CVE Feed

    Dashboard / CVE

    9.8
    Critical

    CVE-2024-24029

    Last Modified: 12 Jun 2025

    JFinalCMS 5.0.0 is vulnerable to SQL injection via /admin/content/data.

    Published: 2 Feb 2024
    7.5
    High

    CVE-2024-24161

    Last Modified: 12 Jun 2025

    MRCMS 3.0 contains an Arbitrary File Read vulnerability in /admin/file/edit.do as the incoming path parameter is not filtered.

    Published: 2 Feb 2024
    6.1
    Medium

    CVE-2024-24388

    Last Modified: 5 Jun 2025

    Cross-site scripting (XSS) vulnerability in XunRuiCMS versions v4.6.2 and before, allows remote attackers to obtain sensitive information via crafted malicious requests to the background login.

    Published: 2 Feb 2024
    8.8
    High

    CVE-2024-24470

    Last Modified: 20 Jun 2025

    Cross Site Request Forgery vulnerability in flusity-CMS v.2.33 allows a remote attacker to execute arbitrary code via the update_post.php component.

    Published: 2 Feb 2024
    9.8
    Critical

    CVE-2024-24482

    Last Modified: 21 Nov 2024

    Aprktool before 2.9.3 on Windows allows ../ and /.. directory traversal.

    Published: 2 Feb 2024
    8.1
    High

    CVE-2024-25006

    Last Modified: 8 May 2025

    XenForo before 2.2.14 allows Directory Traversal (with write access) by an authenticated user who has permissions to administer styles, and uses a ZIP archive for Styles Import.

    Published: 2 Feb 2024
    8.8
    High

    CVE-2024-22899

    Last Modified: 4 Nov 2025

    Vinchin Backup & Recovery v7.2 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the syncNtpTime function.

    Published: 2 Feb 2024
    8.8
    High

    CVE-2024-22900

    Last Modified: 4 Nov 2025

    Vinchin Backup & Recovery v7.2 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the setNetworkCardInfo function.

    Published: 2 Feb 2024
    9.8
    Critical

    CVE-2024-22902

    Last Modified: 4 Nov 2025

    Vinchin Backup & Recovery v7.2 was discovered to be configured with default root credentials.

    Published: 2 Feb 2024
    8.8
    High

    CVE-2024-22903

    Last Modified: 4 Nov 2025

    Vinchin Backup & Recovery v7.2 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the deleteUpdateAPK function.

    Published: 2 Feb 2024
    5.4
    Medium

    CVE-2023-46344

    Last Modified: 7 May 2025

    A vulnerability in Solar-Log Base 15 Firmware 6.0.1 Build 161, and possibly other Solar-Log Base products, allows an attacker to escalate their privileges by exploiting a stored cross-site scripting (XSS) vulnerability in the switch group function under /#ilang=DE&b=c_smartenergy_swgroups in the web portal. The vulnerability can be exploited to gain the rights of an installer or PM, which can then be used to gain administrative access to the web portal and execute further attacks. NOTE: The vendor states that this vulnerability has been fixed with 3.0.0-60 11.10.2013 for SL 200, 500, 1000 / not existing for SL 250, 300, 1200, 2000, SL 50 Gateway, SL Base.

    Published: 2 Feb 2024
    5.4
    Medium

    CVE-2024-24160

    Last Modified: 9 May 2025

    MRCMS 3.0 contains a Cross-Site Scripting (XSS) vulnerability via /admin/system/saveinfo.do.

    Published: 2 Feb 2024
    9.8
    Critical

    CVE-2024-22108

    Last Modified: 5 Jun 2025

    An issue was discovered in GTB Central Console 15.17.1-30814.NG. The method setTermsHashAction at /opt/webapp/lib/PureApi/CCApi.class.php is vulnerable to an unauthenticated SQL injection via /ccapi.php that an attacker can abuse in order to change the Administrator password to a known value.

    Published: 2 Feb 2024
    9.8
    Critical

    CVE-2024-22533

    Last Modified: 17 Dec 2025

    Before Beetl v3.15.12, the rendering template has a server-side template injection (SSTI) vulnerability. When the incoming template is controllable, it will be filtered by the DefaultNativeSecurityManager blacklist. Because blacklist filtering is not strict, the blacklist can be bypassed, leading to arbitrary code execution.

