CVE Feed

    Dashboard / CVE

    8.6
    High

    CVE-2024-55663

    Last Modified: 10 Jan 2025

    XWiki Platform is a generic wiki platform. Starting in version 6.3-milestone-2 and prior to versions 13.10.5 and 14.3-rc-1, in `getdocument.vm`; the ordering of the returned documents is defined from an unsanitized request parameter (request.sort) and can allow any user to inject HQL. Depending on the used database backend, the attacker may be able to not only obtain confidential information such as password hashes from the database, but also execute UPDATE/INSERT/DELETE queries. This has been patched in 13.10.5 and 14.3-rc-1. There is no known workaround, other than upgrading XWiki.

    Published: 12 Dec 2024
    7.5
    High

    CVE-2024-47238

    Last Modified: 4 Feb 2025

    Dell Client Platform BIOS contains an Improper Input Validation vulnerability in an externally developed component. A high privileged attacker with local access could potentially exploit this vulnerability, leading to arbitrary code execution.

    Published: 12 Dec 2024
    9.9
    Critical

    CVE-2024-55662

    Last Modified: 30 Apr 2025

    XWiki Platform is a generic wiki platform. Starting in version 3.3-milestone-1 and prior to versions 15.10.9 and 16.3.0, on instances where `Extension Repository Application` is installed, any user can execute any code requiring `programming` rights on the server. This vulnerability has been fixed in XWiki 15.10.9 and 16.3.0. Since `Extension Repository Application` is not mandatory, it can be safely disabled on instances that do not use it as a workaround. It is also possible to manually apply the patches from commit 8659f17d500522bf33595e402391592a35a162e8 to the page `ExtensionCode.ExtensionSheet` and to the page `ExtensionCode.ExtensionAuthorsDisplayer`.

    Published: 12 Dec 2024
    6.5
    Medium

    CVE-2024-52901

    Last Modified: 7 Jan 2025

    IBM InfoSphere Information Server 11.7 could allow an authenticated user to GUI to not load or stop working due to improper input validation.

    Published: 12 Dec 2024
    7.1
    High

    CVE-2024-55633

    Last Modified: 12 Feb 2025

    Improper Authorization vulnerability in Apache Superset. On Postgres analytic databases an attacker with SQLLab access can craft a specially designed SQL DML statement that is Incorrectly identified as a read-only query, enabling its execution. Non postgres analytics database connections and postgres analytics database connections set with a readonly user (advised) are not vulnerable.  This issue affects Apache Superset: before 4.1.0. Users are recommended to upgrade to version 4.1.0, which fixes the issue.

    Published: 12 Dec 2024
    9.2
    Critical

    CVE-2024-21575

    Last Modified: 15 Apr 2026

    ComfyUI-Impact-Pack is vulnerable to Path Traversal. The issue stems from missing validation of the `image.filename` field in a POST request sent to the `/upload/temp` endpoint added by the extension to the server. This results in writing arbitrary files to the file system which may, under some conditions, result in remote code execution (RCE).

    Published: 12 Dec 2024
    8.4
    High

    CVE-2024-28143

    Last Modified: 15 Apr 2026

    The password change function at /cgi/admin.cgi does not require the current/old password, which makes the application vulnerable to account takeover. An attacker can use this to forcefully set a new password within the -rsetpass+-aaction+- parameter for a user without knowing the old password, e.g. by exploiting a CSRF issue.

    Published: 12 Dec 2024
    8.4
    High

    CVE-2024-28146

    Last Modified: 15 Apr 2026

    The application uses several hard-coded credentials to encrypt config files during backup, to decrypt the new firmware during an update and some passwords allow a direct connection to the database server of the affected device.

    Published: 12 Dec 2024
    4.4
    Medium

    CVE-2024-50584

    Last Modified: 15 Apr 2026

    An authenticated attacker with the user/role "Poweruser" can perform an SQL injection by accessing the /class/template_io.php file and supplying malicious GET parameters. The "templates" parameter is vulnerable against blind boolean-based SQL injection attacks. SQL syntax must be injected into the JSON syntax of the templates parameter.

