CVE Feed

    Dashboard / CVE

    6.5
    Medium

    CVE-2024-1250

    Last Modified: 23 Apr 2026

    An issue has been discovered in GitLab EE affecting all versions starting from 16.8 before 16.8.2. When a user is assigned a custom role with manage_group_access_tokens permission, they may be able to create group access tokens with Owner privileges, which may lead to privilege escalation.

    Published: 12 Feb 2024
    7.5
    High

    CVE-2024-23833

    Last Modified: 7 May 2025

    OpenRefine is a free, open source power tool for working with messy data and improving it. A jdbc attack vulnerability exists in OpenRefine(version<=3.7.7) where an attacker may construct a JDBC query which may read files on the host filesystem. Due to the newer MySQL driver library in the latest version of OpenRefine (8.0.30), there is no associated deserialization utilization point, so original code execution cannot be achieved, but attackers can use this vulnerability to read sensitive files on the target server. This issue has been addressed in version 3.7.8. Users are advised to upgrade. There are no known workarounds for this vulnerability.

    Published: 12 Feb 2024
    9.9
    Critical

    CVE-2024-25108

    Last Modified: 7 May 2025

    Pixelfed is an open source photo sharing platform. When processing requests authorization was improperly and insufficiently checked, allowing attackers to access far more functionality than users intended, including to the administrative and moderator functionality of the Pixelfed server. This vulnerability affects every version of Pixelfed between v0.10.4 and v0.11.9, inclusive. A proof of concept of this vulnerability exists. This vulnerability affects every local user of a Pixelfed server, and can potentially affect the servers' ability to federate. Some user interaction is required to setup the conditions to be able to exercise the vulnerability, but the attacker could conduct this attack time-delayed manner, where user interaction is not actively required. This vulnerability has been addressed in version 0.11.11. Users are advised to upgrade. There are no known workarounds for this vulnerability.

    Published: 12 Feb 2024
    4.2
    Medium

    CVE-2024-1342

    Last Modified: 14 Oct 2024

    Unable to reproduce.

    Published: 12 Feb 2024
    3.5
    Low

    CVE-2021-4437

    Last Modified: 6 May 2025

    A vulnerability, which was classified as problematic, has been found in dbartholomae lambda-middleware frameguard up to 1.0.4. Affected by this issue is some unknown functionality of the file packages/json-deserializer/src/JsonDeserializer.ts of the component JSON Mime-Type Handler. The manipulation leads to inefficient regular expression complexity. Upgrading to version 1.1.0 is able to address this issue. The patch is identified as f689404d830cbc1edd6a1018d3334ff5f44dc6a6. It is recommended to upgrade the affected component. VDB-253406 is the identifier assigned to this vulnerability.

    Published: 12 Feb 2024
    4.6
    Medium

    CVE-2022-22506

    Last Modified: 21 Nov 2024

    IBM Robotic Process Automation 21.0.2 contains a vulnerability that could allow user ids may be exposed across tenants. IBM X-Force ID: 227293.

    Published: 12 Feb 2024
    7.8
    High

    CVE-2024-22223

    Last Modified: 7 May 2025

    Dell Unity, versions prior to 5.4, contains an OS Command Injection Vulnerability within its svc_cbr utility. An authenticated malicious user with local access could potentially exploit this vulnerability, leading to the execution of arbitrary OS commands on the application's underlying OS, with the privileges of the vulnerable application.

    Published: 12 Feb 2024
    5.9
    Medium

    CVE-2022-34309

    Last Modified: 21 Nov 2024

    IBM CICS TX Standard and Advanced 11.1 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 229440.

    Published: 12 Feb 2024
    7.8
    High

    CVE-2024-22222

    Last Modified: 21 Nov 2024

    Dell Unity, versions prior to 5.4, contains an OS Command Injection Vulnerability within its svc_udoctor utility. An authenticated malicious user with local access could potentially exploit this vulnerability, leading to the execution of arbitrary OS commands on the application's underlying OS, with the privileges of the vulnerable application.

