CVE Feed

    Dashboard / CVE

    8.8
    High

    CVE-2024-12259

    Last Modified: 15 Apr 2026

    The CRM WordPress Plugin – RepairBuddy plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 3.8120. This is due to the plugin not properly validating a user's identity prior to updating their email through the wc_update_user_data AJAX action. This makes it possible for authenticated attackers, with subscriber-level access and above, to change arbitrary user's email addresses, including administrators, and leverage that to reset the user's password and gain access to their account.

    Published: 18 Dec 2024
    6.1
    Medium

    CVE-2024-11254

    Last Modified: 8 Apr 2026

    The AMP for WP – Accelerated Mobile Pages plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the disqus_name parameter in all versions up to, and including, 1.1.1 due to insufficient input validation. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

    Published: 18 Dec 2024
    7.5
    High

    CVE-2024-12025

    Last Modified: 15 Apr 2026

    The Collapsing Categories plugin for WordPress is vulnerable to SQL Injection via the 'taxonomy' parameter of the /wp-json/collapsing-categories/v1/get REST API in all versions up to, and including, 3.0.8 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

    Published: 18 Dec 2024
    8.1
    High

    CVE-2024-12432

    Last Modified: 15 Apr 2026

    The WPC Shop as a Customer for WooCommerce plugin for WordPress is vulnerable to account takeover and privilege escalation in all versions up to, and including, 1.2.8. This is due to the 'generate_key' function not producing a sufficiently random value. This makes it possible for authenticated attackers, with Subscriber-level access and above, to log in as site administrators, granted they have triggered the ajax_login() function which generates a unique key that can be used to log in.

    Published: 18 Dec 2024
    6.4
    Medium

    CVE-2024-12513

    Last Modified: 15 Apr 2026

    The Contests by Rewards Fuel plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'RF_CONTEST' shortcode in all versions up to, and including, 2.0.65 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 18 Dec 2024
    6.4
    Medium

    CVE-2024-11881

    Last Modified: 15 Apr 2026

    The Easy Waveform Player plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'easywaveformplayer' shortcode in all versions up to, and including, 1.2.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 18 Dec 2024
    6.4
    Medium

    CVE-2024-12500

    Last Modified: 15 Apr 2026

    The Philantro – Donations and Donor Management plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes like 'donate' in all versions up to, and including, 5.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 18 Dec 2024
    6.4
    Medium

    CVE-2024-11748

    Last Modified: 15 Apr 2026

    The Taeggie Feed plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'taeggie-feed' shortcode in all versions up to, and including, 0.1.9 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 18 Dec 2024
    6.4
    Medium

    CVE-2024-11439

    Last Modified: 15 Apr 2026

    The ScanCircle plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'scancircle' shortcode in all versions up to, and including, 2.9.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 18 Dec 2024
    5.4
    Medium

    CVE-2024-10892

    Last Modified: 14 May 2025

    The Cost Calculator Builder WordPress plugin before 3.2.43 does not have CSRF checks in some AJAX actions, which could allow attackers to make logged in users perform unwanted actions via CSRF attacks.

    Published: 18 Dec 2024
    7.8
    High

    CVE-2024-47480

    Last Modified: 4 Feb 2025

    Dell Inventory Collector Client, versions prior to 12.7.0, contains an Improper Link Resolution Before File Access vulnerability. A low-privilege attacker with local access may exploit this vulnerability, potentially resulting in Elevation of Privileges and unauthorized file system access.

    Published: 18 Dec 2024
    4.1
    Medium

    CVE-2024-55089

    Last Modified: 20 Feb 2026

    Rhymix before 2.1.24 is vulnerable to Server-Side Request Forgery (SSRF) in the background import data function because XML documents may contain external entities.

    Published: 18 Dec 2024
    7.5
    High

    CVE-2024-56319

    Last Modified: 15 Apr 2026

    In Matter (aka connectedhomeip or Project CHIP) through 1.4.0.0 before e3277eb, unlimited user label appends in a userlabel cluster can lead to a denial of service (resource exhaustion).

    Published: 18 Dec 2024
    6.1
    Medium

    CVE-2024-56175

    Last Modified: 5 Jun 2025

    In Optimizely Configured Commerce before 5.2.2408, malicious payloads can be stored and subsequently executed in users' browsers under specific conditions: XSS from client-side template injection in list item names.

