CVE Feed

    Dashboard / CVE

    7.8
    High

    CVE-2024-45561

    Last Modified: 12 Feb 2025

    Memory corruption while handling IOCTL call from user-space to set latency level.

    Published: 3 Feb 2025
    7.8
    High

    CVE-2024-45560

    Last Modified: 12 Feb 2025

    Memory corruption while taking a snapshot with hardware encoder due to unvalidated userspace buffer.

    Published: 3 Feb 2025
    8.8
    High

    CVE-2024-38420

    Last Modified: 5 Feb 2025

    Memory corruption while configuring a Hypervisor based input virtual device.

    Published: 3 Feb 2025
    7.8
    High

    CVE-2024-38418

    Last Modified: 5 Feb 2025

    Memory corruption while parsing the memory map info in IOCTL calls.

    Published: 3 Feb 2025
    6.1
    Medium

    CVE-2024-38417

    Last Modified: 5 Feb 2025

    Information disclosure while processing IO control commands.

    Published: 3 Feb 2025
    6.1
    Medium

    CVE-2024-38416

    Last Modified: 5 Feb 2025

    Information disclosure during audio playback.

    Published: 3 Feb 2025
    6.1
    Medium

    CVE-2024-38414

    Last Modified: 5 Feb 2025

    Information disclosure while processing information on firmware image during core initialization.

    Published: 3 Feb 2025
    6.6
    Medium

    CVE-2024-38413

    Last Modified: 5 Feb 2025

    Memory corruption while processing frame packets.

    Published: 3 Feb 2025
    6.6
    Medium

    CVE-2024-38412

    Last Modified: 5 Feb 2025

    Memory corruption while invoking IOCTL calls from user-space to kernel-space to handle session errors.

    Published: 3 Feb 2025
    6.6
    Medium

    CVE-2024-38411

    Last Modified: 11 Aug 2025

    Memory corruption while registering a buffer from user-space to kernel-space using IOCTL calls.

    Published: 3 Feb 2025
    7.5
    High

    CVE-2024-38404

    Last Modified: 5 Feb 2025

    Transient DOS when registration accept OTA is received with incorrect ciphering key data IE in modem.

    Published: 3 Feb 2025
    —
    Unknown

    CVE-2025-0989

    Last Modified: 11 Feb 2025

    ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2024-12315. Reason: This candidate is a reservation duplicate of CVE-2024-12315. Notes: All CVE users should reference CVE-2024-12315 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage.

    Published: 3 Feb 2025
    8.8
    High

    CVE-2025-24661

    Last Modified: 23 Apr 2026

    Deserialization of Untrusted Data vulnerability in magepeopleteam Taxi Booking Manager for WooCommerce ecab-taxi-booking-manager allows Object Injection.This issue affects Taxi Booking Manager for WooCommerce: from n/a through <= 1.1.8.

    Published: 3 Feb 2025
    7.1
    High

    CVE-2025-23984

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in brainvireinfo Dynamic URL SEO dynamic-url-seo allows Reflected XSS.This issue affects Dynamic URL SEO: from n/a through <= 1.0.

    Published: 3 Feb 2025
    7.1
    High

    CVE-2025-22775

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in idiatech Catalog Importer, Scraper & Crawler intelligent-importer allows Reflected XSS.This issue affects Catalog Importer, Scraper & Crawler: from n/a through <= 5.1.3.

    Published: 3 Feb 2025
    7.1
    High

    CVE-2025-22704

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Abinav Thakuri WordPress Signature wordpress-signature allows Reflected XSS.This issue affects WordPress Signature: from n/a through <= 0.1.

    Published: 3 Feb 2025
    7.1
    High

    CVE-2025-22703

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in manuelvicedo Forge – Front-End Page Builder forge allows Stored XSS.This issue affects Forge – Front-End Page Builder: from n/a through <= 1.4.6.

    Published: 3 Feb 2025
    5.4
    Medium

    CVE-2025-22701

    Last Modified: 23 Apr 2026

    Server-Side Request Forgery (SSRF) vulnerability in shinetheme Traveler Layout Essential For Elementor traveler-layout-essential-for-elementor.This issue affects Traveler Layout Essential For Elementor: from n/a through < 1.4.

