Weekly Vulnerabilities Reports > March 18 to 24, 2024

Overview

281 new vulnerabilities reported during this period, including 54 critical vulnerabilities and 68 high severity vulnerabilities. This weekly summary report vulnerabilities in 152 products from 89 vendors including Campcodes, Tenda, Linux, Debian, and Oretnom23. Vulnerabilities are notably categorized as "Cross-site Scripting", "Out-of-bounds Write", "Missing Authorization", "Path Traversal", and "Code Injection".

  • 247 reported vulnerabilities are remotely exploitables.
  • 45 reported vulnerabilities are related to weaknesses in OWASP Top Ten.
  • 130 reported vulnerabilities are exploitable by an anonymous user.
  • Campcodes has the most reported vulnerabilities, with 43 reported vulnerabilities.
  • Tenda has the most reported critical vulnerabilities, with 16 reported vulnerabilities.

TOTAL
VULNERABILITIES
CRITICAL RISK
VULNERABILITIES
HIGH RISK
VULNERABILITIES
MEDIUM RISK
VULNERABILITIES
LOW RISK
VULNERABILITIES
REMOTELY
EXPLOITABLE
LOCALLY
EXPLOITABLE
EXPLOIT
AVAILABLE
EXPLOITABLE
ANONYMOUSLY
AFFECTING
WEB APPLICATION

Vulnerability Details

The following table list reported vulnerabilities for the period covered by this report:

Expand/Hide

54 Critical Vulnerabilities

DATE CVE VENDOR VULNERABILITY CVSS
2024-03-24 CVE-2024-2856 Tenda Unspecified vulnerability in Tenda Ac10 Firmware 16.03.10.13/16.03.10.20

A vulnerability, which was classified as critical, has been found in Tenda AC10 16.03.10.13/16.03.10.20.

9.8
2024-03-24 CVE-2024-2854 Tenda Unspecified vulnerability in Tenda Ac18 Firmware 15.03.05.05

A vulnerability classified as critical has been found in Tenda AC18 15.03.05.05.

9.8
2024-03-24 CVE-2024-2855 Tenda Unspecified vulnerability in Tenda Ac15 Firmware 15.03.05.18/15.03.05.19/15.03.20Multi

A vulnerability classified as critical was found in Tenda AC15 15.03.05.18/15.03.05.19/15.03.20.

9.8
2024-03-24 CVE-2024-2852 Tenda Unspecified vulnerability in Tenda Ac15 Firmware 15.03.20Multi

A vulnerability was found in Tenda AC15 15.03.20_multi.

9.8
2024-03-24 CVE-2024-2853 Tenda Unspecified vulnerability in Tenda Ac10U Firmware 15.03.06.48/15.03.06.49

A vulnerability was found in Tenda AC10U 15.03.06.48/15.03.06.49.

9.8
2024-03-24 CVE-2024-2851 Tenda Unspecified vulnerability in Tenda Ac15 Firmware 15.03.05.18/15.03.20Multi

A vulnerability was found in Tenda AC15 15.03.05.18/15.03.20_multi.

9.8
2024-03-24 CVE-2024-2850 Tenda Unspecified vulnerability in Tenda Ac15 Firmware 15.03.05.18

A vulnerability was found in Tenda AC15 15.03.05.18 and classified as critical.

9.8
2024-03-23 CVE-2024-2849 Ganeshrkt Unspecified vulnerability in Ganeshrkt Simple File Manager web APP 1.0

A vulnerability classified as critical was found in SourceCodester Simple File Manager 1.0.

9.8
2024-03-22 CVE-2024-2815 Tenda Unspecified vulnerability in Tenda Ac15 Firmware 15.03.05.20Multi

A vulnerability classified as critical has been found in Tenda AC15 15.03.20_multi.

9.8
2024-03-22 CVE-2024-2813 Tenda Unspecified vulnerability in Tenda Ac15 Firmware 15.03.05.20Multi

A vulnerability was found in Tenda AC15 15.03.20_multi.

9.8
2024-03-22 CVE-2024-2814 Tenda Unspecified vulnerability in Tenda Ac15 Firmware 15.03.05.20Multi

A vulnerability was found in Tenda AC15 15.03.20_multi.

9.8
2024-03-22 CVE-2024-2809 Tenda Unspecified vulnerability in Tenda Ac15 Firmware 15.03.05.18/15.03.05.20Multi

A vulnerability, which was classified as critical, was found in Tenda AC15 15.03.05.18/15.03.20_multi.

9.8
2024-03-22 CVE-2024-2810 Tenda Unspecified vulnerability in Tenda Ac15 Firmware 15.03.05.18/15.03.05.20Multi

A vulnerability has been found in Tenda AC15 15.03.05.18/15.03.20_multi and classified as critical.

9.8
2024-03-22 CVE-2024-2811 Tenda Unspecified vulnerability in Tenda Ac15 Firmware 15.03.05.20Multi

A vulnerability was found in Tenda AC15 15.03.20_multi and classified as critical.

9.8
2024-03-22 CVE-2024-2806 Tenda Unspecified vulnerability in Tenda Ac15 Firmware 15.03.05.18/15.03.05.20Multi

A vulnerability classified as critical has been found in Tenda AC15 15.03.05.18/15.03.20_multi.

9.8
2024-03-22 CVE-2024-2807 Tenda Unspecified vulnerability in Tenda Ac15 Firmware 15.03.05.18/15.03.05.20Multi

A vulnerability classified as critical was found in Tenda AC15 15.03.05.18/15.03.20_multi.

9.8
2024-03-22 CVE-2024-2808 Tenda Unspecified vulnerability in Tenda Ac15 Firmware 15.03.05.18/15.03.05.20Multi

A vulnerability, which was classified as critical, has been found in Tenda AC15 15.03.05.18/15.03.20_multi.

9.8
2024-03-21 CVE-2024-27956 Valvepress Unspecified vulnerability in Valvepress Automatic

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ValvePress Automatic allows SQL Injection.This issue affects Automatic: from n/a through 3.92.0.

9.8
2024-03-21 CVE-2024-29870 Sapplica Unspecified vulnerability in Sapplica Sentrifugo 3.2

SQL injection vulnerability in Sentrifugo 3.2, through /sentrifugo/index.php/index/getdepartments/format/html, 'business_id' parameter./sentrifugo/index.php/index/getdepartments/format/html, 'business_id' parameter.

9.8
2024-03-21 CVE-2024-29871 Sapplica Unspecified vulnerability in Sapplica Sentrifugo 3.2

SQL injection vulnerability in Sentrifugo 3.2, through /sentrifugo/index.php/index/getdepartments/sentrifugo/index.php/index/updatecontactnumber, 'id' parameter.

9.8
2024-03-21 CVE-2024-29872 Sapplica Unspecified vulnerability in Sapplica Sentrifugo 3.2

SQL injection vulnerability in Sentrifugo 3.2, through /sentrifugo/index.php/empscreening/add, 'agencyids' parameter.

9.8
2024-03-21 CVE-2024-29873 Sapplica Unspecified vulnerability in Sapplica Sentrifugo 3.2

SQL injection vulnerability in Sentrifugo 3.2, through /sentrifugo/index.php/reports/businessunits/format/html, 'bunitname' parameter.

9.8
2024-03-21 CVE-2024-29874 Sapplica Unspecified vulnerability in Sapplica Sentrifugo 3.2

SQL injection vulnerability in Sentrifugo 3.2, through /sentrifugo/index.php/default/reports/activeuserrptpdf, 'sort_name' parameter.

9.8
2024-03-21 CVE-2024-29875 Sapplica Unspecified vulnerability in Sapplica Sentrifugo 3.2

SQL injection vulnerability in Sentrifugo 3.2, through  /sentrifugo/index.php/default/reports/exportactiveuserrpt, 'sort_name' parameter.

9.8
2024-03-21 CVE-2024-29876 Sapplica Unspecified vulnerability in Sapplica Sentrifugo 3.2

SQL injection vulnerability in Sentrifugo 3.2, through  /sentrifugo/index.php/reports/activitylogreport, 'sortby' parameter.

9.8
2024-03-21 CVE-2024-29859 Misp Unrestricted Upload of File with Dangerous Type vulnerability in Misp

In MISP before 2.4.187, add_misp_export in app/Controller/EventsController.php does not properly check for a valid file upload.

9.8
2024-03-21 CVE-2023-35899 IBM Unspecified vulnerability in IBM Cloud PAK for Business Automation

IBM Cloud Pak for Automation 18.0.0, 18.0.1, 18.0.2, 19.0.1, 19.0.2, 19.0.3, 20.0.1, 20.0.2, 20.0.3, 21.0.1, 21.0.2, 21.0.3, 22.0.1, and 22.0.2 is potentially vulnerable to CSV Injection.

9.8
2024-03-21 CVE-2022-4963 Folio Unspecified vulnerability in Folio Spring Module Core

A vulnerability was found in Folio Spring Module Core up to 1.1.5.

9.8
2024-03-20 CVE-2024-28179 Jupyter Missing Authentication for Critical Function vulnerability in Jupyter Server Proxy

Jupyter Server Proxy allows users to run arbitrary external processes alongside their Jupyter notebook servers and provides authenticated web access.

9.8
2024-03-20 CVE-2024-2690 Razormist Unspecified vulnerability in Razormist Online Discussion Forum Site 1.0

A vulnerability was found in SourceCodester Online Discussion Forum Site 1.0.

9.8
2024-03-20 CVE-2024-2649 Netentsec Unspecified vulnerability in Netentsec Application Security Gateway 6.3

A vulnerability has been found in Netentsec NS-ASG Application Security Gateway 6.3 and classified as critical.

9.8
2024-03-19 CVE-2024-2646 Netentsec Unspecified vulnerability in Netentsec Application Security Gateway 6.3

A vulnerability classified as critical was found in Netentsec NS-ASG Application Security Gateway 6.3.

9.8
2024-03-19 CVE-2024-2647 Netentsec Unspecified vulnerability in Netentsec Application Security Gateway 6.3

A vulnerability, which was classified as critical, has been found in Netentsec NS-ASG Application Security Gateway 6.3.

9.8
2024-03-19 CVE-2024-2644 Netentsec Unspecified vulnerability in Netentsec Application Security Gateway 6.3

A vulnerability was found in Netentsec NS-ASG Application Security Gateway 6.3.

9.8
2024-03-19 CVE-2024-2615 Mozilla Out-of-bounds Write vulnerability in Mozilla Firefox

Memory safety bugs present in Firefox 123.

9.8
2024-03-19 CVE-2024-2622 Kelixin Communication Command AND Dispatch Project Unspecified vulnerability in Kelixin Communication Command and Dispatch Project Kelixin Communication Command and Dispatch

A vulnerability was found in Fujian Kelixin Communication Command and Dispatch Platform up to 20240318.