    Published: 2 Feb 2024
    5.9
    Medium

    CVE-2023-50939

    Last Modified: 21 Nov 2024

    IBM PowerSC 1.3, 2.0, and 2.1 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 275129.

    Published: 1 Feb 2024
    5.3
    Medium

    CVE-2024-21866

    Last Modified: 17 Jun 2025

    In Rapid Software LLC's Rapid SCADA versions prior to Version 5.8.4, the affected product responds back with an error message containing sensitive data if it receives a specific malformed request.

    Published: 1 Feb 2024
    6.2
    Medium

    CVE-2024-21869

    Last Modified: 15 May 2025

    In Rapid Software LLC's Rapid SCADA versions prior to Version 5.8.4, the affected product stores plaintext credentials in various places. This may allow an attacker with local access to see them.

    Published: 1 Feb 2024
    9.8
    Critical

    CVE-2024-21764

    Last Modified: 21 Nov 2024

    In Rapid Software LLC's Rapid SCADA versions prior to Version 5.8.4, the product uses hard-coded credentials, which may allow an attacker to connect to a specific port.

    Published: 1 Feb 2024
    5.4
    Medium

    CVE-2024-21794

    Last Modified: 16 Jun 2025

    In Rapid Software LLC's Rapid SCADA versions prior to Version 5.8.4, an attacker can redirect users to malicious pages through the login page.

    Published: 1 Feb 2024
    7.8
    High

    CVE-2024-22016

    Last Modified: 21 Nov 2024

    In Rapid Software LLC's Rapid SCADA versions prior to Version 5.8.4, an authorized user can write directly to the Scada directory. This may allow privilege escalation.

    Published: 1 Feb 2024
    6.5
    Medium

    CVE-2024-22096

    Last Modified: 9 May 2025

    In Rapid Software LLC's Rapid SCADA versions prior to Version 5.8.4, an attacker can append path traversal characters to the filename when using a specific command, allowing them to read arbitrary files from the system.

    Published: 1 Feb 2024
    8.8
    High

    CVE-2024-21852

    Last Modified: 21 Nov 2024

    In Rapid Software LLC's Rapid SCADA versions prior to Version 5.8.4, an attacker can supply a malicious configuration file by utilizing a Zip Slip vulnerability in the unpacking routine to achieve remote code execution.

    Published: 1 Feb 2024
    7.7
    High

    CVE-2023-36496

    Last Modified: 17 Jun 2025

    Delegated Admin Privilege virtual attribute provider plugin, when enabled, allows an authenticated user to elevate their permissions in the Directory Server.

    Published: 1 Feb 2024
    7.5
    High

    CVE-2024-24756

    Last Modified: 15 May 2025

    Crafatar serves Minecraft avatars based on the skin for use in external applications. Files outside of the `lib/public/` directory can be requested from the server. Instances running behind Cloudflare (including crafatar.com) are not affected. Instances using the Docker container as shown in the README are affected, but only files within the container can be read. By default, all of the files within the container can also be found in this repository and are not confidential. This vulnerability is patched in 2.1.5.

    Published: 1 Feb 2024
    8.1
    High

    CVE-2023-49610

    Last Modified: 21 Nov 2024

    MachineSense FeverWarn Raspberry Pi-based devices lack input sanitization, which could allow an attacker on an adjacent network to send a message running commands or could overflow the stack.

    Published: 1 Feb 2024
    8.8
    High

    CVE-2023-47867

    Last Modified: 21 Nov 2024

    MachineSense FeverWarn devices are configured as Wi-Fi hosts in a way that attackers within range could connect to the device's web services and compromise the device.

    Published: 1 Feb 2024
    7.5
    High

    CVE-2023-49115

    Last Modified: 21 Nov 2024

    MachineSense devices use unauthenticated MQTT messaging to monitor devices and remote viewing of sensor data by users.

