CVE Feed

    Dashboard / CVE

    9.4
    Critical

    CVE-2024-10205

    Last Modified: 15 Apr 2026

    Authentication Bypass vulnerability in Hitachi Ops Center Analyzer on Linux, 64 bit (Hitachi Ops Center Analyzer detail view component), Hitachi Infrastructure Analytics Advisor on Linux, 64 bit (Hitachi Data Center Analytics component ).This issue affects Hitachi Ops Center Analyzer: from 10.0.0-00 before 11.0.3-00; Hitachi Infrastructure Analytics Advisor: from 2.1.0-00 through 4.4.0-00.

    Published: 17 Dec 2024
    7.4
    High

    CVE-2024-11614

    Last Modified: 15 Apr 2026

    An out-of-bounds read vulnerability was found in DPDK's Vhost library checksum offload feature. This issue enables an untrusted or compromised guest to crash the hypervisor's vSwitch by forging Virtio descriptors to cause out-of-bounds reads. This flaw allows an attacker with a malicious VM using a virtio driver to cause the vhost-user side to crash by sending a packet with a Tx checksum offload request and an invalid csum_start offset.

    Published: 17 Dec 2024
    9.1
    Critical

    CVE-2024-55516

    Last Modified: 28 Apr 2025

    A vulnerability was found in Raisecom MSG1200, MSG2100E, MSG2200, and MSG2300 v3.90. The component affected by this issue is /upload_sysconfig.php on the web interface. By crafting a suitable form name, arbitrary files can be uploaded, potentially leading to unauthorized access to server permissions.

    Published: 17 Dec 2024
    9.8
    Critical

    CVE-2024-55515

    Last Modified: 28 Apr 2025

    A vulnerability was found in Raisecom MSG1200, MSG2100E, MSG2200, and MSG2300 3.90. The component affected by this issue is /upload_ipslib.php on the web interface. By crafting a suitable form name, arbitrary files can be uploaded.

    Published: 17 Dec 2024
    6.3
    Medium

    CVE-2024-55514

    Last Modified: 28 Apr 2025

    A vulnerability was found in Raisecom MSG1200, MSG2100E, MSG2200, and MSG2300 3.90. The component affected by this issue is /upload_sfmig.php on the web interface. By crafting a suitable form name, arbitrary files can be uploaded, potentially leading to unauthorized access to server permissions.

    Published: 17 Dec 2024
    6.5
    Medium

    CVE-2024-37606

    Last Modified: 21 May 2025

    A Stack overflow vulnerability in D-Link DCS-932L REVB_FIRMWARE_2.18.01 allows attackers to cause a Denial of Service (DoS) via a crafted HTTP request.

    Published: 17 Dec 2024
    5.4
    Medium

    CVE-2024-55056

    Last Modified: 27 Mar 2025

    A stored cross-site scripting (XSS) vulnerability was identified in Phpgurukul Online Birth Certificate System 1.0 in /user/certificate-form.php via the full name field.

    Published: 17 Dec 2024
    5.4
    Medium

    CVE-2024-55057

    Last Modified: 27 Mar 2025

    Phpgurukul Online Birth Certificate System 1.0 suffers from insufficient password requirements which can lead to unauthorized access to user accounts.

    Published: 17 Dec 2024
    4.3
    Medium

    CVE-2024-55058

    Last Modified: 27 Mar 2025

    An insecure direct object reference (IDOR) vulnerability was discovered in PHPGurukul Online Birth Certificate System v1.0. This vulnerability resides in the viewid parameter of /user/view-application-detail.php. Authenticated users can exploit this flaw by manipulating the viewid parameter in the URL to access sensitive birth certificate details of other users without proper authorization checks.

    Published: 17 Dec 2024
    7.3
    High

    CVE-2024-49194

    Last Modified: 15 Apr 2026

    Databricks JDBC Driver 2.x before 2.6.40 could potentially allow remote code execution (RCE) by triggering a JNDI injection via a JDBC URL parameter. The vulnerability is rooted in the improper handling of the krbJAASFile parameter. An attacker could potentially exploit this vulnerability to achieve Remote Code Execution in the context of the driver by tricking a victim into using a crafted connection URL that uses the property krbJAASFile.

