CVE Feed

    Dashboard / CVE

    7.6
    High

    CVE-2024-51672

    Last Modified: 23 Apr 2026

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WPDeveloper BetterLinks betterlinks allows SQL Injection.This issue affects BetterLinks: from n/a through <= 2.1.7.

    Published: 4 Nov 2024
    7.5
    High

    CVE-2024-50528

    Last Modified: 23 Apr 2026

    Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Stacks Stacks Mobile App Builder stacks-mobile-app-builder allows Retrieve Embedded Sensitive Data.This issue affects Stacks Mobile App Builder: from n/a through <= 5.2.3.

    Published: 4 Nov 2024
    10
    Critical

    CVE-2024-50523

    Last Modified: 23 Apr 2026

    Unrestricted Upload of File with Dangerous Type vulnerability in RainbowLink Inc. All Post Contact Form allpost-contactform allows Upload a Web Shell to a Web Server.This issue affects All Post Contact Form: from n/a through <= 1.8.2.

    Published: 4 Nov 2024
    10
    Critical

    CVE-2024-50525

    Last Modified: 23 Apr 2026

    Unrestricted Upload of File with Dangerous Type vulnerability in helloprint Helloprint helloprint allows Upload a Web Shell to a Web Server.This issue affects Helloprint: from n/a through <= 2.0.4.

    Published: 4 Nov 2024
    10
    Critical

    CVE-2024-50526

    Last Modified: 23 Apr 2026

    Unrestricted Upload of File with Dangerous Type vulnerability in Lindeni Mahlalela Multi Purpose Mail Form multi-purpose-mail-form allows Upload a Web Shell to a Web Server.This issue affects Multi Purpose Mail Form: from n/a through <= 1.0.2.

    Published: 4 Nov 2024
    10
    Critical

    CVE-2024-50527

    Last Modified: 23 Apr 2026

    Unrestricted Upload of File with Dangerous Type vulnerability in Stacks Stacks Mobile App Builder stacks-mobile-app-builder allows Upload a Web Shell to a Web Server.This issue affects Stacks Mobile App Builder: from n/a through <= 5.2.3.

    Published: 4 Nov 2024
    9.9
    Critical

    CVE-2024-50529

    Last Modified: 23 Apr 2026

    Unrestricted Upload of File with Dangerous Type vulnerability in rudrainn Training – Courses training allows Upload a Web Shell to a Web Server.This issue affects Training – Courses: from n/a through <= 2.0.1.

    Published: 4 Nov 2024
    9.9
    Critical

    CVE-2024-50530

    Last Modified: 23 Apr 2026

    Unrestricted Upload of File with Dangerous Type vulnerability in Myriad Solutionz Stars SMTP Mailer stars-smtp-mailer allows Upload a Web Shell to a Web Server.This issue affects Stars SMTP Mailer: from n/a through <= 2.2.1.

    Published: 4 Nov 2024
    10
    Critical

    CVE-2024-50531

    Last Modified: 23 Apr 2026

    Unrestricted Upload of File with Dangerous Type vulnerability in davidfcarr RSVPMaker for Toastmasters rsvpmaker-for-toastmasters allows Upload a Web Shell to a Web Server.This issue affects RSVPMaker for Toastmasters: from n/a through <= 6.2.4.

    Published: 4 Nov 2024
    7.5
    High

    CVE-2024-51582

    Last Modified: 23 Apr 2026

    Path Traversal: '.../...//' vulnerability in ThimPress WP Hotel Booking wp-hotel-booking allows PHP Local File Inclusion.This issue affects WP Hotel Booking: from n/a through <= 2.2.9.

    Published: 4 Nov 2024
    4.9
    Medium

    CVE-2024-51665

    Last Modified: 23 Apr 2026

    Server-Side Request Forgery (SSRF) vulnerability in Noor Alam Magical Addons For Elementor magical-addons-for-elementor allows Server Side Request Forgery.This issue affects Magical Addons For Elementor: from n/a through <= 1.2.1.

    Published: 4 Nov 2024
    5.3
    Medium

    CVE-2024-10766

    Last Modified: 6 Nov 2024

    A vulnerability, which was classified as critical, has been found in Codezips Free Exam Hall Seating Management System 1.0. This issue affects some unknown processing of the file /pages/save_user.php. The manipulation of the argument image leads to unrestricted upload. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The initial researcher disclosure contains confusing vulnerability classes and file names.

    Published: 4 Nov 2024
    6.9
    Medium

    CVE-2024-9147

    Last Modified: 2 Jun 2026

    Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Bna Informatics PosPratik allows XSS Through HTTP Query Strings. This issue affects PosPratik: before v3.2.1.

