CVE Feed

    Dashboard / CVE

    6.3
    Medium

    CVE-2024-1353

    Last Modified: 8 May 2025

    A vulnerability, which was classified as critical, has been found in PHPEMS up to 1.0. Affected by this issue is the function index of the file app/weixin/controller/index.api.php. The manipulation of the argument picurl leads to deserialization. The exploit has been disclosed to the public and may be used. VDB-253226 is the identifier assigned to this vulnerability.

    Published: 8 Feb 2024
    —
    Unknown

    CVE-2024-1373

    Last Modified: 11 Mar 2024

    ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2023-46209. Reason: This candidate is a duplicate of CVE-2023-46209. Notes: All CVE users should reference CVE-2023-46209 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage.

    Published: 8 Feb 2024
    7.3
    High

    CVE-2024-0242

    Last Modified: 21 Nov 2024

    Under certain circumstances IQ Panel4 and IQ4 Hub panel software prior to version 4.4.2 could allow unauthorized access to settings.

    Published: 8 Feb 2024
    7.7
    High

    CVE-2024-1329

    Last Modified: 21 Nov 2024

    HashiCorp Nomad and Nomad Enterprise 1.5.13 up to 1.6.6, and 1.7.3 template renderer is vulnerable to arbitrary file write on the host as the Nomad client user through symlink attacks. This vulnerability, CVE-2024-1329, is fixed in Nomad 1.7.4, 1.6.7, and 1.5.14.

    Published: 8 Feb 2024
    5.9
    Medium

    CVE-2024-24834

    Last Modified: 28 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in realmag777 BEAR – Bulk Editor and Products Manager Professional for WooCommerce by Pluginus.Net allows Stored XSS.This issue affects BEAR – Bulk Editor and Products Manager Professional for WooCommerce by Pluginus.Net: from n/a through 1.1.4.

    Published: 8 Feb 2024
    6.5
    Medium

    CVE-2024-24836

    Last Modified: 28 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Audrasjb GDPR Data Request Form allows Stored XSS.This issue affects GDPR Data Request Form: from n/a through 1.6.

    Published: 8 Feb 2024
    6.5
    Medium

    CVE-2024-24871

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in creativethemeshq Blocksy blocksy.This issue affects Blocksy: from n/a through <= 2.0.19.

    Published: 8 Feb 2024
    7.1
    High

    CVE-2024-24877

    Last Modified: 28 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Magic Hills Pty Ltd Wonder Slider Lite allows Reflected XSS.This issue affects Wonder Slider Lite: from n/a through 13.9.

    Published: 8 Feb 2024
    6
    Medium

    CVE-2023-7169

    Last Modified: 21 Nov 2024

    Authentication Bypass by Spoofing vulnerability in Snow Software Snow Inventory Agent on Windows allows Signature Spoof.This issue affects Snow Inventory Agent: through 6.14.5. Customers advised to upgrade to version 7.0

    Published: 8 Feb 2024
    7.1
    High

    CVE-2024-24878

    Last Modified: 28 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Marco Almeida | Webdados Portugal CTT Tracking for WooCommerce portugal-ctt-tracking-woocommerce.This issue affects Portugal CTT Tracking for WooCommerce: from n/a through <= 2.1.

    Published: 8 Feb 2024
    7.1
    High

    CVE-2024-24879

    Last Modified: 28 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Yannick Lefebvre Link Library allows Reflected XSS.This issue affects Link Library: from n/a through 7.5.13.

    Published: 8 Feb 2024
    6.5
    Medium

    CVE-2024-24880

    Last Modified: 28 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apollo13Themes Apollo13 Framework Extensions allows Stored XSS.This issue affects Apollo13 Framework Extensions: from n/a through 1.9.2.

    Published: 8 Feb 2024
    7.5
    High

    CVE-2023-6519

    Last Modified: 20 May 2026

    Exposure of Data Element to Wrong Session vulnerability in Mia Technology Inc. MİA-MED allows Read Sensitive Strings Within an Executable. This issue affects MİA-MED: before 1.0.7.

    Published: 8 Feb 2024
    7.5
    High

    CVE-2023-6518

    Last Modified: 20 May 2026

    Plaintext Storage of a Password vulnerability in Mia Technology Inc. MİA-MED allows Read Sensitive Strings Within an Executable. This issue affects MİA-MED: before 1.0.7.

