CVE Feed

    Dashboard / CVE

    7.2
    High

    CVE-2024-54928

    Last Modified: 24 Apr 2025

    kashipara E-learning Management System v1.0 is vulnerable to SQL Injection in /admin/delete_teacher.php,

    Published: 9 Dec 2024
    7.2
    High

    CVE-2024-54929

    Last Modified: 18 Mar 2025

    KASHIPARA E-learning Management System v1.0 is vulnerable to SQL Injection in /admin/delete_subject.php.

    Published: 9 Dec 2024
    7.2
    High

    CVE-2024-54930

    Last Modified: 12 Dec 2024

    Kashipara E-learning Management System v1.0 is vulnerable to SQL Injection in /admin/delete_student.php.

    Published: 9 Dec 2024
    9.8
    Critical

    CVE-2024-54931

    Last Modified: 24 Apr 2025

    A SQL Injection was found in /admin/delete_event.php in kashipara E-learning Management System v1.0, which allows remote attackers to execute arbitrary SQL commands to get unauthorized database access via the id parameter.

    Published: 9 Dec 2024
    9.8
    Critical

    CVE-2024-54932

    Last Modified: 24 Apr 2025

    Kashipara E-learning Management System v1.0 is vulnerable to SQL Injection in /admin/delete_department.php.

    Published: 9 Dec 2024
    7.2
    High

    CVE-2024-54933

    Last Modified: 12 Dec 2024

    Kashipara E-learning Management System v1.0 is vulnerable to SQL Injection in /admin/delete_content.php.

    Published: 9 Dec 2024
    9.8
    Critical

    CVE-2024-54934

    Last Modified: 24 Apr 2025

    Kashipara E-learning Management System v1.0 is vulnerable to SQL Injection in /admin/delete_class.php.

    Published: 9 Dec 2024
    5.4
    Medium

    CVE-2024-54935

    Last Modified: 11 Dec 2024

    A Stored Cross-Site Scripting (XSS) vulnerability was found in /send_message_teacher_to_student.php of kashipara E-learning Management System v1.0. This vulnerability allows remote attackers to execute arbitrary scripts via the my_message parameter.

    Published: 9 Dec 2024
    5.4
    Medium

    CVE-2024-54936

    Last Modified: 10 Dec 2024

    A Stored Cross-Site Scripting (XSS) vulnerability was found in /send_message.php of Kashipara E-learning Management System v1.0. This vulnerability allows remote attackers to execute arbitrary scripts via the my_message parameter.

    Published: 9 Dec 2024
    7.5
    High

    CVE-2024-54938

    Last Modified: 24 Apr 2025

    A Directory Listing issue was found in Kashipara E-Learning Management System v1.0, which allows remote attackers to access sensitive files and directories via /admin/uploads.

    Published: 9 Dec 2024
    9.8
    Critical

    CVE-2024-55564

    Last Modified: 15 Apr 2026

    The POSIX::2008 package before 0.24 for Perl has a potential _execve50c env buffer overflow.

    Published: 9 Dec 2024
    5.3
    Medium

    CVE-2024-55563

    Last Modified: 22 May 2025

    Bitcoin Core through 27.2 allows transaction-relay jamming via an off-chain protocol attack, a related issue to CVE-2024-52913. For example, the outcome of an HTLC (Hashed Timelock Contract) can be changed because a flood of transaction traffic prevents propagation of certain Lightning channel transactions.

    Published: 9 Dec 2024
    5.3
    Medium

    CVE-2024-12346

    Last Modified: 15 Apr 2026

    A vulnerability has been found in Talentera up to 20241128 and classified as problematic. This vulnerability affects unknown code of the file /app/control/byt_cv_manager. The manipulation of the argument redirect_url leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The provided PoC only works in Mozilla Firefox. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 8 Dec 2024
    4.8
    Medium

    CVE-2024-12355

    Last Modified: 12 Dec 2024

    A vulnerability has been found in SourceCodester Phone Contact Manager System 1.0 and classified as problematic. Affected by this vulnerability is the function ContactBook::adding of the file ContactBook.cpp. The manipulation leads to improper input validation. The attack needs to be approached locally. The exploit has been disclosed to the public and may be used.

