CVE Feed

    Dashboard / CVE

    8.5
    High

    CVE-2024-55986

    Last Modified: 23 Apr 2026

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in tiny13 Service service allows Blind SQL Injection.This issue affects Service: from n/a through <= 1.0.4.

    Published: 16 Dec 2024
    8.5
    High

    CVE-2024-55987

    Last Modified: 23 Apr 2026

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Ritesh Sanap Advanced What should we write next about advanced-what-should-we-write-about-next allows SQL Injection.This issue affects Advanced What should we write next about: from n/a through <= 1.0.3.

    Published: 16 Dec 2024
    9.3
    Critical

    CVE-2024-55988

    Last Modified: 23 Apr 2026

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Amol Nirmala Waman Navayan CSV Export navayan-csv-export allows Blind SQL Injection.This issue affects Navayan CSV Export: from n/a through <= 1.0.9.

    Published: 16 Dec 2024
    6.1
    Medium

    CVE-2024-55996

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in dreamfox Dreamfox Media Payment gateway per Product for Woocommerce woocommerce-product-payments allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Dreamfox Media Payment gateway per Product for Woocommerce: from n/a through <= 3.5.6.

    Published: 16 Dec 2024
    8.8
    High

    CVE-2024-56013

    Last Modified: 23 Apr 2026

    Authentication Bypass Using an Alternate Path or Channel vulnerability in wovax Wovax IDX wovax-idx allows Authentication Bypass.This issue affects Wovax IDX: from n/a through <= 1.2.2.

    Published: 16 Dec 2024
    6.8
    Medium

    CVE-2024-12662

    Last Modified: 19 Dec 2024

    A vulnerability classified as problematic has been found in IObit Advanced SystemCare Utimate up to 17.0.0. This affects the function 0x8001E040 in the library AscRegistryFilter.sys of the component IOCTL Handler. The manipulation leads to null pointer dereference. An attack has to be approached locally. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 16 Dec 2024
    6.8
    Medium

    CVE-2024-12661

    Last Modified: 2 Jul 2025

    A vulnerability was found in IObit Advanced SystemCare Utimate up to 17.0.0. It has been rated as problematic. Affected by this issue is the function 0x8001E024 in the library AscRegistryFilter.sys of the component IOCTL Handler. The manipulation leads to null pointer dereference. The attack needs to be approached locally. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 16 Dec 2024
    4.3
    Medium

    CVE-2024-54384

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in Anh Tran Falcon – WordPress Optimizations & Tweaks falcon allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Falcon – WordPress Optimizations & Tweaks: from n/a through <= 2.8.3.

    Published: 16 Dec 2024
    5.3
    Medium

    CVE-2024-54417

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in pixelgrade PixProof pixproof allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects PixProof: from n/a through <= 2.0.1.

    Published: 16 Dec 2024
    5.4
    Medium

    CVE-2024-55992

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in Open Tools WooCommerce Basic Ordernumbers woocommerce-basic-ordernumbers allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WooCommerce Basic Ordernumbers: from n/a through <= 1.4.4.

    Published: 16 Dec 2024
    5.3
    Medium

    CVE-2024-55993

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in PickPlugins Job Board Manager job-board-manager allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Job Board Manager: from n/a through <= 2.1.61.

    Published: 16 Dec 2024
    4.3
    Medium

    CVE-2024-55994

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in sohu 畅言评论系统 changyan allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects 畅言评论系统: from n/a through <= 2.0.5.

    Published: 16 Dec 2024
    6.5
    Medium

    CVE-2024-56001

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in ksher thailand Ksher ksher-payment allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Ksher: from n/a through <= 1.1.1.

    Published: 16 Dec 2024
    4.3
    Medium

    CVE-2024-56007

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in leader codes Leader leader allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Leader: from n/a through <= 2.6.1.

    Published: 16 Dec 2024
    5.3
    Medium

    CVE-2024-56009

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in spreadr Spreadr Woocommerce spreadr-for-woocomerce allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Spreadr Woocommerce: from n/a through <= 1.0.4.

    Published: 16 Dec 2024
    6.5
    Medium

    CVE-2024-54360

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in premila Gutensee gutensee allows DOM-Based XSS.This issue affects Gutensee: from n/a through <= 1.0.6.

