CVE Feed

    Dashboard / CVE

    5.3
    Medium

    CVE-2024-10580

    Last Modified: 15 Apr 2026

    The Hustle – Email Marketing, Lead Generation, Optins, Popups plugin for WordPress is vulnerable to unauthorized form submissions due to a missing capability check on the submit_form() function in all versions up to, and including, 7.8.5. This makes it possible for unauthenticated attackers to submit unpublished forms.

    Published: 27 Nov 2024
    6.4
    Medium

    CVE-2024-10895

    Last Modified: 15 Apr 2026

    The Counter Up – Animated Number Counter & Milestone Showcase plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'lgx-counter' shortcode in all versions up to, and including, 2.4.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 27 Nov 2024
    7.5
    High

    CVE-2024-36467

    Last Modified: 8 Oct 2025

    An authenticated user with API access (e.g.: user with default User role), more specifically a user with access to the user.update API endpoint is enough to be able to add themselves to any group (e.g.: Zabbix Administrators), except to groups that are disabled or having restricted GUI access.

    Published: 27 Nov 2024
    5.3
    Medium

    CVE-2024-11219

    Last Modified: 8 Apr 2026

    The Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 3.0.6 via the get_image function. This makes it possible for unauthenticated attackers to view arbitrary images on the server, which can contain sensitive information.

    Published: 27 Nov 2024
    5.3
    Medium

    CVE-2024-11083

    Last Modified: 8 Apr 2026

    The ProfilePress plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.15.18 via the WordPress core search feature. This makes it possible for unauthenticated attackers to extract sensitive data from posts that have been restricted to higher-level roles such as administrator.

    Published: 27 Nov 2024
    9.3
    Critical

    CVE-2024-52959

    Last Modified: 6 Mar 2026

    A Improper Control of Generation of Code ('Code Injection') vulnerability in plugin management in iota C.ai Conversational Platform from 1.0.0 through 2.1.3 allows remote authenticated users to perform arbitrary system commands via a DLL file.

    Published: 27 Nov 2024
    9.3
    Critical

    CVE-2024-52958

    Last Modified: 6 Mar 2026

    A improper verification of cryptographic signature vulnerability in plugin management in iota C.ai Conversational Platform from 1.0.0 through 2.1.3 allows remote authenticated users to load a malicious DLL via upload plugin function.

    Published: 27 Nov 2024
    7.1
    High

    CVE-2024-5921

    Last Modified: 27 Jun 2025

    An insufficient certification validation issue in the Palo Alto Networks GlobalProtect app enables attackers to connect the GlobalProtect app to arbitrary servers. This can enable a local non-administrative operating system user or an attacker on the same subnet to install malicious root certificates on the endpoint and subsequently install malicious software signed by the malicious root certificates on that endpoint. Please subscribe to our RSS feed https://security.paloaltonetworks.com/rss.xml to be alerted to new updates to this and other advisories.

    Published: 27 Nov 2024
    9.8
    Critical

    CVE-2024-53676

    Last Modified: 5 Mar 2025

    A directory traversal vulnerability in Hewlett Packard Enterprise Insight Remote Support may allow remote code execution.

    Published: 27 Nov 2024
    7.8
    High

    CVE-2024-53920

    Last Modified: 21 Sept 2026

    In elisp-mode.el in GNU Emacs before 30.1, a user who chooses to invoke elisp-completion-at-point (for code completion) on untrusted Emacs Lisp source code can trigger unsafe Lisp macro expansion that allows attackers to execute arbitrary code. (This unsafe expansion also occurs if a user chooses to enable on-the-fly diagnosis that byte compiles untrusted Emacs Lisp source code.)

