CVE Feed

    Dashboard / CVE

    5.9
    Medium

    CVE-2024-43382

    Last Modified: 20 Aug 2025

    Snowflake JDBC driver versions >= 3.2.6 and <= 3.19.1 have an Incorrect Security Setting that can result in data being uploaded to an encrypted stage without the additional layer of protection provided by client side encryption.

    Published: 30 Oct 2024
    6.3
    Medium

    CVE-2024-46531

    Last Modified: 4 Apr 2025

    phpgurukul Vehicle Record Management System v1.0 was discovered to contain a SQL injection vulnerability via the searchinputdata parameter at /index.php.

    Published: 30 Oct 2024
    9.8
    Critical

    CVE-2024-48202

    Last Modified: 18 Apr 2025

    icecms <=3.4.7 has a File Upload vulnerability in FileUtils.java,uploadFile.

    Published: 30 Oct 2024
    5.5
    Medium

    CVE-2024-48241

    Last Modified: 13 Jun 2025

    An issue in radare2 v5.8.0 through v5.9.4 allows a local attacker to cause a denial of service via the __bf_div function.

    Published: 30 Oct 2024
    6.5
    Medium

    CVE-2024-48272

    Last Modified: 7 May 2025

    D-Link DSL6740C v6.TR069.20211230 was discovered to use an insecure default Wifi password, possibly allowing attackers to connect to the device via a bruteforce attack.

    Published: 30 Oct 2024
    6.1
    Medium

    CVE-2024-48346

    Last Modified: 15 Apr 2026

    xtreme1 <= v0.9.1 contains a Server-Side Request Forgery (SSRF) vulnerability in the /api/data/upload path. The vulnerability is triggered through the fileUrl parameter, which allows an attacker to make arbitrary requests to internal or external systems.

    Published: 30 Oct 2024
    5.4
    Medium

    CVE-2024-48569

    Last Modified: 15 Apr 2026

    Proactive Risk Manager version 9.1.1.0 is affected by multiple Cross-Site Scripting (XSS) vulnerabilities in the add/edit form fields, at the urls starting with the subpaths: /ar/config/configuation/ and /ar/config/risk-strategy-control/

    Published: 30 Oct 2024
    8.1
    High

    CVE-2024-48646

    Last Modified: 27 Jun 2025

    An Unrestricted File Upload vulnerability exists in Sage 1000 v7.0.0, which allows authorized users to upload files without proper validation. An attacker could exploit this vulnerability by uploading malicious files, such as HTML, scripts, or other executable content, that may be executed on the server, leading to further system compromise.

    Published: 30 Oct 2024
    6.1
    Medium

    CVE-2024-48648

    Last Modified: 27 Jun 2025

    A Reflected Cross-Site Scripting (XSS) vulnerability exists in the Sage 1000 v 7.0.0. This vulnerability allows attackers to inject malicious scripts into URLs, which are reflected back by the server in the response without proper sanitization or encoding.

    Published: 30 Oct 2024
    8.8
    High

    CVE-2024-48734

    Last Modified: 15 Apr 2026

    Unrestricted file upload in /SASStudio/SASStudio/sasexec/{sessionID}/{InternalPath} in SAS Studio 9.4 allows remote attacker to upload malicious files. NOTE: this is disputed by the vendor because file upload is allowed for authorized users.

    Published: 30 Oct 2024
    6.9
    Medium

    CVE-2024-10509

    Last Modified: 1 Nov 2024

    A vulnerability, which was classified as critical, has been found in Codezips Online Institute Management System 1.0. This issue affects some unknown processing of the file /login.php. The manipulation of the argument email leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

    Published: 29 Oct 2024
    6.9
    Medium

    CVE-2024-10507

    Last Modified: 5 Nov 2024

    A vulnerability classified as critical was found in Codezips Free Exam Hall Seating Management System 1.0. This vulnerability affects unknown code of the file /login.php. The manipulation of the argument email leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

    Published: 29 Oct 2024
    5.4
    Medium

    CVE-2024-50348

    Last Modified: 6 Nov 2024

    InstantCMS is a free and open source content management system. In photo upload function in the photo album page there is no input validation taking place. Due to this attackers are able to inject the XSS (Cross Site Scripting) payload and execute. This vulnerability is fixed in 2.16.3.

