CVE Feed

    Dashboard / CVE

    9.4
    Critical

    CVE-2024-38645

    Last Modified: 20 Sept 2025

    A server-side request forgery (SSRF) vulnerability has been reported to affect Notes Station 3. If exploited, the vulnerability could allow remote authenticated attackers to read application data. We have already fixed the vulnerability in the following version: Notes Station 3 3.9.7 and later

    Published: 22 Nov 2024
    8.4
    High

    CVE-2024-38646

    Last Modified: 20 Sept 2025

    An incorrect permission assignment for critical resource vulnerability has been reported to affect Notes Station 3. If exploited, the vulnerability could allow local authenticated attackers who have gained administrator access to read or modify the resource. We have already fixed the vulnerability in the following version: Notes Station 3 3.9.7 and later

    Published: 22 Nov 2024
    7.9
    High

    CVE-2024-38647

    Last Modified: 8 Dec 2025

    An exposure of sensitive information vulnerability has been reported to affect QNAP AI Core. If exploited, the vulnerability could allow remote attackers to compromise the security of the system. We have already fixed the vulnerability in the following version: QNAP AI Core 3.4.1 and later

    Published: 22 Nov 2024
    9.5
    Critical

    CVE-2024-48860

    Last Modified: 24 Sept 2025

    An OS command injection vulnerability has been reported to affect several product versions. If exploited, the vulnerability could allow remote attackers to execute commands. We have already fixed the vulnerability in the following version: QuRouter 2.4.3.103 and later

    Published: 22 Nov 2024
    7.3
    High

    CVE-2024-48861

    Last Modified: 24 Sept 2025

    An OS command injection vulnerability has been reported to affect several product versions. If exploited, the vulnerability could allow local network attackers to execute commands. We have already fixed the vulnerability in the following versions: QuRouter 2.4.4.106 and later

    Published: 22 Nov 2024
    8.7
    High

    CVE-2024-48862

    Last Modified: 8 Dec 2025

    A link following vulnerability has been reported to affect QuLog Center. If exploited, the vulnerability could allow remote attackers to traverse the file system to unintended locations and read or overwrite the contents of unexpected files. We have already fixed the vulnerability in the following versions: QuLog Center 1.7.0.831 ( 2024/10/15 ) and later QuLog Center 1.8.0.888 ( 2024/10/15 ) and later

    Published: 22 Nov 2024
    6.9
    Medium

    CVE-2024-50395

    Last Modified: 8 Dec 2025

    An authorization bypass through user-controlled key vulnerability has been reported to affect Media Streaming add-on. If exploited, the vulnerability could allow local network attackers to gain privilege. We have already fixed the vulnerability in the following version: Media Streaming add-on 500.1.1.6 ( 2024/08/02 ) and later

    Published: 22 Nov 2024
    7.7
    High

    CVE-2024-50396

    Last Modified: 23 Sept 2025

    A use of externally-controlled format string vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers to obtain secret data or modify memory. We have already fixed the vulnerability in the following versions: QTS 5.2.1.2930 build 20241025 and later QuTS hero h5.2.1.2929 build 20241025 and later

    Published: 22 Nov 2024
    7.7
    High

    CVE-2024-50397

    Last Modified: 23 Sept 2025

    A use of externally-controlled format string vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have gained user access to obtain secret data or modify memory. We have already fixed the vulnerability in the following versions: QTS 5.2.1.2930 build 20241025 and later QuTS hero h5.2.1.2929 build 20241025 and later

    Published: 22 Nov 2024
    2.1
    Low

    CVE-2024-50398

    Last Modified: 23 Sept 2025

    A use of externally-controlled format string vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have gained administrator access to obtain secret data or modify memory. We have already fixed the vulnerability in the following versions: QTS 5.2.1.2930 build 20241025 and later QuTS hero h5.2.1.2929 build 20241025 and later

    Published: 22 Nov 2024
    2.1
    Low

    CVE-2024-50399

    Last Modified: 23 Sept 2025

    A use of externally-controlled format string vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have gained administrator access to obtain secret data or modify memory. We have already fixed the vulnerability in the following versions: QTS 5.2.1.2930 build 20241025 and later QuTS hero h5.2.1.2929 build 20241025 and later

    Published: 22 Nov 2024
    2.1
    Low

    CVE-2024-50400

    Last Modified: 23 Sept 2025

    A use of externally-controlled format string vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have gained administrator access to obtain secret data or modify memory. We have already fixed the vulnerability in the following versions: QTS 5.2.1.2930 build 20241025 and later QuTS hero h5.2.1.2929 build 20241025 and later