    Published: 12 Dec 2024
    5.9
    Medium

    CVE-2024-28145

    Last Modified: 15 Apr 2026

    An unauthenticated attacker can perform an SQL injection by accessing the /class/dbconnect.php file and supplying malicious GET parameters. The HTTP GET parameters search, table, field, and value are vulnerable. For example, one SQL injection can be performed on the parameter "field" with the UNION keyword.

    Published: 12 Dec 2024
    5.5
    Medium

    CVE-2024-28144

    Last Modified: 15 Apr 2026

    An attacker who can spoof the IP address and the User-Agent of a logged-in user can takeover the session because of flaws in the self-developed session management. If two users access the web interface from the same IP they are logged in as the other user.

    Published: 12 Dec 2024
    4.7
    Medium

    CVE-2024-36494

    Last Modified: 15 Apr 2026

    Due to missing input sanitization, an attacker can perform cross-site-scripting attacks and run arbitrary Javascript in the browser of other users. The login page at /cgi/slogin.cgi suffers from XSS due to improper input filtering of the -tsetup+-uuser parameter, which can only be exploited if the target user is not already logged in. This makes it ideal for login form phishing attempts.

    Published: 12 Dec 2024
    4.7
    Medium

    CVE-2024-36498

    Last Modified: 15 Apr 2026

    Due to missing input sanitization, an attacker can perform cross-site-scripting attacks and run arbitrary Javascript in the browser of other users. The "Edit Disclaimer Text" function of the configuration menu is vulnerable to stored XSS. Only the users Poweruser and Admin can use this function which is available at the URL https://$SCANNER/cgi/admin.cgi?-rdisclaimer+-apre The stored Javascript payload will be executed every time the ScanWizard is loaded, even in the Kiosk-mode browser. Version 7.40 implemented a fix, but it could be bypassed via URL-encoding the Javascript payload again.

    Published: 12 Dec 2024
    4.4
    Medium

    CVE-2024-12271

    Last Modified: 15 Apr 2026

    The 360 Javascript Viewer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘ref’ parameter in all versions up to, and including, 1.7.29 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.

    Published: 12 Dec 2024
    4.7
    Medium

    CVE-2024-47947

    Last Modified: 15 Apr 2026

    Due to missing input sanitization, an attacker can perform cross-site-scripting attacks and run arbitrary Javascript in the browser of other users. The "Edit Disclaimer Text" function of the configuration menu is vulnerable to stored XSS. Only the users Poweruser and Admin can use this function which is available at the URL https://$SCANNER/cgi/admin.cgi?-rdisclaimer+-apre The stored Javascript payload will be executed every time the ScanWizard is loaded, even in the Kiosk-mode browser.

    Published: 12 Dec 2024
    4.7
    Medium

    CVE-2024-28142

    Last Modified: 15 Apr 2026

    Due to missing input sanitization, an attacker can perform cross-site-scripting attacks and run arbitrary Javascript in the browser of other users. The "File Name" page (/cgi/uset.cgi?-cfilename) in the User Settings menu improperly filters the "file name" and wildcard character input field. By exploiting the wildcard character feature, attackers are able to store arbitrary Javascript code which is being triggered if the page is viewed afterwards, e.g. by higher privileged users such as admins. This attack can even be performed without being logged in because the affected functions are not fully protected. Without logging in, only the file name parameter of the "Default" User can be changed.

    Published: 12 Dec 2024
    6.2
    Medium

    CVE-2024-54122

    Last Modified: 14 Jan 2025

    Concurrent variable access vulnerability in the ability module Impact: Successful exploitation of this vulnerability may affect availability.

    Published: 12 Dec 2024
    6.2
    Medium

    CVE-2024-54119

    Last Modified: 14 Jan 2025

    Cross-process screen stack vulnerability in the UIExtension module Impact: Successful exploitation of this vulnerability may affect service confidentiality.

    Published: 12 Dec 2024
    —
    Unknown

    CVE-2024-54118

    Last Modified: 13 Dec 2024

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

    Published: 12 Dec 2024
    6.2
    Medium

    CVE-2024-54117

    Last Modified: 12 Dec 2024

    Cross-process screen stack vulnerability in the UIExtension module Impact: Successful exploitation of this vulnerability may affect service confidentiality.

