CVE-2024-51672
Last Modified: 23 Apr 2026Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WPDeveloper BetterLinks betterlinks allows SQL Injection.This issue affects BetterLinks: from n/a through <= 2.1.7.
CVE-2024-50528
Last Modified: 23 Apr 2026Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Stacks Stacks Mobile App Builder stacks-mobile-app-builder allows Retrieve Embedded Sensitive Data.This issue affects Stacks Mobile App Builder: from n/a through <= 5.2.3.
CVE-2024-50523
Last Modified: 23 Apr 2026Unrestricted Upload of File with Dangerous Type vulnerability in RainbowLink Inc. All Post Contact Form allpost-contactform allows Upload a Web Shell to a Web Server.This issue affects All Post Contact Form: from n/a through <= 1.8.2.
CVE-2024-50525
Last Modified: 23 Apr 2026Unrestricted Upload of File with Dangerous Type vulnerability in helloprint Helloprint helloprint allows Upload a Web Shell to a Web Server.This issue affects Helloprint: from n/a through <= 2.0.4.
CVE-2024-50526
Last Modified: 23 Apr 2026Unrestricted Upload of File with Dangerous Type vulnerability in Lindeni Mahlalela Multi Purpose Mail Form multi-purpose-mail-form allows Upload a Web Shell to a Web Server.This issue affects Multi Purpose Mail Form: from n/a through <= 1.0.2.
CVE-2024-50527
Last Modified: 23 Apr 2026Unrestricted Upload of File with Dangerous Type vulnerability in Stacks Stacks Mobile App Builder stacks-mobile-app-builder allows Upload a Web Shell to a Web Server.This issue affects Stacks Mobile App Builder: from n/a through <= 5.2.3.
CVE-2024-50529
Last Modified: 23 Apr 2026Unrestricted Upload of File with Dangerous Type vulnerability in rudrainn Training – Courses training allows Upload a Web Shell to a Web Server.This issue affects Training – Courses: from n/a through <= 2.0.1.
CVE-2024-50530
Last Modified: 23 Apr 2026Unrestricted Upload of File with Dangerous Type vulnerability in Myriad Solutionz Stars SMTP Mailer stars-smtp-mailer allows Upload a Web Shell to a Web Server.This issue affects Stars SMTP Mailer: from n/a through <= 2.2.1.
CVE-2024-50531
Last Modified: 23 Apr 2026Unrestricted Upload of File with Dangerous Type vulnerability in davidfcarr RSVPMaker for Toastmasters rsvpmaker-for-toastmasters allows Upload a Web Shell to a Web Server.This issue affects RSVPMaker for Toastmasters: from n/a through <= 6.2.4.
CVE-2024-51582
Last Modified: 23 Apr 2026Path Traversal: '.../...//' vulnerability in ThimPress WP Hotel Booking wp-hotel-booking allows PHP Local File Inclusion.This issue affects WP Hotel Booking: from n/a through <= 2.2.9.
CVE-2024-51665
Last Modified: 23 Apr 2026Server-Side Request Forgery (SSRF) vulnerability in Noor Alam Magical Addons For Elementor magical-addons-for-elementor allows Server Side Request Forgery.This issue affects Magical Addons For Elementor: from n/a through <= 1.2.1.
CVE-2024-10766
Last Modified: 6 Nov 2024A vulnerability, which was classified as critical, has been found in Codezips Free Exam Hall Seating Management System 1.0. This issue affects some unknown processing of the file /pages/save_user.php. The manipulation of the argument image leads to unrestricted upload. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The initial researcher disclosure contains confusing vulnerability classes and file names.
CVE-2024-9147
Last Modified: 2 Jun 2026Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Bna Informatics PosPratik allows XSS Through HTTP Query Strings. This issue affects PosPratik: before v3.2.1.
CVE-2024-51561
Last Modified: 6 Nov 2024This vulnerability exists in Aero due to improper implementation of OTP validation mechanism in certain API endpoints. An authenticated remote attacker could exploit this vulnerability by intercepting and manipulating the responses exchanged during the second factor authentication process. Successful exploitation of this vulnerability could allow the attacker to bypass OTP verification for accessing other user accounts.
CVE-2024-51560
Last Modified: 8 Nov 2024This vulnerability exists in the Wave 2.0 due to improper exception handling for invalid inputs at certain API endpoint. An authenticated remote attacker could exploit this vulnerability by providing invalid inputs for “userId” parameter in the API request leading to generation of error message containing sensitive information on the targeted system.
CVE-2024-51559
Last Modified: 22 Nov 2024This vulnerability exists in the Wave 2.0 due to improper authorization checks on certain API endpoints. An authenticated remote attacker could exploit this vulnerability by manipulating API input parameters to gain unauthorized access and perform malicious activities on other user accounts.
CVE-2024-51558
Last Modified: 8 Nov 2024This vulnerability exists in the Wave 2.0 due to missing restrictions for excessive failed authentication attempts on its API based login. A remote attacker could exploit this vulnerability by conducting a brute force attack against legitimate user OTP, MPIN or password, which could lead to gain unauthorized access and compromise other user accounts.
CVE-2024-51557
Last Modified: 8 Nov 2024This vulnerability exists in the Wave 2.0 due to missing rate limiting on OTP requests in an API endpoint. An authenticated remote attacker could exploit this vulnerability by sending multiple OTP request through vulnerable API endpoint which could lead to the OTP bombing/flooding on the targeted system.
CVE-2024-51556
Last Modified: 22 Nov 2024This vulnerability exists in the Wave 2.0 due to insufficient encryption of sensitive data received at the API response. An authenticated remote attacker could exploit this vulnerability by manipulating API input parameters through API request URL/payload leading to unauthorized access to sensitive information belonging to other users.
