CVE Feed

    Dashboard / CVE

    7.8
    High

    CVE-2024-12670

    Last Modified: 13 Nov 2025

    A maliciously crafted DWFX file, when parsed through Autodesk Navisworks, can be used to cause a Heap-based Overflow vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.

    Published: 17 Dec 2024
    7.8
    High

    CVE-2024-12199

    Last Modified: 2 Oct 2025

    A maliciously crafted DWFX file, when parsed through Autodesk Navisworks, may force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process.

    Published: 17 Dec 2024
    8
    High

    CVE-2024-10476

    Last Modified: 15 Apr 2026

    Default credentials are used in the above listed BD Diagnostic Solutions products. If exploited, threat actors may be able to access, modify or delete data, including sensitive information such as protected health information (PHI) and personally identifiable information (PII). Exploitation of this vulnerability may allow an attacker to shut down or otherwise impact the availability of the system. Note: BD Synapsys™ Informatics Solution is only in scope of this vulnerability when installed on a NUC server. BD Synapsys™ Informatics Solution installed on a customer-provided virtual machine or on the BD Kiestra™ SCU hardware is not in scope.

    Published: 17 Dec 2024
    7.8
    High

    CVE-2024-12178

    Last Modified: 22 Jan 2026

    A maliciously crafted DWFX file, when parsed through Autodesk Navisworks, can force a Memory Corruption vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process.

    Published: 17 Dec 2024
    7.8
    High

    CVE-2024-11422

    Last Modified: 31 Dec 2025

    A maliciously crafted DWFX file, when parsed through Autodesk Navisworks, can force an Out-of-Bounds Write vulnerability. A malicious actor can leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process.

    Published: 17 Dec 2024
    9.8
    Critical

    CVE-2024-8972

    Last Modified: 2 Jun 2026

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Mobil365 Informatics Saha365 App allows SQL Injection. This issue affects Saha365 App: before 30.09.2024.

    Published: 17 Dec 2024
    6.5
    Medium

    CVE-2024-9819

    Last Modified: 2 Jun 2026

    Authorization Bypass Through User-Controlled Key vulnerability in NextGeography NG Analyser allows Functionality Misuse. This issue affects NG Analyser: before 2.2.711.

    Published: 17 Dec 2024
    4.3
    Medium

    CVE-2024-10356

    Last Modified: 8 Apr 2026

    The ElementsReady Addons for Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 6.4.8 in inc/Widgets/accordion/output/content.php. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract sensitive private, pending, and draft template data.

    Published: 17 Dec 2024
    5.3
    Medium

    CVE-2024-54677

    Last Modified: 3 Nov 2025

    Uncontrolled Resource Consumption vulnerability in the examples web application provided with Apache Tomcat leads to denial of service. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.1, from 10.1.0-M1 through 10.1.33, from 9.0.0.M1 through 9.9.97. The following versions were EOL at the time the CVE was created but are known to be affected: 8.5.0 though 8.5.100. Other, older, EOL versions may also be affected. Users are recommended to upgrade to version 11.0.2, 10.1.34 or 9.0.98, which fixes the issue.

    Published: 17 Dec 2024
    9.8
    Critical

    CVE-2024-50379

    Last Modified: 3 Nov 2025

    Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability during JSP compilation in Apache Tomcat permits an RCE on case insensitive file systems when the default servlet is enabled for write (non-default configuration). This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.1, from 10.1.0-M1 through 10.1.33, from 9.0.0.M1 through 9.0.97. The following versions were EOL at the time the CVE was created but are known to be affected: 8.5.0 though 8.5.100. Other, older, EOL versions may also be affected. Users are recommended to upgrade to version 11.0.2, 10.1.34 or 9.0.98, which fixes the issue.

    Published: 17 Dec 2024
    5.7
    Medium

    CVE-2024-53240

    Last Modified: 3 Nov 2025

    In the Linux kernel, the following vulnerability has been resolved: xen/netfront: fix crash when removing device When removing a netfront device directly after a suspend/resume cycle it might happen that the queues have not been setup again, causing a crash during the attempt to stop the queues another time. Fix that by checking the queues are existing before trying to stop them. This is XSA-465 / CVE-2024-53240.

