CVE Feed

    Dashboard / CVE

    8.2
    High

    CVE-2024-23866

    Last Modified: 29 May 2025

    A vulnerability has been reported in Cups Easy (Purchase & Inventory), version 1.0, whereby user-controlled inputs are not sufficiently encoded, resulting in a Cross-Site Scripting (XSS) vulnerability via /cupseasylive/countrycreate.php, in the countryid parameter. Exploitation of this vulnerability could allow a remote attacker to send a specially crafted URL to an authenticated user and steal their session cookie credentials.

    Published: 26 Jan 2024
    8.2
    High

    CVE-2024-23865

    Last Modified: 29 May 2025

    A vulnerability has been reported in Cups Easy (Purchase & Inventory), version 1.0, whereby user-controlled inputs are not sufficiently encoded, resulting in a Cross-Site Scripting (XSS) vulnerability via /cupseasylive/taxstructurelist.php, in the description parameter. Exploitation of this vulnerability could allow a remote attacker to send a specially crafted URL to an authenticated user and steal their session cookie credentials.

    Published: 26 Jan 2024
    8.2
    High

    CVE-2024-23864

    Last Modified: 29 May 2025

    A vulnerability has been reported in Cups Easy (Purchase & Inventory), version 1.0, whereby user-controlled inputs are not sufficiently encoded, resulting in a Cross-Site Scripting (XSS) vulnerability via /cupseasylive/countrylist.php, in the description parameter. Exploitation of this vulnerability could allow a remote attacker to send a specially crafted URL to an authenticated user and steal their session cookie credentials.

    Published: 26 Jan 2024
    8.2
    High

    CVE-2024-23863

    Last Modified: 29 May 2025

    A vulnerability has been reported in Cups Easy (Purchase & Inventory), version 1.0, whereby user-controlled inputs are not sufficiently encoded, resulting in a Cross-Site Scripting (XSS) vulnerability via /cupseasylive/taxstructuredisplay.php, in the description parameter. Exploitation of this vulnerability could allow a remote attacker to send a specially crafted URL to an authenticated user and steal their session cookie credentials.

    Published: 26 Jan 2024
    8.2
    High

    CVE-2024-23862

    Last Modified: 29 May 2025

    A vulnerability has been reported in Cups Easy (Purchase & Inventory), version 1.0, whereby user-controlled inputs are not sufficiently encoded, resulting in a Cross-Site Scripting (XSS) vulnerability via /cupseasylive/grndisplay.php, in the grnno parameter. Exploitation of this vulnerability could allow a remote attacker to send a specially crafted URL to an authenticated user and steal their session cookie credentials.

    Published: 26 Jan 2024
    8.2
    High

    CVE-2024-23861

    Last Modified: 29 May 2025

    A vulnerability has been reported in Cups Easy (Purchase & Inventory), version 1.0, whereby user-controlled inputs are not sufficiently encoded, resulting in a Cross-Site Scripting (XSS) vulnerability via /cupseasylive/unitofmeasurementcreate.php, in the unitofmeasurementid parameter. Exploitation of this vulnerability could allow a remote attacker to send a specially crafted URL to an authenticated user and steal their session cookie credentials.

    Published: 26 Jan 2024
    8.2
    High

    CVE-2024-23860

    Last Modified: 29 May 2025

    A vulnerability has been reported in Cups Easy (Purchase & Inventory), version 1.0, whereby user-controlled inputs are not sufficiently encoded, resulting in a Cross-Site Scripting (XSS) vulnerability via /cupseasylive/currencylist.php, in the description parameter. Exploitation of this vulnerability could allow a remote attacker to send a specially crafted URL to an authenticated user and steal their session cookie credentials.

    Published: 26 Jan 2024
    8.2
    High

    CVE-2024-23859

    Last Modified: 17 Jun 2025

    A vulnerability has been reported in Cups Easy (Purchase & Inventory), version 1.0, whereby user-controlled inputs are not sufficiently encoded, resulting in a Cross-Site Scripting (XSS) vulnerability via /cupseasylive/taxstructurelinecreate.php, in the flatamount parameter. Exploitation of this vulnerability could allow a remote attacker to send a specially crafted URL to an authenticated user and steal their session cookie credentials.

