CVE Feed

    Dashboard / CVE

    6.3
    Medium

    CVE-2024-13185

    Last Modified: 15 Apr 2026

    The MinigameCenter module has insufficient restrictions on loading URLs, which may lead to some information leakage.

    Published: 8 Jan 2025
    6.3
    Medium

    CVE-2024-13173

    Last Modified: 15 Apr 2026

    The health module has insufficient restrictions on loading URLs, which may lead to some information leakage.

    Published: 8 Jan 2025
    9.8
    Critical

    CVE-2024-11635

    Last Modified: 8 Apr 2026

    The WordPress File Upload plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 4.24.12 via the 'wfu_ABSPATH' cookie parameter. This makes it possible for unauthenticated attackers to execute code on the server.

    Published: 8 Jan 2025
    4.4
    Medium

    CVE-2024-12045

    Last Modified: 8 Apr 2026

    The Essential Blocks – Page Builder Gutenberg Blocks, Patterns & Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the maker title value of the Google Maps block in all versions up to, and including, 5.0.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.

    Published: 8 Jan 2025
    6.9
    Medium

    CVE-2024-8002

    Last Modified: 15 Apr 2026

    A vulnerability has been found in VIWIS LMS 9.11 and classified as problematic. Affected by this vulnerability is an unknown functionality of the component File Upload. The manipulation of the argument filename leads to cross site scripting. The attack can be launched remotely. Upgrading to version 9.12 is able to address this issue. It is recommended to upgrade the affected component.

    Published: 8 Jan 2025
    4.3
    Medium

    CVE-2025-22215

    Last Modified: 15 Apr 2026

    VMware Aria Automation contains a server-side request forgery (SSRF) vulnerability. A malicious actor with "Organization Member" access to Aria Automation may exploit this vulnerability enumerate internal services running on the host/network.

    Published: 8 Jan 2025
    4.3
    Medium

    CVE-2024-12584

    Last Modified: 8 Apr 2026

    The 140+ Widgets | Xpro Addons For Elementor – FREE plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.4.6.2 via the 'duplicate' function. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract potentially sensitive data from draft, scheduled (future), private, and password protected posts.

    Published: 8 Jan 2025
    6.4
    Medium

    CVE-2024-12852

    Last Modified: 8 Apr 2026

    The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'ha_cmc_text' parameter of the Happy Mouse Cursor in all versions up to, and including, 3.15.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 8 Jan 2025
    6.4
    Medium

    CVE-2024-12851

    Last Modified: 8 Apr 2026

    The Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid, Carousel and Remote Arrows) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the custom_attributes parameter of the Cookie Consent Widget in all versions up to, and including, 5.10.14 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 8 Jan 2025
    —
    Unknown

    CVE-2024-9673

    Last Modified: 17 Jan 2025

    ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2025-22333. Reason: This candidate is a reservation duplicate of CVE-2025-22333. Notes: All CVE users should reference CVE-2025-22333 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage.

    Published: 8 Jan 2025
    9.8
    Critical

    CVE-2024-11613

    Last Modified: 8 Apr 2026

    The WordPress File Upload plugin for WordPress is vulnerable to Remote Code Execution, Arbitrary File Read, and Arbitrary File Deletion in all versions up to, and including, 4.24.15 via the 'wfu_file_downloader.php' file. This is due to lack of proper sanitization of the 'source' parameter and allowing a user-defined directory path. This makes it possible for unauthenticated attackers to execute code on the server.

    Published: 8 Jan 2025
    5.3
    Medium

    CVE-2024-10585

    Last Modified: 8 Apr 2026

    The InfiniteWP Client plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.13.0 via the 'historyID' parameter of the ~/debug-chart/index.php file. This makes it possible for unauthenticated attackers to read .txt files outside of the intended directory.

    Published: 8 Jan 2025
    8.8
    High

    CVE-2024-11270

    Last Modified: 8 Apr 2026

    The WordPress Webinar Plugin – WebinarPress plugin for WordPress is vulnerable to arbitrary file creation due to a missing capability check on the 'sync-import-imgs' function and missing file type validation in all versions up to, and including, 1.33.24. This makes it possible for authenticated attackers, with subscriber-level access and above, to create arbitrary files that can lead to remote code execution.

    Published: 8 Jan 2025
    6.5
    Medium

    CVE-2024-12030

    Last Modified: 8 Apr 2026

    The MDTF – Meta Data and Taxonomies Filter plugin for WordPress is vulnerable to SQL Injection via the 'key' attribute of the 'mdf_value' shortcode in all versions up to, and including, 1.3.3.5 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with Contributor-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

    Published: 8 Jan 2025
    8.8
    High

    CVE-2024-11271

    Last Modified: 8 Apr 2026

    The WordPress Webinar Plugin – WebinarPress plugin for WordPress is vulnerable to modification of data due to a missing capability check on several functions in all versions up to, and including, 1.33.24. This makes it possible for authenticated attackers, with subscriber-level access and above, to modify webinars.

