Weekly Vulnerabilities Reports > March 18 to 24, 2024
Overview
142 new vulnerabilities reported during this period, including 29 critical vulnerabilities and 44 high severity vulnerabilities. This weekly summary report vulnerabilities in 79 products from 40 vendors including Tenda, Geoserver, Sapplica, Google, and IBM. Vulnerabilities are notably categorized as "Cross-site Scripting", "Out-of-bounds Write", "Code Injection", "Deserialization of Untrusted Data", and "XML Injection (aka Blind XPath Injection)".
- 125 reported vulnerabilities are remotely exploitables.
- 33 reported vulnerabilities are related to weaknesses in OWASP Top Ten.
- 64 reported vulnerabilities are exploitable by an anonymous user.
- Tenda has the most reported vulnerabilities, with 32 reported vulnerabilities.
- Tenda has the most reported critical vulnerabilities, with 16 reported vulnerabilities.
VULNERABILITIES
VULNERABILITIES
VULNERABILITIES
VULNERABILITIES
VULNERABILITIES
EXPLOITABLE
EXPLOITABLE
AVAILABLE
ANONYMOUSLY
WEB APPLICATION
Vulnerability Details
The following table list reported vulnerabilities for the period covered by this report:
29 Critical Vulnerabilities
DATE | CVE | VENDOR | VULNERABILITY | CVSS |
---|---|---|---|---|
2024-03-24 | CVE-2024-2856 | Tenda | Unspecified vulnerability in Tenda Ac10 Firmware 16.03.10.13/16.03.10.20 A vulnerability, which was classified as critical, has been found in Tenda AC10 16.03.10.13/16.03.10.20. | 9.8 |
2024-03-24 | CVE-2024-2854 | Tenda | Unspecified vulnerability in Tenda Ac18 Firmware 15.03.05.05 A vulnerability classified as critical has been found in Tenda AC18 15.03.05.05. | 9.8 |
2024-03-24 | CVE-2024-2855 | Tenda | Unspecified vulnerability in Tenda Ac15 Firmware 15.03.05.18/15.03.05.19/15.03.20Multi A vulnerability classified as critical was found in Tenda AC15 15.03.05.18/15.03.05.19/15.03.20. | 9.8 |
2024-03-24 | CVE-2024-2852 | Tenda | Unspecified vulnerability in Tenda Ac15 Firmware 15.03.20Multi A vulnerability was found in Tenda AC15 15.03.20_multi. | 9.8 |
2024-03-24 | CVE-2024-2853 | Tenda | Unspecified vulnerability in Tenda Ac10U Firmware 15.03.06.48/15.03.06.49 A vulnerability was found in Tenda AC10U 15.03.06.48/15.03.06.49. | 9.8 |
2024-03-24 | CVE-2024-2851 | Tenda | Unspecified vulnerability in Tenda Ac15 Firmware 15.03.05.18/15.03.20Multi A vulnerability was found in Tenda AC15 15.03.05.18/15.03.20_multi. | 9.8 |
2024-03-24 | CVE-2024-2850 | Tenda | Unspecified vulnerability in Tenda Ac15 Firmware 15.03.05.18 A vulnerability was found in Tenda AC15 15.03.05.18 and classified as critical. | 9.8 |
2024-03-22 | CVE-2024-2815 | Tenda | Unspecified vulnerability in Tenda Ac15 Firmware 15.03.05.20Multi A vulnerability classified as critical has been found in Tenda AC15 15.03.20_multi. | 9.8 |
2024-03-22 | CVE-2024-2813 | Tenda | Unspecified vulnerability in Tenda Ac15 Firmware 15.03.05.20Multi A vulnerability was found in Tenda AC15 15.03.20_multi. | 9.8 |
2024-03-22 | CVE-2024-2814 | Tenda | Unspecified vulnerability in Tenda Ac15 Firmware 15.03.05.20Multi A vulnerability was found in Tenda AC15 15.03.20_multi. | 9.8 |
2024-03-22 | CVE-2024-2809 | Tenda | Unspecified vulnerability in Tenda Ac15 Firmware 15.03.05.18/15.03.05.20Multi A vulnerability, which was classified as critical, was found in Tenda AC15 15.03.05.18/15.03.20_multi. | 9.8 |
2024-03-22 | CVE-2024-2810 | Tenda | Unspecified vulnerability in Tenda Ac15 Firmware 15.03.05.18/15.03.05.20Multi A vulnerability has been found in Tenda AC15 15.03.05.18/15.03.20_multi and classified as critical. | 9.8 |
2024-03-22 | CVE-2024-2811 | Tenda | Unspecified vulnerability in Tenda Ac15 Firmware 15.03.05.20Multi A vulnerability was found in Tenda AC15 15.03.20_multi and classified as critical. | 9.8 |
2024-03-22 | CVE-2024-2806 | Tenda | Unspecified vulnerability in Tenda Ac15 Firmware 15.03.05.18/15.03.05.20Multi A vulnerability classified as critical has been found in Tenda AC15 15.03.05.18/15.03.20_multi. | 9.8 |
2024-03-22 | CVE-2024-2807 | Tenda | Unspecified vulnerability in Tenda Ac15 Firmware 15.03.05.18/15.03.05.20Multi A vulnerability classified as critical was found in Tenda AC15 15.03.05.18/15.03.20_multi. | 9.8 |
