CVE Feed

    Dashboard / CVE

    8.8
    High

    CVE-2024-22603

    Last Modified: 21 Nov 2024

    FlyCms v1.0 contains a Cross-Site Request Forgery (CSRF) vulnerability via /system/links/add_link

    Published: 18 Jan 2024
    5.5
    Medium

    CVE-2021-33630

    Last Modified: 7 May 2025

    NULL Pointer Dereference vulnerability in openEuler kernel on Linux (network modules) allows Pointer Manipulation. This vulnerability is associated with program files net/sched/sch_cbs.C. This issue affects openEuler kernel: from 4.19.90 before 4.19.90-2401.3.

    Published: 18 Jan 2024
    8.8
    High

    CVE-2024-22591

    Last Modified: 20 Jun 2025

    FlyCms v1.0 contains a Cross-Site Request Forgery (CSRF) vulnerability via /system/user/group_save.

    Published: 18 Jan 2024
    8.8
    High

    CVE-2024-22592

    Last Modified: 2 Jun 2025

    FlyCms v1.0 contains a Cross-Site Request Forgery (CSRF) vulnerability via /system/user/group_update

    Published: 18 Jan 2024
    5.5
    Medium

    CVE-2021-33631

    Last Modified: 2 Apr 2025

    Integer Overflow or Wraparound vulnerability in openEuler kernel on Linux (filesystem modules) allows Forced Integer Overflow.This issue affects openEuler kernel: from 4.19.90 before 4.19.90-2401.3, from 5.10.0-60.18.0 before 5.10.0-183.0.0.

    Published: 18 Jan 2024
    5.3
    Medium

    CVE-2024-1459

    Last Modified: 11 Nov 2025

    A path traversal vulnerability was found in Undertow. This issue may allow a remote attacker to append a specially-crafted sequence to an HTTP request for an application deployed to JBoss EAP, which may permit access to privileged or restricted files and directories.

    Published: 18 Jan 2024
    8.8
    High

    CVE-2024-22593

    Last Modified: 21 Nov 2024

    FlyCms v1.0 contains a Cross-Site Request Forgery (CSRF) vulnerability via /system/admin/add_group_save

    Published: 18 Jan 2024
    7.5
    High

    CVE-2023-50614

    Last Modified: 2 Jun 2025

    An issue discovereed in EBYTE E880-IR01-V1.1 allows an attacker to obtain sensitive information via crafted POST request to /cgi-bin/luci.

    Published: 18 Jan 2024
    5.4
    Medium

    CVE-2023-49943

    Last Modified: 2 Jun 2025

    Zoho ManageEngine ServiceDesk Plus MSP before 14504 allows stored XSS (by a low-privileged technician) via a task's name in a time sheet.

    Published: 18 Jan 2024
    5
    Medium

    CVE-2024-0690

    Last Modified: 6 Nov 2025

    An information disclosure flaw was found in ansible-core due to a failure to respect the ANSIBLE_NO_LOG configuration in some scenarios. Information is still included in the output in certain tasks, such as loop items. Depending on the task, this issue may include sensitive information, such as decrypted secret values.

    Published: 18 Jan 2024
    5.4
    Medium

    CVE-2024-22548

    Last Modified: 5 Jun 2025

    FlyCms 1.0 is vulnerable to Cross Site Scripting (XSS) in the system website settings website name section.

    Published: 18 Jan 2024
    5.4
    Medium

    CVE-2024-22549

    Last Modified: 20 Jun 2025

    FlyCms 1.0 is vulnerable to Cross Site Scripting (XSS) in the email settings of the website settings section.

    Published: 18 Jan 2024
    8.8
    High

    CVE-2024-22568

    Last Modified: 20 Jun 2025

    FlyCms v1.0 contains a Cross-Site Request Forgery (CSRF) vulnerability via /system/score/del.

    Published: 18 Jan 2024
    8.8
    High

    CVE-2024-22601

    Last Modified: 20 Jun 2025

    FlyCms v1.0 contains a Cross-Site Request Forgery (CSRF) vulnerability via /system/score/scorerule_save

    Published: 18 Jan 2024
    5.5
    Medium

    CVE-2023-6340

    Last Modified: 11 Jun 2025

    SonicWall Capture Client version 3.7.10, NetExtender client version 10.2.337 and earlier versions are installed with sfpmonitor.sys driver. The driver has been found to be vulnerable to Denial-of-Service (DoS) caused by Stack-based Buffer Overflow vulnerability.

