CVE Feed

    Dashboard / CVE

    7.8
    High

    CVE-2018-9367

    Last Modified: 22 Nov 2024

    In FT_ACDK_CCT_V2_OP_ISP_SET_TUNING_PARAS of Meta_CCAP_Para.cpp, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 19 Nov 2024
    7.8
    High

    CVE-2018-9366

    Last Modified: 22 Nov 2024

    In IMSA_Recv_Thread and VT_IMCB_Thread of ImsaClient.cpp and VideoTelephony.c, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 19 Nov 2024
    7.5
    High

    CVE-2018-9364

    Last Modified: 22 Nov 2024

    In the LG LAF component, there is a special command that allowed modification of certain partitions. This could lead to bypass of secure boot. User interaction is not needed for exploitation.

    Published: 19 Nov 2024
    6.5
    Medium

    CVE-2018-9348

    Last Modified: 22 Nov 2024

    In SMF_ParseMetaEvent of eas_smf.c, there is a possible integer overflow. This could lead to remote denial of service due to resource exhaustion with no additional execution privileges needed. User interaction is needed for exploitation.

    Published: 19 Nov 2024
    5.5
    Medium

    CVE-2018-9346

    Last Modified: 22 Nov 2024

    In BnAudioPolicyService::onTransact of AudioPolicyService.cpp, there is a possible information disclosure due to uninitialized data. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 19 Nov 2024
    5.5
    Medium

    CVE-2018-9345

    Last Modified: 22 Nov 2024

    In BnAudioPolicyService::onTransact of AudioPolicyService.cpp, there is a possible information disclosure due to uninitialized data. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 19 Nov 2024
    8
    High

    CVE-2024-51503

    Last Modified: 4 Sept 2025

    A security agent manual scan command injection vulnerability in the Trend Micro Deep Security 20 Agent could allow an attacker to escalate privileges and execute arbitrary code on an affected machine. In certain circumstances, attackers that have legitimate access to the domain may be able to remotely inject commands to other machines in the same domain. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability locally and must have domain user privileges to affect other machines.

    Published: 19 Nov 2024
    8.8
    High

    CVE-2024-21697

    Last Modified: 11 Feb 2025

    This High severity RCE (Remote Code Execution) vulnerability was introduced in versions 4.2.8 of Sourcetree for Mac and 3.4.19 for Sourcetree for Windows. This RCE (Remote Code Execution) vulnerability, with a CVSS Score of 8.8, allows an unauthenticated attacker to execute arbitrary code which has high impact to confidentiality, high impact to integrity, high impact to availability, and requires user interaction. Atlassian recommends that Sourcetree for Mac and Sourcetree for Windows customers upgrade to latest version, if you are unable to do so, upgrade your instance to one of the specified supported fixed versions: Sourcetree for Mac 4.2: Upgrade to a release greater than or equal to 4.2.9 Sourcetree for Windows 3.4: Upgrade to a release greater than or equal to 3.4.20 See the release notes ([https://www.sourcetreeapp.com/download-archives]). You can download the latest version of Sourcetree for Mac and Sourcetree for Windows from the download center ([https://www.sourcetreeapp.com/download-archives]). This vulnerability was reported via our Penetration Testing program.

    Published: 19 Nov 2024
    7.8
    High

    CVE-2018-9344

    Last Modified: 22 Nov 2024

    In several functions of DescramblerImpl.cpp, there is a possible use after free due to improper locking. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 19 Nov 2024
    7.8
    High

    CVE-2018-9341

    Last Modified: 22 Nov 2024

    In impeg2d_mc_fullx_fully of impeg2d_mc.c there is a possible out of bound write due to missing bounds check. This could lead to remote arbitrary code execution with no additional execution privileges needed. User interaction is needed for exploitation.

    Published: 19 Nov 2024
    5.5
    Medium

    CVE-2018-9340

    Last Modified: 22 Nov 2024

    In ResStringPool::setTo of ResourceTypes.cpp, it's possible for an attacker to control the value of mStringPoolSize to be out of bounds, causing information disclosure.

    Published: 19 Nov 2024
    7.8
    High

    CVE-2018-9339

    Last Modified: 22 Nov 2024

    In writeTypedArrayList and readTypedArrayList of Parcel.java, there is a possible escalation of privilege due to type confusion. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 19 Nov 2024
    5.9
    Medium

    CVE-2024-50430

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Beaver Builder Beaver Builder beaver-builder-lite-version allows Stored XSS.This issue affects Beaver Builder: from n/a through <= 2.8.3.7.

    Published: 19 Nov 2024
    —
    Unknown

    CVE-2024-53248

    Last Modified: 22 Jan 2026

    ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. The CVE was never used.

    Published: 19 Nov 2024
    —
    Unknown

    CVE-2024-53249

    Last Modified: 22 Jan 2026

    ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. The CVE was never used.

    Published: 19 Nov 2024
    —
    Unknown

    CVE-2024-53250

    Last Modified: 22 Jan 2026

    ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. The CVE was never used.