    Published: 17 Dec 2024
    5.5
    Medium

    CVE-2024-53241

    Last Modified: 5 Jan 2026

    In the Linux kernel, the following vulnerability has been resolved: x86/xen: don't do PV iret hypercall through hypercall page Instead of jumping to the Xen hypercall page for doing the iret hypercall, directly code the required sequence in xen-asm.S. This is done in preparation of no longer using hypercall page at all, as it has shown to cause problems with speculation mitigations. This is part of XSA-466 / CVE-2024-53241.

    Published: 17 Dec 2024
    6.5
    Medium

    CVE-2024-8475

    Last Modified: 2 Jun 2026

    Authentication Bypass by Assumed-Immutable Data vulnerability in Digital Operation Services WiFiBurada allows Manipulating User-Controlled Variables. This issue affects WiFiBurada: before 1.0.5.

    Published: 17 Dec 2024
    4.3
    Medium

    CVE-2024-8429

    Last Modified: 2 Jun 2026

    Improper Restriction of Excessive Authentication Attempts vulnerability in Digital Operation Services WiFiBurada allows Use of Known Domain Credentials. This issue affects WiFiBurada: before 1.0.5.

    Published: 17 Dec 2024
    4.4
    Medium

    CVE-2024-52542

    Last Modified: 4 Feb 2025

    Dell AppSync, version 4.6.0.x, contain a Symbolic Link (Symlink) Following vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to information tampering.

    Published: 17 Dec 2024
    7.8
    High

    CVE-2024-12671

    Last Modified: 26 Aug 2025

    A maliciously crafted DWFX file, when parsed through Autodesk Navisworks, may force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process.

    Published: 17 Dec 2024
    7.8
    High

    CVE-2024-12669

    Last Modified: 26 Aug 2025

    A maliciously crafted DWFX file, when parsed through Autodesk Navisworks, can be used to cause a Heap-based Overflow vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.

    Published: 17 Dec 2024
    7.8
    High

    CVE-2024-12200

    Last Modified: 26 Aug 2025

    A maliciously crafted DWFX file, when parsed through Autodesk Navisworks, may force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process.

    Published: 17 Dec 2024
    5.3
    Medium

    CVE-2024-11280

    Last Modified: 15 Apr 2026

    The PPWP – Password Protect Pages plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.9.5 via the WordPress core search feature. This makes it possible for unauthenticated attackers to extract sensitive data from posts that have been restricted to higher-level roles such as administrator.

    Published: 17 Dec 2024
    7.8
    High

    CVE-2024-12198

    Last Modified: 26 Aug 2025

    A maliciously crafted DWFX file, when parsed through Autodesk Navisworks, may force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process.

    Published: 17 Dec 2024
    7.8
    High

    CVE-2024-12197

    Last Modified: 26 Aug 2025

    A maliciously crafted DWFX file, when parsed through Autodesk Navisworks, may force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process.

    Published: 17 Dec 2024
    7.8
    High

    CVE-2024-12194

    Last Modified: 26 Aug 2025

    A maliciously crafted DWFX file, when parsed through Autodesk Navisworks, can force a Memory Corruption vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process.

    Published: 17 Dec 2024
    7.8
    High

    CVE-2024-12179

    Last Modified: 26 Aug 2025

    A maliciously crafted DWFX file, when parsed through Autodesk Navisworks, can be used to cause a Heap-based Overflow vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.

    Published: 17 Dec 2024
    7.8
    High

    CVE-2024-12193

    Last Modified: 26 Aug 2025

    A maliciously crafted DWFX file, when parsed through Autodesk Navisworks, may force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process.

    Published: 17 Dec 2024
    7.8
    High

    CVE-2024-12192

    Last Modified: 26 Aug 2025

    A maliciously crafted DWF file, when parsed through Autodesk Navisworks, may force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process.

