CVE Feed

    Dashboard / CVE

    9.8
    Critical

    CVE-2024-12919

    Last Modified: 8 Apr 2026

    The Paid Membership Subscriptions – Effortless Memberships, Recurring Payments & Content Restriction plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 2.13.7. This is due to the pms_pb_payment_redirect_link function using the user-controlled value supplied via the 'pms_payment_id' parameter to authenticate users without any further identity validation. This makes it possible for unauthenticated attackers with knowledge of a valid payment ID to log in as any user who has made a purchase on the targeted site.

    Published: 14 Jan 2025
    6.4
    Medium

    CVE-2024-13156

    Last Modified: 15 Apr 2026

    The HTML5 Video Player – mp4 Video Player Plugin and Block plugin for WordPress is vulnerable to DOM-Based Stored Cross-Site Scripting via the ‘heading’ parameter in all versions up to, and including, 2.5.35 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 14 Jan 2025
    8.8
    High

    CVE-2025-0394

    Last Modified: 21 Apr 2026

    The WordPress CRM, Email & Marketing Automation for WordPress | Award Winner — Groundhogg plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the gh_big_file_upload() function in all versions up to, and including, 3.7.3.5. This makes it possible for authenticated attackers, with Author-level access and above, to upload arbitrary files on the affected site's server which may make remote code execution possible.

    Published: 14 Jan 2025
    6.1
    Medium

    CVE-2025-0393

    Last Modified: 22 Apr 2026

    The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.7.1006. This is due to missing or incorrect nonce validation on the wpr_filter_grid_posts() function. This makes it possible for unauthenticated attackers to inject malicious web scripts via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

    Published: 14 Jan 2025
    5.3
    Medium

    CVE-2024-12008

    Last Modified: 8 Apr 2026

    The W3 Total Cache plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 2.8.1 through the publicly exposed debug log file. This makes it possible for unauthenticated attackers to view potentially sensitive information in the exposed log file. For example, the log file may contain nonce values that can be used in further CSRF attacks. Note: the debug feature must be enabled for this to be a concern, and it is disabled by default.

    Published: 14 Jan 2025
    5.3
    Medium

    CVE-2024-12006

    Last Modified: 8 Apr 2026

    The W3 Total Cache plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on several functions in all versions up to, and including, 2.8.1. This makes it possible for unauthenticated attackers to deactivate the plugin as well as activate and deactivate plugin extensions.

    Published: 14 Jan 2025
    8.5
    High

    CVE-2024-12365

    Last Modified: 8 Apr 2026

    The W3 Total Cache plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the is_w3tc_admin_page function in all versions up to, and including, 2.8.1. This makes it possible for authenticated attackers, with Subscriber-level access and above, to obtain the plugin's nonce value and perform unauthorized actions, resulting in information disclosure, service plan limits consumption as well as making web requests to arbitrary locations originating from the web application that can be used to query information from internal services, including instance metadata on cloud-based applications.

    Published: 14 Jan 2025
    6.4
    Medium

    CVE-2024-13323

    Last Modified: 8 Apr 2026

    The WP Booking Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'booking' shortcode in all versions up to, and including, 10.9.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 14 Jan 2025
    7.2
    High

    CVE-2025-23082

    Last Modified: 18 Nov 2025

    Veeam Backup for Microsoft Azure is vulnerable to Server-Side Request Forgery (SSRF). This may allow an unauthenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks.

    Published: 14 Jan 2025
    6.6
    Medium

    CVE-2024-12083

    Last Modified: 15 Apr 2026

    Path Traversal Vulnerabilities (CWE-22) exist in NJ/NX-series Machine Automation Controllers. An attacker may use these vulnerabilities to perform unauthorized access and to execute unauthorized code remotely to the controller products.

    Published: 14 Jan 2025
    5.5
    Medium

    CVE-2024-12298

    Last Modified: 15 Apr 2026

    We found a vulnerability Improper Restriction of XML External Entity Reference (CWE-611) in NB-series NX-Designer. Attackers may be able to abuse this vulnerability to disclose confidential data on a computer.

