CVE Feed

    Dashboard / CVE

    6.4
    Medium

    CVE-2024-10887

    Last Modified: 15 Apr 2026

    The NiceJob plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several of the plugin's shortcodes (nicejob-lead, nicejob-review, nicejob-engage, nicejob-badge, nicejob-stories) in all versions up to, and including, 3.7.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 13 Nov 2024
    6.1
    Medium

    CVE-2024-10851

    Last Modified: 8 Apr 2026

    The Razorpay Payment Button Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg & remove_query_arg without appropriate escaping on the URL in all versions up to, and including, 2.4.6. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

    Published: 13 Nov 2024
    6.4
    Medium

    CVE-2024-8985

    Last Modified: 15 Apr 2026

    The Social Proof (Testimonial) Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's spslider-block shortcode in all versions up to, and including, 2.2.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 13 Nov 2024
    5.3
    Medium

    CVE-2024-9578

    Last Modified: 8 Apr 2026

    The Hide Links plugin for WordPress is vulnerable to unauthorized shortcode execution due to do_shortcode being hooked through the comment_text filter in all versions up to and including 1.4.2. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes available on the target site.

    Published: 13 Nov 2024
    4.3
    Medium

    CVE-2024-10852

    Last Modified: 15 Apr 2026

    The Buy one click WooCommerce plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the buy_one_click_export_options AJAX action in all versions up to, and including, 2.2.9. This makes it possible for authenticated attackers, with Subscriber-level access and above, to export plugin settings.

    Published: 13 Nov 2024
    4.3
    Medium

    CVE-2024-10778

    Last Modified: 8 Apr 2026

    The BuddyPress Builder for Elementor – BuddyBuilder plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.7.4 via the 'elementor-template' shortcode due to insufficient restrictions on which posts can be included. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract data from private or draft posts crated by Elementor that they should not have access to.

    Published: 13 Nov 2024
    7.2
    High

    CVE-2024-38655

    Last Modified: 27 Jun 2025

    Argument injection in Ivanti Connect Secure before version 22.7R2.1 and 9.1R18.9 and Ivanti Policy Secure before version 22.7R1.1 and 9.1R18.9 allows a remote authenticated attacker with admin privileges to achieve remote code execution.

    Published: 13 Nov 2024
    7.2
    High

    CVE-2024-34784

    Last Modified: 1 May 2025

    SQL injection in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allows a remote authenticated attacker with admin privileges to achieve remote code execution.

    Published: 13 Nov 2024
    7.2
    High

    CVE-2024-34780

    Last Modified: 23 Apr 2025

    SQL injection in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allows a remote authenticated attacker with admin privileges to achieve remote code execution.

    Published: 13 Nov 2024
    4.7
    Medium

    CVE-2024-29211

    Last Modified: 14 Nov 2024

    A race condition in Ivanti Secure Access Client before version 22.7R4 allows a local authenticated attacker to modify sensitive configuration files.

    Published: 13 Nov 2024
    9.1
    Critical

    CVE-2024-39712

    Last Modified: 11 Jul 2025

    Argument injection in Ivanti Connect Secure before version 22.7R2.1 and 9.1R18.7 and Ivanti Policy Secure before version 22.7R1.1 allows a remote authenticated attacker with admin privileges to achieve remote code execution.

    Published: 13 Nov 2024
    7.2
    High

    CVE-2024-34781

    Last Modified: 1 May 2025

    SQL injection in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allows a remote authenticated attacker with admin privileges to achieve remote code execution.

    Published: 13 Nov 2024
    7.5
    High

    CVE-2024-37400

    Last Modified: 27 Jun 2025

    An out of bounds read in Ivanti Connect Secure before version 22.7R2.3 allows a remote unauthenticated attacker to trigger an infinite loop, causing a denial of service.

    Published: 13 Nov 2024
    7.2
    High

    CVE-2024-32839

    Last Modified: 23 Apr 2025

    SQL injection in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allows a remote authenticated attacker with admin privileges to achieve remote code execution.

    Published: 13 Nov 2024
    4.4
    Medium

    CVE-2024-38654

    Last Modified: 27 Jun 2025

    Improper bounds checking in Ivanti Secure Access Client before version 22.7R3 allows a local authenticated attacker with admin privileges to cause a denial of service.

    Published: 13 Nov 2024
    7.5
    High

    CVE-2024-38649

    Last Modified: 16 Jul 2025

    An out-of-bounds write in IPsec of Ivanti Connect Secure before version 22.7R2.1(Not Applicable to 9.1Rx) allows a remote unauthenticated attacker to cause a denial of service.

    Published: 13 Nov 2024
    9.1
    Critical

    CVE-2024-39711

    Last Modified: 11 Jul 2025

    Argument injection in Ivanti Connect Secure before version 22.7R2.1 and 9.1R18.7 and Ivanti Policy Secure before version 22.7R1.1 allows a remote authenticated attacker with admin privileges to achieve remote code execution.

