CVE Feed

    Dashboard / CVE

    7.2
    High

    CVE-2023-52154

    Last Modified: 25 Mar 2025

    File Upload vulnerability in pmb/camera_upload.php in PMB 7.4.7 and earlier allows attackers to run arbitrary code via upload of crafted PHTML files.

    Published: 21 Feb 2024
    7.2
    High

    CVE-2023-52155

    Last Modified: 25 Mar 2025

    A SQL Injection vulnerability in /admin/sauvegarde/run.php in PMB 7.4.7 and earlier allows remote authenticated attackers to execute arbitrary SQL commands via the sauvegardes variable through the /admin/sauvegarde/run.php endpoint.

    Published: 21 Feb 2024
    6.3
    Medium

    CVE-2024-22220

    Last Modified: 8 May 2025

    An issue was discovered in Terminalfour 7.4 through 7.4.0004 QP3 and 8 through 8.3.19, and Formbank through 2.1.10-FINAL. Unauthenticated Stored Cross-Site Scripting can occur, with resultant Admin Session Hijacking. The attack vectors are Form Builder and Form Preview.

    Published: 21 Feb 2024
    8.1
    High

    CVE-2024-22243

    Last Modified: 15 Apr 2026

    Applications that use UriComponentsBuilder to parse an externally provided URL (e.g. through a query parameter) AND perform validation checks on the host of the parsed URL may be vulnerable to a open redirect https://cwe.mitre.org/data/definitions/601.html  attack or to a SSRF attack if the URL is used after passing validation checks.

    Published: 21 Feb 2024
    7.5
    High

    CVE-2024-22778

    Last Modified: 6 May 2025

    HackMD CodiMD <2.5.2 is vulnerable to Denial of Service.

    Published: 21 Feb 2024
    9.8
    Critical

    CVE-2024-25249

    Last Modified: 27 Mar 2025

    An issue in He3 App for macOS version 2.0.17, allows remote attackers to execute arbitrary code via the RunAsNode and enableNodeClilnspectArguments settings.

    Published: 21 Feb 2024
    4.9
    Medium

    CVE-2024-25288

    Last Modified: 5 May 2025

    SLIMS (Senayan Library Management Systems) 9 Bulian v9.6.1 is vulnerable to SQL Injection via pop-scope-vocabolary.php.

    Published: 21 Feb 2024
    6.1
    Medium

    CVE-2024-25381

    Last Modified: 6 May 2025

    There is a Stored XSS Vulnerability in Emlog Pro 2.2.8 Article Publishing, due to non-filtering of quoted content.

    Published: 21 Feb 2024
    7.5
    High

    CVE-2024-25461

    Last Modified: 6 May 2025

    Directory Traversal vulnerability in Terrasoft, Creatio Terrasoft CRM v.7.18.4.1532 allows a remote attacker to obtain sensitive information via a crafted request to the terrasoft.axd component.

    Published: 21 Feb 2024
    7.5
    High

    CVE-2024-25891

    Last Modified: 17 Mar 2025

    ChurchCRM 5.5.0 FRBidSheets.php is vulnerable to Blind SQL Injection (Time-based) via the CurrentFundraiser GET parameter.

    Published: 21 Feb 2024
    8.1
    High

    CVE-2024-25892

    Last Modified: 17 Mar 2025

    ChurchCRM 5.5.0 ConfirmReport.php is vulnerable to Blind SQL Injection (Time-based) via the familyId GET parameter.

    Published: 21 Feb 2024
    9.1
    Critical

    CVE-2024-25893

    Last Modified: 17 Mar 2025

    ChurchCRM 5.5.0 FRCertificates.php is vulnerable to Blind SQL Injection (Time-based) via the CurrentFundraiser GET parameter.

    Published: 21 Feb 2024
    9.8
    Critical

    CVE-2024-25894

    Last Modified: 17 Mar 2025

    ChurchCRM 5.5.0 /EventEditor.php is vulnerable to Blind SQL Injection (Time-based) via the EventCount POST parameter.

