CVE Feed

    Dashboard / CVE

    7.1
    High

    CVE-2024-7755

    Last Modified: 15 Apr 2026

    The EWON FLEXY 202 transmits credentials using a weak encoding method base64. An attacker who is present in the network can sniff the traffic and decode the credentials.

    Published: 17 Oct 2024
    7.1
    High

    CVE-2024-43997

    Last Modified: 15 Apr 2026

    Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in easy.Jobs EasyJobs allows Reflected XSS.This issue affects EasyJobs: from n/a through 2.4.14.

    Published: 17 Oct 2024
    7.1
    High

    CVE-2024-49220

    Last Modified: 29 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Nikel Cookie Scanner cookie-scanner allows Cross Site Request Forgery.This issue affects Cookie Scanner: from n/a through <= 1.1.

    Published: 17 Oct 2024
    7.1
    High

    CVE-2024-49221

    Last Modified: 29 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in julian.weinert cSlider cslider allows Cross Site Request Forgery.This issue affects cSlider: from n/a through <= 2.4.2.

    Published: 17 Oct 2024
    7.1
    High

    CVE-2024-49223

    Last Modified: 29 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in shibulijack CJ Change Howdy cj-change-howdy allows Cross Site Request Forgery.This issue affects CJ Change Howdy: from n/a through <= 3.3.1.

    Published: 17 Oct 2024
    7.1
    High

    CVE-2024-49229

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in arifnezami Better Author Bio better-author-bio allows Reflected XSS.This issue affects Better Author Bio: from n/a through <= 2.7.10.11.

    Published: 17 Oct 2024
    7.1
    High

    CVE-2024-49237

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in ahmeti Ahmeti Wp Timeline ahmeti-wp-timeline allows Stored XSS.This issue affects Ahmeti Wp Timeline: from n/a through <= 5.1.

    Published: 17 Oct 2024
    5.4
    Medium

    CVE-2024-49304

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in DOTonPAPER Pinpoint Booking System booking-system allows Stored XSS.This issue affects Pinpoint Booking System: from n/a through <= 2.9.9.5.7.

    Published: 17 Oct 2024
    7.1
    High

    CVE-2024-49313

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in rudestan VKontakte Wall Post vkontakte-wall-post allows Stored XSS.This issue affects VKontakte Wall Post: from n/a through <= 2.0.

    Published: 17 Oct 2024
    9.8
    Critical

    CVE-2024-49217

    Last Modified: 1 Apr 2026

    Incorrect Privilege Assignment vulnerability in madiriaashish Adding drop down roles in registration user-drop-down-roles-in-registration allows Privilege Escalation.This issue affects Adding drop down roles in registration: from n/a through <= 1.1.

    Published: 17 Oct 2024
    8.8
    High

    CVE-2024-49219

    Last Modified: 11 May 2026

    Incorrect Privilege Assignment vulnerability in themexpo RS-Members rs-members allows Privilege Escalation.This issue affects RS-Members: from n/a through <= 1.0.3.

    Published: 17 Oct 2024
    9.8
    Critical

    CVE-2024-49322

    Last Modified: 29 Apr 2026

    Incorrect Privilege Assignment vulnerability in CodePassenger Job Board Manager for WordPress jemployee allows Privilege Escalation.This issue affects Job Board Manager for WordPress: from n/a through <= 1.0.

    Published: 17 Oct 2024
    8.5
    High

    CVE-2024-47304

    Last Modified: 23 Apr 2026

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Shahjahan Jewel Fluent Support fluent-support allows SQL Injection.This issue affects Fluent Support: from n/a through <= 1.8.0.

    Published: 17 Oct 2024
    8.5
    High

    CVE-2024-47312

    Last Modified: 23 Apr 2026

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WP Grim Classic Editor and Classic Widgets classic-editor-and-classic-widgets allows SQL Injection.This issue affects Classic Editor and Classic Widgets: from n/a through <= 1.4.1.

    Published: 17 Oct 2024
    8.5
    High

    CVE-2024-49244

    Last Modified: 29 Apr 2026

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in vrinsoft CSV Product Import Export for WooCommerce csv-wc-product-import-export.This issue affects CSV Product Import Export for WooCommerce: from n/a through <= 1.0.0.

