CVE Feed

    Dashboard / CVE

    7.2
    High

    CVE-2024-50368

    Last Modified: 23 Jan 2026

    A CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" was discovered affecting the following devices manufactured by Advantech: EKI-6333AC-2G (<= 1.6.3), EKI-6333AC-2GD (<= v1.6.3) and EKI-6333AC-1GPO (<= v1.2.1). The source of the vulnerability relies on multiple parameters belonging to the "basic_htm" API which are not properly sanitized before being concatenated to OS level commands.

    Published: 26 Nov 2024
    7.2
    High

    CVE-2024-50367

    Last Modified: 23 Jan 2026

    A CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" was discovered affecting the following devices manufactured by Advantech: EKI-6333AC-2G (<= 1.6.3), EKI-6333AC-2GD (<= v1.6.3) and EKI-6333AC-1GPO (<= v1.2.1). The source of the vulnerability relies on multiple parameters belonging to the "sta_log_htm" API which are not properly sanitized before being concatenated to OS level commands.

    Published: 26 Nov 2024
    7.2
    High

    CVE-2024-50366

    Last Modified: 23 Jan 2026

    A CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" was discovered affecting the following devices manufactured by Advantech: EKI-6333AC-2G (<= 1.6.3), EKI-6333AC-2GD (<= v1.6.3) and EKI-6333AC-1GPO (<= v1.2.1). The source of the vulnerability relies on multiple parameters belonging to the "applications_apply" API which are not properly sanitized before being concatenated to OS level commands.

    Published: 26 Nov 2024
    7.2
    High

    CVE-2024-50365

    Last Modified: 23 Jan 2026

    A CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" was discovered affecting the following devices manufactured by Advantech: EKI-6333AC-2G (<= 1.6.3), EKI-6333AC-2GD (<= v1.6.3) and EKI-6333AC-1GPO (<= v1.2.1). The source of the vulnerability relies on multiple parameters belonging to the "lan_apply" API which are not properly sanitized before being concatenated to OS level commands.

    Published: 26 Nov 2024
    7.2
    High

    CVE-2024-50364

    Last Modified: 23 Jan 2026

    A CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" was discovered affecting the following devices manufactured by Advantech: EKI-6333AC-2G (<= 1.6.3), EKI-6333AC-2GD (<= v1.6.3) and EKI-6333AC-1GPO (<= v1.2.1). The source of the vulnerability relies on multiple parameters belonging to the "export_log" API which are not properly sanitized before being concatenated to OS level commands.

    Published: 26 Nov 2024
    7.2
    High

    CVE-2024-50363

    Last Modified: 23 Jan 2026

    A CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" was discovered affecting the following devices manufactured by Advantech: EKI-6333AC-2G (<= 1.6.3), EKI-6333AC-2GD (<= v1.6.3) and EKI-6333AC-1GPO (<= v1.2.1). The source of the vulnerability relies on multiple parameters belonging to the "mp_apply" API which are not properly sanitized before being concatenated to OS level commands.

    Published: 26 Nov 2024
    7.2
    High

    CVE-2024-50362

    Last Modified: 23 Jan 2026

    A CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" was discovered affecting the following devices manufactured by Advantech: EKI-6333AC-2G (<= 1.6.3), EKI-6333AC-2GD (<= v1.6.3) and EKI-6333AC-1GPO (<= v1.2.1). The source of the vulnerability relies on multiple parameters belonging to the "connection_profile_apply" API which are not properly sanitized before being concatenated to OS level commands.

    Published: 26 Nov 2024
    7.2
    High

    CVE-2024-50361

    Last Modified: 23 Jan 2026

    A CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" was discovered affecting the following devices manufactured by Advantech: EKI-6333AC-2G (<= 1.6.3), EKI-6333AC-2GD (<= v1.6.3) and EKI-6333AC-1GPO (<= v1.2.1). The source of the vulnerability relies on multiple parameters belonging to the "certificate_file_remove" API which are not properly sanitized before being concatenated to OS level commands.

    Published: 26 Nov 2024
    7.2
    High

    CVE-2024-50360

    Last Modified: 23 Jan 2026

    A CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" was discovered affecting the following devices manufactured by Advantech: EKI-6333AC-2G (<= 1.6.3), EKI-6333AC-2GD (<= v1.6.3) and EKI-6333AC-1GPO (<= v1.2.1). The source of the vulnerability relies on multiple parameters belonging to the "snmp_apply" API which are not properly sanitized before being concatenated to OS level commands.

