Weekly Vulnerabilities Reports > March 18 to 24, 2024

Overview

142 new vulnerabilities reported during this period, including 29 critical vulnerabilities and 44 high severity vulnerabilities. This weekly summary report vulnerabilities in 79 products from 40 vendors including Tenda, Geoserver, Sapplica, Google, and IBM. Vulnerabilities are notably categorized as "Cross-site Scripting", "Out-of-bounds Write", "Code Injection", "Deserialization of Untrusted Data", and "XML Injection (aka Blind XPath Injection)".

  • 125 reported vulnerabilities are remotely exploitables.
  • 33 reported vulnerabilities are related to weaknesses in OWASP Top Ten.
  • 64 reported vulnerabilities are exploitable by an anonymous user.
  • Tenda has the most reported vulnerabilities, with 32 reported vulnerabilities.
  • Tenda has the most reported critical vulnerabilities, with 16 reported vulnerabilities.

TOTAL
VULNERABILITIES
CRITICAL RISK
VULNERABILITIES
HIGH RISK
VULNERABILITIES
MEDIUM RISK
VULNERABILITIES
LOW RISK
VULNERABILITIES
REMOTELY
EXPLOITABLE
LOCALLY
EXPLOITABLE
EXPLOIT
AVAILABLE
EXPLOITABLE
ANONYMOUSLY
AFFECTING
WEB APPLICATION

Vulnerability Details

The following table list reported vulnerabilities for the period covered by this report:

Expand/Hide

29 Critical Vulnerabilities

DATE CVE VENDOR VULNERABILITY CVSS
2024-03-24 CVE-2024-2856 Tenda Unspecified vulnerability in Tenda Ac10 Firmware 16.03.10.13/16.03.10.20

A vulnerability, which was classified as critical, has been found in Tenda AC10 16.03.10.13/16.03.10.20.

9.8
2024-03-24 CVE-2024-2854 Tenda Unspecified vulnerability in Tenda Ac18 Firmware 15.03.05.05

A vulnerability classified as critical has been found in Tenda AC18 15.03.05.05.

9.8
2024-03-24 CVE-2024-2855 Tenda Unspecified vulnerability in Tenda Ac15 Firmware 15.03.05.18/15.03.05.19/15.03.20Multi

A vulnerability classified as critical was found in Tenda AC15 15.03.05.18/15.03.05.19/15.03.20.

9.8
2024-03-24 CVE-2024-2852 Tenda Unspecified vulnerability in Tenda Ac15 Firmware 15.03.20Multi

A vulnerability was found in Tenda AC15 15.03.20_multi.

9.8
2024-03-24 CVE-2024-2853 Tenda Unspecified vulnerability in Tenda Ac10U Firmware 15.03.06.48/15.03.06.49

A vulnerability was found in Tenda AC10U 15.03.06.48/15.03.06.49.

9.8
2024-03-24 CVE-2024-2851 Tenda Unspecified vulnerability in Tenda Ac15 Firmware 15.03.05.18/15.03.20Multi

A vulnerability was found in Tenda AC15 15.03.05.18/15.03.20_multi.

9.8
2024-03-24 CVE-2024-2850 Tenda Unspecified vulnerability in Tenda Ac15 Firmware 15.03.05.18

A vulnerability was found in Tenda AC15 15.03.05.18 and classified as critical.

9.8
2024-03-22 CVE-2024-2815 Tenda Unspecified vulnerability in Tenda Ac15 Firmware 15.03.05.20Multi

A vulnerability classified as critical has been found in Tenda AC15 15.03.20_multi.

9.8
2024-03-22 CVE-2024-2813 Tenda Unspecified vulnerability in Tenda Ac15 Firmware 15.03.05.20Multi

A vulnerability was found in Tenda AC15 15.03.20_multi.

9.8
2024-03-22 CVE-2024-2814 Tenda Unspecified vulnerability in Tenda Ac15 Firmware 15.03.05.20Multi

A vulnerability was found in Tenda AC15 15.03.20_multi.

9.8
2024-03-22 CVE-2024-2809 Tenda Unspecified vulnerability in Tenda Ac15 Firmware 15.03.05.18/15.03.05.20Multi

A vulnerability, which was classified as critical, was found in Tenda AC15 15.03.05.18/15.03.20_multi.

9.8
2024-03-22 CVE-2024-2810 Tenda Unspecified vulnerability in Tenda Ac15 Firmware 15.03.05.18/15.03.05.20Multi

A vulnerability has been found in Tenda AC15 15.03.05.18/15.03.20_multi and classified as critical.

