CVE Feed

    Dashboard / CVE

    7.3
    High

    CVE-2023-32507

    Last Modified: 28 Apr 2026

    Missing Authorization vulnerability in wp3sixty Woo Custom Emails allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Woo Custom Emails: from n/a through 2.2.

    Published: 13 Dec 2024
    6.5
    Medium

    CVE-2023-32506

    Last Modified: 28 Apr 2026

    Missing Authorization vulnerability in Link Whisper Link Whisper Free allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Link Whisper Free: from n/a through 0.6.3.

    Published: 13 Dec 2024
    7.5
    High

    CVE-2023-30490

    Last Modified: 28 Apr 2026

    Missing Authorization vulnerability in Matthew Ruddy Easing Slider allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Easing Slider : from n/a through 3.0.8.

    Published: 13 Dec 2024
    4.3
    Medium

    CVE-2023-28990

    Last Modified: 28 Apr 2026

    Missing Authorization vulnerability in HashThemes Viral Mag allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Viral Mag: from n/a through 1.0.9.

    Published: 13 Dec 2024
    4.3
    Medium

    CVE-2023-27456

    Last Modified: 28 Apr 2026

    Missing Authorization vulnerability in HashThemes Total allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Total: from n/a through 2.1.19.

    Published: 13 Dec 2024
    7.5
    High

    CVE-2023-25988

    Last Modified: 28 Apr 2026

    Missing Authorization vulnerability in Video Gallery by Total-Soft Video Gallery – YouTube Gallery allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Video Gallery – YouTube Gallery: from n/a through 1.7.6.

    Published: 13 Dec 2024
    5.3
    Medium

    CVE-2022-47429

    Last Modified: 28 Apr 2026

    Missing Authorization vulnerability in 8Degree Themes Coming Soon Landing Page and Maintenance Mode WordPress Plugin allows Retrieve Embedded Sensitive Data.This issue affects Coming Soon Landing Page and Maintenance Mode WordPress Plugin: from n/a through 2.2.0.

    Published: 13 Dec 2024
    5.3
    Medium

    CVE-2022-44578

    Last Modified: 28 Apr 2026

    Missing Authorization vulnerability in Pierre JEHAN Owl Carousel allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Owl Carousel: from n/a through 0.5.3.

    Published: 13 Dec 2024
    5.3
    Medium

    CVE-2023-22697

    Last Modified: 28 Apr 2026

    Missing Authorization vulnerability in Survey Maker team Survey Maker allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Survey Maker: from n/a through 3.2.0.

    Published: 13 Dec 2024
    6.5
    Medium

    CVE-2022-47594

    Last Modified: 28 Apr 2026

    Missing Authorization vulnerability in WPDeveloper Essential Blocks for Gutenberg allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Essential Blocks for Gutenberg: from n/a through 3.8.5.

    Published: 13 Dec 2024
    5.3
    Medium

    CVE-2022-47182

    Last Modified: 28 Apr 2026

    Missing Authorization vulnerability in Wpexpertsio APIExperts Square for WooCommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects APIExperts Square for WooCommerce: from n/a through 4.4.1.

    Published: 13 Dec 2024
    4.3
    Medium

    CVE-2022-47176

    Last Modified: 28 Apr 2026

    Missing Authorization vulnerability in Depicter Slider and Popup by Averta Depicter Slider allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Depicter Slider: from n/a through 1.9.0.

    Published: 13 Dec 2024
    4.3
    Medium

    CVE-2022-47168

    Last Modified: 29 Apr 2026

    Missing Authorization vulnerability in printful Printful Integration for WooCommerce printful-shipping-for-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Printful Integration for WooCommerce: from n/a through <= 2.2.3.

    Published: 13 Dec 2024
    5.3
    Medium

    CVE-2022-46846

    Last Modified: 28 Apr 2026

    Missing Authorization vulnerability in WP OnlineSupport, Essential Plugin Trending/Popular Post Slider and Widget allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Trending/Popular Post Slider and Widget: from n/a through 1.5.7.

    Published: 13 Dec 2024
    5.4
    Medium

    CVE-2022-46840

    Last Modified: 28 Apr 2026

    Missing Authorization vulnerability in JS Help Desk JS Help Desk – Best Help Desk & Support Plugin allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects JS Help Desk – Best Help Desk & Support Plugin: from n/a through 2.7.1.

