CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2024-11310

    Last Modified: 20 Nov 2024

    The DVC from TRCore has a Path Traversal vulnerability, allowing unauthenticated remote attackers to exploit this vulnerability to read arbitrary system files.

    Published: 18 Nov 2024
    7.5
    High

    CVE-2024-11309

    Last Modified: 20 Nov 2024

    The DVC from TRCore has a Path Traversal vulnerability, allowing unauthenticated remote attackers to exploit this vulnerability to read arbitrary system files.

    Published: 18 Nov 2024
    6.2
    Medium

    CVE-2024-11308

    Last Modified: 20 Nov 2024

    The DVC from TRCore encrypts files using a hardcoded key. Attackers can use this key to decrypt the files and restore the original content.

    Published: 18 Nov 2024
    6.9
    Medium

    CVE-2024-11306

    Last Modified: 15 Apr 2026

    A vulnerability, which was classified as critical, has been found in Altenergy Power Control Software up to 20241108. This issue affects some unknown processing of the file /index.php/display/database/. The manipulation leads to improper authorization. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. Other endpoints might be affected as well. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 18 Nov 2024
    5.3
    Medium

    CVE-2024-11305

    Last Modified: 15 Apr 2026

    A vulnerability classified as critical was found in Altenergy Power Control Software up to 20241108. This vulnerability affects the function get_status_zigbee of the file /index.php/display/status_zigbee. The manipulation of the argument date leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 18 Nov 2024
    6.5
    Medium

    CVE-2024-48293

    Last Modified: 15 Apr 2026

    Incorrect access control in QuickHeal Antivirus Pro 24.1.0.182 and earlier allows authenticated attackers with low-level privileges to arbitrarily modify antivirus settings.

    Published: 18 Nov 2024
    8.8
    High

    CVE-2024-48292

    Last Modified: 15 Apr 2026

    An issue in the wssrvc.exe service of QuickHeal Antivirus Pro Version v24.0 and Quick Heal Total Security v24.0 allows authenticated attackers to escalate privileges.

    Published: 18 Nov 2024
    5.4
    Medium

    CVE-2024-33231

    Last Modified: 15 Apr 2026

    Cross Site Scripting vulnerability in Ferozo Email version 1.1 allows a local attacker to execute arbitrary code via a crafted payload to the PDF preview component.

    Published: 18 Nov 2024
    9.8
    Critical

    CVE-2015-20111

    Last Modified: 15 Apr 2026

    miniupnp before 4c90b87, as used in Bitcoin Core before 0.12 and other products, lacks checks for snprintf return values, leading to a buffer overflow and significant data leak, a different vulnerability than CVE-2019-12107. In Bitcoin Core before 0.12, remote code execution was possible in conjunction with CVE-2015-6031 exploitation.

    Published: 18 Nov 2024
    7.8
    High

    CVE-2024-52945

    Last Modified: 30 Apr 2025

    An issue was discovered in Veritas NetBackup before 10.5. This only applies to NetBackup components running on a Windows Operating System. If a user executes specific NetBackup commands or an attacker uses social engineering techniques to impel the user to execute the commands, a malicious DLL could be loaded, resulting in execution of the attacker's code in the user's security context.

    Published: 18 Nov 2024
    5.4
    Medium

    CVE-2024-52947

    Last Modified: 15 Apr 2026

    A cross-site scripting (XSS) vulnerability in LemonLDAP::NG before 2.20.1 allows remote attackers to inject arbitrary web script or HTML via the url parameter of the upgrade session confirmation page (upgradeSession / forceUpgrade) if the "Upgrade session" plugin has been enabled by an admin

    Published: 18 Nov 2024
    8.8
    High

    CVE-2024-52946

    Last Modified: 15 Apr 2026

    An issue was discovered in LemonLDAP::NG before 2.20.1. An Improper Check during session refresh allows an authenticated user to raise their authentication level if the admin configured an "Adaptative authentication rule" with an increment instead of an absolute value.