9.8
2024-03-22 CVE-2024-2811 Tenda Unspecified vulnerability in Tenda Ac15 Firmware 15.03.05.20Multi

A vulnerability was found in Tenda AC15 15.03.20_multi and classified as critical.

9.8
2024-03-22 CVE-2024-2806 Tenda Unspecified vulnerability in Tenda Ac15 Firmware 15.03.05.18/15.03.05.20Multi

A vulnerability classified as critical has been found in Tenda AC15 15.03.05.18/15.03.20_multi.

9.8
2024-03-22 CVE-2024-2807 Tenda Unspecified vulnerability in Tenda Ac15 Firmware 15.03.05.18/15.03.05.20Multi

A vulnerability classified as critical was found in Tenda AC15 15.03.05.18/15.03.20_multi.

9.8
2024-03-22 CVE-2024-2808 Tenda Unspecified vulnerability in Tenda Ac15 Firmware 15.03.05.18/15.03.05.20Multi

A vulnerability, which was classified as critical, has been found in Tenda AC15 15.03.05.18/15.03.20_multi.

9.8
2024-03-21 CVE-2024-29870 Sapplica Unspecified vulnerability in Sapplica Sentrifugo 3.2

SQL injection vulnerability in Sentrifugo 3.2, through /sentrifugo/index.php/index/getdepartments/format/html, 'business_id' parameter./sentrifugo/index.php/index/getdepartments/format/html, 'business_id' parameter.

9.8
2024-03-21 CVE-2024-29871 Sapplica Unspecified vulnerability in Sapplica Sentrifugo 3.2

SQL injection vulnerability in Sentrifugo 3.2, through /sentrifugo/index.php/index/getdepartments/sentrifugo/index.php/index/updatecontactnumber, 'id' parameter.

9.8
2024-03-21 CVE-2024-29872 Sapplica Unspecified vulnerability in Sapplica Sentrifugo 3.2

SQL injection vulnerability in Sentrifugo 3.2, through /sentrifugo/index.php/empscreening/add, 'agencyids' parameter.

9.8
2024-03-21 CVE-2024-29873 Sapplica Unspecified vulnerability in Sapplica Sentrifugo 3.2

SQL injection vulnerability in Sentrifugo 3.2, through /sentrifugo/index.php/reports/businessunits/format/html, 'bunitname' parameter.

9.8
2024-03-21 CVE-2024-29874 Sapplica Unspecified vulnerability in Sapplica Sentrifugo 3.2

SQL injection vulnerability in Sentrifugo 3.2, through /sentrifugo/index.php/default/reports/activeuserrptpdf, 'sort_name' parameter.

9.8
2024-03-21 CVE-2024-29875 Sapplica Unspecified vulnerability in Sapplica Sentrifugo 3.2

SQL injection vulnerability in Sentrifugo 3.2, through  /sentrifugo/index.php/default/reports/exportactiveuserrpt, 'sort_name' parameter.

9.8
2024-03-21 CVE-2024-29876 Sapplica Unspecified vulnerability in Sapplica Sentrifugo 3.2

SQL injection vulnerability in Sentrifugo 3.2, through  /sentrifugo/index.php/reports/activitylogreport, 'sortby' parameter.

9.8
2024-03-20 CVE-2024-2649 Netentsec Unspecified vulnerability in Netentsec Application Security Gateway 6.3

A vulnerability has been found in Netentsec NS-ASG Application Security Gateway 6.3 and classified as critical.

9.8
2024-03-19 CVE-2024-2646 Netentsec Unspecified vulnerability in Netentsec Application Security Gateway 6.3

A vulnerability classified as critical was found in Netentsec NS-ASG Application Security Gateway 6.3.

9.8
2024-03-18 CVE-2024-21652 Argoproj Improper Restriction of Excessive Authentication Attempts vulnerability in Argoproj Argo CD

Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes.

9.8
2024-03-18 CVE-2024-27098 Glpi Project Server-Side Request Forgery (SSRF) vulnerability in Glpi-Project Glpi

GLPI is a Free Asset and IT Management Software package, Data center management, ITIL Service Desk, licenses tracking and software auditing.

9.6
2024-03-18 CVE-2024-21662 Argoproj Improper Restriction of Excessive Authentication Attempts vulnerability in Argoproj Argo CD

Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes.

9.1
2024-03-22 CVE-2024-29185 Freescout OS Command Injection vulnerability in Freescout

FreeScout is a self-hosted help desk and shared mailbox.

9.0

44 High Vulnerabilities

DATE CVE VENDOR VULNERABILITY CVSS
2024-03-22 CVE-2024-2812 Tenda Unspecified vulnerability in Tenda Ac15 Firmware 15.03.05.18/15.03.05.20Multi

A vulnerability was found in Tenda AC15 15.03.05.18/15.03.20_multi.

