CVE Feed

    Dashboard / CVE

    5.3
    Medium

    CVE-2024-9679

    Last Modified: 15 Apr 2026

    A Hardcoded Cryptographic key vulnerability existed in DLP Extension 11.11.1.3 which allowed the decryption of previously encrypted user credentials.

    Published: 16 Dec 2024
    6.5
    Medium

    CVE-2024-12645

    Last Modified: 15 Apr 2026

    The topm-client from Chunghwa Telecom has an Arbitrary File Read vulnerability. The application sets up a simple local web server and provides APIs for communication with the target website. Due to the lack of CSRF protection for the APIs, unauthenticated remote attackers could use these APIs through phishing. Additionally, one of the APIs contains a Relative Path Traversal vulnerability, allowing attackers to read arbitrary files on the user's system.

    Published: 16 Dec 2024
    7.1
    High

    CVE-2024-12644

    Last Modified: 15 Apr 2026

    The tbm-client from Chunghwa Telecom has an Arbitrary File vulnerability. The application sets up a simple local web server and provides APIs for communication with the target website. Due to the lack of CSRF protection in the APIs, unauthenticated remote attackers could use these APIs through phishing. Additionally, one of the APIs contains an Absolute Path Traversal vulnerability. Attackers can copy arbitrary files on the user's system and paste them into any path, which poses a potential risk of information leakage or could consume hard drive space by copying files in large volumes.

    Published: 16 Dec 2024
    8.1
    High

    CVE-2024-12643

    Last Modified: 15 Apr 2026

    The tbm-client from Chunghwa Telecom has an Arbitrary File Delete vulnerability. The application sets up a simple local web server and provides APIs for communication with the target website. Due to the lack of CSRF protection in the APIs, unauthenticated remote attackers could use these APIs through phishing. Additionally, one of the APIs contains an Absolute Path Traversal vulnerability, allowing attackers to delete arbitrary files on the user's system.

    Published: 16 Dec 2024
    4.9
    Medium

    CVE-2024-9678

    Last Modified: 15 Apr 2026

    An SQL Injection vulnerability existed in DLP Extension 11.11.1.3. The vulnerability allowed an attacker to perform arbitrary SQL queries potentially leading to command execution.

    Published: 16 Dec 2024
    8.1
    High

    CVE-2024-12642

    Last Modified: 23 Dec 2025

    TenderDocTransfer from Chunghwa Telecom has an Arbitrary File Write vulnerability. The application sets up a simple local web server and provides APIs for communication with the target website. Due to the lack of CSRF protection for the APIs, unauthenticated remote attackers could use these APIs through phishing. Additionally, one of the APIs contains a Relative Path Traversal vulnerability, allowing attackers to write arbitrary files to any path on the user's system.

    Published: 16 Dec 2024
    9.6
    Critical

    CVE-2024-12641

    Last Modified: 23 Dec 2025

    TenderDocTransfer from Chunghwa Telecom has a Reflected Cross-site scripting vulnerability. The application sets up a simple local web server and provides APIs for communication with the target website. Due to the lack of CSRF protection for the APIs, unauthenticated remote attackers could use specific APIs through phishing to execute arbitrary JavaScript code in the user’s browser. Since the web server set by the application supports Node.Js features, attackers can further leverage this to run OS commands.

    Published: 16 Dec 2024
    5.3
    Medium

    CVE-2024-5333

    Last Modified: 27 Aug 2025

    The Events Calendar WordPress plugin before 6.8.2.1 is missing access checks in the REST API, allowing for unauthenticated users to access information about password protected events.

    Published: 16 Dec 2024
    5.3
    Medium

    CVE-2024-8116

    Last Modified: 11 Jul 2025

    An issue has been discovered in GitLab CE/EE affecting all versions from 16.9 before 17.4.6, 17.5 before 17.5.4, and 17.6 before 17.6.2. By using a specific GraphQL query, under specific conditions an unauthorized user can retrieve branch names.

    Published: 16 Dec 2024
    5.3
    Medium

    CVE-2024-8650

    Last Modified: 11 Jul 2025

    An issue was discovered in GitLab CE/EE affecting all versions from 15.0 prior to 17.4.6, 17.5 prior to 17.5.4, and 17.6 prior to 17.6.2 that allowed non-member users to view unresolved threads marked as internal notes in public projects merge requests.

