CVE Feed

    Dashboard / CVE

    5.4
    Medium

    CVE-2024-50575

    Last Modified: 29 Oct 2024

    In JetBrains YouTrack before 2024.3.47707 reflected XSS was possible in Widget API

    Published: 28 Oct 2024
    5.3
    Medium

    CVE-2024-50574

    Last Modified: 29 Oct 2024

    In JetBrains YouTrack before 2024.3.47707 potential ReDoS exploit was possible via email header parsing in Helpdesk functionality

    Published: 28 Oct 2024
    4.3
    Medium

    CVE-2024-50573

    Last Modified: 29 Oct 2024

    In JetBrains Hub before 2024.3.47707 improper access control allowed users to generate permanent tokens for unauthorized services

    Published: 28 Oct 2024
    6.5
    Medium

    CVE-2024-50470

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themes4WP Themes4WP YouTube External Subtitles themes4wp-youtube-external-subtitles allows DOM-Based XSS.This issue affects Themes4WP YouTube External Subtitles: from n/a through <= 1.0.

    Published: 28 Oct 2024
    6.5
    Medium

    CVE-2024-50471

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in checklistcom Trip Plan tripplan allows DOM-Based XSS.This issue affects Trip Plan: from n/a through <= 1.0.10.

    Published: 28 Oct 2024
    6.5
    Medium

    CVE-2024-50472

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in martindrapeau Amilia Store amilia-store allows Stored XSS.This issue affects Amilia Store: from n/a through <= 2.9.8.

    Published: 28 Oct 2024
    6.5
    Medium

    CVE-2024-50501

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Climax Themes Kata Plus kata-plus allows DOM-Based XSS.This issue affects Kata Plus: from n/a through <= 1.4.7.

    Published: 28 Oct 2024
    6.5
    Medium

    CVE-2024-50502

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CozyThemes Cozy Blocks cozy-addons allows DOM-Based XSS.This issue affects Cozy Blocks: from n/a through <= 2.0.18.

    Published: 28 Oct 2024
    8.5
    High

    CVE-2024-50465

    Last Modified: 28 Apr 2026

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WP SEO – Calin Vingan Premium SEO Pack allows SQL Injection.This issue affects Premium SEO Pack: from n/a through 1.6.001.

    Published: 28 Oct 2024
    9.3
    Critical

    CVE-2024-50479

    Last Modified: 23 Apr 2026

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in chenyenming Woocommerce Quote Calculator woo-quote-calculator-order allows Blind SQL Injection.This issue affects Woocommerce Quote Calculator: from n/a through <= 1.1.

    Published: 28 Oct 2024
    9.3
    Critical

    CVE-2024-50491

    Last Modified: 23 Apr 2026

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in MicahBlu RSVP ME rsvp-me allows SQL Injection.This issue affects RSVP ME: from n/a through <= 1.9.9.

    Published: 28 Oct 2024
    8.1
    High

    CVE-2024-50497

    Last Modified: 23 Apr 2026

    Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in wdesco Advanced Online Ordering and Delivery Platform advanced-online-ordering-and-delivery-platform allows PHP Local File Inclusion.This issue affects Advanced Online Ordering and Delivery Platform: from n/a through <= 2.0.0.

    Published: 28 Oct 2024
    4.7
    Medium

    CVE-2024-50463

    Last Modified: 23 Apr 2026

    URL Redirection to Untrusted Site ('Open Redirect') vulnerability in sunshinephotocart Sunshine Photo Cart sunshine-photo-cart.This issue affects Sunshine Photo Cart: from n/a through <= 3.2.9.

    Published: 28 Oct 2024
    9.8
    Critical

    CVE-2024-50478

    Last Modified: 28 Apr 2026

    Authentication Bypass by Primary Weakness vulnerability in Swoop 1-Click Login: Passwordless Authentication allows Authentication Bypass.This issue affects 1-Click Login: Passwordless Authentication: 1.4.5.

