CVE Feed

    Dashboard / CVE

    6.5
    Medium

    CVE-2024-24838

    Last Modified: 28 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Five Star Plugins Five Star Restaurant Reviews allows Stored XSS.This issue affects Five Star Restaurant Reviews: from n/a through 2.3.5.

    Published: 5 Feb 2024
    6.5
    Medium

    CVE-2024-24839

    Last Modified: 28 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Gordon Böhme, Antonio Leutsch Structured Content (JSON-LD) #wpsc allows Stored XSS.This issue affects Structured Content (JSON-LD) #wpsc: from n/a through 1.6.1.

    Published: 5 Feb 2024
    5.9
    Medium

    CVE-2024-24841

    Last Modified: 28 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Dan's Art Add Customer for WooCommerce allows Stored XSS.This issue affects Add Customer for WooCommerce: from n/a through 1.7.

    Published: 5 Feb 2024
    7.1
    High

    CVE-2024-24846

    Last Modified: 28 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in MightyThemes Mighty Addons for Elementor allows Reflected XSS.This issue affects Mighty Addons for Elementor: from n/a through 1.9.3.

    Published: 5 Feb 2024
    7.1
    High

    CVE-2024-24847

    Last Modified: 28 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in jgadbois CalculatorPro Calculators allows Reflected XSS.This issue affects CalculatorPro Calculators: from n/a through 1.1.7.

    Published: 5 Feb 2024
    7.1
    High

    CVE-2024-24848

    Last Modified: 28 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in MJS Software PT Sign Ups – Beautiful volunteer sign ups and management made easy allows Stored XSS.This issue affects PT Sign Ups – Beautiful volunteer sign ups and management made easy: from n/a through 1.0.4.

    Published: 5 Feb 2024
    6.5
    Medium

    CVE-2024-24865

    Last Modified: 28 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Noah Kagan Scroll Triggered Box allows Stored XSS.This issue affects Scroll Triggered Box: from n/a through 2.3.

    Published: 5 Feb 2024
    7.1
    High

    CVE-2024-24866

    Last Modified: 28 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Biteship Biteship: Plugin Ongkos Kirim Kurir Instant, Reguler, Kargo allows Reflected XSS.This issue affects Biteship: Plugin Ongkos Kirim Kurir Instant, Reguler, Kargo: from n/a through 2.2.24.

    Published: 5 Feb 2024
    7.5
    High

    CVE-2024-20004

    Last Modified: 21 Nov 2024

    In Modem NL1, there is a possible system crash due to an improper input validation. This could lead to remote denial of service, if NW sent invalid NR RRC Connection Setup message, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01191612; Issue ID: MOLY01195812 (MSV-985).

    Published: 5 Feb 2024
    6.7
    Medium

    CVE-2024-20002

    Last Modified: 17 Jun 2025

    In TVAPI, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: DTV03961715; Issue ID: DTV03961715.

    Published: 5 Feb 2024
    6.7
    Medium

    CVE-2024-20001

    Last Modified: 15 May 2025

    In TVAPI, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: DTV03961601; Issue ID: DTV03961601.

    Published: 5 Feb 2024
    4.4
    Medium

    CVE-2024-20016

    Last Modified: 21 Nov 2024

    In ged, there is a possible out of bounds write due to an integer overflow. This could lead to local denial of service with System execution privileges needed. User interaction is not needed for exploitation Patch ID: ALPS07835901; Issue ID: ALPS07835901.

    Published: 5 Feb 2024
    7.8
    High

    CVE-2024-20015

    Last Modified: 16 Dec 2025

    In telephony, there is a possible escalation of privilege due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08441419; Issue ID: ALPS08441419.

    Published: 5 Feb 2024
    6.7
    Medium

    CVE-2024-20013

    Last Modified: 20 Jun 2025

    In keyInstall, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08471742; Issue ID: ALPS08308608.

    Published: 5 Feb 2024
    6.7
    Medium

    CVE-2024-20012

    Last Modified: 9 May 2025

    In keyInstall, there is a possible escalation of privilege due to type confusion. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08358566; Issue ID: ALPS08358566.

    Published: 5 Feb 2024
    7.5
    High

    CVE-2024-20003

    Last Modified: 21 Nov 2024

    In Modem NL1, there is a possible system crash due to an improper input validation. This could lead to remote denial of service, if NW sent invalid NR RRC Connection Setup message, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01191612; Issue ID: MOLY01191612 (MSV-981).

    Published: 5 Feb 2024
    9.8
    Critical

    CVE-2024-20011

    Last Modified: 20 Jun 2025

    In alac decoder, there is a possible information disclosure due to an incorrect bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08441146; Issue ID: ALPS08441146.

    Published: 5 Feb 2024
    6.7
    Medium

    CVE-2024-20010

    Last Modified: 17 Apr 2025

    In keyInstall, there is a possible escalation of privilege due to type confusion. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08358560; Issue ID: ALPS08358560.