2024-03-22 | CVE-2024-2808 | Tenda | Unspecified vulnerability in Tenda Ac15 Firmware 15.03.05.18/15.03.05.20Multi A vulnerability, which was classified as critical, has been found in Tenda AC15 15.03.05.18/15.03.20_multi. | 9.8 |
2024-03-21 | CVE-2024-29870 | Sapplica | Unspecified vulnerability in Sapplica Sentrifugo 3.2 SQL injection vulnerability in Sentrifugo 3.2, through /sentrifugo/index.php/index/getdepartments/format/html, 'business_id' parameter./sentrifugo/index.php/index/getdepartments/format/html, 'business_id' parameter. | 9.8 |
2024-03-21 | CVE-2024-29871 | Sapplica | Unspecified vulnerability in Sapplica Sentrifugo 3.2 SQL injection vulnerability in Sentrifugo 3.2, through /sentrifugo/index.php/index/getdepartments/sentrifugo/index.php/index/updatecontactnumber, 'id' parameter. | 9.8 |
2024-03-21 | CVE-2024-29872 | Sapplica | Unspecified vulnerability in Sapplica Sentrifugo 3.2 SQL injection vulnerability in Sentrifugo 3.2, through /sentrifugo/index.php/empscreening/add, 'agencyids' parameter. | 9.8 |
2024-03-21 | CVE-2024-29873 | Sapplica | Unspecified vulnerability in Sapplica Sentrifugo 3.2 SQL injection vulnerability in Sentrifugo 3.2, through /sentrifugo/index.php/reports/businessunits/format/html, 'bunitname' parameter. | 9.8 |
2024-03-21 | CVE-2024-29874 | Sapplica | Unspecified vulnerability in Sapplica Sentrifugo 3.2 SQL injection vulnerability in Sentrifugo 3.2, through /sentrifugo/index.php/default/reports/activeuserrptpdf, 'sort_name' parameter. | 9.8 |
2024-03-21 | CVE-2024-29875 | Sapplica | Unspecified vulnerability in Sapplica Sentrifugo 3.2 SQL injection vulnerability in Sentrifugo 3.2, through /sentrifugo/index.php/default/reports/exportactiveuserrpt, 'sort_name' parameter. | 9.8 |
2024-03-21 | CVE-2024-29876 | Sapplica | Unspecified vulnerability in Sapplica Sentrifugo 3.2 SQL injection vulnerability in Sentrifugo 3.2, through /sentrifugo/index.php/reports/activitylogreport, 'sortby' parameter. | 9.8 |
2024-03-20 | CVE-2024-2649 | Netentsec | Unspecified vulnerability in Netentsec Application Security Gateway 6.3 A vulnerability has been found in Netentsec NS-ASG Application Security Gateway 6.3 and classified as critical. | 9.8 |
2024-03-19 | CVE-2024-2646 | Netentsec | Unspecified vulnerability in Netentsec Application Security Gateway 6.3 A vulnerability classified as critical was found in Netentsec NS-ASG Application Security Gateway 6.3. | 9.8 |
2024-03-18 | CVE-2024-21652 | Argoproj | Improper Restriction of Excessive Authentication Attempts vulnerability in Argoproj Argo CD Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. | 9.8 |
2024-03-18 | CVE-2024-27098 | Glpi Project | Server-Side Request Forgery (SSRF) vulnerability in Glpi-Project Glpi GLPI is a Free Asset and IT Management Software package, Data center management, ITIL Service Desk, licenses tracking and software auditing. | 9.6 |
2024-03-18 | CVE-2024-21662 | Argoproj | Improper Restriction of Excessive Authentication Attempts vulnerability in Argoproj Argo CD Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. | 9.1 |
2024-03-22 | CVE-2024-29185 | Freescout | OS Command Injection vulnerability in Freescout FreeScout is a self-hosted help desk and shared mailbox. | 9.0 |
44 High Vulnerabilities
DATE | CVE | VENDOR | VULNERABILITY | CVSS |
---|---|---|---|---|
2024-03-22 | CVE-2024-2812 | Tenda | Unspecified vulnerability in Tenda Ac15 Firmware 15.03.05.18/15.03.05.20Multi A vulnerability was found in Tenda AC15 15.03.05.18/15.03.20_multi. | 8.8 |
2024-03-22 | CVE-2024-2805 | Tenda | Out-of-bounds Write vulnerability in Tenda Ac15 Firmware 15.03.05.18/15.03.05.20Multi A vulnerability was found in Tenda AC15 15.03.05.18/15.03.20_multi. | 8.8 |
2024-03-21 | CVE-2024-25937 | Deltaww | Unspecified vulnerability in Deltaww Diaenergie SQL injection vulnerability exists in the script DIAE_tagHandler.ashx. | 8.8 |
2024-03-21 | CVE-2024-27921 | Getgrav | Path Traversal vulnerability in Getgrav Grav Grav is an open-source, flat-file content management system. | 8.8 |
2024-03-21 | CVE-2024-28029 | Deltaww | Unspecified vulnerability in Deltaww Diaenergie Privileges are not fully verified server-side, which can be abused by a user with limited privileges to bypass authorization and access privileged functionality. | 8.8 |