    Published: 18 Nov 2024
    5.4
    Medium

    CVE-2024-52943

    Last Modified: 30 Apr 2025

    An issue was discovered in Veritas Enterprise Vault before 15.1 UPD882911, ZDI-CAN-24697. It allows an authenticated remote attacker to inject a parameter into an HTTP request, allowing for Cross-Site Scripting (XSS) while viewing archived content. This could reflect back to an authenticated user without sanitization if executed by that user.

    Published: 18 Nov 2024
    5.4
    Medium

    CVE-2024-52942

    Last Modified: 30 Apr 2025

    An issue was discovered in Veritas Enterprise Vault before 15.1 UPD882911, ZDI-CAN-24696. It allows an authenticated remote attacker to inject a parameter into an HTTP request, allowing for Cross-Site Scripting (XSS) while viewing archived content. This could reflect back to an authenticated user without sanitization if executed by that user.

    Published: 18 Nov 2024
    5.4
    Medium

    CVE-2024-52941

    Last Modified: 15 Apr 2026

    An issue was discovered in Veritas Enterprise Vault before 15.1 UPD882911, ZDI-CAN-24695. It allows an authenticated remote attacker to inject a parameter into an HTTP request, allowing for Cross-Site Scripting (XSS) while viewing archived content. This could reflect back to an authenticated user without sanitization if executed by that user.

    Published: 18 Nov 2024
    6.5
    Medium

    CVE-2024-52922

    Last Modified: 30 Apr 2025

    In Bitcoin Core before 25.1, an attacker can cause a node to not download the latest block, because there can be minutes of delay when an announcing peer stalls instead of complying with the peer-to-peer protocol specification.

    Published: 18 Nov 2024
    7.5
    High

    CVE-2019-25220

    Last Modified: 22 May 2025

    Bitcoin Core before 24.0.1 allows remote attackers to cause a denial of service (daemon crash) via a flood of low-difficulty header chains (aka a "Chain Width Expansion" attack) because a node does not first verify that a presented chain has enough work before committing to store it.

    Published: 18 Nov 2024
    4.8
    Medium

    CVE-2024-50849

    Last Modified: 20 Oct 2025

    A Stored Cross-Site Scripting (XSS) vulnerability in the "Rules" functionality of WorldServer v11.8.2 allows a remote authenticated attacker to execute arbitrary JavaScript code.

    Published: 18 Nov 2024
    7.8
    High

    CVE-2024-50804

    Last Modified: 15 Apr 2026

    Insecure Permissions vulnerability in Micro-star International MSI Center Pro 2.1.37.0 allows a local attacker to execute arbitrary code via the Device_DeviceID.dat.bak file within the C:\ProgramData\MSI\One Dragon Center\Data folder

    Published: 18 Nov 2024
    5.3
    Medium

    CVE-2024-52913

    Last Modified: 30 Apr 2025

    In Bitcoin Core before 0.21.0, an attacker could prevent a node from seeing a specific unconfirmed transaction, because transaction re-requests are mishandled.

    Published: 18 Nov 2024
    5.4
    Medium

    CVE-2024-52944

    Last Modified: 30 Apr 2025

    An issue was discovered in Veritas Enterprise Vault before 15.1 UPD882911, ZDI-CAN-24698. It allows an authenticated remote attacker to inject a parameter into an HTTP request, allowing for Cross-Site Scripting while viewing archived content. This could reflect back to an authenticated user without sanitization if executed by that user.

    Published: 18 Nov 2024
    7.5
    High

    CVE-2023-49952

    Last Modified: 7 May 2025

    Mastodon 4.1.x before 4.1.17 and 4.2.x before 4.2.9 allows a bypass of rate limiting via a crafted HTTP request header.

    Published: 18 Nov 2024
    9.8
    Critical

    CVE-2024-44756

    Last Modified: 1 Oct 2025

    NUS-M9 ERP Management Software v3.0.0 was discovered to contain a SQL injection vulnerability via the usercode parameter at /UserWH/checkLogin.

