Weekly Vulnerabilities Reports > May 6 to 12, 2024

Overview

125 new vulnerabilities reported during this period, including 6 critical vulnerabilities and 39 high severity vulnerabilities. This weekly summary report vulnerabilities in 285 products from 38 vendors including Campcodes, Google, Qualcomm, Samsung, and Dedecms. Vulnerabilities are notably categorized as "Out-of-bounds Write", "Use After Free", "Classic Buffer Overflow", "SQL Injection", and "Cross-site Scripting".

  • 73 reported vulnerabilities are remotely exploitables.
  • 12 reported vulnerabilities are related to weaknesses in OWASP Top Ten.
  • 54 reported vulnerabilities are exploitable by an anonymous user.
  • Campcodes has the most reported vulnerabilities, with 21 reported vulnerabilities.
  • Apache has the most reported critical vulnerabilities, with 2 reported vulnerabilities.

TOTAL
VULNERABILITIES
CRITICAL RISK
VULNERABILITIES
HIGH RISK
VULNERABILITIES
MEDIUM RISK
VULNERABILITIES
LOW RISK
VULNERABILITIES
REMOTELY
EXPLOITABLE
LOCALLY
EXPLOITABLE
EXPLOIT
AVAILABLE
EXPLOITABLE
ANONYMOUSLY
AFFECTING
WEB APPLICATION

Vulnerability Details

The following table list reported vulnerabilities for the period covered by this report:

Expand/Hide

6 Critical Vulnerabilities

DATE CVE VENDOR VULNERABILITY CVSS
2024-05-08 CVE-2024-21793 F5 SQL Injection vulnerability in F5 Big-Ip Next Central Manager 20.1.0

An OData injection vulnerability exists in the BIG-IP Next Central Manager API (URI).  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

9.8
2024-05-08 CVE-2024-26026 F5 SQL Injection vulnerability in F5 Big-Ip Next Central Manager 20.1.0

An SQL injection vulnerability exists in the BIG-IP Next Central Manager API (URI).  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated

9.8
2024-05-08 CVE-2024-26579 Apache Unspecified vulnerability in Apache Inlong

Deserialization of Untrusted Data vulnerability in Apache InLong.This issue affects Apache InLong: from 1.7.0 through 1.11.0,  the attackers can bypass using malicious parameters. Users are advised to upgrade to Apache InLong's 1.12.0 or cherry-pick [1], [2] to solve it. [1] https://github.com/apache/inlong/pull/9694 [2]  https://github.com/apache/inlong/pull/9707

9.8
2024-05-08 CVE-2024-32113 Apache Unspecified vulnerability in Apache Ofbiz

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache OFBiz.This issue affects Apache OFBiz: before 18.12.13. Users are recommended to upgrade to version 18.12.13, which fixes the issue.

9.8
2024-05-06 CVE-2024-21480 Qualcomm Classic Buffer Overflow vulnerability in Qualcomm products

Memory corruption while playing audio file having large-sized input buffer.

9.8
2024-05-07 CVE-2024-4558 Google
Fedoraproject
Apple
Use After Free vulnerability in multiple products

Use after free in ANGLE in Google Chrome prior to 124.0.6367.155 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

9.6

39 High Vulnerabilities

DATE CVE VENDOR VULNERABILITY CVSS
2024-05-08 CVE-2024-24833 Leevio Unspecified vulnerability in Leevio Happy Addons for Elementor

Missing Authorization vulnerability in Leevio Happy Addons for Elementor.This issue affects Happy Addons for Elementor: from n/a through 3.10.1.

8.8
2024-05-07 CVE-2021-35002 BMC Unspecified vulnerability in BMC Track-It!

BMC Track-It! Unrestricted File Upload Remote Code Execution Vulnerability.

8.8
2024-05-06 CVE-2024-33570 Wpmet Unspecified vulnerability in Wpmet Metform Elementor Contact Form Builder

Missing Authorization vulnerability in Wpmet Metform Elementor Contact Form Builder.This issue affects Metform Elementor Contact Form Builder: from n/a through 3.8.3.

