CVE Feed

    Dashboard / CVE

    9.8
    Critical

    CVE-2024-24333

    Last Modified: 12 Jun 2025

    TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the desc parameter in the setWiFiAclRules function.

    Published: 30 Jan 2024
    9.8
    Critical

    CVE-2023-51982

    Last Modified: 29 May 2025

    CrateDB 5.5.1 is contains an authentication bypass vulnerability in the Admin UI component. After configuring password authentication and_ Local_ In the case of an address, identity authentication can be bypassed by setting the X-Real IP request header to a specific value and accessing the Admin UI directly using the default user identity.(https://github.com/crate/crate/issues/15231)

    Published: 30 Jan 2024
    6.1
    Medium

    CVE-2023-37571

    Last Modified: 20 Jun 2025

    Softing TH SCOPE through 3.70 allows XSS.

    Published: 30 Jan 2024
    —
    Unknown

    CVE-2023-51197

    Last Modified: 27 May 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that there was not reasonable evidence to determine the existence of a vulnerability.

    Published: 30 Jan 2024
    —
    Unknown

    CVE-2023-51198

    Last Modified: 27 May 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that there was not reasonable evidence to determine the existence of a vulnerability.

    Published: 30 Jan 2024
    —
    Unknown

    CVE-2023-51202

    Last Modified: 27 May 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that there was not reasonable evidence to determine the existence of a vulnerability.

    Published: 30 Jan 2024
    —
    Unknown

    CVE-2023-51204

    Last Modified: 27 May 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that there was not reasonable evidence to determine the existence of a vulnerability.

    Published: 30 Jan 2024
    8.2
    High

    CVE-2023-51843

    Last Modified: 29 May 2025

    react-dashboard 1.4.0 is vulnerable to Cross Site Scripting (XSS) as httpOnly is not set.

    Published: 30 Jan 2024
    6.5
    Medium

    CVE-2023-51813

    Last Modified: 20 Jun 2025

    Cross Site Request Forgery (CSRF) vulnerability in Free Open-Source Inventory Management System v.1.0 allows a remote attacker to execute arbitrary code via the staff_list parameter in the index.php component.

    Published: 30 Jan 2024
    9.8
    Critical

    CVE-2023-51837

    Last Modified: 29 May 2025

    Ylianst MeshCentral 1.1.16 is vulnerable to Missing SSL Certificate Validation.

    Published: 30 Jan 2024
    8.4
    High

    CVE-2023-6246

    Last Modified: 12 May 2026

    A heap-based buffer overflow was found in the __vsyslog_internal function of the glibc library. This function is called by the syslog and vsyslog functions. This issue occurs when the openlog function was not called, or called with the ident argument set to NULL, and the program name (the basename of argv[0]) is bigger than 1024 bytes, resulting in an application crash or local privilege escalation. This issue affects glibc 2.36 and newer.

    Published: 30 Jan 2024
    7.5
    High

    CVE-2024-22523

    Last Modified: 20 Jun 2025

    Directory Traversal vulnerability in Qiyu iFair version 23.8_ad0 and before, allows remote attackers to obtain sensitive information via uploadimage component.

    Published: 30 Jan 2024
    6.5
    Medium

    CVE-2024-22643

    Last Modified: 30 May 2025

    A Cross-Site Request Forgery (CSRF) vulnerability in SEO Panel version 4.10.0 allows remote attackers to perform unauthorized user password resets.

    Published: 30 Jan 2024
    5.3
    Medium

    CVE-2024-22646

    Last Modified: 4 Jun 2025

    An email address enumeration vulnerability exists in the password reset function of SEO Panel version 4.10.0. This allows an attacker to guess which emails exist on the system.

    Published: 30 Jan 2024
    5.3
    Medium

    CVE-2024-22648

    Last Modified: 20 Jun 2025

    A Blind SSRF vulnerability exists in the "Crawl Meta Data" functionality of SEO Panel version 4.10.0. This makes it possible for remote attackers to scan ports in the local environment.

