CVE Feed

    Dashboard / CVE

    5.3
    Medium

    CVE-2024-25125

    Last Modified: 21 Nov 2024

    Digdag is an open source tool that to build, run, schedule, and monitor complex pipelines of tasks across various platforms. Treasure Data's digdag workload automation system is susceptible to a path traversal vulnerability if it's configured to store log files locally. This issue may lead to information disclosure and has been addressed in release version 0.10.5.1. Users are advised to upgrade. There are no known workarounds for this vulnerability.

    Published: 14 Feb 2024
    9.6
    Critical

    CVE-2024-24691

    Last Modified: 12 May 2025

    Improper input validation in Zoom Desktop Client for Windows, Zoom VDI Client for Windows, and Zoom Meeting SDK for Windows may allow an unauthenticated user to conduct an escalation of privilege via network access.

    Published: 14 Feb 2024
    5.4
    Medium

    CVE-2024-24690

    Last Modified: 21 Nov 2024

    Improper input validation in some Zoom clients may allow an authenticated user to conduct a denial of service via network access.

    Published: 14 Feb 2024
    6.1
    Medium

    CVE-2023-48986

    Last Modified: 20 Mar 2025

    Cross Site Scripting (XSS) vulnerability in CU Solutions Group (CUSG) Content Management System (CMS) before v.7.75 allows a remote attacker to execute arbitrary code, escalate privileges, and obtain sensitive information via a crafted script to the users.php component.

    Published: 14 Feb 2024
    5.3
    Medium

    CVE-2024-25617

    Last Modified: 25 Jun 2025

    Squid is an open source caching proxy for the Web supporting HTTP, HTTPS, FTP, and more. Due to a Collapse of Data into Unsafe Value bug ,Squid may be vulnerable to a Denial of Service attack against HTTP header parsing. This problem allows a remote client or a remote server to perform Denial of Service when sending oversized headers in HTTP messages. In versions of Squid prior to 6.5 this can be achieved if the request_header_max_size or reply_header_max_size settings are unchanged from the default. In Squid version 6.5 and later, the default setting of these parameters is safe. Squid will emit a critical warning in cache.log if the administrator is setting these parameters to unsafe values. Squid will not at this time prevent these settings from being changed to unsafe values. Users are advised to upgrade to version 6.5. There are no known workarounds for this vulnerability. This issue is also tracked as SQUID-2024:2

    Published: 14 Feb 2024
    6.1
    Medium

    CVE-2023-48985

    Last Modified: 19 Mar 2025

    Cross Site Scripting (XSS) vulnerability in CU Solutions Group (CUSG) Content Management System (CMS) before v.7.75 allows a remote attacker to execute arbitrary code, escalate privileges, and obtain sensitive information via a crafted script to the login.php component.

    Published: 14 Feb 2024
    7.5
    High

    CVE-2023-48987

    Last Modified: 21 Nov 2024

    Blind SQL Injection vulnerability in CU Solutions Group (CUSG) Content Management System (CMS) before v.7.75 allows a remote attacker to execute arbitrary code, escalate privileges, and obtain sensitive information via a crafted script to the pages.php component.

    Published: 14 Feb 2024
    6.1
    Medium

    CVE-2024-25218

    Last Modified: 27 Jan 2026

    A cross-site scripting (XSS) vulnerability in Task Manager App v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Project Name parameter /TaskManager/Projects.php.

    Published: 14 Feb 2024
    6.1
    Medium

    CVE-2024-25219

    Last Modified: 27 Jan 2026

    A cross-site scripting (XSS) vulnerability in Task Manager App v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Task Name parameter /TaskManager/Task.php.

    Published: 14 Feb 2024
    6.1
    Medium

    CVE-2024-25221

    Last Modified: 27 Jan 2026

    A cross-site scripting (XSS) vulnerability in Task Manager App v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Note Section parameter at /TaskManager/Tasks.php.

    Published: 14 Feb 2024
    7.8
    High

    CVE-2024-22029

    Last Modified: 15 Apr 2026

    Insecure permissions in the packaging of tomcat allow local users that win a race during package installation to escalate to root

    Published: 14 Feb 2024
    9.8
    Critical

    CVE-2024-24300

    Last Modified: 25 Mar 2025

    4ipnet EAP-767 v3.42.00 is vulnerable to Incorrect Access Control. The device uses the same set of credentials, regardless of how many times a user logs in, the content of the cookie remains unchanged.

