CVE Feed

    Dashboard / CVE

    4.3
    Medium

    CVE-2023-29116

    Last Modified: 8 Nov 2024

    Under certain conditions, through a request directed to the Waybox Enel X web management application, information like Waybox OS version or service configuration details could be obtained.

    Published: 5 Nov 2024
    6.5
    Medium

    CVE-2023-29115

    Last Modified: 8 Nov 2024

    In certain conditions a request directed to the Waybox Enel X Web management application could cause a denial-of-service (e.g. reboot).

    Published: 5 Nov 2024
    5.7
    Medium

    CVE-2023-29114

    Last Modified: 15 Apr 2026

    System logs could be accessed through web management application due to a lack of access control. An attacker can obtain the following sensitive information: •     Wi-Fi access point credentials to which the EV charger can connect. •     APN web address and credentials. •     IPSEC credentials. •     Web interface access credentials for user and admin accounts. •     JuiceBox system components (software installed, model, firmware version, etc.). •     C2G configuration details. •     Internal IP addresses. •     OTA firmware update configurations (DNS servers). All the credentials are stored in logs in an unencrypted plaintext format.

    Published: 5 Nov 2024
    6.9
    Medium

    CVE-2024-10845

    Last Modified: 23 Mar 2026

    A vulnerability has been found in 1000 Projects Bookstore Management System 1.0 and classified as critical. This vulnerability affects unknown code of the file book_detail.php. The manipulation of the argument id leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

    Published: 5 Nov 2024
    6.9
    Medium

    CVE-2024-10844

    Last Modified: 23 Mar 2026

    A vulnerability, which was classified as critical, was found in 1000 Projects Bookstore Management System 1.0. This affects an unknown part of the file search.php. The manipulation of the argument s leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

    Published: 5 Nov 2024
    4.1
    Medium

    CVE-2024-0134

    Last Modified: 8 Nov 2024

    NVIDIA Container Toolkit and NVIDIA GPU Operator for Linux contain a UNIX vulnerability where a specially crafted container image can lead to the creation of unauthorized files on the host. The name and location of the files cannot be controlled by an attacker. A successful exploit of this vulnerability might lead to data tampering.

    Published: 5 Nov 2024
    4.3
    Medium

    CVE-2024-10329

    Last Modified: 8 Apr 2026

    The Ultimate Bootstrap Elements for Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.4.6 via the 'ube_get_page_templates' function. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract sensitive data including the contents of templates that are private.

    Published: 5 Nov 2024
    8.9
    High

    CVE-2024-7059

    Last Modified: 15 Apr 2026

    A high-severity vulnerability that can lead to arbitrary code execution on the system hosting the Web SDK role was found in the Genetec Security Center product line.

    Published: 5 Nov 2024
    7.3
    High

    CVE-2024-10263

    Last Modified: 8 Apr 2026

    The Tickera – WordPress Event Ticketing plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 3.5.4.4. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes.

    Published: 5 Nov 2024
    5.4
    Medium

    CVE-2024-9867

    Last Modified: 8 Apr 2026

    The Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Open Map Widget' marker_content parameter in all versions up to, and including, 5.10.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 5 Nov 2024
    6.5
    Medium

    CVE-2024-9657

    Last Modified: 8 Apr 2026

    The Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘tooltip' parameter in all versions up to, and including, 5.10.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 5 Nov 2024
    6.6
    Medium

    CVE-2024-51530

    Last Modified: 7 Nov 2024

    LaunchAnywhere vulnerability in the account module Impact: Successful exploitation of this vulnerability may affect service confidentiality.

    Published: 5 Nov 2024
    5.5
    Medium

    CVE-2024-51529

    Last Modified: 7 Nov 2024

    Data verification vulnerability in the battery module Impact: Successful exploitation of this vulnerability may affect function stability.

    Published: 5 Nov 2024
    6.4
    Medium

    CVE-2024-9178

    Last Modified: 8 Apr 2026

    The XT Floating Cart for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 2.8.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses the SVG file.

    Published: 5 Nov 2024
    4.3
    Medium

    CVE-2024-10319

    Last Modified: 8 Apr 2026

    The 140+ Widgets | Xpro Addons For Elementor – FREE plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.4.6 via the render function in widgets/content-toggle/layout/frontend.php. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract sensitive private, pending, and draft template data.