    Published: 29 Oct 2024
    7.8
    High

    CVE-2024-7992

    Last Modified: 26 Aug 2025

    A maliciously crafted DWG file, when parsed through Autodesk AutoCAD and certain AutoCAD-based products, can force a Stack-based Buffer Overflow. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.

    Published: 29 Oct 2024
    7.8
    High

    CVE-2024-7991

    Last Modified: 26 Aug 2025

    A maliciously crafted DWG file, when parsed through Autodesk AutoCAD and certain AutoCAD-based products, may force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process.

    Published: 29 Oct 2024
    7.8
    High

    CVE-2024-9997

    Last Modified: 26 Aug 2025

    A maliciously crafted DWG file when parsed in acdb25.dll through Autodesk AutoCAD can force a Memory Corruption vulnerability. A malicious actor can leverage this vulnerability to cause a crash, write sensitive data, or execute arbitrary code in the context of the current process.

    Published: 29 Oct 2024
    7.8
    High

    CVE-2024-9996

    Last Modified: 26 Aug 2025

    A maliciously crafted DWG file, when parsed in acdb25.dll through Autodesk AutoCAD, may force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process.

    Published: 29 Oct 2024
    7.8
    High

    CVE-2024-9489

    Last Modified: 26 Aug 2025

    A maliciously crafted DWG file when parsed in ACAD.exe through Autodesk AutoCAD can force a Memory Corruption vulnerability. A malicious actor can leverage this vulnerability to cause a crash, write sensitive data, or execute arbitrary code in the context of the current process.

    Published: 29 Oct 2024
    7.8
    High

    CVE-2024-8896

    Last Modified: 26 Aug 2025

    A maliciously crafted DXF file when parsed in acdb25.dll through Autodesk AutoCAD can force to access a variable prior to initialization. A malicious actor can leverage this vulnerability to cause a crash, write sensitive data, or execute arbitrary code in the context of the current process.

    Published: 29 Oct 2024
    7.8
    High

    CVE-2024-8592

    Last Modified: 26 Aug 2025

    A maliciously crafted CATPART file when parsed in AcTranslators.exe through Autodesk AutoCAD can force a Memory Corruption vulnerability. A malicious actor can leverage this vulnerability to cause a crash, write sensitive data, or execute arbitrary code in the context of the current process.

    Published: 29 Oct 2024
    5.3
    Medium

    CVE-2024-50421

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in WP Overnight WooCommerce PDF Invoices & Packing Slips woocommerce-pdf-invoices-packing-slips allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WooCommerce PDF Invoices & Packing Slips: from n/a through <= 3.8.6.

    Published: 29 Oct 2024
    5.3
    Medium

    CVE-2024-50422

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in Cloudways Breeze breeze allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Breeze: from n/a through <= 2.1.14.

    Published: 29 Oct 2024
    5.3
    Medium

    CVE-2024-10505

    Last Modified: 6 Nov 2024

    A vulnerability was found in wuzhicms 4.1.0. It has been classified as critical. Affected is the function add/edit of the file www/coreframe/app/content/admin/block.php. The manipulation leads to code injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. Initially two separate issues were created by the researcher for the different function calls. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 29 Oct 2024
    5.4
    Medium

    CVE-2024-50423

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in WPDeveloper Templately templately allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Templately: from n/a through <= 3.1.5.

    Published: 29 Oct 2024
    6.5
    Medium

    CVE-2024-50424

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in WPDeveloper Templately templately allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Templately: from n/a through <= 3.1.5.

    Published: 29 Oct 2024
    6.5
    Medium

    CVE-2024-50425

    Last Modified: 23 Apr 2026

    Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Roland Murg WP Booking System wp-booking-system.This issue affects WP Booking System: from n/a through <= 2.0.19.10.