2024-03-21 | CVE-2024-28116 | Getgrav | Code Injection vulnerability in Getgrav Grav Grav is an open-source, flat-file content management system. | 8.8 |
2024-03-21 | CVE-2024-28117 | Getgrav | Code Injection vulnerability in Getgrav Grav Grav is an open-source, flat-file content management system. | 8.8 |
2024-03-21 | CVE-2024-28118 | Getgrav | Code Injection vulnerability in Getgrav Grav Grav is an open-source, flat-file content management system. | 8.8 |
2024-03-21 | CVE-2024-28119 | Getgrav | Code Injection vulnerability in Getgrav Grav Grav is an open-source, flat-file content management system. | 8.8 |
2024-03-21 | CVE-2024-2763 | Tenda | Out-of-bounds Write vulnerability in Tenda Ac10U Firmware 15.03.06.48 A vulnerability, which was classified as critical, has been found in Tenda AC10U 15.03.06.48. | 8.8 |
2024-03-21 | CVE-2024-2764 | Tenda | Out-of-bounds Write vulnerability in Tenda Ac10U Firmware 15.03.06.48 A vulnerability, which was classified as critical, was found in Tenda AC10U 15.03.06.48. | 8.8 |
2024-03-21 | CVE-2024-27923 | Getgrav | Unrestricted Upload of File with Dangerous Type vulnerability in Getgrav Grav Grav is a content management system (CMS). | 8.8 |
2024-03-21 | CVE-2024-27933 | Deno | Incorrect Authorization vulnerability in Deno 1.39.0 Deno is a JavaScript, TypeScript, and WebAssembly runtime. | 8.8 |
2024-03-21 | CVE-2024-27934 | Deno | Use After Free vulnerability in Deno Deno is a JavaScript, TypeScript, and WebAssembly runtime. | 8.8 |
2024-03-20 | CVE-2024-2708 | Tenda | Out-of-bounds Write vulnerability in Tenda Ac10U Firmware 15.03.06.49 A vulnerability was found in Tenda AC10U 15.03.06.49 and classified as critical. | 8.8 |
2024-03-20 | CVE-2024-2709 | Tenda | Out-of-bounds Write vulnerability in Tenda Ac10U Firmware 15.03.06.49 A vulnerability was found in Tenda AC10U 15.03.06.49. | 8.8 |
2024-03-20 | CVE-2024-2710 | Tenda | Out-of-bounds Write vulnerability in Tenda Ac10U Firmware 15.03.06.49 A vulnerability was found in Tenda AC10U 15.03.06.49. | 8.8 |
2024-03-20 | CVE-2024-2711 | Tenda | Out-of-bounds Write vulnerability in Tenda Ac10U Firmware 15.03.06.48 A vulnerability was found in Tenda AC10U 15.03.06.48. | 8.8 |
2024-03-20 | CVE-2024-2625 | Google Fedoraproject | Object lifecycle issue in V8 in Google Chrome prior to 123.0.6312.58 allowed a remote attacker to potentially exploit object corruption via a crafted HTML page. | 8.8 |
2024-03-20 | CVE-2024-2627 | Google Fedoraproject | Use After Free vulnerability in multiple products Use after free in Canvas in Google Chrome prior to 123.0.6312.58 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | 8.8 |
2024-03-20 | CVE-2024-2705 | Tenda | Out-of-bounds Write vulnerability in Tenda Ac10U Firmware 15.03.06.49 A vulnerability, which was classified as critical, has been found in Tenda AC10U 1.0/15.03.06.49. | 8.8 |
2024-03-20 | CVE-2024-2706 | Tenda | Out-of-bounds Write vulnerability in Tenda Ac10U Firmware 15.03.06.49 A vulnerability, which was classified as critical, was found in Tenda AC10U 15.03.06.49. | 8.8 |
2024-03-20 | CVE-2024-2707 | Tenda | Unspecified vulnerability in Tenda Ac10U Firmware 15.03.06.49 A vulnerability has been found in Tenda AC10U 15.03.06.49 and classified as critical. | 8.8 |
2024-03-20 | CVE-2024-2703 | Tenda | Out-of-bounds Write vulnerability in Tenda Ac10U Firmware 15.03.06.49 A vulnerability classified as critical has been found in Tenda AC10U 15.03.06.49. | 8.8 |
2024-03-20 | CVE-2024-2704 | Tenda | Out-of-bounds Write vulnerability in Tenda Ac10U Firmware 15.03.06.49 A vulnerability classified as critical was found in Tenda AC10U 15.03.06.49. | 8.8 |
2024-03-20 | CVE-2024-1800 | Progress | Deserialization of Untrusted Data vulnerability in Progress Telerik Report Server In Progress® Telerik® Report Server versions prior to 2024 Q1 (10.0.24.130), a remote code execution attack is possible through an insecure deserialization vulnerability. | 8.8 |
2024-03-20 | CVE-2024-1856 | Progress | Deserialization of Untrusted Data vulnerability in Progress Telerik Reporting In Progress® Telerik® Reporting versions prior to 2024 Q1 (18.0.24.130), a code execution attack is possible by a remote threat actor through an insecure deserialization vulnerability. | 8.8 |