    Published: 14 Jan 2025
    9.9
    Critical

    CVE-2025-0070

    Last Modified: 15 Apr 2026

    SAP NetWeaver Application Server for ABAP and ABAP Platform allows an authenticated attacker to obtain illegitimate access to the system by exploiting improper authentication checks, resulting in privilege escalation. On successful exploitation, this can result in potential security concerns. This results in a high impact on confidentiality, integrity, and availability.

    Published: 14 Jan 2025
    7.8
    High

    CVE-2025-0069

    Last Modified: 15 Apr 2026

    Due to DLL injection vulnerability in SAPSetup, an attacker with either local user privileges or with access to a compromised corporate user�s Windows account could gain higher privileges. With this, he could move laterally within the network and further compromise the active directory of a company. This leads to high impact on confidentiality, integrity and availability of the Windows server.

    Published: 14 Jan 2025
    4.3
    Medium

    CVE-2025-0068

    Last Modified: 15 Apr 2026

    An obsolete functionality in SAP NetWeaver Application Server ABAP did not perform necessary authorization checks. Because of this, an authenticated attacker could obtain information that would otherwise be restricted. It has no impact on integrity or availability on the application.

    Published: 14 Jan 2025
    6.3
    Medium

    CVE-2025-0067

    Last Modified: 15 Apr 2026

    Due to a missing authorization check on service endpoints in the SAP NetWeaver Application Server Java, an attacker with standard user role can create JCo connection entries, which are used for remote function calls from or to the application server. This could lead to low impact on confidentiality, integrity, and availability of the application.

    Published: 14 Jan 2025
    9.9
    Critical

    CVE-2025-0066

    Last Modified: 23 Oct 2025

    Under certain conditions SAP NetWeaver AS for ABAP and ABAP Platform (Internet Communication Framework) allows an attacker to access restricted information due to weak access controls. This can have a significant impact on the confidentiality, integrity, and availability of an application

    Published: 14 Jan 2025
    8.8
    High

    CVE-2025-0063

    Last Modified: 24 Oct 2025

    SAP NetWeaver AS ABAP and ABAP Platform does not check for authorization when a user executes some RFC function modules. This could lead to an attacker with basic user privileges to gain control over the data in Informix database, leading to complete compromise of confidentiality, integrity and availability.

    Published: 14 Jan 2025
    8.7
    High

    CVE-2025-0061

    Last Modified: 24 Oct 2025

    SAP BusinessObjects Business Intelligence Platform allows an unauthenticated attacker to perform session hijacking over the network without any user interaction, due to an information disclosure vulnerability. Attacker can access and modify all the data of the application.

    Published: 14 Jan 2025
    6.5
    Medium

    CVE-2025-0060

    Last Modified: 24 Oct 2025

    SAP BusinessObjects Business Intelligence Platform allows an authenticated user with restricted access to inject malicious JS code which can read sensitive information from the server and send it to the attacker. The attacker could further use this information to impersonate as a high privileged user causing high impact on confidentiality and integrity of the application.

    Published: 14 Jan 2025
    6
    Medium

    CVE-2025-0059

    Last Modified: 15 Apr 2026

    Applications based on SAP GUI for HTML in SAP NetWeaver Application Server ABAP store user input in the local browser storage to improve usability. An attacker with administrative privileges or access to the victim�s user directory on the Operating System level would be able to read this data. Depending on the user input provided in transactions, the disclosed data could range from non-critical data to highly sensitive data, causing high impact on confidentiality of the application.

    Published: 14 Jan 2025
    6.5
    Medium

    CVE-2025-0058

    Last Modified: 24 Oct 2025

    In SAP Business Workflow and SAP Flexible Workflow, an authenticated attacker can manipulate a parameter in an otherwise legitimate resource request to view sensitive information that should otherwise be restricted. The attacker does not have the ability to modify the information or to make the information unavailable.

