Weekly Vulnerabilities Reports > April 8 to 14, 2024
Overview
331 new vulnerabilities reported during this period, including 32 critical vulnerabilities and 98 high severity vulnerabilities. This weekly summary report vulnerabilities in 430 products from 113 vendors including Linux, Campcodes, Microsoft, IBM, and Xwiki. Vulnerabilities are notably categorized as "Cross-site Scripting", "Out-of-bounds Write", "NULL Pointer Dereference", "Missing Authorization", and "Out-of-bounds Read".
- 257 reported vulnerabilities are remotely exploitables.
- 79 reported vulnerabilities are related to weaknesses in OWASP Top Ten.
- 123 reported vulnerabilities are exploitable by an anonymous user.
- Linux has the most reported vulnerabilities, with 38 reported vulnerabilities.
- Netentsec has the most reported critical vulnerabilities, with 4 reported vulnerabilities.
VULNERABILITIES
VULNERABILITIES
VULNERABILITIES
VULNERABILITIES
VULNERABILITIES
EXPLOITABLE
EXPLOITABLE
AVAILABLE
ANONYMOUSLY
WEB APPLICATION
Vulnerability Details
The following table list reported vulnerabilities for the period covered by this report:
32 Critical Vulnerabilities
DATE | CVE | VENDOR | VULNERABILITY | CVSS |
---|---|---|---|---|
2024-04-12 | CVE-2024-3400 | Paloaltonetworks | Command Injection vulnerability in Paloaltonetworks Pan-Os A command injection as a result of arbitrary file creation vulnerability in the GlobalProtect feature of Palo Alto Networks PAN-OS software for specific PAN-OS versions and distinct feature configurations may enable an unauthenticated attacker to execute arbitrary code with root privileges on the firewall. Cloud NGFW, Panorama appliances, and Prisma Access are not impacted by this vulnerability. | 10.0 |
2024-04-12 | CVE-2024-3691 | Phpgurukul | Unspecified vulnerability in PHPgurukul Small CRM 3.0 A vulnerability, which was classified as critical, has been found in PHPGurukul Small CRM 3.0. | 9.8 |
2024-04-12 | CVE-2023-51409 | Meowapps | Unspecified vulnerability in Meowapps AI Engine Unrestricted Upload of File with Dangerous Type vulnerability in Jordy Meow AI Engine: ChatGPT Chatbot.This issue affects AI Engine: ChatGPT Chatbot: from n/a through 1.9.98. | 9.8 |
2024-04-12 | CVE-2024-3685 | Dedecms | Unspecified vulnerability in Dedecms 5.7.112 A vulnerability, which was classified as critical, was found in DedeCMS 5.7.112-UTF8. | 9.8 |
2024-04-11 | CVE-2024-25935 | Metagauss | Unspecified vulnerability in Metagauss Registrationmagic Missing Authorization vulnerability in Metagauss RegistrationMagic.This issue affects RegistrationMagic: from n/a through 5.2.5.9. | 9.8 |
2024-04-10 | CVE-2024-31996 | Xwiki | Code Injection vulnerability in Xwiki XWiki Platform is a generic wiki platform. | 9.8 |
2024-04-10 | CVE-2024-31982 | Xwiki | Code Injection vulnerability in Xwiki XWiki Platform is a generic wiki platform. | 9.8 |
2024-04-10 | CVE-2024-3534 | Campcodes | Unspecified vulnerability in Campcodes Church Management System 1.0 A vulnerability, which was classified as critical, has been found in Campcodes Church Management System 1.0. | 9.8 |
2024-04-10 | CVE-2024-3535 | Campcodes | Unspecified vulnerability in Campcodes Church Management System 1.0 A vulnerability, which was classified as critical, was found in Campcodes Church Management System 1.0. | 9.8 |
2024-04-10 | CVE-2023-50347 | Hcltech | Unspecified vulnerability in Hcltech Dryice Myxalytics HCL DRYiCE MyXalytics is impacted by an insecure SQL interface vulnerability, potentially giving an attacker the ability to execute custom SQL queries. | 9.8 |
2024-04-10 | CVE-2024-3119 | Irontec | Out-of-bounds Write vulnerability in Irontec Sngrep A buffer overflow vulnerability exists in all versions of sngrep since v0.4.2, due to improper handling of 'Call-ID' and 'X-Call-ID' SIP headers. | 9.8 |
2024-04-10 | CVE-2024-3120 | Irontec | Out-of-bounds Write vulnerability in Irontec Sngrep A stack-buffer overflow vulnerability exists in all versions of sngrep since v1.4.1. | 9.8 |
2024-04-09 | CVE-2024-3214 | Relevanssi | Improper Neutralization of Formula Elements in a CSV File vulnerability in Relevanssi The Relevanssi – A Better Search plugin for WordPress is vulnerable to CSV Injection in all versions up to, and including, 4.22.1. | 9.8 |
2024-04-09 | CVE-2023-6317 | LG | Unspecified vulnerability in LG Webos A prompt bypass exists in the secondscreen.gateway service running on webOS version 4 through 7. | 9.8 |
2024-04-09 | CVE-2024-2223 | Bitdefender | Incorrect Comparison vulnerability in Bitdefender Endpoint Security and Gravityzone Control Center An Incorrect Regular Expression vulnerability in Bitdefender GravityZone Update Server allows an attacker to cause a Server Side Request Forgery and reconfigure the relay. | 9.8 |
2024-04-09 | CVE-2024-2224 | Bitdefender | Unspecified vulnerability in Bitdefender Endpoint Security and Gravityzone Control Center Improper Limitation of a Pathname to a Restricted Directory (‘Path Traversal’) vulnerability in the UpdateServer component of Bitdefender GravityZone allows an attacker to execute arbitrary code on vulnerable instances. | 9.8 |
2024-04-08 | CVE-2024-3465 | Oretnom23 | Unspecified vulnerability in Oretnom23 Laundry Shop Management System 1.0 A vulnerability was found in SourceCodester Laundry Management System 1.0. | 9.8 |
2024-04-08 | CVE-2024-3464 | Oretnom23 | Unspecified vulnerability in Oretnom23 Laundry Shop Management System 1.0 A vulnerability was found in SourceCodester Laundry Management System 1.0 and classified as critical. | 9.8 |
2024-04-08 | CVE-2024-3457 | Netentsec | Unspecified vulnerability in Netentsec Application Security Gateway 6.3 A vulnerability classified as critical has been found in Netentsec NS-ASG Application Security Gateway 6.3. | 9.8 |
2024-04-08 | CVE-2024-3458 | Netentsec | Unspecified vulnerability in Netentsec Application Security Gateway 6.3 A vulnerability classified as critical was found in Netentsec NS-ASG Application Security Gateway 6.3. | 9.8 |
2024-04-08 | CVE-2024-3456 | Netentsec | Unspecified vulnerability in Netentsec Application Security Gateway 6.3 A vulnerability was found in Netentsec NS-ASG Application Security Gateway 6.3. | 9.8 |
2024-04-08 | CVE-2024-3445 | Oretnom23 | Unspecified vulnerability in Oretnom23 Laundry Shop Management System 1.0 A vulnerability was found in SourceCodester Laundry Management System 1.0. | 9.8 |
2024-04-08 | CVE-2024-3455 | Netentsec | Unspecified vulnerability in Netentsec Application Security Gateway 6.3 A vulnerability was found in Netentsec NS-ASG Application Security Gateway 6.3. | 9.8 |
2024-04-08 | CVE-2024-3439 | Fast5 | Unspecified vulnerability in Fast5 Prison Management System 1.0 A vulnerability was found in SourceCodester Prison Management System 1.0. | 9.8 |
2024-04-08 | CVE-2024-3438 | Fast5 | Unspecified vulnerability in Fast5 Prison Management System 1.0 A vulnerability was found in SourceCodester Prison Management System 1.0 and classified as critical. | 9.8 |
2024-04-10 | CVE-2024-3157 | Google Fedoraproject | Out-of-bounds Write vulnerability in multiple products Out of bounds memory access in Compositing in Google Chrome prior to 123.0.6312.122 allowed a remote attacker who had compromised the GPU process to potentially perform a sandbox escape via specific UI gestures. | 9.6 |
2024-04-10 | CVE-2024-31214 | Traccar | Unrestricted Upload of File with Dangerous Type vulnerability in Traccar Traccar is an open source GPS tracking system. | 9.6 |
2024-04-10 | CVE-2024-1740 | Lunary | Unspecified vulnerability in Lunary In lunary-ai/lunary version 1.0.1, a vulnerability exists where a user removed from an organization can still read, create, modify, and delete logs by re-using an old authorization token. | 9.1 |
2024-04-10 | CVE-2024-1741 | Lunary | Incorrect Authorization vulnerability in Lunary lunary-ai/lunary version 1.0.1 is vulnerable to improper authorization, allowing removed members to read, create, modify, and delete prompt templates using an old authorization token. | 9.1 |
2024-04-10 | CVE-2024-3383 | Paloaltonetworks | Unspecified vulnerability in Paloaltonetworks Pan-Os A vulnerability in how Palo Alto Networks PAN-OS software processes data received from Cloud Identity Engine (CIE) agents enables modification of User-ID groups. | 9.1 |
2024-04-10 | CVE-2024-20758 | Adobe | Unspecified vulnerability in Adobe Commerce and Magento Adobe Commerce versions 2.4.6-p4, 2.4.5-p6, 2.4.4-p7, 2.4.7-beta3 and earlier are affected by an Improper Input Validation vulnerability that could result in arbitrary code execution on the underlying filesystem. | 9.0 |
2024-04-09 | CVE-2024-29990 | Microsoft | Unspecified vulnerability in Microsoft Azure Kubernetes Service Confidential Containers Microsoft Azure Kubernetes Service Confidential Container Elevation of Privilege Vulnerability | 9.0 |
98 High Vulnerabilities
DATE | CVE | VENDOR | VULNERABILITY | CVSS |
---|---|---|---|---|
2024-04-13 | CVE-2024-3719 | Campcodes | Unspecified vulnerability in Campcodes House Rental Management System 1.0 A vulnerability, which was classified as critical, was found in Campcodes House Rental Management System 1.0. | 8.8 |
2024-04-12 | CVE-2024-22358 | IBM | Unspecified vulnerability in IBM Urbancode Deploy IBM UrbanCode Deploy (UCD) 7.0 through 7.0.5.20, 7.1 through 7.1.2.16, 7.2 through 7.2.3.9, 7.3 through 7.3.2.4 and IBM DevOps Deploy 8.0 through 8.0.0.1 does not invalidate session after logout which could allow an authenticated user to impersonate another user on the system. | 8.8 |
2024-04-12 | CVE-2024-3697 | Campcodes | Unspecified vulnerability in Campcodes House Rental Management System 1.0 A vulnerability was found in Campcodes House Rental Management System 1.0. | 8.8 |
2024-04-12 | CVE-2024-3698 | Campcodes | Unspecified vulnerability in Campcodes House Rental Management System 1.0 A vulnerability was found in Campcodes House Rental Management System 1.0. | 8.8 |
2024-04-12 | CVE-2024-3696 | Campcodes | Unspecified vulnerability in Campcodes House Rental Management System 1.0 A vulnerability was found in Campcodes House Rental Management System 1.0 and classified as critical. | 8.8 |
2024-04-12 | CVE-2024-3690 | Phpgurukul | Unspecified vulnerability in PHPgurukul Small CRM 3.0 A vulnerability classified as critical was found in PHPGurukul Small CRM 3.0. | 8.8 |
2024-04-12 | CVE-2024-31238 | Zaytech | Unspecified vulnerability in Zaytech Smart Online Order for Clover Cross-Site Request Forgery (CSRF) vulnerability in Zaytech Smart Online Order for Clover.This issue affects Smart Online Order for Clover: from n/a through 1.5.5. | 8.8 |
2024-04-12 | CVE-2024-31269 | Supsystic | Unspecified vulnerability in Supsystic Easy Google Maps Cross-Site Request Forgery (CSRF) vulnerability in Supsystic Easy Google Maps.This issue affects Easy Google Maps: from n/a through 1.11.11. | 8.8 |
2024-04-12 | CVE-2024-31293 | Sandhillsdev | Unspecified vulnerability in Sandhillsdev Easy Digital Downloads Cross-Site Request Forgery (CSRF) vulnerability in Easy Digital Downloads.This issue affects Easy Digital Downloads: from n/a through 3.2.6. | 8.8 |
2024-04-12 | CVE-2024-31301 | Themeisle | Unspecified vulnerability in Themeisle multiple Page Generator Cross-Site Request Forgery (CSRF) vulnerability in Themeisle Multiple Page Generator Plugin – MPG.This issue affects Multiple Page Generator Plugin – MPG: from n/a through 3.4.0. | 8.8 |
2024-04-12 | CVE-2024-31362 | Metagauss | Unspecified vulnerability in Metagauss Profilegrid Cross-Site Request Forgery (CSRF) vulnerability in Metagauss ProfileGrid.This issue affects ProfileGrid : from n/a through 5.7.8. | 8.8 |
2024-04-12 | CVE-2024-31363 | Lifterlms | Unspecified vulnerability in Lifterlms Cross-Site Request Forgery (CSRF) vulnerability in LifterLMS.This issue affects LifterLMS: from n/a through 7.5.0. | 8.8 |
2024-04-11 | CVE-2024-31932 | Creativethemes | Unspecified vulnerability in Creativethemes Blocksy Companion Cross-Site Request Forgery (CSRF) vulnerability in CreativeThemes Blocksy Companion.This issue affects Blocksy Companion: from n/a through 2.0.28. | 8.8 |
2024-04-11 | CVE-2024-27985 | WP Property Hive | Unspecified vulnerability in Wp-Property-Hive Propertyhive Deserialization of Untrusted Data vulnerability in PropertyHive.This issue affects PropertyHive: from n/a through 2.0.9. | 8.8 |
2024-04-10 | CVE-2024-31997 | Xwiki | Missing Authorization vulnerability in Xwiki XWiki Platform is a generic wiki platform. | 8.8 |
2024-04-10 | CVE-2024-31986 | Xwiki | Cross-Site Request Forgery (CSRF) vulnerability in Xwiki XWiki Platform is a generic wiki platform. | 8.8 |
2024-04-10 | CVE-2024-31987 | Xwiki | Missing Authorization vulnerability in Xwiki XWiki Platform is a generic wiki platform. | 8.8 |
2024-04-10 | CVE-2024-31988 | Xwiki | Cross-Site Request Forgery (CSRF) vulnerability in Xwiki XWiki Platform is a generic wiki platform. | 8.8 |
2024-04-10 | CVE-2024-31430 | Pluginus | Unspecified vulnerability in Pluginus products Cross-Site Request Forgery (CSRF) vulnerability in realmag777 WOLF – WordPress Posts Bulk Editor and Manager Professional, realmag777 BEAR – Bulk Editor and Products Manager Professional for WooCommerce by Pluginus.Net.This issue affects WOLF – WordPress Posts Bulk Editor and Manager Professional: from n/a through 1.0.8.1; BEAR – Bulk Editor and Products Manager Professional for WooCommerce by Pluginus.Net: from n/a through 1.1.4.1. | 8.8 |
