Weekly Vulnerabilities Reports > March 18 to 24, 2024
Overview
281 new vulnerabilities reported during this period, including 54 critical vulnerabilities and 68 high severity vulnerabilities. This weekly summary report vulnerabilities in 152 products from 89 vendors including Campcodes, Tenda, Linux, Debian, and Oretnom23. Vulnerabilities are notably categorized as "Cross-site Scripting", "Out-of-bounds Write", "Missing Authorization", "Path Traversal", and "Code Injection".
- 247 reported vulnerabilities are remotely exploitables.
- 45 reported vulnerabilities are related to weaknesses in OWASP Top Ten.
- 130 reported vulnerabilities are exploitable by an anonymous user.
- Campcodes has the most reported vulnerabilities, with 43 reported vulnerabilities.
- Tenda has the most reported critical vulnerabilities, with 16 reported vulnerabilities.
VULNERABILITIES
VULNERABILITIES
VULNERABILITIES
VULNERABILITIES
VULNERABILITIES
EXPLOITABLE
EXPLOITABLE
AVAILABLE
ANONYMOUSLY
WEB APPLICATION
Vulnerability Details
The following table list reported vulnerabilities for the period covered by this report:
54 Critical Vulnerabilities
DATE | CVE | VENDOR | VULNERABILITY | CVSS |
---|---|---|---|---|
2024-03-24 | CVE-2024-2856 | Tenda | Unspecified vulnerability in Tenda Ac10 Firmware 16.03.10.13/16.03.10.20 A vulnerability, which was classified as critical, has been found in Tenda AC10 16.03.10.13/16.03.10.20. | 9.8 |
2024-03-24 | CVE-2024-2854 | Tenda | Unspecified vulnerability in Tenda Ac18 Firmware 15.03.05.05 A vulnerability classified as critical has been found in Tenda AC18 15.03.05.05. | 9.8 |
2024-03-24 | CVE-2024-2855 | Tenda | Unspecified vulnerability in Tenda Ac15 Firmware 15.03.05.18/15.03.05.19/15.03.20Multi A vulnerability classified as critical was found in Tenda AC15 15.03.05.18/15.03.05.19/15.03.20. | 9.8 |
2024-03-24 | CVE-2024-2852 | Tenda | Unspecified vulnerability in Tenda Ac15 Firmware 15.03.20Multi A vulnerability was found in Tenda AC15 15.03.20_multi. | 9.8 |
2024-03-24 | CVE-2024-2853 | Tenda | Unspecified vulnerability in Tenda Ac10U Firmware 15.03.06.48/15.03.06.49 A vulnerability was found in Tenda AC10U 15.03.06.48/15.03.06.49. | 9.8 |
2024-03-24 | CVE-2024-2851 | Tenda | Unspecified vulnerability in Tenda Ac15 Firmware 15.03.05.18/15.03.20Multi A vulnerability was found in Tenda AC15 15.03.05.18/15.03.20_multi. | 9.8 |
2024-03-24 | CVE-2024-2850 | Tenda | Unspecified vulnerability in Tenda Ac15 Firmware 15.03.05.18 A vulnerability was found in Tenda AC15 15.03.05.18 and classified as critical. | 9.8 |
2024-03-23 | CVE-2024-2849 | Ganeshrkt | Unspecified vulnerability in Ganeshrkt Simple File Manager web APP 1.0 A vulnerability classified as critical was found in SourceCodester Simple File Manager 1.0. | 9.8 |
2024-03-22 | CVE-2024-2815 | Tenda | Unspecified vulnerability in Tenda Ac15 Firmware 15.03.05.20Multi A vulnerability classified as critical has been found in Tenda AC15 15.03.20_multi. | 9.8 |
2024-03-22 | CVE-2024-2813 | Tenda | Unspecified vulnerability in Tenda Ac15 Firmware 15.03.05.20Multi A vulnerability was found in Tenda AC15 15.03.20_multi. | 9.8 |
2024-03-22 | CVE-2024-2814 | Tenda | Unspecified vulnerability in Tenda Ac15 Firmware 15.03.05.20Multi A vulnerability was found in Tenda AC15 15.03.20_multi. | 9.8 |
2024-03-22 | CVE-2024-2809 | Tenda | Unspecified vulnerability in Tenda Ac15 Firmware 15.03.05.18/15.03.05.20Multi A vulnerability, which was classified as critical, was found in Tenda AC15 15.03.05.18/15.03.20_multi. | 9.8 |
2024-03-22 | CVE-2024-2810 | Tenda | Unspecified vulnerability in Tenda Ac15 Firmware 15.03.05.18/15.03.05.20Multi A vulnerability has been found in Tenda AC15 15.03.05.18/15.03.20_multi and classified as critical. | 9.8 |
2024-03-22 | CVE-2024-2811 | Tenda | Unspecified vulnerability in Tenda Ac15 Firmware 15.03.05.20Multi A vulnerability was found in Tenda AC15 15.03.20_multi and classified as critical. | 9.8 |
2024-03-22 | CVE-2024-2806 | Tenda | Unspecified vulnerability in Tenda Ac15 Firmware 15.03.05.18/15.03.05.20Multi A vulnerability classified as critical has been found in Tenda AC15 15.03.05.18/15.03.20_multi. | 9.8 |
2024-03-22 | CVE-2024-2807 | Tenda | Unspecified vulnerability in Tenda Ac15 Firmware 15.03.05.18/15.03.05.20Multi A vulnerability classified as critical was found in Tenda AC15 15.03.05.18/15.03.20_multi. | 9.8 |
2024-03-22 | CVE-2024-2808 | Tenda | Unspecified vulnerability in Tenda Ac15 Firmware 15.03.05.18/15.03.05.20Multi A vulnerability, which was classified as critical, has been found in Tenda AC15 15.03.05.18/15.03.20_multi. | 9.8 |
2024-03-21 | CVE-2024-27956 | Valvepress | Unspecified vulnerability in Valvepress Automatic Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ValvePress Automatic allows SQL Injection.This issue affects Automatic: from n/a through 3.92.0. | 9.8 |
2024-03-21 | CVE-2024-29870 | Sapplica | Unspecified vulnerability in Sapplica Sentrifugo 3.2 SQL injection vulnerability in Sentrifugo 3.2, through /sentrifugo/index.php/index/getdepartments/format/html, 'business_id' parameter./sentrifugo/index.php/index/getdepartments/format/html, 'business_id' parameter. | 9.8 |
2024-03-21 | CVE-2024-29871 | Sapplica | Unspecified vulnerability in Sapplica Sentrifugo 3.2 SQL injection vulnerability in Sentrifugo 3.2, through /sentrifugo/index.php/index/getdepartments/sentrifugo/index.php/index/updatecontactnumber, 'id' parameter. | 9.8 |
2024-03-21 | CVE-2024-29872 | Sapplica | Unspecified vulnerability in Sapplica Sentrifugo 3.2 SQL injection vulnerability in Sentrifugo 3.2, through /sentrifugo/index.php/empscreening/add, 'agencyids' parameter. | 9.8 |
2024-03-21 | CVE-2024-29873 | Sapplica | Unspecified vulnerability in Sapplica Sentrifugo 3.2 SQL injection vulnerability in Sentrifugo 3.2, through /sentrifugo/index.php/reports/businessunits/format/html, 'bunitname' parameter. | 9.8 |
2024-03-21 | CVE-2024-29874 | Sapplica | Unspecified vulnerability in Sapplica Sentrifugo 3.2 SQL injection vulnerability in Sentrifugo 3.2, through /sentrifugo/index.php/default/reports/activeuserrptpdf, 'sort_name' parameter. | 9.8 |
2024-03-21 | CVE-2024-29875 | Sapplica | Unspecified vulnerability in Sapplica Sentrifugo 3.2 SQL injection vulnerability in Sentrifugo 3.2, through /sentrifugo/index.php/default/reports/exportactiveuserrpt, 'sort_name' parameter. | 9.8 |
2024-03-21 | CVE-2024-29876 | Sapplica | Unspecified vulnerability in Sapplica Sentrifugo 3.2 SQL injection vulnerability in Sentrifugo 3.2, through /sentrifugo/index.php/reports/activitylogreport, 'sortby' parameter. | 9.8 |
2024-03-21 | CVE-2024-29859 | Misp | Unrestricted Upload of File with Dangerous Type vulnerability in Misp In MISP before 2.4.187, add_misp_export in app/Controller/EventsController.php does not properly check for a valid file upload. | 9.8 |
2024-03-21 | CVE-2023-35899 | IBM | Unspecified vulnerability in IBM Cloud PAK for Business Automation IBM Cloud Pak for Automation 18.0.0, 18.0.1, 18.0.2, 19.0.1, 19.0.2, 19.0.3, 20.0.1, 20.0.2, 20.0.3, 21.0.1, 21.0.2, 21.0.3, 22.0.1, and 22.0.2 is potentially vulnerable to CSV Injection. | 9.8 |
2024-03-21 | CVE-2022-4963 | Folio | Unspecified vulnerability in Folio Spring Module Core A vulnerability was found in Folio Spring Module Core up to 1.1.5. | 9.8 |
2024-03-20 | CVE-2024-28179 | Jupyter | Missing Authentication for Critical Function vulnerability in Jupyter Server Proxy Jupyter Server Proxy allows users to run arbitrary external processes alongside their Jupyter notebook servers and provides authenticated web access. | 9.8 |
2024-03-20 | CVE-2024-2690 | Razormist | Unspecified vulnerability in Razormist Online Discussion Forum Site 1.0 A vulnerability was found in SourceCodester Online Discussion Forum Site 1.0. | 9.8 |
2024-03-20 | CVE-2024-2649 | Netentsec | Unspecified vulnerability in Netentsec Application Security Gateway 6.3 A vulnerability has been found in Netentsec NS-ASG Application Security Gateway 6.3 and classified as critical. | 9.8 |
2024-03-19 | CVE-2024-2646 | Netentsec | Unspecified vulnerability in Netentsec Application Security Gateway 6.3 A vulnerability classified as critical was found in Netentsec NS-ASG Application Security Gateway 6.3. | 9.8 |
2024-03-19 | CVE-2024-2647 | Netentsec | Unspecified vulnerability in Netentsec Application Security Gateway 6.3 A vulnerability, which was classified as critical, has been found in Netentsec NS-ASG Application Security Gateway 6.3. | 9.8 |
2024-03-19 | CVE-2024-2644 | Netentsec | Unspecified vulnerability in Netentsec Application Security Gateway 6.3 A vulnerability was found in Netentsec NS-ASG Application Security Gateway 6.3. | 9.8 |
2024-03-19 | CVE-2024-2615 | Mozilla | Out-of-bounds Write vulnerability in Mozilla Firefox Memory safety bugs present in Firefox 123. | 9.8 |
2024-03-19 | CVE-2024-2622 | Kelixin Communication Command AND Dispatch Project | Unspecified vulnerability in Kelixin Communication Command and Dispatch Project Kelixin Communication Command and Dispatch A vulnerability was found in Fujian Kelixin Communication Command and Dispatch Platform up to 20240318. | 9.8 |
2024-03-19 | CVE-2024-2620 | Kelixin Communication Command AND Dispatch Project | Unspecified vulnerability in Kelixin Communication Command and Dispatch Project Kelixin Communication Command and Dispatch A vulnerability has been found in Fujian Kelixin Communication Command and Dispatch Platform up to 20240318 and classified as critical. | 9.8 |
2024-03-19 | CVE-2024-2621 | Kelixin Communication Command AND Dispatch Project | Unspecified vulnerability in Kelixin Communication Command and Dispatch Project Kelixin Communication Command and Dispatch A vulnerability was found in Fujian Kelixin Communication Command and Dispatch Platform up to 20240318 and classified as critical. | 9.8 |
2024-03-18 | CVE-2024-2604 | Remyandrade | Unspecified vulnerability in Remyandrade File Manager APP 1.0 A vulnerability was found in SourceCodester File Manager App 1.0. | 9.8 |
