CVE Feed

    Dashboard / CVE

    5.3
    Medium

    CVE-2024-1562

    Last Modified: 8 Apr 2026

    The WooCommerce Google Sheet Connector plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the execute_post_data function in all versions up to, and including, 1.3.11. This makes it possible for unauthenticated attackers to update plugin settings.

    Published: 21 Feb 2024
    4.7
    Medium

    CVE-2024-1501

    Last Modified: 8 Apr 2026

    The Database Reset plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.22. This is due to missing or incorrect nonce validation on the install_wpr() function. This makes it possible for unauthenticated attackers to install the WP Reset Plugin via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

    Published: 21 Feb 2024
    5.4
    Medium

    CVE-2024-25151

    Last Modified: 28 Jan 2025

    The Calendar module in Liferay Portal 7.2.0 through 7.4.2, and older unsupported versions, and Liferay DXP 7.3 before service pack 3, 7.2 before fix pack 15, and older unsupported versions does not escape user supplied data in the default notification email template, which allows remote authenticated users to inject arbitrary web script or HTML via the title of a calendar event or the user's name. This may lead to a content spoofing or cross-site scripting (XSS) attacks depending on the capability of the receiver's mail client.

    Published: 21 Feb 2024
    9
    Critical

    CVE-2023-40191

    Last Modified: 28 Jan 2025

    Reflected cross-site scripting (XSS) vulnerability in the instance settings for Accounts in Liferay Portal 7.4.3.44 through 7.4.3.97, and Liferay DXP 2023.Q3 before patch 6, and 7.4 update 44 through 92 allows remote attackers to inject arbitrary web script or HTML via a crafted payload injected into the “Blocked Email Domains” text field

    Published: 21 Feb 2024
    6.5
    Medium

    CVE-2024-1108

    Last Modified: 8 Apr 2026

    The Plugin Groups plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the admin_init() function in all versions up to, and including, 2.0.6. This makes it possible for unauthenticated attackers to change the settings of the plugin, which can also cause a denial of service due to a misconfiguration.

    Published: 21 Feb 2024
    9.6
    Critical

    CVE-2023-42498

    Last Modified: 28 Jan 2025

    Reflected cross-site scripting (XSS) vulnerability in the Language Override edit screen in Liferay Portal 7.4.3.8 through 7.4.3.97, and Liferay DXP 2023.Q3 before patch 5, and 7.4 update 4 through 92 allows remote attackers to inject arbitrary web script or HTML via the _com_liferay_portal_language_override_web_internal_portlet_PLOPortlet_key parameter.

    Published: 21 Feb 2024
    9.6
    Critical

    CVE-2024-26269

    Last Modified: 22 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Frontend JS module's portlet.js in Liferay Portal 7.2.0 through 7.4.3.37, and Liferay DXP 7.4 before update 38, 7.3 before update 11, 7.2 before fix pack 20, and older unsupported versions allows remote attackers to inject arbitrary web script or HTML via the anchor (hash) part of a URL.

    Published: 21 Feb 2024
    9
    Critical

    CVE-2024-26266

    Last Modified: 28 Jan 2025

    Multiple stored cross-site scripting (XSS) vulnerabilities in Liferay Portal 7.2.0 through 7.4.3.13, and older unsupported versions, and Liferay DXP 7.4 before update 10, 7.3 before update 4, 7.2 before fix pack 17, and older unsupported versions allow remote authenticated users to inject arbitrary web script or HTML via a crafted payload injected into the first/middle/last name text field of the user who creates an entry in the (1) Announcement widget, or (2) Alerts widget.

    Published: 21 Feb 2024
    9.6
    Critical

    CVE-2023-42496

    Last Modified: 28 Jan 2025

    Reflected cross-site scripting (XSS) vulnerability on the add assignees to a role page in Liferay Portal 7.3.3 through 7.4.3.97, and Liferay DXP 2023.Q3 before patch 6, 7.4 GA through update 92, and 7.3 before update 34 allows remote attackers to inject arbitrary web script or HTML via the _com_liferay_roles_admin_web_portlet_RolesAdminPortlet_tabs2 parameter.