    Published: 17 Dec 2024
    7.5
    High

    CVE-2024-36832

    Last Modified: 21 May 2025

    A NULL pointer dereference in D-Link DAP-1513 REVA_FIRMWARE_1.01 allows attackers to cause a Denial of Service (DoS) via a crafted web request without authentication. The vulnerability occurs in the /bin/webs binary of the firmware. When /bin/webs receives a carefully constructed HTTP request, it will crash and exit due to a null pointer reference, leading to a denial of service attack to the device.

    Published: 17 Dec 2024
    9.8
    Critical

    CVE-2024-29646

    Last Modified: 17 Jun 2025

    Buffer Overflow vulnerability in radarorg radare2 v.5.8.8 allows an attacker to execute arbitrary code via the name, type, or group fields.

    Published: 17 Dec 2024
    9.1
    Critical

    CVE-2024-31668

    Last Modified: 3 Jul 2025

    rizin before v0.6.3 is vulnerable to Improper Neutralization of Special Elements via meta_set function in librz/analysis/meta.

    Published: 17 Dec 2024
    5.3
    Medium

    CVE-2024-36831

    Last Modified: 21 May 2025

    A NULL pointer dereference in the plugins_call_handle_uri_clean function of D-Link DAP-1520 REVA_FIRMWARE_1.10B04_BETA02_HOTFIX allows attackers to cause a Denial of Service (DoS) via a crafted HTTP request without authentication.

    Published: 17 Dec 2024
    6.5
    Medium

    CVE-2024-37605

    Last Modified: 21 May 2025

    A NULL pointer dereference in D-Link DIR-860L REVB_FIRMWARE_2.04.B04_ic5b allows attackers to cause a Denial of Service (DoS) via a crafted HTTP request.

    Published: 17 Dec 2024
    6.5
    Medium

    CVE-2024-37607

    Last Modified: 21 May 2025

    A Buffer overflow vulnerability in D-Link DAP-2555 REVA_FIRMWARE_1.20 allows remote attackers to cause a Denial of Service (DoS) via a crafted HTTP request.

    Published: 17 Dec 2024
    7.5
    High

    CVE-2024-51175

    Last Modified: 15 Apr 2026

    An issue in H3C switch h3c-S1526 allows a remote attacker to obtain sensitive information via the S1526.cfg component.

    Published: 17 Dec 2024
    8.8
    High

    CVE-2024-53144

    Last Modified: 4 Aug 2026

    In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_event: Align BR/EDR JUST_WORKS paring with LE This aligned BR/EDR JUST_WORKS method with LE which since 92516cd97fd4 ("Bluetooth: Always request for user confirmation for Just Works") always request user confirmation with confirm_hint set since the likes of bluetoothd have dedicated policy around JUST_WORKS method (e.g. main.conf:JustWorksRepairing). CVE: CVE-2024-8805

    Published: 17 Dec 2024
    9.1
    Critical

    CVE-2024-54662

    Last Modified: 15 Apr 2026

    Dante 1.4.0 through 1.4.3 (fixed in 1.4.4) has incorrect access control for some sockd.conf configurations involving socksmethod.

    Published: 17 Dec 2024
    6.1
    Medium

    CVE-2024-55059

    Last Modified: 27 Mar 2025

    A stored HTML Injection vulnerability was identified in PHPGurukul Online Birth Certificate System v1.0 in /user/certificate-form.php.

    Published: 17 Dec 2024
    9.1
    Critical

    CVE-2024-55496

    Last Modified: 2 May 2025

    A vulnerability has been found in the 1000projects Bookstore Management System PHP MySQL Project 1.0. This issue affects some unknown functionality of add_company.php. Actions on the delete parameter result in SQL injection.

    Published: 17 Dec 2024
    9.1
    Critical

    CVE-2024-55513

    Last Modified: 28 Apr 2025

    A vulnerability was found in Raisecom MSG1200, MSG2100E, MSG2200, and MSG2300 3.90. The component affected by this issue is /upload_netaction.php on the web interface. By crafting a suitable form name, arbitrary files can be uploaded, potentially leading to unauthorized access to server permissions.