    Published: 12 Feb 2024
    4.5
    Medium

    CVE-2024-22221

    Last Modified: 21 Nov 2024

    Dell Unity, versions prior to 5.4, contains SQL Injection vulnerability. An authenticated attacker could potentially exploit this vulnerability, leading to exposure of sensitive information.

    Published: 12 Feb 2024
    3.3
    Low

    CVE-2024-22226

    Last Modified: 21 Nov 2024

    Dell Unity, versions prior to 5.4, contain a path traversal vulnerability in its svc_supportassist utility. An authenticated attacker could potentially exploit this vulnerability, to gain unauthorized write access to the files stored on the server filesystem, with elevated privileges.

    Published: 12 Feb 2024
    7.8
    High

    CVE-2024-22225

    Last Modified: 7 May 2025

    Dell Unity, versions prior to 5.4, contains an OS Command Injection Vulnerability in its svc_supportassist utility. An authenticated attacker could potentially exploit this vulnerability, leading to execution of arbitrary operating system commands with root privileges.

    Published: 12 Feb 2024
    7.8
    High

    CVE-2024-22224

    Last Modified: 7 May 2025

    Dell Unity, versions prior to 5.4, contains an OS Command Injection Vulnerability in its svc_nas utility. An authenticated attacker could potentially exploit this vulnerability, escaping the restricted shell and execute arbitrary operating system commands with root privileges.

    Published: 12 Feb 2024
    6.4
    Medium

    CVE-2024-22230

    Last Modified: 21 Nov 2024

    Dell Unity, versions prior to 5.4, contains a Cross-site scripting vulnerability. An authenticated attacker could potentially exploit this vulnerability, stealing session information, masquerading as the affected user or carry out any actions that this user could perform, or to generally control the victim's browser.

    Published: 12 Feb 2024
    7.8
    High

    CVE-2024-22228

    Last Modified: 7 May 2025

    Dell Unity, versions prior to 5.4, contains an OS Command Injection Vulnerability in its svc_cifssupport utility. An authenticated attacker could potentially exploit this vulnerability, escaping the restricted shell and execute arbitrary operating system commands with root privileges.

    Published: 12 Feb 2024
    7.8
    High

    CVE-2024-22227

    Last Modified: 7 May 2025

    Dell Unity, versions prior to 5.4, contains an OS Command Injection Vulnerability in its svc_dc utility. An authenticated attacker could potentially exploit this vulnerability, leading to the ability execute commands with root privileges.

    Published: 12 Feb 2024
    4.3
    Medium

    CVE-2022-34311

    Last Modified: 6 May 2025

    IBM CICS TX Standard and Advanced 11.1 could allow a user with physical access to the web browser to gain access to the user's session due to insufficiently protected credentials. IBM X-Force ID: 229446.

    Published: 12 Feb 2024
    5.9
    Medium

    CVE-2022-34310

    Last Modified: 24 Apr 2025

    IBM CICS TX Standard and Advanced 11.1 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 229441.

    Published: 12 Feb 2024
    4.9
    Medium

    CVE-2022-38714

    Last Modified: 18 Mar 2025

    IBM DataStage on Cloud Pak for Data 4.0.6 to 4.5.2 stores sensitive credential information that can be read by a privileged user. IBM X-Force ID: 235060.

    Published: 12 Feb 2024
    5.4
    Medium

    CVE-2023-6081

    Last Modified: 6 May 2025

    The chartjs WordPress plugin through 2023.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

    Published: 12 Feb 2024
    7.2
    High

    CVE-2023-6294

    Last Modified: 24 Apr 2025

    The Popup Builder WordPress plugin before 4.2.6 does not validate a parameter before making a request to it, which could allow users with the administrator role to perform SSRF attack in Multisite WordPress configurations.

    Published: 12 Feb 2024
    9.8
    Critical

    CVE-2023-6036

    Last Modified: 6 May 2025

    The Web3 WordPress plugin before 3.0.0 is vulnerable to an authentication bypass due to incorrect authentication checking in the login flow in functions 'handle_auth_request' and 'hadle_login_request'. This makes it possible for non authenticated attackers to log in as any existing user on the site, such as an administrator, if they have access to the username.

