CVE Feed

    Dashboard / CVE

    8.8
    High

    CVE-2024-25450

    Last Modified: 16 Jun 2025

    imlib2 v1.9.1 was discovered to mishandle memory allocation in the function init_imlib_fonts().

    Published: 9 Feb 2024
    5.5
    Medium

    CVE-2024-25454

    Last Modified: 8 May 2025

    Bento4 v1.6.0-640 was discovered to contain a NULL pointer dereference via the AP4_DescriptorFinder::Test() function.

    Published: 9 Feb 2024
    9.8
    Critical

    CVE-2024-25675

    Last Modified: 16 Jun 2025

    An issue was discovered in MISP before 2.4.184. A client does not need to use POST to start an export generation process. This is related to app/Controller/JobsController.php and app/View/Events/export.ctp.

    Published: 9 Feb 2024
    5.4
    Medium

    CVE-2023-31506

    Last Modified: 16 Jun 2025

    A cross-site scripting (XSS) vulnerability in Grav versions 1.7.44 and before, allows remote authenticated attackers to execute arbitrary web scripts or HTML via the onmouseover attribute of an ISINDEX element.

    Published: 9 Feb 2024
    7.8
    High

    CVE-2024-25003

    Last Modified: 8 May 2025

    KiTTY versions 0.76.1.13 and before is vulnerable to a stack-based buffer overflow via the hostname, occurs due to insufficient bounds checking and input sanitization. This allows an attacker to overwrite adjacent memory, which leads to arbitrary code execution.

    Published: 9 Feb 2024
    9.8
    Critical

    CVE-2024-25302

    Last Modified: 8 May 2025

    Sourcecodester Event Student Attendance System 1.0, allows SQL Injection via the 'student' parameter.

    Published: 9 Feb 2024
    5.5
    Medium

    CVE-2024-25452

    Last Modified: 21 Nov 2024

    Bento4 v1.6.0-640 was discovered to contain an out-of-memory bug via the AP4_UrlAtom::AP4_UrlAtom() function.

    Published: 9 Feb 2024
    5.5
    Medium

    CVE-2024-25453

    Last Modified: 16 Jun 2025

    Bento4 v1.6.0-640 was discovered to contain a NULL pointer dereference via the AP4_StszAtom::GetSampleSize() function.

    Published: 9 Feb 2024
    9.8
    Critical

    CVE-2024-25674

    Last Modified: 21 Nov 2024

    An issue was discovered in MISP before 2.4.184. Organisation logo upload is insecure because of a lack of checks for the file extension and MIME type.

    Published: 9 Feb 2024
    6.1
    Medium

    CVE-2023-39683

    Last Modified: 15 May 2025

    Cross Site Scripting (XSS) vulnerability in EasyEmail v.4.12.2 and before allows a local attacker to execute arbitrary code via the user input parameter(s). NOTE: Researcher claims issue is present in all versions prior and later than tested version.

    Published: 9 Feb 2024
    7.5
    High

    CVE-2023-50291

    Last Modified: 15 May 2025

    Insufficiently Protected Credentials vulnerability in Apache Solr. This issue affects Apache Solr: from 6.0.0 through 8.11.2, from 9.0.0 before 9.3.0. One of the two endpoints that publishes the Solr process' Java system properties, /admin/info/properties, was only setup to hide system properties that had "password" contained in the name. There are a number of sensitive system properties, such as "basicauth" and "aws.secretKey" do not contain "password", thus their values were published via the "/admin/info/properties" endpoint. This endpoint populates the list of System Properties on the home screen of the Solr Admin page, making the exposed credentials visible in the UI. This /admin/info/properties endpoint is protected under the "config-read" permission. Therefore, Solr Clouds with Authorization enabled will only be vulnerable through logged-in users that have the "config-read" permission. Users are recommended to upgrade to version 9.3.0 or 8.11.3, which fixes the issue. A single option now controls hiding Java system property for all endpoints, "-Dsolr.hiddenSysProps". By default all known sensitive properties are hidden (including "-Dbasicauth"), as well as any property with a name containing "secret" or "password". Users who cannot upgrade can also use the following Java system property to fix the issue:   '-Dsolr.redaction.system.pattern=.*(password|secret|basicauth).*'

