CVE Feed

    Dashboard / CVE

    5.4
    Medium

    CVE-2024-9584

    Last Modified: 8 Apr 2026

    The Image Map Pro plugin for WordPress is vulnerable to unauthorized modification of data and loss of data due to a missing capability check on the AJAX functions in versions up to, and including, 6.0.20. This makes it possible for authenticated attackers with contributor-level privileges or above, to add, update or delete map projects.

    Published: 25 Oct 2024
    6.4
    Medium

    CVE-2024-9585

    Last Modified: 8 Apr 2026

    The Image Map Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'save_project' function with an arbitrary shortcode in versions up to, and including, 6.0.20 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 25 Oct 2024
    —
    Unknown

    CVE-2024-10401

    Last Modified: 16 Jan 2025

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

    Published: 25 Oct 2024
    4.6
    Medium

    CVE-2024-8036

    Last Modified: 15 Apr 2026

    ABB is aware of privately reported vulnerabilities in the product versions referenced in this CVE. An attacker could exploit these vulnerabilities by sending a specially crafted firmware or configuration to the system node, causing the node to stop, become inaccessible, or allowing the attacker to take control of the node.

    Published: 25 Oct 2024
    7.5
    High

    CVE-2024-49757

    Last Modified: 26 Aug 2025

    The open-source identity infrastructure software Zitadel allows administrators to disable the user self-registration. Due to a missing security check in versions prior to 2.64.0, 2.63.5, 2.62.7, 2.61.4, 2.60.4, 2.59.5, and 2.58.7, disabling the "User Registration allowed" option only hid the registration button on the login page. Users could bypass this restriction by directly accessing the registration URL (/ui/login/loginname) and register a user that way. Versions 2.64.0, 2.63.5, 2.62.7, 2.61.4, 2.60.4, 2.59.5, and 2.58.7 contain a patch. No known workarounds are available.

    Published: 25 Oct 2024
    5.9
    Medium

    CVE-2024-49753

    Last Modified: 26 Aug 2025

    Zitadel is open-source identity infrastructure software. Versions prior to 2.64.1, 2.63.6, 2.62.8, 2.61.4, 2.60.4, 2.59.5, and 2.58.7 have a flaw in the URL validation mechanism of Zitadel actions allows bypassing restrictions intended to block requests to localhost (127.0.0.1). The isHostBlocked check, designed to prevent such requests, can be circumvented by creating a DNS record that resolves to 127.0.0.1. This enables actions to send requests to localhost despite the intended security measures. This vulnerability potentially allows unauthorized access to unsecured internal endpoints, which may contain sensitive information or functionalities. Versions 2.64.1, 2.63.6, 2.62.8, 2.61.4, 2.60.4, 2.59.5, and 2.58.7 contain a patch. No known workarounds are available.

    Published: 25 Oct 2024
    7.7
    High

    CVE-2024-49381

    Last Modified: 14 Nov 2024

    Plenti, a static site generator, has an arbitrary file deletion vulnerability in versions prior to 0.7.2. The `/postLocal` endpoint is vulnerable to an arbitrary file write deletion when a plenti user serves their website. This issue may lead to information loss. Version 0.7.2 fixes the vulnerability.

    Published: 25 Oct 2024
    8.7
    High

    CVE-2024-10387

    Last Modified: 5 Nov 2024

    CVE-2024-10387 IMPACT A Denial-of-Service vulnerability exists in the affected product. The vulnerability could allow a threat actor with network access to send crafted messages to the device, potentially resulting in Denial-of-Service.

    Published: 25 Oct 2024
    9.3
    Critical

    CVE-2024-10386

    Last Modified: 5 Nov 2024

    CVE-2024-10386 IMPACT An authentication vulnerability exists in the affected product. The vulnerability could allow a threat actor with network access to send crafted messages to the device, potentially resulting in database manipulation.

    Published: 25 Oct 2024
    8.9
    High

    CVE-2024-49380

    Last Modified: 6 May 2025

    Plenti, a static site generator, has an arbitrary file write vulnerability in versions prior to 0.7.2. The `/postLocal` endpoint is vulnerable to an arbitrary file write vulnerability when a plenti user serves their website. This issue may lead to Remote Code Execution. Version 0.7.2 fixes the vulnerability.

    Published: 25 Oct 2024
    5.8
    Medium

    CVE-2024-49378

    Last Modified: 15 Apr 2026

    smartUp, a web browser mouse gestures extension, has a universal cross-site scripting issue in the Edge and Firefox versions of smartUp 7.2.622.1170. The vulnerability allows another extension to execute arbitrary code in the context of the user’s tab. As of time of publication, no known patches exist.

