CVE Feed

    Dashboard / CVE

    7.8
    High

    CVE-2024-11454

    Last Modified: 26 Sept 2025

    A maliciously crafted DLL file, when placed in the same directory as an RVT file could be loaded by Autodesk Revit, and execute arbitrary code in the context of the current process due to an untrusted search patch being utilized.

    Published: 9 Dec 2024
    4.3
    Medium

    CVE-2024-45760

    Last Modified: 4 Feb 2025

    Dell OpenManage Server Administrator, versions 11.0.1.0 and prior, contains an improper access control vulnerability. A remote low privileged user could potentially exploit this vulnerability via the HTTP GET method leading to unauthorized action with elevated privileges.

    Published: 9 Dec 2024
    5.4
    Medium

    CVE-2024-45761

    Last Modified: 4 Feb 2025

    Dell OpenManage Server Administrator, versions 11.0.1.0 and prior, contains an improper input validation vulnerability. A remote low-privileged malicious user could potentially exploit this vulnerability to load any web plugins or Java class leading to the possibility of altering the behavior of certain apps/OS or Denial of Service.

    Published: 9 Dec 2024
    4.4
    Medium

    CVE-2023-7298

    Last Modified: 18 Aug 2025

    A maliciously crafted FBX file, when parsed through Autodesk FBX SDK, may force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process.

    Published: 9 Dec 2024
    7.8
    High

    CVE-2024-49600

    Last Modified: 4 Feb 2025

    Dell Power Manager (DPM), versions prior to 3.17, contain an improper access control vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Code execution and Elevation of Privileges.

    Published: 9 Dec 2024
    4.3
    Medium

    CVE-2024-38485

    Last Modified: 4 Feb 2025

    Dell ECS, versions prior to 3.8.0, contain(s) a Host Header Injection Vulnerability. A remote low-privileged attacker could potentially exploit this vulnerability to trigger redirections that leads to sensitive information leakage.

    Published: 9 Dec 2024
    4.3
    Medium

    CVE-2024-42426

    Last Modified: 20 Feb 2026

    Dell PowerScale OneFS Versions 9.5.0.x through 9.8.0.x contain an uncontrolled resource consumption vulnerability. A low privilege remote attacker could potentially exploit this vulnerability, leading to denial of service.

    Published: 9 Dec 2024
    5.6
    Medium

    CVE-2024-11991

    Last Modified: 8 Dec 2025

    Motoko's incremental garbage collector is impacted by an uninitialized memory access bug, caused by incorrect use of write barriers in a few locations. This vulnerability could potentially allow unauthorized read or write access to a Canister's memory. However, exploiting this bug requires the Canister to enable the incremental garbage collector or enhanced orthogonal persistence, which are non-default features in Motoko.

    Published: 9 Dec 2024
    4.3
    Medium

    CVE-2024-49603

    Last Modified: 20 Feb 2026

    Dell PowerScale OneFS Versions 8.2.2.x through 9.9.0.x contain an incorrect specified argument vulnerability. A remote low privileged legitimate user could potentially exploit this vulnerability, leading to information disclosure.

    Published: 9 Dec 2024
    6.5
    Medium

    CVE-2024-49602

    Last Modified: 20 Feb 2026

    Dell PowerScale OneFS Versions 8.2.2.x through 9.8.0.x contain an improper resource unlocking vulnerability. A remote low privileged attacker could potentially exploit this vulnerability, leading to denial of service.

    Published: 9 Dec 2024
    5.5
    Medium

    CVE-2024-11268

    Last Modified: 26 Aug 2025

    A maliciously crafted PDF file, when parsed through Autodesk Revit, can force an Out-of-Bounds Read. A malicious actor can leverage this vulnerability to cause a crash or could lead to an arbitrary memory leak.

    Published: 9 Dec 2024
    7.6
    High

    CVE-2024-53949

    Last Modified: 12 Feb 2025

    Improper Authorization vulnerability in Apache Superset when FAB_ADD_SECURITY_API is enabled (disabled by default). Allows for lower privilege users to use this API.  issue affects Apache Superset: from 2.0.0 before 4.1.0. Users are recommended to upgrade to version 4.1.0, which fixes the issue.

    Published: 9 Dec 2024
    5.3
    Medium

    CVE-2024-53948

    Last Modified: 11 Feb 2025

    Generation of Error Message Containing analytics metadata Information in Apache Superset. This issue affects Apache Superset: before 4.1.0. Users are recommended to upgrade to version 4.1.0, which fixes the issue.

    Published: 9 Dec 2024
    2.3
    Low

    CVE-2024-53947

    Last Modified: 15 Jul 2025

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Superset. Specifically, certain engine-specific functions are not checked, which allows attackers to bypass Apache Superset's SQL authorization. This issue is a follow-up to CVE-2024-39887 with additional disallowed PostgreSQL functions now included: query_to_xml_and_xmlschema, table_to_xml, table_to_xml_and_xmlschema. This issue affects Apache Superset: <4.1.0. Users are recommended to upgrade to version 4.1.0, which fixes the issue or add these Postgres functions to the config set DISALLOWED_SQL_FUNCTIONS.

