CVE Feed

    Dashboard / CVE

    4.3
    Medium

    CVE-2024-12062

    Last Modified: 8 Apr 2026

    The Charity Addon for Elementor plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.3.3 via the 'nacharity_elementor_template' shortcode due to insufficient restrictions on which posts can be included. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract data from private or draft posts created by Elementor that they should not have access to.

    Published: 3 Dec 2024
    5.2
    Medium

    CVE-2024-11325

    Last Modified: 15 Apr 2026

    The AWeber Forms by Optin Cat plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 2.5.7. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

    Published: 3 Dec 2024
    8.1
    High

    CVE-2024-45106

    Last Modified: 1 Jul 2025

    Improper authentication of an HTTP endpoint in the S3 Gateway of Apache Ozone 1.4.0 allows any authenticated Kerberos user to revoke and regenerate the S3 secrets of any other user. This is only possible if: * ozone.s3g.secret.http.enabled is set to true. The default value of this configuration is false. * The user configured in ozone.s3g.kerberos.principal is also configured in ozone.s3.administrators or ozone.administrators. Users are recommended to upgrade to Apache Ozone version 1.4.1 which disables the affected endpoint.

    Published: 3 Dec 2024
    6.4
    Medium

    CVE-2024-11866

    Last Modified: 15 Apr 2026

    The BMLT Tabbed Map plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'bmlt_tabbed_map' shortcode in all versions up to, and including, 1.1.8 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 3 Dec 2024
    4.3
    Medium

    CVE-2024-11844

    Last Modified: 8 Apr 2026

    The IdeaPush plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the idea_push_taxonomy_save_routine function in all versions up to, and including, 8.71. This makes it possible for authenticated attackers, with Subscriber-level access and above, to delete terms for the "boards" taxonomy.

    Published: 3 Dec 2024
    —
    Unknown

    CVE-2024-12095

    Last Modified: 11 Feb 2025

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

    Published: 3 Dec 2024
    5.5
    Medium

    CVE-2024-12082

    Last Modified: 11 Dec 2024

    in OpenHarmony v4.0.0 and prior versions allow a local attacker cause information leak through out-of-bounds Read.

    Published: 3 Dec 2024
    8.8
    High

    CVE-2024-10074

    Last Modified: 11 Dec 2024

    in OpenHarmony v4.1.1 and prior versions allow a local attacker cause the common permission is upgraded to root through use after free.

    Published: 3 Dec 2024
    6.5
    Medium

    CVE-2024-11732

    Last Modified: 15 Apr 2026

    The BP Profile Shortcodes Extra plugin for WordPress is vulnerable to time-based SQL Injection via the ‘tab’ parameter in all versions up to, and including, 2.6.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with Contributor-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

    Published: 3 Dec 2024
    6.1
    Medium

    CVE-2024-11805

    Last Modified: 15 Apr 2026

    The Quick License Manager – WooCommerce Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'submit_qlm_products' parameter in all versions up to, and including, 2.4.17 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

    Published: 3 Dec 2024
    6.4
    Medium

    CVE-2024-11853

    Last Modified: 15 Apr 2026

    The jAlbum Bridge plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘ar’ parameter in all versions up to, and including, 2.0.16 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. It was determined that the patch in 2.0.16 was insufficient, and 2.0.17 is considered the fully patched version.

    Published: 3 Dec 2024
    6.1
    Medium

    CVE-2024-11461

    Last Modified: 15 Apr 2026

    The Form Data Collector plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'page' parameter in all versions up to, and including, 2.2.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

    Published: 3 Dec 2024
    6.4
    Medium

    CVE-2024-11898

    Last Modified: 8 Apr 2026

    The Scratch & Win – Giveaways and Contests. Boost subscribers, traffic, repeat visits, referrals, sales and more plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'swin-campaign' shortcode in all versions up to, and including, 2.6.9 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 3 Dec 2024
    6.1
    Medium

    CVE-2024-11707

    Last Modified: 15 Apr 2026

    The My auctions allegro plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'page' parameter in all versions up to, and including, 3.6.17 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

    Published: 3 Dec 2024
    6.4
    Medium

    CVE-2024-11453

    Last Modified: 8 Apr 2026

    The WordPress Pinterest Plugin – Make a Popup, User Profile, Masonry and Gallery Layout plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'gs_pin_widget' shortcode in all versions up to, and including, 1.8.8 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 3 Dec 2024
    6.4
    Medium

    CVE-2024-9058

    Last Modified: 8 Apr 2026

    The Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Lightbox widget in all versions up to, and including, 5.10.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 3 Dec 2024
    4.3
    Medium

    CVE-2024-49421

    Last Modified: 24 Sept 2025

    Path traversal in Quick Share Agent prior to version 3.5.14.47 in Android 12, 3.5.19.41 in Android 13, and 3.5.19.42 in Android 14 allows adjacent attackers to write file in arbitrary location.

