CVE Feed

    Dashboard / CVE

    9.8
    Critical

    CVE-2024-22836

    Last Modified: 20 Jun 2025

    An OS command injection vulnerability exists in Akaunting v3.1.3 and earlier. An attacker can manipulate the company locale when installing an app to execute system commands on the hosting server.

    Published: 8 Feb 2024
    9.8
    Critical

    CVE-2024-24014

    Last Modified: 5 Jun 2025

    A SQL injection vulnerability exists in Novel-Plus v4.3.0-RC1 and prior versions. An attacker can pass crafted offset, limit, and sort parameters to perform SQL injection via /novel/author/list

    Published: 8 Feb 2024
    9.8
    Critical

    CVE-2024-24017

    Last Modified: 21 Nov 2024

    A SQL injection vulnerability exists in Novel-Plus v4.3.0-RC1 and prior versions. An attacker can pass crafted offset, limit, and sort parameters to perform SQL injection via /common/dict/list

    Published: 8 Feb 2024
    9.8
    Critical

    CVE-2024-24021

    Last Modified: 9 Jun 2025

    A SQL injection vulnerability exists in Novel-Plus v4.3.0-RC1 and prior. An attacker can pass specially crafted offset, limit, and sort parameters to perform SQL injection via /novel/userFeedback/list.

    Published: 8 Feb 2024
    9.8
    Critical

    CVE-2024-24023

    Last Modified: 21 Nov 2024

    A SQL injection vulnerability exists in Novel-Plus v4.3.0-RC1 and prior. An attacker can pass specially crafted offset, limit, and sort parameters to perform SQL injection via /novel/bookContent/list.

    Published: 8 Feb 2024
    9.8
    Critical

    CVE-2024-24024

    Last Modified: 21 Nov 2024

    An arbitrary File download vulnerability exists in Novel-Plus v4.3.0-RC1 and prior at com.java2nb.common.controller.FileController: fileDownload(). An attacker can pass in specially crafted filePath and fieName parameters to perform arbitrary File download.

    Published: 8 Feb 2024
    9.8
    Critical

    CVE-2024-24025

    Last Modified: 12 Jun 2025

    An arbitrary File upload vulnerability exists in Novel-Plus v4.3.0-RC1 and prior at com.java2nb.common.controller.FileController: upload(). An attacker can pass in specially crafted filename parameter to perform arbitrary File download.

    Published: 8 Feb 2024
    6.1
    Medium

    CVE-2024-24034

    Last Modified: 16 Jun 2025

    Setor Informatica S.I.L version 3.0 is vulnerable to Open Redirect via the hprinter parameter, allows remote attackers to execute arbitrary code.

    Published: 8 Feb 2024
    9.8
    Critical

    CVE-2024-24091

    Last Modified: 24 Apr 2025

    Yealink Meeting Server before v26.0.0.66 was discovered to contain an OS command injection vulnerability via the file upload interface.

    Published: 8 Feb 2024
    8.8
    High

    CVE-2024-24113

    Last Modified: 15 May 2025

    xxl-job =< 2.4.1 has a Server-Side Request Forgery (SSRF) vulnerability, which causes low-privileged users to control executor to RCE.

    Published: 8 Feb 2024
    9.8
    Critical

    CVE-2024-24202

    Last Modified: 21 Nov 2024

    An arbitrary file upload vulnerability in /upgrade/control.php of ZenTao Community Edition v18.10, ZenTao Biz v8.10, and ZenTao Max v4.10 allows attackers to execute arbitrary code via uploading a crafted .txt file.

    Published: 8 Feb 2024
    5.3
    Medium

    CVE-2024-24215

    Last Modified: 20 Jun 2025

    An issue in the component /cgi-bin/GetJsonValue.cgi of Cellinx NVT Web Server 5.0.0.014 allows attackers to leak configuration information via a crafted POST request.

    Published: 8 Feb 2024
    9.8
    Critical

    CVE-2024-24216

    Last Modified: 8 May 2025

    Zentao v18.0 to v18.10 was discovered to contain a remote code execution (RCE) vulnerability via the checkConnection method of /app/zentao/module/repo/model.php.