2024-03-18 | CVE-2024-21652 | Argoproj | Improper Restriction of Excessive Authentication Attempts vulnerability in Argoproj Argo CD Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. | 9.8 |
2024-03-18 | CVE-2024-27767 | Unitronics | Unspecified vulnerability in Unitronics Unilogic CWE-287: Improper Authentication may allow Authentication Bypass | 9.8 |
2024-03-18 | CVE-2024-27768 | Unitronics | Unspecified vulnerability in Unitronics Unilogic Unitronics Unistream Unilogic – Versions prior to 1.35.227 - CWE-22: 'Path Traversal' may allow RCE | 9.8 |
2024-03-18 | CVE-2024-2577 | Oretnom23 | Unspecified vulnerability in Oretnom23 Employee Task Management System 1.0 A vulnerability has been found in SourceCodester Employee Task Management System 1.0 and classified as critical. | 9.8 |
2024-03-18 | CVE-2024-2574 | Oretnom23 | Unspecified vulnerability in Oretnom23 Employee Task Management System 1.0 A vulnerability classified as critical was found in SourceCodester Employee Task Management System 1.0. | 9.8 |
2024-03-18 | CVE-2024-2575 | Oretnom23 | Unspecified vulnerability in Oretnom23 Employee Task Management System 1.0 A vulnerability, which was classified as critical, has been found in SourceCodester Employee Task Management System 1.0. | 9.8 |
2024-03-18 | CVE-2024-2576 | Oretnom23 | Unspecified vulnerability in Oretnom23 Employee Task Management System 1.0 A vulnerability, which was classified as critical, was found in SourceCodester Employee Task Management System 1.0. | 9.8 |
2024-03-18 | CVE-2024-2571 | Oretnom23 | Unspecified vulnerability in Oretnom23 Employee Task Management System 1.0 A vulnerability was found in SourceCodester Employee Task Management System 1.0. | 9.8 |
2024-03-18 | CVE-2024-2572 | Oretnom23 | Unspecified vulnerability in Oretnom23 Employee Task Management System 1.0 A vulnerability was found in SourceCodester Employee Task Management System 1.0. | 9.8 |
2024-03-18 | CVE-2024-2573 | Oretnom23 | Unspecified vulnerability in Oretnom23 Employee Task Management System 1.0 A vulnerability classified as critical has been found in SourceCodester Employee Task Management System 1.0. | 9.8 |
2024-03-18 | CVE-2024-2570 | Oretnom23 | Unspecified vulnerability in Oretnom23 Employee Task Management System 1.0 A vulnerability was found in SourceCodester Employee Task Management System 1.0. | 9.8 |
2024-03-18 | CVE-2024-27098 | Glpi Project | Server-Side Request Forgery (SSRF) vulnerability in Glpi-Project Glpi GLPI is a Free Asset and IT Management Software package, Data center management, ITIL Service Desk, licenses tracking and software auditing. | 9.6 |
2024-03-21 | CVE-2020-26942 | Axigen | Unspecified vulnerability in Axigen Mail Server An issue discovered in Axigen Mail Server 10.3.x before 10.3.1.27 and 10.3.2.x before 10.3.3.1 allows unauthenticated attackers to submit a setAdminPassword operation request, subsequently setting a new arbitrary password for the admin account. | 9.1 |
2024-03-18 | CVE-2024-21662 | Argoproj | Improper Restriction of Excessive Authentication Attempts vulnerability in Argoproj Argo CD Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. | 9.1 |
2024-03-22 | CVE-2024-29185 | Freescout | OS Command Injection vulnerability in Freescout FreeScout is a self-hosted help desk and shared mailbox. | 9.0 |
68 High Vulnerabilities
DATE | CVE | VENDOR | VULNERABILITY | CVSS |
---|---|---|---|---|
2024-03-22 | CVE-2024-2448 | Progress | OS Command Injection vulnerability in Progress Loadmaster 7.1.35.10/7.2.48.10 An OS command injection vulnerability has been identified in LoadMaster. An authenticated UI user with any permission settings may be able to inject commands into a UI component using a shell command resulting in OS command injection. | 8.8 |
2024-03-22 | CVE-2024-2812 | Tenda | Unspecified vulnerability in Tenda Ac15 Firmware 15.03.05.18/15.03.05.20Multi A vulnerability was found in Tenda AC15 15.03.05.18/15.03.20_multi. | 8.8 |
2024-03-22 | CVE-2024-2805 | Tenda | Out-of-bounds Write vulnerability in Tenda Ac15 Firmware 15.03.05.18/15.03.05.20Multi A vulnerability was found in Tenda AC15 15.03.05.18/15.03.20_multi. | 8.8 |
2024-03-21 | CVE-2024-25937 | Deltaww | Unspecified vulnerability in Deltaww Diaenergie SQL injection vulnerability exists in the script DIAE_tagHandler.ashx. | 8.8 |
2024-03-21 | CVE-2024-27921 | Getgrav | Path Traversal vulnerability in Getgrav Grav Grav is an open-source, flat-file content management system. | 8.8 |
2024-03-21 | CVE-2024-28029 | Deltaww | Unspecified vulnerability in Deltaww Diaenergie Privileges are not fully verified server-side, which can be abused by a user with limited privileges to bypass authorization and access privileged functionality. | 8.8 |
2024-03-21 | CVE-2024-28116 | Getgrav | Code Injection vulnerability in Getgrav Grav Grav is an open-source, flat-file content management system. | 8.8 |
2024-03-21 | CVE-2024-28117 | Getgrav | Code Injection vulnerability in Getgrav Grav Grav is an open-source, flat-file content management system. | 8.8 |
2024-03-21 | CVE-2024-28118 | Getgrav | Code Injection vulnerability in Getgrav Grav Grav is an open-source, flat-file content management system. | 8.8 |
2024-03-21 | CVE-2024-28119 | Getgrav | Code Injection vulnerability in Getgrav Grav Grav is an open-source, flat-file content management system. | 8.8 |
2024-03-21 | CVE-2024-2763 | Tenda | Out-of-bounds Write vulnerability in Tenda Ac10U Firmware 15.03.06.48 A vulnerability, which was classified as critical, has been found in Tenda AC10U 15.03.06.48. | 8.8 |
2024-03-21 | CVE-2024-2764 | Tenda | Out-of-bounds Write vulnerability in Tenda Ac10U Firmware 15.03.06.48 A vulnerability, which was classified as critical, was found in Tenda AC10U 15.03.06.48. | 8.8 |
2024-03-21 | CVE-2024-27190 | Jeandaviddaviet | Unspecified vulnerability in Jeandaviddaviet Download Media Missing Authorization vulnerability in Jean-David Daviet Download Media.This issue affects Download Media: from n/a through 1.4.2. | 8.8 |
2024-03-21 | CVE-2024-27964 | Gesundheit Bewegt | Unspecified vulnerability in Gesundheit-Bewegt Zippy Unrestricted Upload of File with Dangerous Type vulnerability in Gesundheit Bewegt GmbH Zippy.This issue affects Zippy: from n/a through 1.6.9. | 8.8 |
2024-03-21 | CVE-2024-2754 | Donbermoy | Unspecified vulnerability in Donbermoy Complete E-Commerce Site 1.0 A vulnerability classified as critical has been found in SourceCodester Complete E-Commerce Site 1.0. | 8.8 |
2024-03-21 | CVE-2024-27923 | Getgrav | Unrestricted Upload of File with Dangerous Type vulnerability in Getgrav Grav Grav is a content management system (CMS). | 8.8 |
2024-03-21 | CVE-2024-27933 | Deno | Incorrect Authorization vulnerability in Deno 1.39.0 Deno is a JavaScript, TypeScript, and WebAssembly runtime. | 8.8 |
2024-03-21 | CVE-2024-27934 | Deno | Use After Free vulnerability in Deno Deno is a JavaScript, TypeScript, and WebAssembly runtime. | 8.8 |
2024-03-21 | CVE-2023-49978 | Oretnom23 | Unspecified vulnerability in Oretnom23 Customer Support System 1.0 Incorrect access control in Customer Support System v1 allows non-administrator users to access administrative pages and execute actions reserved for administrators. | 8.8 |
2024-03-20 | CVE-2024-2708 | Tenda | Out-of-bounds Write vulnerability in Tenda Ac10U Firmware 15.03.06.49 A vulnerability was found in Tenda AC10U 15.03.06.49 and classified as critical. | 8.8 |
2024-03-20 | CVE-2024-2709 | Tenda | Out-of-bounds Write vulnerability in Tenda Ac10U Firmware 15.03.06.49 A vulnerability was found in Tenda AC10U 15.03.06.49. | 8.8 |
2024-03-20 | CVE-2024-2710 | Tenda | Out-of-bounds Write vulnerability in Tenda Ac10U Firmware 15.03.06.49 A vulnerability was found in Tenda AC10U 15.03.06.49. | 8.8 |
2024-03-20 | CVE-2024-2711 | Tenda | Out-of-bounds Write vulnerability in Tenda Ac10U Firmware 15.03.06.48 A vulnerability was found in Tenda AC10U 15.03.06.48. | 8.8 |
2024-03-20 | CVE-2024-2625 | Google Fedoraproject | Object lifecycle issue in V8 in Google Chrome prior to 123.0.6312.58 allowed a remote attacker to potentially exploit object corruption via a crafted HTML page. | 8.8 |
2024-03-20 | CVE-2024-2627 | Google Fedoraproject | Use After Free vulnerability in multiple products Use after free in Canvas in Google Chrome prior to 123.0.6312.58 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | 8.8 |
2024-03-20 | CVE-2024-2705 | Tenda | Out-of-bounds Write vulnerability in Tenda Ac10U Firmware 15.03.06.49 A vulnerability, which was classified as critical, has been found in Tenda AC10U 1.0/15.03.06.49. | 8.8 |
2024-03-20 | CVE-2024-2706 | Tenda | Out-of-bounds Write vulnerability in Tenda Ac10U Firmware 15.03.06.49 A vulnerability, which was classified as critical, was found in Tenda AC10U 15.03.06.49. | 8.8 |
2024-03-20 | CVE-2024-2707 | Tenda | Unspecified vulnerability in Tenda Ac10U Firmware 15.03.06.49 A vulnerability has been found in Tenda AC10U 15.03.06.49 and classified as critical. | 8.8 |
2024-03-20 | CVE-2024-2703 | Tenda | Out-of-bounds Write vulnerability in Tenda Ac10U Firmware 15.03.06.49 A vulnerability classified as critical has been found in Tenda AC10U 15.03.06.49. | 8.8 |
2024-03-20 | CVE-2024-2704 | Tenda | Out-of-bounds Write vulnerability in Tenda Ac10U Firmware 15.03.06.49 A vulnerability classified as critical was found in Tenda AC10U 15.03.06.49. | 8.8 |
2024-03-20 | CVE-2024-1800 | Progress | Deserialization of Untrusted Data vulnerability in Progress Telerik Report Server In Progress® Telerik® Report Server versions prior to 2024 Q1 (10.0.24.130), a remote code execution attack is possible through an insecure deserialization vulnerability. | 8.8 |
2024-03-20 | CVE-2024-1856 | Progress | Deserialization of Untrusted Data vulnerability in Progress Telerik Reporting In Progress® Telerik® Reporting versions prior to 2024 Q1 (18.0.24.130), a code execution attack is possible by a remote threat actor through an insecure deserialization vulnerability. | 8.8 |
