CVE Feed

    Dashboard / CVE

    5.1
    Medium

    CVE-2024-56803

    Last Modified: 15 Apr 2026

    Ghostty is a cross-platform terminal emulator. Ghostty, as allowed by default in 1.0.0, allows attackers to modify the window title via a certain character escape sequence and then insert it back to the command line in the user's terminal, e.g. when the user views a file containing the malicious sequence, which could allow the attacker to execute arbitrary commands. This attack requires an attacker to send malicious escape sequences followed by convincing the user to physically press the "enter" key. Fixed in Ghostty v1.0.1.

    Published: 31 Dec 2024
    —
    Unknown

    CVE-2024-56825

    Last Modified: 5 Jan 2026

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2024. Notes: none

    Published: 31 Dec 2024
    5.1
    Medium

    CVE-2024-13080

    Last Modified: 30 Sept 2025

    A vulnerability was found in PHPGurukul Land Record System 1.0. It has been classified as problematic. This affects an unknown part of the file /admin/aboutus.php. The manipulation of the argument Page Description leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

    Published: 31 Dec 2024
    6.9
    Medium

    CVE-2024-13085

    Last Modified: 6 Jan 2025

    A vulnerability, which was classified as critical, has been found in PHPGurukul Land Record System 1.0. Affected by this issue is some unknown functionality of the file /admin/login.php. The manipulation of the argument username leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

    Published: 31 Dec 2024
    5.3
    Medium

    CVE-2024-13084

    Last Modified: 6 Jan 2025

    A vulnerability classified as critical was found in PHPGurukul Land Record System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/search-property.php. The manipulation of the argument searchdata leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

    Published: 31 Dec 2024
    5.3
    Medium

    CVE-2024-13083

    Last Modified: 6 Jan 2025

    A vulnerability classified as problematic has been found in PHPGurukul Land Record System 1.0. Affected is an unknown function of the file /admin/admin-profile.php. The manipulation of the argument Admin Name leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

    Published: 31 Dec 2024
    5.3
    Medium

    CVE-2024-13082

    Last Modified: 6 Jan 2025

    A vulnerability was found in PHPGurukul Land Record System 1.0. It has been rated as problematic. This issue affects some unknown processing of the file /admin/search-property.php. The manipulation of the argument Search By leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

    Published: 31 Dec 2024
    5.3
    Medium

    CVE-2024-13081

    Last Modified: 6 Jan 2025

    A vulnerability was found in PHPGurukul Land Record System 1.0. It has been declared as problematic. This vulnerability affects unknown code of the file /admin/contactus.php. The manipulation of the argument Page Description leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

    Published: 31 Dec 2024
    6.7
    Medium

    CVE-2024-55955

    Last Modified: 9 Sept 2025

    An incorrect permissions assignment vulnerability in Trend Micro Deep Security 20.0 agents between versions 20.0.1-9400 and 20.0.1-23340 could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.

    Published: 31 Dec 2024
    7.8
    High

    CVE-2024-55917

    Last Modified: 31 Dec 2024

    An origin validation error vulnerability in Trend Micro Apex One could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.

    Published: 31 Dec 2024
    7.8
    High

    CVE-2024-55632

    Last Modified: 31 Dec 2024

    A security agent link following vulnerability in Trend Micro Apex One could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.

    Published: 31 Dec 2024
    7.8
    High

    CVE-2024-55631

    Last Modified: 31 Dec 2024

    An engine link following vulnerability in Trend Micro Apex One could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.

    Published: 31 Dec 2024
    6.5
    Medium

    CVE-2024-53647

    Last Modified: 29 Sept 2025

    Trend Micro ID Security, version 3.0 and below contains a vulnerability that could allow an attacker to send an unlimited number of email verification requests without any restriction, potentially leading to abuse or denial of service.

    Published: 31 Dec 2024
    7.8
    High

    CVE-2024-52050

    Last Modified: 31 Dec 2024

    A LogServer arbitrary file creation vulnerability in Trend Micro Apex One could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.

    Published: 31 Dec 2024
    7.8
    High

    CVE-2024-52049

    Last Modified: 31 Dec 2024

    A LogServer link following vulnerability in Trend Micro Apex One could allow a local attacker to escalate privileges on affected installations. This vulnerability is similar to, but not identical to CVE-2024-52048. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.

    Published: 31 Dec 2024
    7.8
    High

    CVE-2024-52048

    Last Modified: 31 Dec 2024

    A LogServer link following vulnerability in Trend Micro Apex One could allow a local attacker to escalate privileges on affected installations. This vulnerability is similar to, but not identical to CVE-2024-52049. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.

