CVE Feed

    Dashboard / CVE

    6.9
    Medium

    CVE-2024-12228

    Last Modified: 10 Dec 2024

    A vulnerability classified as critical has been found in PHPGurukul Complaint Management System 1.0. Affected is an unknown function of the file /admin/user-search.php. The manipulation of the argument search leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

    Published: 5 Dec 2024
    6.1
    Medium

    CVE-2024-11324

    Last Modified: 15 Apr 2026

    The Accounting for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 1.6.6. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

    Published: 5 Dec 2024
    4.3
    Medium

    CVE-2024-10777

    Last Modified: 15 Apr 2026

    The AnyWhere Elementor plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.2.11 via the 'INSERT_ELEMENTOR' shortcode due to insufficient restrictions on which posts can be included. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract data from private or draft posts created by Elementor that they should not have access to.

    Published: 5 Dec 2024
    6.4
    Medium

    CVE-2024-10056

    Last Modified: 15 Apr 2026

    The Contact Form Builder by vcita plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's livesite-pay shortcode in all versions up to, and including, 4.10.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 5 Dec 2024
    6.4
    Medium

    CVE-2024-11779

    Last Modified: 15 Apr 2026

    The WIP WooCarousel Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wip_woocarousel_products_carousel' shortcode in all versions up to, and including, 1.1.6 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 5 Dec 2024
    6.4
    Medium

    CVE-2024-10848

    Last Modified: 15 Apr 2026

    The NewsMunch theme for WordPress is vulnerable to Stored Cross-Site Scripting via a malicious display name in all versions up to, and including, 1.0.35 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 5 Dec 2024
    4.3
    Medium

    CVE-2024-11341

    Last Modified: 15 Apr 2026

    The Simple Redirection plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.5. This is due to missing or incorrect nonce validation on the settings_page() function. This makes it possible for unauthenticated attackers to update the plugin's settings and redirect all site visitors via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

    Published: 5 Dec 2024
    6.4
    Medium

    CVE-2024-11420

    Last Modified: 8 Apr 2026

    The Blocksy theme for WordPress is vulnerable to Stored Cross-Site Scripting via the Contact Info Block link parameter in all versions up to, and including, 2.0.77 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 5 Dec 2024
    9.3
    Critical

    CVE-2024-11317

    Last Modified: 10 Apr 2025

    Session Fixation vulnerabilities allow an attacker to fix a users session identifier before login providing an opportunity for session takeover on a product.  Affected products: ABB ASPECT - Enterprise v3.08.02; NEXUS Series v3.08.02; MATRIX Series v3.08.02

    Published: 5 Dec 2024
    8.7
    High

    CVE-2024-11316

    Last Modified: 10 Apr 2025

    Fileszie Check vulnerabilities allow a malicious user to bypass size limits or overload to the product.  Affected products: ABB ASPECT - Enterprise v3.08.02; NEXUS Series v3.08.02; MATRIX Series v3.08.02

    Published: 5 Dec 2024
    5.3
    Medium

    CVE-2024-10937

    Last Modified: 15 Apr 2026

    The Related Posts, Inline Related Posts, Contextual Related Posts, Related Content By PickPlugins plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.0.58 via the wp_ajax_nopriv_related_post_ajax_get_post_ids AJAX action. This makes it possible for unauthenticated attackers to extract sensitive data including titles of posts in draft status.

    Published: 5 Dec 2024
    8.8
    High

    CVE-2024-11429

    Last Modified: 15 Apr 2026

    The Free Responsive Testimonials, Social Proof Reviews, and Customer Reviews – Stars Testimonials plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.3.3 via the 'stars-testimonials-with-slider-and-masonry-grid' shortcode. This makes it possible for authenticated attackers, with contributor-level access and above, to include and execute arbitrary PHP files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where PHP files can be uploaded and included.

    Published: 5 Dec 2024
    3.1
    Low

    CVE-2024-42195

    Last Modified: 21 Apr 2025

    HCL DevOps Deploy / HCL Launch is vulnerable to HTML injection. This vulnerability may allow a user to embed arbitrary HTML tags in the Web UI potentially leading to sensitive information disclosure.

    Published: 5 Dec 2024
    6.4
    Medium

    CVE-2024-10178

    Last Modified: 8 Apr 2026

    The Gutentor – Gutenberg Blocks – Page Builder for Gutenberg Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Countdown widget in all versions up to, and including, 3.3.9 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 5 Dec 2024
    6.4
    Medium

    CVE-2024-10881

    Last Modified: 15 Apr 2026

    The LUNA RADIO PLAYER plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'lunaradio' shortcode in versions up to, and including, 6.24.11.07 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 5 Dec 2024
    3.6
    Low

    CVE-2024-54014

    Last Modified: 15 Apr 2026

    Improper authorization in handler for custom URL scheme issue in 'Skylark' App for Android 6.2.13 and earlier and 'Skylark' App for iOS 6.2.13 and earlier allows an attacker to lead the application to access an arbitrary web site via another application installed on the user's device.