9.8
2024-03-19 CVE-2024-2620 Kelixin Communication Command AND Dispatch Project Unspecified vulnerability in Kelixin Communication Command and Dispatch Project Kelixin Communication Command and Dispatch

A vulnerability has been found in Fujian Kelixin Communication Command and Dispatch Platform up to 20240318 and classified as critical.

9.8
2024-03-19 CVE-2024-2621 Kelixin Communication Command AND Dispatch Project Unspecified vulnerability in Kelixin Communication Command and Dispatch Project Kelixin Communication Command and Dispatch

A vulnerability was found in Fujian Kelixin Communication Command and Dispatch Platform up to 20240318 and classified as critical.

9.8
2024-03-18 CVE-2024-2604 Remyandrade Unspecified vulnerability in Remyandrade File Manager APP 1.0

A vulnerability was found in SourceCodester File Manager App 1.0.

9.8
2024-03-18 CVE-2024-21652 Argoproj Improper Restriction of Excessive Authentication Attempts vulnerability in Argoproj Argo CD

Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes.

9.8
2024-03-18 CVE-2024-27767 Unitronics Unspecified vulnerability in Unitronics Unilogic

CWE-287: Improper Authentication may allow Authentication Bypass

9.8
2024-03-18 CVE-2024-27768 Unitronics Unspecified vulnerability in Unitronics Unilogic

Unitronics Unistream Unilogic – Versions prior to 1.35.227 - CWE-22: 'Path Traversal' may allow RCE

9.8
2024-03-18 CVE-2024-2577 Oretnom23 Unspecified vulnerability in Oretnom23 Employee Task Management System 1.0

A vulnerability has been found in SourceCodester Employee Task Management System 1.0 and classified as critical.

9.8
2024-03-18 CVE-2024-2574 Oretnom23 Unspecified vulnerability in Oretnom23 Employee Task Management System 1.0

A vulnerability classified as critical was found in SourceCodester Employee Task Management System 1.0.

9.8
2024-03-18 CVE-2024-2575 Oretnom23 Unspecified vulnerability in Oretnom23 Employee Task Management System 1.0

A vulnerability, which was classified as critical, has been found in SourceCodester Employee Task Management System 1.0.

9.8
2024-03-18 CVE-2024-2576 Oretnom23 Unspecified vulnerability in Oretnom23 Employee Task Management System 1.0

A vulnerability, which was classified as critical, was found in SourceCodester Employee Task Management System 1.0.

9.8
2024-03-18 CVE-2024-2571 Oretnom23 Unspecified vulnerability in Oretnom23 Employee Task Management System 1.0

A vulnerability was found in SourceCodester Employee Task Management System 1.0.

9.8
2024-03-18 CVE-2024-2572 Oretnom23 Unspecified vulnerability in Oretnom23 Employee Task Management System 1.0

A vulnerability was found in SourceCodester Employee Task Management System 1.0.

9.8
2024-03-18 CVE-2024-2573 Oretnom23 Unspecified vulnerability in Oretnom23 Employee Task Management System 1.0

A vulnerability classified as critical has been found in SourceCodester Employee Task Management System 1.0.

9.8
2024-03-18 CVE-2024-2570 Oretnom23 Unspecified vulnerability in Oretnom23 Employee Task Management System 1.0

A vulnerability was found in SourceCodester Employee Task Management System 1.0.

9.8
2024-03-18 CVE-2024-27098 Glpi Project Server-Side Request Forgery (SSRF) vulnerability in Glpi-Project Glpi

GLPI is a Free Asset and IT Management Software package, Data center management, ITIL Service Desk, licenses tracking and software auditing.

9.6
2024-03-21 CVE-2020-26942 Axigen Unspecified vulnerability in Axigen Mail Server

An issue discovered in Axigen Mail Server 10.3.x before 10.3.1.27 and 10.3.2.x before 10.3.3.1 allows unauthenticated attackers to submit a setAdminPassword operation request, subsequently setting a new arbitrary password for the admin account.

9.1
2024-03-18 CVE-2024-21662 Argoproj Improper Restriction of Excessive Authentication Attempts vulnerability in Argoproj Argo CD

Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes.

9.1
2024-03-22 CVE-2024-29185 Freescout OS Command Injection vulnerability in Freescout

FreeScout is a self-hosted help desk and shared mailbox.

9.0

68 High Vulnerabilities

DATE CVE VENDOR VULNERABILITY CVSS
2024-03-22 CVE-2024-2448 Progress OS Command Injection vulnerability in Progress Loadmaster 7.1.35.10/7.2.48.10

An OS command injection vulnerability has been identified in LoadMaster.  An authenticated UI user with any permission settings may be able to inject commands into a UI component using a shell command resulting in OS command injection.

8.8
2024-03-22 CVE-2024-2812 Tenda Unspecified vulnerability in Tenda Ac15 Firmware 15.03.05.18/15.03.05.20Multi

A vulnerability was found in Tenda AC15 15.03.05.18/15.03.20_multi.

8.8
2024-03-22 CVE-2024-2805 Tenda Out-of-bounds Write vulnerability in Tenda Ac15 Firmware 15.03.05.18/15.03.05.20Multi

A vulnerability was found in Tenda AC15 15.03.05.18/15.03.20_multi.

8.8
2024-03-21 CVE-2024-25937 Deltaww Unspecified vulnerability in Deltaww Diaenergie

SQL injection vulnerability exists in the script DIAE_tagHandler.ashx.

8.8
2024-03-21 CVE-2024-27921 Getgrav Path Traversal vulnerability in Getgrav Grav

Grav is an open-source, flat-file content management system.

8.8
2024-03-21 CVE-2024-28029 Deltaww Unspecified vulnerability in Deltaww Diaenergie

Privileges are not fully verified server-side, which can be abused by a user with limited privileges to bypass authorization and access privileged functionality.

8.8
2024-03-21 CVE-2024-28116 Getgrav Code Injection vulnerability in Getgrav Grav

Grav is an open-source, flat-file content management system.

8.8
2024-03-21 CVE-2024-28117 Getgrav Code Injection vulnerability in Getgrav Grav

Grav is an open-source, flat-file content management system.

8.8
2024-03-21 CVE-2024-28118 Getgrav Code Injection vulnerability in Getgrav Grav

Grav is an open-source, flat-file content management system.

8.8
2024-03-21 CVE-2024-28119 Getgrav Code Injection vulnerability in Getgrav Grav

Grav is an open-source, flat-file content management system.

8.8
2024-03-21 CVE-2024-2763 Tenda Out-of-bounds Write vulnerability in Tenda Ac10U Firmware 15.03.06.48

A vulnerability, which was classified as critical, has been found in Tenda AC10U 15.03.06.48.

8.8
2024-03-21 CVE-2024-2764 Tenda Out-of-bounds Write vulnerability in Tenda Ac10U Firmware 15.03.06.48

A vulnerability, which was classified as critical, was found in Tenda AC10U 15.03.06.48.

8.8
2024-03-21 CVE-2024-27190 Jeandaviddaviet Unspecified vulnerability in Jeandaviddaviet Download Media

Missing Authorization vulnerability in Jean-David Daviet Download Media.This issue affects Download Media: from n/a through 1.4.2.

8.8
2024-03-21 CVE-2024-27964 Gesundheit Bewegt Unspecified vulnerability in Gesundheit-Bewegt Zippy

Unrestricted Upload of File with Dangerous Type vulnerability in Gesundheit Bewegt GmbH Zippy.This issue affects Zippy: from n/a through 1.6.9.

8.8
2024-03-21 CVE-2024-2754 Donbermoy Unspecified vulnerability in Donbermoy Complete E-Commerce Site 1.0

A vulnerability classified as critical has been found in SourceCodester Complete E-Commerce Site 1.0.

8.8
2024-03-21 CVE-2024-27923 Getgrav Unrestricted Upload of File with Dangerous Type vulnerability in Getgrav Grav

Grav is a content management system (CMS).

8.8
2024-03-21 CVE-2024-27933 Deno Incorrect Authorization vulnerability in Deno 1.39.0

Deno is a JavaScript, TypeScript, and WebAssembly runtime.

8.8
2024-03-21 CVE-2024-27934 Deno Use After Free vulnerability in Deno

Deno is a JavaScript, TypeScript, and WebAssembly runtime.

8.8
2024-03-21 CVE-2023-49978 Oretnom23 Unspecified vulnerability in Oretnom23 Customer Support System 1.0

Incorrect access control in Customer Support System v1 allows non-administrator users to access administrative pages and execute actions reserved for administrators.

8.8
2024-03-20 CVE-2024-2708 Tenda Out-of-bounds Write vulnerability in Tenda Ac10U Firmware 15.03.06.49

A vulnerability was found in Tenda AC10U 15.03.06.49 and classified as critical.

8.8
2024-03-20 CVE-2024-2709 Tenda Out-of-bounds Write vulnerability in Tenda Ac10U Firmware 15.03.06.49

A vulnerability was found in Tenda AC10U 15.03.06.49.

8.8
2024-03-20 CVE-2024-2710 Tenda Out-of-bounds Write vulnerability in Tenda Ac10U Firmware 15.03.06.49

A vulnerability was found in Tenda AC10U 15.03.06.49.

8.8
2024-03-20 CVE-2024-2711 Tenda Out-of-bounds Write vulnerability in Tenda Ac10U Firmware 15.03.06.48

A vulnerability was found in Tenda AC10U 15.03.06.48.

8.8
2024-03-20 CVE-2024-2625 Google
Fedoraproject
Object lifecycle issue in V8 in Google Chrome prior to 123.0.6312.58 allowed a remote attacker to potentially exploit object corruption via a crafted HTML page.
8.8
2024-03-20 CVE-2024-2627 Google
Fedoraproject
Use After Free vulnerability in multiple products

Use after free in Canvas in Google Chrome prior to 123.0.6312.58 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

8.8
2024-03-20 CVE-2024-2705 Tenda Out-of-bounds Write vulnerability in Tenda Ac10U Firmware 15.03.06.49

A vulnerability, which was classified as critical, has been found in Tenda AC10U 1.0/15.03.06.49.

8.8
2024-03-20 CVE-2024-2706 Tenda Out-of-bounds Write vulnerability in Tenda Ac10U Firmware 15.03.06.49

A vulnerability, which was classified as critical, was found in Tenda AC10U 15.03.06.49.

8.8
2024-03-20 CVE-2024-2707 Tenda Unspecified vulnerability in Tenda Ac10U Firmware 15.03.06.49

A vulnerability has been found in Tenda AC10U 15.03.06.49 and classified as critical.

8.8
2024-03-20 CVE-2024-2703 Tenda Out-of-bounds Write vulnerability in Tenda Ac10U Firmware 15.03.06.49

A vulnerability classified as critical has been found in Tenda AC10U 15.03.06.49.

