CVE Feed

    Dashboard / CVE

    6.5
    Medium

    CVE-2023-51669

    Last Modified: 28 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Artios Media Product Code for WooCommerce allows Stored XSS.This issue affects Product Code for WooCommerce: from n/a through 1.4.4.

    Published: 1 Feb 2024
    6.5
    Medium

    CVE-2023-51666

    Last Modified: 28 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PickPlugins Related Post allows Stored XSS.This issue affects Related Post: from n/a through 2.0.53.

    Published: 1 Feb 2024
    5.9
    Medium

    CVE-2023-51548

    Last Modified: 28 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Neil Gee SlickNav Mobile Menu allows Stored XSS.This issue affects SlickNav Mobile Menu: from n/a through 1.9.2.

    Published: 1 Feb 2024
    7.1
    High

    CVE-2023-51540

    Last Modified: 28 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Kunal Nagar Custom 404 Pro allows Stored XSS.This issue affects Custom 404 Pro: from n/a through 3.10.0.

    Published: 1 Feb 2024
    6.5
    Medium

    CVE-2023-52118

    Last Modified: 28 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Event Manager WP User Profile Avatar allows Stored XSS.This issue affects WP User Profile Avatar: from n/a through 1.0.

    Published: 1 Feb 2024
    6.5
    Medium

    CVE-2023-52175

    Last Modified: 28 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Michael Uno (miunosoft) Auto Amazon Links – Amazon Associates Affiliate Plugin allows Stored XSS.This issue affects Auto Amazon Links – Amazon Associates Affiliate Plugin: from n/a through 5.1.1.

    Published: 1 Feb 2024
    6.5
    Medium

    CVE-2023-52188

    Last Modified: 28 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Russell Jamieson Footer Putter allows Stored XSS.This issue affects Footer Putter: from n/a through 1.17.

    Published: 1 Feb 2024
    6.5
    Medium

    CVE-2023-52189

    Last Modified: 28 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jhayghost Ideal Interactive Map allows Stored XSS.This issue affects Ideal Interactive Map: from n/a through 1.2.4.

    Published: 1 Feb 2024
    6.5
    Medium

    CVE-2023-52191

    Last Modified: 28 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Torbjon Infogram – Add charts, maps and infographics allows Stored XSS.This issue affects Infogram – Add charts, maps and infographics: from n/a through 1.6.1.

    Published: 1 Feb 2024
    6.5
    Medium

    CVE-2023-52192

    Last Modified: 28 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Keap Keap Official Opt-in Forms allows Stored XSS.This issue affects Keap Official Opt-in Forms: from n/a through 1.0.11.

    Published: 1 Feb 2024
    5.5
    Medium

    CVE-2024-22430

    Last Modified: 20 Feb 2026

    Dell PowerScale OneFS versions 8.2.x through 9.6.0.x contains an incorrect default permissions vulnerability. A local low privileges malicious user could potentially exploit this vulnerability, leading to denial of service.

    Published: 1 Feb 2024
    6.5
    Medium

    CVE-2023-52193

    Last Modified: 28 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Live Composer Team Page Builder: Live Composer allows Stored XSS.This issue affects Page Builder: Live Composer: from n/a through 1.5.23.

    Published: 1 Feb 2024
    6.6
    Medium

    CVE-2024-22449

    Last Modified: 20 Feb 2026

    Dell PowerScale OneFS versions 9.0.0.x through 9.6.0.x contains a missing authentication for critical function vulnerability. A low privileged local malicious user could potentially exploit this vulnerability to gain elevated access.

    Published: 1 Feb 2024
    6.5
    Medium

    CVE-2023-52194

    Last Modified: 28 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Takayuki Miyauchi oEmbed Gist allows Stored XSS.This issue affects oEmbed Gist: from n/a through 4.9.1.

    Published: 1 Feb 2024
    6.5
    Medium

    CVE-2023-52195

    Last Modified: 28 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Posts to Page Kerry James allows Stored XSS.This issue affects Kerry James: from n/a through 1.7.

