CVE Feed

    Dashboard / CVE

    4.8
    Medium

    CVE-2023-5956

    Last Modified: 9 Jun 2025

    The Wp-Adv-Quiz WordPress plugin through 1.0.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

    Published: 29 Jan 2024
    5.3
    Medium

    CVE-2023-7199

    Last Modified: 29 May 2025

    The Relevanssi WordPress plugin before 4.22.0, Relevanssi Premium WordPress plugin before 2.25.0 allows any unauthenticated user to read draft and private posts via a crafted request

    Published: 29 Jan 2024
    7.1
    High

    CVE-2023-6279

    Last Modified: 20 Feb 2026

    The Woostify Sites Library WordPress plugin before 1.4.8 does not have authorisation in an AJAX action, allowing any authenticated users, such as subscriber to update arbitrary blog options and set them to 'activated' which could lead to DoS when using a specific option name

    Published: 29 Jan 2024
    4.3
    Medium

    CVE-2023-6633

    Last Modified: 21 Nov 2024

    The Site Notes WordPress plugin through 2.0.0 does not have CSRF checks in some of its functionalities, which could allow attackers to make logged in users perform unwanted actions, such as deleting administration notes, via CSRF attacks

    Published: 29 Jan 2024
    6.1
    Medium

    CVE-2023-6389

    Last Modified: 20 Jun 2025

    The WordPress Toolbar WordPress plugin through 2.2.6 redirects to any URL via the "wptbto" parameter. This makes it possible for unauthenticated attackers to redirect users to potentially malicious sites if they can successfully trick them into performing an action.

    Published: 29 Jan 2024
    8.8
    High

    CVE-2023-7074

    Last Modified: 17 Jun 2025

    The WP SOCIAL BOOKMARK MENU WordPress plugin through 1.2 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack.

    Published: 29 Jan 2024
    6.1
    Medium

    CVE-2023-6278

    Last Modified: 20 Jun 2025

    The Biteship: Plugin Ongkos Kirim Kurir Instant, Reguler, Kargo WordPress plugin before 2.2.25 does not sanitise and escape the biteship_error and biteship_message parameters before outputting them back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

    Published: 29 Jan 2024
    5.3
    Medium

    CVE-2024-1017

    Last Modified: 21 Nov 2024

    A vulnerability was found in Gabriels FTP Server 1.2. It has been rated as problematic. This issue affects some unknown processing. The manipulation of the argument USERNAME leads to denial of service. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue. The associated identifier of this vulnerability is VDB-252287.

    Published: 29 Jan 2024
    9.8
    Critical

    CVE-2024-1015

    Last Modified: 20 Jul 2026

    Remote command execution vulnerability in SE-elektronic GmbH E-DDC3.3 affecting versions 03.07.03 and higher. An attacker could send different commands from the operating system to the system via the web configuration functionality of the device.

    Published: 29 Jan 2024
    6.2
    Medium

    CVE-2024-1014

    Last Modified: 20 Jul 2026

    Uncontrolled resource consumption vulnerability in SE-elektronic GmbH E-DDC3.3 affecting versions 03.07.03 and higher. An attacker could interrupt the availability of the administration panel by sending multiple ICMP packets.

    Published: 29 Jan 2024
    5.3
    Medium

    CVE-2024-1016

    Last Modified: 17 Jun 2025

    A vulnerability was found in Solar FTP Server 2.1.1/2.1.2. It has been declared as problematic. This vulnerability affects unknown code of the component PASV Command Handler. The manipulation leads to denial of service. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue. VDB-252286 is the identifier assigned to this vulnerability.

    Published: 29 Jan 2024
    4.3
    Medium

    CVE-2024-1011

    Last Modified: 2 Jun 2025

    A vulnerability classified as problematic was found in SourceCodester Employee Management System 1.0. This vulnerability affects unknown code of the file delete-leave.php of the component Leave Handler. The manipulation of the argument id leads to improper access controls. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-252280.

    Published: 29 Jan 2024
    3.5
    Low

    CVE-2024-1010

    Last Modified: 29 May 2025

    A vulnerability classified as problematic has been found in SourceCodester Employee Management System 1.0. This affects an unknown part of the file edit-profile.php. The manipulation of the argument fullname/phone/date of birth/address/date of appointment leads to cross site scripting. It is possible to initiate the attack remotely. The associated identifier of this vulnerability is VDB-252279.