8.8
2024-03-22 CVE-2024-2805 Tenda Out-of-bounds Write vulnerability in Tenda Ac15 Firmware 15.03.05.18/15.03.05.20Multi

A vulnerability was found in Tenda AC15 15.03.05.18/15.03.20_multi.

8.8
2024-03-21 CVE-2024-25937 Deltaww Unspecified vulnerability in Deltaww Diaenergie

SQL injection vulnerability exists in the script DIAE_tagHandler.ashx.

8.8
2024-03-21 CVE-2024-27921 Getgrav Path Traversal vulnerability in Getgrav Grav

Grav is an open-source, flat-file content management system.

8.8
2024-03-21 CVE-2024-28029 Deltaww Unspecified vulnerability in Deltaww Diaenergie

Privileges are not fully verified server-side, which can be abused by a user with limited privileges to bypass authorization and access privileged functionality.

8.8
2024-03-21 CVE-2024-28116 Getgrav Code Injection vulnerability in Getgrav Grav

Grav is an open-source, flat-file content management system.

8.8
2024-03-21 CVE-2024-28117 Getgrav Code Injection vulnerability in Getgrav Grav

Grav is an open-source, flat-file content management system.

8.8
2024-03-21 CVE-2024-28118 Getgrav Code Injection vulnerability in Getgrav Grav

Grav is an open-source, flat-file content management system.

8.8
2024-03-21 CVE-2024-28119 Getgrav Code Injection vulnerability in Getgrav Grav

Grav is an open-source, flat-file content management system.

8.8
2024-03-21 CVE-2024-2763 Tenda Out-of-bounds Write vulnerability in Tenda Ac10U Firmware 15.03.06.48

A vulnerability, which was classified as critical, has been found in Tenda AC10U 15.03.06.48.

8.8
2024-03-21 CVE-2024-2764 Tenda Out-of-bounds Write vulnerability in Tenda Ac10U Firmware 15.03.06.48

A vulnerability, which was classified as critical, was found in Tenda AC10U 15.03.06.48.

8.8
2024-03-21 CVE-2024-27923 Getgrav Unrestricted Upload of File with Dangerous Type vulnerability in Getgrav Grav

Grav is a content management system (CMS).

8.8
2024-03-21 CVE-2024-27933 Deno Incorrect Authorization vulnerability in Deno 1.39.0

Deno is a JavaScript, TypeScript, and WebAssembly runtime.

8.8
2024-03-21 CVE-2024-27934 Deno Use After Free vulnerability in Deno

Deno is a JavaScript, TypeScript, and WebAssembly runtime.

8.8
2024-03-20 CVE-2024-2708 Tenda Out-of-bounds Write vulnerability in Tenda Ac10U Firmware 15.03.06.49

A vulnerability was found in Tenda AC10U 15.03.06.49 and classified as critical.

8.8
2024-03-20 CVE-2024-2709 Tenda Out-of-bounds Write vulnerability in Tenda Ac10U Firmware 15.03.06.49

A vulnerability was found in Tenda AC10U 15.03.06.49.

8.8
2024-03-20 CVE-2024-2710 Tenda Out-of-bounds Write vulnerability in Tenda Ac10U Firmware 15.03.06.49

A vulnerability was found in Tenda AC10U 15.03.06.49.

8.8
2024-03-20 CVE-2024-2711 Tenda Out-of-bounds Write vulnerability in Tenda Ac10U Firmware 15.03.06.48

A vulnerability was found in Tenda AC10U 15.03.06.48.

8.8
2024-03-20 CVE-2024-2625 Google
Fedoraproject
Object lifecycle issue in V8 in Google Chrome prior to 123.0.6312.58 allowed a remote attacker to potentially exploit object corruption via a crafted HTML page.
8.8
2024-03-20 CVE-2024-2627 Google
Fedoraproject
Use After Free vulnerability in multiple products

Use after free in Canvas in Google Chrome prior to 123.0.6312.58 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

8.8
2024-03-20 CVE-2024-2705 Tenda Out-of-bounds Write vulnerability in Tenda Ac10U Firmware 15.03.06.49

A vulnerability, which was classified as critical, has been found in Tenda AC10U 1.0/15.03.06.49.

8.8
2024-03-20 CVE-2024-2706 Tenda Out-of-bounds Write vulnerability in Tenda Ac10U Firmware 15.03.06.49

A vulnerability, which was classified as critical, was found in Tenda AC10U 15.03.06.49.