    Published: 31 Dec 2024
    7.5
    High

    CVE-2024-52047

    Last Modified: 29 Jul 2025

    A widget local file inclusion vulnerability in Trend Micro Apex One could allow a remote attacker to execute arbitrary code on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.

    Published: 31 Dec 2024
    5.3
    Medium

    CVE-2024-13079

    Last Modified: 6 Jan 2025

    A vulnerability was found in PHPGurukul Land Record System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /admin/property-details.php. The manipulation of the argument editid leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

    Published: 31 Dec 2024
    9.3
    Critical

    CVE-2024-56198

    Last Modified: 15 Apr 2026

    path-sanitizer is a simple lightweight npm package for sanitizing paths to prevent Path Traversal. Prior to 3.1.0, the filters can be bypassed using .=%5c which results in a path traversal. This vulnerability is fixed in 3.1.0.

    Published: 31 Dec 2024
    8.7
    High

    CVE-2024-56802

    Last Modified: 15 Apr 2026

    Tapir is a private Terraform registry. Tapir versions 0.9.0 and 0.9.1 are facing a critical issue with scope-able Deploykeys where attackers can guess the key to get write access to the registry. User must upgrade to 0.9.2.

    Published: 31 Dec 2024
    —
    Unknown

    CVE-2024-56809

    Last Modified: 5 Jan 2026

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2024. Notes: none

    Published: 31 Dec 2024
    5.3
    Medium

    CVE-2024-13078

    Last Modified: 6 Jan 2025

    A vulnerability has been found in PHPGurukul Land Record System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /index.php. The manipulation of the argument searchdata leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

    Published: 31 Dec 2024
    5.3
    Medium

    CVE-2024-13077

    Last Modified: 6 Jan 2025

    A vulnerability, which was classified as problematic, was found in PHPGurukul Land Record System 1.0. Affected is an unknown function of the file /admin/add-property.php. The manipulation of the argument Land Subtype leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

    Published: 31 Dec 2024
    8.8
    High

    CVE-2024-25133

    Last Modified: 15 Apr 2026

    A flaw was found in the Hive ClusterDeployments resource in OpenShift Dedicated. In certain conditions, this issue may allow a developer account on a Hive-enabled cluster to obtain cluster-admin privileges by executing arbitrary commands on the hive/hive-controllers pod.

    Published: 31 Dec 2024
    7.5
    High

    CVE-2023-6603

    Last Modified: 21 Aug 2025

    A flaw was found in FFmpeg's HLS playlist parsing. This vulnerability allows a denial of service via a maliciously crafted HLS playlist that triggers a null pointer dereference during initialization.

    Published: 31 Dec 2024
    5.3
    Medium

    CVE-2023-6602

    Last Modified: 3 Nov 2025

    A flaw was found in FFmpeg's TTY Demuxer. This vulnerability allows possible data exfiltration via improper parsing of non-TTY-compliant input files in HLS playlists.

    Published: 31 Dec 2024
    5.3
    Medium

    CVE-2024-13076

    Last Modified: 6 Jan 2025

    A vulnerability, which was classified as problematic, has been found in PHPGurukul Land Record System 1.0. This issue affects some unknown processing of the file /admin/edit-propertytype.php. The manipulation of the argument Property Type leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

    Published: 31 Dec 2024
    5.4
    Medium

    CVE-2024-49686

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in fatcatapps Landing Page Cat landing-page-cat.This issue affects Landing Page Cat: from n/a through <= 1.7.4.

    Published: 31 Dec 2024
    4.3
    Medium

    CVE-2024-49687

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in storeapps Smart Manager smart-manager-for-wp-e-commerce.This issue affects Smart Manager: from n/a through <= 8.45.0.

    Published: 31 Dec 2024
    5.3
    Medium

    CVE-2024-49694

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in imw3 My Wp Brand my-wp-brand.This issue affects My Wp Brand: from n/a through <= 1.1.2.

    Published: 31 Dec 2024
    4.3
    Medium

    CVE-2024-49698

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in PriceListo Best Restaurant Menu by PriceListo best-restaurant-menu-by-pricelisto.This issue affects Best Restaurant Menu by PriceListo: from n/a through <= 1.4.2.

    Published: 31 Dec 2024
    4.3
    Medium

    CVE-2024-51667

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in paytiumsupport Paytium paytium.This issue affects Paytium: from n/a through <= 4.4.10.

    Published: 31 Dec 2024
    6.5
    Medium

    CVE-2024-55995

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in Torod Company for Information Technology Torod torod allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Torod: from n/a through <= 1.7.

    Published: 31 Dec 2024
    6.4
    Medium

    CVE-2024-56002

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in mightyforms Contact Form, Survey & Form Builder – MightyForms mightyforms allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Contact Form, Survey & Form Builder – MightyForms: from n/a through <= 1.3.9.