    Published: 21 Feb 2024
    9.1
    Critical

    CVE-2024-1631

    Last Modified: 10 Dec 2025

    Impact: The library offers a function to generate an ed25519 key pair via Ed25519KeyIdentity.generate with an optional param to provide a 32 byte seed value, which will then be used as the secret key. When no seed value is provided, it is expected that the library generates the secret key using secure randomness. However, a recent change broke this guarantee and uses an insecure seed for key pair generation. Since the private key of this identity (535yc-uxytb-gfk7h-tny7p-vjkoe-i4krp-3qmcl-uqfgr-cpgej-yqtjq-rqe) is compromised, one could lose funds associated with the principal on ledgers or lose access to a canister where this principal is the controller.

    Published: 21 Feb 2024
    9
    Critical

    CVE-2024-25603

    Last Modified: 28 Jan 2025

    Stored cross-site scripting (XSS) vulnerability in the Dynamic Data Mapping module's DDMForm in Liferay Portal 7.2.0 through 7.4.3.4, and older unsupported versions, and Liferay DXP 7.4.13, 7.3 before update 4, 7.2 before fix pack 17, and older unsupported versions allows remote authenticated users to inject arbitrary web script or HTML via the instanceId parameter.

    Published: 21 Feb 2024
    9
    Critical

    CVE-2024-25152

    Last Modified: 28 Jan 2025

    Stored cross-site scripting (XSS) vulnerability in Message Board widget in Liferay Portal 7.2.0 through 7.4.2, and older unsupported versions, and Liferay DXP 7.3 before service pack 3, 7.2 before fix pack 17, and older unsupported versions allows remote authenticated users to inject arbitrary web script or HTML via the filename of an attachment.

    Published: 21 Feb 2024
    9
    Critical

    CVE-2024-25601

    Last Modified: 28 Jan 2025

    Stored cross-site scripting (XSS) vulnerability in Expando module's geolocation custom fields in Liferay Portal 7.2.0 through 7.4.2, and older unsupported versions, and Liferay DXP 7.3 before service pack 3, 7.2 before fix pack 17, and older unsupported versions allows remote authenticated users to inject arbitrary web script or HTML via a crafted payload injected into the name text field of a geolocation custom field.

    Published: 21 Feb 2024
    9
    Critical

    CVE-2024-25602

    Last Modified: 28 Jan 2025

    Stored cross-site scripting (XSS) vulnerability in Users Admin module's edit user page in Liferay Portal 7.2.0 through 7.4.2, and older unsupported versions, and Liferay DXP 7.3 before service pack 3, 7.2 before fix pack 17, and older unsupported versions allows remote authenticated users to inject arbitrary web script or HTML via a crafted payload injected into an organization’s “Name” text field

    Published: 21 Feb 2024
    9.6
    Critical

    CVE-2024-25147

    Last Modified: 22 Apr 2025

    Cross-site scripting (XSS) vulnerability in HtmlUtil.escapeJsLink in Liferay Portal 7.2.0 through 7.4.1, and older unsupported versions, and Liferay DXP 7.3 before service pack 3, 7.2 before fix pack 15, and older unsupported versions allows remote attackers to inject arbitrary web script or HTML via crafted javascript: style links.

    Published: 21 Feb 2024
    9.8
    Critical

    CVE-2024-26585

    Last Modified: 4 Aug 2026

    In the Linux kernel, the following vulnerability has been resolved: tls: fix race between tx work scheduling and socket close Similarly to previous commit, the submitting thread (recvmsg/sendmsg) may exit as soon as the async crypto handler calls complete(). Reorder scheduling the work before calling complete(). This seems more logical in the first place, as it's the inverse order of what the submitting thread will do.

