CVE Feed

    Dashboard / CVE

    2.4
    Low

    CVE-2024-1265

    Last Modified: 21 Nov 2024

    A vulnerability classified as problematic has been found in CodeAstro University Management System 1.0. Affected is an unknown function of the file /att_add.php of the component Attendance Management. The manipulation of the argument Student Name leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-253008.

    Published: 6 Feb 2024
    4.3
    Medium

    CVE-2024-22241

    Last Modified: 3 Jun 2025

    Aria Operations for Networks contains a cross site scripting vulnerability. A malicious actor with admin privileges can inject a malicious payload into the login banner and takeover the user account.  

    Published: 6 Feb 2024
    4.9
    Medium

    CVE-2024-22240

    Last Modified: 15 May 2025

    Aria Operations for Networks contains a local file read vulnerability. A malicious actor with admin privileges may exploit this vulnerability leading to unauthorized access to sensitive information.

    Published: 6 Feb 2024
    6.5
    Medium

    CVE-2024-0971

    Last Modified: 21 Nov 2024

    A SQL injection vulnerability exists where an authenticated, low-privileged remote attacker could potentially alter scan DB content.

    Published: 6 Feb 2024
    5.3
    Medium

    CVE-2024-22239

    Last Modified: 15 May 2025

    Aria Operations for Networks contains a local privilege escalation vulnerability. A console user with access to Aria Operations for Networks may exploit this vulnerability to escalate privileges to gain regular shell access.

    Published: 6 Feb 2024
    6.4
    Medium

    CVE-2024-22238

    Last Modified: 3 Jun 2025

    Aria Operations for Networks contains a cross site scripting vulnerability. A malicious actor with admin privileges may be able to inject malicious code into user profile configurations due to improper input sanitization.

    Published: 6 Feb 2024
    7.8
    High

    CVE-2024-22237

    Last Modified: 15 May 2025

    Aria Operations for Networks contains a local privilege escalation vulnerability. A console user with access to Aria Operations for Networks may exploit this vulnerability to escalate privileges to gain root access to the system.

    Published: 6 Feb 2024
    4.8
    Medium

    CVE-2024-0955

    Last Modified: 21 Nov 2024

    A stored XSS vulnerability exists where an authenticated, remote attacker with administrator privileges on the Nessus application could alter Nessus proxy settings, which could lead to the execution of remote arbitrary scripts.

    Published: 6 Feb 2024
    6.3
    Medium

    CVE-2024-1264

    Last Modified: 21 Nov 2024

    A vulnerability has been found in Juanpao JPShop up to 1.5.02 and classified as critical. Affected by this vulnerability is the function actionUpdate of the file /api/controllers/common/UploadsController.php. The manipulation of the argument imgage leads to unrestricted upload. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-253003.

    Published: 6 Feb 2024
    9.8
    Critical

    CVE-2024-1283

    Last Modified: 17 Jun 2025

    Heap buffer overflow in Skia in Google Chrome prior to 121.0.6167.160 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

    Published: 6 Feb 2024
    9.8
    Critical

    CVE-2024-1284

    Last Modified: 15 May 2025

    Use after free in Mojo in Google Chrome prior to 121.0.6167.160 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

    Published: 6 Feb 2024
    6.3
    Medium

    CVE-2024-1263

    Last Modified: 21 Nov 2024

    A vulnerability, which was classified as critical, was found in Juanpao JPShop up to 1.5.02. Affected is the function actionUpdate of the file /api/controllers/merchant/shop/PosterController.php of the component API. The manipulation of the argument pic_url leads to unrestricted upload. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-253002 is the identifier assigned to this vulnerability.

    Published: 6 Feb 2024
    6.3
    Medium

    CVE-2024-1262

    Last Modified: 21 Nov 2024

    A vulnerability, which was classified as critical, has been found in Juanpao JPShop up to 1.5.02. This issue affects the function actionUpdate of the file /api/controllers/merchant/design/MaterialController.php of the component API. The manipulation of the argument pic_url leads to unrestricted upload. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-253001 was assigned to this vulnerability.

    Published: 6 Feb 2024
    6.3
    Medium

    CVE-2024-1261

    Last Modified: 8 May 2025

    A vulnerability classified as critical was found in Juanpao JPShop up to 1.5.02. This vulnerability affects the function actionIndex of the file /api/controllers/merchant/app/ComboController.php of the component API. The manipulation of the argument pic_url leads to unrestricted upload. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-253000.

