CVE Feed

    Dashboard / CVE

    4.7
    Medium

    CVE-2024-21863

    Last Modified: 21 Nov 2024

    in OpenHarmony v4.0.0 and prior versions allow a local attacker cause DOS through improper input.

    Published: 2 Feb 2024
    2.9
    Low

    CVE-2024-21851

    Last Modified: 21 Nov 2024

    in OpenHarmony v4.0.0 and prior versions allow a local attacker cause heap overflow through integer overflow.

    Published: 2 Feb 2024
    4.2
    Medium

    CVE-2023-45734

    Last Modified: 21 Nov 2024

    in OpenHarmony v3.2.4 and prior versions allow an adjacent attacker arbitrary code execution through out-of-bounds write.

    Published: 2 Feb 2024
    8.2
    High

    CVE-2024-21860

    Last Modified: 21 Nov 2024

    in OpenHarmony v4.0.0 and prior versions allow an adjacent attacker arbitrary code execution in any apps through use after free.

    Published: 2 Feb 2024
    2.9
    Low

    CVE-2024-21845

    Last Modified: 21 Nov 2024

    in OpenHarmony v4.0.0 and prior versions allow a local attacker cause heap overflow through integer overflow.

    Published: 2 Feb 2024
    2.9
    Low

    CVE-2023-49118

    Last Modified: 21 Nov 2024

    in OpenHarmony v3.2.4 and prior versions allow a local attacker causes information leak through out-of-bounds Read.

    Published: 2 Feb 2024
    2.9
    Low

    CVE-2023-43756

    Last Modified: 21 Nov 2024

    in OpenHarmony v3.2.4 and prior versions allow a local attacker causes information leak through out-of-bounds Read.

    Published: 2 Feb 2024
    4.3
    Medium

    CVE-2024-1162

    Last Modified: 8 Apr 2026

    The Orbit Fox by ThemeIsle plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.10.29. This is due to missing or incorrect nonce validation on the register_reference() function. This makes it possible for unauthenticated attackers to update the connected API keys via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

    Published: 2 Feb 2024
    5.3
    Medium

    CVE-2024-1047

    Last Modified: 8 Apr 2026

    Multiple plugins and/or themes for WordPress with the ThemeIsle SDK are vulnerable to unauthorized modification of data due to a missing capability check on the register_reference() function in various versions. This makes it possible for unauthenticated attackers to update options values that allow ThemeIsle to track promotional activities via utm_source.

    Published: 2 Feb 2024
    7.3
    High

    CVE-2024-0338

    Last Modified: 17 Jun 2025

    A buffer overflow vulnerability has been found in XAMPP affecting version 8.2.4 and earlier. An attacker could execute arbitrary code through a long file debug argument that controls the Structured Exception Handler (SEH).

    Published: 2 Feb 2024
    6.5
    Medium

    CVE-2024-21485

    Last Modified: 15 May 2025

    Versions of the package dash-core-components before 2.13.0; versions of the package dash-core-components before 2.0.0; versions of the package dash before 2.15.0; versions of the package dash-html-components before 2.0.0; versions of the package dash-html-components before 2.0.16 are vulnerable to Cross-site Scripting (XSS) when the href of the a tag is controlled by an adversary. An authenticated attacker who stores a view that exploits this vulnerability could steal the data that's visible to another user who opens that view - not just the data already included on the page, but they could also, in theory, make additional requests and access other data accessible to this user. In some cases, they could also steal the access tokens of that user, which would allow the attacker to act as that user, including viewing other apps and resources hosted on the same server. **Note:** This is only exploitable in Dash apps that include some mechanism to store user input to be reloaded by a different user.

    Published: 2 Feb 2024
    5.9
    Medium

    CVE-2024-0685

    Last Modified: 8 Apr 2026

    The Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress plugin for WordPress is vulnerable to Second Order SQL Injection via the email address value submitted through forms in all versions up to, and including, 3.7.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to inject SQL in their email address that will append additional into the already existing query when an administrator triggers a personal data export.

    Published: 2 Feb 2024
    6.4
    Medium

    CVE-2024-1073

    Last Modified: 8 Apr 2026

    The SlimStat Analytics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'filter_array' parameter in all versions up to, and including, 5.1.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 2 Feb 2024
    4.3
    Medium

    CVE-2023-38020

    Last Modified: 21 Nov 2024

    IBM SOAR QRadar Plugin App 1.0 through 5.0.3 could allow an authenticated user to manipulate output written to log files. IBM X-Force ID: 260576.

    Published: 2 Feb 2024
    8.1
    High

    CVE-2023-38019

    Last Modified: 21 Nov 2024

    IBM SOAR QRadar Plugin App 1.0 through 5.0.3 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system. IBM X-Force ID: 260575.

    Published: 2 Feb 2024
    6.5
    Medium

    CVE-2023-38263

    Last Modified: 21 Nov 2024

    IBM SOAR QRadar Plugin App 1.0 through 5.0.3 could allow an authenticated user to perform unauthorized actions due to improper access controls. IBM X-Force ID: 260577.