    Published: 1 Feb 2024
    7.1
    High

    CVE-2024-21750

    Last Modified: 28 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Scribit Shortcodes Finder allows Reflected XSS.This issue affects Shortcodes Finder: from n/a through 1.5.5.

    Published: 1 Feb 2024
    7.1
    High

    CVE-2024-22148

    Last Modified: 28 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Smart Editor JoomUnited allows Reflected XSS.This issue affects JoomUnited: from n/a through 1.3.3.

    Published: 1 Feb 2024
    4.4
    Medium

    CVE-2024-0935

    Last Modified: 21 Nov 2024

    Insertion of Sensitive Information into Log File vulnerabilities are affecting DELMIA Apriso Release 2019 through Release 2024

    Published: 1 Feb 2024
    6.5
    Medium

    CVE-2024-24548

    Last Modified: 21 Nov 2024

    Payment EX Ver1.1.5b and earlier allows a remote unauthenticated attacker to obtain the information of the user who purchases merchandise using Payment EX.

    Published: 1 Feb 2024
    5.3
    Medium

    CVE-2024-1130

    Last Modified: 8 Apr 2026

    The NEX-Forms – Ultimate Form Builder – Contact forms and much more plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the set_read() function in all versions up to, and including, 8.5.6. This makes it possible for authenticated attackers, with subscriber-level access and above, to mark records as read.

    Published: 1 Feb 2024
    5.3
    Medium

    CVE-2024-1129

    Last Modified: 8 Apr 2026

    The NEX-Forms – Ultimate Form Builder – Contact forms and much more plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the set_starred() function in all versions up to, and including, 8.5.6. This makes it possible for authenticated attackers, with subscriber-level access and above, to mark records as starred.

    Published: 1 Feb 2024
    5.3
    Medium

    CVE-2024-0907

    Last Modified: 8 Apr 2026

    The NEX-Forms – Ultimate Form Builder – Contact forms and much more plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the restore_records() function in all versions up to, and including, 8.5.6. This makes it possible for authenticated attackers, with subscriber-level access and above, to restore records.

    Published: 1 Feb 2024
    5.4
    Medium

    CVE-2024-23941

    Last Modified: 4 Jun 2025

    Cross-site scripting vulnerability exists in Group Office prior to v6.6.182, prior to v6.7.64 and prior to v6.8.31, which may allow a remote authenticated attacker to execute an arbitrary script on the web browser of the user who is logging in to the product.

    Published: 1 Feb 2024
    6.4
    Medium

    CVE-2023-7069

    Last Modified: 8 Apr 2026

    The Advanced iFrame plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'advanced_iframe' shortcode in all versions up to, and including, 2023.10 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CVE-2024-24870 is likely a duplicate of this issue.

    Published: 1 Feb 2024
    6.1
    Medium

    CVE-2024-22927

    Last Modified: 15 May 2025

    Cross Site Scripting (XSS) vulnerability in the func parameter in eyoucms v.1.6.5 allows a remote attacker to run arbitrary code via crafted URL.

    Published: 1 Feb 2024
    6.1
    Medium

    CVE-2024-24041

    Last Modified: 29 May 2025

    A stored cross-site scripting (XSS) vulnerability in Travel Journal Using PHP and MySQL with Source Code v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the location parameter at /travel-journal/write-journal.php.

    Published: 1 Feb 2024
    6.9
    Medium

    CVE-2024-24557

    Last Modified: 15 May 2025

    Moby is an open-source project created by Docker to enable software containerization. The classic builder cache system is prone to cache poisoning if the image is built FROM scratch. Also, changes to some instructions (most important being HEALTHCHECK and ONBUILD) would not cause a cache miss. An attacker with the knowledge of the Dockerfile someone is using could poison their cache by making them pull a specially crafted image that would be considered as a valid cache candidate for some build steps. 23.0+ users are only affected if they explicitly opted out of Buildkit (DOCKER_BUILDKIT=0 environment variable) or are using the /build API endpoint. All users on versions older than 23.0 could be impacted. Image build API endpoint (/build) and ImageBuild function from github.com/docker/docker/client is also affected as it the uses classic builder by default. Patches are included in 24.0.9 and 25.0.2 releases.