    Published: 5 Dec 2024
    7.5
    High

    CVE-2024-53490

    Last Modified: 15 Apr 2026

    Favorites-web 1.3.0 favorites-web has a directory traversal vulnerability in SecurityFilter.java.

    Published: 5 Dec 2024
    9.8
    Critical

    CVE-2024-53442

    Last Modified: 15 Apr 2026

    whapa v1.59 is vulnerable to Command Injection via a crafted filename to the HTML reports component.

    Published: 5 Dec 2024
    7.8
    High

    CVE-2024-30964

    Last Modified: 15 Apr 2026

    Insecure Permissions vulnerability in Open Robotics Robotic Operating System 2 (ROS2) navigation2- ROS2-humble and navigation 2-humble allows a local attacker to execute arbitrary code via the initial_pose_sub thread created by nav2_bt_navigator

    Published: 5 Dec 2024
    9.1
    Critical

    CVE-2023-50913

    Last Modified: 15 Apr 2026

    Oxide control plane software before 5 allows SSRF.

    Published: 5 Dec 2024
    8.4
    High

    CVE-2024-53589

    Last Modified: 15 Apr 2026

    GNU objdump 2.43 is vulnerable to Buffer Overflow in the BFD (Binary File Descriptor) library's handling of tekhex format files.

    Published: 5 Dec 2024
    7.5
    High

    CVE-2024-53523

    Last Modified: 15 Apr 2026

    JSFinder commit d70ab9bc5221e016c08cffaf0d9ac79646c90645 is vulnerable to Directory Traversal in the find_by_file function.

    Published: 5 Dec 2024
    8.8
    High

    CVE-2024-53472

    Last Modified: 9 Apr 2025

    WeGIA v3.2.0 was discovered to contain a Cross-Site Request Forgery (CSRF).

    Published: 5 Dec 2024
    6.1
    Medium

    CVE-2024-53471

    Last Modified: 9 Apr 2025

    Multiple stored cross-site scripting (XSS) vulnerabilities in the component /configuracao/meio_pagamento.php of WeGIA v3.2.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the id or name parameter.

    Published: 5 Dec 2024
    6.1
    Medium

    CVE-2024-53470

    Last Modified: 9 Apr 2025

    Multiple stored cross-site scripting (XSS) vulnerabilities in the component /configuracao/gateway_pagamento.php of WeGIA v3.2.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the id or name parameter.

    Published: 5 Dec 2024
    5.4
    Medium

    CVE-2024-53457

    Last Modified: 7 Apr 2025

    A stored cross-site scripting (XSS) vulnerability in the Device Settings section of LibreNMS v24.9.0 to v24.10.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Display Name parameter.

    Published: 5 Dec 2024
    4.3
    Medium

    CVE-2024-54679

    Last Modified: 5 Sept 2025

    CyberPanel (aka Cyber Panel) before 6778ad1 does not require the FilemanagerAdmin capability for restartMySQL actions.

    Published: 5 Dec 2024
    7.5
    High

    CVE-2024-38910

    Last Modified: 15 Apr 2026

    Open Robotics Robotic Operating System 2 (ROS2) and Nav2 humble version was discovered to contain a use-after-free in the nav2_amcl process. This vulnerability is triggered via sending a request to change dynamic parameters.

    Published: 5 Dec 2024
    9.1
    Critical

    CVE-2024-38920

    Last Modified: 15 Apr 2026

    Open Robotics Robotic Operating System 2 (ROS2) and Nav2 humble versions were discovered to contain a use-after-free via the nav2_amcl process. This vulnerability is triggerd via remotely sending a request for change the value of dynamic-parameter`/amcl max_beams` .

    Published: 5 Dec 2024
    7.3
    High

    CVE-2024-37862

    Last Modified: 15 Apr 2026

    Buffer Overflow vulnerability in Open Robotic Robotic Operating System 2 ROS2 navigation2- ROS2-humble&& navigation2-humble allows a local attacker to execute arbitrary code via a crafted .yaml file to the nav2_planner process.

    Published: 5 Dec 2024
    9.8
    Critical

    CVE-2023-48010

    Last Modified: 15 Apr 2026

    STMicroelectronics SPC58 is vulnerable to Missing Protection Mechanism for Alternate Hardware Interface. Code running as Supervisor on the SPC58 PowerPC microcontrollers may disable the System Memory Protection Unit and gain unabridged read/write access to protected assets.

    Published: 5 Dec 2024
    7.8
    High

    CVE-2024-30963

    Last Modified: 15 Apr 2026

    Buffer Overflow vulnerability in Open Robotics Robotic Operating System 2 (ROS2) navigation2- ROS2-humble and navigation 2-humble allows a local attacker to execute arbitrary code via a crafted script.

    Published: 5 Dec 2024
    7.8
    High

    CVE-2024-30961

    Last Modified: 18 Dec 2024

    Insecure Permissions vulnerability in Open Robotics Robotic Operating System 2 (ROS2) navigation2- ROS2-humble and navigation 2-humble allows a local attacker to execute arbitrary code via the error-thrown mechanism in nav2_bt_navigator.