    Published: 26 Jan 2024
    8.2
    High

    CVE-2024-23858

    Last Modified: 29 May 2025

    A vulnerability has been reported in Cups Easy (Purchase & Inventory), version 1.0, whereby user-controlled inputs are not sufficiently encoded, resulting in a Cross-Site Scripting (XSS) vulnerability via /cupseasylive/stockissuancelinecreate.php, in the batchno parameter. Exploitation of this vulnerability could allow a remote attacker to send a specially crafted URL to an authenticated user and steal their session cookie credentials.

    Published: 26 Jan 2024
    8.2
    High

    CVE-2024-23857

    Last Modified: 29 May 2025

    A vulnerability has been reported in Cups Easy (Purchase & Inventory), version 1.0, whereby user-controlled inputs are not sufficiently encoded, resulting in a Cross-Site Scripting (XSS) vulnerability via /cupseasylive/grnlinecreate.php, in the batchno parameter. Exploitation of this vulnerability could allow a remote attacker to send a specially crafted URL to an authenticated user and steal their session cookie credentials.

    Published: 26 Jan 2024
    8.2
    High

    CVE-2024-23856

    Last Modified: 29 May 2025

    A vulnerability has been reported in Cups Easy (Purchase & Inventory), version 1.0, whereby user-controlled inputs are not sufficiently encoded, resulting in a Cross-Site Scripting (XSS) vulnerability via /cupseasylive/itemlist.php, in the description parameter. Exploitation of this vulnerability could allow a remote attacker to send a specially crafted URL to an authenticated user and steal their session cookie credentials.

    Published: 26 Jan 2024
    7.5
    High

    CVE-2023-6919

    Last Modified: 20 May 2026

    Path Traversal: '/../filedir' vulnerability in Biges Safe Life Technologies Electronics Inc. VGuard allows Absolute Path Traversal. This issue affects VGuard: before V500.0003.R008.4011.C0012.B351.C.

    Published: 26 Jan 2024
    6.1
    Medium

    CVE-2024-23388

    Last Modified: 3 Jun 2025

    Improper authorization in handler for custom URL scheme issue in "Mercari" App for Android prior to version 5.78.0 allows a remote attacker to lead a user to access an arbitrary website via the vulnerable App. As a result, the user may become a victim of a phishing attack.

    Published: 26 Jan 2024
    7.2
    High

    CVE-2024-0920

    Last Modified: 17 Jun 2025

    A vulnerability was found in TRENDnet TEW-822DRE 1.03B02. It has been declared as critical. This vulnerability affects unknown code of the file /admin_ping.htm of the component POST Request Handler. The manipulation of the argument ipv4_ping/ipv6_ping leads to command injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-252124. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 26 Jan 2024
    8.8
    High

    CVE-2024-0919

    Last Modified: 21 Nov 2024

    A vulnerability was found in TRENDnet TEW-815DAP 1.0.2.0. It has been classified as critical. This affects the function do_setNTP of the component POST Request Handler. The manipulation of the argument NtpDstStart/NtpDstEnd leads to command injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-252123. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 26 Jan 2024
    7.2
    High

    CVE-2024-0918

    Last Modified: 21 Nov 2024

    A vulnerability was found in TRENDnet TEW-800MB 1.0.1.0 and classified as critical. Affected by this issue is some unknown functionality of the component POST Request Handler. The manipulation of the argument DeviceURL leads to os command injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-252122 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 26 Jan 2024
    5.3
    Medium

    CVE-2023-5612

    Last Modified: 20 Nov 2025

    An issue has been discovered in GitLab affecting all versions before 16.6.6, 16.7 prior to 16.7.4, and 16.8 prior to 16.8.1. It was possible to read the user email address via tags feed although the visibility in the user profile has been disabled.

    Published: 26 Jan 2024
    6.5
    Medium

    CVE-2023-6159

    Last Modified: 20 Nov 2025

    An issue has been discovered in GitLab CE/EE affecting all versions from 12.7 prior to 16.6.6, 16.7 prior to 16.7.4, and 16.8 prior to 16.8.1 It was possible for an attacker to trigger a Regular Expression Denial of Service via a `Cargo.toml` containing maliciously crafted input.