CVE-2024-10035
Last Modified: 2 Jun 2026Improper Control of Generation of Code ('Code Injection'), Improper Neutralization of Special Elements used in a Command ('Command Injection'), Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in BG-TEK Informatics Security Technologies CoslatV3 allows Command Injection, Privilege Escalation. This issue affects CoslatV3: through 3.1069. NOTE: The vendor was contacted and it was learned that the product is not supported.
CVE-2024-10765
Last Modified: 6 Nov 2024A vulnerability classified as critical was found in Codezips Online Institute Management System up to 1.0. This vulnerability affects unknown code of the file /profile.php. The manipulation of the argument old_image leads to unrestricted upload. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
CVE-2024-10764
Last Modified: 6 Nov 2024A vulnerability classified as critical has been found in Codezips Online Institute Management System 1.0. This affects an unknown part of the file /pages/save_user.php. The manipulation of the argument image leads to unrestricted upload. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
CVE-2024-36485
Last Modified: 7 Nov 2024Zohocorp ManageEngine ADAudit Plus versions below 8121 are vulnerable to SQL Injection in Technician reports option.
CVE-2024-51661
Last Modified: 23 Apr 2026Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in David Lingren Media LIbrary Assistant media-library-assistant allows Command Injection.This issue affects Media LIbrary Assistant: from n/a through <= 3.19.
CVE-2024-48878
Last Modified: 5 Nov 2024Zohocorp ManageEngine ADManager Plus versions 7241 and prior are vulnerable to SQL Injection in Archived Audit Report.
CVE-2024-38424
Last Modified: 16 Nov 2024Memory corruption during GNSS HAL process initialization.
CVE-2024-38423
Last Modified: 7 Nov 2024Memory corruption while processing GPU page table switch.
CVE-2024-38422
Last Modified: 7 Nov 2024Memory corruption while processing voice packet with arbitrary data received from ADSP.
CVE-2024-38421
Last Modified: 7 Nov 2024Memory corruption while processing GPU commands.
CVE-2024-38419
Last Modified: 7 Nov 2024Memory corruption while invoking IOCTL calls from the use-space for HGSL memory node.
CVE-2024-38415
Last Modified: 7 Nov 2024Memory corruption while handling session errors from firmware.
CVE-2024-38410
Last Modified: 16 Nov 2024Memory corruption while IOCLT is called when device is in invalid state and the WMI command buffer may be freed twice.
CVE-2024-38409
Last Modified: 16 Nov 2024Memory corruption while station LL statistic handling.
CVE-2024-38408
Last Modified: 8 Nov 2024Cryptographic issue when a controller receives an LMP start encryption command under unexpected conditions.
CVE-2024-38407
Last Modified: 16 Nov 2024Memory corruption while processing input parameters for any IOCTL call in the JPEG Encoder driver.
CVE-2024-38406
Last Modified: 16 Nov 2024Memory corruption while handling IOCTL calls in JPEG Encoder driver.
CVE-2024-38405
Last Modified: 7 Nov 2024Transient DOS while processing the CU information from RNR IE.
CVE-2024-38403
Last Modified: 7 Nov 2024Transient DOS while parsing BTM ML IE when per STA profile is not included.
CVE-2024-33068
Last Modified: 7 Nov 2024Transient DOS while parsing fragments of MBSSID IE from beacon frame.
CVE-2024-33033
Last Modified: 8 Nov 2024Memory corruption while processing IOCTL calls to unmap the buffers.
CVE-2024-33032
Last Modified: 8 Nov 2024Memory corruption when the user application modifies the same shared memory asynchronously when kernel is accessing it.
CVE-2024-33031
Last Modified: 16 Nov 2024Memory corruption while processing the update SIM PB records request.
CVE-2024-33030
Last Modified: 8 Nov 2024Memory corruption while parsing IPC frequency table parameters for LPLH that has size greater than expected size.
CVE-2024-33029
Last Modified: 8 Nov 2024Memory corruption while handling the PDR in driver for getting the remote heap maps.
CVE-2024-23386
Last Modified: 16 Nov 2024memory corruption when WiFi display APIs are invoked with large random inputs.
CVE-2024-23385
Last Modified: 7 Nov 2024Transient DOS as modem reset occurs when an unexpected MAC RAR (with invalid PDU length) is seen at UE.
CVE-2024-23377
Last Modified: 8 Nov 2024Memory corruption while invoking IOCTL command from user-space, when a user modifies the original packet size of the command after system properties have been already sent to the EVA driver.
CVE-2024-23590
Last Modified: 10 Jul 2025Session Fixation vulnerability in Apache Kylin. This issue affects Apache Kylin: from 2.0.0 through 4.x. Users are recommended to upgrade to version 5.0.0 or above, which fixes the issue.
CVE-2024-10523
Last Modified: 8 Nov 2024This vulnerability exists in TP-Link IoT Smart Hub due to storage of Wi-Fi credentials in plain text within the device firmware. An attacker with physical access could exploit this by extracting the firmware and analyzing the binary data to obtain the Wi-Fi credentials stored on the vulnerable device.
CVE-2024-10389
Last Modified: 23 Jul 2025There exists a Path Traversal vulnerability in Safearchive on Platforms with Case-Insensitive Filesystems (e.g., NTFS). This allows Attackers to Write Arbitrary Files via Archive Extraction containing symbolic links. We recommend upgrading past commit f7ce9d7b6f9c6ecd72d0b0f16216b046e55e44dc