    Published: 17 Dec 2024
    6.4
    Medium

    CVE-2024-11906

    Last Modified: 15 Apr 2026

    The TPG Get Posts plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'tpg_get_posts' shortcode in all versions up to, and including, 3.6.5 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 16 Dec 2024
    6.4
    Medium

    CVE-2024-11905

    Last Modified: 15 Apr 2026

    The Animated Counters plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'animatedcounte' shortcode in all versions up to, and including, 2.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 16 Dec 2024
    6.4
    Medium

    CVE-2024-11902

    Last Modified: 15 Apr 2026

    The Slope Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'slope-reservations' shortcode in all versions up to, and including, 4.2.12 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 16 Dec 2024
    6.4
    Medium

    CVE-2024-11900

    Last Modified: 15 Apr 2026

    The Portfolio – Filterable Masonry Portfolio Gallery for Professionals plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'portfolio-pro' shortcode in all versions up to, and including, 1.2.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 16 Dec 2024
    6.4
    Medium

    CVE-2024-12443

    Last Modified: 15 Apr 2026

    The CRM Perks – WordPress HelpDesk Integration – Zendesk, Freshdesk, HelpScout plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'crm-perks-tickets' shortcode in all versions up to, and including, 1.1.6 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 16 Dec 2024
    7.1
    High

    CVE-2024-56017

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Tom Royal Stop Registration Spam allows Stored XSS.This issue affects Stop Registration Spam: from n/a through 1.23.

    Published: 16 Dec 2024
    5.3
    Medium

    CVE-2024-35230

    Last Modified: 26 Aug 2025

    GeoServer is an open source software server written in Java that allows users to share and edit geospatial data. In affected versions the welcome and about page includes version and revision information about the software in use (including library and components used). This information is sensitive from a security point of view because it allows software used by the server to be easily identified. This issue has been patched in version 2.26.0 and all users are advised to upgrade. There are no known workarounds for this vulnerability.

    Published: 16 Dec 2024
    6.5
    Medium

    CVE-2024-12698

    Last Modified: 15 Apr 2026

    An incomplete fix for ose-olm-catalogd-container was issued for the Rapid Reset Vulnerability (CVE-2023-39325/CVE-2023-44487) where only unauthenticated streams were protected, not streams created by authenticated sources.

    Published: 16 Dec 2024
    4.8
    Medium

    CVE-2024-55951

    Last Modified: 15 Apr 2026

    Metabase is an open-source data analytics platform. For new sandboxing configurations created in 1.52.0 till 1.52.2.4, sandboxed users are able to see field filter values from other sandboxed users. This is fixed in 1.52.2.5. Users on 1.52.0 or 1.52.1 or 1.5.2 should upgrade to 1.52.2.5. There are no workarounds for this issue aside from upgrading.

    Published: 16 Dec 2024
    9.3
    Critical

    CVE-2024-55949

    Last Modified: 15 Apr 2026

    MinIO is a high-performance, S3 compatible object store, open sourced under GNU AGPLv3 license. Minio is subject to a privilege escalation in IAM import API, all users are impacted since MinIO commit `580d9db85e04f1b63cc2909af50f0ed08afa965f`. This issue has been addressed in commit `f246c9053f9603e610d98439799bdd2a6b293427` which is included in RELEASE.2024-12-13T22-19-12Z. There are no workarounds possible, all users are advised to upgrade immediately.

    Published: 16 Dec 2024
    8.6
    High

    CVE-2024-12687

    Last Modified: 10 Oct 2025

    Deserialization of Untrusted Data vulnerability in PlexTrac (Runbooks modules) which allows Object Injection and arbitrary file writes. This issue affects PlexTrac: from 1.61.3 before 2.8.1.

    Published: 16 Dec 2024
    6.3
    Medium

    CVE-2024-12663

    Last Modified: 15 Apr 2026

    A vulnerability classified as problematic was found in funnyzpc Mee-Admin up to 1.6. This vulnerability affects unknown code of the file /mee/login of the component Login. The manipulation of the argument username leads to observable response discrepancy. The attack can be initiated remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used.

    Published: 16 Dec 2024
    7.6
    High

    CVE-2024-8058

    Last Modified: 15 Apr 2026

    An improper parsing vulnerability was reported in the FileZ client that could allow a crafted file in the FileZ directory to read arbitrary files on the device due to URL preloading.

    Published: 16 Dec 2024
    8.1
    High

    CVE-2024-6001

    Last Modified: 15 Apr 2026

    An improper certificate validation vulnerability was reported in LADM that could allow a network attacker with the ability to redirect an update request to a remote server and execute code with elevated privileges.