    Published: 29 Jan 2024
    7.3
    High

    CVE-2024-1009

    Last Modified: 5 Jun 2025

    A vulnerability was found in SourceCodester Employee Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /Admin/login.php. The manipulation of the argument txtusername leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-252278 is the identifier assigned to this vulnerability.

    Published: 29 Jan 2024
    7.5
    High

    CVE-2023-29055

    Last Modified: 20 Jun 2025

    In Apache Kylin version 2.0.0 to 4.0.3, there is a Server Config web interface that displays the content of file 'kylin.properties', that may contain serverside credentials. When the kylin service runs over HTTP (or other plain text protocol), it is possible for network sniffers to hijack the HTTP payload and get access to the content of kylin.properties and potentially the containing credentials. To avoid this threat, users are recommended to  * Always turn on HTTPS so that network payload is encrypted. * Avoid putting credentials in kylin.properties, or at least not in plain text. * Use network firewalls to protect the serverside such that it is not accessible to external attackers. * Upgrade to version Apache Kylin 4.0.4, which filters out the sensitive content that goes to the Server Config web interface.

    Published: 29 Jan 2024
    6.6
    Medium

    CVE-2024-0788

    Last Modified: 20 May 2025

    SUPERAntiSpyware Pro X v10.0.1260 is vulnerable to kernel-level API parameters manipulation and Denial of Service vulnerabilities by triggering the 0x9C402140 IOCTL code of the saskutil64.sys driver.

    Published: 29 Jan 2024
    4.7
    Medium

    CVE-2024-1008

    Last Modified: 21 Nov 2024

    A vulnerability was found in SourceCodester Employee Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file edit-photo.php of the component Profile Page. The manipulation leads to unrestricted upload. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-252277 was assigned to this vulnerability.

    Published: 29 Jan 2024
    6.3
    Medium

    CVE-2024-1007

    Last Modified: 21 Nov 2024

    A vulnerability was found in SourceCodester Employee Management System 1.0. It has been classified as critical. Affected is an unknown function of the file edit_profile.php. The manipulation of the argument txtfullname leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-252276.

    Published: 29 Jan 2024
    7.3
    High

    CVE-2024-1006

    Last Modified: 29 May 2025

    A vulnerability was found in Shanxi Diankeyun Technology NODERP up to 6.0.2 and classified as critical. This issue affects some unknown processing of the file application/index/common.php of the component Cookie Handler. The manipulation of the argument Nod_User_Id/Nod_User_Token leads to improper authentication. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-252275. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 29 Jan 2024
    8.8
    High

    CVE-2023-5378

    Last Modified: 17 Jun 2025

    Improper Input Validation vulnerability in MegaBIP and already unsupported SmodBIP software allows for Stored XSS.This issue affects SmodBIP in all versions and MegaBIP in versions up to 4.36.2. MegaBIP 5.08 was tested and is not vulnerable. A precise range of vulnerable versions remains unknown.

    Published: 29 Jan 2024
    5.3
    Medium

    CVE-2024-1005

    Last Modified: 21 Nov 2024

    A vulnerability has been found in Shanxi Diankeyun Technology NODERP up to 6.0.2 and classified as critical. This vulnerability affects unknown code of the file /runtime/log. The manipulation leads to files or directories accessible. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-252274 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 29 Jan 2024
    7.2
    High

    CVE-2024-1004

    Last Modified: 17 Jun 2025

    A vulnerability, which was classified as critical, was found in Totolink N200RE 9.3.5u.6139_B20201216. This affects the function loginAuth of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument http_host leads to stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-252273 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 29 Jan 2024
    7.2
    High

    CVE-2024-1003

    Last Modified: 17 Jun 2025

    A vulnerability, which was classified as critical, has been found in Totolink N200RE 9.3.5u.6139_B20201216. Affected by this issue is the function setLanguageCfg of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument lang leads to stack-based buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-252272. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 29 Jan 2024
    7.5
    High

    CVE-2023-46838

    Last Modified: 4 Nov 2025

    Transmit requests in Xen's virtual network protocol can consist of multiple parts. While not really useful, except for the initial part any of them may be of zero length, i.e. carry no data at all. Besides a certain initial portion of the to be transferred data, these parts are directly translated into what Linux calls SKB fragments. Such converted request parts can, when for a particular SKB they are all of length zero, lead to a de-reference of NULL in core networking code.

