Weekly Vulnerabilities Reports > May 6 to 12, 2024
Overview
125 new vulnerabilities reported during this period, including 6 critical vulnerabilities and 39 high severity vulnerabilities. This weekly summary report vulnerabilities in 285 products from 38 vendors including Campcodes, Google, Qualcomm, Samsung, and Dedecms. Vulnerabilities are notably categorized as "Out-of-bounds Write", "Use After Free", "Classic Buffer Overflow", "SQL Injection", and "Cross-site Scripting".
- 73 reported vulnerabilities are remotely exploitables.
- 12 reported vulnerabilities are related to weaknesses in OWASP Top Ten.
- 54 reported vulnerabilities are exploitable by an anonymous user.
- Campcodes has the most reported vulnerabilities, with 21 reported vulnerabilities.
- Apache has the most reported critical vulnerabilities, with 2 reported vulnerabilities.
VULNERABILITIES
VULNERABILITIES
VULNERABILITIES
VULNERABILITIES
VULNERABILITIES
EXPLOITABLE
EXPLOITABLE
AVAILABLE
ANONYMOUSLY
WEB APPLICATION
Vulnerability Details
The following table list reported vulnerabilities for the period covered by this report:
6 Critical Vulnerabilities
DATE | CVE | VENDOR | VULNERABILITY | CVSS |
---|---|---|---|---|
2024-05-08 | CVE-2024-21793 | F5 | SQL Injection vulnerability in F5 Big-Ip Next Central Manager 20.1.0 An OData injection vulnerability exists in the BIG-IP Next Central Manager API (URI). Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. | 9.8 |
2024-05-08 | CVE-2024-26026 | F5 | SQL Injection vulnerability in F5 Big-Ip Next Central Manager 20.1.0 An SQL injection vulnerability exists in the BIG-IP Next Central Manager API (URI). Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated | 9.8 |
2024-05-08 | CVE-2024-26579 | Apache | Unspecified vulnerability in Apache Inlong Deserialization of Untrusted Data vulnerability in Apache InLong.This issue affects Apache InLong: from 1.7.0 through 1.11.0, the attackers can bypass using malicious parameters. Users are advised to upgrade to Apache InLong's 1.12.0 or cherry-pick [1], [2] to solve it. [1] https://github.com/apache/inlong/pull/9694 [2] https://github.com/apache/inlong/pull/9707 | 9.8 |
2024-05-08 | CVE-2024-32113 | Apache | Unspecified vulnerability in Apache Ofbiz Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache OFBiz.This issue affects Apache OFBiz: before 18.12.13. Users are recommended to upgrade to version 18.12.13, which fixes the issue. | 9.8 |
2024-05-06 | CVE-2024-21480 | Qualcomm | Classic Buffer Overflow vulnerability in Qualcomm products Memory corruption while playing audio file having large-sized input buffer. | 9.8 |
2024-05-07 | CVE-2024-4558 | Google Fedoraproject Apple | Use After Free vulnerability in multiple products Use after free in ANGLE in Google Chrome prior to 124.0.6367.155 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | 9.6 |
39 High Vulnerabilities
DATE | CVE | VENDOR | VULNERABILITY | CVSS |
---|---|---|---|---|
2024-05-08 | CVE-2024-24833 | Leevio | Unspecified vulnerability in Leevio Happy Addons for Elementor Missing Authorization vulnerability in Leevio Happy Addons for Elementor.This issue affects Happy Addons for Elementor: from n/a through 3.10.1. | 8.8 |
2024-05-07 | CVE-2021-35002 | BMC | Unspecified vulnerability in BMC Track-It! BMC Track-It! Unrestricted File Upload Remote Code Execution Vulnerability. | 8.8 |
2024-05-06 | CVE-2024-33570 | Wpmet | Unspecified vulnerability in Wpmet Metform Elementor Contact Form Builder Missing Authorization vulnerability in Wpmet Metform Elementor Contact Form Builder.This issue affects Metform Elementor Contact Form Builder: from n/a through 3.8.3. | 8.8 |
2024-05-06 | CVE-2024-33912 | Kodezen | Unspecified vulnerability in Kodezen Academy LMS Missing Authorization vulnerability in Academy LMS.This issue affects Academy LMS: from n/a through 1.9.16. | 8.8 |