2024-03-18 | CVE-2024-2581 | Tenda | Out-of-bounds Write vulnerability in Tenda Ac10 Firmware 16.03.10.13 A vulnerability was found in Tenda AC10 16.03.10.13 and classified as critical. | 8.8 |
2024-03-21 | CVE-2024-27935 | Deno | Unspecified vulnerability in Deno Deno is a JavaScript, TypeScript, and WebAssembly runtime. | 8.3 |
2024-03-22 | CVE-2024-29184 | Freescout | Cross-site Scripting vulnerability in Freescout FreeScout is a self-hosted help desk and shared mailbox. | 8.0 |
2024-03-22 | CVE-2024-28824 | Checkmk | Unspecified vulnerability in Checkmk Least privilege violation and reliance on untrusted inputs in the mk_informix Checkmk agent plugin before Checkmk 2.3.0b4 (beta), 2.2.0p24, 2.1.0p41 and 2.0.0 (EOL) allows local users to escalate privileges. | 7.8 |
2024-03-21 | CVE-2024-29880 | Jetbrains | Unspecified vulnerability in Jetbrains Teamcity In JetBrains TeamCity before 2023.11 users with access to the agent machine might obtain permissions of the user running the agent process | 7.8 |
2024-03-20 | CVE-2024-1801 | Progress | Deserialization of Untrusted Data vulnerability in Progress Telerik Reporting In Progress® Telerik® Reporting versions prior to 2024 Q1 (18.0.24.130), a code execution attack is possible by a local threat actor through an insecure deserialization vulnerability. | 7.8 |
2024-03-19 | CVE-2023-42920 | Claris | Unspecified vulnerability in Claris PRO and Filemaker PRO Claris International has fixed a dylib hijacking vulnerability in the FileMaker Pro.app and Claris Pro.app versions on macOS. | 7.8 |
2024-03-18 | CVE-2024-20754 | Adobe | Unspecified vulnerability in Adobe Lightroom 5.1 Lightroom Desktop versions 7.1.2 and earlier are affected by an Untrusted Search Path vulnerability that could result in arbitrary code execution in the context of the current user. | 7.8 |
2024-03-18 | CVE-2023-52614 | Linux | Classic Buffer Overflow vulnerability in Linux Kernel In the Linux kernel, the following vulnerability has been resolved: PM / devfreq: Fix buffer overflow in trans_stat_show Fix buffer overflow in trans_stat_show(). Convert simple snprintf to the more secure scnprintf with size of PAGE_SIZE. Add condition checking if we are exceeding PAGE_SIZE and exit early from loop. | 7.8 |
2024-03-23 | CVE-2024-1603 | Paddlepaddle | Unspecified vulnerability in Paddlepaddle 2.6.0 paddlepaddle/paddle 2.6.0 allows arbitrary file read via paddle.vision.ops.read_file. | 7.5 |
2024-03-23 | CVE-2024-24832 | Metagauss | Unspecified vulnerability in Metagauss Eventprime Missing Authorization vulnerability in Metagauss EventPrime.This issue affects EventPrime: from n/a through 3.3.9. | 7.5 |
2024-03-18 | CVE-2024-21661 | Argoproj | Unspecified vulnerability in Argoproj Argo CD Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. | 7.5 |
2024-03-18 | CVE-2022-47037 | Siklu | Insufficiently Protected Credentials vulnerability in Siklu TG Firmware Siklu TG Terragraph devices before 2.1.1 allow attackers to discover valid, randomly generated credentials via GetCredentials. | 7.5 |
2024-03-18 | CVE-2024-20767 | Adobe | Unspecified vulnerability in Adobe Coldfusion 2021/2023 ColdFusion versions 2023.6, 2021.12 and earlier are affected by an Improper Access Control vulnerability that could result in arbitrary file system read. | 7.4 |
2024-03-20 | CVE-2023-41877 | Geoserver | Path Traversal vulnerability in Geoserver GeoServer is an open source software server written in Java that allows users to share and edit geospatial data. | 7.2 |
2024-03-20 | CVE-2023-51444 | Geoserver | Unrestricted Upload of File with Dangerous Type vulnerability in Geoserver GeoServer is an open source software server written in Java that allows users to share and edit geospatial data. | 7.2 |
2024-03-18 | CVE-2024-28248 | Cilium | Unspecified vulnerability in Cilium Cilium is a networking, observability, and security solution with an eBPF-based dataplane. | 7.2 |
67 Medium Vulnerabilities
DATE | CVE | VENDOR | VULNERABILITY | CVSS |
---|---|---|---|---|
2024-03-19 | CVE-2024-25942 | Dell | Out-of-bounds Write vulnerability in Dell products Dell PowerEdge Server BIOS contains an Improper SMM communication buffer verification vulnerability. | 6.8 |
