CVE Feed

    Dashboard / CVE

    5.4
    Medium

    CVE-2024-53761

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in P Roy WP Revisions Manager wp-revisions-manager allows Cross Site Request Forgery.This issue affects WP Revisions Manager: from n/a through <= 1.0.2.

    Published: 2 Dec 2024
    7.1
    High

    CVE-2024-53762

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in FasterThemes FastBook fastbook-responsive-appointment-booking-and-scheduling-system allows Stored XSS.This issue affects FastBook: from n/a through <= 1.1.

    Published: 2 Dec 2024
    7.1
    High

    CVE-2024-53765

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Think201 Mins To Read mins-to-read allows Stored XSS.This issue affects Mins To Read: from n/a through <= 1.2.2.

    Published: 2 Dec 2024
    7.1
    High

    CVE-2024-53769

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in lriaudel Custom Post Type to Map Store cpt-to-map-store allows Stored XSS.This issue affects Custom Post Type to Map Store: from n/a through <= 1.1.0.

    Published: 2 Dec 2024
    7.1
    High

    CVE-2024-53770

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in pbmacintyre RingCentral Communications rccp-free allows Stored XSS.This issue affects RingCentral Communications: from n/a through <= 1.7.0.

    Published: 2 Dec 2024
    4.3
    Medium

    CVE-2024-53775

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in benmoreassynt DancePress (TRWA) dancepress-trwa allows Cross Site Request Forgery.This issue affects DancePress (TRWA): from n/a through <= 3.1.11.

    Published: 2 Dec 2024
    7.1
    High

    CVE-2024-53776

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in raphaelheide Donate Me donate-me allows Stored XSS.This issue affects Donate Me: from n/a through <= 1.2.5.

    Published: 2 Dec 2024
    7.1
    High

    CVE-2024-53777

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Alberto Reineri Simple Header and Footer simple-header-and-footer allows Stored XSS.This issue affects Simple Header and Footer: from n/a through <= 1.0.0.

    Published: 2 Dec 2024
    7.1
    High

    CVE-2024-53779

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in 8bitkid Yahoo! WebPlayer yahoo-media-player allows Stored XSS.This issue affects Yahoo! WebPlayer: from n/a through <= 2.0.6.

    Published: 2 Dec 2024
    7.1
    High

    CVE-2024-53780

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in rajeevglocify Load More Posts load-more-posts allows Stored XSS.This issue affects Load More Posts: from n/a through <= 1.5.0.

    Published: 2 Dec 2024
    7.1
    High

    CVE-2024-53781

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in homejunction SpatialMatch IDX spatialmatch-free-lifestyle-search allows Stored XSS.This issue affects SpatialMatch IDX: from n/a through <= 3.0.9.

    Published: 2 Dec 2024
    7.1
    High

    CVE-2024-53782

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in cmsaccount Photo Video Store photo-video-store allows Cross-Site Scripting (XSS).This issue affects Photo Video Store: from n/a through <= 21.07.

    Published: 2 Dec 2024
    4.3
    Medium

    CVE-2024-53784

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in E-goi Smart Marketing SMS and Newsletters Forms smart-marketing-for-wp allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Smart Marketing SMS and Newsletters Forms: from n/a through <= 5.0.4.

    Published: 2 Dec 2024
    7.1
    High

    CVE-2024-53789

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Ritesh Sanap Advanced What should we write next about advanced-what-should-we-write-about-next allows Stored XSS.This issue affects Advanced What should we write next about: from n/a through <= 1.0.3.

    Published: 2 Dec 2024
    8.5
    High

    CVE-2024-53792

    Last Modified: 23 Apr 2026

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Bob Watu Quiz watu allows SQL Injection.This issue affects Watu Quiz: from n/a through <= 3.4.1.2.

    Published: 2 Dec 2024
    8.2
    High

    CVE-2024-53793

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in jerodmoore eDoc Easy Tables edoc-easy-tables allows Blind SQL Injection.This issue affects eDoc Easy Tables: from n/a through <= 1.29.

    Published: 2 Dec 2024
    7.1
    High

    CVE-2024-53730

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in springthistle April's Call Posts aprils-call-posts allows Stored XSS.This issue affects April's Call Posts: from n/a through <= 2.1.1.