    Published: 2 Feb 2024
    4.8
    Medium

    CVE-2022-40744

    Last Modified: 21 Nov 2024

    IBM Aspera Faspex 5.0.6 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 236441.

    Published: 2 Feb 2024
    4.7
    Medium

    CVE-2024-0285

    Last Modified: 7 May 2025

    in OpenHarmony v4.0.0 and prior versions allow a local attacker cause DOS through improper input.

    Published: 2 Feb 2024
    9.8
    Critical

    CVE-2024-22320

    Last Modified: 7 May 2025

    IBM Operational Decision Manager 8.10.3 could allow a remote authenticated attacker to execute arbitrary code on the system, caused by an unsafe deserialization. By sending specially crafted request, an attacker could exploit this vulnerability to execute arbitrary code in the context of SYSTEM. IBM X-Force ID: 279146.

    Published: 2 Feb 2024
    8.1
    High

    CVE-2024-22319

    Last Modified: 21 Nov 2024

    IBM Operational Decision Manager 8.10.3, 8.10.4, 8.10.5.1, 8.11, 8.11.0.1, 8.11.1 and 8.12.0.1 is susceptible to remote code execution attack via JNDI injection when passing an unchecked argument to a certain API. IBM X-Force ID: 279145.

    Published: 2 Feb 2024
    9.3
    Critical

    CVE-2024-1143

    Last Modified: 3 Jun 2025

    Central Dogma versions prior to 0.64.1 is vulnerable to Cross-Site Scripting (XSS), which could allow for the leakage of user sessions and subsequent authentication bypass.

    Published: 2 Feb 2024
    6.5
    Medium

    CVE-2023-32333

    Last Modified: 21 Nov 2024

    IBM Maximo Asset Management 7.6.1.3 could allow a remote attacker to log into the admin panel due to improper access controls. IBM X-Force ID: 255073.

    Published: 2 Feb 2024
    5.9
    Medium

    CVE-2023-50962

    Last Modified: 21 Nov 2024

    IBM PowerSC 1.3, 2.0, and 2.1 MFA does not implement the "HTTP Strict Transport Security" (HSTS) web security policy mechanism. IBM X-Force ID: 276004.

    Published: 2 Feb 2024
    3.7
    Low

    CVE-2023-50328

    Last Modified: 21 Nov 2024

    IBM PowerSC 1.3, 2.0, and 2.1 may allow a remote attacker to view session identifiers passed via URL query strings. IBM X-Force ID: 275110.

    Published: 2 Feb 2024
    6.5
    Medium

    CVE-2023-50938

    Last Modified: 21 Nov 2024

    IBM PowerSC 1.3, 2.0, and 2.1 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click actions and possibly launch further attacks against the victim. IBM X-Force ID: 275128.

    Published: 2 Feb 2024
    6.5
    Medium

    CVE-2023-50935

    Last Modified: 21 Nov 2024

    IBM PowerSC 1.3, 2.0, and 2.1 fails to properly restrict access to a URL or resource, which may allow a remote attacker to obtain unauthorized access to application functionality and/or resources. IBM X-Force ID: 275115.

    Published: 2 Feb 2024
    6.3
    Medium

    CVE-2023-50941

    Last Modified: 21 Nov 2024

    IBM PowerSC 1.3, 2.0, and 2.1 does not provide logout functionality, which could allow an authenticated user to gain access to an unauthorized user using session fixation. IBM X-Force ID: 275131.

    Published: 2 Feb 2024
    5.3
    Medium

    CVE-2023-50934

    Last Modified: 21 Nov 2024

    IBM PowerSC 1.3, 2.0, and 2.1 uses single-factor authentication which can lead to unnecessary risk of compromise when compared with the benefits of a dual-factor authentication scheme. IBM X-Force ID: 275114.

    Published: 2 Feb 2024
    5.3
    Medium

    CVE-2023-50940

    Last Modified: 21 Nov 2024

    IBM PowerSC 1.3, 2.0, and 2.1 uses Cross-Origin Resource Sharing (CORS) which could allow an attacker to carry out privileged actions and retrieve sensitive information as the domain name is not being limited to only trusted domains. IBM X-Force ID: 275130.

    Published: 2 Feb 2024
    6.3
    Medium

    CVE-2023-50936

    Last Modified: 21 Nov 2024

    IBM PowerSC 1.3, 2.0, and 2.1 does not invalidate session after logout which could allow an authenticated user to impersonate another user on the system. IBM X-Force ID: 275116.

    Published: 2 Feb 2024
    5.3
    Medium

    CVE-2023-50327

    Last Modified: 21 Nov 2024

    IBM PowerSC 1.3, 2.0, and 2.1 uses insecure HTTP methods which could allow a remote attacker to perform unauthorized file request modification. IBM X-Force ID: 275109.

    Published: 2 Feb 2024
    5.9
    Medium

    CVE-2023-50937

    Last Modified: 21 Nov 2024

    IBM PowerSC 1.3, 2.0, and 2.1 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 275117.

    Published: 2 Feb 2024
    8.3
    High

    CVE-2024-21399

    Last Modified: 3 May 2025

    Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability

    Published: 2 Feb 2024
    6.1
    Medium

    CVE-2023-50933

    Last Modified: 3 Jun 2025

    IBM PowerSC 1.3, 2.0, and 2.1 is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the victim's Web browser within the security context of the hosting site. IBM X-Force ID: 275113.

