CVE Feed

    Dashboard / CVE

    —
    Unknown

    CVE-2023-45738

    Last Modified: 13 Feb 2025

    This is unused.

    Published: 1 Feb 2024
    —
    Unknown

    CVE-2023-49588

    Last Modified: 13 Feb 2025

    This is unused.

    Published: 1 Feb 2024
    —
    Unknown

    CVE-2023-49870

    Last Modified: 13 Feb 2025

    This is unused.

    Published: 1 Feb 2024
    —
    Unknown

    CVE-2023-49590

    Last Modified: 13 Feb 2025

    This is unused.

    Published: 1 Feb 2024
    —
    Unknown

    CVE-2023-39450

    Last Modified: 13 Feb 2025

    This is unused.

    Published: 1 Feb 2024
    —
    Unknown

    CVE-2023-51755

    Last Modified: 13 Feb 2025

    This is unused.

    Published: 1 Feb 2024
    —
    Unknown

    CVE-2023-50335

    Last Modified: 13 Feb 2025

    This is unused.

    Published: 1 Feb 2024
    —
    Unknown

    CVE-2023-51754

    Last Modified: 13 Feb 2025

    This is unused.

    Published: 1 Feb 2024
    —
    Unknown

    CVE-2023-49710

    Last Modified: 13 Feb 2025

    This is unused.

    Published: 1 Feb 2024
    —
    Unknown

    CVE-2023-49712

    Last Modified: 13 Feb 2025

    This is unused.

    Published: 1 Feb 2024
    —
    Unknown

    CVE-2023-50241

    Last Modified: 13 Feb 2025

    This is unused.

    Published: 1 Feb 2024
    —
    Unknown

    CVE-2023-50337

    Last Modified: 13 Feb 2025

    This is unused.

    Published: 1 Feb 2024
    5.4
    Medium

    CVE-2024-24569

    Last Modified: 17 Jun 2025

    The Pixee Java Code Security Toolkit is a set of security APIs meant to help secure Java code. `ZipSecurity#isBelowCurrentDirectory` is vulnerable to a partial-path traversal bypass. To be vulnerable to the bypass, the application must use toolkit version <=1.1.1, use ZipSecurity as a guard against path traversal, and have an exploit path. Although the control still protects attackers from escaping the application path into higher level directories (e.g., /etc/), it will allow "escaping" into sibling paths. For example, if your running path is /my/app/path you an attacker could navigate into /my/app/path-something-else. This vulnerability is patched in 1.1.2.

    Published: 1 Feb 2024
    3.6
    Low

    CVE-2024-0325

    Last Modified: 21 Nov 2024

    In Helix Sync versions prior to 2024.1, a local command injection was identified. Reported by Bryan Riggins.  

    Published: 1 Feb 2024
    4.4
    Medium

    CVE-2024-1040

    Last Modified: 7 Aug 2025

    Gessler GmbH WEB-MASTER user account is stored using a weak hashing algorithm. The attacker can restore the passwords by breaking the hashes stored on the device.

    Published: 1 Feb 2024
    9.8
    Critical

    CVE-2024-1039

    Last Modified: 7 Aug 2025

    Gessler GmbH WEB-MASTER has a restoration account that uses weak hard coded credentials and if exploited could allow an attacker control over the web management of the device.

    Published: 1 Feb 2024
    8.2
    High

    CVE-2024-24570

    Last Modified: 17 Jun 2025

    Statamic is a Laravel and Git powered CMS. HTML files crafted to look like jpg files are able to be uploaded, allowing for XSS. This affects the front-end forms with asset fields without any mime type validation, asset fields in the control panel, and asset browser in the control panel. Additionally, if the XSS is crafted in a specific way, the "copy password reset link" feature may be exploited to gain access to a user's password reset token and gain access to their account. The authorized user is required to execute the XSS in order for the vulnerability to occur. In versions 4.46.0 and 3.4.17, the XSS vulnerability has been patched, and the copy password reset link functionality has been disabled.