2024-05-07 | CVE-2024-29889 | Glpi Project | SQL Injection vulnerability in Glpi-Project Glpi GLPI is a Free Asset and IT Management Software package. | 8.1 |
2024-05-08 | CVE-2024-33612 | F5 | Improper Certificate Validation vulnerability in F5 Big-Ip Next Central Manager 20.1.0 An improper certificate validation vulnerability exists in BIG-IP Next Central Manager and may allow an attacker to impersonate an Instance Provider system. | 8.0 |
2024-05-08 | CVE-2024-2860 | Broadcom | Missing Authentication for Critical Function vulnerability in Broadcom Brocade Sannav The PostgreSQL implementation in Brocade SANnav versions before 2.3.0a is vulnerable to an incorrect local authentication flaw. | 7.8 |
2024-05-07 | CVE-2024-0024 | Unspecified vulnerability in Google Android In multiple methods of UserManagerService.java, there is a possible failure to persist or enforce user restrictions due to improper input validation. | 7.8 | |
2024-05-07 | CVE-2024-0025 | Unspecified vulnerability in Google Android In sendIntentSender of ActivityManagerService.java, there is a possible background activity launch due to a logic error. | 7.8 | |
2024-05-07 | CVE-2024-0042 | Improper Certificate Validation vulnerability in Google Android In TBD of TBD, there is a possible confusion of OEM and DRM certificates due to improperly used crypto. | 7.8 | |
2024-05-07 | CVE-2024-0043 | Unspecified vulnerability in Google Android In multiple locations, there is a possible notification listener grant to an app running in the work profile due to a logic error in the code. | 7.8 | |
2024-05-07 | CVE-2024-23704 | Missing Authorization vulnerability in Google Android 13.0/14.0 In onCreate of WifiDialogActivity.java, there is a possible way to bypass the DISALLOW_ADD_WIFI_CONFIG restriction due to a missing permission check. | 7.8 | |
2024-05-07 | CVE-2024-23705 | Unspecified vulnerability in Google Android In multiple locations, there is a possible failure to persist or enforce user restrictions due to improper input validation. | 7.8 | |
2024-05-07 | CVE-2024-23706 | Unspecified vulnerability in Google Android 14.0 In multiple locations, there is a possible bypass of health data permissions due to an improper input validation. | 7.8 | |
2024-05-07 | CVE-2024-23707 | Unspecified vulnerability in Google Android 14.0 In multiple locations, there is a possible permissions bypass due to improper input validation. | 7.8 | |
2024-05-07 | CVE-2024-23708 | Unspecified vulnerability in Google Android In multiple functions of NotificationManagerService.java, there is a possible way to not show a toast message when a clipboard message has been accessed. | 7.8 | |
2024-05-07 | CVE-2024-23710 | Unspecified vulnerability in Google Android 13.0/14.0 In assertPackageWithSharedUserIdIsPrivileged of InstallPackageHelper.java, there is a possible execution of arbitrary app code as a privileged app due to a logic error in the code. | 7.8 | |
2024-05-07 | CVE-2024-23713 | Unspecified vulnerability in Google Android In migrateNotificationFilter of NotificationManagerService.java, there is a possible failure to persist notifications settings due to improper input validation. | 7.8 | |
2024-05-07 | CVE-2024-23808 | Openatom | NULL Pointer Dereference vulnerability in Openatom Openharmony in OpenHarmony v4.0.0 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through use after free or cause DOS through NULL pointer dereference. | 7.8 |
2024-05-07 | CVE-2024-27217 | Openatom | Use After Free vulnerability in Openatom Openharmony in OpenHarmony v4.0.0 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through use after free. | 7.8 |
2024-05-07 | CVE-2024-3758 | Openatom | Out-of-bounds Write vulnerability in Openatom Openharmony in OpenHarmony v4.0.0 and prior versions allow a local attacker arbitrary code execution in TCB through heap buffer overflow. | 7.8 |