    Published: 26 Jan 2024
    6.4
    Medium

    CVE-2023-5933

    Last Modified: 25 Apr 2026

    An issue has been discovered in GitLab CE/EE affecting all versions after 13.7 before 16.6.6, 16.7 prior to 16.7.4, and 16.8 prior to 16.8.1. Improper input sanitization of user name allows arbitrary API PUT requests.

    Published: 26 Jan 2024
    4.3
    Medium

    CVE-2024-0456

    Last Modified: 26 Apr 2026

    An authorization vulnerability exists in GitLab versions 14.0 prior to 16.6.6, 16.7 prior to 16.7.4, and 16.8 prior to 16.8.1. An unauthorized attacker is able to assign arbitrary users to MRs that they created within the project

    Published: 26 Jan 2024
    9.9
    Critical

    CVE-2024-0402

    Last Modified: 23 Apr 2026

    An issue has been discovered in GitLab CE/EE affecting all versions from 16.0 prior to 16.6.6, 16.7 prior to 16.7.4, and 16.8 prior to 16.8.1 which allows an authenticated user to write files to arbitrary locations on the GitLab server while creating a workspace.

    Published: 26 Jan 2024
    5.3
    Medium

    CVE-2024-21387

    Last Modified: 3 May 2025

    Microsoft Edge for Android Spoofing Vulnerability

    Published: 26 Jan 2024
    8.3
    High

    CVE-2024-21385

    Last Modified: 29 May 2025

    Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability

    Published: 26 Jan 2024
    3.3
    Low

    CVE-2024-21383

    Last Modified: 3 May 2025

    Microsoft Edge (Chromium-based) Spoofing Vulnerability

    Published: 26 Jan 2024
    4.3
    Medium

    CVE-2024-21382

    Last Modified: 29 May 2025

    Microsoft Edge for Android Information Disclosure Vulnerability

    Published: 26 Jan 2024
    9.6
    Critical

    CVE-2024-21326

    Last Modified: 17 Jun 2025

    Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability

    Published: 26 Jan 2024
    5.4
    Medium

    CVE-2023-48132

    Last Modified: 20 Jun 2025

    An issue in kosei entertainment esportsstudioLegends mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token.

    Published: 26 Jan 2024
    5.4
    Medium

    CVE-2023-48126

    Last Modified: 29 May 2025

    An issue in Luxe Beauty Clinic mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token.

    Published: 26 Jan 2024
    7.8
    High

    CVE-2022-48622

    Last Modified: 21 Nov 2024

    In GNOME GdkPixbuf (aka gdk-pixbuf) through 2.42.10, the ANI (Windows animated cursor) decoder encounters heap memory corruption (in ani_load_chunk in io-ani.c) when parsing chunks in a crafted .ani file. A crafted file could allow an attacker to overwrite heap metadata, leading to a denial of service or code execution attack. This occurs in gdk_pixbuf_set_option() in gdk-pixbuf.c.

    Published: 26 Jan 2024
    9.8
    Critical

    CVE-2023-38317

    Last Modified: 3 Jun 2025

    An issue was discovered in OpenNDS before 10.1.3. It fails to sanitize the network interface name entry in the configuration file, allowing attackers that have direct or indirect access to this file to execute arbitrary OS commands.

    Published: 26 Jan 2024
    9.8
    Critical

    CVE-2023-38318

    Last Modified: 20 Jun 2025

    An issue was discovered in OpenNDS before 10.1.3. It fails to sanitize the gateway FQDN entry in the configuration file, allowing attackers that have direct or indirect access to this file to execute arbitrary OS commands.

    Published: 26 Jan 2024
    9.8
    Critical

    CVE-2023-38319

    Last Modified: 20 Jun 2025

    An issue was discovered in OpenNDS before 10.1.3. It fails to sanitize the FAS key entry in the configuration file, allowing attackers that have direct or indirect access to this file to execute arbitrary OS commands.

    Published: 26 Jan 2024
    9.8
    Critical

    CVE-2023-38323

    Last Modified: 29 May 2025

    An issue was discovered in OpenNDS before 10.1.3. It fails to sanitize the status path script entry in the configuration file, allowing attackers that have direct or indirect access to this file to execute arbitrary OS commands.

    Published: 26 Jan 2024
    3.3
    Low

    CVE-2023-45918

    Last Modified: 21 Nov 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

    Published: 26 Jan 2024
    5.4
    Medium

    CVE-2023-48127

    Last Modified: 11 Jun 2025

    An issue in myGAKUYA mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token.