    Published: 1 Feb 2024
    5.5
    Medium

    CVE-2023-47256

    Last Modified: 17 Jun 2025

    ConnectWise ScreenConnect through 23.8.4 allows local users to connect to arbitrary relay servers via implicit trust of proxy settings

    Published: 1 Feb 2024
    8.1
    High

    CVE-2023-47257

    Last Modified: 7 May 2025

    ConnectWise ScreenConnect through 23.8.4 allows man-in-the-middle attackers to achieve remote code execution via crafted messages.

    Published: 1 Feb 2024
    6.8
    Medium

    CVE-2023-51835

    Last Modified: 1 Apr 2025

    An issue in TRENDnet TEW-822DRE v.1.03B02 allows a local attacker to execute arbitrary code via the parameters ipv4_ping in the /boafrm/formSystemCheck.

    Published: 1 Feb 2024
    8.8
    High

    CVE-2023-51939

    Last Modified: 16 Jun 2025

    An issue in the cp_bbs_sig function in relic/src/cp/relic_cp_bbs.c of Relic relic-toolkit 0.6.0 allows a remote attacker to obtain sensitive information and escalate privileges via the cp_bbs_sig function.

    Published: 1 Feb 2024
    8.8
    High

    CVE-2024-22859

    Last Modified: 29 May 2025

    Cross-Site Request Forgery (CSRF) vulnerability in livewire before v3.0.4, allows remote attackers to execute arbitrary code getCsrfToken function. NOTE: the vendor disputes this because the 5d88731 commit fixes a usability problem (HTTP 419 status codes for legitimate client activity), not a security problem.

    Published: 1 Feb 2024
    6.1
    Medium

    CVE-2024-22936

    Last Modified: 16 Jan 2025

    Cross-site scripting (XSS) vulnerability in Parents & Student Portal in Genesis School Management Systems in Genesis AIMS Student Information Systems v.3053 allows remote attackers to inject arbitrary web script or HTML via the message parameter.

    Published: 1 Feb 2024
    8.8
    High

    CVE-2024-22939

    Last Modified: 16 Jan 2025

    Cross Site Request Forgery vulnerability in FlyCms v.1.0 allows a remote attacker to execute arbitrary code via the system/article/category_edit component.

    Published: 1 Feb 2024
    6.1
    Medium

    CVE-2024-23031

    Last Modified: 4 Jun 2025

    Cross Site Scripting (XSS) vulnerability in is_water parameter in eyoucms v.1.6.5 allows a remote attacker to run arbitrary code via crafted URL.

    Published: 1 Feb 2024
    6.1
    Medium

    CVE-2024-23032

    Last Modified: 20 Jun 2025

    Cross Site Scripting vulnerability in num parameter in eyoucms v.1.6.5 allows a remote attacker to run arbitrary code via crafted URL.

    Published: 1 Feb 2024
    6.1
    Medium

    CVE-2024-23033

    Last Modified: 29 May 2025

    Cross Site Scripting vulnerability in the path parameter in eyoucms v.1.6.5 allows a remote attacker to run arbitrary code via crafted URL.

    Published: 1 Feb 2024
    6.1
    Medium

    CVE-2024-23034

    Last Modified: 29 May 2025

    Cross Site Scripting vulnerability in the input parameter in eyoucms v.1.6.5 allows a remote attacker to run arbitrary code via crafted URL.

    Published: 1 Feb 2024
    9.8
    Critical

    CVE-2024-23052

    Last Modified: 16 Jan 2025

    An issue in WuKongOpenSource WukongCRM v.72crm_9.0.1_20191202 allows a remote attacker to execute arbitrary code via the parseObject() function in the fastjson component.

    Published: 1 Feb 2024
    5.4
    Medium

    CVE-2024-24059

    Last Modified: 15 May 2025

    springboot-manager v1.6 is vulnerable to Arbitrary File Upload. The system does not filter the suffixes of uploaded files.

    Published: 1 Feb 2024
    5.4
    Medium

    CVE-2024-24060

    Last Modified: 12 Jun 2025

    springboot-manager v1.6 is vulnerable to Cross Site Scripting (XSS) via /sys/user.