    Published: 26 Nov 2024
    7.2
    High

    CVE-2024-50359

    Last Modified: 23 Jan 2026

    A CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" was discovered affecting the following devices manufactured by Advantech: EKI-6333AC-2G (<= 1.6.3), EKI-6333AC-2GD (<= v1.6.3) and EKI-6333AC-1GPO (<= v1.2.1). The source of the vulnerability relies on multiple parameters belonging to the "scan_ap" API which are not properly sanitized before being concatenated to OS level commands.

    Published: 26 Nov 2024
    7.2
    High

    CVE-2024-50358

    Last Modified: 23 Jan 2026

    A CWE-15 "External Control of System or Configuration Setting" was discovered affecting the following devices manufactured by Advantech: EKI-6333AC-2G (<= 1.6.3), EKI-6333AC-2GD (<= v1.6.3) and EKI-6333AC-1GPO (<= v1.2.1). The vulnerability can be exploited by authenticated users by restoring a tampered configuration backup.

    Published: 26 Nov 2024
    9.8
    Critical

    CVE-2024-11680

    Last Modified: 22 Nov 2025

    ProjectSend versions prior to r1720 are affected by an improper authentication vulnerability. Remote, unauthenticated attackers can exploit this flaw by sending crafted HTTP requests to options.php, enabling unauthorized modification of the application's configuration. Successful exploitation allows attackers to create accounts, upload webshells, and embed malicious JavaScript.

    Published: 26 Nov 2024
    6.5
    Medium

    CVE-2024-11708

    Last Modified: 4 Apr 2025

    Missing thread synchronization primitives could have led to a data race on members of the PlaybackParams structure. This vulnerability affects Firefox < 133 and Thunderbird < 133.

    Published: 26 Nov 2024
    9.1
    Critical

    CVE-2024-11705

    Last Modified: 24 Jun 2025

    `NSC_DeriveKey` inadvertently assumed that the `phKey` parameter is always non-NULL. When it was passed as NULL, a segmentation fault (SEGV) occurred, leading to crashes. This behavior conflicted with the PKCS#11 v3.0 specification, which allows `phKey` to be NULL for certain mechanisms. This vulnerability affects Firefox < 133 and Thunderbird < 133.

    Published: 26 Nov 2024
    6.5
    Medium

    CVE-2024-11706

    Last Modified: 7 Apr 2025

    A null pointer dereference may have inadvertently occurred in `pk12util`, and specifically in the `SEC_ASN1DecodeItem_Util` function, when handling malformed or improperly formatted input files. This vulnerability affects Firefox < 133 and Thunderbird < 133.

    Published: 26 Nov 2024
    9.8
    Critical

    CVE-2024-11698

    Last Modified: 24 Jun 2025

    A flaw in handling fullscreen transitions may have inadvertently caused the application to become stuck in fullscreen mode when a modal dialog was opened during the transition. This issue left users unable to exit fullscreen mode using standard actions like pressing "Esc" or accessing right-click menus, resulting in a disrupted browsing experience until the browser is restarted. *This bug only affects the application when running on macOS. Other operating systems are unaffected.* This vulnerability affects Firefox < 133, Firefox ESR < 128.5, Thunderbird < 133, and Thunderbird < 128.5.

    Published: 26 Nov 2024
    5.7
    Medium

    CVE-2024-11703

    Last Modified: 5 Apr 2025

    On Android, Firefox may have inadvertently allowed viewing saved passwords without the required device PIN authentication. This vulnerability affects Firefox < 133.

    Published: 26 Nov 2024
    7.5
    High

    CVE-2024-11702

    Last Modified: 5 Apr 2025

    Copying sensitive information from Private Browsing tabs on Android, such as passwords, may have inadvertently stored data in the cloud-based clipboard history if enabled. This vulnerability affects Firefox < 133 and Thunderbird < 133.

    Published: 26 Nov 2024
    9.8
    Critical

    CVE-2024-11693

    Last Modified: 3 Apr 2025

    The executable file warning was not presented when downloading .library-ms files. *Note: This issue only affected Windows operating systems. Other operating systems are unaffected.* This vulnerability affects Firefox < 133, Firefox ESR < 128.5, Thunderbird < 133, and Thunderbird < 128.5.

    Published: 26 Nov 2024
    4.3
    Medium

    CVE-2024-11701

    Last Modified: 5 Apr 2025

    The incorrect domain may have been displayed in the address bar during an interrupted navigation attempt. This could have led to user confusion and possible spoofing attacks. This vulnerability affects Firefox < 133 and Thunderbird < 133.

    Published: 26 Nov 2024
    8.1
    High

    CVE-2024-11700

    Last Modified: 3 Apr 2025

    Malicious websites may have been able to perform user intent confirmation through tapjacking. This could have led to users unknowingly approving the launch of external applications, potentially exposing them to underlying vulnerabilities. This vulnerability affects Firefox < 133 and Thunderbird < 133.

