CVE Feed

    Dashboard / CVE

    9.4
    Critical

    CVE-2024-49805

    Last Modified: 29 Jan 2025

    IBM Security Verify Access Appliance 10.0.0 through 10.0.8 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data.

    Published: 29 Nov 2024
    9.8
    Critical

    CVE-2024-49803

    Last Modified: 29 Jan 2025

    IBM Security Verify Access Appliance 10.0.0 through 10.0.8 could allow a remote authenticated attacker to execute arbitrary commands on the system by sending a specially crafted request.

    Published: 29 Nov 2024
    9.1
    Critical

    CVE-2024-11992

    Last Modified: 15 Apr 2026

    Absolute path traversal vulnerability in Quick.CMS, version 6.7, the exploitation of which could allow remote users to bypass the intended restrictions and download any file if it has the appropriate permissions outside of documentroot configured on the server via the aDirFiles%5B0%5D parameter in the admin.php page. This vulnerability allows an attacker to delete files stored on the server due to a lack of proper verification of user-supplied input.

    Published: 29 Nov 2024
    4.6
    Medium

    CVE-2024-11990

    Last Modified: 15 Apr 2026

    A Cross-Site Scripting (XSS) vulnerability in SurgeMail v78c2 could allow an attacker to execute arbitrary JavaScript code via an elaborate payload injected into vulnerable parameters.

    Published: 29 Nov 2024
    5.7
    Medium

    CVE-2024-47094

    Last Modified: 11 Sept 2025

    Insertion of Sensitive Information into Log File in Checkmk GmbH's Checkmk versions <2.3.0p22, <2.2.0p37, <2.1.0p50 (EOL) causes remote site secrets to be written to web log files accessible to local site users.

    Published: 29 Nov 2024
    9.8
    Critical

    CVE-2024-50357

    Last Modified: 15 Apr 2026

    FutureNet NXR series routers provided by Century Systems Co., Ltd. have REST-APIs, which are configured as disabled in the initial (factory default) configuration. But, REST-APIs are unexpectedly enabled when the affected product is powered up, provided either http-server (GUI) or Web authentication is enabled. The factory default configuration makes http-server (GUI) enabled, which means REST-APIs are also enabled. The username and the password for REST-APIs are configured in the factory default configuration. As a result, an attacker may obtain and/or alter the affected product's settings via REST-APIs.

    Published: 29 Nov 2024
    4.3
    Medium

    CVE-2024-11014

    Last Modified: 15 Apr 2026

    Cross-site request forgery (CSRF) vulnerability in NEC Corporation UNIVERGE IX from Ver9.2 to Ver10.10.21, for Ver10.8 up to Ver10.8.27 and for Ver10.9 up to Ver10.9.14 allows a attacker to hijack the authentication of screens on the device via the management interface.

    Published: 29 Nov 2024
    7.2
    High

    CVE-2024-11013

    Last Modified: 15 Apr 2026

    Command Injection vulnerability in NEC Corporation UNIVERGE IX from Ver9.2 to Ver10.10.21, for Ver10.8 up to Ver10.8.27, for Ver10.9 up to Ver10.9.14 and UNIVERGE IX-R/IX-V Ver1.2.15 and earlier allows a attacker to inject an arbitrary CLI commands to be executed on the device via the management interface.

    Published: 29 Nov 2024
    4.6
    Medium

    CVE-2024-9044

    Last Modified: 15 Apr 2026

    A XML External Entity (XXE) vulnerability has been identified in Easy Tax Client Software 2023 1.2 and earlier across multiple platforms, including Windows, Linux, and macOS.

    Published: 29 Nov 2024
    9.8
    Critical

    CVE-2024-11482

    Last Modified: 28 Oct 2025

    A vulnerability in ESM 11.6.10 allows unauthenticated access to the internal Snowservice API and enables remote code execution through command injection, executed as the root user.

    Published: 29 Nov 2024
    8.2
    High

    CVE-2024-11481

    Last Modified: 28 Oct 2025

    A vulnerability in ESM 11.6.10 allows unauthenticated access to the internal Snowservice API. This leads to improper handling of path traversal, insecure forwarding to an AJP backend without adequate validation, and lack of authentication for accessing internal API endpoints.