    Published: 13 Dec 2024
    9.1
    Critical

    CVE-2022-46838

    Last Modified: 28 Apr 2026

    Missing Authorization vulnerability in JS Help Desk JS Help Desk – Best Help Desk & Support Plugin allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects JS Help Desk – Best Help Desk & Support Plugin: from n/a through 2.7.1.

    Published: 13 Dec 2024
    4.3
    Medium

    CVE-2022-46811

    Last Modified: 28 Apr 2026

    Missing Authorization vulnerability in VillaTheme(villatheme.com) ALD – Dropshipping and Fulfillment for AliExpress and WooCommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects ALD – Dropshipping and Fulfillment for AliExpress and WooCommerce: from n/a through 1.0.21.

    Published: 13 Dec 2024
    4.3
    Medium

    CVE-2022-46807

    Last Modified: 28 Apr 2026

    Missing Authorization vulnerability in Lauri Karisola / WP Trio Stock Sync for WooCommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Stock Sync for WooCommerce: from n/a through 2.3.2.

    Published: 13 Dec 2024
    6.5
    Medium

    CVE-2022-46796

    Last Modified: 28 Apr 2026

    Missing Authorization vulnerability in VillaTheme CURCY allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects CURCY: from n/a through 2.1.25.

    Published: 13 Dec 2024
    6.5
    Medium

    CVE-2022-46795

    Last Modified: 28 Apr 2026

    Missing Authorization vulnerability in Tyche Softwares Print Invoice & Delivery Notes for WooCommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Print Invoice & Delivery Notes for WooCommerce: from n/a through 4.7.2.

    Published: 13 Dec 2024
    5.4
    Medium

    CVE-2022-45841

    Last Modified: 28 Apr 2026

    Missing Authorization vulnerability in RoboSoft Robo Gallery allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Robo Gallery: from n/a through 3.2.9.

    Published: 13 Dec 2024
    6.5
    Medium

    CVE-2022-45840

    Last Modified: 28 Apr 2026

    Missing Authorization vulnerability in Lucian Apostol Auto Affiliate Links allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Auto Affiliate Links: from n/a through 6.2.1.5.

    Published: 13 Dec 2024
    5.4
    Medium

    CVE-2022-45826

    Last Modified: 11 Apr 2025

    Missing Authorization vulnerability in WP Sunshine Sunshine Photo Cart allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Sunshine Photo Cart: from n/a through 2.9.13.

    Published: 13 Dec 2024
    3.5
    Low

    CVE-2022-45819

    Last Modified: 28 Apr 2026

    Missing Authorization vulnerability in Popup Maker Popup Maker allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Popup Maker: from n/a through 1.17.1.

    Published: 13 Dec 2024
    4.3
    Medium

    CVE-2022-45806

    Last Modified: 28 Apr 2026

    Missing Authorization vulnerability in Strategy11 Form Builder Team Formidable Forms allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Formidable Forms: from n/a through 5.5.4.

    Published: 13 Dec 2024
    4.3
    Medium

    CVE-2022-43472

    Last Modified: 28 Apr 2026

    Missing Authorization vulnerability in StylemixThemes eRoom – Zoom Meetings & Webinar allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects eRoom – Zoom Meetings & Webinar: from n/a through 1.4.6.

    Published: 13 Dec 2024
    6.5
    Medium

    CVE-2024-28980

    Last Modified: 4 Feb 2025

    Dell RecoverPoint for VMs, version(s) 6.0.x contain(s) a Use of a Broken or Risky Cryptographic Algorithm vulnerability in the SSH. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Remote execution.

    Published: 13 Dec 2024
    4.4
    Medium

    CVE-2024-47984

    Last Modified: 4 Feb 2025

    Dell RecoverPoint for Virtual Machines 6.0.x contains Denial of Service vulnerability. A User with Remote access could potentially exploit this vulnerability, leading to the disruption of most functionalities of the RPA persistent after reboot, resulting in need of technical support intervention in getting system back to stable state.

    Published: 13 Dec 2024
    6.6
    Medium

    CVE-2024-24902

    Last Modified: 4 Feb 2025

    Dell RecoverPoint for Virtual Machines 6.0.x contains an Improper access control vulnerability. A low privileged local attacker could potentially exploit this vulnerability leading to gaining access to unauthorized data for a limited time.