8.8
2024-03-20 CVE-2024-2704 Tenda Out-of-bounds Write vulnerability in Tenda Ac10U Firmware 15.03.06.49

A vulnerability classified as critical was found in Tenda AC10U 15.03.06.49.

8.8
2024-03-20 CVE-2024-1800 Progress Deserialization of Untrusted Data vulnerability in Progress Telerik Report Server

In Progress® Telerik® Report Server versions prior to 2024 Q1 (10.0.24.130), a remote code execution attack is possible through an insecure deserialization vulnerability.

8.8
2024-03-20 CVE-2024-1856 Progress Deserialization of Untrusted Data vulnerability in Progress Telerik Reporting

In Progress® Telerik® Reporting versions prior to 2024 Q1 (18.0.24.130), a code execution attack is possible by a remote threat actor through an insecure deserialization vulnerability.

8.8
2024-03-19 CVE-2024-21677 Atlassian Path Traversal vulnerability in Atlassian Confluence Data Center and Confluence Server

This High severity Path Traversal vulnerability was introduced in version 6.13.0 of Confluence Data Center.

8.8
2024-03-19 CVE-2024-29135 Themefic Unspecified vulnerability in Themefic Tourfic

Unrestricted Upload of File with Dangerous Type vulnerability in Tourfic.This issue affects Tourfic: from n/a through 2.11.15.

8.8
2024-03-19 CVE-2024-29136 Themefic Unspecified vulnerability in Themefic Tourfic

Deserialization of Untrusted Data vulnerability in Themefic Tourfic.This issue affects Tourfic: from n/a through 2.11.17.

8.8
2024-03-19 CVE-2024-2614 Mozilla
Debian
Out-of-bounds Write vulnerability in multiple products

Memory safety bugs present in Firefox 123, Firefox ESR 115.8, and Thunderbird 115.8.

8.8
2024-03-18 CVE-2024-0780 Mediabetaprojects Missing Authorization vulnerability in Mediabetaprojects Enjoy Social Feed

The Enjoy Social Feed plugin for WordPress website WordPress plugin through 6.2.2 does not have authorisation when resetting its database, allowing any authenticated users, such as subscriber to perform such action

8.8
2024-03-18 CVE-2024-27769 Unitronics Unspecified vulnerability in Unitronics Unilogic

Unitronics Unistream Unilogic – Versions prior to 1.35.227 - CWE-200: Exposure of Sensitive Information to an Unauthorized Actor may allow Taking Ownership Over Devices

8.8
2024-03-18 CVE-2024-27770 Unitronics Path Traversal vulnerability in Unitronics Unilogic

Unitronics Unistream Unilogic – Versions prior to 1.35.227 - CWE-23: Relative Path Traversal

8.8
2024-03-18 CVE-2024-27771 Unitronics Unspecified vulnerability in Unitronics Unilogic

Unitronics Unistream Unilogic – Versions prior to 1.35.227 - CWE-22: 'Path Traversal' may allow RCE

8.8
2024-03-18 CVE-2024-27772 Unitronics Unspecified vulnerability in Unitronics Unilogic

Unitronics Unistream Unilogic – Versions prior to 1.35.227 - CWE-78: 'OS Command Injection' may allow RCE

8.8
2024-03-18 CVE-2024-27773 Unitronics Insufficient Verification of Data Authenticity vulnerability in Unitronics Unilogic

Unitronics Unistream Unilogic – Versions prior to 1.35.227 - CWE-348: Use of Less Trusted Source may allow RCE

8.8
2024-03-18 CVE-2024-2581 Tenda Out-of-bounds Write vulnerability in Tenda Ac10 Firmware 16.03.10.13

A vulnerability was found in Tenda AC10 16.03.10.13 and classified as critical.

8.8
2024-03-21 CVE-2024-27935 Deno Unspecified vulnerability in Deno

Deno is a JavaScript, TypeScript, and WebAssembly runtime.

8.3
2024-03-22 CVE-2024-29184 Freescout Cross-site Scripting vulnerability in Freescout

FreeScout is a self-hosted help desk and shared mailbox.

8.0
2024-03-22 CVE-2024-28824 Checkmk Unspecified vulnerability in Checkmk

Least privilege violation and reliance on untrusted inputs in the mk_informix Checkmk agent plugin before Checkmk 2.3.0b4 (beta), 2.2.0p24, 2.1.0p41 and 2.0.0 (EOL) allows local users to escalate privileges.

7.8
2024-03-21 CVE-2024-29880 Jetbrains Unspecified vulnerability in Jetbrains Teamcity

In JetBrains TeamCity before 2023.11 users with access to the agent machine might obtain permissions of the user running the agent process

7.8
2024-03-20 CVE-2024-1801 Progress Deserialization of Untrusted Data vulnerability in Progress Telerik Reporting

In Progress® Telerik® Reporting versions prior to 2024 Q1 (18.0.24.130), a code execution attack is possible by a local threat actor through an insecure deserialization vulnerability.

7.8
2024-03-19 CVE-2023-42920 Claris Unspecified vulnerability in Claris PRO and Filemaker PRO

Claris International has fixed a dylib hijacking vulnerability in the FileMaker Pro.app and Claris Pro.app versions on macOS.

7.8
2024-03-18 CVE-2024-20754 Adobe Unspecified vulnerability in Adobe Lightroom 5.1

Lightroom Desktop versions 7.1.2 and earlier are affected by an Untrusted Search Path vulnerability that could result in arbitrary code execution in the context of the current user.

7.8
2024-03-18 CVE-2023-52612 Linux
Debian
Classic Buffer Overflow vulnerability in multiple products

In the Linux kernel, the following vulnerability has been resolved: crypto: scomp - fix req->dst buffer overflow The req->dst buffer size should be checked before copying from the scomp_scratch->dst to avoid req->dst buffer overflow problem.

7.8
2024-03-18 CVE-2023-52614 Linux Classic Buffer Overflow vulnerability in Linux Kernel

In the Linux kernel, the following vulnerability has been resolved: PM / devfreq: Fix buffer overflow in trans_stat_show Fix buffer overflow in trans_stat_show(). Convert simple snprintf to the more secure scnprintf with size of PAGE_SIZE. Add condition checking if we are exceeding PAGE_SIZE and exit early from loop.

7.8
2024-03-18 CVE-2024-1605 BMC Incorrect Default Permissions vulnerability in BMC Control-M

BMC Control-M branches 9.0.20 and 9.0.21 upon user login load all Dynamic Link Libraries (DLL) from a directory that grants Write and Read permissions to all users.

7.8
2024-03-23 CVE-2024-1603 Paddlepaddle Unspecified vulnerability in Paddlepaddle 2.6.0

paddlepaddle/paddle 2.6.0 allows arbitrary file read via paddle.vision.ops.read_file.

7.5
2024-03-23 CVE-2024-24832 Metagauss Unspecified vulnerability in Metagauss Eventprime

Missing Authorization vulnerability in Metagauss EventPrime.This issue affects EventPrime: from n/a through 3.3.9.

7.5
2024-03-23 CVE-2024-29059 Microsoft Information Exposure Through an Error Message vulnerability in Microsoft .Net Framework

.NET Framework Information Disclosure Vulnerability

7.5
2024-03-22 CVE-2024-2449 Progress Cross-Site Request Forgery (CSRF) vulnerability in Progress Loadmaster 7.1.35.10/7.2.48.10

A cross-site request forgery vulnerability has been identified in LoadMaster.  It is possible for a malicious actor, who has prior knowledge of the IP or hostname of a specific LoadMaster, to direct an authenticated LoadMaster administrator to a third-party site.

7.5
2024-03-21 CVE-2023-49979 Mayurik Missing Authorization vulnerability in Mayurik Best Student Management System 1.0

A directory listing vulnerability in Customer Support System v1 allows attackers to list directories and sensitive files within the application without requiring authorization.

7.5
2024-03-21 CVE-2023-49980 Mayurik Missing Authorization vulnerability in Mayurik Best Student Result Management System 1.0

A directory listing vulnerability in Best Student Result Management System v1.0 allows attackers to list directories and sensitive files within the application without requiring authorization.

7.5
2024-03-21 CVE-2023-49981 Oretnom23 Missing Authorization vulnerability in Oretnom23 School Fees Management System 1.0

A directory listing vulnerability in School Fees Management System v1.0 allows attackers to list directories and sensitive files within the application without requiring authorization.

7.5
2024-03-19 CVE-2024-2613 Mozilla Improper Restriction of Rendered UI Layers or Frames vulnerability in Mozilla Firefox

Data was not properly sanitized when decoding a QUIC ACK frame; this could have led to unrestricted memory consumption and a crash.

7.5
2024-03-18 CVE-2024-21661 Argoproj Unspecified vulnerability in Argoproj Argo CD

Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes.

7.5
2024-03-18 CVE-2022-47037 Siklu Insufficiently Protected Credentials vulnerability in Siklu TG Firmware

Siklu TG Terragraph devices before 2.1.1 allow attackers to discover valid, randomly generated credentials via GetCredentials.

7.5
2024-03-18 CVE-2023-52159 Bizdelnick
Debian
Out-of-bounds Write vulnerability in multiple products

A stack-based buffer overflow vulnerability in gross 0.9.3 through 1.x before 1.0.4 allows remote attackers to trigger a denial of service (grossd daemon crash) or potentially execute arbitrary code in grossd via crafted SMTP transaction parameters that cause an incorrect strncat for a log entry.

7.5
2024-03-18 CVE-2024-20767 Adobe Unspecified vulnerability in Adobe Coldfusion 2021/2023

ColdFusion versions 2023.6, 2021.12 and earlier are affected by an Improper Access Control vulnerability that could result in arbitrary file system read.

7.4
2024-03-20 CVE-2023-41877 Geoserver Path Traversal vulnerability in Geoserver

GeoServer is an open source software server written in Java that allows users to share and edit geospatial data.

7.2
2024-03-20 CVE-2023-51444 Geoserver Unrestricted Upload of File with Dangerous Type vulnerability in Geoserver

GeoServer is an open source software server written in Java that allows users to share and edit geospatial data.

7.2
2024-03-18 CVE-2024-28248 Cilium Unspecified vulnerability in Cilium

Cilium is a networking, observability, and security solution with an eBPF-based dataplane.

7.2

156 Medium Vulnerabilities

DATE CVE VENDOR VULNERABILITY CVSS
2024-03-19 CVE-2024-25942 Dell Out-of-bounds Write vulnerability in Dell products

Dell PowerEdge Server BIOS contains an Improper SMM communication buffer verification vulnerability.