8.8
2024-03-20 CVE-2024-2707 Tenda Unspecified vulnerability in Tenda Ac10U Firmware 15.03.06.49

A vulnerability has been found in Tenda AC10U 15.03.06.49 and classified as critical.

8.8
2024-03-20 CVE-2024-2703 Tenda Out-of-bounds Write vulnerability in Tenda Ac10U Firmware 15.03.06.49

A vulnerability classified as critical has been found in Tenda AC10U 15.03.06.49.

8.8
2024-03-20 CVE-2024-2704 Tenda Out-of-bounds Write vulnerability in Tenda Ac10U Firmware 15.03.06.49

A vulnerability classified as critical was found in Tenda AC10U 15.03.06.49.

8.8
2024-03-20 CVE-2024-1800 Progress Deserialization of Untrusted Data vulnerability in Progress Telerik Report Server

In Progress® Telerik® Report Server versions prior to 2024 Q1 (10.0.24.130), a remote code execution attack is possible through an insecure deserialization vulnerability.

8.8
2024-03-20 CVE-2024-1856 Progress Deserialization of Untrusted Data vulnerability in Progress Telerik Reporting

In Progress® Telerik® Reporting versions prior to 2024 Q1 (18.0.24.130), a code execution attack is possible by a remote threat actor through an insecure deserialization vulnerability.

8.8
2024-03-18 CVE-2024-2581 Tenda Out-of-bounds Write vulnerability in Tenda Ac10 Firmware 16.03.10.13

A vulnerability was found in Tenda AC10 16.03.10.13 and classified as critical.

8.8
2024-03-21 CVE-2024-27935 Deno Unspecified vulnerability in Deno

Deno is a JavaScript, TypeScript, and WebAssembly runtime.

8.3
2024-03-22 CVE-2024-29184 Freescout Cross-site Scripting vulnerability in Freescout

FreeScout is a self-hosted help desk and shared mailbox.

8.0
2024-03-22 CVE-2024-28824 Checkmk Unspecified vulnerability in Checkmk

Least privilege violation and reliance on untrusted inputs in the mk_informix Checkmk agent plugin before Checkmk 2.3.0b4 (beta), 2.2.0p24, 2.1.0p41 and 2.0.0 (EOL) allows local users to escalate privileges.

7.8
2024-03-21 CVE-2024-29880 Jetbrains Unspecified vulnerability in Jetbrains Teamcity

In JetBrains TeamCity before 2023.11 users with access to the agent machine might obtain permissions of the user running the agent process

7.8
2024-03-20 CVE-2024-1801 Progress Deserialization of Untrusted Data vulnerability in Progress Telerik Reporting

In Progress® Telerik® Reporting versions prior to 2024 Q1 (18.0.24.130), a code execution attack is possible by a local threat actor through an insecure deserialization vulnerability.

7.8
2024-03-19 CVE-2023-42920 Claris Unspecified vulnerability in Claris PRO and Filemaker PRO

Claris International has fixed a dylib hijacking vulnerability in the FileMaker Pro.app and Claris Pro.app versions on macOS.

7.8
2024-03-18 CVE-2024-20754 Adobe Unspecified vulnerability in Adobe Lightroom 5.1

Lightroom Desktop versions 7.1.2 and earlier are affected by an Untrusted Search Path vulnerability that could result in arbitrary code execution in the context of the current user.

7.8
2024-03-18 CVE-2023-52614 Linux Classic Buffer Overflow vulnerability in Linux Kernel

In the Linux kernel, the following vulnerability has been resolved: PM / devfreq: Fix buffer overflow in trans_stat_show Fix buffer overflow in trans_stat_show(). Convert simple snprintf to the more secure scnprintf with size of PAGE_SIZE. Add condition checking if we are exceeding PAGE_SIZE and exit early from loop.

7.8
2024-03-23 CVE-2024-1603 Paddlepaddle Unspecified vulnerability in Paddlepaddle 2.6.0

paddlepaddle/paddle 2.6.0 allows arbitrary file read via paddle.vision.ops.read_file.

7.5
2024-03-23 CVE-2024-24832 Metagauss Unspecified vulnerability in Metagauss Eventprime

Missing Authorization vulnerability in Metagauss EventPrime.This issue affects EventPrime: from n/a through 3.3.9.

7.5
2024-03-18 CVE-2024-21661 Argoproj Unspecified vulnerability in Argoproj Argo CD

Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes.

7.5
2024-03-18 CVE-2022-47037 Siklu Insufficiently Protected Credentials vulnerability in Siklu TG Firmware

Siklu TG Terragraph devices before 2.1.1 allow attackers to discover valid, randomly generated credentials via GetCredentials.