2024-03-22 | CVE-2024-0638 | Checkmk | Unspecified vulnerability in Checkmk Least privilege violation in the Checkmk agent plugins mk_oracle, mk_oracle.ps1, and mk_oracle_crs before Checkmk 2.3.0b4 (beta), 2.2.0p24, 2.1.0p41 and 2.0.0 (EOL) allows local users to escalate privileges. | 6.7 |
2024-03-22 | CVE-2022-32753 | IBM | Unspecified vulnerability in IBM Security Verify Directory 10.0.0 IBM Security Verify Directory 10.0.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. | 6.5 |
2024-03-22 | CVE-2024-2816 | Tenda | Unspecified vulnerability in Tenda Ac15 Firmware 15.03.05.18 A vulnerability classified as problematic was found in Tenda AC15 15.03.05.18. | 6.5 |
2024-03-22 | CVE-2024-2817 | Tenda | Unspecified vulnerability in Tenda Ac15 Firmware 15.03.05.18 A vulnerability, which was classified as problematic, has been found in Tenda AC15 15.03.05.18. | 6.5 |
2024-03-21 | CVE-2024-27936 | Deno | Unspecified vulnerability in Deno and Deno Runtime Deno is a JavaScript, TypeScript, and WebAssembly runtime with secure defaults. | 6.5 |
2024-03-20 | CVE-2024-2626 | Google Fedoraproject | Out-of-bounds Read vulnerability in multiple products Out of bounds read in Swiftshader in Google Chrome prior to 123.0.6312.58 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. | 6.5 |
2024-03-20 | CVE-2024-2630 | Google Fedoraproject | Inappropriate implementation in iOS in Google Chrome prior to 123.0.6312.58 allowed a remote attacker to leak cross-origin data via a crafted HTML page. | 6.5 |
2024-03-19 | CVE-2023-50811 | Seling | Unspecified vulnerability in Seling Visual Access Manager 4.38.6 An issue discovered in SELESTA Visual Access Manager 4.38.6 allows attackers to modify the “computer” POST parameter related to the ID of a specific reception by POST HTTP request interception. | 6.5 |
2024-03-18 | CVE-2024-27096 | Glpi Project | SQL Injection vulnerability in Glpi-Project Glpi GLPI is a Free Asset and IT Management Software package, Data center management, ITIL Service Desk, licenses tracking and software auditing. | 6.5 |
2024-03-18 | CVE-2024-27930 | Glpi Project | Unspecified vulnerability in Glpi-Project Glpi GLPI is a Free Asset and IT Management Software package, Data center management, ITIL Service Desk, licenses tracking and software auditing. | 6.5 |
2024-03-21 | CVE-2024-29877 | Sapplica | Unspecified vulnerability in Sapplica Sentrifugo 3.2 Cross-Site Scripting (XSS) vulnerability in Sentrifugo 3.2, through /sentrifugo/index.php/expenses/expensecategories/edit, 'expense_category_name' parameter. | 6.1 |
2024-03-21 | CVE-2024-29878 | Sapplica | Unspecified vulnerability in Sapplica Sentrifugo 3.2 Cross-Site Scripting (XSS) vulnerability in Sentrifugo 3.2, through /sentrifugo/index.php/sitepreference/add, 'description' parameter. | 6.1 |
2024-03-21 | CVE-2024-29879 | Sapplica | Unspecified vulnerability in Sapplica Sentrifugo 3.2 Cross-Site Scripting (XSS) vulnerability in Sentrifugo 3.2, through /sentrifugo/index.php/index/getdepartments/format/html, 'business_id' parameter. | 6.1 |
2024-03-19 | CVE-2024-29113 | Metagauss | Unspecified vulnerability in Metagauss Registrationmagic Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Metagauss RegistrationMagic allows Reflected XSS.This issue affects RegistrationMagic: from n/a through 5.2.5.9. | 6.1 |
2024-03-18 | CVE-2024-28249 | Cilium | Cleartext Transmission of Sensitive Information vulnerability in Cilium Cilium is a networking, observability, and security solution with an eBPF-based dataplane. | 6.1 |
2024-03-18 | CVE-2024-28250 | Cilium | Cleartext Transmission of Sensitive Information vulnerability in Cilium Cilium is a networking, observability, and security solution with an eBPF-based dataplane. | 6.1 |
2024-03-18 | CVE-2024-28855 | Zitadel | Cross-site Scripting vulnerability in Zitadel ZITADEL, open source authentication management software, uses Go templates to render the login UI. | 6.1 |
2024-03-18 | CVE-2024-27914 | Glpi Project | Cross-site Scripting vulnerability in Glpi-Project Glpi GLPI is a Free Asset and IT Management Software package, Data center management, ITIL Service Desk, licenses tracking and software auditing. | 6.1 |
2024-03-20 | CVE-2024-23634 | Geoserver | Unspecified vulnerability in Geoserver GeoServer is an open source software server written in Java that allows users to share and edit geospatial data. | 6.0 |