    Published: 27 Nov 2024
    6.8
    Medium

    CVE-2024-51228

    Last Modified: 15 Apr 2026

    An issue in TOTOLINK-CX-A3002RU V1.0.4-B20171106.1512 and TOTOLINK-CX-N150RT V2.1.6-B20171121.1002 and TOTOLINK-CX-N300RT V2.1.6-B20170724.1420 and TOTOLINK-CX-N300RT V2.1.8-B20171113.1408 and TOTOLINK-CX-N300RT V2.1.8-B20191010.1107 and TOTOLINK-CX-N302RE V2.0.2-B20170511.1523 allows a remote attacker to execute arbitrary code via the /boafrm/formSysCmd component.

    Published: 27 Nov 2024
    4.2
    Medium

    CVE-2024-37816

    Last Modified: 15 Apr 2026

    Quectel EC25-EUX EC25EUXGAR08A05M1G was discovered to contain a stack overflow.

    Published: 27 Nov 2024
    4.8
    Medium

    CVE-2024-53635

    Last Modified: 4 Apr 2025

    A Reflected Cross Site Scripting (XSS) vulnerability was found in /covid-tms/patient-search-report.php in PHPGurukul COVID 19 Testing Management System v1.0, which allows remote attackers to execute arbitrary code via the searchdata POST request parameter.

    Published: 27 Nov 2024
    8
    High

    CVE-2024-31976

    Last Modified: 26 Jan 2026

    EnGenius EWS356-FIR 1.1.30 and earlier devices allow a remote attacker to execute arbitrary OS commands via the Controller connectivity parameter.

    Published: 27 Nov 2024
    8
    High

    CVE-2024-52951

    Last Modified: 15 Apr 2026

    Stored Cross-Site Scripting in the Access Request History in Omada Identity before version 15 update 1 allows an authenticated attacker to execute arbitrary code in the browser of a victim via a specially crafted link or by viewing a manipulated Access Request History

    Published: 27 Nov 2024
    9.8
    Critical

    CVE-2024-46054

    Last Modified: 15 May 2025

    OpenVidReview 1.0 is vulnerable to Incorrect Access Control. The /upload route is accessible without authentication, allowing any user to upload files.

    Published: 27 Nov 2024
    4.8
    Medium

    CVE-2024-46055

    Last Modified: 15 May 2025

    OpenVidReview 1.0 is vulnerable to Cross Site Scripting (XSS) in review names.

    Published: 27 Nov 2024
    7.3
    High

    CVE-2024-53603

    Last Modified: 27 Mar 2025

    A SQL Injection vulnerability was found in /covid-tms/password-recovery.php in PHPGurukul COVID 19 Testing Management System v1.0, which allows remote attackers to execute arbitrary code via the contactno POST request parameter.

    Published: 27 Nov 2024
    9.8
    Critical

    CVE-2024-53604

    Last Modified: 27 Mar 2025

    A SQL Injection vulnerability was found in /covid-tms/check_availability.php in PHPGurukul COVID 19 Testing Management System v1.0, which allows remote attackers to execute arbitrary code via the mobnumber POST request parameter.

    Published: 27 Nov 2024
    4.8
    Medium

    CVE-2024-53849

    Last Modified: 15 Apr 2026

    editorconfig-core-c is theEditorConfig core library written in C (for use by plugins supporting EditorConfig parsing). In affected versions several overflows may occur in switch case '[' when the input pattern contains many escaped characters. The added backslashes leave too little space in the output pattern when processing nested brackets such that the remaining input length exceeds the output capacity. This issue has been addressed in release version 0.12.7. Users are advised to upgrade. There are no known workarounds for this vulnerability.

    Published: 26 Nov 2024
    7.3
    High

    CVE-2024-53675

    Last Modified: 12 Dec 2024

    An XML external entity injection (XXE) vulnerability in HPE Insight Remote Support may allow remote users to disclose information in certain cases.

    Published: 26 Nov 2024
    7.3
    High

    CVE-2024-53674

    Last Modified: 12 Dec 2024

    An XML external entity injection (XXE) vulnerability in HPE Insight Remote Support may allow remote users to disclose information in certain cases.

    Published: 26 Nov 2024
    8.1
    High

    CVE-2024-53673

    Last Modified: 12 Dec 2024

    A java deserialization vulnerability in HPE Remote Insight Support may allow an unauthenticated attacker to execute code.