    Published: 9 Dec 2024
    9.8
    Critical

    CVE-2024-8259

    Last Modified: 2 Jun 2026

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Eryaz Information Technologies NatraCar B2B Dealer Management Program allows SQL Injection. This issue affects NatraCar B2B Dealer Management Program: through 09.12.2024. NOTE: The vendor was contacted and it was learned that the product is not supported.

    Published: 9 Dec 2024
    5.3
    Medium

    CVE-2023-41953

    Last Modified: 9 Jun 2025

    Missing Authorization vulnerability in ProfilePress Membership Team ProfilePress.This issue affects ProfilePress: from n/a through 4.13.1.

    Published: 9 Dec 2024
    6.5
    Medium

    CVE-2024-53814

    Last Modified: 23 Apr 2026

    Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Adnan Analytify wp-analytify.This issue affects Analytify: from n/a through <= 5.4.3.

    Published: 9 Dec 2024
    6.5
    Medium

    CVE-2024-54218

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in thehp AIO Contact aio-contact.This issue affects AIO Contact: from n/a through <= 2.8.1.

    Published: 9 Dec 2024
    4.3
    Medium

    CVE-2024-52385

    Last Modified: 23 Apr 2026

    Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in wpmart Team Member team-showcase-supreme.This issue affects Team Member: from n/a through <= 7.4.

    Published: 9 Dec 2024
    5.3
    Medium

    CVE-2024-52391

    Last Modified: 28 Apr 2026

    Missing Authorization vulnerability in Genetech Pie Register Premium.This issue affects Pie Register Premium: from n/a before 3.8.3.3.

    Published: 9 Dec 2024
    5.3
    Medium

    CVE-2024-52480

    Last Modified: 29 Apr 2026

    Missing Authorization vulnerability in Astoundify Jobify jobify.This issue affects Jobify: from n/a through < 4.3.0.

    Published: 9 Dec 2024
    4.3
    Medium

    CVE-2024-53785

    Last Modified: 28 Apr 2026

    Missing Authorization vulnerability in Alexander Volkov Chatter.This issue affects Chatter: from n/a through 1.0.1.

    Published: 9 Dec 2024
    4.3
    Medium

    CVE-2024-53816

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in Themeum Tutor LMS Elementor Addons tutor-lms-elementor-addons.This issue affects Tutor LMS Elementor Addons: from n/a through <= 2.1.5.

    Published: 9 Dec 2024
    5.4
    Medium

    CVE-2024-54217

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in reputeinfosystems ARForms arforms.This issue affects ARForms: from n/a through <= 6.4.1.

    Published: 9 Dec 2024
    6.5
    Medium

    CVE-2024-53791

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ogun Labs Lenxel Core for Lenxel(LNX) LMS lenxel-core allows DOM-Based XSS.This issue affects Lenxel Core for Lenxel(LNX) LMS: from n/a through <= 1.3.9.

    Published: 9 Dec 2024
    5.4
    Medium

    CVE-2024-53798

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in BAKKBONE Australia FloristPress bakkbone-florist-companion.This issue affects FloristPress: from n/a through <= 7.3.0.

    Published: 9 Dec 2024
    6.5
    Medium

    CVE-2024-53818

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPXPO PostX ultimate-post.This issue affects PostX: from n/a through <= 4.1.15.

    Published: 9 Dec 2024
    7.1
    High

    CVE-2024-54219

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in thehp AIO Contact aio-contact.This issue affects AIO Contact: from n/a through <= 2.8.1.

    Published: 9 Dec 2024
    7.1
    High

    CVE-2024-54220

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in roninwp FAT Services Booking fat-services-booking allows Stored XSS.This issue affects FAT Services Booking: from n/a through <= 5.6.

    Published: 9 Dec 2024
    6.5
    Medium

    CVE-2024-54247

    Last Modified: 28 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ABCBiz ABCBiz Addons and Templates for Elementor allows Stored XSS.This issue affects ABCBiz Addons and Templates for Elementor: from n/a through 2.0.2.

    Published: 9 Dec 2024
    6.5
    Medium

    CVE-2024-54253

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Xpro Xpro Elementor Addons xpro-elementor-addons.This issue affects Xpro Elementor Addons: from n/a through <= 1.4.6.5.

    Published: 9 Dec 2024
    6.3
    Medium

    CVE-2024-54254

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in Kofi Mokome Message Filter for Contact Form 7 cf7-message-filter.This issue affects Message Filter for Contact Form 7: from n/a through <= 1.6.3.