2024-04-10 | CVE-2024-31465 | Xwiki | Code Injection vulnerability in Xwiki XWiki Platform is a generic wiki platform. | 8.8 |
2024-04-10 | CVE-2024-31981 | Xwiki | Missing Authorization vulnerability in Xwiki XWiki Platform is a generic wiki platform. | 8.8 |
2024-04-10 | CVE-2024-31983 | Xwiki | Missing Authorization vulnerability in Xwiki XWiki Platform is a generic wiki platform. | 8.8 |
2024-04-10 | CVE-2024-31984 | Xwiki | Code Injection vulnerability in Xwiki XWiki Platform is a generic wiki platform. | 8.8 |
2024-04-10 | CVE-2024-3538 | Campcodes | Unspecified vulnerability in Campcodes Church Management System 1.0 A vulnerability was found in Campcodes Church Management System 1.0. | 8.8 |
2024-04-10 | CVE-2024-3539 | Campcodes | Unspecified vulnerability in Campcodes Church Management System 1.0 A vulnerability was found in Campcodes Church Management System 1.0. | 8.8 |
2024-04-10 | CVE-2024-3540 | Campcodes | Unspecified vulnerability in Campcodes Church Management System 1.0 A vulnerability was found in Campcodes Church Management System 1.0. | 8.8 |
2024-04-10 | CVE-2024-3536 | Campcodes | Unspecified vulnerability in Campcodes Church Management System 1.0 A vulnerability has been found in Campcodes Church Management System 1.0 and classified as critical. | 8.8 |
2024-04-10 | CVE-2024-3537 | Campcodes | Unspecified vulnerability in Campcodes Church Management System 1.0 A vulnerability was found in Campcodes Church Management System 1.0 and classified as critical. | 8.8 |
2024-04-09 | CVE-2024-3522 | Campcodes | Unspecified vulnerability in Campcodes Online Event Management System 1.0 A vulnerability classified as critical has been found in Campcodes Online Event Management System 1.0. | 8.8 |
2024-04-09 | CVE-2024-3523 | Campcodes | Unspecified vulnerability in Campcodes Online Event Management System 1.0 A vulnerability classified as critical was found in Campcodes Online Event Management System 1.0. | 8.8 |
2024-04-09 | CVE-2024-2018 | Melapress | SQL Injection vulnerability in Melapress WP Activity LOG The WP Activity Log Premium plugin for WordPress is vulnerable to SQL Injection via the entry->roles parameter in all versions up to, and including, 4.6.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. | 8.8 |
2024-04-09 | CVE-2023-41677 | Fortinet | Unspecified vulnerability in Fortinet Fortiproxy A insufficiently protected credentials in Fortinet FortiProxy 7.4.0, 7.2.0 through 7.2.6, 7.0.0 through 7.0.12, 2.0.0 through 2.0.13, 1.2.0 through 1.2.13, 1.1.0 through 1.1.6, 1.0.0 through 1.0.7, Fortinet FortiOS 7.4.0 through 7.4.1, 7.2.0 through 7.2.6, 7.0.0 through 7.0.12, 6.4.0 through 6.4.14, 6.2.0 through 6.2.15, 6.0.0 through 6.0.17 allows attacker to execute unauthorized code or commands via targeted social engineering attack | 8.8 |
2024-04-09 | CVE-2023-45590 | Fortinet | Unspecified vulnerability in Fortinet Forticlient An improper control of generation of code ('code injection') in Fortinet FortiClientLinux version 7.2.0, 7.0.6 through 7.0.10 and 7.0.3 through 7.0.4 allows attacker to execute unauthorized code or commands via tricking a FortiClientLinux user into visiting a malicious website | 8.8 |
2024-04-09 | CVE-2024-21755 | Fortinet | Unspecified vulnerability in Fortinet Fortisandbox A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiSandbox version 4.4.0 through 4.4.3 and 4.2.0 through 4.2.6 and 4.0.0 through 4.0.4 allows attacker to execute unauthorized code or commands via crafted requests.. | 8.8 |
2024-04-09 | CVE-2024-21756 | Fortinet | Unspecified vulnerability in Fortinet Fortisandbox A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiSandbox version 4.4.0 through 4.4.3 and 4.2.0 through 4.2.6 and 4.0.0 through 4.0.4 allows attacker to execute unauthorized code or commands via crafted requests.. | 8.8 |
2024-04-08 | CVE-2024-3466 | Oretnom23 | Unspecified vulnerability in Oretnom23 Laundry Shop Management System 1.0 A vulnerability was found in SourceCodester Laundry Management System 1.0. | 8.8 |
2024-04-08 | CVE-2024-3442 | Fast5 | Unspecified vulnerability in Fast5 Prison Management System 1.0 A vulnerability classified as critical has been found in SourceCodester Prison Management System 1.0. | 8.8 |
2024-04-08 | CVE-2024-3441 | Fast5 | Unspecified vulnerability in Fast5 Prison Management System 1.0 A vulnerability was found in SourceCodester Prison Management System 1.0. | 8.8 |
2024-04-09 | CVE-2024-3213 | Relevanssi | Missing Authorization vulnerability in Relevanssi The Relevanssi – A Better Search plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the relevanssi_update_counts() function in all versions up to, and including, 4.22.1. | 8.2 |
2024-04-11 | CVE-2023-50949 | IBM | Unspecified vulnerability in IBM Qradar Security Information and Event Manager 7.5.0 IBM QRadar SIEM 7.5 could allow an unauthorized user to perform unauthorized actions due to improper certificate validation. | 8.1 |
2024-04-10 | CVE-2024-31240 | Infotheme | Unspecified vulnerability in Infotheme WP Poll Maker Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in InfoTheme WP Poll Maker.This issue affects WP Poll Maker: from n/a through 3.1. | 8.1 |
2024-04-10 | CVE-2024-31871 | IBM | Unspecified vulnerability in IBM Security Verify Access IBM Security Verify Access Appliance 10.0.0 through 10.0.7 could allow a malicious actor to conduct a man in the middle attack when deploying Python scripts due to improper certificate validation. | 8.1 |
2024-04-10 | CVE-2024-31872 | IBM | Unspecified vulnerability in IBM Security Verify Access IBM Security Verify Access Appliance 10.0.0 through 10.0.7 could allow a malicious actor to conduct a man in the middle attack when deploying Open Source scripts due to missing certificate validation. | 8.1 |
2024-04-09 | CVE-2024-23671 | Fortinet | Unspecified vulnerability in Fortinet Fortisandbox A improper limitation of a pathname to a restricted directory ('path traversal') in Fortinet FortiSandbox version 4.4.0 through 4.4.3 and 4.2.0 through 4.2.6 and 4.0.0 through 4.0.4 allows attacker to execute unauthorized code or commands via crafted HTTP requests. | 8.1 |
2024-04-11 | CVE-2024-30271 | Adobe | Out-of-bounds Write vulnerability in Adobe Illustrator Illustrator versions 28.3, 27.9.2 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. | 7.8 |
2024-04-11 | CVE-2024-30272 | Adobe | Out-of-bounds Write vulnerability in Adobe Illustrator Illustrator versions 28.3, 27.9.2 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. | 7.8 |
2024-04-11 | CVE-2024-30273 | Adobe | Out-of-bounds Write vulnerability in Adobe Illustrator Illustrator versions 28.3, 27.9.2 and earlier are affected by a Stack-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. | 7.8 |
2024-04-11 | CVE-2024-20795 | Adobe | Integer Overflow or Wraparound vulnerability in Adobe Animate Animate versions 23.0.4, 24.0.1 and earlier are affected by an Integer Overflow or Wraparound vulnerability that could result in arbitrary code execution in the context of the current user. | 7.8 |
2024-04-11 | CVE-2024-20797 | Adobe | Out-of-bounds Read vulnerability in Adobe Animate Animate versions 23.0.4, 24.0.1 and earlier are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. | 7.8 |
2024-04-10 | CVE-2021-47194 | Linux | Improper Initialization vulnerability in Linux Kernel In the Linux kernel, the following vulnerability has been resolved: cfg80211: call cfg80211_stop_ap when switch from P2P_GO type If the userspace tools switch from NL80211_IFTYPE_P2P_GO to NL80211_IFTYPE_ADHOC via send_msg(NL80211_CMD_SET_INTERFACE), it does not call the cleanup cfg80211_stop_ap(), this leads to the initialization of in-use data. | 7.8 |
2024-04-10 | CVE-2021-47196 | Linux | Unspecified vulnerability in Linux Kernel In the Linux kernel, the following vulnerability has been resolved: RDMA/core: Set send and receive CQ before forwarding to the driver Preset both receive and send CQ pointers prior to call to the drivers and overwrite it later again till the mlx4 is going to be changed do not overwrite ibqp properties. This change is needed for mlx5, because in case of QP creation failure, it will go to the path of QP destroy which relies on proper CQ pointers. BUG: KASAN: use-after-free in create_qp.cold+0x164/0x16e [mlx5_ib] Write of size 8 at addr ffff8880064c55c0 by task a.out/246 CPU: 0 PID: 246 Comm: a.out Not tainted 5.15.0+ #291 Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS rel-1.13.0-0-gf21b5a4aeb02-prebuilt.qemu.org 04/01/2014 Call Trace: dump_stack_lvl+0x45/0x59 print_address_description.constprop.0+0x1f/0x140 kasan_report.cold+0x83/0xdf create_qp.cold+0x164/0x16e [mlx5_ib] mlx5_ib_create_qp+0x358/0x28a0 [mlx5_ib] create_qp.part.0+0x45b/0x6a0 [ib_core] ib_create_qp_user+0x97/0x150 [ib_core] ib_uverbs_handler_UVERBS_METHOD_QP_CREATE+0x92c/0x1250 [ib_uverbs] ib_uverbs_cmd_verbs+0x1c38/0x3150 [ib_uverbs] ib_uverbs_ioctl+0x169/0x260 [ib_uverbs] __x64_sys_ioctl+0x866/0x14d0 do_syscall_64+0x3d/0x90 entry_SYSCALL_64_after_hwframe+0x44/0xae Allocated by task 246: kasan_save_stack+0x1b/0x40 __kasan_kmalloc+0xa4/0xd0 create_qp.part.0+0x92/0x6a0 [ib_core] ib_create_qp_user+0x97/0x150 [ib_core] ib_uverbs_handler_UVERBS_METHOD_QP_CREATE+0x92c/0x1250 [ib_uverbs] ib_uverbs_cmd_verbs+0x1c38/0x3150 [ib_uverbs] ib_uverbs_ioctl+0x169/0x260 [ib_uverbs] __x64_sys_ioctl+0x866/0x14d0 do_syscall_64+0x3d/0x90 entry_SYSCALL_64_after_hwframe+0x44/0xae Freed by task 246: kasan_save_stack+0x1b/0x40 kasan_set_track+0x1c/0x30 kasan_set_free_info+0x20/0x30 __kasan_slab_free+0x10c/0x150 slab_free_freelist_hook+0xb4/0x1b0 kfree+0xe7/0x2a0 create_qp.part.0+0x52b/0x6a0 [ib_core] ib_create_qp_user+0x97/0x150 [ib_core] ib_uverbs_handler_UVERBS_METHOD_QP_CREATE+0x92c/0x1250 [ib_uverbs] ib_uverbs_cmd_verbs+0x1c38/0x3150 [ib_uverbs] ib_uverbs_ioctl+0x169/0x260 [ib_uverbs] __x64_sys_ioctl+0x866/0x14d0 do_syscall_64+0x3d/0x90 entry_SYSCALL_64_after_hwframe+0x44/0xae | 7.8 |
2024-04-10 | CVE-2021-47198 | Linux | Use After Free vulnerability in Linux Kernel In the Linux kernel, the following vulnerability has been resolved: scsi: lpfc: Fix use-after-free in lpfc_unreg_rpi() routine An error is detected with the following report when unloading the driver: "KASAN: use-after-free in lpfc_unreg_rpi+0x1b1b" The NLP_REG_LOGIN_SEND nlp_flag is set in lpfc_reg_fab_ctrl_node(), but the flag is not cleared upon completion of the login. This allows a second call to lpfc_unreg_rpi() to proceed with nlp_rpi set to LPFC_RPI_ALLOW_ERROR. | 7.8 |
2024-04-10 | CVE-2021-47200 | Linux | Use After Free vulnerability in Linux Kernel In the Linux kernel, the following vulnerability has been resolved: drm/prime: Fix use after free in mmap with drm_gem_ttm_mmap drm_gem_ttm_mmap() drops a reference to the gem object on success. | 7.8 |
2024-04-10 | CVE-2021-47204 | Linux | Use After Free vulnerability in Linux Kernel In the Linux kernel, the following vulnerability has been resolved: net: dpaa2-eth: fix use-after-free in dpaa2_eth_remove Access to netdev after free_netdev() will cause use-after-free bug. Move debug log before free_netdev() call to avoid it. | 7.8 |
2024-04-10 | CVE-2024-31492 | Fortinet | Unspecified vulnerability in Fortinet Forticlient An external control of file name or path vulnerability [CWE-73] in FortiClientMac version 7.2.3 and below, version 7.0.10 and below installer may allow a local attacker to execute arbitrary code or commands via writing a malicious configuration file in /tmp before starting the installation process. | 7.8 |
2024-04-10 | CVE-2024-22450 | Dell | Unspecified vulnerability in Dell Alienware Command Center Dell Alienware Command Center, versions prior to 6.2.7.0, contain an uncontrolled search path element vulnerability. | 7.8 |
2024-04-09 | CVE-2024-29050 | Microsoft | Improper Certificate Validation vulnerability in Microsoft products Windows Cryptographic Services Remote Code Execution Vulnerability | 7.8 |
2024-04-09 | CVE-2024-2871 | Davidlingren | SQL Injection vulnerability in Davidlingren Media Library Assistant The Media Library Assistant plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcode(s) in all versions up to, and including, 3.13 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. | 7.7 |
2024-04-12 | CVE-2024-30405 | Juniper | Incorrect Calculation of Buffer Size vulnerability in Juniper Junos An Incorrect Calculation of Buffer Size vulnerability in Juniper Networks Junos OS SRX 5000 Series devices using SPC2 line cards while ALGs are enabled allows an attacker sending specific crafted packets to cause a transit traffic Denial of Service (DoS). Continued receipt and processing of these specific packets will sustain the Denial of Service condition. This issue affects: Juniper Networks Junos OS SRX 5000 Series with SPC2 with ALGs enabled. * All versions earlier than 21.2R3-S7; * 21.4 versions earlier than 21.4R3-S6; * 22.1 versions earlier than 22.1R3-S5; * 22.2 versions earlier than 22.2R3-S3; * 22.3 versions earlier than 22.3R3-S2; * 22.4 versions earlier than 22.4R3; * 23.2 versions earlier than 23.2R2. | 7.5 |
2024-04-12 | CVE-2024-3686 | Dedecms | Path Traversal vulnerability in Dedecms 5.7.112 A vulnerability has been found in DedeCMS 5.7.112-UTF8 and classified as problematic. | 7.5 |
2024-04-11 | CVE-2024-2966 | Bdthemes | Unspecified vulnerability in Bdthemes Element Pack The Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 5.5.6 via the element_pack_ajax_search function. | 7.5 |