    Published: 21 Feb 2024
    9.8
    Critical

    CVE-2024-26584

    Last Modified: 4 Aug 2026

    In the Linux kernel, the following vulnerability has been resolved: net: tls: handle backlogging of crypto requests Since we're setting the CRYPTO_TFM_REQ_MAY_BACKLOG flag on our requests to the crypto API, crypto_aead_{encrypt,decrypt} can return -EBUSY instead of -EINPROGRESS in valid situations. For example, when the cryptd queue for AESNI is full (easy to trigger with an artificially low cryptd.cryptd_max_cpu_qlen), requests will be enqueued to the backlog but still processed. In that case, the async callback will also be called twice: first with err == -EINPROGRESS, which it seems we can just ignore, then with err == 0. Compared to Sabrina's original patch this version uses the new tls_*crypt_async_wait() helpers and converts the EBUSY to EINPROGRESS to avoid having to modify all the error handling paths. The handling is identical.

    Published: 21 Feb 2024
    9.8
    Critical

    CVE-2024-26583

    Last Modified: 4 Aug 2026

    In the Linux kernel, the following vulnerability has been resolved: tls: fix race between async notify and socket close The submitting thread (one which called recvmsg/sendmsg) may exit as soon as the async crypto handler calls complete() so any code past that point risks touching already freed data. Try to avoid the locking and extra flags altogether. Have the main thread hold an extra reference, this way we can depend solely on the atomic ref counter for synchronization. Don't futz with reiniting the completion, either, we are now tightly controlling when completion fires.

    Published: 21 Feb 2024
    3.7
    Low

    CVE-2024-1722

    Last Modified: 21 Nov 2025

    A flaw was found in Keycloak. In certain conditions, this issue may allow a remote unauthenticated attacker to block other accounts from logging in.

    Published: 21 Feb 2024
    4.4
    Medium

    CVE-2023-49100

    Last Modified: 15 Apr 2026

    Trusted Firmware-A (TF-A) before 2.10 has a potential read out-of-bounds in the SDEI service. The input parameter passed in register x1 is not validated well enough in the function sdei_interrupt_bind. The parameter is passed to a call to plat_ic_get_interrupt_type. It can be any arbitrary value passing checks in the function plat_ic_is_sgi. A compromised Normal World (Linux kernel) can enable a root-privileged attacker to issue arbitrary SMC calls. Using this primitive, he can control the content of registers x0 through x6, which are used to send parameters to TF-A. Out-of-bounds addresses can be read in the context of TF-A (EL3). Because the read value is never returned to non-secure memory or in registers, no leak is possible. An attacker can still crash TF-A, however.

    Published: 21 Feb 2024
    7.5
    High

    CVE-2022-45177

    Last Modified: 21 Nov 2024

    An issue was discovered in LIVEBOX Collaboration vDesk through v031. An Observable Response Discrepancy can occur under the /api/v1/vdeskintegration/user/isenableuser endpoint, the /api/v1/sharedsearch?search={NAME]+{SURNAME] endpoint, and the /login endpoint. The web application provides different responses to incoming requests in a way that reveals internal state information to an unauthorized actor outside of the intended control sphere.

    Published: 21 Feb 2024
    6.1
    Medium

    CVE-2024-25898

    Last Modified: 28 Mar 2025

    A XSS vulnerability was found in the ChurchCRM v.5.5.0 functionality, edit your event, where malicious JS or HTML code can be inserted in the Event Sermon field in EventEditor.php.

    Published: 21 Feb 2024
    7.5
    High

    CVE-2024-24478

    Last Modified: 14 Apr 2025

    An issue in Wireshark before 4.2.0 allows a remote attacker to cause a denial of service via the packet-bgp.c, dissect_bgp_open(tvbuff_t*tvb, proto_tree*tree, packet_info*pinfo), optlen components. NOTE: this is disputed by the vendor because neither release 4.2.0 nor any other release was affected.

    Published: 21 Feb 2024
    7.5
    High

    CVE-2024-24476

    Last Modified: 4 Nov 2025

    A buffer overflow in Wireshark before 4.2.0 allows a remote attacker to cause a denial of service via the pan/addr_resolv.c, and ws_manuf_lookup_str(), size components. NOTE: this is disputed by the vendor because neither release 4.2.0 nor any other release was affected.

    Published: 21 Feb 2024
    7.5
    High

    CVE-2024-26130

    Last Modified: 5 Feb 2025

    cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Starting in version 38.0.0 and prior to version 42.0.4, if `pkcs12.serialize_key_and_certificates` is called with both a certificate whose public key did not match the provided private key and an `encryption_algorithm` with `hmac_hash` set (via `PrivateFormat.PKCS12.encryption_builder().hmac_hash(...)`, then a NULL pointer dereference would occur, crashing the Python process. This has been resolved in version 42.0.4, the first version in which a `ValueError` is properly raised.

