CVE Feed

    Dashboard / CVE

    8.8
    High

    CVE-2023-36237

    Last Modified: 11 Apr 2025

    Cross Site Request Forgery vulnerability in Bagisto before v.1.5.1 allows an attacker to execute arbitrary code via a crafted HTML script.

    Published: 26 Feb 2024
    7.8
    High

    CVE-2019-25162

    Last Modified: 4 May 2025

    In the Linux kernel, the following vulnerability has been resolved: i2c: Fix a potential use after free Free the adap structure only after we are done using it. This patch just moves the put_device() down a bit to avoid the use after free. [wsa: added comment to the code, added Fixes tag]

    Published: 26 Feb 2024
    5.5
    Medium

    CVE-2020-36775

    Last Modified: 11 Jul 2025

    In the Linux kernel, the following vulnerability has been resolved: f2fs: fix to avoid potential deadlock Using f2fs_trylock_op() in f2fs_write_compressed_pages() to avoid potential deadlock like we did in f2fs_write_single_data_page().

    Published: 26 Feb 2024
    9.8
    Critical

    CVE-2024-24402

    Last Modified: 24 Mar 2025

    An issue in Nagios XI 2024R1.01 allows a remote attacker to escalate privileges via a crafted script to the /usr/local/nagios/bin/npcd component.

    Published: 26 Feb 2024
    4.2
    Medium

    CVE-2024-25081

    Last Modified: 4 Nov 2025

    Splinefont in FontForge through 20230101 allows command injection via crafted filenames.

    Published: 26 Feb 2024
    7.5
    High

    CVE-2024-26455

    Last Modified: 12 May 2025

    fluent-bit 2.2.2 contains a Use-After-Free vulnerability in /fluent-bit/plugins/custom_calyptia/calyptia.c.

    Published: 26 Feb 2024
    6.1
    Medium

    CVE-2024-26466

    Last Modified: 19 May 2025

    A DOM based cross-site scripting (XSS) vulnerability in the component /dom/ranges/Range-test-iframe.html of web-platform-tests/wpt before commit 938e843 allows attackers to execute arbitrary Javascript via sending a crafted URL.

    Published: 26 Feb 2024
    9.8
    Critical

    CVE-2023-49959

    Last Modified: 5 May 2025

    In Indo-Sol PROFINET-INspektor NT through 2.4.0, a command injection vulnerability in the gedtupdater service of the firmware allows remote attackers to execute arbitrary system commands with root privileges via a crafted filename parameter in POST requests to the /api/updater/ctrl/start_update endpoint.

    Published: 26 Feb 2024
    7.5
    High

    CVE-2023-49960

    Last Modified: 25 Apr 2025

    In Indo-Sol PROFINET-INspektor NT through 2.4.0, a path traversal vulnerability in the httpuploadd service of the firmware allows remote attackers to write to arbitrary files via a crafted filename parameter in requests to the /upload endpoint.

    Published: 26 Feb 2024
    7.8
    High

    CVE-2023-52474

    Last Modified: 4 May 2025

    In the Linux kernel, the following vulnerability has been resolved: IB/hfi1: Fix bugs with non-PAGE_SIZE-end multi-iovec user SDMA requests hfi1 user SDMA request processing has two bugs that can cause data corruption for user SDMA requests that have multiple payload iovecs where an iovec other than the tail iovec does not run up to the page boundary for the buffer pointed to by that iovec.a Here are the specific bugs: 1. user_sdma_txadd() does not use struct user_sdma_iovec->iov.iov_len. Rather, user_sdma_txadd() will add up to PAGE_SIZE bytes from iovec to the packet, even if some of those bytes are past iovec->iov.iov_len and are thus not intended to be in the packet. 2. user_sdma_txadd() and user_sdma_send_pkts() fail to advance to the next iovec in user_sdma_request->iovs when the current iovec is not PAGE_SIZE and does not contain enough data to complete the packet. The transmitted packet will contain the wrong data from the iovec pages. This has not been an issue with SDMA packets from hfi1 Verbs or PSM2 because they only produce iovecs that end short of PAGE_SIZE as the tail iovec of an SDMA request. Fixing these bugs exposes other bugs with the SDMA pin cache (struct mmu_rb_handler) that get in way of supporting user SDMA requests with multiple payload iovecs whose buffers do not end at PAGE_SIZE. So this commit fixes those issues as well. Here are the mmu_rb_handler bugs that non-PAGE_SIZE-end multi-iovec payload user SDMA requests can hit: 1. Overlapping memory ranges in mmu_rb_handler will result in duplicate pinnings. 2. When extending an existing mmu_rb_handler entry (struct mmu_rb_node), the mmu_rb code (1) removes the existing entry under a lock, (2) releases that lock, pins the new pages, (3) then reacquires the lock to insert the extended mmu_rb_node. If someone else comes in and inserts an overlapping entry between (2) and (3), insert in (3) will fail. The failure path code in this case unpins _all_ pages in either the original mmu_rb_node or the new mmu_rb_node that was inserted between (2) and (3). 3. In hfi1_mmu_rb_remove_unless_exact(), mmu_rb_node->refcount is incremented outside of mmu_rb_handler->lock. As a result, mmu_rb_node could be evicted by another thread that gets mmu_rb_handler->lock and checks mmu_rb_node->refcount before mmu_rb_node->refcount is incremented. 4. Related to #2 above, SDMA request submission failure path does not check mmu_rb_node->refcount before freeing mmu_rb_node object. If there are other SDMA requests in progress whose iovecs have pointers to the now-freed mmu_rb_node(s), those pointers to the now-freed mmu_rb nodes will be dereferenced when those SDMA requests complete.