    Published: 14 Jan 2025
    4.8
    Medium

    CVE-2025-0057

    Last Modified: 15 Apr 2026

    SAP NetWeaver AS JAVA (User Admin Application) is vulnerable to stored cross site scripting vulnerability. An attacker posing as an admin can upload a photo with malicious JS content. When a victim visits the vulnerable component, the attacker can read and modify information within the scope of victim's web browser.

    Published: 14 Jan 2025
    6
    Medium

    CVE-2025-0056

    Last Modified: 15 Apr 2026

    SAP GUI for Java saves user input on the client PC to improve usability. An attacker with administrative privileges or access to the victim�s user directory on the Operating System level would be able to read this data. Depending on the user input provided in transactions, the disclosed data could range from non-critical data to highly sensitive data, causing high impact on confidentiality of the application.

    Published: 14 Jan 2025
    6
    Medium

    CVE-2025-0055

    Last Modified: 15 Apr 2026

    SAP GUI for Windows stores user input on the client PC to improve usability. Under very specific circumstances an attacker with administrative privileges or access to the victim�s user directory on the Operating System level would be able to read this data. Depending on the user input provided in transactions, the disclosed data could range from non-critical data to highly sensitive data, causing high impact on confidentiality of the application.

    Published: 14 Jan 2025
    5.3
    Medium

    CVE-2025-0053

    Last Modified: 24 Oct 2025

    SAP NetWeaver Application Server for ABAP and ABAP Platform allows an attacker to gain unauthorized access to system information. By using a specific URL parameter, an unauthenticated attacker could retrieve details such as system configuration. This has a limited impact on the confidentiality of the application and may be leveraged to facilitate further attacks or exploits.

    Published: 14 Jan 2025
    6.5
    Medium

    CVE-2025-23366

    Last Modified: 19 Aug 2026

    A flaw was found in the HAL Console in the Wildfly component, which does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output used as a web page that is served to other users. The attacker must be authenticated as a user that belongs to management groups “SuperUser”, “Admin”, or “Maintainer”.

    Published: 14 Jan 2025
    7.5
    High

    CVE-2024-54730

    Last Modified: 15 Apr 2026

    Flatnotes <v5.3.1 is vulnerable to denial of service through the upload image function.

    Published: 14 Jan 2025
    5.4
    Medium

    CVE-2024-53563

    Last Modified: 15 Apr 2026

    A stored cross-site scripting (XSS) vulnerability in Arcadyan Meteor 2 CPE FG360 Firmware ETV2.10 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload.

    Published: 14 Jan 2025
    5.4
    Medium

    CVE-2024-55000

    Last Modified: 23 Apr 2025

    Sourcecodester House Rental Management system v1.0 is vulnerable to Cross Site Scripting (XSS) in rental/manage_categories.php.

    Published: 14 Jan 2025
    5.8
    Medium

    CVE-2024-56374

    Last Modified: 3 Oct 2025

    An issue was discovered in Django 5.1 before 5.1.5, 5.0 before 5.0.11, and 4.2 before 4.2.18. Lack of upper-bound limit enforcement in strings passed when performing IPv6 validation could lead to a potential denial-of-service attack. The undocumented and private functions clean_ipv6_address and is_valid_ipv6_address are vulnerable, as is the django.forms.GenericIPAddressField form field. (The django.db.models.GenericIPAddressField model field is not affected.)

    Published: 14 Jan 2025
    9.8
    Critical

    CVE-2024-57471

    Last Modified: 27 May 2025

    H3C N12 V100R005 contains a buffer overflow vulnerability due to the lack of length verification in the 2.4G wireless network processing function. Attackers who successfully exploit this vulnerability can cause the remote target device to crash or execute arbitrary commands by sending a POST request to /bin/webs.

    Published: 14 Jan 2025
    7.5
    High

    CVE-2024-57619

    Last Modified: 10 Apr 2025

    An issue in the atom_get_int component of MonetDB Server v11.47.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.

    Published: 14 Jan 2025
    7.5
    High

    CVE-2024-57625

    Last Modified: 10 Apr 2025

    An issue in the merge_table_prune_and_unionize component of MonetDB Server v11.49.1 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.