    Published: 18 Dec 2024
    4.7
    Medium

    CVE-2024-56173

    Last Modified: 5 Jun 2025

    In Optimizely Configured Commerce before 5.2.2408, malicious payloads can be stored and subsequently executed in users' browsers under specific conditions: XSS from JavaScript in an SVG document.

    Published: 18 Dec 2024
    7.2
    High

    CVE-2024-55086

    Last Modified: 18 Apr 2025

    In the GetSimple CMS CE 3.3.19 management page, Server-Side Request Forgery (SSRF) can be achieved in the plug-in download address in the backend management system.

    Published: 18 Dec 2024
    5.4
    Medium

    CVE-2024-55232

    Last Modified: 28 Mar 2025

    An IDOR vulnerability in the manage-notes.php module in PHPGurukul Online Notes Sharing Management System v1.0 allows unauthorized users to delete notes belonging to other accounts due to missing authorization checks. This flaw enables attackers to delete another user's information.

    Published: 18 Dec 2024
    8.1
    High

    CVE-2024-56174

    Last Modified: 5 Jun 2025

    In Optimizely Configured Commerce before 5.2.2408, malicious payloads can be stored and subsequently executed in users' browsers under specific conditions: XSS from client-side template injection in search history.

    Published: 18 Dec 2024
    4.3
    Medium

    CVE-2024-49201

    Last Modified: 15 Apr 2026

    Keyfactor Remote File Orchestrator (aka remote-file-orchestrator) 2.8 before 2.8.1 allows Information Disclosure: sensitive information could be exposed at the debug logging level.

    Published: 18 Dec 2024
    7.5
    High

    CVE-2024-53580

    Last Modified: 3 Nov 2025

    iperf v3.17.1 was discovered to contain a segmentation violation via the iperf_exchange_parameters() function.

    Published: 18 Dec 2024
    7.2
    High

    CVE-2024-36694

    Last Modified: 22 Apr 2025

    OpenCart 4.0.2.3 is vulnerable to Server-Side Template Injection (SSTI) via the Theme Editor Function.

    Published: 18 Dec 2024
    4.6
    Medium

    CVE-2024-37649

    Last Modified: 15 Apr 2026

    Insecure Permissions vulnerability in SecureSTATION v.2.5.5.3116-S50-SMA-B20160811A and before allows a physically proximate attacker to obtain sensitive information via the modification of user credentials.

    Published: 18 Dec 2024
    7.5
    High

    CVE-2024-56317

    Last Modified: 15 Apr 2026

    In Matter (aka connectedhomeip or Project CHIP) through 1.4.0.0, the WriteAcl function deletes all existing ACL entries first, and then attempts to recreate them based on user input. If input validation fails during decoding, the process stops, and no entries are restored by access-control-server.cpp, i.e., a denial of service.

    Published: 18 Dec 2024
    7.5
    High

    CVE-2024-56318

    Last Modified: 15 Apr 2026

    In raw\TCP.cpp in Matter (aka connectedhomeip or Project CHIP) through 1.4.0.0 before 27ca6ec, there is a NULL pointer dereference in TCPBase::ProcessSingleMessage via TCP packets with zero messageSize, leading to denial of service.

    Published: 18 Dec 2024
    8.7
    High

    CVE-2024-39703

    Last Modified: 15 Apr 2026

    In ThreatQuotient ThreatQ before 5.29.3, authenticated users are able to execute arbitrary commands by sending a crafted request to an API endpoint.

    Published: 18 Dec 2024
    7.6
    High

    CVE-2024-49202

    Last Modified: 15 Apr 2026

    Keyfactor Command before 12.5.0 has Incorrect Access Control: access tokens are over permissioned, aka 64099. The fixed versions are 11.5.1.1, 11.5.2.1, 11.5.3.1, 11.5.4.5, 11.5.6.1, 11.6.0, 12.2.0.1, 12.3.0.1, 12.4.0.1, 12.5.0, and 24.4.0.

    Published: 18 Dec 2024
    8.8
    High

    CVE-2024-55088

    Last Modified: 17 Apr 2025

    GetSimple CMS CE 3.3.19 is vulnerable to Server-Side Request Forgery (SSRF) in the backend plugin module.

    Published: 18 Dec 2024
    4.3
    Medium

    CVE-2024-55231

    Last Modified: 27 Mar 2025

    An IDOR vulnerability in the edit-notes.php module of PHPGurukul Online Notes Sharing Management System v1.0 allows unauthorized users to modify notes belonging to other accounts due to missing authorization checks. This flaw exposes sensitive data and enables attackers to alter another user's information.