2024-05-07 | CVE-2024-3759 | Openatom | Use After Free vulnerability in Openatom Openharmony in OpenHarmony v4.0.0 and prior versions allow a local attacker arbitrary code execution in TCB through use after free. | 7.8 |
2024-05-06 | CVE-2023-43521 | Qualcomm | Use After Free vulnerability in Qualcomm products Memory corruption when multiple listeners are being registered with the same file descriptor. | 7.8 |
2024-05-06 | CVE-2023-43524 | Qualcomm | Classic Buffer Overflow vulnerability in Qualcomm products Memory corruption when the bandpass filter order received from AHAL is not within the expected range. | 7.8 |
2024-05-06 | CVE-2023-43525 | Qualcomm | Classic Buffer Overflow vulnerability in Qualcomm products Memory corruption while copying the sound model data from user to kernel buffer during sound model register. | 7.8 |
2024-05-06 | CVE-2023-43526 | Qualcomm | Classic Buffer Overflow vulnerability in Qualcomm products Memory corruption while querying module parameters from Listen Sound model client in kernel from user space. | 7.8 |
2024-05-06 | CVE-2023-43530 | Qualcomm | Integer Overflow or Wraparound vulnerability in Qualcomm products Memory corruption in HLOS while checking for the storage type. | 7.8 |
2024-05-06 | CVE-2023-43531 | Qualcomm | Access of Uninitialized Pointer vulnerability in Qualcomm products Memory corruption while verifying the serialized header when the key pairs are generated. | 7.8 |
2024-05-06 | CVE-2024-21471 | Qualcomm | Use After Free vulnerability in Qualcomm products Memory corruption when IOMMU unmap of a GPU buffer fails in Linux. | 7.8 |
2024-05-06 | CVE-2024-21474 | Qualcomm | Out-of-bounds Write vulnerability in Qualcomm products Memory corruption when size of buffer from previous call is used without validation or re-initialization. | 7.8 |
2024-05-06 | CVE-2024-23351 | Qualcomm | Unspecified vulnerability in Qualcomm products Memory corruption as GPU registers beyond the last protected range can be accessed through LPAC submissions. | 7.8 |
2024-05-06 | CVE-2024-23354 | Qualcomm | Use After Free vulnerability in Qualcomm products Memory corruption when the IOCTL call is interrupted by a signal. | 7.8 |
2024-05-06 | CVE-2024-20064 | Out-of-bounds Write vulnerability in Google Android 13.0/14.0 In wlan service, there is a possible out of bounds write due to improper input validation. | 7.8 | |
2024-05-06 | CVE-2024-3661 | Fortinet Cisco Paloaltonetworks Citrix F5 Watchguard Zscaler | Missing Authentication for Critical Function vulnerability in multiple products DHCP can add routes to a client’s routing table via the classless static route option (121). | 7.6 |
2024-05-07 | CVE-2024-32663 | Oisf | Allocation of Resources Without Limits or Throttling vulnerability in Oisf Suricata Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. | 7.5 |
2024-05-08 | CVE-2024-32049 | F5 | Unspecified vulnerability in F5 Big-Ip Next Central Manager BIG-IP Next Central Manager (CM) may allow an unauthenticated, remote attacker to obtain the BIG-IP Next LTM/WAF instance credentials. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. | 7.4 |
2024-05-07 | CVE-2024-32664 | Oisf | Classic Buffer Overflow vulnerability in Oisf Suricata Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. | 7.3 |
2024-05-08 | CVE-2024-22460 | Dell | Unspecified vulnerability in Dell Dm5500 Firmware 5.14.0.0/5.15.0.0 Dell PowerProtect DM5500 version 5.15.0.0 and prior contains an insecure deserialization Vulnerability. | 7.2 |
2024-05-06 | CVE-2023-33119 | Qualcomm | Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in Qualcomm products Memory corruption while loading a VM from a signed VM image that is not coherent in the processor cache. | 7.0 |
78 Medium Vulnerabilities
DATE | CVE | VENDOR | VULNERABILITY | CVSS |