2024-04-10 | CVE-2024-29903 | Sigstore | Allocation of Resources Without Limits or Throttling vulnerability in Sigstore Cosign Cosign provides code signing and transparency for containers and binaries. | 7.5 |
2024-04-10 | CVE-2024-1902 | Lunary | Unspecified vulnerability in Lunary lunary-ai/lunary is vulnerable to a session reuse attack, allowing a removed user to change the organization name without proper authorization. | 7.5 |
2024-04-10 | CVE-2024-31343 | Sonaar | Unspecified vulnerability in Sonaar MP3 Audio Player for Music, Radio & Podcast Missing Authorization vulnerability in Sonaar Music MP3 Audio Player for Music, Radio & Podcast by Sonaar.This issue affects MP3 Audio Player for Music, Radio & Podcast by Sonaar: from n/a through 4.10.1. | 7.5 |
2024-04-10 | CVE-2024-3382 | Paloaltonetworks | Memory Leak vulnerability in Paloaltonetworks Pan-Os A memory leak exists in Palo Alto Networks PAN-OS software that enables an attacker to send a burst of crafted packets through the firewall that eventually prevents the firewall from processing traffic. | 7.5 |
2024-04-10 | CVE-2024-3384 | Paloaltonetworks | Unspecified vulnerability in Paloaltonetworks Pan-Os A vulnerability in Palo Alto Networks PAN-OS software enables a remote attacker to reboot PAN-OS firewalls when receiving Windows New Technology LAN Manager (NTLM) packets from Windows servers. | 7.5 |
2024-04-10 | CVE-2024-3385 | Paloaltonetworks | NULL Pointer Dereference vulnerability in Paloaltonetworks Pan-Os A packet processing mechanism in Palo Alto Networks PAN-OS software enables a remote attacker to reboot hardware-based firewalls. | 7.5 |
2024-04-10 | CVE-2024-31245 | Convertkit | Unspecified vulnerability in Convertkit - Email Marketing, Email Newsletter and Landing Pages Insertion of Sensitive Information into Log File vulnerability in ConvertKit.This issue affects ConvertKit: from n/a through 2.4.5. | 7.5 |
2024-04-10 | CVE-2024-31247 | Fredericgilles | Unspecified vulnerability in Fredericgilles FG Drupal Insertion of Sensitive Information into Log File vulnerability in Frédéric GILLES FG Drupal to WordPress.This issue affects FG Drupal to WordPress: from n/a through 3.70.3. | 7.5 |
2024-04-10 | CVE-2024-31249 | Wpkube | Unspecified vulnerability in Wpkube Subscribe to Comments Reloaded Insertion of Sensitive Information into Log File vulnerability in WPKube Subscribe To Comments Reloaded.This issue affects Subscribe To Comments Reloaded: from n/a through 220725. | 7.5 |
2024-04-10 | CVE-2024-31254 | Webtoffee | Unspecified vulnerability in Webtoffee Backup and Migration Insertion of Sensitive Information into Log File vulnerability in WebToffee WordPress Backup & Migration.This issue affects WordPress Backup & Migration: from n/a through 1.4.7. | 7.5 |
2024-04-10 | CVE-2024-31259 | Searchiq | Unspecified vulnerability in Searchiq Insertion of Sensitive Information into Log File vulnerability in Searchiq SearchIQ.This issue affects SearchIQ: from n/a through 4.5. | 7.5 |
2024-04-10 | CVE-2024-31298 | Joelhardi | Unspecified vulnerability in Joelhardi User Spam Remover Insertion of Sensitive Information into Log File vulnerability in Joel Hardi User Spam Remover.This issue affects User Spam Remover: from n/a through 1.0. | 7.5 |
2024-04-10 | CVE-2024-31873 | IBM | Unspecified vulnerability in IBM Security Verify Access IBM Security Verify Access Appliance 10.0.0 through 10.0.7 contains hard-coded credentials which it uses for its own inbound authentication that could be obtained by a malicious actor. | 7.5 |
2024-04-09 | CVE-2024-2112 | 10Web | Unspecified vulnerability in 10Web Form Maker The Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.15.22 via the signature functionality. | 7.5 |
2024-04-09 | CVE-2024-31506 | Tamparongj03 | SQL Injection vulnerability in Tamparongj03 Online Graduate Tracer System 1.0 Sourcecodester Online Graduate Tracer System v1.0 is vulnerable to SQL Injection via the "id" parameter in admin/admin_cs.php. | 7.5 |
2024-04-09 | CVE-2024-23662 | Fortinet | Unspecified vulnerability in Fortinet Fortios An exposure of sensitive information to an unauthorized actor in Fortinet FortiOS at least version at least 7.4.0 through 7.4.1 and 7.2.0 through 7.2.5 and 7.0.0 through 7.0.15 and 6.4.0 through 6.4.15 allows attacker to information disclosure via HTTP requests. | 7.5 |
2024-04-09 | CVE-2024-3046 | Eclipse | Unspecified vulnerability in Eclipse Kura In Eclipse Kura LogServlet component included in versions 5.0.0 to 5.4.1, a specifically crafted request to the servlet can allow an unauthenticated user to retrieve the device logs. | 7.5 |
2024-04-08 | CVE-2023-52386 | Huawei | Out-of-bounds Write vulnerability in Huawei Emui and Harmonyos Out-of-bounds write vulnerability in the RSMC module. Impact: Successful exploitation of this vulnerability will affect availability. | 7.5 |
2024-04-08 | CVE-2024-27895 | Huawei | Unspecified vulnerability in Huawei Harmonyos 4.0.0 Vulnerability of permission control in the window module. | 7.5 |
2024-04-08 | CVE-2023-52359 | Huawei | Unspecified vulnerability in Huawei Emui and Harmonyos Vulnerability of permission verification in some APIs in the ActivityTaskManagerService module. Impact: Successful exploitation of this vulnerability will affect availability. | 7.5 |
2024-04-08 | CVE-2023-52540 | Huawei | Unspecified vulnerability in Huawei Emui and Harmonyos Vulnerability of improper authentication in the Iaware module. Impact: Successful exploitation of this vulnerability will affect availability. | 7.5 |
2024-04-08 | CVE-2023-52546 | Huawei | Unspecified vulnerability in Huawei Emui and Harmonyos Vulnerability of package name verification being bypassed in the Calendar app. Impact: Successful exploitation of this vulnerability may affect service confidentiality. | 7.5 |
2024-04-11 | CVE-2024-3621 | Mayurik | Unspecified vulnerability in Mayurik Advocate Office Management System 1.0 A vulnerability was found in SourceCodester Kortex Lite Advocate Office Management System 1.0. | 7.2 |
2024-04-11 | CVE-2024-3618 | Mayurik | Unspecified vulnerability in Mayurik Advocate Office Management System 1.0 A vulnerability, which was classified as critical, was found in SourceCodester Kortex Lite Advocate Office Management System 1.0. | 7.2 |
2024-04-11 | CVE-2024-3619 | Mayurik | Unspecified vulnerability in Mayurik Advocate Office Management System 1.0 A vulnerability has been found in SourceCodester Kortex Lite Advocate Office Management System 1.0 and classified as critical. | 7.2 |
2024-04-11 | CVE-2024-3620 | Mayurik | Unspecified vulnerability in Mayurik Advocate Office Management System 1.0 A vulnerability was found in SourceCodester Kortex Lite Advocate Office Management System 1.0 and classified as critical. | 7.2 |
2024-04-11 | CVE-2024-3617 | Mayurik | Unspecified vulnerability in Mayurik Advocate Office Management System 1.0 A vulnerability, which was classified as critical, has been found in SourceCodester Kortex Lite Advocate Office Management System 1.0. | 7.2 |
2024-04-09 | CVE-2023-6318 | LG | Unspecified vulnerability in LG Webos 5.5.0/6.3.3442/7.3.143 A command injection vulnerability exists in the processAnalyticsReport method from the com.webos.service.cloudupload service on webOS version 5 through 7. | 7.2 |
2024-04-09 | CVE-2023-6319 | LG | Unspecified vulnerability in LG Webos A command injection vulnerability exists in the getAudioMetadata method from the com.webos.service.attachedstoragemanager service on webOS version 4 through 7. | 7.2 |
2024-04-09 | CVE-2023-6320 | LG | Unspecified vulnerability in LG Webos 5.5.0/6.3.3442 A command injection vulnerability exists in the com.webos.service.connectionmanager/tv/setVlanStaticAddress endpoint on webOS versions 5 and 6. | 7.2 |
2024-04-08 | CVE-2024-3440 | Fast5 | Unspecified vulnerability in Fast5 Prison Management System 1.0 A vulnerability was found in SourceCodester Prison Management System 1.0. | 7.2 |
2024-04-08 | CVE-2024-3436 | Fast5 | Unspecified vulnerability in Fast5 Prison Management System 1.0 A vulnerability was found in SourceCodester Prison Management System 1.0. | 7.2 |
2024-04-08 | CVE-2024-3437 | Fast5 | Unspecified vulnerability in Fast5 Prison Management System 1.0 A vulnerability was found in SourceCodester Prison Management System 1.0. | 7.2 |
2024-04-11 | CVE-2024-30916 | Eprosima | Unspecified vulnerability in Eprosima Fast DDS An issue was discovered in eProsima FastDDS v.2.14.0 and before, allows a local attacker to cause a denial of service (DoS) and obtain sensitive information via a crafted max_samples parameter in DurabilityService QoS component. | 7.1 |
2024-04-10 | CVE-2021-47191 | Linux | Out-of-bounds Read vulnerability in Linux Kernel In the Linux kernel, the following vulnerability has been resolved: scsi: scsi_debug: Fix out-of-bound read in resp_readcap16() The following warning was observed running syzkaller: [ 3813.830724] sg_write: data in/out 65466/242 bytes for SCSI command 0x9e-- guessing data in; [ 3813.830724] program syz-executor not setting count and/or reply_len properly [ 3813.836956] ================================================================== [ 3813.839465] BUG: KASAN: stack-out-of-bounds in sg_copy_buffer+0x157/0x1e0 [ 3813.841773] Read of size 4096 at addr ffff8883cf80f540 by task syz-executor/1549 [ 3813.846612] Call Trace: [ 3813.846995] dump_stack+0x108/0x15f [ 3813.847524] print_address_description+0xa5/0x372 [ 3813.848243] kasan_report.cold+0x236/0x2a8 [ 3813.849439] check_memory_region+0x240/0x270 [ 3813.850094] memcpy+0x30/0x80 [ 3813.850553] sg_copy_buffer+0x157/0x1e0 [ 3813.853032] sg_copy_from_buffer+0x13/0x20 [ 3813.853660] fill_from_dev_buffer+0x135/0x370 [ 3813.854329] resp_readcap16+0x1ac/0x280 [ 3813.856917] schedule_resp+0x41f/0x1630 [ 3813.858203] scsi_debug_queuecommand+0xb32/0x17e0 [ 3813.862699] scsi_dispatch_cmd+0x330/0x950 [ 3813.863329] scsi_request_fn+0xd8e/0x1710 [ 3813.863946] __blk_run_queue+0x10b/0x230 [ 3813.864544] blk_execute_rq_nowait+0x1d8/0x400 [ 3813.865220] sg_common_write.isra.0+0xe61/0x2420 [ 3813.871637] sg_write+0x6c8/0xef0 [ 3813.878853] __vfs_write+0xe4/0x800 [ 3813.883487] vfs_write+0x17b/0x530 [ 3813.884008] ksys_write+0x103/0x270 [ 3813.886268] __x64_sys_write+0x77/0xc0 [ 3813.886841] do_syscall_64+0x106/0x360 [ 3813.887415] entry_SYSCALL_64_after_hwframe+0x44/0xa9 This issue can be reproduced with the following syzkaller log: r0 = openat(0xffffffffffffff9c, &(0x7f0000000040)='./file0\x00', 0x26e1, 0x0) r1 = syz_open_procfs(0xffffffffffffffff, &(0x7f0000000000)='fd/3\x00') open_by_handle_at(r1, &(0x7f00000003c0)=ANY=[@ANYRESHEX], 0x602000) r2 = syz_open_dev$sg(&(0x7f0000000000), 0x0, 0x40782) write$binfmt_aout(r2, &(0x7f0000000340)=ANY=[@ANYBLOB="00000000deff000000000000000000000000000000000000000000000000000047f007af9e107a41ec395f1bded7be24277a1501ff6196a83366f4e6362bc0ff2b247f68a972989b094b2da4fb3607fcf611a22dd04310d28c75039d"], 0x126) In resp_readcap16() we get "int alloc_len" value -1104926854, and then pass the huge arr_len to fill_from_dev_buffer(), but arr is only 32 bytes. | 7.1 |
2024-04-10 | CVE-2021-47219 | Linux | Unspecified vulnerability in Linux Kernel In the Linux kernel, the following vulnerability has been resolved: scsi: scsi_debug: Fix out-of-bound read in resp_report_tgtpgs() The following issue was observed running syzkaller: BUG: KASAN: slab-out-of-bounds in memcpy include/linux/string.h:377 [inline] BUG: KASAN: slab-out-of-bounds in sg_copy_buffer+0x150/0x1c0 lib/scatterlist.c:831 Read of size 2132 at addr ffff8880aea95dc8 by task syz-executor.0/9815 CPU: 0 PID: 9815 Comm: syz-executor.0 Not tainted 4.19.202-00874-gfc0fe04215a9 #2 Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.10.2-1ubuntu1 04/01/2014 Call Trace: __dump_stack lib/dump_stack.c:77 [inline] dump_stack+0xe4/0x14a lib/dump_stack.c:118 print_address_description+0x73/0x280 mm/kasan/report.c:253 kasan_report_error mm/kasan/report.c:352 [inline] kasan_report+0x272/0x370 mm/kasan/report.c:410 memcpy+0x1f/0x50 mm/kasan/kasan.c:302 memcpy include/linux/string.h:377 [inline] sg_copy_buffer+0x150/0x1c0 lib/scatterlist.c:831 fill_from_dev_buffer+0x14f/0x340 drivers/scsi/scsi_debug.c:1021 resp_report_tgtpgs+0x5aa/0x770 drivers/scsi/scsi_debug.c:1772 schedule_resp+0x464/0x12f0 drivers/scsi/scsi_debug.c:4429 scsi_debug_queuecommand+0x467/0x1390 drivers/scsi/scsi_debug.c:5835 scsi_dispatch_cmd+0x3fc/0x9b0 drivers/scsi/scsi_lib.c:1896 scsi_request_fn+0x1042/0x1810 drivers/scsi/scsi_lib.c:2034 __blk_run_queue_uncond block/blk-core.c:464 [inline] __blk_run_queue+0x1a4/0x380 block/blk-core.c:484 blk_execute_rq_nowait+0x1c2/0x2d0 block/blk-exec.c:78 sg_common_write.isra.19+0xd74/0x1dc0 drivers/scsi/sg.c:847 sg_write.part.23+0x6e0/0xd00 drivers/scsi/sg.c:716 sg_write+0x64/0xa0 drivers/scsi/sg.c:622 __vfs_write+0xed/0x690 fs/read_write.c:485 kill_bdev:block_device:00000000e138492c vfs_write+0x184/0x4c0 fs/read_write.c:549 ksys_write+0x107/0x240 fs/read_write.c:599 do_syscall_64+0xc2/0x560 arch/x86/entry/common.c:293 entry_SYSCALL_64_after_hwframe+0x49/0xbe We get 'alen' from command its type is int. | 7.1 |
2024-04-09 | CVE-2024-30262 | Contao | Insufficient Session Expiration vulnerability in Contao Contao is an open source content management system. | 7.1 |
198 Medium Vulnerabilities
DATE | CVE | VENDOR | VULNERABILITY | CVSS |
---|---|---|---|---|