    Published: 9 Feb 2024
    7.5
    High

    CVE-2023-50298

    Last Modified: 13 Feb 2025

    Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Solr.This issue affects Apache Solr: from 6.0.0 through 8.11.2, from 9.0.0 before 9.4.1. Solr Streaming Expressions allows users to extract data from other Solr Clouds, using a "zkHost" parameter. When original SolrCloud is setup to use ZooKeeper credentials and ACLs, they will be sent to whatever "zkHost" the user provides. An attacker could setup a server to mock ZooKeeper, that accepts ZooKeeper requests with credentials and ACLs and extracts the sensitive information, then send a streaming expression using the mock server's address in "zkHost". Streaming Expressions are exposed via the "/streaming" handler, with "read" permissions. Users are recommended to upgrade to version 8.11.3 or 9.4.1, which fix the issue. From these versions on, only zkHost values that have the same server address (regardless of chroot), will use the given ZooKeeper credentials and ACLs when connecting.

    Published: 9 Feb 2024
    7.8
    High

    CVE-2024-23749

    Last Modified: 15 May 2025

    KiTTY versions 0.76.1.13 and before is vulnerable to command injection via the filename variable, occurs due to insufficient input sanitization and validation, failure to escape special characters, and insecure system calls (at lines 2369-2390). This allows an attacker to add inputs inside the filename variable, leading to arbitrary code execution.

    Published: 9 Feb 2024
    9.8
    Critical

    CVE-2024-24308

    Last Modified: 21 Nov 2024

    SQL Injection vulnerability in Boostmyshop (boostmyshopagent) module for Prestashop versions 1.1.9 and before, allows remote attackers to escalate privileges and obtain sensitive information via changeOrderCarrier.php, relayPoint.php, and shippingConfirmation.php.

    Published: 9 Feb 2024
    7.8
    High

    CVE-2024-25004

    Last Modified: 15 May 2025

    KiTTY versions 0.76.1.13 and before is vulnerable to a stack-based buffer overflow via the username, occurs due to insufficient bounds checking and input sanitization (at line 2600). This allows an attacker to overwrite adjacent memory, which leads to arbitrary code execution.

    Published: 9 Feb 2024
    8.8
    High

    CVE-2024-25305

    Last Modified: 15 May 2025

    Code-projects Simple School Managment System 1.0 allows Authentication Bypass via the username and password parameters at School/index.php.

    Published: 9 Feb 2024
    8.8
    High

    CVE-2024-25306

    Last Modified: 21 Nov 2024

    Code-projects Simple School Managment System 1.0 allows SQL Injection via the 'aname' parameter at "School/index.php".

    Published: 9 Feb 2024
    9.8
    Critical

    CVE-2024-25307

    Last Modified: 20 Jun 2025

    Code-projects Cinema Seat Reservation System 1.0 allows SQL Injection via the 'id' parameter at "/Cinema-Reservation/booking.php?id=1."

    Published: 9 Feb 2024
    8.8
    High

    CVE-2024-25309

    Last Modified: 17 Jun 2025

    Code-projects Simple School Managment System 1.0 allows SQL Injection via the 'pass' parameter at School/teacher_login.php.

    Published: 9 Feb 2024
    8.8
    High

    CVE-2024-25312

    Last Modified: 20 Jun 2025

    Code-projects Simple School Managment System 1.0 allows SQL Injection via the 'id' parameter at "School/sub_delete.php?id=5."

    Published: 9 Feb 2024
    8.8
    High

    CVE-2024-25313

    Last Modified: 21 Nov 2024

    Code-projects Simple School Managment System 1.0 allows Authentication Bypass via the username and password parameters at School/teacher_login.php.

    Published: 9 Feb 2024
    9.8
    Critical

    CVE-2024-25314

    Last Modified: 15 May 2025

    Code-projects Hotel Managment System 1.0, allows SQL Injection via the 'sid' parameter in Hotel/admin/show.php?sid=2.

    Published: 9 Feb 2024
    9.8
    Critical

    CVE-2024-25315

    Last Modified: 15 May 2025

    Code-projects Hotel Managment System 1.0, allows SQL Injection via the 'rid' parameter in Hotel/admin/roombook.php?rid=2.

    Published: 9 Feb 2024
    9.8
    Critical

    CVE-2024-25316

    Last Modified: 21 Nov 2024

    Code-projects Hotel Managment System 1.0 allows SQL Injection via the 'eid' parameter in Hotel/admin/usersettingdel.php?eid=2.

    Published: 9 Feb 2024
    8.8
    High

    CVE-2024-25318

    Last Modified: 16 Jun 2025

    Code-projects Hotel Managment System 1.0 allows SQL Injection via the 'pid' parameter in Hotel/admin/print.php?pid=2.

