CVE Feed

    Dashboard / CVE

    7.2
    High

    CVE-2024-24140

    Last Modified: 29 May 2025

    Sourcecodester Daily Habit Tracker App 1.0 allows SQL Injection via the parameter 'tracker.'

    Published: 29 Jan 2024
    7.2
    High

    CVE-2024-24139

    Last Modified: 21 Nov 2024

    Sourcecodester Login System with Email Verification 1.0 allows SQL Injection via the 'user' parameter.

    Published: 29 Jan 2024
    7.5
    High

    CVE-2023-51842

    Last Modified: 2 Jun 2025

    An algorithm-downgrade issue was discovered in Ylianst MeshCentral 1.1.16.

    Published: 29 Jan 2024
    9.1
    Critical

    CVE-2023-51839

    Last Modified: 20 Jun 2025

    DeviceFarmer stf v3.6.6 suffers from Use of a Broken or Risky Cryptographic Algorithm.

    Published: 29 Jan 2024
    9.8
    Critical

    CVE-2023-51840

    Last Modified: 29 May 2025

    DoraCMS 2.1.8 is vulnerable to Use of Hard-coded Cryptographic Key.

    Published: 29 Jan 2024
    5.4
    Medium

    CVE-2024-22559

    Last Modified: 29 May 2025

    LightCMS v2.0 is vulnerable to Cross Site Scripting (XSS) in the Content Management - Articles field.

    Published: 29 Jan 2024
    5.4
    Medium

    CVE-2024-22570

    Last Modified: 20 Jun 2025

    A stored cross-site scripting (XSS) vulnerability in /install.php?m=install&c=index&a=step3 of GreenCMS v2.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.

    Published: 29 Jan 2024
    7.5
    High

    CVE-2024-23747

    Last Modified: 20 Jun 2025

    The Moderna Sistemas ModernaNet Hospital Management System 2024 is susceptible to an Insecure Direct Object Reference (IDOR) vulnerability. This vulnerability resides in the system's handling of user data access through a /Modernanet/LAUDO/LAU0000100/Laudo?id= URI. By manipulating this id parameter, an attacker can gain access to sensitive medical information.

    Published: 29 Jan 2024
    6.1
    Medium

    CVE-2024-24136

    Last Modified: 20 Jun 2025

    The 'Your Name' field in the Submit Score section of Sourcecodester Math Game with Leaderboard v1.0 is vulnerable to Cross-Site Scripting (XSS) attacks.

    Published: 29 Jan 2024
    4.8
    Medium

    CVE-2024-24134

    Last Modified: 29 May 2025

    Sourcecodester Online Food Menu 1.0 is vulnerable to Cross Site Scripting (XSS) via the 'Menu Name' and 'Description' fields in the Update Menu section.

    Published: 29 Jan 2024
    6.1
    Medium

    CVE-2024-24135

    Last Modified: 5 Jun 2025

    Product Name and Product Code in the 'Add Product' section of Sourcecodester Product Inventory with Export to Excel 1.0 are vulnerable to XSS attacks.

    Published: 29 Jan 2024
    7.5
    High

    CVE-2024-24736

    Last Modified: 20 Jun 2025

    The POP3 service in YahooPOPs (aka YPOPs!) 1.6 allows a remote denial of service (reboot) via a long string to TCP port 110, a related issue to CVE-2004-1558.

    Published: 29 Jan 2024
    6.5
    Medium

    CVE-2024-1102

    Last Modified: 11 Nov 2025

    A vulnerability was found in jberet-core logging. An exception in 'dbProperties' might display user credentials such as the username and password for the database-connection.

    Published: 29 Jan 2024
    7.5
    High

    CVE-2024-12705

    Last Modified: 15 Apr 2026

    Clients using DNS-over-HTTPS (DoH) can exhaust a DNS resolver's CPU and/or memory by flooding it with crafted valid or invalid HTTP/2 traffic. This issue affects BIND 9 versions 9.18.0 through 9.18.32, 9.20.0 through 9.20.4, 9.21.0 through 9.21.3, and 9.18.11-S1 through 9.18.32-S1.