    Published: 14 Feb 2024
    8.8
    High

    CVE-2024-24301

    Last Modified: 25 Mar 2025

    Command Injection vulnerability discovered in 4ipnet EAP-767 device v3.42.00 within the web interface of the device allows attackers with valid credentials to inject arbitrary shell commands to be executed by the device with root privileges.

    Published: 14 Feb 2024
    7.5
    High

    CVE-2024-24990

    Last Modified: 8 May 2025

    When NGINX Plus or NGINX OSS are configured to use the HTTP/3 QUIC module, undisclosed requests can cause NGINX worker processes to terminate. Note: The HTTP/3 QUIC module is not enabled by default and is considered experimental. For more information, refer to Support for QUIC and HTTP/3 https://nginx.org/en/docs/quic.html . Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated

    Published: 14 Feb 2024
    9.8
    Critical

    CVE-2024-25217

    Last Modified: 27 Mar 2025

    Online Medicine Ordering System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /omos/?p=products/view_product.

    Published: 14 Feb 2024
    7.8
    High

    CVE-2024-25165

    Last Modified: 5 May 2025

    A global-buffer-overflow vulnerability was found in SWFTools v0.9.2, in the function LineText at lib/swf5compiler.flex.

    Published: 14 Feb 2024
    5.4
    Medium

    CVE-2024-25207

    Last Modified: 12 May 2025

    Barangay Population Monitoring System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability in the Add Resident function at /barangay-population-monitoring-system/masterlist.php. This vulnerabiity allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Contact Number parameter.

    Published: 14 Feb 2024
    5.4
    Medium

    CVE-2024-25208

    Last Modified: 24 Apr 2025

    Barangay Population Monitoring System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability in the Add Resident function at /barangay-population-monitoring-system/masterlist.php. This vulnerabiity allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Full Name parameter.

    Published: 14 Feb 2024
    9.8
    Critical

    CVE-2024-25209

    Last Modified: 12 May 2025

    Barangay Population Monitoring System 1.0 was discovered to contain a SQL injection vulnerability via the resident parameter at /endpoint/delete-resident.php.

    Published: 14 Feb 2024
    9.8
    Critical

    CVE-2024-25210

    Last Modified: 12 May 2025

    Simple Expense Tracker v1.0 was discovered to contain a SQL injection vulnerability via the expense parameter at /endpoint/delete_expense.php.

    Published: 14 Feb 2024
    9.8
    Critical

    CVE-2024-25211

    Last Modified: 12 May 2025

    Simple Expense Tracker v1.0 was discovered to contain a SQL injection vulnerability via the category parameter at /endpoint/delete_category.php.

    Published: 14 Feb 2024
    7.2
    High

    CVE-2024-25212

    Last Modified: 21 Nov 2024

    Employee Managment System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /delete.php.

    Published: 14 Feb 2024
    7.2
    High

    CVE-2024-25213

    Last Modified: 12 May 2025

    Employee Managment System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /edit.php.

    Published: 14 Feb 2024
    9.8
    Critical

    CVE-2024-25214

    Last Modified: 21 Nov 2024

    An issue in Employee Managment System v1.0 allows attackers to bypass authentication via injecting a crafted payload into the E-mail and Password parameters at /alogin.html.

    Published: 14 Feb 2024
    9.8
    Critical

    CVE-2024-25215

    Last Modified: 8 May 2025

    Employee Managment System v1.0 was discovered to contain a SQL injection vulnerability via the pwd parameter at /aprocess.php.

    Published: 14 Feb 2024
    9.8
    Critical

    CVE-2024-25216

    Last Modified: 13 Mar 2025

    Employee Managment System v1.0 was discovered to contain a SQL injection vulnerability via the mailud parameter at /aprocess.php.

    Published: 14 Feb 2024
    9.8
    Critical

    CVE-2024-25220

    Last Modified: 27 Jan 2026

    Task Manager App v1.0 was discovered to contain a SQL injection vulnerability via the taskID parameter at /TaskManager/EditTask.php.

