CVE Feed

    Dashboard / CVE

    8
    High

    CVE-2024-8979

    Last Modified: 8 Apr 2026

    The Essential Addons for Elementor – Best Elementor Addon, Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 6.0.9 via the 'init_content_lostpassword_user_email_controls' function. This makes it possible for authenticated attackers, with Author-level access and above, to extract sensitive data including usernames and passwords of any user, including Administrators, as long as that user opens the email notification for a password change request and images are not blocked by the email client.

    Published: 15 Nov 2024
    6.9
    Medium

    CVE-2024-11238

    Last Modified: 19 Nov 2024

    A vulnerability, which was classified as critical, was found in Landray EKP up to 16.0. This affects the function delPreviewFile of the file /sys/ui/sys_ui_component/sysUiComponent.do?method=delPreviewFile. The manipulation of the argument directoryPath leads to path traversal. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 15 Nov 2024
    7.5
    High

    CVE-2024-45784

    Last Modified: 3 Jun 2025

    Apache Airflow versions before 2.10.3 contain a vulnerability that could expose sensitive configuration variables in task logs. This vulnerability allows DAG authors to unintentionally or intentionally log sensitive configuration variables. Unauthorized users could access these logs, potentially exposing critical data that could be exploited to compromise the security of the Airflow deployment. In version 2.10.3, secrets are now masked in task logs to prevent sensitive configuration variables from being exposed in the logging output. Users should upgrade to Airflow 2.10.3 or the latest version to eliminate this vulnerability. If you suspect that DAG authors could have logged the secret values to the logs and that your logs are not additionally protected, it is also recommended that you update those secrets.

    Published: 15 Nov 2024
    8.7
    High

    CVE-2024-11237

    Last Modified: 19 Nov 2024

    A vulnerability, which was classified as critical, has been found in TP-Link VN020 F3v(T) TT_V6.2.1021. Affected by this issue is some unknown functionality of the component DHCP DISCOVER Packet Parser. The manipulation of the argument hostname leads to stack-based buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

    Published: 15 Nov 2024
    4.8
    Medium

    CVE-2024-0875

    Last Modified: 19 Nov 2024

    A stored cross-site scripting (XSS) vulnerability exists in openemr/openemr version 7.0.1. An attacker can inject malicious payloads into the 'inputBody' field in the Secure Messaging feature, which can then be sent to other users. When the recipient views the malicious message, the payload is executed, potentially compromising their account. This issue is fixed in version 7.0.2.1.

    Published: 15 Nov 2024
    5.4
    Medium

    CVE-2024-1097

    Last Modified: 19 Nov 2024

    A stored cross-site scripting (XSS) vulnerability exists in craigk5n/webcalendar version 1.3.0. The vulnerability occurs in the 'Report Name' input field while creating a new report. An attacker can inject malicious scripts, which are then executed in the context of other users who view the report, potentially leading to the theft of user accounts and cookies.

    Published: 15 Nov 2024
    6.1
    Medium

    CVE-2024-1240

    Last Modified: 19 Nov 2024

    An open redirection vulnerability exists in pyload/pyload version 0.5.0. The vulnerability is due to improper handling of the 'next' parameter in the login functionality. An attacker can exploit this vulnerability to redirect users to malicious sites, which can be used for phishing or other malicious activities. The issue is fixed in pyload-ng 0.5.0b3.dev79.

    Published: 15 Nov 2024
    5.9
    Medium

    CVE-2024-0787

    Last Modified: 19 Nov 2024

    phpIPAM version 1.5.1 contains a vulnerability where an attacker can bypass the IP block mechanism to brute force passwords for users by using the 'X-Forwarded-For' header. The issue lies in the 'get_user_ip()' function in 'class.Common.php' at lines 1044 and 1045, where the presence of the 'X-Forwarded-For' header is checked and used instead of 'REMOTE_ADDR'. This vulnerability allows attackers to perform brute force attacks on user accounts, including the admin account. The issue is fixed in version 1.7.0.

    Published: 15 Nov 2024
    6.1
    Medium

    CVE-2024-10825

    Last Modified: 8 Apr 2026

    The Hide My WP Ghost – Security & Firewall plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the URL in all versions up to, and including, 5.3.01 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick an administrative user into performing an action such as clicking on a link.

    Published: 15 Nov 2024
    6.4
    Medium

    CVE-2024-8961

    Last Modified: 8 Apr 2026

    The Essential Addons for Elementor – Best Elementor Addon, Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘nomore_items_text’ parameter in all versions up to, and including, 6.0.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 15 Nov 2024
    9.8
    Critical

    CVE-2024-10443

    Last Modified: 16 Sept 2025

    Improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability in Task Manager component in Synology BeePhotos before 1.0.2-10026 and 1.1.0-10053 and Synology Photos before 1.6.2-0720 and 1.7.0-0795 allows remote attackers to execute arbitrary code via unspecified vectors.