    Published: 16 Dec 2024
    6.5
    Medium

    CVE-2024-54441

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Meini Utech World Time utech-world-time-for-wp allows Stored XSS.This issue affects Utech World Time: from n/a through <= 1.0.

    Published: 16 Dec 2024
    5.9
    Medium

    CVE-2024-54442

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in cortesfrau Better WP Login Page better-wp-login-page allows Stored XSS.This issue affects Better WP Login Page: from n/a through <= 1.1.2.

    Published: 16 Dec 2024
    6.5
    Medium

    CVE-2024-54443

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PluginsCafe Advanced Data Table For Elementor advanced-data-table-for-elementor allows Stored XSS.This issue affects Advanced Data Table For Elementor: from n/a through <= 1.0.0.

    Published: 16 Dec 2024
    6.5
    Medium

    CVE-2024-56011

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ilja Zaglov Responsive Google Maps | by imbaa responsive-google-maps allows Stored XSS.This issue affects Responsive Google Maps | by imbaa: from n/a through <= 1.2.5.

    Published: 16 Dec 2024
    7.1
    High

    CVE-2024-54331

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Micha I Plant A Tree i-plant-a-tree allows Stored XSS.This issue affects I Plant A Tree: from n/a through <= 1.7.3.

    Published: 16 Dec 2024
    8.8
    High

    CVE-2024-54352

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Sabri Sogrid sogrid allows Privilege Escalation.This issue affects Sogrid: from n/a through <= 1.5.2.

    Published: 16 Dec 2024
    4.3
    Medium

    CVE-2024-54355

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in brandtoss WP Mailster wp-mailster allows Cross Site Request Forgery.This issue affects WP Mailster: from n/a through <= 1.8.17.0.

    Published: 16 Dec 2024
    5.4
    Medium

    CVE-2024-54356

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in vcita Online Booking & Scheduling Calendar for WordPress by vcita meeting-scheduler-by-vcita allows Cross Site Request Forgery.This issue affects Online Booking & Scheduling Calendar for WordPress by vcita: from n/a through <= 4.5.

    Published: 16 Dec 2024
    9.6
    Critical

    CVE-2024-54372

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Sourov Amin Insertify insertify allows Code Injection.This issue affects Insertify: from n/a through <= 1.1.4.

    Published: 16 Dec 2024
    4.3
    Medium

    CVE-2024-54396

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in elmervillanueva Bet sport Free bet-sport-free allows Cross Site Request Forgery.This issue affects Bet sport Free: from n/a through <= 1.0.0.

    Published: 16 Dec 2024
    5.4
    Medium

    CVE-2024-54418

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Diversified Technology Corp. DTC Documents dtc-documents allows Cross Site Request Forgery.This issue affects DTC Documents: from n/a through <= 1.1.05.

    Published: 16 Dec 2024
    5.4
    Medium

    CVE-2024-54419

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in chenyenming Ui Slider Filter By Price ui-slider-filter-by-price allows Cross Site Request Forgery.This issue affects Ui Slider Filter By Price: from n/a through <= 1.1.

    Published: 16 Dec 2024
    6.5
    Medium

    CVE-2024-56005

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Posti Posti Shipping posti-shipping allows Cross Site Request Forgery.This issue affects Posti Shipping: from n/a through <= 3.10.3.

    Published: 16 Dec 2024
    7.1
    High

    CVE-2024-54332

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in WPFactory WP Currency Exchange Rates wp-currency-exchange-rates allows Stored XSS.This issue affects WP Currency Exchange Rates: from n/a through <= 1.2.0.

    Published: 16 Dec 2024
    7.1
    High

    CVE-2024-54353

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in wpgear Hack-Info hack-info allows Stored XSS.This issue affects Hack-Info: from n/a through <= 3.17.

    Published: 16 Dec 2024
    7.1
    High

    CVE-2024-54386

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in pushmonkey Push Monkey Pro – Web Push Notifications and WooCommerce Abandoned Cart push-monkey-desktop-push-notifications allows Cross Site Request Forgery.This issue affects Push Monkey Pro – Web Push Notifications and WooCommerce Abandoned Cart: from n/a through <= 3.9.

