CVE Feed

    Dashboard / CVE

    8.9
    High

    CVE-2024-9348

    Last Modified: 15 Apr 2026

    Docker Desktop before v4.34.3 allows RCE via unsanitized GitHub source link in Build view.

    Published: 16 Oct 2024
    5.9
    Medium

    CVE-2024-49266

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Thimo Grauerholz WP-Spreadplugin wp-spreadplugin allows Cross-Site Scripting (XSS).This issue affects WP-Spreadplugin: from n/a through <= 4.8.9.

    Published: 16 Oct 2024
    6.5
    Medium

    CVE-2024-49267

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in nayon46 Unlimited Addon For Elementor unlimited-addon-for-elementor allows Stored XSS.This issue affects Unlimited Addon For Elementor: from n/a through <= 2.0.0.

    Published: 16 Oct 2024
    7.1
    High

    CVE-2024-49268

    Last Modified: 28 Apr 2026

    Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in sunburntkamel disconnected allows Reflected XSS.This issue affects disconnected: from n/a through 1.3.0.

    Published: 16 Oct 2024
    8.6
    High

    CVE-2024-45844

    Last Modified: 21 Oct 2025

    BIG-IP monitor functionality may allow an attacker to bypass access control restrictions, regardless of the port lockdown settings.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

    Published: 16 Oct 2024
    4.8
    Medium

    CVE-2024-47139

    Last Modified: 6 Aug 2025

    A stored cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IQ Configuration utility that allows an attacker with the Administrator role to run JavaScript in the context of the currently logged-in user.   Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

    Published: 16 Oct 2024
    9.8
    Critical

    CVE-2024-9893

    Last Modified: 15 Apr 2026

    The Nextend Social Login Pro plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 3.1.14. This is due to insufficient verification on the user being returned by the social login token. This makes it possible for unauthenticated attackers to log in as any existing user on the site, such as an administrator, if they have access to the email and the user does not have an already-existing account for the service returning the token.

    Published: 16 Oct 2024
    6.5
    Medium

    CVE-2024-49270

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in hashthemes Smart Blocks smart-blocks allows Stored XSS.This issue affects Smart Blocks: from n/a through <= 2.0.

    Published: 16 Oct 2024
    6.4
    Medium

    CVE-2023-32189

    Last Modified: 15 Apr 2026

    Insecure handling of ssh keys used to bootstrap clients allows local attackers to potentially gain access to the keys

    Published: 16 Oct 2024
    5.3
    Medium

    CVE-2024-49252

    Last Modified: 23 Apr 2026

    Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in VaultDweller Leyka leyka.This issue affects Leyka: from n/a through <= 3.31.6.

    Published: 16 Oct 2024
    7.5
    High

    CVE-2024-49245

    Last Modified: 29 Apr 2026

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in nahimsalami Ahime Image Printer ahime-image-printer.This issue affects Ahime Image Printer: from n/a through <= 1.0.0.

    Published: 16 Oct 2024
    5.5
    Medium

    CVE-2024-22034

    Last Modified: 15 Apr 2026

    Attackers could put the special files in .osc into the actual package sources (e.g. _apiurl). This allows the attacker to change the configuration of osc for the victim

    Published: 16 Oct 2024
    6.5
    Medium

    CVE-2024-49258

    Last Modified: 23 Apr 2026

    Path Traversal: '.../...//' vulnerability in Limbcode WordPress Gallery Plugin – Limb Image Gallery limb-gallery.This issue affects WordPress Gallery Plugin – Limb Image Gallery: from n/a through <= 1.5.7.

    Published: 16 Oct 2024
    9.9
    Critical

    CVE-2024-48034

    Last Modified: 23 Apr 2026

    Unrestricted Upload of File with Dangerous Type vulnerability in fliperrr Creates 3D Flipbook, PDF Flipbook create-flipbook-from-pdf allows Upload a Web Shell to a Web Server.This issue affects Creates 3D Flipbook, PDF Flipbook: from n/a through <= 1.2.

