CVE Feed

    Dashboard / CVE

    4.6
    Medium

    CVE-2024-23169

    Last Modified: 15 Apr 2026

    The web interface in RSA NetWitness 11.7.2.0 allows Cross-Site Scripting (XSS) via the Where textbox on the Reports screen during new rule creation.

    Published: 15 Nov 2024
    7.5
    High

    CVE-2024-24426

    Last Modified: 15 Apr 2026

    Reachable assertions in the NGAP_FIND_PROTOCOLIE_BY_ID function of OpenAirInterface Magma v1.8.0 and OAI EPC Federation v1.2.0 allow attackers to cause a Denial of Service (DoS) via a crafted NGAP packet.

    Published: 15 Nov 2024
    7.5
    High

    CVE-2024-24431

    Last Modified: 22 Apr 2025

    A reachable assertion in the ogs_nas_emm_decode function of Open5GS v2.7.0 allows attackers to cause a Denial of Service (DoS) via a crafted NAS packet with a zero-length EMM message length.

    Published: 15 Nov 2024
    6.5
    Medium

    CVE-2024-24449

    Last Modified: 15 Apr 2026

    An uninitialized pointer dereference in the NasPdu::NasPdu component of OpenAirInterface CN5G AMF up to v2.0.0 allows attackers to cause a Denial of Service (DoS) via a crafted InitialUEMessage message sent to the AMF.

    Published: 15 Nov 2024
    5.3
    Medium

    CVE-2024-24447

    Last Modified: 15 Apr 2026

    A buffer overflow in the ngap_amf_handle_pdu_session_resource_setup_response function of oai-cn5g-amf up to v2.0.0 allows attackers to cause a Denial of Service (DoS) via a PDU Session Resource Setup Response with an empty Response Item list.

    Published: 15 Nov 2024
    5.9
    Medium

    CVE-2024-24458

    Last Modified: 15 Apr 2026

    An invalid memory access when handling the ENB Configuration Transfer messages containing invalid PLMN Identities in Athonet vEPC MME v11.4.0 allows attackers to cause a Denial of Service (DoS) to the cellular network by repeatedly initiating connections and sending a crafted payload.

    Published: 15 Nov 2024
    5.9
    Medium

    CVE-2024-24453

    Last Modified: 15 Apr 2026

    An invalid memory access when handling the ProtocolIE_ID field of E-RAB NotToBeModifiedBearerModInd information element in Athonet vEPC MME v11.4.0 allows attackers to cause a Denial of Service (DoS) to the cellular network by repeatedly initiating connections and sending a crafted payload.

    Published: 15 Nov 2024
    8.8
    High

    CVE-2024-44625

    Last Modified: 21 Nov 2024

    Gogs <=0.13.0 is vulnerable to Directory Traversal via the editFilePost function of internal/route/repo/editor.go.

    Published: 15 Nov 2024
    7.5
    High

    CVE-2024-44759

    Last Modified: 1 Oct 2025

    An arbitrary file download vulnerability in the component /Doc/DownloadFile of NUS-M9 ERP Management Software v3.0.0 allows attackers to download arbitrary files and access sensitive information via a crafted interface request.

    Published: 15 Nov 2024
    2.4
    Low

    CVE-2024-46383

    Last Modified: 15 Apr 2026

    Hathway Skyworth Router CM5100-511 v4.1.1.24 was discovered to store sensitive information about USB and Wifi connected devices in plaintext.

    Published: 15 Nov 2024
    7.8
    High

    CVE-2024-46462

    Last Modified: 15 Apr 2026

    By default, dedicated folders of ZEDMAIL for Windows up to 2024.3 can be accessed by other users to misuse technical files and make them perform tasks with higher privileges. Configuration of ZEDMAIL has to be modified to prevent this vulnerability.

    Published: 15 Nov 2024
    7.8
    High

    CVE-2024-46466

    Last Modified: 15 Apr 2026

    By default, dedicated folders of ZONECENTRAL for Windows up to 2024.3 or up to Q.2021.2 (ANSSI qualification submission) can be accessed by other users to misuse technical files and make them perform tasks with higher privileges. Configuration of ZONECENTRAL has to be modified to prevent this vulnerability.

    Published: 15 Nov 2024
    7.8
    High

    CVE-2024-46467

    Last Modified: 15 Apr 2026

    By default, dedicated folders of ZONEPOINT for Windows up to 2024.1 can be accessed by other users to misuse technical files and make them perform tasks with higher privileges. Configuration of ZONEPOINT has to be modified to prevent this vulnerability.

