Weekly Vulnerabilities Reports > March 25 to 31, 2024
Overview
302 new vulnerabilities reported during this period, including 28 critical vulnerabilities and 125 high severity vulnerabilities. This weekly summary report vulnerabilities in 134 products from 98 vendors including Tenda, Linux, Dell, Synology, and Apple. Vulnerabilities are notably categorized as "Out-of-bounds Write", "Cross-site Scripting", "NULL Pointer Dereference", "Use After Free", and "Memory Leak".
- 253 reported vulnerabilities are remotely exploitables.
- 43 reported vulnerabilities are related to weaknesses in OWASP Top Ten.
- 94 reported vulnerabilities are exploitable by an anonymous user.
- Tenda has the most reported vulnerabilities, with 39 reported vulnerabilities.
- Anisha has the most reported critical vulnerabilities, with 5 reported vulnerabilities.
VULNERABILITIES
VULNERABILITIES
VULNERABILITIES
VULNERABILITIES
VULNERABILITIES
EXPLOITABLE
EXPLOITABLE
AVAILABLE
ANONYMOUSLY
WEB APPLICATION
Vulnerability Details
The following table list reported vulnerabilities for the period covered by this report:
28 Critical Vulnerabilities
DATE | CVE | VENDOR | VULNERABILITY | CVSS |
---|---|---|---|---|
2024-03-29 | CVE-2024-3094 | Tukaani | Unspecified vulnerability in Tukaani XZ 5.6.0/5.6.1 Malicious code was discovered in the upstream tarballs of xz, starting with version 5.6.0. | 10.0 |
2024-03-29 | CVE-2024-30498 | Crmperks | Unspecified vulnerability in Crmperks CRM Perks Forms Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in CRM Perks CRM Perks Forms.This issue affects CRM Perks Forms: from n/a through 1.1.4. | 10.0 |
2024-03-31 | CVE-2023-46808 | Ivanti | Unrestricted Upload of File with Dangerous Type vulnerability in Ivanti Neurons for Itsm An file upload vulnerability in Ivanti ITSM before 2023.4, allows an authenticated remote user to perform file writes to the server. | 9.9 |
2024-03-29 | CVE-2024-29201 | Fit2Cloud | Code Injection vulnerability in Fit2Cloud Jumpserver JumpServer is an open source bastion host and an operation and maintenance security audit system. | 9.9 |
2024-03-29 | CVE-2024-29202 | Fit2Cloud | Code Injection vulnerability in Fit2Cloud Jumpserver JumpServer is an open source bastion host and an operation and maintenance security audit system. | 9.9 |
2024-03-30 | CVE-2024-3087 | Phpgurukul | Unspecified vulnerability in PHPgurukul Emergency Ambulance Hiring Portal 1.0 A vulnerability, which was classified as critical, has been found in PHPGurukul Emergency Ambulance Hiring Portal 1.0. | 9.8 |
2024-03-30 | CVE-2024-3085 | Phpgurukul | Unspecified vulnerability in PHPgurukul Emergency Ambulance Hiring Portal 1.0 A vulnerability classified as critical has been found in PHPGurukul Emergency Ambulance Hiring Portal 1.0. | 9.8 |
2024-03-29 | CVE-2024-23538 | Apache | Unspecified vulnerability in Apache Fineract Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Fineract.This issue affects Apache Fineract: <1.8.5. Users are recommended to upgrade to version 1.8.5 or 1.9.0, which fix the issue. | 9.8 |
2024-03-29 | CVE-2024-23539 | Apache | Unspecified vulnerability in Apache Fineract Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Fineract.This issue affects Apache Fineract: <1.8.5. Users are recommended to upgrade to version 1.8.5 or 1.9.0, which fix the issue. | 9.8 |
2024-03-29 | CVE-2024-30502 | Wptravelengine | Unspecified vulnerability in Wptravelengine WP Travel Engine Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WP Travel Engine.This issue affects WP Travel Engine: from n/a through 5.7.9. | 9.8 |
2024-03-29 | CVE-2024-30508 | Thimpress | Unspecified vulnerability in Thimpress WP Hotel Booking Missing Authorization vulnerability in ThimPress WP Hotel Booking.This issue affects WP Hotel Booking: from n/a through 2.0.9.2. | 9.8 |
2024-03-29 | CVE-2024-30490 | Metagauss | Unspecified vulnerability in Metagauss Profilegrid Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Metagauss ProfileGrid.This issue affects ProfileGrid : from n/a through 5.7.8. | 9.8 |
2024-03-29 | CVE-2024-30510 | Salonbookingsystem | Unspecified vulnerability in Salonbookingsystem Salon Booking System Unrestricted Upload of File with Dangerous Type vulnerability in Salon Booking System Salon booking system.This issue affects Salon booking system: from n/a through 9.5. | 9.8 |
2024-03-28 | CVE-2024-3039 | Shanghai Brad Technology Bladex Project | Unspecified vulnerability in Shanghai Brad Technology Bladex Project Shanghai Brad Technology Bladex 3.4.0 A vulnerability classified as critical has been found in Shanghai Brad Technology BladeX 3.4.0. | 9.8 |
2024-03-28 | CVE-2024-3040 | Netentsec | Unspecified vulnerability in Netentsec Application Security Gateway 6.3 A vulnerability, which was classified as critical, was found in Netentsec NS-ASG Application Security Gateway 6.3. | 9.8 |
2024-03-28 | CVE-2024-3041 | Netentsec | Unspecified vulnerability in Netentsec Application Security Gateway 6.3 A vulnerability has been found in Netentsec NS-ASG Application Security Gateway 6.3 and classified as critical. | 9.8 |
2024-03-27 | CVE-2024-3000 | Anisha | Unspecified vulnerability in Anisha Online Book System 1.0 A vulnerability classified as critical was found in code-projects Online Book System 1.0. | 9.8 |
2024-03-27 | CVE-2024-3001 | Anisha | Unspecified vulnerability in Anisha Online Book System 1.0 A vulnerability, which was classified as critical, has been found in code-projects Online Book System 1.0. | 9.8 |
2024-03-27 | CVE-2024-3002 | Anisha | Unspecified vulnerability in Anisha Online Book System 1.0 A vulnerability, which was classified as critical, was found in code-projects Online Book System 1.0. | 9.8 |
2024-03-27 | CVE-2024-3003 | Anisha | Unspecified vulnerability in Anisha Online Book System 1.0 A vulnerability has been found in code-projects Online Book System 1.0 and classified as critical. | 9.8 |
2024-03-27 | CVE-2023-0582 | Forgerock | Path Traversal vulnerability in Forgerock Access Management 7.2.0 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in ForgeRock Access Management allows Authorization Bypass. This issue affects access management: before 7.3.0, before 7.2.1, before 7.1.4, through 7.0.2. | 9.8 |
2024-03-27 | CVE-2024-2941 | Campcodes | Unspecified vulnerability in Campcodes Online Examination System 1.0 A vulnerability, which was classified as critical, has been found in Campcodes Online Examination System 1.0. | 9.8 |
2024-03-27 | CVE-2024-2934 | Remyandrade | Unspecified vulnerability in Remyandrade Todo List in Kanban Board 1.0 A vulnerability classified as critical was found in SourceCodester Todo List in Kanban Board 1.0. | 9.8 |
2024-03-27 | CVE-2024-2930 | Oretnom23 | Unspecified vulnerability in Oretnom23 Music Gallery Site 1.0 A vulnerability was found in SourceCodester Music Gallery Site 1.0. | 9.8 |
2024-03-26 | CVE-2024-2917 | Campcodes | Unspecified vulnerability in Campcodes House Rental Management System 1.0 A vulnerability was found in Campcodes House Rental Management System 1.0. | 9.8 |
2024-03-26 | CVE-2024-2927 | Anisha | Unspecified vulnerability in Anisha Mobile Shop 1.0 A vulnerability was found in code-projects Mobile Shop 1.0. | 9.8 |
2024-03-26 | CVE-2024-2452 | Eclipse | Integer Overflow or Wraparound vulnerability in Eclipse Threadx Netx DUO In Eclipse ThreadX NetX Duo before 6.4.0, if an attacker can control parameters of __portable_aligned_alloc() could cause an integer wrap-around and an allocation smaller than expected. | 9.8 |
2024-03-28 | CVE-2024-3042 | Oretnom23 | Unspecified vulnerability in Oretnom23 Simple Subscription Website 1.0 A vulnerability was found in SourceCodester Simple Subscription Website 1.0 and classified as critical. | 9.1 |
125 High Vulnerabilities
DATE | CVE | VENDOR | VULNERABILITY | CVSS |
---|---|---|---|---|
2024-03-31 | CVE-2023-41724 | Ivanti | Command Injection vulnerability in Ivanti Standalone Sentry A command injection vulnerability in Ivanti Sentry prior to 9.19.0 allows unauthenticated threat actor to execute arbitrary commands on the underlying operating system of the appliance within the same physical or logical network. | 8.8 |
2024-03-29 | CVE-2024-23537 | Apache | Unspecified vulnerability in Apache Fineract Improper Privilege Management vulnerability in Apache Fineract.This issue affects Apache Fineract: <1.8.5. Users are recommended to upgrade to version 1.9.0, which fixes the issue. | 8.8 |
2024-03-29 | CVE-2024-30491 | Metagauss | Unspecified vulnerability in Metagauss Profilegrid Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Metagauss ProfileGrid.This issue affects ProfileGrid : from n/a through 5.7.8. | 8.8 |
2024-03-29 | CVE-2024-30496 | Bdthemes | Unspecified vulnerability in Bdthemes Element Pack Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in BdThemes Element Pack Elementor Addons.This issue affects Element Pack Elementor Addons: from n/a through 5.5.3. | 8.8 |
2024-03-29 | CVE-2024-30497 | I13Websolution | Unspecified vulnerability in I13Websolution WP Responsive Tabs Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in I Thirteen Web Solution WP Responsive Tabs horizontal vertical and accordion Tabs.This issue affects WP Responsive Tabs horizontal vertical and accordion Tabs: from n/a through 1.1.17. | 8.8 |
2024-03-29 | CVE-2024-30499 | Crmperks | Unspecified vulnerability in Crmperks CRM Perks Forms Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in CRM Perks CRM Perks Forms.This issue affects CRM Perks Forms: from n/a through 1.1.4. | 8.8 |
2024-03-29 | CVE-2024-30500 | Cubewp | Unspecified vulnerability in Cubewp Unrestricted Upload of File with Dangerous Type vulnerability in CubeWP CubeWP – All-in-One Dynamic Content Framework.This issue affects CubeWP – All-in-One Dynamic Content Framework: from n/a through 1.1.12. | 8.8 |
2024-03-29 | CVE-2024-30457 | Pluginus | Unspecified vulnerability in Pluginus Wordpress Meta Data and Taxonomies Filter Cross-Site Request Forgery (CSRF) vulnerability in realmag777 WordPress Meta Data and Taxonomies Filter (MDTF).This issue affects WordPress Meta Data and Taxonomies Filter (MDTF): from n/a through 1.3.3.1. | 8.8 |
2024-03-28 | CVE-2024-25946 | Dell | Command Injection vulnerability in Dell products Dell vApp Manager, versions prior to 9.2.4.9 contain a Command Injection Vulnerability. | 8.8 |
2024-03-28 | CVE-2024-25955 | Dell | Command Injection vulnerability in Dell products Dell vApp Manager, versions prior to 9.2.4.9 contain a Command Injection Vulnerability. | 8.8 |
2024-03-28 | CVE-2023-42913 | Apple | Unspecified vulnerability in Apple Macos This issue was addressed through improved state management. | 8.8 |
2024-03-28 | CVE-2023-42950 | Apple | Unspecified vulnerability in Apple products A use after free issue was addressed with improved memory management. | 8.8 |
