CVE Feed

    Dashboard / CVE

    7.1
    High

    CVE-2024-22290

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in AboZain,O7abeeb,UnitOne Custom Dashboard Widgets allows Cross-Site Scripting (XSS).This issue affects Custom Dashboard Widgets: from n/a through 1.3.1.

    Published: 31 Jan 2024
    8.5
    High

    CVE-2024-23507

    Last Modified: 23 Apr 2026

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in InstaWP InstaWP Connect instawp-connect.This issue affects InstaWP Connect: from n/a through <= 0.1.0.9.

    Published: 31 Jan 2024
    7.5
    High

    CVE-2024-22305

    Last Modified: 28 Apr 2026

    Authorization Bypass Through User-Controlled Key vulnerability in ali Forms Contact Form builder with drag & drop for WordPress – Kali Forms.This issue affects Contact Form builder with drag & drop for WordPress – Kali Forms: from n/a through 2.3.36.

    Published: 31 Jan 2024
    7.8
    High

    CVE-2024-0833

    Last Modified: 21 Nov 2024

    In Telerik Test Studio versions prior to v2023.3.1330, a privilege elevation vulnerability has been identified in the applications installer component.  In an environment where an existing Telerik Test Studio install is present, a lower privileged user has the ability to manipulate the installation package to elevate their privileges on the underlying operating system.

    Published: 31 Jan 2024
    7.8
    High

    CVE-2024-0832

    Last Modified: 21 Nov 2024

    In Telerik Reporting versions prior to 2024 R1, a privilege elevation vulnerability has been identified in the applications installer component.  In an environment where an existing Telerik Reporting install is present, a lower privileged user has the ability to manipulate the installation package to elevate their privileges on the underlying operating system.

    Published: 31 Jan 2024
    7.8
    High

    CVE-2024-0219

    Last Modified: 29 May 2025

    In Telerik JustDecompile versions prior to 2024 R1, a privilege elevation vulnerability has been identified in the applications installer component.  In an environment where an existing Telerik JustDecompile install is present, a lower privileged user has the ability to manipulate the installation package to elevate their privileges on the underlying operating system.

    Published: 31 Jan 2024
    3.5
    Low

    CVE-2024-1103

    Last Modified: 17 Jun 2025

    A vulnerability was found in CodeAstro Real Estate Management System 1.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the file profile.php of the component Feedback Form. The manipulation of the argument Your Feedback with the input <img src=x onerror=alert(document.cookie)> leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-252458 is the identifier assigned to this vulnerability.

    Published: 31 Jan 2024
    5.4
    Medium

    CVE-2023-50357

    Last Modified: 21 Nov 2024

    A cross site scripting vulnerability in the AREAL SAS Websrv1 ASP website allows a remote low-privileged attacker to gain escalated privileges of other non-admin users.

    Published: 31 Jan 2024
    6.5
    Medium

    CVE-2023-50356

    Last Modified: 17 Jun 2025

    SSL connections to some LDAP servers are vulnerable to a man-in-the-middle attack due to improper certificate validation in AREAL Topkapi Vision (Server). This allows a remote unauthenticated attacker to gather sensitive information and prevent valid users from login.

    Published: 31 Jan 2024
    7.3
    High

    CVE-2024-1112

    Last Modified: 29 May 2025

    Heap-based buffer overflow vulnerability in Resource Hacker, developed by Angus Johnson, affecting version 3.6.0.92. This vulnerability could allow an attacker to execute arbitrary code via a long filename argument.

    Published: 31 Jan 2024
    5.4
    Medium

    CVE-2024-0589

    Last Modified: 9 Jun 2025

    Cross-site scripting (XSS) vulnerability in the entry overview tab in Devolutions Remote Desktop Manager 2023.3.36 and earlier on Windows allows an attacker with access to a data source to inject a malicious script via a specially crafted input in an entry.

