CVE Feed

    Dashboard / CVE

    6.5
    Medium

    CVE-2023-41706

    Last Modified: 4 Nov 2025

    Processing time of drive search expressions now gets monitored, and the related request is terminated if a resource threshold is reached. Availability of OX App Suite could be reduced due to high processing load. Please deploy the provided updates and patch releases. Processing of user-defined drive search expressions is not limited No publicly available exploits are known.

    Published: 12 Feb 2024
    6.5
    Medium

    CVE-2023-41705

    Last Modified: 4 Nov 2025

    Processing of user-defined DAV user-agent strings is not limited. Availability of OX App Suite could be reduced due to high processing load. Please deploy the provided updates and patch releases. Processing time of DAV user-agents now gets monitored, and the related request is terminated if a resource threshold is reached. No publicly available exploits are known.

    Published: 12 Feb 2024
    7.1
    High

    CVE-2023-41704

    Last Modified: 4 Nov 2025

    Processing of CID references at E-Mail can be abused to inject malicious script code that passes the sanitization engine. Malicious script code could be injected to a users sessions when interacting with E-Mails. Please deploy the provided updates and patch releases. CID handing has been improved and resulting content is checked for malicious content. No publicly available exploits are known.

    Published: 12 Feb 2024
    6.1
    Medium

    CVE-2023-41703

    Last Modified: 4 Nov 2025

    User ID references at mentions in document comments were not correctly sanitized. Script code could be injected to a users session when working with a malicious document. Please deploy the provided updates and patch releases. User-defined content like comments and mentions are now filtered to avoid potentially malicious content. No publicly available exploits are known.

    Published: 12 Feb 2024
    8.7
    High

    CVE-2024-23513

    Last Modified: 28 Apr 2026

    Deserialization of Untrusted Data vulnerability in PropertyHive.This issue affects PropertyHive: from n/a through 2.0.5.

    Published: 12 Feb 2024
    8.2
    High

    CVE-2024-24796

    Last Modified: 28 Apr 2026

    Deserialization of Untrusted Data vulnerability in MagePeople Team Event Manager and Tickets Selling Plugin for WooCommerce – WpEvently – WordPress Plugin.This issue affects Event Manager and Tickets Selling Plugin for WooCommerce – WpEvently – WordPress Plugin: from n/a through 4.1.1.

    Published: 12 Feb 2024
    9.8
    Critical

    CVE-2024-24797

    Last Modified: 28 Apr 2026

    Deserialization of Untrusted Data vulnerability in G5Theme ERE Recently Viewed – Essential Real Estate Add-On.This issue affects ERE Recently Viewed – Essential Real Estate Add-On: from n/a through 1.3.

    Published: 12 Feb 2024
    7.5
    High

    CVE-2024-24926

    Last Modified: 28 Apr 2026

    Deserialization of Untrusted Data vulnerability in UnitedThemes Brooklyn | Creative Multi-Purpose Responsive WordPress Theme.This issue affects Brooklyn | Creative Multi-Purpose Responsive WordPress Theme: from n/a through 4.9.7.6.

    Published: 12 Feb 2024
    10
    Critical

    CVE-2024-25100

    Last Modified: 28 Apr 2026

    Deserialization of Untrusted Data vulnerability in WP Swings Coupon Referral Program allows Object Injection.This issue affects Coupon Referral Program: from n/a before 1.8.4.

    Published: 12 Feb 2024
    5.9
    Medium

    CVE-2023-47526

    Last Modified: 28 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Chart Builder Team Chartify – WordPress Chart Plugin allows Stored XSS.This issue affects Chartify – WordPress Chart Plugin: from n/a through 2.0.6.

    Published: 12 Feb 2024
    6.5
    Medium

    CVE-2024-1439

    Last Modified: 21 Nov 2024

    Inadequate access control in Moodle LMS. This vulnerability could allow a local user with a student role to create arbitrary events intended for users with higher roles. It could also allow the attacker to add events to the calendar of all users without their prior consent.