    Published: 26 Feb 2024
    7.5
    High

    CVE-2024-22201

    Last Modified: 13 Feb 2025

    Jetty is a Java based web server and servlet engine. An HTTP/2 SSL connection that is established and TCP congested will be leaked when it times out. An attacker can cause many connections to end up in this state, and the server may run out of file descriptors, eventually causing the server to stop accepting new connections from valid clients. The vulnerability is patched in 9.4.54, 10.0.20, 11.0.20, and 12.0.6.

    Published: 26 Feb 2024
    8.1
    High

    CVE-2024-22873

    Last Modified: 5 Jul 2026

    Tencent Blueking CMDB v3.2.x to v3.9.x was discovered to contain a Server-Side Request Forgery (SSRF) via the event subscription function (/service/subscription.go). This vulnerability allows attackers to access internal requests via a crafted POST request.

    Published: 26 Feb 2024
    9.8
    Critical

    CVE-2024-24401

    Last Modified: 27 Jun 2025

    SQL Injection vulnerability in Nagios XI 2024R1.01 allows a remote attacker to execute arbitrary code via a crafted payload to the monitoringwizard.php component.

    Published: 26 Feb 2024
    6.5
    Medium

    CVE-2024-24721

    Last Modified: 18 Sept 2025

    An issue was discovered on Innovaphone PBX before 14r1 devices. The password form, used to authenticate, allows a Brute Force Attack through which an attacker may be able to access the administration panel

    Published: 26 Feb 2024
    6.5
    Medium

    CVE-2024-25082

    Last Modified: 4 Nov 2025

    Splinefont in FontForge through 20230101 allows command injection via crafted archives or compressed files.

    Published: 26 Feb 2024
    9.8
    Critical

    CVE-2024-25247

    Last Modified: 18 Sept 2025

    SQL Injection vulnerability in /app/api/controller/Store.php in Niushop B2B2C V5 allows attackers to run arbitrary SQL commands via latitude and longitude parameters.

    Published: 26 Feb 2024
    9.8
    Critical

    CVE-2024-25248

    Last Modified: 27 Mar 2025

    SQL Injection vulnerability in the orderGoodsDelivery() function in Niushop B2B2C V5 allows attackers to run arbitrary SQL commands via the order_id parameter.

    Published: 26 Feb 2024
    6.1
    Medium

    CVE-2024-25344

    Last Modified: 25 Apr 2025

    Cross Site Scripting vulnerability in ITFlow.org before commit v.432488eca3998c5be6b6b9e8f8ba01f54bc12378 allows a remtoe attacker to execute arbitrary code and obtain sensitive information via the settings.php, settings+company.php, settings_defaults.php,settings_integrations.php, settings_invoice.php, settings_localization.php, settings_mail.php components.

    Published: 26 Feb 2024
    6.5
    Medium

    CVE-2024-25410

    Last Modified: 25 Mar 2025

    flusity-CMS 2.33 is vulnerable to Unrestricted Upload of File with Dangerous Type in update_setting.php.

    Published: 26 Feb 2024
    9.8
    Critical

    CVE-2024-25751

    Last Modified: 13 Mar 2025

    A Stack Based Buffer Overflow vulnerability in Tenda AC9 v.3.0 with firmware version v.15.03.06.42_multi allows a remote attacker to execute arbitrary code via the fromSetSysTime function.

    Published: 26 Feb 2024
    5.5
    Medium

    CVE-2024-25763

    Last Modified: 14 Apr 2025

    openNDS 10.2.0 is vulnerable to Use-After-Free via /openNDS/src/auth.c.

    Published: 26 Feb 2024
    6.5
    Medium

    CVE-2024-25767

    Last Modified: 1 May 2025

    nanomq 0.21.2 contains a Use-After-Free vulnerability in /nanomq/nng/src/core/socket.c.

