aug 2025

    A vulnerability has been identified in armeria-saml versions less than 1.27.2, allowing the use of malicious SAML messages to bypass authentication. All users who rely on armeria-saml older than version 1.27.2 must upgrade to 1.27.2 or later.

    Published: 26 Feb 2024
    6.3
    Medium

    CVE-2024-1878

    Last Modified: 23 Dec 2024

    A vulnerability was found in SourceCodester Employee Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /myprofile.php. The manipulation of the argument id with the input 1%20or%201=1 leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-254726 is the identifier assigned to this vulnerability.

    Published: 26 Feb 2024
    6.3
    Medium

    CVE-2024-1877

    Last Modified: 23 Dec 2024

    A vulnerability was found in SourceCodester Employee Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /cancel.php. The manipulation of the argument id with the input 1%20or%201=1 leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-254725 was assigned to this vulnerability.

    Published: 26 Feb 2024
    7.3
    High

    CVE-2024-1876

    Last Modified: 23 Dec 2024

    A vulnerability was found in SourceCodester Employee Management System 1.0. It has been classified as critical. Affected is an unknown function of the file /psubmit.php. The manipulation of the argument pid with the input '+or+1%3d1%23 leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-254724.

    Published: 26 Feb 2024
    9.1
    Critical

    CVE-2019-25160

    Last Modified: 4 Aug 2026

    In the Linux kernel, the following vulnerability has been resolved: netlabel: fix out-of-bounds memory accesses There are two array out-of-bounds memory accesses, one in cipso_v4_map_lvl_valid(), the other in netlbl_bitmap_walk(). Both errors are embarassingly simple, and the fixes are straightforward. As a FYI for anyone backporting this patch to kernels prior to v4.8, you'll want to apply the netlbl_bitmap_walk() patch to cipso_v4_bitmap_walk() as netlbl_bitmap_walk() doesn't exist before Linux v4.8.

    Published: 26 Feb 2024
    6.1
    Medium

    CVE-2024-26465

    Last Modified: 15 Apr 2026

    A DOM based cross-site scripting (XSS) vulnerability in the component /beep/Beep.Instrument.js of stewdio beep.js before commit ef22ad7 allows attackers to execute arbitrary Javascript via sending a crafted URL.

    Published: 26 Feb 2024
    5.5
    Medium

    CVE-2021-46906

    Last Modified: 2 Jan 2026

    In the Linux kernel, the following vulnerability has been resolved: HID: usbhid: fix info leak in hid_submit_ctrl In hid_submit_ctrl(), the way of calculating the report length doesn't take into account that report->size can be zero. When running the syzkaller reproducer, a report of size 0 causes hid_submit_ctrl) to calculate transfer_buffer_length as 16384. When this urb is passed to the usb core layer, KMSAN reports an info leak of 16384 bytes. To fix this, first modify hid_report_len() to account for the zero report size case by using DIV_ROUND_UP for the division. Then, call it from hid_submit_ctrl().

    Published: 26 Feb 2024
    5.3
    Medium

    CVE-2024-26458

    Last Modified: 23 May 2025

    Kerberos 5 (aka krb5) 1.21.2 contains a memory leak in /krb5/src/lib/rpc/pmap_rmt.c.

    Published: 26 Feb 2024