2024-03-28 | CVE-2024-29230 | Synology | Unspecified vulnerability in Synology Surveillance Station Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in SnapShot.CountByCategory webapi component in Synology Surveillance Station before 9.2.0-9289 and 9.2.0-11289 allows remote authenticated users to inject SQL commands via unspecified vectors. | 8.8 |
2024-03-28 | CVE-2024-29231 | Synology | Unspecified vulnerability in Synology Surveillance Station Improper validation of array index vulnerability in UserPrivilege.Enum webapi component in Synology Surveillance Station before 9.2.0-9289 and 9.2.0-11289 allows remote authenticated users to bypass security constraints via unspecified vectors. | 8.8 |
2024-03-28 | CVE-2024-29232 | Synology | Unspecified vulnerability in Synology Surveillance Station Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in Alert.Enum webapi component in Synology Surveillance Station before 9.2.0-11289 and 9.2.0-9289 allows remote authenticated users to inject SQL commands via unspecified vectors. | 8.8 |
2024-03-28 | CVE-2024-29233 | Synology | Unspecified vulnerability in Synology Surveillance Station Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in Emap.Delete webapi component in Synology Surveillance Station before 9.2.0-9289 and 9.2.0-11289 allows remote authenticated users to inject SQL commands via unspecified vectors. | 8.8 |
2024-03-28 | CVE-2024-29234 | Synology | Unspecified vulnerability in Synology Surveillance Station Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in Group.Save webapi component in Synology Surveillance Station before 9.2.0-11289 and 9.2.0-9289 allows remote authenticated users to inject SQL commands via unspecified vectors. | 8.8 |
2024-03-28 | CVE-2024-29235 | Synology | Unspecified vulnerability in Synology Surveillance Station Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in IOModule.EnumLog webapi component in Synology Surveillance Station before 9.2.0-11289 and 9.2.0-9289 allows remote authenticated users to inject SQL commands via unspecified vectors. | 8.8 |
2024-03-28 | CVE-2024-29236 | Synology | Unspecified vulnerability in Synology Surveillance Station Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in AudioPattern.Delete webapi component in Synology Surveillance Station before 9.2.0-9289 and 9.2.0-11289 allows remote authenticated users to inject SQL commands via unspecified vectors. | 8.8 |
2024-03-28 | CVE-2024-29237 | Synology | Unspecified vulnerability in Synology Surveillance Station Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in ActionRule.Delete webapi component in Synology Surveillance Station before 9.2.0-11289 and 9.2.0-9289 allows remote authenticated users to inject SQL commands via unspecified vectors. | 8.8 |
2024-03-28 | CVE-2024-29238 | Synology | Unspecified vulnerability in Synology Surveillance Station Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in Log.CountByCategory webapi component in Synology Surveillance Station before 9.2.0-9289 and 9.2.0-11289 allows remote authenticated users to inject SQL commands via unspecified vectors. | 8.8 |
2024-03-28 | CVE-2024-29239 | Synology | Unspecified vulnerability in Synology Surveillance Station Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in Recording.CountByCategory webapi component in Synology Surveillance Station before 9.2.0-11289 and 9.2.0-9289 allows remote authenticated users to inject SQL commands via unspecified vectors. | 8.8 |
2024-03-28 | CVE-2024-29241 | Synology | Unspecified vulnerability in Synology Surveillance Station Missing authorization vulnerability in System webapi component in Synology Surveillance Station before 9.2.0-9289 and 9.2.0-11289 allows remote authenticated users to bypass security constraints via unspecified vectors. | 8.8 |
2024-03-28 | CVE-2024-29227 | Synology | Unspecified vulnerability in Synology Surveillance Station Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in Layout.LayoutSave webapi component in Synology Surveillance Station before 9.2.0-9289 and 9.2.0-11289 allows remote authenticated users to inject SQL commands via unspecified vectors. | 8.8 |
2024-03-28 | CVE-2024-30241 | Metagauss | Unspecified vulnerability in Metagauss Profilegrid Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Metagauss ProfileGrid.This issue affects ProfileGrid : from n/a through 5.7.1. | 8.8 |
2024-03-28 | CVE-2024-3015 | Oretnom23 | Unspecified vulnerability in Oretnom23 Simple Subscription Website 1.0 A vulnerability classified as critical was found in SourceCodester Simple Subscription Website 1.0. | 8.8 |
2024-03-28 | CVE-2024-3014 | Oretnom23 | Unspecified vulnerability in Oretnom23 Simple Subscription Website 1.0 A vulnerability classified as critical has been found in SourceCodester Simple Subscription Website 1.0. | 8.8 |
2024-03-28 | CVE-2024-3009 | Tenda | Unspecified vulnerability in Tenda Fh1205 Firmware 2.0.0.7(775) A vulnerability has been found in Tenda FH1205 2.0.0.7(775) and classified as critical. | 8.8 |
2024-03-28 | CVE-2024-3010 | Tenda | Out-of-bounds Write vulnerability in Tenda Fh1205 Firmware 2.0.0.7(775) A vulnerability was found in Tenda FH1205 2.0.0.7(775) and classified as critical. | 8.8 |
2024-03-28 | CVE-2024-3011 | Tenda | Out-of-bounds Write vulnerability in Tenda Fh1205 Firmware 2.0.0.7(775) A vulnerability was found in Tenda FH1205 2.0.0.7(775). | 8.8 |
2024-03-28 | CVE-2024-3012 | Tenda | Out-of-bounds Write vulnerability in Tenda Fh1205 Firmware 2.0.0.7(775) A vulnerability was found in Tenda FH1205 2.0.0.7(775). | 8.8 |
2024-03-27 | CVE-2024-3006 | Tenda | Out-of-bounds Write vulnerability in Tenda Fh1205 Firmware 2.0.0.7(775) A vulnerability classified as critical was found in Tenda FH1205 2.0.0.7(775). | 8.8 |
2024-03-27 | CVE-2024-3007 | Tenda | Out-of-bounds Write vulnerability in Tenda Fh1205 Firmware 2.0.0.7(775) A vulnerability, which was classified as critical, has been found in Tenda FH1205 2.0.0.7(775). | 8.8 |
2024-03-27 | CVE-2024-3008 | Tenda | Out-of-bounds Write vulnerability in Tenda Fh1205 Firmware 2.0.0.7(775) A vulnerability, which was classified as critical, was found in Tenda FH1205 2.0.0.7(775). | 8.8 |
2024-03-27 | CVE-2024-2993 | Tenda | Out-of-bounds Write vulnerability in Tenda Fh1203 Firmware 2.0.1.6 A vulnerability was found in Tenda FH1203 2.0.1.6. | 8.8 |
2024-03-27 | CVE-2024-2994 | Tenda | Out-of-bounds Write vulnerability in Tenda Fh1203 Firmware 2.0.1.6 A vulnerability was found in Tenda FH1203 2.0.1.6. | 8.8 |
2024-03-27 | CVE-2024-2990 | Tenda | Out-of-bounds Write vulnerability in Tenda Fh1203 Firmware 2.0.1.6 A vulnerability, which was classified as critical, was found in Tenda FH1203 2.0.1.6. | 8.8 |
2024-03-27 | CVE-2024-2991 | Tenda | Unspecified vulnerability in Tenda Fh1203 Firmware 2.0.1.6 A vulnerability has been found in Tenda FH1203 2.0.1.6 and classified as critical. | 8.8 |
2024-03-27 | CVE-2024-2992 | Tenda | Out-of-bounds Write vulnerability in Tenda Fh1203 Firmware 2.0.1.6 A vulnerability was found in Tenda FH1203 2.0.1.6 and classified as critical. | 8.8 |
2024-03-27 | CVE-2024-2988 | Tenda | Out-of-bounds Write vulnerability in Tenda Fh1203 Firmware 2.0.1.6 A vulnerability classified as critical was found in Tenda FH1203 2.0.1.6. | 8.8 |
2024-03-27 | CVE-2024-2989 | Tenda | Out-of-bounds Write vulnerability in Tenda Fh1203 Firmware 2.0.1.6 A vulnerability, which was classified as critical, has been found in Tenda FH1203 2.0.1.6. | 8.8 |
2024-03-27 | CVE-2024-2985 | Tenda | Out-of-bounds Write vulnerability in Tenda Fh1202 Firmware 1.2.0.14(408) A vulnerability was found in Tenda FH1202 1.2.0.14(408). | 8.8 |
2024-03-27 | CVE-2024-2986 | Tenda | Out-of-bounds Write vulnerability in Tenda Fh1202 Firmware 1.2.0.14(408) A vulnerability was found in Tenda FH1202 1.2.0.14(408). | 8.8 |
2024-03-27 | CVE-2024-2987 | Tenda | Out-of-bounds Write vulnerability in Tenda Fh1202 Firmware 1.2.0.14(408) A vulnerability classified as critical has been found in Tenda FH1202 1.2.0.14(408). | 8.8 |
2024-03-27 | CVE-2024-2982 | Tenda | Unspecified vulnerability in Tenda Fh1202 Firmware 1.2.0.14(408) A vulnerability has been found in Tenda FH1202 1.2.0.14(408) and classified as critical. | 8.8 |
2024-03-27 | CVE-2024-2983 | Tenda | Out-of-bounds Write vulnerability in Tenda Fh1202 Firmware 1.2.0.14(408) A vulnerability was found in Tenda FH1202 1.2.0.14(408) and classified as critical. | 8.8 |
2024-03-27 | CVE-2024-2984 | Tenda | Out-of-bounds Write vulnerability in Tenda Fh1202 Firmware 1.2.0.14(408) A vulnerability was found in Tenda FH1202 1.2.0.14(408). | 8.8 |
2024-03-27 | CVE-2024-2980 | Tenda | Out-of-bounds Write vulnerability in Tenda Fh1202 Firmware 1.2.0.14(408) A vulnerability, which was classified as critical, has been found in Tenda FH1202 1.2.0.14(408). | 8.8 |
2024-03-27 | CVE-2024-2981 | Tenda | Out-of-bounds Write vulnerability in Tenda Fh1202 Firmware 1.2.0.14(408) A vulnerability, which was classified as critical, was found in Tenda FH1202 1.2.0.14(408). | 8.8 |
2024-03-27 | CVE-2023-44999 | Woocommerce | Unspecified vulnerability in Woocommerce Stripe Payment Gateway Cross-Site Request Forgery (CSRF) vulnerability in WooCommerce WooCommerce Stripe Payment Gateway.This issue affects WooCommerce Stripe Payment Gateway: from n/a through 7.6.0. | 8.8 |
2024-03-27 | CVE-2024-2976 | Tenda | Out-of-bounds Write vulnerability in Tenda F1203 Firmware 2.0.1.6 A vulnerability was found in Tenda F1203 2.0.1.6. | 8.8 |
2024-03-27 | CVE-2024-2977 | Tenda | Out-of-bounds Write vulnerability in Tenda F1203 Firmware 2.0.1.6 A vulnerability was found in Tenda F1203 2.0.1.6. | 8.8 |
2024-03-27 | CVE-2024-2978 | Tenda | Out-of-bounds Write vulnerability in Tenda F1203 Firmware 2.0.1.6 A vulnerability classified as critical has been found in Tenda F1203 2.0.1.6. | 8.8 |
2024-03-27 | CVE-2024-2979 | Tenda | Out-of-bounds Write vulnerability in Tenda F1203 Firmware 2.0.1.6 A vulnerability classified as critical was found in Tenda F1203 2.0.1.6. | 8.8 |
2024-03-27 | CVE-2024-2203 | Posimyth | Unspecified vulnerability in Posimyth the Plus Addons for Elementor The The Plus Addons for Elementor plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 5.4.1 via the Clients widget. | 8.8 |
2024-03-26 | CVE-2023-39307 | Theme Fusion | Unspecified vulnerability in Theme-Fusion Avada Unrestricted Upload of File with Dangerous Type vulnerability in ThemeFusion Avada.This issue affects Avada: from n/a through 7.11.1. | 8.8 |
2024-03-26 | CVE-2023-48777 | Elementor | Unspecified vulnerability in Elementor Website Builder Unrestricted Upload of File with Dangerous Type vulnerability in Elementor.Com Elementor Website Builder.This issue affects Elementor Website Builder: from 3.3.0 through 3.18.1. | 8.8 |
2024-03-26 | CVE-2024-2883 | Google Fedoraproject | Use After Free vulnerability in multiple products Use after free in ANGLE in Google Chrome prior to 123.0.6312.86 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | 8.8 |