    Published: 4 Nov 2024
    9.3
    Critical

    CVE-2024-51561

    Last Modified: 6 Nov 2024

    This vulnerability exists in Aero due to improper implementation of OTP validation mechanism in certain API endpoints. An authenticated remote attacker could exploit this vulnerability by intercepting and manipulating the responses exchanged during the second factor authentication process. Successful exploitation of this vulnerability could allow the attacker to bypass OTP verification for accessing other user accounts.

    Published: 4 Nov 2024
    7.1
    High

    CVE-2024-51560

    Last Modified: 8 Nov 2024

    This vulnerability exists in the Wave 2.0 due to improper exception handling for invalid inputs at certain API endpoint. An authenticated remote attacker could exploit this vulnerability by providing invalid inputs for “userId” parameter in the API request leading to generation of error message containing sensitive information on the targeted system.

    Published: 4 Nov 2024
    7.1
    High

    CVE-2024-51559

    Last Modified: 22 Nov 2024

    This vulnerability exists in the Wave 2.0 due to improper authorization checks on certain API endpoints. An authenticated remote attacker could exploit this vulnerability by manipulating API input parameters to gain unauthorized access and perform malicious activities on other user accounts.

    Published: 4 Nov 2024
    9.3
    Critical

    CVE-2024-51558

    Last Modified: 8 Nov 2024

    This vulnerability exists in the Wave 2.0 due to missing restrictions for excessive failed authentication attempts on its API based login. A remote attacker could exploit this vulnerability by conducting a brute force attack against legitimate user OTP, MPIN or password, which could lead to gain unauthorized access and compromise other user accounts.

    Published: 4 Nov 2024
    7.1
    High

    CVE-2024-51557

    Last Modified: 8 Nov 2024

    This vulnerability exists in the Wave 2.0 due to missing rate limiting on OTP requests in an API endpoint. An authenticated remote attacker could exploit this vulnerability by sending multiple OTP request through vulnerable API endpoint which could lead to the OTP bombing/flooding on the targeted system.

    Published: 4 Nov 2024
    7.1
    High

    CVE-2024-51556

    Last Modified: 22 Nov 2024

    This vulnerability exists in the Wave 2.0 due to insufficient encryption of sensitive data received at the API response. An authenticated remote attacker could exploit this vulnerability by manipulating API input parameters through API request URL/payload leading to unauthorized access to sensitive information belonging to other users.

    Published: 4 Nov 2024
    9.2
    Critical

    CVE-2024-10035

    Last Modified: 2 Jun 2026

    Improper Control of Generation of Code ('Code Injection'), Improper Neutralization of Special Elements used in a Command ('Command Injection'), Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in BG-TEK Informatics Security Technologies CoslatV3 allows Command Injection, Privilege Escalation. This issue affects CoslatV3: through 3.1069. NOTE: The vendor was contacted and it was learned that the product is not supported.

    Published: 4 Nov 2024
    5.3
    Medium

    CVE-2024-10765

    Last Modified: 6 Nov 2024

    A vulnerability classified as critical was found in Codezips Online Institute Management System up to 1.0. This vulnerability affects unknown code of the file /profile.php. The manipulation of the argument old_image leads to unrestricted upload. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

    Published: 4 Nov 2024
    5.3
    Medium

    CVE-2024-10764

    Last Modified: 6 Nov 2024

    A vulnerability classified as critical has been found in Codezips Online Institute Management System 1.0. This affects an unknown part of the file /pages/save_user.php. The manipulation of the argument image leads to unrestricted upload. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

    Published: 4 Nov 2024
    8.3
    High

    CVE-2024-36485

    Last Modified: 7 Nov 2024

    Zohocorp ManageEngine ADAudit Plus versions below 8121 are vulnerable to SQL Injection in Technician reports option.

    Published: 4 Nov 2024
    9.1
    Critical

    CVE-2024-51661

    Last Modified: 23 Apr 2026

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in David Lingren Media LIbrary Assistant media-library-assistant allows Command Injection.This issue affects Media LIbrary Assistant: from n/a through <= 3.19.

    Published: 4 Nov 2024
    8.3
    High

    CVE-2024-48878

    Last Modified: 5 Nov 2024

    Zohocorp ManageEngine ADManager Plus versions 7241 and prior are vulnerable to SQL Injection in Archived Audit Report.

    Published: 4 Nov 2024
    7.8
    High

    CVE-2024-38424

    Last Modified: 16 Nov 2024

    Memory corruption during GNSS HAL process initialization.

    Published: 4 Nov 2024
    7.8
    High

    CVE-2024-38423

    Last Modified: 7 Nov 2024

    Memory corruption while processing GPU page table switch.

    Published: 4 Nov 2024
    7.8
    High

    CVE-2024-38422

    Last Modified: 7 Nov 2024

    Memory corruption while processing voice packet with arbitrary data received from ADSP.

    Published: 4 Nov 2024
    7.8
    High

    CVE-2024-38421

    Last Modified: 7 Nov 2024

    Memory corruption while processing GPU commands.