    Published: 29 Oct 2024
    7.8
    High

    CVE-2024-9827

    Last Modified: 25 Apr 2025

    A maliciously crafted CATPART file when parsed in CC5Dll.dll through Autodesk AutoCAD can force an Out-of-Bounds Read vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.

    Published: 29 Oct 2024
    7.8
    High

    CVE-2024-9826

    Last Modified: 26 Aug 2025

    A maliciously crafted 3DM file when parsed in atf_api.dll through Autodesk AutoCAD can force a Use-After-Free vulnerability. A malicious actor can leverage this vulnerability to cause a crash, write sensitive data, or execute arbitrary code in the context of the current process.

    Published: 29 Oct 2024
    7.8
    High

    CVE-2024-8600

    Last Modified: 26 Aug 2025

    A maliciously crafted SLDPRT file when parsed in odxsw_dll.dll through Autodesk AutoCAD can force a Memory Corruption vulnerability. A malicious actor can leverage this vulnerability to cause a crash, write sensitive data, or execute arbitrary code in the context of the current process.

    Published: 29 Oct 2024
    7.8
    High

    CVE-2024-8599

    Last Modified: 26 Aug 2025

    A maliciously crafted STP file when parsed in ACTranslators.exe through Autodesk AutoCAD can force a Memory Corruption vulnerability. A malicious actor can leverage this vulnerability to cause a crash, write sensitive data, or execute arbitrary code in the context of the current process.

    Published: 29 Oct 2024
    7.8
    High

    CVE-2024-8598

    Last Modified: 26 Aug 2025

    A maliciously crafted STP file when parsed in ACTranslators.exe through Autodesk AutoCAD can force a Memory Corruption vulnerability. A malicious actor can leverage this vulnerability to cause a crash, write sensitive data, or execute arbitrary code in the context of the current process.

    Published: 29 Oct 2024
    7.8
    High

    CVE-2024-8597

    Last Modified: 26 Aug 2025

    A maliciously crafted STP file when parsed in ASMDATAX230A.dll through Autodesk AutoCAD can force a Memory Corruption vulnerability. A malicious actor can leverage this vulnerability to cause a crash, write sensitive data, or execute arbitrary code in the context of the current process.

    Published: 29 Oct 2024
    7.8
    High

    CVE-2024-8596

    Last Modified: 26 Aug 2025

    A maliciously crafted MODEL file, when parsed in libodxdll.dll through Autodesk AutoCAD, may force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process.

    Published: 29 Oct 2024
    4.3
    Medium

    CVE-2024-50428

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in mondula2016 Multi Step Form multi-step-form allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Multi Step Form: from n/a through <= 1.7.21.

    Published: 29 Oct 2024
    7.8
    High

    CVE-2024-8595

    Last Modified: 26 Aug 2025

    A maliciously crafted MODEL file when parsed in libodxdll.dll through Autodesk AutoCAD can force a Use-After-Free vulnerability. A malicious actor can leverage this vulnerability to cause a crash, write sensitive data, or execute arbitrary code in the context of the current process.

    Published: 29 Oct 2024
    7.8
    High

    CVE-2024-8594

    Last Modified: 26 Aug 2025

    A maliciously crafted MODEL file when parsed in libodxdll.dll through Autodesk AutoCAD can force a Heap-Based Overflow vulnerability. A malicious actor can leverage this vulnerability to cause a crash, write sensitive data, or execute arbitrary code in the context of the current process.

    Published: 29 Oct 2024
    7.8
    High

    CVE-2024-8593

    Last Modified: 26 Aug 2025

    A maliciously crafted CATPART file, when parsed in ASMKERN230A.dll through Autodesk AutoCAD, may force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process.

    Published: 29 Oct 2024
    7.8
    High

    CVE-2024-8591

    Last Modified: 26 Aug 2025

    A maliciously crafted 3DM file when parsed in AcTranslators.exe through Autodesk AutoCAD can force a Heap-Based Buffer Overflow vulnerability. A malicious actor can leverage this vulnerability to cause a crash, write sensitive data, or execute arbitrary code in the context of the current process.