2024-03-26 | CVE-2024-2885 | Google Fedoraproject | Use After Free vulnerability in multiple products Use after free in Dawn in Google Chrome prior to 123.0.6312.86 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | 8.8 |
2024-03-26 | CVE-2024-2903 | Tenda | Out-of-bounds Write vulnerability in Tenda AC7 Firmware 15.03.06.44 A vulnerability was found in Tenda AC7 15.03.06.44. | 8.8 |
2024-03-26 | CVE-2024-2900 | Tenda | Out-of-bounds Write vulnerability in Tenda AC7 Firmware 15.03.06.44 A vulnerability, which was classified as critical, was found in Tenda AC7 15.03.06.44. | 8.8 |
2024-03-26 | CVE-2024-2901 | Tenda | Out-of-bounds Write vulnerability in Tenda AC7 Firmware 15.03.06.44 A vulnerability has been found in Tenda AC7 15.03.06.44 and classified as critical. | 8.8 |
2024-03-26 | CVE-2024-2902 | Tenda | Out-of-bounds Write vulnerability in Tenda AC7 Firmware 15.03.06.44 A vulnerability was found in Tenda AC7 15.03.06.44 and classified as critical. | 8.8 |
2024-03-26 | CVE-2024-2897 | Tenda | Unspecified vulnerability in Tenda AC7 Firmware 15.03.06.44 A vulnerability classified as critical has been found in Tenda AC7 15.03.06.44. | 8.8 |
2024-03-26 | CVE-2024-2898 | Tenda | Out-of-bounds Write vulnerability in Tenda AC7 Firmware 15.03.06.44 A vulnerability classified as critical was found in Tenda AC7 15.03.06.44. | 8.8 |
2024-03-26 | CVE-2024-2899 | Tenda | Out-of-bounds Write vulnerability in Tenda AC7 Firmware 15.03.06.44 A vulnerability, which was classified as critical, has been found in Tenda AC7 15.03.06.44. | 8.8 |
2024-03-26 | CVE-2024-2895 | Tenda | Out-of-bounds Write vulnerability in Tenda AC7 Firmware 15.03.06.44 A vulnerability was found in Tenda AC7 15.03.06.44. | 8.8 |
2024-03-26 | CVE-2024-2896 | Tenda | Out-of-bounds Write vulnerability in Tenda AC7 Firmware 15.03.06.44 A vulnerability was found in Tenda AC7 15.03.06.44. | 8.8 |
2024-03-26 | CVE-2024-2893 | Tenda | Out-of-bounds Write vulnerability in Tenda AC7 Firmware 15.03.06.44 A vulnerability was found in Tenda AC7 15.03.06.44 and classified as critical. | 8.8 |
2024-03-26 | CVE-2024-2894 | Tenda | Out-of-bounds Write vulnerability in Tenda AC7 Firmware 15.03.06.44 A vulnerability was found in Tenda AC7 15.03.06.44. | 8.8 |
2024-03-26 | CVE-2024-2892 | Tenda | Out-of-bounds Write vulnerability in Tenda AC7 Firmware 15.03.06.44 A vulnerability has been found in Tenda AC7 15.03.06.44 and classified as critical. | 8.8 |
2024-03-26 | CVE-2024-2891 | Tenda | Out-of-bounds Write vulnerability in Tenda AC7 Firmware 15.03.06.44 A vulnerability, which was classified as critical, was found in Tenda AC7 15.03.06.44. | 8.8 |
2024-03-26 | CVE-2023-52214 | Voidcoders | Unspecified vulnerability in Voidcoders Void Contact Form 7 Widget for Elementor Page Builder Missing Authorization vulnerability in voidCoders Void Contact Form 7 Widget For Elementor Page Builder.This issue affects Void Contact Form 7 Widget For Elementor Page Builder: from n/a through 2.3. | 8.8 |
2024-03-26 | CVE-2024-30235 | Themeisle | Unspecified vulnerability in Themeisle multiple Page Generator Missing Authorization vulnerability in Themeisle Multiple Page Generator Plugin – MPG.This issue affects Multiple Page Generator Plugin – MPG: from n/a through 3.4.0. | 8.8 |
2024-03-26 | CVE-2024-24799 | Woocommerce | Unspecified vulnerability in Woocommerce BOX Office Missing Authorization vulnerability in WooCommerce WooCommerce Box Office.This issue affects WooCommerce Box Office: from n/a through 1.2.2. | 8.8 |
2024-03-25 | CVE-2024-27299 | Phpmyfaq | SQL Injection vulnerability in PHPmyfaq 3.2.5 phpMyFAQ is an open source FAQ web application for PHP 8.1+ and MySQL, PostgreSQL and other databases. | 8.8 |
2024-03-25 | CVE-2024-28107 | Phpmyfaq | SQL Injection vulnerability in PHPmyfaq 3.2.5 phpMyFAQ is an open source FAQ web application for PHP 8.1+ and MySQL, PostgreSQL and other databases. | 8.8 |
2024-03-25 | CVE-2022-45356 | Muffingroup | Unspecified vulnerability in Muffingroup Betheme Missing Authorization vulnerability in Muffingroup Betheme.This issue affects Betheme: from n/a through 26.6.1. | 8.8 |
2024-03-27 | CVE-2024-29891 | Zitadel | Cross-site Scripting vulnerability in Zitadel ZITADEL users can upload their own avatar image and various image types are allowed. | 8.7 |
2024-03-28 | CVE-2023-42947 | Apple | Unspecified vulnerability in Apple products A path handling issue was addressed with improved validation. | 8.6 |
2024-03-28 | CVE-2024-31139 | Jetbrains | XXE vulnerability in Jetbrains Teamcity In JetBrains TeamCity before 2024.03 xXE was possible in the Maven build steps detector | 8.1 |
2024-03-27 | CVE-2024-29946 | Splunk | Command Injection vulnerability in Splunk In Splunk Enterprise versions below 9.2.1, 9.1.4, and 9.0.9, the Dashboard Examples Hub lacks protections for risky SPL commands. | 8.1 |
2024-03-28 | CVE-2024-25960 | Dell | Unspecified vulnerability in Dell Powerscale Onefs Dell PowerScale OneFS versions 8.2.2.x through 9.7.0.x contains a cleartext transmission of sensitive information vulnerability. | 7.8 |
2024-03-28 | CVE-2023-42892 | Apple | Unspecified vulnerability in Apple Macos A use-after-free issue was addressed with improved memory management. | 7.8 |
2024-03-28 | CVE-2023-42931 | Apple | Unspecified vulnerability in Apple Macos The issue was addressed with improved checks. | 7.8 |
2024-03-26 | CVE-2024-21912 | Rockwellautomation | Out-of-bounds Write vulnerability in Rockwellautomation Arena An arbitrary code execution vulnerability in Rockwell Automation Arena Simulation could let a malicious user insert unauthorized code into the software. | 7.8 |
2024-03-26 | CVE-2024-21913 | Rockwellautomation | Out-of-bounds Write vulnerability in Rockwellautomation Arena A heap-based memory buffer overflow vulnerability in Rockwell Automation Arena Simulation software could potentially allow a malicious user to insert unauthorized code into the software by overstepping the memory boundaries, which triggers an access violation. | 7.8 |
2024-03-26 | CVE-2024-21918 | Rockwellautomation | Use After Free vulnerability in Rockwellautomation Arena A memory buffer vulnerability in Rockwell Automation Arena Simulation software could potentially allow a malicious user to insert unauthorized code to the software by corrupting the memory and triggering an access violation. | 7.8 |
2024-03-26 | CVE-2024-21919 | Rockwellautomation | Access of Uninitialized Pointer vulnerability in Rockwellautomation Arena An uninitialized pointer in Rockwell Automation Arena Simulation software could potentially allow a malicious user to insert unauthorized code to the software by leveraging the pointer after it is properly. | 7.8 |
2024-03-26 | CVE-2024-25958 | Dell | Unspecified vulnerability in Dell Grab Dell Grab for Windows, versions up to and including 5.0.4, contain Weak Application Folder Permissions vulnerability. | 7.8 |
2024-03-26 | CVE-2024-2212 | Eclipse | Integer Overflow or Wraparound vulnerability in Eclipse Threadx In Eclipse ThreadX before 6.4.0, xQueueCreate() and xQueueCreateSet() functions from the FreeRTOS compatibility API (utility/rtos_compatibility_layers/FreeRTOS/tx_freertos.c) were missing parameter checks. | 7.8 |
2024-03-26 | CVE-2024-2214 | Eclipse | Improper Validation of Array Index vulnerability in Eclipse Threadx In Eclipse ThreadX before version 6.4.0, the _Mtxinit() function in the Xtensa port was missing an array size check causing a memory overwrite. | 7.8 |
2024-03-26 | CVE-2024-2929 | Rockwellautomation | Out-of-bounds Write vulnerability in Rockwellautomation Arena A memory corruption vulnerability in Rockwell Automation Arena Simulation software could potentially allow a malicious user to insert unauthorized code to the software by corrupting the memory triggering an access violation. | 7.8 |
2024-03-25 | CVE-2021-47148 | Linux | Out-of-bounds Write vulnerability in Linux Kernel In the Linux kernel, the following vulnerability has been resolved: octeontx2-pf: fix a buffer overflow in otx2_set_rxfh_context() This function is called from ethtool_set_rxfh() and "*rss_context" comes from the user. | 7.8 |
2024-03-28 | CVE-2024-29228 | Synology | Unspecified vulnerability in Synology Surveillance Station Missing authorization vulnerability in GetStmUrlPath webapi component in Synology Surveillance Station before 9.2.0-9289 and 9.2.0-11289 allows remote authenticated users to obtain sensitive information via unspecified vectors. | 7.7 |
2024-03-28 | CVE-2024-29229 | Synology | Unspecified vulnerability in Synology Surveillance Station Missing authorization vulnerability in GetLiveViewPath webapi component in Synology Surveillance Station before 9.2.0-9289 and 9.2.0-11289 allows remote authenticated users to obtain sensitive information via unspecified vectors. | 7.7 |
2024-03-28 | CVE-2023-39313 | Theme Fusion | Unspecified vulnerability in Theme-Fusion Avada Server-Side Request Forgery (SSRF) vulnerability in ThemeFusion Avada.This issue affects Avada: from n/a through 7.11.1. | 7.7 |
2024-03-26 | CVE-2024-2887 | Google Fedoraproject | Type Confusion vulnerability in multiple products Type Confusion in WebAssembly in Google Chrome prior to 123.0.6312.86 allowed a remote attacker to execute arbitrary code via a crafted HTML page. | 7.7 |
2024-03-29 | CVE-2024-30487 | Sonaar | Unspecified vulnerability in Sonaar MP3 Audio Player for Music, Radio & Podcast Missing Authorization vulnerability in Sonaar Music MP3 Audio Player for Music, Radio & Podcast by Sonaar.This issue affects MP3 Audio Player for Music, Radio & Podcast by Sonaar: from n/a through 5.1. | 7.6 |
2024-03-31 | CVE-2024-22353 | IBM | Unspecified vulnerability in IBM Websphere Application Server IBM WebSphere Application Server Liberty 17.0.0.3 through 24.0.0.4 is vulnerable to a denial of service, caused by sending a specially crafted request. | 7.5 |
2024-03-29 | CVE-2024-25944 | Dell | Path Traversal vulnerability in Dell Openmanage Enterprise Dell OpenManage Enterprise, v4.0 and prior, contain(s) a path traversal vulnerability. | 7.5 |
2024-03-28 | CVE-2024-25954 | Dell | Unspecified vulnerability in Dell Powerscale Onefs Dell PowerScale OneFS, versions 9.5.0.x through 9.7.0.x, contain an insufficient session expiration vulnerability. | 7.5 |
2024-03-28 | CVE-2024-25963 | Dell | Unspecified vulnerability in Dell Powerscale Onefs Dell PowerScale OneFS, versions 8.2.2.x through 9.5.0.x contains a use of a broken cryptographic algorithm vulnerability. | 7.5 |
2024-03-28 | CVE-2023-42962 | Apple | Unspecified vulnerability in Apple Ipados This issue was addressed with improved checks This issue is fixed in iOS 17.2 and iPadOS 17.2, iOS 16.7.3 and iPadOS 16.7.3. | 7.5 |
2024-03-27 | CVE-2024-2999 | Campcodes | Unspecified vulnerability in Campcodes Online ART Gallery Management System 1.0 A vulnerability classified as critical has been found in Campcodes Online Art Gallery Management System 1.0. | 7.5 |