    Published: 8 Dec 2024
    4.8
    Medium

    CVE-2024-12354

    Last Modified: 10 Dec 2024

    A vulnerability, which was classified as critical, was found in SourceCodester Phone Contact Manager System 1.0. Affected is the function UserInterface::MenuDisplayStart of the component User Menu. The manipulation leads to buffer overflow. It is possible to launch the attack on the local host. The exploit has been disclosed to the public and may be used.

    Published: 8 Dec 2024
    4.8
    Medium

    CVE-2024-12353

    Last Modified: 12 Dec 2024

    A vulnerability, which was classified as problematic, has been found in SourceCodester Phone Contact Manager System 1.0. This issue affects the function UserInterface::MenuDisplayStart of the component User Menu. The manipulation of the argument name leads to improper input validation. Attacking locally is a requirement. The exploit has been disclosed to the public and may be used.

    Published: 8 Dec 2024
    5.3
    Medium

    CVE-2024-12352

    Last Modified: 10 Dec 2024

    A vulnerability classified as problematic was found in TOTOLINK EX1800T 9.1.0cu.2112_B20220316. This vulnerability affects the function sub_40662C of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument ssid leads to stack-based buffer overflow. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

    Published: 8 Dec 2024
    5.3
    Medium

    CVE-2024-12351

    Last Modified: 11 Dec 2024

    A vulnerability classified as critical has been found in JFinalCMS 1.0. This affects the function findPage of the file src\main\java\com\cms\entity\ContentModel.java of the component File Content Handler. The manipulation of the argument name leads to sql injection. It is possible to initiate the attack remotely.

    Published: 8 Dec 2024
    5.3
    Medium

    CVE-2024-12350

    Last Modified: 11 Dec 2024

    A vulnerability was found in JFinalCMS 1.0. It has been rated as critical. Affected by this issue is the function update of the file \src\main\java\com\cms\controller\admin\TemplateController.java of the component Template Handler. The manipulation of the argument content leads to command injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

    Published: 8 Dec 2024
    6.9
    Medium

    CVE-2024-12349

    Last Modified: 11 Dec 2024

    A vulnerability was found in JFinalCMS 1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /admin/tag/save. The manipulation leads to cross-site request forgery. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

    Published: 8 Dec 2024
    5.3
    Medium

    CVE-2024-12348

    Last Modified: 4 Jun 2025

    A vulnerability was found in Guizhou Xiaoma Technology jpress 5.1.2. It has been classified as problematic. Affected is the function AttachmentUtils.isUnSafe of the file /commons/attachment/upload of the component Attachment Upload Handler. The manipulation of the argument files[] leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

    Published: 8 Dec 2024
    6.9
    Medium

    CVE-2024-12347

    Last Modified: 11 Sept 2025

    A vulnerability was found in Guangzhou Huayi Intelligent Technology Jeewms up to 1.0.0 and classified as critical. This issue affects some unknown processing of the file /jeewms_war/webpage/system/druid/index.html of the component Druid Monitoring Interface. The manipulation leads to improper authorization. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 8 Dec 2024
    5.3
    Medium

    CVE-2024-12344

    Last Modified: 10 Dec 2024

    A vulnerability, which was classified as critical, was found in TP-Link VN020 F3v(T) TT_V6.2.1021. This affects an unknown part of the component FTP USER Command Handler. The manipulation leads to memory corruption. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

    Published: 8 Dec 2024
    7.1
    High

    CVE-2024-12342

    Last Modified: 15 Apr 2026

    A vulnerability was found in TP-Link VN020 F3v(T) TT_V6.2.1021. It has been rated as critical. This issue affects some unknown processing of the file /control/WANIPConnection of the component Incomplete SOAP Request Handler. The manipulation leads to denial of service. The attack can only be initiated within the local network. The exploit has been disclosed to the public and may be used.