    Published: 18 Dec 2024
    5.4
    Medium

    CVE-2024-55239

    Last Modified: 3 Jul 2025

    A reflected Cross-Site Scripting vulnerability in the standard documentation upload functionality in Portabilis i-Educar 2.9 allows attacker to craft malicious urls with arbitrary javascript in the 'titulo_documento' parameter.

    Published: 18 Dec 2024
    9.8
    Critical

    CVE-2024-55461

    Last Modified: 28 Mar 2025

    SeaCMS <=13.0 is vulnerable to command execution in phome.php via the function Ebak_RepPathFiletext().

    Published: 18 Dec 2024
    6.1
    Medium

    CVE-2024-55492

    Last Modified: 17 Jul 2025

    Winmail Server 4.4 is vulnerable to f_user=%22%3E%3Csvg%20onload Cross Site Scripting (XSS).

    Published: 18 Dec 2024
    8.8
    High

    CVE-2024-55505

    Last Modified: 17 Apr 2025

    An issue in CodeAstro Complaint Management System v.1.0 allows a remote attacker to escalate privileges via the mess-view.php component.

    Published: 18 Dec 2024
    8.8
    High

    CVE-2024-55506

    Last Modified: 3 Apr 2025

    An IDOR vulnerability in CodeAstro's Complaint Management System v1.0 (version with 0 updates) enables an attacker to execute arbitrary code and obtain sensitive information via the delete.php file and modifying the id parameter.

    Published: 18 Dec 2024
    6.1
    Medium

    CVE-2024-56115

    Last Modified: 23 Apr 2025

    A vulnerability in Amiro.CMS before 7.8.4 exists due to the failure to take measures to neutralize special elements. It allows remote attackers to conduct a Cross-Site Scripting (XSS) attack.

    Published: 18 Dec 2024
    8.8
    High

    CVE-2024-56116

    Last Modified: 23 Apr 2025

    A Cross-Site Request Forgery vulnerability in Amiro.CMS before 7.8.4 allows remote attackers to create an administrator account.

    Published: 18 Dec 2024
    5.3
    Medium

    CVE-2024-56169

    Last Modified: 22 Apr 2025

    A validation integrity issue was discovered in Fort through 1.6.4 before 2.0.0. RPKI Relying Parties (such as Fort) are supposed to maintain a backup cache of the remote RPKI data. This can be employed as a fallback in case a new fetch fails or yields incorrect files. However, the product currently uses its cache merely as a bandwidth saving tool (because fetching is performed through deltas). If a fetch fails midway or yields incorrect files, there is no viable fallback. This leads to incomplete route origin validation data.

    Published: 18 Dec 2024
    5.3
    Medium

    CVE-2024-56170

    Last Modified: 22 Apr 2025

    A validation integrity issue was discovered in Fort through 1.6.4 before 2.0.0. RPKI manifests are listings of relevant files that clients are supposed to verify. Assuming everything else is correct, the most recent version of a manifest should be prioritized over other versions, to prevent replays, accidental or otherwise. Manifests contain the manifestNumber and thisUpdate fields, which can be used to gauge the relevance of a given manifest, when compared to other manifests. The former is a serial-like sequential number, and the latter is the date on which the manifest was created. However, the product does not compare the up-to-dateness of the most recently fetched manifest against the cached manifest. As such, it's prone to a rollback to a previous version if it's served a valid outdated manifest. This leads to outdated route origin validation.

    Published: 18 Dec 2024
    6.5
    Medium

    CVE-2024-52792

    Last Modified: 15 Apr 2026

    LDAP Account Manager (LAM) is a php webfrontend for managing entries (e.g. users, groups, DHCP settings) stored in an LDAP directory. In affected versions LAM does not properly sanitize configuration values, that are set via `mainmanage.php` and `confmain.php`. This allows setting arbitrary config values and thus effectively bypassing `mitigation` of CVE-2024-23333/GHSA-fm9w-7m7v-wxqv. Configuration values for the main config or server profiles are set via `mainmanage.php` and `confmain.php`. The values are written to `config.cfg` or `serverprofile.conf` in the format of `settingsName: settingsValue` line-by-line. An attacker can smuggle arbitrary config values in a config file, by inserting a newline into certain config fields, followed by the value. This vulnerability has been addressed in version 9.0. All users are advised to upgrade. There are no known workarounds for this vulnerability.