    Published: 8 Feb 2024
    7.5
    High

    CVE-2023-6517

    Last Modified: 20 May 2026

    Exposure of Sensitive Information Due to Incompatible Policies vulnerability in Mia Technology Inc. MİA-MED allows Collect Data as Provided by Users. This issue affects MİA-MED: before 1.0.7.

    Published: 8 Feb 2024
    6.5
    Medium

    CVE-2023-6564

    Last Modified: 21 Nov 2024

    An issue has been discovered in GitLab EE Premium and Ultimate affecting versions 16.4.3, 16.5.3, and 16.6.1. In projects using subgroups to define who can push and/or merge to protected branches, there may have been instances in which subgroup members with the Developer role were able to push or merge to protected branches.

    Published: 8 Feb 2024
    7.1
    High

    CVE-2024-24881

    Last Modified: 28 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in VeronaLabs WP SMS – Messaging & SMS Notification for WordPress, WooCommerce, GravityForms, etc allows Reflected XSS.This issue affects WP SMS – Messaging & SMS Notification for WordPress, WooCommerce, GravityForms, etc: from n/a through 6.5.2.

    Published: 8 Feb 2024
    5.9
    Medium

    CVE-2024-24885

    Last Modified: 28 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Lê Văn Toản Woocommerce Vietnam Checkout allows Stored XSS.This issue affects Woocommerce Vietnam Checkout: from n/a through 2.0.7.

    Published: 8 Feb 2024
    5.9
    Medium

    CVE-2024-24886

    Last Modified: 28 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Acowebs Product Labels For Woocommerce (Sale Badges) allows Stored XSS.This issue affects Product Labels For Woocommerce (Sale Badges): from n/a through 1.5.3.

    Published: 8 Feb 2024
    8.8
    High

    CVE-2023-6515

    Last Modified: 20 May 2026

    Authorization Bypass Through User-Controlled Key vulnerability in Mia Technology Inc. MİA-MED allows Authentication Abuse. This issue affects MİA-MED: before 1.0.7.

    Published: 8 Feb 2024
    6.2
    Medium

    CVE-2024-22464

    Last Modified: 24 Apr 2025

    Dell EMC AppSync, versions from 4.2.0.0 to 4.6.0.0 including all Service Pack releases, contain an exposure of sensitive information vulnerability in AppSync server logs. A high privileged remote attacker could potentially exploit this vulnerability, leading to the disclosure of certain user credentials. The attacker may be able to use the exposed credentials to access the vulnerable system with privileges of the compromised account.

    Published: 8 Feb 2024
    7.8
    High

    CVE-2024-1150

    Last Modified: 21 Nov 2024

    Improper Verification of Cryptographic Signature vulnerability in Snow Software Inventory Agent on Unix allows File Manipulation through Snow Update Packages.This issue affects Inventory Agent: through 7.3.1.

    Published: 8 Feb 2024
    7.8
    High

    CVE-2024-1149

    Last Modified: 15 May 2025

    Improper Verification of Cryptographic Signature vulnerability in Snow Software Inventory Agent on MacOS, Snow Software Inventory Agent on Windows, Snow Software Inventory Agent on Linux allows File Manipulation through Snow Update Packages.This issue affects Inventory Agent: through 6.12.0; Inventory Agent: through 6.14.5; Inventory Agent: through 6.7.2.

    Published: 8 Feb 2024
    7.5
    High

    CVE-2024-23452

    Last Modified: 4 Jun 2025

    Request smuggling vulnerability in HTTP server in Apache bRPC 0.9.5~1.7.0 on all platforms allows attacker to smuggle request. Vulnerability Cause Description: The http_parser does not comply with the RFC-7230 HTTP 1.1 specification. Attack scenario: If a message is received with both a Transfer-Encoding and a Content-Length header field, such a message might indicate an attempt to perform request smuggling or response splitting. One particular attack scenario is that a bRPC made http server on the backend receiving requests in one persistent connection from frontend server that uses TE to parse request with the logic that 'chunk' is contained in the TE field. in that case an attacker can smuggle a request into the connection to the backend server.  Solution: You can choose one solution from below: 1. Upgrade bRPC to version 1.8.0, which fixes this issue. Download link: https://github.com/apache/brpc/releases/tag/1.8.0 2. Apply this patch:  https://github.com/apache/brpc/pull/2518

    Published: 8 Feb 2024
    5.3
    Medium

    CVE-2024-0965

    Last Modified: 8 Apr 2026

    The Simple Page Access Restriction plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.0.21 via the REST API. This makes it possible for unauthenticated attackers to bypass the plugin's page restriction and view page content.