    Published: 8 Feb 2024
    9.8
    Critical

    CVE-2024-24321

    Last Modified: 20 Jun 2025

    An issue in Dlink DIR-816A2 v.1.10CNB05 allows a remote attacker to execute arbitrary code via the wizardstep4_ssid_2 parameter in the sub_42DA54 function.

    Published: 8 Feb 2024
    9.8
    Critical

    CVE-2024-24393

    Last Modified: 15 May 2025

    File Upload vulnerability index.php in Pichome v.1.1.01 allows a remote attacker to execute arbitrary code via crafted POST request.

    Published: 8 Feb 2024
    6.1
    Medium

    CVE-2024-24494

    Last Modified: 15 May 2025

    Cross Site Scripting vulnerability in Daily Habit Tracker v.1.0 allows a remote attacker to execute arbitrary code via the day, exercise, pray, read_book, vitamins, laundry, alcohol and meat parameters in the add-tracker.php and update-tracker.php components.

    Published: 8 Feb 2024
    9.8
    Critical

    CVE-2024-24495

    Last Modified: 15 May 2025

    SQL Injection vulnerability in delete-tracker.php in Daily Habit Tracker v.1.0 allows a remote attacker to execute arbitrary code via crafted GET request.

    Published: 8 Feb 2024
    9.8
    Critical

    CVE-2024-24496

    Last Modified: 21 Nov 2024

    An issue in Daily Habit Tracker v.1.0 allows a remote attacker to manipulate trackers via the home.php, add-tracker.php, delete-tracker.php, update-tracker.php components.

    Published: 8 Feb 2024
    9.8
    Critical

    CVE-2024-25190

    Last Modified: 21 Nov 2024

    l8w8jwt 2.2.1 uses memcmp (which is not constant time) to verify authentication, which makes it easier to bypass authentication via a timing side channel.

    Published: 8 Feb 2024
    9.8
    Critical

    CVE-2024-25191

    Last Modified: 12 Jun 2025

    php-jwt 1.0.0 uses strcmp (which is not constant time) to verify authentication, which makes it easier to bypass authentication via a timing side channel.

    Published: 8 Feb 2024
    9.8
    Critical

    CVE-2024-25189

    Last Modified: 18 Nov 2025

    libjwt 1.15.3 uses strcmp (which is not constant time) to verify authentication, which makes it easier to bypass authentication via a timing side channel.

    Published: 8 Feb 2024
    8.8
    High

    CVE-2023-40265

    Last Modified: 15 May 2025

    An issue was discovered in Atos Unify OpenScape Xpressions WebAssistant V7 before V7R1 FR5 HF42 P911. It allows authenticated remote code execution via file upload.

    Published: 8 Feb 2024
    9.8
    Critical

    CVE-2023-42282

    Last Modified: 15 May 2025

    The ip package before 1.1.9 for Node.js might allow SSRF because some IP addresses (such as 0x7f.1) are improperly categorized as globally routable via isPublic.

    Published: 8 Feb 2024
    7.5
    High

    CVE-2024-23660

    Last Modified: 15 May 2025

    The Binance Trust Wallet app for iOS in commit 3cd6e8f647fbba8b5d8844fcd144365a086b629f, git tag 0.0.4 misuses the trezor-crypto library and consequently generates mnemonic words for which the device time is the only entropy source, leading to economic losses, as exploited in the wild in July 2023. An attacker can systematically generate mnemonics for each timestamp within an applicable timeframe, and link them to specific wallet addresses in order to steal funds from those wallets.

    Published: 8 Feb 2024
    9.8
    Critical

    CVE-2024-24003

    Last Modified: 8 May 2025

    jshERP v3.3 is vulnerable to SQL Injection. The com.jsh.erp.controller.DepotHeadController: com.jsh.erp.utils.BaseResponseInfo findInOutMaterialCount() function of jshERP does not filter `column` and `order` parameters well enough, and an attacker can construct malicious payload to bypass jshERP's protection mechanism in `safeSqlParse` method for sql injection.