8.8
2024-05-06 CVE-2024-33912 Kodezen Unspecified vulnerability in Kodezen Academy LMS

Missing Authorization vulnerability in Academy LMS.This issue affects Academy LMS: from n/a through 1.9.16.

8.8
2024-05-07 CVE-2024-29889 Glpi Project SQL Injection vulnerability in Glpi-Project Glpi

GLPI is a Free Asset and IT Management Software package.

8.1
2024-05-08 CVE-2024-33612 F5 Improper Certificate Validation vulnerability in F5 Big-Ip Next Central Manager 20.1.0

An improper certificate validation vulnerability exists in BIG-IP Next Central Manager and may allow an attacker to impersonate an Instance Provider system.

8.0
2024-05-08 CVE-2024-2860 Broadcom Missing Authentication for Critical Function vulnerability in Broadcom Brocade Sannav

The PostgreSQL implementation in Brocade SANnav versions before 2.3.0a is vulnerable to an incorrect local authentication flaw.

7.8
2024-05-07 CVE-2024-0024 Google Unspecified vulnerability in Google Android

In multiple methods of UserManagerService.java, there is a possible failure to persist or enforce user restrictions due to improper input validation.

7.8
2024-05-07 CVE-2024-0025 Google Unspecified vulnerability in Google Android

In sendIntentSender of ActivityManagerService.java, there is a possible background activity launch due to a logic error.

7.8
2024-05-07 CVE-2024-0042 Google Improper Certificate Validation vulnerability in Google Android

In TBD of TBD, there is a possible confusion of OEM and DRM certificates due to improperly used crypto.

7.8
2024-05-07 CVE-2024-0043 Google Unspecified vulnerability in Google Android

In multiple locations, there is a possible notification listener grant to an app running in the work profile due to a logic error in the code.

7.8
2024-05-07 CVE-2024-23704 Google Missing Authorization vulnerability in Google Android 13.0/14.0

In onCreate of WifiDialogActivity.java, there is a possible way to bypass the DISALLOW_ADD_WIFI_CONFIG restriction due to a missing permission check.

7.8
2024-05-07 CVE-2024-23705 Google Unspecified vulnerability in Google Android

In multiple locations, there is a possible failure to persist or enforce user restrictions due to improper input validation.

7.8
2024-05-07 CVE-2024-23706 Google Unspecified vulnerability in Google Android 14.0

In multiple locations, there is a possible bypass of health data permissions due to an improper input validation.

7.8
2024-05-07 CVE-2024-23707 Google Unspecified vulnerability in Google Android 14.0

In multiple locations, there is a possible permissions bypass due to improper input validation.

7.8
2024-05-07 CVE-2024-23708 Google Unspecified vulnerability in Google Android

In multiple functions of NotificationManagerService.java, there is a possible way to not show a toast message when a clipboard message has been accessed.

7.8
2024-05-07 CVE-2024-23710 Google Unspecified vulnerability in Google Android 13.0/14.0

In assertPackageWithSharedUserIdIsPrivileged of InstallPackageHelper.java, there is a possible execution of arbitrary app code as a privileged app due to a logic error in the code.

7.8
2024-05-07 CVE-2024-23713 Google Unspecified vulnerability in Google Android

In migrateNotificationFilter of NotificationManagerService.java, there is a possible failure to persist notifications settings due to improper input validation.

7.8
2024-05-07 CVE-2024-23808 Openatom NULL Pointer Dereference vulnerability in Openatom Openharmony

in OpenHarmony v4.0.0 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through use after free or cause DOS through NULL pointer dereference.

7.8
2024-05-07 CVE-2024-27217 Openatom Use After Free vulnerability in Openatom Openharmony

in OpenHarmony v4.0.0 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through use after free.