    Published: 12 Feb 2024
    5.4
    Medium

    CVE-2023-6082

    Last Modified: 21 Nov 2024

    The chartjs WordPress plugin through 2023.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

    Published: 12 Feb 2024
    4.8
    Medium

    CVE-2023-6591

    Last Modified: 21 Nov 2024

    The Popup Box WordPress plugin before 20.9.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed

    Published: 12 Feb 2024
    5.4
    Medium

    CVE-2023-6499

    Last Modified: 6 May 2025

    The lasTunes WordPress plugin through 3.6.1 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack

    Published: 12 Feb 2024
    4.8
    Medium

    CVE-2023-7233

    Last Modified: 14 Mar 2025

    The GigPress WordPress plugin through 2.3.29 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

    Published: 12 Feb 2024
    4.3
    Medium

    CVE-2023-6501

    Last Modified: 21 Nov 2024

    The Splashscreen WordPress plugin through 0.20 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack

    Published: 12 Feb 2024
    —
    Unknown

    CVE-2024-1457

    Last Modified: 11 Feb 2025

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

    Published: 12 Feb 2024
    7.8
    High

    CVE-2024-0164

    Last Modified: 21 Nov 2024

    Dell Unity, versions prior to 5.4, contain an OS Command Injection Vulnerability in its svc_topstats utility. An authenticated attacker could potentially exploit this vulnerability, leading to the execution of arbitrary commands with elevated privileges.

    Published: 12 Feb 2024
    7.8
    High

    CVE-2024-0165

    Last Modified: 6 May 2025

    Dell Unity, versions prior to 5.4, contains an OS Command Injection Vulnerability in its svc_acldb_dump utility. An authenticated attacker could potentially exploit this vulnerability, leading to execution of arbitrary operating system commands with root privileges.

    Published: 12 Feb 2024
    7.8
    High

    CVE-2024-0166

    Last Modified: 6 May 2025

    Dell Unity, versions prior to 5.4, contains an OS Command Injection Vulnerability in its svc_tcpdump utility. An authenticated attacker could potentially exploit this vulnerability, leading to the execution of arbitrary OS commands with elevated privileges.

    Published: 12 Feb 2024
    7.8
    High

    CVE-2024-0167

    Last Modified: 6 May 2025

    Dell Unity, versions prior to 5.4, contains an OS Command Injection Vulnerability in the svc_topstats utility. An authenticated attacker could potentially exploit this vulnerability, leading to the ability to overwrite arbitrary files on the file system with root privileges.

    Published: 12 Feb 2024
    7.8
    High

    CVE-2024-0168

    Last Modified: 21 Nov 2024

    Dell Unity, versions prior to 5.4, contains a Command Injection Vulnerability in svc_oscheck utility. An authenticated attacker could potentially exploit this vulnerability, leading to the ability to inject arbitrary operating system commands. This vulnerability allows an authenticated attacker to execute commands with root privileges.

    Published: 12 Feb 2024
    5.7
    Medium

    CVE-2024-0169

    Last Modified: 24 Apr 2025

    Dell Unity, version(s) 5.3 and prior, contain(s) an Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Information exposure.

    Published: 12 Feb 2024
    7.8
    High

    CVE-2024-0170

    Last Modified: 6 May 2025

    Dell Unity, versions prior to 5.4, contains an OS Command Injection Vulnerability in its svc_cava utility. An authenticated attacker could potentially exploit this vulnerability, escaping the restricted shell and execute arbitrary operating system commands with root privileges.

    Published: 12 Feb 2024
    7.2
    High

    CVE-2024-0566

    Last Modified: 7 May 2025

    The Smart Manager WordPress plugin before 8.28.0 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by high privilege users such as admin.

    Published: 12 Feb 2024
    4.3
    Medium

    CVE-2024-0248

    Last Modified: 7 May 2025

    The EazyDocs WordPress plugin before 2.4.0 re-introduced CVE-2023-6029 (https://wpscan.com/vulnerability/7a0aaf85-8130-4fd7-8f09-f8edc929597e/) in 2.3.8, allowing any authenticated users, such as subscriber to delete arbitrary posts, as well as add and delete documents/sections. The issue was partially fixed in 2.3.9.