    Published: 19 Nov 2024
    —
    Unknown

    CVE-2024-53251

    Last Modified: 22 Jan 2026

    ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. The CVE was never used.

    Published: 19 Nov 2024
    —
    Unknown

    CVE-2024-53252

    Last Modified: 22 Jan 2026

    ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. The CVE was never used.

    Published: 19 Nov 2024
    7.8
    High

    CVE-2018-9338

    Last Modified: 22 Nov 2024

    In ResStringPool::setTo of ResourceTypes.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 19 Nov 2024
    7.8
    High

    CVE-2023-21270

    Last Modified: 18 Dec 2024

    In restorePermissionState of PermissionManagerServiceImpl.java, there is a possible way for an app to keep permissions that should be revoked due to incorrect permission flags cleared during an update. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.

    Published: 19 Nov 2024
    7.8
    High

    CVE-2017-13315

    Last Modified: 18 Dec 2024

    In writeToParcel and createFromParcel of DcParamObject.java, there is a permission bypass due to a write size mismatch. This could lead to an elevation of privileges where the user can start an activity with system privileges, with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 19 Nov 2024
    7.8
    High

    CVE-2024-48992

    Last Modified: 3 Nov 2025

    Qualys discovered that needrestart, before version 3.8, allows local attackers to execute arbitrary code as root by tricking needrestart into running the Ruby interpreter with an attacker-controlled RUBYLIB environment variable.

    Published: 19 Nov 2024
    7.8
    High

    CVE-2024-48991

    Last Modified: 3 Nov 2025

    Qualys discovered that needrestart, before version 3.8, allows local attackers to execute arbitrary code as root by winning a race condition and tricking needrestart into running their own, fake Python interpreter (instead of the system's real Python interpreter). The initial security fix (6ce6136) introduced a regression which was subsequently resolved (42af5d3).

    Published: 19 Nov 2024
    7.8
    High

    CVE-2024-48990

    Last Modified: 3 Nov 2025

    Qualys discovered that needrestart, before version 3.8, allows local attackers to execute arbitrary code as root by tricking needrestart into running the Python interpreter with an attacker-controlled PYTHONPATH environment variable.

    Published: 19 Nov 2024
    7.8
    High

    CVE-2024-11003

    Last Modified: 3 Nov 2025

    Qualys discovered that needrestart, before version 3.8, passes unsanitized data to a library (Modules::ScanDeps) which expects safe input. This could allow a local attacker to execute arbitrary shell commands. Please see the related CVE-2024-10224 in Modules::ScanDeps.

    Published: 19 Nov 2024
    5.3
    Medium

    CVE-2024-10224

    Last Modified: 3 Nov 2025

    Qualys discovered that if unsanitized input was used with the library Modules::ScanDeps, before version 1.36 a local attacker could possibly execute arbitrary shell commands by open()ing a "pesky pipe" (such as passing "commands|" as a filename) or by passing arbitrary strings to eval().

    Published: 19 Nov 2024
    10
    Critical

    CVE-2024-42450

    Last Modified: 3 Sept 2026

    The Versa Director uses PostgreSQL (Postgres) to store operational and configuration data. It is also needed for High Availability function of the Versa Director. The default configuration has a common password across all instances of Versa Director. By default, Versa Director configures Postgres to listen on all network interfaces. This combination allows an unauthenticated attacker to access and administer the database or read local filesystem contents to escalate privileges on the system. Exploitation Status: Versa Networks is not aware of this exploitation in any production systems. A proof of concept exists in the lab environment. Workarounds or Mitigation: Starting with the latest 22.1.4 version of Versa Director, the software will automatically restrict access to the Postgres and HA ports to only the local and peer Versa Directors. For older releases, Versa recommends performing manual hardening of HA ports. Please refer to the following link for the steps https://docs.versa-networks.com/Solutions/System_Hardening/Perform_Manual_Hardening_for_Versa_Director#Secure_HA_Ports This vulnerability is not exploitable on Versa Directors if published Firewall guidelines are implemented. We have validated that no Versa-hosted head ends have been affected by this vulnerability. All Versa-hosted head ends are patched and hardened. Please contact Versa Technical Support or Versa account team for any further assistance. Software Download Links: 22.1.4: https://support.versa-networks.com/support/solutions/articles/23000026708-release-22-1-4

    Published: 19 Nov 2024
    5.4
    Medium

    CVE-2022-47424

    Last Modified: 26 Jan 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Repute InfoSystems ARMember, Repute InfoSystems ARMember Premium allows Cross-Site Request Forgery.This issue affects ARMember: from n/a through 4.0.5; ARMember Premium: from n/a before 6.7.1.

    Published: 19 Nov 2024
    4.3
    Medium

    CVE-2024-43338

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Automattic Crowdsignal Dashboard – Polls, Surveys & more polldaddy allows Cross Site Request Forgery.This issue affects Crowdsignal Dashboard – Polls, Surveys & more: from n/a through <= 3.1.3.

    Published: 19 Nov 2024
    4.3
    Medium

    CVE-2024-51686

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Deepak Khokhar Manage User Columns manage-user-columns allows Cross Site Request Forgery.This issue affects Manage User Columns: from n/a through <= 1.0.5.