    Published: 31 Jan 2024
    7.6
    High

    CVE-2023-44313

    Last Modified: 13 Feb 2025

    Server-Side Request Forgery (SSRF) vulnerability in Apache ServiceComb Service-Center. Attackers can obtain sensitive server information through specially crafted requests.This issue affects Apache ServiceComb before 2.1.0(include). Users are recommended to upgrade to version 2.2.0, which fixes the issue.

    Published: 31 Jan 2024
    5.8
    Medium

    CVE-2023-44312

    Last Modified: 30 May 2025

    Exposure of Sensitive Information to an Unauthorized Actor in Apache ServiceComb Service-Center.This issue affects Apache ServiceComb Service-Center before 2.1.0 (include). Users are recommended to upgrade to version 2.2.0, which fixes the issue.

    Published: 31 Jan 2024
    4.3
    Medium

    CVE-2024-0836

    Last Modified: 8 Apr 2026

    The WordPress Review & Structure Data Schema Plugin – Review Schema plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the rtrs_review_edit() function in all versions up to, and including, 2.1.14. This makes it possible for authenticated attackers, with subscriber-level access and above, to modify arbitrary reviews.

    Published: 31 Jan 2024
    3.5
    Low

    CVE-2024-1099

    Last Modified: 21 Nov 2024

    A vulnerability was found in Rebuild up to 3.5.5. It has been classified as problematic. Affected is the function getFileOfData of the file /filex/read-raw. The manipulation of the argument url leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-252456.

    Published: 31 Jan 2024
    4.3
    Medium

    CVE-2024-1098

    Last Modified: 29 May 2025

    A vulnerability was found in Rebuild up to 3.5.5 and classified as problematic. This issue affects the function QiniuCloud.getStorageFile of the file /filex/proxy-download. The manipulation of the argument url leads to information disclosure. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-252455.

    Published: 31 Jan 2024
    3.3
    Low

    CVE-2024-22236

    Last Modified: 3 Jun 2025

    In Spring Cloud Contract, versions 4.1.x prior to 4.1.1, versions 4.0.x prior to 4.0.5, and versions 3.1.x prior to 3.1.10, test execution is vulnerable to local information disclosure via temporary directory created with unsafe permissions through the shaded com.google.guava:guava dependency in the org.springframework.cloud:spring-cloud-contract-shade dependency.

    Published: 31 Jan 2024
    6.3
    Medium

    CVE-2024-1012

    Last Modified: 13 Jun 2025

    A vulnerability, which was classified as critical, has been found in Wanhu ezOFFICE 11.1.0. This issue affects some unknown processing of the file defaultroot/platform/bpm/work_flow/operate/wf_printnum.jsp. The manipulation of the argument recordId leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-252281 was assigned to this vulnerability.

    Published: 31 Jan 2024
    6.4
    Medium

    CVE-2023-2439

    Last Modified: 17 Jun 2025

    The UserPro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'userpro' shortcode in versions up to, and including, 5.1.5 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 31 Jan 2024
    7.2
    High

    CVE-2024-1069

    Last Modified: 8 Apr 2026

    The Contact Form Entries plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file validation on the 'view_page' function in versions up to, and including, 1.3.2. This makes it possible for authenticated attackers with administrator-level capabilities or above, to upload arbitrary files on the affected site's server which may make remote code execution possible.

    Published: 31 Jan 2024
    8.7
    High

    CVE-2024-23651

    Last Modified: 29 May 2025

    BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner. Two malicious build steps running in parallel sharing the same cache mounts with subpaths could cause a race condition that can lead to files from the host system being accessible to the build container. The issue has been fixed in v0.12.5. Workarounds include, avoiding using BuildKit frontend from an untrusted source or building an untrusted Dockerfile containing cache mounts with --mount=type=cache,source=... options.

    Published: 31 Jan 2024
    7.8
    High

    CVE-2024-1086

    Last Modified: 7 Aug 2026

    A use-after-free vulnerability in the Linux kernel's netfilter: nf_tables component can be exploited to achieve local privilege escalation. The nft_verdict_init() function allows positive values as drop error within the hook verdict, and hence the nf_hook_slow() function can cause a double free vulnerability when NF_DROP is issued with a drop error which resembles NF_ACCEPT. We recommend upgrading past commit f342de4e2f33e0e39165d8639387aa6c19dff660.