    Published: 21 Feb 2024
    8.8
    High

    CVE-2023-24330

    Last Modified: 25 Mar 2025

    Command Injection vulnerability in D-Link Dir 882 with firmware version DIR882A1_FW130B06 allows attackers to run arbitrary commands via crafted POST request to /HNAP1/.

    Published: 21 Feb 2024
    9.8
    Critical

    CVE-2023-24331

    Last Modified: 25 Mar 2025

    Command Injection vulnerability in D-Link Dir 816 with firmware version DIR-816_A2_v1.10CNB04 allows attackers to run arbitrary commands via the urlAdd parameter.

    Published: 21 Feb 2024
    8.1
    High

    CVE-2023-24332

    Last Modified: 25 Mar 2025

    A stack overflow vulnerability in Tenda AC6 with firmware version US_AC6V5.0re_V03.03.02.01_cn_TDC01 allows attackers to run arbitrary commands via crafted POST request to /goform/PowerSaveSet.

    Published: 21 Feb 2024
    8.8
    High

    CVE-2023-24333

    Last Modified: 25 Mar 2025

    A stack overflow vulnerability in Tenda AC21 with firmware version US_AC21V1.0re_V16.03.08.15_cn_TDC01 allows attackers to run arbitrary commands via crafted POST request to /goform/openSchedWifi.

    Published: 21 Feb 2024
    8
    High

    CVE-2023-24334

    Last Modified: 25 Mar 2025

    A stack overflow vulnerability in Tenda AC23 with firmware version US_AC23V1.0re_V16.03.07.45_cn_TDC01 allows attackers to run arbitrary commands via schedStartTime parameter.

    Published: 21 Feb 2024
    9.8
    Critical

    CVE-2023-37177

    Last Modified: 25 Mar 2025

    SQL Injection vulnerability in PMB Services PMB v.7.4.7 and before allows a remote unauthenticated attacker to execute arbitrary code via the query parameter in the /admin/convert/export_z3950.php endpoint.

    Published: 21 Feb 2024
    7.5
    High

    CVE-2023-38844

    Last Modified: 25 Mar 2025

    SQL injection vulnerability in PMB v.7.4.7 and earlier allows a remote attacker to execute arbitrary code via the thesaurus parameter in export_skos.php.

    Published: 21 Feb 2024
    8.4
    High

    CVE-2023-50975

    Last Modified: 6 May 2025

    The TD Bank TD Advanced Dashboard client through 3.0.3 for macOS allows arbitrary code execution because of the lack of electron::fuses::IsRunAsNodeEnabled (i.e., ELECTRON_RUN_AS_NODE can be used in production). This makes it easier for a compromised process to access banking information.

    Published: 21 Feb 2024
    9.8
    Critical

    CVE-2023-51828

    Last Modified: 25 Mar 2025

    A SQL Injection vulnerability in /admin/convert/export.class.php in PMB 7.4.7 and earlier versions allows remote unauthenticated attackers to execute arbitrary SQL commands via the query parameter in get_next_notice function.

    Published: 21 Feb 2024
    9.8
    Critical

    CVE-2023-52153

    Last Modified: 25 Mar 2025

    A SQL Injection vulnerability in /pmb/opac_css/includes/sessions.inc.php in PMB 7.4.7 and earlier allows remote unauthenticated attackers to inject arbitrary SQL commands via the PmbOpac-LOGIN cookie value.

    Published: 21 Feb 2024
    7.2
    High

    CVE-2023-52154

    Last Modified: 25 Mar 2025

    File Upload vulnerability in pmb/camera_upload.php in PMB 7.4.7 and earlier allows attackers to run arbitrary code via upload of crafted PHTML files.

    Published: 21 Feb 2024
    7.2
    High

    CVE-2023-52155

    Last Modified: 25 Mar 2025

    A SQL Injection vulnerability in /admin/sauvegarde/run.php in PMB 7.4.7 and earlier allows remote authenticated attackers to execute arbitrary SQL commands via the sauvegardes variable through the /admin/sauvegarde/run.php endpoint.

