CVE Feed

    Dashboard / CVE

    7.1
    High

    CVE-2024-54415

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in cconoly WP-HideThat wp-hide-that allows Stored XSS.This issue affects WP-HideThat: from n/a through <= 1.2.

    Published: 16 Dec 2024
    7.1
    High

    CVE-2024-54416

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Navdeep Wp Login with Ajax wp-login-with-ajax allows Stored XSS.This issue affects Wp Login with Ajax: from n/a through <= 0.6.

    Published: 16 Dec 2024
    7.1
    High

    CVE-2024-54420

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Aleksandr Novikov Metrika metrika allows Cross Site Request Forgery.This issue affects Metrika: from n/a through <= 1.2.

    Published: 16 Dec 2024
    7.1
    High

    CVE-2024-54421

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Sanjay_Negi Floating Video Player floating-player allows Stored XSS.This issue affects Floating Video Player: from n/a through <= 1.0.

    Published: 16 Dec 2024
    7.1
    High

    CVE-2024-54423

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Jesse Overright Social Media Sharing social-media-sharing allows Stored XSS.This issue affects Social Media Sharing: from n/a through <= 1.1.

    Published: 16 Dec 2024
    7.1
    High

    CVE-2024-54424

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ilya_compman Like in Vk.com like-on-vkontakte allows Stored XSS.This issue affects Like in Vk.com: from n/a through <= 0.5.2.

    Published: 16 Dec 2024
    7.1
    High

    CVE-2024-54425

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in LionScripts.com LionScripts: Site Maintenance & Noindex Nofollow Plugin maintenance-and-noindex-nofollow allows Stored XSS.This issue affects LionScripts: Site Maintenance & Noindex Nofollow Plugin: from n/a through <= 2.1.

    Published: 16 Dec 2024
    7.1
    High

    CVE-2024-54426

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in crossfitatgg LeaderBoard Plugin leaderboard-lite allows Stored XSS.This issue affects LeaderBoard Plugin: from n/a through <= 1.2.4.

    Published: 16 Dec 2024
    7.1
    High

    CVE-2024-54427

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in ljmacphee Category of Posts list-one-category-of-posts allows Stored XSS.This issue affects Category of Posts: from n/a through <= 1.0.

    Published: 16 Dec 2024
    7.1
    High

    CVE-2024-54428

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in onigetoc Add image to Post add-image-to-post allows Stored XSS.This issue affects Add image to Post: from n/a through <= 0.6.

    Published: 16 Dec 2024
    7.1
    High

    CVE-2024-54429

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in ivan-ovsyannikov Aphorismus aphorismus allows Stored XSS.This issue affects Aphorismus: from n/a through <= 1.2.0.

    Published: 16 Dec 2024
    5.4
    Medium

    CVE-2024-54430

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Europe Ecologie Les Verts EELV Newsletter eelv-newsletter allows Cross Site Request Forgery.This issue affects EELV Newsletter: from n/a through <= 4.8.2.

    Published: 16 Dec 2024
    7.1
    High

    CVE-2024-54431

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in phpdevp Admin Customization wpp-customization allows Stored XSS.This issue affects Admin Customization: from n/a through <= 2.2.

    Published: 16 Dec 2024
    7.1
    High

    CVE-2024-54432

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Shambhu Patnaik WP Flipkart Importer wp-flipkart-importer allows Stored XSS.This issue affects WP Flipkart Importer: from n/a through <= 1.4.

    Published: 16 Dec 2024
    7.1
    High

    CVE-2024-54433

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Marcel CL Simple Booking Widget simple-booking-widget allows Stored XSS.This issue affects Simple Booking Widget: from n/a through <= 1.1.

    Published: 16 Dec 2024
    7.1
    High

    CVE-2024-54434

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in BenJemin phZoom phzoom allows Stored XSS.This issue affects phZoom: from n/a through <= 1.2.92.

    Published: 16 Dec 2024
    7.1
    High

    CVE-2024-54435

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Thomas Hoefter Onlywire Multi Autosubmitter onlywire-multi-autosubmitter allows Stored XSS.This issue affects Onlywire Multi Autosubmitter: from n/a through <= 1.2.4.

    Published: 16 Dec 2024
    7.1
    High

    CVE-2024-54436

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in milordk Jet Footer Code jet-footer-code allows Stored XSS.This issue affects Jet Footer Code: from n/a through <= 1.4.

    Published: 16 Dec 2024
    7.1
    High

    CVE-2024-54437

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in koolkatwebdesigns jCarousel jcarousel-for-wordpress allows Stored XSS.This issue affects jCarousel: from n/a through <= 1.0.

    Published: 16 Dec 2024
    7.1
    High

    CVE-2024-54438

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in gaxx Gaxx Keywords gaxx-keywords allows Stored XSS.This issue affects Gaxx Keywords: from n/a through <= 0.2.