    Published: 13 Nov 2024
    7.8
    High

    CVE-2024-39709

    Last Modified: 16 Jul 2025

    Incorrect file permissions in Ivanti Connect Secure before version 22.6R2 (Not Applicable to 9.1Rx) and Ivanti Policy Secure before version 22.7R1 (Not Applicable to 9.1Rx) allow a local authenticated attacker to escalate their privileges.

    Published: 13 Nov 2024
    9.1
    Critical

    CVE-2024-38656

    Last Modified: 27 Jun 2025

    Argument injection in Ivanti Connect Secure before version 22.7R2.2 and 9.1R18.9 and Ivanti Policy Secure before version 22.7R1.2 allows a remote authenticated attacker with admin privileges to achieve remote code execution.

    Published: 13 Nov 2024
    7.2
    High

    CVE-2024-32844

    Last Modified: 23 Apr 2025

    SQL injection in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allows a remote authenticated attacker with admin privileges to achieve remote code execution.

    Published: 13 Nov 2024
    7.8
    High

    CVE-2024-34787

    Last Modified: 1 May 2025

    Path traversal in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allows a local unauthenticated attacker to achieve code execution. User interaction is required.

    Published: 13 Nov 2024
    7.2
    High

    CVE-2024-32847

    Last Modified: 24 Apr 2025

    SQL injection in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allows a remote authenticated attacker with admin privileges to achieve remote code execution.

    Published: 13 Nov 2024
    7.8
    High

    CVE-2024-37398

    Last Modified: 13 Mar 2025

    Insufficient validation in Ivanti Secure Access Client before 22.7R4 allows a local authenticated attacker to escalate their privileges.

    Published: 13 Nov 2024
    7.2
    High

    CVE-2024-34782

    Last Modified: 1 May 2025

    SQL injection in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allows a remote authenticated attacker with admin privileges to achieve remote code execution.

    Published: 13 Nov 2024
    7.2
    High

    CVE-2024-32841

    Last Modified: 23 Apr 2025

    SQL injection in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allows a remote authenticated attacker with admin privileges to achieve remote code execution.

    Published: 13 Nov 2024
    9.1
    Critical

    CVE-2024-39710

    Last Modified: 11 Jul 2025

    Argument injection in Ivanti Connect Secure before version 22.7R2.1 and 9.1R18.7 and Ivanti Policy Secure before version 22.7R1.1 allows a remote authenticated attacker with admin privileges to achieve remote code execution.

    Published: 13 Nov 2024
    7.2
    High

    CVE-2024-37376

    Last Modified: 1 May 2025

    SQL injection in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allows a remote authenticated attacker with admin privileges to achieve remote code execution.

    Published: 13 Nov 2024
    10
    Critical

    CVE-2024-10575

    Last Modified: 19 Nov 2024

    CWE-862: Missing Authorization vulnerability exists that could cause unauthorized access when enabled on the network and potentially impacting connected devices.

    Published: 13 Nov 2024
    6.5
    Medium

    CVE-2024-51027

    Last Modified: 15 Apr 2026

    Ruijie NBR800G gateway NBR_RGOS_11.1(6)B4P9 is vulnerable to command execution in /itbox_pi/networksafe.php via the province parameter.

    Published: 13 Nov 2024
    7.2
    High

    CVE-2024-50972

    Last Modified: 18 Nov 2024

    A SQL injection vulnerability in printtool.php of Itsourcecode Construction Management System 1.0 allows remote attackers to execute arbitrary SQL commands via the borrow_id parameter.

    Published: 13 Nov 2024
    9.8
    Critical

    CVE-2024-40404

    Last Modified: 1 May 2025

    Cybele Software Thinfinity Workspace before v7.0.2.113 was discovered to contain an access control issue in the API endpoint where Web Sockets connections are established.

    Published: 13 Nov 2024
    7.3
    High

    CVE-2024-40408

    Last Modified: 1 May 2025

    Cybele Software Thinfinity Workspace before v7.0.2.113 was discovered to contain an access control issue in the Create Profile section. This vulnerability allows attackers to create arbitrary user profiles with elevated privileges.

    Published: 13 Nov 2024
    4.8
    Medium

    CVE-2024-40410

    Last Modified: 1 May 2025

    Cybele Software Thinfinity Workspace before v7.0.2.113 was discovered to contain a hardcoded cryptographic key used for encryption.

    Published: 13 Nov 2024
    4.3
    Medium

    CVE-2024-40443

    Last Modified: 16 Apr 2025

    SQL Injection vulnerability in Simple Laboratory Management System using PHP and MySQL v.1.0 allows a remote attacker to cause a denial of service via the delete_users function in the Useres.php

    Published: 13 Nov 2024
    6.5
    Medium

    CVE-2024-45877

    Last Modified: 15 Apr 2026

    baltic-it TOPqw Webportal v1.35.283.2 is vulnerable to Incorrect Access Control in the User Management function in /Apps/TOPqw/BenutzerManagement.aspx. This allows a low privileged user to access all modules in the web portal, view and manipulate information and permissions of other users, lock other user or unlock the own account, change the password of other users, create new users or delete existing users and view, manipulate and delete reference data.

    Published: 13 Nov 2024
    8.8
    High

    CVE-2024-50853

    Last Modified: 21 Nov 2024

    Tenda G3 v3.0 v15.11.0.20 was discovered to contain a command injection vulnerability via the formSetDebugCfg function.