    Published: 17 Oct 2024
    9.3
    Critical

    CVE-2024-49246

    Last Modified: 29 Apr 2026

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in anand23 Ajax Rating with Custom Login ajax-rating-with-custom-login allows SQL Injection.This issue affects Ajax Rating with Custom Login: from n/a through <= 1.1.

    Published: 17 Oct 2024
    8.5
    High

    CVE-2024-49297

    Last Modified: 23 Apr 2026

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in zohocrm Zoho CRM Lead Magnet zoho-crm-forms allows SQL Injection.This issue affects Zoho CRM Lead Magnet: from n/a through <= 1.7.9.7.

    Published: 17 Oct 2024
    7.6
    High

    CVE-2024-49299

    Last Modified: 23 Apr 2026

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Surfer Surfer surferseo allows SQL Injection.This issue affects Surfer: from n/a through <= 1.5.0.502.

    Published: 17 Oct 2024
    9.3
    Critical

    CVE-2024-49305

    Last Modified: 23 Apr 2026

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WPFactory Email Verification for WooCommerce emails-verification-for-woocommerce allows SQL Injection.This issue affects Email Verification for WooCommerce: from n/a through <= 2.8.10.

    Published: 17 Oct 2024
    7.5
    High

    CVE-2024-49235

    Last Modified: 29 Apr 2026

    Insertion of Sensitive Information Into Sent Data vulnerability in videowhisper Contact Forms, Live Support, CRM, Video Messages live-support-tickets allows Retrieve Embedded Sensitive Data.This issue affects Contact Forms, Live Support, CRM, Video Messages: from n/a through <= 1.10.2.

    Published: 17 Oct 2024
    5.3
    Medium

    CVE-2024-49284

    Last Modified: 23 Apr 2026

    Exposure of Sensitive Information to an Unauthorized Actor vulnerability in BogdanFix WP SendFox wp-sendfox allows Retrieve Embedded Sensitive Data.This issue affects WP SendFox: from n/a through <= 1.3.1.

    Published: 17 Oct 2024
    10
    Critical

    CVE-2024-49291

    Last Modified: 28 Apr 2026

    Unrestricted Upload of File with Dangerous Type vulnerability in Gora Tech LLC Cooked Pro.This issue affects Cooked Pro: from n/a before 1.8.0.

    Published: 17 Oct 2024
    10
    Critical

    CVE-2024-49314

    Last Modified: 29 Apr 2026

    Unrestricted Upload of File with Dangerous Type vulnerability in jiangqie JiangQie Free Mini Program jiangqie-free-mini-program allows Upload a Web Shell to a Web Server.This issue affects JiangQie Free Mini Program: from n/a through <= 2.5.2.

    Published: 17 Oct 2024
    7.5
    High

    CVE-2024-49285

    Last Modified: 23 Apr 2026

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Jeroen Berkvens SSV MailChimp ssv-mailchimp allows PHP Local File Inclusion.This issue affects SSV MailChimp: from n/a through <= 3.1.5.

    Published: 17 Oct 2024
    7.5
    High

    CVE-2024-49287

    Last Modified: 23 Apr 2026

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in mh6webentwicklung PDF-Rechnungsverwaltung pdf-rechnungsverwaltung allows PHP Local File Inclusion.This issue affects PDF-Rechnungsverwaltung: from n/a through <= 0.0.1.

    Published: 17 Oct 2024
    9.8
    Critical

    CVE-2024-49400

    Last Modified: 15 Apr 2026

    Tacquito prior to commit 07b49d1358e6ec0b5aa482fcd284f509191119e2 was not properly performing regex matches on authorized commands and arguments. Configured allowed commands/arguments were intended to require a match on the entire string, but instead only enforced a match on a sub-string. That would have potentially allowed unauthorized commands to be executed.

    Published: 17 Oct 2024
    7.5
    High

    CVE-2024-49317

    Last Modified: 29 Apr 2026

    Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ZIPANG Point Maker point-maker allows PHP Local File Inclusion.This issue affects Point Maker: from n/a through <= 0.1.4.