7.5
2024-03-18 CVE-2024-20767 Adobe Unspecified vulnerability in Adobe Coldfusion 2021/2023

ColdFusion versions 2023.6, 2021.12 and earlier are affected by an Improper Access Control vulnerability that could result in arbitrary file system read.

7.4
2024-03-20 CVE-2023-41877 Geoserver Path Traversal vulnerability in Geoserver

GeoServer is an open source software server written in Java that allows users to share and edit geospatial data.

7.2
2024-03-20 CVE-2023-51444 Geoserver Unrestricted Upload of File with Dangerous Type vulnerability in Geoserver

GeoServer is an open source software server written in Java that allows users to share and edit geospatial data.

7.2
2024-03-18 CVE-2024-28248 Cilium Unspecified vulnerability in Cilium

Cilium is a networking, observability, and security solution with an eBPF-based dataplane.

7.2

67 Medium Vulnerabilities

DATE CVE VENDOR VULNERABILITY CVSS
2024-03-19 CVE-2024-25942 Dell Out-of-bounds Write vulnerability in Dell products

Dell PowerEdge Server BIOS contains an Improper SMM communication buffer verification vulnerability.

6.8
2024-03-22 CVE-2024-0638 Checkmk Unspecified vulnerability in Checkmk

Least privilege violation in the Checkmk agent plugins mk_oracle, mk_oracle.ps1, and mk_oracle_crs before Checkmk 2.3.0b4 (beta), 2.2.0p24, 2.1.0p41 and 2.0.0 (EOL) allows local users to escalate privileges.

6.7
2024-03-22 CVE-2022-32753 IBM Unspecified vulnerability in IBM Security Verify Directory 10.0.0

IBM Security Verify Directory 10.0.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information.

6.5
2024-03-22 CVE-2024-2816 Tenda Unspecified vulnerability in Tenda Ac15 Firmware 15.03.05.18

A vulnerability classified as problematic was found in Tenda AC15 15.03.05.18.

6.5
2024-03-22 CVE-2024-2817 Tenda Unspecified vulnerability in Tenda Ac15 Firmware 15.03.05.18

A vulnerability, which was classified as problematic, has been found in Tenda AC15 15.03.05.18.

6.5
2024-03-21 CVE-2024-27936 Deno Unspecified vulnerability in Deno and Deno Runtime

Deno is a JavaScript, TypeScript, and WebAssembly runtime with secure defaults.

6.5
2024-03-20 CVE-2024-2626 Google
Fedoraproject
Out-of-bounds Read vulnerability in multiple products

Out of bounds read in Swiftshader in Google Chrome prior to 123.0.6312.58 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page.

6.5
2024-03-20 CVE-2024-2630 Google
Fedoraproject
Inappropriate implementation in iOS in Google Chrome prior to 123.0.6312.58 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
6.5
2024-03-19 CVE-2023-50811 Seling Unspecified vulnerability in Seling Visual Access Manager 4.38.6

An issue discovered in SELESTA Visual Access Manager 4.38.6 allows attackers to modify the “computer” POST parameter related to the ID of a specific reception by POST HTTP request interception.

6.5
2024-03-18 CVE-2024-27096 Glpi Project SQL Injection vulnerability in Glpi-Project Glpi

GLPI is a Free Asset and IT Management Software package, Data center management, ITIL Service Desk, licenses tracking and software auditing.

6.5
2024-03-18 CVE-2024-27930 Glpi Project Unspecified vulnerability in Glpi-Project Glpi

GLPI is a Free Asset and IT Management Software package, Data center management, ITIL Service Desk, licenses tracking and software auditing.

6.5
2024-03-21 CVE-2024-29877 Sapplica Unspecified vulnerability in Sapplica Sentrifugo 3.2

Cross-Site Scripting (XSS) vulnerability in Sentrifugo 3.2, through  /sentrifugo/index.php/expenses/expensecategories/edit, 'expense_category_name' parameter.

6.1
2024-03-21 CVE-2024-29878 Sapplica Unspecified vulnerability in Sapplica Sentrifugo 3.2

Cross-Site Scripting (XSS) vulnerability in Sentrifugo 3.2, through  /sentrifugo/index.php/sitepreference/add, 'description' parameter.

6.1
2024-03-21 CVE-2024-29879 Sapplica Unspecified vulnerability in Sapplica Sentrifugo 3.2

Cross-Site Scripting (XSS) vulnerability in Sentrifugo 3.2, through  /sentrifugo/index.php/index/getdepartments/format/html, 'business_id' parameter.