    Published: 25 Oct 2024
    7.1
    High

    CVE-2024-49376

    Last Modified: 14 Nov 2024

    Autolab, a course management service that enables auto-graded programming assignments, has misconfigured reset password permissions in version 3.0.0. For email-based accounts, users with insufficient privileges could reset and theoretically access privileged users' accounts by resetting their passwords. This issue is fixed in version 3.0.1. No known workarounds exist.

    Published: 25 Oct 2024
    7
    High

    CVE-2024-9991

    Last Modified: 15 Apr 2026

    This vulnerability exists in Philips lighting devices due to storage of Wi-Fi credentials in plain text within the device firmware. An attacker with physical access could exploit this by extracting the firmware and analyzing the binary data to obtain the plaintext Wi-Fi credentials stored on the vulnerable device. Successful exploitation of this vulnerability could allow an attacker to gain unauthorized access to the Wi-Fi network to which vulnerable device is connected.

    Published: 25 Oct 2024
    6.4
    Medium

    CVE-2024-10374

    Last Modified: 8 Apr 2026

    The WP-Members Membership Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wpmem_loginout shortcode in all versions up to, and including, 3.4.9.5 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 25 Oct 2024
    —
    Unknown

    CVE-2024-10391

    Last Modified: 9 Jul 2025

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

    Published: 25 Oct 2024
    2.9
    Low

    CVE-2024-47483

    Last Modified: 31 Oct 2024

    Dell Data Lakehouse, version(s) 1.0.0.0 and 1.1.0.0, contain(s) an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability. An unauthenticated attacker with local access could potentially exploit this vulnerability, leading to Information disclosure.

    Published: 25 Oct 2024
    6.5
    Medium

    CVE-2024-47481

    Last Modified: 31 Oct 2024

    Dell Data Lakehouse, version(s) 1.0.0.0, 1.1.0., contain(s) an Improper Access Control vulnerability. An unauthenticated attacker with adjacent network access could potentially exploit this vulnerability, leading to Denial of service.

    Published: 25 Oct 2024
    7.8
    High

    CVE-2024-47041

    Last Modified: 4 Nov 2024

    In valid_address of syscall.c, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 25 Oct 2024
    7.8
    High

    CVE-2024-47035

    Last Modified: 31 Oct 2024

    In vring_init of external/headers/include/virtio/virtio_ring.h, there is a possible out of bounds write due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 25 Oct 2024
    5.5
    Medium

    CVE-2024-47034

    Last Modified: 28 Oct 2024

    there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 25 Oct 2024
    7.8
    High

    CVE-2024-47033

    Last Modified: 28 Oct 2024

    In lwis_allocator_free of lwis_allocator.c, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 25 Oct 2024
    7.4
    High

    CVE-2024-47031

    Last Modified: 24 Jul 2025

    Android before 2024-10-05 on Google Pixel devices allows privilege escalation in the ABL component, A-329163861.

    Published: 25 Oct 2024
    5.1
    Medium

    CVE-2024-47030

    Last Modified: 24 Jul 2025

    Android before 2024-10-05 on Google Pixel devices allows information disclosure in the ACPM component, A-315191818.

    Published: 25 Oct 2024
    5.5
    Medium

    CVE-2024-47029

    Last Modified: 28 Oct 2024

    In TrustySharedMemoryManager::GetSharedMemory of ondevice/trusty/trusty_shared_memory_manager.cc, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 25 Oct 2024
    4.4
    Medium

    CVE-2024-47028

    Last Modified: 28 Oct 2024

    In ffu_flash_pack of ffu.c, there is a possible out of bounds read due to an integer overflow. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.

    Published: 25 Oct 2024
    7.8
    High

    CVE-2024-47027

    Last Modified: 28 Oct 2024

    In sm_mem_compat_get_vmm_obj of lib/sm/shared_mem.c, there is a possible arbitrary physical memory access due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 25 Oct 2024
    5.5
    Medium

    CVE-2024-47026

    Last Modified: 28 Oct 2024

    In gsc_gsa_rescue of gsc_gsa.c, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 25 Oct 2024
    5.5
    Medium

    CVE-2024-47025

    Last Modified: 28 Oct 2024

    In ppmp_protect_buf of drm_fw.c, there is a possible information disclosure due to a logic error in the code. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 25 Oct 2024
    7.8
    High

    CVE-2024-47024

    Last Modified: 28 Oct 2024

    In vring_size of external/headers/include/virtio/virtio_ring.h, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 25 Oct 2024
    8.1
    High

    CVE-2024-47023

    Last Modified: 28 Oct 2024

    there is a possible man-in-the-middle attack due to a logic error in the code. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 25 Oct 2024
    7.5
    High

    CVE-2024-47022

    Last Modified: 28 Oct 2024

    Android before 2024-10-05 on Google Pixel devices allows information disclosure in the ACPM component, A-331255656.