    Published: 16 Oct 2024
    5.1
    Medium

    CVE-2024-22033

    Last Modified: 15 Apr 2026

    The OBS service obs-service-download_url was vulnerable to a command injection vulnerability. The attacker could provide a configuration to the service that allowed to execute command in later steps

    Published: 16 Oct 2024
    10
    Critical

    CVE-2024-49216

    Last Modified: 29 Apr 2026

    Unrestricted Upload of File with Dangerous Type vulnerability in jclay06 Feed Comments Number feed-comments-number allows Upload a Web Shell to a Web Server.This issue affects Feed Comments Number: from n/a through <= 0.2.1.

    Published: 16 Oct 2024
    10
    Critical

    CVE-2024-49242

    Last Modified: 29 Apr 2026

    Unrestricted Upload of File with Dangerous Type vulnerability in Shafiq Digital Lottery digital-lottery allows Upload a Web Shell to a Web Server.This issue affects Digital Lottery: from n/a through <= 3.0.5.

    Published: 16 Oct 2024
    9.9
    Critical

    CVE-2024-49260

    Last Modified: 23 Apr 2026

    Unrestricted Upload of File with Dangerous Type vulnerability in Limbcode WordPress Gallery Plugin – Limb Image Gallery limb-gallery allows Code Injection.This issue affects WordPress Gallery Plugin – Limb Image Gallery: from n/a through <= 1.5.7.

    Published: 16 Oct 2024
    7.5
    High

    CVE-2024-47351

    Last Modified: 23 Apr 2026

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in The CSSIgniter Team MaxSlider maxslider allows Path Traversal.This issue affects MaxSlider: from n/a through <= 1.2.3.

    Published: 16 Oct 2024
    7.5
    High

    CVE-2024-47645

    Last Modified: 23 Apr 2026

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Danish Ali Malik Top Bar – PopUps – by WPOptin wpoptin allows PHP Local File Inclusion.This issue affects Top Bar – PopUps – by WPOptin: from n/a through <= 2.0.1.

    Published: 16 Oct 2024
    7.5
    High

    CVE-2024-48029

    Last Modified: 23 Apr 2026

    Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Hung Trang Si SB Random Posts Widget sb-random-posts-widget allows PHP Local File Inclusion.This issue affects SB Random Posts Widget: from n/a through <= 1.0.

    Published: 16 Oct 2024
    7.5
    High

    CVE-2024-49251

    Last Modified: 23 Apr 2026

    Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Acnoo Maan Addons For Elementor maan-elementor-addons allows Local Code Inclusion.This issue affects Maan Addons For Elementor: from n/a through <= 1.0.1.

    Published: 16 Oct 2024
    7.1
    High

    CVE-2024-22032

    Last Modified: 15 Apr 2026

    A vulnerability has been identified in which an RKE1 cluster keeps constantly reconciling when secrets encryption configuration is enabled. When reconciling, the Kube API secret values are written in plaintext on the AppliedSpec. Cluster owners, Cluster members, and Project members (for projects within the cluster), all have RBAC permissions to view the cluster object from the apiserver.

    Published: 16 Oct 2024
    9.8
    Critical

    CVE-2024-48026

    Last Modified: 23 Apr 2026

    Deserialization of Untrusted Data vulnerability in GMRobbins Disc Golf Manager disc-golf-manager allows Object Injection.This issue affects Disc Golf Manager: from n/a through <= 1.0.0.

    Published: 16 Oct 2024
    8
    High

    CVE-2024-22030

    Last Modified: 15 Apr 2026

    A vulnerability has been identified within Rancher that can be exploited in narrow circumstances through a man-in-the-middle (MITM) attack. An attacker would need to have control of an expired domain or execute a DNS spoofing/hijacking attack against the domain to exploit this vulnerability. The targeted domain is the one used as the Rancher URL.

    Published: 16 Oct 2024
    9.8
    Critical

    CVE-2024-48028

    Last Modified: 23 Apr 2026

    Deserialization of Untrusted Data vulnerability in Boyan Raichev IP Loc8 ip-loc8 allows Object Injection.This issue affects IP Loc8: from n/a through <= 1.1.