    Published: 9 Dec 2024
    5.3
    Medium

    CVE-2024-53819

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in BoldGrid Client Invoicing by Sprout Invoices sprout-invoices.This issue affects Client Invoicing by Sprout Invoices: from n/a through <= 20.8.0.

    Published: 9 Dec 2024
    9.3
    Critical

    CVE-2024-54215

    Last Modified: 23 Apr 2026

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in roninwp Revy revy.This issue affects Revy: from n/a through <= 1.18.

    Published: 9 Dec 2024
    10
    Critical

    CVE-2024-53822

    Last Modified: 28 Apr 2026

    Unrestricted Upload of File with Dangerous Type vulnerability in Genetech Pie Register Premium.This issue affects Pie Register Premium: from n/a before 3.8.3.3.

    Published: 9 Dec 2024
    7.5
    High

    CVE-2024-53790

    Last Modified: 23 Apr 2026

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Ogun Labs Lenxel Core for Lenxel(LNX) LMS lenxel-core allows PHP Local File Inclusion.This issue affects Lenxel Core for Lenxel(LNX) LMS: from n/a through <= 1.3.9.

    Published: 9 Dec 2024
    9.8
    Critical

    CVE-2024-43222

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in SeventhQueen Sweet Date sweetdate allows Privilege Escalation.This issue affects Sweet Date: from n/a through <= 3.7.3.

    Published: 9 Dec 2024
    4.3
    Medium

    CVE-2023-48277

    Last Modified: 29 Apr 2026

    Missing Authorization vulnerability in SuperPWA Super Progressive Web Apps super-progressive-web-apps allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Super Progressive Web Apps: from n/a through <= 2.2.21.

    Published: 9 Dec 2024
    4.3
    Medium

    CVE-2024-54227

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in Dotstore Minimum and Maximum Quantity for WooCommerce min-and-max-quantity-for-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Minimum and Maximum Quantity for WooCommerce: from n/a through <= 2.0.0.

    Published: 9 Dec 2024
    6.5
    Medium

    CVE-2024-54251

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in prodigycommerce Prodigy Commerce prodigy-commerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Prodigy Commerce: from n/a through <= 3.1.2.

    Published: 9 Dec 2024
    6.5
    Medium

    CVE-2024-54224

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in quomodosoft ElementsReady Addons for Elementor element-ready-lite allows DOM-Based XSS.This issue affects ElementsReady Addons for Elementor: from n/a through <= 6.4.7.

    Published: 9 Dec 2024
    6.5
    Medium

    CVE-2024-54228

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Weboccult Technologies Pvt Ltd Wot Elementor Widgets wot-elementor-widgets allows DOM-Based XSS.This issue affects Wot Elementor Widgets: from n/a through <= 1.0.1.

    Published: 9 Dec 2024
    6.5
    Medium

    CVE-2024-54230

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Masud Hasan Unlock Addons for Elementor unlock-addons-for-elementor allows DOM-Based XSS.This issue affects Unlock Addons for Elementor: from n/a through <= 2.2.4.

    Published: 9 Dec 2024
    6.5
    Medium

    CVE-2024-54232

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in RRDevs RRAddons for Elementor rrdevs-for-elementor allows Stored XSS.This issue affects RRAddons for Elementor: from n/a through <= 1.1.0.

    Published: 9 Dec 2024
    6.5
    Medium

    CVE-2024-54260

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in blazethemes News Kit Elementor Addons news-kit-elementor-addons allows Stored XSS.This issue affects News Kit Elementor Addons: from n/a through <= 1.4.2.

    Published: 9 Dec 2024
    7.1
    High

    CVE-2024-54226

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in karlkiesinger Country Blocker country-blocker allows Stored XSS.This issue affects Country Blocker: from n/a through <= 3.2.

    Published: 9 Dec 2024
    4.7
    Medium

    CVE-2024-54255

    Last Modified: 23 Apr 2026

    URL Redirection to Untrusted Site ('Open Redirect') vulnerability in aviplugins.com Login Widget With Shortcode login-sidebar-widget allows Phishing.This issue affects Login Widget With Shortcode: from n/a through <= 6.1.2.

    Published: 9 Dec 2024
    7.5
    High

    CVE-2024-54225

    Last Modified: 23 Apr 2026

    Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in codegearthemes Designer designer allows PHP Local File Inclusion.This issue affects Designer: from n/a through <= 1.4.1.

    Published: 9 Dec 2024
    5.3
    Medium

    CVE-2024-54223

    Last Modified: 23 Apr 2026

    Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in reputeinfosystems ARForms Form Builder arforms-form-builder allows Code Injection.This issue affects ARForms Form Builder: from n/a through <= 1.7.1.

    Published: 9 Dec 2024
    7.5
    High

    CVE-2023-22701

    Last Modified: 28 Apr 2026

    Missing Authorization vulnerability in Shopfiles Ltd Ebook Store allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Ebook Store: from n/a through 5.775.

    Published: 9 Dec 2024