2024-03-19 | CVE-2024-21677 | Atlassian | Path Traversal vulnerability in Atlassian Confluence Data Center and Confluence Server This High severity Path Traversal vulnerability was introduced in version 6.13.0 of Confluence Data Center. | 8.8 |
2024-03-19 | CVE-2024-29135 | Themefic | Unspecified vulnerability in Themefic Tourfic Unrestricted Upload of File with Dangerous Type vulnerability in Tourfic.This issue affects Tourfic: from n/a through 2.11.15. | 8.8 |
2024-03-19 | CVE-2024-29136 | Themefic | Unspecified vulnerability in Themefic Tourfic Deserialization of Untrusted Data vulnerability in Themefic Tourfic.This issue affects Tourfic: from n/a through 2.11.17. | 8.8 |
2024-03-19 | CVE-2024-2614 | Mozilla Debian | Out-of-bounds Write vulnerability in multiple products Memory safety bugs present in Firefox 123, Firefox ESR 115.8, and Thunderbird 115.8. | 8.8 |
2024-03-18 | CVE-2024-0780 | Mediabetaprojects | Missing Authorization vulnerability in Mediabetaprojects Enjoy Social Feed The Enjoy Social Feed plugin for WordPress website WordPress plugin through 6.2.2 does not have authorisation when resetting its database, allowing any authenticated users, such as subscriber to perform such action | 8.8 |
2024-03-18 | CVE-2024-27769 | Unitronics | Unspecified vulnerability in Unitronics Unilogic Unitronics Unistream Unilogic – Versions prior to 1.35.227 - CWE-200: Exposure of Sensitive Information to an Unauthorized Actor may allow Taking Ownership Over Devices | 8.8 |
2024-03-18 | CVE-2024-27770 | Unitronics | Path Traversal vulnerability in Unitronics Unilogic Unitronics Unistream Unilogic – Versions prior to 1.35.227 - CWE-23: Relative Path Traversal | 8.8 |
2024-03-18 | CVE-2024-27771 | Unitronics | Unspecified vulnerability in Unitronics Unilogic Unitronics Unistream Unilogic – Versions prior to 1.35.227 - CWE-22: 'Path Traversal' may allow RCE | 8.8 |
2024-03-18 | CVE-2024-27772 | Unitronics | Unspecified vulnerability in Unitronics Unilogic Unitronics Unistream Unilogic – Versions prior to 1.35.227 - CWE-78: 'OS Command Injection' may allow RCE | 8.8 |
2024-03-18 | CVE-2024-27773 | Unitronics | Insufficient Verification of Data Authenticity vulnerability in Unitronics Unilogic Unitronics Unistream Unilogic – Versions prior to 1.35.227 - CWE-348: Use of Less Trusted Source may allow RCE | 8.8 |
2024-03-18 | CVE-2024-2581 | Tenda | Out-of-bounds Write vulnerability in Tenda Ac10 Firmware 16.03.10.13 A vulnerability was found in Tenda AC10 16.03.10.13 and classified as critical. | 8.8 |
2024-03-21 | CVE-2024-27935 | Deno | Unspecified vulnerability in Deno Deno is a JavaScript, TypeScript, and WebAssembly runtime. | 8.3 |
2024-03-22 | CVE-2024-29184 | Freescout | Cross-site Scripting vulnerability in Freescout FreeScout is a self-hosted help desk and shared mailbox. | 8.0 |
2024-03-22 | CVE-2024-28824 | Checkmk | Unspecified vulnerability in Checkmk Least privilege violation and reliance on untrusted inputs in the mk_informix Checkmk agent plugin before Checkmk 2.3.0b4 (beta), 2.2.0p24, 2.1.0p41 and 2.0.0 (EOL) allows local users to escalate privileges. | 7.8 |
2024-03-21 | CVE-2024-29880 | Jetbrains | Unspecified vulnerability in Jetbrains Teamcity In JetBrains TeamCity before 2023.11 users with access to the agent machine might obtain permissions of the user running the agent process | 7.8 |
2024-03-20 | CVE-2024-1801 | Progress | Deserialization of Untrusted Data vulnerability in Progress Telerik Reporting In Progress® Telerik® Reporting versions prior to 2024 Q1 (18.0.24.130), a code execution attack is possible by a local threat actor through an insecure deserialization vulnerability. | 7.8 |
2024-03-19 | CVE-2023-42920 | Claris | Unspecified vulnerability in Claris PRO and Filemaker PRO Claris International has fixed a dylib hijacking vulnerability in the FileMaker Pro.app and Claris Pro.app versions on macOS. | 7.8 |
2024-03-18 | CVE-2024-20754 | Adobe | Unspecified vulnerability in Adobe Lightroom 5.1 Lightroom Desktop versions 7.1.2 and earlier are affected by an Untrusted Search Path vulnerability that could result in arbitrary code execution in the context of the current user. | 7.8 |
2024-03-18 | CVE-2023-52612 | Linux Debian | Classic Buffer Overflow vulnerability in multiple products In the Linux kernel, the following vulnerability has been resolved: crypto: scomp - fix req->dst buffer overflow The req->dst buffer size should be checked before copying from the scomp_scratch->dst to avoid req->dst buffer overflow problem. | 7.8 |
2024-03-18 | CVE-2023-52614 | Linux | Classic Buffer Overflow vulnerability in Linux Kernel In the Linux kernel, the following vulnerability has been resolved: PM / devfreq: Fix buffer overflow in trans_stat_show Fix buffer overflow in trans_stat_show(). Convert simple snprintf to the more secure scnprintf with size of PAGE_SIZE. Add condition checking if we are exceeding PAGE_SIZE and exit early from loop. | 7.8 |
2024-03-18 | CVE-2024-1605 | BMC | Incorrect Default Permissions vulnerability in BMC Control-M BMC Control-M branches 9.0.20 and 9.0.21 upon user login load all Dynamic Link Libraries (DLL) from a directory that grants Write and Read permissions to all users. | 7.8 |
2024-03-23 | CVE-2024-1603 | Paddlepaddle | Unspecified vulnerability in Paddlepaddle 2.6.0 paddlepaddle/paddle 2.6.0 allows arbitrary file read via paddle.vision.ops.read_file. | 7.5 |
2024-03-23 | CVE-2024-24832 | Metagauss | Unspecified vulnerability in Metagauss Eventprime Missing Authorization vulnerability in Metagauss EventPrime.This issue affects EventPrime: from n/a through 3.3.9. | 7.5 |
2024-03-23 | CVE-2024-29059 | Microsoft | Information Exposure Through an Error Message vulnerability in Microsoft .Net Framework .NET Framework Information Disclosure Vulnerability | 7.5 |
2024-03-22 | CVE-2024-2449 | Progress | Cross-Site Request Forgery (CSRF) vulnerability in Progress Loadmaster 7.1.35.10/7.2.48.10 A cross-site request forgery vulnerability has been identified in LoadMaster. It is possible for a malicious actor, who has prior knowledge of the IP or hostname of a specific LoadMaster, to direct an authenticated LoadMaster administrator to a third-party site. | 7.5 |
2024-03-21 | CVE-2023-49979 | Mayurik | Missing Authorization vulnerability in Mayurik Best Student Management System 1.0 A directory listing vulnerability in Customer Support System v1 allows attackers to list directories and sensitive files within the application without requiring authorization. | 7.5 |
2024-03-21 | CVE-2023-49980 | Mayurik | Missing Authorization vulnerability in Mayurik Best Student Result Management System 1.0 A directory listing vulnerability in Best Student Result Management System v1.0 allows attackers to list directories and sensitive files within the application without requiring authorization. | 7.5 |
2024-03-21 | CVE-2023-49981 | Oretnom23 | Missing Authorization vulnerability in Oretnom23 School Fees Management System 1.0 A directory listing vulnerability in School Fees Management System v1.0 allows attackers to list directories and sensitive files within the application without requiring authorization. | 7.5 |
2024-03-19 | CVE-2024-2613 | Mozilla | Improper Restriction of Rendered UI Layers or Frames vulnerability in Mozilla Firefox Data was not properly sanitized when decoding a QUIC ACK frame; this could have led to unrestricted memory consumption and a crash. | 7.5 |
2024-03-18 | CVE-2024-21661 | Argoproj | Unspecified vulnerability in Argoproj Argo CD Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. | 7.5 |
2024-03-18 | CVE-2022-47037 | Siklu | Insufficiently Protected Credentials vulnerability in Siklu TG Firmware Siklu TG Terragraph devices before 2.1.1 allow attackers to discover valid, randomly generated credentials via GetCredentials. | 7.5 |
2024-03-18 | CVE-2023-52159 | Bizdelnick Debian | Out-of-bounds Write vulnerability in multiple products A stack-based buffer overflow vulnerability in gross 0.9.3 through 1.x before 1.0.4 allows remote attackers to trigger a denial of service (grossd daemon crash) or potentially execute arbitrary code in grossd via crafted SMTP transaction parameters that cause an incorrect strncat for a log entry. | 7.5 |
2024-03-18 | CVE-2024-20767 | Adobe | Unspecified vulnerability in Adobe Coldfusion 2021/2023 ColdFusion versions 2023.6, 2021.12 and earlier are affected by an Improper Access Control vulnerability that could result in arbitrary file system read. | 7.4 |
2024-03-20 | CVE-2023-41877 | Geoserver | Path Traversal vulnerability in Geoserver GeoServer is an open source software server written in Java that allows users to share and edit geospatial data. | 7.2 |
2024-03-20 | CVE-2023-51444 | Geoserver | Unrestricted Upload of File with Dangerous Type vulnerability in Geoserver GeoServer is an open source software server written in Java that allows users to share and edit geospatial data. | 7.2 |
2024-03-18 | CVE-2024-28248 | Cilium | Unspecified vulnerability in Cilium Cilium is a networking, observability, and security solution with an eBPF-based dataplane. | 7.2 |
156 Medium Vulnerabilities
DATE | CVE | VENDOR | VULNERABILITY | CVSS |
---|---|---|---|---|
2024-03-19 | CVE-2024-25942 | Dell | Out-of-bounds Write vulnerability in Dell products Dell PowerEdge Server BIOS contains an Improper SMM communication buffer verification vulnerability. | 6.8 |
2024-03-18 | CVE-2024-1604 | BMC | Authorization Bypass Through User-Controlled Key vulnerability in BMC Control-M Improper authorization in the report management and creation module of BMC Control-M branches 9.0.20 and 9.0.21 allows logged-in users to read and make unauthorized changes to any reports available within the application, even without proper permissions. | 6.8 |
