CVE Feed

    Dashboard / CVE

    5.3
    Medium

    CVE-2024-43923

    Last Modified: 13 Nov 2024

    Missing Authorization vulnerability in Arraytics Timetics allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Timetics: from n/a through 1.0.23.

    Published: 1 Nov 2024
    4.3
    Medium

    CVE-2024-43925

    Last Modified: 13 Nov 2024

    Missing Authorization vulnerability in Envira Gallery Team Envira Photo Gallery allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Envira Photo Gallery: from n/a through 1.8.14.

    Published: 1 Nov 2024
    5.4
    Medium

    CVE-2024-43928

    Last Modified: 12 Nov 2024

    Missing Authorization vulnerability in eyecix JobSearch allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects JobSearch: from n/a through 2.5.4.

    Published: 1 Nov 2024
    6.5
    Medium

    CVE-2024-43929

    Last Modified: 12 Nov 2024

    Missing Authorization vulnerability in eyecix JobSearch allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects JobSearch: from n/a through 2.5.4.

    Published: 1 Nov 2024
    6.5
    Medium

    CVE-2024-43932

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in POSIMYTH The Plus Addons for Elementor Page Builder Lite the-plus-addons-for-elementor-page-builder.This issue affects The Plus Addons for Elementor Page Builder Lite: from n/a through <= 5.6.2.

    Published: 1 Nov 2024
    6.4
    Medium

    CVE-2024-43937

    Last Modified: 8 Nov 2024

    Missing Authorization vulnerability in Themeum WP Crowdfunding allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Crowdfunding: from n/a through 2.1.10.

    Published: 1 Nov 2024
    6.5
    Medium

    CVE-2024-43956

    Last Modified: 28 Apr 2026

    Missing Authorization vulnerability in Caseproof, LLC Memberpress allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Memberpress: from n/a through 1.11.34.

    Published: 1 Nov 2024
    5.4
    Medium

    CVE-2024-43962

    Last Modified: 8 Nov 2024

    Missing Authorization vulnerability in LWS LWS Affiliation allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects LWS Affiliation: from n/a through 2.3.4.

    Published: 1 Nov 2024
    4.3
    Medium

    CVE-2024-43968

    Last Modified: 13 Nov 2025

    Broken Access Control vulnerability in Automattic Newspack allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Newspack: from n/a through 3.8.6.

    Published: 1 Nov 2024
    4.3
    Medium

    CVE-2024-43973

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in Stiofan GetPaid invoicing allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects GetPaid: from n/a through <= 2.8.11.

    Published: 1 Nov 2024
    6.5
    Medium

    CVE-2024-43974

    Last Modified: 8 Nov 2024

    Missing Authorization vulnerability in CozyThemes ReviveNews allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects ReviveNews: from n/a through 1.0.2.

    Published: 1 Nov 2024
    6.5
    Medium

    CVE-2024-43979

    Last Modified: 8 Nov 2024

    Missing Authorization vulnerability in CozyThemes Blockbooster allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Blockbooster: from n/a through 1.0.10.

    Published: 1 Nov 2024
    6.5
    Medium

    CVE-2024-43980

    Last Modified: 8 Nov 2024

    Missing Authorization vulnerability in CozyThemes Fota WP allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Fota WP: from n/a through 1.4.1.

    Published: 1 Nov 2024
    4.3
    Medium

    CVE-2024-43981

    Last Modified: 8 Nov 2024

    Missing Authorization vulnerability in AyeCode – WP Business Directory Plugins GeoDirectory allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects GeoDirectory: from n/a through 2.3.70.

    Published: 1 Nov 2024
    8.8
    High

    CVE-2024-43982

    Last Modified: 8 Nov 2024

    Missing Authorization vulnerability in Geek Code Lab Login As Users allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Login As Users: from n/a through 1.4.3.

    Published: 1 Nov 2024
    6.5
    Medium

    CVE-2024-43998

    Last Modified: 8 Nov 2024

    Missing Authorization vulnerability in WebsiteinWP Blogpoet allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Blogpoet: from n/a through 1.0.3.

    Published: 1 Nov 2024
    4.3
    Medium

    CVE-2024-44006

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in Amir Helzer WooCommerce Multilingual & Multicurrency woocommerce-multilingual.This issue affects WooCommerce Multilingual & Multicurrency: from n/a through <= 5.3.6.

    Published: 1 Nov 2024
    5.3
    Medium

    CVE-2024-44019

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in Renzo Johnson Contact Form 7 Campaign Monitor Extension contact-form-7-campaign-monitor-extension.This issue affects Contact Form 7 Campaign Monitor Extension: from n/a through <= 0.4.67.

