CVE Feed

    Dashboard / CVE

    5.4
    Medium

    CVE-2024-43445

    Last Modified: 15 Apr 2026

    A vulnerability exists in OTRS and ((OTRS Community Edition)) that fail to set the HTTP response header X-Content-Type-Options to nosniff. An attacker could exploit this vulnerability by uploading or inserting content that would be treated as a different MIME type than intended. This issue affects: * OTRS 7.0.X * OTRS 8.0.X * OTRS 2023.X * OTRS 2024.X * ((OTRS)) Community Edition: 6.0.x Products based on the ((OTRS)) Community Edition also very likely to be affected

    Published: 27 Jan 2025
    6.5
    Medium

    CVE-2024-13117

    Last Modified: 13 May 2025

    The Social Share Buttons for WordPress plugin through 2.7 allows an unauthenticated user to upload arbitrary images and change the path where they are uploaded

    Published: 27 Jan 2025
    3.8
    Low

    CVE-2024-13116

    Last Modified: 13 May 2025

    The Crelly Slider WordPress plugin before 1.4.7 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

    Published: 27 Jan 2025
    4.8
    Medium

    CVE-2024-13095

    Last Modified: 5 May 2025

    The WP Triggers Lite WordPress plugin through 2.5.3 does not sanitize and escape a parameter before using it in a SQL statement, allowing admins to perform SQL injection attacks

    Published: 27 Jan 2025
    7.1
    High

    CVE-2024-13094

    Last Modified: 7 May 2025

    The WP Triggers Lite WordPress plugin through 2.5.3 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

    Published: 27 Jan 2025
    7.1
    High

    CVE-2024-13057

    Last Modified: 7 May 2025

    The Dyn Business Panel WordPress plugin through 1.0.0 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack.

    Published: 27 Jan 2025
    7.1
    High

    CVE-2024-13056

    Last Modified: 7 May 2025

    The Dyn Business Panel WordPress plugin through 1.0.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

    Published: 27 Jan 2025
    7.1
    High

    CVE-2024-13055

    Last Modified: 7 May 2025

    The Dyn Business Panel WordPress plugin through 1.0.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

    Published: 27 Jan 2025
    7.1
    High

    CVE-2024-13052

    Last Modified: 13 May 2025

    The Dental Optimizer Patient Generator App WordPress plugin through 1.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

    Published: 27 Jan 2025
    7.2
    High

    CVE-2024-12773

    Last Modified: 7 May 2025

    The Altra Side Menu WordPress plugin through 2.0 does not sanitize and escape a parameter before using it in a SQL statement, allowing admins to perform SQL injection attacks

    Published: 27 Jan 2025
    4.3
    Medium

    CVE-2024-12436

    Last Modified: 8 May 2025

    The WP Customer Area WordPress plugin through 8.2.4 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions via CSRF attacks

    Published: 27 Jan 2025
    7.1
    High

    CVE-2024-12321

    Last Modified: 13 May 2025

    The WC Affiliate WordPress plugin through 2.3.9 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

    Published: 27 Jan 2025
    4.3
    Medium

    CVE-2024-12280

    Last Modified: 8 May 2025

    The WP Customer Area WordPress plugin through 8.2.4 does not have CSRF check in place when deleting its logs, which could allow attackers to make a logged in to delete them via a CSRF attack

    Published: 27 Jan 2025
    5.4
    Medium

    CVE-2023-46187

    Last Modified: 18 Aug 2025

    IBM InfoSphere Master Data Management 11.6, 12.0, and 14.0 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.

    Published: 27 Jan 2025
    2.4
    Low

    CVE-2024-28766

    Last Modified: 14 Jul 2025

    IBM Security Directory Integrator 7.2.0 and IBM Security Verify Directory Integrator 10.0.0 could disclose sensitive information about directory contents that could aid in further attacks against the system.

    Published: 27 Jan 2025
    4.8
    Medium

    CVE-2024-28770

    Last Modified: 14 Jul 2025

    IBM Security Directory Integrator 7.2.0 and IBM Security Verify Directory Integrator 10.0.0 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user goes to. The cookie will be sent to the insecure link and the attacker can then obtain the cookie value by snooping the traffic.

    Published: 27 Jan 2025
    4.8
    Medium

    CVE-2024-28771

    Last Modified: 14 Jul 2025

    IBM Security Directory Integrator 7.2.0 and IBM Security Verify Directory Integrator 10.0.0 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user goes to. The cookie will be sent to the insecure link and the attacker can then obtain the cookie value by snooping the traffic.

    Published: 27 Jan 2025
    5.5
    Medium

    CVE-2025-0736

    Last Modified: 15 Apr 2026

    A flaw was found in Infinispan, when using JGroups with JDBC_PING. This issue occurs when an application inadvertently exposes sensitive information, such as configuration details or credentials, through logging mechanisms. This exposure can lead to unauthorized access and exploitation by malicious actors.

    Published: 27 Jan 2025
    6.5
    Medium

    CVE-2024-56972

    Last Modified: 15 Apr 2026

    An issue in Midea Group Co., Ltd Midea Home iOS 9.3.12 allows attackers to access sensitive user information via supplying a crafted link.