2024-03-27 | CVE-2024-23450 | Elastic | Unspecified vulnerability in Elastic Elasticsearch A flaw was discovered in Elasticsearch, where processing a document in a deeply nested pipeline on an ingest node could cause the Elasticsearch node to crash. | 7.5 |
2024-03-27 | CVE-2024-2932 | Donbermoy | Unspecified vulnerability in Donbermoy Online Chatting System 1.0 A vulnerability classified as critical has been found in SourceCodester Online Chatting System 1.0. | 7.5 |
2024-03-26 | CVE-2024-2886 | Google Fedoraproject | Use After Free vulnerability in multiple products Use after free in WebCodecs in Google Chrome prior to 123.0.6312.86 allowed a remote attacker to perform arbitrary read/write via a crafted HTML page. | 7.5 |
2024-03-25 | CVE-2024-2425 | Rockwellautomation | Unspecified vulnerability in Rockwellautomation Powerflex 527 AC Drives Firmware A denial-of-service vulnerability exists in the Rockwell Automation PowerFlex® 527 due to improper input validation in the device. | 7.5 |
2024-03-25 | CVE-2024-2426 | Rockwellautomation | Unspecified vulnerability in Rockwellautomation Powerflex 527 AC Drives Firmware A denial-of-service vulnerability exists in the Rockwell Automation PowerFlex® 527 due to improper input validation in the device. | 7.5 |
2024-03-25 | CVE-2024-2427 | Rockwellautomation | Unspecified vulnerability in Rockwellautomation Powerflex 527 AC Drives Firmware A denial-of-service vulnerability exists in the Rockwell Automation PowerFlex® 527 due to improper traffic throttling in the device. | 7.5 |
2024-03-25 | CVE-2024-25964 | Dell | Unspecified vulnerability in Dell Powerscale Onefs Dell PowerScale OneFS 9.5.0.x through 9.7.0.x contain a covert timing channel vulnerability. | 7.5 |
2024-03-28 | CVE-2024-31136 | Jetbrains | Unspecified vulnerability in Jetbrains Teamcity In JetBrains TeamCity before 2024.03 2FA could be bypassed by providing a special URL parameter | 7.4 |
2024-03-31 | CVE-2024-31116 | 10Web | Unspecified vulnerability in 10Web MAP Builder for Google Maps Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in 10Web 10Web Map Builder for Google Maps.This issue affects 10Web Map Builder for Google Maps: from n/a through 1.0.74. | 7.2 |
2024-03-29 | CVE-2024-30504 | Wptravelengine | Unspecified vulnerability in Wptravelengine WP Travel Engine Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WP Travel Engine.This issue affects WP Travel Engine: from n/a through 5.7.9. | 7.2 |
2024-03-29 | CVE-2024-30478 | Rocksolidplugins | Unspecified vulnerability in Rocksolidplugins Bulletin Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Bulletin WordPress Announcement & Notification Banner Plugin – Bulletin.This issue affects WordPress Announcement & Notification Banner Plugin – Bulletin: from n/a through 3.8.5. | 7.2 |
2024-03-29 | CVE-2024-30495 | Faboba | Unspecified vulnerability in Faboba Falang Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Faboba Falang multilanguage.This issue affects Falang multilanguage: from n/a through 1.3.47. | 7.2 |
2024-03-29 | CVE-2024-30501 | Wpchill | Unspecified vulnerability in Wpchill Download Monitor Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WPChill Download Monitor.This issue affects Download Monitor: from n/a through 4.9.4. | 7.2 |
2024-03-28 | CVE-2023-45705 | Hcltech | Server-Side Request Forgery (SSRF) vulnerability in Hcltech Bigfix Platform An administrative user of WebReports may perform a Server Side Request Forgery (SSRF) exploit through SMTP configuration options. | 7.2 |
2024-03-28 | CVE-2024-30229 | Givewp | Unspecified vulnerability in Givewp Deserialization of Untrusted Data vulnerability in GiveWP.This issue affects GiveWP: from n/a through 3.4.2. | 7.2 |
2024-03-27 | CVE-2024-29945 | Splunk | Information Exposure Through Log Files vulnerability in Splunk In Splunk Enterprise versions below 9.2.1, 9.1.4, and 9.0.9, the software potentially exposes authentication tokens during the token validation process. | 7.2 |
2024-03-26 | CVE-2024-30231 | Webtoffee | Unspecified vulnerability in Webtoffee Product Import Export for Woocommerce Unrestricted Upload of File with Dangerous Type vulnerability in WebToffee Product Import Export for WooCommerce.This issue affects Product Import Export for WooCommerce: from n/a through 2.4.1. | 7.2 |
2024-03-25 | CVE-2024-28105 | Phpmyfaq | Unrestricted Upload of File with Dangerous Type vulnerability in PHPmyfaq 3.2.5 phpMyFAQ is an open source FAQ web application for PHP 8.1+ and MySQL, PostgreSQL and other databases. | 7.2 |
2024-03-26 | CVE-2024-21920 | Rockwellautomation | Out-of-bounds Read vulnerability in Rockwellautomation Arena A memory buffer vulnerability in Rockwell Automation Arena Simulation could potentially let a threat actor read beyond the intended memory boundaries. | 7.1 |
2024-03-28 | CVE-2023-42974 | Apple | Race Condition vulnerability in Apple products A race condition was addressed with improved state handling. | 7.0 |
148 Medium Vulnerabilities
DATE | CVE | VENDOR | VULNERABILITY | CVSS |
---|---|---|---|---|
2024-03-28 | CVE-2024-25961 | Dell | Unspecified vulnerability in Dell Powerscale Onefs Dell PowerScale OneFS versions 8.2.2.x through 9.7.0.x contains an improper privilege management vulnerability. | 6.7 |
2024-03-31 | CVE-2023-50959 | IBM | Unspecified vulnerability in IBM Cloud PAK for Business Automation IBM Cloud Pak for Business Automation 18.0.0, 18.0.1, 18.0.2,19.0.1, 19.0.2, 19.0.3,20.0.1, 20.0.2, 20.0.3, 21.0.1, 21.0.2, 21.0.3, 22.0.1,2 2.0.2, 23.0.1, and 23.0.2 may allow end users to query more documents than expected from a connected Enterprise Content Management system when configured to use a system account. | 6.5 |
2024-03-29 | CVE-2024-30513 | Metagauss | Unspecified vulnerability in Metagauss Profilegrid Authorization Bypass Through User-Controlled Key vulnerability in Metagauss ProfileGrid.This issue affects ProfileGrid : from n/a through 5.7.2. | 6.5 |
2024-03-29 | CVE-2024-29893 | Argoproj | Unspecified vulnerability in Argoproj Argo CD Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. | 6.5 |
2024-03-29 | CVE-2024-3077 | Zephyrproject | Integer Underflow (Wrap or Wraparound) vulnerability in Zephyrproject Zephyr An malicious BLE device can crash BLE victim device by sending malformed gatt packet | 6.5 |
2024-03-28 | CVE-2024-25971 | Dell | Unspecified vulnerability in Dell Powerprotect Data Manager Dell PowerProtect Data Manager, version 19.15, contains an XML External Entity Injection vulnerability. | 6.5 |
2024-03-28 | CVE-2023-42956 | Apple | Unspecified vulnerability in Apple products The issue was addressed with improved memory handling. | 6.5 |
2024-03-28 | CVE-2024-31134 | Jetbrains | Incorrect Authorization vulnerability in Jetbrains Teamcity In JetBrains TeamCity before 2024.03 authenticated users without administrative permissions could register other users when self-registration was disabled | 6.5 |
2024-03-28 | CVE-2024-2818 | Gitlab | Allocation of Resources Without Limits or Throttling vulnerability in Gitlab An issue has been discovered in GitLab CE/EE affecting all versions before 16.8.5, all versions starting from 16.9 before 16.9.3, all versions starting from 16.10 before 16.10.1. | 6.5 |
2024-03-28 | CVE-2024-29240 | Synology | Unspecified vulnerability in Synology Surveillance Station Missing authorization vulnerability in LayoutSave webapi component in Synology Surveillance Station before 9.2.0-11289 and 9.2.0-9289 allows remote authenticated users to conduct denial-of-service attacks via unspecified vectors. | 6.5 |
2024-03-28 | CVE-2023-52231 | Booster | Unspecified vulnerability in Booster for Woocommerce 5.6.5/5.6.6 Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Booster Booster Plus for WooCommerce.This issue affects Booster Plus for WooCommerce: from n/a before 7.1.2. | 6.5 |
2024-03-28 | CVE-2023-52234 | Booster | Unspecified vulnerability in Booster for Woocommerce Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Booster Booster Elite for WooCommerce.This issue affects Booster Elite for WooCommerce: from n/a before 7.1.2. | 6.5 |
2024-03-28 | CVE-2023-36679 | Brainstormforce | Unspecified vulnerability in Brainstormforce Spectra Server-Side Request Forgery (SSRF) vulnerability in Brainstorm Force Spectra.This issue affects Spectra: from n/a through 2.6.6. | 6.5 |
2024-03-28 | CVE-2024-23500 | Kadencewp | Unspecified vulnerability in Kadencewp Gutenberg Blocks With AI Server-Side Request Forgery (SSRF) vulnerability in Kadence WP Gutenberg Blocks by Kadence Blocks.This issue affects Gutenberg Blocks by Kadence Blocks: from n/a through 3.2.19. | 6.5 |
2024-03-27 | CVE-2024-23451 | Elastic | Incorrect Authorization vulnerability in Elastic Elasticsearch Incorrect Authorization issue exists in the API key based security model for Remote Cluster Security, which is currently in Beta, in Elasticsearch 8.10.0 and before 8.13.0. | 6.5 |
2024-03-27 | CVE-2024-25962 | Dell | Unspecified vulnerability in Dell Insightiq 5.0.0 Dell InsightIQ, version 5.0, contains an improper access control vulnerability. | 6.5 |
2024-03-27 | CVE-2024-2942 | Campcodes | Unspecified vulnerability in Campcodes Online Examination System 1.0 A vulnerability, which was classified as critical, was found in Campcodes Online Examination System 1.0. | 6.5 |
2024-03-27 | CVE-2024-2943 | Campcodes | Unspecified vulnerability in Campcodes Online Examination System 1.0 A vulnerability has been found in Campcodes Online Examination System 1.0 and classified as critical. | 6.5 |
2024-03-27 | CVE-2024-2944 | Campcodes | Unspecified vulnerability in Campcodes Online Examination System 1.0 A vulnerability was found in Campcodes Online Examination System 1.0 and classified as critical. | 6.5 |
2024-03-27 | CVE-2024-2945 | Campcodes | Unspecified vulnerability in Campcodes Online Examination System 1.0 A vulnerability was found in Campcodes Online Examination System 1.0. | 6.5 |
2024-03-27 | CVE-2024-2938 | Campcodes | Unspecified vulnerability in Campcodes Online Examination System 1.0 A vulnerability was found in Campcodes Online Examination System 1.0. | 6.5 |
2024-03-26 | CVE-2024-2916 | Campcodes | Unspecified vulnerability in Campcodes House Rental Management System 1.0 A vulnerability was found in Campcodes House Rental Management System 1.0. | 6.5 |
2024-03-26 | CVE-2024-24718 | WP Property Hive | Unspecified vulnerability in Wp-Property-Hive Propertyhive Missing Authorization vulnerability in PropertyHive.This issue affects PropertyHive: from n/a through 2.0.6. | 6.5 |
2024-03-30 | CVE-2024-3086 | Phpgurukul | Unspecified vulnerability in PHPgurukul Emergency Ambulance Hiring Portal 1.0 A vulnerability classified as problematic was found in PHPGurukul Emergency Ambulance Hiring Portal 1.0. | 6.1 |
2024-03-30 | CVE-2024-3084 | Phpgurukul | Unspecified vulnerability in PHPgurukul Emergency Ambulance Hiring Portal 1.0 A vulnerability was found in PHPGurukul Emergency Ambulance Hiring Portal 1.0. | 6.1 |