    Published: 8 Feb 2024
    6.1
    Medium

    CVE-2023-40262

    Last Modified: 30 Dec 2025

    An issue was discovered in Atos Unify OpenScape Voice Trace Manager V8 before V8 R0.9.11. It allows unauthenticated Stored Cross-Site Scripting (XSS) in the administration component via Access Request.

    Published: 8 Feb 2024
    8.8
    High

    CVE-2023-40263

    Last Modified: 30 Dec 2025

    An issue was discovered in Atos Unify OpenScape Voice Trace Manager V8 before V8 R0.9.11. It allows authenticated command injection via ftp.

    Published: 8 Feb 2024
    4.3
    Medium

    CVE-2023-40264

    Last Modified: 30 Dec 2025

    An issue was discovered in Atos Unify OpenScape Voice Trace Manager V8 before V8 R0.9.11. It allows authenticated path traversal in the user interface.

    Published: 8 Feb 2024
    7
    High

    CVE-2024-22795

    Last Modified: 26 Feb 2026

    Insecure Permissions vulnerability in Forescout SecureConnector v.11.3.06.0063 allows a local attacker to escalate privileges via the Recheck Compliance Status component.

    Published: 8 Feb 2024
    7.4
    High

    CVE-2023-4639

    Last Modified: 15 Apr 2026

    A flaw was found in Undertow, which incorrectly parses cookies with certain value-delimiting characters in incoming requests. This issue could allow an attacker to construct a cookie value to exfiltrate HttpOnly cookie values or spoof arbitrary additional cookie values, leading to unauthorized data access or modification. The main threat from this flaw impacts data confidentiality and integrity.

    Published: 8 Feb 2024
    6.5
    Medium

    CVE-2023-6736

    Last Modified: 24 Apr 2026

    An issue has been discovered in GitLab EE affecting all versions starting from 11.3 before 16.7.6, all versions starting from 16.8 before 16.8.3, all versions starting from 16.9 before 16.9.1. It was possible for an attacker to cause a client-side denial of service using malicious crafted content in the CODEOWNERS file.

    Published: 7 Feb 2024
    6.7
    Medium

    CVE-2023-6840

    Last Modified: 24 Apr 2026

    An issue has been discovered in GitLab EE affecting all versions from 16.4 prior to 16.6.7, 16.7 prior to 16.7.5, and 16.8 prior to 16.8.2 which allows a maintainer to change the name of a protected branch that bypasses the security policy added to block MR.

    Published: 7 Feb 2024
    6.5
    Medium

    CVE-2024-1066

    Last Modified: 23 Apr 2026

    An issue has been discovered in GitLab EE affecting all versions from 13.3.0 prior to 16.6.7, 16.7 prior to 16.7.5, and 16.8 prior to 16.8.2 which allows an attacker to do a resource exhaustion using GraphQL `vulnerabilitiesCountByDay`

    Published: 7 Feb 2024
    5.7
    Medium

    CVE-2024-23448

    Last Modified: 21 Nov 2024

    An issue was discovered whereby APM Server could log at ERROR level, a response from Elasticsearch indicating that indexing the document failed and that response would contain parts of the original document. Depending on the nature of the document that the APM Server attempted to ingest, this could lead to the insertion of sensitive or private information in the APM Server logs.

    Published: 7 Feb 2024
    8
    High

    CVE-2024-0985

    Last Modified: 13 Jun 2025

    Late privilege drop in REFRESH MATERIALIZED VIEW CONCURRENTLY in PostgreSQL allows an object creator to execute arbitrary SQL functions as the command issuer. The command intends to run SQL functions as the owner of the materialized view, enabling safe refresh of untrusted materialized views. The victim is a superuser or member of one of the attacker's roles. The attack requires luring the victim into running REFRESH MATERIALIZED VIEW CONCURRENTLY on the attacker's materialized view. Versions before PostgreSQL 16.2, 15.6, 14.11, 13.14, and 12.18 are affected.