    Published: 12 Feb 2024
    5.4
    Medium

    CVE-2024-0420

    Last Modified: 21 Nov 2024

    The MapPress Maps for WordPress plugin before 2.88.15 does not sanitize and escape the map title when outputting it back in the admin dashboard, allowing Contributors and above roles to perform Stored Cross-Site Scripting attacks

    Published: 12 Feb 2024
    6.1
    Medium

    CVE-2024-0250

    Last Modified: 26 Mar 2025

    The Analytics Insights for Google Analytics 4 (AIWP) WordPress plugin before 6.3 is vulnerable to Open Redirect due to insufficient validation on the redirect oauth2callback.php file. This makes it possible for unauthenticated attackers to redirect users to potentially malicious sites if they can successfully trick them into performing an action.

    Published: 12 Feb 2024
    5.3
    Medium

    CVE-2024-0421

    Last Modified: 7 May 2025

    The MapPress Maps for WordPress plugin before 2.88.16 is affected by an IDOR as it does not ensure that posts to be retrieve via an AJAX action is a public map, allowing unauthenticated users to read arbitrary private and draft posts.

    Published: 12 Feb 2024
    —
    Unknown

    CVE-2024-1444

    Last Modified: 16 Feb 2024

    Erroneous assignment

    Published: 12 Feb 2024
    4.3
    Medium

    CVE-2024-24875

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Yannick Lefebvre Link Library.This issue affects Link Library: from n/a through 7.5.13.

    Published: 12 Feb 2024
    4.3
    Medium

    CVE-2024-24884

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in ARI Soft Contact Form 7 Connector.This issue affects Contact Form 7 Connector: from n/a through 1.2.2.

    Published: 12 Feb 2024
    5.4
    Medium

    CVE-2024-24887

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Contest Gallery Photos and Files Contest Gallery – Contact Form, Upload Form, Social Share and Voting Plugin for WordPress.This issue affects Photos and Files Contest Gallery – Contact Form, Upload Form, Social Share and Voting Plugin for WordPress: from n/a through 21.2.8.4.

    Published: 12 Feb 2024
    4.3
    Medium

    CVE-2024-24929

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Ryan Duff, Peter Westwood WP Contact Form.This issue affects WP Contact Form: from n/a through 1.6.

    Published: 12 Feb 2024
    4.3
    Medium

    CVE-2024-24935

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in WpSimpleTools Basic Log Viewer.This issue affects Basic Log Viewer: from n/a through 1.0.4.

    Published: 12 Feb 2024
    5.4
    Medium

    CVE-2023-46615

    Last Modified: 28 Apr 2026

    Deserialization of Untrusted Data vulnerability in Kalli Dan. KD Coming Soon.This issue affects KD Coming Soon: from n/a through 1.7.

    Published: 12 Feb 2024
    8.7
    High

    CVE-2024-23512

    Last Modified: 28 Apr 2026

    Deserialization of Untrusted Data vulnerability in wpxpo ProductX – WooCommerce Builder & Gutenberg WooCommerce Blocks.This issue affects ProductX – WooCommerce Builder & Gutenberg WooCommerce Blocks: from n/a through 3.1.4.

    Published: 12 Feb 2024
    5.4
    Medium

    CVE-2023-41708

    Last Modified: 4 Nov 2025

    References to the "app loader" functionality could contain redirects to unexpected locations. Attackers could forge app references that bypass existing safeguards to inject malicious script code. Please deploy the provided updates and patch releases. References to apps are now controlled more strict to avoid relative references. No publicly available exploits are known.

    Published: 12 Feb 2024
    6.5
    Medium

    CVE-2023-41707

    Last Modified: 4 Nov 2025

    Processing of user-defined mail search expressions is not limited. Availability of OX App Suite could be reduced due to high processing load. Please deploy the provided updates and patch releases. Processing time of mail search expressions now gets monitored, and the related request is terminated if a resource threshold is reached. No publicly available exploits are known.

    Published: 12 Feb 2024