CVE Feed

    Dashboard / CVE

    5.3
    Medium

    CVE-2024-10656

    Last Modified: 4 Nov 2024

    A vulnerability was found in Tongda OA 2017 up to 11.9. It has been rated as critical. This issue affects some unknown processing of the file /pda/meeting/apply.php. The manipulation of the argument mr_id leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

    Published: 1 Nov 2024
    7.2
    High

    CVE-2024-10653

    Last Modified: 15 Apr 2026

    IDExpert from CHANGING Information Technology does not properly validate a specific parameter in the administrator interface, allowing remote attackers with administrative privileges to inject and execute OS commands on the server.

    Published: 1 Nov 2024
    6.1
    Medium

    CVE-2024-10652

    Last Modified: 15 Apr 2026

    IDExpert from CHANGING Information Technology does not properly validate a parameter for a specific functionality, allowing unauthenticated remote attackers to inject JavsScript code and perform Reflected Cross-site scripting attacks.

    Published: 1 Nov 2024
    4.9
    Medium

    CVE-2024-10651

    Last Modified: 15 Apr 2026

    IDExpert from CHANGING Information Technology does not properly validate a specific parameter in the administrator interface, allowing remote attackers with administrator privileges to exploit this vulnerability to read arbitrary system files.

    Published: 1 Nov 2024
    5.3
    Medium

    CVE-2024-10655

    Last Modified: 4 Nov 2024

    A vulnerability was found in Tongda OA 2017 up to 11.9. It has been declared as critical. This vulnerability affects unknown code of the file /pda/reportshop/new.php. The manipulation of the argument repid leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

    Published: 1 Nov 2024
    6.4
    Medium

    CVE-2024-10232

    Last Modified: 15 Apr 2026

    The Group Chat & Video Chat by AtomChat plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's atomchat shortcode in all versions up to, and including, 1.1.5 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 1 Nov 2024
    6.4
    Medium

    CVE-2024-9655

    Last Modified: 8 Apr 2026

    The Gutenberg Blocks with AI by Kadence WP – Page Builder Features plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Icon widget in all versions up to, and including, 6.6.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 1 Nov 2024
    5.4
    Medium

    CVE-2024-7424

    Last Modified: 15 Apr 2026

    The Multiple Page Generator Plugin – MPG plugin for WordPress is vulnerable to unauthorized modification of and access to data due to a missing capability check on several functions in all versions up to, and including, 4.0.1. This makes it possible for authenticated attackers, with Subscriber-level access and above, to invoke those functions intended for admin use resulting in subscribers being able to upload csv files and view the contents of MPG projects.

    Published: 1 Nov 2024
    6.9
    Medium

    CVE-2024-10654

    Last Modified: 5 Nov 2024

    A vulnerability has been found in TOTOLINK LR350 up to 9.3.5u.6369 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /formLoginAuth.htm. The manipulation of the argument authCode with the input 1 leads to authorization bypass. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 9.3.5u.6698_B20230810 is able to address this issue. It is recommended to upgrade the affected component.

    Published: 1 Nov 2024
    8.7
    High

    CVE-2024-0106

    Last Modified: 15 Apr 2026

    NVIDIA ConnectX Host Firmware for the BlueField Data Processing Unit (DPU) contains a vulnerability where an attacker may cause an improper handling of insufficient privileges issue. A successful exploit of this vulnerability may lead to denial of service, data tampering, and limited information disclosure.

    Published: 1 Nov 2024
    8.9
    High

    CVE-2024-0105

    Last Modified: 15 Apr 2026

    NVIDIA ConnectX Firmware contains a vulnerability where an attacker may cause an improper handling of insufficient privileges issue. A successful exploit of this vulnerability may lead to denial of service, data tampering, and limited information disclosure.