    Published: 5 Feb 2024
    8.8
    High

    CVE-2024-20009

    Last Modified: 20 Jun 2025

    In alac decoder, there is a possible out of bounds write due to an incorrect error handling. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS08441150; Issue ID: ALPS08441150.

    Published: 5 Feb 2024
    7.5
    High

    CVE-2024-20007

    Last Modified: 15 May 2025

    In mp3 decoder, there is a possible out of bounds write due to a race condition. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS08441369; Issue ID: ALPS08441369.

    Published: 5 Feb 2024
    6.7
    Medium

    CVE-2024-20006

    Last Modified: 16 Dec 2025

    In da, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08477148; Issue ID: ALPS08477148.

    Published: 5 Feb 2024
    6.5
    Medium

    CVE-2024-24870

    Last Modified: 28 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Michael Dempfle Advanced iFrame allows Stored XSS.This issue affects Advanced iFrame: from n/a through 2023.10.

    Published: 5 Feb 2024
    6.5
    Medium

    CVE-2023-51504

    Last Modified: 28 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Dan Dulaney Dan's Embedder for Google Calendar allows Stored XSS.This issue affects Dan's Embedder for Google Calendar: from n/a through 1.2.

    Published: 5 Feb 2024
    5.4
    Medium

    CVE-2023-5800

    Last Modified: 17 Jun 2025

    Vintage, member of the AXIS OS Bug Bounty Program, has found that the VAPIX API create_overlay.cgi did not have a sufficient input validation allowing for a possible remote code execution. This flaw can only be exploited after authenticating with an operator- or administrator-privileged service account. Axis has released patched AXIS OS versions for the highlighted flaw. Please refer to the Axis security advisory for more information and solution.

    Published: 5 Feb 2024
    6.3
    Medium

    CVE-2023-5677

    Last Modified: 17 Jun 2025

    Brandon Rothel from QED Secure Solutions and Sam Hanson of Dragos have found that the VAPIX API tcptest.cgi did not have a sufficient input validation allowing for a possible remote code execution. This flaw can only be exploited after authenticating with an operator- or administrator-privileged service account. The impact of exploiting this vulnerability is lower with operator-privileges compared to administrator-privileges service accounts. Please refer to the Axis security advisory for more information and solution.

    Published: 5 Feb 2024
    —
    Unknown

    CVE-2024-21856

    Last Modified: 17 Jun 2025

    This candidate was in a CNA pool that was not assigned to any issues during 2024.

    Published: 5 Feb 2024
    8
    High

    CVE-2024-1485

    Last Modified: 24 Mar 2026

    A flaw was found in the decompression function of registry-support. This issue can be triggered if an unauthenticated remote attacker tricks a user into parsing a devfile which uses the `parent` or `plugin` keywords. This could download a malicious archive and cause the cleanup process to overwrite or delete files outside of the archive, which should not be allowed.

    Published: 5 Feb 2024
    4.6
    Medium

    CVE-2024-24857

    Last Modified: 12 May 2026

    A race condition was found in the Linux kernel's net/bluetooth device driver in conn_info_{min,max}_age_set() function. This can result in integrity overflow issue, possibly leading to bluetooth connection abnormality or denial of service.

    Published: 5 Feb 2024
    5
    Medium

    CVE-2024-24855

    Last Modified: 12 May 2026

    A race condition was found in the Linux kernel's scsi device driver in lpfc_unregister_fcf_rescan() function. This can result in a null pointer dereference issue, possibly leading to a kernel panic or denial of service issue.

    Published: 5 Feb 2024
    9.8
    Critical

    CVE-2023-51951

    Last Modified: 6 Feb 2026

    SQL Injection vulnerability in Stock Management System 1.0 allows a remote attacker to execute arbitrary code via the id parameter in the manage_bo.php file.

    Published: 5 Feb 2024
    7.5
    High

    CVE-2024-24259

    Last Modified: 4 Nov 2025

    freeglut through 3.4.0 was discovered to contain a memory leak via the menuEntry variable in the glutAddMenuEntry function.

    Published: 5 Feb 2024
    4.1
    Medium

    CVE-2023-34042

    Last Modified: 3 Jun 2025

    The spring-security.xsd file inside the spring-security-config jar is world writable which means that if it were extracted it could be written by anyone with access to the file system. While there are no known exploits, this is an example of “CWE-732: Incorrect Permission Assignment for Critical Resource” and could result in an exploit. Users should update to the latest version of Spring Security to mitigate any future exploits found around this issue.

    Published: 5 Feb 2024
    7.5
    High

    CVE-2023-47355

    Last Modified: 20 Jun 2025

    The com.eypcnnapps.quickreboot (aka Eyuep Can Yilmaz {ROOT] Quick Reboot) application 1.0.8 for Android has exposed broadcast receivers for PowerOff, Reboot, and Recovery (e.g., com.eypcnnapps.quickreboot.widget.PowerOff) that are susceptible to unauthorized broadcasts because of missing input validation.