    Published: 16 Dec 2024
    7.1
    High

    CVE-2024-54388

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Phuc Pham Multiple Admin Emails multiple-admin-emails allows Cross Site Request Forgery.This issue affects Multiple Admin Emails: from n/a through <= 1.0.

    Published: 16 Dec 2024
    7.1
    High

    CVE-2024-54389

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Eduardo addWeather myweather allows Cross Site Request Forgery.This issue affects addWeather: from n/a through <= 2.5.1.

    Published: 16 Dec 2024
    7.1
    High

    CVE-2024-54391

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in mattwalters WordPress Filter wordpress-filter allows Stored XSS.This issue affects WordPress Filter: from n/a through <= 1.4.1.

    Published: 16 Dec 2024
    7.1
    High

    CVE-2024-54392

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in midoks WP微信机器人 wp-weixin-robot allows Stored XSS.This issue affects WP微信机器人: from n/a through <= 5.3.5.

    Published: 16 Dec 2024
    7.1
    High

    CVE-2024-54393

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Sheikh Heera WP Fiddle wp-fiddle allows Stored XSS.This issue affects WP Fiddle: from n/a through <= 1.0.

    Published: 16 Dec 2024
    7.1
    High

    CVE-2024-54394

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in khubbaib Mandrill WP email-form-under-post allows Stored XSS.This issue affects Mandrill WP: from n/a through <= 1.0.5.

    Published: 16 Dec 2024
    7.1
    High

    CVE-2024-54397

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in antonio.gocaj Go Animate goanimate allows Stored XSS.This issue affects Go Animate: from n/a through <= 1.0.

    Published: 16 Dec 2024
    7.1
    High

    CVE-2024-54398

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in jcaruso001 Flaming Forms flaming-forms allows Stored XSS.This issue affects Flaming Forms: from n/a through <= 1.0.1.

    Published: 16 Dec 2024
    7.1
    High

    CVE-2024-54399

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in CRUDLab CRUDLab Google Plus Button crudlab-google-plus allows Stored XSS.This issue affects CRUDLab Google Plus Button: from n/a through <= 1.0.2.

    Published: 16 Dec 2024
    7.1
    High

    CVE-2024-54400

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in meloniq AppMaps appmaps allows Stored XSS.This issue affects AppMaps: from n/a through <= 1.1.

    Published: 16 Dec 2024
    7.1
    High

    CVE-2024-54401

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Ciprian Turcu Advanced Fancybox advanced-fancybox allows Stored XSS.This issue affects Advanced Fancybox: from n/a through <= 1.1.1.

    Published: 16 Dec 2024
    4.3
    Medium

    CVE-2024-54402

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in Mohamed Abd Elhalim Arabic Webfonts arabic-webfonts allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Arabic Webfonts: from n/a through <= 1.4.6.

    Published: 16 Dec 2024
    7.1
    High

    CVE-2024-54404

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Nazmul Ahsan MDC Comment Toolbar mdc-comment-toolbar allows Stored XSS.This issue affects MDC Comment Toolbar: from n/a through <= 1.1.

    Published: 16 Dec 2024
    7.1
    High

    CVE-2024-54405

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in etemplates ECT Social Share ect-social-share allows Stored XSS.This issue affects ECT Social Share: from n/a through <= 1.3.

    Published: 16 Dec 2024
    7.1
    High

    CVE-2024-54407

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in a328496647 CK and SyntaxHighlighter ck-and-syntaxhighlighter allows Stored XSS.This issue affects CK and SyntaxHighlighter: from n/a through <= 3.4.2.

    Published: 16 Dec 2024
    6.5
    Medium

    CVE-2024-54408

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in codehandling Youtube Video Grid youmax-channel-embeds-for-youtube-businesses allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Youtube Video Grid: from n/a through <= 1.9.

    Published: 16 Dec 2024
    7.1
    High

    CVE-2024-54409

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in fzmaster XPD Reduce Image Filesize xpd-reduce-image-filesize allows Stored XSS.This issue affects XPD Reduce Image Filesize: from n/a through <= 1.0.

    Published: 16 Dec 2024
    7.1
    High

    CVE-2024-54410

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in eagerterrier SOPA Blackout sopa-blackout allows Stored XSS.This issue affects SOPA Blackout: from n/a through <= 1.4.

    Published: 16 Dec 2024