    Published: 1 Feb 2024
    9.8
    Critical

    CVE-2024-24561

    Last Modified: 17 Jun 2025

    Vyper is a pythonic Smart Contract Language for the ethereum virtual machine. In versions 0.3.10 and earlier, the bounds check for slices does not account for the ability for start + length to overflow when the values aren't literals. If a slice() function uses a non-literal argument for the start or length variable, this creates the ability for an attacker to overflow the bounds check. This issue can be used to do OOB access to storage, memory or calldata addresses. It can also be used to corrupt the length slot of the respective array.

    Published: 1 Feb 2024
    9.4
    Critical

    CVE-2024-23832

    Last Modified: 13 Feb 2025

    Mastodon is a free, open-source social network server based on ActivityPub Mastodon allows configuration of LDAP for authentication. Due to insufficient origin validation in all Mastodon, attackers can impersonate and take over any remote account. Every Mastodon version prior to 3.5.17 is vulnerable, as well as 4.0.x versions prior to 4.0.13, 4.1.x version prior to 4.1.13, and 4.2.x versions prior to 4.2.5.

    Published: 1 Feb 2024
    3.7
    Low

    CVE-2024-24754

    Last Modified: 15 May 2025

    Bref enable serverless PHP on AWS Lambda. When Bref is used with the Event-Driven Function runtime and the handler is a `RequestHandlerInterface`, then the Lambda event is converted to a PSR7 object. During the conversion process, if the request is a MultiPart, each part is parsed and its content added in the `$files` or `$parsedBody` arrays. The conversion process produces a different output compared to the one of plain PHP when keys ending with and open square bracket ([) are used. Based on the application logic the difference in the body parsing might lead to vulnerabilities and/or undefined behaviors. This vulnerability is patched in 2.1.13.

    Published: 1 Feb 2024
    6.5
    Medium

    CVE-2024-24752

    Last Modified: 21 Nov 2024

    Bref enable serverless PHP on AWS Lambda. When Bref is used with the Event-Driven Function runtime and the handler is a `RequestHandlerInterface`, then the Lambda event is converted to a PSR7 object. During the conversion process, if the request is a MultiPart, each part is parsed and for each which contains a file, it is extracted and saved in `/tmp` with a random filename starting with `bref_upload_`. The flow mimics what plain PHP does but it does not delete the temporary files when the request has been processed. An attacker could fill the Lambda instance disk by performing multiple MultiPart requests containing files. This vulnerability is patched in 2.1.13.

    Published: 1 Feb 2024
    4.8
    Medium

    CVE-2024-24753

    Last Modified: 17 Jun 2025

    Bref enable serverless PHP on AWS Lambda. When Bref is used in combination with an API Gateway with the v2 format, it does not handle multiple values headers. If PHP generates a response with two headers having the same key but different values only the latest one is kept. If an application relies on multiple headers with the same key being set for security reasons, then Bref would lower the application security. For example, if an application sets multiple `Content-Security-Policy` headers, then Bref would just reflect the latest one. This vulnerability is patched in 2.1.13.

    Published: 1 Feb 2024
    8.8
    High

    CVE-2024-22433

    Last Modified: 21 Nov 2024

    Dell Data Protection Search 19.2.0 and above contain an exposed password opportunity in plain text when using LdapSettings.get_ldap_info in DP Search. A remote unauthorized unauthenticated attacker could potentially exploit this vulnerability leading to a loss of Confidentiality, Integrity, Protection, and remote takeover of the system. This is a high-severity vulnerability as it allows an attacker to take complete control of DP Search to affect downstream protected devices.