    Published: 16 Oct 2024
    9.8
    Critical

    CVE-2024-48030

    Last Modified: 23 Apr 2026

    Deserialization of Untrusted Data vulnerability in Webextends Telecash Ricaricaweb telecash-ricaricaweb allows Object Injection.This issue affects Telecash Ricaricaweb: from n/a through <= 2.2.

    Published: 16 Oct 2024
    9.8
    Critical

    CVE-2024-49218

    Last Modified: 29 Apr 2026

    Deserialization of Untrusted Data vulnerability in Al Imran Akash Recently recently-viewed-most-viewed-and-sold-products-for-woocommerce allows Object Injection.This issue affects Recently: from n/a through <= 1.1.

    Published: 16 Oct 2024
    8.8
    High

    CVE-2024-49226

    Last Modified: 29 Apr 2026

    Deserialization of Untrusted Data vulnerability in taketin TAKETIN To WP Membership taketin-to-wp-membership allows Object Injection.This issue affects TAKETIN To WP Membership: from n/a through <= 2.8.17.

    Published: 16 Oct 2024
    9.8
    Critical

    CVE-2024-49227

    Last Modified: 29 Apr 2026

    Deserialization of Untrusted Data vulnerability in foter Free Stock Photos Foter free-stock-photos-foter allows Object Injection.This issue affects Free Stock Photos Foter: from n/a through <= 1.5.4.

    Published: 16 Oct 2024
    10
    Critical

    CVE-2024-49254

    Last Modified: 23 Apr 2026

    Improper Control of Generation of Code ('Code Injection') vulnerability in sunjianle ajax-extend ajax-extend allows Code Injection.This issue affects ajax-extend: from n/a through <= 1.0.

    Published: 16 Oct 2024
    8.8
    High

    CVE-2024-47637

    Last Modified: 23 Apr 2026

    Relative Path Traversal vulnerability in LiteSpeed Technologies LiteSpeed Cache litespeed-cache allows Path Traversal.This issue affects LiteSpeed Cache: from n/a through <= 6.4.1.

    Published: 16 Oct 2024
    8.6
    High

    CVE-2024-49253

    Last Modified: 29 Apr 2026

    Relative Path Traversal vulnerability in JamesPark.ninja Analyse Uploads analyse-uploads allows Relative Path Traversal.This issue affects Analyse Uploads: from n/a through <= 0.5.

    Published: 16 Oct 2024
    9.1
    Critical

    CVE-2024-47649

    Last Modified: 23 Apr 2026

    Unrestricted Upload of File with Dangerous Type vulnerability in THATplugin Iconize iconize.This issue affects Iconize: from n/a through <= 1.2.4.

    Published: 16 Oct 2024
    9.9
    Critical

    CVE-2024-48027

    Last Modified: 23 Apr 2026

    Unrestricted Upload of File with Dangerous Type vulnerability in xaraartech External featured image from bing external-featured-image-from-bing allows Upload a Web Shell to a Web Server.This issue affects External featured image from bing: from n/a through <= 1.0.2.

    Published: 16 Oct 2024
    9.9
    Critical

    CVE-2024-48035

    Last Modified: 23 Apr 2026

    Unrestricted Upload of File with Dangerous Type vulnerability in takayukii ACF Images Search And Insert acf-images-search-and-insert allows Upload a Web Shell to a Web Server.This issue affects ACF Images Search And Insert: from n/a through <= 1.1.4.

    Published: 16 Oct 2024
    7.5
    High

    CVE-2023-32196

    Last Modified: 15 Apr 2026

    A vulnerability has been identified whereby privilege escalation checks are not properly enforced for RoleTemplateobjects when external=true, which in specific scenarios can lead to privilege escalation.

    Published: 16 Oct 2024
    9.1
    Critical

    CVE-2024-48042

    Last Modified: 23 Apr 2026

    Deserialization of Untrusted Data vulnerability in supsystic Contact Form by Supsystic contact-form-by-supsystic allows Command Injection.This issue affects Contact Form by Supsystic: from n/a through <= 1.7.28.