    Published: 15 Nov 2024
    6.6
    Medium

    CVE-2024-9529

    Last Modified: 11 Jun 2025

    The Secure Custom Fields WordPress plugin before 6.3.9, Secure Custom Fields WordPress plugin before 6.3.6.3, Advanced Custom Fields Pro WordPress plugin before 6.3.9 does not prevent users from running arbitrary functions through its setting import functionalities, which could allow high privilege users such as admin to run arbitrary PHP functions.

    Published: 15 Nov 2024
    7.2
    High

    CVE-2024-10793

    Last Modified: 8 Apr 2026

    The WP Activity Log plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the user_id parameter in all versions up to, and including, 5.2.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever an administrative user accesses an injected page.

    Published: 15 Nov 2024
    7.2
    High

    CVE-2024-10260

    Last Modified: 8 Apr 2026

    The Tripetto plugin for WordPress is vulnerable to Stored Cross-Site Scripting via File uploads in all versions up to, and including, 8.0.11 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses the file.

    Published: 15 Nov 2024
    6.1
    Medium

    CVE-2024-9356

    Last Modified: 8 Apr 2026

    The Yotpo: Product & Photo Reviews for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'yotpo_user_email' and 'yotpo_user_name' parameters in all versions up to, and including, 1.7.9 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

    Published: 15 Nov 2024
    4.3
    Medium

    CVE-2024-10582

    Last Modified: 8 Apr 2026

    The Music Player for Elementor – Audio Player & Podcast Player plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the import_mpfe_template() function in all versions up to, and including, 2.4.1. This makes it possible for authenticated attackers, with Subscriber-level access and above, to import templates.

    Published: 15 Nov 2024
    6.4
    Medium

    CVE-2024-10113

    Last Modified: 8 Apr 2026

    The WP AdCenter – Ad Manager & Adsense Ads plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wpadcenter_ad shortcode in all versions up to, and including, 2.5.7 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 15 Nov 2024
    6.1
    Medium

    CVE-2024-39610

    Last Modified: 20 Nov 2024

    Cross-site scripting vulnerability exists in FitNesse releases prior to 20241026. If this vulnerability is exploited, an arbitrary script may be executed on the web browser of the user who is using the product.

    Published: 15 Nov 2024
    5.3
    Medium

    CVE-2024-42499

    Last Modified: 15 Apr 2026

    Improper limitation of a pathname to a restricted directory ('Path Traversal') issue exists in FitNesse releases prior to 20241026. If this vulnerability is exploited, an attacker may be able to know whether a file exists at a specific path, and/or obtain some part of the file contents under specific conditions.

    Published: 15 Nov 2024
    6.1
    Medium

    CVE-2024-9609

    Last Modified: 8 Apr 2026

    The LearnPress Export Import – WordPress extension for LearnPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'learnpress_import_form_server' parameter in all versions up to, and including, 4.0.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

    Published: 15 Nov 2024
    4.3
    Medium

    CVE-2024-10897

    Last Modified: 8 Apr 2026

    The Tutor LMS Elementor Addons plugin for WordPress is vulnerable to unauthorized plugin installation due to a missing capability check on the install_etlms_dependency_plugin() function in all versions up to, and including, 2.1.5. This makes it possible for authenticated attackers, with Subscriber-level access and above, to install Elementor or Tutor LMS. Please note the impact of this issue is incredibly limited due to the fact that these two plugins will likely already be installed as a dependency of the plugin.

    Published: 15 Nov 2024
    9.8
    Critical

    CVE-2024-10924

    Last Modified: 23 Jan 2026

    The Really Simple Security (Free, Pro, and Pro Multisite) plugins for WordPress are vulnerable to authentication bypass in versions 9.0.0 to 9.1.1.1. This is due to improper user check error handling in the two-factor REST API actions with the 'check_login_and_get_user' function. This makes it possible for unauthenticated attackers to log in as any existing user on the site, such as an administrator, when the "Two-Factor Authentication" setting is enabled (disabled by default).

    Published: 15 Nov 2024
    9.8
    Critical

    CVE-2024-11120

    Last Modified: 30 Oct 2025

    Certain EOL GeoVision devices have an OS Command Injection vulnerability. Unauthenticated remote attackers can exploit this vulnerability to inject and execute arbitrary system commands on the device. Moreover, this vulnerability has already been exploited by attackers, and we have received related reports.