    Published: 5 Nov 2024
    5.1
    Medium

    CVE-2024-10842

    Last Modified: 6 Nov 2024

    A vulnerability, which was classified as problematic, has been found in romadebrian WEB-Sekolah 1.0. Affected by this issue is some unknown functionality of the file /Admin/Proses_Edit_Akun.php of the component Backend. The manipulation of the argument Username_Baru/Password leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

    Published: 5 Nov 2024
    5.3
    Medium

    CVE-2024-10841

    Last Modified: 6 Nov 2024

    A vulnerability classified as critical was found in romadebrian WEB-Sekolah 1.0. Affected by this vulnerability is an unknown functionality of the file /Proses_Kirim.php of the component Mail Handler. The manipulation of the argument Name leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. Other parameters might be affected as well.

    Published: 5 Nov 2024
    4
    Medium

    CVE-2024-51528

    Last Modified: 7 Nov 2024

    Vulnerability of improper log printing in the Super Home Screen module Impact: Successful exploitation of this vulnerability may affect service confidentiality.

    Published: 5 Nov 2024
    9.8
    Critical

    CVE-2024-10687

    Last Modified: 8 Apr 2026

    The Photos, Files, YouTube, Twitter, Instagram, TikTok, Ecommerce Contest Gallery – Upload, Vote, Sell via PayPal, Social Share Buttons plugin for WordPress is vulnerable to time-based SQL Injection via the $collectedIds parameter in all versions up to, and including, 24.0.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

    Published: 5 Nov 2024
    4.4
    Medium

    CVE-2024-9878

    Last Modified: 8 Apr 2026

    The Photo Gallery by 10Web – Mobile-Friendly Image Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.8.30 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.

    Published: 5 Nov 2024
    4.3
    Medium

    CVE-2024-7429

    Last Modified: 8 Apr 2026

    The Zotpress plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the Zotpress_process_accounts_AJAX function in all versions up to, and including, 7.3.12. This makes it possible for authenticated attackers, with Contributor-level access and above, to reset the plugin's settings.

    Published: 5 Nov 2024
    5.1
    Medium

    CVE-2024-51527

    Last Modified: 7 Nov 2024

    Permission control vulnerability in the Gallery app Impact: Successful exploitation of this vulnerability may affect service confidentiality.

    Published: 5 Nov 2024
    8.2
    High

    CVE-2024-51526

    Last Modified: 7 Nov 2024

    Permission control vulnerability in the hidebug module Impact: Successful exploitation of this vulnerability may affect service confidentiality.

    Published: 5 Nov 2024
    6.2
    Medium

    CVE-2024-51525

    Last Modified: 18 Sept 2025

    Permission control vulnerability in the clipboard module Impact: Successful exploitation of this vulnerability may affect service confidentiality.

    Published: 5 Nov 2024
    4.7
    Medium

    CVE-2024-47255

    Last Modified: 9 Jan 2026

    In 2N Access Commander versions 3.1.1.2 and prior, a local attacker can escalate their privileges in the system which could allow for arbitrary code execution with root permissions.

    Published: 5 Nov 2024
    4
    Medium

    CVE-2024-51524

    Last Modified: 7 Nov 2024

    Permission control vulnerability in the Wi-Fi module Impact: Successful exploitation of this vulnerability may affect service confidentiality.

    Published: 5 Nov 2024
    7.1
    High

    CVE-2024-51523

    Last Modified: 7 Nov 2024

    Information management vulnerability in the Gallery module Impact: Successful exploitation of this vulnerability may affect service confidentiality.

    Published: 5 Nov 2024
    6.2
    Medium

    CVE-2024-51522

    Last Modified: 7 Nov 2024

    Vulnerability of improper device information processing in the device management module Impact: Successful exploitation of this vulnerability may affect availability.

    Published: 5 Nov 2024
    6.3
    Medium

    CVE-2024-47254

    Last Modified: 9 Jan 2026

    In 2N Access Commander versions 3.1.1.2 and prior, an Insufficient Verification of Data Authenticity vulnerability could allow an attacker to escalate their privileges and gain root access to the system.

    Published: 5 Nov 2024
    5.7
    Medium

    CVE-2024-51521

    Last Modified: 7 Nov 2024

    Input parameter verification vulnerability in the background service module Impact: Successful exploitation of this vulnerability may affect availability.

    Published: 5 Nov 2024
    5.5
    Medium

    CVE-2024-51520

    Last Modified: 7 Nov 2024

    Vulnerability of input parameters not being verified in the HDC module Impact: Successful exploitation of this vulnerability may affect availability.

    Published: 5 Nov 2024
    5
    Medium

    CVE-2024-51519

    Last Modified: 6 Nov 2024

    Vulnerability of input parameters not being verified in the HDC module Impact: Successful exploitation of this vulnerability may affect availability.

    Published: 5 Nov 2024
    7.2
    High

    CVE-2024-47253

    Last Modified: 9 Jan 2026

    In 2N Access Commander versions 3.1.1.2 and prior, a Path Traversal vulnerability could allow an attacker with administrative privileges to write files on the filesystem and potentially achieve arbitrary remote code execution. This vulnerability cannot be exploited by users with lower privilege roles.