    Published: 8 Jan 2025
    6.4
    Medium

    CVE-2024-12205

    Last Modified: 8 Apr 2026

    The Themesflat Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the TF E Slider Widget in all versions up to, and including, 2.2.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 8 Jan 2025
    4.8
    Medium

    CVE-2025-21603

    Last Modified: 15 Apr 2026

    Cross-site scripting vulnerability exists in MZK-DP300N firmware versions 1.05 and earlier. If an attacker logs in to the affected product and manipulates the device settings, an arbitrary script may be executed on the logged-in user's web browser when accessing a crafted URL.

    Published: 8 Jan 2025
    6.2
    Medium

    CVE-2024-54121

    Last Modified: 13 Jan 2025

    Startup control vulnerability in the ability module Impact: Successful exploitation of this vulnerability may cause features to perform abnormally.

    Published: 8 Jan 2025
    6.8
    Medium

    CVE-2024-56456

    Last Modified: 13 Jan 2025

    Vulnerability of input parameters not being verified during glTF model loading in the 3D engine module Impact: Successful exploitation of this vulnerability may affect availability.

    Published: 8 Jan 2025
    5.5
    Medium

    CVE-2024-56455

    Last Modified: 13 Jan 2025

    Vulnerability of input parameters not being verified during glTF model loading in the 3D engine module Impact: Successful exploitation of this vulnerability may affect availability.

    Published: 8 Jan 2025
    5.5
    Medium

    CVE-2024-56454

    Last Modified: 13 Jan 2025

    Vulnerability of input parameters not being verified during glTF model loading in the 3D engine module Impact: Successful exploitation of this vulnerability may affect availability.

    Published: 8 Jan 2025
    6.8
    Medium

    CVE-2024-56453

    Last Modified: 13 Jan 2025

    Vulnerability of input parameters not being verified during glTF model loading in the 3D engine module Impact: Successful exploitation of this vulnerability may affect availability.

    Published: 8 Jan 2025
    8.8
    High

    CVE-2024-11816

    Last Modified: 8 Apr 2026

    The Ultimate WordPress Toolkit – WP Extended plugin for WordPress is vulnerable to Remote Code Execution in version 3.0.11. This is due to a missing capability check on the 'wpext_handle_snippet_update' function. This makes it possible for authenticated attackers, with Subscriber-level access and above, to execute code on the server providing an admin has created at least one code snippet.

    Published: 8 Jan 2025
    6.4
    Medium

    CVE-2024-12112

    Last Modified: 15 Apr 2026

    The Easy Form Builder – WordPress plugin form builder: contact form, survey form, payment form, and custom form builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'name' parameter of the 'add_form_Emsfb' AJAX action in all versions up to, and including, 3.8.8 due to insufficient input sanitization and output escaping and missing authorization checks. This makes it possible for authenticated attackers, with Subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 8 Jan 2025
    7.4
    High

    CVE-2024-11916

    Last Modified: 8 Apr 2026

    The The Ultimate WordPress Toolkit – WP Extended plugin for WordPress is vulnerable to unauthorized modification and retrieval of data due to a missing capability check on several functions in all versions up to, and including, 3.0.11. This makes it possible for authenticated attackers, with subscriber-level access and above, to import and activate arbitrary code snippets along with

    Published: 8 Jan 2025
    5.3
    Medium

    CVE-2024-12713

    Last Modified: 8 Apr 2026

    The SureForms – Drag and Drop Form Builder for WordPress plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.2.2 via the handle_export_form() function due to a missing capability check. This makes it possible for unauthenticated attackers to export data from password protected, private, or draft posts that they should not have access to.

    Published: 8 Jan 2025
    6.4
    Medium

    CVE-2024-12521

    Last Modified: 15 Apr 2026

    The Slotti Ajanvaraus plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'slotti-embed-ga' shortcode in all versions up to, and including, 1.3.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 8 Jan 2025
    5.5
    Medium

    CVE-2024-56452

    Last Modified: 13 Jan 2025

    Vulnerability of input parameters not being verified during glTF model loading in the 3D engine module Impact: Successful exploitation of this vulnerability may affect availability.

    Published: 8 Jan 2025
    7.3
    High

    CVE-2024-56451

    Last Modified: 13 Jan 2025

    Integer overflow vulnerability during glTF model loading in the 3D engine module Impact: Successful exploitation of this vulnerability may affect availability.

    Published: 8 Jan 2025
    6.3
    Medium

    CVE-2024-56450

    Last Modified: 13 Jan 2025

    Buffer overflow vulnerability in the component driver module Impact: Successful exploitation of this vulnerability may affect availability.

    Published: 8 Jan 2025
    6.6
    Medium

    CVE-2024-56449

    Last Modified: 13 Jan 2025

    Privilege escalation vulnerability in the Account module Impact: Successful exploitation of this vulnerability may affect service confidentiality.