    Published: 16 Dec 2024
    5.4
    Medium

    CVE-2024-11841

    Last Modified: 17 May 2025

    The Tithe.ly Giving Button WordPress plugin through 1.1 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

    Published: 16 Dec 2024
    5.4
    Medium

    CVE-2024-55554

    Last Modified: 15 Apr 2026

    Intrexx Portal Server before 12.0.2 allows XSS via a user-defined portlet.

    Published: 16 Dec 2024
    7.5
    High

    CVE-2024-52949

    Last Modified: 14 Oct 2025

    iptraf-ng 1.2.1 has a stack-based buffer overflow. In src/ifaces.c, the strcpy function consistently fails to control the size, and it is consequently possible to overflow memory on the stack.

    Published: 16 Dec 2024
    6.1
    Medium

    CVE-2024-56112

    Last Modified: 5 Sept 2025

    CyberPanel (aka Cyber Panel) before f0cf648 allows XSS via token or username to plogical/phpmyadminsignin.php.

    Published: 16 Dec 2024
    5.9
    Medium

    CVE-2024-56087

    Last Modified: 17 Apr 2025

    An issue was discovered in Logpoint before 7.5.0. Authenticated users can inject payloads while querying Search Template Dashboard. These are executed, leading to Server-Side Template Injection.

    Published: 16 Dec 2024
    4.8
    Medium

    CVE-2024-55100

    Last Modified: 28 Mar 2025

    A stored cross-site scripting (XSS) vulnerability in the component /admin/profile.php of Online Nurse Hiring System v1.0 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the fullname parameter.

    Published: 16 Dec 2024
    5.9
    Medium

    CVE-2024-56085

    Last Modified: 17 Apr 2025

    An issue was discovered in Logpoint before 7.5.0. Authenticated users can inject payloads while creating Search Template Dashboard. These are executed, leading to Server-Side Template Injection.

    Published: 16 Dec 2024
    8.1
    High

    CVE-2024-56083

    Last Modified: 15 Apr 2026

    Cognition Devin before 2024-12-12 provides write access to code by an attacker who discovers the https://vscode-randomly_generated_string.devinapps.com URL (aka the VSCode live share URL) for a specific "Use Devin's Machine" session. For example, this URL may be discovered if a customer posts a screenshot of a Devin session to social media, or publicly streams their Devin session.

    Published: 16 Dec 2024
    9.8
    Critical

    CVE-2024-29671

    Last Modified: 15 Apr 2026

    Buffer Overflow vulnerability in NEXTU FLATA AX1500 Router v.1.0.2 allows a remote attacker to execute arbitrary code via the POST request handler component.

    Published: 16 Dec 2024
    4.8
    Medium

    CVE-2024-37773

    Last Modified: 20 Jun 2025

    An HTML injection vulnerability in Sunbird DCIM dcTrack 9.1.2 allows attackers authenticated as administrators to inject arbitrary HTML code in an admin screen.

    Published: 16 Dec 2024
    8
    High

    CVE-2024-37774

    Last Modified: 20 Jun 2025

    A Cross-Site Request Forgery (CSRF) in Sunbird DCIM dcTrack v9.1.2 allows authenticated attackers to escalate their privileges by forcing an Administrator user to perform sensitive requests in some admin screens.

    Published: 16 Dec 2024
    7.5
    High

    CVE-2024-37775

    Last Modified: 20 Jun 2025

    Incorrect access control in Sunbird DCIM dcTrack v9.1.2 allows attackers to create or update a ticket with a location which bypasses an RBAC check.

    Published: 16 Dec 2024
    4.8
    Medium

    CVE-2024-37776

    Last Modified: 20 Jun 2025

    A cross-site scripting (XSS) vulnerability in Sunbird DCIM dcTrack v9.1.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload in some admin screens.

    Published: 16 Dec 2024
    8.8
    High

    CVE-2024-53376

    Last Modified: 5 Sept 2025

    CyberPanel before 2.3.8 allows remote authenticated users to execute arbitrary commands via shell metacharacters in the phpSelection field to the websites/submitWebsiteCreation URI.

    Published: 16 Dec 2024
    9.8
    Critical

    CVE-2024-55085

    Last Modified: 17 Apr 2025

    GetSimple CMS CE 3.3.19 suffers from arbitrary code execution in the template editing function in the background management system, which can be used by an attacker to implement RCE.