2024-03-22 | CVE-2024-0638 | Checkmk | Unspecified vulnerability in Checkmk Least privilege violation in the Checkmk agent plugins mk_oracle, mk_oracle.ps1, and mk_oracle_crs before Checkmk 2.3.0b4 (beta), 2.2.0p24, 2.1.0p41 and 2.0.0 (EOL) allows local users to escalate privileges. | 6.7 |
2024-03-22 | CVE-2022-32753 | IBM | Unspecified vulnerability in IBM Security Verify Directory 10.0.0 IBM Security Verify Directory 10.0.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. | 6.5 |
2024-03-22 | CVE-2024-2816 | Tenda | Unspecified vulnerability in Tenda Ac15 Firmware 15.03.05.18 A vulnerability classified as problematic was found in Tenda AC15 15.03.05.18. | 6.5 |
2024-03-22 | CVE-2024-2817 | Tenda | Unspecified vulnerability in Tenda Ac15 Firmware 15.03.05.18 A vulnerability, which was classified as problematic, has been found in Tenda AC15 15.03.05.18. | 6.5 |
2024-03-22 | CVE-2024-2776 | Campcodes | Unspecified vulnerability in Campcodes Online Marriage Registration System 1.0 A vulnerability, which was classified as critical, was found in Campcodes Online Marriage Registration System 1.0. | 6.5 |
2024-03-22 | CVE-2024-2777 | Campcodes | Unspecified vulnerability in Campcodes Online Marriage Registration System 1.0 A vulnerability has been found in Campcodes Online Marriage Registration System 1.0 and classified as critical. | 6.5 |
2024-03-21 | CVE-2024-2770 | Campcodes | Unspecified vulnerability in Campcodes Complete Online Beauty Parlor Management System 1.0 A vulnerability was found in Campcodes Complete Online Beauty Parlor Management System 1.0. | 6.5 |
2024-03-21 | CVE-2024-2774 | Campcodes | Unspecified vulnerability in Campcodes Online Marriage Registration System 1.0 A vulnerability classified as critical was found in Campcodes Online Marriage Registration System 1.0. | 6.5 |
2024-03-21 | CVE-2024-2768 | Campcodes | Unspecified vulnerability in Campcodes Complete Online Beauty Parlor Management System 1.0 A vulnerability was found in Campcodes Complete Online Beauty Parlor Management System 1.0. | 6.5 |
2024-03-21 | CVE-2024-2769 | Campcodes | Unspecified vulnerability in Campcodes Complete Online Beauty Parlor Management System 1.0 A vulnerability was found in Campcodes Complete Online Beauty Parlor Management System 1.0. | 6.5 |
2024-03-21 | CVE-2024-2766 | Campcodes | Unspecified vulnerability in Campcodes Complete Online Beauty Parlor Management System 1.0 A vulnerability has been found in Campcodes Complete Online Beauty Parlor Management System 1.0 and classified as critical. | 6.5 |
2024-03-21 | CVE-2024-2767 | Campcodes | Unspecified vulnerability in Campcodes Complete Online Beauty Parlor Management System 1.0 A vulnerability was found in Campcodes Complete Online Beauty Parlor Management System 1.0 and classified as critical. | 6.5 |
2024-03-21 | CVE-2024-27936 | Deno | Unspecified vulnerability in Deno and Deno Runtime Deno is a JavaScript, TypeScript, and WebAssembly runtime with secure defaults. | 6.5 |
2024-03-21 | CVE-2024-2712 | Campcodes | Unspecified vulnerability in Campcodes Complete Online DJ Booking System 1.0 A vulnerability, which was classified as critical, has been found in Campcodes Complete Online DJ Booking System 1.0. | 6.5 |
2024-03-21 | CVE-2024-2713 | Campcodes | Unspecified vulnerability in Campcodes Complete Online DJ Booking System 1.0 A vulnerability, which was classified as critical, was found in Campcodes Complete Online DJ Booking System 1.0. | 6.5 |
2024-03-21 | CVE-2023-38825 | Vanderbilt | SQL Injection vulnerability in Vanderbilt Redcap SQL injection vulnerability in Vanderbilt REDCap before v.13.8.0 allows a remote attacker to obtain sensitive information via the password reset mechanism in MyCapMobileApp/update.php. | 6.5 |
2024-03-20 | CVE-2024-2714 | Campcodes | Unspecified vulnerability in Campcodes Complete Online DJ Booking System 1.0 A vulnerability has been found in Campcodes Complete Online DJ Booking System 1.0 and classified as critical. | 6.5 |
2024-03-20 | CVE-2024-2626 | Google Fedoraproject | Out-of-bounds Read vulnerability in multiple products Out of bounds read in Swiftshader in Google Chrome prior to 123.0.6312.58 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. | 6.5 |
2024-03-20 | CVE-2024-2630 | Google Fedoraproject | Inappropriate implementation in iOS in Google Chrome prior to 123.0.6312.58 allowed a remote attacker to leak cross-origin data via a crafted HTML page. | 6.5 |
2024-03-20 | CVE-2024-2687 | Campcodes | Unspecified vulnerability in Campcodes Online JOB Finder System 1.0 A vulnerability was found in Campcodes Online Job Finder System 1.0 and classified as critical. | 6.5 |
2024-03-20 | CVE-2024-2677 | Campcodes | Unspecified vulnerability in Campcodes Online JOB Finder System 1.0 A vulnerability has been found in Campcodes Online Job Finder System 1.0 and classified as critical. | 6.5 |
2024-03-20 | CVE-2024-2678 | Campcodes | Unspecified vulnerability in Campcodes Online JOB Finder System 1.0 A vulnerability was found in Campcodes Online Job Finder System 1.0 and classified as critical. | 6.5 |
2024-03-20 | CVE-2024-2674 | Campcodes | Unspecified vulnerability in Campcodes Online JOB Finder System 1.0 A vulnerability classified as critical was found in Campcodes Online Job Finder System 1.0. | 6.5 |
2024-03-20 | CVE-2024-2675 | Campcodes | Unspecified vulnerability in Campcodes Online JOB Finder System 1.0 A vulnerability, which was classified as critical, has been found in Campcodes Online Job Finder System 1.0. | 6.5 |
2024-03-20 | CVE-2024-2676 | Campcodes | Unspecified vulnerability in Campcodes Online JOB Finder System 1.0 A vulnerability, which was classified as critical, was found in Campcodes Online Job Finder System 1.0. | 6.5 |
2024-03-20 | CVE-2024-2672 | Campcodes | Unspecified vulnerability in Campcodes Online JOB Finder System 1.0 A vulnerability was found in Campcodes Online Job Finder System 1.0. | 6.5 |
2024-03-20 | CVE-2024-2673 | Campcodes | Unspecified vulnerability in Campcodes Online JOB Finder System 1.0 A vulnerability classified as critical has been found in Campcodes Online Job Finder System 1.0. | 6.5 |
2024-03-20 | CVE-2024-2670 | Campcodes | Unspecified vulnerability in Campcodes Online JOB Finder System 1.0 A vulnerability was found in Campcodes Online Job Finder System 1.0. | 6.5 |
2024-03-20 | CVE-2024-2671 | Campcodes | Unspecified vulnerability in Campcodes Online JOB Finder System 1.0 A vulnerability was found in Campcodes Online Job Finder System 1.0. | 6.5 |
2024-03-20 | CVE-2024-2668 | Campcodes | Unspecified vulnerability in Campcodes Online JOB Finder System 1.0 A vulnerability has been found in Campcodes Online Job Finder System 1.0 and classified as critical. | 6.5 |
2024-03-20 | CVE-2024-2669 | Campcodes | Unspecified vulnerability in Campcodes Online JOB Finder System 1.0 A vulnerability was found in Campcodes Online Job Finder System 1.0 and classified as critical. | 6.5 |
2024-03-19 | CVE-2023-50811 | Seling | Unspecified vulnerability in Seling Visual Access Manager 4.38.6 An issue discovered in SELESTA Visual Access Manager 4.38.6 allows attackers to modify the “computer” POST parameter related to the ID of a specific reception by POST HTTP request interception. | 6.5 |
2024-03-18 | CVE-2023-6821 | Bestwebsoft | Missing Authorization vulnerability in Bestwebsoft Error LOG Viewer The Error Log Viewer by BestWebSoft WordPress plugin before 1.1.3 is affected by a Directory Listing issue, allowing users to read and download PHP logs without authorization | 6.5 |
2024-03-18 | CVE-2024-27096 | Glpi Project | SQL Injection vulnerability in Glpi-Project Glpi GLPI is a Free Asset and IT Management Software package, Data center management, ITIL Service Desk, licenses tracking and software auditing. | 6.5 |
2024-03-18 | CVE-2024-27930 | Glpi Project | Unspecified vulnerability in Glpi-Project Glpi GLPI is a Free Asset and IT Management Software package, Data center management, ITIL Service Desk, licenses tracking and software auditing. | 6.5 |
2024-03-18 | CVE-2024-27774 | Unitronics | Use of Hard-coded Credentials vulnerability in Unitronics Unilogic Unitronics Unistream Unilogic – Versions prior to 1.35.227 - CWE-259: Use of Hard-coded Password may allow disclosing Sensitive Information Embedded inside Device's Firmware | 6.5 |
2024-03-18 | CVE-2024-29156 | Openstack | Unspecified vulnerability in Openstack Murano and Yaql In OpenStack Murano through 16.0.0, when YAQL before 3.0.0 is used, the Murano service's MuranoPL extension to the YAQL language fails to sanitize the supplied environment, leading to potential leakage of sensitive service account information. | 6.5 |
2024-03-23 | CVE-2024-2832 | Campcodes | Unspecified vulnerability in Campcodes Online Shopping System 1.0 A vulnerability classified as problematic was found in Campcodes Online Shopping System 1.0. | 6.1 |
2024-03-22 | CVE-2024-2780 | Campcodes | Unspecified vulnerability in Campcodes Online Marriage Registration System 1.0 A vulnerability was found in Campcodes Online Marriage Registration System 1.0. | 6.1 |
2024-03-22 | CVE-2024-2778 | Campcodes | Unspecified vulnerability in Campcodes Online Marriage Registration System 1.0 A vulnerability was found in Campcodes Online Marriage Registration System 1.0 and classified as problematic. | 6.1 |
2024-03-21 | CVE-2024-2773 | Campcodes | Unspecified vulnerability in Campcodes Online Marriage Registration System 1.0 A vulnerability classified as problematic has been found in Campcodes Online Marriage Registration System 1.0. | 6.1 |
2024-03-21 | CVE-2024-2775 | Campcodes | Unspecified vulnerability in Campcodes Online Marriage Registration System 1.0 A vulnerability, which was classified as problematic, has been found in Campcodes Online Marriage Registration System 1.0. | 6.1 |
2024-03-21 | CVE-2024-27962 | Fkrauthan | Unspecified vulnerability in Fkrauthan Wp-Mpdf Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Florian 'fkrauthan' Krauthan allows Reflected XSS.This issue affects wp-mpdf: from n/a through 3.7.1. | 6.1 |