    Published: 2 Dec 2024
    7.1
    High

    CVE-2024-53740

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPSwings WooCommerce Ultimate Gift Card woocommerce-ultimate-gift-card allows Reflected XSS.This issue affects WooCommerce Ultimate Gift Card: from n/a through < 2.9.1.

    Published: 2 Dec 2024
    7.7
    High

    CVE-2024-12015

    Last Modified: 15 Apr 2026

    The 'Project Manager' WordPress Plugin is affected by an authenticated SQL injection vulnerability in the 'orderby' parameter in the '/pm/v2/activites' route.

    Published: 2 Dec 2024
    7.8
    High

    CVE-2024-43053

    Last Modified: 12 Dec 2024

    Memory corruption while invoking IOCTL calls from user space to read WLAN target diagnostic information.

    Published: 2 Dec 2024
    7.8
    High

    CVE-2024-43052

    Last Modified: 12 Dec 2024

    Memory corruption while processing API calls to NPU with invalid input.

    Published: 2 Dec 2024
    7.8
    High

    CVE-2024-43050

    Last Modified: 12 Dec 2024

    Memory corruption while invoking IOCTL calls from user space to issue factory test command inside WLAN driver.

    Published: 2 Dec 2024
    7.8
    High

    CVE-2024-43049

    Last Modified: 12 Dec 2024

    Memory corruption while invoking IOCTL calls from user space to set generic private command inside WLAN driver.

    Published: 2 Dec 2024
    7.8
    High

    CVE-2024-43048

    Last Modified: 12 Dec 2024

    Memory corruption when invalid input is passed to invoke GPU Headroom API call.

    Published: 2 Dec 2024
    7.5
    High

    CVE-2024-33063

    Last Modified: 12 Dec 2024

    Transient DOS while parsing the ML IE when a beacon with common info length of the ML IE greater than the ML IE inside which this element is present.

    Published: 2 Dec 2024
    8.4
    High

    CVE-2024-33056

    Last Modified: 12 Dec 2024

    Memory corruption when allocating and accessing an entry in an SMEM partition continuously.

    Published: 2 Dec 2024
    6.7
    Medium

    CVE-2024-33053

    Last Modified: 12 Dec 2024

    Memory corruption when multiple threads try to unregister the CVP buffer at the same time.

    Published: 2 Dec 2024
    8.4
    High

    CVE-2024-33044

    Last Modified: 12 Dec 2024

    Memory corruption while Configuring the SMR/S2CR register in Bypass mode.

    Published: 2 Dec 2024
    6.7
    Medium

    CVE-2024-33040

    Last Modified: 12 Dec 2024

    Memory corruption while invoking redundant release command to release one buffer from user space as race condition can occur in kernel space between buffer release and buffer access.

    Published: 2 Dec 2024
    6.7
    Medium

    CVE-2024-33039

    Last Modified: 11 Dec 2024

    Memory corruption when PAL client calls PAL service APIs by passing a random value as handle and the handle is not validated by the service.

    Published: 2 Dec 2024
    6.1
    Medium

    CVE-2024-33037

    Last Modified: 11 Dec 2024

    Information disclosure as NPU firmware can send invalid IPC message to NPU driver as the driver doesn`t validate the IPC message received from the firmware.

    Published: 2 Dec 2024
    6.7
    Medium

    CVE-2024-33036

    Last Modified: 11 Dec 2024

    Memory corruption while parsing sensor packets in camera driver, user-space variable is used while allocating memory in kernel and parsing which can lead to huge allocation or invalid memory access.

    Published: 2 Dec 2024
    8.4
    High

    CVE-2024-10490

    Last Modified: 15 Apr 2026

    An “Authentication Bypass Using an Alternate Path or Channel” vulnerability in the OPC UA Server configuration required for B&R mapp Cockpit before 6.0, B&R mapp View before 6.0, B&R mapp Services before 6.0, B&R mapp Motion before 6.0 and B&R mapp Vision before 6.0 may be used by an unauthenticated network-based attacker to cause information disclosure, unintended change of data, or denial of service conditions. B&R mapp Services is only affected, when mpUserX or mpCodeBox are used in the Automation Studio project.

    Published: 2 Dec 2024
    6.5
    Medium

    CVE-2024-20139

    Last Modified: 12 Jan 2026

    In Bluetooth firmware, there is a possible firmware asssert due to improper handling of exceptional conditions. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS09001270; Issue ID: MSV-1600.