---|---|---|---|---|
2024-05-07 | CVE-2024-20865 | Samsung | Unspecified vulnerability in Samsung Android 12.0/13.0 Authentication bypass in bootloader prior to SMR May-2024 Release 1 allows physical attackers to flash arbitrary images. | 6.8 |
2024-05-07 | CVE-2024-20861 | Samsung | Use After Free vulnerability in Samsung Android 12.0/13.0 Use after free vulnerability in SveService prior to SMR May-2024 Release 1 allows local privileged attackers to cause memory corruption. | 6.7 |
2024-05-07 | CVE-2024-20862 | Samsung | Out-of-bounds Write vulnerability in Samsung Android 11.0/12.0 Out-of-bounds write in SveService prior to SMR May-2024 Release 1 allows local privileged attackers to execute arbitrary code. | 6.7 |
2024-05-07 | CVE-2024-20863 | Samsung | Out-of-bounds Write vulnerability in Samsung Android 12.0/13.0 Out of bounds write vulnerability in SNAP in HAL prior to SMR May-2024 Release 1 allows local privileged attackers to execute arbitrary code. | 6.7 |
2024-05-06 | CVE-2023-32873 | Out-of-bounds Write vulnerability in Google Android 12.0/13.0/14.0 In keyInstall, there is a possible out of bounds write due to a missing bounds check. | 6.7 | |
2024-05-07 | CVE-2024-20866 | Samsung | Unspecified vulnerability in Samsung Android 12.0/13.0 Authentication bypass vulnerability in Setupwizard prior to SMR May-2024 Release 1 allows physical attackers to skip activation step. | 6.6 |
2024-05-08 | CVE-2024-24908 | Dell | Unspecified vulnerability in Dell Dm5500 Firmware 5.14.0.0/5.15.0.0 Dell PowerProtect DM5500 version 5.15.0.0 and prior contain an Arbitrary File Delete via Path Traversal vulnerability. | 6.5 |
2024-05-07 | CVE-2021-35001 | BMC | Unspecified vulnerability in BMC Track-It! BMC Track-It! GetData Missing Authorization Information Disclosure Vulnerability. | 6.5 |
2024-05-07 | CVE-2024-23709 | Out-of-bounds Write vulnerability in Google Android In multiple locations, there is a possible out of bounds write due to a heap buffer overflow. | 6.5 | |
2024-05-07 | CVE-2024-4559 | Google Fedoraproject | Out-of-bounds Write vulnerability in multiple products Heap buffer overflow in WebAudio in Google Chrome prior to 124.0.6367.155 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | 6.5 |
2024-05-07 | CVE-2024-34517 | The Cypher component in Neo4j between v.5.0.0 and v.5.19.0 mishandles IMMUTABLE | 6.5 | |
2024-05-07 | CVE-2024-31456 | Glpi Project | SQL Injection vulnerability in Glpi-Project Glpi GLPI is a Free Asset and IT Management Software package. | 6.5 |
2024-05-08 | CVE-2024-4649 | Campcodes | Unspecified vulnerability in Campcodes Complete Web-Based School Management System 1.0 A vulnerability classified as problematic has been found in Campcodes Complete Web-Based School Management System 1.0. | 6.1 |
2024-05-08 | CVE-2024-4650 | Campcodes | Unspecified vulnerability in Campcodes Complete Web-Based School Management System 1.0 A vulnerability classified as problematic was found in Campcodes Complete Web-Based School Management System 1.0. | 6.1 |
2024-05-08 | CVE-2024-4651 | Campcodes | Unspecified vulnerability in Campcodes Complete Web-Based School Management System 1.0 A vulnerability, which was classified as problematic, has been found in Campcodes Complete Web-Based School Management System 1.0. | 6.1 |
2024-05-08 | CVE-2024-4652 | Campcodes | Unspecified vulnerability in Campcodes Complete Web-Based School Management System 1.0 A vulnerability, which was classified as problematic, was found in Campcodes Complete Web-Based School Management System 1.0. | 6.1 |
2024-05-08 | CVE-2024-4646 | Campcodes | Unspecified vulnerability in Campcodes Complete Web-Based School Management System 1.0 A vulnerability was found in Campcodes Complete Web-Based School Management System 1.0. | 6.1 |