    Published: 15 Nov 2024
    7.8
    High

    CVE-2024-46465

    Last Modified: 1 Oct 2025

    By default, dedicated folders of CRYHOD for Windows up to 2024.3 can be accessed by other users to misuse technical files and make them perform tasks with higher privileges. Configuration of CRYHOD has to be modified to prevent this vulnerability.

    Published: 15 Nov 2024
    6.1
    Medium

    CVE-2024-48068

    Last Modified: 15 Apr 2026

    A cross-site scripting (XSS) vulnerability in Shenzhen Landray Software Co.,LTD Landray EKP v16 and earlier allows attackers to execute arbitrary web scripts or HTML via a crafted payload.

    Published: 15 Nov 2024
    9.8
    Critical

    CVE-2024-50648

    Last Modified: 17 Jun 2025

    yshopmall V1.0 has an arbitrary file upload vulnerability, which can enable RCE or even take over the server when improperly configured to parse JSP files.

    Published: 15 Nov 2024
    9.8
    Critical

    CVE-2024-50649

    Last Modified: 17 Jun 2025

    The user avatar upload function in python_book V1.0 has an arbitrary file upload vulnerability.

    Published: 15 Nov 2024
    7.5
    High

    CVE-2024-50650

    Last Modified: 17 Jun 2025

    python_book V1.0 is vulnerable to Incorrect Access Control, which allows attackers to obtain sensitive information of users with different IDs by modifying the ID parameter.

    Published: 15 Nov 2024
    6.5
    Medium

    CVE-2024-50651

    Last Modified: 27 Nov 2024

    java_shop 1.0 is vulnerable to Incorrect Access Control, which allows attackers to obtain sensitive information of users with different IDs by modifying the ID parameter.

    Published: 15 Nov 2024
    4.3
    Medium

    CVE-2024-50652

    Last Modified: 22 Nov 2024

    A file upload vulnerability in java_shop 1.0 allows attackers to upload arbitrary files by modifying the avatar function.

    Published: 15 Nov 2024
    7.5
    High

    CVE-2024-50654

    Last Modified: 21 Nov 2024

    lilishop <=4.2.4 is vulnerable to Incorrect Access Control, which can allow attackers to obtain coupons beyond the quantity limit by capturing and sending the data packets for coupon collection in high concurrency.

    Published: 15 Nov 2024
    5.4
    Medium

    CVE-2024-50655

    Last Modified: 21 Nov 2024

    emlog pro <=2.3.18 is vulnerable to Cross Site Scripting (XSS), which allows attackers to write malicious JavaScript code in published articles.

    Published: 15 Nov 2024
    5.4
    Medium

    CVE-2024-50800

    Last Modified: 15 Apr 2026

    Cross Site Scripting vulnerability in M2000 Smart4Web before v.5.020241004 allows a remote attacker to execute arbitrary code via the error parameter in URL

    Published: 15 Nov 2024
    8
    High

    CVE-2024-52308

    Last Modified: 20 Nov 2024

    The GitHub CLI version 2.6.1 and earlier are vulnerable to remote code execution through a malicious codespace SSH server when using `gh codespace ssh` or `gh codespace logs` commands. This has been patched in the cli v2.62.0. Developers connect to remote codespaces through an SSH server running within the devcontainer, which is generally provided through the [default devcontainer image]( https://docs.github.com/en/codespaces/setting-up-your-project-for-codespaces/adding-a-dev-container-... https://docs.github.com/en/codespaces/setting-up-your-project-for-codespaces/adding-a-dev-container-configuration/introduction-to-dev-containers#using-the-default-dev-container-configuration) . GitHub CLI [retrieves SSH connection details]( https://github.com/cli/cli/blob/30066b0042d0c5928d959e288144300cb28196c9/internal/codespaces/rpc/inv... https://github.com/cli/cli/blob/30066b0042d0c5928d959e288144300cb28196c9/internal/codespaces/rpc/invoker.go#L230-L244 ), such as remote username, which is used in [executing `ssh` commands]( https://github.com/cli/cli/blob/e356c69a6f0125cfaac782c35acf77314f18908d/pkg/cmd/codespace/ssh.go#L2... https://github.com/cli/cli/blob/e356c69a6f0125cfaac782c35acf77314f18908d/pkg/cmd/codespace/ssh.go#L263 ) for `gh codespace ssh` or `gh codespace logs` commands. This exploit occurs when a malicious third-party devcontainer contains a modified SSH server that injects `ssh` arguments within the SSH connection details. `gh codespace ssh` and `gh codespace logs` commands could execute arbitrary code on the user's workstation if the remote username contains something like `-oProxyCommand="echo hacked" #`. The `-oProxyCommand` flag causes `ssh` to execute the provided command while `#` shell comment causes any other `ssh` arguments to be ignored. In `2.62.0`, the remote username information is being validated before being used.