    Published: 29 Jan 2024
    7.2
    High

    CVE-2024-1002

    Last Modified: 29 May 2025

    A vulnerability classified as critical was found in Totolink N200RE 9.3.5u.6139_B20201216. Affected by this vulnerability is the function setIpPortFilterRules of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument ePort leads to stack-based buffer overflow. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-252271. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 29 Jan 2024
    7.2
    High

    CVE-2024-1001

    Last Modified: 16 Jun 2025

    A vulnerability classified as critical has been found in Totolink N200RE 9.3.5u.6139_B20201216. Affected is the function main of the file /cgi-bin/cstecgi.cgi. The manipulation leads to stack-based buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-252270 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 29 Jan 2024
    7.2
    High

    CVE-2024-1000

    Last Modified: 21 Nov 2024

    A vulnerability was found in Totolink N200RE 9.3.5u.6139_B20201216. It has been rated as critical. This issue affects the function setTracerouteCfg of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument command leads to stack-based buffer overflow. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-252269 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 29 Jan 2024
    3.5
    Low

    CVE-2024-23790

    Last Modified: 17 Jun 2025

    Improper Input Validation vulnerability in the upload functionality for user avatars allows functionality misuse due to missing check of filetypes. This issue affects OTRS: from 7.0.X through 7.0.48, from 8.0.X through 8.0.37, from 2023 through 2023.1.1.

    Published: 29 Jan 2024
    4.9
    Medium

    CVE-2024-23791

    Last Modified: 29 May 2025

    Insertion of debug information into log file during building the elastic search index allows reading of sensitive information from articles.This issue affects OTRS: from 7.0.X through 7.0.48, from 8.0.X through 8.0.37, from 2023.X through 2023.1.1.

    Published: 29 Jan 2024
    5.3
    Medium

    CVE-2024-23792

    Last Modified: 21 Nov 2024

    When adding attachments to ticket comments, another user can add attachments as well impersonating the orginal user. The attack requires a logged-in other user to know the UUID. While the legitimate user completes the comment, the malicious user can add more files to the comment. This issue affects OTRS: from 7.0.X through 7.0.48, from 8.0.X through 8.0.37, from 2023.X through 2023.1.1.

    Published: 29 Jan 2024
    7.2
    High

    CVE-2024-0999

    Last Modified: 21 Nov 2024

    A vulnerability was found in Totolink N200RE 9.3.5u.6139_B20201216. It has been declared as critical. This vulnerability affects the function setParentalRules of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument eTime leads to stack-based buffer overflow. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-252268. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 29 Jan 2024
    7.2
    High

    CVE-2024-0998

    Last Modified: 29 May 2025

    A vulnerability was found in Totolink N200RE 9.3.5u.6139_B20201216. It has been classified as critical. This affects the function setDiagnosisCfg of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument ip leads to stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-252267. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 29 Jan 2024
    7.2
    High

    CVE-2024-0997

    Last Modified: 21 Nov 2024

    A vulnerability was found in Totolink N200RE 9.3.5u.6139_B20201216 and classified as critical. Affected by this issue is the function setOpModeCfg of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument pppoeUser leads to stack-based buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-252266 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 29 Jan 2024
    8.1
    High

    CVE-2024-0212

    Last Modified: 6 Jun 2025

    The Cloudflare Wordpress plugin was found to be vulnerable to improper authentication. The vulnerability enables attackers with a lower privileged account to access data from the Cloudflare API.

    Published: 29 Jan 2024
    7.2
    High

    CVE-2023-49038

    Last Modified: 2 Jun 2025

    Command injection in the ping utility on Buffalo LS210D 1.78-0.03 allows a remote authenticated attacker to inject arbitrary commands onto the NAS as root.

    Published: 29 Jan 2024
    9.8
    Critical

    CVE-2024-24141

    Last Modified: 21 Nov 2024

    Sourcecodester School Task Manager App 1.0 allows SQL Injection via the 'task' parameter.