    Published: 26 Nov 2024
    5.7
    Medium

    CVE-2024-43784

    Last Modified: 15 Apr 2026

    lakeFS is an open-source tool that transforms object storage into a Git-like repository. Existing lakeFS users who have issued credentials to users who have been deleted are affected by this vulnerability. When creating a new user with the same username as a deleted user, that user will inherit all of the previous user's credentials. This issue has been addressed in release version 1.33.0 and all users are advised to upgrade. The only known workaround for those who cannot upgrade is to not reuse usernames.

    Published: 26 Nov 2024
    5.3
    Medium

    CVE-2024-11820

    Last Modified: 3 Dec 2024

    A vulnerability, which was classified as problematic, has been found in code-projects Crud Operation System 1.0. This issue affects some unknown processing of the file /add.php. The manipulation of the argument saddress leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. Other parameters might be affected as well.

    Published: 26 Nov 2024
    7.6
    High

    CVE-2024-49053

    Last Modified: 8 Jul 2025

    Microsoft Dynamics 365 Sales Spoofing Vulnerability

    Published: 26 Nov 2024
    8.2
    High

    CVE-2024-49052

    Last Modified: 8 Jul 2025

    Missing authentication for critical function in Microsoft Azure PolicyWatch allows an unauthorized attacker to elevate privileges over a network.

    Published: 26 Nov 2024
    9.3
    Critical

    CVE-2024-49038

    Last Modified: 8 Jul 2025

    Improper neutralization of input during web page generation ('Cross-site Scripting') in Copilot Studio by an unauthorized attacker leads to elevation of privilege over a network.

    Published: 26 Nov 2024
    8.7
    High

    CVE-2024-49035

    Last Modified: 28 Oct 2025

    An improper access control vulnerability in Partner.Microsoft.com allows an a unauthenticated attacker to elevate privileges over a network.

    Published: 26 Nov 2024
    9
    Critical

    CVE-2019-17082

    Last Modified: 15 Apr 2026

    Insufficiently Protected Credentials vulnerability in OpenText™ AccuRev allows Authentication Bypass. When installed on a Linux or Solaris system the vulnerability could allow anyone who knows a valid AccuRev username can use the AccuRev client to login and gain access to AccuRev source control without knowing the user’s password. This issue affects AccuRev: 2017.1.

    Published: 26 Nov 2024
    6.9
    Medium

    CVE-2024-11819

    Last Modified: 3 Dec 2024

    A vulnerability classified as critical was found in 1000 Projects Portfolio Management System MCA 1.0. This vulnerability affects unknown code of the file /forgot_password_process.php. The manipulation of the argument username leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

    Published: 26 Nov 2024
    6.9
    Medium

    CVE-2024-11818

    Last Modified: 3 Dec 2024

    A vulnerability classified as critical has been found in PHPGurukul User Registration & Login and User Management System 1.0. This affects an unknown part of the file /signup.php. The manipulation of the argument email leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

    Published: 26 Nov 2024
    9.3
    Critical

    CVE-2024-11145

    Last Modified: 23 Sept 2025

    Valor Apps Easy Folder Listing Pro has a deserialization vulnerability that allows an unauthenticated, remote attacker to execute arbitrary code with the privileges of the Joomla! application. Fixed in versions 3.8 and 4.5.

    Published: 26 Nov 2024
    6.9
    Medium

    CVE-2024-11817

    Last Modified: 3 Dec 2024

    A vulnerability was found in PHPGurukul User Registration & Login and User Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /admin/index.php. The manipulation of the argument username leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