    Published: 7 Feb 2024
    8.8
    High

    CVE-2024-24824

    Last Modified: 17 Jun 2025

    Graylog is a free and open log management platform. Starting in version 2.0.0 and prior to versions 5.1.11 and 5.2.4, arbitrary classes can be loaded and instantiated using a HTTP PUT request to the `/api/system/cluster_config/` endpoint. Graylog's cluster config system uses fully qualified class names as config keys. To validate the existence of the requested class before using them, Graylog loads the class using the class loader. If a user with the appropriate permissions performs the request, arbitrary classes with 1-arg String constructors can be instantiated. This will execute arbitrary code that is run during class instantiation. In the specific use case of `java.io.File`, the behavior of the internal web-server stack will lead to information exposure by including the entire file content in the response to the REST request. Versions 5.1.11 and 5.2.4 contain a fix for this issue.

    Published: 7 Feb 2024
    5.7
    Medium

    CVE-2024-24823

    Last Modified: 21 Nov 2024

    Graylog is a free and open log management platform. Starting in version 4.3.0 and prior to versions 5.1.11 and 5.2.4, reauthenticating with an existing session cookie would re-use that session id, even if for different user credentials. In this case, the pre-existing session could be used to gain elevated access to an existing Graylog login session, provided the malicious user could successfully inject their session cookie into someone else's browser. The complexity of such an attack is high, because it requires presenting a spoofed login screen and injection of a session cookie into an existing browser, potentially through a cross-site scripting attack. No such attack has been discovered. Graylog 5.1.11 and 5.2.4, and any versions of the 6.0 development branch, contain patches to not re-use sessions under any circumstances. Some workarounds are available. Using short session expiration and explicit log outs of unused sessions can help limiting the attack vector. Unpatched this vulnerability exists, but is relatively hard to exploit. A proxy could be leveraged to clear the `authentication` cookie for the Graylog server URL for the `/api/system/sessions` endpoint, as that is the only one vulnerable.

    Published: 7 Feb 2024
    6.5
    Medium

    CVE-2024-24822

    Last Modified: 21 Nov 2024

    Pimcore's Admin Classic Bundle provides a backend user interface for Pimcore. Prior to version 1.3.3, an attacker can create, delete etc. tags without having the permission to do so. A fix is available in version 1.3.3. As a workaround, one may apply the patch manually.

    Published: 7 Feb 2024
    9.8
    Critical

    CVE-2024-24563

    Last Modified: 17 Jun 2025

    Vyper is a Pythonic Smart Contract Language for the Ethereum Virtual Machine. Arrays can be keyed by a signed integer, while they are defined for unsigned integers only. The typechecker doesn't throw when spotting the usage of an `int` as an index for an array. The typechecker allows the usage of signed integers to be used as indexes to arrays. The vulnerability is present in different forms in all versions, including `0.3.10`. For ints, the 2's complement representation is used. Because the array was declared very large, the bounds checking will pass Negative values will simply be represented as very large numbers. As of time of publication, a fixed version does not exist. There are three potential vulnerability classes: unpredictable behavior, accessing inaccessible elements and denial of service. Class 1: If it is possible to index an array with a negative integer without reverting, this is most likely not anticipated by the developer and such accesses can cause unpredictable behavior for the contract. Class 2: If a contract has an invariant in the form `assert index < x`, the developer will suppose that no elements on indexes `y | y >= x` are accessible. However, by using negative indexes, this can be bypassed. Class 3: If the index is dependent on the state of the contract, this poses a risk of denial of service. If the state of the contract can be manipulated in such way that the index will be forced to be negative, the array access can always revert (because most likely the array won't be declared extremely large). However, all these the scenarios are highly unlikely. Most likely behavior is a revert on the bounds check.

    Published: 7 Feb 2024
    6.1
    Medium

    CVE-2024-24816

    Last Modified: 21 Nov 2024

    CKEditor4 is an open source what-you-see-is-what-you-get HTML editor. A cross-site scripting vulnerability vulnerability has been discovered in versions prior to 4.24.0-lts in samples that use the `preview` feature. All integrators that use these samples in the production code can be affected. The vulnerability allows an attacker to execute JavaScript code by abusing the misconfigured preview feature. It affects all users using the CKEditor 4 at version < 4.24.0-lts with affected samples used in a production environment. A fix is available in version 4.24.0-lts.