    Published: 14 Feb 2024
    9.8
    Critical

    CVE-2024-25222

    Last Modified: 27 Jan 2026

    Task Manager App v1.0 was discovered to contain a SQL injection vulnerability via the projectID parameter at /TaskManager/EditProject.php.

    Published: 14 Feb 2024
    9.8
    Critical

    CVE-2024-25223

    Last Modified: 12 May 2025

    Simple Admin Panel App v1.0 was discovered to contain a SQL injection vulnerability via the orderID parameter at /adminView/viewEachOrder.php.

    Published: 14 Feb 2024
    5.4
    Medium

    CVE-2024-25225

    Last Modified: 8 May 2025

    A cross-site scripting (XSS) vulnerability in Simple Admin Panel App v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Category Name parameter under the Add Category function.

    Published: 14 Feb 2024
    6.1
    Medium

    CVE-2024-25226

    Last Modified: 14 Mar 2025

    A cross-site scripting (XSS) vulnerability in Simple Admin Panel App v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Category Name parameter under the Add Category function.

    Published: 14 Feb 2024
    4.8
    Medium

    CVE-2024-25300

    Last Modified: 13 Mar 2025

    A cross-site scripting (XSS) vulnerability in Redaxo v5.15.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name parameter in the Template section.

    Published: 14 Feb 2024
    7.2
    High

    CVE-2024-25301

    Last Modified: 12 May 2025

    Redaxo v5.15.1 was discovered to contain a remote code execution (RCE) vulnerability via the component /pages/templates.php.

    Published: 14 Feb 2024
    7.5
    High

    CVE-2024-24989

    Last Modified: 12 May 2025

    When NGINX Plus or NGINX OSS are configured to use the HTTP/3 QUIC module, undisclosed requests can cause NGINX worker processes to terminate. Note: The HTTP/3 QUIC module is not enabled by default and is considered experimental. For more information, refer to Support for QUIC and HTTP/3 https://nginx.org/en/docs/quic.html . NOTE: Software versions which have reached End of Technical Support (EoTS) are not evaluated

    Published: 14 Feb 2024
    5.4
    Medium

    CVE-2024-25224

    Last Modified: 12 May 2025

    A cross-site scripting (XSS) vulnerability in Simple Admin Panel App v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Size Number parameter under the Add Size function.

    Published: 14 Feb 2024
    6.5
    Medium

    CVE-2023-28746

    Last Modified: 12 May 2026

    Information exposure through microarchitectural state after transient execution from some register files for some Intel(R) Atom(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.

    Published: 14 Feb 2024
    5.5
    Medium

    CVE-2023-38575

    Last Modified: 15 Apr 2026

    Non-transparent sharing of return predictor targets between contexts in some Intel(R) Processors may allow an authorized user to potentially enable information disclosure via local access.

    Published: 14 Feb 2024
    6.5
    Medium

    CVE-2023-39368

    Last Modified: 15 Apr 2026

    Protection mechanism failure of bus lock regulator for some Intel(R) Processors may allow an unauthenticated user to potentially enable denial of service via network access.

    Published: 14 Feb 2024
    5.3
    Medium

    CVE-2023-43490

    Last Modified: 15 Apr 2026

    Incorrect calculation in microcode keying mechanism for some Intel(R) Xeon(R) D Processors with Intel(R) SGX may allow a privileged user to potentially enable information disclosure via local access.

    Published: 14 Feb 2024
    6.5
    Medium

    CVE-2024-24699

    Last Modified: 13 Mar 2025

    Business logic error in some Zoom clients may allow an authenticated user to conduct information disclosure via network access.

    Published: 13 Feb 2024
    4.9
    Medium

    CVE-2024-24698

    Last Modified: 21 Nov 2024

    Improper authentication in some Zoom clients may allow a privileged user to conduct a disclosure of information via local access.

    Published: 13 Feb 2024
    7.2
    High

    CVE-2024-24697

    Last Modified: 8 May 2025

    Untrusted search path in some Zoom 32 bit Windows clients may allow an authenticated user to conduct an escalation of privilege via local access.

    Published: 13 Feb 2024
    6.8
    Medium

    CVE-2024-24696

    Last Modified: 21 Nov 2024

    Improper input validation in Zoom Desktop Client for Windows, Zoom VDI Client for Windows, and Zoom Meeting SDK for Windows may allow an authenticated user to conduct a disclosure of information via network access.