    Published: 22 Nov 2024
    2.1
    Low

    CVE-2024-50401

    Last Modified: 23 Sept 2025

    A use of externally-controlled format string vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have gained administrator access to obtain secret data or modify memory. We have already fixed the vulnerability in the following versions: QTS 5.2.1.2930 build 20241025 and later QuTS hero h5.2.1.2929 build 20241025 and later

    Published: 22 Nov 2024
    4.3
    Medium

    CVE-2024-49054

    Last Modified: 8 Jul 2025

    Microsoft Edge (Chromium-based) Spoofing Vulnerability

    Published: 22 Nov 2024
    2.6
    Low

    CVE-2024-45719

    Last Modified: 1 Jul 2025

    Inadequate Encryption Strength vulnerability in Apache Answer. This issue affects Apache Answer: through 1.4.0. The ids generated using the UUID v1 version are to some extent not secure enough. It can cause the generated token to be predictable. Users are recommended to upgrade to version 1.4.1, which fixes the issue.

    Published: 22 Nov 2024
    —
    Unknown

    CVE-2024-11637

    Last Modified: 14 Jan 2025

    ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All references and descriptions in this candidate have been removed to prevent accidental usage.

    Published: 22 Nov 2024
    9.8
    Critical

    CVE-2024-41779

    Last Modified: 15 Aug 2025

    IBM Engineering Systems Design Rhapsody - Model Manager 7.0.2 and 7.0.3 could allow a remote attacker to bypass security restrictions, caused by a race condition. By sending a specially crafted request, an attacker could exploit this vulnerability to remotely execute code.

    Published: 22 Nov 2024
    5.1
    Medium

    CVE-2024-41781

    Last Modified: 15 Aug 2025

    IBM PowerVM Platform KeyStore (IBM PowerVM Hypervisor FW950.00 through FW950.90, FW1030.00 through FW1030.60, FW1050.00 through FW1050.20, and FW1060.00 through FW1060.10 functionality can be compromised if an attacker gains service access to the HMC. An attacker that gains service access to the HMC can locate and through a series of service procedures decrypt data contained in the Platform KeyStore.

    Published: 22 Nov 2024
    6.5
    Medium

    CVE-2024-51766

    Last Modified: 15 Apr 2026

    A potential security vulnerability has been identified in the HPE NonStop DISK UTIL (T9208) product. This vulnerability could be exploited to cause a denial of service (DoS) to NonStop server. It exists in all prior DISK UTIL product versions of L-series and J-series.

    Published: 22 Nov 2024
    6.7
    Medium

    CVE-2021-30299

    Last Modified: 25 Nov 2024

    Possible out of bound access in audio module due to lack of validation of user provided input.

    Published: 22 Nov 2024
    6.7
    Medium

    CVE-2017-9711

    Last Modified: 25 Nov 2024

    Certain unprivileged processes are able to perform IOCTL calls.

    Published: 22 Nov 2024
    6.5
    Medium

    CVE-2024-7882

    Last Modified: 2 Jun 2026

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Special Minds Design and Software e-Commerce allows SQL Injection. This issue affects e-Commerce: before 22.11.2024.

    Published: 22 Nov 2024
    8.2
    High

    CVE-2024-7837

    Last Modified: 4 Sept 2026

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Firmanet Software ERP allows SQL Injection. This issue affects ERP: before 15.0.1.

    Published: 22 Nov 2024
    5.8
    Medium

    CVE-2024-8929

    Last Modified: 3 Nov 2025

    In PHP versions 8.1.* before 8.1.31, 8.2.* before 8.2.26, 8.3.* before 8.3.14, a hostile MySQL server can cause the client to disclose the content of its heap containing data from other SQL requests and possible other data belonging to different users of the same server.

    Published: 22 Nov 2024
    9.8
    Critical

    CVE-2024-8932

    Last Modified: 3 Nov 2025

    In PHP versions 8.1.* before 8.1.31, 8.2.* before 8.2.26, 8.3.* before 8.3.14, uncontrolled long string inputs to ldap_escape() function on 32-bit systems can cause an integer overflow, resulting in an out-of-bounds write.

    Published: 22 Nov 2024
    6.6
    Medium

    CVE-2024-9422

    Last Modified: 9 Jun 2025

    The GEO my WP WordPress plugin before 4.5, gmw-premium-settings WordPress plugin before 3.1 does not sufficiently validate files to be uploaded, which could allow attackers to upload arbitrary files such as PHP on the server.