    Published: 29 Nov 2024
    7.2
    High

    CVE-2024-11983

    Last Modified: 15 Apr 2026

    Certain models of routers from Billion Electric has an OS Command Injection vulnerability, allowing remote attackers with administrator privileges to inject arbitrary system commands into a specific SSH function and execute them on the device.

    Published: 29 Nov 2024
    7.2
    High

    CVE-2024-11982

    Last Modified: 15 Apr 2026

    Certain models of routers from Billion Electric has a Plaintext Storage of a Password vulnerability. Remote attackers with administrator privileges can access the user settings page to retrieve plaintext passwords.

    Published: 29 Nov 2024
    7.5
    High

    CVE-2024-11981

    Last Modified: 15 Apr 2026

    Certain models of routers from Billion Electric has an Authentication Bypass vulnerability, allowing unautheticated attackers to retrive contents of arbitrary web pages.

    Published: 29 Nov 2024
    8.6
    High

    CVE-2024-11980

    Last Modified: 15 Apr 2026

    Certain modes of routers from Billion Electric have a Missing Authentication vulnerability, allowing unauthenticated remote attackers to directly access the specific functionality to obtain partial device information, modify the WiFi SSID, and restart the device.

    Published: 29 Nov 2024
    3.1
    Low

    CVE-2024-53701

    Last Modified: 15 Apr 2026

    Multiple FCNT Android devices provide the original security features such as "privacy mode" where arbitrary applications can be set not to be displayed, etc. Under certain conditions, and when an attacker can directly operate the device which its screen is unlocked by a user, the provided security features' setting pages may be exposed and/or the settings may be altered, without authentication. For example, specific applications in the device configured to be hidden may be displayed and/or activated.

    Published: 29 Nov 2024
    9.8
    Critical

    CVE-2024-11979

    Last Modified: 15 Apr 2026

    DreamMaker from Interinfo has a Path Traversal vulnerability and does not restrict the types of uploaded files. This allows unauthenticated remote attackers to upload arbitrary files to any directory, leading to arbitrary code execution by uploading webshells.

    Published: 29 Nov 2024
    7.5
    High

    CVE-2024-11978

    Last Modified: 15 Apr 2026

    DreamMaker from Interinfo has a Path Traversal vulnerability, allowing unauthenticated remote attackers to exploit this vulnerability to read arbitrary system files.

    Published: 29 Nov 2024
    5.4
    Medium

    CVE-2024-10980

    Last Modified: 7 May 2025

    The Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid, Carousel and Remote Arrows) WordPress plugin before 5.10.3 does not validate and escape some of its Cookie Consent block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

    Published: 29 Nov 2024
    4.8
    Medium

    CVE-2024-10704

    Last Modified: 7 May 2025

    The Photo Gallery by 10Web WordPress plugin before 1.8.31 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

    Published: 29 Nov 2024
    9.8
    Critical

    CVE-2024-48406

    Last Modified: 15 Apr 2026

    Buffer Overflow vulnerability in SunBK201 umicat through v.0.3.2 and fixed in v.0.3.3 allows an attacker to execute arbitrary code via the power(uct_int_t x, uct_int_t n) in src/uct_upstream.c.

    Published: 29 Nov 2024
    4.3
    Medium

    CVE-2024-45495

    Last Modified: 15 Apr 2026

    MSA FieldServer Gateway 5.0.0 through 6.5.2 allows cross-origin WebSocket hijacking.

    Published: 29 Nov 2024
    6.1
    Medium

    CVE-2024-39162

    Last Modified: 15 Apr 2026

    pyspider through 0.3.10 allows /update XSS. NOTE: This vulnerability only affects products that are no longer supported by the maintainer

    Published: 29 Nov 2024
    9.8
    Critical

    CVE-2024-36671

    Last Modified: 15 Apr 2026

    nodemcu before v3.0.0-release_20240225 was discovered to contain an integer overflow via the getnum function at /modules/struct.c.