    Published: 6 Feb 2024
    6.3
    Medium

    CVE-2024-1260

    Last Modified: 7 May 2025

    A vulnerability classified as critical has been found in Juanpao JPShop up to 1.5.02. This affects the function actionIndex of the file /api/controllers/admin/app/ComboController.php of the component API. The manipulation of the argument pic_url leads to unrestricted upload. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-252999.

    Published: 6 Feb 2024
    8.8
    High

    CVE-2023-40545

    Last Modified: 21 Nov 2024

    Authentication bypass when an OAuth2 Client is using client_secret_jwt as its authentication method on affected 11.3 versions via specially crafted requests.

    Published: 6 Feb 2024
    6.3
    Medium

    CVE-2024-1259

    Last Modified: 18 Dec 2024

    A vulnerability was found in Juanpao JPShop up to 1.5.02. It has been rated as critical. Affected by this issue is some unknown functionality of the file /api/controllers/admin/app/AppController.php of the component API. The manipulation of the argument app_pic_url leads to unrestricted upload. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-252998 is the identifier assigned to this vulnerability.

    Published: 6 Feb 2024
    3.1
    Low

    CVE-2024-1258

    Last Modified: 21 Nov 2024

    A vulnerability was found in Juanpao JPShop up to 1.5.02. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file api/config/params.php of the component API. The manipulation of the argument JWT_KEY_ADMIN leads to use of hard-coded cryptographic key . The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used. The identifier VDB-252997 was assigned to this vulnerability.

    Published: 6 Feb 2024
    7.2
    High

    CVE-2023-43482

    Last Modified: 4 Nov 2025

    A command execution vulnerability exists in the guest resource functionality of Tp-Link ER7206 Omada Gigabit VPN Router 1.3.0 build 20230322 Rel.70591. A specially crafted HTTP request can lead to arbitrary command execution. An attacker can make an authenticated HTTP request to trigger this vulnerability.

    Published: 6 Feb 2024
    7.2
    High

    CVE-2023-36498

    Last Modified: 4 Nov 2025

    A post-authentication command injection vulnerability exists in the PPTP client functionality of Tp-Link ER7206 Omada Gigabit VPN Router 1.3.0 build 20230322 Rel.70591. A specially crafted HTTP request can lead to arbitrary command injection. An attacker can make an authenticated HTTP request to trigger this vulnerability and gain access to an unrestricted shell.

    Published: 6 Feb 2024
    7.2
    High

    CVE-2023-47209

    Last Modified: 4 Nov 2025

    A post authentication command injection vulnerability exists in the ipsec policy functionality of Tp-Link ER7206 Omada Gigabit VPN Router 1.3.0 build 20230322 Rel.70591. A specially crafted HTTP request can lead to arbitrary command injection. An attacker can make an authenticated HTTP request to trigger this vulnerability.

    Published: 6 Feb 2024
    7.2
    High

    CVE-2023-47167

    Last Modified: 4 Nov 2025

    A post authentication command injection vulnerability exists in the GRE policy functionality of Tp-Link ER7206 Omada Gigabit VPN Router 1.3.0 build 20230322 Rel.70591. A specially crafted HTTP request can lead to arbitrary command injection. An attacker can make an authenticated HTTP request to trigger this vulnerability.

    Published: 6 Feb 2024
    7.2
    High

    CVE-2023-42664

    Last Modified: 4 Nov 2025

    A post authentication command injection vulnerability exists when setting up the PPTP global configuration of Tp-Link ER7206 Omada Gigabit VPN Router 1.3.0 build 20230322 Rel.70591. A specially crafted HTTP request can lead to arbitrary command injection. An attacker can make an authenticated HTTP request to trigger this vulnerability.

    Published: 6 Feb 2024
    7.2
    High

    CVE-2023-46683

    Last Modified: 4 Nov 2025

    A post authentication command injection vulnerability exists when configuring the wireguard VPN functionality of Tp-Link ER7206 Omada Gigabit VPN Router 1.3.0 build 20230322 Rel.70591. A specially crafted HTTP request can lead to arbitrary command injection . An attacker can make an authenticated HTTP request to trigger this vulnerability.

    Published: 6 Feb 2024
    7.2
    High

    CVE-2023-47617

    Last Modified: 4 Nov 2025

    A post authentication command injection vulnerability exists when configuring the web group member of Tp-Link ER7206 Omada Gigabit VPN Router 1.3.0 build 20230322 Rel.70591. A specially crafted HTTP request can lead to arbitrary command injection. An attacker can make an authenticated HTTP request to trigger this vulnerability.