    Published: 8 Feb 2024
    9.8
    Critical

    CVE-2024-1207

    Last Modified: 8 Apr 2026

    The WP Booking Calendar plugin for WordPress is vulnerable to SQL Injection via the 'calendar_request_params[dates_ddmmyy_csv]' parameter in all versions up to, and including, 9.9 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

    Published: 8 Feb 2024
    4.3
    Medium

    CVE-2024-0511

    Last Modified: 8 Apr 2026

    The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.3.87. This is due to missing or incorrect nonce validation on the wpr_update_form_action_meta function. This makes it possible for unauthenticated attackers to post metadata via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

    Published: 8 Feb 2024
    5.4
    Medium

    CVE-2024-25148

    Last Modified: 13 May 2025

    In Liferay Portal 7.2.0 through 7.4.1, and older unsupported versions, and Liferay DXP 7.3 before service pack 3, 7.2 before fix pack 15, and older unsupported versions the `doAsUserId` URL parameter may get leaked when creating linked content using the WYSIWYG editor and while impersonating a user. This may allow remote authenticated users to impersonate a user after accessing the linked content.

    Published: 8 Feb 2024
    5.3
    Medium

    CVE-2024-25146

    Last Modified: 15 May 2025

    Liferay Portal 7.2.0 through 7.4.1, and older unsupported versions, and Liferay DXP 7.3 before service pack 3, 7.2 before fix pack 18, and older unsupported versions returns with different responses depending on whether a site does not exist or if the user does not have permission to access the site, which allows remote attackers to discover the existence of sites by enumerating URLs. This vulnerability occurs if locale.prepend.friendly.url.style=2 and if a custom 404 page is used.

    Published: 8 Feb 2024
    6.4
    Medium

    CVE-2023-5665

    Last Modified: 8 Apr 2026

    The Payment Forms for Paystack plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in all versions up to, and including, 3.4.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CVE-2024-32130 is likely a duplicate of this issue.

    Published: 8 Feb 2024
    4.1
    Medium

    CVE-2024-25144

    Last Modified: 13 May 2025

    The IFrame widget in Liferay Portal 7.2.0 through 7.4.3.26, and older unsupported versions, and Liferay DXP 7.4 before update 27, 7.3 before update 6, 7.2 before fix pack 19, and older unsupported versions does not check the URL of the IFrame, which allows remote authenticated users to cause a denial-of-service (DoS) via a self referencing IFrame.

    Published: 8 Feb 2024
    5.4
    Medium

    CVE-2023-47798

    Last Modified: 15 May 2025

    Account lockout in Liferay Portal 7.2.0 through 7.3.0, and older unsupported versions, and Liferay DXP 7.2 before fix pack 5, and older unsupported versions does not invalidate existing user sessions, which allows remote authenticated users to remain authenticated after an account has been locked.

    Published: 8 Feb 2024
    9.8
    Critical

    CVE-2024-22394

    Last Modified: 21 Nov 2024

    An improper authentication vulnerability has been identified in SonicWall SonicOS SSL-VPN feature, which in specific conditions could allow a remote attacker to bypass authentication.  This issue affects only firmware version SonicOS 7.1.1-7040.

    Published: 8 Feb 2024
    7.8
    High

    CVE-2023-25365

    Last Modified: 17 Jun 2025

    Cross Site Scripting vulnerability found in October CMS v.3.2.0 allows local attacker to execute arbitrary code via the file type .mp3

    Published: 8 Feb 2024
    5.4
    Medium

    CVE-2024-24115

    Last Modified: 23 Jan 2026

    A stored cross-site scripting (XSS) vulnerability in the Edit Page function of Cotonti CMS v0.9.24 allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload.

    Published: 8 Feb 2024
    8.8
    High

    CVE-2023-47020

    Last Modified: 10 Jun 2025

    Multiple Cross-Site Request Forgery (CSRF) chaining in NCR Terminal Handler v.1.5.1 allows privileges to be escalated by an attacker through a crafted request involving user account creation and adding the user to an administrator group. This is exploited by an undisclosed function in the WSDL that lacks security controls and can accept custom content types.

    Published: 8 Feb 2024
    9.8
    Critical

    CVE-2023-47132

    Last Modified: 11 Jun 2025

    An issue discovered in N-able N-central before 2023.6 and earlier allows attackers to gain escalated privileges via API calls.