2024-03-19 | CVE-2024-22453 | Dell | Out-of-bounds Write vulnerability in Dell products Dell PowerEdge Server BIOS contains a heap-based buffer overflow vulnerability. | 6.0 |
2024-03-20 | CVE-2023-35888 | IBM | Unspecified vulnerability in IBM Security Verify Governance 10.0.2 IBM Security Verify Governance 10.0.2 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. | 5.9 |
2024-03-21 | CVE-2024-22352 | IBM | Unspecified vulnerability in IBM Infosphere Information Server 11.7 IBM InfoSphere Information Server 11.7 stores potentially sensitive information in log files that could be read by a local user. | 5.5 |
2024-03-18 | CVE-2023-52615 | Linux | Improper Locking vulnerability in Linux Kernel In the Linux kernel, the following vulnerability has been resolved: hwrng: core - Fix page fault dead lock on mmap-ed hwrng There is a dead-lock in the hwrng device read path. | 5.5 |
2024-03-23 | CVE-2024-24840 | Bdthemes | Unspecified vulnerability in Bdthemes Element Pack Missing Authorization vulnerability in BdThemes Element Pack Elementor Addons.This issue affects Element Pack Elementor Addons: from n/a through 5.4.11. | 5.4 |
2024-03-23 | CVE-2024-2468 | Wpdeveloper | Cross-site Scripting vulnerability in Wpdeveloper Embedpress The EmbedPress – Embed PDF, Google Docs, Vimeo, Wistia, Embed YouTube Videos, Audios, Maps & Embed Any Documents in Gutenberg & Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the EmbedPress widget 'embedpress_pro_twitch_theme ' attribute in all versions up to, and including, 3.9.12 due to insufficient input sanitization and output escaping on user supplied attributes. | 5.4 |
2024-03-23 | CVE-2024-2688 | Wpdeveloper | Cross-site Scripting vulnerability in Wpdeveloper Embedpress The EmbedPress – Embed PDF, Google Docs, Vimeo, Wistia, Embed YouTube Videos, Audios, Maps & Embed Any Documents in Gutenberg & Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the EmbedPress document widget in all versions up to, and including, 3.9.12 due to insufficient input sanitization and output escaping on user supplied attributes. | 5.4 |
2024-03-23 | CVE-2024-2131 | Moveaddons | Cross-site Scripting vulnerability in Moveaddons Move Addons for Elementor The Move Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's infobox and button widget in all versions up to, and including, 1.2.9 due to insufficient input sanitization and output escaping on user supplied attributes. | 5.4 |
2024-03-22 | CVE-2024-2392 | Creativethemes | Cross-site Scripting vulnerability in Creativethemes Blocksy Companion The Blocksy Companion plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Newsletter widget in all versions up to, and including, 2.0.31 due to insufficient input sanitization and output escaping on user supplied attributes. | 5.4 |
2024-03-21 | CVE-2024-1278 | Easysocialfeed | Cross-site Scripting vulnerability in Easysocialfeed Easy Social Feed The Easy Social Feed – Social Photos Gallery – Post Feed – Like Box plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'efb_likebox' shortcode in all versions up to, and including, 6.5.4 due to insufficient input sanitization and output escaping on user supplied attributes. | 5.4 |
2024-03-21 | CVE-2024-1326 | Jegtheme | Cross-site Scripting vulnerability in Jegtheme JEG Elementor KIT The Jeg Elementor Kit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via HTML Tag attributes in all versions up to, and including, 2.6.2 due to insufficient input sanitization and output escaping. | 5.4 |
2024-03-20 | CVE-2024-29471 | Zhyd | Cross-site Scripting vulnerability in Zhyd Oneblog 2.3.4 OneBlog v2.3.4 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Notice Manage module. | 5.4 |
2024-03-20 | CVE-2024-29472 | Zhyd | Cross-site Scripting vulnerability in Zhyd Oneblog 2.3.4 OneBlog v2.3.4 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Privilege Management module. | 5.4 |
2024-03-20 | CVE-2024-2255 | Wpdeveloper | Cross-site Scripting vulnerability in Wpdeveloper Essential Blocks The Essential Blocks – Page Builder Gutenberg Blocks, Patterns & Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's widgets in all versions up to, and including, 4.5.2 due to insufficient input sanitization and output escaping on user supplied attributes such as listStyle. | 5.4 |
