CVE Feed

    Dashboard / CVE

    10
    Critical

    CVE-2024-50510

    Last Modified: 23 Apr 2026

    Unrestricted Upload of File with Dangerous Type vulnerability in webandprint AR For Woocommerce ar-for-woocommerce allows Upload a Web Shell to a Web Server.This issue affects AR For Woocommerce: from n/a through <= 6.3.

    Published: 30 Oct 2024
    9.9
    Critical

    CVE-2024-50511

    Last Modified: 23 Apr 2026

    Unrestricted Upload of File with Dangerous Type vulnerability in donimedia WP donimedia carousel wp-donimedia-carousel allows Upload a Web Shell to a Web Server.This issue affects WP donimedia carousel: from n/a through <= 1.0.1.

    Published: 30 Oct 2024
    9.8
    Critical

    CVE-2024-50507

    Last Modified: 23 Apr 2026

    Deserialization of Untrusted Data vulnerability in Daschmi DS.DownloadList dsdownloadlist allows Object Injection.This issue affects DS.DownloadList: from n/a through <= 1.3.

    Published: 30 Oct 2024
    5.3
    Medium

    CVE-2024-50512

    Last Modified: 23 Apr 2026

    Generation of Error Message Containing Sensitive Information vulnerability in Posti Posti Shipping posti-shipping allows Retrieve Embedded Sensitive Data.This issue affects Posti Shipping: from n/a through <= 3.10.2.

    Published: 30 Oct 2024
    8.6
    High

    CVE-2024-50509

    Last Modified: 23 Apr 2026

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Chetan Khandla Woocommerce Product Design woo-product-design allows Path Traversal.This issue affects Woocommerce Product Design: from n/a through <= 1.0.0.

    Published: 30 Oct 2024
    9.8
    Critical

    CVE-2024-50503

    Last Modified: 23 Apr 2026

    Authentication Bypass Using an Alternate Path or Channel vulnerability in Deryck User Toolkit user-toolkit allows Authentication Bypass.This issue affects User Toolkit: from n/a through <= 1.2.3.

    Published: 30 Oct 2024
    7.2
    High

    CVE-2024-10108

    Last Modified: 15 Apr 2026

    The WPAdverts – Classifieds Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's adverts_add shortcode in all versions up to, and including, 2.1.6 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 30 Oct 2024
    6.4
    Medium

    CVE-2024-10223

    Last Modified: 15 Apr 2026

    The WP Team – WordPress Team Member Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's htteamember shortcode in all versions up to, and including, 1.1.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 30 Oct 2024
    5.4
    Medium

    CVE-2024-8444

    Last Modified: 10 Apr 2025

    The Download Manager WordPress plugin before 3.3.00 doesn't sanitize some of it's shortcode parameters, leading to cross site scripting.

    Published: 30 Oct 2024
    6.1
    Medium

    CVE-2024-8871

    Last Modified: 15 Apr 2026

    The Pricing Tables WordPress Plugin – Easy Pricing Tables plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 3.2.5. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

    Published: 30 Oct 2024
    4.3
    Medium

    CVE-2024-10399

    Last Modified: 15 Apr 2026

    The Download Monitor plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the ajax_search_users function in all versions up to, and including, 5.0.13. This makes it possible for authenticated attackers, with Subscriber-level access and above, to obtain usernames and emails of site users.

    Published: 30 Oct 2024
    6.1
    Medium

    CVE-2024-8792

    Last Modified: 8 Apr 2026

    The Subscribe to Comments plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 2.3. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

    Published: 30 Oct 2024
    6.4
    Medium

    CVE-2024-8627

    Last Modified: 8 Apr 2026

    The Ultimate TinyMCE plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'field' shortcode in all versions up to, and including, 5.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 30 Oct 2024
    6.4
    Medium

    CVE-2024-9885

    Last Modified: 15 Apr 2026

    The Widget or Sidebar Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'sidebar' shortcode in all versions up to, and including, 0.6.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 30 Oct 2024
    7.3
    High

    CVE-2024-9846

    Last Modified: 8 Apr 2026

    The The Enable Shortcodes inside Widgets,Comments and Experts plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 1.0.0. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes.

    Published: 30 Oct 2024
    6.4
    Medium

    CVE-2024-9886

    Last Modified: 15 Apr 2026

    The WP Baidu Map plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'baidu_map' shortcode in all versions up to, and including, 1.2.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 30 Oct 2024
    4.9
    Medium

    CVE-2023-5816

    Last Modified: 8 Apr 2026

    The Code Explorer plugin for WordPress is vulnerable to arbitrary external file reading in all versions up to, and including, 1.4.5. This is due to the fact that the plugin does not restrict accessing files to those outside of the WordPress instance, though the intention of the plugin is to only access WordPress related files. This makes it possible for authenticated attackers, with administrator-level access, to read files outside of the WordPress instance.