    Published: 29 Nov 2024
    7.5
    High

    CVE-2024-36611

    Last Modified: 15 Apr 2026

    In Symfony v7.07, a security vulnerability was identified in the FormLoginAuthenticator component, where it failed to adequately handle cases where the username or password field of a login request is empty. This flaw could lead to various security risks, including improper authentication logic handling or denial of service. NOTE: the Supplier has concluded that this is a false report.

    Published: 29 Nov 2024
    7.5
    High

    CVE-2024-35371

    Last Modified: 15 Apr 2026

    Ant-Media-Serverv2.8.2 is affected by Improper Output Neutralization for Logs. The vulnerability stems from insufficient input sanitization in the logging mechanism. Without proper filtering or validation, user-controllable data, such as identifiers or other sensitive information, can be included in log entries without restrictions.

    Published: 29 Nov 2024
    5.4
    Medium

    CVE-2024-36625

    Last Modified: 25 Nov 2025

    Zulip 8.3 is vulnerable to Cross Site Scripting (XSS) via the replace_emoji_with_text function in ui_util.ts.

    Published: 29 Nov 2024
    5.4
    Medium

    CVE-2024-36624

    Last Modified: 25 Nov 2025

    Zulip 8.3 is vulnerable to Cross Site Scripting (XSS) via the construct_copy_div function in copy_and_paste.js.

    Published: 29 Nov 2024
    6.1
    Medium

    CVE-2024-54123

    Last Modified: 6 Apr 2026

    Backdrop CMS before 1.28.4 and 1.29.x before 1.29.2 allows XSS via an SVG document, if the SVG tag is allowed for a text format.

    Published: 29 Nov 2024
    9.8
    Critical

    CVE-2024-52779

    Last Modified: 6 Nov 2025

    DCME-320 <=7.4.12.90, DCME-520 <=9.25.5.11, DCME-320-L <=9.3.5.26, and DCME-720 <=9.1.5.11 are vulnerable to Remote Code Execution via /function/audit/newstatistics/mon_stat_top10.php.

    Published: 29 Nov 2024
    9.8
    Critical

    CVE-2024-52778

    Last Modified: 6 Nov 2025

    DCME-320 <=7.4.12.90, DCME-520 <=9.25.5.11, DCME-320-L <=9.3.5.26, and DCME-720 <=9.1.5.11 are vulnerable to Remote Code Execution via /function/audit/newstatistics/mon_stat_hist.php.

    Published: 29 Nov 2024
    7.5
    High

    CVE-2024-48651

    Last Modified: 15 Apr 2026

    In ProFTPD through 1.3.8b before cec01cc, supplemental group inheritance grants unintended access to GID 0 because of the lack of supplemental groups from mod_sql.

    Published: 29 Nov 2024
    9.1
    Critical

    CVE-2024-35366

    Last Modified: 3 Jun 2025

    FFmpeg n6.1.1 is Integer Overflow. The vulnerability exists in the parse_options function of sbgdec.c within the libavformat module. When parsing certain options, the software does not adequately validate the input. This allows for negative duration values to be accepted without proper bounds checking.

    Published: 29 Nov 2024
    5.3
    Medium

    CVE-2024-36619

    Last Modified: 3 Jun 2025

    FFmpeg n6.1.1 has a vulnerability in the WAVARC decoder of the libavcodec library which allows for an integer overflow when handling certain block types, leading to a denial-of-service (DoS) condition.

    Published: 29 Nov 2024
    6.5
    Medium

    CVE-2024-36621

    Last Modified: 2 Jul 2025

    moby v25.0.5 is affected by a Race Condition in builder/builder-next/adapters/snapshot/layer.go. The vulnerability could be used to trigger concurrent builds that call the EnsureLayer function resulting in resource leaks/exhaustion.

    Published: 29 Nov 2024
    5.3
    Medium

    CVE-2024-36626

    Last Modified: 15 Sept 2025

    In prestashop 8.1.4, a NULL pointer dereference was identified in the math_round function within Tools.php.