    Published: 18 Nov 2024
    7.5
    High

    CVE-2024-44757

    Last Modified: 1 Oct 2025

    An arbitrary file download vulnerability in the component /Basics/DownloadInpFile of NUS-M9 ERP Management Software v3.0.0 allows attackers to download arbitrary files and access sensitive information via a crafted interface request.

    Published: 18 Nov 2024
    6.5
    Medium

    CVE-2024-52926

    Last Modified: 15 Apr 2026

    Delinea Privilege Manager before 12.0.2 mishandles the security of the Windows agent.

    Published: 18 Nov 2024
    7.5
    High

    CVE-2024-52940

    Last Modified: 15 Apr 2026

    AnyDesk through 8.1.0 on Windows, when Allow Direct Connections is enabled, inadvertently exposes a public IP address within network traffic. The attacker must know the victim's AnyDesk ID.

    Published: 18 Nov 2024
    7.5
    High

    CVE-2024-28058

    Last Modified: 15 Apr 2026

    In RSA NetWitness (NW) Platform before 12.5.1, even when an administrator revokes the access of a specific user with an active session, an internal threat actor could impersonate the revoked user and gain unauthorized access to sensitive data.

    Published: 18 Nov 2024
    5.5
    Medium

    CVE-2024-48294

    Last Modified: 15 Apr 2026

    A NULL pointer dereference in the component libPdfCore.dll of Wondershare PDF Reader v1.0.9.2544 allows attackers to cause a Denial of Service (DoS) via a crafted PDF file.

    Published: 18 Nov 2024
    6.5
    Medium

    CVE-2024-50848

    Last Modified: 20 Oct 2025

    An XML External Entity (XXE) vulnerability in the Import object and Translation Memory import functionalities of WorldServer v11.8.2 to access sensitive information and execute arbitrary commands via supplying a crafted .tmx file.

    Published: 18 Nov 2024
    9.8
    Critical

    CVE-2024-50919

    Last Modified: 21 May 2025

    Jpress until v5.1.1 has arbitrary file uploads on the windows platform, and the construction of non-standard file formats such as .jsp. can lead to arbitrary command execution

    Published: 18 Nov 2024
    9.8
    Critical

    CVE-2024-51053

    Last Modified: 15 Apr 2026

    An arbitrary file upload vulnerability in the component /main/fileupload.php of AVSCMS v8.2.0 allows attackers to execute arbitrary code via uploading a crafted file.

    Published: 18 Nov 2024
    9.8
    Critical

    CVE-2024-51051

    Last Modified: 15 Apr 2026

    AVSCMS v8.2.0 was discovered to contain weak default credentials for the Administrator account.

    Published: 18 Nov 2024
    7.5
    High

    CVE-2024-52912

    Last Modified: 30 Apr 2025

    Bitcoin Core before 0.21.0 allows a network split that is resultant from an integer overflow (calculating the time offset for newly connecting peers) and an abs64 logic bug.

    Published: 18 Nov 2024
    6.5
    Medium

    CVE-2024-52918

    Last Modified: 15 Apr 2026

    Bitcoin-Qt in Bitcoin Core before 0.20.0 allows remote attackers to cause a denial of service (memory consumption and application crash) via a BIP21 r parameter for a URL that has a large file.

    Published: 18 Nov 2024
    7.5
    High

    CVE-2024-52914

    Last Modified: 30 Apr 2025

    In Bitcoin Core before 0.18.0, a node could be stalled for hours when processing the orphans of a crafted unconfirmed transaction.

    Published: 18 Nov 2024
    7.5
    High

    CVE-2024-52915

    Last Modified: 30 Apr 2025

    Bitcoin Core before 0.20.0 allows remote attackers to cause a denial of service (memory consumption) via a crafted INV message.

    Published: 18 Nov 2024
    7.5
    High

    CVE-2024-52916

    Last Modified: 30 Apr 2025

    Bitcoin Core before 0.15.0 allows a denial of service (OOM kill of a daemon process) via a flood of minimum difficulty headers.

