CVE Feed

    Dashboard / CVE

    6.9
    Medium

    CVE-2024-13108

    Last Modified: 2 May 2025

    A vulnerability was found in D-Link DIR-816 A2 1.10CNB05_R1B011D88210. It has been declared as critical. This vulnerability affects unknown code of the file /goform/form2NetSniper.cgi. The manipulation leads to improper access controls. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

    Published: 2 Jan 2025
    6.9
    Medium

    CVE-2024-13107

    Last Modified: 2 May 2025

    A vulnerability was found in D-Link DIR-816 A2 1.10CNB05_R1B011D88210. It has been classified as critical. This affects an unknown part of the file /goform/form2LocalAclEditcfg.cgi of the component ACL Handler. The manipulation leads to improper access controls. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

    Published: 2 Jan 2025
    6.9
    Medium

    CVE-2024-13106

    Last Modified: 2 May 2025

    A vulnerability was found in D-Link DIR-816 A2 1.10CNB05_R1B011D88210 and classified as critical. Affected by this issue is some unknown functionality of the file /goform/form2IPQoSTcAdd of the component IP QoS Handler. The manipulation leads to improper access controls. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

    Published: 2 Jan 2025
    6.9
    Medium

    CVE-2024-13105

    Last Modified: 2 May 2025

    A vulnerability has been found in D-Link DIR-816 A2 1.10CNB05_R1B011D88210 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /goform/form2Dhcpd.cgi of the component DHCPD Setting Handler. The manipulation leads to improper access controls. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

    Published: 2 Jan 2025
    6.9
    Medium

    CVE-2024-13104

    Last Modified: 2 May 2025

    A vulnerability, which was classified as critical, was found in D-Link DIR-816 A2 1.10CNB05_R1B011D88210. Affected is an unknown function of the file /goform/form2AdvanceSetup.cgi of the component WiFi Settings Handler. The manipulation leads to improper access controls. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

    Published: 2 Jan 2025
    6.9
    Medium

    CVE-2024-13103

    Last Modified: 2 May 2025

    A vulnerability, which was classified as critical, has been found in D-Link DIR-816 A2 1.10CNB05_R1B011D88210. This issue affects some unknown processing of the file /goform/form2AddVrtsrv.cgi of the component Virtual Service Handler. The manipulation leads to improper access controls. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

    Published: 2 Jan 2025
    6.9
    Medium

    CVE-2024-13102

    Last Modified: 2 May 2025

    A vulnerability classified as critical was found in D-Link DIR-816 A2 1.10CNB05_R1B011D88210. This vulnerability affects unknown code of the file /goform/DDNS of the component DDNS Service. The manipulation leads to improper access controls. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

    Published: 2 Jan 2025
    5.3
    Medium

    CVE-2024-13093

    Last Modified: 3 Apr 2025

    A vulnerability, which was classified as critical, has been found in code-projects Job Recruitment 1.0. This issue affects some unknown processing of the file /_parse/_call_main_search_ajax.php of the component Seeker Profile Handler. The manipulation of the argument s1 leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

    Published: 2 Jan 2025
    5.3
    Medium

    CVE-2024-13092

    Last Modified: 3 Apr 2025

    A vulnerability classified as critical was found in code-projects Job Recruitment 1.0. This vulnerability affects unknown code of the file /_parse/_call_job/search_ajax.php of the component Job Post Handler. The manipulation of the argument n leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

    Published: 2 Jan 2025
    4.7
    Medium

    CVE-2024-12595

    Last Modified: 12 Jun 2025

    The AHAthat Plugin WordPress plugin through 1.6 does not escape the $_SERVER['REQUEST_URI'] parameter before outputting it back in an attribute, which could lead to Reflected Cross-Site Scripting in old web browsers

    Published: 2 Jan 2025
    5.9
    Medium

    CVE-2024-11357

    Last Modified: 5 Jun 2025

    The goodlayers-core WordPress plugin before 2.0.10 does not sanitise and escape some of its settings, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

    Published: 2 Jan 2025
    4.8
    Medium

    CVE-2024-11184

    Last Modified: 24 Jun 2025

    The wp-enable-svg WordPress plugin through 0.7 does not sanitize SVG files when uploaded, allowing for authors and above to upload SVGs containing malicious scripts

    Published: 2 Jan 2025
    4.3
    Medium

    CVE-2025-22214

    Last Modified: 15 Apr 2026

    Landray EIS 2001 through 2006 allows Message/fi_message_receiver.aspx?replyid= SQL injection.

    Published: 2 Jan 2025
    5.4
    Medium

    CVE-2024-56830

    Last Modified: 15 Apr 2026

    The Net::EasyTCP package 0.15 through 0.26 for Perl uses Perl's builtin rand() if no strong randomization module is present.

    Published: 2 Jan 2025
    5.4
    Medium

    CVE-2002-20002

    Last Modified: 15 Apr 2026

    The Net::EasyTCP package before 0.15 for Perl always uses Perl's builtin rand(), which is not a strong random number generator, for cryptographic keys.

    Published: 2 Jan 2025
    5.5
    Medium

    CVE-2022-49035

    Last Modified: 29 Oct 2025

    In the Linux kernel, the following vulnerability has been resolved: media: s5p_cec: limit msg.len to CEC_MAX_MSG_SIZE I expect that the hardware will have limited this to 16, but just in case it hasn't, check for this corner case.

    Published: 2 Jan 2025
    4.7
    Medium

    CVE-2024-48197

    Last Modified: 15 Apr 2026

    Cross Site Scripting vulnerability in Audiocodes MP-202b v.4.4.3 allows a remote attacker to escalate privileges via the login page of the web interface.