    Published: 16 Dec 2024
    7.1
    High

    CVE-2024-54439

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Alok Tiwari Amazon Product Price amazon-product-price allows Stored XSS.This issue affects Amazon Product Price: from n/a through <= 1.1.

    Published: 16 Dec 2024
    7.1
    High

    CVE-2024-54440

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in blueskyy WP-Ban-User wp-ban-user allows Stored XSS.This issue affects WP-Ban-User: from n/a through <= 1.0.

    Published: 16 Dec 2024
    9.8
    Critical

    CVE-2024-56012

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in lizeipe Flash News / Post (Responsive) flashnews-fading-effect-pearlbells allows Privilege Escalation.This issue affects Flash News / Post (Responsive): from n/a through <= 4.1.

    Published: 16 Dec 2024
    7.6
    High

    CVE-2024-55989

    Last Modified: 23 Apr 2026

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Kyle M Brown WP Simple Pay Lite Manager stripe-manager allows SQL Injection.This issue affects WP Simple Pay Lite Manager: from n/a through <= 1.4.

    Published: 16 Dec 2024
    7.6
    High

    CVE-2024-55990

    Last Modified: 23 Apr 2026

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in tsjippy Mollie for Contact Form 7 cf7-mollie allows Blind SQL Injection.This issue affects Mollie for Contact Form 7: from n/a through <= 5.0.0.

    Published: 16 Dec 2024
    7.5
    High

    CVE-2024-54373

    Last Modified: 23 Apr 2026

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Chris Gardenberg EduAdmin Booking eduadmin-booking allows PHP Local File Inclusion.This issue affects EduAdmin Booking: from n/a through <= 5.2.0.

    Published: 16 Dec 2024
    5.4
    Medium

    CVE-2024-55998

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in Eric Sloan Popup Surveys & Polls for WordPress (Mare.io) popup-surveys allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Popup Surveys & Polls for WordPress (Mare.io): from n/a through <= 1.36.

    Published: 16 Dec 2024
    5.4
    Medium

    CVE-2024-56004

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in awfowler Easy Site Importer easy-site-importer allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Easy Site Importer: from n/a through <= 1.0.1.

    Published: 16 Dec 2024
    5.3
    Medium

    CVE-2024-54366

    Last Modified: 23 Apr 2026

    Generation of Error Message Containing Sensitive Information vulnerability in videogallery Vimeography vimeography allows Retrieve Embedded Sensitive Data.This issue affects Vimeography: from n/a through <= 2.4.4.

    Published: 16 Dec 2024
    6.8
    Medium

    CVE-2024-12660

    Last Modified: 19 Dec 2024

    A vulnerability was found in IObit Advanced SystemCare Utimate up to 17.0.0. It has been declared as problematic. Affected by this vulnerability is the function 0x8001E018 in the library AscRegistryFilter.sys of the component IOCTL Handler. The manipulation leads to null pointer dereference. It is possible to launch the attack on the local host. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 16 Dec 2024
    6.8
    Medium

    CVE-2024-12659

    Last Modified: 19 Dec 2024

    A vulnerability was found in IObit Advanced SystemCare Utimate up to 17.0.0. It has been classified as problematic. Affected is the function 0x8001E004 in the library AscRegistryFilter.sys of the component IOCTL Handler. The manipulation leads to null pointer dereference. Attacking locally is a requirement. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 16 Dec 2024
    6.8
    Medium

    CVE-2024-12658

    Last Modified: 19 Dec 2024

    A vulnerability was found in IObit Advanced SystemCare Utimate up to 17.0.0 and classified as problematic. This issue affects the function 0x8001E01C in the library AscRegistryFilter.sys of the component IOCTL Handler. The manipulation leads to null pointer dereference. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 16 Dec 2024
    —
    Unknown

    CVE-2024-12685

    Last Modified: 5 Jul 2025

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

    Published: 16 Dec 2024
    6.8
    Medium

    CVE-2024-12657

    Last Modified: 19 Dec 2024

    A vulnerability has been found in IObit Advanced SystemCare Utimate up to 17.0.0 and classified as problematic. This vulnerability affects the function 0x8001E000 in the library AscRegistryFilter.sys of the component IOCTL Handler. The manipulation leads to null pointer dereference. An attack has to be approached locally. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 16 Dec 2024
    6.8
    Medium

    CVE-2024-12656

    Last Modified: 19 Dec 2024

    A vulnerability, which was classified as problematic, was found in FabulaTech USB over Network 6.0.6.1. This affects the function 0x220448 in the library ftusbbus2.sys of the component IOCT Handler. The manipulation leads to null pointer dereference. The attack needs to be approached locally. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 16 Dec 2024
    8.4
    High

    CVE-2024-10095

    Last Modified: 18 Dec 2024

    In Progress Telerik UI for WPF versions prior to 2024 Q4 (2024.4.1213), a code execution attack is possible through an insecure deserialization vulnerability.