    Published: 5 Dec 2024
    7.8
    High

    CVE-2024-30962

    Last Modified: 9 Jan 2025

    Buffer Overflow vulnerability in Open Robotics Robotic Operating System 2 (ROS2) navigation2- ROS2-humble and navigation 2-humble allows a local attacker to execute arbitrary code via the nav2_amcl process

    Published: 5 Dec 2024
    7.3
    High

    CVE-2024-37860

    Last Modified: 15 Apr 2026

    Buffer Overflow vulnerability in Open Robotic Operating System 2 ROS2 navigation2- ROS2-humble&& navigation2-humble allows a local attacker to execute arbitrary code via a crafted .yaml file to the nav2_amcl process

    Published: 5 Dec 2024
    9.8
    Critical

    CVE-2024-37861

    Last Modified: 15 Apr 2026

    Open Robotics Robotic Operating System 2 (ROS2) and Nav2 humble versions were discovered to contain a buffer overflow via the nav2_amcl process. This vulnerability is triggered via sending a crafted .yaml file.

    Published: 5 Dec 2024
    9.8
    Critical

    CVE-2024-37863

    Last Modified: 15 Apr 2026

    Open Robotics Robotic Operating System 2 (ROS2) and Nav2 humble versions were discovered to contain a buffer overflow via the nav2_amcl process. This vulnerability is triggered via sending a crafted .yaml file.

    Published: 5 Dec 2024
    9.8
    Critical

    CVE-2024-41579

    Last Modified: 15 Apr 2026

    DTStack Taier 1.4.0 allows remote attackers to specify the jobName parameter in the console listNames function to cause a SQL injection vulnerability

    Published: 5 Dec 2024
    6.7
    Medium

    CVE-2018-9463

    Last Modified: 19 Dec 2024

    In sw49408_irq_runtime_engine_debug of touch_sw49408.c, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.

    Published: 4 Dec 2024
    6.7
    Medium

    CVE-2018-9462

    Last Modified: 19 Dec 2024

    In store_cmd of ftm4_pdc.c, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.

    Published: 4 Dec 2024
    6.7
    Medium

    CVE-2018-9439

    Last Modified: 19 Dec 2024

    In __unregister_prot_hook and packet_release of af_packet.c, there is a possible use-after-free due to improper locking. This could lead to local escalation of privilege in the kernel with System execution privileges needed. User interaction is not needed for exploitation.

    Published: 4 Dec 2024
    10
    Critical

    CVE-2018-9416

    Last Modified: 18 Dec 2024

    In sg_remove_scat of scsi/sg.c, there is a possible memory corruption due to an unusual root cause. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.

    Published: 4 Dec 2024
    4.4
    Medium

    CVE-2018-9408

    Last Modified: 19 Dec 2024

    In m3326_gps_write and m3326_gps_read of gps.s, there is a possible Out Of Bounds Read due to a missing bounds check. This could lead to a local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.

    Published: 4 Dec 2024
    5.5
    Medium

    CVE-2018-9407

    Last Modified: 19 Dec 2024

    In emmc_rpmb_ioctl of emmc_rpmb.c, there is an Information Disclosure due to a Missing Bounds Check. This could lead to Information Disclosure of kernel data.

    Published: 4 Dec 2024
    6.7
    Medium

    CVE-2018-9404

    Last Modified: 19 Dec 2024

    In oemCallback of ril.cpp, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.

    Published: 4 Dec 2024
    6.7
    Medium

    CVE-2018-9403

    Last Modified: 19 Dec 2024

    In the MTK_FLP_MSG_HAL_DIAG_REPORT_DATA_NTF handler of flp2hal_- interface.c, there is a possible stack buffer overflow due to a missing bounds check. This could lead to local escalation of privilege in a privileged process with System execution privileges needed. User interaction is not needed for exploitation.

    Published: 4 Dec 2024
    7.8
    High

    CVE-2018-9402

    Last Modified: 19 Dec 2024

    In multiple functions of gl_proc.c, there is a buffer overwrite due to a missing bounds check. This could lead to escalation of privileges in the kernel.

    Published: 4 Dec 2024
    9.3
    Critical

    CVE-2024-54221

    Last Modified: 23 Apr 2026

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in roninwp FAT Services Booking fat-services-booking.This issue affects FAT Services Booking: from n/a through <= 5.6.

    Published: 4 Dec 2024
    6.7
    Medium

    CVE-2018-9400

    Last Modified: 19 Dec 2024

    In gt1x_debug_write_proc and gt1x_tool_write of drivers/input/touchscreen/mediatek/GT1151/gt1x_generic.c and gt1x_tools.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.

    Published: 4 Dec 2024
    6.7
    Medium

    CVE-2018-9399

    Last Modified: 19 Dec 2024

    In /proc/driver/wmt_dbg driver, there are several possible out of bounds writes. These could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.

    Published: 4 Dec 2024