6.8
2024-03-18 CVE-2024-1604 BMC Authorization Bypass Through User-Controlled Key vulnerability in BMC Control-M

Improper authorization in the report management and creation module of BMC Control-M branches 9.0.20 and 9.0.21 allows logged-in users to read and make unauthorized changes to any reports available within the application, even without proper permissions.

6.8
2024-03-22 CVE-2024-0638 Checkmk Unspecified vulnerability in Checkmk

Least privilege violation in the Checkmk agent plugins mk_oracle, mk_oracle.ps1, and mk_oracle_crs before Checkmk 2.3.0b4 (beta), 2.2.0p24, 2.1.0p41 and 2.0.0 (EOL) allows local users to escalate privileges.

6.7
2024-03-22 CVE-2022-32753 IBM Unspecified vulnerability in IBM Security Verify Directory 10.0.0

IBM Security Verify Directory 10.0.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information.

6.5
2024-03-22 CVE-2024-2816 Tenda Unspecified vulnerability in Tenda Ac15 Firmware 15.03.05.18

A vulnerability classified as problematic was found in Tenda AC15 15.03.05.18.

6.5
2024-03-22 CVE-2024-2817 Tenda Unspecified vulnerability in Tenda Ac15 Firmware 15.03.05.18

A vulnerability, which was classified as problematic, has been found in Tenda AC15 15.03.05.18.

6.5
2024-03-22 CVE-2024-2776 Campcodes Unspecified vulnerability in Campcodes Online Marriage Registration System 1.0

A vulnerability, which was classified as critical, was found in Campcodes Online Marriage Registration System 1.0.

6.5
2024-03-22 CVE-2024-2777 Campcodes Unspecified vulnerability in Campcodes Online Marriage Registration System 1.0

A vulnerability has been found in Campcodes Online Marriage Registration System 1.0 and classified as critical.

6.5
2024-03-21 CVE-2024-2770 Campcodes Unspecified vulnerability in Campcodes Complete Online Beauty Parlor Management System 1.0

A vulnerability was found in Campcodes Complete Online Beauty Parlor Management System 1.0.

6.5
2024-03-21 CVE-2024-2774 Campcodes Unspecified vulnerability in Campcodes Online Marriage Registration System 1.0

A vulnerability classified as critical was found in Campcodes Online Marriage Registration System 1.0.

6.5
2024-03-21 CVE-2024-2768 Campcodes Unspecified vulnerability in Campcodes Complete Online Beauty Parlor Management System 1.0

A vulnerability was found in Campcodes Complete Online Beauty Parlor Management System 1.0.

6.5
2024-03-21 CVE-2024-2769 Campcodes Unspecified vulnerability in Campcodes Complete Online Beauty Parlor Management System 1.0

A vulnerability was found in Campcodes Complete Online Beauty Parlor Management System 1.0.

6.5
2024-03-21 CVE-2024-2766 Campcodes Unspecified vulnerability in Campcodes Complete Online Beauty Parlor Management System 1.0

A vulnerability has been found in Campcodes Complete Online Beauty Parlor Management System 1.0 and classified as critical.

6.5
2024-03-21 CVE-2024-2767 Campcodes Unspecified vulnerability in Campcodes Complete Online Beauty Parlor Management System 1.0

A vulnerability was found in Campcodes Complete Online Beauty Parlor Management System 1.0 and classified as critical.

6.5
2024-03-21 CVE-2024-27936 Deno Unspecified vulnerability in Deno and Deno Runtime

Deno is a JavaScript, TypeScript, and WebAssembly runtime with secure defaults.

6.5
2024-03-21 CVE-2024-2712 Campcodes Unspecified vulnerability in Campcodes Complete Online DJ Booking System 1.0

A vulnerability, which was classified as critical, has been found in Campcodes Complete Online DJ Booking System 1.0.

6.5
2024-03-21 CVE-2024-2713 Campcodes Unspecified vulnerability in Campcodes Complete Online DJ Booking System 1.0

A vulnerability, which was classified as critical, was found in Campcodes Complete Online DJ Booking System 1.0.

6.5
2024-03-21 CVE-2023-38825 Vanderbilt SQL Injection vulnerability in Vanderbilt Redcap

SQL injection vulnerability in Vanderbilt REDCap before v.13.8.0 allows a remote attacker to obtain sensitive information via the password reset mechanism in MyCapMobileApp/update.php.

6.5
2024-03-20 CVE-2024-2714 Campcodes Unspecified vulnerability in Campcodes Complete Online DJ Booking System 1.0

A vulnerability has been found in Campcodes Complete Online DJ Booking System 1.0 and classified as critical.

6.5
2024-03-20 CVE-2024-2626 Google
Fedoraproject
Out-of-bounds Read vulnerability in multiple products

Out of bounds read in Swiftshader in Google Chrome prior to 123.0.6312.58 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page.

6.5
2024-03-20 CVE-2024-2630 Google
Fedoraproject
Inappropriate implementation in iOS in Google Chrome prior to 123.0.6312.58 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
6.5
2024-03-20 CVE-2024-2687 Campcodes Unspecified vulnerability in Campcodes Online JOB Finder System 1.0

A vulnerability was found in Campcodes Online Job Finder System 1.0 and classified as critical.

6.5
2024-03-20 CVE-2024-2677 Campcodes Unspecified vulnerability in Campcodes Online JOB Finder System 1.0

A vulnerability has been found in Campcodes Online Job Finder System 1.0 and classified as critical.

6.5
2024-03-20 CVE-2024-2678 Campcodes Unspecified vulnerability in Campcodes Online JOB Finder System 1.0

A vulnerability was found in Campcodes Online Job Finder System 1.0 and classified as critical.

6.5
2024-03-20 CVE-2024-2674 Campcodes Unspecified vulnerability in Campcodes Online JOB Finder System 1.0

A vulnerability classified as critical was found in Campcodes Online Job Finder System 1.0.

6.5
2024-03-20 CVE-2024-2675 Campcodes Unspecified vulnerability in Campcodes Online JOB Finder System 1.0

A vulnerability, which was classified as critical, has been found in Campcodes Online Job Finder System 1.0.

6.5
2024-03-20 CVE-2024-2676 Campcodes Unspecified vulnerability in Campcodes Online JOB Finder System 1.0

A vulnerability, which was classified as critical, was found in Campcodes Online Job Finder System 1.0.

6.5
2024-03-20 CVE-2024-2672 Campcodes Unspecified vulnerability in Campcodes Online JOB Finder System 1.0

A vulnerability was found in Campcodes Online Job Finder System 1.0.

6.5
2024-03-20 CVE-2024-2673 Campcodes Unspecified vulnerability in Campcodes Online JOB Finder System 1.0

A vulnerability classified as critical has been found in Campcodes Online Job Finder System 1.0.

6.5
2024-03-20 CVE-2024-2670 Campcodes Unspecified vulnerability in Campcodes Online JOB Finder System 1.0

A vulnerability was found in Campcodes Online Job Finder System 1.0.

6.5
2024-03-20 CVE-2024-2671 Campcodes Unspecified vulnerability in Campcodes Online JOB Finder System 1.0

A vulnerability was found in Campcodes Online Job Finder System 1.0.

6.5
2024-03-20 CVE-2024-2668 Campcodes Unspecified vulnerability in Campcodes Online JOB Finder System 1.0

A vulnerability has been found in Campcodes Online Job Finder System 1.0 and classified as critical.

6.5
2024-03-20 CVE-2024-2669 Campcodes Unspecified vulnerability in Campcodes Online JOB Finder System 1.0

A vulnerability was found in Campcodes Online Job Finder System 1.0 and classified as critical.

6.5
2024-03-19 CVE-2023-50811 Seling Unspecified vulnerability in Seling Visual Access Manager 4.38.6

An issue discovered in SELESTA Visual Access Manager 4.38.6 allows attackers to modify the “computer” POST parameter related to the ID of a specific reception by POST HTTP request interception.

6.5
2024-03-18 CVE-2023-6821 Bestwebsoft Missing Authorization vulnerability in Bestwebsoft Error LOG Viewer

The Error Log Viewer by BestWebSoft WordPress plugin before 1.1.3 is affected by a Directory Listing issue, allowing users to read and download PHP logs without authorization

6.5
2024-03-18 CVE-2024-27096 Glpi Project SQL Injection vulnerability in Glpi-Project Glpi

GLPI is a Free Asset and IT Management Software package, Data center management, ITIL Service Desk, licenses tracking and software auditing.

6.5
2024-03-18 CVE-2024-27930 Glpi Project Unspecified vulnerability in Glpi-Project Glpi

GLPI is a Free Asset and IT Management Software package, Data center management, ITIL Service Desk, licenses tracking and software auditing.

6.5
2024-03-18 CVE-2024-27774 Unitronics Use of Hard-coded Credentials vulnerability in Unitronics Unilogic

Unitronics Unistream Unilogic – Versions prior to 1.35.227 - CWE-259: Use of Hard-coded Password may allow disclosing Sensitive Information Embedded inside Device's Firmware

6.5
2024-03-18 CVE-2024-29156 Openstack Unspecified vulnerability in Openstack Murano and Yaql

In OpenStack Murano through 16.0.0, when YAQL before 3.0.0 is used, the Murano service's MuranoPL extension to the YAQL language fails to sanitize the supplied environment, leading to potential leakage of sensitive service account information.

6.5
2024-03-23 CVE-2024-2832 Campcodes Unspecified vulnerability in Campcodes Online Shopping System 1.0

A vulnerability classified as problematic was found in Campcodes Online Shopping System 1.0.

6.1
2024-03-22 CVE-2024-2780 Campcodes Unspecified vulnerability in Campcodes Online Marriage Registration System 1.0

A vulnerability was found in Campcodes Online Marriage Registration System 1.0.

6.1
2024-03-22 CVE-2024-2778 Campcodes Unspecified vulnerability in Campcodes Online Marriage Registration System 1.0

A vulnerability was found in Campcodes Online Marriage Registration System 1.0 and classified as problematic.

6.1
2024-03-21 CVE-2024-2773 Campcodes Unspecified vulnerability in Campcodes Online Marriage Registration System 1.0

A vulnerability classified as problematic has been found in Campcodes Online Marriage Registration System 1.0.

6.1
2024-03-21 CVE-2024-2775 Campcodes Unspecified vulnerability in Campcodes Online Marriage Registration System 1.0

A vulnerability, which was classified as problematic, has been found in Campcodes Online Marriage Registration System 1.0.

6.1
2024-03-21 CVE-2024-27962 Fkrauthan Unspecified vulnerability in Fkrauthan Wp-Mpdf

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Florian 'fkrauthan' Krauthan allows Reflected XSS.This issue affects wp-mpdf: from n/a through 3.7.1.