2024-03-29 | CVE-2024-30427 | Spiffyplugins | Unspecified vulnerability in Spiffyplugins Spiffy Calendar Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Spiffy Plugins Spiffy Calendar allows Reflected XSS.This issue affects Spiffy Calendar: from n/a through 4.9.7. | 6.1 |
2024-03-29 | CVE-2024-30428 | Contest Gallery | Unspecified vulnerability in Contest-Gallery Contest Gallery Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Contest Gallery allows Reflected XSS.This issue affects Contest Gallery: from n/a through 21.3.5. | 6.1 |
2024-03-29 | CVE-2024-0609 | Wedevs | Cross-site Scripting vulnerability in Wedevs WP ERP The WP ERP | Complete HR solution with recruitment & job listings | WooCommerce CRM & Accounting plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'api_key' parameter in all versions up to, and including, 1.12.9 due to insufficient input sanitization and output escaping. | 6.1 |
2024-03-28 | CVE-2023-33528 | Halo | Cross-site Scripting vulnerability in Halo 1.6.0 halo v1.6.0 is vulnerable to Cross Site Scripting (XSS). | 6.1 |
2024-03-28 | CVE-2024-31135 | Jetbrains | Open Redirect vulnerability in Jetbrains Teamcity In JetBrains TeamCity before 2024.03 open redirect was possible on the login page | 6.1 |
2024-03-28 | CVE-2024-31137 | Jetbrains | Cross-site Scripting vulnerability in Jetbrains Teamcity In JetBrains TeamCity before 2024.03 reflected XSS was possible via Space connection configuration | 6.1 |
2024-03-27 | CVE-2024-3004 | Anisha | Unspecified vulnerability in Anisha Online Book System 1.0 A vulnerability was found in code-projects Online Book System 1.0 and classified as problematic. | 6.1 |
2024-03-27 | CVE-2024-28852 | Ampache | Cross-site Scripting vulnerability in Ampache Ampache is a web based audio/video streaming application and file manager. | 6.1 |
2024-03-27 | CVE-2024-29759 | Codepeople | Unspecified vulnerability in Codepeople Calculated Fields Form Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CodePeople Calculated Fields Form allows Reflected XSS.This issue affects Calculated Fields Form: from n/a through 1.2.54. | 6.1 |
2024-03-27 | CVE-2024-29760 | Booster | Unspecified vulnerability in Booster for Woocommerce Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Pluggabl LLC Booster for WooCommerce allows Reflected XSS.This issue affects Booster for WooCommerce: from n/a through 7.1.7. | 6.1 |
2024-03-27 | CVE-2024-29763 | Pluginus | Unspecified vulnerability in Pluginus Wordpress Meta Data and Taxonomies Filter Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in realmag777 WordPress Meta Data and Taxonomies Filter (MDTF) allows Reflected XSS.This issue affects WordPress Meta Data and Taxonomies Filter (MDTF): from n/a through 1.3.3. | 6.1 |
2024-03-27 | CVE-2024-27270 | IBM | Unspecified vulnerability in IBM Websphere Application Server 24.0.0.3 IBM WebSphere Application Server Liberty 23.0.0.3 through 24.0.0.3 is vulnerable to cross-site scripting. | 6.1 |
2024-03-27 | CVE-2024-29774 | Wpdirectorykit | Unspecified vulnerability in Wpdirectorykit WP Directory KIT Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WpDirectoryKit WP Directory Kit allows Reflected XSS.This issue affects WP Directory Kit: from n/a through 1.2.9. | 6.1 |
2024-03-27 | CVE-2024-29777 | Incsub | Unspecified vulnerability in Incsub Forminator Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPMU DEV Forminator allows Reflected XSS.This issue affects Forminator: from n/a through 1.29.0. | 6.1 |
2024-03-27 | CVE-2024-29792 | Unlimited Elements | Unspecified vulnerability in Unlimited-Elements Unlimited Elements for Elementor Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates) allows Reflected XSS.This issue affects Unlimited Elements For Elementor (Free Widgets, Addons, Templates): from n/a through 1.5.93. | 6.1 |
2024-03-27 | CVE-2024-29931 | Codecabin | Unspecified vulnerability in Codecabin WP GO Maps Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Go Maps (formerly WP Google Maps) WP Google Maps allows Reflected XSS.This issue affects WP Google Maps: from n/a through 9.0.29. | 6.1 |
2024-03-27 | CVE-2024-29923 | WP Property Hive | Unspecified vulnerability in Wp-Property-Hive Propertyhive Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PropertyHive allows Reflected XSS.This issue affects PropertyHive: from n/a through 2.0.8. | 6.1 |
2024-03-27 | CVE-2024-22288 | Webtoffee | Unspecified vulnerability in Webtoffee Woocommerce PDF Invoices, Packing Slips, Delivery Notes and Shipping Labels Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WebToffee WooCommerce PDF Invoices, Packing Slips, Delivery Notes and Shipping Labels allows Reflected XSS.This issue affects WooCommerce PDF Invoices, Packing Slips, Delivery Notes and Shipping Labels: from n/a through 4.4.0. | 6.1 |
2024-03-27 | CVE-2024-2940 | Campcodes | Unspecified vulnerability in Campcodes Online Examination System 1.0 A vulnerability classified as problematic was found in Campcodes Online Examination System 1.0. | 6.1 |
2024-03-27 | CVE-2024-2935 | Remyandrade | Unspecified vulnerability in Remyandrade Todo List in Kanban Board 1.0 A vulnerability, which was classified as problematic, has been found in SourceCodester Todo List in Kanban Board 1.0. | 6.1 |
2024-03-27 | CVE-2024-2939 | Campcodes | Unspecified vulnerability in Campcodes Online Examination System 1.0 A vulnerability classified as problematic has been found in Campcodes Online Examination System 1.0. | 6.1 |
2024-03-25 | CVE-2024-28108 | Phpmyfaq | Cross-site Scripting vulnerability in PHPmyfaq 3.2.5 phpMyFAQ is an open source FAQ web application for PHP 8.1+ and MySQL, PostgreSQL and other databases. | 6.1 |
2024-03-28 | CVE-2024-25952 | Dell | Link Following vulnerability in Dell Powerscale Onefs Dell PowerScale OneFS versions 8.2.2.x through 9.7.0.x contains an UNIX symbolic link (symlink) following vulnerability. | 6.0 |
2024-03-28 | CVE-2024-25953 | Dell | Link Following vulnerability in Dell Powerscale Onefs Dell PowerScale OneFS versions 9.4.0.x through 9.7.0.x contains an UNIX symbolic link (symlink) following vulnerability. | 6.0 |
2024-03-27 | CVE-2024-28853 | Ampache | Cross-site Scripting vulnerability in Ampache Ampache is a web based audio/video streaming application and file manager. | 5.9 |
2024-03-31 | CVE-2024-25027 | IBM | Unspecified vulnerability in IBM Security Verify Access 10.0.6 IBM Security Verify Access 10.0.6 could disclose sensitive snapshot information due to missing encryption. | 5.5 |
2024-03-28 | CVE-2024-25959 | Dell | Unspecified vulnerability in Dell Powerscale Onefs Dell PowerScale OneFS versions 9.4.0.x through 9.7.0.x contains an insertion of sensitive information into log file vulnerability. | 5.5 |
2024-03-28 | CVE-2023-40390 | Apple | Unspecified vulnerability in Apple Macos A privacy issue was addressed by moving sensitive data to a protected location. | 5.5 |
2024-03-28 | CVE-2023-42893 | Apple | Unspecified vulnerability in Apple products A permissions issue was addressed by removing vulnerable code and adding additional checks. | 5.5 |
2024-03-28 | CVE-2023-42896 | Apple | Unspecified vulnerability in Apple Ipados and Macos An issue was addressed with improved handling of temporary files. | 5.5 |
2024-03-28 | CVE-2023-42930 | Apple | Unspecified vulnerability in Apple Macos This issue was addressed with improved checks. | 5.5 |
2024-03-28 | CVE-2023-42936 | Apple | Unspecified vulnerability in Apple products This issue was addressed with improved redaction of sensitive information. | 5.5 |
2024-03-26 | CVE-2024-2971 | Xpdfreader | Out-of-bounds Write vulnerability in Xpdfreader Xpdf Out-of-bounds array write in Xpdf 4.05 and earlier, triggered by negative object number in indirect reference in the input PDF file. | 5.5 |
2024-03-26 | CVE-2024-26647 | Linux | NULL Pointer Dereference vulnerability in Linux Kernel In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Fix late derefrence 'dsc' check in 'link_set_dsc_pps_packet()' In link_set_dsc_pps_packet(), 'struct display_stream_compressor *dsc' was dereferenced in a DC_LOGGER_INIT(dsc->ctx->logger); before the 'dsc' NULL pointer check. Fixes the below: drivers/gpu/drm/amd/amdgpu/../display/dc/link/link_dpms.c:905 link_set_dsc_pps_packet() warn: variable dereferenced before check 'dsc' (see line 903) | 5.5 |
2024-03-26 | CVE-2024-26649 | Linux | NULL Pointer Dereference vulnerability in Linux Kernel In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: Fix the null pointer when load rlc firmware If the RLC firmware is invalid because of wrong header size, the pointer to the rlc firmware is released in function amdgpu_ucode_request. | 5.5 |
2024-03-26 | CVE-2024-25956 | Dell | Unspecified vulnerability in Dell Grab Dell Grab for Windows, versions 5.0.4 and below, contains an improper file permissions vulnerability. | 5.5 |
2024-03-26 | CVE-2024-25957 | Dell | Unspecified vulnerability in Dell Grab Dell Grab for Windows, versions 5.0.4 and below, contains a cleartext storage of sensitive information vulnerability in its appsync module. | 5.5 |
2024-03-25 | CVE-2021-47158 | Linux | Memory Leak vulnerability in Linux Kernel In the Linux kernel, the following vulnerability has been resolved: net: dsa: sja1105: add error handling in sja1105_setup() If any of sja1105_static_config_load(), sja1105_clocking_setup() or sja1105_devlink_setup() fails, we can't just return in the middle of sja1105_setup() or memory will leak. | 5.5 |
2024-03-25 | CVE-2021-47164 | Linux | NULL Pointer Dereference vulnerability in Linux Kernel In the Linux kernel, the following vulnerability has been resolved: net/mlx5e: Fix null deref accessing lag dev It could be the lag dev is null so stop processing the event. In bond_enslave() the active/backup slave being set before setting the upper dev so first event is without an upper dev. After setting the upper dev with bond_master_upper_dev_link() there is a second event and in that event we have an upper dev. | 5.5 |
2024-03-25 | CVE-2021-47165 | Linux | Unspecified vulnerability in Linux Kernel In the Linux kernel, the following vulnerability has been resolved: drm/meson: fix shutdown crash when component not probed When main component is not probed, by example when the dw-hdmi module is not loaded yet or in probe defer, the following crash appears on shutdown: Unable to handle kernel NULL pointer dereference at virtual address 0000000000000038 ... pc : meson_drv_shutdown+0x24/0x50 lr : platform_drv_shutdown+0x20/0x30 ... Call trace: meson_drv_shutdown+0x24/0x50 platform_drv_shutdown+0x20/0x30 device_shutdown+0x158/0x360 kernel_restart_prepare+0x38/0x48 kernel_restart+0x18/0x68 __do_sys_reboot+0x224/0x250 __arm64_sys_reboot+0x24/0x30 ... Simply check if the priv struct has been allocated before using it. | 5.5 |