    Published: 28 Oct 2024
    9.8
    Critical

    CVE-2024-50483

    Last Modified: 23 Apr 2026

    Authorization Bypass Through User-Controlled Key vulnerability in Tareq Hasan Meetup meetup allows Privilege Escalation.This issue affects Meetup: from n/a through <= 0.1.

    Published: 28 Oct 2024
    8.8
    High

    CVE-2024-50488

    Last Modified: 23 Apr 2026

    Authentication Bypass Using an Alternate Path or Channel vulnerability in yespbs Token Login token-login allows Authentication Bypass.This issue affects Token Login: from n/a through <= 1.0.3.

    Published: 28 Oct 2024
    6.5
    Medium

    CVE-2024-10469

    Last Modified: 25 Aug 2025

    VINCE versions before 3.0.9 is vulnerable to exposure of User information to authenticated users.

    Published: 28 Oct 2024
    8.8
    High

    CVE-2024-50408

    Last Modified: 23 Apr 2026

    Deserialization of Untrusted Data vulnerability in Bob Namaste! LMS namaste-lms allows Object Injection.This issue affects Namaste! LMS: from n/a through <= 2.6.3.

    Published: 28 Oct 2024
    8.8
    High

    CVE-2024-50416

    Last Modified: 23 Apr 2026

    Deserialization of Untrusted Data vulnerability in WPClever WPC Shop as a Customer for WooCommerce wpc-shop-as-customer allows Object Injection.This issue affects WPC Shop as a Customer for WooCommerce: from n/a through <= 1.2.6.

    Published: 28 Oct 2024
    7.3
    High

    CVE-2024-50450

    Last Modified: 23 Apr 2026

    Improper Control of Generation of Code ('Code Injection') vulnerability in RealMag777 MDTF wp-meta-data-filter-and-taxonomy-filter allows Code Injection.This issue affects MDTF: from n/a through <= 1.3.3.4.

    Published: 28 Oct 2024
    8.3
    High

    CVE-2024-50492

    Last Modified: 21 Sept 2026

    Improper Control of Generation of Code ('Code Injection') vulnerability in Scott Paterson ScottCart scottcart allows Code Injection.This issue affects ScottCart: from n/a through <= 1.1.

    Published: 28 Oct 2024
    10
    Critical

    CVE-2024-50498

    Last Modified: 23 Apr 2026

    Improper Control of Generation of Code ('Code Injection') vulnerability in Ajit Bohra WP Query Console wp-query-console allows Code Injection.This issue affects WP Query Console: from n/a through <= 1.0.

    Published: 28 Oct 2024
    9.8
    Critical

    CVE-2024-50477

    Last Modified: 23 Apr 2026

    Authentication Bypass Using an Alternate Path or Channel vulnerability in Stacks Stacks Mobile App Builder stacks-mobile-app-builder allows Authentication Bypass.This issue affects Stacks Mobile App Builder: from n/a through <= 5.2.3.

    Published: 28 Oct 2024
    9.8
    Critical

    CVE-2024-50486

    Last Modified: 23 Apr 2026

    Authentication Bypass Using an Alternate Path or Channel vulnerability in Acnoo Acnoo Flutter API acnoo-flutter-api allows Authentication Bypass.This issue affects Acnoo Flutter API: from n/a through <= 1.0.5.

    Published: 28 Oct 2024
    9.8
    Critical

    CVE-2024-50487

    Last Modified: 23 Apr 2026

    Authentication Bypass Using an Alternate Path or Channel vulnerability in Acnoo MaanStore API maanstore-api allows Authentication Bypass.This issue affects MaanStore API: from n/a through <= 1.0.1.

    Published: 28 Oct 2024
    9.8
    Critical

    CVE-2024-50489

    Last Modified: 23 Apr 2026

    Authentication Bypass Using an Alternate Path or Channel vulnerability in realtyworkstation Realty Workstation realty-workstation allows Authentication Bypass.This issue affects Realty Workstation: from n/a through <= 1.0.45.