6.1
2024-03-21 CVE-2024-27968 Optimole Unspecified vulnerability in Optimole Super Page Cache

Cross-Site Request Forgery (CSRF) vulnerability in Optimole Super Page Cache for Cloudflare allows Stored XSS.This issue affects Super Page Cache for Cloudflare: from n/a through 4.7.5.

6.1
2024-03-21 CVE-2024-29877 Sapplica Unspecified vulnerability in Sapplica Sentrifugo 3.2

Cross-Site Scripting (XSS) vulnerability in Sentrifugo 3.2, through  /sentrifugo/index.php/expenses/expensecategories/edit, 'expense_category_name' parameter.

6.1
2024-03-21 CVE-2024-29878 Sapplica Unspecified vulnerability in Sapplica Sentrifugo 3.2

Cross-Site Scripting (XSS) vulnerability in Sentrifugo 3.2, through  /sentrifugo/index.php/sitepreference/add, 'description' parameter.

6.1
2024-03-21 CVE-2024-29879 Sapplica Unspecified vulnerability in Sapplica Sentrifugo 3.2

Cross-Site Scripting (XSS) vulnerability in Sentrifugo 3.2, through  /sentrifugo/index.php/index/getdepartments/format/html, 'business_id' parameter.

6.1
2024-03-20 CVE-2024-2720 Campcodes Unspecified vulnerability in Campcodes Complete Online DJ Booking System 1.0

A vulnerability classified as problematic was found in Campcodes Complete Online DJ Booking System 1.0.

6.1
2024-03-20 CVE-2024-2717 Campcodes Unspecified vulnerability in Campcodes Complete Online DJ Booking System 1.0

A vulnerability was found in Campcodes Complete Online DJ Booking System 1.0.

6.1
2024-03-20 CVE-2024-2718 Campcodes Unspecified vulnerability in Campcodes Complete Online DJ Booking System 1.0

A vulnerability was found in Campcodes Complete Online DJ Booking System 1.0.

6.1
2024-03-20 CVE-2024-2719 Campcodes Unspecified vulnerability in Campcodes Complete Online DJ Booking System 1.0

A vulnerability classified as problematic has been found in Campcodes Complete Online DJ Booking System 1.0.

6.1
2024-03-20 CVE-2024-2715 Campcodes Unspecified vulnerability in Campcodes Complete Online DJ Booking System 1.0

A vulnerability was found in Campcodes Complete Online DJ Booking System 1.0 and classified as problematic.

6.1
2024-03-20 CVE-2024-2716 Campcodes Unspecified vulnerability in Campcodes Complete Online DJ Booking System 1.0

A vulnerability was found in Campcodes Complete Online DJ Booking System 1.0.

6.1
2024-03-20 CVE-2024-2683 Campcodes Unspecified vulnerability in Campcodes Online JOB Finder System 1.0

A vulnerability classified as problematic was found in Campcodes Online Job Finder System 1.0.

6.1
2024-03-20 CVE-2024-2684 Campcodes Unspecified vulnerability in Campcodes Online JOB Finder System 1.0

A vulnerability, which was classified as problematic, has been found in Campcodes Online Job Finder System 1.0.

6.1
2024-03-20 CVE-2024-2685 Campcodes Unspecified vulnerability in Campcodes Online JOB Finder System 1.0

A vulnerability, which was classified as problematic, was found in Campcodes Online Job Finder System 1.0.

6.1
2024-03-20 CVE-2024-2686 Campcodes Unspecified vulnerability in Campcodes Online JOB Finder System 1.0

A vulnerability has been found in Campcodes Online Job Finder System 1.0 and classified as problematic.

6.1
2024-03-20 CVE-2024-2680 Campcodes Unspecified vulnerability in Campcodes Online JOB Finder System 1.0

A vulnerability was found in Campcodes Online Job Finder System 1.0.

6.1
2024-03-20 CVE-2024-2681 Campcodes Unspecified vulnerability in Campcodes Online JOB Finder System 1.0

A vulnerability was found in Campcodes Online Job Finder System 1.0.

6.1
2024-03-20 CVE-2024-2682 Campcodes Unspecified vulnerability in Campcodes Online JOB Finder System 1.0

A vulnerability classified as problematic has been found in Campcodes Online Job Finder System 1.0.

6.1
2024-03-20 CVE-2024-2679 Campcodes Unspecified vulnerability in Campcodes Online JOB Finder System 1.0

A vulnerability was found in Campcodes Online Job Finder System 1.0.

6.1
2024-03-19 CVE-2024-29092 Permalink Manager Lite Project Unspecified vulnerability in Permalink Manager Lite Project Permalink Manager Lite

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Maciej Bis Permalink Manager Lite allows Reflected XSS.This issue affects Permalink Manager Lite: from n/a through 2.4.3.

6.1
2024-03-19 CVE-2024-29099 Evergreencontentposter Unspecified vulnerability in Evergreencontentposter Evergreen Content Poster

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Evergreen Content Poster allows Reflected XSS.This issue affects Evergreen Content Poster: from n/a through 1.4.1.

6.1
2024-03-19 CVE-2024-29113 Metagauss Unspecified vulnerability in Metagauss Registrationmagic

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Metagauss RegistrationMagic allows Reflected XSS.This issue affects RegistrationMagic: from n/a through 5.2.5.9.

6.1
2024-03-19 CVE-2024-29123 Ylefebvre Unspecified vulnerability in Ylefebvre Link Library

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Yannick Lefebvre Link Library allows Reflected XSS.This issue affects Link Library: from n/a through 7.6.

6.1
2024-03-19 CVE-2024-29127 Vasyltech Unspecified vulnerability in Vasyltech Advanced Access Manager

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in AAM Advanced Access Manager allows Reflected XSS.This issue affects Advanced Access Manager: from n/a through 6.9.20.

6.1
2024-03-19 CVE-2024-29128 Wpexperts Unspecified vulnerability in Wpexperts Post Smtp

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Post SMTP POST SMTP allows Reflected XSS.This issue affects POST SMTP: from n/a through 2.8.6.

6.1
2024-03-19 CVE-2024-29130 Wpplugin Unspecified vulnerability in Wpplugin Paypal & Stripe Add-On

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Scott Paterson Contact Form 7 – PayPal & Stripe Add-on allows Reflected XSS.This issue affects Contact Form 7 – PayPal & Stripe Add-on: from n/a through 2.0.

6.1
2024-03-19 CVE-2024-29137 Themefic Unspecified vulnerability in Themefic Tourfic

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themefic Tourfic allows Reflected XSS.This issue affects Tourfic: from n/a through 2.11.7.

6.1
2024-03-19 CVE-2024-29138 DEV Institute Unspecified vulnerability in Dev.Institute Restrict User Access

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in DEV Institute Restrict User Access – Membership Plugin with Force allows Reflected XSS.This issue affects Restrict User Access – Membership Plugin with Force: from n/a through 2.5.

6.1
2024-03-18 CVE-2024-28249 Cilium Cleartext Transmission of Sensitive Information vulnerability in Cilium

Cilium is a networking, observability, and security solution with an eBPF-based dataplane.

6.1
2024-03-18 CVE-2024-28250 Cilium Cleartext Transmission of Sensitive Information vulnerability in Cilium

Cilium is a networking, observability, and security solution with an eBPF-based dataplane.

6.1
2024-03-18 CVE-2024-28855 Zitadel Cross-site Scripting vulnerability in Zitadel

ZITADEL, open source authentication management software, uses Go templates to render the login UI.

6.1
2024-03-18 CVE-2024-27914 Glpi Project Cross-site Scripting vulnerability in Glpi-Project Glpi

GLPI is a Free Asset and IT Management Software package, Data center management, ITIL Service Desk, licenses tracking and software auditing.

6.1
2024-03-18 CVE-2024-23604 Cleancoder Unspecified vulnerability in Cleancoder Fitnesse

Cross-site scripting vulnerability exists in FitNesse all releases, which may allow a remote unauthenticated attacker to execute an arbitrary script on the web browser of the user who is using the product and accessing a link with specially crafted multiple parameters.

6.1
2024-03-18 CVE-2024-28128 Cleancoder Unspecified vulnerability in Cleancoder Fitnesse

Cross-site scripting vulnerability exists in FitNesse releases prior to 20220319, which may allow a remote unauthenticated attacker to execute an arbitrary script on the web browser of the user who is using the product and accessing a link with a specially crafted certain parameter.

6.1
2024-03-20 CVE-2024-23634 Geoserver Unspecified vulnerability in Geoserver

GeoServer is an open source software server written in Java that allows users to share and edit geospatial data.

6.0
2024-03-19 CVE-2024-22453 Dell Out-of-bounds Write vulnerability in Dell products

Dell PowerEdge Server BIOS contains a heap-based buffer overflow vulnerability.

6.0
2024-03-20 CVE-2023-35888 IBM Unspecified vulnerability in IBM Security Verify Governance 10.0.2

IBM Security Verify Governance 10.0.2 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security.

5.9
2024-03-21 CVE-2024-27277 IBM Unspecified vulnerability in IBM Storage Protect Plus 10.1.0

The private key for the IBM Storage Protect Plus Server 10.1.0 through 10.1.16 certificate can be disclosed, undermining the security of the certificate.

5.5
2024-03-21 CVE-2024-22352 IBM Unspecified vulnerability in IBM Infosphere Information Server 11.7

IBM InfoSphere Information Server 11.7 stores potentially sensitive information in log files that could be read by a local user.

5.5
2024-03-18 CVE-2024-25654 Avsystem Information Exposure Through Log Files vulnerability in Avsystem Unified Management Platform 23.07.0.16567

Insecure permissions for log files of AVSystem Unified Management Platform (UMP) 23.07.0.16567~LTS allow members (with local access to the UMP application server) to access credentials to authenticate to all services, and to decrypt sensitive data stored in the database.

5.5
2024-03-18 CVE-2023-52610 Linux Memory Leak vulnerability in Linux Kernel

In the Linux kernel, the following vulnerability has been resolved: net/sched: act_ct: fix skb leak and crash on ooo frags act_ct adds skb->users before defragmentation.

5.5
2024-03-18 CVE-2023-52611 Linux Unspecified vulnerability in Linux Kernel 6.7/6.7.1

In the Linux kernel, the following vulnerability has been resolved: wifi: rtw88: sdio: Honor the host max_req_size in the RX path Lukas reports skb_over_panic errors on his Banana Pi BPI-CM4 which comes with an Amlogic A311D (G12B) SoC and a RTL8822CS SDIO wifi/Bluetooth combo card.

5.5
2024-03-18 CVE-2023-52615 Linux Improper Locking vulnerability in Linux Kernel

In the Linux kernel, the following vulnerability has been resolved: hwrng: core - Fix page fault dead lock on mmap-ed hwrng There is a dead-lock in the hwrng device read path.