7.8
2024-05-07 CVE-2024-3758 Openatom Out-of-bounds Write vulnerability in Openatom Openharmony

in OpenHarmony v4.0.0 and prior versions allow a local attacker arbitrary code execution in TCB through heap buffer overflow.

7.8
2024-05-07 CVE-2024-3759 Openatom Use After Free vulnerability in Openatom Openharmony

in OpenHarmony v4.0.0 and prior versions allow a local attacker arbitrary code execution in TCB through use after free.

7.8
2024-05-06 CVE-2023-43521 Qualcomm Use After Free vulnerability in Qualcomm products

Memory corruption when multiple listeners are being registered with the same file descriptor.

7.8
2024-05-06 CVE-2023-43524 Qualcomm Classic Buffer Overflow vulnerability in Qualcomm products

Memory corruption when the bandpass filter order received from AHAL is not within the expected range.

7.8
2024-05-06 CVE-2023-43525 Qualcomm Classic Buffer Overflow vulnerability in Qualcomm products

Memory corruption while copying the sound model data from user to kernel buffer during sound model register.

7.8
2024-05-06 CVE-2023-43526 Qualcomm Classic Buffer Overflow vulnerability in Qualcomm products

Memory corruption while querying module parameters from Listen Sound model client in kernel from user space.

7.8
2024-05-06 CVE-2023-43530 Qualcomm Integer Overflow or Wraparound vulnerability in Qualcomm products

Memory corruption in HLOS while checking for the storage type.

7.8
2024-05-06 CVE-2023-43531 Qualcomm Access of Uninitialized Pointer vulnerability in Qualcomm products

Memory corruption while verifying the serialized header when the key pairs are generated.

7.8
2024-05-06 CVE-2024-21471 Qualcomm Use After Free vulnerability in Qualcomm products

Memory corruption when IOMMU unmap of a GPU buffer fails in Linux.

7.8
2024-05-06 CVE-2024-21474 Qualcomm Out-of-bounds Write vulnerability in Qualcomm products

Memory corruption when size of buffer from previous call is used without validation or re-initialization.

7.8
2024-05-06 CVE-2024-23351 Qualcomm Unspecified vulnerability in Qualcomm products

Memory corruption as GPU registers beyond the last protected range can be accessed through LPAC submissions.

7.8
2024-05-06 CVE-2024-23354 Qualcomm Use After Free vulnerability in Qualcomm products

Memory corruption when the IOCTL call is interrupted by a signal.

7.8
2024-05-06 CVE-2024-20064 Google Out-of-bounds Write vulnerability in Google Android 13.0/14.0

In wlan service, there is a possible out of bounds write due to improper input validation.

7.8
2024-05-06 CVE-2024-3661 Fortinet
Cisco
Paloaltonetworks
Citrix
F5
Watchguard
Zscaler
Missing Authentication for Critical Function vulnerability in multiple products

DHCP can add routes to a client’s routing table via the classless static route option (121).

7.6
2024-05-07 CVE-2024-32663 Oisf Allocation of Resources Without Limits or Throttling vulnerability in Oisf Suricata

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine.

7.5
2024-05-08 CVE-2024-32049 F5 Unspecified vulnerability in F5 Big-Ip Next Central Manager

BIG-IP Next Central Manager (CM) may allow an unauthenticated, remote attacker to obtain the BIG-IP Next LTM/WAF instance credentials.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

7.4
2024-05-07 CVE-2024-32664 Oisf Classic Buffer Overflow vulnerability in Oisf Suricata

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine.

7.3
2024-05-08 CVE-2024-22460 Dell Unspecified vulnerability in Dell Dm5500 Firmware 5.14.0.0/5.15.0.0

Dell PowerProtect DM5500 version 5.15.0.0 and prior contains an insecure deserialization Vulnerability.

7.2
2024-05-06 CVE-2023-33119 Qualcomm Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in Qualcomm products

Memory corruption while loading a VM from a signed VM image that is not coherent in the processor cache.