    Published: 14 Nov 2024
    5.5
    Medium

    CVE-2017-13227

    Last Modified: 20 Nov 2024

    In the autofill service, the package name that is provided by the app process is trusted inappropriately.  This could lead to information disclosure with no additional execution privileges needed.  User interaction is not needed for exploitation.

    Published: 14 Nov 2024
    10
    Critical

    CVE-2024-48967

    Last Modified: 15 Apr 2026

    The ventilator and the Service PC lack sufficient audit logging capabilities to allow for detection of malicious activity and subsequent forensic examination. An attacker with access to the ventilator and/or the Service PC could, without detection, make unauthorized changes to ventilator settings that result in unauthorized disclosure of information and/or have unintended impacts on device performance.

    Published: 14 Nov 2024
    10
    Critical

    CVE-2024-48966

    Last Modified: 15 Apr 2026

    The software tools used by service personnel to test & calibrate the ventilator do not support user authentication. An attacker with access to the Service PC where the tools are installed could obtain diagnostic information through the test tool or manipulate the ventilator's settings and embedded software via the calibration tool, without having to authenticate to either tool. This could result in unauthorized disclosure of information and/or have unintended impacts on device settings and performance.

    Published: 14 Nov 2024
    7.1
    High

    CVE-2024-51658

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Henrik Hoff WP Course Manager wp-course-manager allows Stored XSS.This issue affects WP Course Manager: from n/a through <= 1.3.

    Published: 14 Nov 2024
    7.1
    High

    CVE-2024-51659

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in GeekRMX Twitter @Anywhere Plus twitter-anywhere-plus allows Stored XSS.This issue affects Twitter @Anywhere Plus: from n/a through <= 2.0.

    Published: 14 Nov 2024
    7.1
    High

    CVE-2024-51679

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in gentlesource Appointmind appointmind allows Stored XSS.This issue affects Appointmind: from n/a through <= 4.0.0.

    Published: 14 Nov 2024
    9.3
    Critical

    CVE-2024-48970

    Last Modified: 15 Apr 2026

    The ventilator's microcontroller lacks memory protection. An attacker could connect to the internal JTAG interface and read or write to flash memory using an off-the-shelf debugging tool, which could disrupt the function of the device and/or cause unauthorized information disclosure.

    Published: 14 Nov 2024
    9.3
    Critical

    CVE-2024-48974

    Last Modified: 15 Apr 2026

    The ventilator does not perform proper file integrity checks when adopting firmware updates. This makes it possible for an attacker to force unauthorized changes to the device's configuration settings and/or compromise device functionality by pushing a compromised/illegitimate firmware file. This could disrupt the function of the device and/or cause unauthorized information disclosure.

    Published: 14 Nov 2024
    9.3
    Critical

    CVE-2024-48973

    Last Modified: 15 Apr 2026

    The debug port on the ventilator's serial interface is enabled by default. This could allow an attacker to send and receive messages over the debug port (which are unencrypted; see 3.2.1) that result in unauthorized disclosure of information and/or have unintended impacts on device settings and performance.

    Published: 14 Nov 2024
    9.3
    Critical

    CVE-2024-48971

    Last Modified: 15 Apr 2026

    The Clinician Password and Serial Number Clinician Password are hard-coded into the ventilator in plaintext form. This could allow an attacker to obtain the password off the ventilator and use it to gain unauthorized access to the device, with clinician privileges.

    Published: 14 Nov 2024
    9.3
    Critical

    CVE-2024-9832

    Last Modified: 15 Apr 2026

    There is no limit on the number of failed login attempts permitted with the Clinician Password or the Serial Number Clinician Password. An attacker could execute a brute-force attack to gain unauthorized access to the ventilator, and then make changes to device settings that could disrupt the function of the device and/or result in unauthorized information disclosure.

    Published: 14 Nov 2024
    9.3
    Critical

    CVE-2024-9834

    Last Modified: 15 Apr 2026

    Improper data protection on the ventilator's serial interface could allow an attacker to send and receive messages that result in unauthorized disclosure of information and/or have unintended impacts on device settings and performance.

    Published: 14 Nov 2024
    7.1
    High

    CVE-2024-51684

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Ciprian Popescu W3P SEO wp-perfect-plugin allows Stored XSS.This issue affects W3P SEO: from n/a through < 1.8.6.