    Published: 1 Feb 2024
    5.4
    Medium

    CVE-2024-24061

    Last Modified: 29 May 2025

    springboot-manager v1.6 is vulnerable to Cross Site Scripting (XSS) via /sysContent/add.

    Published: 1 Feb 2024
    5.4
    Medium

    CVE-2024-24062

    Last Modified: 12 Jun 2025

    springboot-manager v1.6 is vulnerable to Cross Site Scripting (XSS) via /sys/role.

    Published: 1 Feb 2024
    9.1
    Critical

    CVE-2023-5841

    Last Modified: 4 Nov 2025

    Due to a failure in validating the number of scanline samples of a OpenEXR file containing deep scanline data, Academy Software Foundation OpenEX image parsing library version 3.2.1 and prior is susceptible to a heap-based buffer overflow vulnerability. This issue was resolved as of versions v3.2.2 and v3.1.12 of the affected library.

    Published: 1 Feb 2024
    6.1
    Medium

    CVE-2024-24945

    Last Modified: 29 May 2025

    A stored cross-site scripting (XSS) vulnerability in Travel Journal Using PHP and MySQL with Source Code v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Share Your Moments parameter at /travel-journal/write-journal.php.

    Published: 1 Feb 2024
    8.8
    High

    CVE-2024-24573

    Last Modified: 16 Jun 2025

    facileManager is a modular suite of web apps built with the sysadmin in mind. In versions 4.5.0 and earlier, when a user updates their profile, a POST request containing user information is sent to the endpoint server/fm-modules/facileManager/ajax/processPost.php. It was found that non-admins can arbitrarily set their permissions and grant their non-admin accounts with super user privileges.

    Published: 31 Jan 2024
    6.5
    Medium

    CVE-2024-24572

    Last Modified: 21 Nov 2024

    facileManager is a modular suite of web apps built with the sysadmin in mind. In versions 4.5.0 and earlier, the $_REQUEST global array was unsafely called inside an extract() function in admin-logs.php. The PHP file fm-init.php prevents arbitrary manipulation of $_SESSION via the GET/POST parameters. However, it does not prevent manipulation of any other sensitive variables such as $search_sql. Knowing this, an authenticated user with privileges to view site logs can manipulate the search_sql variable by appending a GET parameter search_sql in the URL. The information above means that the checks and SQL injection prevention attempts were rendered unusable.

    Published: 31 Jan 2024
    5.4
    Medium

    CVE-2024-24571

    Last Modified: 29 May 2025

    facileManager is a modular suite of web apps built with the sysadmin in mind. For the facileManager web application versions 4.5.0 and earlier, we have found that XSS was present in almost all of the input fields as there is insufficient input validation.

    Published: 31 Jan 2024
    8.8
    High

    CVE-2024-24747

    Last Modified: 21 Nov 2024

    MinIO is a High Performance Object Storage. When someone creates an access key, it inherits the permissions of the parent key. Not only for `s3:*` actions, but also `admin:*` actions. Which means unless somewhere above in the access-key hierarchy, the `admin` rights are denied, access keys will be able to simply override their own `s3` permissions to something more permissive. The vulnerability is fixed in RELEASE.2024-01-31T20-20-33Z.

    Published: 31 Jan 2024
    8.6
    High

    CVE-2024-21626

    Last Modified: 15 May 2025

    runc is a CLI tool for spawning and running containers on Linux according to the OCI specification. In runc 1.1.11 and earlier, due to an internal file descriptor leak, an attacker could cause a newly-spawned container process (from runc exec) to have a working directory in the host filesystem namespace, allowing for a container escape by giving access to the host filesystem ("attack 2"). The same attack could be used by a malicious image to allow a container process to gain access to the host filesystem through runc run ("attack 1"). Variants of attacks 1 and 2 could be also be used to overwrite semi-arbitrary host binaries, allowing for complete container escapes ("attack 3a" and "attack 3b"). runc 1.1.12 includes patches for this issue.

    Published: 31 Jan 2024