    Published: 29 Jan 2024
    5.4
    Medium

    CVE-2024-23782

    Last Modified: 2 Jun 2025

    Cross-site scripting vulnerability exists in a-blog cms Ver.3.1.x series versions prior to Ver.3.1.7, Ver.3.0.x series versions prior to Ver.3.0.29, Ver.2.11.x series versions prior to Ver.2.11.58, Ver.2.10.x series versions prior to Ver.2.10.50, and Ver.2.9.0 and earlier versions. If this vulnerability is exploited, a user with a contributor or higher privilege may execute an arbitrary script on the web browser of the user who accessed the website using the product.

    Published: 28 Jan 2024
    7.2
    High

    CVE-2024-0996

    Last Modified: 17 Jun 2025

    A vulnerability classified as critical has been found in Tenda i9 1.0.0.9(4122). This affects the function formSetCfm of the file /goform/setcfm of the component httpd. The manipulation of the argument funcpara1 leads to stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-252261 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 28 Jan 2024
    7.2
    High

    CVE-2024-0995

    Last Modified: 2 Jun 2025

    A vulnerability was found in Tenda W6 1.0.0.9(4122). It has been rated as critical. Affected by this issue is the function formwrlSSIDset of the file /goform/wifiSSIDset of the component httpd. The manipulation of the argument index leads to stack-based buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-252260. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 28 Jan 2024
    7.2
    High

    CVE-2024-0994

    Last Modified: 21 Nov 2024

    A vulnerability was found in Tenda W6 1.0.0.9(4122). It has been declared as critical. Affected by this vulnerability is the function formSetCfm of the file /goform/setcfm of the component httpd. The manipulation of the argument funcpara1 leads to stack-based buffer overflow. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-252259. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 28 Jan 2024
    7.2
    High

    CVE-2024-0993

    Last Modified: 29 May 2025

    A vulnerability was found in Tenda i6 1.0.0.9(3857). It has been classified as critical. Affected is the function formWifiMacFilterGet of the file /goform/WifiMacFilterGet of the component httpd. The manipulation of the argument index leads to stack-based buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-252258 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 28 Jan 2024
    7.2
    High

    CVE-2024-0992

    Last Modified: 16 Jun 2025

    A vulnerability was found in Tenda i6 1.0.0.9(3857) and classified as critical. This issue affects the function formwrlSSIDset of the file /goform/wifiSSIDset of the component httpd. The manipulation of the argument index leads to stack-based buffer overflow. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-252257 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 28 Jan 2024
    7.2
    High

    CVE-2024-0991

    Last Modified: 21 Nov 2024

    A vulnerability has been found in Tenda i6 1.0.0.9(3857) and classified as critical. This vulnerability affects the function formSetCfm of the file /goform/setcfm of the component httpd. The manipulation of the argument funcpara1 leads to stack-based buffer overflow. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-252256. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 28 Jan 2024
    7.2
    High

    CVE-2024-0990

    Last Modified: 21 Nov 2024

    A vulnerability, which was classified as critical, was found in Tenda i6 1.0.0.9(3857). This affects the function formSetAutoPing of the file /goform/setAutoPing of the component httpd. The manipulation of the argument ping1 leads to stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-252255. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 28 Jan 2024
    5.4
    Medium

    CVE-2024-0989

    Last Modified: 29 May 2025

    A vulnerability, which was classified as problematic, has been found in Sichuan Yougou Technology KuERP up to 1.0.4. Affected by this issue is the function del_sn_db of the file /application/index/controller/Service.php. The manipulation of the argument file leads to path traversal: '../filedir'. The exploit has been disclosed to the public and may be used. VDB-252254 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 28 Jan 2024
    6.3
    Medium

    CVE-2024-0988

    Last Modified: 21 Nov 2024

    A vulnerability classified as critical was found in Sichuan Yougou Technology KuERP up to 1.0.4. Affected by this vulnerability is the function checklogin of the file /application/index/common.php. The manipulation of the argument App_User_id/App_user_Token leads to improper authentication. The exploit has been disclosed to the public and may be used. The identifier VDB-252253 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 28 Jan 2024
    6.3
    Medium

    CVE-2024-0987

    Last Modified: 21 Nov 2024

    A vulnerability classified as critical has been found in Sichuan Yougou Technology KuERP up to 1.0.4. Affected is an unknown function of the file /runtime/log. The manipulation leads to improper output neutralization for logs. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-252252. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 28 Jan 2024
    4.7
    Medium