    Published: 14 Nov 2024
    7.1
    High

    CVE-2024-51687

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Platform.ly Platform.ly Official platformly allows Stored XSS.This issue affects Platform.ly Official: from n/a through <= 1.1.3.

    Published: 14 Nov 2024
    7.1
    High

    CVE-2024-51688

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in fraudlabspro FraudLabs Pro SMS Verification fraudlabs-pro-sms-verification allows Stored XSS.This issue affects FraudLabs Pro SMS Verification: from n/a through <= 1.10.1.

    Published: 14 Nov 2024
    5.4
    Medium

    CVE-2024-49025

    Last Modified: 8 Jul 2025

    Microsoft Edge (Chromium-based) Information Disclosure Vulnerability

    Published: 14 Nov 2024
    7.7
    High

    CVE-2024-10397

    Last Modified: 23 Dec 2025

    A malicious server can crash the OpenAFS cache manager and other client utilities, and possibly execute arbitrary code.

    Published: 14 Nov 2024
    6.5
    Medium

    CVE-2024-10396

    Last Modified: 23 Dec 2025

    An authenticated user can provide a malformed ACL to the fileserver's StoreACL RPC, causing the fileserver to crash, possibly expose uninitialized memory, and possibly store garbage data in the audit log. Malformed ACLs provided in responses to client FetchACL RPCs can cause client processes to crash and possibly expose uninitialized memory into other ACLs stored on the server.

    Published: 14 Nov 2024
    8.4
    High

    CVE-2024-10394

    Last Modified: 23 Dec 2025

    A local user can bypass the OpenAFS PAG (Process Authentication Group) throttling mechanism in Unix clients, allowing the user to create a PAG using an existing id number, effectively joining the PAG and letting the user steal the credentials in that PAG.

    Published: 14 Nov 2024
    7.5
    High

    CVE-2024-3760

    Last Modified: 18 Nov 2024

    In lunary-ai/lunary version 1.2.7, there is a lack of rate limiting on the forgot password page, leading to an email bombing vulnerability. Attackers can exploit this by automating forgot password requests to flood targeted user accounts with a high volume of password reset emails. This not only overwhelms the victim's mailbox, making it difficult to manage and locate legitimate emails, but also significantly impacts mail servers by consuming their resources. The increased load can cause performance degradation and, in severe cases, make the mail servers unresponsive or unavailable, disrupting email services for the entire organization.

    Published: 14 Nov 2024
    9.9
    Critical

    CVE-2024-52369

    Last Modified: 23 Apr 2026

    Unrestricted Upload of File with Dangerous Type vulnerability in Optimal Access KBucket kbucket allows Upload a Web Shell to a Web Server.This issue affects KBucket: from n/a through <= 4.2.2.

    Published: 14 Nov 2024
    9.9
    Critical

    CVE-2024-52370

    Last Modified: 23 Apr 2026

    Unrestricted Upload of File with Dangerous Type vulnerability in Hive Support Hive Support hive-support allows Upload a Web Shell to a Web Server.This issue affects Hive Support: from n/a through <= 1.1.1.

    Published: 14 Nov 2024
    10
    Critical

    CVE-2024-52372

    Last Modified: 23 Apr 2026

    Unrestricted Upload of File with Dangerous Type vulnerability in WebTechGlobal Easy CSV Importer BETA easy-csv-importer allows Upload a Web Shell to a Web Server.This issue affects Easy CSV Importer BETA: from n/a through <= 7.0.0.

    Published: 14 Nov 2024
    10
    Critical

    CVE-2024-52373

    Last Modified: 23 Apr 2026

    Unrestricted Upload of File with Dangerous Type vulnerability in Team Devexhub Devexhub Gallery devexhub-gallery allows Upload a Web Shell to a Web Server.This issue affects Devexhub Gallery: from n/a through <= 2.0.1.

    Published: 14 Nov 2024
    10
    Critical

    CVE-2024-52374

    Last Modified: 23 Apr 2026

    Unrestricted Upload of File with Dangerous Type vulnerability in DoThatTask Do That Task do-that-task allows Upload a Web Shell to a Web Server.This issue affects Do That Task: from n/a through <= 1.5.5.

    Published: 14 Nov 2024
    10
    Critical

    CVE-2024-52375

    Last Modified: 23 Apr 2026

    Unrestricted Upload of File with Dangerous Type vulnerability in Arttia Creative Datasets Manager by Arttia Creative datasets-manager-by-arttia-creative.This issue affects Datasets Manager by Arttia Creative: from n/a through <= 1.5.

    Published: 14 Nov 2024