    Published: 16 Dec 2024
    7.8
    High

    CVE-2024-4762

    Last Modified: 15 Apr 2026

    An improper validation vulnerability was reported in the firmware update mechanism of LADM and LDCC that could allow a local attacker to escalate privileges.

    Published: 16 Dec 2024
    9.2
    Critical

    CVE-2024-11144

    Last Modified: 15 Apr 2026

    The server lacks thread safety and can be crashed by anomalous data sent by an anonymous user from a remote network. The crash causes the FTP service to become unavailable, affecting all users and processes that rely on it for file transfers. If the crash occurs during file upload or download, it could lead to incomplete file transfers, potentially corrupting data. The repeated crash might also affect the stability of the underlying system, especially if it leads to resource leaks or affects other services.

    Published: 16 Dec 2024
    5.7
    Medium

    CVE-2024-11358

    Last Modified: 24 Sept 2025

    Mattermost Android Mobile Apps versions <=2.21.0 fail to properly configure file providers which allows an attacker with local access to access files via file provider.

    Published: 16 Dec 2024
    6.3
    Medium

    CVE-2024-12667

    Last Modified: 19 Dec 2024

    A vulnerability was found in InvoicePlane up to 1.6.1 and classified as problematic. Affected by this issue is some unknown functionality of the file /invoices/view. The manipulation leads to session expiration. The attack may be launched remotely. The complexity of an attack is rather high. The exploitation is known to be difficult. The exploit has been disclosed to the public and may be used. Upgrading to version 1.6.2-beta-1 is able to address this issue. It is recommended to upgrade the affected component. The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product.

    Published: 16 Dec 2024
    5.1
    Medium

    CVE-2024-12666

    Last Modified: 19 Dec 2024

    A vulnerability has been found in ClassCMS up to 4.8 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /admin?do=admin:user:editPost of the component User Management Page. The manipulation leads to improper handling of insufficient privileges. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

    Published: 16 Dec 2024
    4.3
    Medium

    CVE-2024-54357

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in ThemeFusion Avada avada.This issue affects Avada: from n/a through <= 7.11.10.

    Published: 16 Dec 2024
    7.5
    High

    CVE-2024-54376

    Last Modified: 23 Apr 2026

    Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Spider Themes EazyDocs eazydocs allows PHP Local File Inclusion.This issue affects EazyDocs: from n/a through <= 2.8.0.

    Published: 16 Dec 2024
    4.3
    Medium

    CVE-2024-56003

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in David Cramer Caldera SMTP Mailer caldera-smtp-mailer.This issue affects Caldera SMTP Mailer: from n/a through <= 1.0.1.

    Published: 16 Dec 2024
    5.3
    Medium

    CVE-2024-55999

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in Marco Giannini XML Multilanguage Sitemap Generator xml-multilanguage-sitemap-generator.This issue affects XML Multilanguage Sitemap Generator: from n/a through <= 2.0.6.

    Published: 16 Dec 2024
    6.5
    Medium

    CVE-2024-54348

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in yaycommerce Brand brand allows Stored XSS.This issue affects Brand: from n/a through <= 1.1.6.

    Published: 16 Dec 2024
    9.1
    Critical

    CVE-2024-54285

    Last Modified: 28 Apr 2026

    Unrestricted Upload of File with Dangerous Type vulnerability in SeedProd LLC SeedProd Pro allows Upload a Web Shell to a Web Server.This issue affects SeedProd Pro: from n/a through 6.18.10.

    Published: 16 Dec 2024
    7.6
    High

    CVE-2024-54284

    Last Modified: 28 Apr 2026

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in SeedProd LLC SeedProd Pro allows SQL Injection.This issue affects SeedProd Pro: from n/a through 6.18.10.

    Published: 16 Dec 2024
    7.6
    High

    CVE-2024-54283

    Last Modified: 28 Apr 2026

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in SeedProd LLC SeedProd Pro allows SQL Injection.This issue affects SeedProd Pro: from n/a through 6.18.10.

    Published: 16 Dec 2024
    9.3
    Critical

    CVE-2024-54280

    Last Modified: 23 Apr 2026

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Iqonic Design WPBookit wpbookit allows SQL Injection.This issue affects WPBookit: from n/a through <= 1.6.0.

    Published: 16 Dec 2024