7.0

78 Medium Vulnerabilities

DATE CVE VENDOR VULNERABILITY CVSS
2024-05-07 CVE-2024-20865 Samsung Unspecified vulnerability in Samsung Android 12.0/13.0

Authentication bypass in bootloader prior to SMR May-2024 Release 1 allows physical attackers to flash arbitrary images.

6.8
2024-05-07 CVE-2024-20861 Samsung Use After Free vulnerability in Samsung Android 12.0/13.0

Use after free vulnerability in SveService prior to SMR May-2024 Release 1 allows local privileged attackers to cause memory corruption.

6.7
2024-05-07 CVE-2024-20862 Samsung Out-of-bounds Write vulnerability in Samsung Android 11.0/12.0

Out-of-bounds write in SveService prior to SMR May-2024 Release 1 allows local privileged attackers to execute arbitrary code.

6.7
2024-05-07 CVE-2024-20863 Samsung Out-of-bounds Write vulnerability in Samsung Android 12.0/13.0

Out of bounds write vulnerability in SNAP in HAL prior to SMR May-2024 Release 1 allows local privileged attackers to execute arbitrary code.

6.7
2024-05-06 CVE-2023-32873 Google Out-of-bounds Write vulnerability in Google Android 12.0/13.0/14.0

In keyInstall, there is a possible out of bounds write due to a missing bounds check.

6.7
2024-05-07 CVE-2024-20866 Samsung Unspecified vulnerability in Samsung Android 12.0/13.0

Authentication bypass vulnerability in Setupwizard prior to SMR May-2024 Release 1 allows physical attackers to skip activation step.

6.6
2024-05-08 CVE-2024-24908 Dell Unspecified vulnerability in Dell Dm5500 Firmware 5.14.0.0/5.15.0.0

Dell PowerProtect DM5500 version 5.15.0.0 and prior contain an Arbitrary File Delete via Path Traversal vulnerability.

6.5
2024-05-07 CVE-2021-35001 BMC Unspecified vulnerability in BMC Track-It!

BMC Track-It! GetData Missing Authorization Information Disclosure Vulnerability.

6.5
2024-05-07 CVE-2024-23709 Google Out-of-bounds Write vulnerability in Google Android

In multiple locations, there is a possible out of bounds write due to a heap buffer overflow.

6.5
2024-05-07 CVE-2024-4559 Google
Fedoraproject
Out-of-bounds Write vulnerability in multiple products

Heap buffer overflow in WebAudio in Google Chrome prior to 124.0.6367.155 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

6.5
2024-05-07 CVE-2024-34517 The Cypher component in Neo4j between v.5.0.0 and v.5.19.0 mishandles IMMUTABLE
6.5
2024-05-07 CVE-2024-31456 Glpi Project SQL Injection vulnerability in Glpi-Project Glpi

GLPI is a Free Asset and IT Management Software package.

6.5
2024-05-08 CVE-2024-4649 Campcodes Unspecified vulnerability in Campcodes Complete Web-Based School Management System 1.0

A vulnerability classified as problematic has been found in Campcodes Complete Web-Based School Management System 1.0.

6.1
2024-05-08 CVE-2024-4650 Campcodes Unspecified vulnerability in Campcodes Complete Web-Based School Management System 1.0

A vulnerability classified as problematic was found in Campcodes Complete Web-Based School Management System 1.0.

6.1
2024-05-08 CVE-2024-4651 Campcodes Unspecified vulnerability in Campcodes Complete Web-Based School Management System 1.0

A vulnerability, which was classified as problematic, has been found in Campcodes Complete Web-Based School Management System 1.0.

6.1
2024-05-08 CVE-2024-4652 Campcodes Unspecified vulnerability in Campcodes Complete Web-Based School Management System 1.0

A vulnerability, which was classified as problematic, was found in Campcodes Complete Web-Based School Management System 1.0.

6.1
2024-05-08 CVE-2024-4646 Campcodes Unspecified vulnerability in Campcodes Complete Web-Based School Management System 1.0

A vulnerability was found in Campcodes Complete Web-Based School Management System 1.0.