    Published: 30 Oct 2024
    6.4
    Medium

    CVE-2024-9884

    Last Modified: 15 Apr 2026

    The T(-) Countdown plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'tminus' shortcode in all versions up to, and including, 2.4.8 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 30 Oct 2024
    5.3
    Medium

    CVE-2024-10506

    Last Modified: 23 Oct 2025

    A vulnerability classified as critical has been found in code-projects Blood Bank System 1.0. This affects an unknown part of the file /admin/blood/update/B-.php. The manipulation of the argument Bloodname leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

    Published: 30 Oct 2024
    8.8
    High

    CVE-2024-48733

    Last Modified: 5 Jul 2026

    SQL injection vulnerability in /SASStudio/sasexec/sessions/{sessionID}/sql in SAS Studio 9.4 allows remote attacker to execute arbitrary SQL commands via the POST body request. NOTE: this is disputed by the vendor because SQL statement execution is allowed for authorized users.

    Published: 30 Oct 2024
    9.8
    Critical

    CVE-2024-51427

    Last Modified: 15 Apr 2026

    An issue in the PepeGxng smart contract (which can be run on the Ethereum blockchain) allows remote attackers to have an unspecified impact via the mint function. NOTE: this is disputed by third parties because the impact is limited to function calls.

    Published: 30 Oct 2024
    6.1
    Medium

    CVE-2024-51419

    Last Modified: 15 Apr 2026

    Cross Site Scripting vulnerability in Shenzhen Interconnection Harbor Network Technology Co., Ltd Ofweek Online Exhibition v.1.0.0 allows a remote attacker to execute arbitrary code.

    Published: 30 Oct 2024
    8.4
    High

    CVE-2024-37573

    Last Modified: 15 Apr 2026

    The Talkatone com.talkatone.android application 8.4.6 for Android enables any installed application (with no permissions) to place phone calls without user interaction by sending a crafted intent via the com.talkatone.vedroid.ui.launcher.OutgoingCallInterceptor component.

    Published: 30 Oct 2024
    5.2
    Medium

    CVE-2024-31973

    Last Modified: 15 Apr 2026

    Hitron CODA-4582 2AHKM-CODA4589 7.2.4.5.1b8 devices allow a remote attacker within Wi-Fi proximity to conduct stored XSS attacks via the 'Network Name (SSID)' input fields to the /index.html#wireless_basic page.

    Published: 30 Oct 2024
    6.7
    Medium

    CVE-2024-10573

    Last Modified: 15 Apr 2026

    An out-of-bounds write flaw was found in mpg123 when handling crafted streams. When decoding PCM, the libmpg123 may write past the end of a heap-located buffer. Consequently, heap corruption may happen, and arbitrary code execution is not discarded. The complexity required to exploit this flaw is considered high as the payload must be validated by the MPEG decoder and the PCM synth before execution. Additionally, to successfully execute the attack, the user must scan through the stream, making web live stream content (such as web radios) a very unlikely attack vector.

    Published: 30 Oct 2024
    8.8
    High

    CVE-2024-51426

    Last Modified: 15 Apr 2026

    An issue in the PepeGxng smart contract (which can be run on the Ethereum blockchain) allows remote attackers to have an unspecified impact via the _transfer function. NOTE: this is disputed by third parties because the impact is limited to function calls.

    Published: 30 Oct 2024
    8.8
    High

    CVE-2024-51425

    Last Modified: 15 Apr 2026

    An issue in the WaterToken smart contract (which can be run on the Ethereum blockchain) allows remote attackers to have an unspecified impact. NOTE: this is disputed by third parties because the impact is limited to function calls.

    Published: 30 Oct 2024
    8.8
    High

    CVE-2024-51304

    Last Modified: 10 Apr 2025

    In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the ldap_search_dn function.

    Published: 30 Oct 2024
    8.8
    High

    CVE-2024-51301

    Last Modified: 10 Apr 2025

    In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the packet_monitor function.

    Published: 30 Oct 2024
    8.8
    High

    CVE-2024-51300

    Last Modified: 10 Apr 2025

    In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the get_rrd function.

    Published: 30 Oct 2024
    8.8
    High

    CVE-2024-51299

    Last Modified: 10 Apr 2025

    In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the dumpSyslog function.

    Published: 30 Oct 2024
    9.8
    Critical

    CVE-2024-51298

    Last Modified: 10 Apr 2025

    In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the doGRETunnel function.

    Published: 30 Oct 2024
    8.8
    High

    CVE-2024-51257

    Last Modified: 10 Apr 2025

    DrayTek Vigor3900 1.5.1.3 allows attackers to inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the doCertificate function.

    Published: 30 Oct 2024
    8.8
    High

    CVE-2024-51258

    Last Modified: 10 Apr 2025

    DrayTek Vigor3900 1.5.1.3 allows attackers to inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the doSSLTunnel function.

    Published: 30 Oct 2024
    5.4
    Medium

    CVE-2024-48807

    Last Modified: 31 Mar 2025

    Cross Site Scripting vulnerability in PHPGurukul Doctor Appointment Management System v.1.0 allows a local attacker to execute arbitrary code via the search parameter.