    Published: 31 Dec 2024
    7.4
    High

    CVE-2024-56070

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in azzaroco WP SuperBackup indeed-wp-superbackup allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP SuperBackup: from n/a through <= 2.3.3.

    Published: 31 Dec 2024
    8.8
    High

    CVE-2024-56207

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in EditionGuard EditionGuard for WooCommerce – eBook Sales with DRM editionguard-for-woocommerce-ebook-sales-with-drm allows Privilege Escalation.This issue affects EditionGuard for WooCommerce – eBook Sales with DRM: from n/a through <= 3.4.2.

    Published: 31 Dec 2024
    5.3
    Medium

    CVE-2024-13075

    Last Modified: 6 Jan 2025

    A vulnerability classified as problematic was found in PHPGurukul Land Record System 1.0. This vulnerability affects unknown code of the file /admin/add-propertytype.php. The manipulation of the argument Land Property Type leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

    Published: 31 Dec 2024
    8.8
    High

    CVE-2024-56206

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in krishankakkar gap-hub-user-role gap-hub-user-role allows Authentication Bypass.This issue affects gap-hub-user-role: from n/a through <= 3.4.1.

    Published: 31 Dec 2024
    8.8
    High

    CVE-2024-56204

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in yonisink Sinking Dropdowns sinking-dropdowns allows Privilege Escalation.This issue affects Sinking Dropdowns: from n/a through <= 1.25.

    Published: 31 Dec 2024
    8.8
    High

    CVE-2024-56203

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in gholme4 Wayne Audio Player wayne-audio-player allows Privilege Escalation.This issue affects Wayne Audio Player: from n/a through <= 1.0.

    Published: 31 Dec 2024
    9.8
    Critical

    CVE-2024-56066

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in inspry Agency Toolkit agency-toolkit allows Privilege Escalation.This issue affects Agency Toolkit: from n/a through <= 1.0.23.

    Published: 31 Dec 2024
    8.8
    High

    CVE-2024-56061

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in Ateeq Rafeeq RepairBuddy computer-repair-shop allows Privilege Escalation.This issue affects RepairBuddy: from n/a through <= 3.8119.

    Published: 31 Dec 2024
    9.3
    Critical

    CVE-2024-56045

    Last Modified: 23 Apr 2026

    Path Traversal: '.../...//' vulnerability in VibeThemes WPLMS wplms_plugin allows Path Traversal.This issue affects WPLMS: from n/a through < 1.9.9.5.

    Published: 31 Dec 2024
    9.8
    Critical

    CVE-2024-56044

    Last Modified: 23 Apr 2026

    Authentication Bypass Using an Alternate Path or Channel vulnerability in VibeThemes WPLMS wplms_plugin allows Authentication Bypass.This issue affects WPLMS: from n/a through <= 1.9.9.

    Published: 31 Dec 2024
    9.8
    Critical

    CVE-2024-56043

    Last Modified: 23 Apr 2026

    Incorrect Privilege Assignment vulnerability in VibeThemes WPLMS wplms_plugin allows Privilege Escalation.This issue affects WPLMS: from n/a through <= 1.9.9.

    Published: 31 Dec 2024
    9.8
    Critical

    CVE-2024-56040

    Last Modified: 23 Apr 2026

    Incorrect Privilege Assignment vulnerability in VibeThemes VibeBP vibebp allows Privilege Escalation.This issue affects VibeBP: from n/a through <= 1.9.9.4.1.

    Published: 31 Dec 2024
    9.3
    Critical

    CVE-2024-56042

    Last Modified: 23 Apr 2026

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in VibeThemes WPLMS wplms_plugin allows SQL Injection.This issue affects WPLMS: from n/a through < 1.9.9.5.3.

    Published: 31 Dec 2024
    8.5
    High

    CVE-2024-56041

    Last Modified: 23 Apr 2026

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in VibeThemes VibeBP vibebp allows SQL Injection.This issue affects VibeBP: from n/a through < 1.9.9.5.1.

    Published: 31 Dec 2024
    9.3
    Critical

    CVE-2024-56039

    Last Modified: 23 Apr 2026

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in VibeThemes VibeBP vibebp allows SQL Injection.This issue affects VibeBP: from n/a through < 1.9.9.7.7.

    Published: 31 Dec 2024
    10
    Critical

    CVE-2024-56064

    Last Modified: 23 Apr 2026

    Unrestricted Upload of File with Dangerous Type vulnerability in azzaroco WP SuperBackup indeed-wp-superbackup allows Upload a Web Shell to a Web Server.This issue affects WP SuperBackup: from n/a through <= 2.3.3.

    Published: 31 Dec 2024