    Published: 31 Jan 2024
    7.5
    High

    CVE-2024-23775

    Last Modified: 5 Jun 2026

    Integer Overflow vulnerability in Mbed TLS 2.x before 2.28.7 and 3.x before 3.5.2, allows attackers to cause a denial of service (DoS) via mbedtls_x509_set_extension().

    Published: 31 Jan 2024
    9.8
    Critical

    CVE-2024-23653

    Last Modified: 21 Nov 2024

    BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner. In addition to running containers as build steps, BuildKit also provides APIs for running interactive containers based on built images. It was possible to use these APIs to ask BuildKit to run a container with elevated privileges. Normally, running such containers is only allowed if special `security.insecure` entitlement is enabled both by buildkitd configuration and allowed by the user initializing the build request. The issue has been fixed in v0.12.5 . Avoid using BuildKit frontends from untrusted sources.

    Published: 31 Jan 2024
    9.8
    Critical

    CVE-2022-47072

    Last Modified: 17 Jun 2025

    SQL injection vulnerability in Enterprise Architect 16.0.1605 32-bit allows attackers to run arbitrary SQL commands via the Find parameter in the Select Classifier dialog box..

    Published: 31 Jan 2024
    5.3
    Medium

    CVE-2024-23650

    Last Modified: 21 Nov 2024

    BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner. A malicious BuildKit client or frontend could craft a request that could lead to BuildKit daemon crashing with a panic. The issue has been fixed in v0.12.5. As a workaround, avoid using BuildKit frontends from untrusted sources.

    Published: 31 Jan 2024
    7.2
    High

    CVE-2023-31505

    Last Modified: 20 Jun 2025

    An arbitrary file upload vulnerability in Schlix CMS v2.2.8-1, allows remote authenticated attackers to execute arbitrary code and obtain sensitive information via a crafted .phtml file.

    Published: 31 Jan 2024
    6.1
    Medium

    CVE-2024-0406

    Last Modified: 20 Nov 2025

    A flaw was discovered in the mholt/archiver package. This flaw allows an attacker to create a specially crafted tar file, which, when unpacked, may allow access to restricted files or directories. This issue can allow the creation or overwriting of files with the user's or application's privileges using the library.

    Published: 31 Jan 2024
    10
    Critical

    CVE-2024-23652

    Last Modified: 17 Jun 2025

    BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner. A malicious BuildKit frontend or Dockerfile using RUN --mount could trick the feature that removes empty files created for the mountpoints into removing a file outside the container, from the host system. The issue has been fixed in v0.12.5. Workarounds include avoiding using BuildKit frontends from an untrusted source or building an untrusted Dockerfile containing RUN --mount feature.

    Published: 31 Jan 2024
    9.8
    Critical

    CVE-2024-23745

    Last Modified: 21 Nov 2024

    In Notion Web Clipper 1.0.3(7), a .nib file is susceptible to the Dirty NIB attack. NIB files can be manipulated to execute arbitrary commands. Additionally, even if a NIB file is modified within an application, Gatekeeper may still permit the execution of the application, enabling the execution of arbitrary commands within the application's context. NOTE: the vendor's perspective is that this is simply an instance of CVE-2022-48505, cannot properly be categorized as a product-level vulnerability, and cannot have a product-level fix because it is about incorrect caching of file signatures on macOS.

    Published: 31 Jan 2024
    4.3
    Medium

    CVE-2024-44244

    Last Modified: 2 Apr 2026

    A memory corruption issue was addressed with improved input validation. This issue is fixed in Safari 18.1, iOS 18.1 and iPadOS 18.1, macOS Sequoia 15.1, tvOS 18.1, visionOS 2.1, watchOS 11.1. Processing maliciously crafted web content may lead to an unexpected process crash.