    Published: 1 Nov 2024
    5.4
    Medium

    CVE-2024-21510

    Last Modified: 15 Apr 2026

    Versions of the package sinatra from 0.0.0 are vulnerable to Reliance on Untrusted Inputs in a Security Decision via the X-Forwarded-Host (XFH) header. When making a request to a method with redirect applied, it is possible to trigger an Open Redirect Attack by inserting an arbitrary address into this header. If used for caching purposes, such as with servers like Nginx, or as a reverse proxy, without handling the X-Forwarded-Host header, attackers can potentially exploit Cache Poisoning or Routing-based SSRF.

    Published: 1 Nov 2024
    6.9
    Medium

    CVE-2024-10620

    Last Modified: 15 Apr 2026

    A vulnerability was found in knightliao Disconf 2.6.36. It has been classified as critical. This affects an unknown part of the file /api/config/list of the component Configuration Center. The manipulation leads to improper authentication. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

    Published: 1 Nov 2024
    7.7
    High

    CVE-2024-47939

    Last Modified: 15 Apr 2026

    Stack-based buffer overflow vulnerability exists in multiple laser printers and MFPs which implement Ricoh Web Image Monitor. If this vulnerability is exploited, receiving a specially crafted request created and sent by an attacker may lead to arbitrary code execution and/or a denial-of-service (DoS) condition. As for the details of affected product names and versions, refer to the information provided by the vendors under [References].

    Published: 1 Nov 2024
    5.7
    Medium

    CVE-2024-49501

    Last Modified: 15 Apr 2026

    Sysmac Studio provided by OMRON Corporation contains an incorrect authorization vulnerability. If this vulnerability is exploited, an attacker may access the program which is protected by Data Protection function.

    Published: 1 Nov 2024
    5.3
    Medium

    CVE-2024-10619

    Last Modified: 4 Nov 2024

    A vulnerability, which was classified as critical, was found in Tongda OA 2017 up to 11.10. Affected is an unknown function of the file /pda/reportshop/next_detail.php. The manipulation of the argument repid leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

    Published: 1 Nov 2024
    6.5
    Medium

    CVE-2024-51398

    Last Modified: 15 Apr 2026

    Altai Technologies Ltd Altai X500 Indoor 22 802.11ac Wave 2 AP web Management Weak password leakage in the background may lead to unauthorized access, data theft, and network attacks, seriously threatening network security.

    Published: 1 Nov 2024
    8.8
    High

    CVE-2024-48217

    Last Modified: 15 Apr 2026

    An Insecure Direct Object Reference (IDOR) in the dashboard of SiSMART v7.4.0 allows attackers to execute a horizontal-privilege escalation.

    Published: 1 Nov 2024
    9.8
    Critical

    CVE-2024-51431

    Last Modified: 5 Nov 2024

    LB-LINK BL-WR 1300H v.1.0.4 contains hardcoded credentials stored in /etc/shadow which are easily guessable.

    Published: 1 Nov 2024
    4.8
    Medium

    CVE-2024-51432

    Last Modified: 15 Apr 2026

    Cross Site Scripting vulnerability in FiberHome HG6544C RP2743 allows an attacker to execute arbitrary code via the SSID field in the WIFI Clients List not being sanitized

    Published: 1 Nov 2024
    6.2
    Medium

    CVE-2024-51407

    Last Modified: 27 May 2025

    Floodlight SDN OpenFlow Controller v.1.2 has an issue that allows local hosts to construct false broadcast ports causing inter-host communication anomalies.

    Published: 1 Nov 2024
    6.2
    Medium

    CVE-2024-51406

    Last Modified: 11 Jun 2025

    Floodlight SDN Open Flow Controller v.1.2 has an issue that allows local hosts to build fake LLDP packets that allow specific clusters to be missed by Floodlight, which in turn leads to missed hosts inside and outside the cluster.

    Published: 1 Nov 2024
    8.8
    High

    CVE-2024-51244

    Last Modified: 5 Nov 2024

    In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the doIPSec function.

    Published: 1 Nov 2024
    9.8
    Critical

    CVE-2024-51252

    Last Modified: 5 Nov 2024

    In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the restore function.

