CVE Feed

    Dashboard / CVE

    8.2
    High

    CVE-2024-24810

    Last Modified: 21 Nov 2024

    WiX toolset lets developers create installers for Windows Installer, the Windows installation engine. The .be TEMP folder is vulnerable to DLL redirection attacks that allow the attacker to escalate privileges. This impacts any installer built with the WiX installer framework. This issue has been patched in version 4.0.4.

    Published: 7 Feb 2024
    8.8
    High

    CVE-2024-22022

    Last Modified: 3 Jun 2025

    Vulnerability CVE-2024-22022 allows a Veeam Recovery Orchestrator user that has been assigned a low-privileged role to access the NTLM hash of the service account used by the Veeam Orchestrator Server Service.

    Published: 7 Feb 2024
    4.3
    Medium

    CVE-2024-22021

    Last Modified: 2 Mar 2026

    Vulnerability CVE-2024-22021 allows a Veeam Recovery Orchestrator user with a low privileged role (Plan Author) to retrieve plans from a Scope other than the one they are assigned to.

    Published: 7 Feb 2024
    5.4
    Medium

    CVE-2023-40355

    Last Modified: 17 Jun 2025

    Cross Site Scripting (XSS) vulnerability in Axigen versions 10.3.3.0 before 10.3.3.59, 10.4.0 before 10.4.19, and 10.5.0 before 10.5.5, allows authenticated attackers to execute arbitrary code and obtain sensitive information via the logic for switching between the Standard and Ajax versions.

    Published: 7 Feb 2024
    6.1
    Medium

    CVE-2023-1932

    Last Modified: 24 Jun 2025

    A flaw was found in hibernate-validator's 'isValid' method in the org.hibernate.validator.internal.constraintvalidators.hv.SafeHtmlValidator class, which can be bypassed by omitting the tag ending in a less-than character. Browsers may render an invalid html, allowing HTML injection or Cross-Site-Scripting (XSS) attacks.

    Published: 7 Feb 2024
    7.5
    High

    CVE-2024-24304

    Last Modified: 9 Jun 2025

    In the module "Mailjet" (mailjet) from Mailjet for PrestaShop before versions 3.5.1, a guest can download technical information without restriction.

    Published: 7 Feb 2024
    5.5
    Medium

    CVE-2024-24488

    Last Modified: 5 Jun 2025

    An issue in Shenzen Tenda Technology CP3V2.0 V11.10.00.2311090948 allows a local attacker to obtain sensitive information via the password component.

    Published: 7 Feb 2024
    7.3
    High

    CVE-2024-24806

    Last Modified: 17 Jun 2025

    libuv is a multi-platform support library with a focus on asynchronous I/O. The `uv_getaddrinfo` function in `src/unix/getaddrinfo.c` (and its windows counterpart `src/win/getaddrinfo.c`), truncates hostnames to 256 characters before calling `getaddrinfo`. This behavior can be exploited to create addresses like `0x00007f000001`, which are considered valid by `getaddrinfo` and could allow an attacker to craft payloads that resolve to unintended IP addresses, bypassing developer checks. The vulnerability arises due to how the `hostname_ascii` variable (with a length of 256 bytes) is handled in `uv_getaddrinfo` and subsequently in `uv__idna_toascii`. When the hostname exceeds 256 characters, it gets truncated without a terminating null byte. As a result attackers may be able to access internal APIs or for websites (similar to MySpace) that allows users to have `username.example.com` pages. Internal services that crawl or cache these user pages can be exposed to SSRF attacks if a malicious user chooses a long vulnerable username. This issue has been addressed in release version 1.48.0. Users are advised to upgrade. There are no known workarounds for this vulnerability.

    Published: 7 Feb 2024
    9.8
    Critical

    CVE-2023-38995

    Last Modified: 15 May 2025

    An issue in SCHUHFRIED v.8.22.00 allows remote attacker to obtain the database password via crafted curl command.

    Published: 7 Feb 2024
    9.8
    Critical

    CVE-2023-46914

    Last Modified: 21 Nov 2024

    SQL Injection vulnerability in RM bookingcalendar module for PrestaShop versions 2.7.9 and before, allows remote attackers to execute arbitrary code, escalate privileges, and obtain sensitive information via ics_export.php.