2024-05-08 | CVE-2024-4647 | Campcodes | Unspecified vulnerability in Campcodes Complete Web-Based School Management System 1.0 A vulnerability was found in Campcodes Complete Web-Based School Management System 1.0. | 6.1 |
2024-05-08 | CVE-2024-4648 | Campcodes | Unspecified vulnerability in Campcodes Complete Web-Based School Management System 1.0 A vulnerability was found in Campcodes Complete Web-Based School Management System 1.0. | 6.1 |
2024-05-06 | CVE-2024-23186 | Open Xchange | Cross-site Scripting vulnerability in Open-Xchange OX APP Suite E-Mail containing malicious display-name information could trigger client-side script execution when using specific mobile devices. | 6.1 |
2024-05-06 | CVE-2024-23187 | Open Xchange | Cross-site Scripting vulnerability in Open-Xchange OX APP Suite Content-ID based embedding of resources in E-Mails could be abused to trigger client-side script code when using the "show more" option. | 6.1 |
2024-05-06 | CVE-2024-4524 | Campcodes | Unspecified vulnerability in Campcodes Complete Web-Based School Management System 1.0 A vulnerability, which was classified as problematic, was found in Campcodes Complete Web-Based School Management System 1.0. | 6.1 |
2024-05-06 | CVE-2024-4525 | Campcodes | Unspecified vulnerability in Campcodes Complete Web-Based School Management System 1.0 A vulnerability has been found in Campcodes Complete Web-Based School Management System 1.0 and classified as problematic. | 6.1 |
2024-05-06 | CVE-2024-4526 | Campcodes | Unspecified vulnerability in Campcodes Complete Web-Based School Management System 1.0 A vulnerability was found in Campcodes Complete Web-Based School Management System 1.0 and classified as problematic. | 6.1 |
2024-05-06 | CVE-2024-4527 | Campcodes | Unspecified vulnerability in Campcodes Complete Web-Based School Management System 1.0 A vulnerability was found in Campcodes Complete Web-Based School Management System 1.0. | 6.1 |
2024-05-06 | CVE-2024-4521 | Campcodes | Unspecified vulnerability in Campcodes Complete Web-Based School Management System 1.0 A vulnerability classified as problematic has been found in Campcodes Complete Web-Based School Management System 1.0. | 6.1 |
2024-05-06 | CVE-2024-4522 | Campcodes | Unspecified vulnerability in Campcodes Complete Web-Based School Management System 1.0 A vulnerability classified as problematic was found in Campcodes Complete Web-Based School Management System 1.0. | 6.1 |
2024-05-06 | CVE-2024-4523 | Campcodes | Unspecified vulnerability in Campcodes Complete Web-Based School Management System 1.0 A vulnerability, which was classified as problematic, has been found in Campcodes Complete Web-Based School Management System 1.0. | 6.1 |
2024-05-06 | CVE-2024-4518 | Campcodes | Unspecified vulnerability in Campcodes Complete Web-Based School Management System 1.0 A vulnerability was found in Campcodes Complete Web-Based School Management System 1.0. | 6.1 |
2024-05-06 | CVE-2024-4519 | Campcodes | Unspecified vulnerability in Campcodes Complete Web-Based School Management System 1.0 A vulnerability was found in Campcodes Complete Web-Based School Management System 1.0. | 6.1 |
2024-05-06 | CVE-2024-4516 | Campcodes | Unspecified vulnerability in Campcodes Complete Web-Based School Management System 1.0 A vulnerability was found in Campcodes Complete Web-Based School Management System 1.0 and classified as problematic. | 6.1 |
2024-05-06 | CVE-2024-4517 | Campcodes | Unspecified vulnerability in Campcodes Complete Web-Based School Management System 1.0 A vulnerability was found in Campcodes Complete Web-Based School Management System 1.0. | 6.1 |
2024-05-06 | CVE-2024-4513 | Campcodes | Unspecified vulnerability in Campcodes Complete Web-Based School Management System 1.0 A vulnerability, which was classified as problematic, has been found in Campcodes Complete Web-Based School Management System 1.0. | 6.1 |