    Published: 3 Feb 2025
    4.3
    Medium

    CVE-2025-22695

    Last Modified: 23 Apr 2026

    Authorization Bypass Through User-Controlled Key vulnerability in NirWp Team Nirweb support nirweb-support.This issue affects Nirweb support: from n/a through <= 3.0.3.

    Published: 3 Feb 2025
    4.3
    Medium

    CVE-2025-22694

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in Dotstore Hide Shipping Method For WooCommerce hide-shipping-method-for-woocommerce.This issue affects Hide Shipping Method For WooCommerce: from n/a through <= 1.5.1.

    Published: 3 Feb 2025
    7.6
    High

    CVE-2025-22693

    Last Modified: 23 Apr 2026

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Wasiliy Strecker / ContestGallery developer Contest Gallery contest-gallery allows SQL Injection.This issue affects Contest Gallery: from n/a through <= 25.1.0.

    Published: 3 Feb 2025
    7.6
    High

    CVE-2025-22691

    Last Modified: 23 Apr 2026

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WP Travel WP Travel wp-travel allows SQL Injection.This issue affects WP Travel: from n/a through <= 10.1.3.

    Published: 3 Feb 2025
    7.1
    High

    CVE-2025-22690

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in DigiTimber DigiTimber cPanel Integration digitimber-cpanel-integration allows Stored XSS.This issue affects DigiTimber cPanel Integration: from n/a through <= 1.4.6.

    Published: 3 Feb 2025
    7.1
    High

    CVE-2025-22688

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Ederson Peka Unlimited Page Sidebars unlimited-page-sidebars allows Stored XSS.This issue affects Unlimited Page Sidebars: from n/a through <= 0.2.6.

    Published: 3 Feb 2025
    5.3
    Medium

    CVE-2025-22686

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in WesternDeal CF7 Google Sheets Connector cf7-google-sheets-connector allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects CF7 Google Sheets Connector: from n/a through <= 5.0.17.

    Published: 3 Feb 2025
    7.1
    High

    CVE-2025-22685

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in CheGevara29 Tags to Keywords tags-to-meta-keywords allows Stored XSS.This issue affects Tags to Keywords: from n/a through <= 1.0.1.

    Published: 3 Feb 2025
    7.1
    High

    CVE-2025-22684

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Hakan Ozevin WP BASE Booking wp-base-booking-of-appointments-services-and-events allows Stored XSS.This issue affects WP BASE Booking: from n/a through <= 5.0.0.

    Published: 3 Feb 2025
    6.5
    Medium

    CVE-2025-22683

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPDeveloper NotificationX notificationx allows Stored XSS.This issue affects NotificationX: from n/a through <= 2.9.5.

    Published: 3 Feb 2025
    7.1
    High

    CVE-2025-22682

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Saeed Sattar Beglou Hesabfa Accounting hesabfa-accounting allows Reflected XSS.This issue affects Hesabfa Accounting: from n/a through <= 2.1.2.

    Published: 3 Feb 2025
    4.3
    Medium

    CVE-2025-22681

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in Xfinitysoft Content Cloner super-seo-content-cloner allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Content Cloner: from n/a through <= 1.0.1.

    Published: 3 Feb 2025
    7.1
    High

    CVE-2025-22679

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PickPlugins Job Board Manager job-board-manager allows Reflected XSS.This issue affects Job Board Manager: from n/a through <= 2.1.61.

    Published: 3 Feb 2025
    4.8
    Medium

    CVE-2025-22677

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in UIUX Lab Uix Shortcodes uix-shortcodes allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Uix Shortcodes: from n/a through <= 2.0.3.

    Published: 3 Feb 2025
    6.5
    Medium

    CVE-2025-22292

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Felipe Peixoto Powerful Auto Chat powers-triggers-of-woo-to-chat allows Stored XSS.This issue affects Powerful Auto Chat: from n/a through <= 1.9.8.

    Published: 3 Feb 2025
    4.3
    Medium

    CVE-2025-22260

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in Marcus (aka @msykes) Meta Tag Manager meta-tag-manager.This issue affects Meta Tag Manager: from n/a through <= 3.1.