    Published: 2 Dec 2024
    7.5
    High

    CVE-2024-20138

    Last Modified: 22 Apr 2025

    In wlan driver, there is a possible out of bound read due to improper input validation. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08998291; Issue ID: MSV-1604.

    Published: 2 Dec 2024
    4.4
    Medium

    CVE-2024-20116

    Last Modified: 22 Apr 2025

    In cmdq, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS09057438; Issue ID: MSV-1696.

    Published: 2 Dec 2024
    7.5
    High

    CVE-2024-20137

    Last Modified: 15 Apr 2026

    In wlan driver, there is a possible client disconnection due to improper handling of exceptional conditions. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00384543; Issue ID: MSV-1727.

    Published: 2 Dec 2024
    6.2
    Medium

    CVE-2024-20136

    Last Modified: 22 Apr 2025

    In da, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS09121847; Issue ID: MSV-1821.

    Published: 2 Dec 2024
    6.7
    Medium

    CVE-2024-20135

    Last Modified: 22 Apr 2025

    In soundtrigger, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS09142526; Issue ID: MSV-1841.

    Published: 2 Dec 2024
    6.7
    Medium

    CVE-2024-20134

    Last Modified: 22 Apr 2025

    In ril, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS09154589; Issue ID: MSV-1866.

    Published: 2 Dec 2024
    6.7
    Medium

    CVE-2024-20133

    Last Modified: 22 Apr 2025

    In Modem, there is a possible escalation of privilege due to an incorrect bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01395886; Issue ID: MSV-1871.

    Published: 2 Dec 2024
    6.7
    Medium

    CVE-2024-20132

    Last Modified: 25 Jun 2025

    In Modem, there is a possible out of bonds write due to a mission bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY00957388; Issue ID: MSV-1872.

    Published: 2 Dec 2024
    6.7
    Medium

    CVE-2024-20131

    Last Modified: 22 Apr 2025

    In Modem, there is a possible escalation of privilege due to an incorrect bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01395886; Issue ID: MSV-1873.

    Published: 2 Dec 2024
    6.7
    Medium

    CVE-2024-20130

    Last Modified: 22 Apr 2025

    In power, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS09193374; Issue ID: MSV-1982.

    Published: 2 Dec 2024
    7.5
    High

    CVE-2024-20127

    Last Modified: 22 Apr 2025

    In Telephony, there is a possible out of bounds read due to a missing bounds check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS09289881; Issue ID: MSV-2023.

    Published: 2 Dec 2024
    7.5
    High

    CVE-2024-20128

    Last Modified: 22 Apr 2025

    In Telephony, there is a possible out of bounds read due to a missing bounds check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS09289881; Issue ID: MSV-2024.

    Published: 2 Dec 2024
    7.5
    High

    CVE-2024-20129

    Last Modified: 13 Mar 2025

    In Telephony, there is a possible out of bounds read due to a missing bounds check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS09289881; Issue ID: MSV-2025.

    Published: 2 Dec 2024
    6.7
    Medium

    CVE-2024-20125

    Last Modified: 22 Apr 2025

    In vdec, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained System privileges. User interaction is not needed for exploitation. Patch ID: ALPS09046782; Issue ID: MSV-1728.

    Published: 2 Dec 2024
    3.7
    Low

    CVE-2024-11856

    Last Modified: 15 Apr 2026

    A security vulnerability in HPE IceWall products could be exploited remotely to cause Unauthorized Data Modification.