    Published: 26 Feb 2024
    7.5
    High

    CVE-2024-25768

    Last Modified: 1 May 2025

    OpenDMARC 1.4.2 contains a null pointer dereference vulnerability in /OpenDMARC/libopendmarc/opendmarc_policy.c.

    Published: 26 Feb 2024
    4.3
    Medium

    CVE-2024-25770

    Last Modified: 16 Apr 2025

    libming 0.4.8 contains a memory leak vulnerability in /libming/src/actioncompiler/listaction.c.

    Published: 26 Feb 2024
    —
    Unknown

    CVE-2024-27698

    Last Modified: 9 Mar 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

    Published: 26 Feb 2024
    7.5
    High

    CVE-2024-26461

    Last Modified: 23 May 2025

    Kerberos 5 (aka krb5) 1.21.2 contains a memory leak vulnerability in /krb5/src/lib/gssapi/krb5/k5sealv3.c.

    Published: 26 Feb 2024
    5.5
    Medium

    CVE-2024-26462

    Last Modified: 25 Mar 2025

    Kerberos 5 (aka krb5) 1.21.2 contains a memory leak vulnerability in /krb5/src/kdc/ndr.c.

    Published: 26 Feb 2024
    6.1
    Medium

    CVE-2024-26467

    Last Modified: 2 Jun 2025

    A DOM based cross-site scripting (XSS) vulnerability in the component generator.html of tabatkins/railroad-diagrams before commit ea9a123 allows attackers to execute arbitrary Javascript via sending a crafted URL.

    Published: 26 Feb 2024
    6.1
    Medium

    CVE-2024-26468

    Last Modified: 2 Jun 2025

    A DOM based cross-site scripting (XSS) vulnerability in the component index.html of jstrieb/urlpages before commit 035b647 allows attackers to execute arbitrary Javascript via sending a crafted URL.

    Published: 26 Feb 2024
    —
    Unknown

    CVE-2024-27441

    Last Modified: 13 Mar 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

    Published: 26 Feb 2024
    5.5
    Medium

    CVE-2024-26606

    Last Modified: 4 Nov 2025

    In the Linux kernel, the following vulnerability has been resolved: binder: signal epoll threads of self-work In (e)poll mode, threads often depend on I/O events to determine when data is ready for consumption. Within binder, a thread may initiate a command via BINDER_WRITE_READ without a read buffer and then make use of epoll_wait() or similar to consume any responses afterwards. It is then crucial that epoll threads are signaled via wakeup when they queue their own work. Otherwise, they risk waiting indefinitely for an event leaving their work unhandled. What is worse, subsequent commands won't trigger a wakeup either as the thread has pending work.

    Published: 26 Feb 2024
    7.5
    High

    CVE-2024-27454

    Last Modified: 18 Sept 2025

    orjson.loads in orjson before 3.9.15 does not limit recursion for deeply nested JSON documents.

    Published: 26 Feb 2024
    9.1
    Critical

    CVE-2024-27456

    Last Modified: 18 Sept 2025

    rack-cors (aka Rack CORS Middleware) 2.0.1 has 0666 permissions for the .rb files.

    Published: 26 Feb 2024
    9.1
    Critical

    CVE-2024-27455

    Last Modified: 15 Apr 2026

    In the Bentley ALIM Web application, certain configuration settings can cause exposure of a user's ALIM session token when the user attempts to download files. This is fixed in Assetwise ALIM Web 23.00.04.04 and Assetwise Information Integrity Server 23.00.02.03.

    Published: 26 Feb 2024
    9.8
    Critical

    CVE-2024-27444

    Last Modified: 14 Jul 2025

    langchain_experimental (aka LangChain Experimental) in LangChain before 0.1.8 allows an attacker to bypass the CVE-2023-44467 fix and execute arbitrary code via the __import__, __subclasses__, __builtins__, __globals__, __getattribute__, __bases__, __mro__, or __base__ attribute in Python code. These are not prohibited by pal_chain/base.py.

    Published: 26 Feb 2024
    9.8
    Critical

    CVE-2024-27447

    Last Modified: 11 Jun 2025

    pretix before 2024.1.1 mishandles file validation.

    Published: 26 Feb 2024
    —
    Unknown

    CVE-2024-27462

    Last Modified: 14 Apr 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

    Published: 26 Feb 2024
    —
    Unknown

    CVE-2024-27536

    Last Modified: 23 Apr 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

    Published: 26 Feb 2024
    —
    Unknown

    CVE-2024-27537

    Last Modified: 23 Apr 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

    Published: 26 Feb 2024
    —
    Unknown

    CVE-2024-27673

    Last Modified: 3 Apr 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

    Published: 26 Feb 2024
    —
    Unknown

    CVE-2024-27692

    Last Modified: 1 Mar 2024

    * REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2024-22939. Reason: This candidate is a duplicate of CVE-2024-22939. Notes: All CVE users should reference CVE-2024-22939 instead of this candidate.