    Published: 26 Jan 2024
    5.4
    Medium

    CVE-2023-48128

    Last Modified: 29 May 2025

    An issue in UNITED BOXING GYM mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token.

    Published: 26 Jan 2024
    5.4
    Medium

    CVE-2023-48129

    Last Modified: 20 Jun 2025

    An issue in kimono-oldnew mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token.

    Published: 26 Jan 2024
    5.4
    Medium

    CVE-2023-48130

    Last Modified: 21 Nov 2024

    An issue in GINZA CAFE mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token.

    Published: 26 Jan 2024
    5.4
    Medium

    CVE-2023-48131

    Last Modified: 17 Jun 2025

    An issue in CHIGASAKI BAKERY mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token.

    Published: 26 Jan 2024
    5.4
    Medium

    CVE-2023-48133

    Last Modified: 16 Jun 2025

    An issue in angel coffee mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token.

    Published: 26 Jan 2024
    5.4
    Medium

    CVE-2023-48135

    Last Modified: 17 Jun 2025

    An issue in mimasaka_farm mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token.

    Published: 26 Jan 2024
    7.8
    High

    CVE-2024-22545

    Last Modified: 29 May 2025

    An issue was discovered in TRENDnet TEW-824DRU version 1.04b01, allows unauthenticated attackers to execute arbitrary code via the system.ntp.server parameter in the sub_420AE0() function. The attack can be launched remotely.

    Published: 26 Jan 2024
    6.1
    Medium

    CVE-2024-22550

    Last Modified: 21 Nov 2024

    An arbitrary file upload vulnerability in the component /alsdemo/ss/mediam.cgi of ShopSite v14.0 allows attackers to execute arbitrary code via uploading a crafted SVG file.

    Published: 26 Jan 2024
    6.1
    Medium

    CVE-2024-22551

    Last Modified: 29 May 2025

    WhatACart v2.0.7 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the component /site/default/search.

    Published: 26 Jan 2024
    6.5
    Medium

    CVE-2024-1023

    Last Modified: 23 Sept 2026

    A vulnerability in the Eclipse Vert.x toolkit results in a memory leak due to using Netty FastThreadLocal data structures. Specifically, when the Vert.x HTTP client establishes connections to different hosts, triggering the memory leak. The leak can be accelerated with intimate runtime knowledge, allowing an attacker to exploit this vulnerability. For instance, a server accepting arbitrary internet addresses could serve as an attack vector by connecting to these addresses, thereby accelerating the memory leak.

    Published: 26 Jan 2024
    9
    Critical

    CVE-2024-23630

    Last Modified: 17 Jun 2025

    An arbitrary firmware upload vulnerability exists in the Motorola MR2600. An attacker can exploit this vulnerability to achieve code execution on the device. Authentication is required, however can be bypassed.

    Published: 25 Jan 2024
    9.6
    Critical

    CVE-2024-23629

    Last Modified: 21 Nov 2024

    An authentication bypass vulnerability exists in the web component of the Motorola MR2600. An attacker can exploit this vulnerability to access protected URLs and retrieve sensitive information.

    Published: 25 Jan 2024
    9
    Critical

    CVE-2024-23628

    Last Modified: 21 Nov 2024

    A command injection vulnerability exists in the 'SaveStaticRouteIPv6Params' parameter of the Motorola MR2600. A remote attacker can exploit this vulnerability to achieve command execution. Authentication is required, however can be bypassed.

    Published: 25 Jan 2024
    9
    Critical

    CVE-2024-23627

    Last Modified: 29 May 2025

    A command injection vulnerability exists in the 'SaveStaticRouteIPv4Params' parameter of the Motorola MR2600. A remote attacker can exploit this vulnerability to achieve command execution. Authentication is required, however can be bypassed.

    Published: 25 Jan 2024
    9
    Critical

    CVE-2024-23626

    Last Modified: 21 Nov 2024

    A command injection vulnerability exists in the ‘SaveSysLogParams’ parameter of the Motorola MR2600. A remote attacker can exploit this vulnerability to achieve command execution. Authentication is required, however can be bypassed.

    Published: 25 Jan 2024