    Published: 9 Feb 2024
    7.8
    High

    CVE-2024-25443

    Last Modified: 4 Nov 2025

    An issue in the HuginBase::ImageVariable<double>::linkWith function of Hugin v2022.0.0 allows attackers to cause a heap-use-after-free via parsing a crafted image.

    Published: 9 Feb 2024
    7.8
    High

    CVE-2024-25446

    Last Modified: 4 Nov 2025

    An issue in the HuginBase::PTools::setDestImage function of Hugin v2022.0.0 allows attackers to cause a heap buffer overflow via parsing a crafted image.

    Published: 9 Feb 2024
    8.8
    High

    CVE-2024-25447

    Last Modified: 15 May 2025

    An issue in the imlib_load_image_with_error_return function of imlib2 v1.9.1 allows attackers to cause a heap buffer overflow via parsing a crafted image.

    Published: 9 Feb 2024
    8.8
    High

    CVE-2024-25448

    Last Modified: 21 Nov 2024

    An issue in the imlib_free_image_and_decache function of imlib2 v1.9.1 allows attackers to cause a heap buffer overflow via parsing a crafted image.

    Published: 9 Feb 2024
    8.8
    High

    CVE-2024-25677

    Last Modified: 16 Jun 2025

    In Min before 1.31.0, local files are not correctly treated as unique security origins, which allows them to improperly request cross-origin resources. For example, a local file may request other local files through an XML document.

    Published: 9 Feb 2024
    9.8
    Critical

    CVE-2024-25678

    Last Modified: 20 Jun 2025

    In LiteSpeed QUIC (LSQUIC) Library before 4.0.4, DCID validation is mishandled.

    Published: 9 Feb 2024
    6.5
    Medium

    CVE-2024-25679

    Last Modified: 16 Jun 2025

    In PQUIC before 5bde5bb, retention of unused initial encryption keys allows attackers to disrupt a connection with a PSK configuration by sending a CONNECTION_CLOSE frame that is encrypted via the initial key computed. Network traffic sniffing is needed as part of exploitation.

    Published: 9 Feb 2024
    7
    High

    CVE-2023-29483

    Last Modified: 4 Nov 2025

    eventlet before 0.35.2, as used in dnspython before 2.6.0, allows remote attackers to interfere with DNS name resolution by quickly sending an invalid packet from the expected IP address and source port, aka a "TuDoor" attack. In other words, dnspython does not have the preferred behavior in which the DNS name resolution algorithm would proceed, within the full time window, in order to wait for a valid packet. NOTE: dnspython 2.6.0 is unusable for a different reason that was addressed in 2.6.1.

    Published: 9 Feb 2024
    7.8
    High

    CVE-2024-25442

    Last Modified: 4 Nov 2025

    An issue in the HuginBase::PanoramaMemento::loadPTScript function of Hugin v2022.0.0 allows attackers to cause a heap buffer overflow via parsing a crafted image.

    Published: 9 Feb 2024
    7.8
    High

    CVE-2024-25445

    Last Modified: 4 Nov 2025

    Improper handling of values in HuginBase::PTools::Transform::transform of Hugin 2022.0.0 leads to an assertion failure.

    Published: 9 Feb 2024
    9.8
    Critical

    CVE-2023-46350

    Last Modified: 20 Jun 2025

    SQL injection vulnerability in InnovaDeluxe "Manufacturer or supplier alphabetical search" (idxrmanufacturer) module for PrestaShop versions 2.0.4 and before, allows remote attackers to escalate privileges and obtain sensitive information via the methods IdxrmanufacturerFunctions::getCornersLink, IdxrmanufacturerFunctions::getManufacturersLike and IdxrmanufacturerFunctions::getSuppliersLike.

    Published: 9 Feb 2024
    9.8
    Critical

    CVE-2023-50026

    Last Modified: 15 May 2025

    SQL injection vulnerability in Presta Monster "Multi Accessories Pro" (hsmultiaccessoriespro) module for PrestaShop versions 5.1.1 and before, allows remote attackers to escalate privileges and obtain sensitive information via the method HsAccessoriesGroupProductAbstract::getAccessoriesByIdProducts().