    Published: 8 Dec 2024
    7.1
    High

    CVE-2024-12343

    Last Modified: 10 Dec 2024

    A vulnerability classified as critical has been found in TP-Link VN020 F3v(T) TT_V6.2.1021. Affected is an unknown function of the file /control/WANIPConnection of the component SOAP Request Handler. The manipulation of the argument NewConnectionType leads to buffer overflow. The attack needs to be done within the local network. The exploit has been disclosed to the public and may be used.

    Published: 8 Dec 2024
    9.8
    Critical

    CVE-2024-12209

    Last Modified: 15 Apr 2026

    The WP Umbrella: Update Backup Restore & Monitoring plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.17.0 via the 'filename' parameter of the 'umbrella-restore' action. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where images and other “safe” file types can be uploaded and included.

    Published: 8 Dec 2024
    9.8
    Critical

    CVE-2024-55560

    Last Modified: 15 Apr 2026

    MailCleaner before 28d913e has default values of ssh_host_dsa_key, ssh_host_rsa_key, and ssh_host_ed25519_key that persist after installation.

    Published: 8 Dec 2024
    6.4
    Medium

    CVE-2024-47107

    Last Modified: 25 Jul 2025

    IBM QRadar SIEM 7.5 is vulnerable to stored cross-site scripting. This vulnerability allows authenticated users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.

    Published: 7 Dec 2024
    5.3
    Medium

    CVE-2024-41762

    Last Modified: 31 Jan 2025

    IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to a denial of service as the server may crash under certain conditions with a specially crafted query.

    Published: 7 Dec 2024
    5.3
    Medium

    CVE-2024-37071

    Last Modified: 9 Aug 2025

    IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 could allow an authenticated user to cause a denial of service with a specially crafted query due to improper memory allocation.

    Published: 7 Dec 2024
    7.8
    High

    CVE-2024-47115

    Last Modified: 21 Jan 2025

    IBM AIX 7.2, 7.3 and VIOS 3.1 and 4.1 could allow a local user to execute arbitrary commands on the system due to improper neutralization of input.

    Published: 7 Dec 2024
    6.1
    Medium

    CVE-2024-11457

    Last Modified: 15 Apr 2026

    The Feedpress Generator – External RSS Frontend Customizer plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'tab' parameter in all versions up to, and including, 1.2.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

    Published: 7 Dec 2024
    6.4
    Medium

    CVE-2024-11380

    Last Modified: 15 Apr 2026

    The Mini Program API plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'qvideo' shortcode in all versions up to, and including, 1.4.5 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 7 Dec 2024
    8.8
    High

    CVE-2024-11501

    Last Modified: 15 Apr 2026

    The Gallery plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.3 via deserialization of untrusted input from wd_gallery_$id parameter. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject a PHP Object. No known POP chain is present in the vulnerable software. If a POP chain is present via an additional plugin or theme installed on the target system, it could allow the attacker to delete arbitrary files, retrieve sensitive data, or execute code.

    Published: 7 Dec 2024
    6.1
    Medium

    CVE-2024-11464

    Last Modified: 15 Apr 2026

    The Easy Code Snippets plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'page' parameter in all versions up to, and including, 1.0.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

    Published: 7 Dec 2024
    6.1
    Medium

    CVE-2024-12128

    Last Modified: 15 Apr 2026

    The Simple Ecommerce Shopping Cart Plugin- Sell products through Paypal plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘monthly_sales_current_year’ parameter in all versions up to, and including, 3.1.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

    Published: 7 Dec 2024
    7.2
    High

    CVE-2024-11010

    Last Modified: 15 Apr 2026

    The FileOrganizer – Manage WordPress and Website Files plugin for WordPress is vulnerable to Local JavaScript File Inclusion in all versions up to, and including, 1.1.4 via the 'default_lang' parameter. This makes it possible for authenticated attackers, with Administrator-level access and above, to include and execute arbitrary JavaScript files on the server, allowing the execution of any JavaScript code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where images and other “safe” file types can be uploaded and included.