    Published: 7 Feb 2024
    5.4
    Medium

    CVE-2024-24706

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Forum One WP-CFM wp-cfm.This issue affects WP-CFM: from n/a through 1.7.8.

    Published: 7 Feb 2024
    5.3
    Medium

    CVE-2024-23806

    Last Modified: 13 Jun 2025

    Sensitive data can be extracted from HID iCLASS SE reader configuration cards. This could include credential and device administrator keys.

    Published: 7 Feb 2024
    5.9
    Medium

    CVE-2023-47700

    Last Modified: 21 Nov 2024

    IBM SAN Volume Controller, IBM Storwize, IBM FlashSystem and IBM Storage Virtualize 8.6 products could allow a remote attacker to spoof a trusted system that would not be correctly validated by the Storwize server. This could lead to a user connecting to a malicious host, believing that it was a trusted system and deceived into accepting spoofed data. IBM X-Force ID: 271016.

    Published: 7 Feb 2024
    7.5
    High

    CVE-2024-20290

    Last Modified: 13 Feb 2025

    A vulnerability in the OLE2 file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to an incorrect check for end-of-string values during scanning, which may result in a heap buffer over-read. An attacker could exploit this vulnerability by submitting a crafted file containing OLE2 content to be scanned by ClamAV on an affected device. A successful exploit could allow the attacker to cause the ClamAV scanning process to terminate, resulting in a DoS condition on the affected software and consuming available system resources. For a description of this vulnerability, see the ClamAV blog .

    Published: 7 Feb 2024
    8.2
    High

    CVE-2024-20255

    Last Modified: 8 May 2025

    A vulnerability in the SOAP API of Cisco Expressway Series and Cisco TelePresence Video Communication Server could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack on an affected system. This vulnerability is due to insufficient CSRF protections for the web-based management interface of an affected system. An attacker could exploit this vulnerability by persuading a user of the REST API to follow a crafted link. A successful exploit could allow the attacker to cause the affected system to reload.

    Published: 7 Feb 2024
    9.6
    Critical

    CVE-2024-20254

    Last Modified: 21 Nov 2024

    Multiple vulnerabilities in Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow an unauthenticated, remote attacker to conduct cross-site request forgery (CSRF) attacks that perform arbitrary actions on an affected device. Note: "Cisco Expressway Series" refers to Cisco Expressway Control (Expressway-C) devices and Cisco Expressway Edge (Expressway-E) devices. For more information about these vulnerabilities, see the Details ["#details"] section of this advisory.

    Published: 7 Feb 2024
    9.6
    Critical

    CVE-2024-20252

    Last Modified: 21 Nov 2024

    Multiple vulnerabilities in Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow an unauthenticated, remote attacker to conduct cross-site request forgery (CSRF) attacks that perform arbitrary actions on an affected device. Note: "Cisco Expressway Series" refers to Cisco Expressway Control (Expressway-C) devices and Cisco Expressway Edge (Expressway-E) devices. For more information about these vulnerabilities, see the Details ["#details"] section of this advisory.

    Published: 7 Feb 2024
    6.2
    Medium

    CVE-2023-38369

    Last Modified: 3 Nov 2025

    IBM Security Access Manager Container 10.0.0.0 through 10.0.6.1 does not require that docker images should have strong passwords by default, which makes it easier for attackers to compromise user accounts. IBM X-Force ID: 261196.

    Published: 7 Feb 2024
    5.1
    Medium

    CVE-2023-31002

    Last Modified: 3 Nov 2025

    IBM Security Access Manager Container 10.0.0.0 through 10.0.6.1 temporarily stores sensitive information in files that could be accessed by a local user. IBM X-Force ID: 254657.

    Published: 7 Feb 2024
    8.2
    High

    CVE-2023-43017

    Last Modified: 3 Nov 2025

    IBM Security Verify Access 10.0.0.0 through 10.0.6.1 could allow a privileged user to install a configuration file that could allow remote access. IBM X-Force ID: 266155.

    Published: 7 Feb 2024