    Published: 9 Feb 2024
    7.5
    High

    CVE-2023-50292

    Last Modified: 15 May 2025

    Incorrect Permission Assignment for Critical Resource, Improper Control of Dynamically-Managed Code Resources vulnerability in Apache Solr. This issue affects Apache Solr: from 8.10.0 through 8.11.2, from 9.0.0 before 9.3.0. The Schema Designer was introduced to allow users to more easily configure and test new Schemas and configSets. However, when the feature was created, the "trust" (authentication) of these configSets was not considered. External library loading is only available to configSets that are "trusted" (created by authenticated users), thus non-authenticated users are unable to perform Remote Code Execution. Since the Schema Designer loaded configSets without taking their "trust" into account, configSets that were created by unauthenticated users were allowed to load external libraries when used in the Schema Designer. Users are recommended to upgrade to version 9.3.0, which fixes the issue.

    Published: 9 Feb 2024
    8.8
    High

    CVE-2023-50386

    Last Modified: 24 Apr 2025

    Improper Control of Dynamically-Managed Code Resources, Unrestricted Upload of File with Dangerous Type, Inclusion of Functionality from Untrusted Control Sphere vulnerability in Apache Solr.This issue affects Apache Solr: from 6.0.0 through 8.11.2, from 9.0.0 before 9.4.1. In the affected versions, Solr ConfigSets accepted Java jar and class files to be uploaded through the ConfigSets API. When backing up Solr Collections, these configSet files would be saved to disk when using the LocalFileSystemRepository (the default for backups). If the backup was saved to a directory that Solr uses in its ClassPath/ClassLoaders, then the jar and class files would be available to use with any ConfigSet, trusted or untrusted. When Solr is run in a secure way (Authorization enabled), as is strongly suggested, this vulnerability is limited to extending the Backup permissions with the ability to add libraries. Users are recommended to upgrade to version 8.11.3 or 9.4.1, which fix the issue. In these versions, the following protections have been added: * Users are no longer able to upload files to a configSet that could be executed via a Java ClassLoader. * The Backup API restricts saving backups to directories that are used in the ClassLoader.

    Published: 9 Feb 2024
    8.8
    High

    CVE-2024-25304

    Last Modified: 15 May 2025

    Code-projects Simple School Managment System 1.0 allows SQL Injection via the 'apass' parameter at "School/index.php."

    Published: 9 Feb 2024
    8.8
    High

    CVE-2024-25308

    Last Modified: 12 Jun 2025

    Code-projects Simple School Managment System 1.0 allows SQL Injection via the 'name' parameter at School/teacher_login.php.

    Published: 9 Feb 2024
    6.5
    Medium

    CVE-2024-25451

    Last Modified: 12 Jun 2025

    Bento4 v1.6.0-640 was discovered to contain an out-of-memory bug via the AP4_DataBuffer::ReallocateBuffer() function.

    Published: 9 Feb 2024
    8.8
    High

    CVE-2024-25310

    Last Modified: 20 Jun 2025

    Code-projects Simple School Managment System 1.0 allows SQL Injection via the 'id' parameter at "School/delete.php?id=5."

    Published: 9 Feb 2024
    8.8
    High

    CVE-2024-24821

    Last Modified: 17 Jun 2025

    Composer is a dependency Manager for the PHP language. In affected versions several files within the local working directory are included during the invocation of Composer and in the context of the executing user. As such, under certain conditions arbitrary code execution may lead to local privilege escalation, provide lateral user movement or malicious code execution when Composer is invoked within a directory with tampered files. All Composer CLI commands are affected, including composer.phar's self-update. The following scenarios are of high risk: Composer being run with sudo, Pipelines which may execute Composer on untrusted projects, Shared environments with developers who run Composer individually on the same project. This vulnerability has been addressed in versions 2.7.0 and 2.2.23. It is advised that the patched versions are applied at the earliest convenience. Where not possible, the following should be addressed: Remove all sudo composer privileges for all users to mitigate root privilege escalation, and avoid running Composer within an untrusted directory, or if needed, verify that the contents of `vendor/composer/InstalledVersions.php` and `vendor/composer/installed.php` do not include untrusted code. A reset can also be done on these files by the following:```sh rm vendor/composer/installed.php vendor/composer/InstalledVersions.php composer install --no-scripts --no-plugins ```

    Published: 8 Feb 2024
    4.3
    Medium

    CVE-2024-24829

    Last Modified: 21 Nov 2024

    Sentry is an error tracking and performance monitoring platform. Sentry’s integration platform provides a way for external services to interact with Sentry. One of such integrations, the Phabricator integration (maintained by Sentry) with version <=24.1.1 contains a constrained SSRF vulnerability. An attacker could make Sentry send POST HTTP requests to arbitrary URLs (including internal IP addresses) by providing an unsanitized input to the Phabricator integration. However, the body payload is constrained to a specific format. If an attacker has access to a Sentry instance, this allows them to: 1. interact with internal network; 2. scan local/remote ports. This issue has been fixed in Sentry self-hosted release 24.1.2, and has already been mitigated on sentry.io on February 8. Users are advised to upgrade. There are no known workarounds for this vulnerability.