    Published: 18 Nov 2024
    6.5
    Medium

    CVE-2024-52917

    Last Modified: 30 Apr 2025

    Bitcoin Core before 22.0 has a miniupnp infinite loop in which it allocates memory on the basis of random data received over the network, e.g., large M-SEARCH replies from a fake UPnP device.

    Published: 18 Nov 2024
    6.5
    Medium

    CVE-2024-52919

    Last Modified: 30 Apr 2025

    Bitcoin Core before 22.0 has a CAddrMan nIdCount integer overflow and resultant assertion failure (and daemon exit) via a flood of addr messages.

    Published: 18 Nov 2024
    7.5
    High

    CVE-2024-52920

    Last Modified: 30 Apr 2025

    Bitcoin Core before 0.20.0 allows remote attackers to cause a denial of service (infinite loop) via a malformed GETDATA message.

    Published: 18 Nov 2024
    5.3
    Medium

    CVE-2024-52921

    Last Modified: 30 Apr 2025

    In Bitcoin Core before 25.0, a peer can affect the download state of other peers by sending a mutated block.

    Published: 18 Nov 2024
    9.8
    Critical

    CVE-2023-43091

    Last Modified: 6 Aug 2025

    A flaw was found in GNOME Maps, which is vulnerable to a code injection attack via its service.json configuration file. If the configuration file is malicious, it may execute arbitrary code.

    Published: 17 Nov 2024
    8.1
    High

    CVE-2024-52867

    Last Modified: 15 Apr 2026

    guix-daemon in GNU Guix before 5ab3c4c allows privilege escalation because build outputs are accessible by local users before file metadata concerns (e.g., for setuid and setgid programs) are properly addressed. The vulnerability can be remediated within the product via certain pull, reconfigure, and restart actions. Both 5ab3c4c and 5582241 are needed to resolve the vulnerability.

    Published: 17 Nov 2024
    7.5
    High

    CVE-2024-52871

    Last Modified: 7 Jul 2025

    In Flagsmith before 2.134.1, it is possible to bypass the ALLOW_REGISTRATION_WITHOUT_INVITE setting.

    Published: 17 Nov 2024
    7.5
    High

    CVE-2024-52872

    Last Modified: 7 Jul 2025

    In Flagsmith before 2.134.1, the get_document endpoint is not correctly protected by permissions.

    Published: 17 Nov 2024
    7.5
    High

    CVE-2024-52876

    Last Modified: 15 Apr 2026

    Holy Stone Remote ID Module HSRID01, firmware distributed with the Drone Go2 mobile application before 1.1.8, allows unauthenticated "remote power off" actions (in broadcast mode) via multiple read operations on the ASTM Remote ID (0xFFFA) GATT.

    Published: 17 Nov 2024
    9.1
    Critical

    CVE-2024-52397

    Last Modified: 23 Apr 2026

    Unrestricted Upload of File with Dangerous Type vulnerability in Davor Zeljkovic Convert Docx2post convert-docx2post allows Upload a Web Shell to a Web Server.This issue affects Convert Docx2post: from n/a through <= 1.4.

    Published: 16 Nov 2024
    9.1
    Critical

    CVE-2024-52398

    Last Modified: 23 Apr 2026

    Unrestricted Upload of File with Dangerous Type vulnerability in Halyra CDI collect-and-deliver-interface-for-woocommerce.This issue affects CDI: from n/a through <= 5.5.3.

    Published: 16 Nov 2024
    9.9
    Critical

    CVE-2024-52399

    Last Modified: 23 Apr 2026

    Unrestricted Upload of File with Dangerous Type vulnerability in Clarisse K. Writer Helper writer-helper allows Upload a Web Shell to a Web Server.This issue affects Writer Helper: from n/a through <= 3.1.6.

    Published: 16 Nov 2024
    9.9
    Critical

    CVE-2024-52400

    Last Modified: 23 Apr 2026

    Unrestricted Upload of File with Dangerous Type vulnerability in Subhasis Laha Gallerio gallerio allows Upload a Web Shell to a Web Server.This issue affects Gallerio: from n/a through <= 1.01.

    Published: 16 Nov 2024