    Published: 8 Feb 2024
    9.8
    Critical

    CVE-2024-24018

    Last Modified: 15 May 2025

    A SQL injection vulnerability exists in Novel-Plus v4.3.0-RC1 and prior versions. An attacker can pass in crafted offset, limit, and sort parameters to perform SQL injection via /system/dataPerm/list

    Published: 8 Feb 2024
    9.8
    Critical

    CVE-2024-24026

    Last Modified: 24 Apr 2025

    An arbitrary File upload vulnerability exists in Novel-Plus v4.3.0-RC1 and prior versions at com.java2nb.system.controller.SysUserController: uploadImg(). An attacker can pass in specially crafted filename parameter to perform arbitrary File download.

    Published: 8 Feb 2024
    8.8
    High

    CVE-2024-24350

    Last Modified: 8 May 2025

    File Upload vulnerability in Software Publico e-Sic Livre v.2.0 and before allows a remote attacker to execute arbitrary code via the extension filtering component.

    Published: 8 Feb 2024
    7.5
    High

    CVE-2024-23756

    Last Modified: 15 May 2025

    The HTTP PUT and DELETE methods are enabled in the Plone official Docker version 5.2.13 (5221), allowing unauthenticated attackers to execute dangerous actions such as uploading files to the server or deleting them.

    Published: 8 Feb 2024
    6.7
    Medium

    CVE-2024-23764

    Last Modified: 15 May 2025

    Certain WithSecure products allow Local Privilege Escalation. This affects WithSecure Client Security 15 and later, WithSecure Server Security 15 and later, WithSecure Email and Server Security 15 and later, and WithSecure Elements Endpoint Protection 17 and later.

    Published: 8 Feb 2024
    9.8
    Critical

    CVE-2024-24213

    Last Modified: 21 Nov 2024

    Supabase PostgreSQL v15.1 was discovered to contain a SQL injection vulnerability via the component /pg_meta/default/query. NOTE: the vendor's position is that this is an intended feature; also, it exists in the Supabase dashboard product, not the Supabase PostgreSQL product. Specifically, /pg_meta/default/query is for SQL queries that are entered in an intended UI by an authorized user. Nothing is injected.

    Published: 8 Feb 2024
    8.8
    High

    CVE-2023-27001

    Last Modified: 17 Jun 2025

    An issue discovered in Egerie Risk Manager v4.0.5 allows attackers to bypass the signature mechanism and tamper with the values inside the JWT payload resulting in privilege escalation.

    Published: 8 Feb 2024
    7.5
    High

    CVE-2023-3966

    Last Modified: 16 May 2025

    A flaw was found in Open vSwitch where multiple versions are vulnerable to crafted Geneve packets, which may result in a denial of service and invalid memory accesses. Triggering this issue requires that hardware offloading via the netlink path is enabled.

    Published: 8 Feb 2024
    9.8
    Critical

    CVE-2023-40266

    Last Modified: 15 May 2025

    An issue was discovered in Atos Unify OpenScape Xpressions WebAssistant V7 before V7R1 FR5 HF42 P911. It allows path traversal.

    Published: 8 Feb 2024
    7.5
    High

    CVE-2023-47131

    Last Modified: 21 Nov 2024

    The N-able PassPortal extension before 3.29.2 for Chrome inserts sensitive information into a log file.

    Published: 8 Feb 2024
    9.6
    Critical

    CVE-2023-48974

    Last Modified: 17 Jun 2025

    Cross Site Scripting vulnerability in Axigen WebMail prior to 10.3.3.61 allows a remote attacker to escalate privileges via a crafted script to the serverName_input parameter.

    Published: 8 Feb 2024
    6.1
    Medium

    CVE-2023-49101

    Last Modified: 17 Jun 2025

    WebAdmin in Axigen 10.3.x before 10.3.3.61, 10.4.x before 10.4.24, and 10.5.x before 10.5.10 allows XSS attacks against admins because of mishandling of viewing the usage of SSL certificates.

    Published: 8 Feb 2024
    9.8
    Critical

    CVE-2023-50061

    Last Modified: 21 Nov 2024

    PrestaShop Op'art Easy Redirect >= 1.3.8 and <= 1.3.12 is vulnerable to SQL Injection via Oparteasyredirect::hookActionDispatcher().

    Published: 8 Feb 2024