    Published: 21 Feb 2024
    6.1
    Medium

    CVE-2024-25895

    Last Modified: 17 Mar 2025

    A reflected cross-site scripting (XSS) vulnerability in ChurchCRM 5.5.0 allows remote attackers to inject arbitrary web script or HTML via the type parameter of /EventAttendance.php

    Published: 21 Feb 2024
    5.3
    Medium

    CVE-2024-25896

    Last Modified: 17 Mar 2025

    ChurchCRM 5.5.0 EventEditor.php is vulnerable to Blind SQL Injection (Time-based) via the EID POST parameter.

    Published: 21 Feb 2024
    9.8
    Critical

    CVE-2024-25897

    Last Modified: 22 Apr 2025

    ChurchCRM 5.5.0 FRCatalog.php is vulnerable to Blind SQL Injection (Time-based) via the CurrentFundraiser GET parameter.

    Published: 21 Feb 2024
    4.3
    Medium

    CVE-2024-26310

    Last Modified: 18 Mar 2025

    Archer Platform 6.8 before 6.14 P2 (6.14.0.2) contains an improper access control vulnerability. A remote authenticated malicious user could potentially exploit this to gain access to API information that should only be accessible with extra privileges.

    Published: 21 Feb 2024
    5.7
    Medium

    CVE-2024-26311

    Last Modified: 27 Aug 2025

    Archer Platform 6.x before 6.14 P2 HF1 (6.14.0.2.1) contains a reflected XSS vulnerability. A remote authenticated malicious Archer user could potentially exploit this by tricking a victim application user into supplying malicious JavaScript code to the vulnerable web application. This code is then reflected to the victim and gets executed by the web browser in the context of the vulnerable web application.

    Published: 21 Feb 2024
    —
    Unknown

    CVE-2024-27215

    Last Modified: 21 Feb 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2024-1709. Reason: This candidate is a duplicate of CVE-2024-1709. Notes: All CVE users should reference CVE-2024-1709 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage.

    Published: 21 Feb 2024
    7.5
    High

    CVE-2024-24479

    Last Modified: 4 Nov 2025

    A Buffer Overflow in Wireshark before 4.2.0 allows a remote attacker to cause a denial of service via the wsutil/to_str.c, and format_fractional_part_nsecs components. NOTE: this is disputed by the vendor because neither release 4.2.0 nor any other release was affected.

    Published: 21 Feb 2024
    9.8
    Critical

    CVE-2024-26582

    Last Modified: 4 Aug 2026

    In the Linux kernel, the following vulnerability has been resolved: net: tls: fix use-after-free with partial reads and async decrypt tls_decrypt_sg doesn't take a reference on the pages from clear_skb, so the put_page() in tls_decrypt_done releases them, and we trigger a use-after-free in process_rx_list when we try to read from the partially-read skb.

    Published: 21 Feb 2024
    6.5
    Medium

    CVE-2023-6787

    Last Modified: 11 Nov 2025

    A flaw was found in Keycloak that occurs from an error in the re-authentication mechanism within org.keycloak.authentication. This flaw allows hijacking an active Keycloak session by triggering a new authentication process with the query parameter "prompt=login," prompting the user to re-enter their credentials. If the user cancels this re-authentication by selecting "Restart login," an account takeover may occur, as the new session, with a different SUB, will possess the same SID as the previous session.

    Published: 21 Feb 2024
    5.4
    Medium

    CVE-2022-45169

    Last Modified: 21 Nov 2024

    An issue was discovered in LIVEBOX Collaboration vDesk through v031. A URL Redirection to an Untrusted Site (Open Redirect) can occur under the /api/v1/notification/createnotification endpoint, allowing an authenticated user to send an arbitrary push notification to any other user of the system. This push notification can include an (invisible) clickable link.

    Published: 21 Feb 2024
    5.4
    Medium

    CVE-2022-45179

    Last Modified: 26 Feb 2026

    An issue was discovered in LIVEBOX Collaboration vDesk through v031. A basic XSS vulnerability exists under the /api/v1/vdeskintegration/todo/createorupdate endpoint via the title parameter and /dashboard/reminders. A remote user (authenticated to the product) can store arbitrary HTML code in the reminder section title in order to corrupt the web page (for example, by creating phishing sections to exfiltrate victims' credentials).