6.1
2024-03-19 CVE-2024-29113 Metagauss Unspecified vulnerability in Metagauss Registrationmagic

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Metagauss RegistrationMagic allows Reflected XSS.This issue affects RegistrationMagic: from n/a through 5.2.5.9.

6.1
2024-03-18 CVE-2024-28249 Cilium Cleartext Transmission of Sensitive Information vulnerability in Cilium

Cilium is a networking, observability, and security solution with an eBPF-based dataplane.

6.1
2024-03-18 CVE-2024-28250 Cilium Cleartext Transmission of Sensitive Information vulnerability in Cilium

Cilium is a networking, observability, and security solution with an eBPF-based dataplane.

6.1
2024-03-18 CVE-2024-28855 Zitadel Cross-site Scripting vulnerability in Zitadel

ZITADEL, open source authentication management software, uses Go templates to render the login UI.

6.1
2024-03-18 CVE-2024-27914 Glpi Project Cross-site Scripting vulnerability in Glpi-Project Glpi

GLPI is a Free Asset and IT Management Software package, Data center management, ITIL Service Desk, licenses tracking and software auditing.

6.1
2024-03-20 CVE-2024-23634 Geoserver Unspecified vulnerability in Geoserver

GeoServer is an open source software server written in Java that allows users to share and edit geospatial data.

6.0
2024-03-19 CVE-2024-22453 Dell Out-of-bounds Write vulnerability in Dell products

Dell PowerEdge Server BIOS contains a heap-based buffer overflow vulnerability.

6.0
2024-03-20 CVE-2023-35888 IBM Unspecified vulnerability in IBM Security Verify Governance 10.0.2

IBM Security Verify Governance 10.0.2 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security.

5.9
2024-03-21 CVE-2024-22352 IBM Unspecified vulnerability in IBM Infosphere Information Server 11.7

IBM InfoSphere Information Server 11.7 stores potentially sensitive information in log files that could be read by a local user.

5.5
2024-03-18 CVE-2023-52615 Linux Improper Locking vulnerability in Linux Kernel

In the Linux kernel, the following vulnerability has been resolved: hwrng: core - Fix page fault dead lock on mmap-ed hwrng There is a dead-lock in the hwrng device read path.

5.5
2024-03-23 CVE-2024-24840 Bdthemes Unspecified vulnerability in Bdthemes Element Pack

Missing Authorization vulnerability in BdThemes Element Pack Elementor Addons.This issue affects Element Pack Elementor Addons: from n/a through 5.4.11.

5.4
2024-03-23 CVE-2024-2468 Wpdeveloper Cross-site Scripting vulnerability in Wpdeveloper Embedpress

The EmbedPress – Embed PDF, Google Docs, Vimeo, Wistia, Embed YouTube Videos, Audios, Maps & Embed Any Documents in Gutenberg & Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the EmbedPress widget 'embedpress_pro_twitch_theme ' attribute in all versions up to, and including, 3.9.12 due to insufficient input sanitization and output escaping on user supplied attributes.

5.4
2024-03-23 CVE-2024-2688 Wpdeveloper Cross-site Scripting vulnerability in Wpdeveloper Embedpress

The EmbedPress – Embed PDF, Google Docs, Vimeo, Wistia, Embed YouTube Videos, Audios, Maps & Embed Any Documents in Gutenberg & Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the EmbedPress document widget in all versions up to, and including, 3.9.12 due to insufficient input sanitization and output escaping on user supplied attributes.

5.4
2024-03-23 CVE-2024-2131 Moveaddons Cross-site Scripting vulnerability in Moveaddons Move Addons for Elementor

The Move Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's infobox and button widget in all versions up to, and including, 1.2.9 due to insufficient input sanitization and output escaping on user supplied attributes.

5.4
2024-03-22 CVE-2024-2392 Creativethemes Cross-site Scripting vulnerability in Creativethemes Blocksy Companion

The Blocksy Companion plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Newsletter widget in all versions up to, and including, 2.0.31 due to insufficient input sanitization and output escaping on user supplied attributes.

5.4
2024-03-21 CVE-2024-1278 Easysocialfeed Cross-site Scripting vulnerability in Easysocialfeed Easy Social Feed

The Easy Social Feed – Social Photos Gallery – Post Feed – Like Box plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'efb_likebox' shortcode in all versions up to, and including, 6.5.4 due to insufficient input sanitization and output escaping on user supplied attributes.

5.4
2024-03-21 CVE-2024-1326 Jegtheme Cross-site Scripting vulnerability in Jegtheme JEG Elementor KIT

The Jeg Elementor Kit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via HTML Tag attributes in all versions up to, and including, 2.6.2 due to insufficient input sanitization and output escaping.