    Published: 26 Nov 2024
    8.8
    High

    CVE-2024-11691

    Last Modified: 24 Jun 2025

    Certain WebGL operations on Apple silicon M series devices could have lead to an out-of-bounds write and memory corruption due to a flaw in Apple's GPU driver. *This bug only affected the application on Apple M series hardware. Other platforms were unaffected.* This vulnerability affects Firefox < 133, Firefox ESR < 128.5, Firefox ESR < 115.18, Thunderbird < 133, Thunderbird < 128.5, and Thunderbird < 115.18.

    Published: 26 Nov 2024
    6.1
    Medium

    CVE-2024-11032

    Last Modified: 15 Apr 2026

    The Parsi Date plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 5.1.1. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

    Published: 26 Nov 2024
    8.4
    High

    CVE-2018-11952

    Last Modified: 9 Jan 2025

    An image with a version lower than the fuse version may potentially be booted lead to improper authentication.

    Published: 26 Nov 2024
    9.8
    Critical

    CVE-2018-11922

    Last Modified: 9 Jan 2025

    Wrong configuration in Touch Pal application can collect user behavior data without awareness by the user.

    Published: 26 Nov 2024
    8.4
    High

    CVE-2017-18153

    Last Modified: 9 Jan 2025

    A race condition exists in a driver potentially leading to a use-after-free condition.

    Published: 26 Nov 2024
    9.8
    Critical

    CVE-2017-17772

    Last Modified: 9 Jan 2025

    In multiple functions that process 802.11 frames, out-of-bounds reads can occur due to insufficient validation.

    Published: 26 Nov 2024
    8.4
    High

    CVE-2017-15832

    Last Modified: 9 Jan 2025

    Buffer overwrite in the WLAN host driver by leveraging a compromised WLAN FW

    Published: 26 Nov 2024
    9.8
    Critical

    CVE-2017-11076

    Last Modified: 9 Jan 2025

    On some hardware revisions where VP9 decoding is hardware-accelerated, the frame size is not programmed correctly into the decoder hardware which can lead to an invalid memory access by the decoder.

    Published: 26 Nov 2024
    8.4
    High

    CVE-2016-10394

    Last Modified: 9 Jan 2025

    Initial xbl_sec revision does not have all the debug policy features and critical checks.

    Published: 26 Nov 2024
    6.4
    Medium

    CVE-2024-11091

    Last Modified: 15 Apr 2026

    The Support SVG – Upload svg files in wordpress without hassle plugin for WordPress is vulnerable to Stored Cross-Site Scripting via REST API SVG File uploads in all versions up to, and including, 1.1.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses the SVG file.

    Published: 26 Nov 2024
    6.4
    Medium

    CVE-2024-11192

    Last Modified: 15 Apr 2026

    The Spotify Play Button for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's spotifyplaybutton shortcode in all versions up to, and including, 2.11 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 26 Nov 2024
    6.4
    Medium

    CVE-2024-11119

    Last Modified: 15 Apr 2026

    The BNE Gallery Extended plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'gallery' shortcode in all versions up to, and including, 1.2.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 26 Nov 2024
    5.5
    Medium

    CVE-2024-9170

    Last Modified: 8 Apr 2026

    The Booster for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wcj_product_meta shortcode in all versions up to, and including, 7.2.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with ShopManager-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 26 Nov 2024
    7.5
    High

    CVE-2024-36254

    Last Modified: 15 Apr 2026

    Out-of-bounds read vulnerability exists in Sharp Corporation and Toshiba Tec Corporation multiple MFPs (multifunction printers), which may lead to a denial-of-service (DoS) condition.

    Published: 26 Nov 2024
    7.5
    High

    CVE-2024-36251

    Last Modified: 15 Apr 2026

    The web interface of the affected devices process some crafted HTTP requests improperly, leading to a device crash. More precisely, a crafted parameter to billcodedef_sub_sel.html is not processed properly and device-crash happens. As for the details of affected product names, model numbers, and versions, refer to the information provided by the respective vendors listed under [References].

    Published: 26 Nov 2024
    7.4
    High

    CVE-2024-36249

    Last Modified: 15 Apr 2026

    Cross-site scripting vulnerability exists in Sharp Corporation and Toshiba Tech Corporation multiple MFPs (multifunction printers). If this vulnerability is exploited, an arbitrary script may be executed on the administrative page of the affected MFPs. As for the details of affected product names, model numbers, and versions, refer to the information provided by the respective vendors listed under [References].