    Published: 16 Dec 2024
    7.2
    High

    CVE-2024-55103

    Last Modified: 28 Mar 2025

    Online Nurse Hiring System v1.0 was discovered to contain a SQL injection vulnerability in the component /admin/profile.php via the fullname parameter.

    Published: 16 Dec 2024
    7.2
    High

    CVE-2024-55104

    Last Modified: 28 Mar 2025

    Online Nurse Hiring System v1.0 was discovered to contain multiple SQL injection vulnerabilities in the component /admin/add-nurse.php via the gender and emailid parameters.

    Published: 16 Dec 2024
    4.8
    Medium

    CVE-2024-55451

    Last Modified: 24 Apr 2025

    A Stored Cross-Site Scripting (XSS) vulnerability exists in authenticated SVG file upload and viewing functionality in UJCMS 9.6.3. The vulnerability arises from insufficient sanitization of embedded attributes in uploaded SVG files. When a maliciously crafted SVG file is viewed by other backend users, it allows authenticated attackers to execute arbitrary JavaScript in the context of other backend users' browsers, potentially leading to the theft of sensitive tokens.

    Published: 16 Dec 2024
    5.4
    Medium

    CVE-2024-55452

    Last Modified: 24 Apr 2025

    A URL redirection vulnerability exists in UJCMS 9.6.3 due to improper validation of URLs in the upload and rendering of new block / carousel items. This vulnerability allows authenticated attackers to redirect unprivileged users to an arbitrary, attacker-controlled webpage. When an authenticated user clicks on the malicious block item, they are redirected to the arbitrary untrusted domains, where sensitive tokens, such as JSON Web Tokens, can be stolen via a crafted webpage.

    Published: 16 Dec 2024
    9.8
    Critical

    CVE-2024-55557

    Last Modified: 15 Apr 2026

    ui/pref/ProxyPrefView.java in weasis-core in Weasis 4.5.1 has a hardcoded key for symmetric encryption of proxy credentials.

    Published: 16 Dec 2024
    7.1
    High

    CVE-2024-56084

    Last Modified: 20 Jun 2025

    An issue was discovered in Logpoint UniversalNormalizer before 5.7.0. Authenticated users can inject payloads while creating Universal Normalizer. These are executed, leading to Remote Code Execution.

    Published: 16 Dec 2024
    7.1
    High

    CVE-2024-56086

    Last Modified: 17 Apr 2025

    An issue was discovered in Logpoint before 7.5.0. Authenticated users can inject payloads in Report Templates. These are executed when the backup process is initiated, leading to Remote Code Execution.

    Published: 16 Dec 2024
    7.5
    High

    CVE-2024-8798

    Last Modified: 17 Sept 2025

    No proper validation of the length of user input in olcp_ind_handler in zephyr/subsys/bluetooth/services/ots/ots_client.c.

    Published: 15 Dec 2024
    5.1
    Medium

    CVE-2024-7701

    Last Modified: 5 Aug 2025

    Use of Password Hash With Insufficient Computational Effort vulnerability in percona percona-toolkit allows Encryption Brute Forcing.This issue affects percona-toolkit: 3.6.0.

    Published: 15 Dec 2024
    8.6
    High

    CVE-2024-11858

    Last Modified: 5 Aug 2025

    A flaw was found in Radare2, which contains a command injection vulnerability caused by insufficient input validation when handling Pebble Application files. Maliciously crafted inputs can inject shell commands during command parsing, leading to unintended behavior during file processing​

    Published: 15 Dec 2024
    7.6
    High

    CVE-2024-45497

    Last Modified: 11 Aug 2026

    A flaw was found in the OpenShift build process, where the docker-build container is configured with a hostPath volume mount that maps the node's /var/lib/kubelet/config.json file into the build pod. This file contains sensitive credentials necessary for pulling images from private repositories. The mount is not read-only, which allows the attacker to overwrite it. By modifying the config.json file, the attacker can cause a denial of service by preventing the node from pulling new images and potentially exfiltrating sensitive secrets. This flaw impacts the availability of services dependent on image pulls and exposes sensitive information to unauthorized parties.

    Published: 15 Dec 2024
    7.5
    High

    CVE-2024-56073

    Last Modified: 20 Jun 2025

    An issue was discovered in FastNetMon Community Edition through 1.2.7. Zero-length templates for Netflow v9 allow remote attackers to cause a denial of service (divide-by-zero error and application crash).