    Published: 27 Jan 2025
    6.5
    Medium

    CVE-2024-56969

    Last Modified: 15 Apr 2026

    An issue in Pixocial Technology (Singapore) Pte. Ltd BeautyPlus iOS 7.8.010 allows attackers to access sensitive user information via supplying a crafted link.

    Published: 27 Jan 2025
    6.5
    Medium

    CVE-2024-56949

    Last Modified: 15 Apr 2026

    An issue in Guangzhou Polar Future Culture Technology Co., Ltd University Search iOS 2.27.0 allows attackers to access sensitive user information via supplying a crafted link.

    Published: 27 Jan 2025
    6.1
    Medium

    CVE-2024-48662

    Last Modified: 15 Apr 2026

    Cross Site Scripting vulnerability in AdGuard Application v.7.18.1 (4778) and before allows an attacker to execute arbitrary code via a crafted payload to the fontMatrix component.

    Published: 27 Jan 2025
    6.5
    Medium

    CVE-2024-56968

    Last Modified: 15 Apr 2026

    An issue in Shenzhen Intellirocks Tech Co. Ltd Govee Home iOS 6.5.01 allows attackers to access sensitive user information via supplying a crafted payload.

    Published: 27 Jan 2025
    6.5
    Medium

    CVE-2024-56964

    Last Modified: 15 Apr 2026

    An issue in Che Hao Duo Used Automobile Agency (Beijing) Co., Ltd Guazi Used Car iOS 10.15.1 allows attackers to access sensitive user information via supplying a crafted link.

    Published: 27 Jan 2025
    6.5
    Medium

    CVE-2024-56962

    Last Modified: 15 Apr 2026

    An issue in Tencent Technology (Shanghai) Co., Ltd WeSing iOS v9.3.39 allows attackers to access sensitive user information via supplying a crafted link.

    Published: 27 Jan 2025
    6.5
    Medium

    CVE-2024-56960

    Last Modified: 15 Apr 2026

    An issue in Tianjin Xiaowu Information technology Co., Ltd BeiKe Holdings iOS 1.3.50 allows attackers to access sensitive user information via supplying a crafted link.

    Published: 27 Jan 2025
    6.5
    Medium

    CVE-2024-56957

    Last Modified: 15 Apr 2026

    An issue in Kingsoft Office Software Corporation Limited WPS Office iOS 12.20.0 allows attackers to access sensitive user information via supplying a crafted link.

    Published: 27 Jan 2025
    6.5
    Medium

    CVE-2024-56950

    Last Modified: 15 Apr 2026

    An issue in KuGou Technology Co., Ltd KuGou Concept iOS 4.0.61 allows attackers to access sensitive user information via supplying a crafted link.

    Published: 27 Jan 2025
    9.8
    Critical

    CVE-2024-57590

    Last Modified: 29 May 2025

    TRENDnet TEW-632BRP v1.010B31 devices have an OS command injection vulnerability in the CGl interface "ntp_sync.cgi",which allows remote attackers to execute arbitrary commands via parameter "ntp_server" passed to the "ntp_sync.cgi" binary through a POST request.

    Published: 27 Jan 2025
    9.8
    Critical

    CVE-2024-57595

    Last Modified: 15 Apr 2026

    DLINK DIR-825 REVB 2.03 devices have an OS command injection vulnerability in the CGl interface apc_client_pin.cgi, which allows remote attackers to execute arbitrary commands via the parameter "wps_pin" passed to the apc_client_pin.cgi binary through a POST request.

    Published: 27 Jan 2025
    9.1
    Critical

    CVE-2024-57548

    Last Modified: 11 Apr 2025

    CMSimple 5.16 allows the user to edit log.php file via print page.

    Published: 27 Jan 2025
    7.5
    High

    CVE-2024-57547

    Last Modified: 11 Apr 2025

    Insecure Permissions vulnerability in CMSimple v.5.16 allows a remote attacker to obtain sensitive information via a crafted script to the Functionality of downloading php backup files.

    Published: 27 Jan 2025
    6.1
    Medium

    CVE-2024-57272

    Last Modified: 15 Apr 2026

    SecuSTATION Camera V2.5.5.3116-S50-SMA-B20160811A and lower is vulnerable to Cross Site Scripting (XSS).

    Published: 27 Jan 2025
    6.5
    Medium

    CVE-2024-56971

    Last Modified: 15 Apr 2026

    An issue in Zhiyuan Yuedu (Guangzhou) Literature Information Technology Co., Ltd Shuqi Novel iOS 5.3.8 allows attackers to access sensitive user information via supplying a crafted link.

    Published: 27 Jan 2025
    8.8
    High

    CVE-2024-48418

    Last Modified: 28 May 2025

    In Edimax AC1200 Wi-Fi 5 Dual-Band Router BR-6476AC 1.06, the request /goform/fromSetDDNS does not properly handle special characters in any of user provided parameters, allowing an attacker with access to the web interface to inject and execute arbitrary shell commands.