    Published: 7 Feb 2024
    9.8
    Critical

    CVE-2024-24188

    Last Modified: 9 Jun 2025

    Jsish v3.5.0 was discovered to contain a heap-buffer-overflow in ./src/jsiUtils.c.

    Published: 7 Feb 2024
    9.8
    Critical

    CVE-2024-24189

    Last Modified: 20 Jun 2025

    Jsish v3.5.0 (commit 42c694c) was discovered to contain a use-after-free via the SplitChar at ./src/jsiUtils.c.

    Published: 7 Feb 2024
    7.3
    High

    CVE-2024-23769

    Last Modified: 15 May 2025

    Improper privilege control for the named pipe in Samsung Magician PC Software 8.0.0 (for Windows) allows a local attacker to read privileged data.

    Published: 7 Feb 2024
    9.8
    Critical

    CVE-2024-24019

    Last Modified: 5 Jun 2025

    A SQL injection vulnerability exists in Novel-Plus v4.3.0-RC1 and prior versions. An attacker can pass in crafted offset, limit, and sort parameters to perform SQL injection via /system/roleDataPerm/list

    Published: 7 Feb 2024
    6.1
    Medium

    CVE-2024-24131

    Last Modified: 5 Jun 2025

    SuperWebMailer v9.31.0.01799 was discovered to contain a reflected cross-site scripting (XSS) vulenrability via the component api.php.

    Published: 7 Feb 2024
    9.8
    Critical

    CVE-2024-24133

    Last Modified: 21 Nov 2024

    Atmail v6.6.0 was discovered to contain a SQL injection vulnerability via the username parameter on the login page.

    Published: 7 Feb 2024
    9.8
    Critical

    CVE-2024-24186

    Last Modified: 8 May 2025

    Jsish v3.5.0 (commit 42c694c) was discovered to contain a stack-overflow via the component IterGetKeysCallback at /jsish/src/jsiValue.c.

    Published: 7 Feb 2024
    9.8
    Critical

    CVE-2024-24303

    Last Modified: 21 Nov 2024

    SQL Injection vulnerability in HiPresta "Gift Wrapping Pro" (hiadvancedgiftwrapping) module for PrestaShop before version 1.4.1, allows remote attackers to escalate privileges and obtain sensitive information via the HiAdvancedGiftWrappingGiftWrappingModuleFrontController::addGiftWrappingCartValue() method.

    Published: 7 Feb 2024
    7.5
    High

    CVE-2024-24311

    Last Modified: 5 Jun 2025

    Path Traversal vulnerability in Linea Grafica "Multilingual and Multistore Sitemap Pro - SEO" (lgsitemaps) module for PrestaShop before version 1.6.6, a guest can download personal information without restriction.

    Published: 7 Feb 2024
    7.5
    High

    CVE-2024-25200

    Last Modified: 20 Jun 2025

    Espruino 2v20 (commit fcc9ba4) was discovered to contain a Stack Overflow via the jspeFactorFunctionCall at src/jsparse.c.

    Published: 7 Feb 2024
    7.5
    High

    CVE-2024-25201

    Last Modified: 17 Jun 2025

    Espruino 2v20 (commit fcc9ba4) was discovered to contain an Out-of-bounds Read via jsvStringIteratorPrintfCallback at src/jsvar.c.

    Published: 7 Feb 2024
    5.5
    Medium

    CVE-2024-1151

    Last Modified: 7 Nov 2025

    A vulnerability was reported in the Open vSwitch sub-component in the Linux Kernel. The flaw occurs when a recursive operation of code push recursively calls into the code block. The OVS module does not validate the stack depth, pushing too many frames and causing a stack overflow. As a result, this can lead to a crash or other related issues.

    Published: 7 Feb 2024
    7.7
    High

    CVE-2024-0793

    Last Modified: 15 Apr 2026

    A flaw was found in kube-controller-manager. This issue occurs when the initial application of a HPA config YAML lacking a .spec.behavior.scaleUp block causes a denial of service due to KCM pods going into restart churn.