    Published: 15 Nov 2024
    5.9
    Medium

    CVE-2024-10104

    Last Modified: 11 Apr 2025

    The Jobs for WordPress plugin before 2.7.8 does not sanitise and escape some of its Job settings, which could allow high privilege users such as contributor to perform Stored Cross-Site Scripting attacks

    Published: 15 Nov 2024
    5.3
    Medium

    CVE-2024-52616

    Last Modified: 29 Jun 2026

    A flaw was found in the Avahi-daemon, where it initializes DNS transaction IDs randomly only once at startup, incrementing them sequentially after that. This predictable behavior facilitates DNS spoofing attacks, allowing attackers to guess transaction IDs.

    Published: 15 Nov 2024
    5.3
    Medium

    CVE-2024-52615

    Last Modified: 29 Jun 2026

    A flaw was found in Avahi-daemon, which relies on fixed source ports for wide-area DNS queries. This issue simplifies attacks where malicious DNS responses are injected.

    Published: 15 Nov 2024
    9.8
    Critical

    CVE-2024-50724

    Last Modified: 15 Apr 2026

    KASO v9.0 was discovered to contain a SQL injection vulnerability via the person_id parameter at /cardcase/editcard.jsp.

    Published: 15 Nov 2024
    7.5
    High

    CVE-2024-50647

    Last Modified: 15 Apr 2026

    The python_food ordering system V1.0 has an unauthorized vulnerability that leads to the leakage of sensitive user information. Attackers can access it through https://ip:port/api/myapp/index/user/info?id=1 And modify the ID value to obtain sensitive user information beyond authorization.

    Published: 15 Nov 2024
    6.7
    Medium

    CVE-2024-49592

    Last Modified: 15 Apr 2026

    Trial installer for McAfee Total Protection (legacy trial installer software) 16.0.53 allows local privilege escalation because of an Uncontrolled Search Path Element. The attacker could be "an adversary or knowledgeable user" and the type of attack could be called "DLL-squatting." The issue only affects execution of this installer, and does not leave McAfee Total Protection in a vulnerable state after installation is completed. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.

    Published: 15 Nov 2024
    7.8
    High

    CVE-2024-46463

    Last Modified: 15 Apr 2026

    By default, dedicated folders of ORIZON for Windows up to 2024.3 can be accessed by other users to misuse technical files and make them perform tasks with higher privileges. Configuration of ORIZON has to be modified to prevent this vulnerability.

    Published: 15 Nov 2024
    6.5
    Medium

    CVE-2024-24425

    Last Modified: 15 Apr 2026

    Magma v1.8.0 and OAI EPC Federation v1.20 were discovered to contain an out-of-bounds read in the amf_as_establish_req function at /tasks/amf/amf_as.cpp. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted NAS packet.

    Published: 15 Nov 2024
    5.1
    Medium

    CVE-2024-51330

    Last Modified: 15 Apr 2026

    An issue in UltiMaker Cura v.4.41 and 5.8.1 and before allows a local attacker to execute arbitrary code via Inter-process communication (IPC) mechanism between Cura application and CuraEngine processes, localhost network stack, printing settings and G-code processing and transmission components, Ultimaker 3D Printers.

    Published: 15 Nov 2024
    9.1
    Critical

    CVE-2024-51164

    Last Modified: 24 Jun 2025

    Multiple parameters have SQL injection vulnerability in JEPaaS 7.2.8 via /je/login/btnLog/insertBtnLog, which could allow a remote user to submit a specially crafted query, allowing an attacker to retrieve all the information stored in the DB.

    Published: 15 Nov 2024
    5.4
    Medium

    CVE-2024-51142

    Last Modified: 18 Apr 2025

    Cross Site Scripting vulnerability in Chamilo LMS v.1.11.26 allows an attacker to execute arbitrary code via the svkey parameter of the storageapi.php file.

    Published: 15 Nov 2024
    7.8
    High

    CVE-2024-51141

    Last Modified: 17 Jun 2025

    An issue in TOTOLINK Bluetooth Wireless Adapter A600UB allows a local attacker to execute arbitrary code via the WifiAutoInstallDriver.exe and MSASN1.dll components.

    Published: 15 Nov 2024
    7.3
    High

    CVE-2024-50986

    Last Modified: 7 Jul 2025

    An issue in Clementine v.1.3.1 allows a local attacker to execute arbitrary code via a crafted DLL file.

    Published: 15 Nov 2024
    7.5
    High

    CVE-2024-50653

    Last Modified: 13 Mar 2025

    CRMEB <=5.4.0 is vulnerable to Incorrect Access Control. Users can bypass the front-end restriction of only being able to claim coupons once by capturing packets and sending a large number of data packets for coupon collection, achieving unlimited coupon collection.