    Published: 13 Dec 2024
    6.5
    Medium

    CVE-2024-38488

    Last Modified: 4 Feb 2025

    Dell RecoverPoint for Virtual Machines 6.0.x contains a vulnerability. An improper Restriction of Excessive Authentication vulnerability where a Network attacker could potentially exploit this vulnerability, leading to a brute force attack or a dictionary attack against the RecoverPoint login form and a complete system compromise. This allows attackers to brute-force the password of valid users in an automated manner.

    Published: 13 Dec 2024
    5.3
    Medium

    CVE-2024-48007

    Last Modified: 13 Mar 2025

    Dell RecoverPoint for Virtual Machines 6.0.x contains use of hard-coded credentials vulnerability. A Remote unauthenticated attacker could potentially exploit this vulnerability by gaining access to the source code, easily retrieving these secrets and reusing them to access the system leading to gaining access to unauthorized data.

    Published: 13 Dec 2024
    9.6
    Critical

    CVE-2024-11986

    Last Modified: 15 Apr 2026

    Improper input handling in the 'Host Header' allows an unauthenticated attacker to store a payload in web application logs. When an Administrator views the logs using the application's standard functionality, it enables the execution of the payload, resulting in Stored XSS or 'Cross-Site Scripting'.

    Published: 13 Dec 2024
    4.9
    Medium

    CVE-2024-55889

    Last Modified: 14 Aug 2025

    phpMyFAQ is an open source FAQ web application. Prior to version 3.2.10, a vulnerability exists in the FAQ Record component where a privileged attacker can trigger a file download on a victim's machine upon page visit by embedding it in an <iframe> element without user interaction or explicit consent. Version 3.2.10 fixes the issue.

    Published: 13 Dec 2024
    5.3
    Medium

    CVE-2024-48008

    Last Modified: 4 Feb 2025

    Dell RecoverPoint for Virtual Machines 6.0.x contains a OS Command Injection vulnerability. An Low privileged remote attacker could potentially exploit this vulnerability leading to information disclosure ,allowing of unintended actions like reading files that may contain sensitive information

    Published: 13 Dec 2024
    8.8
    High

    CVE-2024-22461

    Last Modified: 4 Feb 2025

    Dell RecoverPoint for Virtual Machines 6.0.x contains an OS Command injection vulnerability. A low privileged remote attacker could potentially exploit this vulnerability by running any command as root, leading to gaining of root-level access and compromise of complete system.

    Published: 13 Dec 2024
    6.1
    Medium

    CVE-2024-9608

    Last Modified: 15 Apr 2026

    The MyParcel plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 4.24.1. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link. Please note this is only exploitable when the WooCommerce store is set to Belgium.

    Published: 13 Dec 2024
    6.4
    Medium

    CVE-2024-11827

    Last Modified: 15 Apr 2026

    The Out of the Block: OpenStreetMap plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's ootb_query shortcode in all versions up to, and including, 2.8.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 13 Dec 2024
    10
    Critical

    CVE-2024-21577

    Last Modified: 15 Apr 2026

    ComfyUI-Ace-Nodes is vulnerable to Code Injection. The ACE_ExpressionEval node contains an eval() in its entrypoint function that accepts arbitrary user-controlled data. A user can create a workflow that results in executing arbitrary code on the server.

    Published: 13 Dec 2024
    10
    Critical

    CVE-2024-21576

    Last Modified: 15 Apr 2026

    ComfyUI-Bmad-Nodes is vulnerable to Code Injection. The issue stems from a validation bypass in the BuildColorRangeHSVAdvanced, FilterContour and FindContour custom nodes. In the entrypoint function to each node, there’s a call to eval which can be triggered by generating a workflow that injects a crafted string into the node. This can result in executing arbitrary code on the server.

    Published: 13 Dec 2024
    3.5
    Low

    CVE-2021-32007

    Last Modified: 15 Apr 2026

    This issue affects: Secomea GateManager Version 9.5 and all prior versions. Protection Mechanism Failure vulnerability in web server of Secomea GateManager to potentially leak information to remote servers.