    Published: 16 Dec 2024
    6.8
    Medium

    CVE-2024-12655

    Last Modified: 19 Dec 2024

    A vulnerability, which was classified as problematic, has been found in FabulaTech USB over Network 6.0.6.1. Affected by this issue is the function 0x220420 in the library ftusbbus2.sys of the component IOCT Handler. The manipulation leads to null pointer dereference. It is possible to launch the attack on the local host. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 16 Dec 2024
    —
    Unknown

    CVE-2024-12681

    Last Modified: 5 Jul 2025

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

    Published: 16 Dec 2024
    6.8
    Medium

    CVE-2024-12654

    Last Modified: 18 Dec 2024

    A vulnerability classified as problematic was found in FabulaTech USB over Network 6.0.6.1. Affected by this vulnerability is the function 0x220408 in the library ftusbbus2.sys of the component IOCT Handler. The manipulation leads to null pointer dereference. Attacking locally is a requirement. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 16 Dec 2024
    6.8
    Medium

    CVE-2024-12653

    Last Modified: 18 Dec 2024

    A vulnerability classified as problematic has been found in FabulaTech USB over Network 6.0.6.1. Affected is the function 0x22040C in the library ftusbbus2.sys of the component IOCT Handler. The manipulation leads to null pointer dereference. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 16 Dec 2024
    5.3
    Medium

    CVE-2024-12478

    Last Modified: 15 Oct 2025

    A vulnerability was found in InvoicePlane up to 1.6.1. It has been declared as critical. This vulnerability affects the function upload_file of the file /index.php/upload/upload_file/1/1. The manipulation of the argument file leads to unrestricted upload. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 1.6.2-beta-1 is able to address this issue. It is recommended to upgrade the affected component. The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product.

    Published: 16 Dec 2024
    5.3
    Medium

    CVE-2024-12362

    Last Modified: 15 Oct 2025

    A vulnerability was found in InvoicePlane up to 1.6.1. It has been classified as problematic. This affects the function download of the file invoices.php. The manipulation of the argument invoice leads to path traversal. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 1.6.2-beta-1 is able to address this issue. It is recommended to upgrade the affected component. The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product.

    Published: 16 Dec 2024
    6.5
    Medium

    CVE-2024-54682

    Last Modified: 30 Sept 2025

    Mattermost versions 10.1.x <= 10.1.2, 10.0.x <= 10.0.2, 9.11.x <= 9.11.4, 9.5.x <= 9.5.12 fail to limit the file size for slack import file uploads which allows a user to cause a DoS via zip bomb by importing data in a team they are a team admin.

    Published: 16 Dec 2024
    6.5
    Medium

    CVE-2024-54083

    Last Modified: 30 Sept 2025

    Mattermost versions 10.1.x <= 10.1.2, 10.0.x <= 10.0.2, 9.11.x <= 9.11.4, 9.5.x <= 9.5.12 fail to properly validate the type of callProps which allows a user to cause a client side (webapp and mobile) DoS to users of particular channels, by sending a specially crafted post.

    Published: 16 Dec 2024
    4.8
    Medium

    CVE-2024-48872

    Last Modified: 15 Oct 2025

    Mattermost versions 10.1.x <= 10.1.2, 10.0.x <= 10.0.2, 9.11.x <= 9.11.4, and 9.5.x <= 9.5.12 fail to prevent concurrently checking and updating the failed login attempts. which allows an attacker to bypass of "Max failed attempts" restriction and send a big number of login attempts before being blocked via simultaneously sending multiple login requests

    Published: 16 Dec 2024
    —
    Unknown

    CVE-2024-56123

    Last Modified: 8 Jun 2026

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

    Published: 16 Dec 2024
    —
    Unknown

    CVE-2024-56122

    Last Modified: 8 Jun 2026

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

    Published: 16 Dec 2024
    —
    Unknown

    CVE-2024-56121

    Last Modified: 8 Jun 2026

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

    Published: 16 Dec 2024
    —
    Unknown

    CVE-2024-56120

    Last Modified: 8 Jun 2026

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

    Published: 16 Dec 2024
    8.1
    High

    CVE-2024-12646

    Last Modified: 15 Apr 2026

    The topm-client from Chunghwa Telecom has an Arbitrary File Delete vulnerability. The application sets up a simple local web server and provides APIs for communication with the target website. Due to the lack of CSRF protection in the APIs, unauthenticated remote attackers could use these APIs through phishing. Additionally, one of the APIs contains an Absolute Path Traversal vulnerability, allowing attackers to delete arbitrary files on the user's system.

    Published: 16 Dec 2024