5.5
2024-03-18 CVE-2023-52616 Linux
Debian
In the Linux kernel, the following vulnerability has been resolved: crypto: lib/mpi - Fix unexpected pointer access in mpi_ec_init When the mpi_ec_ctx structure is initialized, some fields are not cleared, causing a crash when referencing the field when the structure was released.
5.5
2024-03-18 CVE-2023-52619 Linux
Debian
In the Linux kernel, the following vulnerability has been resolved: pstore/ram: Fix crash when setting number of cpus to an odd number When the number of cpu cores is adjusted to 7 or other odd numbers, the zone size will become an odd number. The address of the zone will become: addr of zone0 = BASE addr of zone1 = BASE + zone_size addr of zone2 = BASE + zone_size*2 ... The address of zone1/3/5/7 will be mapped to non-alignment va. Eventually crashes will occur when accessing these va. So, use ALIGN_DOWN() to make sure the zone size is even to avoid this bug.
5.5
2024-03-18 CVE-2024-26632 Linux Unspecified vulnerability in Linux Kernel

In the Linux kernel, the following vulnerability has been resolved: block: Fix iterating over an empty bio with bio_for_each_folio_all If the bio contains no data, bio_first_folio() calls page_folio() on a NULL pointer and oopses.

5.5
2024-03-18 CVE-2024-26634 Linux Unspecified vulnerability in Linux Kernel

In the Linux kernel, the following vulnerability has been resolved: net: fix removing a namespace with conflicting altnames Mark reports a BUG() when a net namespace is removed. kernel BUG at net/core/dev.c:11520! Physical interfaces moved outside of init_net get "refunded" to init_net when that namespace disappears.

5.5
2024-03-18 CVE-2024-26635 Linux
Debian
Missing Initialization of Resource vulnerability in multiple products

In the Linux kernel, the following vulnerability has been resolved: llc: Drop support for ETH_P_TR_802_2. syzbot reported an uninit-value bug below.

5.5
2024-03-18 CVE-2024-26636 Linux
Debian
In the Linux kernel, the following vulnerability has been resolved: llc: make llc_ui_sendmsg() more robust against bonding changes syzbot was able to trick llc_ui_sendmsg(), allocating an skb with no headroom, but subsequently trying to push 14 bytes of Ethernet header [1] Like some others, llc_ui_sendmsg() releases the socket lock before calling sock_alloc_send_skb(). Then it acquires it again, but does not redo all the sanity checks that were performed. This fix: - Uses LL_RESERVED_SPACE() to reserve space. - Check all conditions again after socket lock is held again. - Do not account Ethernet header for mtu limitation. [1] skbuff: skb_under_panic: text:ffff800088baa334 len:1514 put:14 head:ffff0000c9c37000 data:ffff0000c9c36ff2 tail:0x5dc end:0x6c0 dev:bond0 kernel BUG at net/core/skbuff.c:193 ! Internal error: Oops - BUG: 00000000f2000800 [#1] PREEMPT SMP Modules linked in: CPU: 0 PID: 6875 Comm: syz-executor.0 Not tainted 6.7.0-rc8-syzkaller-00101-g0802e17d9aca-dirty #0 Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 11/17/2023 pstate: 60400005 (nZCv daif +PAN -UAO -TCO -DIT -SSBS BTYPE=--) pc : skb_panic net/core/skbuff.c:189 [inline] pc : skb_under_panic+0x13c/0x140 net/core/skbuff.c:203 lr : skb_panic net/core/skbuff.c:189 [inline] lr : skb_under_panic+0x13c/0x140 net/core/skbuff.c:203 sp : ffff800096f97000 x29: ffff800096f97010 x28: ffff80008cc8d668 x27: dfff800000000000 x26: ffff0000cb970c90 x25: 00000000000005dc x24: ffff0000c9c36ff2 x23: ffff0000c9c37000 x22: 00000000000005ea x21: 00000000000006c0 x20: 000000000000000e x19: ffff800088baa334 x18: 1fffe000368261ce x17: ffff80008e4ed000 x16: ffff80008a8310f8 x15: 0000000000000001 x14: 1ffff00012df2d58 x13: 0000000000000000 x12: 0000000000000000 x11: 0000000000000001 x10: 0000000000ff0100 x9 : e28a51f1087e8400 x8 : e28a51f1087e8400 x7 : ffff80008028f8d0 x6 : 0000000000000000 x5 : 0000000000000001 x4 : 0000000000000001 x3 : ffff800082b78714 x2 : 0000000000000001 x1 : 0000000100000000 x0 : 0000000000000089 Call trace: skb_panic net/core/skbuff.c:189 [inline] skb_under_panic+0x13c/0x140 net/core/skbuff.c:203 skb_push+0xf0/0x108 net/core/skbuff.c:2451 eth_header+0x44/0x1f8 net/ethernet/eth.c:83 dev_hard_header include/linux/netdevice.h:3188 [inline] llc_mac_hdr_init+0x110/0x17c net/llc/llc_output.c:33 llc_sap_action_send_xid_c+0x170/0x344 net/llc/llc_s_ac.c:85 llc_exec_sap_trans_actions net/llc/llc_sap.c:153 [inline] llc_sap_next_state net/llc/llc_sap.c:182 [inline] llc_sap_state_process+0x1ec/0x774 net/llc/llc_sap.c:209 llc_build_and_send_xid_pkt+0x12c/0x1c0 net/llc/llc_sap.c:270 llc_ui_sendmsg+0x7bc/0xb1c net/llc/af_llc.c:997 sock_sendmsg_nosec net/socket.c:730 [inline] __sock_sendmsg net/socket.c:745 [inline] sock_sendmsg+0x194/0x274 net/socket.c:767 splice_to_socket+0x7cc/0xd58 fs/splice.c:881 do_splice_from fs/splice.c:933 [inline] direct_splice_actor+0xe4/0x1c0 fs/splice.c:1142 splice_direct_to_actor+0x2a0/0x7e4 fs/splice.c:1088 do_splice_direct+0x20c/0x348 fs/splice.c:1194 do_sendfile+0x4bc/0xc70 fs/read_write.c:1254 __do_sys_sendfile64 fs/read_write.c:1322 [inline] __se_sys_sendfile64 fs/read_write.c:1308 [inline] __arm64_sys_sendfile64+0x160/0x3b4 fs/read_write.c:1308 __invoke_syscall arch/arm64/kernel/syscall.c:37 [inline] invoke_syscall+0x98/0x2b8 arch/arm64/kernel/syscall.c:51 el0_svc_common+0x130/0x23c arch/arm64/kernel/syscall.c:136 do_el0_svc+0x48/0x58 arch/arm64/kernel/syscall.c:155 el0_svc+0x54/0x158 arch/arm64/kernel/entry-common.c:678 el0t_64_sync_handler+0x84/0xfc arch/arm64/kernel/entry-common.c:696 el0t_64_sync+0x190/0x194 arch/arm64/kernel/entry.S:595 Code: aa1803e6 aa1903e7 a90023f5 94792f6a (d4210000)
5.5
2024-03-18 CVE-2024-26637 Linux Unspecified vulnerability in Linux Kernel

In the Linux kernel, the following vulnerability has been resolved: wifi: ath11k: rely on mac80211 debugfs handling for vif mac80211 started to delete debugfs entries in certain cases, causing a ath11k to crash when it tried to delete the entries later.

5.5
2024-03-18 CVE-2024-26640 Linux
Debian
In the Linux kernel, the following vulnerability has been resolved: tcp: add sanity checks to rx zerocopy TCP rx zerocopy intent is to map pages initially allocated from NIC drivers, not pages owned by a fs. This patch adds to can_map_frag() these additional checks: - Page must not be a compound one. - page->mapping must be NULL. This fixes the panic reported by ZhangPeng. syzbot was able to loopback packets built with sendfile(), mapping pages owned by an ext4 file to TCP rx zerocopy. r3 = socket$inet_tcp(0x2, 0x1, 0x0) mmap(&(0x7f0000ff9000/0x4000)=nil, 0x4000, 0x0, 0x12, r3, 0x0) r4 = socket$inet_tcp(0x2, 0x1, 0x0) bind$inet(r4, &(0x7f0000000000)={0x2, 0x4e24, @multicast1}, 0x10) connect$inet(r4, &(0x7f00000006c0)={0x2, 0x4e24, @empty}, 0x10) r5 = openat$dir(0xffffffffffffff9c, &(0x7f00000000c0)='./file0\x00', 0x181e42, 0x0) fallocate(r5, 0x0, 0x0, 0x85b8) sendfile(r4, r5, 0x0, 0x8ba0) getsockopt$inet_tcp_TCP_ZEROCOPY_RECEIVE(r4, 0x6, 0x23, &(0x7f00000001c0)={&(0x7f0000ffb000/0x3000)=nil, 0x3000, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0}, &(0x7f0000000440)=0x40) r6 = openat$dir(0xffffffffffffff9c, &(0x7f00000000c0)='./file0\x00', 0x181e42, 0x0)
5.5
2024-03-18 CVE-2024-26641 Linux
Debian
Netapp
Use of Uninitialized Resource vulnerability in multiple products