    Published: 6 Feb 2024
    7.2
    High

    CVE-2023-47618

    Last Modified: 4 Nov 2025

    A post authentication command execution vulnerability exists in the web filtering functionality of Tp-Link ER7206 Omada Gigabit VPN Router 1.3.0 build 20230322 Rel.70591. A specially crafted HTTP request can lead to arbitrary command execution. An attacker can make an authenticated HTTP request to trigger this vulnerability.

    Published: 6 Feb 2024
    6.2
    Medium

    CVE-2024-22331

    Last Modified: 21 Nov 2024

    IBM UrbanCode Deploy (UCD) 7.0 through 7.0.5.19, 7.1 through 7.1.2.15, 7.2 through 7.2.3.8, 7.3 through 7.3.2.3, and IBM UrbanCode Deploy (UCD) - IBM DevOps Deploy 8.0.0.0 could disclose sensitive user information when installing the Windows agent. IBM X-Force ID: 279971.

    Published: 6 Feb 2024
    5.3
    Medium

    CVE-2023-46183

    Last Modified: 21 Nov 2024

    IBM PowerVM Hypervisor FW950.00 through FW950.90, FW1020.00 through FW1020.40, and FW1030.00 through FW1030.30 could allow a system administrator to obtain sensitive partition information. IBM X-Force ID: 269695.

    Published: 6 Feb 2024
    8
    High

    CVE-2023-35188

    Last Modified: 15 May 2025

    SQL Injection Remote Code Execution Vulnerability was found using a create statement in the SolarWinds Platform. This vulnerability requires user authentication to be exploited.

    Published: 6 Feb 2024
    3.5
    Low

    CVE-2024-1257

    Last Modified: 17 Jun 2025

    A vulnerability was found in Jspxcms 10.2.0. It has been classified as problematic. Affected is an unknown function of the file /ext/collect/find_text.do. The manipulation leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-252996.

    Published: 6 Feb 2024
    8
    High

    CVE-2023-50395

    Last Modified: 13 Jun 2025

    SQL Injection Remote Code Execution Vulnerability was found using an update statement in the SolarWinds Platform. This vulnerability requires user authentication to be exploited

    Published: 6 Feb 2024
    5.3
    Medium

    CVE-2024-23344

    Last Modified: 9 May 2025

    Tuleap is an Open Source Suite to improve management of software developments and collaboration. Some users might get access to restricted information when a process validates the permissions of multiple users (e.g. mail notifications). This issue has been patched in version 15.4.99.140 of Tuleap Community Edition.

    Published: 6 Feb 2024
    3.5
    Low

    CVE-2024-1256

    Last Modified: 21 Nov 2024

    A vulnerability was found in Jspxcms 10.2.0 and classified as problematic. This issue affects some unknown processing of the file /ext/collect/filter_text.do. The manipulation leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-252995.

    Published: 6 Feb 2024
    5.3
    Medium

    CVE-2024-1255

    Last Modified: 21 Nov 2024

    A vulnerability has been found in sepidz SepidzDigitalMenu up to 7.1.0728.1 and classified as problematic. This vulnerability affects unknown code of the file /Waiters. The manipulation leads to information disclosure. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-252994 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 6 Feb 2024
    9.9
    Critical

    CVE-2024-24594

    Last Modified: 21 Nov 2024

    A cross-site scripting (XSS) vulnerability in all versions of the web server component of Allegro AI’s ClearML platform allows a remote attacker to execute a JavaScript payload when a user views the Debug Samples tab in the web UI.

    Published: 6 Feb 2024
    9.6
    Critical

    CVE-2024-24593

    Last Modified: 17 Jun 2025

    A cross-site request forgery (CSRF) vulnerability in all versions up to 1.14.1 of the api server component of Allegro AI’s ClearML platform allows a remote attacker to impersonate a user by sending API requests via maliciously crafted html. Exploitation of the vulnerability allows an attacker to compromise confidential workspaces and files, leak sensitive information, and target instances of the ClearML platform within closed off networks.

    Published: 6 Feb 2024
    9.8
    Critical

    CVE-2024-24592

    Last Modified: 21 Nov 2024

    Lack of authentication in all versions of the fileserver component of Allegro AI’s ClearML platform allows a remote attacker to arbitrarily access, create, modify and delete files.