2024-05-06 | CVE-2024-4514 | Campcodes | Unspecified vulnerability in Campcodes Complete Web-Based School Management System 1.0 A vulnerability, which was classified as problematic, was found in Campcodes Complete Web-Based School Management System 1.0. | 6.1 |
2024-05-06 | CVE-2024-4515 | Campcodes | Unspecified vulnerability in Campcodes Complete Web-Based School Management System 1.0 A vulnerability has been found in Campcodes Complete Web-Based School Management System 1.0 and classified as problematic. | 6.1 |
2024-05-07 | CVE-2024-0022 | Unspecified vulnerability in Google Android 13.0/14.0 In multiple functions of CompanionDeviceManagerService.java, there is a possible launch NotificationAccessConfirmationActivity of another user profile due to improper input validation. | 5.5 | |
2024-05-07 | CVE-2024-0026 | Allocation of Resources Without Limits or Throttling vulnerability in Google Android In multiple functions of SnoozeHelper.java, there is a possible persistent denial of service due to resource exhaustion. | 5.5 | |
2024-05-07 | CVE-2024-0027 | Allocation of Resources Without Limits or Throttling vulnerability in Google Android In multiple functions of SnoozeHelper.java, there is a possible way to cause a boot loop due to resource exhaustion. | 5.5 | |
2024-05-07 | CVE-2024-23712 | Unspecified vulnerability in Google Android In multiple functions of AppOpsService.java, there is a possible way to saturate the content of /data/system/appops_accesses.xml due to resource exhaustion. | 5.5 | |
2024-05-07 | CVE-2024-31078 | Openatom | NULL Pointer Dereference vulnerability in Openatom Openharmony in OpenHarmony v4.0.0 and prior versions allow a local attacker cause service crash through NULL pointer dereference. | 5.5 |
2024-05-07 | CVE-2024-3757 | Openatom | Integer Overflow or Wraparound vulnerability in Openatom Openharmony in OpenHarmony v4.0.0 and prior versions allow a local attacker cause service crash through integer overflow. | 5.5 |
2024-05-07 | CVE-2024-20857 | Samsung | Unspecified vulnerability in Samsung Android 12.0/13.0 Improper access control vulnerability in startListening of CocktailBarService prior to SMR May-2024 Release 1 allows local attackers to access information of current application. | 5.5 |
2024-05-07 | CVE-2024-20858 | Samsung | Unspecified vulnerability in Samsung Android 12.0/13.0 Improper access control vulnerability in setCocktailHostCallbacks of CocktailBarService prior to SMR May-2024 Release 1 allows local attackers to access information of current application. | 5.5 |
2024-05-07 | CVE-2024-20859 | Samsung | Unspecified vulnerability in Samsung Android 12.0/13.0 Improper access control vulnerability in FactoryCamera prior to SMR May-2024 Release 1 allows local attackers to take pictures without privilege. | 5.5 |
2024-05-07 | CVE-2024-20864 | Samsung | Unspecified vulnerability in Samsung Android 14.0 Improper access control vulnerability in DarManagerService prior to SMR May-2024 Release 1 allows local attackers to monitor system resources. | 5.5 |
2024-05-06 | CVE-2024-4568 | Xpdfreader | Uncontrolled Recursion vulnerability in Xpdfreader Xpdf In Xpdf 4.05 (and earlier), a PDF object loop in the PDF resources leads to infinite recursion and a stack overflow. | 5.5 |
2024-05-06 | CVE-2023-43527 | Qualcomm | Out-of-bounds Read vulnerability in Qualcomm products Information disclosure while parsing dts header atom in Video. | 5.5 |
2024-05-06 | CVE-2023-43528 | Qualcomm | Out-of-bounds Read vulnerability in Qualcomm products Information disclosure when the ADSP payload size received in HLOS in response to Audio Stream Manager matrix session is less than this expected size. | 5.5 |
2024-05-08 | CVE-2024-4645 | Fast5 | Unspecified vulnerability in Fast5 Prison Management System 1.0 A vulnerability was found in SourceCodester Prison Management System 1.0 and classified as problematic. | 5.4 |