    Published: 21 Feb 2024
    5.4
    Medium

    CVE-2024-1676

    Last Modified: 13 Feb 2025

    Inappropriate implementation in Navigation in Google Chrome prior to 122.0.6261.57 allowed a remote attacker to spoof security UI via a crafted HTML page. (Chromium security severity: Low)

    Published: 20 Feb 2024
    8.8
    High

    CVE-2024-1675

    Last Modified: 14 Mar 2025

    Insufficient policy enforcement in Download in Google Chrome prior to 122.0.6261.57 allowed a remote attacker to bypass filesystem restrictions via a crafted HTML page. (Chromium security severity: Medium)

    Published: 20 Feb 2024
    8.8
    High

    CVE-2024-1674

    Last Modified: 13 Feb 2025

    Inappropriate implementation in Navigation in Google Chrome prior to 122.0.6261.57 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Medium)

    Published: 20 Feb 2024
    8.8
    High

    CVE-2024-1673

    Last Modified: 13 Feb 2025

    Use after free in Accessibility in Google Chrome prior to 122.0.6261.57 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via specific UI gestures. (Chromium security severity: Medium)

    Published: 20 Feb 2024
    5.4
    Medium

    CVE-2024-1672

    Last Modified: 13 Feb 2025

    Inappropriate implementation in Content Security Policy in Google Chrome prior to 122.0.6261.57 allowed a remote attacker to bypass content security policy via a crafted HTML page. (Chromium security severity: Medium)

    Published: 20 Feb 2024
    6.5
    Medium

    CVE-2024-1671

    Last Modified: 27 Mar 2025

    Inappropriate implementation in Site Isolation in Google Chrome prior to 122.0.6261.57 allowed a remote attacker to bypass content security policy via a crafted HTML page. (Chromium security severity: Medium)

    Published: 20 Feb 2024
    8.8
    High

    CVE-2024-1670

    Last Modified: 13 Feb 2025

    Use after free in Mojo in Google Chrome prior to 122.0.6261.57 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

    Published: 20 Feb 2024
    8.8
    High

    CVE-2024-1669

    Last Modified: 13 Feb 2025

    Out of bounds memory access in Blink in Google Chrome prior to 122.0.6261.57 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High)

    Published: 20 Feb 2024
    5.3
    Medium

    CVE-2023-6936

    Last Modified: 26 Mar 2025

    In wolfSSL prior to 5.6.6, if callback functions are enabled (via the WOLFSSL_CALLBACKS flag), then a malicious TLS client or network attacker can trigger a buffer over-read on the heap of 5 bytes (WOLFSSL_CALLBACKS is only intended for debugging).

    Published: 20 Feb 2024
    4.6
    Medium

    CVE-2024-26140

    Last Modified: 5 Feb 2025

    com.yetanalytics/lrs is the Yet Analytics Core LRS Library. Prior to version 1.2.17 of the LRS library and version 0.7.5 of SQL LRS, a maliciously crafted xAPI statement could be used to perform script or other tag injection in the LRS Statement Browser. The problem is patched in version 1.2.17 of the LRS library and version 0.7.5 of SQL LRS. No known workarounds exist.

    Published: 20 Feb 2024
    8.3
    High

    CVE-2024-23830

    Last Modified: 18 Dec 2024

    MantisBT is an open source issue tracker. Prior to version 2.26.1, an unauthenticated attacker who knows a user's email address and username can hijack the user's account by poisoning the link in the password reset notification message. A patch is available in version 2.26.1. As a workaround, define `$g_path` as appropriate in `config_inc.php`.

    Published: 20 Feb 2024
    7.5
    High

    CVE-2024-26136

    Last Modified: 5 Feb 2025

    kedi ElectronCord is a bot management tool for Discord. Commit aaaeaf4e6c99893827b2eea4dd02f755e1e24041 exposes an account access token in the `config.json` file. Malicious actors could potentially exploit this vulnerability to gain unauthorized access to sensitive information or perform malicious actions on behalf of the repository owner. As of time of publication, it is unknown whether the owner of the repository has rotated the token or taken other mitigation steps aside from informing users of the situation.

    Published: 20 Feb 2024
    9.1
    Critical

    CVE-2024-25141

    Last Modified: 28 Apr 2025

    When ssl was enabled for Mongo Hook, default settings included "allow_insecure" which caused that certificates were not validated. This was unexpected and undocumented. Users are recommended to upgrade to version 4.0.0, which fixes this issue.