    Published: 1 Nov 2024
    4.3
    Medium

    CVE-2024-44020

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in prasadkirpekar WP Free SSL – Free SSL Certificate for WordPress and force HTTPS wp-free-ssl.This issue affects WP Free SSL – Free SSL Certificate for WordPress and force HTTPS: from n/a through <= 1.2.7.

    Published: 1 Nov 2024
    5.4
    Medium

    CVE-2024-44021

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in truepushplugin Truepush truepush-free-web-push-notifications.This issue affects Truepush: from n/a through <= 1.0.8.

    Published: 1 Nov 2024
    4.3
    Medium

    CVE-2024-44031

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in beardev JoomSport joomsport-sports-league-results-management.This issue affects JoomSport: from n/a through <= 5.6.3.

    Published: 1 Nov 2024
    4.3
    Medium

    CVE-2024-44052

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in HelloAsso HelloAsso helloasso.This issue affects HelloAsso: from n/a through <= 1.1.10.

    Published: 1 Nov 2024
    6.5
    Medium

    CVE-2024-47308

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in WPDeveloper Templately templately.This issue affects Templately: from n/a through <= 3.1.2.

    Published: 1 Nov 2024
    4.3
    Medium

    CVE-2024-47317

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in Ads by WPQuads Ads by WPQuads quick-adsense-reloaded.This issue affects Ads by WPQuads: from n/a through <= 2.0.84.

    Published: 1 Nov 2024
    4.3
    Medium

    CVE-2024-47318

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in Magazine3 PWA for WP & AMP pwa-for-wp.This issue affects PWA for WP & AMP: from n/a through <= 1.7.72.

    Published: 1 Nov 2024
    6.5
    Medium

    CVE-2024-47321

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in Fahad Mahmood WP Datepicker wp-datepicker.This issue affects WP Datepicker: from n/a through <= 2.1.1.

    Published: 1 Nov 2024
    5.3
    Medium

    CVE-2024-47358

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in Daniel Iser Popup Maker popup-maker.This issue affects Popup Maker: from n/a through <= 1.19.2.

    Published: 1 Nov 2024
    5.3
    Medium

    CVE-2024-47359

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in averta Depicter Slider depicter.This issue affects Depicter Slider: from n/a through <= 3.2.2.

    Published: 1 Nov 2024
    6.5
    Medium

    CVE-2024-47361

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in WPVibes Elementor Addon Elements addon-elements-for-elementor-page-builder.This issue affects Elementor Addon Elements: from n/a through <= 1.13.6.

    Published: 1 Nov 2024
    4.3
    Medium

    CVE-2024-47362

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in WP Chill Strong Testimonials strong-testimonials.This issue affects Strong Testimonials: from n/a through <= 3.1.16.

    Published: 1 Nov 2024
    8.2
    High

    CVE-2024-37094

    Last Modified: 22 Jan 2025

    Missing Authorization vulnerability in StylemixThemes MasterStudy LMS allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects MasterStudy LMS: from n/a through 3.2.12.

    Published: 1 Nov 2024
    —
    Unknown

    CVE-2024-10694

    Last Modified: 11 Nov 2024

    ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2024-9542. Reason: This candidate is a reservation duplicate of CVE-2024-9542. Notes: All CVE users should reference CVE-2024-9542 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage.

    Published: 1 Nov 2024
    9.8
    Critical

    CVE-2024-7456

    Last Modified: 6 Nov 2024

    A SQL injection vulnerability exists in the `/api/v1/external-users` route of lunary-ai/lunary version v1.4.2. The `order by` clause of the SQL query uses `sql.unsafe` without prior sanitization, allowing for SQL injection. The `orderByClause` variable is constructed without server-side validation or sanitization, enabling an attacker to execute arbitrary SQL commands. Successful exploitation can lead to complete data loss, modification, or corruption.

    Published: 1 Nov 2024
    8.7
    High

    CVE-2024-10662

    Last Modified: 5 Nov 2024

    A vulnerability was found in Tenda AC15 15.03.05.19 and classified as critical. This issue affects the function formSetDeviceName of the file /goform/SetOnlineDevName. The manipulation of the argument devName leads to stack-based buffer overflow. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

    Published: 1 Nov 2024
    8.7
    High

    CVE-2024-10661

    Last Modified: 5 Nov 2024

    A vulnerability has been found in Tenda AC15 15.03.05.19 and classified as critical. This vulnerability affects the function SetDlnaCfg of the file /goform/SetDlnaCfg. The manipulation of the argument scanList leads to stack-based buffer overflow. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

    Published: 1 Nov 2024
    —
    Unknown

    CVE-2024-10691

    Last Modified: 15 Nov 2024

    ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2024-9530. Reason: This candidate is a reservation duplicate of CVE-2024-9530. Notes: All CVE users should reference CVE-2024-9530 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage.