    Published: 29 Nov 2024
    —
    Unknown

    CVE-2024-36610

    Last Modified: 24 Dec 2024

    DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All references and descriptions in this candidate have been removed to prevent accidental usage.

    Published: 29 Nov 2024
    9.1
    Critical

    CVE-2024-35367

    Last Modified: 3 Nov 2025

    FFmpeg n6.1.1 has an Out-of-bounds Read via libavcodec/ppc/vp8dsp_altivec.c, static const vec_s8 h_subpel_filters_outer

    Published: 29 Nov 2024
    9.8
    Critical

    CVE-2024-35368

    Last Modified: 3 Nov 2025

    FFmpeg n7.0 is affected by a Double Free via the rkmpp_retrieve_frame function within libavcodec/rkmppdec.c.

    Published: 29 Nov 2024
    5.5
    Medium

    CVE-2024-35369

    Last Modified: 3 Jun 2025

    In FFmpeg version n6.1.1, specifically within the avcodec/speexdec.c module, a potential security vulnerability exists due to insufficient validation of certain parameters when parsing Speex codec extradata. This vulnerability could lead to integer overflow conditions, potentially resulting in undefined behavior or crashes during the decoding process.

    Published: 29 Nov 2024
    4.8
    Medium

    CVE-2024-35451

    Last Modified: 3 Jul 2025

    LinkStack 2.7.9 through 4.7.7 allows resources\views\components\favicon.blade.php link SSRF.

    Published: 29 Nov 2024
    6.2
    Medium

    CVE-2024-36618

    Last Modified: 3 Nov 2025

    FFmpeg n6.1.1 has a vulnerability in the AVI demuxer of the libavformat library which allows for an integer overflow, potentially resulting in a denial-of-service (DoS) condition.

    Published: 29 Nov 2024
    7.5
    High

    CVE-2024-36612

    Last Modified: 9 Apr 2025

    Zulip from 8.0 to 8.3 contains a memory leak vulnerability in the handling of popovers.

    Published: 29 Nov 2024
    5.9
    Medium

    CVE-2024-36615

    Last Modified: 3 Jun 2025

    FFmpeg n7.0 has a race condition vulnerability in the VP9 decoder. This could lead to a data race if video encoding parameters were being exported, as the side data would be attached in the decoder thread while being read in the output thread.

    Published: 29 Nov 2024
    6.5
    Medium

    CVE-2024-36616

    Last Modified: 3 Jun 2025

    An integer overflow in the component /libavformat/westwood_vqa.c of FFmpeg n6.1.1 allows attackers to cause a denial of service in the application via a crafted VQA file.

    Published: 29 Nov 2024
    6.2
    Medium

    CVE-2024-36617

    Last Modified: 3 Jun 2025

    FFmpeg n6.1.1 has an integer overflow vulnerability in the FFmpeg CAF decoder.

    Published: 29 Nov 2024
    6.5
    Medium

    CVE-2024-36620

    Last Modified: 5 Sept 2025

    moby v25.0.0 - v26.0.2 is vulnerable to NULL Pointer Dereference via daemon/images/image_history.go.

    Published: 29 Nov 2024
    9.8
    Critical

    CVE-2024-36622

    Last Modified: 2 Jul 2025

    In RaspAP raspap-webgui 3.0.9 and earlier, a command injection vulnerability exists in the clearlog.php script. The vulnerability is due to improper sanitization of user input passed via the logfile parameter.

    Published: 29 Nov 2024
    8.1
    High

    CVE-2024-36623

    Last Modified: 2 Jul 2025

    moby through v25.0.3 has a Race Condition vulnerability in the streamformatter package which can be used to trigger multiple concurrent write operations resulting in data corruption or application crashes.

    Published: 29 Nov 2024
    5.5
    Medium

    CVE-2024-47193

    Last Modified: 15 Apr 2026

    WithSecure Elements Agent for Mac before 24.3, MDR before 24.3, and Elements Client Security for Mac before 16.10 allow a remote Denial of Service.

    Published: 29 Nov 2024