    Published: 17 Oct 2024
    9.8
    Critical

    CVE-2024-49318

    Last Modified: 23 Apr 2026

    Deserialization of Untrusted Data vulnerability in Scott My Reading Library my-reading-library allows Object Injection.This issue affects My Reading Library: from n/a through <= 1.0.

    Published: 17 Oct 2024
    4.9
    Medium

    CVE-2024-49312

    Last Modified: 23 Apr 2026

    Server-Side Request Forgery (SSRF) vulnerability in WisdmLabs Edwiser Bridge edwiser-bridge.This issue affects Edwiser Bridge: from n/a through <= 3.0.7.

    Published: 17 Oct 2024
    8.7
    High

    CVE-2024-49399

    Last Modified: 15 Apr 2026

    The affected product is vulnerable to an attacker being able to use commands without providing a password which may allow an attacker to leak information.

    Published: 17 Oct 2024
    8.8
    High

    CVE-2024-49398

    Last Modified: 15 Apr 2026

    The affected product is vulnerable to unrestricted file uploads, which may allow an attacker to remotely execute code.

    Published: 17 Oct 2024
    9.2
    Critical

    CVE-2024-49397

    Last Modified: 15 Apr 2026

    The affected product is vulnerable to a cross-site scripting attack which may allow an attacker to bypass authentication and takeover admin accounts.

    Published: 17 Oct 2024
    8.7
    High

    CVE-2024-49396

    Last Modified: 15 Apr 2026

    The affected product is vulnerable due to insufficiently protected credentials, which may allow an attacker to impersonate Elvaco and send false information.

    Published: 17 Oct 2024
    7
    High

    CVE-2024-9414

    Last Modified: 15 Apr 2026

    In LAquis SCADA version 4.7.1.511, a cross-site scripting vulnerability could allow an attacker to inject arbitrary code into a web page. This could allow an attacker to steal cookies, redirect users, or perform unauthorized actions.

    Published: 17 Oct 2024
    5.3
    Medium

    CVE-2018-25104

    Last Modified: 15 Apr 2026

    A vulnerability was found in CoinGate Plugin up to 1.2.7 on PrestaShop. It has been rated as problematic. Affected by this issue is the function postProcess of the file modules/coingate/controllers/front/callback.php of the component Payment Handler. The manipulation leads to business logic errors. The attack may be launched remotely. Upgrading to version 1.2.8 is able to address this issue. The patch is identified as 0a3097db0aec7c5d66686c142c6abaa1e126ca16. It is recommended to upgrade the affected component.

    Published: 17 Oct 2024
    5.5
    Medium

    CVE-2024-47459

    Last Modified: 23 Oct 2024

    Substance3D - Sampler versions 4.5 and earlier are affected by a NULL Pointer Dereference vulnerability that could lead to an application denial-of-service (DoS) condition. An attacker could exploit this vulnerability to crash the application, resulting in a DoS. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 17 Oct 2024
    9.1
    Critical

    CVE-2024-48920

    Last Modified: 15 Apr 2026

    PutongOJ is online judging software. Prior to version 2.1.0-beta.1, unprivileged users can escalate privileges by constructing requests. This can lead to unauthorized access, enabling users to perform admin-level operations, potentially compromising sensitive data and system integrity. This problem has been fixed in v2.1.0.beta.1. As a workaround, one may apply the patch from commit `211dfe9` manually.

    Published: 17 Oct 2024
    6.1
    Medium

    CVE-2024-10099

    Last Modified: 21 Oct 2024

    A stored cross-site scripting (XSS) vulnerability exists in comfyanonymous/comfyui version 0.2.2 and possibly earlier. The vulnerability occurs when an attacker uploads an HTML file containing a malicious XSS payload via the `/api/upload/image` endpoint. The payload is executed when the file is viewed through the `/view` API endpoint, leading to potential execution of arbitrary JavaScript code.

    Published: 17 Oct 2024
    5.4
    Medium

    CVE-2024-10101

    Last Modified: 11 Jul 2025

    A stored cross-site scripting (XSS) vulnerability exists in binary-husky/gpt_academic version 3.83. The vulnerability occurs at the /file endpoint, which renders HTML files. Malicious HTML files containing XSS payloads can be uploaded and stored in the backend, leading to the execution of the payload in the victim's browser when the file is accessed. This can result in the theft of session cookies or other sensitive information.