    Published: 30 Jan 2024
    —
    Unknown

    CVE-2024-22682

    Last Modified: 19 Jul 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

    Published: 30 Jan 2024
    6.8
    Medium

    CVE-2024-22894

    Last Modified: 21 Nov 2024

    An issue fixed in AIT-Deutschland Alpha Innotec Heatpumps V2.88.3 or later, V3.89.0 or later, V4.81.3 or later and Novelan Heatpumps V2.88.3 or later, V3.89.0 or later, V4.81.3 or later, allows remote attackers to execute arbitrary code via the password component in the shadow file.

    Published: 30 Jan 2024
    7.8
    High

    CVE-2024-22938

    Last Modified: 29 May 2025

    Insecure Permissions vulnerability in BossCMS v.1.3.0 allows a local attacker to execute arbitrary code and escalate privileges via the init function in admin.class.php component.

    Published: 30 Jan 2024
    5.5
    Medium

    CVE-2024-23840

    Last Modified: 29 May 2025

    GoReleaser builds Go binaries for several platforms, creates a GitHub release and then pushes a Homebrew formula to a tap repository. `goreleaser release --debug` log shows secret values used in the in the custom publisher. This vulnerability is fixed in 1.24.0.

    Published: 30 Jan 2024
    9.8
    Critical

    CVE-2024-24324

    Last Modified: 20 Jun 2025

    TOTOLINK A8000RU v7.1cu.643_B20200521 was discovered to contain a hardcoded password for root stored in /etc/shadow.

    Published: 30 Jan 2024
    9.8
    Critical

    CVE-2024-24325

    Last Modified: 20 Jun 2025

    TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the enable parameter in the setParentalRules function.

    Published: 30 Jan 2024
    9.8
    Critical

    CVE-2024-24326

    Last Modified: 21 Nov 2024

    TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the arpEnable parameter in the setStaticDhcpRules function.

    Published: 30 Jan 2024
    9.8
    Critical

    CVE-2024-24328

    Last Modified: 21 Nov 2024

    TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the enable parameter in the setMacFilterRules function.

    Published: 30 Jan 2024
    9.8
    Critical

    CVE-2024-24329

    Last Modified: 12 Jun 2025

    TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the enable parameter in the setPortForwardRules function.

    Published: 30 Jan 2024
    9.8
    Critical

    CVE-2024-24330

    Last Modified: 9 Jun 2025

    TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the port or enable parameter in the setRemoteCfg function.

    Published: 30 Jan 2024
    9.8
    Critical

    CVE-2024-24331

    Last Modified: 29 May 2025

    TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the enable parameter in the setWiFiScheduleCfg function.

    Published: 30 Jan 2024
    9.8
    Critical

    CVE-2024-24332

    Last Modified: 30 May 2025

    TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the url parameter in the setUrlFilterRules function.

    Published: 30 Jan 2024
    7.5
    High

    CVE-2023-36260

    Last Modified: 21 Nov 2024

    An issue was discovered in the Feed Me plugin 4.6.1 for Craft CMS. It allows remote attackers to cause a denial of service (DoS) via crafted strings to Feed-Me Name and Feed-Me URL fields, due to saving a feed using an Asset element type with no volume selected. NOTE: this is not a report about code provided by the Craft CMS product; it is only a report about the Feed Me plugin. NOTE: a third-party report states that commit b5d6ede51848349bd91bc95fec288b6793f15e28 has "nothing to do with security."

    Published: 30 Jan 2024
    5.5
    Medium

    CVE-2024-1062

    Last Modified: 25 Feb 2026

    A heap overflow flaw was found in 389-ds-base. This issue leads to a denial of service when writing a value larger than 256 chars in log_entry_attr.

    Published: 30 Jan 2024
    3.5
    Low

    CVE-2024-21803

    Last Modified: 15 Aug 2025

    Use After Free vulnerability in Linux Linux kernel kernel on Linux, x86, ARM (bluetooth modules) allows Local Execution of Code. This vulnerability is associated with program files https://gitee.Com/anolis/cloud-kernel/blob/devel-5.10/net/bluetooth/af_bluetooth.C. This issue affects Linux kernel: from v2.6.12-rc2 before v6.8-rc1.

    Published: 30 Jan 2024
    6.3
    Medium

    CVE-2024-1027

    Last Modified: 30 May 2025

    A vulnerability, which was classified as critical, was found in SourceCodester Facebook News Feed Like 1.0. Affected is an unknown function of the component Post Handler. The manipulation leads to unrestricted upload. It is possible to launch the attack remotely. The identifier of this vulnerability is VDB-252300.