    Published: 26 Nov 2024
    2
    Low

    CVE-2024-52008

    Last Modified: 23 Sept 2025

    Fides is an open-source privacy engineering platform. The user invite acceptance API endpoint lacks server-side password policy enforcement, allowing users to set arbitrarily weak passwords by bypassing client-side validation. While the UI enforces password complexity requirements, direct API calls can circumvent these checks, enabling the creation of accounts with passwords as short as a single character. When an email messaging provider is enabled and a new user account is created in the system, an invite email containing a special link is sent to the new user's email address. This link directs the new user to a page where they can set their initial password. While the user interface implements password complexity checks, these validations are only performed client-side. The underlying `/api/v1/user/accept-invite` API endpoint does not implement the same password policy validations. This vulnerability allows an invited user to set an extremely weak password for their own account during the initial account setup process. Therefore that specific user's account can be compromised easily by an attacker guessing or brute forcing the password. The vulnerability has been patched in Fides version `2.50.0`. Users are advised to upgrade to this version or later to secure their systems against this threat. There are no known workarounds for this vulnerability.

    Published: 26 Nov 2024
    5.5
    Medium

    CVE-2024-53267

    Last Modified: 15 Apr 2026

    sigstore-java is a sigstore java client for interacting with sigstore infrastructure. sigstore-java has insufficient verification for a situation where a validly-signed but "mismatched" bundle is presented as proof of inclusion into a transparency log. This bug impacts clients using any variation of KeylessVerifier.verify(). The verifier may accept a bundle with an unrelated log entry, cryptographically verifying everything but fails to ensure the log entry applies to the artifact in question, thereby "verifying" a bundle without any proof the signing event was logged. This allows the creation of a bundle without fulcio certificate and private key combined with an unrelated but time-correct log entry to fake logging of a signing event. A malicious actor using a compromised identity may want to do this to prevent discovery via rekor's log monitors. The signer's identity will still be available to the verifier. The signature on the bundle must still be on the correct artifact for the verifier to pass. sigstore-gradle-plugin and sigstore-maven-plugin are not affected by this as they only provide signing functionality. This issue has been patched in v1.1.0 release with PR #856. All users are advised to upgrade. There are no known workarounds for this vulnerability.

    Published: 26 Nov 2024
    6.3
    Medium

    CVE-2024-53844

    Last Modified: 15 Apr 2026

    E.D.D.I (Enhanced Dialog Driven Interface) is a middleware to connect and manage LLM API bots. A path traversal vulnerability exists in the backup export functionality of EDDI, as implemented in `RestExportService.java`. This vulnerability allows an attacker to access sensitive files on the server by manipulating the `botFilename` parameter in requests. The application fails to sanitize user input, enabling malicious inputs such as `..%2f..%2fetc%2fpasswd` to access arbitrary files. However, the **severity of this vulnerability is significantly limited** because EDDI typically runs within a **Docker container**, which provides additional layers of isolation and restricted permissions. As a result, while this vulnerability exposes files within the container, it does not inherently threaten the underlying host system or other containers. A patch is required to sanitize and validate the botFilename input parameter. Users should ensure they are using version 5.4 which contains this patdch. For temporary mitigation, access to the vulnerable endpoint should be restricted through firewall rules or authentication mechanisms.

    Published: 26 Nov 2024
    8.2
    High

    CVE-2024-8114

    Last Modified: 12 Dec 2024

    An issue has been discovered in GitLab CE/EE affecting all versions from 8.12 before 17.4.5, 17.5 before 17.5.3, and 17.6 before 17.6.1. This issue allows an attacker with access to a victim's Personal Access Token (PAT) to escalate privileges.

    Published: 26 Nov 2024
    5.3
    Medium

    CVE-2024-8177

    Last Modified: 13 Dec 2024

    An issue was discovered in GitLab CE/EE affecting all versions starting from 15.6 prior to 17.4.5, starting from 17.5 prior to 17.5.3, starting from 17.6 prior to 17.6.1 which could cause Denial of Service via integrating a malicious harbor registry.

    Published: 26 Nov 2024
    6.5
    Medium

    CVE-2024-8237

    Last Modified: 13 Dec 2024

    A Denial of Service (DoS) issue has been discovered in GitLab CE/EE affecting all versions prior to 12.6 prior to 17.4.5, 17.5 prior to 17.5.3, and 17.6 prior to 17.6.1. An attacker could cause a denial of service with a crafted cargo.toml file.