    Published: 28 Oct 2024
    6.5
    Medium

    CVE-2024-50442

    Last Modified: 23 Apr 2026

    Improper Restriction of XML External Entity Reference vulnerability in WP Royal Royal Elementor Addons royal-elementor-addons allows XML Injection.This issue affects Royal Elementor Addons: from n/a through <= 1.3.980.

    Published: 28 Oct 2024
    5.3
    Medium

    CVE-2024-10450

    Last Modified: 22 Nov 2024

    A vulnerability has been found in SourceCodester Kortex Lite Advocate Office Management System 1.0 and classified as critical. This vulnerability affects unknown code of the file /kortex_lite/control/edit_profile.php of the component POST Parameter Handler. The manipulation of the argument id leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

    Published: 28 Oct 2024
    6.9
    Medium

    CVE-2024-10449

    Last Modified: 31 Oct 2024

    A vulnerability, which was classified as critical, was found in Codezips Hospital Appointment System 1.0. This affects an unknown part of the file /loginAction.php. The manipulation of the argument Username leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

    Published: 28 Oct 2024
    3.5
    Low

    CVE-2024-10214

    Last Modified: 5 Nov 2024

    Mattermost versions 9.11.X <= 9.11.1, 9.5.x <= 9.5.9 icorrectly issues two sessions when using desktop SSO - one in the browser and one in desktop with incorrect settings.

    Published: 28 Oct 2024
    7.5
    High

    CVE-2024-10455

    Last Modified: 7 Aug 2025

    Reachable Assertion in BPv7 parser in µD3TN v0.14.0 allows attacker to disrupt service via malformed Extension Block

    Published: 28 Oct 2024
    5.3
    Medium

    CVE-2024-10447

    Last Modified: 31 Oct 2024

    A vulnerability classified as critical was found in Project Worlds Online Time Table Generator 1.0. Affected by this vulnerability is an unknown functionality of the file /timetable/staff/staffdashboard.php?info=updateprofile. The manipulation of the argument n leads to sql injection. The attack can be launched remotely.

    Published: 28 Oct 2024
    5.3
    Medium

    CVE-2024-10446

    Last Modified: 1 Nov 2024

    A vulnerability classified as critical has been found in Project Worlds Online Time Table Generator 1.0. Affected is an unknown function of the file /timetable/admin/admindashboard.php?info=add_course. The manipulation of the argument c leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

    Published: 28 Oct 2024
    9.1
    Critical

    CVE-2024-38821

    Last Modified: 15 Apr 2026

    Spring WebFlux applications that have Spring Security authorization rules on static resources can be bypassed under certain circumstances. For this to impact an application, all of the following must be true: * It must be a WebFlux application * It must be using Spring's static resources support * It must have a non-permitAll authorization rule applied to the static resources support

    Published: 28 Oct 2024
    7.2
    High

    CVE-2024-9162

    Last Modified: 15 Apr 2026

    The All-in-One WP Migration and Backup plugin for WordPress is vulnerable to arbitrary PHP Code Injection due to missing file type validation during the export in all versions up to, and including, 7.86. This makes it possible for authenticated attackers, with Administrator-level access and above, to create an export file with the .php extension on the affected site's server, adding an arbitrary PHP code to it, which may make remote code execution possible.

    Published: 28 Oct 2024
    5.5
    Medium

    CVE-2024-50307

    Last Modified: 15 Apr 2026

    Use of potentially dangerous function issue exists in Chatwork Desktop Application (Windows) versions prior to 2.9.2. If a user clicks a specially crafted link in the application, an arbitrary file may be downloaded from an external website and executed. As a result, arbitrary code may be executed on the device that runs Chatwork Desktop Application (Windows).

    Published: 28 Oct 2024
    9.8
    Critical

    CVE-2024-10440

    Last Modified: 25 Sept 2025

    The eHDR CTMS from Sunnet has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary SQL command to read, modify, and delete database contents.