2024-03-21 | CVE-2024-27968 | Optimole | Unspecified vulnerability in Optimole Super Page Cache Cross-Site Request Forgery (CSRF) vulnerability in Optimole Super Page Cache for Cloudflare allows Stored XSS.This issue affects Super Page Cache for Cloudflare: from n/a through 4.7.5. | 6.1 |
2024-03-21 | CVE-2024-29877 | Sapplica | Unspecified vulnerability in Sapplica Sentrifugo 3.2 Cross-Site Scripting (XSS) vulnerability in Sentrifugo 3.2, through /sentrifugo/index.php/expenses/expensecategories/edit, 'expense_category_name' parameter. | 6.1 |
2024-03-21 | CVE-2024-29878 | Sapplica | Unspecified vulnerability in Sapplica Sentrifugo 3.2 Cross-Site Scripting (XSS) vulnerability in Sentrifugo 3.2, through /sentrifugo/index.php/sitepreference/add, 'description' parameter. | 6.1 |
2024-03-21 | CVE-2024-29879 | Sapplica | Unspecified vulnerability in Sapplica Sentrifugo 3.2 Cross-Site Scripting (XSS) vulnerability in Sentrifugo 3.2, through /sentrifugo/index.php/index/getdepartments/format/html, 'business_id' parameter. | 6.1 |
2024-03-20 | CVE-2024-2720 | Campcodes | Unspecified vulnerability in Campcodes Complete Online DJ Booking System 1.0 A vulnerability classified as problematic was found in Campcodes Complete Online DJ Booking System 1.0. | 6.1 |
2024-03-20 | CVE-2024-2717 | Campcodes | Unspecified vulnerability in Campcodes Complete Online DJ Booking System 1.0 A vulnerability was found in Campcodes Complete Online DJ Booking System 1.0. | 6.1 |
2024-03-20 | CVE-2024-2718 | Campcodes | Unspecified vulnerability in Campcodes Complete Online DJ Booking System 1.0 A vulnerability was found in Campcodes Complete Online DJ Booking System 1.0. | 6.1 |
2024-03-20 | CVE-2024-2719 | Campcodes | Unspecified vulnerability in Campcodes Complete Online DJ Booking System 1.0 A vulnerability classified as problematic has been found in Campcodes Complete Online DJ Booking System 1.0. | 6.1 |
2024-03-20 | CVE-2024-2715 | Campcodes | Unspecified vulnerability in Campcodes Complete Online DJ Booking System 1.0 A vulnerability was found in Campcodes Complete Online DJ Booking System 1.0 and classified as problematic. | 6.1 |
2024-03-20 | CVE-2024-2716 | Campcodes | Unspecified vulnerability in Campcodes Complete Online DJ Booking System 1.0 A vulnerability was found in Campcodes Complete Online DJ Booking System 1.0. | 6.1 |
2024-03-20 | CVE-2024-2683 | Campcodes | Unspecified vulnerability in Campcodes Online JOB Finder System 1.0 A vulnerability classified as problematic was found in Campcodes Online Job Finder System 1.0. | 6.1 |
2024-03-20 | CVE-2024-2684 | Campcodes | Unspecified vulnerability in Campcodes Online JOB Finder System 1.0 A vulnerability, which was classified as problematic, has been found in Campcodes Online Job Finder System 1.0. | 6.1 |
2024-03-20 | CVE-2024-2685 | Campcodes | Unspecified vulnerability in Campcodes Online JOB Finder System 1.0 A vulnerability, which was classified as problematic, was found in Campcodes Online Job Finder System 1.0. | 6.1 |
2024-03-20 | CVE-2024-2686 | Campcodes | Unspecified vulnerability in Campcodes Online JOB Finder System 1.0 A vulnerability has been found in Campcodes Online Job Finder System 1.0 and classified as problematic. | 6.1 |
2024-03-20 | CVE-2024-2680 | Campcodes | Unspecified vulnerability in Campcodes Online JOB Finder System 1.0 A vulnerability was found in Campcodes Online Job Finder System 1.0. | 6.1 |
2024-03-20 | CVE-2024-2681 | Campcodes | Unspecified vulnerability in Campcodes Online JOB Finder System 1.0 A vulnerability was found in Campcodes Online Job Finder System 1.0. | 6.1 |
2024-03-20 | CVE-2024-2682 | Campcodes | Unspecified vulnerability in Campcodes Online JOB Finder System 1.0 A vulnerability classified as problematic has been found in Campcodes Online Job Finder System 1.0. | 6.1 |
2024-03-20 | CVE-2024-2679 | Campcodes | Unspecified vulnerability in Campcodes Online JOB Finder System 1.0 A vulnerability was found in Campcodes Online Job Finder System 1.0. | 6.1 |
2024-03-19 | CVE-2024-29092 | Permalink Manager Lite Project | Unspecified vulnerability in Permalink Manager Lite Project Permalink Manager Lite Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Maciej Bis Permalink Manager Lite allows Reflected XSS.This issue affects Permalink Manager Lite: from n/a through 2.4.3. | 6.1 |
2024-03-19 | CVE-2024-29099 | Evergreencontentposter | Unspecified vulnerability in Evergreencontentposter Evergreen Content Poster Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Evergreen Content Poster allows Reflected XSS.This issue affects Evergreen Content Poster: from n/a through 1.4.1. | 6.1 |
2024-03-19 | CVE-2024-29113 | Metagauss | Unspecified vulnerability in Metagauss Registrationmagic Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Metagauss RegistrationMagic allows Reflected XSS.This issue affects RegistrationMagic: from n/a through 5.2.5.9. | 6.1 |
2024-03-19 | CVE-2024-29123 | Ylefebvre | Unspecified vulnerability in Ylefebvre Link Library Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Yannick Lefebvre Link Library allows Reflected XSS.This issue affects Link Library: from n/a through 7.6. | 6.1 |
2024-03-19 | CVE-2024-29127 | Vasyltech | Unspecified vulnerability in Vasyltech Advanced Access Manager Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in AAM Advanced Access Manager allows Reflected XSS.This issue affects Advanced Access Manager: from n/a through 6.9.20. | 6.1 |
2024-03-19 | CVE-2024-29128 | Wpexperts | Unspecified vulnerability in Wpexperts Post Smtp Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Post SMTP POST SMTP allows Reflected XSS.This issue affects POST SMTP: from n/a through 2.8.6. | 6.1 |
2024-03-19 | CVE-2024-29130 | Wpplugin | Unspecified vulnerability in Wpplugin Paypal & Stripe Add-On Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Scott Paterson Contact Form 7 – PayPal & Stripe Add-on allows Reflected XSS.This issue affects Contact Form 7 – PayPal & Stripe Add-on: from n/a through 2.0. | 6.1 |
2024-03-19 | CVE-2024-29137 | Themefic | Unspecified vulnerability in Themefic Tourfic Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themefic Tourfic allows Reflected XSS.This issue affects Tourfic: from n/a through 2.11.7. | 6.1 |
2024-03-19 | CVE-2024-29138 | DEV Institute | Unspecified vulnerability in Dev.Institute Restrict User Access Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in DEV Institute Restrict User Access – Membership Plugin with Force allows Reflected XSS.This issue affects Restrict User Access – Membership Plugin with Force: from n/a through 2.5. | 6.1 |
2024-03-18 | CVE-2024-28249 | Cilium | Cleartext Transmission of Sensitive Information vulnerability in Cilium Cilium is a networking, observability, and security solution with an eBPF-based dataplane. | 6.1 |
2024-03-18 | CVE-2024-28250 | Cilium | Cleartext Transmission of Sensitive Information vulnerability in Cilium Cilium is a networking, observability, and security solution with an eBPF-based dataplane. | 6.1 |
2024-03-18 | CVE-2024-28855 | Zitadel | Cross-site Scripting vulnerability in Zitadel ZITADEL, open source authentication management software, uses Go templates to render the login UI. | 6.1 |
2024-03-18 | CVE-2024-27914 | Glpi Project | Cross-site Scripting vulnerability in Glpi-Project Glpi GLPI is a Free Asset and IT Management Software package, Data center management, ITIL Service Desk, licenses tracking and software auditing. | 6.1 |
2024-03-18 | CVE-2024-23604 | Cleancoder | Unspecified vulnerability in Cleancoder Fitnesse Cross-site scripting vulnerability exists in FitNesse all releases, which may allow a remote unauthenticated attacker to execute an arbitrary script on the web browser of the user who is using the product and accessing a link with specially crafted multiple parameters. | 6.1 |
2024-03-18 | CVE-2024-28128 | Cleancoder | Unspecified vulnerability in Cleancoder Fitnesse Cross-site scripting vulnerability exists in FitNesse releases prior to 20220319, which may allow a remote unauthenticated attacker to execute an arbitrary script on the web browser of the user who is using the product and accessing a link with a specially crafted certain parameter. | 6.1 |
2024-03-20 | CVE-2024-23634 | Geoserver | Unspecified vulnerability in Geoserver GeoServer is an open source software server written in Java that allows users to share and edit geospatial data. | 6.0 |
2024-03-19 | CVE-2024-22453 | Dell | Out-of-bounds Write vulnerability in Dell products Dell PowerEdge Server BIOS contains a heap-based buffer overflow vulnerability. | 6.0 |
2024-03-20 | CVE-2023-35888 | IBM | Unspecified vulnerability in IBM Security Verify Governance 10.0.2 IBM Security Verify Governance 10.0.2 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. | 5.9 |
2024-03-21 | CVE-2024-27277 | IBM | Unspecified vulnerability in IBM Storage Protect Plus 10.1.0 The private key for the IBM Storage Protect Plus Server 10.1.0 through 10.1.16 certificate can be disclosed, undermining the security of the certificate. | 5.5 |
2024-03-21 | CVE-2024-22352 | IBM | Unspecified vulnerability in IBM Infosphere Information Server 11.7 IBM InfoSphere Information Server 11.7 stores potentially sensitive information in log files that could be read by a local user. | 5.5 |
2024-03-18 | CVE-2024-25654 | Avsystem | Information Exposure Through Log Files vulnerability in Avsystem Unified Management Platform 23.07.0.16567 Insecure permissions for log files of AVSystem Unified Management Platform (UMP) 23.07.0.16567~LTS allow members (with local access to the UMP application server) to access credentials to authenticate to all services, and to decrypt sensitive data stored in the database. | 5.5 |