2024-04-12 | CVE-2024-27261 | IBM | Unspecified vulnerability in IBM Storage Defender Resiliency Service 2.0 IBM Storage Defender - Resiliency Service 2.0.0 through 2.0.2 could allow a privileged user to install a potentially dangerous tar file, which could give them access to subsequent systems where the package was installed. | 6.8 |
2024-04-09 | CVE-2024-20665 | Microsoft | Unspecified vulnerability in Microsoft products BitLocker Security Feature Bypass Vulnerability | 6.7 |
2024-04-09 | CVE-2023-47540 | Fortinet | Unspecified vulnerability in Fortinet Fortisandbox An improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiSandbox version 4.4.0 through 4.4.2 and 4.2.0 through 4.2.6 and 4.0.0 through 4.0.5 and 3.2.0 through 3.2.4 and 3.0.5 through 3.0.7 may allows attacker to execute unauthorized code or commands via CLI. | 6.7 |
2024-04-09 | CVE-2023-47541 | Fortinet | Unspecified vulnerability in Fortinet Fortisandbox An improper limitation of a pathname to a restricted directory ('path traversal') in Fortinet FortiSandbox version 4.4.0 through 4.4.2 and 4.2.0 through 4.2.6 and 4.0.0 through 4.0.5 and 3.2.0 through 3.2.4 and 3.1.0 through 3.1.5 and 3.0.0 through 3.0.7 and 2.5.0 through 2.5.2 and 2.4.0 through 2.4.1 and 2.3.0 through 2.3.3 and 2.2.0 through 2.2.2 and 2.1.0 through 2.1.3 and 2.0.0 through 2.0.3 allows attacker to execute unauthorized code or commands via CLI. | 6.7 |
2024-04-09 | CVE-2023-47542 | Fortinet | Code Injection vulnerability in Fortinet Fortimanager A improper neutralization of special elements used in a template engine [CWE-1336] in FortiManager versions 7.4.1 and below, versions 7.2.4 and below, and 7.0.10 and below allows attacker to execute unauthorized code or commands via specially crafted templates. | 6.7 |
2024-04-09 | CVE-2023-48784 | Fortinet | Unspecified vulnerability in Fortinet Fortios A use of externally-controlled format string vulnerability [CWE-134] in FortiOS version 7.4.1 and below, version 7.2.7 and below, 7.0 all versions, 6.4 all versions command line interface may allow a local privileged attacker with super-admin profile and CLI access to execute arbitrary code or commands via specially crafted requests. | 6.7 |
2024-04-09 | CVE-2024-26221 | Microsoft | Information Exposure Through Discrepancy vulnerability in Microsoft products Windows DNS Server Remote Code Execution Vulnerability | 6.6 |
2024-04-09 | CVE-2024-26222 | Microsoft | Unspecified vulnerability in Microsoft products Windows DNS Server Remote Code Execution Vulnerability | 6.6 |
2024-04-09 | CVE-2024-26223 | Microsoft | Unspecified vulnerability in Microsoft products Windows DNS Server Remote Code Execution Vulnerability | 6.6 |
2024-04-09 | CVE-2024-26224 | Microsoft | Unspecified vulnerability in Microsoft products Windows DNS Server Remote Code Execution Vulnerability | 6.6 |
2024-04-09 | CVE-2024-26227 | Microsoft | Unspecified vulnerability in Microsoft products Windows DNS Server Remote Code Execution Vulnerability | 6.6 |
2024-04-09 | CVE-2024-26231 | Microsoft | Unspecified vulnerability in Microsoft products Windows DNS Server Remote Code Execution Vulnerability | 6.6 |
2024-04-09 | CVE-2024-26233 | Microsoft | Unspecified vulnerability in Microsoft products Windows DNS Server Remote Code Execution Vulnerability | 6.6 |
2024-04-12 | CVE-2024-0157 | Dell | Session Fixation vulnerability in Dell products Dell Storage Resource Manager, 4.9.0.0 and below, contain(s) a Session Fixation Vulnerability in SRM Windows Host Agent. | 6.5 |
2024-04-12 | CVE-2024-21590 | Juniper | Unspecified vulnerability in Juniper Junos OS Evolved An Improper Input Validation vulnerability in Juniper Tunnel Driver (jtd) and ICMP module of Juniper Networks Junos OS Evolved allows an unauthenticated attacker within the MPLS administrative domain to send specifically crafted packets to the Routing Engine (RE) to cause a Denial of Service (DoS). When specifically crafted transit MPLS IPv4 packets are received by the Packet Forwarding Engine (PFE), these packets are internally forwarded to the RE. Continued receipt of these packets may create a sustained Denial of Service (DoS) condition. This issue affects Juniper Networks Junos OS: * All versions before 21.2R3-S8-EVO; * from 21.4-EVO before 21.4R3-S6-EVO; * from 22.2-EVO before 22.2R3-S4-EVO; * from 22.3-EVO before 22.3R3-S3-EVO; * from 22.4-EVO before 22.4R3-EVO; * from 23.2-EVO before 23.2R2-EVO. * from 23.4-EVO before 23.4R1-S1-EVO. | 6.5 |
2024-04-12 | CVE-2024-21609 | Juniper | Memory Leak vulnerability in Juniper Junos A Missing Release of Memory after Effective Lifetime vulnerability in the IKE daemon (iked) of Juniper Networks Junos OS on MX Series with SPC3, and SRX Series allows an administratively adjacent attacker which is able to successfully establish IPsec tunnels to cause a Denial of Service (DoS). If specific values for the IPsec parameters local-ip, remote-ip, remote ike-id, and traffic selectors are sent from the peer, a memory leak occurs during every IPsec SA rekey which is carried out with a specific message sequence. | 6.5 |
2024-04-12 | CVE-2023-6489 | Gitlab | Unspecified vulnerability in Gitlab A denial of service vulnerability was identified in GitLab CE/EE, versions 16.7.7 prior to 16.8.6, 16.9 prior to 16.9.4 and 16.10 prior to 16.10.2 which allows an attacker to spike the GitLab instance resources usage resulting in service degradation via chat integration feature. | 6.5 |
2024-04-12 | CVE-2023-6678 | Gitlab | Unspecified vulnerability in Gitlab An issue has been discovered in GitLab EE affecting all versions before 16.8.6, all versions starting from 16.9 before 16.9.4, all versions starting from 16.10 before 16.10.2. | 6.5 |
2024-04-10 | CVE-2024-3515 | Google Fedoraproject | Use After Free vulnerability in multiple products Use after free in Dawn in Google Chrome prior to 123.0.6312.122 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | 6.5 |
2024-04-10 | CVE-2024-3516 | Google Fedoraproject | Out-of-bounds Write vulnerability in multiple products Heap buffer overflow in ANGLE in Google Chrome prior to 123.0.6312.122 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | 6.5 |
2024-04-10 | CVE-2024-1625 | Lunary | Authorization Bypass Through User-Controlled Key vulnerability in Lunary 0.3.0 An Insecure Direct Object Reference (IDOR) vulnerability exists in the lunary-ai/lunary application version 0.3.0, allowing unauthorized deletion of any organization's project. | 6.5 |
2024-04-10 | CVE-2024-31278 | Leap13 | Insecure Storage of Sensitive Information vulnerability in Leap13 Premium Addons for Elementor Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Leap13 Premium Addons for Elementor.This issue affects Premium Addons for Elementor: from n/a through 4.10.22. | 6.5 |
2024-04-10 | CVE-2024-31287 | Maxfoundry | Unspecified vulnerability in Maxfoundry Media Library Folders Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Max Foundry Media Library Folders.This issue affects Media Library Folders: from n/a through 8.1.8. | 6.5 |
2024-04-09 | CVE-2023-6695 | Fastlinemedia | Unspecified vulnerability in Fastlinemedia Beaver Themer The Beaver Themer plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.4.9 via the 'wpbb' shortcode. | 6.5 |
2024-04-09 | CVE-2023-6777 | Codecabin | Unspecified vulnerability in Codecabin WP GO Maps The WP Go Maps (formerly WP Google Maps) plugin for WordPress is vulnerable to unauthenticated API key disclosure in versions up to, and including, 9.0.34 due to the plugin adding the API key to several plugin files. | 6.5 |
2024-04-09 | CVE-2024-1974 | Hasthemes | Path Traversal vulnerability in Hasthemes HT Mega The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.4.6 via the render function. | 6.5 |
2024-04-09 | CVE-2024-2341 | Nsquared | SQL Injection vulnerability in Nsquared Simply Schedule Appointments The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to SQL Injection via the keys parameter in all versions up to, and including, 1.6.7.7 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. | 6.5 |
2024-04-09 | CVE-2024-28235 | Contao | Unspecified vulnerability in Contao Contao is an open source content management system. | 6.5 |
2024-04-09 | CVE-2024-31487 | Fortinet | Unspecified vulnerability in Fortinet Fortisandbox A improper limitation of a pathname to a restricted directory ('path traversal') in Fortinet FortiSandbox version 4.4.0 through 4.4.4 and 4.2.0 through 4.2.6 and 4.0.0 through 4.0.5 and 3.2.0 through 3.2.4 and 3.1.0 through 3.1.5 and 3.0.0 through 3.0.7 and 2.5.0 through 2.5.2 and 2.4.0 through 2.4.1 may allows attacker to information disclosure via crafted http requests. | 6.5 |
2024-04-09 | CVE-2023-6964 | Kadencewp | Server-Side Request Forgery (SSRF) vulnerability in Kadencewp Gutenberg Blocks With AI The Gutenberg Blocks by Kadence Blocks – Page Builder Features plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 3.1.26 via the 'kadence_import_get_new_connection_data' AJAX action. | 6.4 |
2024-04-09 | CVE-2024-3167 | Oceanwp | Cross-site Scripting vulnerability in Oceanwp Ocean Extra The Ocean Extra plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘twitter_username’ parameter in versions up to, and including, 2.2.6 due to insufficient input sanitization and output escaping. | 6.4 |
2024-04-12 | CVE-2024-22359 | IBM | Unspecified vulnerability in IBM Urbancode Deploy IBM UrbanCode Deploy (UCD) 7.0 through 7.0.5.20, 7.1 through 7.1.2.16, 7.2 through 7.2.3.9, 7.3 through 7.3.2.4 and IBM DevOps Deploy 8.0 through 8.0.0.1 are vulnerable to cross-site scripting. | 6.1 |
2024-04-10 | CVE-2024-31253 | WP Oauth | Unspecified vulnerability in Wp-Oauth WP Oauth Server URL Redirection to Untrusted Site ('Open Redirect') vulnerability in WP OAuth Server OAuth Server.This issue affects OAuth Server: from n/a through 4.3.3. | 6.1 |
2024-04-10 | CVE-2024-31282 | Appcheap | Unspecified vulnerability in Appcheap APP Builder URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Appcheap.Io App Builder.This issue affects App Builder: from n/a through 3.8.7. | 6.1 |
2024-04-10 | CVE-2024-3541 | Campcodes | Unspecified vulnerability in Campcodes Church Management System 1.0 A vulnerability classified as problematic has been found in Campcodes Church Management System 1.0. | 6.1 |
2024-04-10 | CVE-2024-3542 | Campcodes | Unspecified vulnerability in Campcodes Church Management System 1.0 A vulnerability classified as problematic was found in Campcodes Church Management System 1.0. | 6.1 |
2024-04-10 | CVE-2024-3531 | Campcodes | Unspecified vulnerability in Campcodes Online Student Management System 1.0 A vulnerability was found in Campcodes Complete Online Student Management System 1.0. | 6.1 |
2024-04-10 | CVE-2024-3532 | Campcodes | Unspecified vulnerability in Campcodes Online Student Management System 1.0 A vulnerability classified as problematic has been found in Campcodes Complete Online Student Management System 1.0. | 6.1 |
2024-04-10 | CVE-2024-3533 | Campcodes | Unspecified vulnerability in Campcodes Online Student Management System 1.0 A vulnerability classified as problematic was found in Campcodes Complete Online Student Management System 1.0. | 6.1 |
2024-04-10 | CVE-2024-3528 | Campcodes | Unspecified vulnerability in Campcodes Online Student Management System 1.0 A vulnerability was found in Campcodes Complete Online Student Management System 1.0 and classified as problematic. | 6.1 |
2024-04-10 | CVE-2024-3529 | Campcodes | Unspecified vulnerability in Campcodes Online Student Management System 1.0 A vulnerability was found in Campcodes Complete Online Student Management System 1.0. | 6.1 |
2024-04-10 | CVE-2024-3530 | Campcodes | Unspecified vulnerability in Campcodes Online Student Management System 1.0 A vulnerability was found in Campcodes Complete Online Student Management System 1.0. | 6.1 |
2024-04-09 | CVE-2024-1412 | Caseproof | Cross-site Scripting vulnerability in Caseproof Memberpress The Memberpress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘message’ and 'error' parameters in all versions up to, and including, 1.11.26 due to insufficient input sanitization and output escaping. | 6.1 |
2024-04-09 | CVE-2024-1794 | Incsub | Cross-site Scripting vulnerability in Incsub Forminator The Forminator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via an uploaded file (e.g. | 6.1 |
2024-04-09 | CVE-2024-1852 | Butlerblog | Cross-site Scripting vulnerability in Butlerblog Wp-Members The WP-Members Membership Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the X-Forwarded-For header in all versions up to, and including, 3.4.9.2 due to insufficient input sanitization and output escaping. | 6.1 |
2024-04-08 | CVE-2011-10006 | Lesterchan | Unspecified vulnerability in Lesterchan Wp-Postratings A vulnerability was found in GamerZ WP-PostRatings up to 1.64. | 6.1 |
2024-04-08 | CVE-2023-52345 | Unspecified vulnerability in Google Android 12.0/13.0/14.0 In modem driver, there is a possible system crash due to improper input validation. | 6.0 | |
2024-04-10 | CVE-2024-29902 | Sigstore | Allocation of Resources Without Limits or Throttling vulnerability in Sigstore Cosign Cosign provides code signing and transparency for containers and binaries. | 5.9 |
2024-04-09 | CVE-2023-6799 | Webfactoryltd | Unspecified vulnerability in Webfactoryltd WP Reset The WP Reset – Most Advanced WordPress Reset Tool plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.0 via the use of insufficiently random snapshot names. | 5.9 |