    Published: 17 Dec 2024
    4.8
    Medium

    CVE-2024-56142

    Last Modified: 15 Apr 2026

    pghoard is a PostgreSQL backup daemon and restore tooling that stores backup data in cloud object stores. A vulnerability has been discovered that could allow an attacker to acquire disk access with privileges equivalent to those of pghoard, allowing for unintended path traversal. Depending on the permissions/privileges assigned to pghoard, this could allow disclosure of sensitive information. This issue has been addressed in releases after 2.2.2a. Users are advised to upgrade. There are no known workarounds for this vulnerability.

    Published: 17 Dec 2024
    4.8
    Medium

    CVE-2023-37940

    Last Modified: 28 Jan 2025

    Cross-site scripting (XSS) vulnerability in the edit Service Access Policy page in Liferay Portal 7.0.0 through 7.4.3.87, and Liferay DXP 7.4 GA through update 87, 7.3 GA through update 29, and older unsupported versions allows remote attackers to inject arbitrary web script or HTML via a crafted payload injected into a service access policy's `Service Class` text field.

    Published: 17 Dec 2024
    6.9
    Medium

    CVE-2024-56139

    Last Modified: 15 Apr 2026

    pdftools is a high level tools to convert PDF files to ePUB formats. In versions up to and including 0.5.0 maliciously crafted epub files can cause a stack overflow leading to a crash. This issue has not yet been addressed and users are advised to avoid untrusted input to their systems.

    Published: 17 Dec 2024
    7.5
    High

    CVE-2024-51479

    Last Modified: 10 Sept 2025

    Next.js is a React framework for building full-stack web applications. In affected versions if a Next.js application is performing authorization in middleware based on pathname, it was possible for this authorization to be bypassed for pages directly under the application's root directory. For example: * [Not affected] `https://example.com/` * [Affected] `https://example.com/foo` * [Not affected] `https://example.com/foo/bar`. This issue is patched in Next.js `14.2.15` and later. If your Next.js application is hosted on Vercel, this vulnerability has been automatically mitigated, regardless of Next.js version. There are no official workarounds for this vulnerability.

    Published: 17 Dec 2024
    4.9
    Medium

    CVE-2024-49816

    Last Modified: 7 Jan 2025

    IBM Security Guardium Key Lifecycle Manager 4.1, 4.1.1, 4.2.0, and 4.2.1 stores potentially sensitive information in log files that could be read by a local privileged user.

    Published: 17 Dec 2024
    3.7
    Low

    CVE-2024-49820

    Last Modified: 10 Jan 2025

    IBM Security Guardium Key Lifecycle Manager 4.1, 4.1.1, 4.2.0, and 4.2.1 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques.

    Published: 17 Dec 2024
    4.1
    Medium

    CVE-2024-49819

    Last Modified: 10 Jan 2025

    IBM Security Guardium Key Lifecycle Manager 4.1, 4.1.1, 4.2.0, and 4.2.1 could allow a remote attacker to obtain sensitive information in cleartext in a communication channel that can be sniffed by unauthorized actors.

    Published: 17 Dec 2024
    4.3
    Medium

    CVE-2024-49818

    Last Modified: 7 Jan 2025

    IBM Security Guardium Key Lifecycle Manager 4.1, 4.1.1, 4.2.0, and 4.2.1 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system.

    Published: 17 Dec 2024
    4.4
    Medium

    CVE-2024-49817

    Last Modified: 7 Jan 2025

    IBM Security Guardium Key Lifecycle Manager 4.1, 4.1.1, 4.2.0, and 4.2.1 stores user credentials in configuration files which can be read by a local privileged user.

    Published: 17 Dec 2024
    3.1
    Low

    CVE-2024-42194

    Last Modified: 15 Apr 2026

    An improper handling of insufficient permissions or privileges affects HCL BigFix Inventory. An attacker having access via a read-only account can possibly change certain configuration parameters by crafting a specific REST API call.

    Published: 17 Dec 2024
    6
    Medium

    CVE-2024-12539

    Last Modified: 4 Feb 2025

    An issue was discovered where improper authorization controls affected certain queries that could allow a malicious actor to circumvent Document Level Security in Elasticsearch and get access to documents that their roles would normally not allow.

    Published: 17 Dec 2024
    4.6
    Medium

    CVE-2024-11993

    Last Modified: 28 Mar 2025

    Reflected cross-site scripting (XSS) vulnerability in Liferay Portal 7.4.0 through 7.4.3.38, and Liferay DXP 7.4 GA through update 38 allows remote attackers to execute arbitrary web script or HTML via Dispatch name field

    Published: 17 Dec 2024