2024-03-25 | CVE-2021-47169 | Linux | Unspecified vulnerability in Linux Kernel In the Linux kernel, the following vulnerability has been resolved: serial: rp2: use 'request_firmware' instead of 'request_firmware_nowait' In 'rp2_probe', the driver registers 'rp2_uart_interrupt' then calls 'rp2_fw_cb' through 'request_firmware_nowait'. | 5.5 |
2024-03-25 | CVE-2021-47171 | Linux | Memory Leak vulnerability in Linux Kernel In the Linux kernel, the following vulnerability has been resolved: net: usb: fix memory leak in smsc75xx_bind Syzbot reported memory leak in smsc75xx_bind(). The problem was is non-freed memory in case of errors after memory allocation. backtrace: [<ffffffff84245b62>] kmalloc include/linux/slab.h:556 [inline] [<ffffffff84245b62>] kzalloc include/linux/slab.h:686 [inline] [<ffffffff84245b62>] smsc75xx_bind+0x7a/0x334 drivers/net/usb/smsc75xx.c:1460 [<ffffffff82b5b2e6>] usbnet_probe+0x3b6/0xc30 drivers/net/usb/usbnet.c:1728 | 5.5 |
2024-03-25 | CVE-2021-47173 | Linux | Memory Leak vulnerability in Linux Kernel In the Linux kernel, the following vulnerability has been resolved: misc/uss720: fix memory leak in uss720_probe uss720_probe forgets to decrease the refcount of usbdev in uss720_probe. Fix this by decreasing the refcount of usbdev by usb_put_dev. BUG: memory leak unreferenced object 0xffff888101113800 (size 2048): comm "kworker/0:1", pid 7, jiffies 4294956777 (age 28.870s) hex dump (first 32 bytes): ff ff ff ff 31 00 00 00 00 00 00 00 00 00 00 00 ....1........... 00 00 00 00 00 00 00 00 00 00 00 00 03 00 00 00 ................ backtrace: [<ffffffff82b8e822>] kmalloc include/linux/slab.h:554 [inline] [<ffffffff82b8e822>] kzalloc include/linux/slab.h:684 [inline] [<ffffffff82b8e822>] usb_alloc_dev+0x32/0x450 drivers/usb/core/usb.c:582 [<ffffffff82b98441>] hub_port_connect drivers/usb/core/hub.c:5129 [inline] [<ffffffff82b98441>] hub_port_connect_change drivers/usb/core/hub.c:5363 [inline] [<ffffffff82b98441>] port_event drivers/usb/core/hub.c:5509 [inline] [<ffffffff82b98441>] hub_event+0x1171/0x20c0 drivers/usb/core/hub.c:5591 [<ffffffff81259229>] process_one_work+0x2c9/0x600 kernel/workqueue.c:2275 [<ffffffff81259b19>] worker_thread+0x59/0x5d0 kernel/workqueue.c:2421 [<ffffffff81261228>] kthread+0x178/0x1b0 kernel/kthread.c:292 [<ffffffff8100227f>] ret_from_fork+0x1f/0x30 arch/x86/entry/entry_64.S:294 | 5.5 |
2024-03-25 | CVE-2021-47179 | Linux | NULL Pointer Dereference vulnerability in Linux Kernel In the Linux kernel, the following vulnerability has been resolved: NFSv4: Fix a NULL pointer dereference in pnfs_mark_matching_lsegs_return() Commit de144ff4234f changes _pnfs_return_layout() to call pnfs_mark_matching_lsegs_return() passing NULL as the struct pnfs_layout_range argument. | 5.5 |
2024-03-25 | CVE-2021-47180 | Linux | Memory Leak vulnerability in Linux Kernel In the Linux kernel, the following vulnerability has been resolved: NFC: nci: fix memory leak in nci_allocate_device nfcmrvl_disconnect fails to free the hci_dev field in struct nci_dev. Fix this by freeing hci_dev in nci_free_device. BUG: memory leak unreferenced object 0xffff888111ea6800 (size 1024): comm "kworker/1:0", pid 19, jiffies 4294942308 (age 13.580s) hex dump (first 32 bytes): 00 00 00 00 00 00 00 00 00 60 fd 0c 81 88 ff ff .........`...... 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ backtrace: [<000000004bc25d43>] kmalloc include/linux/slab.h:552 [inline] [<000000004bc25d43>] kzalloc include/linux/slab.h:682 [inline] [<000000004bc25d43>] nci_hci_allocate+0x21/0xd0 net/nfc/nci/hci.c:784 [<00000000c59cff92>] nci_allocate_device net/nfc/nci/core.c:1170 [inline] [<00000000c59cff92>] nci_allocate_device+0x10b/0x160 net/nfc/nci/core.c:1132 [<00000000006e0a8e>] nfcmrvl_nci_register_dev+0x10a/0x1c0 drivers/nfc/nfcmrvl/main.c:153 [<000000004da1b57e>] nfcmrvl_probe+0x223/0x290 drivers/nfc/nfcmrvl/usb.c:345 [<00000000d506aed9>] usb_probe_interface+0x177/0x370 drivers/usb/core/driver.c:396 [<00000000bc632c92>] really_probe+0x159/0x4a0 drivers/base/dd.c:554 [<00000000f5009125>] driver_probe_device+0x84/0x100 drivers/base/dd.c:740 [<000000000ce658ca>] __device_attach_driver+0xee/0x110 drivers/base/dd.c:846 [<000000007067d05f>] bus_for_each_drv+0xb7/0x100 drivers/base/bus.c:431 [<00000000f8e13372>] __device_attach+0x122/0x250 drivers/base/dd.c:914 [<000000009cf68860>] bus_probe_device+0xc6/0xe0 drivers/base/bus.c:491 [<00000000359c965a>] device_add+0x5be/0xc30 drivers/base/core.c:3109 [<00000000086e4bd3>] usb_set_configuration+0x9d9/0xb90 drivers/usb/core/message.c:2164 [<00000000ca036872>] usb_generic_driver_probe+0x8c/0xc0 drivers/usb/core/generic.c:238 [<00000000d40d36f6>] usb_probe_device+0x5c/0x140 drivers/usb/core/driver.c:293 [<00000000bc632c92>] really_probe+0x159/0x4a0 drivers/base/dd.c:554 | 5.5 |
2024-03-25 | CVE-2021-47141 | Linux | NULL Pointer Dereference vulnerability in Linux Kernel In the Linux kernel, the following vulnerability has been resolved: gve: Add NULL pointer checks when freeing irqs. When freeing notification blocks, we index priv->msix_vectors. If we failed to allocate priv->msix_vectors (see abort_with_msix_vectors) this could lead to a NULL pointer dereference if the driver is unloaded. | 5.5 |
2024-03-25 | CVE-2021-47142 | Linux | Use After Free vulnerability in Linux Kernel In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: Fix a use-after-free looks like we forget to set ttm->sg to NULL. Hit panic below [ 1235.844104] general protection fault, probably for non-canonical address 0x6b6b6b6b6b6b7b4b: 0000 [#1] SMP DEBUG_PAGEALLOC NOPTI [ 1235.989074] Call Trace: [ 1235.991751] sg_free_table+0x17/0x20 [ 1235.995667] amdgpu_ttm_backend_unbind.cold+0x4d/0xf7 [amdgpu] [ 1236.002288] amdgpu_ttm_backend_destroy+0x29/0x130 [amdgpu] [ 1236.008464] ttm_tt_destroy+0x1e/0x30 [ttm] [ 1236.013066] ttm_bo_cleanup_memtype_use+0x51/0xa0 [ttm] [ 1236.018783] ttm_bo_release+0x262/0xa50 [ttm] [ 1236.023547] ttm_bo_put+0x82/0xd0 [ttm] [ 1236.027766] amdgpu_bo_unref+0x26/0x50 [amdgpu] [ 1236.032809] amdgpu_amdkfd_gpuvm_alloc_memory_of_gpu+0x7aa/0xd90 [amdgpu] [ 1236.040400] kfd_ioctl_alloc_memory_of_gpu+0xe2/0x330 [amdgpu] [ 1236.046912] kfd_ioctl+0x463/0x690 [amdgpu] | 5.5 |
2024-03-25 | CVE-2021-47144 | Linux | Unspecified vulnerability in Linux Kernel In the Linux kernel, the following vulnerability has been resolved: drm/amd/amdgpu: fix refcount leak [Why] the gem object rfb->base.obj[0] is get according to num_planes in amdgpufb_create, but is not put according to num_planes [How] put rfb->base.obj[0] in amdgpu_fbdev_destroy according to num_planes | 5.5 |
2024-03-25 | CVE-2021-47145 | Linux | Unspecified vulnerability in Linux Kernel In the Linux kernel, the following vulnerability has been resolved: btrfs: do not BUG_ON in link_to_fixup_dir While doing error injection testing I got the following panic kernel BUG at fs/btrfs/tree-log.c:1862! invalid opcode: 0000 [#1] SMP NOPTI CPU: 1 PID: 7836 Comm: mount Not tainted 5.13.0-rc1+ #305 Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.13.0-2.fc32 04/01/2014 RIP: 0010:link_to_fixup_dir+0xd5/0xe0 RSP: 0018:ffffb5800180fa30 EFLAGS: 00010216 RAX: fffffffffffffffb RBX: 00000000fffffffb RCX: ffff8f595287faf0 RDX: ffffb5800180fa37 RSI: ffff8f5954978800 RDI: 0000000000000000 RBP: ffff8f5953af9450 R08: 0000000000000019 R09: 0000000000000001 R10: 000151f408682970 R11: 0000000120021001 R12: ffff8f5954978800 R13: ffff8f595287faf0 R14: ffff8f5953c77dd0 R15: 0000000000000065 FS: 00007fc5284c8c40(0000) GS:ffff8f59bbd00000(0000) knlGS:0000000000000000 CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 CR2: 00007fc5287f47c0 CR3: 000000011275e002 CR4: 0000000000370ee0 Call Trace: replay_one_buffer+0x409/0x470 ? btree_read_extent_buffer_pages+0xd0/0x110 walk_up_log_tree+0x157/0x1e0 walk_log_tree+0xa6/0x1d0 btrfs_recover_log_trees+0x1da/0x360 ? replay_one_extent+0x7b0/0x7b0 open_ctree+0x1486/0x1720 btrfs_mount_root.cold+0x12/0xea ? __kmalloc_track_caller+0x12f/0x240 legacy_get_tree+0x24/0x40 vfs_get_tree+0x22/0xb0 vfs_kern_mount.part.0+0x71/0xb0 btrfs_mount+0x10d/0x380 ? vfs_parse_fs_string+0x4d/0x90 legacy_get_tree+0x24/0x40 vfs_get_tree+0x22/0xb0 path_mount+0x433/0xa10 __x64_sys_mount+0xe3/0x120 do_syscall_64+0x3d/0x80 entry_SYSCALL_64_after_hwframe+0x44/0xae We can get -EIO or any number of legitimate errors from btrfs_search_slot(), panicing here is not the appropriate response. | 5.5 |
2024-03-25 | CVE-2021-47146 | Linux | Unspecified vulnerability in Linux Kernel In the Linux kernel, the following vulnerability has been resolved: mld: fix panic in mld_newpack() mld_newpack() doesn't allow to allocate high order page, only order-0 allocation is allowed. If headroom size is too large, a kernel panic could occur in skb_put(). Test commands: ip netns del A ip netns del B ip netns add A ip netns add B ip link add veth0 type veth peer name veth1 ip link set veth0 netns A ip link set veth1 netns B ip netns exec A ip link set lo up ip netns exec A ip link set veth0 up ip netns exec A ip -6 a a 2001:db8:0::1/64 dev veth0 ip netns exec B ip link set lo up ip netns exec B ip link set veth1 up ip netns exec B ip -6 a a 2001:db8:0::2/64 dev veth1 for i in {1..99} do let A=$i-1 ip netns exec A ip link add ip6gre$i type ip6gre \ local 2001:db8:$A::1 remote 2001:db8:$A::2 encaplimit 100 ip netns exec A ip -6 a a 2001:db8:$i::1/64 dev ip6gre$i ip netns exec A ip link set ip6gre$i up ip netns exec B ip link add ip6gre$i type ip6gre \ local 2001:db8:$A::2 remote 2001:db8:$A::1 encaplimit 100 ip netns exec B ip -6 a a 2001:db8:$i::2/64 dev ip6gre$i ip netns exec B ip link set ip6gre$i up done Splat looks like: kernel BUG at net/core/skbuff.c:110! invalid opcode: 0000 [#1] SMP DEBUG_PAGEALLOC KASAN PTI CPU: 0 PID: 7 Comm: kworker/0:1 Not tainted 5.12.0+ #891 Workqueue: ipv6_addrconf addrconf_dad_work RIP: 0010:skb_panic+0x15d/0x15f Code: 92 fe 4c 8b 4c 24 10 53 8b 4d 70 45 89 e0 48 c7 c7 00 ae 79 83 41 57 41 56 41 55 48 8b 54 24 a6 26 f9 ff <0f> 0b 48 8b 6c 24 20 89 34 24 e8 4a 4e 92 fe 8b 34 24 48 c7 c1 20 RSP: 0018:ffff88810091f820 EFLAGS: 00010282 RAX: 0000000000000089 RBX: ffff8881086e9000 RCX: 0000000000000000 RDX: 0000000000000089 RSI: 0000000000000008 RDI: ffffed1020123efb RBP: ffff888005f6eac0 R08: ffffed1022fc0031 R09: ffffed1022fc0031 R10: ffff888117e00187 R11: ffffed1022fc0030 R12: 0000000000000028 R13: ffff888008284eb0 R14: 0000000000000ed8 R15: 0000000000000ec0 FS: 0000000000000000(0000) GS:ffff888117c00000(0000) knlGS:0000000000000000 CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 CR2: 00007f8b801c5640 CR3: 0000000033c2c006 CR4: 00000000003706f0 DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000 DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400 Call Trace: ? ip6_mc_hdr.isra.26.constprop.46+0x12a/0x600 ? ip6_mc_hdr.isra.26.constprop.46+0x12a/0x600 skb_put.cold.104+0x22/0x22 ip6_mc_hdr.isra.26.constprop.46+0x12a/0x600 ? rcu_read_lock_sched_held+0x91/0xc0 mld_newpack+0x398/0x8f0 ? ip6_mc_hdr.isra.26.constprop.46+0x600/0x600 ? lock_contended+0xc40/0xc40 add_grhead.isra.33+0x280/0x380 add_grec+0x5ca/0xff0 ? mld_sendpack+0xf40/0xf40 ? lock_downgrade+0x690/0x690 mld_send_initial_cr.part.34+0xb9/0x180 ipv6_mc_dad_complete+0x15d/0x1b0 addrconf_dad_completed+0x8d2/0xbb0 ? lock_downgrade+0x690/0x690 ? addrconf_rs_timer+0x660/0x660 ? addrconf_dad_work+0x73c/0x10e0 addrconf_dad_work+0x73c/0x10e0 Allowing high order page allocation could fix this problem. | 5.5 |