5.4
2024-03-20 CVE-2024-29471 Zhyd Cross-site Scripting vulnerability in Zhyd Oneblog 2.3.4

OneBlog v2.3.4 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Notice Manage module.

5.4
2024-03-20 CVE-2024-29472 Zhyd Cross-site Scripting vulnerability in Zhyd Oneblog 2.3.4

OneBlog v2.3.4 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Privilege Management module.

5.4
2024-03-20 CVE-2024-2255 Wpdeveloper Cross-site Scripting vulnerability in Wpdeveloper Essential Blocks

The Essential Blocks – Page Builder Gutenberg Blocks, Patterns & Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's widgets in all versions up to, and including, 4.5.2 due to insufficient input sanitization and output escaping on user supplied attributes such as listStyle.

5.4
2024-03-19 CVE-2024-29101 Jegtheme Unspecified vulnerability in Jegtheme JEG Elementor KIT

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jegtheme Jeg Elementor Kit allows Stored XSS.This issue affects Jeg Elementor Kit: from n/a through 2.6.2.

5.4
2024-03-19 CVE-2024-29106 Leap13 Unspecified vulnerability in Leap13 Premium Addons for Elementor

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Leap13 Premium Addons for Elementor allows Stored XSS.This issue affects Premium Addons for Elementor: from n/a through 4.10.16.

5.4
2024-03-19 CVE-2024-29107 Webtechstreet Unspecified vulnerability in Webtechstreet Elementor Addon Elements

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPVibes Elementor Addon Elements allows Stored XSS.This issue affects Elementor Addon Elements: from n/a through 1.12.10.

5.4
2024-03-19 CVE-2024-29108 Leevio Unspecified vulnerability in Leevio Happy Addons for Elementor

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Leevio Happy Addons for Elementor allows Stored XSS.This issue affects Happy Addons for Elementor: from n/a through 3.10.1.

5.4
2024-03-18 CVE-2024-26051 Adobe Unspecified vulnerability in Adobe Experience Manager

Adobe Experience Manager versions 6.5.19 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields.

5.4
2024-03-22 CVE-2022-32751 IBM Unspecified vulnerability in IBM Security Verify Directory 10.0.0

IBM Security Verify Directory 10.0.0 could disclose sensitive server information that could be used in further attacks against the system.

5.3
2024-03-19 CVE-2024-2645 Netentsec XML Injection (aka Blind XPath Injection) vulnerability in Netentsec Application Security Gateway 6.3

A vulnerability classified as problematic has been found in Netentsec NS-ASG Application Security Gateway 6.3.

5.3
2024-03-19 CVE-2024-2648 Netentsec XML Injection (aka Blind XPath Injection) vulnerability in Netentsec Application Security Gateway 6.3

A vulnerability, which was classified as problematic, was found in Netentsec NS-ASG Application Security Gateway 6.3.

5.3
2024-03-18 CVE-2024-26119 Adobe Unspecified vulnerability in Adobe Experience Manager

Adobe Experience Manager versions 6.5.19 and earlier are affected by an Information Exposure vulnerability that could result in a security feature bypass.

5.3
2024-03-21 CVE-2023-42954 Claris Unspecified vulnerability in Claris PRO and Filemaker Server

A privilege escalation issue existed in FileMaker Server, potentially exposing sensitive information to front-end websites when signed in to the Admin Console with an administrator role.

4.9
2024-03-22 CVE-2022-32754 IBM Unspecified vulnerability in IBM Security Verify Directory 10.0.0

IBM Security Verify Directory 10.0.0 is vulnerable to cross-site scripting.

4.8
2024-03-20 CVE-2024-23642 Geoserver Cross-site Scripting vulnerability in Geoserver

GeoServer is an open source software server written in Java that allows users to share and edit geospatial data.

4.8
2024-03-20 CVE-2024-23643 Geoserver Cross-site Scripting vulnerability in Geoserver

GeoServer is an open source software server written in Java that allows users to share and edit geospatial data.

4.8
2024-03-20 CVE-2024-23818 Geoserver Cross-site Scripting vulnerability in Geoserver

GeoServer is an open source software server written in Java that allows users to share and edit geospatial data.

4.8
2024-03-20 CVE-2024-23819 Geoserver Cross-site Scripting vulnerability in Geoserver

GeoServer is an open source software server written in Java that allows users to share and edit geospatial data.

4.8
2024-03-20 CVE-2024-23821 Geoserver Cross-site Scripting vulnerability in Geoserver

GeoServer is an open source software server written in Java that allows users to share and edit geospatial data.