    Published: 28 Oct 2024
    5.3
    Medium

    CVE-2024-10439

    Last Modified: 25 Sept 2025

    The eHRD CTMS from Sunnet has an Insecure Direct Object Reference (IDOR) vulnerability, allowing unauthenticated remote attackers to modify a specific parameter to access arbitrary files uploaded by any user.

    Published: 28 Oct 2024
    7.5
    High

    CVE-2024-10438

    Last Modified: 25 Sept 2025

    The eHRD CTMS from Sunnet has an Authentication Bypass vulnerability, allowing unauthenticated remote attackers to bypass authentication by satisfying specific conditions in order to access certain functionalities.

    Published: 28 Oct 2024
    2.2
    Low

    CVE-2024-23843

    Last Modified: 15 Apr 2026

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Genians Genian NAC V5.0, Genians Genian NAC LTS V5.0.This issue affects Genian NAC V5.0: from V5.0.0 through V5.0.60; Genian NAC LTS V5.0: from 5.0.0 LTS through 5.0.55 LTS(Revision 125558), from 5.0.0 LTS through 5.0.56 LTS(Revision 125560).

    Published: 28 Oct 2024
    5.3
    Medium

    CVE-2024-10435

    Last Modified: 15 Apr 2026

    A vulnerability was found in didi Super-Jacoco 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /cov/triggerEnvCov. The manipulation of the argument uuid leads to command injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

    Published: 28 Oct 2024
    7.5
    High

    CVE-2024-42011

    Last Modified: 15 Apr 2026

    The Spotify app 8.9.58 for iOS has a buffer overflow in its use of strcat.

    Published: 28 Oct 2024
    9.8
    Critical

    CVE-2024-39205

    Last Modified: 15 Apr 2026

    An issue in pyload-ng v0.5.0b3.dev85 running under python3.11 or below allows attackers to execute arbitrary code via a crafted HTTP request.

    Published: 28 Oct 2024
    4.8
    Medium

    CVE-2024-51509

    Last Modified: 3 Jun 2025

    Tiki through 27.0 allows users who have certain permissions to insert a "Modules" (aka tiki-admin_modules.php) stored XSS payload in the Name.

    Published: 28 Oct 2024
    4.8
    Medium

    CVE-2024-51507

    Last Modified: 3 Jun 2025

    Tiki through 27.0 allows users who have certain permissions to insert a "Create/Edit External Wiki" stored XSS payload in the Name.

    Published: 28 Oct 2024
    9.8
    Critical

    CVE-2024-48465

    Last Modified: 15 Apr 2026

    The MRBS version 1.5.0 has an SQL injection vulnerability in the edit_entry_handler.php file, specifically in the rooms%5B%5D parameter

    Published: 28 Oct 2024
    4.9
    Medium

    CVE-2024-34537

    Last Modified: 3 Sept 2025

    TYPO3 before 13.3.1 allows denial of service (interface error) in the Bookmark Toolbar (ext:backend), exploitable by an administrator-level backend user account via manipulated data saved in the bookmark toolbar of the backend user interface. The fixed versions are 10.4.46 ELTS, 11.5.40 LTS, 12.4.21 LTS, and 13.3.1.

    Published: 28 Oct 2024
    6.1
    Medium

    CVE-2024-42930

    Last Modified: 17 Apr 2025

    PbootCMS 3.2.8 is vulnerable to URL Redirect.

    Published: 28 Oct 2024
    8.8
    High

    CVE-2024-48177

    Last Modified: 18 Apr 2025

    MRCMS 3.1.2 contains a SQL injection vulnerability via the RID parameter in /admin/article/delete.do.

    Published: 28 Oct 2024
    8.1
    High

    CVE-2024-48178

    Last Modified: 10 Jun 2025

    newbee-mall v1.0.0 is vulnerable to Server-Side Request Forgery (SSRF) via the goodsCoverImg parameter.

    Published: 28 Oct 2024