    Published: 27 Jan 2025
    8.8
    High

    CVE-2024-48419

    Last Modified: 28 May 2025

    Edimax AC1200 Wi-Fi 5 Dual-Band Router BR-6476AC 1.06 suffers from Command Injection issues in /bin/goahead. Specifically, these issues can be triggered through /goform/tracerouteDiagnosis, /goform/pingDiagnosis, and /goform/fromSysToolPingCmd Each of these issues allows an attacker with access to the web interface to inject and execute arbitrary shell commands, with "root" privileges.

    Published: 27 Jan 2025
    7.5
    High

    CVE-2024-56316

    Last Modified: 15 Apr 2026

    In AXESS ACS (Auto Configuration Server) through 5.2.0, unsanitized user input in the TR069 API allows remote unauthenticated attackers to cause a permanent Denial of Service via crafted TR069 requests on TCP port 9675 or 7547. Rebooting does not resolve the permanent Denial of Service.

    Published: 27 Jan 2025
    6.1
    Medium

    CVE-2024-26317

    Last Modified: 15 Apr 2026

    In illumos illumos-gate 2024-02-15, an error occurs in the elliptic curve point addition algorithm that uses mixed Jacobian-affine coordinates, causing the algorithm to yield a result of POINT_AT_INFINITY when it should not. A man-in-the-middle attacker could use this to interfere with a connection, resulting in an attacked party computing an incorrect shared secret.

    Published: 27 Jan 2025
    9.8
    Critical

    CVE-2024-57052

    Last Modified: 27 Jun 2025

    An issue in youdiancms v.9.5.20 and before allows a remote attacker to escalate privileges via the sessionID parameter in the index.php file.

    Published: 27 Jan 2025
    7.5
    High

    CVE-2024-57546

    Last Modified: 16 Apr 2025

    An issue in CMSimple v.5.16 allows a remote attacker to obtain sensitive information via a crafted script to the validate link function.

    Published: 27 Jan 2025
    7.5
    High

    CVE-2024-57549

    Last Modified: 11 Apr 2025

    CMSimple 5.16 allows the user to read cms source code through manipulation of the file name in the file parameter of a GET request.

    Published: 27 Jan 2025
    7.3
    High

    CVE-2024-57276

    Last Modified: 15 Apr 2026

    In Electronic Arts Dragon Age Origins 1.05, the DAUpdaterSVC service contains an unquoted service path vulnerability. This service is configured with insecure permissions, allowing users to modify the executable file path used by the service. The service runs with NT AUTHORITY\SYSTEM privileges, enabling attackers to escalate privileges by replacing or placing a malicious executable in the service path.

    Published: 27 Jan 2025
    8.1
    High

    CVE-2024-57373

    Last Modified: 15 Apr 2026

    Cross Site Request Forgery (CSRF) vulnerability in LifestyleStore v1.0 allows a remote attacker to execute unauthorized actions on behalf of an authenticated user, potentially leading to account modifications or data compromise.

    Published: 27 Jan 2025
    8.8
    High

    CVE-2024-48416

    Last Modified: 28 May 2025

    Edimax AC1200 Wi-Fi 5 Dual-Band Router BR-6476AC 1.06 is vulnerable to Buffer Overflow via /goform/fromSetLanDhcpsClientbinding.

    Published: 27 Jan 2025
    5.2
    Medium

    CVE-2024-48417

    Last Modified: 28 May 2025

    Edimax AC1200 Wi-Fi 5 Dual-Band Router BR-6476AC 1.06 is vulnerable to Cross Site Scripting (XSS) in : /bin/goahead via /goform/setStaticRoute, /goform/fromSetFilterUrlFilter, and /goform/fromSetFilterClientFilter.

    Published: 27 Jan 2025
    8.8
    High

    CVE-2024-48420

    Last Modified: 28 May 2025

    Edimax AC1200 Wi-Fi 5 Dual-Band Router BR-6476AC 1.06 is vulnerable to Buffer Overflow via /goform/getWifiBasic.

    Published: 27 Jan 2025
    6.5
    Medium

    CVE-2024-54728

    Last Modified: 15 Apr 2026

    Incorrect access control in BYD QIN PLUS DM-i Dilink OS 3.0_13.1.7.2204050.1 allows unauthorized attackers to access system logcat logs.

    Published: 27 Jan 2025
    9
    Critical

    CVE-2024-55227

    Last Modified: 19 Feb 2025

    A cross-site scripting (XSS) vulnerability in the Events/Agenda module of Dolibarr v21.0.0-beta allows attackers to execute arbitrary web scripts or HTMl via a crafted payload injected into the Title parameter.

    Published: 27 Jan 2025
    9
    Critical

    CVE-2024-55228

    Last Modified: 19 Feb 2025

    A cross-site scripting (XSS) vulnerability in the Product module of Dolibarr v21.0.0-beta allows attackers to execute arbitrary web scripts or HTMl via a crafted payload injected into the Title parameter.

    Published: 27 Jan 2025
    6.5
    Medium

    CVE-2024-56178

    Last Modified: 18 Apr 2025

    An issue was discovered in Couchbase Server 7.6.x through 7.6.3. A user with the security_admin_local role can create a new user in a group that has the admin role.

    Published: 27 Jan 2025