    Published: 30 Oct 2024
    9.8
    Critical

    CVE-2024-48112

    Last Modified: 17 Jun 2025

    A deserialization vulnerability in the component \controller\Index.php of Thinkphp v6.1.3 to v8.0.4 allows attackers to execute arbitrary code.

    Published: 30 Oct 2024
    8.8
    High

    CVE-2024-48271

    Last Modified: 7 May 2025

    D-Link DSL6740C v6.TR069.20211230 was discovered to use insecure default credentials for Administrator access, possibly allowing attackers to bypass authentication and escalate privileges on the device via a bruteforce attack.

    Published: 30 Oct 2024
    7.2
    High

    CVE-2024-48647

    Last Modified: 27 Jun 2025

    A file disclosure vulnerability exists in Sage 1000 v7.0.0. This vulnerability allows remote attackers to retrieve arbitrary files from the server's file system by manipulating the URL parameter in HTTP requests. The attacker can exploit this flaw to access sensitive information, including configuration files that may contain credentials and system settings, which could lead to further compromise of the server.

    Published: 30 Oct 2024
    6.5
    Medium

    CVE-2024-51242

    Last Modified: 17 May 2025

    A Server-Side Request Forgery (SSRF) vulnerability has been identified in eladmin 2.7 and earlier in ServerDeployController.java. The manipulation of the HTTP Body ip parameter leads to SSRF.

    Published: 30 Oct 2024
    7.2
    High

    CVE-2024-51243

    Last Modified: 6 May 2025

    The eladmin v2.7 and before contains a remote code execution (RCE) vulnerability that can control all application deployment servers of this management system via DeployController.java.

    Published: 30 Oct 2024
    8.8
    High

    CVE-2024-51296

    Last Modified: 10 Apr 2025

    In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the pingtrace function.

    Published: 30 Oct 2024
    9.8
    Critical

    CVE-2024-51424

    Last Modified: 15 Apr 2026

    An issue in the PepeGxng smart contract (which can be run on the Ethereum blockchain) allows remote attackers to have an unspecified impact via the Owned.setOwner function. NOTE: this is disputed by third parties because the impact is limited to function calls.

    Published: 30 Oct 2024
    7.2
    High

    CVE-2023-52066

    Last Modified: 15 Apr 2026

    http.zig commit 76cf5 was discovered to contain a CRLF injection vulnerability via the url parameter.

    Published: 30 Oct 2024
    8
    High

    CVE-2024-48093

    Last Modified: 15 Apr 2026

    Unrestricted File Upload in the Discussions tab in Operately v.0.1.0 allows a privileged user to achieve Remote Code Execution via uploading and executing malicious files without validating file extensions or content types.

    Published: 30 Oct 2024
    8.4
    High

    CVE-2024-48214

    Last Modified: 15 Apr 2026

    KERUI HD 3MP 1080P Tuya Camera 1.0.4 has a command injection vulnerability in the module that connects to the local network via a QR code. This vulnerability allows an attacker to create a custom, unauthenticated QR code and abuse one of the parameters, either SSID or PASSWORD, in the JSON data contained within the QR code. By that, the attacker can execute arbitrary code on the camera.

    Published: 30 Oct 2024
    7.7
    High

    CVE-2024-48735

    Last Modified: 15 Apr 2026

    Directory Traversal in /SASStudio/sasexec/sessions/{sessionID}/workspace/{InternalPath} in SAS Studio 9.4 allows remote attacker to access internal files by manipulating default path during file download. NOTE: this is disputed by the vendor because these filesystem paths are allowed for authorized users.

    Published: 30 Oct 2024
    4.8
    Medium

    CVE-2024-31975

    Last Modified: 26 Jan 2026

    EnGenius EWS356-Fit devices through 1.1.30 allow a remote attacker to conduct stored XSS attacks via the Wi-Fi SSID parameters. JavaScript embedded into a vulnerable field is executed when the user clicks the SSID field's corresponding EDIT button.

    Published: 30 Oct 2024
    4.3
    Medium

    CVE-2024-31972

    Last Modified: 15 Apr 2026

    EnGenius ESR580 A8J-EMR5000 devices allow a remote attacker to conduct stored XSS attacks that could lead to arbitrary JavaScript code execution (under the context of the user's session) via the Wi-Fi SSID input fields. Web scripts embedded into the vulnerable fields this way are executed immediately when a user logs into the admin page. This affects /admin/wifi/wlan1 and /admin/wifi/wlan_guest.

    Published: 30 Oct 2024
    8.8
    High

    CVE-2024-36060

    Last Modified: 15 Apr 2026

    EnGenius EnStation5-AC A8J-ENS500AC 1.0.0 devices allow blind OS command injection via shell metacharacters in the Ping and Speed Test parameters.

    Published: 30 Oct 2024
    8.1
    High

    CVE-2024-42041

    Last Modified: 15 Apr 2026

    The com.videodownload.browser.videodownloader (aka AppTool-Browser-Video All Video Downloader) application 20-30.05.24 for Android allows an attacker to execute arbitrary JavaScript code via the acr.browser.lightning.DefaultBrowserActivity component.

    Published: 30 Oct 2024