    Published: 12 Dec 2024
    4.3
    Medium

    CVE-2024-54116

    Last Modified: 12 Dec 2024

    Out-of-bounds read vulnerability in the M3U8 module Impact: Successful exploitation of this vulnerability may cause features to perform abnormally.

    Published: 12 Dec 2024
    4.3
    Medium

    CVE-2024-54115

    Last Modified: 12 Dec 2024

    Out-of-bounds read vulnerability in the DASH module Impact: Successful exploitation of this vulnerability will affect availability.

    Published: 12 Dec 2024
    4.4
    Medium

    CVE-2024-54114

    Last Modified: 12 Dec 2024

    Out-of-bounds access vulnerability in playback in the DASH module Impact: Successful exploitation of this vulnerability will affect availability.

    Published: 12 Dec 2024
    6.5
    Medium

    CVE-2024-54113

    Last Modified: 18 Sept 2025

    Process residence vulnerability in abnormal scenarios in the print module Impact: Successful exploitation of this vulnerability may affect power consumption.

    Published: 12 Dec 2024
    5.5
    Medium

    CVE-2024-54112

    Last Modified: 18 Sept 2025

    Cross-process screen stack vulnerability in the UIExtension module Impact: Successful exploitation of this vulnerability may affect service confidentiality.

    Published: 12 Dec 2024
    5.7
    Medium

    CVE-2024-54111

    Last Modified: 12 Dec 2024

    Read/Write vulnerability in the image decoding module Impact: Successful exploitation of this vulnerability will affect availability.

    Published: 12 Dec 2024
    6.2
    Medium

    CVE-2024-54110

    Last Modified: 18 Sept 2025

    Cross-process screen stack vulnerability in the UIExtension module Impact: Successful exploitation of this vulnerability may affect service confidentiality.

    Published: 12 Dec 2024
    6.5
    Medium

    CVE-2024-54109

    Last Modified: 18 Sept 2025

    Read/Write vulnerability in the image decoding module Impact: Successful exploitation of this vulnerability will affect availability.

    Published: 12 Dec 2024
    6.5
    Medium

    CVE-2024-54108

    Last Modified: 18 Sept 2025

    Read/Write vulnerability in the image decoding module Impact: Successful exploitation of this vulnerability will affect availability.

    Published: 12 Dec 2024
    5.4
    Medium

    CVE-2024-8179

    Last Modified: 11 Jul 2025

    An issue has been discovered in GitLab CE/EE affecting all versions from 17.3 before 17.4.6, 17.5 before 17.5.4, and 17.6 before 17.6.2. Improper output encoding could lead to XSS if CSP is not enabled.

    Published: 12 Dec 2024
    7.5
    High

    CVE-2024-8233

    Last Modified: 11 Jul 2025

    An issue has been discovered in GitLab CE/EE affecting all versions from 9.4 before 17.4.6, 17.5 before 17.5.4, and 17.6 before 17.6.2. An attacker could cause a denial of service with requests for diff files on a commit or merge request.

    Published: 12 Dec 2024
    5.4
    Medium

    CVE-2024-8647

    Last Modified: 11 Jul 2025

    An issue was discovered in GitLab affecting all versions starting 15.2 to 17.4.6, 17.5 prior to 17.5.4, and 17.6 prior to 17.6.2. On self hosted installs, it was possible to leak the anti-CSRF-token to an external site while the Harbor integration was enabled.

    Published: 12 Dec 2024
    4.3
    Medium

    CVE-2024-9367

    Last Modified: 11 Jul 2025

    An issue was discovered in GitLab CE/EE affecting all versions starting from 13.9 before 17.4.6, 17.5 before 17.5.4, and 17.6 before 17.6.2, that allows an attacker to cause uncontrolled CPU consumption, potentially leading to a Denial of Service (DoS) condition while parsing templates to generate changelogs.

    Published: 12 Dec 2024
    6.4
    Medium

    CVE-2024-9387

    Last Modified: 11 Jul 2025

    An issue was discovered in GitLab CE/EE affecting all versions from 11.8 before 17.4.6, 17.5 before 17.5.4, and 17.6 before 17.6.2. An attacker could potentially perform an open redirect against a given releases API endpoint.