    Published: 5 Feb 2024
    7.5
    High

    CVE-2024-24267

    Last Modified: 26 Sept 2025

    gpac v2.2.1 (fixed in v2.4.0) was discovered to contain a memory leak via the gfio_blob variable in the gf_fileio_from_blob function.

    Published: 5 Feb 2024
    5.3
    Medium

    CVE-2023-7216

    Last Modified: 25 Feb 2026

    A path traversal vulnerability was found in the CPIO utility. This issue could allow a remote unauthenticated attacker to trick a user into opening a specially crafted archive. During the extraction process, the archiver could follow symlinks outside of the intended directory, which allows files to be written in arbitrary directories through symlinks.

    Published: 5 Feb 2024
    8.8
    High

    CVE-2024-22567

    Last Modified: 17 Jun 2025

    File Upload vulnerability in MCMS 5.3.5 allows attackers to upload arbitrary files via crafted POST request to /ms/file/upload.do.

    Published: 5 Feb 2024
    9.8
    Critical

    CVE-2024-23049

    Last Modified: 17 Jun 2025

    An issue in symphony v.3.6.3 and before allows a remote attacker to execute arbitrary code via the log4j component.

    Published: 5 Feb 2024
    9.8
    Critical

    CVE-2024-23054

    Last Modified: 5 Jul 2026

    An issue in Plone Docker Official Image 5.2.13 (5221) open-source software that could allow for remote code execution due to a package listed in ++plone++static/components not existing in the public package index (npm).

    Published: 5 Feb 2024
    5.3
    Medium

    CVE-2024-23196

    Last Modified: 21 Nov 2024

    A race condition was found in the Linux kernel's sound/hda device driver in snd_hdac_regmap_sync() function. This can result in a null pointer dereference issue, possibly leading to a kernel panic or denial of service issue.

    Published: 5 Feb 2024
    7.5
    High

    CVE-2024-24260

    Last Modified: 21 Nov 2024

    media-server v1.0.0 was discovered to contain a Use-After-Free (UAF) vulnerability via the sip_subscribe_remove function at /uac/sip-uac-subscribe.c.

    Published: 5 Feb 2024
    7.5
    High

    CVE-2024-24262

    Last Modified: 6 Jun 2025

    media-server v1.0.0 was discovered to contain a Use-After-Free (UAF) vulnerability via the sip_uac_stop_timer function at /uac/sip-uac-transaction.c.

    Published: 5 Feb 2024
    7.5
    High

    CVE-2024-24263

    Last Modified: 12 Jun 2025

    Lotos WebServer v0.1.1 was discovered to contain a Use-After-Free (UAF) vulnerability via the response_append_status_line function at /lotos/src/response.c.

    Published: 5 Feb 2024
    7.5
    High

    CVE-2024-24265

    Last Modified: 9 May 2025

    gpac v2.2.1 was discovered to contain a memory leak via the dst_props variable in the gf_filter_pid_merge_properties_internal function.

    Published: 5 Feb 2024
    7.5
    High

    CVE-2024-24266

    Last Modified: 5 Jun 2025

    gpac v2.2.1 was discovered to contain a Use-After-Free (UAF) vulnerability via the dasher_configure_pid function at /src/filters/dasher.c.

    Published: 5 Feb 2024
    6.1
    Medium

    CVE-2024-24396

    Last Modified: 21 Nov 2024

    Cross Site Scripting vulnerability in Stimulsoft GmbH Stimulsoft Dashboard.JS before v.2024.1.2 allows a remote attacker to execute arbitrary code via a crafted payload to the search bar component.

    Published: 5 Feb 2024
    5.4
    Medium

    CVE-2024-24397

    Last Modified: 15 May 2025

    Cross Site Scripting vulnerability in Stimulsoft GmbH Stimulsoft Dashboard.JS before v.2024.1.2 allows a remote attacker to execute arbitrary code via a crafted payload to the ReportName field.

    Published: 5 Feb 2024
    8.8
    High

    CVE-2024-24468

    Last Modified: 15 May 2025

    Cross Site Request Forgery vulnerability in flusity-CMS v.2.33 allows a remote attacker to execute arbitrary code via the add_customblock.php.

    Published: 5 Feb 2024
    8.8
    High

    CVE-2024-24469

    Last Modified: 21 Nov 2024

    Cross Site Request Forgery vulnerability in flusity-CMS v.2.33 allows a remote attacker to execute arbitrary code via the delete_post .php.

    Published: 5 Feb 2024
    9.8
    Critical

    CVE-2024-24543

    Last Modified: 15 May 2025

    Buffer Overflow vulnerability in the function setSchedWifi in Tenda AC9 v.3.0, firmware version v.15.03.06.42_multi allows a remote attacker to cause a denial of service or run arbitrary code via crafted overflow data.

    Published: 5 Feb 2024
    4.6
    Medium

    CVE-2024-24858

    Last Modified: 12 May 2026

    A race condition was found in the Linux kernel's net/bluetooth in {conn,adv}_{min,max}_interval_set() function. This can result in I2cap connection or broadcast abnormality issue, possibly leading to denial of service.

    Published: 5 Feb 2024