2024-04-13 | CVE-2024-26817 | Linux Debian | Integer Overflow or Wraparound vulnerability in multiple products In the Linux kernel, the following vulnerability has been resolved: amdkfd: use calloc instead of kzalloc to avoid integer overflow This uses calloc instead of doing the multiplication which might overflow. | 5.5 |
2024-04-11 | CVE-2024-20794 | Adobe | NULL Pointer Dereference vulnerability in Adobe Animate Animate versions 23.0.4, 24.0.1 and earlier are affected by a NULL Pointer Dereference vulnerability that could lead to an application denial-of-service. | 5.5 |
2024-04-11 | CVE-2024-20796 | Adobe | Out-of-bounds Read vulnerability in Adobe Animate Animate versions 23.0.4, 24.0.1 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. | 5.5 |
2024-04-11 | CVE-2024-20798 | Adobe | Out-of-bounds Read vulnerability in Adobe Illustrator Illustrator versions 28.3, 27.9.2 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. | 5.5 |
2024-04-10 | CVE-2021-47181 | Linux | NULL Pointer Dereference vulnerability in Linux Kernel In the Linux kernel, the following vulnerability has been resolved: usb: musb: tusb6010: check return value after calling platform_get_resource() It will cause null-ptr-deref if platform_get_resource() returns NULL, we need check the return value. | 5.5 |
2024-04-10 | CVE-2021-47182 | Linux | Allocation of Resources Without Limits or Throttling vulnerability in Linux Kernel In the Linux kernel, the following vulnerability has been resolved: scsi: core: Fix scsi_mode_sense() buffer length handling Several problems exist with scsi_mode_sense() buffer length handling: 1) The allocation length field of the MODE SENSE(10) command is 16-bits, occupying bytes 7 and 8 of the CDB. | 5.5 |
2024-04-10 | CVE-2021-47183 | Linux | NULL Pointer Dereference vulnerability in Linux Kernel In the Linux kernel, the following vulnerability has been resolved: scsi: lpfc: Fix link down processing to address NULL pointer dereference If an FC link down transition while PLOGIs are outstanding to fabric well known addresses, outstanding ABTS requests may result in a NULL pointer dereference. | 5.5 |
2024-04-10 | CVE-2021-47184 | Linux | NULL Pointer Dereference vulnerability in Linux Kernel In the Linux kernel, the following vulnerability has been resolved: i40e: Fix NULL ptr dereference on VSI filter sync Remove the reason of null pointer dereference in sync VSI filters. Added new I40E_VSI_RELEASING flag to signalize deleting and releasing of VSI resources to sync this thread with sync filters subtask. Without this patch it is possible to start update the VSI filter list after VSI is removed, that's causing a kernel oops. | 5.5 |
2024-04-10 | CVE-2021-47186 | Linux | Unspecified vulnerability in Linux Kernel In the Linux kernel, the following vulnerability has been resolved: tipc: check for null after calling kmemdup kmemdup can return a null pointer so need to check for it, otherwise the null key will be dereferenced later in tipc_crypto_key_xmit as can be seen in the trace [1]. [1] https://syzkaller.appspot.com/bug?id=bca180abb29567b189efdbdb34cbf7ba851c2a58 | 5.5 |
2024-04-10 | CVE-2021-47187 | Linux | Unspecified vulnerability in Linux Kernel In the Linux kernel, the following vulnerability has been resolved: arm64: dts: qcom: msm8998: Fix CPU/L2 idle state latency and residency The entry/exit latency and minimum residency in state for the idle states of MSM8998 were ..bad: first of all, for all of them the timings were written for CPU sleep but the min-residency-us param was miscalculated (supposedly, while porting this from downstream); Then, the power collapse states are setting PC on both the CPU cluster *and* the L2 cache, which have different timings: in the specific case of L2 the times are higher so these ones should be taken into account instead of the CPU ones. This parameter misconfiguration was not giving particular issues because on MSM8998 there was no CPU scaling at all, so cluster/L2 power collapse was rarely (if ever) hit. When CPU scaling is enabled, though, the wrong timings will produce SoC unstability shown to the user as random, apparently error-less, sudden reboots and/or lockups. This set of parameters are stabilizing the SoC when CPU scaling is ON and when power collapse is frequently hit. | 5.5 |
2024-04-10 | CVE-2021-47188 | Linux | Unspecified vulnerability in Linux Kernel In the Linux kernel, the following vulnerability has been resolved: scsi: ufs: core: Improve SCSI abort handling The following has been observed on a test setup: WARNING: CPU: 4 PID: 250 at drivers/scsi/ufs/ufshcd.c:2737 ufshcd_queuecommand+0x468/0x65c Call trace: ufshcd_queuecommand+0x468/0x65c scsi_send_eh_cmnd+0x224/0x6a0 scsi_eh_test_devices+0x248/0x418 scsi_eh_ready_devs+0xc34/0xe58 scsi_error_handler+0x204/0x80c kthread+0x150/0x1b4 ret_from_fork+0x10/0x30 That warning is triggered by the following statement: WARN_ON(lrbp->cmd); Fix this warning by clearing lrbp->cmd from the abort handler. | 5.5 |
2024-04-10 | CVE-2021-47190 | Linux | Memory Leak vulnerability in Linux Kernel In the Linux kernel, the following vulnerability has been resolved: perf bpf: Avoid memory leak from perf_env__insert_btf() perf_env__insert_btf() doesn't insert if a duplicate BTF id is encountered and this causes a memory leak. | 5.5 |
2024-04-10 | CVE-2021-47193 | Linux | Memory Leak vulnerability in Linux Kernel In the Linux kernel, the following vulnerability has been resolved: scsi: pm80xx: Fix memory leak during rmmod Driver failed to release all memory allocated. | 5.5 |
2024-04-10 | CVE-2021-47195 | Linux | Use After Free vulnerability in Linux Kernel In the Linux kernel, the following vulnerability has been resolved: spi: fix use-after-free of the add_lock mutex Commit 6098475d4cb4 ("spi: Fix deadlock when adding SPI controllers on SPI buses") introduced a per-controller mutex. | 5.5 |
2024-04-10 | CVE-2021-47197 | Linux | Unspecified vulnerability in Linux Kernel In the Linux kernel, the following vulnerability has been resolved: net/mlx5e: nullify cq->dbg pointer in mlx5_debug_cq_remove() Prior to this patch in case mlx5_core_destroy_cq() failed it proceeds to rest of destroy operations. | 5.5 |
2024-04-10 | CVE-2021-47199 | Linux | Memory Leak vulnerability in Linux Kernel In the Linux kernel, the following vulnerability has been resolved: net/mlx5e: CT, Fix multiple allocations and memleak of mod acts CT clear action offload adds additional mod hdr actions to the flow's original mod actions in order to clear the registers which hold ct_state. When such flow also includes encap action, a neigh update event can cause the driver to unoffload the flow and then reoffload it. Each time this happens, the ct clear handling adds that same set of mod hdr actions to reset ct_state until the max of mod hdr actions is reached. Also the driver never releases the allocated mod hdr actions and causing a memleak. Fix above two issues by moving CT clear mod acts allocation into the parsing actions phase and only use it when offloading the rule. The release of mod acts will be done in the normal flow_put(). backtrace: [<000000007316e2f3>] krealloc+0x83/0xd0 [<00000000ef157de1>] mlx5e_mod_hdr_alloc+0x147/0x300 [mlx5_core] [<00000000970ce4ae>] mlx5e_tc_match_to_reg_set_and_get_id+0xd7/0x240 [mlx5_core] [<0000000067c5fa17>] mlx5e_tc_match_to_reg_set+0xa/0x20 [mlx5_core] [<00000000d032eb98>] mlx5_tc_ct_entry_set_registers.isra.0+0x36/0xc0 [mlx5_core] [<00000000fd23b869>] mlx5_tc_ct_flow_offload+0x272/0x1f10 [mlx5_core] [<000000004fc24acc>] mlx5e_tc_offload_fdb_rules.part.0+0x150/0x620 [mlx5_core] [<00000000dc741c17>] mlx5e_tc_encap_flows_add+0x489/0x690 [mlx5_core] [<00000000e92e49d7>] mlx5e_rep_update_flows+0x6e4/0x9b0 [mlx5_core] [<00000000f60f5602>] mlx5e_rep_neigh_update+0x39a/0x5d0 [mlx5_core] | 5.5 |
2024-04-10 | CVE-2021-47201 | Linux | Unspecified vulnerability in Linux Kernel In the Linux kernel, the following vulnerability has been resolved: iavf: free q_vectors before queues in iavf_disable_vf iavf_free_queues() clears adapter->num_active_queues, which iavf_free_q_vectors() relies on, so swap the order of these two function calls in iavf_disable_vf(). | 5.5 |
2024-04-10 | CVE-2021-47202 | Linux | NULL Pointer Dereference vulnerability in Linux Kernel In the Linux kernel, the following vulnerability has been resolved: thermal: Fix NULL pointer dereferences in of_thermal_ functions of_parse_thermal_zones() parses the thermal-zones node and registers a thermal_zone device for each subnode. | 5.5 |
2024-04-10 | CVE-2021-47203 | Linux | Out-of-bounds Write vulnerability in Linux Kernel In the Linux kernel, the following vulnerability has been resolved: scsi: lpfc: Fix list_add() corruption in lpfc_drain_txq() When parsing the txq list in lpfc_drain_txq(), the driver attempts to pass the requests to the adapter. | 5.5 |
2024-04-10 | CVE-2021-47205 | Linux | Unspecified vulnerability in Linux Kernel In the Linux kernel, the following vulnerability has been resolved: clk: sunxi-ng: Unregister clocks/resets when unbinding Currently, unbinding a CCU driver unmaps the device's MMIO region, while leaving its clocks/resets and their providers registered. | 5.5 |
2024-04-10 | CVE-2021-47206 | Linux | NULL Pointer Dereference vulnerability in Linux Kernel In the Linux kernel, the following vulnerability has been resolved: usb: host: ohci-tmio: check return value after calling platform_get_resource() It will cause null-ptr-deref if platform_get_resource() returns NULL, we need check the return value. | 5.5 |
2024-04-10 | CVE-2021-47207 | Linux | NULL Pointer Dereference vulnerability in Linux Kernel In the Linux kernel, the following vulnerability has been resolved: ALSA: gus: fix null pointer dereference on pointer block The pointer block return from snd_gf1_dma_next_block could be null, so there is a potential null pointer dereference issue. Fix this by adding a null check before dereference. | 5.5 |
2024-04-10 | CVE-2021-47209 | Linux | Use After Free vulnerability in Linux Kernel In the Linux kernel, the following vulnerability has been resolved: sched/fair: Prevent dead task groups from regaining cfs_rq's Kevin is reporting crashes which point to a use-after-free of a cfs_rq in update_blocked_averages(). | 5.5 |
2024-04-10 | CVE-2021-47210 | Linux | Out-of-bounds Read vulnerability in Linux Kernel In the Linux kernel, the following vulnerability has been resolved: usb: typec: tipd: Remove WARN_ON in tps6598x_block_read Calling tps6598x_block_read with a higher than allowed len can be handled by just returning an error. | 5.5 |
2024-04-10 | CVE-2021-47211 | Linux | NULL Pointer Dereference vulnerability in Linux Kernel In the Linux kernel, the following vulnerability has been resolved: ALSA: usb-audio: fix null pointer dereference on pointer cs_desc The pointer cs_desc return from snd_usb_find_clock_source could be null, so there is a potential null pointer dereference issue. Fix this by adding a null check before dereference. | 5.5 |
2024-04-10 | CVE-2021-47212 | Linux | Unspecified vulnerability in Linux Kernel In the Linux kernel, the following vulnerability has been resolved: net/mlx5: Update error handler for UCTX and UMEM In the fast unload flow, the device state is set to internal error, which indicates that the driver started the destroy process. In this case, when a destroy command is being executed, it should return MLX5_CMD_STAT_OK. Fix MLX5_CMD_OP_DESTROY_UCTX and MLX5_CMD_OP_DESTROY_UMEM to return OK instead of EIO. This fixes a call trace in the umem release process - [ 2633.536695] Call Trace: [ 2633.537518] ib_uverbs_remove_one+0xc3/0x140 [ib_uverbs] [ 2633.538596] remove_client_context+0x8b/0xd0 [ib_core] [ 2633.539641] disable_device+0x8c/0x130 [ib_core] [ 2633.540615] __ib_unregister_device+0x35/0xa0 [ib_core] [ 2633.541640] ib_unregister_device+0x21/0x30 [ib_core] [ 2633.542663] __mlx5_ib_remove+0x38/0x90 [mlx5_ib] [ 2633.543640] auxiliary_bus_remove+0x1e/0x30 [auxiliary] [ 2633.544661] device_release_driver_internal+0x103/0x1f0 [ 2633.545679] bus_remove_device+0xf7/0x170 [ 2633.546640] device_del+0x181/0x410 [ 2633.547606] mlx5_rescan_drivers_locked.part.10+0x63/0x160 [mlx5_core] [ 2633.548777] mlx5_unregister_device+0x27/0x40 [mlx5_core] [ 2633.549841] mlx5_uninit_one+0x21/0xc0 [mlx5_core] [ 2633.550864] remove_one+0x69/0xe0 [mlx5_core] [ 2633.551819] pci_device_remove+0x3b/0xc0 [ 2633.552731] device_release_driver_internal+0x103/0x1f0 [ 2633.553746] unbind_store+0xf6/0x130 [ 2633.554657] kernfs_fop_write+0x116/0x190 [ 2633.555567] vfs_write+0xa5/0x1a0 [ 2633.556407] ksys_write+0x4f/0xb0 [ 2633.557233] do_syscall_64+0x5b/0x1a0 [ 2633.558071] entry_SYSCALL_64_after_hwframe+0x65/0xca [ 2633.559018] RIP: 0033:0x7f9977132648 [ 2633.559821] Code: 89 02 48 c7 c0 ff ff ff ff eb b3 0f 1f 80 00 00 00 00 f3 0f 1e fa 48 8d 05 55 6f 2d 00 8b 00 85 c0 75 17 b8 01 00 00 00 0f 05 <48> 3d 00 f0 ff ff 77 58 c3 0f 1f 80 00 00 00 00 41 54 49 89 d4 55 [ 2633.562332] RSP: 002b:00007fffb1a83888 EFLAGS: 00000246 ORIG_RAX: 0000000000000001 [ 2633.563472] RAX: ffffffffffffffda RBX: 000000000000000c RCX: 00007f9977132648 [ 2633.564541] RDX: 000000000000000c RSI: 000055b90546e230 RDI: 0000000000000001 [ 2633.565596] RBP: 000055b90546e230 R08: 00007f9977406860 R09: 00007f9977a54740 [ 2633.566653] R10: 0000000000000000 R11: 0000000000000246 R12: 00007f99774056e0 [ 2633.567692] R13: 000000000000000c R14: 00007f9977400880 R15: 000000000000000c [ 2633.568725] ---[ end trace 10b4fe52945e544d ]--- | 5.5 |