    Published: 1 Feb 2024
    9.1
    Critical

    CVE-2024-23328

    Last Modified: 8 Jan 2025

    Dataease is an open source data visualization analysis tool. A deserialization vulnerability exists in the DataEase datasource, which can be exploited to execute arbitrary code. The location of the vulnerability code is `core/core-backend/src/main/java/io/dataease/datasource/type/Mysql.java.` The blacklist of mysql jdbc attacks can be bypassed and attackers can further exploit it for deserialized execution or reading arbitrary files. This vulnerability is patched in 1.18.15 and 2.3.0.

    Published: 1 Feb 2024
    5.9
    Medium

    CVE-2023-51446

    Last Modified: 21 Nov 2024

    GLPI is a Free Asset and IT Management Software package. When authentication is made against a LDAP, the authentication form can be used to perform LDAP injection. Upgrade to 10.0.12.

    Published: 1 Feb 2024
    6.5
    Medium

    CVE-2024-23645

    Last Modified: 21 Nov 2024

    GLPI is a Free Asset and IT Management Software package. A malicious URL can be used to execute XSS on reports pages. Upgrade to 10.0.12.

    Published: 1 Feb 2024
    5.5
    Medium

    CVE-2024-1167

    Last Modified: 15 May 2025

    When SEW-EURODRIVE MOVITOOLS MotionStudio processes XML information unrestricted file access can occur.

    Published: 1 Feb 2024
    8.8
    High

    CVE-2023-6078

    Last Modified: 9 Jun 2025

    An OS Command Injection vulnerability exists in BIOVIA Materials Studio products from Release BIOVIA 2021 through Release BIOVIA 2023. Upload of a specially crafted perl script can lead to arbitrary command execution.

    Published: 1 Feb 2024
    7.1
    High

    CVE-2023-51509

    Last Modified: 28 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Metagauss RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login allows Reflected XSS.This issue affects RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login: from n/a through 5.2.4.1.

    Published: 1 Feb 2024
    5.5
    Medium

    CVE-2023-51506

    Last Modified: 28 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in realmag777 WPCS – WordPress Currency Switcher Professional allows Stored XSS.This issue affects WPCS – WordPress Currency Switcher Professional: from n/a through 1.2.0.

    Published: 1 Feb 2024
    6.5
    Medium

    CVE-2023-51514

    Last Modified: 28 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Codeboxr Team CBX Bookmark & Favorite allows Stored XSS.This issue affects CBX Bookmark & Favorite: from n/a through 1.7.13.

    Published: 1 Feb 2024
    6.5
    Medium

    CVE-2023-51520

    Last Modified: 28 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPdevelop / Oplugins WP Booking Calendar allows Stored XSS.This issue affects WP Booking Calendar: from n/a before 9.7.4.

    Published: 1 Feb 2024
    5.9
    Medium

    CVE-2023-51695

    Last Modified: 28 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPEverest Everest Forms – Build Contact Forms, Surveys, Polls, Application Forms, and more with Ease! allows Stored XSS.This issue affects Everest Forms – Build Contact Forms, Surveys, Polls, Application Forms, and more with Ease!: from n/a through 2.0.4.1.

    Published: 1 Feb 2024
    6.5
    Medium

    CVE-2023-51694

    Last Modified: 28 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Epiphyt Embed Privacy allows Stored XSS.This issue affects Embed Privacy: from n/a through 1.8.0.

    Published: 1 Feb 2024
    6.5
    Medium

    CVE-2023-51693

    Last Modified: 28 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themify Icons allows Stored XSS.This issue affects Themify Icons: from n/a through 2.0.1.

    Published: 1 Feb 2024
    6.5
    Medium

    CVE-2023-51532

    Last Modified: 28 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Icegram Icegram Engage – WordPress Lead Generation, Popup Builder, CTA, Optins and Email List Building allows Stored XSS.This issue affects Icegram Engage – WordPress Lead Generation, Popup Builder, CTA, Optins and Email List Building: from n/a through 3.1.19.