    Published: 14 Jan 2025
    7.5
    High

    CVE-2024-57631

    Last Modified: 10 Apr 2025

    An issue in the exp_ref component of MonetDB Server v11.49.1 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.

    Published: 14 Jan 2025
    7.5
    High

    CVE-2024-57635

    Last Modified: 17 Apr 2025

    An issue in the chash_array component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.

    Published: 14 Jan 2025
    7.5
    High

    CVE-2024-57637

    Last Modified: 17 Apr 2025

    An issue in the dfe_unit_gb_dependant component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.

    Published: 14 Jan 2025
    7.5
    High

    CVE-2024-57639

    Last Modified: 17 Apr 2025

    An issue in the dc_elt_size component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.

    Published: 14 Jan 2025
    7.5
    High

    CVE-2024-57645

    Last Modified: 17 Apr 2025

    An issue in the qi_inst_state_free component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.

    Published: 14 Jan 2025
    7.5
    High

    CVE-2024-57647

    Last Modified: 17 Apr 2025

    An issue in the row_insert_cast component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.

    Published: 14 Jan 2025
    7.5
    High

    CVE-2024-57651

    Last Modified: 17 Apr 2025

    An issue in the jp_add component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.

    Published: 14 Jan 2025
    7.5
    High

    CVE-2024-57658

    Last Modified: 17 Apr 2025

    An issue in the sql_tree_hash_1 component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.

    Published: 14 Jan 2025
    7.5
    High

    CVE-2024-57664

    Last Modified: 17 Apr 2025

    An issue in the sqlg_group_node component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.

    Published: 14 Jan 2025
    8.1
    High

    CVE-2024-57761

    Last Modified: 11 Sept 2025

    An arbitrary file upload vulnerability in the parserXML() method of JeeWMS before v2025.01.01 allows attackers to execute arbitrary code via uploading a crafted file.

    Published: 14 Jan 2025
    9.1
    Critical

    CVE-2024-57764

    Last Modified: 10 Apr 2025

    MSFM before 2025.01.01 was discovered to contain a fastjson deserialization vulnerability via the component system/table/add.

    Published: 14 Jan 2025
    7.5
    High

    CVE-2024-57765

    Last Modified: 10 Apr 2025

    MSFM before 2025.01.01 was discovered to contain a SQL injection vulnerability via the s_name parameter at table/list.

    Published: 14 Jan 2025
    4.8
    Medium

    CVE-2025-22997

    Last Modified: 11 Jun 2025

    A stored cross-site scripting (XSS) vulnerability in the prf_table_content component of Linksys E5600 Router Ver. 1.1.0.26 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the desc parameter.

    Published: 14 Jan 2025
    5.4
    Medium

    CVE-2025-23018

    Last Modified: 3 Nov 2025

    IPv4-in-IPv6 and IPv6-in-IPv6 tunneling (RFC 2473) do not require the validation or verification of the source of a network packet, allowing an attacker to spoof and route arbitrary traffic via an exposed network interface. This is a similar issue to CVE-2020-10136.

    Published: 14 Jan 2025
    7.4
    High

    CVE-2024-42911

    Last Modified: 15 Apr 2026

    ECOVACS Robotics Deebot T20 OMNI and T20e OMNI before 1.24.0 was discovered to contain a WiFi Remote Code Execution vulnerability.

    Published: 14 Jan 2025
    9.8
    Critical

    CVE-2024-48760

    Last Modified: 6 Jun 2025

    An issue in GestioIP v3.5.7 allows a remote attacker to execute arbitrary code via the file upload function. The attacker can upload a malicious perlcmd.cgi file that overwrites the original upload.cgi file, enabling remote command execution.

    Published: 14 Jan 2025
    4.8
    Medium

    CVE-2024-50857

    Last Modified: 6 Jun 2025

    The ip_do_job request in GestioIP v3.5.7 is vulnerable to Cross-Site Scripting (XSS). It allows data exfiltration and enables CSRF attacks. The vulnerability requires specific user permissions within the application to exploit successfully.

    Published: 14 Jan 2025