    Published: 8 Feb 2024
    9.1
    Critical

    CVE-2024-24825

    Last Modified: 17 Jun 2025

    DIRAC is a distributed resource framework. In affected versions any user could get a token that has been requested by another user/agent. This may expose resources to unintended parties. This issue has been addressed in release version 8.0.37. Users are advised to upgrade. There are no known workarounds for this vulnerability.

    Published: 8 Feb 2024
    9.9
    Critical

    CVE-2024-24830

    Last Modified: 27 Aug 2025

    OpenObserve is a observability platform built specifically for logs, metrics, traces, analytics, designed to work at petabyte scale. A vulnerability has been identified in the "/api/{org_id}/users" endpoint. This vulnerability allows any authenticated regular user ('member') to add new users with elevated privileges, including the 'root' role, to an organization. This issue circumvents the intended security controls for role assignments. The vulnerability resides in the user creation process, where the payload does not validate the user roles. A regular user can manipulate the payload to assign root-level privileges. This vulnerability leads to Unauthorized Privilege Escalation and significantly compromises the application's role-based access control system. It allows unauthorized control over application resources and poses a risk to data security. All users, particularly those in administrative roles, are impacted. This issue has been addressed in release version 0.8.0. Users are advised to upgrade. There are no known workarounds for this vulnerability.

    Published: 8 Feb 2024
    9.1
    Critical

    CVE-2024-25106

    Last Modified: 21 Nov 2024

    OpenObserve is a observability platform built specifically for logs, metrics, traces, analytics, designed to work at petabyte scale. A critical vulnerability has been identified in the "/api/{org_id}/users/{email_id}" endpoint. This vulnerability allows any authenticated user within an organization to remove any other user from that same organization, irrespective of their respective roles. This includes the ability to remove users with "Admin" and "Root" roles. By enabling any organizational member to unilaterally alter the user base, it opens the door to unauthorized access and can cause considerable disruptions in operations. The core of the vulnerability lies in the `remove_user_from_org` function in the user management system. This function is designed to allow organizational users to remove members from their organization. The function does not check if the user initiating the request has the appropriate administrative privileges to remove a user. Any user who is part of the organization, irrespective of their role, can remove any other user, including those with higher privileges. This vulnerability is categorized as an Authorization issue leading to Unauthorized User Removal. The impact is severe, as it compromises the integrity of user management within organizations. By exploiting this vulnerability, any user within an organization, without the need for administrative privileges, can remove critical users, including "Admins" and "Root" users. This could result in unauthorized system access, administrative lockout, or operational disruptions. Given that user accounts are typically created by "Admins" or "Root" users, this vulnerability can be exploited by any user who has been granted access to an organization, thereby posing a critical risk to the security and operational stability of the application. This issue has been addressed in release version 0.8.0. Users are advised to upgrade.

    Published: 8 Feb 2024
    4.9
    Medium

    CVE-2024-25107

    Last Modified: 17 Jun 2025

    WikiDiscover is an extension designed for use with a CreateWiki managed farm to display wikis. On Special:WikiDiscover, the `Language::date` function is used when making the human-readable timestamp for inclusion on the wiki_creation column. This function uses interface messages to translate the names of months and days. It uses the `->text()` output mode, returning unescaped interface messages. Since the output is not escaped later, the unescaped interface message is included on the output, resulting in an XSS vulnerability. Exploiting this on-wiki requires the `(editinterface)` right. This vulnerability has been addressed in commit `267e763a0`. Users are advised to update their installations. There are no known workarounds for this vulnerability.

    Published: 8 Feb 2024
    6.1
    Medium

    CVE-2023-51630

    Last Modified: 21 Nov 2024

    Paessler PRTG Network Monitor Cross-Site Scripting Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authentication on affected installations of Paessler PRTG Network Monitor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the web console. The issue results from the lack of proper validation of user-supplied data, which can lead to the injection of an arbitrary script. An attacker can leverage this vulnerability to bypass authentication on the system. . Was ZDI-CAN-21182.

    Published: 8 Feb 2024