2024-03-18 | CVE-2023-52610 | Linux | Memory Leak vulnerability in Linux Kernel In the Linux kernel, the following vulnerability has been resolved: net/sched: act_ct: fix skb leak and crash on ooo frags act_ct adds skb->users before defragmentation. | 5.5 |
2024-03-18 | CVE-2023-52611 | Linux | Unspecified vulnerability in Linux Kernel 6.7/6.7.1 In the Linux kernel, the following vulnerability has been resolved: wifi: rtw88: sdio: Honor the host max_req_size in the RX path Lukas reports skb_over_panic errors on his Banana Pi BPI-CM4 which comes with an Amlogic A311D (G12B) SoC and a RTL8822CS SDIO wifi/Bluetooth combo card. | 5.5 |
2024-03-18 | CVE-2023-52615 | Linux | Improper Locking vulnerability in Linux Kernel In the Linux kernel, the following vulnerability has been resolved: hwrng: core - Fix page fault dead lock on mmap-ed hwrng There is a dead-lock in the hwrng device read path. | 5.5 |
2024-03-18 | CVE-2023-52616 | Linux Debian | In the Linux kernel, the following vulnerability has been resolved: crypto: lib/mpi - Fix unexpected pointer access in mpi_ec_init When the mpi_ec_ctx structure is initialized, some fields are not cleared, causing a crash when referencing the field when the structure was released. | 5.5 |
2024-03-18 | CVE-2023-52619 | Linux Debian | In the Linux kernel, the following vulnerability has been resolved: pstore/ram: Fix crash when setting number of cpus to an odd number When the number of cpu cores is adjusted to 7 or other odd numbers, the zone size will become an odd number. The address of the zone will become: addr of zone0 = BASE addr of zone1 = BASE + zone_size addr of zone2 = BASE + zone_size*2 ... The address of zone1/3/5/7 will be mapped to non-alignment va. Eventually crashes will occur when accessing these va. So, use ALIGN_DOWN() to make sure the zone size is even to avoid this bug. | 5.5 |
2024-03-18 | CVE-2024-26632 | Linux | Unspecified vulnerability in Linux Kernel In the Linux kernel, the following vulnerability has been resolved: block: Fix iterating over an empty bio with bio_for_each_folio_all If the bio contains no data, bio_first_folio() calls page_folio() on a NULL pointer and oopses. | 5.5 |
2024-03-18 | CVE-2024-26634 | Linux | Unspecified vulnerability in Linux Kernel In the Linux kernel, the following vulnerability has been resolved: net: fix removing a namespace with conflicting altnames Mark reports a BUG() when a net namespace is removed. kernel BUG at net/core/dev.c:11520! Physical interfaces moved outside of init_net get "refunded" to init_net when that namespace disappears. | 5.5 |
2024-03-18 | CVE-2024-26635 | Linux Debian | Missing Initialization of Resource vulnerability in multiple products In the Linux kernel, the following vulnerability has been resolved: llc: Drop support for ETH_P_TR_802_2. syzbot reported an uninit-value bug below. | 5.5 |
2024-03-18 | CVE-2024-26636 | Linux Debian | In the Linux kernel, the following vulnerability has been resolved: llc: make llc_ui_sendmsg() more robust against bonding changes syzbot was able to trick llc_ui_sendmsg(), allocating an skb with no headroom, but subsequently trying to push 14 bytes of Ethernet header [1] Like some others, llc_ui_sendmsg() releases the socket lock before calling sock_alloc_send_skb(). Then it acquires it again, but does not redo all the sanity checks that were performed. This fix: - Uses LL_RESERVED_SPACE() to reserve space. - Check all conditions again after socket lock is held again. - Do not account Ethernet header for mtu limitation. [1] skbuff: skb_under_panic: text:ffff800088baa334 len:1514 put:14 head:ffff0000c9c37000 data:ffff0000c9c36ff2 tail:0x5dc end:0x6c0 dev:bond0 kernel BUG at net/core/skbuff.c:193 ! Internal error: Oops - BUG: 00000000f2000800 [#1] PREEMPT SMP Modules linked in: CPU: 0 PID: 6875 Comm: syz-executor.0 Not tainted 6.7.0-rc8-syzkaller-00101-g0802e17d9aca-dirty #0 Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 11/17/2023 pstate: 60400005 (nZCv daif +PAN -UAO -TCO -DIT -SSBS BTYPE=--) pc : skb_panic net/core/skbuff.c:189 [inline] pc : skb_under_panic+0x13c/0x140 net/core/skbuff.c:203 lr : skb_panic net/core/skbuff.c:189 [inline] lr : skb_under_panic+0x13c/0x140 net/core/skbuff.c:203 sp : ffff800096f97000 x29: ffff800096f97010 x28: ffff80008cc8d668 x27: dfff800000000000 x26: ffff0000cb970c90 x25: 00000000000005dc x24: ffff0000c9c36ff2 x23: ffff0000c9c37000 x22: 00000000000005ea x21: 00000000000006c0 x20: 000000000000000e x19: ffff800088baa334 x18: 1fffe000368261ce x17: ffff80008e4ed000 x16: ffff80008a8310f8 x15: 0000000000000001 x14: 1ffff00012df2d58 x13: 0000000000000000 x12: 0000000000000000 x11: 0000000000000001 x10: 0000000000ff0100 x9 : e28a51f1087e8400 x8 : e28a51f1087e8400 x7 : ffff80008028f8d0 x6 : 0000000000000000 x5 : 0000000000000001 x4 : 0000000000000001 x3 : ffff800082b78714 x2 : 0000000000000001 x1 : 0000000100000000 x0 : 0000000000000089 Call trace: skb_panic net/core/skbuff.c:189 [inline] skb_under_panic+0x13c/0x140 net/core/skbuff.c:203 skb_push+0xf0/0x108 net/core/skbuff.c:2451 eth_header+0x44/0x1f8 net/ethernet/eth.c:83 dev_hard_header include/linux/netdevice.h:3188 [inline] llc_mac_hdr_init+0x110/0x17c net/llc/llc_output.c:33 llc_sap_action_send_xid_c+0x170/0x344 net/llc/llc_s_ac.c:85 llc_exec_sap_trans_actions net/llc/llc_sap.c:153 [inline] llc_sap_next_state net/llc/llc_sap.c:182 [inline] llc_sap_state_process+0x1ec/0x774 net/llc/llc_sap.c:209 llc_build_and_send_xid_pkt+0x12c/0x1c0 net/llc/llc_sap.c:270 llc_ui_sendmsg+0x7bc/0xb1c net/llc/af_llc.c:997 sock_sendmsg_nosec net/socket.c:730 [inline] __sock_sendmsg net/socket.c:745 [inline] sock_sendmsg+0x194/0x274 net/socket.c:767 splice_to_socket+0x7cc/0xd58 fs/splice.c:881 do_splice_from fs/splice.c:933 [inline] direct_splice_actor+0xe4/0x1c0 fs/splice.c:1142 splice_direct_to_actor+0x2a0/0x7e4 fs/splice.c:1088 do_splice_direct+0x20c/0x348 fs/splice.c:1194 do_sendfile+0x4bc/0xc70 fs/read_write.c:1254 __do_sys_sendfile64 fs/read_write.c:1322 [inline] __se_sys_sendfile64 fs/read_write.c:1308 [inline] __arm64_sys_sendfile64+0x160/0x3b4 fs/read_write.c:1308 __invoke_syscall arch/arm64/kernel/syscall.c:37 [inline] invoke_syscall+0x98/0x2b8 arch/arm64/kernel/syscall.c:51 el0_svc_common+0x130/0x23c arch/arm64/kernel/syscall.c:136 do_el0_svc+0x48/0x58 arch/arm64/kernel/syscall.c:155 el0_svc+0x54/0x158 arch/arm64/kernel/entry-common.c:678 el0t_64_sync_handler+0x84/0xfc arch/arm64/kernel/entry-common.c:696 el0t_64_sync+0x190/0x194 arch/arm64/kernel/entry.S:595 Code: aa1803e6 aa1903e7 a90023f5 94792f6a (d4210000) | 5.5 |
2024-03-18 | CVE-2024-26637 | Linux | Unspecified vulnerability in Linux Kernel In the Linux kernel, the following vulnerability has been resolved: wifi: ath11k: rely on mac80211 debugfs handling for vif mac80211 started to delete debugfs entries in certain cases, causing a ath11k to crash when it tried to delete the entries later. | 5.5 |
2024-03-18 | CVE-2024-26640 | Linux Debian | In the Linux kernel, the following vulnerability has been resolved: tcp: add sanity checks to rx zerocopy TCP rx zerocopy intent is to map pages initially allocated from NIC drivers, not pages owned by a fs. This patch adds to can_map_frag() these additional checks: - Page must not be a compound one. - page->mapping must be NULL. This fixes the panic reported by ZhangPeng. syzbot was able to loopback packets built with sendfile(), mapping pages owned by an ext4 file to TCP rx zerocopy. r3 = socket$inet_tcp(0x2, 0x1, 0x0) mmap(&(0x7f0000ff9000/0x4000)=nil, 0x4000, 0x0, 0x12, r3, 0x0) r4 = socket$inet_tcp(0x2, 0x1, 0x0) bind$inet(r4, &(0x7f0000000000)={0x2, 0x4e24, @multicast1}, 0x10) connect$inet(r4, &(0x7f00000006c0)={0x2, 0x4e24, @empty}, 0x10) r5 = openat$dir(0xffffffffffffff9c, &(0x7f00000000c0)='./file0\x00', 0x181e42, 0x0) fallocate(r5, 0x0, 0x0, 0x85b8) sendfile(r4, r5, 0x0, 0x8ba0) getsockopt$inet_tcp_TCP_ZEROCOPY_RECEIVE(r4, 0x6, 0x23, &(0x7f00000001c0)={&(0x7f0000ffb000/0x3000)=nil, 0x3000, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0, 0x0}, &(0x7f0000000440)=0x40) r6 = openat$dir(0xffffffffffffff9c, &(0x7f00000000c0)='./file0\x00', 0x181e42, 0x0) | 5.5 |
2024-03-18 | CVE-2024-26641 | Linux Debian Netapp | Use of Uninitialized Resource vulnerability in multiple products In the Linux kernel, the following vulnerability has been resolved: ip6_tunnel: make sure to pull inner header in __ip6_tnl_rcv() syzbot found __ip6_tnl_rcv() could access unitiliazed data [1]. Call pskb_inet_may_pull() to fix this, and initialize ipv6h variable after this call as it can change skb->head. [1] BUG: KMSAN: uninit-value in __INET_ECN_decapsulate include/net/inet_ecn.h:253 [inline] BUG: KMSAN: uninit-value in INET_ECN_decapsulate include/net/inet_ecn.h:275 [inline] BUG: KMSAN: uninit-value in IP6_ECN_decapsulate+0x7df/0x1e50 include/net/inet_ecn.h:321 __INET_ECN_decapsulate include/net/inet_ecn.h:253 [inline] INET_ECN_decapsulate include/net/inet_ecn.h:275 [inline] IP6_ECN_decapsulate+0x7df/0x1e50 include/net/inet_ecn.h:321 ip6ip6_dscp_ecn_decapsulate+0x178/0x1b0 net/ipv6/ip6_tunnel.c:727 __ip6_tnl_rcv+0xd4e/0x1590 net/ipv6/ip6_tunnel.c:845 ip6_tnl_rcv+0xce/0x100 net/ipv6/ip6_tunnel.c:888 gre_rcv+0x143f/0x1870 ip6_protocol_deliver_rcu+0xda6/0x2a60 net/ipv6/ip6_input.c:438 ip6_input_finish net/ipv6/ip6_input.c:483 [inline] NF_HOOK include/linux/netfilter.h:314 [inline] ip6_input+0x15d/0x430 net/ipv6/ip6_input.c:492 ip6_mc_input+0xa7e/0xc80 net/ipv6/ip6_input.c:586 dst_input include/net/dst.h:461 [inline] ip6_rcv_finish+0x5db/0x870 net/ipv6/ip6_input.c:79 NF_HOOK include/linux/netfilter.h:314 [inline] ipv6_rcv+0xda/0x390 net/ipv6/ip6_input.c:310 __netif_receive_skb_one_core net/core/dev.c:5532 [inline] __netif_receive_skb+0x1a6/0x5a0 net/core/dev.c:5646 netif_receive_skb_internal net/core/dev.c:5732 [inline] netif_receive_skb+0x58/0x660 net/core/dev.c:5791 tun_rx_batched+0x3ee/0x980 drivers/net/tun.c:1555 tun_get_user+0x53af/0x66d0 drivers/net/tun.c:2002 tun_chr_write_iter+0x3af/0x5d0 drivers/net/tun.c:2048 call_write_iter