2024-03-25 | CVE-2021-47149 | Linux | NULL Pointer Dereference vulnerability in Linux Kernel In the Linux kernel, the following vulnerability has been resolved: net: fujitsu: fix potential null-ptr-deref In fmvj18x_get_hwinfo(), if ioremap fails there will be NULL pointer deref. | 5.5 |
2024-03-25 | CVE-2021-47150 | Linux | Memory Leak vulnerability in Linux Kernel In the Linux kernel, the following vulnerability has been resolved: net: fec: fix the potential memory leak in fec_enet_init() If the memory allocated for cbd_base is failed, it should free the memory allocated for the queues, otherwise it causes memory leak. And if the memory allocated for the queues is failed, it can return error directly. | 5.5 |
2024-03-25 | CVE-2021-47151 | Linux | Unspecified vulnerability in Linux Kernel In the Linux kernel, the following vulnerability has been resolved: interconnect: qcom: bcm-voter: add a missing of_node_put() Add a missing of_node_put() in of_bcm_voter_get() to avoid the reference leak. | 5.5 |
2024-03-31 | CVE-2024-30530 | Sonaar | Unspecified vulnerability in Sonaar MP3 Audio Player for Music, Radio & Podcast Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Sonaar Music MP3 Audio Player for Music, Radio & Podcast by Sonaar allows Stored XSS.This issue affects MP3 Audio Player for Music, Radio & Podcast by Sonaar: from n/a through 5.1. | 5.4 |
2024-03-30 | CVE-2024-3091 | Phpgurukul | Unspecified vulnerability in PHPgurukul Emergency Ambulance Hiring Portal 1.0 A vulnerability was found in PHPGurukul Emergency Ambulance Hiring Portal 1.0. | 5.4 |
2024-03-30 | CVE-2024-2491 | Ideabox | Cross-site Scripting vulnerability in Ideabox Powerpack Addons for Elementor The PowerPack Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the *_html_tag* attribute of multiple widgets in all versions up to, and including, 2.7.17 due to insufficient input sanitization and output escaping. | 5.4 |
2024-03-30 | CVE-2024-2140 | Brainstormforce | Cross-site Scripting vulnerability in Brainstormforce Ultimate Addons for Beaver Builder The Ultimate Addons for Beaver Builder – Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Advanced Icons widget in all versions up to, and including, 1.5.7 due to insufficient input sanitization and output escaping. | 5.4 |
2024-03-30 | CVE-2024-2141 | Brainstormforce | Cross-site Scripting vulnerability in Brainstormforce Ultimate Addons for Beaver Builder The Ultimate Addons for Beaver Builder – Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Button widget in all versions up to, and including, 1.5.7 due to insufficient input sanitization and output escaping. | 5.4 |
2024-03-30 | CVE-2024-2142 | Brainstormforce | Cross-site Scripting vulnerability in Brainstormforce Ultimate Addons for Beaver Builder The Ultimate Addons for Beaver Builder – Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Info Table widget in all versions up to, and including, 1.5.7 due to insufficient input sanitization and output escaping. | 5.4 |
2024-03-30 | CVE-2024-2143 | Brainstormforce | Cross-site Scripting vulnerability in Brainstormforce Ultimate Addons for Beaver Builder The Ultimate Addons for Beaver Builder – Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Heading widget in all versions up to, and including, 1.5.7 due to insufficient input sanitization and output escaping. | 5.4 |
2024-03-30 | CVE-2024-2144 | Brainstormforce | Cross-site Scripting vulnerability in Brainstormforce Ultimate Addons for Beaver Builder The Ultimate Addons for Beaver Builder – Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Image Separator widget in all versions up to, and including, 1.5.7 due to insufficient input sanitization and output escaping. | 5.4 |
2024-03-30 | CVE-2024-0367 | Unlimited Elements | Cross-site Scripting vulnerability in Unlimited-Elements Unlimited Elements for Elementor The Unlimited Elements For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the link field of an installed widget (e.g., 'Button Link') in all versions up to, and including, 1.5.96 due to insufficient input sanitization and output escaping on user supplied attributes. | 5.4 |
2024-03-30 | CVE-2024-1238 | Wpmet | Cross-site Scripting vulnerability in Wpmet Elements KIT Elementor Addons The ElementsKit Elementor addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the button ID parameter in all versions up to, and including, 3.0.6 due to insufficient input sanitization and output escaping. | 5.4 |
2024-03-29 | CVE-2024-30442 | Bold Themes | Unspecified vulnerability in Bold-Themes Bold Page Builder Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in BoldThemes Bold Page Builder allows Stored XSS.This issue affects Bold Page Builder: from n/a through 4.8.0. | 5.4 |
2024-03-29 | CVE-2024-30446 | Crmperks | Unspecified vulnerability in Crmperks CRM Perks Forms Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CRM Perks CRM Perks Forms allows Stored XSS.This issue affects CRM Perks Forms: from n/a through 1.1.4. | 5.4 |
2024-03-29 | CVE-2024-30423 | Kitforest | Unspecified vulnerability in Kitforest Better Elementor Addons Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in BetterAddons Better Elementor Addons allows Stored XSS.This issue affects Better Elementor Addons: from n/a through 1.3.7. | 5.4 |
2024-03-29 | CVE-2024-30425 | Fastlinemedia | Unspecified vulnerability in Fastlinemedia Beaver Builder Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in The Beaver Builder Team Beaver Builder allows Stored XSS.This issue affects Beaver Builder: from n/a through 2.7.4.4. | 5.4 |
2024-03-29 | CVE-2024-30426 | Hashthemes | Unspecified vulnerability in Hashthemes Hash Elements Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in HashThemes Hash Elements allows Stored XSS.This issue affects Hash Elements: from n/a through 1.3.3. | 5.4 |
2024-03-29 | CVE-2024-30429 | Tuxlog | Unspecified vulnerability in Tuxlog Wp-Forecast Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Hans Matzen allows Stored XSS.This issue affects wp-forecast: from n/a through 9.2. | 5.4 |
2024-03-29 | CVE-2024-2108 | Ninjaforms | Cross-site Scripting vulnerability in Ninjaforms Ninja Forms The Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via an image title embedded into a form in all versions up to, and including, 3.8.0 due to insufficient input sanitization and output escaping. | 5.4 |
2024-03-29 | CVE-2024-2280 | Kitforest | Unspecified vulnerability in Kitforest Better Elementor Addons The Better Elementor Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the widget link URL values in all versions up to, and including, 1.4.1 due to insufficient input sanitization and output escaping on user supplied attributes. | 5.4 |
2024-03-29 | CVE-2024-2842 | Easy Appointments | Cross-site Scripting vulnerability in Easy-Appointments Easy Appointments The Easy Appointments plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'ea_full_calendar' shortcode in all versions up to, and including, 3.11.18 due to insufficient input sanitization and output escaping on user supplied attributes. | 5.4 |
2024-03-29 | CVE-2024-2936 | Athemes | Cross-site Scripting vulnerability in Athemes Sydney Toolbox The Sydney Toolbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the _id attribute of widgets in all versions up to, and including, 1.26 due to insufficient input sanitization and output escaping on user supplied attributes. | 5.4 |
2024-03-29 | CVE-2024-2475 | Davidlingren | Cross-site Scripting vulnerability in Davidlingren Media Library Assistant The Media Library Assistant plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in all versions up to, and including, 3.13 due to insufficient input sanitization and output escaping on user supplied attributes. | 5.4 |
2024-03-29 | CVE-2024-2841 | Themeisle | Cross-site Scripting vulnerability in Themeisle Otter Blocks The Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's widgets in all versions up to, and including, 2.6.5 due to insufficient input sanitization and output escaping on user supplied attributes such as 'id'. | 5.4 |
2024-03-28 | CVE-2024-28456 | Campcodes | Cross-site Scripting vulnerability in Campcodes Online Marriage Registration System 1.0 Cross Site Scripting vulnerability in Campcodes Online Marriage Registration System v.1.0 allows a remote attacker to execute arbitrary code via the text fields in the marriage registration request form. | 5.4 |
2024-03-28 | CVE-2024-31138 | Jetbrains | Cross-site Scripting vulnerability in Jetbrains Teamcity In JetBrains TeamCity before 2024.03 xSS was possible via Agent Distribution settings | 5.4 |
2024-03-28 | CVE-2024-30422 | Webtechstreet | Unspecified vulnerability in Webtechstreet Elementor Addon Elements Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPVibes Elementor Addon Elements allows Stored XSS.This issue affects Elementor Addon Elements: from n/a through 1.13.1. | 5.4 |
2024-03-28 | CVE-2023-6371 | Gitlab | Cross-site Scripting vulnerability in Gitlab An issue has been discovered in GitLab CE/EE affecting all versions before 16.8.5, all versions starting from 16.9 before 16.9.3, all versions starting from 16.10 before 16.10.1. | 5.4 |
2024-03-28 | CVE-2024-2111 | Pixelite | Cross-site Scripting vulnerability in Pixelite Events Manager The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the physical location value in all versions up to, and including, 6.4.7.1 due to insufficient input sanitization and output escaping. | 5.4 |
2024-03-27 | CVE-2023-50961 | IBM | Unspecified vulnerability in IBM Qradar Security Information and Event Manager 7.5.0 IBM QRadar SIEM 7.5 is vulnerable to stored cross-site scripting. | 5.4 |
2024-03-27 | CVE-2024-29793 | Mailmunch | Unspecified vulnerability in Mailmunch Mailchimp Forms Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in MailMunch MailChimp Forms by MailMunch allows Stored XSS.This issue affects MailChimp Forms by MailMunch: from n/a through 3.2.2. | 5.4 |
2024-03-27 | CVE-2024-30179 | Bold Themes | Unspecified vulnerability in Bold-Themes Bold Page Builder Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in BoldThemes Bold Page Builder allows Stored XSS.This issue affects Bold Page Builder: from n/a through 4.7.6. | 5.4 |
2024-03-27 | CVE-2024-30182 | Hasthemes | Unspecified vulnerability in Hasthemes HT Mega Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in HasThemes HT Mega allows Stored XSS.This issue affects HT Mega: from n/a through 2.4.3. | 5.4 |