    Published: 12 Feb 2024
    6.5
    Medium

    CVE-2023-50875

    Last Modified: 28 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Automattic Sensei LMS – Online Courses, Quizzes, & Learning allows Stored XSS.This issue affects Sensei LMS – Online Courses, Quizzes, & Learning: from n/a through 4.17.0.

    Published: 12 Feb 2024
    5.9
    Medium

    CVE-2023-51370

    Last Modified: 28 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NinjaTeam WP Chat App allows Stored XSS.This issue affects WP Chat App: from n/a through 3.4.4.

    Published: 12 Feb 2024
    6.5
    Medium

    CVE-2023-51403

    Last Modified: 28 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Nicdark Restaurant Reservations allows Stored XSS.This issue affects Restaurant Reservations: from n/a through 1.8.

    Published: 12 Feb 2024
    6.1
    Medium

    CVE-2024-24889

    Last Modified: 28 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Geek Code Lab All 404 Pages Redirect to Homepage allows Stored XSS.This issue affects All 404 Pages Redirect to Homepage: from n/a through 1.9.

    Published: 12 Feb 2024
    7.1
    High

    CVE-2024-24927

    Last Modified: 28 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in UnitedThemes Brooklyn | Creative Multi-Purpose Responsive WordPress Theme allows Reflected XSS.This issue affects Brooklyn | Creative Multi-Purpose Responsive WordPress Theme: from n/a through 4.9.7.6.

    Published: 12 Feb 2024
    6.5
    Medium

    CVE-2024-24928

    Last Modified: 28 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Arunas Liuiza Content Cards allows Stored XSS.This issue affects Content Cards: from n/a through 0.9.7.

    Published: 12 Feb 2024
    6.5
    Medium

    CVE-2024-24930

    Last Modified: 28 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in OTWthemes.Com Buttons Shortcode and Widget allows Stored XSS.This issue affects Buttons Shortcode and Widget: from n/a through 1.16.

    Published: 12 Feb 2024
    6.5
    Medium

    CVE-2024-24931

    Last Modified: 28 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in swadeshswain Before After Image Slider WP allows Stored XSS.This issue affects Before After Image Slider WP: from n/a through 2.2.

    Published: 12 Feb 2024
    7.1
    High

    CVE-2024-24932

    Last Modified: 28 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Djo VK Poster Group allows Reflected XSS.This issue affects VK Poster Group: from n/a through 2.0.3.

    Published: 12 Feb 2024
    7.1
    High

    CVE-2024-24933

    Last Modified: 28 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Prasidhda Malla Honeypot for WP Comment allows Reflected XSS.This issue affects Honeypot for WP Comment: from n/a through 2.2.3.

    Published: 12 Feb 2024
    6.1
    Medium

    CVE-2023-52430

    Last Modified: 6 May 2025

    The caddy-security plugin 1.1.20 for Caddy allows reflected XSS via a GET request to a URL that contains an XSS payload and begins with either a /admin or /settings/mfa/delete/ substring.

    Published: 12 Feb 2024
    5.5
    Medium

    CVE-2023-52429

    Last Modified: 4 Nov 2025

    dm_table_create in drivers/md/dm-table.c in the Linux kernel through 6.7.4 can attempt to (in alloc_targets) allocate more than INT_MAX bytes, and crash, because of a missing check for struct dm_ioctl.target_count.

    Published: 12 Feb 2024
    9.8
    Critical

    CVE-2024-23759

    Last Modified: 7 May 2025

    Deserialization of Untrusted Data in Gambio through 4.9.2.0 allows attackers to run arbitrary code via "search" parameter of the Parcelshopfinder/AddAddressBookEntry" function.

    Published: 12 Feb 2024
    2.7
    Low

    CVE-2024-23760

    Last Modified: 28 Mar 2025

    Cleartext Storage of Sensitive Information in Gambio 4.9.2.0 allows attackers to obtain sensitive information via error-handler.log.json and legacy-error-handler.log.txt under the webroot.

    Published: 12 Feb 2024
    9.8
    Critical

    CVE-2024-23761

    Last Modified: 21 Nov 2024

    Server Side Template Injection in Gambio 4.9.2.0 allows attackers to run arbitrary code via crafted smarty email template.