In the Linux kernel, the following vulnerability has been resolved: ip6_tunnel: make sure to pull inner header in __ip6_tnl_rcv() syzbot found __ip6_tnl_rcv() could access unitiliazed data [1]. Call pskb_inet_may_pull() to fix this, and initialize ipv6h variable after this call as it can change skb->head. [1] BUG: KMSAN: uninit-value in __INET_ECN_decapsulate include/net/inet_ecn.h:253 [inline] BUG: KMSAN: uninit-value in INET_ECN_decapsulate include/net/inet_ecn.h:275 [inline] BUG: KMSAN: uninit-value in IP6_ECN_decapsulate+0x7df/0x1e50 include/net/inet_ecn.h:321 __INET_ECN_decapsulate include/net/inet_ecn.h:253 [inline] INET_ECN_decapsulate include/net/inet_ecn.h:275 [inline] IP6_ECN_decapsulate+0x7df/0x1e50 include/net/inet_ecn.h:321 ip6ip6_dscp_ecn_decapsulate+0x178/0x1b0 net/ipv6/ip6_tunnel.c:727 __ip6_tnl_rcv+0xd4e/0x1590 net/ipv6/ip6_tunnel.c:845 ip6_tnl_rcv+0xce/0x100 net/ipv6/ip6_tunnel.c:888 gre_rcv+0x143f/0x1870 ip6_protocol_deliver_rcu+0xda6/0x2a60 net/ipv6/ip6_input.c:438 ip6_input_finish net/ipv6/ip6_input.c:483 [inline] NF_HOOK include/linux/netfilter.h:314 [inline] ip6_input+0x15d/0x430 net/ipv6/ip6_input.c:492 ip6_mc_input+0xa7e/0xc80 net/ipv6/ip6_input.c:586 dst_input include/net/dst.h:461 [inline] ip6_rcv_finish+0x5db/0x870 net/ipv6/ip6_input.c:79 NF_HOOK include/linux/netfilter.h:314 [inline] ipv6_rcv+0xda/0x390 net/ipv6/ip6_input.c:310 __netif_receive_skb_one_core net/core/dev.c:5532 [inline] __netif_receive_skb+0x1a6/0x5a0 net/core/dev.c:5646 netif_receive_skb_internal net/core/dev.c:5732 [inline] netif_receive_skb+0x58/0x660 net/core/dev.c:5791 tun_rx_batched+0x3ee/0x980 drivers/net/tun.c:1555 tun_get_user+0x53af/0x66d0 drivers/net/tun.c:2002 tun_chr_write_iter+0x3af/0x5d0 drivers/net/tun.c:2048 call_write_iter include/linux/fs.h:2084 [inline] new_sync_write fs/read_write.c:497 [inline] vfs_write+0x786/0x1200 fs/read_write.c:590 ksys_write+0x20f/0x4c0 fs/read_write.c:643 __do_sys_write fs/read_write.c:655 [inline] __se_sys_write fs/read_write.c:652 [inline] __x64_sys_write+0x93/0xd0 fs/read_write.c:652 do_syscall_x64 arch/x86/entry/common.c:52 [inline] do_syscall_64+0x6d/0x140 arch/x86/entry/common.c:83 entry_SYSCALL_64_after_hwframe+0x63/0x6b Uninit was created at: slab_post_alloc_hook+0x129/0xa70 mm/slab.h:768 slab_alloc_node mm/slub.c:3478 [inline] kmem_cache_alloc_node+0x5e9/0xb10 mm/slub.c:3523 kmalloc_reserve+0x13d/0x4a0 net/core/skbuff.c:560 __alloc_skb+0x318/0x740 net/core/skbuff.c:651 alloc_skb include/linux/skbuff.h:1286 [inline] alloc_skb_with_frags+0xc8/0xbd0 net/core/skbuff.c:6334 sock_alloc_send_pskb+0xa80/0xbf0 net/core/sock.c:2787 tun_alloc_skb drivers/net/tun.c:1531 [inline] tun_get_user+0x1e8a/0x66d0 drivers/net/tun.c:1846 tun_chr_write_iter+0x3af/0x5d0 drivers/net/tun.c:2048 call_write_iter include/linux/fs.h:2084 [inline] new_sync_write fs/read_write.c:497 [inline] vfs_write+0x786/0x1200 fs/read_write.c:590 ksys_write+0x20f/0x4c0 fs/read_write.c:643 __do_sys_write fs/read_write.c:655 [inline] __se_sys_write fs/read_write.c:652 [inline] __x64_sys_write+0x93/0xd0 fs/read_write.c:652 do_syscall_x64 arch/x86/entry/common.c:52 [inline] do_syscall_64+0x6d/0x140 arch/x86/entry/common.c:83 entry_SYSCALL_64_after_hwframe+0x63/0x6b CPU: 0 PID: 5034 Comm: syz-executor331 Not tainted 6.7.0-syzkaller-00562-g9f8413c4a66f #0 Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 11/17/2023

5.5
2024-03-23 CVE-2024-24840 Bdthemes Unspecified vulnerability in Bdthemes Element Pack

Missing Authorization vulnerability in BdThemes Element Pack Elementor Addons.This issue affects Element Pack Elementor Addons: from n/a through 5.4.11.

5.4
2024-03-23 CVE-2024-1049 Godaddy Cross-site Scripting vulnerability in Godaddy Coblocks

The Page Builder Gutenberg Blocks – CoBlocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Icon Widget's in all versions up to, and including, 3.1.6 due to insufficient input sanitization and output escaping on the link value.

5.4
2024-03-23 CVE-2024-2202 Siteorigin Cross-site Scripting vulnerability in Siteorigin Page Builder

The Page Builder by SiteOrigin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the legacy Image widget in all versions up to, and including, 2.29.6 due to insufficient input sanitization and output escaping.

5.4
2024-03-23 CVE-2024-2468 Wpdeveloper Cross-site Scripting vulnerability in Wpdeveloper Embedpress

The EmbedPress – Embed PDF, Google Docs, Vimeo, Wistia, Embed YouTube Videos, Audios, Maps & Embed Any Documents in Gutenberg & Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the EmbedPress widget 'embedpress_pro_twitch_theme ' attribute in all versions up to, and including, 3.9.12 due to insufficient input sanitization and output escaping on user supplied attributes.

5.4
2024-03-23 CVE-2024-2688 Wpdeveloper Cross-site Scripting vulnerability in Wpdeveloper Embedpress

The EmbedPress – Embed PDF, Google Docs, Vimeo, Wistia, Embed YouTube Videos, Audios, Maps & Embed Any Documents in Gutenberg & Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the EmbedPress document widget in all versions up to, and including, 3.9.12 due to insufficient input sanitization and output escaping on user supplied attributes.

5.4
2024-03-23 CVE-2024-1697 Themelocation Cross-site Scripting vulnerability in Themelocation Custom Woocommerce Checkout Fields Editor

The Custom WooCommerce Checkout Fields Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the save_wcfe_options function in all versions up to, and including, 1.3.1 due to insufficient input sanitization and output escaping.

5.4
2024-03-23 CVE-2024-2131 Moveaddons Cross-site Scripting vulnerability in Moveaddons Move Addons for Elementor

The Move Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's infobox and button widget in all versions up to, and including, 1.2.9 due to insufficient input sanitization and output escaping on user supplied attributes.

5.4
2024-03-22 CVE-2024-2392 Creativethemes Cross-site Scripting vulnerability in Creativethemes Blocksy Companion

The Blocksy Companion plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Newsletter widget in all versions up to, and including, 2.0.31 due to insufficient input sanitization and output escaping on user supplied attributes.

5.4
2024-03-22 CVE-2024-2779 Campcodes Unspecified vulnerability in Campcodes Online Marriage Registration System 1.0

A vulnerability was found in Campcodes Online Marriage Registration System 1.0.

5.4
2024-03-21 CVE-2024-27963 Crisp Unspecified vulnerability in Crisp

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crisp allows Stored XSS.This issue affects Crisp: from n/a through 0.44.

5.4
2024-03-21 CVE-2024-1278 Easysocialfeed Cross-site Scripting vulnerability in Easysocialfeed Easy Social Feed

The Easy Social Feed – Social Photos Gallery – Post Feed – Like Box plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'efb_likebox' shortcode in all versions up to, and including, 6.5.4 due to insufficient input sanitization and output escaping on user supplied attributes.

5.4
2024-03-21 CVE-2024-1326 Jegtheme Cross-site Scripting vulnerability in Jegtheme JEG Elementor KIT

The Jeg Elementor Kit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via HTML Tag attributes in all versions up to, and including, 2.6.2 due to insufficient input sanitization and output escaping.

5.4
2024-03-20 CVE-2024-29471 Zhyd Cross-site Scripting vulnerability in Zhyd Oneblog 2.3.4

OneBlog v2.3.4 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Notice Manage module.

5.4
2024-03-20 CVE-2024-29472 Zhyd Cross-site Scripting vulnerability in Zhyd Oneblog 2.3.4

OneBlog v2.3.4 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Privilege Management module.

5.4
2024-03-20 CVE-2024-29419 Totolink Cross-site Scripting vulnerability in Totolink X2000R Firmware

There is a Cross-site scripting (XSS) vulnerability in the Wireless settings under the Easy Setup Page of TOTOLINK X2000R before v1.0.0-B20231213.1013.

5.4
2024-03-20 CVE-2024-2255 Wpdeveloper Cross-site Scripting vulnerability in Wpdeveloper Essential Blocks

The Essential Blocks – Page Builder Gutenberg Blocks, Patterns & Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's widgets in all versions up to, and including, 4.5.2 due to insufficient input sanitization and output escaping on user supplied attributes such as listStyle.

5.4
2024-03-19 CVE-2024-29101 Jegtheme Unspecified vulnerability in Jegtheme JEG Elementor KIT

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jegtheme Jeg Elementor Kit allows Stored XSS.This issue affects Jeg Elementor Kit: from n/a through 2.6.2.

5.4
2024-03-19 CVE-2024-29106 Leap13 Unspecified vulnerability in Leap13 Premium Addons for Elementor

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Leap13 Premium Addons for Elementor allows Stored XSS.This issue affects Premium Addons for Elementor: from n/a through 4.10.16.

5.4
2024-03-19 CVE-2024-29107 Webtechstreet Unspecified vulnerability in Webtechstreet Elementor Addon Elements

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPVibes Elementor Addon Elements allows Stored XSS.This issue affects Elementor Addon Elements: from n/a through 1.12.10.

5.4
2024-03-19 CVE-2024-29108 Leevio Unspecified vulnerability in Leevio Happy Addons for Elementor

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Leevio Happy Addons for Elementor allows Stored XSS.This issue affects Happy Addons for Elementor: from n/a through 3.10.1.

5.4
2024-03-19 CVE-2024-29115 Zaytech Unspecified vulnerability in Zaytech Smart Online Order for Clover

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Zaytech Smart Online Order for Clover allows Stored XSS.This issue affects Smart Online Order for Clover: from n/a through 1.5.5.

5.4
2024-03-19 CVE-2024-29134 Themefic Unspecified vulnerability in Themefic Tourfic

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themefic Tourfic allows Stored XSS.This issue affects Tourfic: from n/a through 2.11.8.

5.4
2024-03-18 CVE-2024-0820 Blueglass Cross-site Scripting vulnerability in Blueglass Jobs for Wordpress

The Jobs for WordPress plugin before 2.7.4 does not sanitise and escape some parameters, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks

5.4
2024-03-18 CVE-2024-26051 Adobe Unspecified vulnerability in Adobe Experience Manager

Adobe Experience Manager versions 6.5.19 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields.

5.4
2024-03-18 CVE-2024-1606 BMC Unspecified vulnerability in BMC Control-M

Lack of input sanitization in BMC Control-M branches 9.0.20 and 9.0.21 allows logged-in users for manipulation of generated web pages via injection of HTML code.

5.4
2024-03-22 CVE-2022-32751 IBM Unspecified vulnerability in IBM Security Verify Directory 10.0.0

IBM Security Verify Directory 10.0.0 could disclose sensitive server information that could be used in further attacks against the system.

5.3
2024-03-20 CVE-2024-28868 Umbraco Information Exposure Through Discrepancy vulnerability in Umbraco CMS

Umbraco is an ASP.NET content management system.

5.3
2024-03-19 CVE-2024-2645 Netentsec XML Injection (aka Blind XPath Injection) vulnerability in Netentsec Application Security Gateway 6.3

A vulnerability classified as problematic has been found in Netentsec NS-ASG Application Security Gateway 6.3.