    Published: 17 Jan 2024
    9.6
    Critical

    CVE-2024-22416

    Last Modified: 17 Jun 2025

    pyLoad is a free and open-source Download Manager written in pure Python. The `pyload` API allows any API call to be made using GET requests. Since the session cookie is not set to `SameSite: strict`, this opens the library up to severe attack possibilities via a Cross-Site Request Forgery (CSRF) attack. As a result any API call can be made via a CSRF attack by an unauthenticated user. This issue has been addressed in release `0.5.0b3.dev78`. All users are advised to upgrade.

    Published: 17 Jan 2024
    4.3
    Medium

    CVE-2024-0650

    Last Modified: 23 Jan 2026

    A vulnerability was found in Project Worlds Visitor Management System 1.0. It has been classified as problematic. Affected is an unknown function of the file dataset.php of the component URL Handler. The manipulation of the argument name with the input "><script>alert('torada')</script> leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-251376.

    Published: 17 Jan 2024
    5.5
    Medium

    CVE-2024-0655

    Last Modified: 17 Jun 2025

    A vulnerability has been found in Novel-Plus 4.3.0-RC1 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /novel/bookSetting/list. The manipulation of the argument sort leads to sql injection. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-251383.

    Published: 17 Jan 2024
    5.3
    Medium

    CVE-2024-0654

    Last Modified: 2 Jun 2025

    A vulnerability, which was classified as problematic, was found in DeepFaceLab pretrained DF.wf.288res.384.92.72.22. Affected is an unknown function of the file mainscripts/Util.py. The manipulation leads to deserialization. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used. VDB-251382 is the identifier assigned to this vulnerability.

    Published: 17 Jan 2024
    3.5
    Low

    CVE-2024-0652

    Last Modified: 17 Jun 2025

    A vulnerability was found in PHPGurukul Company Visitor Management System 1.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the file search-visitor.php. The manipulation leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-251378 is the identifier assigned to this vulnerability.

    Published: 17 Jan 2024
    6.5
    Medium

    CVE-2024-22414

    Last Modified: 17 Jun 2025

    flaskBlog is a simple blog app built with Flask. Improper storage and rendering of the `/user/<user>` page allows a user's comments to execute arbitrary javascript code. The html template `user.html` contains the following code snippet to render comments made by a user: `<div class="content" tag="content">{{comment[2]|safe}}</div>`. Use of the "safe" tag causes flask to _not_ escape the rendered content. To remediate this, simply remove the `|safe` tag from the HTML above. No fix is is available and users are advised to manually edit their installation.

    Published: 17 Jan 2024
    3.3
    Low

    CVE-2024-22410

    Last Modified: 21 Nov 2024

    Creditcoin is a network that enables cross-blockchain credit transactions. The Windows binary of the Creditcoin node loads a suite of DLLs provided by Microsoft at startup. If a malicious user has access to overwrite the program files directory it is possible to replace these DLLs and execute arbitrary code. It is the view of the blockchain development team that the threat posed by a hypothetical binary planting attack is minimal and represents a low-security risk. The vulnerable DLL files are from the Windows networking subsystem, the Visual C++ runtime, and low-level cryptographic primitives. Collectively these dependencies are required for a large ecosystem of applications, ranging from enterprise-level security applications to game engines, and don’t represent a fundamental lack of security or oversight in the design and implementation of Creditcoin. The blockchain team takes the stance that running Creditcoin on Windows is officially unsupported and at best should be thought of as experimental.

    Published: 17 Jan 2024
    5.4
    Medium

    CVE-2023-5914

    Last Modified: 17 Jun 2025

      Cross-site scripting (XSS)

    Published: 17 Jan 2024
    8.2
    High

    CVE-2023-6549

    Last Modified: 26 Feb 2026

    Improper Restriction of Operations within the Bounds of a Memory Buffer in NetScaler ADC and NetScaler Gateway allows Unauthenticated Denial of Service and Out-Of-Bounds Memory Read

    Published: 17 Jan 2024
    5.5
    Medium

    CVE-2023-6548

    Last Modified: 24 Oct 2025

    Improper Control of Generation of Code ('Code Injection') in NetScaler ADC and NetScaler Gateway allows an attacker with access to NSIP, CLIP or SNIP with management interface to perform Authenticated (low privileged) remote code execution on Management Interface.

    Published: 17 Jan 2024
    6.3
    Medium

    CVE-2024-0651

    Last Modified: 21 Nov 2024

    A vulnerability was found in PHPGurukul Company Visitor Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file search-visitor.php. The manipulation leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-251377 was assigned to this vulnerability.

    Published: 17 Jan 2024
    6.3
    Medium

    CVE-2024-0649

    Last Modified: 17 Jun 2025

    A vulnerability was found in ZhiHuiYun up to 4.4.13 and classified as critical. This issue affects the function download_network_image of the file /app/Http/Controllers/ImageController.php of the component Search. The manipulation of the argument url leads to server-side request forgery. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-251375.