    Published: 29 Jan 2024
    5.9
    Medium

    CVE-2024-23334

    Last Modified: 4 Feb 2026

    aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. When using aiohttp as a web server and configuring static routes, it is necessary to specify the root path for static files. Additionally, the option 'follow_symlinks' can be used to determine whether to follow symbolic links outside the static root directory. When 'follow_symlinks' is set to True, there is no validation to check if reading a file is within the root directory. This can lead to directory traversal vulnerabilities, resulting in unauthorized access to arbitrary files on the system, even when symlinks are not present. Disabling follow_symlinks and using a reverse proxy are encouraged mitigations. Version 3.9.2 fixes this issue.

    Published: 29 Jan 2024
    6.5
    Medium

    CVE-2024-23829

    Last Modified: 3 Nov 2025

    aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. Security-sensitive parts of the Python HTTP parser retained minor differences in allowable character sets, that must trigger error handling to robustly match frame boundaries of proxies in order to protect against injection of additional requests. Additionally, validation could trigger exceptions that were not handled consistently with processing of other malformed input. Being more lenient than internet standards require could, depending on deployment environment, assist in request smuggling. The unhandled exception could cause excessive resource consumption on the application server and/or its logging facilities. This vulnerability exists due to an incomplete fix for CVE-2023-47627. Version 3.9.2 fixes this vulnerability.

    Published: 29 Jan 2024
    3.5
    Low

    CVE-2024-1026

    Last Modified: 9 Jun 2025

    A vulnerability was found in Cogites eReserv 7.7.58 and classified as problematic. This issue affects some unknown processing of the file front/admin/config.php. The manipulation of the argument id with the input %22%3E%3Cscript%3Ealert(%27XSS%27)%3C/script%3E leads to cross site scripting. The attack may be initiated remotely. The identifier VDB-252293 was assigned to this vulnerability.

    Published: 29 Jan 2024
    4.9
    Medium

    CVE-2023-4554

    Last Modified: 29 May 2025

    Improper Restriction of XML External Entity Reference vulnerability in OpenText AppBuilder on Windows, Linux allows Server Side Request Forgery, Probe System Files. AppBuilder's XML processor is vulnerable to XML External Entity Processing (XXE), allowing an authenticated user to upload specially crafted XML files to induce server-side request forgery, disclose files local to the server that processes them. This issue affects AppBuilder: from 21.2 before 23.2.

    Published: 29 Jan 2024
    5.3
    Medium

    CVE-2023-4553

    Last Modified: 21 Nov 2024

    Improper Input Validation vulnerability in OpenText AppBuilder on Windows, Linux allows Probe System Files. AppBuilder configuration files are viewable by unauthenticated users. This issue affects AppBuilder: from 21.2 before 23.2.

    Published: 29 Jan 2024
    5.5
    Medium

    CVE-2023-4552

    Last Modified: 17 Jun 2025

    Improper Input Validation vulnerability in OpenText AppBuilder on Windows, Linux allows Probe System Files. An authenticated AppBuilder user with the ability to create or manage existing databases can leverage them to exploit the AppBuilder server - including access to its local file system. This issue affects AppBuilder: from 21.2 before 23.2.

    Published: 29 Jan 2024
    7.2
    High

    CVE-2023-4551

    Last Modified: 21 Nov 2024

    Improper Input Validation vulnerability in OpenText AppBuilder on Windows, Linux allows OS Command Injection. The AppBuilder's Scheduler functionality that facilitates creation of scheduled tasks is vulnerable to command injection. This allows authenticated users to inject arbitrary operating system commands into the executing process. This issue affects AppBuilder: from 21.2 before 23.2.

    Published: 29 Jan 2024
    7.5
    High

    CVE-2023-4550

    Last Modified: 21 Nov 2024

    Improper Input Validation, Files or Directories Accessible to External Parties vulnerability in OpenText AppBuilder on Windows, Linux allows Probe System Files. An unauthenticated or authenticated user can abuse a page of AppBuilder to read arbitrary files on the server on which it is hosted. This issue affects AppBuilder: from 21.2 before 23.2.