    Published: 4 Nov 2024
    7.8
    High

    CVE-2024-38419

    Last Modified: 7 Nov 2024

    Memory corruption while invoking IOCTL calls from the use-space for HGSL memory node.

    Published: 4 Nov 2024
    7.8
    High

    CVE-2024-38415

    Last Modified: 7 Nov 2024

    Memory corruption while handling session errors from firmware.

    Published: 4 Nov 2024
    7.8
    High

    CVE-2024-38410

    Last Modified: 16 Nov 2024

    Memory corruption while IOCLT is called when device is in invalid state and the WMI command buffer may be freed twice.

    Published: 4 Nov 2024
    7.8
    High

    CVE-2024-38409

    Last Modified: 16 Nov 2024

    Memory corruption while station LL statistic handling.

    Published: 4 Nov 2024
    8.2
    High

    CVE-2024-38408

    Last Modified: 8 Nov 2024

    Cryptographic issue when a controller receives an LMP start encryption command under unexpected conditions.

    Published: 4 Nov 2024
    7.8
    High

    CVE-2024-38407

    Last Modified: 16 Nov 2024

    Memory corruption while processing input parameters for any IOCTL call in the JPEG Encoder driver.

    Published: 4 Nov 2024
    7.8
    High

    CVE-2024-38406

    Last Modified: 16 Nov 2024

    Memory corruption while handling IOCTL calls in JPEG Encoder driver.

    Published: 4 Nov 2024
    7.5
    High

    CVE-2024-38405

    Last Modified: 7 Nov 2024

    Transient DOS while processing the CU information from RNR IE.

    Published: 4 Nov 2024
    7.5
    High

    CVE-2024-38403

    Last Modified: 7 Nov 2024

    Transient DOS while parsing BTM ML IE when per STA profile is not included.

    Published: 4 Nov 2024
    7.5
    High

    CVE-2024-33068

    Last Modified: 7 Nov 2024

    Transient DOS while parsing fragments of MBSSID IE from beacon frame.

    Published: 4 Nov 2024
    6.7
    Medium

    CVE-2024-33033

    Last Modified: 8 Nov 2024

    Memory corruption while processing IOCTL calls to unmap the buffers.

    Published: 4 Nov 2024
    6.7
    Medium

    CVE-2024-33032

    Last Modified: 8 Nov 2024

    Memory corruption when the user application modifies the same shared memory asynchronously when kernel is accessing it.

    Published: 4 Nov 2024
    6.7
    Medium

    CVE-2024-33031

    Last Modified: 16 Nov 2024

    Memory corruption while processing the update SIM PB records request.

    Published: 4 Nov 2024
    6.7
    Medium

    CVE-2024-33030

    Last Modified: 8 Nov 2024

    Memory corruption while parsing IPC frequency table parameters for LPLH that has size greater than expected size.

    Published: 4 Nov 2024
    6.7
    Medium

    CVE-2024-33029

    Last Modified: 8 Nov 2024

    Memory corruption while handling the PDR in driver for getting the remote heap maps.

    Published: 4 Nov 2024
    6.7
    Medium

    CVE-2024-23386

    Last Modified: 16 Nov 2024

    memory corruption when WiFi display APIs are invoked with large random inputs.

    Published: 4 Nov 2024
    7.5
    High

    CVE-2024-23385

    Last Modified: 7 Nov 2024

    Transient DOS as modem reset occurs when an unexpected MAC RAR (with invalid PDU length) is seen at UE.

    Published: 4 Nov 2024
    6.7
    Medium

    CVE-2024-23377

    Last Modified: 8 Nov 2024

    Memory corruption while invoking IOCTL command from user-space, when a user modifies the original packet size of the command after system properties have been already sent to the EVA driver.

    Published: 4 Nov 2024
    9.1
    Critical

    CVE-2024-23590

    Last Modified: 10 Jul 2025

    Session Fixation vulnerability in Apache Kylin. This issue affects Apache Kylin: from 2.0.0 through 4.x. Users are recommended to upgrade to version 5.0.0 or above, which fixes the issue.

    Published: 4 Nov 2024
    4.4
    Medium

    CVE-2024-10523

    Last Modified: 8 Nov 2024

    This vulnerability exists in TP-Link IoT Smart Hub due to storage of Wi-Fi credentials in plain text within the device firmware. An attacker with physical access could exploit this by extracting the firmware and analyzing the binary data to obtain the Wi-Fi credentials stored on the vulnerable device.

    Published: 4 Nov 2024
    5.9
    Medium

    CVE-2024-10389

    Last Modified: 23 Jul 2025

    There exists a Path Traversal vulnerability in Safearchive on Platforms with Case-Insensitive Filesystems (e.g., NTFS). This allows Attackers to Write Arbitrary Files via Archive Extraction containing symbolic links. We recommend upgrading past commit f7ce9d7b6f9c6ecd72d0b0f16216b046e55e44dc

    Published: 4 Nov 2024