    Published: 7 Dec 2024
    6.1
    Medium

    CVE-2024-11367

    Last Modified: 15 Apr 2026

    The Smoove connector for Elementor forms plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 4.1.0. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

    Published: 7 Dec 2024
    7.5
    High

    CVE-2024-12270

    Last Modified: 15 Apr 2026

    The Beautiful taxonomy filters plugin for WordPress is vulnerable to SQL Injection via the 'selects[0][term]' parameter in all versions up to, and including, 2.4.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

    Published: 7 Dec 2024
    6.1
    Medium

    CVE-2024-11374

    Last Modified: 15 Apr 2026

    The TWChat – Send or receive messages from users plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of remove_query_arg without appropriate escaping on the URL in all versions up to, and including, 4.0.4. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

    Published: 7 Dec 2024
    5.4
    Medium

    CVE-2024-12253

    Last Modified: 15 Apr 2026

    The Simple Ecommerce Shopping Cart Plugin- Sell products through Paypal plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the 'save_settings', 'export_csv', and 'simpleecommcart-action' actions in all versions up to, and including, 3.1.2. This makes it possible for authenticated attackers, with subscriber-level access and above, to update the plugins settings and retrieve order and log data (which is also accessible to unauthenticated users).

    Published: 7 Dec 2024
    4.8
    Medium

    CVE-2024-11183

    Last Modified: 6 May 2025

    The Simple Side Tab WordPress plugin before 2.2.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

    Published: 7 Dec 2024
    5.3
    Medium

    CVE-2024-7894

    Last Modified: 15 Apr 2026

    The If Menu plugin for WordPress is vulnerable to unauthorized modification of the plugin's license key due to a missing capability check on the 'actions' function in versions up to, and including, 0.19.1. This makes it possible for unauthenticated attackers to modify delete or modify the license key.

    Published: 7 Dec 2024
    6.8
    Medium

    CVE-2024-8679

    Last Modified: 15 Apr 2026

    The Library Management System – Manage e-Digital Books Library plugin for WordPress is vulnerable to SQL Injection via the ‘value' parameter of the owt_lib_handler AJAX action in all versions up to, and including, 3.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with Administrator-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

    Published: 7 Dec 2024
    4.3
    Medium

    CVE-2024-12115

    Last Modified: 8 Apr 2026

    The Poll Maker – Versus Polls, Anonymous Polls, Image Polls plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 5.5.4. This is due to missing or incorrect nonce validation on the duplicate_poll() function. This makes it possible for unauthenticated attackers to duplicate polls via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

    Published: 7 Dec 2024
    6.1
    Medium

    CVE-2024-12167

    Last Modified: 8 Apr 2026

    The Shortcodes Blocks Creator Ultimate plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the '_wpnonce' parameter in all versions up to, and including, 2.2.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

    Published: 7 Dec 2024
    6.1
    Medium

    CVE-2024-12165

    Last Modified: 15 Apr 2026

    The Mollie for Contact Form 7 plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'page' parameter in all versions up to, and including, 5.0.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

    Published: 7 Dec 2024
    4.3
    Medium

    CVE-2024-11353

    Last Modified: 15 Apr 2026

    The SMS for Lead Capture Forms plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the delete_message() function in all versions up to, and including, 1.1.0. This makes it possible for authenticated attackers, with Subscriber-level access and above, to delete arbitrary messages.

    Published: 7 Dec 2024
    6.1
    Medium

    CVE-2024-12257

    Last Modified: 15 Apr 2026

    The CardGate Payments for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'page' parameter in all versions up to, and including, 3.2.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

    Published: 7 Dec 2024
    6.4
    Medium

    CVE-2024-11904

    Last Modified: 15 Apr 2026

    The 코드엠샵 소셜톡 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'msntt_add_plus_talk' shortcode in all versions up to, and including, 1.2.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 7 Dec 2024