    Published: 1 Nov 2024
    7.5
    High

    CVE-2024-22733

    Last Modified: 5 Nov 2024

    TP Link MR200 V4 Firmware version 210201 was discovered to contain a null-pointer-dereference in the web administration panel on /cgi/login via the sign, Action or LoginStatus query parameters which could lead to a denial of service by a local or remote unauthenticated attacker.

    Published: 1 Nov 2024
    7.1
    High

    CVE-2024-27524

    Last Modified: 17 Apr 2025

    Cross Site Scripting vulnerability in Chamilo LMS v.1.11.26 allows a remote attacker to escalate privileges via a crafted script to the filename parameter of the new_ticket.php component.

    Published: 1 Nov 2024
    4.6
    Medium

    CVE-2024-27525

    Last Modified: 18 Apr 2025

    Cross Site Scripting vulnerability in Chamilo LMS v.1.11.26 allows a remote attacker to escalate privileges via a crafted script to the filename parameter of the home.php component.

    Published: 1 Nov 2024
    9.1
    Critical

    CVE-2024-28265

    Last Modified: 11 Jul 2025

    IBOS v4.5.5 has an arbitrary file deletion vulnerability via \system\modules\dashboard\controllers\LoginController.php.

    Published: 1 Nov 2024
    7.5
    High

    CVE-2024-40490

    Last Modified: 15 Apr 2026

    An issue in Sourcebans++ before v.1.8.0 allows a remote attacker to obtain sensitive information via a crafted XAJAX call to the Forgot Password function.

    Published: 1 Nov 2024
    7.5
    High

    CVE-2024-48270

    Last Modified: 7 Jul 2025

    An issue in the component /logins of oasys v1.1 allows attackers to access sensitive information via a burst attack.

    Published: 1 Nov 2024
    6.5
    Medium

    CVE-2024-48289

    Last Modified: 15 Apr 2026

    An issue in the Bluetooth Low Energy implementation of Cypress Bluetooth SDK v3.66 allows attackers to cause a Denial of Service (DoS) via supplying a crafted LL_PAUSE_ENC_REQ packet.

    Published: 1 Nov 2024
    7.5
    High

    CVE-2024-48352

    Last Modified: 5 Nov 2024

    Yealink Meeting Server before V26.0.0.67 is vulnerable to sensitive data exposure in the server response via sending HTTP request with enterprise ID.

    Published: 1 Nov 2024
    7.5
    High

    CVE-2024-48353

    Last Modified: 7 Mar 2025

    Yealink Meeting Server before V26.0.0.67 allows attackers to obtain static key information from a front-end JS file and decrypt the plaintext passwords based on the obtained key information.

    Published: 1 Nov 2024
    6.1
    Medium

    CVE-2024-48410

    Last Modified: 15 Apr 2026

    Cross Site Scripting vulnerability in Camtrace v.9.16.2.1 allows a remote attacker to execute arbitrary code via the login.php.

    Published: 1 Nov 2024
    8.8
    High

    CVE-2024-51245

    Last Modified: 5 Nov 2024

    In DrayTek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the rename_table function.

    Published: 1 Nov 2024
    8.8
    High

    CVE-2024-51247

    Last Modified: 5 Nov 2024

    In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the doPPPo function.

    Published: 1 Nov 2024
    8.8
    High

    CVE-2024-51248

    Last Modified: 5 Nov 2024

    In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the modifyrow function.

    Published: 1 Nov 2024
    5.4
    Medium

    CVE-2024-51377

    Last Modified: 14 Nov 2024

    An issue in Ladybird Web Solution Faveo Helpdesk & Servicedesk (On-Premise and Cloud) 9.2.0 allows a remote attacker to execute arbitrary code via the Subject and Identifier fields

    Published: 1 Nov 2024
    5.7
    Medium

    CVE-2024-51399

    Last Modified: 15 Apr 2026

    Altai Technologies Ltd Altai IX500 Indoor 22 802.11ac Wave 2 AP After login, there are file reads in the background, and attackers can obtain sensitive information such as user credentials, system configuration, and database connection strings, which can lead to data breaches and identity theft.