    Published: 3 Dec 2024
    7.5
    High

    CVE-2024-49420

    Last Modified: 15 Apr 2026

    Improper handling of responses in GamingHub prior to version 6.1.04.6 in Korea, 7.1.03.7 in Global allows remote attackers to launch arbitrary activity.

    Published: 3 Dec 2024
    4.3
    Medium

    CVE-2024-49419

    Last Modified: 15 Apr 2026

    Insufficient verification of url authenticity in GamingHub prior to version 6.1.03.4 in Korea, 7.1.02.4 in Global allows remote attackers to load an arbitrary URL in its webview.

    Published: 3 Dec 2024
    6.5
    Medium

    CVE-2024-49418

    Last Modified: 15 Apr 2026

    Insufficient verification of url authenticity in GamingHub prior to version 6.1.03.4 in Korea, 7.1.02.4 in Global allows remote attackers to enable JavaScript in its webview.

    Published: 3 Dec 2024
    2
    Low

    CVE-2024-49417

    Last Modified: 9 Jan 2026

    Use of implicit intent for sensitive communication in Smart Touch Call prior to 1.0.0.8 allows local attackers to launch privileged activities. User interaction is required for triggering this vulnerability.

    Published: 3 Dec 2024
    4
    Medium

    CVE-2024-49416

    Last Modified: 17 Jul 2025

    Use of implicit intent for sensitive communication in SmartThings prior to version 1.8.21 allows local attackers to get sensitive information.

    Published: 3 Dec 2024
    8.1
    High

    CVE-2024-49415

    Last Modified: 10 Feb 2025

    Out-of-bound write in libsaped.so prior to SMR Dec-2024 Release 1 allows remote attackers to execute arbitrary code.

    Published: 3 Dec 2024
    2.4
    Low

    CVE-2024-49414

    Last Modified: 10 Feb 2025

    Authentication Bypass Using an Alternate Path in Dex Mode prior to SMR Dec-2024 Release 1 allows physical attackers to temporarily access to recent app list.

    Published: 3 Dec 2024
    7.1
    High

    CVE-2024-49413

    Last Modified: 10 Feb 2025

    Improper Verification of Cryptographic Signature in SmartSwitch prior to SMR Dec-2024 Release 1 allows local attackers to install malicious applications.

    Published: 3 Dec 2024
    5.5
    Medium

    CVE-2024-49412

    Last Modified: 15 Apr 2026

    Improper input validation in Settings prior to SMR Dec-2024 Release 1 allows local attackers to broadcast signal for discovering Bluetooth on Galaxy Watch.

    Published: 3 Dec 2024
    4.3
    Medium

    CVE-2024-49411

    Last Modified: 10 Feb 2025

    Path Traversal in ThemeCenter prior to SMR Dec-2024 Release 1 allows physical attackers to copy apk files to arbitrary path with ThemeCenter privilege.

    Published: 3 Dec 2024
    5.9
    Medium

    CVE-2024-49410

    Last Modified: 10 Feb 2025

    Out-of-bounds write in libswmfextractor.so prior to SMR Dec-2024 Release 1 allows local attackers to execute arbitrary code.

    Published: 3 Dec 2024
    6.4
    Medium

    CVE-2024-10484

    Last Modified: 8 Apr 2026

    The Spectra – WordPress Gutenberg Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'Team' widget in all versions up to, and including, 2.16.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 3 Dec 2024
    7.1
    High

    CVE-2024-45068

    Last Modified: 15 Apr 2026

    Authentication credentials leakage vulnerability in Hitachi Ops Center Common Services within Hitachi Ops Center OVA. This issue affects Hitachi Ops Center Common Services: from 10.9.3-00 before 11.0.3-00; Hitachi Ops Center OVA: from 10.9.3-00 before 11.0.2-01.

    Published: 3 Dec 2024
    6.4
    Medium

    CVE-2024-9694

    Last Modified: 15 Apr 2026

    The CMSMasters Elementor Addon plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple widgets in all versions up to, and including, 1.14.7 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 3 Dec 2024
    4.8
    Medium

    CVE-2024-10893

    Last Modified: 17 May 2025

    The WP Booking Calendar WordPress plugin before 10.6.5 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

    Published: 3 Dec 2024
    7.2
    High

    CVE-2024-9200

    Last Modified: 21 Jan 2025

    A post-authentication command injection vulnerability in the "host" parameter of the diagnostic function in Zyxel VMG4005-B50A firmware versions through V5.15(ABQA.2.2)C0 could allow an authenticated attacker with administrator privileges to execute operating system (OS) commands on a vulnerable device.