    Published: 15 Nov 2024
    5.4
    Medium

    CVE-2024-50983

    Last Modified: 7 Jul 2025

    FlightPath 7.5 contains a Cross Site Scripting (XSS) vulnerability, which allows authenticated remote attackers with administrative rights to inject arbitrary JavaScript in the web browser of a user by including a malicious payload into the Last Name section in the Create/Edit Faculty/Staff User or Create/Edit Student User sections.

    Published: 15 Nov 2024
    6.5
    Medium

    CVE-2024-24446

    Last Modified: 15 Apr 2026

    An uninitialized pointer dereference in OpenAirInterface CN5G AMF up to v2.0.0 allows attackers to cause a Denial of Service (DoS) via a crafted InitialContextSetupResponse message sent to the AMF.

    Published: 15 Nov 2024
    5.3
    Medium

    CVE-2024-24450

    Last Modified: 15 Apr 2026

    Stack-based memcpy buffer overflow in the ngap_handle_pdu_session_resource_setup_response routine in OpenAirInterface CN5G AMF <= 2.0.0 allows a remote attacker with access to the N2 interface to carry out denial of service against the AMF and potentially execute code by sending a PDU Session Resource Setup Response with a suffciently large FailedToSetupList IE.

    Published: 15 Nov 2024
    5.9
    Medium

    CVE-2024-24457

    Last Modified: 15 Apr 2026

    An invalid memory access when handling the ProtocolIE_ID field of E-RAB Setup List Context SURes messages in Athonet vEPC MME v11.4.0 allows attackers to cause a Denial of Service (DoS) to the cellular network by repeatedly initiating connections and sending a crafted payload.

    Published: 15 Nov 2024
    5.9
    Medium

    CVE-2024-24459

    Last Modified: 15 Apr 2026

    An invalid memory access when handling the ProtocolIE_ID field of S1Setup Request messages in Athonet vEPC MME v11.4.0 allows attackers to cause a Denial of Service (DoS) to the cellular network by repeatedly initiating connections and sending a crafted payload.

    Published: 15 Nov 2024
    7.5
    High

    CVE-2024-45969

    Last Modified: 15 Apr 2026

    NULL pointer dereference in the MMS Client in MZ Automation LibIEC1850 before commit 7afa40390b26ad1f4cf93deaa0052fe7e357ef33 allows a malicious server to Cause a Denial-of-Service via the MMS InitiationResponse message.

    Published: 15 Nov 2024
    5.3
    Medium

    CVE-2024-51037

    Last Modified: 16 Sept 2025

    An issue in kodbox v.1.52.04 and before allows a remote attacker to obtain sensitive information via the captcha feature in the password reset function.

    Published: 15 Nov 2024
    5.9
    Medium

    CVE-2024-24452

    Last Modified: 15 Apr 2026

    An invalid memory access when handling the ProtocolIE_ID field of E-RAB Release Indication messages in Athonet vEPC MME v11.4.0 allows attackers to cause a Denial of Service (DoS) to the cellular network by repeatedly initiating connections and sending a crafted payload.

    Published: 15 Nov 2024
    5.9
    Medium

    CVE-2024-24454

    Last Modified: 15 Apr 2026

    An invalid memory access when handling the ProtocolIE_ID field of E-RAB Modify Request messages in Athonet vEPC MME v11.4.0 allows attackers to cause a Denial of Service (DoS) to the cellular network by repeatedly initiating connections and sending a crafted payload.

    Published: 15 Nov 2024
    5.9
    Medium

    CVE-2024-24455

    Last Modified: 15 Apr 2026

    An invalid memory access when handling a UE Context Release message containing an invalid UE identifier in Athonet vEPC MME v11.4.0 allows attackers to cause a Denial of Service (DoS) to the cellular network by repeatedly initiating connections and sending a crafted payload.

    Published: 15 Nov 2024
    9.8
    Critical

    CVE-2024-44758

    Last Modified: 1 Oct 2025

    An arbitrary file upload vulnerability in the component /Production/UploadFile of NUS-M9 ERP Management Software v3.0.0 allows attackers to execute arbitrary code via uploading crafted files.

    Published: 15 Nov 2024
    9.8
    Critical

    CVE-2024-45970

    Last Modified: 1 Oct 2025

    Multiple Buffer overflows in the MMS Client in MZ Automation LibIEC61850 before commit ac925fae8e281ac6defcd630e9dd756264e9c5bc allow a malicious server to cause a stack-based buffer overflow via the MMS FileDirResponse message.

    Published: 15 Nov 2024
    9.8
    Critical

    CVE-2024-45971

    Last Modified: 1 Oct 2025

    Multiple Buffer overflows in the MMS Client in MZ Automation LibIEC61850 before commit 1f52be9ddeae00e69cd43e4cac3cb4f0c880c4f0 allow a malicious server to cause a stack-based buffer overflow via the MMS IdentifyResponse message.

    Published: 15 Nov 2024