    CVE-2024-0986

    Last Modified: 29 May 2025

    A vulnerability was found in Issabel PBX 4.0.0. It has been rated as critical. This issue affects some unknown processing of the file /index.php?menu=asterisk_cli of the component Asterisk-Cli. The manipulation of the argument Command leads to os command injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-252251. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 28 Jan 2024
    9.8
    Critical

    CVE-2024-23739

    Last Modified: 29 May 2025

    An issue in Discord for macOS version 0.0.291 and before, allows remote attackers to execute arbitrary code via the RunAsNode and enableNodeClilnspectArguments settings.

    Published: 28 Jan 2024
    9.8
    Critical

    CVE-2024-23738

    Last Modified: 21 Nov 2024

    An issue in Postman version 10.22 and before on macOS allows a remote attacker to execute arbitrary code via the RunAsNode and enableNodeClilnspectArguments settings. NOTE: the vendor states "we dispute the report's accuracy ... the configuration does not enable remote code execution.."

    Published: 28 Jan 2024
    9.8
    Critical

    CVE-2024-23740

    Last Modified: 16 Jun 2025

    An issue in Kap for macOS version 3.6.0 and before, allows remote attackers to execute arbitrary code via the RunAsNode and enableNodeClilnspectArguments settings.

    Published: 28 Jan 2024
    9.8
    Critical

    CVE-2024-23741

    Last Modified: 3 Jun 2025

    An issue in Hyper on macOS version 3.4.1 and before, allows remote attackers to execute arbitrary code via the RunAsNode and enableNodeClilnspectArguments settings.

    Published: 28 Jan 2024
    9.8
    Critical

    CVE-2024-23742

    Last Modified: 21 Nov 2024

    An issue in Loom on macOS version 0.196.1 and before, allows remote attackers to execute arbitrary code via the RunAsNode and enableNodeClilnspectArguments settings. NOTE: the vendor disputes this because it requires local access to a victim's machine.

    Published: 28 Jan 2024
    3.3
    Low

    CVE-2024-23743

    Last Modified: 21 Nov 2024

    Notion through 3.1.0 on macOS might allow code execution because of RunAsNode and enableNodeClilnspectArguments. NOTE: the vendor states "the attacker must launch the Notion Desktop application with nonstandard flags that turn the Electron-based application into a Node.js execution environment."

    Published: 28 Jan 2024
    7.1
    High

    CVE-2025-24528

    Last Modified: 15 Apr 2026

    In MIT Kerberos 5 (aka krb5) before 1.22 (with incremental propagation), there is an integer overflow for a large update size to resize() in kdb_log.c. An authenticated attacker can cause an out-of-bounds write and kadmind daemon crash.

    Published: 28 Jan 2024
    6.3
    Medium

    CVE-2024-0962

    Last Modified: 17 Jun 2025

    A vulnerability was found in obgm libcoap 4.3.4. It has been rated as critical. Affected by this issue is the function get_split_entry of the file src/coap_oscore.c of the component Configuration File Handler. The manipulation leads to stack-based buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue. VDB-252206 is the identifier assigned to this vulnerability.

    Published: 27 Jan 2024
    5
    Medium

    CVE-2024-0960

    Last Modified: 2 Jun 2025

    A vulnerability was found in flink-extended ai-flow 0.3.1. It has been declared as critical. Affected by this vulnerability is the function cloudpickle.loads of the file \ai_flow\cli\commands\workflow_command.py. The manipulation leads to deserialization. The attack can be launched remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used. The identifier VDB-252205 was assigned to this vulnerability.

    Published: 27 Jan 2024
    5
    Medium

    CVE-2024-0959

    Last Modified: 21 Nov 2024

    A vulnerability was found in StanfordVL GibsonEnv 0.3.1. It has been classified as critical. Affected is the function cloudpickle.load of the file gibson\utils\pposgd_fuse.py. The manipulation leads to deserialization. It is possible to launch the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-252204.

    Published: 27 Jan 2024
    4.4
    Medium

    CVE-2024-0618

    Last Modified: 8 Apr 2026

    The Contact Form Plugin – Fastest Contact Form Builder Plugin for WordPress by Fluent Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via imported form titles in all versions up to, and including, 5.1.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.