6.1
2024-05-08 CVE-2024-4647 Campcodes Unspecified vulnerability in Campcodes Complete Web-Based School Management System 1.0

A vulnerability was found in Campcodes Complete Web-Based School Management System 1.0.

6.1
2024-05-08 CVE-2024-4648 Campcodes Unspecified vulnerability in Campcodes Complete Web-Based School Management System 1.0

A vulnerability was found in Campcodes Complete Web-Based School Management System 1.0.

6.1
2024-05-06 CVE-2024-23186 Open Xchange Cross-site Scripting vulnerability in Open-Xchange OX APP Suite

E-Mail containing malicious display-name information could trigger client-side script execution when using specific mobile devices.

6.1
2024-05-06 CVE-2024-23187 Open Xchange Cross-site Scripting vulnerability in Open-Xchange OX APP Suite

Content-ID based embedding of resources in E-Mails could be abused to trigger client-side script code when using the "show more" option.

6.1
2024-05-06 CVE-2024-4524 Campcodes Unspecified vulnerability in Campcodes Complete Web-Based School Management System 1.0

A vulnerability, which was classified as problematic, was found in Campcodes Complete Web-Based School Management System 1.0.

6.1
2024-05-06 CVE-2024-4525 Campcodes Unspecified vulnerability in Campcodes Complete Web-Based School Management System 1.0

A vulnerability has been found in Campcodes Complete Web-Based School Management System 1.0 and classified as problematic.

6.1
2024-05-06 CVE-2024-4526 Campcodes Unspecified vulnerability in Campcodes Complete Web-Based School Management System 1.0

A vulnerability was found in Campcodes Complete Web-Based School Management System 1.0 and classified as problematic.

6.1
2024-05-06 CVE-2024-4527 Campcodes Unspecified vulnerability in Campcodes Complete Web-Based School Management System 1.0

A vulnerability was found in Campcodes Complete Web-Based School Management System 1.0.

6.1
2024-05-06 CVE-2024-4521 Campcodes Unspecified vulnerability in Campcodes Complete Web-Based School Management System 1.0

A vulnerability classified as problematic has been found in Campcodes Complete Web-Based School Management System 1.0.

6.1
2024-05-06 CVE-2024-4522 Campcodes Unspecified vulnerability in Campcodes Complete Web-Based School Management System 1.0

A vulnerability classified as problematic was found in Campcodes Complete Web-Based School Management System 1.0.

6.1
2024-05-06 CVE-2024-4523 Campcodes Unspecified vulnerability in Campcodes Complete Web-Based School Management System 1.0

A vulnerability, which was classified as problematic, has been found in Campcodes Complete Web-Based School Management System 1.0.

6.1
2024-05-06 CVE-2024-4518 Campcodes Unspecified vulnerability in Campcodes Complete Web-Based School Management System 1.0

A vulnerability was found in Campcodes Complete Web-Based School Management System 1.0.

6.1
2024-05-06 CVE-2024-4519 Campcodes Unspecified vulnerability in Campcodes Complete Web-Based School Management System 1.0

A vulnerability was found in Campcodes Complete Web-Based School Management System 1.0.

6.1
2024-05-06 CVE-2024-4516 Campcodes Unspecified vulnerability in Campcodes Complete Web-Based School Management System 1.0

A vulnerability was found in Campcodes Complete Web-Based School Management System 1.0 and classified as problematic.

6.1
2024-05-06 CVE-2024-4517 Campcodes Unspecified vulnerability in Campcodes Complete Web-Based School Management System 1.0

A vulnerability was found in Campcodes Complete Web-Based School Management System 1.0.

6.1
2024-05-06 CVE-2024-4513 Campcodes Unspecified vulnerability in Campcodes Complete Web-Based School Management System 1.0

A vulnerability, which was classified as problematic, has been found in Campcodes Complete Web-Based School Management System 1.0.