2024-04-10 | CVE-2021-47214 | Linux | Memory Leak vulnerability in Linux Kernel In the Linux kernel, the following vulnerability has been resolved: hugetlb, userfaultfd: fix reservation restore on userfaultfd error Currently in the is_continue case in hugetlb_mcopy_atomic_pte(), if we bail out using "goto out_release_unlock;" in the cases where idx >= size, or !huge_pte_none(), the code will detect that new_pagecache_page == false, and so call restore_reserve_on_error(). | 5.5 |
2024-04-10 | CVE-2021-47215 | Linux | Unspecified vulnerability in Linux Kernel In the Linux kernel, the following vulnerability has been resolved: net/mlx5e: kTLS, Fix crash in RX resync flow For the TLS RX resync flow, we maintain a list of TLS contexts that require some attention, to communicate their resync information to the HW. Here we fix list corruptions, by protecting the entries against movements coming from resync_handle_seq_match(), until their resync handling in napi is fully completed. | 5.5 |
2024-04-10 | CVE-2021-47216 | Linux | Unspecified vulnerability in Linux Kernel In the Linux kernel, the following vulnerability has been resolved: scsi: advansys: Fix kernel pointer leak Pointers should be printed with %p or %px rather than cast to 'unsigned long' and printed with %lx. Change %lx to %p to print the hashed pointer. | 5.5 |
2024-04-10 | CVE-2021-47217 | Linux | NULL Pointer Dereference vulnerability in Linux Kernel In the Linux kernel, the following vulnerability has been resolved: x86/hyperv: Fix NULL deref in set_hv_tscchange_cb() if Hyper-V setup fails Check for a valid hv_vp_index array prior to derefencing hv_vp_index when setting Hyper-V's TSC change callback. | 5.5 |
2024-04-10 | CVE-2021-47218 | Linux | NULL Pointer Dereference vulnerability in Linux Kernel In the Linux kernel, the following vulnerability has been resolved: selinux: fix NULL-pointer dereference when hashtab allocation fails When the hash table slot array allocation fails in hashtab_init(), h->size is left initialized with a non-zero value, but the h->htable pointer is NULL. | 5.5 |
2024-04-10 | CVE-2024-31874 | IBM | Use of Uninitialized Resource vulnerability in IBM Security Verify Access IBM Security Verify Access Appliance 10.0.0 through 10.0.7 uses uninitialized variables when deploying that could allow a local user to cause a denial of service. | 5.5 |
2024-04-10 | CVE-2024-3567 | Qemu Redhat | A flaw was found in QEMU. | 5.5 |
2024-04-10 | CVE-2024-26816 | Linux Debian | Allocation of Resources Without Limits or Throttling vulnerability in multiple products In the Linux kernel, the following vulnerability has been resolved: x86, relocs: Ignore relocations in .notes section When building with CONFIG_XEN_PV=y, .text symbols are emitted into the .notes section so that Xen can find the "startup_xen" entry point. This information is used prior to booting the kernel, so relocations are not useful. | 5.5 |
2024-04-10 | CVE-2024-20766 | Adobe | Out-of-bounds Read vulnerability in Adobe Indesign InDesign Desktop versions 18.5.1, 19.2 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. | 5.5 |
2024-04-10 | CVE-2024-26815 | Linux | Out-of-bounds Write vulnerability in Linux Kernel In the Linux kernel, the following vulnerability has been resolved: net/sched: taprio: proper TCA_TAPRIO_TC_ENTRY_INDEX check taprio_parse_tc_entry() is not correctly checking TCA_TAPRIO_TC_ENTRY_INDEX attribute: int tc; // Signed value tc = nla_get_u32(tb[TCA_TAPRIO_TC_ENTRY_INDEX]); if (tc >= TC_QOPT_MAX_QUEUE) { NL_SET_ERR_MSG_MOD(extack, "TC entry index out of range"); return -ERANGE; } syzbot reported that it could fed arbitary negative values: UBSAN: shift-out-of-bounds in net/sched/sch_taprio.c:1722:18 shift exponent -2147418108 is negative CPU: 0 PID: 5066 Comm: syz-executor367 Not tainted 6.8.0-rc7-syzkaller-00136-gc8a5c731fd12 #0 Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 02/29/2024 Call Trace: <TASK> __dump_stack lib/dump_stack.c:88 [inline] dump_stack_lvl+0x1e7/0x2e0 lib/dump_stack.c:106 ubsan_epilogue lib/ubsan.c:217 [inline] __ubsan_handle_shift_out_of_bounds+0x3c7/0x420 lib/ubsan.c:386 taprio_parse_tc_entry net/sched/sch_taprio.c:1722 [inline] taprio_parse_tc_entries net/sched/sch_taprio.c:1768 [inline] taprio_change+0xb87/0x57d0 net/sched/sch_taprio.c:1877 taprio_init+0x9da/0xc80 net/sched/sch_taprio.c:2134 qdisc_create+0x9d4/0x1190 net/sched/sch_api.c:1355 tc_modify_qdisc+0xa26/0x1e40 net/sched/sch_api.c:1776 rtnetlink_rcv_msg+0x885/0x1040 net/core/rtnetlink.c:6617 netlink_rcv_skb+0x1e3/0x430 net/netlink/af_netlink.c:2543 netlink_unicast_kernel net/netlink/af_netlink.c:1341 [inline] netlink_unicast+0x7ea/0x980 net/netlink/af_netlink.c:1367 netlink_sendmsg+0xa3b/0xd70 net/netlink/af_netlink.c:1908 sock_sendmsg_nosec net/socket.c:730 [inline] __sock_sendmsg+0x221/0x270 net/socket.c:745 ____sys_sendmsg+0x525/0x7d0 net/socket.c:2584 ___sys_sendmsg net/socket.c:2638 [inline] __sys_sendmsg+0x2b0/0x3a0 net/socket.c:2667 do_syscall_64+0xf9/0x240 entry_SYSCALL_64_after_hwframe+0x6f/0x77 RIP: 0033:0x7f1b2dea3759 Code: 48 83 c4 28 c3 e8 d7 19 00 00 0f 1f 80 00 00 00 00 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 c7 c1 b8 ff ff ff f7 d8 64 89 01 48 RSP: 002b:00007ffd4de452f8 EFLAGS: 00000246 ORIG_RAX: 000000000000002e RAX: ffffffffffffffda RBX: 00007f1b2def0390 RCX: 00007f1b2dea3759 RDX: 0000000000000000 RSI: 00000000200007c0 RDI: 0000000000000004 RBP: 0000000000000003 R08: 0000555500000000 R09: 0000555500000000 R10: 0000555500000000 R11: 0000000000000246 R12: 00007ffd4de45340 R13: 00007ffd4de45310 R14: 0000000000000001 R15: 00007ffd4de45340 | 5.5 |
2024-04-10 | CVE-2024-0159 | Dell | Unspecified vulnerability in Dell Alienware Command Center Dell Alienware Command Center, versions 5.5.52.0 and prior, contain improper access control vulnerability, leading to Denial of Service on local system. | 5.5 |
2024-04-09 | CVE-2024-29063 | Microsoft | Unspecified vulnerability in Microsoft Azure AI Search Azure AI Search Information Disclosure Vulnerability | 5.5 |
2024-04-09 | CVE-2024-29064 | Microsoft | Unspecified vulnerability in Microsoft products Windows Hyper-V Denial of Service Vulnerability | 5.5 |
2024-04-08 | CVE-2024-26811 | Linux | Out-of-bounds Write vulnerability in Linux Kernel In the Linux kernel, the following vulnerability has been resolved: ksmbd: validate payload size in ipc response If installing malicious ksmbd-tools, ksmbd.mountd can return invalid ipc response to ksmbd kernel server. | 5.5 |
2024-04-08 | CVE-2023-52352 | Missing Authorization vulnerability in Google Android 13.0/14.0 In Network Adapter Service, there is a possible missing permission check. | 5.5 | |
2024-04-14 | CVE-2024-3763 | Emlog | Unspecified vulnerability in Emlog 2.2.10 A vulnerability was found in Emlog Pro 2.2.10. | 5.4 |
2024-04-14 | CVE-2024-3762 | Emlog | Unspecified vulnerability in Emlog 2.2.10 A vulnerability was found in Emlog Pro 2.2.10. | 5.4 |
2024-04-13 | CVE-2024-1957 | Givewp | Cross-site Scripting vulnerability in Givewp The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'give_form' shortcode in all versions up to, and including, 3.6.1 due to insufficient input sanitization and output escaping on user supplied attributes. | 5.4 |
2024-04-12 | CVE-2024-3695 | Oretnom23 | Unspecified vulnerability in Oretnom23 Computer Laboratory Management System 1.0 A vulnerability has been found in SourceCodester Computer Laboratory Management System 1.0 and classified as problematic. | 5.4 |
2024-04-12 | CVE-2023-47714 | IBM | Unspecified vulnerability in IBM Sterling File Gateway IBM Sterling File Gateway 6.0.0.0 through 6.0.3.9, 6.1.0.0 through 6.1.2.3, and 6.2.0.0 is vulnerable to cross-site scripting. | 5.4 |
2024-04-12 | CVE-2023-45186 | IBM | Unspecified vulnerability in IBM Sterling B2B Integrator IBM Sterling B2B Integrator 6.0.0.0 through 6.0.3.9, 6.1.0.0 through 6.1.2.3, and 6.2.0.0 is vulnerable to cross-site scripting. | 5.4 |
2024-04-12 | CVE-2023-50307 | IBM | Unspecified vulnerability in IBM Sterling B2B Integrator IBM Sterling B2B Integrator 6.0.0.0 through 6.0.3.9, 6.1.0.0 through 6.1.2.3, and 6.2.0.0 is vulnerable to cross-site scripting. | 5.4 |
2024-04-12 | CVE-2024-22357 | IBM | Unspecified vulnerability in IBM Sterling B2B Integrator IBM Sterling B2B Integrator 6.0.0.0 through 6.0.3.9, 6.1.0.0 through 6.1.2.3, and 6.2.0.0 is vulnerable to cross-site scripting. | 5.4 |
2024-04-12 | CVE-2024-2137 | Themesgrove | Cross-site Scripting vulnerability in Themesgrove All-In-One Addons for Elementor The All-in-One Addons for Elementor – WidgetKit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple pricing widgets (e.g. | 5.4 |
2024-04-12 | CVE-2024-2279 | Gitlab | Cross-site Scripting vulnerability in Gitlab An issue has been discovered in GitLab CE/EE affecting all versions starting from 16.7 to 16.8.6 all versions starting from 16.9 before 16.9.4, all versions starting from 16.10 before 16.10.2. | 5.4 |
2024-04-12 | CVE-2024-3092 | Gitlab | Cross-site Scripting vulnerability in Gitlab An issue has been discovered in GitLab CE/EE affecting all versions starting from 16.9 before 16.9.4, all versions starting from 16.10 before 16.10.2. | 5.4 |
2024-04-11 | CVE-2024-3343 | Themeisle | Cross-site Scripting vulnerability in Themeisle Otter Blocks The Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's block attributes in all versions up to, and including, 2.6.8 due to insufficient input sanitization and output escaping on user supplied attributes. | 5.4 |
2024-04-11 | CVE-2024-3344 | Themeisle | Cross-site Scripting vulnerability in Themeisle Otter Blocks The Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG file upload in all versions up to, and including, 2.6.8 due to insufficient input sanitization and output escaping. | 5.4 |
2024-04-11 | CVE-2024-3285 | Metaslider | Cross-site Scripting vulnerability in Metaslider Slider, Gallery, and Carousel The Slider, Gallery, and Carousel by MetaSlider – Responsive WordPress Slideshows plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'metaslider' shortcode in all versions up to, and including, 3.70.0 due to insufficient input sanitization and output escaping on user supplied attributes. | 5.4 |
2024-04-11 | CVE-2024-3614 | Oretnom23 | Unspecified vulnerability in Oretnom23 Warehouse Management System 1.0 A vulnerability classified as problematic has been found in SourceCodester Warehouse Management System 1.0. | 5.4 |
2024-04-11 | CVE-2024-3616 | Oretnom23 | Unspecified vulnerability in Oretnom23 Warehouse Management System 1.0 A vulnerability classified as problematic was found in SourceCodester Warehouse Management System 1.0. | 5.4 |
2024-04-11 | CVE-2024-3612 | Oretnom23 | Unspecified vulnerability in Oretnom23 Warehouse Management System 1.0 A vulnerability was found in SourceCodester Warehouse Management System 1.0. | 5.4 |
2024-04-11 | CVE-2024-3613 | Oretnom23 | Unspecified vulnerability in Oretnom23 Warehouse Management System 1.0 A vulnerability was found in SourceCodester Warehouse Management System 1.0. | 5.4 |
2024-04-10 | CVE-2024-31985 | Xwiki | Cross-Site Request Forgery (CSRF) vulnerability in Xwiki XWiki Platform is a generic wiki platform. | 5.4 |
2024-04-10 | CVE-2024-2539 | Livemeshelementor | Cross-site Scripting vulnerability in Livemeshelementor Addons for Elementor The Elementor Addons by Livemesh plugin for WordPress is vulnerable to Stored Cross-Site Scripting via widget '_id' attributes in all versions up to, and including, 8.3.6 due to insufficient input sanitization and output escaping on user supplied attributes. | 5.4 |
2024-04-10 | CVE-2024-2655 | Livemeshelementor | Cross-site Scripting vulnerability in Livemeshelementor Addons for Elementor The Elementor Addons by Livemesh plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Post widgets in all versions up to, and including, 8.3.5 due to insufficient input sanitization and output escaping on author display names. | 5.4 |
2024-04-10 | CVE-2024-3210 | Properfraction | Cross-site Scripting vulnerability in Properfraction Profilepress The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'reg-single-checkbox' shortcode in all versions up to, and including, 4.15.5 due to insufficient input sanitization and output escaping on user supplied attributes. | 5.4 |
2024-04-10 | CVE-2024-1041 | Wpmilitary | Cross-site Scripting vulnerability in Wpmilitary WP Radio The WP Radio – Worldwide Online Radio Stations Directory for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's settings in all versions up to, and including, 3.1.9 due to insufficient input sanitization and output escaping as well as insufficient access control on the settings. | 5.4 |
2024-04-10 | CVE-2024-1042 | Wpmilitary | Missing Authorization vulnerability in Wpmilitary WP Radio The WP Radio – Worldwide Online Radio Stations Directory for WordPress plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on multiple AJAX functions in all versions up to, and including, 3.1.9. | 5.4 |
2024-04-10 | CVE-2024-2734 | Bold Themes | Cross-site Scripting vulnerability in Bold-Themes Bold Page Builder The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's AI features all versions up to, and including, 4.8.8 due to insufficient input sanitization and output escaping on user supplied attributes. | 5.4 |