    Published: 17 Oct 2024
    7.5
    High

    CVE-2024-10100

    Last Modified: 11 Jul 2025

    A path traversal vulnerability exists in binary-husky/gpt_academic version 3.83. The vulnerability is due to improper handling of the file parameter, which is open to path traversal through URL encoding. This allows attackers to view any file on the host system, including sensitive files such as critical application files, SSH keys, API keys, and configuration values.

    Published: 17 Oct 2024
    6.3
    Medium

    CVE-2005-10003

    Last Modified: 14 Nov 2024

    A vulnerability classified as critical has been found in mikexstudios Xcomic up to 0.8.2. This affects an unknown part. The manipulation of the argument cmd leads to os command injection. It is possible to initiate the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used. Upgrading to version 0.8.3 is able to address this issue. The patch is named 6ed8e3cc336e29f09c7e791863d0559939da98bf. It is recommended to upgrade the affected component.

    Published: 17 Oct 2024
    7.2
    High

    CVE-2024-6333

    Last Modified: 15 Apr 2026

    Authenticated Remote Code Execution in Altalink, Versalink & WorkCentre Products.

    Published: 17 Oct 2024
    8.6
    High

    CVE-2024-49315

    Last Modified: 29 Apr 2026

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in CodeFlock FREE DOWNLOAD MANAGER free-download-manager allows Path Traversal.This issue affects FREE DOWNLOAD MANAGER: from n/a through <= 1.0.0.

    Published: 17 Oct 2024
    5.3
    Medium

    CVE-2024-50312

    Last Modified: 11 Aug 2026

    A vulnerability was found in GraphQL due to improper access controls on the GraphQL introspection query. This flaw allows unauthorized users to retrieve a comprehensive list of available queries and mutations. Exposure to this flaw increases the attack surface, as it can facilitate the discovery of flaws or errors specific to the application's GraphQL implementation.

    Published: 17 Oct 2024
    6.5
    Medium

    CVE-2024-50311

    Last Modified: 20 Nov 2025

    A denial of service (DoS) vulnerability was found in OpenShift. This flaw allows attackers to exploit the GraphQL batching functionality. The vulnerability arises when multiple queries can be sent within a single request, enabling an attacker to submit a request containing thousands of aliases in one query. This issue causes excessive resource consumption, leading to application unavailability for legitimate users.

    Published: 17 Oct 2024
    5.3
    Medium

    CVE-2024-49580

    Last Modified: 6 Dec 2024

    In JetBrains Ktor before 2.3.13 improper caching in HttpCache Plugin could lead to response information disclosure

    Published: 17 Oct 2024
    8.1
    High

    CVE-2024-49579

    Last Modified: 14 Nov 2024

    In JetBrains YouTrack before 2024.3.47197 insecure plugin iframe allowed arbitrary JavaScript execution and unauthorized API requests

    Published: 17 Oct 2024
    6.3
    Medium

    CVE-2024-10073

    Last Modified: 29 Oct 2024

    A vulnerability, which was classified as critical, was found in flairNLP flair 0.14.0. Affected is the function ClusteringModel of the file flair\models\clustering.py of the component Mode File Loader. The manipulation leads to code injection. It is possible to launch the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 17 Oct 2024
    5.3
    Medium

    CVE-2024-10072

    Last Modified: 22 Oct 2024

    A vulnerability, which was classified as critical, has been found in ESAFENET CDG 5. This issue affects the function actionAddEncryptPolicyGroup of the file /com/esafenet/servlet/policy/EncryptPolicyService.java. The manipulation of the argument checklist leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 17 Oct 2024
    7.1
    High

    CVE-2024-48021

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Scott Paterson Contact Form 7 – PayPal & Stripe Add-on contact-form-7-paypal-add-on allows Reflected XSS.This issue affects Contact Form 7 – PayPal & Stripe Add-on: from n/a through <= 2.3.

    Published: 17 Oct 2024