6.1
2024-05-06 CVE-2024-4514 Campcodes Unspecified vulnerability in Campcodes Complete Web-Based School Management System 1.0

A vulnerability, which was classified as problematic, was found in Campcodes Complete Web-Based School Management System 1.0.

6.1
2024-05-06 CVE-2024-4515 Campcodes Unspecified vulnerability in Campcodes Complete Web-Based School Management System 1.0

A vulnerability has been found in Campcodes Complete Web-Based School Management System 1.0 and classified as problematic.

6.1
2024-05-07 CVE-2024-0022 Google Unspecified vulnerability in Google Android 13.0/14.0

In multiple functions of CompanionDeviceManagerService.java, there is a possible launch NotificationAccessConfirmationActivity of another user profile due to improper input validation.

5.5
2024-05-07 CVE-2024-0026 Google Allocation of Resources Without Limits or Throttling vulnerability in Google Android

In multiple functions of SnoozeHelper.java, there is a possible persistent denial of service due to resource exhaustion.

5.5
2024-05-07 CVE-2024-0027 Google Allocation of Resources Without Limits or Throttling vulnerability in Google Android

In multiple functions of SnoozeHelper.java, there is a possible way to cause a boot loop due to resource exhaustion.

5.5
2024-05-07 CVE-2024-23712 Google Unspecified vulnerability in Google Android

In multiple functions of AppOpsService.java, there is a possible way to saturate the content of /data/system/appops_accesses.xml due to resource exhaustion.

5.5
2024-05-07 CVE-2024-31078 Openatom NULL Pointer Dereference vulnerability in Openatom Openharmony

in OpenHarmony v4.0.0 and prior versions allow a local attacker cause service crash through NULL pointer dereference.

5.5
2024-05-07 CVE-2024-3757 Openatom Integer Overflow or Wraparound vulnerability in Openatom Openharmony

in OpenHarmony v4.0.0 and prior versions allow a local attacker cause service crash through integer overflow.

5.5
2024-05-07 CVE-2024-20857 Samsung Unspecified vulnerability in Samsung Android 12.0/13.0

Improper access control vulnerability in startListening of CocktailBarService prior to SMR May-2024 Release 1 allows local attackers to access information of current application.

5.5
2024-05-07 CVE-2024-20858 Samsung Unspecified vulnerability in Samsung Android 12.0/13.0

Improper access control vulnerability in setCocktailHostCallbacks of CocktailBarService prior to SMR May-2024 Release 1 allows local attackers to access information of current application.

5.5
2024-05-07 CVE-2024-20859 Samsung Unspecified vulnerability in Samsung Android 12.0/13.0

Improper access control vulnerability in FactoryCamera prior to SMR May-2024 Release 1 allows local attackers to take pictures without privilege.

5.5
2024-05-07 CVE-2024-20864 Samsung Unspecified vulnerability in Samsung Android 14.0

Improper access control vulnerability in DarManagerService prior to SMR May-2024 Release 1 allows local attackers to monitor system resources.

5.5
2024-05-06 CVE-2024-4568 Xpdfreader Uncontrolled Recursion vulnerability in Xpdfreader Xpdf

In Xpdf 4.05 (and earlier), a PDF object loop in the PDF resources leads to infinite recursion and a stack overflow.

5.5
2024-05-06 CVE-2023-43527 Qualcomm Out-of-bounds Read vulnerability in Qualcomm products

Information disclosure while parsing dts header atom in Video.

5.5
2024-05-06 CVE-2023-43528 Qualcomm Out-of-bounds Read vulnerability in Qualcomm products

Information disclosure when the ADSP payload size received in HLOS in response to Audio Stream Manager matrix session is less than this expected size.

5.5
2024-05-08 CVE-2024-4645 Fast5 Unspecified vulnerability in Fast5 Prison Management System 1.0

A vulnerability was found in SourceCodester Prison Management System 1.0 and classified as problematic.