    Published: 2 Feb 2024
    7.5
    High

    CVE-2023-50326

    Last Modified: 21 Nov 2024

    IBM PowerSC 1.3, 2.0, and 2.1 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials. IBM X-Force ID: 275107.

    Published: 2 Feb 2024
    7.8
    High

    CVE-2023-48645

    Last Modified: 3 Jun 2025

    An issue was discovered in the Archibus app 4.0.3 for iOS. It uses a local database that is synchronized with a Web central server instance every time the application is opened, or when the refresh button is used. There is a SQL injection in the search work request feature in the Maintenance module of the app. This allows performing queries on the local database.

    Published: 2 Feb 2024
    9.8
    Critical

    CVE-2024-23746

    Last Modified: 4 Jun 2025

    Miro Desktop 0.8.18 on macOS allows local Electron code injection via a complex series of steps that might be usable in some environments (bypass a kTCCServiceSystemPolicyAppBundles requirement via a file copy, an app.app/Contents rename, an asar modification, and a rename back to app.app/Contents).

    Published: 2 Feb 2024
    8.8
    High

    CVE-2024-24524

    Last Modified: 21 Nov 2024

    Cross Site Request Forgery (CSRF) vulnerability in flusity-CMS v.2.33, allows remote attackers to execute arbitrary code via the add_menu.php component.

    Published: 2 Feb 2024
    7.5
    High

    CVE-2023-39611

    Last Modified: 16 Jun 2025

    An issue in Software FX Chart FX 7 version 7.0.4962.20829 allows attackers to enumerate and read files from the local filesystem by sending crafted web requests.

    Published: 2 Feb 2024
    7.8
    High

    CVE-2023-46045

    Last Modified: 4 Nov 2025

    Graphviz 2.36.0 through 9.x before 10.0.1 has an out-of-bounds read via a crafted config6a file. NOTE: exploitability may be uncommon because this file is typically owned by root.

    Published: 2 Feb 2024
    9.8
    Critical

    CVE-2023-48792

    Last Modified: 11 Jun 2025

    Zoho ManageEngine ADAudit Plus through 7250 is vulnerable to SQL Injection in the report export option.

    Published: 2 Feb 2024
    9.8
    Critical

    CVE-2023-48793

    Last Modified: 11 Jun 2025

    Zoho ManageEngine ADAudit Plus through 7250 allows SQL Injection in the aggregate report feature.

    Published: 2 Feb 2024
    9.8
    Critical

    CVE-2023-50488

    Last Modified: 17 Jun 2025

    An issue in Blurams Lumi Security Camera (A31C) v23.0406.435.4120 allows attackers to execute arbitrary code.

    Published: 2 Feb 2024
    5.4
    Medium

    CVE-2023-51072

    Last Modified: 16 Jun 2025

    A stored cross-site scripting (XSS) vulnerability in the NOC component of Nagios XI version up to and including 2024R1 allows low-privileged users to execute malicious HTML or JavaScript code via the audio file upload functionality from the Operation Center section. This allows any authenticated user to execute arbitrary JavaScript code on behalf of other users, including the administrators.

    Published: 2 Feb 2024
    6.8
    Medium

    CVE-2023-51820

    Last Modified: 20 Jun 2025

    An issue in Blurams Lumi Security Camera (A31C) v.2.3.38.12558 allows a physically proximate attackers to execute arbitrary code.

    Published: 2 Feb 2024
    7.5
    High

    CVE-2023-51838

    Last Modified: 16 Jun 2025

    Ylianst MeshCentral 1.1.16 suffers from Use of a Broken or Risky Cryptographic Algorithm.

    Published: 2 Feb 2024
    8.8
    High

    CVE-2024-22779

    Last Modified: 21 Nov 2024

    Directory Traversal vulnerability in Kihron ServerRPExposer v.1.0.2 and before allows a remote attacker to execute arbitrary code via the loadServerPack in ServerResourcePackProviderMixin.java.

    Published: 2 Feb 2024
    7.2
    High

    CVE-2024-22107

    Last Modified: 15 May 2025

    An issue was discovered in GTB Central Console 15.17.1-30814.NG. The method systemSettingsDnsDataAction at /opt/webapp/src/AppBundle/Controller/React/SystemSettingsController.php is vulnerable to command injection via the /old/react/v1/api/system/dns/data endpoint. An authenticated attacker can abuse it to inject an arbitrary command and compromise the platform.

    Published: 2 Feb 2024
    7.5
    High

    CVE-2024-22851

    Last Modified: 5 Jun 2025

    Directory Traversal Vulnerability in LiveConfig before v.2.5.2 allows a remote attacker to obtain sensitive information via a crafted request to the /static/ endpoint.

    Published: 2 Feb 2024
    9.8
    Critical

    CVE-2024-22901

    Last Modified: 4 Nov 2025

    Vinchin Backup & Recovery v7.2 was discovered to use default MYSQL credentials.

    Published: 2 Feb 2024