    Published: 15 Dec 2024
    3.5
    Low

    CVE-2024-56082

    Last Modified: 15 Apr 2026

    ChatBar.tsx in Lumos before 1.0.17 parses raw HTML in Markdown because the markdown-to-jsx package is used without disableParsingRawHTML set to true.

    Published: 15 Dec 2024
    5.5
    Medium

    CVE-2024-56074

    Last Modified: 15 Apr 2026

    gitingest before 9996a06 mishandles symbolic links that point outside of the base directory.

    Published: 15 Dec 2024
    7.5
    High

    CVE-2024-56072

    Last Modified: 20 Jun 2025

    An issue was discovered in FastNetMon Community Edition through 1.2.7. The sFlow v5 plugin allows remote attackers to cause a denial of service (application crash) via a crafted packet that specifies many sFlow samples.

    Published: 15 Dec 2024
    9.1
    Critical

    CVE-2024-55969

    Last Modified: 15 Apr 2026

    DocIO in Syncfusion Essential Studio for ASP.NET MVC before 27.1.55 throws XMLException during the resaving of a DOCX document with an external reference XML, aka I640714.

    Published: 15 Dec 2024
    7.5
    High

    CVE-2024-55970

    Last Modified: 15 Apr 2026

    File Manager in Syncfusion Essential Studio for ASP.NET MVC before 27.1.55 has a traversal issue that is related to the request parameter, aka I644734.

    Published: 15 Dec 2024
    7.8
    High

    CVE-2024-31891

    Last Modified: 25 Jul 2025

    IBM Storage Scale GUI 5.1.9.0 through 5.1.9.6 and 5.2.0.0 through 5.2.1.1 contains a local privilege escalation vulnerability. A malicious actor with command line access to the 'scalemgmt' user can elevate privileges to gain root access to the host operating system.

    Published: 14 Dec 2024
    7.5
    High

    CVE-2024-31892

    Last Modified: 25 Jul 2025

    IBM Storage Scale GUI 5.1.9.0 through 5.1.9.6 and 5.2.0.0 through 5.2.1.1 could allow a user to perform unauthorized actions after intercepting and modifying a csv file due to improper neutralization of formula elements.

    Published: 14 Dec 2024
    8.1
    High

    CVE-2024-11721

    Last Modified: 8 Apr 2026

    The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 3.24.5. This is due to insufficient controls on the user role select field when utilizing the 'Role' field in a form. This makes it possible for unauthenticated attackers to create new administrative user accounts, even when the administrative user role has not been provided as an option to the user, granted that unauthenticated users have been provided access to the form.

    Published: 14 Dec 2024
    7.2
    High

    CVE-2024-11720

    Last Modified: 8 Apr 2026

    The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to Stored Cross-Site Scripting via submission forms in all versions up to, and including, 3.24.5 due to insufficient input sanitization and output escaping on the new Taxonomy form. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This is only exploitable when lower-level users have been granted access to submit specific forms, which is disabled by default.

    Published: 14 Dec 2024
    5.3
    Medium

    CVE-2024-11712

    Last Modified: 8 Apr 2026

    The WP Job Portal – A Complete Recruitment System for Company or Job Board website plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the getResumeFileDownloadById() function in all versions up to, and including, 2.2.2. This makes it possible for unauthenticated attackers to download other users resumes.

    Published: 14 Dec 2024
    4.9
    Medium

    CVE-2024-11710

    Last Modified: 8 Apr 2026

    The WP Job Portal – A Complete Recruitment System for Company or Job Board website plugin for WordPress is vulnerable to SQL Injection via the 'fieldfor', 'visibleParent' and 'id' parameters in all versions up to, and including, 2.2.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with Administrator-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

    Published: 14 Dec 2024
    7.5
    High

    CVE-2024-11711

    Last Modified: 8 Apr 2026

    The WP Job Portal – A Complete Recruitment System for Company or Job Board website plugin for WordPress is vulnerable to SQL Injection via the 'resumeid' parameter in all versions up to, and including, 2.2.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

    Published: 14 Dec 2024
    4.9
    Medium

    CVE-2024-11714

    Last Modified: 8 Apr 2026

    The WP Job Portal – A Complete Recruitment System for Company or Job Board website plugin for WordPress is vulnerable to SQL Injection via the 'ff' parameter of the getFieldsForVisibleCombobox() function in all versions up to, and including, 2.2.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with Administrator-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

    Published: 14 Dec 2024