    Published: 12 Dec 2024
    7.1
    High

    CVE-2024-54107

    Last Modified: 18 Sept 2025

    Read/Write vulnerability in the image decoding module Impact: Successful exploitation of this vulnerability will affect availability.

    Published: 12 Dec 2024
    7.1
    High

    CVE-2024-54106

    Last Modified: 12 Dec 2024

    Null pointer dereference vulnerability in the image decoding module Impact: Successful exploitation of this vulnerability will affect availability.

    Published: 12 Dec 2024
    5.1
    Medium

    CVE-2024-54105

    Last Modified: 12 Dec 2024

    Read/Write vulnerability in the image decoding module Impact: Successful exploitation of this vulnerability will affect availability.

    Published: 12 Dec 2024
    6.2
    Medium

    CVE-2024-54104

    Last Modified: 12 Dec 2024

    Cross-process screen stack vulnerability in the UIExtension module Impact: Successful exploitation of this vulnerability may affect service confidentiality.

    Published: 12 Dec 2024
    6.1
    Medium

    CVE-2024-54103

    Last Modified: 18 Sept 2025

    Vulnerability of improper access control in the album module Impact: Successful exploitation of this vulnerability may affect service confidentiality.

    Published: 12 Dec 2024
    6.1
    Medium

    CVE-2024-54102

    Last Modified: 14 Jan 2025

    Race condition vulnerability in the DDR module Impact: Successful exploitation of this vulnerability may affect service confidentiality.

    Published: 12 Dec 2024
    6.2
    Medium

    CVE-2024-54101

    Last Modified: 17 Jan 2025

    Denial of service (DoS) vulnerability in the installation module Impact: Successful exploitation of this vulnerability will affect availability.

    Published: 12 Dec 2024
    6.2
    Medium

    CVE-2024-54100

    Last Modified: 14 Jan 2025

    Vulnerability of improper access control in the secure input module Impact: Successful exploitation of this vulnerability may cause features to perform abnormally.

    Published: 12 Dec 2024
    6.7
    Medium

    CVE-2024-54099

    Last Modified: 18 Sept 2025

    File replacement vulnerability on some devices Impact: Successful exploitation of this vulnerability will affect integrity and confidentiality.

    Published: 12 Dec 2024
    8.5
    High

    CVE-2024-54098

    Last Modified: 10 Jan 2025

    Service logic error vulnerability in the system service module Impact: Successful exploitation of this vulnerability may affect service integrity.

    Published: 12 Dec 2024
    7.3
    High

    CVE-2024-54097

    Last Modified: 10 Jan 2025

    Security vulnerability in the HiView module Impact: Successful exploitation of this vulnerability may affect feature implementation and integrity.

    Published: 12 Dec 2024
    5.3
    Medium

    CVE-2024-54096

    Last Modified: 10 Jan 2025

    Vulnerability of improper access control in the MTP module Impact: Successful exploitation of this vulnerability may affect integrity and accuracy.

    Published: 12 Dec 2024
    —
    Unknown

    CVE-2024-12573

    Last Modified: 15 Aug 2025

    ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2025-24752 Reason: This candidate is a reservation duplicate of CVE-2025-24752. Notes: All CVE users should reference CVE-2025-24752 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage.

    Published: 12 Dec 2024
    6.1
    Medium

    CVE-2024-12160

    Last Modified: 15 Apr 2026

    The Seraphinite Bulk Discounts for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 2.4.6. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

    Published: 12 Dec 2024
    6.4
    Medium

    CVE-2024-11760

    Last Modified: 15 Apr 2026

    The Currency Converter Widget ⚡ PRO plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'currency-converter-widget-pro' shortcode in all versions up to, and including, 1.0.6 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 12 Dec 2024
    6.5
    Medium

    CVE-2024-12333

    Last Modified: 15 Apr 2026

    The Woodmart theme for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 8.0.3. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode through the woodmart_instagram_ajax_query AJAX action. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes.

    Published: 12 Dec 2024