5.4
2024-05-08 CVE-2024-34547 Wpthemespace Unspecified vulnerability in Wpthemespace Magical Addons for Elementor

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Noor alam Magical Addons For Elementor allows Stored XSS.This issue affects Magical Addons For Elementor: from n/a through 1.1.34.

5.4
2024-05-08 CVE-2024-4644 Fast5 Unspecified vulnerability in Fast5 Prison Management System 1.0

A vulnerability has been found in SourceCodester Prison Management System 1.0 and classified as problematic.

5.4
2024-05-08 CVE-2024-34562 Moveaddons Unspecified vulnerability in Moveaddons Move Addons for Elementor

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Moveaddons Move Addons for Elementor allows Stored XSS.This issue affects Move Addons for Elementor: from n/a through 1.3.0.

5.4
2024-05-08 CVE-2024-34566 Vanderwijk Unspecified vulnerability in Vanderwijk Content Blocks

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Johan van der Wijk Content Blocks (Custom Post Widget) allows Stored XSS.This issue affects Content Blocks (Custom Post Widget): from n/a through 3.3.0.

5.4
2024-05-08 CVE-2024-4281 Ylefebvre Cross-site Scripting vulnerability in Ylefebvre Link Library

The Link Library plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'link-library' shortcode in all versions up to, and including, 7.6.11 due to insufficient input sanitization and output escaping on user supplied attributes.

5.4
2024-05-06 CVE-2024-34373 Posimyth Unspecified vulnerability in Posimyth the Plus Addons for Elementor

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in POSIMYTH The Plus Addons for Elementor Page Builder Lite allows Stored XSS.This issue affects The Plus Addons for Elementor Page Builder Lite: from n/a through 5.4.2.

5.4
2024-05-06 CVE-2024-34374 Quomodosoft Unspecified vulnerability in Quomodosoft Elementsready

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in QuomodoSoft ElementsReady Addons for Elementor allows Stored XSS.This issue affects ElementsReady Addons for Elementor: from n/a through 5.8.0.

5.4
2024-05-06 CVE-2024-34381 WP Property Hive Unspecified vulnerability in Wp-Property-Hive Propertyhive

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PropertyHive allows Stored XSS.This issue affects PropertyHive: from n/a through 2.0.10.

5.4
2024-05-06 CVE-2024-4512 Fast5 Unspecified vulnerability in Fast5 Prison Management System 1.0

A vulnerability classified as problematic was found in SourceCodester Prison Management System 1.0.

5.4
2024-05-07 CVE-2024-32867 Oisf Improper Check for Unusual or Exceptional Conditions vulnerability in Oisf Suricata

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine.

5.3
2024-05-07 CVE-2024-4536 Eclipse Insufficiently Protected Credentials vulnerability in Eclipse EDC Connector

In Eclipse Dataspace Components from version 0.2.1 to 0.6.2, in the EDC Connector component ( https://github.com/eclipse-edc/Connector ), an attacker might obtain OAuth2 client secrets from the vault. In Eclipse Dataspace Components from version 0.2.1 to 0.6.2, we have identified a security vulnerability in the EDC Connector component ( https://github.com/eclipse-edc/Connector ) regarding the OAuth2-protected data sink feature.

5.3
2024-05-08 CVE-2024-28971 Dell Insufficiently Protected Credentials vulnerability in Dell Openmanage Enterprise Update Manager

Dell Update Manager Plugin, versions 1.4.0 through 1.5.0, contains a Plain-text Password Storage Vulnerability in Log file.

4.9
2024-05-07 CVE-2024-34314 Cmseasy Unspecified vulnerability in Cmseasy 7.7.7.9

CmsEasy v7.7.7.9 was discovered to contain a local file inclusion vunerability via the file_get_contents function in the fetch_action method of /admin/template_admin.php.