    Published: 16 Oct 2024
    10
    Critical

    CVE-2024-49257

    Last Modified: 23 Apr 2026

    Unrestricted Upload of File with Dangerous Type vulnerability in Denis Azz Anonim Posting azz-anonim-posting allows Upload a Web Shell to a Web Server.This issue affects Azz Anonim Posting: from n/a through <= 0.9.

    Published: 16 Oct 2024
    8.6
    High

    CVE-2023-32194

    Last Modified: 15 Apr 2026

    A vulnerability has been identified when granting a create or * global role for a resource type of "namespaces"; no matter the API group, the subject will receive * permissions for core namespaces. This can lead to someone being capable of accessing, creating, updating, or deleting a namespace in the project.

    Published: 16 Oct 2024
    9.1
    Critical

    CVE-2024-49271

    Last Modified: 23 Apr 2026

    Deserialization of Untrusted Data vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates) unlimited-elements-for-elementor allows Command Injection.This issue affects Unlimited Elements For Elementor (Free Widgets, Addons, Templates): from n/a through <= 1.5.121.

    Published: 16 Oct 2024
    5.3
    Medium

    CVE-2020-36841

    Last Modified: 15 Apr 2026

    The WooCommerce Smart Coupons plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the woocommerce_coupon_admin_init function in versions up to, and including, 4.6.0. This makes it possible for unauthenticated attackers to send themselves gift certificates of any value, which could be redeemed for products sold on the victim’s storefront.

    Published: 16 Oct 2024
    9.8
    Critical

    CVE-2024-49247

    Last Modified: 29 Apr 2026

    Authentication Bypass Using an Alternate Path or Channel vulnerability in SK BuddyPress Better Registration better-bp-registration allows Authentication Bypass.This issue affects BuddyPress Better Registration: from n/a through <= 1.6.

    Published: 16 Oct 2024
    —
    Unknown

    CVE-2024-10042

    Last Modified: 11 Feb 2025

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

    Published: 16 Oct 2024
    8.3
    High

    CVE-2023-32193

    Last Modified: 15 Apr 2026

    A vulnerability has been identified in which unauthenticated cross-site scripting (XSS) in Norman's public API endpoint can be exploited. This can lead to an attacker exploiting the vulnerability to trigger JavaScript code and execute commands remotely.

    Published: 16 Oct 2024
    8.3
    High

    CVE-2023-32192

    Last Modified: 15 Apr 2026

    A vulnerability has been identified in which unauthenticated cross-site scripting (XSS) in the API Server's public API endpoint can be exploited, allowing an attacker to execute arbitrary JavaScript code in the victim browser

    Published: 16 Oct 2024
    9.9
    Critical

    CVE-2023-32191

    Last Modified: 15 Apr 2026

    When RKE provisions a cluster, it stores the cluster state in a configmap called `full-cluster-state` inside the `kube-system` namespace of the cluster itself. The information available in there allows non-admin users to escalate to admin.

    Published: 16 Oct 2024
    8.5
    High

    CVE-2023-32190

    Last Modified: 15 Apr 2026

    mlocate's %post script allows RUN_UPDATEDB_AS user to make arbitrary files world readable by abusing insecure file operations that run with root privileges.

    Published: 16 Oct 2024
    7.7
    High

    CVE-2024-8040

    Last Modified: 15 Apr 2026

    An authorization bypass through user-controlled key vulnerability affecting 3DSwym in 3DSwymer on Release 3DEXPERIENCE R2024x allows an authenticated attacker to access some unauthorized data.

    Published: 16 Oct 2024
    8.7
    High

    CVE-2024-6380

    Last Modified: 22 Oct 2025

    A reflected Cross-site Scripting (XSS) vulnerability affecting ENOVIA Collaborative Industry Innovator from Release 3DEXPERIENCE R2022x through Release 3DEXPERIENCE R2024x allows an attacker to execute arbitrary script code in user's browser session.

    Published: 16 Oct 2024