    Published: 1 Nov 2024
    6.9
    Medium

    CVE-2024-10605

    Last Modified: 23 Oct 2025

    A vulnerability was found in code-projects Blood Bank Management System 1.0. It has been classified as problematic. This affects an unknown part of the file /file/request.php. The manipulation leads to cross-site request forgery. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

    Published: 31 Oct 2024
    5.3
    Medium

    CVE-2024-10618

    Last Modified: 4 Nov 2024

    A vulnerability, which was classified as critical, has been found in Tongda OA 2017 up to 11.10. This issue affects some unknown processing of the file /pda/reportshop/record_detail.php. The manipulation of the argument repid leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

    Published: 31 Oct 2024
    5.3
    Medium

    CVE-2024-10617

    Last Modified: 4 Nov 2024

    A vulnerability classified as critical was found in Tongda OA up to 11.10. This vulnerability affects unknown code of the file /pda/workflow/check_seal.php. The manipulation of the argument ID leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

    Published: 31 Oct 2024
    5.3
    Medium

    CVE-2024-10616

    Last Modified: 4 Nov 2024

    A vulnerability classified as critical has been found in Tongda OA up to 11.9. This affects an unknown part of the file /pda/workflow/webSignSubmit.php. The manipulation of the argument saleId leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

    Published: 31 Oct 2024
    5.3
    Medium

    CVE-2024-10615

    Last Modified: 4 Nov 2024

    A vulnerability was found in Tongda OA 2017 up to 11.10. It has been rated as critical. Affected by this issue is some unknown functionality of the file /general/approve_center/query/list/input_form/delete_data_attach.php. The manipulation of the argument RUN_ID leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

    Published: 31 Oct 2024
    5.3
    Medium

    CVE-2024-10613

    Last Modified: 5 Nov 2024

    A vulnerability was found in ESAFENET CDG 5. It has been declared as critical. Affected by this vulnerability is the function delSystemEncryptPolicy of the file /com/esafenet/servlet/system/SystemEncryptPolicyService.java. The manipulation of the argument id leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 31 Oct 2024
    5.3
    Medium

    CVE-2024-10612

    Last Modified: 5 Nov 2024

    A vulnerability was found in ESAFENET CDG 5. It has been classified as critical. Affected is the function removeHookInvalidCourse of the file /com/esafenet/servlet/system/HookInvalidCourseService.java. The manipulation of the argument id leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 31 Oct 2024
    5.3
    Medium

    CVE-2024-10611

    Last Modified: 5 Nov 2024

    A vulnerability was found in ESAFENET CDG 5 and classified as critical. This issue affects the function delProtocol of the file /com/esafenet/servlet/system/PrintScreenListService.java. The manipulation of the argument id leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 31 Oct 2024
    5.3
    Medium

    CVE-2024-10610

    Last Modified: 5 Nov 2024

    A vulnerability has been found in ESAFENET CDG 5 and classified as critical. This vulnerability affects the function delProtocol of the file /com/esafenet/servlet/system/ProtocolService.java. The manipulation of the argument id leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 31 Oct 2024
    6.5
    Medium

    CVE-2024-6479

    Last Modified: 8 Apr 2026

    The SIP Reviews Shortcode for WooCommerce plugin for WordPress is vulnerable to SQL Injection via the 'no_of_reviews' attribute in the woocommerce_reviews shortcode in all versions up to, and including, 1.2.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

    Published: 31 Oct 2024
    6.4
    Medium

    CVE-2024-6480

    Last Modified: 8 Apr 2026

    The SIP Reviews Shortcode for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'no_of_reviews' attribute in the woocommerce_reviews shortcode in all versions up to, and including, 1.2.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 31 Oct 2024