    Published: 22 Nov 2024
    4.3
    Medium

    CVE-2024-10666

    Last Modified: 15 Apr 2026

    The Easy Twitter Feed – Twitter feeds plugin for WP plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.2.6 via the [etf] shortcode. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract data from password protected, private, or draft posts that they should not have access to.

    Published: 22 Nov 2024
    6.1
    Medium

    CVE-2024-8735

    Last Modified: 8 Apr 2026

    The MailMunch – Grow your Email List plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 3.1.8. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

    Published: 22 Nov 2024
    6.1
    Medium

    CVE-2024-11225

    Last Modified: 15 Apr 2026

    The Premium Packages – Sell Digital Products Securely plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 5.9.3. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

    Published: 22 Nov 2024
    5.5
    Medium

    CVE-2024-10034

    Last Modified: 15 Apr 2026

    The Gallery Blocks with Lightbox. Image Gallery, (HTML5 video , YouTube, Vimeo) Video Gallery and Lightbox for native gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the gallery link text parameter in all versions up to, and including, 3.2.4.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Editor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 22 Nov 2024
    8.1
    High

    CVE-2024-11601

    Last Modified: 8 Apr 2026

    The Sky Addons for Elementor (Free Templates Library, Live Copy, Animations, Post Grid, Post Carousel, Particles, Sliders, Chart, Blog, Video Gallery) plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.6.1. This is due to missing or incorrect nonce validation on the save_options() function. This makes it possible for unauthenticated attackers to update arbitrary options on the WordPress site via a forged request granted they can trick a site administrator into performing an action such as clicking on a link. Please note this is limited to option values that can be saved as arrays.

    Published: 22 Nov 2024
    4.3
    Medium

    CVE-2024-11355

    Last Modified: 15 Apr 2026

    The Ultimate YouTube Video & Shorts Player With Vimeo plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the get_setting() function in all versions up to, and including, 3.3. This makes it possible for authenticated attackers, with Subscriber-level access and above, to view settings for playlists.

    Published: 22 Nov 2024
    8.1
    High

    CVE-2024-11104

    Last Modified: 8 Apr 2026

    The Sky Addons for Elementor (Free Templates Library, Live Copy, Animations, Post Grid, Post Carousel, Particles, Sliders, Chart, Blogs) plugin for WordPress is vulnerable to unauthorized modification of data that can lead to a denial of service due to a missing capability check on the save_options() function in all versions up to, and including, 2.6.2. This makes it possible for authenticated attackers, with subscriber-level access and above, to update arbitrary options on the WordPress site. Please note this is limited to option values that can be saved as arrays.

    Published: 22 Nov 2024
    6.4
    Medium

    CVE-2024-11381

    Last Modified: 15 Apr 2026

    The Control horas plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'ch_registro' shortcode in all versions up to, and including, 1.0.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 22 Nov 2024
    6.7
    Medium

    CVE-2024-38296

    Last Modified: 4 Feb 2025

    Dell Edge Gateway 3200, versions prior to 15.40.30.2879, and Edge Gateway 5200, versions prior to 12.0.94.2380, contain an Exposure of Sensitive Information in Shared Microarchitectural Structures during Transient Execution vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to information exposure.

    Published: 22 Nov 2024
    5.5
    Medium

    CVE-2024-47142

    Last Modified: 15 Apr 2026

    AIPHONE IXG SYSTEM IXG-2C7 firmware Ver.2.03 and earlier and IXG-2C7-L firmware Ver.2.03 and earlier contain an issue with insufficiently protected credentials, which may allow a network-adjacent authenticated attacker to perform unintended operations.

    Published: 22 Nov 2024
    5.4
    Medium

    CVE-2024-45837

    Last Modified: 15 Apr 2026

    Use of hard-coded cryptographic key issue exists in AIPHONE IX SYSTEM, IXG SYSTEM, and System Support Software. A network-adjacent unauthenticated attacker may log in to SFTP service and obtain and/or manipulate unauthorized files.

    Published: 22 Nov 2024
    6.5
    Medium

    CVE-2024-39290

    Last Modified: 15 Apr 2026

    Insufficiently protected credentials issue exists in AIPHONE IX SYSTEM and IXG SYSTEM. A network-adjacent unauthenticated attacker may obtain sensitive information such as a username and its password in the address book.

    Published: 22 Nov 2024
    8
    High

    CVE-2024-31408

    Last Modified: 15 Apr 2026

    OS command injection vulnerability exists in AIPHONE IX SYSTEM and IXG SYSTEM. A network-adjacent authenticated attacker may execute an arbitrary OS command with root privileges by sending a specially crafted request.