    Published: 26 Nov 2024
    8.1
    High

    CVE-2024-32965

    Last Modified: 23 Sept 2025

    Lobe Chat is an open-source, AI chat framework. Versions of lobe-chat prior to 1.19.13 have an unauthorized ssrf vulnerability. An attacker can construct malicious requests to cause SSRF without logging in, attack intranet services, and leak sensitive information. The jwt token header X-Lobe-Chat-Auth strored proxy address and OpenAI API Key, can be modified to scan an internal network in the target lobe-web environment. This issue has been addressed in release version 1.19.13 and all users are advised to upgrade. There are no known workarounds for this vulnerability.

    Published: 26 Nov 2024
    7.4
    High

    CVE-2024-8676

    Last Modified: 24 Apr 2026

    A vulnerability was found in CRI-O, where it can be requested to take a checkpoint archive of a container and later be asked to restore it. When it does that restoration, it attempts to restore the mounts from the restore archive instead of the pod request. As a result, the validations run on the pod spec, verifying that the pod has access to the mounts it specifies are not applicable to a restored container. This flaw allows a malicious user to trick CRI-O into restoring a pod that doesn't have access to host mounts. The user needs access to the kubelet or cri-o socket to call the restore endpoint and trigger the restore.

    Published: 26 Nov 2024
    6.1
    Medium

    CVE-2024-10878

    Last Modified: 8 Apr 2026

    The Sugar Calendar – Simple Event Management plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg & remove_query_arg without appropriate escaping on the URL in all versions up to, and including, 3.3.0. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

    Published: 26 Nov 2024
    7.3
    High

    CVE-2024-11622

    Last Modified: 12 Dec 2024

    An XML external entity injection (XXE) vulnerability in HPE Insight Remote Support may allow remote users to disclose information in certain cases.

    Published: 26 Nov 2024
    8.7
    High

    CVE-2024-11745

    Last Modified: 3 Dec 2024

    A vulnerability was found in Tenda AC8 16.03.34.09 and classified as critical. Affected by this issue is the function route_static_check of the file /goform/SetStaticRouteCfg. The manipulation of the argument list leads to stack-based buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

    Published: 26 Nov 2024
    6.9
    Medium

    CVE-2024-11744

    Last Modified: 3 Dec 2024

    A vulnerability has been found in 1000 Projects Portfolio Management System MCA 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /register.php. The manipulation of the argument name leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. Other parameters might be affected as well.

    Published: 26 Nov 2024
    6.9
    Medium

    CVE-2024-11743

    Last Modified: 4 Dec 2024

    A vulnerability, which was classified as problematic, was found in SourceCodester Best House Rental Management System 1.0. Affected is an unknown function of the file /rental/ajax.php?action=delete_user of the component POST Request Handler. The manipulation leads to cross-site request forgery. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

    Published: 26 Nov 2024
    5.3
    Medium

    CVE-2024-11742

    Last Modified: 4 Dec 2024

    A vulnerability, which was classified as problematic, has been found in SourceCodester Best House Rental Management System 1.0. This issue affects some unknown processing of the file /rental/ajax.php?action=save_tenant. The manipulation of the argument lastname/firstname/middlename leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. Other parameters might be affected as well.

    Published: 26 Nov 2024
    5.3
    Medium

    CVE-2024-10240

    Last Modified: 13 Dec 2024

    An issue has been discovered in GitLab EE affecting all versions starting from 17.3 before 17.3.7, all versions starting from 17.4 before 17.4.4, all versions starting from 17.5 before 17.5.2 in which an unauthenticated user may be able to read some information about an MR in a private project, under certain circumstances.

    Published: 26 Nov 2024
    6.5
    Medium

    CVE-2024-36463

    Last Modified: 8 Oct 2025

    The implementation of atob in "Zabbix JS" allows to create a string with arbitrary content and use it to access internal properties of objects.

    Published: 26 Nov 2024