    Published: 17 Dec 2024
    7.8
    High

    CVE-2024-12191

    Last Modified: 26 Aug 2025

    A maliciously crafted DWFX file, when parsed through Autodesk Navisworks, may force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process.

    Published: 17 Dec 2024
    3.7
    Low

    CVE-2024-9654

    Last Modified: 7 Feb 2025

    The Easy Digital Downloads plugin for WordPress is vulnerable to Improper Authorization in versions 3.1 through 3.3.4. This is due to a lack of sufficient validation checks within the 'verify_guest_email' function to ensure the requesting user is the intended recipient of the purchase receipt. This makes it possible for unauthenticated attackers to bypass intended security restrictions and view the receipts of other users, which contains a link to download paid content. Successful exploitation requires knowledge of another customers email address as well as the file ID of the content they purchased.

    Published: 17 Dec 2024
    6.1
    Medium

    CVE-2024-12395

    Last Modified: 15 Apr 2026

    The WooCommerce Additional Fees On Checkout (Free) plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘number’ parameter in all versions up to, and including, 1.4.7 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

    Published: 17 Dec 2024
    5.3
    Medium

    CVE-2024-12601

    Last Modified: 8 Apr 2026

    The Calculated Fields Form plugin for WordPress is vulnerable to Denial of Service in all versions up to, and including, 5.2.63. This is due to unlimited height and width parameters for CAPTCHA images. This makes it possible for unauthenticated attackers to send multiple requests with large values, resulting in slowing server resources if the server does not mitigate Denial of Service attacks.

    Published: 17 Dec 2024
    6.1
    Medium

    CVE-2024-12469

    Last Modified: 15 Apr 2026

    The WP BASE Booking of Appointments, Services and Events plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘status’ parameter in all versions up to, and including, 4.9.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

    Published: 17 Dec 2024
    6.1
    Medium

    CVE-2024-12127

    Last Modified: 15 Apr 2026

    The Learning Management System, eLearning, Course Builder, WordPress LMS Plugin – Sikshya LMS plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘page’ parameter in all versions up to, and including, 0.0.21 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

    Published: 17 Dec 2024
    7.2
    High

    CVE-2024-12024

    Last Modified: 8 Apr 2026

    The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the em_ticket_category_data and em_ticket_individual_data parameters in all versions up to, and including, 4.0.7.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever an administrative user accesses an injected page. Note: this vulnerability requires the "Guest Submissions" setting to be enabled. It is disabled by default.

    Published: 17 Dec 2024
    8.8
    High

    CVE-2024-8326

    Last Modified: 15 Apr 2026

    The s2Member – Excellent for All Kinds of Memberships, Content Restriction Paywalls & Member Access Subscriptions plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 241114 via the 'sc_get_details' function. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract sensitive data including user data and database configuration information, which can lead to reading, updating, or dropping database tables. The vulnerability was partially patched in version 241114.

    Published: 17 Dec 2024
    8.8
    High

    CVE-2024-12293

    Last Modified: 15 Apr 2026

    The User Role Editor plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.64.3. This is due to missing or incorrect nonce validation on the update_roles() function. This makes it possible for unauthenticated attackers to add or remove roles for arbitrary users, including escalating their privileges to administrator, via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

    Published: 17 Dec 2024
    5.3
    Medium

    CVE-2024-11294

    Last Modified: 15 Apr 2026

    The Memberful plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.73.9 via the WordPress core search feature. This makes it possible for unauthenticated attackers to extract sensitive data from posts that have been restricted to higher-level roles such as site members.

    Published: 17 Dec 2024
    6.1
    Medium

    CVE-2024-12220

    Last Modified: 15 Apr 2026

    The SMS for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.8.1. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to inject malicious web scripts via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

    Published: 17 Dec 2024
    6.1
    Medium

    CVE-2024-12219

    Last Modified: 15 Apr 2026

    The Stop Registration Spam plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.23. This is due to missing or incorrect nonce validation. This makes it possible for unauthenticated attackers to inject malicious web scripts via a forged request granted they can trick a site administrator into performing an action such as clicking on a link. CVE-2024-56017 is likely a duplicate of this issue.