2024-03-27 | CVE-2024-30185 | Bdthemes | Unspecified vulnerability in Bdthemes Element Pack Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in BdThemes Element Pack Elementor Addons allows Stored XSS.This issue affects Element Pack Elementor Addons: from n/a through 5.5.3. | 5.4 |
2024-03-27 | CVE-2024-30186 | Bdthemes | Unspecified vulnerability in Bdthemes Prime Slider Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in BdThemes Prime Slider – Addons For Elementor allows Stored XSS.This issue affects Prime Slider – Addons For Elementor: from n/a through 3.13.1. | 5.4 |
2024-03-27 | CVE-2024-29935 | Sinaextra | Unspecified vulnerability in Sinaextra Sina Extension for Elementor Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in SinaExtra Sina Extension for Elementor allows Stored XSS.This issue affects Sina Extension for Elementor: from n/a through 3.5.0. | 5.4 |
2024-03-27 | CVE-2024-30177 | Exclusiveaddons | Unspecified vulnerability in Exclusiveaddons Exclusive Addons for Elementor Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Exclusive Addons Exclusive Addons Elementor allows Stored XSS.This issue affects Exclusive Addons Elementor: from n/a through 2.6.8. | 5.4 |
2024-03-27 | CVE-2024-29932 | Pluginus | Unspecified vulnerability in Pluginus Wordpress Meta Data and Taxonomies Filter Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in realmag777 WordPress Meta Data and Taxonomies Filter (MDTF) allows Stored XSS.This issue affects WordPress Meta Data and Taxonomies Filter (MDTF): from n/a through 1.3.2. | 5.4 |
2024-03-27 | CVE-2024-29920 | Moveaddons | Unspecified vulnerability in Moveaddons Move Addons for Elementor Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Moveaddons Move Addons for Elementor allows Stored XSS.This issue affects Move Addons for Elementor: from n/a through 1.2.9. | 5.4 |
2024-03-27 | CVE-2024-29925 | Wpwax | Unspecified vulnerability in Wpwax Post Grid, Slider & Carousel Ultimate Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpWax Post Grid, Slider & Carousel Ultimate allows Stored XSS.This issue affects Post Grid, Slider & Carousel Ultimate: from n/a through 1.6.6. | 5.4 |
2024-03-27 | CVE-2024-29906 | Pluginus | Unspecified vulnerability in Pluginus Wordpress Meta Data and Taxonomies Filter Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in realmag777 WordPress Meta Data and Taxonomies Filter (MDTF) allows Stored XSS.This issue affects WordPress Meta Data and Taxonomies Filter (MDTF): from n/a through 1.3.2. | 5.4 |
2024-03-27 | CVE-2024-29911 | Master Addons | Unspecified vulnerability in Master-Addons Master Addons Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jewel Theme Master Addons for Elementor allows Stored XSS.This issue affects Master Addons for Elementor: from n/a through 2.0.5.4.1. | 5.4 |
2024-03-27 | CVE-2024-29913 | Themeum | Unspecified vulnerability in Themeum Tutor LMS Elementor Addons Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themeum Tutor LMS Elementor Addons allows Stored XSS.This issue affects Tutor LMS Elementor Addons: from n/a through 2.1.3. | 5.4 |
2024-03-27 | CVE-2024-2120 | Elementor | Cross-site Scripting vulnerability in Elementor Website Builder The Elementor Website Builder – More than Just a Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Post Navigation widget in all versions up to, and including, 3.20.1 due to insufficient input sanitization and output escaping on user supplied attributes. | 5.4 |
2024-03-27 | CVE-2024-2139 | Master Addons | Cross-site Scripting vulnerability in Master-Addons Master Addons The Master Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Pricing Table widget in all versions up to, and including, 2.0.5.6 due to insufficient input sanitization and output escaping. | 5.4 |
2024-03-26 | CVE-2024-30232 | Exclusiveaddons | Unspecified vulnerability in Exclusiveaddons Exclusive Addons for Elementor Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Exclusive Addons Exclusive Addons Elementor allows Stored XSS.This issue affects Exclusive Addons Elementor: from n/a through 2.6.9. | 5.4 |
2024-03-26 | CVE-2024-2732 | Themify | Unspecified vulnerability in Themify Shortcodes The Themify Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'themify_post_slider shortcode in all versions up to, and including, 2.0.8 due to insufficient input sanitization and output escaping on user supplied attributes. | 5.4 |
2024-03-25 | CVE-2024-27300 | Phpmyfaq | Cross-site Scripting vulnerability in PHPmyfaq 3.2.5 phpMyFAQ is an open source FAQ web application for PHP 8.1+ and MySQL, PostgreSQL and other databases. | 5.4 |
2024-03-25 | CVE-2024-28106 | Phpmyfaq | Cross-site Scripting vulnerability in PHPmyfaq 3.2.5 phpMyFAQ is an open source FAQ web application for PHP 8.1+ and MySQL, PostgreSQL and other databases. | 5.4 |
2024-03-25 | CVE-2022-45351 | Muffingroup | Unspecified vulnerability in Muffingroup Betheme Missing Authorization vulnerability in Muffingroup Betheme.This issue affects Betheme: from n/a through 26.6.1. | 5.4 |
2024-03-29 | CVE-2024-29020 | Fit2Cloud | Authorization Bypass Through User-Controlled Key vulnerability in Fit2Cloud Jumpserver JumpServer is an open source bastion host and an operation and maintenance security audit system. | 5.3 |
2024-03-29 | CVE-2024-29024 | Fit2Cloud | Authorization Bypass Through User-Controlled Key vulnerability in Fit2Cloud Jumpserver JumpServer is an open source bastion host and an operation and maintenance security audit system. An authenticated user can exploit the Insecure Direct Object Reference (IDOR) vulnerability in the file manager's bulk transfer by manipulating job IDs to upload malicious files, potentially compromising the integrity and security of the system. | 5.3 |
2024-03-29 | CVE-2024-23449 | Elastic | Unspecified vulnerability in Elastic Elasticsearch An uncaught exception in Elasticsearch >= 8.4.0 and < 8.11.1 occurs when an encrypted PDF is passed to an attachment processor through the REST API. | 5.3 |
2024-03-28 | CVE-2024-31140 | Jetbrains | Unspecified vulnerability in Jetbrains Teamcity In JetBrains TeamCity before 2024.03 server administrators could remove arbitrary files from the server by installing tools | 4.9 |
2024-03-27 | CVE-2024-29892 | Zitadel | Incorrect Authorization vulnerability in Zitadel ZITADEL, open source authentication management software, uses Go templates to render the login UI. | 4.9 |
2024-03-26 | CVE-2024-22356 | IBM | Improper Encoding or Escaping of Output vulnerability in IBM APP Connect Enterprise and Integration BUS IBM App Connect Enterprise 11.0.0.1 through 11.0.0.23, 12.0.1.0 through 12.0.9.0 and IBM Integration Bus for z/OS 10.1 through 10.1.0.2store potentially sensitive information in log or trace files that could be read by a privileged user. | 4.9 |
2024-03-30 | CVE-2024-3090 | Phpgurukul | Unspecified vulnerability in PHPgurukul Emergency Ambulance Hiring Portal 1.0 A vulnerability was found in PHPGurukul Emergency Ambulance Hiring Portal 1.0 and classified as problematic. | 4.8 |
2024-03-29 | CVE-2024-30430 | Wpmanageninja | Unspecified vulnerability in Wpmanageninja Fluentcrm Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Email Newsletter Team - FluentCRM Fluent CRM allows Stored XSS.This issue affects Fluent CRM: from n/a through 2.8.44. | 4.8 |
2024-03-29 | CVE-2024-2963 | Logicore | Unspecified vulnerability in Logicore Pocket News Generator The Pocket News Generator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings such as "Consumer Key" and "Access Token" in all versions up to, and including, 0.2.0 due to insufficient input sanitization and output escaping. | 4.8 |
2024-03-27 | CVE-2024-29921 | Supsystic | Unspecified vulnerability in Supsystic Photo Gallery Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Supsystic Photo Gallery by Supsystic allows Stored XSS.This issue affects Photo Gallery by Supsystic: from n/a through 1.15.16. | 4.8 |
2024-03-25 | CVE-2024-29179 | Phpmyfaq | Cross-site Scripting vulnerability in PHPmyfaq 3.2.5 phpMyFAQ is an open source FAQ web application for PHP 8.1+ and MySQL, PostgreSQL and other databases. | 4.8 |
2024-03-28 | CVE-2024-2091 | Webtechstreet | Cross-site Scripting vulnerability in Webtechstreet Elementor Addon Elements The Elementor Addon Elements plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's widgets in all versions up to, and including, 1.13.1 due to insufficient input sanitization and output escaping on user supplied attributes. | 4.6 |
2024-03-30 | CVE-2024-3089 | Phpgurukul | Unspecified vulnerability in PHPgurukul Emergency Ambulance Hiring Portal 1.0 A vulnerability has been found in PHPGurukul Emergency Ambulance Hiring Portal 1.0 and classified as problematic. | 4.3 |
2024-03-29 | CVE-2024-30455 | Gamipress | Unspecified vulnerability in Gamipress Cross-Site Request Forgery (CSRF) vulnerability in GamiPress.This issue affects GamiPress: from n/a through 6.8.5. | 4.3 |
2024-03-29 | CVE-2024-2113 | Ninjaforms | Cross-site Scripting vulnerability in Ninjaforms Ninja Forms The Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.8.0. | 4.3 |
2024-03-29 | CVE-2024-2964 | Logicore | Unspecified vulnerability in Logicore Pocket News Generator The Pocket News Generator plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 0.2.0. | 4.3 |
2024-03-28 | CVE-2024-28004 | Extendthemes | Unspecified vulnerability in Extendthemes Colibri Page Builder Missing Authorization vulnerability in ExtendThemes Colibri Page Builder.This issue affects Colibri Page Builder: from n/a through 1.0.248. | 4.3 |
2024-03-26 | CVE-2024-2951 | Metagauss | Unspecified vulnerability in Metagauss Registrationmagic Cross-Site Request Forgery (CSRF) vulnerability in Metagauss RegistrationMagic.This issue affects RegistrationMagic: from n/a through 5.3.0.0. | 4.3 |
2024-03-25 | CVE-2023-45824 | Oroinc | Unspecified vulnerability in Oroinc Oroplatform OroPlatform is a PHP Business Application Platform (BAP). | 4.3 |
2024-03-25 | CVE-2023-48296 | Oroinc | Unspecified vulnerability in Oroinc Oroplatform OroPlatform is a PHP Business Application Platform (BAP). | 4.3 |
2024-03-25 | CVE-2022-45349 | Muffingroup | Unspecified vulnerability in Muffingroup Betheme Missing Authorization vulnerability in Muffingroup Betheme.This issue affects Betheme: from n/a through 26.6.1. | 4.3 |
2024-03-25 | CVE-2022-45352 | Muffingroup | Unspecified vulnerability in Muffingroup Betheme Missing Authorization vulnerability in Muffingroup Betheme.This issue affects Betheme: from n/a through 26.6.1. | 4.3 |
1 Low Vulnerabilities
DATE | CVE | VENDOR | VULNERABILITY | CVSS |
---|---|---|---|---|
2024-03-26 | CVE-2024-29196 | Phpmyfaq | Path Traversal vulnerability in PHPmyfaq 3.2.5 phpMyFAQ is an open source FAQ web application for PHP 8.1+ and MySQL, PostgreSQL and other databases. | 2.7 |