5.3
2024-03-19 CVE-2024-2648 Netentsec XML Injection (aka Blind XPath Injection) vulnerability in Netentsec Application Security Gateway 6.3

A vulnerability, which was classified as problematic, was found in Netentsec NS-ASG Application Security Gateway 6.3.

5.3
2024-03-18 CVE-2024-26119 Adobe Unspecified vulnerability in Adobe Experience Manager

Adobe Experience Manager versions 6.5.19 and earlier are affected by an Information Exposure vulnerability that could result in a security feature bypass.

5.3
2024-03-21 CVE-2023-42954 Claris Unspecified vulnerability in Claris PRO and Filemaker Server

A privilege escalation issue existed in FileMaker Server, potentially exposing sensitive information to front-end websites when signed in to the Admin Console with an administrator role.

4.9
2024-03-22 CVE-2022-32754 IBM Unspecified vulnerability in IBM Security Verify Directory 10.0.0

IBM Security Verify Directory 10.0.0 is vulnerable to cross-site scripting.

4.8
2024-03-21 CVE-2024-27965 Getwpfunnels Unspecified vulnerability in Getwpfunnels Wpfunnels

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPFunnels Team WPFunnels allows Stored XSS.This issue affects WPFunnels: from n/a through 3.0.6.

4.8
2024-03-20 CVE-2024-23642 Geoserver Cross-site Scripting vulnerability in Geoserver

GeoServer is an open source software server written in Java that allows users to share and edit geospatial data.

4.8
2024-03-20 CVE-2024-23643 Geoserver Cross-site Scripting vulnerability in Geoserver

GeoServer is an open source software server written in Java that allows users to share and edit geospatial data.

4.8
2024-03-20 CVE-2024-23818 Geoserver Cross-site Scripting vulnerability in Geoserver

GeoServer is an open source software server written in Java that allows users to share and edit geospatial data.

4.8
2024-03-20 CVE-2024-23819 Geoserver Cross-site Scripting vulnerability in Geoserver

GeoServer is an open source software server written in Java that allows users to share and edit geospatial data.

4.8
2024-03-20 CVE-2024-23821 Geoserver Cross-site Scripting vulnerability in Geoserver

GeoServer is an open source software server written in Java that allows users to share and edit geospatial data.

4.8
2024-03-20 CVE-2023-51445 Geoserver Cross-site Scripting vulnerability in Geoserver

GeoServer is an open source software server written in Java that allows users to share and edit geospatial data.

4.8
2024-03-20 CVE-2024-23640 Geoserver Cross-site Scripting vulnerability in Geoserver

GeoServer is an open source software server written in Java that allows users to share and edit geospatial data.

4.8
2024-03-19 CVE-2024-29112 Wpmarketingrobot Unspecified vulnerability in Wpmarketingrobot Woocommerce Google Feed Manager

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Marketing Robot WooCommerce Google Feed Manager allows Stored XSS.This issue affects WooCommerce Google Feed Manager: from n/a through 2.2.0.

4.8
2024-03-18 CVE-2024-28237 Octoprint Cross-site Scripting vulnerability in Octoprint

OctoPrint provides a web interface for controlling consumer 3D printers.

4.8
2024-03-18 CVE-2024-0951 Shahaji9 Cross-site Scripting vulnerability in Shahaji9 Advanced Social Feeds Widget & Shortcode

The Advanced Social Feeds Widget & Shortcode WordPress plugin through 1.7 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

4.8
2024-03-18 CVE-2024-26050 Adobe Unspecified vulnerability in Adobe Experience Manager

Adobe Experience Manager versions 6.5.19 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an admin attacker to inject malicious scripts into vulnerable form fields.

4.8
2024-03-18 CVE-2024-27104 Glpi Project Cross-site Scripting vulnerability in Glpi-Project Glpi

GLPI is a Free Asset and IT Management Software package, Data center management, ITIL Service Desk, licenses tracking and software auditing.

4.8
2024-03-18 CVE-2023-52609 Linux
Debian
Race Condition vulnerability in multiple products

In the Linux kernel, the following vulnerability has been resolved: binder: fix race between mmput() and do_exit() Task A calls binder_update_page_range() to allocate and insert pages on a remote address space from Task B.

4.7
2024-03-18 CVE-2024-26631 Linux Improper Locking vulnerability in Linux Kernel

In the Linux kernel, the following vulnerability has been resolved: ipv6: mcast: fix data-race in ipv6_mc_down / mld_ifc_work idev->mc_ifc_count can be written over without proper locking. Originally found by syzbot [1], fix this issue by encapsulating calls to mld_ifc_stop_work() (and mld_gq_stop_work() for good measure) with mutex_lock() and mutex_unlock() accordingly as these functions should only be called with mc_lock per their declarations. [1] BUG: KCSAN: data-race in ipv6_mc_down / mld_ifc_work write to 0xffff88813a80c832 of 1 bytes by task 3771 on cpu 0: mld_ifc_stop_work net/ipv6/mcast.c:1080 [inline] ipv6_mc_down+0x10a/0x280 net/ipv6/mcast.c:2725 addrconf_ifdown+0xe32/0xf10 net/ipv6/addrconf.c:3949 addrconf_notify+0x310/0x980 notifier_call_chain kernel/notifier.c:93 [inline] raw_notifier_call_chain+0x6b/0x1c0 kernel/notifier.c:461 __dev_notify_flags+0x205/0x3d0 dev_change_flags+0xab/0xd0 net/core/dev.c:8685 do_setlink+0x9f6/0x2430 net/core/rtnetlink.c:2916 rtnl_group_changelink net/core/rtnetlink.c:3458 [inline] __rtnl_newlink net/core/rtnetlink.c:3717 [inline] rtnl_newlink+0xbb3/0x1670 net/core/rtnetlink.c:3754 rtnetlink_rcv_msg+0x807/0x8c0 net/core/rtnetlink.c:6558 netlink_rcv_skb+0x126/0x220 net/netlink/af_netlink.c:2545 rtnetlink_rcv+0x1c/0x20 net/core/rtnetlink.c:6576 netlink_unicast_kernel net/netlink/af_netlink.c:1342 [inline] netlink_unicast+0x589/0x650 net/netlink/af_netlink.c:1368 netlink_sendmsg+0x66e/0x770 net/netlink/af_netlink.c:1910 ... write to 0xffff88813a80c832 of 1 bytes by task 22 on cpu 1: mld_ifc_work+0x54c/0x7b0 net/ipv6/mcast.c:2653 process_one_work kernel/workqueue.c:2627 [inline] process_scheduled_works+0x5b8/0xa30 kernel/workqueue.c:2700 worker_thread+0x525/0x730 kernel/workqueue.c:2781 ...

4.7
2024-03-21 CVE-2024-27932 Deno Unspecified vulnerability in Deno

Deno is a JavaScript, TypeScript, and WebAssembly runtime.

4.6
2024-03-22 CVE-2024-29057 Microsoft Unspecified vulnerability in Microsoft Edge

Microsoft Edge (Chromium-based) Spoofing Vulnerability

4.3
2024-03-22 CVE-2024-2823 Dedecms Unspecified vulnerability in Dedecms 5.7

A vulnerability has been found in DedeCMS 5.7 and classified as problematic.

4.3
2024-03-22 CVE-2024-2820 Dedecms Unspecified vulnerability in Dedecms 5.7

A vulnerability classified as problematic was found in DedeCMS 5.7.

4.3
2024-03-21 CVE-2023-47715 IBM Unspecified vulnerability in IBM Storage Protect Plus 10.1.0/10.1.16

IBM Storage Protect Plus Server 10.1.0 through 10.1.16 could allow an authenticated user with read-only permissions to add or delete entries from an existing HyperVisor configuration.

4.3
2024-03-21 CVE-2024-1213 Easysocialfeed Cross-Site Request Forgery (CSRF) vulnerability in Easysocialfeed Easy Social Feed

The Easy Social Feed – Social Photos Gallery – Post Feed – Like Box plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 6.5.4.

4.3
2024-03-21 CVE-2024-1502 Themeum Missing Authorization vulnerability in Themeum Tutor LMS

The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the tutor_delete_announcement() function in all versions up to, and including, 2.6.1.

4.3
2024-03-20 CVE-2024-2628 Google
Fedoraproject
Inappropriate implementation in Downloads in Google Chrome prior to 123.0.6312.58 allowed a remote attacker to perform UI spoofing via a crafted URL.
4.3
2024-03-20 CVE-2024-2629 Google
Fedoraproject
Incorrect security UI in iOS in Google Chrome prior to 123.0.6312.58 allowed a remote attacker to perform UI spoofing via a crafted HTML page.
4.3
2024-03-20 CVE-2024-2631 Google
Fedoraproject
Inappropriate implementation in iOS in Google Chrome prior to 123.0.6312.58 allowed a remote attacker to perform UI spoofing via a crafted HTML page.
4.3
2024-03-20 CVE-2024-2291 Progress Unspecified vulnerability in Progress Moveit Transfer

In Progress MOVEit Transfer versions released before 2022.0.11 (14.0.11), 2022.1.12 (14.1.12), 2023.0.9 (15.0.9), 2023.1.4 (15.1.4), a logging bypass vulnerability has been discovered.  An authenticated user could manipulate a request to bypass the logging mechanism within the web application which results in user activity not being logged properly.

4.3
2024-03-20 CVE-2024-2538 Permalink Manager Lite Project Missing Authorization vulnerability in Permalink Manager Lite Project Permalink Manager Lite

The Permalink Manager Lite plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'ajax_save_permalink' function in all versions up to, and including, 2.4.3.1.

4.3
2024-03-18 CVE-2024-27937 Glpi Project Unspecified vulnerability in Glpi-Project Glpi

GLPI is a Free Asset and IT Management Software package, Data center management, ITIL Service Desk, licenses tracking and software auditing.

4.3

3 Low Vulnerabilities

DATE CVE VENDOR VULNERABILITY CVSS
2024-03-22 CVE-2024-1742 Checkmk Unspecified vulnerability in Checkmk

Invocation of the sqlplus command with sensitive information in the command line in the mk_oracle Checkmk agent plugin before Checkmk 2.3.0b4 (beta), 2.2.0p24, 2.1.0p41 and 2.0.0 (EOL) allows the extraction of this information from the process list.

3.3
2024-03-22 CVE-2022-32756 IBM Unspecified vulnerability in IBM Security Verify Directory 10.0.0

IBM Security Verify Directory 10.0.0 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser.

2.7
2024-03-19 CVE-2024-2616 Mozilla Out-of-bounds Write vulnerability in Mozilla Firefox

To harden ICU against exploitation, the behavior for out-of-memory conditions was changed to crash instead of attempt to continue.

2.7