4.8
2024-03-20 CVE-2023-51445 Geoserver Cross-site Scripting vulnerability in Geoserver

GeoServer is an open source software server written in Java that allows users to share and edit geospatial data.

4.8
2024-03-20 CVE-2024-23640 Geoserver Cross-site Scripting vulnerability in Geoserver

GeoServer is an open source software server written in Java that allows users to share and edit geospatial data.

4.8
2024-03-18 CVE-2024-28237 Octoprint Cross-site Scripting vulnerability in Octoprint

OctoPrint provides a web interface for controlling consumer 3D printers.

4.8
2024-03-18 CVE-2024-26050 Adobe Unspecified vulnerability in Adobe Experience Manager

Adobe Experience Manager versions 6.5.19 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an admin attacker to inject malicious scripts into vulnerable form fields.

4.8
2024-03-18 CVE-2024-27104 Glpi Project Cross-site Scripting vulnerability in Glpi-Project Glpi

GLPI is a Free Asset and IT Management Software package, Data center management, ITIL Service Desk, licenses tracking and software auditing.

4.8
2024-03-21 CVE-2024-27932 Deno Unspecified vulnerability in Deno

Deno is a JavaScript, TypeScript, and WebAssembly runtime.

4.6
2024-03-22 CVE-2024-29057 Microsoft Unspecified vulnerability in Microsoft Edge

Microsoft Edge (Chromium-based) Spoofing Vulnerability

4.3
2024-03-22 CVE-2024-2823 Dedecms Unspecified vulnerability in Dedecms 5.7

A vulnerability has been found in DedeCMS 5.7 and classified as problematic.

4.3
2024-03-22 CVE-2024-2820 Dedecms Unspecified vulnerability in Dedecms 5.7

A vulnerability classified as problematic was found in DedeCMS 5.7.

4.3
2024-03-21 CVE-2023-47715 IBM Unspecified vulnerability in IBM Storage Protect Plus 10.1.0/10.1.16

IBM Storage Protect Plus Server 10.1.0 through 10.1.16 could allow an authenticated user with read-only permissions to add or delete entries from an existing HyperVisor configuration.

4.3
2024-03-21 CVE-2024-1213 Easysocialfeed Cross-Site Request Forgery (CSRF) vulnerability in Easysocialfeed Easy Social Feed

The Easy Social Feed – Social Photos Gallery – Post Feed – Like Box plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 6.5.4.

4.3
2024-03-21 CVE-2024-1502 Themeum Missing Authorization vulnerability in Themeum Tutor LMS

The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the tutor_delete_announcement() function in all versions up to, and including, 2.6.1.

4.3
2024-03-20 CVE-2024-2628 Google
Fedoraproject
Inappropriate implementation in Downloads in Google Chrome prior to 123.0.6312.58 allowed a remote attacker to perform UI spoofing via a crafted URL.
4.3
2024-03-20 CVE-2024-2629 Google
Fedoraproject
Incorrect security UI in iOS in Google Chrome prior to 123.0.6312.58 allowed a remote attacker to perform UI spoofing via a crafted HTML page.
4.3
2024-03-20 CVE-2024-2631 Google
Fedoraproject
Inappropriate implementation in iOS in Google Chrome prior to 123.0.6312.58 allowed a remote attacker to perform UI spoofing via a crafted HTML page.
4.3
2024-03-20 CVE-2024-2291 Progress Unspecified vulnerability in Progress Moveit Transfer

In Progress MOVEit Transfer versions released before 2022.0.11 (14.0.11), 2022.1.12 (14.1.12), 2023.0.9 (15.0.9), 2023.1.4 (15.1.4), a logging bypass vulnerability has been discovered.  An authenticated user could manipulate a request to bypass the logging mechanism within the web application which results in user activity not being logged properly.

4.3
2024-03-18 CVE-2024-27937 Glpi Project Unspecified vulnerability in Glpi-Project Glpi

GLPI is a Free Asset and IT Management Software package, Data center management, ITIL Service Desk, licenses tracking and software auditing.

4.3

2 Low Vulnerabilities

DATE CVE VENDOR VULNERABILITY CVSS
2024-03-22 CVE-2024-1742 Checkmk Unspecified vulnerability in Checkmk

Invocation of the sqlplus command with sensitive information in the command line in the mk_oracle Checkmk agent plugin before Checkmk 2.3.0b4 (beta), 2.2.0p24, 2.1.0p41 and 2.0.0 (EOL) allows the extraction of this information from the process list.

3.3
2024-03-22 CVE-2022-32756 IBM Unspecified vulnerability in IBM Security Verify Directory 10.0.0

IBM Security Verify Directory 10.0.0 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser.

2.7