    Published: 7 Feb 2024
    6.1
    Medium

    CVE-2024-24130

    Last Modified: 30 Dec 2025

    Mail2World v12 Business Control Center was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the Usr parameter at resellercenter/login.asp.

    Published: 7 Feb 2024
    5.9
    Medium

    CVE-2024-22388

    Last Modified: 7 May 2025

    Certain configuration available in the communication channel for encoders could expose sensitive data when reader configuration cards are programmed. This data could include credential and device administration keys.

    Published: 6 Feb 2024
    2.4
    Low

    CVE-2024-1269

    Last Modified: 10 Jun 2025

    A vulnerability has been found in SourceCodester Product Management System 1.0 and classified as problematic. This vulnerability affects unknown code of the file /supplier.php. The manipulation of the argument supplier_name/supplier_contact leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-253012.

    Published: 6 Feb 2024
    5.4
    Medium

    CVE-2023-40143

    Last Modified: 21 Nov 2024

    An attacker with access to the Westermo Lynx web application that has the vulnerable software could introduce arbitrary JavaScript by injecting a cross-site scripting payload into the "forward.0.domain" parameter.

    Published: 6 Feb 2024
    8
    High

    CVE-2023-45735

    Last Modified: 21 Nov 2024

    A potential attacker with access to the Westermo Lynx device may be able to execute malicious code that could affect the correct functioning of the device.

    Published: 6 Feb 2024
    5.4
    Medium

    CVE-2023-45222

    Last Modified: 21 Nov 2024

    An attacker with access to the web application that has the vulnerable software could introduce arbitrary JavaScript by injecting a cross-site scripting payload into the "autorefresh" parameter.

    Published: 6 Feb 2024
    6.6
    Medium

    CVE-2023-45213

    Last Modified: 15 May 2025

    A potential attacker with access to the Westermo Lynx device would be able to execute malicious code that could affect the correct functioning of the device.

    Published: 6 Feb 2024
    5.4
    Medium

    CVE-2023-42765

    Last Modified: 21 Nov 2024

    An attacker with access to the vulnerable software could introduce arbitrary JavaScript by injecting a cross-site scripting payload into the "username" parameter in the SNMP configuration.

    Published: 6 Feb 2024
    6.3
    Medium

    CVE-2024-1268

    Last Modified: 21 Nov 2024

    A vulnerability, which was classified as critical, was found in CodeAstro Restaurant POS System 1.0. This affects an unknown part of the file update_product.php. The manipulation leads to unrestricted upload. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-253011.

    Published: 6 Feb 2024
    5.7
    Medium

    CVE-2023-40544

    Last Modified: 21 Nov 2024

    An attacker with access to the network where the affected devices are located could maliciously actions to obtain, via a sniffer, sensitive information exchanged via TCP communications.

    Published: 6 Feb 2024
    5.4
    Medium

    CVE-2023-45227

    Last Modified: 21 Nov 2024

    An attacker with access to the web application with vulnerable software could introduce arbitrary JavaScript by injecting a cross-site scripting payload into the "dns.0.server" parameter.

    Published: 6 Feb 2024
    8
    High

    CVE-2023-38579

    Last Modified: 21 Nov 2024

    The cross-site request forgery token in the request may be predictable or easily guessable allowing attackers to craft a malicious request, which could be triggered by a victim unknowingly. In a successful CSRF attack, the attacker could lead the victim user to carry out an action unintentionally.

    Published: 6 Feb 2024
    3.5
    Low

    CVE-2024-1267

    Last Modified: 24 Apr 2025

    A vulnerability, which was classified as problematic, has been found in CodeAstro Restaurant POS System 1.0. Affected by this issue is some unknown functionality of the file create_account.php. The manipulation of the argument Full Name leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-253010 is the identifier assigned to this vulnerability.

    Published: 6 Feb 2024
    2.4
    Low

    CVE-2024-1266

    Last Modified: 21 Nov 2024

    A vulnerability classified as problematic was found in CodeAstro University Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /st_reg.php of the component Student Registration Form. The manipulation of the argument Address leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-253009 was assigned to this vulnerability.