    Published: 27 Jan 2024
    6.4
    Medium

    CVE-2024-0824

    Last Modified: 8 Apr 2026

    The Exclusive Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Link Anything functionality in all versions up to, and including, 2.6.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 27 Jan 2024
    6.5
    Medium

    CVE-2024-0697

    Last Modified: 8 Apr 2026

    The Backuply – Backup, Restore, Migrate and Clone plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.2.3 via the node_id parameter in the backuply_get_jstree function. This makes it possible for attackers with administrator privileges or higher to read the contents of arbitrary files on the server, which can contain sensitive information.

    Published: 27 Jan 2024
    5.4
    Medium

    CVE-2024-0667

    Last Modified: 8 Apr 2026

    The Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.15.21. This is due to missing or incorrect nonce validation on the 'execute' function. This makes it possible for unauthenticated attackers to execute arbitrary methods in the 'BoosterController' class via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

    Published: 27 Jan 2024
    4.4
    Medium

    CVE-2023-6497

    Last Modified: 8 Apr 2026

    The WordPress Simple Shopping Cart plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the automatic redirect URL setting in all versions up to and including 4.7.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.

    Published: 27 Jan 2024
    4.4
    Medium

    CVE-2024-0664

    Last Modified: 8 Apr 2026

    The Meks Smart Social Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Meks Smart Social Widget in all versions up to, and including, 1.6.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.

    Published: 27 Jan 2024
    3.5
    Low

    CVE-2024-0958

    Last Modified: 21 Nov 2024

    A vulnerability was found in CodeAstro Stock Management System 1.0 and classified as problematic. This issue affects some unknown processing of the file /index.php of the component Add Category Handler. The manipulation of the argument Category Name/Category Description leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-252203.

    Published: 27 Jan 2024
    5.2
    Medium

    CVE-2023-6482

    Last Modified: 21 Nov 2024

    Use of encryption key derived from static information in Synaptics Fingerprint Driver allows an attacker to set up a TLS session with the fingerprint sensor and send restricted commands to the fingerprint sensor. This may allow an attacker, who has physical access to the sensor, to enroll a fingerprint into the template database.

    Published: 27 Jan 2024
    5.4
    Medium

    CVE-2023-48201

    Last Modified: 29 May 2025

    Cross Site Scripting (XSS) vulnerability in Sunlight CMS v.8.0.1, allows remote authenticated attackers to execute arbitrary code and escalate privileges via a crafted script to the Content text editor component.

    Published: 27 Jan 2024
    5.4
    Medium

    CVE-2023-48202

    Last Modified: 29 May 2025

    Cross-Site Scripting (XSS) vulnerability in Sunlight CMS 8.0.1 allows an authenticated low-privileged user to escalate privileges via a crafted SVG file in the File Manager component.

    Published: 27 Jan 2024
    9.8
    Critical

    CVE-2023-52389

    Last Modified: 29 May 2025

    UTF32Encoding.cpp in POCO has a Poco::UTF32Encoding integer overflow and resultant stack buffer overflow because Poco::UTF32Encoding::convert() and Poco::UTF32::queryConvert() may return a negative integer if a UTF-32 byte sequence evaluates to a value of 0x80000000 or higher. This is fixed in 1.11.8p2, 1.12.5p2, and 1.13.0.

    Published: 27 Jan 2024
    9.8
    Critical

    CVE-2024-22860

    Last Modified: 11 Aug 2025

    Integer overflow vulnerability in FFmpeg before n6.1, allows remote attackers to execute arbitrary code via the jpegxl_anim_read_packet component in the JPEG XL Animation decoder.

    Published: 27 Jan 2024
    7.5
    High

    CVE-2024-22861

    Last Modified: 11 Aug 2025

    Integer overflow vulnerability in FFmpeg before n6.1, allows attackers to cause a denial of service (DoS) via the avcodec/osq module.

    Published: 27 Jan 2024
    9.8
    Critical

    CVE-2024-22862

    Last Modified: 11 Aug 2025

    Integer overflow vulnerability in FFmpeg before n6.1, allows remote attackers to execute arbitrary code via the JJPEG XL Parser.

    Published: 27 Jan 2024