    Published: 12 Feb 2024
    7.8
    High

    CVE-2024-23762

    Last Modified: 18 Mar 2025

    Unrestricted File Upload vulnerability in Content Manager feature in Gambio 4.9.2.0 allows attackers to execute arbitrary code via upload of crafted PHP file.

    Published: 12 Feb 2024
    9.8
    Critical

    CVE-2024-23763

    Last Modified: 7 May 2025

    SQL Injection vulnerability in Gambio through 4.9.2.0 allows attackers to run arbitrary SQL commands via crafted GET request using modifiers[attribute][] parameter.

    Published: 12 Feb 2024
    8
    High

    CVE-2024-24337

    Last Modified: 29 Sept 2025

    CSV Injection vulnerability in '/members/moremember.pl' and '/admin/aqbudgets.pl' endpoints in Koha Library Management System version 23.05.05 and earlier allows attackers to to inject DDE commands into csv exports via the 'Budget' and 'Patrons Member' components.

    Published: 12 Feb 2024
    5.3
    Medium

    CVE-2024-25360

    Last Modified: 21 Nov 2024

    A hidden interface in Motorola CX2L Router firmware v1.0.1 leaks information regarding the SystemWizardStatus component via sending a crafted request to device_web_ip.

    Published: 12 Feb 2024
    5.5
    Medium

    CVE-2024-25740

    Last Modified: 7 May 2025

    A memory leak flaw was found in the UBI driver in drivers/mtd/ubi/attach.c in the Linux kernel through 6.7.4 for UBI_IOCATT, because kobj->name is not released.

    Published: 12 Feb 2024
    5.5
    Medium

    CVE-2024-25739

    Last Modified: 12 May 2026

    create_empty_lvol in drivers/mtd/ubi/vtbl.c in the Linux kernel through 6.7.4 can attempt to allocate zero bytes, and crash, because of a missing check for ubi->leb_size.

    Published: 12 Feb 2024
    8.8
    High

    CVE-2024-25744

    Last Modified: 7 May 2025

    In the Linux kernel before 6.6.7, an untrusted VMM can trigger int80 syscall handling at any given point. This is related to arch/x86/coco/tdx/tdx.c and arch/x86/mm/mem_encrypt_amd.c.

    Published: 12 Feb 2024
    —
    Unknown

    CVE-2024-25760

    Last Modified: 27 Feb 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

    Published: 12 Feb 2024
    5.5
    Medium

    CVE-2024-25741

    Last Modified: 3 Nov 2025

    printer_write in drivers/usb/gadget/function/f_printer.c in the Linux kernel through 6.7.4 does not properly call usb_ep_queue, which might allow attackers to cause a denial of service or have unspecified other impact.

    Published: 12 Feb 2024
    3.4
    Low

    CVE-2024-1454

    Last Modified: 7 Nov 2025

    The use-after-free vulnerability was found in the AuthentIC driver in OpenSC packages, occuring in the card enrolment process using pkcs15-init when a user or administrator enrols or modifies cards. An attacker must have physical access to the computer system and requires a crafted USB device or smart card to present the system with specially crafted responses to the APDUs, which are considered high complexity and low severity. This manipulation can allow for compromised card management operations during enrolment.

    Published: 12 Feb 2024
    3.1
    Low

    CVE-2024-1433

    Last Modified: 24 Apr 2025

    A vulnerability, which was classified as problematic, was found in KDE Plasma Workspace up to 5.93.0. This affects the function EventPluginsManager::enabledPlugins of the file components/calendar/eventpluginsmanager.cpp of the component Theme File Handler. The manipulation of the argument pluginId leads to path traversal. It is possible to initiate the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The patch is named 6cdf42916369ebf4ad5bd876c4dfa0170d7b2f01. It is recommended to apply a patch to fix this issue. The associated identifier of this vulnerability is VDB-253407. NOTE: This requires write access to user's home or the installation of third party global themes.

    Published: 11 Feb 2024
    6.5
    Medium

    CVE-2024-21875

    Last Modified: 11 Mar 2025

    Allocation of Resources Without Limits or Throttling vulnerability in Badge leading to a denial of service attack.Team Hacker Hotel Badge 2024 on risc-v (billboard modules) allows Flooding.This issue affects Hacker Hotel Badge 2024: from 0.1.0 through 0.1.3.