4.9
2024-05-08 CVE-2024-34570 Wpxpro Unspecified vulnerability in Wpxpro Xpro Addons for Elementor

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Xpro Xpro Elementor Addons allows Stored XSS.This issue affects Xpro Elementor Addons: from n/a through 1.4.3.

4.8
2024-05-06 CVE-2024-4528 Fast5 Unspecified vulnerability in Fast5 Prison Management System 1.0

A vulnerability was found in SourceCodester Prison Management System 1.0.

4.8
2024-05-07 CVE-2024-4594 Dedecms Unspecified vulnerability in Dedecms 5.7

A vulnerability, which was classified as problematic, was found in DedeCMS 5.7.

4.3
2024-05-07 CVE-2024-28148 Apache Unspecified vulnerability in Apache Superset

An authenticated user could potentially access metadata for a datasource they are not authorized to view by submitting a targeted REST API request.This issue affects Apache Superset: before 3.1.2. Users are recommended to upgrade to version 3.1.2 or above, which fixes the issue.

4.3
2024-05-07 CVE-2024-4590 Dedecms Unspecified vulnerability in Dedecms 5.7

A vulnerability was found in DedeCMS 5.7.

4.3
2024-05-07 CVE-2024-4591 Dedecms Unspecified vulnerability in Dedecms 5.7

A vulnerability classified as problematic has been found in DedeCMS 5.7.

4.3
2024-05-07 CVE-2024-4592 Dedecms Unspecified vulnerability in Dedecms 5.7

A vulnerability classified as problematic was found in DedeCMS 5.7.

4.3
2024-05-07 CVE-2024-4593 Dedecms Unspecified vulnerability in Dedecms 5.7

A vulnerability, which was classified as problematic, has been found in DedeCMS 5.7.

4.3
2024-05-07 CVE-2024-4586 Dedecms Unspecified vulnerability in Dedecms 5.7

A vulnerability has been found in DedeCMS 5.7 and classified as problematic.

4.3
2024-05-07 CVE-2024-4587 Dedecms Unspecified vulnerability in Dedecms 5.7

A vulnerability was found in DedeCMS 5.7 and classified as problematic.

4.3
2024-05-07 CVE-2024-4588 Dedecms Unspecified vulnerability in Dedecms 5.7

A vulnerability was found in DedeCMS 5.7.

4.3
2024-05-07 CVE-2024-4589 Dedecms Unspecified vulnerability in Dedecms 5.7

A vulnerability was found in DedeCMS 5.7.

4.3
2024-05-07 CVE-2024-4585 Dedecms Unspecified vulnerability in Dedecms 5.7

A vulnerability, which was classified as problematic, was found in DedeCMS 5.7.

4.3
2024-05-07 CVE-2024-20856 Samsung Improper Authentication vulnerability in Samsung Android 14.0

Improper Authentication vulnerability in Secure Folder prior to SMR May-2024 Release 1 allows physical attackers to access Secure Folder without proper authentication in a specific scenario.

4.3
2024-05-06 CVE-2024-34387 Afthemes Unspecified vulnerability in Afthemes WP Post Author

Missing Authorization vulnerability in AF themes WP Post Author.This issue affects WP Post Author: from n/a through 3.6.4.

4.3
2024-05-06 CVE-2024-34389 Afthemes Unspecified vulnerability in Afthemes WP Post Author

Missing Authorization vulnerability in AF themes WP Post Author.This issue affects WP Post Author: from n/a through 3.6.4.

4.3

2 Low Vulnerabilities

DATE CVE VENDOR VULNERABILITY CVSS
2024-05-07 CVE-2024-20860 Samsung Unspecified vulnerability in Samsung Android 14.0

Improper export of android application components vulnerability in TelephonyUI prior to SMR May-2024 Release 1 allows local attackers to reboot the device without proper permission.

3.3
2024-05-07 CVE-2024-20855 Samsung Unspecified vulnerability in Samsung Android 14.0

Improper access control vulnerability in multitasking framework prior to SMR May-2024 Release 1 allows physical attackers to access unlocked screen for a while.

2.4