    Published: 13 Dec 2024
    8.3
    High

    CVE-2024-52066

    Last Modified: 2 Oct 2025

    Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in RTI Connext Professional (Routing Service) allows Overflow Variables and Tags.This issue affects Connext Professional: from 7.4.0 before 7.5.0, from 7.0.0 before 7.3.0.5, from 6.1.0 before 6.1.2.21, from 6.0.0 before 6.0.1.40.

    Published: 13 Dec 2024
    6.9
    Medium

    CVE-2024-52065

    Last Modified: 2 Oct 2025

    Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in RTI Connext Professional on non-Windows (Persistence Service) allows Buffer Overflow via Environment Variables.This issue affects Connext Professional: from 7.0.0 before 7.3.0.2, from 6.1.1.2 before 6.1.2.21, from 5.3.1.40 before 5.3.1.41.

    Published: 13 Dec 2024
    6.9
    Medium

    CVE-2024-52064

    Last Modified: 2 Oct 2025

    Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in RTI Connext Professional (Core Libraries) allows Overflow Variables and Tags.This issue affects Connext Professional: from 7.0.0 before 7.3.0.2, from 6.1.0 before 6.1.2.21, from 6.0.0 before 6.0.1.40, from 5.0.0 before 5.3.1.45.

    Published: 13 Dec 2024
    8.3
    High

    CVE-2024-52063

    Last Modified: 2 Oct 2025

    Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in RTI Connext Professional (Core Libraries, Routing Service) allows Overflow Variables and Tags.This issue affects Connext Professional: from 7.0.0 before 7.3.0.5, from 6.1.0 before 6.1.2.21, from 6.0.0 before 6.0.1.40, from 5.0.0 before 5.3.1.45.

    Published: 13 Dec 2024
    6.9
    Medium

    CVE-2024-52062

    Last Modified: 2 Oct 2025

    Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in RTI Connext Professional (Core Libraries) allows Overflow Variables and Tags.This issue affects Connext Professional: from 7.0.0 before 7.3.0.5, from 6.1.0 before 6.1.2.21, from 6.0.0 before 6.0.1.40, from 5.0.0 before 5.3.1.45.

    Published: 13 Dec 2024
    8.3
    High

    CVE-2024-52061

    Last Modified: 2 Oct 2025

    Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in RTI Connext Professional (Core Libraries, Queuing Service, Recording Service, Routing Service) allows Overflow Variables and Tags.This issue affects Connext Professional: from 7.4.0 before 7.5.0, from 7.0.0 before 7.3.0.5, from 6.1.0 before 6.1.2.21, from 6.0.0 before 6.0.1.40, from 5.0.0 before 5.3.1.45.

    Published: 13 Dec 2024
    8.3
    High

    CVE-2024-52060

    Last Modified: 2 Oct 2025

    Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in RTI Connext Professional (Routing Service, Recording Service, Queuing Service, Observability Collector Service, Cloud Discovery Service) allows Buffer Overflow via Environment Variables.This issue affects Connext Professional: from 7.0.0 before 7.3.0.5, from 6.1.0 before 6.1.2.21, from 6.0.0 before 6.0.*, from 5.3.0 before 5.3.1.45.

    Published: 13 Dec 2024
    6.9
    Medium

    CVE-2024-52059

    Last Modified: 22 Sept 2026

    Buffer Copy without Checking Size of Input ('Classic Buffer Overflow'), Heap-based Buffer Overflow, Integer Overflow or Wraparound vulnerability in RTI Connext Professional (Security Plugins) allows Overflow Variables and Tags. This issue affects Connext Professional: from 7.0.0 before 7.3.0.2, from 6.1.0 before 6.1.2.17.

    Published: 13 Dec 2024
    8.6
    High

    CVE-2024-52058

    Last Modified: 2 Oct 2025

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in RTI Connext Professional (System Designer) allows OS Command Injection.This issue affects Connext Professional: from 7.0.0 before 7.3.0.2, from 6.1.0 before 6.1.2.19.

    Published: 13 Dec 2024
    9.1
    Critical

    CVE-2024-52057

    Last Modified: 2 Oct 2025

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in RTI Connext Professional (Queuing Service) allows SQL Injection.This issue affects Connext Professional: from 7.0.0 before 7.3.0, from 6.1.0 before 6.1.2.17, from 6.0.0 before 6.0.*, from 5.2.0 before 5.3.*.

    Published: 13 Dec 2024