    Published: 31 Jan 2024
    5.5
    Medium

    CVE-2024-23170

    Last Modified: 5 Jun 2026

    An issue was discovered in Mbed TLS 2.x before 2.28.7 and 3.x before 3.5.2. There was a timing side channel in RSA private operations. This side channel could be sufficient for a local attacker to recover the plaintext. It requires the attacker to send a large number of messages for decryption, as described in "Everlasting ROBOT: the Marvin Attack" by Hubert Kario.

    Published: 31 Jan 2024
    5.4
    Medium

    CVE-2024-22569

    Last Modified: 30 May 2025

    Stored Cross-Site Scripting (XSS) vulnerability in POSCMS v4.6.2, allows attackers to execute arbitrary code via a crafted payload to /index.php?c=install&m=index&step=2&is_install_db=0.

    Published: 31 Jan 2024
    6.3
    Medium

    CVE-2024-23834

    Last Modified: 21 Nov 2024

    Discourse is an open-source discussion platform. Improperly sanitized user input could lead to an XSS vulnerability in some situations. This vulnerability only affects Discourse instances which have disabled the default Content Security Policy. The vulnerability is patched in 3.1.5 and 3.2.0.beta5. As a workaround, ensure Content Security Policy is enabled and does not include `unsafe-inline`.

    Published: 30 Jan 2024
    4.8
    Medium

    CVE-2024-24567

    Last Modified: 16 Jun 2025

    Vyper is a pythonic Smart Contract Language for the ethereum virtual machine. Vyper compiler allows passing a value in builtin raw_call even if the call is a delegatecall or a staticcall. But in the context of delegatecall and staticcall the handling of value is not possible due to the semantics of the respective opcodes, and vyper will silently ignore the value= argument. If the semantics of the EVM are unknown to the developer, he could suspect that by specifying the `value` kwarg, exactly the given amount will be sent along to the target. This vulnerability affects 0.3.10 and earlier versions.

    Published: 30 Jan 2024
    9.1
    Critical

    CVE-2023-5389

    Last Modified: 17 Jun 2025

    An attacker could potentially exploit this vulnerability, leading to the ability to modify files on Honeywell Experion ControlEdge VirtualUOC and ControlEdge UOC . This exploit could be used to write a file that may result in unexpected behavior based on configuration changes or updating of files that could result in subsequent execution of a malicious application if triggered. Honeywell recommends updating to the most recent version of the product. See Honeywell Security Notification for recommendations on upgrading and versioning. 

    Published: 30 Jan 2024
    7.8
    High

    CVE-2024-1085

    Last Modified: 29 May 2025

    A use-after-free vulnerability in the Linux kernel's netfilter: nf_tables component can be exploited to achieve local privilege escalation. The nft_setelem_catchall_deactivate() function checks whether the catch-all set element is active in the current generation instead of the next generation before freeing it, but only flags it inactive in the next generation, making it possible to free the element multiple times, leading to a double free vulnerability. We recommend upgrading past commit b1db244ffd041a49ecc9618e8feb6b5c1afcdaa7.

    Published: 30 Jan 2024
    5.3
    Medium

    CVE-2024-0853

    Last Modified: 20 Jun 2025

    curl inadvertently kept the SSL session ID for connections in its cache even when the verify status (*OCSP stapling*) test failed. A subsequent transfer to the same hostname could then succeed if the session ID cache was still fresh, which then skipped the verify status check.

    Published: 30 Jan 2024
    8.2
    High

    CVE-2024-24558

    Last Modified: 21 Nov 2024

    TanStack Query supplies asynchronous state management, server-state utilities and data fetching for the web. The `@tanstack/react-query-next-experimental` NPM package is vulnerable to a cross-site scripting vulnerability. To exploit this, an attacker would need to either inject malicious input or arrange to have malicious input be returned from an endpoint. To fix this issue, please update to version 5.18.0 or later.