    Published: 11 Feb 2024
    5
    Medium

    CVE-2024-1432

    Last Modified: 30 Dec 2025

    ** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in DeepFaceLab pretrained DF.wf.288res.384.92.72.22 and classified as problematic. This issue affects the function apply_xseg of the file main.py. The manipulation leads to deserialization. The attack may be initiated remotely. The complexity of an attack is rather high. The exploitation is known to be difficult. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-253391. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.

    Published: 11 Feb 2024
    9
    Critical

    CVE-2024-23724

    Last Modified: 21 Nov 2024

    Ghost through 5.76.0 allows stored XSS, and resultant privilege escalation in which a contributor can take over any account, via an SVG profile picture that contains JavaScript code to interact with the API on localhost TCP port 3001. NOTE: The discoverer reports that "The vendor does not view this as a valid vector."

    Published: 11 Feb 2024
    7.5
    High

    CVE-2023-52428

    Last Modified: 21 Nov 2024

    In Connect2id Nimbus JOSE+JWT before 9.37.2, an attacker can cause a denial of service (resource consumption) via a large JWE p2c header value (aka iteration count) for the PasswordBasedDecrypter (PBKDF2) component.

    Published: 11 Feb 2024
    7.5
    High

    CVE-2023-52427

    Last Modified: 21 Nov 2024

    In OpenDDS through 3.27, there is a segmentation fault for a DataWriter with a large value of resource_limits.max_samples. NOTE: the vendor's position is that the product is not designed to handle a max_samples value that is too large for the amount of memory on the system.

    Published: 11 Feb 2024
    8.8
    High

    CVE-2024-25419

    Last Modified: 15 May 2025

    flusity-CMS v2.33 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /core/tools/update_menu.php.

    Published: 11 Feb 2024
    6.1
    Medium

    CVE-2024-25712

    Last Modified: 16 Jun 2025

    http-swagger before 1.2.6 allows XSS via PUT requests, because a file that has been uploaded (via httpSwagger.WrapHandler and *webdav.memFile) can subsequently be accessed via a GET request. NOTE: this is independently fixable with respect to CVE-2022-24863, because (if a solution continued to allow PUT requests) large files could have been blocked without blocking JavaScript, or JavaScript could have been blocked without blocking large files.

    Published: 11 Feb 2024
    6.1
    Medium

    CVE-2024-25715

    Last Modified: 16 Jun 2025

    Glewlwyd SSO server 2.x through 2.7.6 allows open redirection via redirect_uri.

    Published: 11 Feb 2024
    9.8
    Critical

    CVE-2024-25718

    Last Modified: 24 Apr 2025

    In the Samly package before 1.4.0 for Elixir, Samly.State.Store.get_assertion/3 can return an expired session, which interferes with access control because Samly.AuthHandler uses a cached session and does not replace it, even after expiry.

    Published: 11 Feb 2024
    9.8
    Critical

    CVE-2024-25722

    Last Modified: 11 Jun 2025

    qanything_kernel/connector/database/mysql/mysql_client.py in qanything.ai QAnything before 1.2.0 allows SQL Injection.

    Published: 11 Feb 2024
    8.6
    High

    CVE-2024-25713

    Last Modified: 4 Nov 2025

    yyjson through 0.8.0 has a double free, leading to remote code execution in some cases, because the pool_free function lacks loop checks. (pool_free is part of the pool series allocator, along with pool_malloc and pool_realloc.)

    Published: 11 Feb 2024
    7.5
    High

    CVE-2024-25711

    Last Modified: 4 Nov 2025

    diffoscope before 256 allows directory traversal via an embedded filename in a GPG file. Contents of any file, such as ../.ssh/id_rsa, may be disclosed to an attacker. This occurs because the value of the gpg --use-embedded-filenames option is trusted.

    Published: 11 Feb 2024
    8.8
    High

    CVE-2024-25417

    Last Modified: 12 Jun 2025

    flusity-CMS v2.33 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /core/tools/add_translation.php.

    Published: 11 Feb 2024