    Published: 17 Jan 2024
    5.7
    Medium

    CVE-2023-7031

    Last Modified: 21 Nov 2024

    Insecure Direct Object Reference vulnerabilities were discovered in the Avaya Aura Experience Portal Manager which may allow partial information disclosure to an authenticated non-privileged user. Affected versions include 8.0.x and 8.1.x, prior to 8.1.2 patch 0402. Versions prior to 8.0 are end of manufacturer support.

    Published: 17 Jan 2024
    7.3
    High

    CVE-2024-0648

    Last Modified: 17 Jun 2025

    A vulnerability has been found in Yunyou CMS up to 2.2.6 and classified as critical. This vulnerability affects unknown code of the file /app/index/controller/Common.php. The manipulation of the argument templateFile leads to unrestricted upload. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-251374 is the identifier assigned to this vulnerability.

    Published: 17 Jan 2024
    5.4
    Medium

    CVE-2022-42884

    Last Modified: 28 Apr 2026

    Missing Authorization vulnerability in ThemeinProgress WIP Custom Login.This issue affects WIP Custom Login: from n/a through 1.2.7.

    Published: 17 Jan 2024
    4.3
    Medium

    CVE-2022-41790

    Last Modified: 28 Apr 2026

    Missing Authorization vulnerability in CodePeople WP Time Slots Booking Form.This issue affects WP Time Slots Booking Form: from n/a through 1.1.76.

    Published: 17 Jan 2024
    5.4
    Medium

    CVE-2022-41786

    Last Modified: 28 Apr 2026

    Missing Authorization vulnerability in WP Job Portal WP Job Portal – A Complete Job Board.This issue affects WP Job Portal – A Complete Job Board: from n/a through 2.0.1.

    Published: 17 Jan 2024
    5.4
    Medium

    CVE-2022-41695

    Last Modified: 28 Apr 2026

    Missing Authorization vulnerability in SedLex Traffic Manager.This issue affects Traffic Manager: from n/a through 1.4.5.

    Published: 17 Jan 2024
    3.7
    Low

    CVE-2023-50950

    Last Modified: 21 Nov 2024

    IBM QRadar SIEM 7.5 could disclose sensitive email information in responses from offense rules. IBM X-Force ID: 275709.

    Published: 17 Jan 2024
    5.4
    Medium

    CVE-2022-41619

    Last Modified: 28 Apr 2026

    Missing Authorization vulnerability in SedLex Image Zoom.This issue affects Image Zoom: from n/a through 1.8.8.

    Published: 17 Jan 2024
    6.8
    Medium

    CVE-2024-20277

    Last Modified: 21 Nov 2024

    A vulnerability in the web-based management interface of Cisco ThousandEyes Enterprise Agent, Virtual Appliance installation type, could allow an authenticated, remote attacker to perform a command injection and elevate privileges to root. This vulnerability is due to insufficient validation of user-supplied input for the web interface. An attacker could exploit this vulnerability by sending a crafted HTTP packet to the affected device. A successful exploit could allow the attacker to execute arbitrary commands and elevate privileges to root.

    Published: 17 Jan 2024
    6.5
    Medium

    CVE-2024-20287

    Last Modified: 2 Jun 2025

    A vulnerability in the web-based management interface of the Cisco WAP371 Wireless-AC/N Dual Radio Access Point (AP) with Single Point Setup could allow an authenticated, remote attacker to perform command injection attacks against an affected device. This vulnerability is due to improper validation of user-supplied input. An attacker could exploit this vulnerability by sending crafted HTTP requests to the web-based management interface of an affected system. A successful exploit could allow the attacker to execute arbitrary commands with root privileges on the device. To exploit this vulnerability, the attacker must have valid administrative credentials for the device.

    Published: 17 Jan 2024
    6
    Medium

    CVE-2023-20260

    Last Modified: 21 Nov 2024

    A vulnerability in the application CLI of Cisco Prime Infrastructure and Cisco Evolved Programmable Network Manager could allow an authenticated, local attacker to gain escalated privileges. This vulnerability is due to improper processing of command line arguments to application scripts. An attacker could exploit this vulnerability by issuing a command on the CLI with malicious options. A successful exploit could allow the attacker to gain the escalated privileges of the root user on the underlying operating system.

    Published: 17 Jan 2024
    6.5
    Medium

    CVE-2023-20258

    Last Modified: 2 Jun 2025

    A vulnerability in the web-based management interface of Cisco Prime Infrastructure could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system. This vulnerability is due to improper processing of serialized Java objects by the affected application. An attacker could exploit this vulnerability by uploading a document containing malicious serialized Java objects to be processed by the affected application. A successful exploit could allow the attacker to cause the application to execute arbitrary commands.