    Published: 1 Nov 2024
    5.3
    Medium

    CVE-2024-10660

    Last Modified: 5 Nov 2024

    A vulnerability, which was classified as critical, was found in ESAFENET CDG 5. This affects the function deleteHook of the file /com/esafenet/servlet/policy/HookService.java. The manipulation of the argument hookId leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

    Published: 1 Nov 2024
    5.3
    Medium

    CVE-2024-10659

    Last Modified: 5 Nov 2024

    A vulnerability, which was classified as critical, has been found in ESAFENET CDG 5. Affected by this issue is the function delSystemEncryptPolicy of the file /com/esafenet/servlet/document/CDGAuthoriseTempletService.java. The manipulation of the argument id leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

    Published: 1 Nov 2024
    6.4
    Medium

    CVE-2024-10367

    Last Modified: 15 Apr 2026

    The Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE plugin for WordPress is vulnerable to Stored Cross-Site Scripting via REST API SVG File uploads in all versions up to, and including, 3.0.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses the SVG file.

    Published: 1 Nov 2024
    5.3
    Medium

    CVE-2024-10658

    Last Modified: 4 Nov 2024

    A vulnerability classified as critical was found in Tongda OA up to 11.10. Affected by this vulnerability is an unknown functionality of the file /pda/approve_center/check_seal.php. The manipulation of the argument ID leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

    Published: 1 Nov 2024
    5.3
    Medium

    CVE-2024-10657

    Last Modified: 4 Nov 2024

    A vulnerability classified as critical has been found in Tongda OA up to 11.10. Affected is an unknown function of the file /pda/approve_center/prcs_info.php. The manipulation of the argument RUN_ID leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

    Published: 1 Nov 2024
    5.3
    Medium

    CVE-2024-10656

    Last Modified: 4 Nov 2024

    A vulnerability was found in Tongda OA 2017 up to 11.9. It has been rated as critical. This issue affects some unknown processing of the file /pda/meeting/apply.php. The manipulation of the argument mr_id leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

    Published: 1 Nov 2024
    7.2
    High

    CVE-2024-10653

    Last Modified: 15 Apr 2026

    IDExpert from CHANGING Information Technology does not properly validate a specific parameter in the administrator interface, allowing remote attackers with administrative privileges to inject and execute OS commands on the server.

    Published: 1 Nov 2024
    6.1
    Medium

    CVE-2024-10652

    Last Modified: 15 Apr 2026

    IDExpert from CHANGING Information Technology does not properly validate a parameter for a specific functionality, allowing unauthenticated remote attackers to inject JavsScript code and perform Reflected Cross-site scripting attacks.

    Published: 1 Nov 2024
    4.9
    Medium

    CVE-2024-10651

    Last Modified: 15 Apr 2026

    IDExpert from CHANGING Information Technology does not properly validate a specific parameter in the administrator interface, allowing remote attackers with administrator privileges to exploit this vulnerability to read arbitrary system files.

    Published: 1 Nov 2024
    5.3
    Medium

    CVE-2024-10655

    Last Modified: 4 Nov 2024

    A vulnerability was found in Tongda OA 2017 up to 11.9. It has been declared as critical. This vulnerability affects unknown code of the file /pda/reportshop/new.php. The manipulation of the argument repid leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

    Published: 1 Nov 2024
    6.4
    Medium

    CVE-2024-10232

    Last Modified: 15 Apr 2026

    The Group Chat & Video Chat by AtomChat plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's atomchat shortcode in all versions up to, and including, 1.1.5 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 1 Nov 2024
    6.4
    Medium

    CVE-2024-9655

    Last Modified: 8 Apr 2026

    The Gutenberg Blocks with AI by Kadence WP – Page Builder Features plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Icon widget in all versions up to, and including, 6.6.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 1 Nov 2024
    5.4
    Medium

    CVE-2024-7424

    Last Modified: 15 Apr 2026

    The Multiple Page Generator Plugin – MPG plugin for WordPress is vulnerable to unauthorized modification of and access to data due to a missing capability check on several functions in all versions up to, and including, 4.0.1. This makes it possible for authenticated attackers, with Subscriber-level access and above, to invoke those functions intended for admin use resulting in subscribers being able to upload csv files and view the contents of MPG projects.

    Published: 1 Nov 2024
    6.9
    Medium

    CVE-2024-10654

    Last Modified: 5 Nov 2024

    A vulnerability has been found in TOTOLINK LR350 up to 9.3.5u.6369 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /formLoginAuth.htm. The manipulation of the argument authCode with the input 1 leads to authorization bypass. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 9.3.5u.6698_B20230810 is able to address this issue. It is recommended to upgrade the affected component.

    Published: 1 Nov 2024