2024-03-19 | CVE-2024-29101 | Jegtheme | Unspecified vulnerability in Jegtheme JEG Elementor KIT Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jegtheme Jeg Elementor Kit allows Stored XSS.This issue affects Jeg Elementor Kit: from n/a through 2.6.2. | 5.4 |
2024-03-19 | CVE-2024-29106 | Leap13 | Unspecified vulnerability in Leap13 Premium Addons for Elementor Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Leap13 Premium Addons for Elementor allows Stored XSS.This issue affects Premium Addons for Elementor: from n/a through 4.10.16. | 5.4 |
2024-03-19 | CVE-2024-29107 | Webtechstreet | Unspecified vulnerability in Webtechstreet Elementor Addon Elements Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPVibes Elementor Addon Elements allows Stored XSS.This issue affects Elementor Addon Elements: from n/a through 1.12.10. | 5.4 |
2024-03-19 | CVE-2024-29108 | Leevio | Unspecified vulnerability in Leevio Happy Addons for Elementor Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Leevio Happy Addons for Elementor allows Stored XSS.This issue affects Happy Addons for Elementor: from n/a through 3.10.1. | 5.4 |
2024-03-18 | CVE-2024-26051 | Adobe | Unspecified vulnerability in Adobe Experience Manager Adobe Experience Manager versions 6.5.19 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. | 5.4 |
2024-03-22 | CVE-2022-32751 | IBM | Unspecified vulnerability in IBM Security Verify Directory 10.0.0 IBM Security Verify Directory 10.0.0 could disclose sensitive server information that could be used in further attacks against the system. | 5.3 |
2024-03-19 | CVE-2024-2645 | Netentsec | XML Injection (aka Blind XPath Injection) vulnerability in Netentsec Application Security Gateway 6.3 A vulnerability classified as problematic has been found in Netentsec NS-ASG Application Security Gateway 6.3. | 5.3 |
2024-03-19 | CVE-2024-2648 | Netentsec | XML Injection (aka Blind XPath Injection) vulnerability in Netentsec Application Security Gateway 6.3 A vulnerability, which was classified as problematic, was found in Netentsec NS-ASG Application Security Gateway 6.3. | 5.3 |
2024-03-18 | CVE-2024-26119 | Adobe | Unspecified vulnerability in Adobe Experience Manager Adobe Experience Manager versions 6.5.19 and earlier are affected by an Information Exposure vulnerability that could result in a security feature bypass. | 5.3 |
2024-03-21 | CVE-2023-42954 | Claris | Unspecified vulnerability in Claris PRO and Filemaker Server A privilege escalation issue existed in FileMaker Server, potentially exposing sensitive information to front-end websites when signed in to the Admin Console with an administrator role. | 4.9 |
2024-03-22 | CVE-2022-32754 | IBM | Unspecified vulnerability in IBM Security Verify Directory 10.0.0 IBM Security Verify Directory 10.0.0 is vulnerable to cross-site scripting. | 4.8 |
2024-03-20 | CVE-2024-23642 | Geoserver | Cross-site Scripting vulnerability in Geoserver GeoServer is an open source software server written in Java that allows users to share and edit geospatial data. | 4.8 |
2024-03-20 | CVE-2024-23643 | Geoserver | Cross-site Scripting vulnerability in Geoserver GeoServer is an open source software server written in Java that allows users to share and edit geospatial data. | 4.8 |
2024-03-20 | CVE-2024-23818 | Geoserver | Cross-site Scripting vulnerability in Geoserver GeoServer is an open source software server written in Java that allows users to share and edit geospatial data. | 4.8 |
2024-03-20 | CVE-2024-23819 | Geoserver | Cross-site Scripting vulnerability in Geoserver GeoServer is an open source software server written in Java that allows users to share and edit geospatial data. | 4.8 |
2024-03-20 | CVE-2024-23821 | Geoserver | Cross-site Scripting vulnerability in Geoserver GeoServer is an open source software server written in Java that allows users to share and edit geospatial data. | 4.8 |
2024-03-20 | CVE-2023-51445 | Geoserver | Cross-site Scripting vulnerability in Geoserver GeoServer is an open source software server written in Java that allows users to share and edit geospatial data. | 4.8 |