    Published: 17 Jan 2024
    6.5
    Medium

    CVE-2023-20271

    Last Modified: 17 Jun 2025

    A vulnerability in the web-based management interface of Cisco Prime Infrastructure and Cisco Evolved Programmable Network Manager (EPNM) could allow an authenticated, remote attacker to conduct SQL injection attacks on an affected system. This vulnerability is due to improper validation of user-submitted parameters. An attacker could exploit this vulnerability by authenticating to the application and sending malicious requests to an affected system. A successful exploit could allow the attacker to obtain and modify sensitive information that is stored in the underlying database.

    Published: 17 Jan 2024
    4.8
    Medium

    CVE-2023-20257

    Last Modified: 17 Jun 2025

    A vulnerability in the web-based management interface of Cisco Prime Infrastructure could allow an authenticated, remote attacker to conduct cross-site scripting attacks. This vulnerability is due to improper validation of user-supplied input to the web-based management interface. An attacker could exploit this vulnerability by submitting malicious input containing script or HTML content within requests that would stored within the application interface. A successful exploit could allow the attacker to conduct cross-site scripting attacks against other users of the affected application.

    Published: 17 Jan 2024
    4.8
    Medium

    CVE-2024-20251

    Last Modified: 21 Nov 2024

    A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to perform a stored cross-site scripting (XSS) attack against a user of the interface on an affected device. This vulnerability exists because the web-based management interface does not properly validate user-supplied input. An attacker could exploit this vulnerability by injecting malicious code into specific pages of the interface. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information.

    Published: 17 Jan 2024
    7.3
    High

    CVE-2024-20272

    Last Modified: 2 Jun 2025

    A vulnerability in the web-based management interface of Cisco Unity Connection could allow an unauthenticated, remote attacker to upload arbitrary files to an affected system and execute commands on the underlying operating system. This vulnerability is due to a lack of authentication in a specific API and improper validation of user-supplied data. An attacker could exploit this vulnerability by uploading arbitrary files to an affected system. A successful exploit could allow the attacker to store malicious files on the system, execute arbitrary commands on the operating system, and elevate privileges to root.

    Published: 17 Jan 2024
    4.8
    Medium

    CVE-2024-20270

    Last Modified: 2 Jun 2025

    A vulnerability in the web-based management interface of Cisco BroadWorks Application Delivery Platform and Cisco BroadWorks Xtended Services Platform could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface. This vulnerability exists because the web-based management interface does not properly validate user-supplied input. An attacker could exploit this vulnerability by persuading a user of the interface to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information.

    Published: 17 Jan 2024
    5.4
    Medium

    CVE-2022-40702

    Last Modified: 28 Apr 2026

    Missing Authorization vulnerability in Zorem Advanced Local Pickup for WooCommerce.This issue affects Advanced Local Pickup for WooCommerce: from n/a through 1.5.2.

    Published: 17 Jan 2024
    4.3
    Medium

    CVE-2023-23882

    Last Modified: 28 Apr 2026

    Missing Authorization vulnerability in Brainstorm Force Ultimate Addons for Beaver Builder – Lite.This issue affects Ultimate Addons for Beaver Builder – Lite: from n/a through 1.5.5.

    Published: 17 Jan 2024
    5.4
    Medium

    CVE-2023-23896

    Last Modified: 28 Apr 2026

    Missing Authorization vulnerability in MyThemeShop URL Shortener by MyThemeShop.This issue affects URL Shortener by MyThemeShop: from n/a through 1.0.17.

    Published: 17 Jan 2024
    7.1
    High

    CVE-2022-41990

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Vinoj Cardoza 3D Tag Cloud allows Stored XSS.This issue affects 3D Tag Cloud: from n/a through 3.8.

    Published: 17 Jan 2024
    5.4
    Medium

    CVE-2023-34379

    Last Modified: 28 Apr 2026

    Missing Authorization vulnerability in MagneticOne Cart2Cart: Magento to WooCommerce Migration.This issue affects Cart2Cart: Magento to WooCommerce Migration: from n/a through 2.0.0.

    Published: 17 Jan 2024
    6.3
    Medium

    CVE-2022-40203

    Last Modified: 28 Apr 2026

    Missing Authorization vulnerability in AlgolPlus Advanced Dynamic Pricing for WooCommerce.This issue affects Advanced Dynamic Pricing for WooCommerce: from n/a through 4.1.5.

    Published: 17 Jan 2024