2024-04-10 | CVE-2024-2735 | Bold Themes | Cross-site Scripting vulnerability in Bold-Themes Bold Page Builder The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Price List' element in all versions up to, and including, 4.8.8 due to insufficient input sanitization and output escaping on user supplied attributes. | 5.4 |
2024-04-10 | CVE-2024-2736 | Bold Themes | Cross-site Scripting vulnerability in Bold-Themes Bold Page Builder The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via HTML Tags in all versions up to, and including, 4.8.8 due to insufficient input sanitization and output escaping on user supplied attributes. | 5.4 |
2024-04-10 | CVE-2024-2733 | Bold Themes | Cross-site Scripting vulnerability in Bold-Themes Bold Page Builder The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's "Separator" element in all versions up to, and including, 4.8.8 due to insufficient input sanitization and output escaping on user supplied attributes. | 5.4 |
2024-04-10 | CVE-2024-3526 | Campcodes | Unspecified vulnerability in Campcodes Online Event Management System 1.0 A vulnerability has been found in Campcodes Online Event Management System 1.0 and classified as problematic. | 5.4 |
2024-04-10 | CVE-2024-3524 | Campcodes | Unspecified vulnerability in Campcodes Online Event Management System 1.0 A vulnerability, which was classified as problematic, has been found in Campcodes Online Event Management System 1.0. | 5.4 |
2024-04-10 | CVE-2024-3525 | Campcodes | Unspecified vulnerability in Campcodes Online Event Management System 1.0 A vulnerability, which was classified as problematic, was found in Campcodes Online Event Management System 1.0. | 5.4 |
2024-04-09 | CVE-2023-6486 | Brainstormforce | Cross-site Scripting vulnerability in Brainstormforce Spectra The Spectra – WordPress Gutenberg Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Custom CSS metabox in all versions up to and including 2.10.3 due to insufficient input sanitization and output escaping. | 5.4 |
2024-04-09 | CVE-2023-6694 | Fastlinemedia | Cross-site Scripting vulnerability in Fastlinemedia Beaver Themer The Beaver Themer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 1.4.9 due to insufficient input sanitization and output escaping on user supplied custom fields. | 5.4 |
2024-04-09 | CVE-2024-0376 | Leap13 | Cross-site Scripting vulnerability in Leap13 Premium Addons for Elementor The Premium Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Wrapper Link Widget in all versions up to, and including, 4.10.16 due to insufficient input sanitization and output escaping on user supplied URLs. | 5.4 |
2024-04-09 | CVE-2024-0826 | Qodeinteractive | Cross-site Scripting vulnerability in Qodeinteractive QI Addons for Elementor The Qi Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's widgets in all versions up to, and including, 1.6.7 due to insufficient input sanitization and output escaping on user supplied attributes. | 5.4 |
2024-04-09 | CVE-2024-1289 | Thimpress | Authorization Bypass Through User-Controlled Key vulnerability in Thimpress Learnpress The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 4.2.6.3 due to missing validation on a user controlled key when looking up order information. | 5.4 |
2024-04-09 | CVE-2024-1424 | Givewp | Cross-site Scripting vulnerability in Givewp The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 3.5.1 due to insufficient input sanitization and output escaping on user supplied attributes. | 5.4 |
2024-04-09 | CVE-2024-1458 | Livemeshelementor | Cross-site Scripting vulnerability in Livemeshelementor Addons for Elementor The Elementor Addons by Livemesh plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘text_alignment’ attribute of the Animated Text widget in all versions up to, and including, 8.3.4 due to insufficient input sanitization and output escaping. | 5.4 |
2024-04-09 | CVE-2024-1461 | Livemeshelementor | Cross-site Scripting vulnerability in Livemeshelementor Addons for Elementor The Elementor Addons by Livemesh plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘style’ attribute of the Team Members widget in all versions up to, and including, 8.3.4 due to insufficient input sanitization and output escaping. | 5.4 |
2024-04-09 | CVE-2024-1464 | Livemeshelementor | Cross-site Scripting vulnerability in Livemeshelementor Addons for Elementor The Elementor Addons by Livemesh plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘style’ attribute of the Posts Slider widget in all versions up to, and including, 8.3.4 due to insufficient input sanitization and output escaping. | 5.4 |
2024-04-09 | CVE-2024-1465 | Livemeshelementor | Cross-site Scripting vulnerability in Livemeshelementor Addons for Elementor The Elementor Addons by Livemesh plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘carousel_skin’ attribute of the Posts Carousel widget in all versions up to, and including, 8.3.4 due to insufficient input sanitization and output escaping. | 5.4 |
2024-04-09 | CVE-2024-1466 | Livemeshelementor | Cross-site Scripting vulnerability in Livemeshelementor Addons for Elementor The Elementor Addons by Livemesh plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘slider_style’ attribute of the Posts Multislider widget in all versions up to, and including, 8.3.4 due to insufficient input sanitization and output escaping. | 5.4 |
2024-04-09 | CVE-2024-1498 | Leevio | Cross-site Scripting vulnerability in Leevio Happy Addons for Elementor The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Photo Stack Widget in all versions up to, and including, 3.10.3 due to insufficient input sanitization and output escaping on user supplied attributes. | 5.4 |
2024-04-09 | CVE-2024-1948 | Motopress | Cross-site Scripting vulnerability in Motopress Getwid The Getwid – Gutenberg Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the block content in all versions up to, and including, 2.0.5 due to insufficient input sanitization and output escaping. | 5.4 |
2024-04-09 | CVE-2024-1960 | Hasthemes | Cross-site Scripting vulnerability in Hasthemes Shoplentor The ShopLentor – WooCommerce Builder for Elementor & Gutenberg +12 Modules – All in One Solution (formerly WooLentor) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Special Offer Day Widget Banner Link in all versions up to, and including, 2.8.1 due to insufficient input sanitization and output escaping on user supplied attributes. | 5.4 |
2024-04-09 | CVE-2024-1999 | Kadencewp | Cross-site Scripting vulnerability in Kadencewp Gutenberg Blocks With AI The Gutenberg Blocks by Kadence Blocks – Page Builder Features plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Testimonial Widget's anchor style parameter in all versions up to, and including, 3.2.25 due to insufficient input sanitization and output escaping. | 5.4 |
2024-04-09 | CVE-2024-2026 | Wpchill | Cross-site Scripting vulnerability in Wpchill Passster The Passster plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's content_protector shortcode in all versions up to, and including, 4.2.6.4 due to insufficient input sanitization and output escaping on user supplied attributes. | 5.4 |
2024-04-09 | CVE-2024-2027 | Devowl | Cross-site Scripting vulnerability in Devowl Real Media Library The Real Media Library: Media Library Folder & File Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via its style attributes in all versions up to, and including, 4.22.7 due to insufficient input sanitization and output escaping. | 5.4 |
2024-04-09 | CVE-2024-2081 | Fooplugins | Cross-site Scripting vulnerability in Fooplugins Foogallery The Best WordPress Gallery Plugin – FooGallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the foogallery_attachment_modal_save action in all versions up to, and including, 2.4.14 due to insufficient input sanitization and output escaping. | 5.4 |
2024-04-09 | CVE-2024-2117 | Elementor | Cross-site Scripting vulnerability in Elementor Website Builder The Elementor Website Builder – More than Just a Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Path Widget in all versions up to, and including, 3.20.2 due to insufficient output escaping on user supplied attributes. | 5.4 |
2024-04-09 | CVE-2024-2138 | Crocoblock | Cross-site Scripting vulnerability in Crocoblock Jetwidgets for Elementor The JetWidgets For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Animated Box widget in all versions up to, and including, 1.0.15 due to insufficient input sanitization and output escaping. | 5.4 |
2024-04-09 | CVE-2024-2181 | Wpzoom | Cross-site Scripting vulnerability in Wpzoom Beaver Builder Addons The Beaver Builder Addons by WPZOOM plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Button widget in all versions up to, and including, 1.3.4 due to insufficient input sanitization and output escaping. | 5.4 |
2024-04-09 | CVE-2024-2183 | Wpzoom | Cross-site Scripting vulnerability in Wpzoom Beaver Builder Addons The Beaver Builder Addons by WPZOOM plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Heading widget in all versions up to, and including, 1.3.4 due to insufficient input sanitization and output escaping. | 5.4 |
2024-04-09 | CVE-2024-2185 | Wpzoom | Cross-site Scripting vulnerability in Wpzoom Beaver Builder Addons The Beaver Builder Addons by WPZOOM plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Image Box widget in all versions up to, and including, 1.3.4 due to insufficient input sanitization and output escaping. | 5.4 |
2024-04-09 | CVE-2024-2186 | Wpzoom | Cross-site Scripting vulnerability in Wpzoom Beaver Builder Addons The Beaver Builder Addons by WPZOOM plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Team Members widget in all versions up to, and including, 1.3.4 due to insufficient input sanitization and output escaping. | 5.4 |
2024-04-09 | CVE-2024-2187 | Wpzoom | Cross-site Scripting vulnerability in Wpzoom Beaver Builder Addons The Beaver Builder Addons by WPZOOM plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Testimonials widget in all versions up to, and including, 1.3.4 due to insufficient input sanitization and output escaping. | 5.4 |
2024-04-09 | CVE-2024-2226 | Themeisle | Cross-site Scripting vulnerability in Themeisle Otter Blocks The Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the id parameter in the google-map block in all versions up to, and including, 2.6.4 due to insufficient input sanitization and output escaping. | 5.4 |
2024-04-09 | CVE-2024-2289 | Ideabox | Cross-site Scripting vulnerability in Ideabox Powerpack for Beaver Builder The PowerPack Lite for Beaver Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the link in multiple elements in all versions up to, and including, 1.3.0 due to insufficient input sanitization and output escaping on user supplied attributes. | 5.4 |
2024-04-09 | CVE-2024-2305 | Brainstormforce | Cross-site Scripting vulnerability in Brainstormforce Cards for Beaver Builder The Cards for Beaver Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the BootstrapCard link in all versions up to, and including, 1.1.2 due to insufficient input sanitization and output escaping on user supplied attributes. | 5.4 |
2024-04-09 | CVE-2024-2311 | Theme Fusion | Cross-site Scripting vulnerability in Theme-Fusion Avada The Avada theme for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in all versions up to, and including, 7.11.6 due to insufficient input sanitization and output escaping on user supplied attributes. | 5.4 |
2024-04-09 | CVE-2024-2336 | Code Atlantic | Cross-site Scripting vulnerability in Code-Atlantic Popup Maker The Popup Maker – Popup for opt-ins, lead gen, & more plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 1.18.2 due to insufficient input sanitization and output escaping on user supplied attributes. | 5.4 |
2024-04-09 | CVE-2024-2436 | Smartwp | Cross-site Scripting vulnerability in Smartwp Lightweight Accordion The Lightweight Accordion plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 1.5.16 due to insufficient input sanitization and output escaping on user supplied attributes. | 5.4 |
2024-04-09 | CVE-2024-2492 | Ideabox | Cross-site Scripting vulnerability in Ideabox Powerpack Addons for Elementor The PowerPack Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Twitter Tweet widget in all versions up to, and including, 2.7.18 due to insufficient input sanitization and output escaping. | 5.4 |
2024-04-09 | CVE-2024-2507 | Crocoblock | Cross-site Scripting vulnerability in Crocoblock Jetwidgets for Elementor The JetWidgets For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the widget button URL in all versions up to, and including, 1.0.16 due to insufficient input sanitization and output escaping on user supplied attributes. | 5.4 |
2024-04-09 | CVE-2024-2513 | Ninjateam | Unspecified vulnerability in Ninjateam WP Chat APP The WP Chat App plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'imageAlt' block attribute in all versions up to, and including, 3.6.2 due to insufficient input sanitization and output escaping on user supplied attributes. | 5.4 |
2024-04-09 | CVE-2024-2783 | Gamipress | Cross-site Scripting vulnerability in Gamipress The GamiPress – The #1 gamification plugin to reward points, achievements, badges & ranks in WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 6.9.0 due to insufficient input sanitization and output escaping on user supplied attributes. | 5.4 |