2024-03-20 | CVE-2024-23640 | Geoserver | Cross-site Scripting vulnerability in Geoserver GeoServer is an open source software server written in Java that allows users to share and edit geospatial data. | 4.8 |
2024-03-18 | CVE-2024-28237 | Octoprint | Cross-site Scripting vulnerability in Octoprint OctoPrint provides a web interface for controlling consumer 3D printers. | 4.8 |
2024-03-18 | CVE-2024-26050 | Adobe | Unspecified vulnerability in Adobe Experience Manager Adobe Experience Manager versions 6.5.19 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an admin attacker to inject malicious scripts into vulnerable form fields. | 4.8 |
2024-03-18 | CVE-2024-27104 | Glpi Project | Cross-site Scripting vulnerability in Glpi-Project Glpi GLPI is a Free Asset and IT Management Software package, Data center management, ITIL Service Desk, licenses tracking and software auditing. | 4.8 |
2024-03-21 | CVE-2024-27932 | Deno | Unspecified vulnerability in Deno Deno is a JavaScript, TypeScript, and WebAssembly runtime. | 4.6 |
2024-03-22 | CVE-2024-29057 | Microsoft | Unspecified vulnerability in Microsoft Edge Microsoft Edge (Chromium-based) Spoofing Vulnerability | 4.3 |
2024-03-22 | CVE-2024-2823 | Dedecms | Unspecified vulnerability in Dedecms 5.7 A vulnerability has been found in DedeCMS 5.7 and classified as problematic. | 4.3 |
2024-03-22 | CVE-2024-2820 | Dedecms | Unspecified vulnerability in Dedecms 5.7 A vulnerability classified as problematic was found in DedeCMS 5.7. | 4.3 |
2024-03-21 | CVE-2023-47715 | IBM | Unspecified vulnerability in IBM Storage Protect Plus 10.1.0/10.1.16 IBM Storage Protect Plus Server 10.1.0 through 10.1.16 could allow an authenticated user with read-only permissions to add or delete entries from an existing HyperVisor configuration. | 4.3 |
2024-03-21 | CVE-2024-1213 | Easysocialfeed | Cross-Site Request Forgery (CSRF) vulnerability in Easysocialfeed Easy Social Feed The Easy Social Feed – Social Photos Gallery – Post Feed – Like Box plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 6.5.4. | 4.3 |
2024-03-21 | CVE-2024-1502 | Themeum | Missing Authorization vulnerability in Themeum Tutor LMS The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the tutor_delete_announcement() function in all versions up to, and including, 2.6.1. | 4.3 |
2024-03-20 | CVE-2024-2628 | Google Fedoraproject | Inappropriate implementation in Downloads in Google Chrome prior to 123.0.6312.58 allowed a remote attacker to perform UI spoofing via a crafted URL. | 4.3 |
2024-03-20 | CVE-2024-2629 | Google Fedoraproject | Incorrect security UI in iOS in Google Chrome prior to 123.0.6312.58 allowed a remote attacker to perform UI spoofing via a crafted HTML page. | 4.3 |
2024-03-20 | CVE-2024-2631 | Google Fedoraproject | Inappropriate implementation in iOS in Google Chrome prior to 123.0.6312.58 allowed a remote attacker to perform UI spoofing via a crafted HTML page. | 4.3 |
2024-03-20 | CVE-2024-2291 | Progress | Unspecified vulnerability in Progress Moveit Transfer In Progress MOVEit Transfer versions released before 2022.0.11 (14.0.11), 2022.1.12 (14.1.12), 2023.0.9 (15.0.9), 2023.1.4 (15.1.4), a logging bypass vulnerability has been discovered. An authenticated user could manipulate a request to bypass the logging mechanism within the web application which results in user activity not being logged properly. | 4.3 |
2024-03-18 | CVE-2024-27937 | Glpi Project | Unspecified vulnerability in Glpi-Project Glpi GLPI is a Free Asset and IT Management Software package, Data center management, ITIL Service Desk, licenses tracking and software auditing. | 4.3 |
2 Low Vulnerabilities
DATE | CVE | VENDOR | VULNERABILITY | CVSS |
---|---|---|---|---|
2024-03-22 | CVE-2024-1742 | Checkmk | Unspecified vulnerability in Checkmk Invocation of the sqlplus command with sensitive information in the command line in the mk_oracle Checkmk agent plugin before Checkmk 2.3.0b4 (beta), 2.2.0p24, 2.1.0p41 and 2.0.0 (EOL) allows the extraction of this information from the process list. | 3.3 |
2024-03-22 | CVE-2022-32756 | IBM | Unspecified vulnerability in IBM Security Verify Directory 10.0.0 IBM Security Verify Directory 10.0.0 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. | 2.7 |