    Published: 26 Feb 2024
    5
    Medium

    CVE-2024-2496

    Last Modified: 8 Nov 2025

    A NULL pointer dereference flaw was found in the udevConnectListAllInterfaces() function in libvirt. This issue can occur when detaching a host interface while at the same time collecting the list of interfaces via virConnectListAllInterfaces API. This flaw could be used to perform a denial of service attack by causing the libvirt daemon to crash.

    Published: 26 Feb 2024
    6.3
    Medium

    CVE-2024-1875

    Last Modified: 10 Dec 2024

    A vulnerability was found in SourceCodester Complaint Management System 1.0 and classified as critical. This issue affects some unknown processing of the file users/register-complaint.php of the component Lodge Complaint Section. The manipulation leads to unrestricted upload. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-254723.

    Published: 25 Feb 2024
    8.8
    High

    CVE-2024-0439

    Last Modified: 21 Nov 2024

    As a manager, you should not be able to modify a series of settings. In the UI this is indeed hidden as a convenience for the role since most managers would not be savvy enough to modify these settings. They can use their token to still modify those settings though through a standard HTTP request While this is not a critical vulnerability, it does indeed need to be patched to enforce the expected permission level.

    Published: 25 Feb 2024
    6.5
    Medium

    CVE-2024-0440

    Last Modified: 27 Feb 2025

    Attacker, with permission to submit a link or submits a link via POST to be collected that is using the file:// protocol can then introspect host files and other relatively stored files.

    Published: 25 Feb 2024
    5.5
    Medium

    CVE-2021-46905

    Last Modified: 4 May 2025

    In the Linux kernel, the following vulnerability has been resolved: net: hso: fix NULL-deref on disconnect regression Commit 8a12f8836145 ("net: hso: fix null-ptr-deref during tty device unregistration") fixed the racy minor allocation reported by syzbot, but introduced an unconditional NULL-pointer dereference on every disconnect instead. Specifically, the serial device table must no longer be accessed after the minor has been released by hso_serial_tty_unregister().

    Published: 25 Feb 2024
    5.5
    Medium

    CVE-2021-46904

    Last Modified: 4 May 2025

    In the Linux kernel, the following vulnerability has been resolved: net: hso: fix null-ptr-deref during tty device unregistration Multiple ttys try to claim the same the minor number causing a double unregistration of the same device. The first unregistration succeeds but the next one results in a null-ptr-deref. The get_free_serial_index() function returns an available minor number but doesn't assign it immediately. The assignment is done by the caller later. But before this assignment, calls to get_free_serial_index() would return the same minor number. Fix this by modifying get_free_serial_index to assign the minor number immediately after one is found to be and rename it to obtain_minor() to better reflect what it does. Similary, rename set_serial_by_index() to release_minor() and modify it to free up the minor number of the given hso_serial. Every obtain_minor() should have corresponding release_minor() call.

    Published: 25 Feb 2024
    5.4
    Medium

    CVE-2024-0435

    Last Modified: 25 Feb 2025

    User can send a chat that contains an XSS opportunity that will then run when the chat is sent and on subsequent page loads. Given the minimum requirement for a user to send a chat is to be given access to a workspace via an admin the risk is low. Additionally, the location in which the XSS renders is only limited to the user who submits the XSS. Ultimately, this attack is limited to the user attacking themselves. There is no anonymous chat submission unless the user does not take the minimum steps required to protect their instance.

    Published: 25 Feb 2024
    6.5
    Medium

    CVE-2024-0798

    Last Modified: 27 Feb 2025

    A privilege escalation vulnerability exists in mintplex-labs/anything-llm, allowing users with 'default' role to delete documents uploaded by 'admin'. Despite the intended restriction that prevents 'default' role users from deleting admin-uploaded documents, an attacker can exploit this vulnerability by sending a crafted DELETE request to the /api/system/remove-document endpoint. This vulnerability is due to improper access control checks, enabling unauthorized document deletion and potentially leading to loss of data integrity.

    Published: 25 Feb 2024
    5.9
    Medium

    CVE-2024-0436

    Last Modified: 27 Mar 2025

    Theoretically, it would be possible for an attacker to brute-force the password for an instance in single-user password protection mode via a timing attack given the linear nature of the `!==` used for comparison. The risk is minified by the additional overhead of the request, which varies in a non-constant nature making the attack less reliable to execute

    Published: 25 Feb 2024