    Published: 1 Feb 2024
    5.9
    Medium

    CVE-2023-51691

    Last Modified: 28 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in gVectors Team Comments – wpDiscuz allows Stored XSS.This issue affects Comments – wpDiscuz: from n/a through 7.6.12.

    Published: 1 Feb 2024
    6.5
    Medium

    CVE-2023-51690

    Last Modified: 28 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Advanced iFrame allows Stored XSS.This issue affects Advanced iFrame: from n/a through 2023.8.

    Published: 1 Feb 2024
    6.5
    Medium

    CVE-2023-51689

    Last Modified: 28 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in naa986 Easy Video Player allows Stored XSS.This issue affects Easy Video Player: from n/a through 1.2.2.10.

    Published: 1 Feb 2024
    5.9
    Medium

    CVE-2023-51685

    Last Modified: 28 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LJ Apps WP Review Slider allows Stored XSS.This issue affects WP Review Slider: from n/a through 12.7.

    Published: 1 Feb 2024
    6.5
    Medium

    CVE-2023-51684

    Last Modified: 28 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Easy Digital Downloads Easy Digital Downloads – Sell Digital Files (eCommerce Store & Payments Made Easy) allows Stored XSS.This issue affects Easy Digital Downloads – Sell Digital Files (eCommerce Store & Payments Made Easy): from n/a through 3.2.5.

    Published: 1 Feb 2024
    5.9
    Medium

    CVE-2023-51534

    Last Modified: 28 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Brave Brave – Create Popup, Optins, Lead Generation, Survey, Sticky Elements & Interactive Content allows Stored XSS.This issue affects Brave – Create Popup, Optins, Lead Generation, Survey, Sticky Elements & Interactive Content: from n/a through 0.6.2.

    Published: 1 Feb 2024
    6.5
    Medium

    CVE-2023-51677

    Last Modified: 28 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Magazine3 Schema & Structured Data for WP & AMP allows Stored XSS.This issue affects Schema & Structured Data for WP & AMP: from n/a through 1.23.

    Published: 1 Feb 2024
    5.9
    Medium

    CVE-2023-51536

    Last Modified: 28 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CRM Perks CRM Perks Forms – WordPress Form Builder allows Stored XSS.This issue affects CRM Perks Forms – WordPress Form Builder: from n/a through 1.1.2.

    Published: 1 Feb 2024
    6.5
    Medium

    CVE-2023-51674

    Last Modified: 28 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in AAM Advanced Access Manager – Restricted Content, Users & Roles, Enhanced Security and More allows Stored XSS.This issue affects Advanced Access Manager – Restricted Content, Users & Roles, Enhanced Security and More: from n/a through 6.9.18.

    Published: 1 Feb 2024
    6.5
    Medium

    CVE-2023-51669

    Last Modified: 28 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Artios Media Product Code for WooCommerce allows Stored XSS.This issue affects Product Code for WooCommerce: from n/a through 1.4.4.

    Published: 1 Feb 2024
    6.5
    Medium

    CVE-2023-51666

    Last Modified: 28 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PickPlugins Related Post allows Stored XSS.This issue affects Related Post: from n/a through 2.0.53.

    Published: 1 Feb 2024
    5.9
    Medium

    CVE-2023-51548

    Last Modified: 28 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Neil Gee SlickNav Mobile Menu allows Stored XSS.This issue affects SlickNav Mobile Menu: from n/a through 1.9.2.

    Published: 1 Feb 2024
    7.1
    High

    CVE-2023-51540

    Last Modified: 28 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Kunal Nagar Custom 404 Pro allows Stored XSS.This issue affects Custom 404 Pro: from n/a through 3.10.0.

    Published: 1 Feb 2024
    6.5
    Medium

    CVE-2023-52118

    Last Modified: 28 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Event Manager WP User Profile Avatar allows Stored XSS.This issue affects WP User Profile Avatar: from n/a through 1.0.

    Published: 1 Feb 2024