    Published: 8 Jan 2025
    6.7
    Medium

    CVE-2024-56448

    Last Modified: 13 Jan 2025

    Vulnerability of improper access control in the home screen widget module Impact: Successful exploitation of this vulnerability may affect availability.

    Published: 8 Jan 2025
    7.8
    High

    CVE-2024-56447

    Last Modified: 13 Jan 2025

    Vulnerability of improper permission control in the window management module Impact: Successful exploitation of this vulnerability may affect service confidentiality.

    Published: 8 Jan 2025
    4
    Medium

    CVE-2024-56446

    Last Modified: 13 Jan 2025

    Vulnerability of variables not being initialized in the notification module Impact: Successful exploitation of this vulnerability may affect availability.

    Published: 8 Jan 2025
    4.3
    Medium

    CVE-2024-56445

    Last Modified: 13 Jan 2025

    Instruction authentication bypass vulnerability in the Findnetwork module Impact: Successful exploitation of this vulnerability may cause features to perform abnormally.

    Published: 8 Jan 2025
    6.9
    Medium

    CVE-2024-47934

    Last Modified: 15 Apr 2026

    Improper Input Validation vulnerability in Management Program in TXOne Networks Portable Inspector and Portable Inspector Pro Edition allows remote attacker to crash management service. The Denial of Service situation can be resolved by restarting the management service. This issue affects Portable Inspector: through 1.0.0; Portable Inspector Pro Edition: through 1.0.0.

    Published: 8 Jan 2025
    7.5
    High

    CVE-2024-56444

    Last Modified: 13 Jan 2025

    Cross-process screen stack vulnerability in the UIExtension module Impact: Successful exploitation of this vulnerability may affect service confidentiality.

    Published: 8 Jan 2025
    6.2
    Medium

    CVE-2024-56443

    Last Modified: 13 Jan 2025

    Cross-process screen stack vulnerability in the UIExtension module Impact: Successful exploitation of this vulnerability may affect service confidentiality.

    Published: 8 Jan 2025
    4.1
    Medium

    CVE-2024-54120

    Last Modified: 13 Jan 2025

    Race condition vulnerability in the distributed notification module Impact: Successful exploitation of this vulnerability may cause features to perform abnormally.

    Published: 8 Jan 2025
    5.5
    Medium

    CVE-2024-56442

    Last Modified: 13 Jan 2025

    Vulnerability of native APIs not being implemented in the NFC service module Impact: Successful exploitation of this vulnerability may cause features to perform abnormally.

    Published: 8 Jan 2025
    4.1
    Medium

    CVE-2024-56441

    Last Modified: 13 Jan 2025

    Race condition vulnerability in the Bastet module Impact: Successful exploitation of this vulnerability may affect service confidentiality.

    Published: 8 Jan 2025
    6.2
    Medium

    CVE-2024-56440

    Last Modified: 13 Jan 2025

    Permission control vulnerability in the Connectivity module Impact: Successful exploitation of this vulnerability may cause features to perform abnormally.

    Published: 8 Jan 2025
    7.5
    High

    CVE-2024-56439

    Last Modified: 26 Sept 2025

    Access control vulnerability in the identity authentication module Impact: Successful exploitation of this vulnerability may affect service confidentiality.

    Published: 8 Jan 2025
    6
    Medium

    CVE-2024-56438

    Last Modified: 26 Sept 2025

    Vulnerability of improper memory address protection in the HUKS module Impact: Successful exploitation of this vulnerability may affect availability.

    Published: 8 Jan 2025
    5.7
    Medium

    CVE-2024-56437

    Last Modified: 13 Jan 2025

    Vulnerability of input parameters not being verified in the widget framework module Impact: Successful exploitation of this vulnerability may affect availability.

    Published: 8 Jan 2025
    6.5
    Medium

    CVE-2023-52955

    Last Modified: 13 Jan 2025

    Vulnerability of improper authentication in the ANS system service module Impact: Successful exploitation of this vulnerability may cause features to perform abnormally.

    Published: 8 Jan 2025
    6.5
    Medium

    CVE-2024-47239

    Last Modified: 20 Feb 2026

    Dell PowerScale OneFS versions 8.2.2.x through 9.9.0.0 contain an uncontrolled resource consumption vulnerability. A remote low privileged attacker could potentially exploit this vulnerability, leading to denial of service.

    Published: 8 Jan 2025
    6.1
    Medium

    CVE-2024-12585

    Last Modified: 14 May 2025

    The Property Hive WordPress plugin before 2.1.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

    Published: 8 Jan 2025
    5.4
    Medium

    CVE-2024-10151

    Last Modified: 14 May 2025

    The Auto iFrame WordPress plugin before 2.0 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

    Published: 8 Jan 2025
    4.4
    Medium

    CVE-2023-52954

    Last Modified: 13 Jan 2025

    Vulnerability of improper permission control in the Gallery module Impact: Successful exploitation of this vulnerability may affect availability.

    Published: 8 Jan 2025