    Published: 19 Nov 2024
    7.1
    High

    CVE-2024-52388

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in mikeage Hebrew Date hebrewdates allows Stored XSS.This issue affects Hebrew Date: from n/a through <= 2.1.0.

    Published: 19 Nov 2024
    9.6
    Critical

    CVE-2024-52401

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in HuangYe WuDeng Hacklog DownloadManager hacklog-downloadmanager allows Upload a Web Shell to a Web Server.This issue affects Hacklog DownloadManager: from n/a through <= 2.1.4.

    Published: 19 Nov 2024
    9.6
    Critical

    CVE-2024-52402

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in gunghoinc Exclusive Content Password Protect exclusive-content-password-protect allows Upload a Web Shell to a Web Server.This issue affects Exclusive Content Password Protect: from n/a through <= 1.1.0.

    Published: 19 Nov 2024
    4.3
    Medium

    CVE-2024-52420

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Themeisle Disable Admin Notices individually disable-admin-notices allows Cross Site Request Forgery.This issue affects Disable Admin Notices individually: from n/a through <= 1.4.0.

    Published: 19 Nov 2024
    7.1
    High

    CVE-2024-50532

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jerin K Alexander Events Manager Pro – extended events-manager-pro-extended allows Reflected XSS.This issue affects Events Manager Pro – extended: from n/a through <= 0.1.

    Published: 19 Nov 2024
    7.1
    High

    CVE-2024-50533

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in David Garcia Domain Sharding domain-sharding allows Stored XSS.This issue affects Domain Sharding: from n/a through <= 1.2.1.

    Published: 19 Nov 2024
    7.1
    High

    CVE-2024-50534

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in techdabang World Prayer Time world-prayer-time allows Stored XSS.This issue affects World Prayer Time: from n/a through <= 2.0.

    Published: 19 Nov 2024
    7.1
    High

    CVE-2024-51631

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Md Eftakhairul Islam Sticky Social Bar sticky-social-bar allows Cross Site Request Forgery.This issue affects Sticky Social Bar: from n/a through <= 2.0.

    Published: 19 Nov 2024
    7.1
    High

    CVE-2024-51632

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Sam Hoe SH Slideshow sh-slideshow allows Stored XSS.This issue affects SH Slideshow: from n/a through <= 4.3.

    Published: 19 Nov 2024
    7.1
    High

    CVE-2024-51633

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in ivycat Simple Page Specific Sidebars page-specific-sidebars allows Stored XSS.This issue affects Simple Page Specific Sidebars: from n/a through <= 2.14.1.

    Published: 19 Nov 2024
    7.1
    High

    CVE-2024-51634

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in a.ankit Webriti Custom Login webriti-custom-login-page allows Reflected XSS.This issue affects Webriti Custom Login: from n/a through <= 0.3.

    Published: 19 Nov 2024
    7.1
    High

    CVE-2024-51635

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Garmur While Loading while-it-is-loading allows Stored XSS.This issue affects While Loading: from n/a through <= 3.0.

    Published: 19 Nov 2024
    7.1
    High

    CVE-2024-51636

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Z.com byGMO GMO Social Connection gmo-social-connection allows Cross-Site Scripting (XSS).This issue affects GMO Social Connection: from n/a through <= 1.2.

    Published: 19 Nov 2024
    7.1
    High

    CVE-2024-51637

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in sroyalty Admin SMS Alert admin-sms-alert allows Stored XSS.This issue affects Admin SMS Alert: from n/a through <= 1.1.0.

    Published: 19 Nov 2024
    7.1
    High

    CVE-2024-51638

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Sanjeev Mohindra Awesome Shortcodes For Genesis awesome-shortcodes-for-genesis allows Stored XSS.This issue affects Awesome Shortcodes For Genesis: from n/a through 1.1.8.

    Published: 19 Nov 2024
    7.1
    High

    CVE-2024-51639

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Hints Naver Blog naver-blog-api allows Stored XSS.This issue affects Naver Blog: from n/a through <= 1.0.

    Published: 19 Nov 2024
    7.1
    High

    CVE-2024-51640

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Matt Rude MDR Webmaster Tools mdr-webmaster-tools allows Stored XSS.This issue affects MDR Webmaster Tools: from n/a through <= 1.1.

    Published: 19 Nov 2024
    7.1
    High

    CVE-2024-51641

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Juan Camilo Advanced PDF Generator advanced-pdf-generator allows Stored XSS.This issue affects Advanced PDF Generator: from n/a through <= 0.4.0.

    Published: 19 Nov 2024
    7.1
    High

    CVE-2024-51642

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in ivan9146 Seo Free seo-free allows Stored XSS.This issue affects Seo Free: from n/a through <= 1.4.

    Published: 19 Nov 2024
    7.1
    High

    CVE-2024-51643

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in ragaskar Amazon Associate Filter amazon-associate-filter allows Stored XSS.This issue affects Amazon Associate Filter: from n/a through <= 0.4.

    Published: 19 Nov 2024