    Published: 2 Dec 2024
    7.8
    High

    CVE-2024-53121

    Last Modified: 4 Aug 2026

    In the Linux kernel, the following vulnerability has been resolved: net/mlx5: fs, lock FTE when checking if active The referenced commits introduced a two-step process for deleting FTEs: - Lock the FTE, delete it from hardware, set the hardware deletion function to NULL and unlock the FTE. - Lock the parent flow group, delete the software copy of the FTE, and remove it from the xarray. However, this approach encounters a race condition if a rule with the same match value is added simultaneously. In this scenario, fs_core may set the hardware deletion function to NULL prematurely, causing a panic during subsequent rule deletions. To prevent this, ensure the active flag of the FTE is checked under a lock, which will prevent the fs_core layer from attaching a new steering rule to an FTE that is in the process of deletion. [ 438.967589] MOSHE: 2496 mlx5_del_flow_rules del_hw_func [ 438.968205] ------------[ cut here ]------------ [ 438.968654] refcount_t: decrement hit 0; leaking memory. [ 438.969249] WARNING: CPU: 0 PID: 8957 at lib/refcount.c:31 refcount_warn_saturate+0xfb/0x110 [ 438.970054] Modules linked in: act_mirred cls_flower act_gact sch_ingress openvswitch nsh mlx5_vdpa vringh vhost_iotlb vdpa mlx5_ib mlx5_core xt_conntrack xt_MASQUERADE nf_conntrack_netlink nfnetlink xt_addrtype iptable_nat nf_nat br_netfilter rpcsec_gss_krb5 auth_rpcgss oid_registry overlay rpcrdma rdma_ucm ib_iser libiscsi scsi_transport_iscsi ib_umad rdma_cm ib_ipoib iw_cm ib_cm ib_uverbs ib_core zram zsmalloc fuse [last unloaded: cls_flower] [ 438.973288] CPU: 0 UID: 0 PID: 8957 Comm: tc Not tainted 6.12.0-rc1+ #8 [ 438.973888] Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS rel-1.13.0-0-gf21b5a4aeb02-prebuilt.qemu.org 04/01/2014 [ 438.974874] RIP: 0010:refcount_warn_saturate+0xfb/0x110 [ 438.975363] Code: 40 66 3b 82 c6 05 16 e9 4d 01 01 e8 1f 7c a0 ff 0f 0b c3 cc cc cc cc 48 c7 c7 10 66 3b 82 c6 05 fd e8 4d 01 01 e8 05 7c a0 ff <0f> 0b c3 cc cc cc cc 66 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 00 90 [ 438.976947] RSP: 0018:ffff888124a53610 EFLAGS: 00010286 [ 438.977446] RAX: 0000000000000000 RBX: ffff888119d56de0 RCX: 0000000000000000 [ 438.978090] RDX: ffff88852c828700 RSI: ffff88852c81b3c0 RDI: ffff88852c81b3c0 [ 438.978721] RBP: ffff888120fa0e88 R08: 0000000000000000 R09: ffff888124a534b0 [ 438.979353] R10: 0000000000000001 R11: 0000000000000001 R12: ffff888119d56de0 [ 438.979979] R13: ffff888120fa0ec0 R14: ffff888120fa0ee8 R15: ffff888119d56de0 [ 438.980607] FS: 00007fe6dcc0f800(0000) GS:ffff88852c800000(0000) knlGS:0000000000000000 [ 438.983984] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 [ 438.984544] CR2: 00000000004275e0 CR3: 0000000186982001 CR4: 0000000000372eb0 [ 438.985205] DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000 [ 438.985842] DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400 [ 438.986507] Call Trace: [ 438.986799] <TASK> [ 438.987070] ? __warn+0x7d/0x110 [ 438.987426] ? refcount_warn_saturate+0xfb/0x110 [ 438.987877] ? report_bug+0x17d/0x190 [ 438.988261] ? prb_read_valid+0x17/0x20 [ 438.988659] ? handle_bug+0x53/0x90 [ 438.989054] ? exc_invalid_op+0x14/0x70 [ 438.989458] ? asm_exc_invalid_op+0x16/0x20 [ 438.989883] ? refcount_warn_saturate+0xfb/0x110 [ 438.990348] mlx5_del_flow_rules+0x2f7/0x340 [mlx5_core] [ 438.990932] __mlx5_eswitch_del_rule+0x49/0x170 [mlx5_core] [ 438.991519] ? mlx5_lag_is_sriov+0x3c/0x50 [mlx5_core] [ 438.992054] ? xas_load+0x9/0xb0 [ 438.992407] mlx5e_tc_rule_unoffload+0x45/0xe0 [mlx5_core] [ 438.993037] mlx5e_tc_del_fdb_flow+0x2a6/0x2e0 [mlx5_core] [ 438.993623] mlx5e_flow_put+0x29/0x60 [mlx5_core] [ 438.994161] mlx5e_delete_flower+0x261/0x390 [mlx5_core] [ 438.994728] tc_setup_cb_destroy+0xb9/0x190 [ 438.995150] fl_hw_destroy_filter+0x94/0xc0 [cls_flower] [ 438.995650] fl_change+0x11a4/0x13c0 [cls_flower] [ 438.996105] tc_new_tfilter+0x347/0xbc0 [ 438.996503] ? __ ---truncated---

    Published: 2 Dec 2024