    Published: 2 Jan 2025
    10
    Critical

    CVE-2024-56829

    Last Modified: 15 Apr 2026

    Huang Yaoshi Pharmaceutical Management Software through 16.0 allows arbitrary file upload via a .asp filename in the fileName element of the UploadFile element in a SOAP request to /XSDService.asmx.

    Published: 2 Jan 2025
    5.3
    Medium

    CVE-2025-0168

    Last Modified: 25 Feb 2025

    A vulnerability classified as critical has been found in code-projects Job Recruitment 1.0. This affects an unknown part of the file /_parse/_feedback_system.php. The manipulation of the argument person leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

    Published: 1 Jan 2025
    6.1
    Medium

    CVE-2024-11846

    Last Modified: 9 Jan 2026

    The does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

    Published: 1 Jan 2025
    —
    Unknown

    CVE-2025-22203

    Last Modified: 1 Jan 2026

    To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used.

    Published: 1 Jan 2025
    —
    Unknown

    CVE-2025-22197

    Last Modified: 1 Jan 2026

    To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used.

    Published: 1 Jan 2025
    —
    Unknown

    CVE-2025-22198

    Last Modified: 1 Jan 2026

    To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used.

    Published: 1 Jan 2025
    —
    Unknown

    CVE-2025-22199

    Last Modified: 1 Jan 2026

    To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used.

    Published: 1 Jan 2025
    —
    Unknown

    CVE-2025-22200

    Last Modified: 1 Jan 2026

    To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used.

    Published: 1 Jan 2025
    —
    Unknown

    CVE-2025-22201

    Last Modified: 1 Jan 2026

    To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used.

    Published: 1 Jan 2025
    —
    Unknown

    CVE-2025-22202

    Last Modified: 1 Jan 2026

    To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used.

    Published: 1 Jan 2025
    —
    Unknown

    CVE-2025-22194

    Last Modified: 1 Jan 2026

    To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used.

    Published: 1 Jan 2025
    —
    Unknown

    CVE-2025-22195

    Last Modified: 1 Jan 2026

    To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used.

    Published: 1 Jan 2025
    —
    Unknown

    CVE-2025-22196

    Last Modified: 1 Jan 2026

    To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used.

    Published: 1 Jan 2025
    —
    Unknown

    CVE-2025-22192

    Last Modified: 1 Jan 2026

    To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used.

    Published: 1 Jan 2025
    —
    Unknown

    CVE-2025-22193

    Last Modified: 1 Jan 2026

    To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used.

    Published: 1 Jan 2025
    —
    Unknown

    CVE-2025-22185

    Last Modified: 1 Jan 2026

    To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used.

    Published: 1 Jan 2025
    —
    Unknown

    CVE-2025-22186

    Last Modified: 1 Jan 2026

    To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used.

    Published: 1 Jan 2025
    —
    Unknown

    CVE-2025-22187

    Last Modified: 1 Jan 2026

    To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used.

    Published: 1 Jan 2025
    —
    Unknown

    CVE-2025-22188

    Last Modified: 1 Jan 2026

    To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used.

    Published: 1 Jan 2025
    —
    Unknown

    CVE-2025-22189

    Last Modified: 1 Jan 2026

    To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used.

    Published: 1 Jan 2025
    —
    Unknown

    CVE-2025-22190

    Last Modified: 1 Jan 2026

    To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used.

    Published: 1 Jan 2025
    —
    Unknown

    CVE-2025-22191

    Last Modified: 1 Jan 2026

    To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used.

    Published: 1 Jan 2025
    —
    Unknown

    CVE-2025-22182

    Last Modified: 1 Jan 2026

    To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used.

    Published: 1 Jan 2025
    —
    Unknown

    CVE-2025-22183

    Last Modified: 1 Jan 2026

    To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used.

    Published: 1 Jan 2025
    —
    Unknown

    CVE-2025-22184

    Last Modified: 1 Jan 2026

    To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used.

    Published: 1 Jan 2025
    —
    Unknown

    CVE-2025-22180

    Last Modified: 1 Jan 2026

    To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used.

    Published: 1 Jan 2025
    —
    Unknown

    CVE-2025-22181

    Last Modified: 1 Jan 2026

    To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used.

    Published: 1 Jan 2025
    —
    Unknown

    CVE-2025-22154

    Last Modified: 1 Jan 2026

    To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used.

    Published: 1 Jan 2025
    —
    Unknown

    CVE-2025-22155

    Last Modified: 1 Jan 2026

    To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used.

    Published: 1 Jan 2025
    6.5
    Medium

    CVE-2024-56020

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in svegliadesign SvegliaT Buttons svegliat-buttons allows Stored XSS.This issue affects SvegliaT Buttons: from n/a through <= 1.3.0.

    Published: 31 Dec 2024
    6.5
    Medium

    CVE-2024-56021

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ibnuyahya Category Post Shortcode category-post-shortcode allows Stored XSS.This issue affects Category Post Shortcode: from n/a through <= 2.4.

    Published: 31 Dec 2024
    6.5
    Medium

    CVE-2024-56062

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Royal Royal Elementor Addons royal-elementor-addons allows Stored XSS.This issue affects Royal Elementor Addons: from n/a through <= 1.3.987.

    Published: 31 Dec 2024
    6.5
    Medium

    CVE-2024-56063

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPDeveloper Essential Addons for Elementor essential-addons-for-elementor-lite allows Stored XSS.This issue affects Essential Addons for Elementor: from n/a through <= 6.0.7.

    Published: 31 Dec 2024