    Published: 1 Feb 2024
    10
    Critical

    CVE-2023-49617

    Last Modified: 6 Jun 2025

    The MachineSense application programmable interface (API) is improperly protected and can be accessed without authentication. A remote attacker could retrieve and modify sensitive information without any authentication.

    Published: 1 Feb 2024
    9.1
    Critical

    CVE-2023-46706

    Last Modified: 21 Nov 2024

    Multiple MachineSense devices have credentials unable to be changed by the user or administrator.

    Published: 1 Feb 2024
    7.7
    High

    CVE-2023-6221

    Last Modified: 15 May 2025

    The cloud provider MachineSense uses for integration and deployment for multiple MachineSense devices, such as the programmable logic controller (PLC), PumpSense, PowerAnalyzer, FeverWarn, and others is insufficiently protected against unauthorized access. An attacker with access to the internal procedures could view source code, secret credentials, and more.

    Published: 1 Feb 2024
    4.3
    Medium

    CVE-2024-24755

    Last Modified: 21 Nov 2024

    discourse-group-membership-ip-block is a discourse plugin that adds support for adding users to groups based on their IP address. discourse-group-membership-ip-block was sending all group custom fields to the client, including group custom fields from other plugins which may expect their custom fields to remain secret.

    Published: 1 Feb 2024
    9.8
    Critical

    CVE-2023-4472

    Last Modified: 11 Jun 2025

    Objectplanet Opinio version 7.22 and prior uses a cryptographically weak pseudo-random number generator (PRNG) coupled to a predictable seed, which could lead to an unauthenticated account takeover of any user on the application.

    Published: 1 Feb 2024
    —
    Unknown

    CVE-2023-49611

    Last Modified: 13 Feb 2025

    This is unused.

    Published: 1 Feb 2024
    —
    Unknown

    CVE-2023-49872

    Last Modified: 13 Feb 2025

    This is unused.

    Published: 1 Feb 2024
    —
    Unknown

    CVE-2023-49811

    Last Modified: 13 Feb 2025

    This is unused.

    Published: 1 Feb 2024
    —
    Unknown

    CVE-2023-50293

    Last Modified: 13 Feb 2025

    This is unused.

    Published: 1 Feb 2024
    —
    Unknown

    CVE-2023-45850

    Last Modified: 13 Feb 2025

    This is unused.

    Published: 1 Feb 2024
    —
    Unknown

    CVE-2023-50336

    Last Modified: 13 Feb 2025

    This is unused.

    Published: 1 Feb 2024
    —
    Unknown

    CVE-2023-50329

    Last Modified: 13 Feb 2025

    This is unused.

    Published: 1 Feb 2024
    —
    Unknown

    CVE-2023-50174

    Last Modified: 13 Feb 2025

    This is unused.

    Published: 1 Feb 2024
    —
    Unknown

    CVE-2023-50170

    Last Modified: 13 Feb 2025

    This is unused.

    Published: 1 Feb 2024
    —
    Unknown

    CVE-2023-52392

    Last Modified: 13 Feb 2025

    This is unused.

    Published: 1 Feb 2024
    —
    Unknown

    CVE-2023-52398

    Last Modified: 13 Feb 2025

    This is unused.

    Published: 1 Feb 2024
    —
    Unknown

    CVE-2023-48729

    Last Modified: 13 Feb 2025

    This is unused.

    Published: 1 Feb 2024
    —
    Unknown

    CVE-2023-52396

    Last Modified: 13 Feb 2025

    This is unused.

    Published: 1 Feb 2024
    —
    Unknown

    CVE-2023-49609

    Last Modified: 13 Feb 2025

    This is unused.

    Published: 1 Feb 2024
    —
    Unknown

    CVE-2023-48734

    Last Modified: 13 Feb 2025

    This is unused.

    Published: 1 Feb 2024
    —
    Unknown

    CVE-2023-52399

    Last Modified: 13 Feb 2025

    This is unused.

    Published: 1 Feb 2024
    —
    Unknown

    CVE-2023-52395

    Last Modified: 13 Feb 2025

    This is unused.

    Published: 1 Feb 2024
    —
    Unknown

    CVE-2023-42437

    Last Modified: 13 Feb 2025

    This is unused.

    Published: 1 Feb 2024