    Published: 6 Feb 2024
    8
    High

    CVE-2024-24591

    Last Modified: 15 May 2025

    A path traversal vulnerability in versions 1.4.0 to 1.14.1 of the client SDK of Allegro AI’s ClearML platform enables a maliciously uploaded dataset to write local or remote files to an arbitrary location on an end user’s system when interacted with.

    Published: 6 Feb 2024
    8
    High

    CVE-2024-24590

    Last Modified: 17 Jun 2025

    Deserialization of untrusted data can occur in versions 0.17.0 to 1.14.2 of the client SDK of Allegro AI’s ClearML platform, enabling a maliciously uploaded artifact to run arbitrary code on an end user’s system when interacted with.

    Published: 6 Feb 2024
    4.7
    Medium

    CVE-2024-1254

    Last Modified: 21 Nov 2024

    A vulnerability, which was classified as critical, was found in Byzoro Smart S20 Management Platform up to 20231120. This affects an unknown part of the file /sysmanage/sysmanageajax.php. The manipulation of the argument id leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-252993 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 6 Feb 2024
    4.7
    Medium

    CVE-2024-1253

    Last Modified: 10 Jun 2025

    A vulnerability, which was classified as critical, has been found in Byzoro Smart S40 Management Platform up to 20240126. Affected by this issue is some unknown functionality of the file /useratte/web.php of the component Import Handler. The manipulation of the argument file_upload leads to unrestricted upload. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-252992. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 6 Feb 2024
    5.5
    Medium

    CVE-2024-1252

    Last Modified: 17 Jun 2025

    A vulnerability classified as critical was found in Tongda OA 2017 up to 11.9. Affected by this vulnerability is an unknown functionality of the file /general/attendance/manage/ask_duty/delete.php. The manipulation of the argument ASK_DUTY_ID leads to sql injection. The exploit has been disclosed to the public and may be used. Upgrading to version 11.10 is able to address this issue. It is recommended to upgrade the affected component. The associated identifier of this vulnerability is VDB-252991.

    Published: 6 Feb 2024
    5.5
    Medium

    CVE-2024-1251

    Last Modified: 1 Aug 2025

    A vulnerability classified as critical has been found in Tongda OA 2017 up to 11.10. Affected is an unknown function of the file /general/email/outbox/delete.php. The manipulation of the argument DELETE_STR leads to sql injection. The exploit has been disclosed to the public and may be used. VDB-252990 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 6 Feb 2024
    8.5
    High

    CVE-2024-23673

    Last Modified: 9 May 2025

    Malicious code execution via path traversal in Apache Software Foundation Apache Sling Servlets Resolver.This issue affects all version of Apache Sling Servlets Resolver before 2.11.0. However, whether a system is vulnerable to this attack depends on the exact configuration of the system. If the system is vulnerable, a user with write access to the repository might be able to trick the Sling Servlet Resolver to load a previously uploaded script.  Users are recommended to upgrade to version 2.11.0, which fixes this issue. It is recommended to upgrade, regardless of whether your system configuration currently allows this attack or not.

    Published: 6 Feb 2024
    5.3
    Medium

    CVE-2024-24943

    Last Modified: 21 Nov 2024

    In JetBrains Toolbox App before 2.2 a DoS attack was possible via a malicious SVG image

    Published: 6 Feb 2024
    9.8
    Critical

    CVE-2024-23917

    Last Modified: 21 Nov 2024

    In JetBrains TeamCity before 2023.11.3 authentication bypass leading to RCE was possible

    Published: 6 Feb 2024
    5.3
    Medium

    CVE-2024-24942

    Last Modified: 21 Nov 2024

    In JetBrains TeamCity before 2023.11.3 path traversal allowed reading data within JAR archives

    Published: 6 Feb 2024
    6.1
    Medium

    CVE-2024-24941

    Last Modified: 21 Nov 2024

    In JetBrains IntelliJ IDEA before 2023.3.3 a plugin for JetBrains Space was able to send an authentication token to an inappropriate URL

    Published: 6 Feb 2024
    2.8
    Low

    CVE-2024-24940

    Last Modified: 15 May 2025

    In JetBrains IntelliJ IDEA before 2023.3.3 path traversal was possible when unpacking archives

    Published: 6 Feb 2024
    3.3
    Low

    CVE-2024-24939

    Last Modified: 21 Nov 2024

    In JetBrains Rider before 2023.3.3 logging of environment variables containing secret values was possible

    Published: 6 Feb 2024