    Published: 3 Dec 2024
    4.9
    Medium

    CVE-2024-9197

    Last Modified: 21 Jan 2025

    A post-authentication buffer overflow vulnerability in the parameter "action" of the CGI program in Zyxel VMG3625-T50B firmware versions through V5.50(ABPM.9.2)C0 could allow an authenticated attacker with administrator privileges to cause a temporary denial of service (DoS) condition against the web management interface by sending a crafted HTTP GET request to a vulnerable device if the function ZyEE is enabled.

    Published: 3 Dec 2024
    7.5
    High

    CVE-2024-8748

    Last Modified: 21 Jan 2025

    A buffer overflow vulnerability in the packet parser of the third-party library "libclinkc" in Zyxel VMG8825-T50K firmware versions through V5.50(ABOM.8.4)C0 could allow an attacker to cause a temporary denial of service (DoS) condition against the web management interface by sending a crafted HTTP POST request to a vulnerable device.

    Published: 3 Dec 2024
    5.5
    Medium

    CVE-2018-9449

    Last Modified: 18 Dec 2024

    In process_service_search_attr_rsp of sdp_discovery.cc, there is a possible out of bound read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 3 Dec 2024
    5.5
    Medium

    CVE-2018-9441

    Last Modified: 18 Dec 2024

    In sdp_copy_raw_data of sdp_discovery.cc, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.

    Published: 3 Dec 2024
    9.8
    Critical

    CVE-2024-51363

    Last Modified: 15 Apr 2026

    Insecure deserialization in Hodoku v2.3.0 to v2.3.2 allows attackers to execute arbitrary code.

    Published: 3 Dec 2024
    8.8
    High

    CVE-2024-51114

    Last Modified: 15 Apr 2026

    An issue in Beijing Digital China Yunke Information Technology Co.Ltd v.7.2.6.120 allows a remote attacker to execute arbitrary code via the code/function/dpi/web_auth/customizable.php file

    Published: 3 Dec 2024
    2.8
    Low

    CVE-2024-53921

    Last Modified: 3 Jun 2025

    An issue was discovered in the installer in Samsung Magician 8.1.0 on Windows. An attacker can create arbitrary folders in the system permission directory via a symbolic link during the installation process.

    Published: 3 Dec 2024
    3.8
    Low

    CVE-2024-53502

    Last Modified: 4 Apr 2025

    Seecms v4.8 was discovered to contain a SQL injection vulnerability in the SEMCMS_SeoAndTag.php page.

    Published: 3 Dec 2024
    7.5
    High

    CVE-2024-50948

    Last Modified: 15 Apr 2026

    mochiMQTT v2.6.3 is vulnerable to Denial of Service (DoS) due to improper resource management. An attacker can exhaust system memory and crash the broker by establishing and maintaining a large number of malicious, long-term publish/subscribe sessions.

    Published: 3 Dec 2024
    7.8
    High

    CVE-2024-29404

    Last Modified: 15 Apr 2026

    An issue in Razer Synapse 3 v.3.9.131.20813 and Synapse 3 App v.20240213 allows a local attacker to execute arbitrary code via the export parameter of the Chroma Effects function in the Profiles component.

    Published: 3 Dec 2024
    7.2
    High

    CVE-2024-45757

    Last Modified: 15 Apr 2026

    An issue was discovered in Centreon centreon-bam 24.04, 23.10, 23.04, and 22.10. SQL injection can occur in the user-settings form. Exploitation is only accessible to authenticated users with high-privileged access.

    Published: 3 Dec 2024
    7.5
    High

    CVE-2024-48080

    Last Modified: 15 Apr 2026

    An issue in aedes v0.51.2 allows attackers to cause a Denial of Service(DoS) via a crafted request. NOTE: the Supplier indicates that exploitation cannot occur because of the protection mechanism in the validateTopic function in lib/utils.js.

    Published: 3 Dec 2024
    8.8
    High

    CVE-2024-46624

    Last Modified: 15 Apr 2026

    An issue in InfoDom Performa 365 v4.0.1 allows authenticated attackers to elevate their privileges to Administrator via a crafted payload sent to /api/users.

    Published: 3 Dec 2024
    8.8
    High

    CVE-2024-46625

    Last Modified: 15 Apr 2026

    An authenticated arbitrary file upload vulnerability in the /documentCache/upload endpoint of InfoDom Performa 365 v4.0.1 allows attackers to execute arbitrary code via uploading a crafted SVG file.

    Published: 3 Dec 2024
    5.5
    Medium

    CVE-2018-9435

    Last Modified: 18 Dec 2024

    In gatt_process_error_rsp of gatt_cl.cc, there is a possible out of bound read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 2 Dec 2024
    7.8
    High

    CVE-2018-9431

    Last Modified: 18 Dec 2024

    In OSUInfo of OSUInfo.java, there is a possible escalation of privilege due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 2 Dec 2024
    9.8
    Critical

    CVE-2018-9430

    Last Modified: 18 Dec 2024

    In prop2cfg of btif_storage.cc, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 2 Dec 2024