2024-05-08 | CVE-2024-34547 | Wpthemespace | Unspecified vulnerability in Wpthemespace Magical Addons for Elementor Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Noor alam Magical Addons For Elementor allows Stored XSS.This issue affects Magical Addons For Elementor: from n/a through 1.1.34. | 5.4 |
2024-05-08 | CVE-2024-4644 | Fast5 | Unspecified vulnerability in Fast5 Prison Management System 1.0 A vulnerability has been found in SourceCodester Prison Management System 1.0 and classified as problematic. | 5.4 |
2024-05-08 | CVE-2024-34562 | Moveaddons | Unspecified vulnerability in Moveaddons Move Addons for Elementor Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Moveaddons Move Addons for Elementor allows Stored XSS.This issue affects Move Addons for Elementor: from n/a through 1.3.0. | 5.4 |
2024-05-08 | CVE-2024-34566 | Vanderwijk | Unspecified vulnerability in Vanderwijk Content Blocks Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Johan van der Wijk Content Blocks (Custom Post Widget) allows Stored XSS.This issue affects Content Blocks (Custom Post Widget): from n/a through 3.3.0. | 5.4 |
2024-05-08 | CVE-2024-4281 | Ylefebvre | Cross-site Scripting vulnerability in Ylefebvre Link Library The Link Library plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'link-library' shortcode in all versions up to, and including, 7.6.11 due to insufficient input sanitization and output escaping on user supplied attributes. | 5.4 |
2024-05-06 | CVE-2024-34373 | Posimyth | Unspecified vulnerability in Posimyth the Plus Addons for Elementor Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in POSIMYTH The Plus Addons for Elementor Page Builder Lite allows Stored XSS.This issue affects The Plus Addons for Elementor Page Builder Lite: from n/a through 5.4.2. | 5.4 |
2024-05-06 | CVE-2024-34374 | Quomodosoft | Unspecified vulnerability in Quomodosoft Elementsready Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in QuomodoSoft ElementsReady Addons for Elementor allows Stored XSS.This issue affects ElementsReady Addons for Elementor: from n/a through 5.8.0. | 5.4 |
2024-05-06 | CVE-2024-34381 | WP Property Hive | Unspecified vulnerability in Wp-Property-Hive Propertyhive Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PropertyHive allows Stored XSS.This issue affects PropertyHive: from n/a through 2.0.10. | 5.4 |
2024-05-06 | CVE-2024-4512 | Fast5 | Unspecified vulnerability in Fast5 Prison Management System 1.0 A vulnerability classified as problematic was found in SourceCodester Prison Management System 1.0. | 5.4 |
2024-05-07 | CVE-2024-32867 | Oisf | Improper Check for Unusual or Exceptional Conditions vulnerability in Oisf Suricata Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. | 5.3 |
2024-05-07 | CVE-2024-4536 | Eclipse | Insufficiently Protected Credentials vulnerability in Eclipse EDC Connector In Eclipse Dataspace Components from version 0.2.1 to 0.6.2, in the EDC Connector component ( https://github.com/eclipse-edc/Connector ), an attacker might obtain OAuth2 client secrets from the vault. In Eclipse Dataspace Components from version 0.2.1 to 0.6.2, we have identified a security vulnerability in the EDC Connector component ( https://github.com/eclipse-edc/Connector ) regarding the OAuth2-protected data sink feature. | 5.3 |
2024-05-08 | CVE-2024-28971 | Dell | Insufficiently Protected Credentials vulnerability in Dell Openmanage Enterprise Update Manager Dell Update Manager Plugin, versions 1.4.0 through 1.5.0, contains a Plain-text Password Storage Vulnerability in Log file. | 4.9 |
2024-05-07 | CVE-2024-34314 | Cmseasy | Unspecified vulnerability in Cmseasy 7.7.7.9 CmsEasy v7.7.7.9 was discovered to contain a local file inclusion vunerability via the file_get_contents function in the fetch_action method of /admin/template_admin.php. | 4.9 |