    Published: 21 Feb 2024
    6.3
    Medium

    CVE-2024-22220

    Last Modified: 8 May 2025

    An issue was discovered in Terminalfour 7.4 through 7.4.0004 QP3 and 8 through 8.3.19, and Formbank through 2.1.10-FINAL. Unauthenticated Stored Cross-Site Scripting can occur, with resultant Admin Session Hijacking. The attack vectors are Form Builder and Form Preview.

    Published: 21 Feb 2024
    8.1
    High

    CVE-2024-22243

    Last Modified: 15 Apr 2026

    Applications that use UriComponentsBuilder to parse an externally provided URL (e.g. through a query parameter) AND perform validation checks on the host of the parsed URL may be vulnerable to a open redirect https://cwe.mitre.org/data/definitions/601.html  attack or to a SSRF attack if the URL is used after passing validation checks.

    Published: 21 Feb 2024
    7.5
    High

    CVE-2024-22778

    Last Modified: 6 May 2025

    HackMD CodiMD <2.5.2 is vulnerable to Denial of Service.

    Published: 21 Feb 2024
    9.8
    Critical

    CVE-2024-25249

    Last Modified: 27 Mar 2025

    An issue in He3 App for macOS version 2.0.17, allows remote attackers to execute arbitrary code via the RunAsNode and enableNodeClilnspectArguments settings.

    Published: 21 Feb 2024
    4.9
    Medium

    CVE-2024-25288

    Last Modified: 5 May 2025

    SLIMS (Senayan Library Management Systems) 9 Bulian v9.6.1 is vulnerable to SQL Injection via pop-scope-vocabolary.php.

    Published: 21 Feb 2024
    6.1
    Medium

    CVE-2024-25381

    Last Modified: 6 May 2025

    There is a Stored XSS Vulnerability in Emlog Pro 2.2.8 Article Publishing, due to non-filtering of quoted content.

    Published: 21 Feb 2024
    7.5
    High

    CVE-2024-25461

    Last Modified: 6 May 2025

    Directory Traversal vulnerability in Terrasoft, Creatio Terrasoft CRM v.7.18.4.1532 allows a remote attacker to obtain sensitive information via a crafted request to the terrasoft.axd component.

    Published: 21 Feb 2024
    7.5
    High

    CVE-2024-25891

    Last Modified: 17 Mar 2025

    ChurchCRM 5.5.0 FRBidSheets.php is vulnerable to Blind SQL Injection (Time-based) via the CurrentFundraiser GET parameter.

    Published: 21 Feb 2024
    8.1
    High

    CVE-2024-25892

    Last Modified: 17 Mar 2025

    ChurchCRM 5.5.0 ConfirmReport.php is vulnerable to Blind SQL Injection (Time-based) via the familyId GET parameter.

    Published: 21 Feb 2024
    9.1
    Critical

    CVE-2024-25893

    Last Modified: 17 Mar 2025

    ChurchCRM 5.5.0 FRCertificates.php is vulnerable to Blind SQL Injection (Time-based) via the CurrentFundraiser GET parameter.

    Published: 21 Feb 2024
    9.8
    Critical

    CVE-2024-25894

    Last Modified: 17 Mar 2025

    ChurchCRM 5.5.0 /EventEditor.php is vulnerable to Blind SQL Injection (Time-based) via the EventCount POST parameter.

    Published: 21 Feb 2024
    6.1
    Medium

    CVE-2024-25895

    Last Modified: 17 Mar 2025

    A reflected cross-site scripting (XSS) vulnerability in ChurchCRM 5.5.0 allows remote attackers to inject arbitrary web script or HTML via the type parameter of /EventAttendance.php

    Published: 21 Feb 2024
    5.3
    Medium

    CVE-2024-25896

    Last Modified: 17 Mar 2025

    ChurchCRM 5.5.0 EventEditor.php is vulnerable to Blind SQL Injection (Time-based) via the EID POST parameter.

    Published: 21 Feb 2024