2024-04-09 | CVE-2024-2787 | Leevio | Cross-site Scripting vulnerability in Leevio Happy Addons for Elementor The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Page Title HTML Tag in all versions up to, and including, 3.10.4 due to insufficient input sanitization and output escaping on user supplied attributes. | 5.4 |
2024-04-09 | CVE-2024-2788 | Leevio | Cross-site Scripting vulnerability in Leevio Happy Addons for Elementor The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Post Title HTML Tag in all versions up to, and including, 3.10.4 due to insufficient input sanitization and output escaping on user supplied attributes. | 5.4 |
2024-04-09 | CVE-2024-2789 | Leevio | Cross-site Scripting vulnerability in Leevio Happy Addons for Elementor The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Calendy widget in all versions up to, and including, 3.10.4 due to insufficient input sanitization and output escaping on user supplied attributes. | 5.4 |
2024-04-09 | CVE-2024-2792 | Webtechstreet | Cross-site Scripting vulnerability in Webtechstreet Elementor Addon Elements The Elementor Addon Elements plugin for WordPress is vulnerable to Stored Cross-Site Scripting via widgets in all versions up to, and including, 1.13.2 due to insufficient input sanitization and output escaping on user supplied attributes. | 5.4 |
2024-04-09 | CVE-2024-2847 | Iptanus | Cross-site Scripting vulnerability in Iptanus Wordpress File Upload The WordPress File Upload plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 4.24.5 due to insufficient input sanitization and output escaping on user supplied attributes. | 5.4 |
2024-04-09 | CVE-2024-3053 | Incsub | Cross-site Scripting vulnerability in Incsub Forminator The Forminator – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘id’ forminator_form shortcode attribute in versions up to, and including, 1.29.2 due to insufficient input sanitization and output escaping. | 5.4 |
2024-04-09 | CVE-2024-3208 | Athemes | Cross-site Scripting vulnerability in Athemes Sydney Toolbox The Sydney Toolbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Filterable Gallery widget in all versions up to, and including, 1.28 due to insufficient input sanitization and output escaping on user supplied attributes. | 5.4 |
2024-04-09 | CVE-2024-3244 | Wpdeveloper | Cross-site Scripting vulnerability in Wpdeveloper Embedpress The EmbedPress – Embed PDF, Google Docs, Vimeo, Wistia, Embed YouTube Videos, Audios, Maps & Embed Any Documents in Gutenberg & Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'embedpress_calendar' shortcode in all versions up to, and including, 3.9.14 due to insufficient input sanitization and output escaping on user supplied attributes. | 5.4 |
2024-04-09 | CVE-2024-3266 | Bold Themes | Cross-site Scripting vulnerability in Bold-Themes Bold Page Builder The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the URL attribute of widgets in all versions up to, and including, 4.8.8 due to insufficient input sanitization and output escaping on user supplied attributes. | 5.4 |
2024-04-09 | CVE-2024-3267 | Bold Themes | Cross-site Scripting vulnerability in Bold-Themes Bold Page Builder The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's bt_bb_price_list shortcode in all versions up to, and including, 4.8.8 due to insufficient input sanitization and output escaping on user supplied attributes. | 5.4 |
2024-04-09 | CVE-2024-28190 | Contao | Cross-site Scripting vulnerability in Contao Contao is an open source content management system. | 5.4 |
2024-04-09 | CVE-2024-28191 | Contao | Injection vulnerability in Contao Contao is an open source content management system. | 5.4 |
2024-04-08 | CVE-2024-3463 | Oretnom23 | Unspecified vulnerability in Oretnom23 Laundry Shop Management System 1.0 A vulnerability has been found in SourceCodester Laundry Management System 1.0 and classified as problematic. | 5.4 |
2024-04-08 | CVE-2024-3443 | Fast5 | Unspecified vulnerability in Fast5 Prison Management System 1.0 A vulnerability classified as problematic was found in SourceCodester Prison Management System 1.0. | 5.4 |
2024-04-12 | CVE-2024-30402 | Juniper | Improper Check for Unusual or Exceptional Conditions vulnerability in Juniper Junos and Junos OS Evolved An Improper Check for Unusual or Exceptional Conditions vulnerability in the Layer 2 Address Learning Daemon (l2ald) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated, adjacent attacker to cause a Denial of Service (DoS). When telemetry requests are sent to the device, and the Dynamic Rendering Daemon (drend) is suspended, the l2ald crashes and restarts due to factors outside the attackers control. | 5.3 |
2024-04-10 | CVE-2024-3386 | Paloaltonetworks | Interpretation Conflict vulnerability in Paloaltonetworks Pan-Os An incorrect string comparison vulnerability in Palo Alto Networks PAN-OS software prevents Predefined Decryption Exclusions from functioning as intended. | 5.3 |
2024-04-10 | CVE-2024-31297 | Wpexperts | Missing Authorization vulnerability in Wpexperts Wholesale for Woocommerce Missing Authorization vulnerability in WPExperts Wholesale For WooCommerce.This issue affects Wholesale For WooCommerce: from n/a through 2.3.0. | 5.3 |
2024-04-10 | CVE-2024-31302 | Codepeople | Unspecified vulnerability in Codepeople Contact Form Email Exposure of Sensitive Information to an Unauthorized Actor vulnerability in CodePeople Contact Form Email.This issue affects Contact Form Email: from n/a through 1.3.44. | 5.3 |
2024-04-10 | CVE-2024-31353 | Tribulant | Unspecified vulnerability in Tribulant Slideshow Gallery Insertion of Sensitive Information into Log File vulnerability in Tribulant Slideshow Gallery.This issue affects Slideshow Gallery: from n/a through 1.7.8. | 5.3 |
2024-04-09 | CVE-2024-1352 | Radiustheme | Missing Authorization vulnerability in Radiustheme Classified Listing The Classified Listing – Classified ads & Business Directory Plugin plugin for WordPress is vulnerable to unauthorized access & modification of data due to a missing capability check on the rtcl_import_location() rtcl_import_category() functions in all versions up to, and including, 3.0.4. | 5.3 |
2024-04-09 | CVE-2024-2093 | Vektor INC | Unspecified vulnerability in Vektor-Inc VK ALL in ONE Expansion Unit The VK All in One Expansion Unit plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 9.95.0.1 via social meta tags. | 5.3 |
2024-04-09 | CVE-2024-3097 | Imagely | Missing Authorization vulnerability in Imagely Nextgen Gallery The WordPress Gallery Plugin – NextGEN Gallery plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the get_item function in versions up to, and including, 3.59. | 5.3 |
2024-04-09 | CVE-2024-31863 | Apache | Unspecified vulnerability in Apache Zeppelin 0.10.1 Authentication Bypass by Spoofing vulnerability by replacing to exsiting notes in Apache Zeppelin.This issue affects Apache Zeppelin: from 0.10.1 before 0.11.0. Users are recommended to upgrade to version 0.11.0, which fixes the issue. | 5.3 |
2024-04-09 | CVE-2024-27898 | SAP | Unspecified vulnerability in SAP Netweaver 7.5 SAP NetWeaver application, due to insufficient input validation, allows an attacker to send a crafted request from a vulnerable web application targeting internal systems behind firewalls that are normally inaccessible to an attacker from the external network, resulting in a Server-Side Request Forgery vulnerability. | 5.3 |
2024-04-08 | CVE-2024-30269 | Dataease | Unspecified vulnerability in Dataease DataEase, an open source data visualization and analysis tool, has a database configuration information exposure vulnerability prior to version 2.5.0. | 5.3 |
2024-04-10 | CVE-2024-3388 | Paloaltonetworks | Incorrect Authorization vulnerability in Paloaltonetworks Pan-Os A vulnerability in the GlobalProtect Gateway in Palo Alto Networks PAN-OS software enables an authenticated attacker to impersonate another user and send network packets to internal assets. | 5.0 |
2024-04-10 | CVE-2024-31464 | Xwiki | Use of Password Hash With Insufficient Computational Effort vulnerability in Xwiki XWiki Platform is a generic wiki platform. | 4.9 |
2024-04-12 | CVE-2024-30391 | Juniper | Missing Authentication for Critical Function vulnerability in Juniper Junos A Missing Authentication for Critical Function vulnerability in the Packet Forwarding Engine (pfe) of Juniper Networks Junos OS on MX Series with SPC3, and SRX Series allows an unauthenticated network-based attacker to cause limited impact to the integrity or availability of the device. If a device is configured with IPsec authentication algorithm hmac-sha-384 or hmac-sha-512, tunnels are established normally but for traffic traversing the tunnel no authentication information is sent with the encrypted data on egress, and no authentication information is expected on ingress. | 4.8 |
2024-04-12 | CVE-2022-40211 | Givewp | Unspecified vulnerability in Givewp Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in GiveWP allows Stored XSS.This issue affects GiveWP: from n/a through 2.25.1. | 4.8 |
2024-04-09 | CVE-2024-0598 | Kadencewp | Cross-site Scripting vulnerability in Kadencewp Gutenberg Blocks With AI The Gutenberg Blocks by Kadence Blocks – Page Builder Features plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the contact form message settings in all versions up to and including 3.2.17 due to insufficient input sanitization and output escaping. | 4.8 |
2024-04-09 | CVE-2024-0662 | Colorlib | Cross-site Scripting vulnerability in Colorlib Fancybox The FancyBox for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions 3.0.2 to 3.3.3 due to insufficient input sanitization and output escaping. | 4.8 |
2024-04-09 | CVE-2024-1463 | Thimpress | Cross-site Scripting vulnerability in Thimpress Learnpress The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Course, Lesson, and Quiz title and content in all versions up to, and including, 4.2.6.3 due to insufficient input sanitization and output escaping. | 4.8 |
2024-04-09 | CVE-2024-1571 | Bootstrapped | Cross-site Scripting vulnerability in Bootstrapped WP Recipe Maker The WP Recipe Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Video Embed parameter in all versions up to, and including, 9.2.1 due to insufficient input sanitization and output escaping. | 4.8 |
2024-04-09 | CVE-2024-28234 | Contao | Unspecified vulnerability in Contao Contao is an open source content management system. | 4.7 |
2024-04-12 | CVE-2024-22334 | IBM | Unspecified vulnerability in IBM Urbancode Deploy IBM UrbanCode Deploy (UCD) 7.0 through 7.0.5.20, 7.1 through 7.1.2.16, 7.2 through 7.2.3.9, 7.3 through 7.3.2.4 and IBM DevOps Deploy 8.0 through 8.0.0.1 could be vulnerable to incomplete revocation of permissions when deleting a custom security resource type. | 4.4 |
2024-04-10 | CVE-2024-22448 | Dell | Unspecified vulnerability in Dell products Dell BIOS contains an Out-of-Bounds Write vulnerability. | 4.4 |
2024-04-08 | CVE-2023-52349 | Out-of-bounds Write vulnerability in Google Android 12.0/13.0/14.0 In ril service, there is a possible out of bounds write due to a missing bounds check. | 4.4 | |
2024-04-08 | CVE-2023-52350 | Out-of-bounds Write vulnerability in Google Android 12.0/13.0/14.0 In ril service, there is a possible out of bounds write due to a missing bounds check. | 4.4 | |
2024-04-08 | CVE-2023-52536 | Out-of-bounds Read vulnerability in Google Android 12.0/13.0/14.0 In faceid service, there is a possible out of bounds read due to a missing bounds check. | 4.4 | |
2024-04-12 | CVE-2024-22339 | IBM | Unspecified vulnerability in IBM Urbancode Deploy IBM UrbanCode Deploy (UCD) 7.0 through 7.0.5.20, 7.1 through 7.1.2.16, 7.2 through 7.2.3.9, 7.3 through 7.3.2.4 and IBM DevOps Deploy 8.0 through 8.0.0.1 is vulnerable to a sensitive information due to insufficient obfuscation of sensitive values from some log files. | 4.3 |
2024-04-12 | CVE-2024-21610 | Juniper | Unspecified vulnerability in Juniper Junos An Improper Handling of Exceptional Conditions vulnerability in the Class of Service daemon (cosd) of Juniper Networks Junos OS on MX Series allows an authenticated, network-based attacker with low privileges to cause a limited Denial of Service (DoS). In a scaled subscriber scenario when specific low privileged commands, received over NETCONF, SSH or telnet, are handled by cosd on behalf of mgd, the respective child management daemon (mgd) processes will get stuck. | 4.3 |
2024-04-11 | CVE-2024-24883 | Bdthemes | Unspecified vulnerability in Bdthemes Prime Slider Missing Authorization vulnerability in BdThemes Prime Slider – Addons For Elementor.This issue affects Prime Slider – Addons For Elementor: from n/a through 3.11.10. | 4.3 |
3 Low Vulnerabilities
DATE | CVE | VENDOR | VULNERABILITY | CVSS |
---|---|---|---|---|
2024-04-09 | CVE-2024-26217 | Microsoft | Unspecified vulnerability in Microsoft products Windows Remote Access Connection Manager Information Disclosure Vulnerability | 3.3 |
2024-04-08 | CVE-2024-23081 | Threeten | NULL Pointer Dereference vulnerability in Threeten Backport 1.6.8 ThreeTen Backport v1.6.8 was discovered to contain a NullPointerException via the component org.threeten.bp.LocalDate::compareTo(ChronoLocalDate). | 3.3 |
2024-04-09 | CVE-2024-26251 | Microsoft | Unspecified vulnerability in Microsoft Sharepoint Server 2016/2019 Microsoft SharePoint Server Spoofing Vulnerability | 3.1 |