    Published: 26 Nov 2024
    9.1
    Critical

    CVE-2024-36248

    Last Modified: 15 Apr 2026

    API keys for some cloud services are hardcoded in the "main" binary. As for the details of affected product names, model numbers, and versions, refer to the information provided by the respective vendors listed under [References].

    Published: 26 Nov 2024
    9.1
    Critical

    CVE-2024-35244

    Last Modified: 15 Apr 2026

    There are several hidden accounts. Some of them are intended for maintenance engineers, and with the knowledge of their passwords (e.g., by examining the coredump), these accounts can be used to re-configure the device. As for the details of affected product names, model numbers, and versions, refer to the information provided by the respective vendors listed under [References].

    Published: 26 Nov 2024
    5.3
    Medium

    CVE-2024-34162

    Last Modified: 15 Apr 2026

    The web interface of the affected devices is designed to hide the LDAP credentials even for administrative users. But configuring LDAP authentication to "SIMPLE", the device communicates with the LDAP server in clear-text. The LDAP password can be retrieved from this clear-text communication. As for the details of affected product names, model numbers, and versions, refer to the information provided by the respective vendors listed under [References].

    Published: 26 Nov 2024
    5.3
    Medium

    CVE-2024-33616

    Last Modified: 15 Apr 2026

    Admin authentication can be bypassed with some specific invalid credentials, which allows logging in with an administrative privilege. Sharp Corporation states the telnet feature is implemented on older models only, and is planning to provide the firmware update to remove the feature. As for the details of affected product names, model numbers, and versions, refer to the information provided by the respective vendors listed under [References].

    Published: 26 Nov 2024
    9.1
    Critical

    CVE-2024-33610

    Last Modified: 15 Apr 2026

    "sessionlist.html" and "sys_trayentryreboot.html" are accessible with no authentication. "sessionlist.html" provides logged-in users' session information including session cookies, and "sys_trayentryreboot.html" allows to reboot the device. As for the details of affected product names, model numbers, and versions, refer to the information provided by the respective vendors listed under [References].

    Published: 26 Nov 2024
    7.5
    High

    CVE-2024-33605

    Last Modified: 15 Apr 2026

    Improper processing of some parameters of installed_emanual_list.html leads to a path traversal vulnerability. As for the details of affected product names, model numbers, and versions, refer to the information provided by the respective vendors listed under [References].

    Published: 26 Nov 2024
    5.9
    Medium

    CVE-2024-32151

    Last Modified: 15 Apr 2026

    User passwords are decrypted and stored on memory before any user logged in. Those decrypted passwords can be retrieved from the coredump file. As for the details of affected product names, model numbers, and versions, refer to the information provided by the respective vendors listed under [References].

    Published: 26 Nov 2024
    5.9
    Medium

    CVE-2024-29978

    Last Modified: 15 Apr 2026

    User passwords are decrypted and stored on memory before any user logged in. Those decrypted passwords can be retrieved from the coredump file. As for the details of affected product names, model numbers, and versions, refer to the information provided by the respective vendors listed under [References].

    Published: 26 Nov 2024
    5.9
    Medium

    CVE-2024-29146

    Last Modified: 15 Apr 2026

    User passwords are decrypted and stored on memory before any user logged in. Those decrypted passwords can be retrieved from the coredump file. As for the details of affected product names, model numbers, and versions, refer to the information provided by the respective vendors listed under [References].

    Published: 26 Nov 2024
    5.9
    Medium

    CVE-2024-28955

    Last Modified: 15 Apr 2026

    Affected devices create coredump files when crashed, storing them with world-readable permission. Any local user of the device can examine the coredump files, and research the memory contents. As for the details of affected product names, model numbers, and versions, refer to the information provided by the respective vendors listed under [References].

    Published: 26 Nov 2024
    9
    Critical

    CVE-2024-28038

    Last Modified: 15 Apr 2026

    The web interface of the affected devices processes a cookie value improperly, leading to a stack buffer overflow. More precisely, giving too long character string to MFPSESSIONID parameter results in a stack buffer overflow. As for the details of affected product names, model numbers, and versions, refer to the information provided by the respective vendors listed under [References].

    Published: 26 Nov 2024
    6.1
    Medium

    CVE-2024-11202

    Last Modified: 15 Apr 2026

    Multiple plugins for WordPress are vulnerable to Reflected Cross-Site Scripting via the cminds_free_guide shortcode in various versions due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

    Published: 26 Nov 2024
    7.2
    High

    CVE-2024-9504

    Last Modified: 15 Apr 2026

    The Booking calendar, Appointment Booking System plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 3.2.15 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses the SVG file.

    Published: 26 Nov 2024