    Published: 29 Jan 2024
    3.5
    Low

    CVE-2024-1024

    Last Modified: 21 Nov 2024

    A vulnerability has been found in SourceCodester Facebook News Feed Like 1.0 and classified as problematic. This vulnerability affects unknown code of the component New Account Handler. The manipulation of the argument First Name/Last Name with the input <script>alert(1)</script> leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-252292.

    Published: 29 Jan 2024
    2.4
    Low

    CVE-2024-1022

    Last Modified: 29 May 2025

    A vulnerability, which was classified as problematic, was found in CodeAstro Simple Student Result Management System 5.6. This affects an unknown part of the file /add_classes.php of the component Add Class Page. The manipulation of the argument Class Name leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-252291.

    Published: 29 Jan 2024
    3.5
    Low

    CVE-2023-22836

    Last Modified: 17 Jun 2025

    In cases where a multi-tenant stack user is operating Foundry’s Linter service, and the user changes a group name from the default value, the renamed value may be visible to the rest of the stack’s tenants.

    Published: 29 Jan 2024
    6.5
    Medium

    CVE-2023-30970

    Last Modified: 29 May 2025

    Gotham Table service and Forward App were found to be vulnerable to a Path traversal issue allowing an authenticated user to read arbitrary files on the file system.

    Published: 29 Jan 2024
    7.8
    High

    CVE-2024-23940

    Last Modified: 29 May 2025

    Trend Micro uiAirSupport, included in the Trend Micro Security 2023 family of consumer products, version 6.0.2092 and below is vulnerable to a DLL hijacking/proxying vulnerability, which if exploited could allow an attacker to impersonate and modify a library to execute code on the system and ultimately escalate privileges on an affected system.

    Published: 29 Jan 2024
    6.3
    Medium

    CVE-2024-1021

    Last Modified: 6 Jun 2025

    A vulnerability, which was classified as critical, has been found in Rebuild up to 3.5.5. Affected by this issue is the function readRawText of the component HTTP Request Handler. The manipulation of the argument url leads to server-side request forgery. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-252290 is the identifier assigned to this vulnerability.

    Published: 29 Jan 2024
    3.5
    Low

    CVE-2024-1020

    Last Modified: 21 Nov 2024

    A vulnerability classified as problematic was found in Rebuild up to 3.5.5. Affected by this vulnerability is the function getStorageFile of the file /filex/proxy-download. The manipulation of the argument url leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-252289 was assigned to this vulnerability.

    Published: 29 Jan 2024
    8.8
    High

    CVE-2024-23828

    Last Modified: 21 Nov 2024

    Nginx-UI is a web interface to manage Nginx configurations. It is vulnerable to an authenticated arbitrary command execution via CRLF attack when changing the value of test_config_cmd or start_cmd. This vulnerability exists due to an incomplete fix for CVE-2024-22197 and CVE-2024-22198. This vulnerability has been patched in version 2.0.0.beta.12.

    Published: 29 Jan 2024
    8.4
    High

    CVE-2023-1705

    Last Modified: 29 May 2025

    Missing Authorization vulnerability in Forcepoint F|One SmartEdge Agent on Windows (bgAutoinstaller service modules) allows Privilege Escalation, Functionality Bypass.This issue affects F|One SmartEdge Agent: before 1.7.0.230330-554.

    Published: 29 Jan 2024
    9.8
    Critical

    CVE-2024-23827

    Last Modified: 21 Nov 2024

    Nginx-UI is a web interface to manage Nginx configurations. The Import Certificate feature allows arbitrary write into the system. The feature does not check if the provided user input is a certification/key and allows to write into arbitrary paths in the system. It's possible to leverage the vulnerability into a remote code execution overwriting the config file app.ini. Version 2.0.0.beta.12 fixed the issue.

    Published: 29 Jan 2024
    5.5
    Medium

    CVE-2024-23441

    Last Modified: 20 Apr 2026

    Vba32 Antivirus v3.36.0 is vulnerable to a Denial of Service vulnerability by triggering the 0x2220A7 IOCTL code of the Vba32m64.sys driver.

    Published: 29 Jan 2024