    Published: 29 Oct 2024
    5.3
    Medium

    CVE-2024-50454

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in Benjamin Denis SEOPress wp-seopress allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects SEOPress: from n/a through <= 8.1.1.

    Published: 29 Oct 2024
    7.8
    High

    CVE-2024-8590

    Last Modified: 26 Aug 2025

    A maliciously crafted 3DM file when parsed in atf_api.dll through Autodesk AutoCAD can force a Use-After-Free vulnerability. A malicious actor can leverage this vulnerability to cause a crash, write sensitive data, or execute arbitrary code in the context of the current process.

    Published: 29 Oct 2024
    7.8
    High

    CVE-2024-8589

    Last Modified: 26 Aug 2025

    A maliciously crafted SLDPRT file when parsed in odxsw_dll.dll through Autodesk AutoCAD can force a Out-of-Bounds Read vulnerability. A malicious actor can leverage this vulnerability to cause a crash, write sensitive data, or execute arbitrary code in the context of the current process.

    Published: 29 Oct 2024
    7.8
    High

    CVE-2024-8588

    Last Modified: 26 Aug 2025

    A maliciously crafted SLDPRT file when parsed in odxsw_dll.dll through Autodesk AutoCAD can force a Out-of-Bounds Read vulnerability. A malicious actor can leverage this vulnerability to cause a crash, write sensitive data, or execute arbitrary code in the context of the current process.

    Published: 29 Oct 2024
    7.8
    High

    CVE-2024-8587

    Last Modified: 3 Sept 2025

    A maliciously crafted SLDPRT file when parsed in odxsw_dll.dll through Autodesk AutoCAD can force a Heap Based Buffer Overflow vulnerability. A malicious actor can leverage this vulnerability to cause a crash, write sensitive data, or execute arbitrary code in the context of the current process.

    Published: 29 Oct 2024
    4.3
    Medium

    CVE-2024-50455

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in Benjamin Denis SEOPress wp-seopress allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects SEOPress: from n/a through <= 8.1.1.

    Published: 29 Oct 2024
    5.4
    Medium

    CVE-2024-50456

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in Benjamin Denis SEOPress wp-seopress allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects SEOPress: from n/a through <= 8.1.1.

    Published: 29 Oct 2024
    5.3
    Medium

    CVE-2024-10503

    Last Modified: 7 Nov 2024

    A vulnerability was found in Klokan MapTiler tileserver-gl 2.3.1 and classified as problematic. This issue affects some unknown processing of the component URL Handler. The manipulation of the argument key leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 29 Oct 2024
    5.3
    Medium

    CVE-2024-10502

    Last Modified: 6 Nov 2024

    A vulnerability has been found in ESAFENET CDG 5 and classified as critical. This vulnerability affects the function getOneFileDirectory of the file /com/esafenet/servlet/fileManagement/FileDirectoryService.java. The manipulation of the argument directoryId leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 29 Oct 2024
    5.3
    Medium

    CVE-2024-10501

    Last Modified: 6 Nov 2024

    A vulnerability, which was classified as critical, was found in ESAFENET CDG 5. This affects the function findById of the file /com/esafenet/servlet/document/ExamCDGDocService.java. The manipulation of the argument id leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 29 Oct 2024
    5.3
    Medium

    CVE-2024-10500

    Last Modified: 5 Nov 2024

    A vulnerability, which was classified as critical, has been found in ESAFENET CDG 5. Affected by this issue is some unknown functionality of the file /com/esafenet/servlet/policy/HookWhiteListService.java. The manipulation of the argument policyId leads to sql injection. The attack may be launched remotely. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 29 Oct 2024
    8.8
    High

    CVE-2024-10488

    Last Modified: 2 Jan 2025

    Use after free in WebRTC in Google Chrome prior to 130.0.6723.92 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

    Published: 29 Oct 2024