    Published: 20 Feb 2024
    8.3
    High

    CVE-2024-26135

    Last Modified: 22 Apr 2025

    MeshCentral is a full computer management web site. Versions prior to 1.1.21 a cross-site websocket hijacking (CSWSH) vulnerability within the control.ashx endpoint. This component is the primary mechanism used within MeshCentral to perform administrative actions on the server. The vulnerability is exploitable when an attacker is able to convince a victim end-user to click on a malicious link to a page hosting an attacker-controlled site. The attacker can then originate a cross-site websocket connection using client-side JavaScript code to connect to `control.ashx` as the victim user within MeshCentral. Version 1.1.21 contains a patch for this issue.

    Published: 20 Feb 2024
    6.4
    Medium

    CVE-2024-1058

    Last Modified: 8 Apr 2026

    The SiteOrigin Widgets Bundle plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the onclick parameter in all versions up to, and including, 1.58.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with contributor access or higher to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. 1.58.3 offers a partial fix.

    Published: 20 Feb 2024
    6.5
    Medium

    CVE-2024-1043

    Last Modified: 8 Apr 2026

    The AMP for WP – Accelerated Mobile Pages plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the 'amppb_remove_saved_layout_data' function in all versions up to, and including, 1.0.93.1. This makes it possible for authenticated attackers, with contributor access and above, to delete arbitrary posts on the site.

    Published: 20 Feb 2024
    5.4
    Medium

    CVE-2024-1171

    Last Modified: 8 Apr 2026

    The Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Filterable Gallery Widget in all versions up to, and including, 5.9.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 20 Feb 2024
    4.3
    Medium

    CVE-2024-1090

    Last Modified: 8 Apr 2026

    The ImageRecycle pdf & image compression plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the stopOptimizeAll function in all versions up to, and including, 3.1.13. This makes it possible for authenticated attackers, with subscriber-level access and above, to modify image optimization settings.

    Published: 20 Feb 2024
    5.4
    Medium

    CVE-2024-1172

    Last Modified: 8 Apr 2026

    The Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Accordion widget in all versions up to, and including, 5.9.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 20 Feb 2024
    4.3
    Medium

    CVE-2024-1218

    Last Modified: 8 Apr 2026

    The Contact Form builder with drag & drop for WordPress – Kali Forms plugin for WordPress is vulnerable to unauthorized access and modification of data via API due to an inconsistent capability check on several REST endpoints in all versions up to, and including, 2.3.41. This makes it possible for authenticated attackers, with contributor access and higher, to obtain access to or modify forms or entries.

    Published: 20 Feb 2024
    4.3
    Medium

    CVE-2024-1133

    Last Modified: 8 Apr 2026

    The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to unauthorized access of restricted Q&A content due to a missing capability check when interacting with questions in all versions up to, and including, 2.6.0. This makes it possible for authenticated attackers, with subscriber access or higher, to interact with questions in courses in which they are not enrolled including private courses.

    Published: 20 Feb 2024
    5.3
    Medium

    CVE-2024-1294

    Last Modified: 8 Apr 2026

    The Sunshine Photo Cart: Free Client Galleries for Photographers plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.0.24 via the 'invoice'. This makes it possible for unauthenticated attackers to extract sensitive data including customer email and physical addresses.

    Published: 20 Feb 2024
    6.4
    Medium

    CVE-2024-0838

    Last Modified: 8 Apr 2026

    The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the side image URL parameter in the Age Gate in all versions up to, and including, 3.10.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor access or higher, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CVE-2024-29108 is likely a duplicate of this issue.

    Published: 20 Feb 2024
    5.3
    Medium

    CVE-2024-0516

    Last Modified: 8 Apr 2026

    The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to unauthorized post metadata update due to a missing capability check on the wpr_update_form_action_meta function in all versions up to, and including, 1.3.87. This makes it possible for unauthenticated attackers to update certain metadata.

    Published: 20 Feb 2024
    4.4
    Medium

    CVE-2024-0604

    Last Modified: 8 Apr 2026

    The Best WordPress Gallery Plugin – FooGallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 2.4.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.

    Published: 20 Feb 2024
    6.1
    Medium

    CVE-2024-0821

    Last Modified: 8 Apr 2026

    The Cost of Goods Sold (COGS): Cost & Profit Calculator for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'section' parameter in all versions up to, and including, 3.2.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

    Published: 20 Feb 2024