    Published: 6 Feb 2024
    2.4
    Low

    CVE-2024-1265

    Last Modified: 21 Nov 2024

    A vulnerability classified as problematic has been found in CodeAstro University Management System 1.0. Affected is an unknown function of the file /att_add.php of the component Attendance Management. The manipulation of the argument Student Name leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-253008.

    Published: 6 Feb 2024
    4.3
    Medium

    CVE-2024-22241

    Last Modified: 3 Jun 2025

    Aria Operations for Networks contains a cross site scripting vulnerability. A malicious actor with admin privileges can inject a malicious payload into the login banner and takeover the user account.  

    Published: 6 Feb 2024
    4.9
    Medium

    CVE-2024-22240

    Last Modified: 15 May 2025

    Aria Operations for Networks contains a local file read vulnerability. A malicious actor with admin privileges may exploit this vulnerability leading to unauthorized access to sensitive information.

    Published: 6 Feb 2024
    6.5
    Medium

    CVE-2024-0971

    Last Modified: 21 Nov 2024

    A SQL injection vulnerability exists where an authenticated, low-privileged remote attacker could potentially alter scan DB content.

    Published: 6 Feb 2024
    5.3
    Medium

    CVE-2024-22239

    Last Modified: 15 May 2025

    Aria Operations for Networks contains a local privilege escalation vulnerability. A console user with access to Aria Operations for Networks may exploit this vulnerability to escalate privileges to gain regular shell access.

    Published: 6 Feb 2024
    6.4
    Medium

    CVE-2024-22238

    Last Modified: 3 Jun 2025

    Aria Operations for Networks contains a cross site scripting vulnerability. A malicious actor with admin privileges may be able to inject malicious code into user profile configurations due to improper input sanitization.

    Published: 6 Feb 2024
    7.8
    High

    CVE-2024-22237

    Last Modified: 15 May 2025

    Aria Operations for Networks contains a local privilege escalation vulnerability. A console user with access to Aria Operations for Networks may exploit this vulnerability to escalate privileges to gain root access to the system.

    Published: 6 Feb 2024
    4.8
    Medium

    CVE-2024-0955

    Last Modified: 21 Nov 2024

    A stored XSS vulnerability exists where an authenticated, remote attacker with administrator privileges on the Nessus application could alter Nessus proxy settings, which could lead to the execution of remote arbitrary scripts.

    Published: 6 Feb 2024
    6.3
    Medium

    CVE-2024-1264

    Last Modified: 21 Nov 2024

    A vulnerability has been found in Juanpao JPShop up to 1.5.02 and classified as critical. Affected by this vulnerability is the function actionUpdate of the file /api/controllers/common/UploadsController.php. The manipulation of the argument imgage leads to unrestricted upload. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-253003.

    Published: 6 Feb 2024
    9.8
    Critical

    CVE-2024-1283

    Last Modified: 17 Jun 2025

    Heap buffer overflow in Skia in Google Chrome prior to 121.0.6167.160 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

    Published: 6 Feb 2024
    9.8
    Critical

    CVE-2024-1284

    Last Modified: 15 May 2025

    Use after free in Mojo in Google Chrome prior to 121.0.6167.160 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

    Published: 6 Feb 2024
    6.3
    Medium

    CVE-2024-1263

    Last Modified: 21 Nov 2024

    A vulnerability, which was classified as critical, was found in Juanpao JPShop up to 1.5.02. Affected is the function actionUpdate of the file /api/controllers/merchant/shop/PosterController.php of the component API. The manipulation of the argument pic_url leads to unrestricted upload. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-253002 is the identifier assigned to this vulnerability.

    Published: 6 Feb 2024
    6.3
    Medium

    CVE-2024-1262

    Last Modified: 21 Nov 2024

    A vulnerability, which was classified as critical, has been found in Juanpao JPShop up to 1.5.02. This issue affects the function actionUpdate of the file /api/controllers/merchant/design/MaterialController.php of the component API. The manipulation of the argument pic_url leads to unrestricted upload. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-253001 was assigned to this vulnerability.

    Published: 6 Feb 2024