include/linux/fs.h:2084 [inline] new_sync_write fs/read_write.c:497 [inline] vfs_write+0x786/0x1200 fs/read_write.c:590 ksys_write+0x20f/0x4c0 fs/read_write.c:643 __do_sys_write fs/read_write.c:655 [inline] __se_sys_write fs/read_write.c:652 [inline] __x64_sys_write+0x93/0xd0 fs/read_write.c:652 do_syscall_x64 arch/x86/entry/common.c:52 [inline] do_syscall_64+0x6d/0x140 arch/x86/entry/common.c:83 entry_SYSCALL_64_after_hwframe+0x63/0x6b Uninit was created at: slab_post_alloc_hook+0x129/0xa70 mm/slab.h:768 slab_alloc_node mm/slub.c:3478 [inline] kmem_cache_alloc_node+0x5e9/0xb10 mm/slub.c:3523 kmalloc_reserve+0x13d/0x4a0 net/core/skbuff.c:560 __alloc_skb+0x318/0x740 net/core/skbuff.c:651 alloc_skb include/linux/skbuff.h:1286 [inline] alloc_skb_with_frags+0xc8/0xbd0 net/core/skbuff.c:6334 sock_alloc_send_pskb+0xa80/0xbf0 net/core/sock.c:2787 tun_alloc_skb drivers/net/tun.c:1531 [inline] tun_get_user+0x1e8a/0x66d0 drivers/net/tun.c:1846 tun_chr_write_iter+0x3af/0x5d0 drivers/net/tun.c:2048 call_write_iter include/linux/fs.h:2084 [inline] new_sync_write fs/read_write.c:497 [inline] vfs_write+0x786/0x1200 fs/read_write.c:590 ksys_write+0x20f/0x4c0 fs/read_write.c:643 __do_sys_write fs/read_write.c:655 [inline] __se_sys_write fs/read_write.c:652 [inline] __x64_sys_write+0x93/0xd0 fs/read_write.c:652 do_syscall_x64 arch/x86/entry/common.c:52 [inline] do_syscall_64+0x6d/0x140 arch/x86/entry/common.c:83 entry_SYSCALL_64_after_hwframe+0x63/0x6b CPU: 0 PID: 5034 Comm: syz-executor331 Not tainted 6.7.0-syzkaller-00562-g9f8413c4a66f #0 Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 11/17/2023 | 5.5 |
2024-03-23 | CVE-2024-24840 | Bdthemes | Unspecified vulnerability in Bdthemes Element Pack Missing Authorization vulnerability in BdThemes Element Pack Elementor Addons.This issue affects Element Pack Elementor Addons: from n/a through 5.4.11. | 5.4 |
2024-03-23 | CVE-2024-1049 | Godaddy | Cross-site Scripting vulnerability in Godaddy Coblocks The Page Builder Gutenberg Blocks – CoBlocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Icon Widget's in all versions up to, and including, 3.1.6 due to insufficient input sanitization and output escaping on the link value. | 5.4 |
2024-03-23 | CVE-2024-2202 | Siteorigin | Cross-site Scripting vulnerability in Siteorigin Page Builder The Page Builder by SiteOrigin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the legacy Image widget in all versions up to, and including, 2.29.6 due to insufficient input sanitization and output escaping. | 5.4 |
2024-03-23 | CVE-2024-2468 | Wpdeveloper | Cross-site Scripting vulnerability in Wpdeveloper Embedpress The EmbedPress – Embed PDF, Google Docs, Vimeo, Wistia, Embed YouTube Videos, Audios, Maps & Embed Any Documents in Gutenberg & Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the EmbedPress widget 'embedpress_pro_twitch_theme ' attribute in all versions up to, and including, 3.9.12 due to insufficient input sanitization and output escaping on user supplied attributes. | 5.4 |
2024-03-23 | CVE-2024-2688 | Wpdeveloper | Cross-site Scripting vulnerability in Wpdeveloper Embedpress The EmbedPress – Embed PDF, Google Docs, Vimeo, Wistia, Embed YouTube Videos, Audios, Maps & Embed Any Documents in Gutenberg & Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the EmbedPress document widget in all versions up to, and including, 3.9.12 due to insufficient input sanitization and output escaping on user supplied attributes. | 5.4 |
2024-03-23 | CVE-2024-1697 | Themelocation | Cross-site Scripting vulnerability in Themelocation Custom Woocommerce Checkout Fields Editor The Custom WooCommerce Checkout Fields Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the save_wcfe_options function in all versions up to, and including, 1.3.1 due to insufficient input sanitization and output escaping. | 5.4 |
2024-03-23 | CVE-2024-2131 | Moveaddons | Cross-site Scripting vulnerability in Moveaddons Move Addons for Elementor The Move Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's infobox and button widget in all versions up to, and including, 1.2.9 due to insufficient input sanitization and output escaping on user supplied attributes. | 5.4 |
2024-03-22 | CVE-2024-2392 | Creativethemes | Cross-site Scripting vulnerability in Creativethemes Blocksy Companion The Blocksy Companion plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Newsletter widget in all versions up to, and including, 2.0.31 due to insufficient input sanitization and output escaping on user supplied attributes. | 5.4 |
2024-03-22 | CVE-2024-2779 | Campcodes | Unspecified vulnerability in Campcodes Online Marriage Registration System 1.0 A vulnerability was found in Campcodes Online Marriage Registration System 1.0. | 5.4 |
2024-03-21 | CVE-2024-27963 | Crisp | Unspecified vulnerability in Crisp Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crisp allows Stored XSS.This issue affects Crisp: from n/a through 0.44. | 5.4 |
2024-03-21 | CVE-2024-1278 | Easysocialfeed | Cross-site Scripting vulnerability in Easysocialfeed Easy Social Feed The Easy Social Feed – Social Photos Gallery – Post Feed – Like Box plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'efb_likebox' shortcode in all versions up to, and including, 6.5.4 due to insufficient input sanitization and output escaping on user supplied attributes. | 5.4 |
2024-03-21 | CVE-2024-1326 | Jegtheme | Cross-site Scripting vulnerability in Jegtheme JEG Elementor KIT The Jeg Elementor Kit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via HTML Tag attributes in all versions up to, and including, 2.6.2 due to insufficient input sanitization and output escaping. | 5.4 |
2024-03-20 | CVE-2024-29471 | Zhyd | Cross-site Scripting vulnerability in Zhyd Oneblog 2.3.4 OneBlog v2.3.4 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Notice Manage module. | 5.4 |
2024-03-20 | CVE-2024-29472 | Zhyd | Cross-site Scripting vulnerability in Zhyd Oneblog 2.3.4 OneBlog v2.3.4 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Privilege Management module. | 5.4 |
2024-03-20 | CVE-2024-29419 | Totolink | Cross-site Scripting vulnerability in Totolink X2000R Firmware There is a Cross-site scripting (XSS) vulnerability in the Wireless settings under the Easy Setup Page of TOTOLINK X2000R before v1.0.0-B20231213.1013. | 5.4 |
2024-03-20 | CVE-2024-2255 | Wpdeveloper | Cross-site Scripting vulnerability in Wpdeveloper Essential Blocks The Essential Blocks – Page Builder Gutenberg Blocks, Patterns & Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's widgets in all versions up to, and including, 4.5.2 due to insufficient input sanitization and output escaping on user supplied attributes such as listStyle. | 5.4 |
2024-03-19 | CVE-2024-29101 | Jegtheme | Unspecified vulnerability in Jegtheme JEG Elementor KIT Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jegtheme Jeg Elementor Kit allows Stored XSS.This issue affects Jeg Elementor Kit: from n/a through 2.6.2. | 5.4 |
2024-03-19 | CVE-2024-29106 | Leap13 | Unspecified vulnerability in Leap13 Premium Addons for Elementor Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Leap13 Premium Addons for Elementor allows Stored XSS.This issue affects Premium Addons for Elementor: from n/a through 4.10.16. | 5.4 |
2024-03-19 | CVE-2024-29107 | Webtechstreet | Unspecified vulnerability in Webtechstreet Elementor Addon Elements Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPVibes Elementor Addon Elements allows Stored XSS.This issue affects Elementor Addon Elements: from n/a through 1.12.10. | 5.4 |
2024-03-19 | CVE-2024-29108 | Leevio | Unspecified vulnerability in Leevio Happy Addons for Elementor Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Leevio Happy Addons for Elementor allows Stored XSS.This issue affects Happy Addons for Elementor: from n/a through 3.10.1. | 5.4 |
2024-03-19 | CVE-2024-29115 | Zaytech | Unspecified vulnerability in Zaytech Smart Online Order for Clover Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Zaytech Smart Online Order for Clover allows Stored XSS.This issue affects Smart Online Order for Clover: from n/a through 1.5.5. | 5.4 |
2024-03-19 | CVE-2024-29134 | Themefic | Unspecified vulnerability in Themefic Tourfic Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themefic Tourfic allows Stored XSS.This issue affects Tourfic: from n/a through 2.11.8. | 5.4 |
2024-03-18 | CVE-2024-0820 | Blueglass | Cross-site Scripting vulnerability in Blueglass Jobs for Wordpress The Jobs for WordPress plugin before 2.7.4 does not sanitise and escape some parameters, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks | 5.4 |
2024-03-18 | CVE-2024-26051 | Adobe | Unspecified vulnerability in Adobe Experience Manager Adobe Experience Manager versions 6.5.19 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. | 5.4 |
2024-03-18 | CVE-2024-1606 | BMC | Unspecified vulnerability in BMC Control-M Lack of input sanitization in BMC Control-M branches 9.0.20 and 9.0.21 allows logged-in users for manipulation of generated web pages via injection of HTML code. | 5.4 |
2024-03-22 | CVE-2022-32751 | IBM | Unspecified vulnerability in IBM Security Verify Directory 10.0.0 IBM Security Verify Directory 10.0.0 could disclose sensitive server information that could be used in further attacks against the system. | 5.3 |
2024-03-20 | CVE-2024-28868 | Umbraco | Information Exposure Through Discrepancy vulnerability in Umbraco CMS Umbraco is an ASP.NET content management system. | 5.3 |
2024-03-19 | CVE-2024-2645 | Netentsec | XML Injection (aka Blind XPath Injection) vulnerability in Netentsec Application Security Gateway 6.3 A vulnerability classified as problematic has been found in Netentsec NS-ASG Application Security Gateway 6.3. | 5.3 |
2024-03-19 | CVE-2024-2648 | Netentsec | XML Injection (aka Blind XPath Injection) vulnerability in Netentsec Application Security Gateway 6.3 A vulnerability, which was classified as problematic, was found in Netentsec NS-ASG Application Security Gateway 6.3. | 5.3 |