    Published: 29 Jan 2024
    7.2
    High

    CVE-2024-24140

    Last Modified: 29 May 2025

    Sourcecodester Daily Habit Tracker App 1.0 allows SQL Injection via the parameter 'tracker.'

    Published: 29 Jan 2024
    7.2
    High

    CVE-2024-24139

    Last Modified: 21 Nov 2024

    Sourcecodester Login System with Email Verification 1.0 allows SQL Injection via the 'user' parameter.

    Published: 29 Jan 2024
    7.5
    High

    CVE-2023-51842

    Last Modified: 2 Jun 2025

    An algorithm-downgrade issue was discovered in Ylianst MeshCentral 1.1.16.

    Published: 29 Jan 2024
    9.1
    Critical

    CVE-2023-51839

    Last Modified: 20 Jun 2025

    DeviceFarmer stf v3.6.6 suffers from Use of a Broken or Risky Cryptographic Algorithm.

    Published: 29 Jan 2024
    9.8
    Critical

    CVE-2023-51840

    Last Modified: 29 May 2025

    DoraCMS 2.1.8 is vulnerable to Use of Hard-coded Cryptographic Key.

    Published: 29 Jan 2024
    5.4
    Medium

    CVE-2024-22559

    Last Modified: 29 May 2025

    LightCMS v2.0 is vulnerable to Cross Site Scripting (XSS) in the Content Management - Articles field.

    Published: 29 Jan 2024
    5.4
    Medium

    CVE-2024-22570

    Last Modified: 20 Jun 2025

    A stored cross-site scripting (XSS) vulnerability in /install.php?m=install&c=index&a=step3 of GreenCMS v2.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.

    Published: 29 Jan 2024
    7.5
    High

    CVE-2024-23747

    Last Modified: 20 Jun 2025

    The Moderna Sistemas ModernaNet Hospital Management System 2024 is susceptible to an Insecure Direct Object Reference (IDOR) vulnerability. This vulnerability resides in the system's handling of user data access through a /Modernanet/LAUDO/LAU0000100/Laudo?id= URI. By manipulating this id parameter, an attacker can gain access to sensitive medical information.

    Published: 29 Jan 2024
    6.1
    Medium

    CVE-2024-24136

    Last Modified: 20 Jun 2025

    The 'Your Name' field in the Submit Score section of Sourcecodester Math Game with Leaderboard v1.0 is vulnerable to Cross-Site Scripting (XSS) attacks.

    Published: 29 Jan 2024
    4.8
    Medium

    CVE-2024-24134

    Last Modified: 29 May 2025

    Sourcecodester Online Food Menu 1.0 is vulnerable to Cross Site Scripting (XSS) via the 'Menu Name' and 'Description' fields in the Update Menu section.

    Published: 29 Jan 2024
    6.1
    Medium

    CVE-2024-24135

    Last Modified: 5 Jun 2025

    Product Name and Product Code in the 'Add Product' section of Sourcecodester Product Inventory with Export to Excel 1.0 are vulnerable to XSS attacks.

    Published: 29 Jan 2024
    7.5
    High

    CVE-2024-24736

    Last Modified: 20 Jun 2025

    The POP3 service in YahooPOPs (aka YPOPs!) 1.6 allows a remote denial of service (reboot) via a long string to TCP port 110, a related issue to CVE-2004-1558.

    Published: 29 Jan 2024
    6.5
    Medium

    CVE-2024-1102

    Last Modified: 11 Nov 2025

    A vulnerability was found in jberet-core logging. An exception in 'dbProperties' might display user credentials such as the username and password for the database-connection.

    Published: 29 Jan 2024
    7.5
    High

    CVE-2024-12705

    Last Modified: 15 Apr 2026

    Clients using DNS-over-HTTPS (DoH) can exhaust a DNS resolver's CPU and/or memory by flooding it with crafted valid or invalid HTTP/2 traffic. This issue affects BIND 9 versions 9.18.0 through 9.18.32, 9.20.0 through 9.20.4, 9.21.0 through 9.21.3, and 9.18.11-S1 through 9.18.32-S1.

    Published: 29 Jan 2024