    Published: 5 Nov 2024
    5.3
    Medium

    CVE-2024-51518

    Last Modified: 6 Nov 2024

    Vulnerability of message types not being verified in the advanced messaging modul Impact: Successful exploitation of this vulnerability may affect availability.

    Published: 5 Nov 2024
    5.1
    Medium

    CVE-2024-51517

    Last Modified: 6 Nov 2024

    Vulnerability of improper memory access in the phone service module Impact: Successful exploitation of this vulnerability may affect availability.

    Published: 5 Nov 2024
    6.2
    Medium

    CVE-2024-51516

    Last Modified: 18 Sept 2025

    Permission control vulnerability in the ability module Impact: Successful exploitation of this vulnerability may cause features to function abnormally.

    Published: 5 Nov 2024
    6.2
    Medium

    CVE-2024-51515

    Last Modified: 7 Nov 2024

    Race condition vulnerability in the kernel network module Impact:Successful exploitation of this vulnerability may affect availability.

    Published: 5 Nov 2024
    5.1
    Medium

    CVE-2024-10840

    Last Modified: 6 Nov 2024

    A vulnerability classified as problematic has been found in romadebrian WEB-Sekolah 1.0. Affected is an unknown function of the file /Admin/akun_edit.php of the component Backend. The manipulation of the argument kode leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

    Published: 5 Nov 2024
    5.3
    Medium

    CVE-2024-51514

    Last Modified: 7 Nov 2024

    Vulnerability of pop-up windows belonging to no app in the VPN module Impact: Successful exploitation of this vulnerability may affect service confidentiality.

    Published: 5 Nov 2024
    5.5
    Medium

    CVE-2024-51513

    Last Modified: 18 Sept 2025

    Vulnerability of processes not being fully terminated in the VPN module Impact: Successful exploitation of this vulnerability will affect power consumption.

    Published: 5 Nov 2024
    6.2
    Medium

    CVE-2024-51512

    Last Modified: 7 Nov 2024

    Vulnerability of parameter type not being verified in the WantAgent module Impact: Successful exploitation of this vulnerability may affect availability.

    Published: 5 Nov 2024
    6.2
    Medium

    CVE-2024-51511

    Last Modified: 7 Nov 2024

    Vulnerability of parameter type not being verified in the WantAgent module Impact: Successful exploitation of this vulnerability may affect availability.

    Published: 5 Nov 2024
    6.1
    Medium

    CVE-2024-9667

    Last Modified: 8 Apr 2026

    The Seriously Simple Podcasting plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 3.5.0. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

    Published: 5 Nov 2024
    8.8
    High

    CVE-2024-10711

    Last Modified: 8 Apr 2026

    The WooCommerce Report plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.5.1. This is due to missing or incorrect nonce validation on the settings update functionality. This makes it possible for unauthenticated attackers to update arbitrary options that can be leveraged for privilege escalation via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

    Published: 5 Nov 2024
    8.1
    High

    CVE-2024-10114

    Last Modified: 8 Apr 2026

    The WooCommerce - Social Login plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 2.7.7. This is due to insufficient verification on the user being returned by the social login token. This makes it possible for unauthenticated attackers to log in as any existing user on the site, such as an administrator, if they have access to the email and the user does not have an already-existing account for the service returning the token.

    Published: 5 Nov 2024
    6.4
    Medium

    CVE-2024-9443

    Last Modified: 8 Apr 2026

    The Basticom Framework plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.5.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses the SVG file.

    Published: 5 Nov 2024
    7.6
    High

    CVE-2024-51510

    Last Modified: 7 Nov 2024

    Out-of-bounds access vulnerability in the logo module Impact: Successful exploitation of this vulnerability may affect service confidentiality.

    Published: 5 Nov 2024
    3.3
    Low

    CVE-2024-47402

    Last Modified: 6 Nov 2024

    in OpenHarmony v4.0.0 and prior versions allow a local attacker cause DOS through out-of-bounds read.

    Published: 5 Nov 2024
    8.4
    High

    CVE-2024-47137

    Last Modified: 6 Nov 2024

    in OpenHarmony v4.1.0 and prior versions allow a local attacker cause the common permission is upgraded to root and sensitive information leak through out-of-bounds write.

    Published: 5 Nov 2024
    8.4
    High

    CVE-2024-47404

    Last Modified: 6 Nov 2024

    in OpenHarmony v4.1.0 and prior versions allow a local attacker cause the common permission is upgraded to root and sensitive information leak through double free.

    Published: 5 Nov 2024