    Published: 25 Oct 2024
    7.5
    High

    CVE-2024-47021

    Last Modified: 28 Oct 2024

    In sms_ExtractCbLanguage of sms_CellBroadcast.c, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 25 Oct 2024
    7.5
    High

    CVE-2024-47020

    Last Modified: 28 Oct 2024

    Android before 2024-10-05 on Google Pixel devices allows information disclosure in the ABL component, A-331966488.

    Published: 25 Oct 2024
    5.5
    Medium

    CVE-2024-47019

    Last Modified: 28 Oct 2024

    In ProtocolEmbmsSaiListAdapter::Init() of protocolembmsadapter.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with baseband firmware compromise required. User Interaction is not needed for exploitation.

    Published: 25 Oct 2024
    5.5
    Medium

    CVE-2024-47018

    Last Modified: 28 Oct 2024

    In pmucal_rae_handle_seq_int of flexpmu_cal_rae.c, there is a possible out of bounds read due to a buffer overflow. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 25 Oct 2024
    7.8
    High

    CVE-2024-47017

    Last Modified: 28 Oct 2024

    In ufshc_scsi_cmd of ufs.c, there is a possible stack variable use after free due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 25 Oct 2024
    7.8
    High

    CVE-2024-47016

    Last Modified: 24 Jul 2025

    there is a possible privilege escalation due to an insecure default value. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 25 Oct 2024
    5.5
    Medium

    CVE-2024-47015

    Last Modified: 24 Jul 2025

    In ProtocolMiscHwConfigChangeAdapter::GetData() of protocolmiscadapter.cpp, there is a possible out-of-bounds read due to a missing bounds check. This could lead to local information disclosure with baseband firmware compromise required. User Interaction is not needed for exploitation.

    Published: 25 Oct 2024
    8.8
    High

    CVE-2024-47014

    Last Modified: 24 Jul 2025

    Android before 2024-10-05 on Google Pixel devices allows privilege escalation in the ABL component, A-330537292.

    Published: 25 Oct 2024
    7.8
    High

    CVE-2024-47013

    Last Modified: 24 Jul 2025

    In pmucal_rae_handle_seq_int of flexpmu_cal_rae.c, there is a possible arbitrary write due to uninitialized data. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 25 Oct 2024
    7.8
    High

    CVE-2024-47012

    Last Modified: 28 Oct 2024

    In mm_GetMobileIdIndexForNsUpdate of mm_GmmPduCodec.c, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 25 Oct 2024
    7.5
    High

    CVE-2024-44101

    Last Modified: 28 Oct 2024

    there is a possible Null Pointer Dereference (modem crash) due to improper input validation. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 25 Oct 2024
    7.5
    High

    CVE-2024-44100

    Last Modified: 28 Oct 2024

    Android before 2024-10-05 on Google Pixel devices allows information disclosure in the modem component, A-299774545.

    Published: 25 Oct 2024
    5.5
    Medium

    CVE-2024-44099

    Last Modified: 28 Oct 2024

    There is a possible Local bypass of user interaction due to an insecure default value. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 25 Oct 2024
    7.4
    High

    CVE-2024-44098

    Last Modified: 24 Jul 2025

    In lwis_device_event_states_clear_locked of lwis_event.c, there is a possible privilege escalation due to a double free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 25 Oct 2024
    5.3
    Medium

    CVE-2024-10380

    Last Modified: 1 Nov 2024

    A vulnerability, which was classified as critical, has been found in SourceCodester Petrol Pump Management Software 1.0. Affected by this issue is some unknown functionality of the file /admin/ajax_product.php. The manipulation of the argument drop_services leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

    Published: 25 Oct 2024
    9.3
    Critical

    CVE-2024-10381

    Last Modified: 14 Nov 2024

    This vulnerability exists in Matrix Door Controller Cosec Vega FAXQ due to improper implementation of session management at the web-based management interface. A remote attacker could exploit this vulnerability by sending a specially crafted http request on the vulnerable device. Successful exploitation of this vulnerability could allow remote attacker to gain unauthorized access and take complete control of the targeted device.

    Published: 25 Oct 2024
    6.4
    Medium

    CVE-2024-8666

    Last Modified: 15 Apr 2026

    The Shoutcast Icecast HTML5 Radio Player plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'html5radio' shortcode in all versions up to, and including, 2.1.7 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 25 Oct 2024
    6.4
    Medium

    CVE-2024-10112

    Last Modified: 15 Apr 2026

    The Simple News plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'news' shortcode in all versions up to, and including, 2.8 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 25 Oct 2024
    6.4
    Medium

    CVE-2024-10343

    Last Modified: 15 Apr 2026

    The Beek Widget Extention plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcodes in versions up to, and including, 0.9.5 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 25 Oct 2024