    Published: 13 Feb 2024
    6.8
    Medium

    CVE-2024-24695

    Last Modified: 10 Apr 2025

    Improper input validation in Zoom Desktop Client for Windows, Zoom VDI Client for Windows, and Zoom Meeting SDK for Windows may allow an authenticated user to conduct a disclosure of information via network access.

    Published: 13 Feb 2024
    4.3
    Medium

    CVE-2024-25118

    Last Modified: 21 Nov 2024

    TYPO3 is an open source PHP based web content management system released under the GNU GPL. Password hashes were being reflected in the editing forms of the TYPO3 backend user interface. This allowed attackers to crack the plaintext password using brute force techniques. Exploiting this vulnerability requires a valid backend user account. Users are advised to update to TYPO3 versions 8.7.57 ELTS, 9.5.46 ELTS, 10.4.43 ELTS, 11.5.35 LTS, 12.4.11 LTS, 13.0.1 that fix the problem described. There are no known workarounds for this issue.

    Published: 13 Feb 2024
    4.9
    Medium

    CVE-2024-25119

    Last Modified: 21 Nov 2024

    TYPO3 is an open source PHP based web content management system released under the GNU GPL. The plaintext value of `$GLOBALS['SYS']['encryptionKey']` was displayed in the editing forms of the TYPO3 Install Tool user interface. This allowed attackers to utilize the value to generate cryptographic hashes used for verifying the authenticity of HTTP request parameters. Exploiting this vulnerability requires an administrator-level backend user account with system maintainer permissions. Users are advised to update to TYPO3 versions 8.7.57 ELTS, 9.5.46 ELTS, 10.4.43 ELTS, 11.5.35 LTS, 12.4.11 LTS, 13.0.1 that fix the problem described. There are no known workarounds for this vulnerability.

    Published: 13 Feb 2024
    4.3
    Medium

    CVE-2024-25120

    Last Modified: 24 Apr 2025

    TYPO3 is an open source PHP based web content management system released under the GNU GPL. The TYPO3-specific `t3://` URI scheme could be used to access resources outside of the users' permission scope. This encompassed files, folders, pages, and records (although only if a valid link-handling configuration was provided). Exploiting this vulnerability requires a valid backend user account. Users are advised to update to TYPO3 versions 8.7.57 ELTS, 9.5.46 ELTS, 10.4.43 ELTS, 11.5.35 LTS, 12.4.11 LTS, 13.0.1 that fix the problem described. There are no known workarounds for this issue.

    Published: 13 Feb 2024
    7.1
    High

    CVE-2024-25121

    Last Modified: 9 May 2025

    TYPO3 is an open source PHP based web content management system released under the GNU GPL. In affected versions of TYPO3 entities of the File Abstraction Layer (FAL) could be persisted directly via `DataHandler`. This allowed attackers to reference files in the fallback storage directly and retrieve their file names and contents. The fallback storage ("zero-storage") is used as a backward compatibility layer for files located outside properly configured file storages and within the public web root directory. Exploiting this vulnerability requires a valid backend user account. Users are advised to update to TYPO3 version 8.7.57 ELTS, 9.5.46 ELTS, 10.4.43 ELTS, 11.5.35 LTS, 12.4.11 LTS, or 13.0.1 which fix the problem described. When persisting entities of the File Abstraction Layer directly via DataHandler, `sys_file` entities are now denied by default, and `sys_file_reference` & `sys_file_metadata` entities are not permitted to reference files in the fallback storage anymore. When importing data from secure origins, this must be explicitly enabled in the corresponding DataHandler instance by using `$dataHandler->isImporting = true;`.

    Published: 13 Feb 2024
    5.4
    Medium

    CVE-2023-6152

    Last Modified: 15 Feb 2025

    A user changing their email after signing up and verifying it can change it without verification in profile settings. The configuration option "verify_email_enabled" will only validate email only on sign up.

    Published: 13 Feb 2024
    7.8
    High

    CVE-2021-46757

    Last Modified: 7 May 2025

    Insufficient checking of memory buffer in ASP Secure OS may allow an attacker with a malicious TA to read/write to the ASP Secure OS kernel virtual address space potentially leading to privilege escalation.

    Published: 13 Feb 2024