    Published: 3 Feb 2025
    4.3
    Medium

    CVE-2024-50500

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in averta Shortcodes and extra features for Phlox theme auxin-elements allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Shortcodes and extra features for Phlox theme: from n/a through <= 2.17.4.

    Published: 3 Feb 2025
    7.5
    High

    CVE-2024-43333

    Last Modified: 28 Apr 2026

    Incorrect Privilege Assignment vulnerability in NotFound Admin and Site Enhancements (ASE) Pro allows Privilege Escalation. This issue affects Admin and Site Enhancements (ASE) Pro: from n/a through 7.6.2.1.

    Published: 3 Feb 2025
    7.1
    High

    CVE-2025-24707

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in gt3themes Photo Gallery gt3-photo-video-gallery allows Reflected XSS.This issue affects Photo Gallery: from n/a through <= 2.7.7.24.

    Published: 3 Feb 2025
    6.5
    Medium

    CVE-2025-24697

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in Realwebcare Image Gallery – Responsive Photo Gallery awesome-responsive-photo-gallery allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Image Gallery – Responsive Photo Gallery: from n/a through <= 1.0.5.

    Published: 3 Feb 2025
    7.1
    High

    CVE-2025-24684

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ederson Peka Media Downloader media-downloader allows Reflected XSS.This issue affects Media Downloader: from n/a through <= 0.4.7.5.

    Published: 3 Feb 2025
    7.1
    High

    CVE-2025-24676

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in umangmetatagg Custom WP Store Locator custom-store-locator allows Reflected XSS.This issue affects Custom WP Store Locator: from n/a through <= 1.4.7.

    Published: 3 Feb 2025
    7.1
    High

    CVE-2025-24660

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wp.insider Simple Membership Custom Messages simple-membership-custom-messages allows Reflected XSS.This issue affects Simple Membership Custom Messages: from n/a through <= 2.4.

    Published: 3 Feb 2025
    7.1
    High

    CVE-2025-24656

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Realtyna Realtyna Provisioning realtyna-provisioning allows Reflected XSS.This issue affects Realtyna Provisioning: from n/a through <= 1.2.2.

    Published: 3 Feb 2025
    7.1
    High

    CVE-2025-24646

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in icopydoc XML for Avito xml-for-avito allows Reflected XSS.This issue affects XML for Avito: from n/a through <= 2.5.2.

    Published: 3 Feb 2025
    6.5
    Medium

    CVE-2025-24643

    Last Modified: 29 Apr 2026

    Missing Authorization vulnerability in AmentoTech Private Limited WPGuppy wpguppy-lite allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WPGuppy: from n/a through <= 1.1.0.

    Published: 3 Feb 2025
    6.5
    Medium

    CVE-2025-24642

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in theme funda Setup Default Featured Image setup-default-feature-image allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Setup Default Featured Image: from n/a through <= 1.2.

    Published: 3 Feb 2025
    6.5
    Medium

    CVE-2025-24639

    Last Modified: 23 Apr 2026

    Insertion of Sensitive Information Into Sent Data vulnerability in Greys Korea for WooCommerce korea-for-woocommerce allows Retrieve Embedded Sensitive Data.This issue affects Korea for WooCommerce: from n/a through <= 1.1.11.

    Published: 3 Feb 2025
    7.1
    High

    CVE-2025-24631

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in shanebp BP Email Assign Templates bp-email-assign-templates allows Reflected XSS.This issue affects BP Email Assign Templates: from n/a through <= 1.5.

    Published: 3 Feb 2025
    7.1
    High

    CVE-2025-24630

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in MantraBrain Sikshya LMS sikshya allows Reflected XSS.This issue affects Sikshya LMS: from n/a through <= 0.0.21.

    Published: 3 Feb 2025
    7.1
    High

    CVE-2025-24629

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpgear Import Excel to Gravity Forms gf-excel-import allows Reflected XSS.This issue affects Import Excel to Gravity Forms: from n/a through <= 1.18.

    Published: 3 Feb 2025
    7.1
    High

    CVE-2025-24620

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in hkharpreetkumar1 AIO Shortcodes aio-shortcodes allows Stored XSS.This issue affects AIO Shortcodes: from n/a through <= 1.3.

    Published: 3 Feb 2025