    Published: 17 Dec 2024
    5.5
    Medium

    CVE-2021-26281

    Last Modified: 15 Apr 2026

    Some parameters of the alarm clock module are improperly stored, leaking some sensitive information.

    Published: 17 Dec 2024
    7.9
    High

    CVE-2021-26280

    Last Modified: 15 Apr 2026

    Locally installed application can bypass the permission check and perform system operations that require permission.

    Published: 17 Dec 2024
    8.7
    High

    CVE-2024-11999

    Last Modified: 15 Apr 2026

    CWE-1104: Use of Unmaintained Third-Party Components vulnerability exists that could cause complete control of the device when an authenticated user installs malicious code into HMI product.

    Published: 17 Dec 2024
    7.3
    High

    CVE-2024-38499

    Last Modified: 15 Apr 2026

    CA Client Automation (ITCM) allows non-admin/non-root users to encrypt a string using CAF CLI and SD_ACMD CLI. This would allow the non admin user to access the critical encryption keys which further causes the exploitation of stored credentials. This fix doesn't allow a non-admin/non-root user to execute "caf encrypt"/"sd_acmd encrypt" commands.

    Published: 17 Dec 2024
    3.3
    Low

    CVE-2024-54125

    Last Modified: 15 Apr 2026

    Improper authorization in handler for custom URL scheme issue in "Shonen Jump+" App for Android versions prior to 4.0.0 allows an attacker to lead a user to access an arbitrary website via the vulnerable App. As a result, the user may become a victim of a phishing attack.

    Published: 17 Dec 2024
    7.6
    High

    CVE-2024-9624

    Last Modified: 15 Apr 2026

    The WP All Import Pro plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 4.9.3 due to missing SSRF protection on the pmxi_curl_download function. This makes it possible for authenticated attackers, with Administrator-level access and above, to make web requests to arbitrary locations originating from the web application and can be used to query and modify information from internal services. On cloud platforms, it might allow attackers to read the Instance metadata.

    Published: 17 Dec 2024
    4.8
    Medium

    CVE-2024-55864

    Last Modified: 15 Apr 2026

    Cross-site scripting vulnerability exists in My WP Customize Admin/Frontend versions prior to ver 1.24.1. If a malicious administrative user customizes the administrative page with some malicious contents, an arbitrary script may be executed on the web browser of the other users who are accessing the page.

    Published: 17 Dec 2024
    9.8
    Critical

    CVE-2024-12356

    Last Modified: 24 Oct 2025

    A critical vulnerability has been discovered in Privileged Remote Access (PRA) and Remote Support (RS) products which can allow an unauthenticated attacker to inject commands that are run as a site user.

    Published: 17 Dec 2024
    5.9
    Medium

    CVE-2021-26279

    Last Modified: 15 Apr 2026

    Some parameters of the weather module are improperly stored, leaking some sensitive information.

    Published: 17 Dec 2024
    6.3
    Medium

    CVE-2021-26278

    Last Modified: 15 Apr 2026

    The wifi module exposes the interface and has improper permission control, leaking sensitive information about the device.

    Published: 17 Dec 2024
    7
    High

    CVE-2020-12487

    Last Modified: 15 Apr 2026

    Due to the flaws in the verification of input parameters, the attacker can input carefully constructed commands to make the ABE service execute some commands with root privilege.

    Published: 17 Dec 2024
    6.4
    Medium

    CVE-2020-12484

    Last Modified: 15 Apr 2026

    When using special mode to connect to enterprise wifi, certain options are not properly configured and attackers can pretend to be enterprise wifi through a carefully constructed wifi with the same name, which can lead to man-in-the-middle attacks.

    Published: 17 Dec 2024
    6.1
    Medium

    CVE-2024-12239

    Last Modified: 8 Apr 2026

    The PowerPack Lite for Beaver Builder plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the navigate parameter in all versions up to, and including, 1.3.0.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick an administrative user into performing an action such as clicking on a link.

    Published: 17 Dec 2024