    Published: 13 Nov 2024
    6.1
    Medium

    CVE-2024-50969

    Last Modified: 21 Nov 2024

    A Reflected cross-site scripting (XSS) vulnerability in browse.php of Code-projects Jonnys Liquor 1.0 allows remote attackers to inject arbitrary web scripts or HTML via the search parameter.

    Published: 13 Nov 2024
    5.4
    Medium

    CVE-2024-42834

    Last Modified: 15 Apr 2026

    A stored cross-site scripting (XSS) vulnerability in the Create Customer API in Incognito Service Activation Center (SAC) UI v14.11 allows authenticated attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the lastName parameter.

    Published: 13 Nov 2024
    5.4
    Medium

    CVE-2024-45875

    Last Modified: 15 Apr 2026

    The create user function in baltic-it TOPqw Webportal 1.35.287.1 (fixed in version1.35.291), in /Apps/TOPqw/BenutzerManagement.aspx/SaveNewUser, is vulnerable to SQL injection. The JSON object username allows the manipulation of SQL queries.

    Published: 13 Nov 2024
    4.8
    Medium

    CVE-2023-38920

    Last Modified: 27 Mar 2025

    Cross Site Scripting vulnerability in Cyber Cafe Management System v.1.0 allows a local attacker to execute arbitrary code via a crafted script to the adminname parameter.

    Published: 13 Nov 2024
    8.1
    High

    CVE-2024-40405

    Last Modified: 1 May 2025

    Incorrect access control in Cybele Software Thinfinity Workspace before v7.0.3.109 allows attackers to gain access to a secondary broker via a crafted request.

    Published: 13 Nov 2024
    7.5
    High

    CVE-2024-40407

    Last Modified: 1 May 2025

    A full path disclosure in Cybele Software Thinfinity Workspace before v7.0.2.113 allows attackers to obtain the root path of the application via unspecified vectors.

    Published: 13 Nov 2024
    6.5
    Medium

    CVE-2024-45876

    Last Modified: 15 Apr 2026

    The login form of baltic-it TOPqw Webportal v1.35.283.2 (fixed in version 1.35.283.4) at /Apps/TOPqw/Login.aspx is vulnerable to SQL injection. The vulnerability exists in the POST parameter txtUsername, which allows for manipulation of SQL queries.

    Published: 13 Nov 2024
    5.4
    Medium

    CVE-2024-45878

    Last Modified: 15 Apr 2026

    The "Stammdaten" menu of baltic-it TOPqw Webportal v1.35.283.2 (fixed in version 1.35.291), in /Apps/TOPqw/qwStammdaten.aspx, is vulnerable to persistent Cross-Site Scripting (XSS).

    Published: 13 Nov 2024
    5.4
    Medium

    CVE-2024-45879

    Last Modified: 15 Apr 2026

    The file upload function in the "QWKalkulation" tool of baltic-it TOPqw Webportal v1.35.287.1 (fixed in version 1.35.291), in /Apps/TOPqw/QWKalkulation/QWKalkulation.aspx, is vulnerable to Cross-Site Scripting (XSS). To exploit the persistent XSS vulnerability, an attacker has to be authenticated to the application that uses the "TOPqw Webportal" as a software. When authenticated, the attacker can persistently place the malicious JavaScript code in the "QWKalkulation" menu.'

    Published: 13 Nov 2024
    9.8
    Critical

    CVE-2024-48510

    Last Modified: 2 May 2025

    Directory Traversal vulnerability in DotNetZip v.1.16.0 and before allows a remote attacker to execute arbitrary code via the src/Zip.Shared/ZipEntry.Extract.cs component NOTE: This vulnerability only affects products that are no longer supported by the maintainer.

    Published: 13 Nov 2024
    8.8
    High

    CVE-2024-50852

    Last Modified: 21 Nov 2024

    Tenda G3 v3.0 v15.11.0.20 was discovered to contain a command injection vulnerability via the formSetUSBPartitionUmount function.

    Published: 13 Nov 2024
    8.8
    High

    CVE-2024-50854

    Last Modified: 14 Mar 2025

    Tenda G3 v3.0 v15.11.0.20 was discovered to contain a stack overflow via the formSetPortMapping function.

    Published: 13 Nov 2024
    7.5
    High

    CVE-2024-50955

    Last Modified: 15 Apr 2026

    An issue in how XINJE XD5E-24R and XL5E-16T v3.5.3b handles TCP protocol messages allows attackers to cause a Denial of Service (DoS) via a crafted TCP message.

    Published: 13 Nov 2024
    6.5
    Medium

    CVE-2024-50956

    Last Modified: 15 Apr 2026

    A buffer overflow in the RecvSocketData function of Inovance HCPLC_AM401-CPU1608TPTN 21.38.0.0, HCPLC_AM402-CPU1608TPTN 41.38.0.0, and HCPLC_AM403-CPU1608TN 81.38.0.0 allows attackers to cause a Denial of Service (DoS) or execute arbitrary code via a crafted Modbus message.

    Published: 13 Nov 2024