    Published: 22 Nov 2024
    6.7
    Medium

    CVE-2024-51073

    Last Modified: 15 Apr 2026

    An issue in KIA Seltos vehicle instrument cluster with software and hardware v1.0 allows attackers to control or disrupt CAN communication between the instrument cluster and CAN bus. NOTE: this is disputed by the Supplier because the findings came from a potentially unrealistic test environment (an isolated ECU part that was not in a vehicle), and because the observed behavior follows the UDS (Unified Diagnostic Services) specification.

    Published: 22 Nov 2024
    5.3
    Medium

    CVE-2024-51072

    Last Modified: 15 Apr 2026

    An issue in KIA Seltos vehicle instrument cluster with software and hardware v1.0 allows attackers to cause a Denial of Service (DoS) via ECU reset UDS service. NOTE: this is disputed by the Supplier because the findings came from a potentially unrealistic test environment (an isolated ECU part that was not in a vehicle), and because the ECUReset specification does not allow a manufacturer to require SecurityAccess and Authentication.

    Published: 22 Nov 2024
    6.8
    Medium

    CVE-2024-50657

    Last Modified: 15 Apr 2026

    An issue in Owncloud android apk v.4.3.1 allows a physically proximate attacker to escalate privileges via the PassCodeViewModel class, specifically in the checkPassCodeIsValid method

    Published: 22 Nov 2024
    9.8
    Critical

    CVE-2024-37782

    Last Modified: 15 Apr 2026

    An LDAP injection vulnerability in the login page of Gladinet CentreStack v13.12.9934.54690 allows attackers to access sensitive data or execute arbitrary commands via a crafted payload injected into the username field.

    Published: 22 Nov 2024
    7.5
    High

    CVE-2024-52726

    Last Modified: 7 Jul 2025

    CRMEB v5.4.0 is vulnerable to Arbitrary file read in the save_basics function which allows an attacker to obtain sensitive information

    Published: 22 Nov 2024
    6.7
    Medium

    CVE-2024-51074

    Last Modified: 15 Apr 2026

    Incorrect access control in KIA Seltos vehicle instrument cluster with software and hardware v1.0 allows attackers to arbitrarily change odometer readings in the vehicle by targeting the instrument cluster through the unsecured CAN network. NOTE: this is disputed by the supplier because the CAN bus is not externally exposed, and because the packets can only increase the odometer reading (which typically has no value to an adversary). Also, this is disputed by the Supplier because the findings came from a potentially unrealistic test environment (an isolated ECU part that was not in a vehicle), and because the observed behavior follows the UDS (Unified Diagnostic Services) specification.

    Published: 22 Nov 2024
    9.8
    Critical

    CVE-2024-52723

    Last Modified: 13 Mar 2025

    In TOTOLINK X6000R V9.4.0cu.1041_B20240224 in the shttpd file, the Uci_Set Str function is used without strict parameter filtering. An attacker can achieve arbitrary command execution by constructing the payload.

    Published: 22 Nov 2024
    9.8
    Critical

    CVE-2024-53438

    Last Modified: 28 Mar 2025

    EventAttendance.php in ChurchCRM 5.7.0 is vulnerable to SQL injection. An attacker can exploit this vulnerability by manipulating the 'Event' parameter, which is directly interpolated into the SQL query without proper sanitization or validation, allowing attackers to execute arbitrary SQL commands.

    Published: 22 Nov 2024
    5.4
    Medium

    CVE-2024-37783

    Last Modified: 15 Apr 2026

    A reflected cross-site scripting (XSS) vulnerability in Gladinet CentreStack v13.12.9934.54690 allows attackers to inject malicious JavaScript into the web browser of a victim via the sessionId parameter at /portal/ForgotPassword.aspx.

    Published: 22 Nov 2024
    7.5
    High

    CVE-2024-44786

    Last Modified: 15 Apr 2026

    Incorrect access control in Meabilis CMS 1.0 allows attackers to access other users' address books via unspecified vectors.

    Published: 22 Nov 2024
    6.2
    Medium

    CVE-2024-47863

    Last Modified: 15 Apr 2026

    An issue was discovered in Centreon Web 24.10.x before 24.10.0, 24.04.x before 24.04.8, 23.10.x before 23.10.18, 23.04.x before 23.04.23, and 22.10.x before 22.10.26. A stored XSS was found in the user configuration contact name field. This form is only accessible to authenticated users with high-privilege access.

    Published: 22 Nov 2024