    Published: 30 Jan 2024
    6.5
    Medium

    CVE-2024-21388

    Last Modified: 29 May 2025

    Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability

    Published: 30 Jan 2024
    7.2
    High

    CVE-2024-24556

    Last Modified: 29 May 2025

    urql is a GraphQL client that exposes a set of helpers for several frameworks. The `@urql/next` package is vulnerable to XSS. To exploit this an attacker would need to ensure that the response returns `html` tags and that the web-application is using streamed responses (non-RSC). This vulnerability is due to improper escaping of html-like characters in the response-stream. To fix this vulnerability upgrade to version 1.1.1

    Published: 30 Jan 2024
    8.8
    High

    CVE-2024-1077

    Last Modified: 3 Jun 2025

    Use after free in Network in Google Chrome prior to 121.0.6167.139 allowed a remote attacker to potentially exploit heap corruption via a malicious file. (Chromium security severity: High)

    Published: 30 Jan 2024
    8.8
    High

    CVE-2024-1060

    Last Modified: 29 May 2025

    Use after free in Canvas in Google Chrome prior to 121.0.6167.139 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

    Published: 30 Jan 2024
    8.8
    High

    CVE-2024-1059

    Last Modified: 8 May 2025

    Use after free in Peer Connection in Google Chrome prior to 121.0.6167.139 allowed a remote attacker to potentially exploit stack corruption via a crafted HTML page. (Chromium security severity: High)

    Published: 30 Jan 2024
    8.2
    High

    CVE-2024-23841

    Last Modified: 17 Jun 2025

    apollo-client-nextjs is the Apollo Client support for the Next.js App Router. The @apollo/experimental-apollo-client-nextjs NPM package is vulnerable to a cross-site scripting vulnerability. To exploit this vulnerability, an attacker would need to either inject malicious input (e.g. by redirecting a user to a specifically-crafted link) or arrange to have malicious input be returned by a GraphQL server (e.g. by persisting it in a database). To fix this issue, please update to version 0.7.0 or later.

    Published: 30 Jan 2024
    8.2
    High

    CVE-2023-46230

    Last Modified: 30 May 2025

    In Splunk Add-on Builder versions below 4.1.4, the app writes sensitive information to internal log files.

    Published: 30 Jan 2024
    6.8
    Medium

    CVE-2023-46231

    Last Modified: 28 Feb 2025

    In Splunk Add-on Builder versions below 4.1.4, the application writes user session tokens to its internal log files when you visit the Splunk Add-on Builder or when you build or edit a custom app or add-on.

    Published: 30 Jan 2024
    8.1
    High

    CVE-2023-6258

    Last Modified: 17 Jun 2025

    A security vulnerability has been identified in the pkcs11-provider, which is associated with Public-Key Cryptography Standards (PKCS#11). If exploited successfully, this vulnerability could result in a Bleichenbacher-like security flaw, potentially enabling a side-channel attack on PKCS#1 1.5 decryption.

    Published: 30 Jan 2024
    5.7
    Medium

    CVE-2024-24565

    Last Modified: 21 Nov 2024

    CrateDB is a distributed SQL database that makes it simple to store and analyze massive amounts of data in real-time. There is a COPY FROM function in the CrateDB database that is used to import file data into database tables. This function has a flaw, and authenticated attackers can use the COPY FROM function to import arbitrary file content into database tables, resulting in information leakage. This vulnerability is patched in 5.3.9, 5.4.8, 5.5.4, and 5.6.1.

    Published: 30 Jan 2024
    7.5
    High

    CVE-2024-23838

    Last Modified: 21 Nov 2024

    TrueLayer.NET is the .Net client for TrueLayer. The vulnerability could potentially allow a malicious actor to gain control over the destination URL of the HttpClient used in the API classes. For applications using the SDK, requests to unexpected resources on local networks or to the internet could be made which could lead to information disclosure. The issue can be mitigated by having strict egress rules limiting the destinations to which requests can be made, and applying strict validation to any user input passed to the `truelayer-dotnet` library. Versions of TrueLayer.Client `v1.6.0` and later are not affected.

    Published: 30 Jan 2024