2024-05-08 | CVE-2024-34570 | Wpxpro | Unspecified vulnerability in Wpxpro Xpro Addons for Elementor Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Xpro Xpro Elementor Addons allows Stored XSS.This issue affects Xpro Elementor Addons: from n/a through 1.4.3. | 4.8 |
2024-05-06 | CVE-2024-4528 | Fast5 | Unspecified vulnerability in Fast5 Prison Management System 1.0 A vulnerability was found in SourceCodester Prison Management System 1.0. | 4.8 |
2024-05-07 | CVE-2024-4594 | Dedecms | Unspecified vulnerability in Dedecms 5.7 A vulnerability, which was classified as problematic, was found in DedeCMS 5.7. | 4.3 |
2024-05-07 | CVE-2024-28148 | Apache | Unspecified vulnerability in Apache Superset An authenticated user could potentially access metadata for a datasource they are not authorized to view by submitting a targeted REST API request.This issue affects Apache Superset: before 3.1.2. Users are recommended to upgrade to version 3.1.2 or above, which fixes the issue. | 4.3 |
2024-05-07 | CVE-2024-4590 | Dedecms | Unspecified vulnerability in Dedecms 5.7 A vulnerability was found in DedeCMS 5.7. | 4.3 |
2024-05-07 | CVE-2024-4591 | Dedecms | Unspecified vulnerability in Dedecms 5.7 A vulnerability classified as problematic has been found in DedeCMS 5.7. | 4.3 |
2024-05-07 | CVE-2024-4592 | Dedecms | Unspecified vulnerability in Dedecms 5.7 A vulnerability classified as problematic was found in DedeCMS 5.7. | 4.3 |
2024-05-07 | CVE-2024-4593 | Dedecms | Unspecified vulnerability in Dedecms 5.7 A vulnerability, which was classified as problematic, has been found in DedeCMS 5.7. | 4.3 |
2024-05-07 | CVE-2024-4586 | Dedecms | Unspecified vulnerability in Dedecms 5.7 A vulnerability has been found in DedeCMS 5.7 and classified as problematic. | 4.3 |
2024-05-07 | CVE-2024-4587 | Dedecms | Unspecified vulnerability in Dedecms 5.7 A vulnerability was found in DedeCMS 5.7 and classified as problematic. | 4.3 |
2024-05-07 | CVE-2024-4588 | Dedecms | Unspecified vulnerability in Dedecms 5.7 A vulnerability was found in DedeCMS 5.7. | 4.3 |
2024-05-07 | CVE-2024-4589 | Dedecms | Unspecified vulnerability in Dedecms 5.7 A vulnerability was found in DedeCMS 5.7. | 4.3 |
2024-05-07 | CVE-2024-4585 | Dedecms | Unspecified vulnerability in Dedecms 5.7 A vulnerability, which was classified as problematic, was found in DedeCMS 5.7. | 4.3 |
2024-05-07 | CVE-2024-20856 | Samsung | Improper Authentication vulnerability in Samsung Android 14.0 Improper Authentication vulnerability in Secure Folder prior to SMR May-2024 Release 1 allows physical attackers to access Secure Folder without proper authentication in a specific scenario. | 4.3 |
2024-05-06 | CVE-2024-34387 | Afthemes | Unspecified vulnerability in Afthemes WP Post Author Missing Authorization vulnerability in AF themes WP Post Author.This issue affects WP Post Author: from n/a through 3.6.4. | 4.3 |
2024-05-06 | CVE-2024-34389 | Afthemes | Unspecified vulnerability in Afthemes WP Post Author Missing Authorization vulnerability in AF themes WP Post Author.This issue affects WP Post Author: from n/a through 3.6.4. | 4.3 |
2 Low Vulnerabilities
DATE | CVE | VENDOR | VULNERABILITY | CVSS |
---|---|---|---|---|
2024-05-07 | CVE-2024-20860 | Samsung | Unspecified vulnerability in Samsung Android 14.0 Improper export of android application components vulnerability in TelephonyUI prior to SMR May-2024 Release 1 allows local attackers to reboot the device without proper permission. | 3.3 |
2024-05-07 | CVE-2024-20855 | Samsung | Unspecified vulnerability in Samsung Android 14.0 Improper access control vulnerability in multitasking framework prior to SMR May-2024 Release 1 allows physical attackers to access unlocked screen for a while. | 2.4 |