2024-03-18 | CVE-2024-26119 | Adobe | Unspecified vulnerability in Adobe Experience Manager Adobe Experience Manager versions 6.5.19 and earlier are affected by an Information Exposure vulnerability that could result in a security feature bypass. | 5.3 |
2024-03-21 | CVE-2023-42954 | Claris | Unspecified vulnerability in Claris PRO and Filemaker Server A privilege escalation issue existed in FileMaker Server, potentially exposing sensitive information to front-end websites when signed in to the Admin Console with an administrator role. | 4.9 |
2024-03-22 | CVE-2022-32754 | IBM | Unspecified vulnerability in IBM Security Verify Directory 10.0.0 IBM Security Verify Directory 10.0.0 is vulnerable to cross-site scripting. | 4.8 |
2024-03-21 | CVE-2024-27965 | Getwpfunnels | Unspecified vulnerability in Getwpfunnels Wpfunnels Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPFunnels Team WPFunnels allows Stored XSS.This issue affects WPFunnels: from n/a through 3.0.6. | 4.8 |
2024-03-20 | CVE-2024-23642 | Geoserver | Cross-site Scripting vulnerability in Geoserver GeoServer is an open source software server written in Java that allows users to share and edit geospatial data. | 4.8 |
2024-03-20 | CVE-2024-23643 | Geoserver | Cross-site Scripting vulnerability in Geoserver GeoServer is an open source software server written in Java that allows users to share and edit geospatial data. | 4.8 |
2024-03-20 | CVE-2024-23818 | Geoserver | Cross-site Scripting vulnerability in Geoserver GeoServer is an open source software server written in Java that allows users to share and edit geospatial data. | 4.8 |
2024-03-20 | CVE-2024-23819 | Geoserver | Cross-site Scripting vulnerability in Geoserver GeoServer is an open source software server written in Java that allows users to share and edit geospatial data. | 4.8 |
2024-03-20 | CVE-2024-23821 | Geoserver | Cross-site Scripting vulnerability in Geoserver GeoServer is an open source software server written in Java that allows users to share and edit geospatial data. | 4.8 |
2024-03-20 | CVE-2023-51445 | Geoserver | Cross-site Scripting vulnerability in Geoserver GeoServer is an open source software server written in Java that allows users to share and edit geospatial data. | 4.8 |
2024-03-20 | CVE-2024-23640 | Geoserver | Cross-site Scripting vulnerability in Geoserver GeoServer is an open source software server written in Java that allows users to share and edit geospatial data. | 4.8 |
2024-03-19 | CVE-2024-29112 | Wpmarketingrobot | Unspecified vulnerability in Wpmarketingrobot Woocommerce Google Feed Manager Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Marketing Robot WooCommerce Google Feed Manager allows Stored XSS.This issue affects WooCommerce Google Feed Manager: from n/a through 2.2.0. | 4.8 |
2024-03-18 | CVE-2024-28237 | Octoprint | Cross-site Scripting vulnerability in Octoprint OctoPrint provides a web interface for controlling consumer 3D printers. | 4.8 |
2024-03-18 | CVE-2024-0951 | Shahaji9 | Cross-site Scripting vulnerability in Shahaji9 Advanced Social Feeds Widget & Shortcode The Advanced Social Feeds Widget & Shortcode WordPress plugin through 1.7 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup) | 4.8 |
2024-03-18 | CVE-2024-26050 | Adobe | Unspecified vulnerability in Adobe Experience Manager Adobe Experience Manager versions 6.5.19 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an admin attacker to inject malicious scripts into vulnerable form fields. | 4.8 |
2024-03-18 | CVE-2024-27104 | Glpi Project | Cross-site Scripting vulnerability in Glpi-Project Glpi GLPI is a Free Asset and IT Management Software package, Data center management, ITIL Service Desk, licenses tracking and software auditing. | 4.8 |
2024-03-18 | CVE-2023-52609 | Linux Debian | Race Condition vulnerability in multiple products In the Linux kernel, the following vulnerability has been resolved: binder: fix race between mmput() and do_exit() Task A calls binder_update_page_range() to allocate and insert pages on a remote address space from Task B. | 4.7 |
2024-03-18 | CVE-2024-26631 | Linux | Improper Locking vulnerability in Linux Kernel In the Linux kernel, the following vulnerability has been resolved: ipv6: mcast: fix data-race in ipv6_mc_down / mld_ifc_work idev->mc_ifc_count can be written over without proper locking. Originally found by syzbot [1], fix this issue by encapsulating calls to mld_ifc_stop_work() (and mld_gq_stop_work() for good measure) with mutex_lock() and mutex_unlock() accordingly as these functions should only be called with mc_lock per their declarations. [1] BUG: KCSAN: data-race in ipv6_mc_down / mld_ifc_work write to 0xffff88813a80c832 of 1 bytes by task 3771 on cpu 0: mld_ifc_stop_work net/ipv6/mcast.c:1080 [inline] ipv6_mc_down+0x10a/0x280 net/ipv6/mcast.c:2725 addrconf_ifdown+0xe32/0xf10 net/ipv6/addrconf.c:3949 addrconf_notify+0x310/0x980 notifier_call_chain kernel/notifier.c:93 [inline] raw_notifier_call_chain+0x6b/0x1c0 kernel/notifier.c:461 __dev_notify_flags+0x205/0x3d0 dev_change_flags+0xab/0xd0 net/core/dev.c:8685 do_setlink+0x9f6/0x2430 net/core/rtnetlink.c:2916 rtnl_group_changelink net/core/rtnetlink.c:3458 [inline] __rtnl_newlink net/core/rtnetlink.c:3717 [inline] rtnl_newlink+0xbb3/0x1670 net/core/rtnetlink.c:3754 rtnetlink_rcv_msg+0x807/0x8c0 net/core/rtnetlink.c:6558 netlink_rcv_skb+0x126/0x220 net/netlink/af_netlink.c:2545 rtnetlink_rcv+0x1c/0x20 net/core/rtnetlink.c:6576 netlink_unicast_kernel net/netlink/af_netlink.c:1342 [inline] netlink_unicast+0x589/0x650 net/netlink/af_netlink.c:1368 netlink_sendmsg+0x66e/0x770 net/netlink/af_netlink.c:1910 ... write to 0xffff88813a80c832 of 1 bytes by task 22 on cpu 1: mld_ifc_work+0x54c/0x7b0 net/ipv6/mcast.c:2653 process_one_work kernel/workqueue.c:2627 [inline] process_scheduled_works+0x5b8/0xa30 kernel/workqueue.c:2700 worker_thread+0x525/0x730 kernel/workqueue.c:2781 ... | 4.7 |
2024-03-21 | CVE-2024-27932 | Deno | Unspecified vulnerability in Deno Deno is a JavaScript, TypeScript, and WebAssembly runtime. | 4.6 |
2024-03-22 | CVE-2024-29057 | Microsoft | Unspecified vulnerability in Microsoft Edge Microsoft Edge (Chromium-based) Spoofing Vulnerability | 4.3 |
2024-03-22 | CVE-2024-2823 | Dedecms | Unspecified vulnerability in Dedecms 5.7 A vulnerability has been found in DedeCMS 5.7 and classified as problematic. | 4.3 |
2024-03-22 | CVE-2024-2820 | Dedecms | Unspecified vulnerability in Dedecms 5.7 A vulnerability classified as problematic was found in DedeCMS 5.7. | 4.3 |
2024-03-21 | CVE-2023-47715 | IBM | Unspecified vulnerability in IBM Storage Protect Plus 10.1.0/10.1.16 IBM Storage Protect Plus Server 10.1.0 through 10.1.16 could allow an authenticated user with read-only permissions to add or delete entries from an existing HyperVisor configuration. | 4.3 |
2024-03-21 | CVE-2024-1213 | Easysocialfeed | Cross-Site Request Forgery (CSRF) vulnerability in Easysocialfeed Easy Social Feed The Easy Social Feed – Social Photos Gallery – Post Feed – Like Box plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 6.5.4. | 4.3 |
2024-03-21 | CVE-2024-1502 | Themeum | Missing Authorization vulnerability in Themeum Tutor LMS The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the tutor_delete_announcement() function in all versions up to, and including, 2.6.1. | 4.3 |
2024-03-20 | CVE-2024-2628 | Google Fedoraproject | Inappropriate implementation in Downloads in Google Chrome prior to 123.0.6312.58 allowed a remote attacker to perform UI spoofing via a crafted URL. | 4.3 |
2024-03-20 | CVE-2024-2629 | Google Fedoraproject | Incorrect security UI in iOS in Google Chrome prior to 123.0.6312.58 allowed a remote attacker to perform UI spoofing via a crafted HTML page. | 4.3 |
2024-03-20 | CVE-2024-2631 | Google Fedoraproject | Inappropriate implementation in iOS in Google Chrome prior to 123.0.6312.58 allowed a remote attacker to perform UI spoofing via a crafted HTML page. | 4.3 |
2024-03-20 | CVE-2024-2291 | Progress | Unspecified vulnerability in Progress Moveit Transfer In Progress MOVEit Transfer versions released before 2022.0.11 (14.0.11), 2022.1.12 (14.1.12), 2023.0.9 (15.0.9), 2023.1.4 (15.1.4), a logging bypass vulnerability has been discovered. An authenticated user could manipulate a request to bypass the logging mechanism within the web application which results in user activity not being logged properly. | 4.3 |
2024-03-20 | CVE-2024-2538 | Permalink Manager Lite Project | Missing Authorization vulnerability in Permalink Manager Lite Project Permalink Manager Lite The Permalink Manager Lite plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'ajax_save_permalink' function in all versions up to, and including, 2.4.3.1. | 4.3 |
2024-03-18 | CVE-2024-27937 | Glpi Project | Unspecified vulnerability in Glpi-Project Glpi GLPI is a Free Asset and IT Management Software package, Data center management, ITIL Service Desk, licenses tracking and software auditing. | 4.3 |
3 Low Vulnerabilities
DATE | CVE | VENDOR | VULNERABILITY | CVSS |
---|---|---|---|---|
2024-03-22 | CVE-2024-1742 | Checkmk | Unspecified vulnerability in Checkmk Invocation of the sqlplus command with sensitive information in the command line in the mk_oracle Checkmk agent plugin before Checkmk 2.3.0b4 (beta), 2.2.0p24, 2.1.0p41 and 2.0.0 (EOL) allows the extraction of this information from the process list. | 3.3 |
2024-03-22 | CVE-2022-32756 | IBM | Unspecified vulnerability in IBM Security Verify Directory 10.0.0 IBM Security Verify Directory 10.0.0 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. | 2.7 |
2024-03-19 | CVE-2024-2616 | Mozilla | Out-of-bounds Write vulnerability in Mozilla Firefox To harden ICU against exploitation, the behavior for out-of-memory conditions was changed to crash instead of attempt to continue. | 2.7 |