CVE Feed

    Dashboard / CVE

    7.3
    High

    CVE-2024-9837

    Last Modified: 15 Apr 2026

    The The AADMY – Add Auto Date Month Year Into Posts plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 2.0.1. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes.

    Published: 15 Oct 2024
    9.8
    Critical

    CVE-2024-9972

    Last Modified: 15 Apr 2026

    Property Management System from ChanGate has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary SQL commands to read, modify, and delete database contents.

    Published: 15 Oct 2024
    7.5
    High

    CVE-2024-46898

    Last Modified: 23 Oct 2024

    SHIRASAGI prior to v1.19.1 processes URLs in HTTP requests improperly, resulting in a path traversal vulnerability. If this vulnerability is exploited, arbitrary files on the server may be retrieved when processing crafted HTTP requests.

    Published: 15 Oct 2024
    5.3
    Medium

    CVE-2024-9944

    Last Modified: 8 Apr 2026

    The WooCommerce plugin for WordPress is vulnerable to HTML Injection in all versions up to, and including, 9.0.2. This is due to the plugin not properly neutralizing HTML elements from submitted order forms. This makes it possible for unauthenticated attackers to inject arbitrary HTML that will render when the administrator views order form submissions.

    Published: 15 Oct 2024
    6.1
    Medium

    CVE-2024-21535

    Last Modified: 17 Oct 2024

    Versions of the package markdown-to-jsx before 7.4.0 are vulnerable to Cross-site Scripting (XSS) via the src property due to improper input sanitization. An attacker can execute arbitrary code by injecting a malicious iframe element in the markdown.

    Published: 15 Oct 2024
    8.8
    High

    CVE-2024-9971

    Last Modified: 17 Oct 2024

    The specific query functionality in the FlowMaster BPM Plus from NewType does not properly restrict user input, allowing remote attackers with regular privileges to inject SQL commands to read, modify, or delete database contents.

    Published: 15 Oct 2024
    8.8
    High

    CVE-2024-9970

    Last Modified: 17 Oct 2024

    The FlowMaster BPM Plus system from NewType has a privilege escalation vulnerability. Remote attackers with regular privileges can elevate their privileges to administrator by tampering with a specific cookie.

    Published: 15 Oct 2024
    5.4
    Medium

    CVE-2024-9969

    Last Modified: 19 Oct 2024

    NewType WebEIP v3.0 does not properly validate user input, allowing a remote attacker with regular privileges to insert JavaScript into specific parameters, resulting in a Reflected Cross-site Scripting (XSS) attack. The affected product is no longer maintained. It is recommended to upgrade to the new product.

    Published: 15 Oct 2024
    8.8
    High

    CVE-2024-9968

    Last Modified: 19 Oct 2024

    WebEIP v3.0 from NewType does not properly validate user input, allowing remote attackers with regular privilege to inject SQL commands to read, modify, and delete data stored in database. The affected product is no longer maintained. It is recommended to upgrade to the new product.

    Published: 15 Oct 2024
    6.5
    Medium

    CVE-2024-9820

    Last Modified: 8 Apr 2026

    The WP 2FA with Telegram plugin for WordPress is vulnerable to Two-Factor Authentication Bypass in versions up to, and including, 3.0. This is due to the two-factor code being stored in a cookie, which makes it possible to bypass two-factor authentication.

    Published: 15 Oct 2024
    4.3
    Medium

    CVE-2024-6757

    Last Modified: 8 Apr 2026

    The Elementor Website Builder – More than Just a Page Builder plugin for WordPress is vulnerable to Basic Information Exposure in all versions up to, and including, 3.23.5 via the get_image_alt function. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract either excerpt data or titles of private or password-protected posts.

    Published: 15 Oct 2024
    8.8
    High

    CVE-2024-9687

    Last Modified: 8 Apr 2026

    The WP 2FA with Telegram plugin for WordPress is vulnerable to Authentication Bypass in versions up to, and including, 3.0. This is due to insufficient validation of the user-controlled key on the 'validate_tg' action. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to log in as any existing user on the site, such as an administrator.

    Published: 15 Oct 2024
    5.1
    Medium

    CVE-2024-9952

    Last Modified: 16 Oct 2024

    A vulnerability was found in SourceCodester Online Eyewear Shop 1.0 and classified as problematic. This issue affects some unknown processing of the file /admin/?page=system_info/contact_info of the component Contact Information Page. The manipulation of the argument Address leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. Other parameters might be affected as well.

    Published: 15 Oct 2024
    6.3
    Medium

    CVE-2024-0129

    Last Modified: 8 Nov 2024

    NVIDIA NeMo contains a vulnerability in SaveRestoreConnector where a user may cause a path traversal issue via an unsafe .tar file extraction. A successful exploit of this vulnerability may lead to code execution and data tampering.

    Published: 15 Oct 2024
    6.6
    Medium

    CVE-2023-31493

    Last Modified: 5 Jul 2026

    RCE (Remote Code Execution) exists in ZoneMinder through 1.36.33 as an attacker can create a new .php log file in language folder, while executing a crafted payload and escalate privileges allowing execution of any commands on the remote system.

    Published: 15 Oct 2024
    9.8
    Critical

    CVE-2024-49195

    Last Modified: 5 Jun 2026

    Mbed TLS 3.5.x through 3.6.x before 3.6.2 has a buffer underrun in pkwrite when writing an opaque key pair

    Published: 15 Oct 2024
    5.1
    Medium

    CVE-2024-44337

    Last Modified: 15 Apr 2026

    The package `github.com/gomarkdown/markdown` is a Go library for parsing Markdown text and rendering as HTML. Prior to pseudoversion `v0.0.0-20240729232818-a2a9c4f`, which corresponds with commit `a2a9c4f76ef5a5c32108e36f7c47f8d310322252`, there was a logical problem in the paragraph function of the parser/block.go file, which allowed a remote attacker to cause a denial of service (DoS) condition by providing a tailor-made input that caused an infinite loop, causing the program to hang and consume resources indefinitely. Submit `a2a9c4f76ef5a5c32108e36f7c47f8d310322252` contains fixes to this problem.

    Published: 15 Oct 2024
    7.8
    High

    CVE-2024-47674

    Last Modified: 4 Aug 2026

    In the Linux kernel, the following vulnerability has been resolved: mm: avoid leaving partial pfn mappings around in error case As Jann points out, PFN mappings are special, because unlike normal memory mappings, there is no lifetime information associated with the mapping - it is just a raw mapping of PFNs with no reference counting of a 'struct page'. That's all very much intentional, but it does mean that it's easy to mess up the cleanup in case of errors. Yes, a failed mmap() will always eventually clean up any partial mappings, but without any explicit lifetime in the page table mapping itself, it's very easy to do the error handling in the wrong order. In particular, it's easy to mistakenly free the physical backing store before the page tables are actually cleaned up and (temporarily) have stale dangling PTE entries. To make this situation less error-prone, just make sure that any partial pfn mapping is torn down early, before any other error handling.

    Published: 15 Oct 2024
    4.8
    Medium

    CVE-2024-48948

    Last Modified: 25 Nov 2025

    The Elliptic package 6.5.7 for Node.js, in its for ECDSA implementation, does not correctly verify valid signatures if the hash contains at least four leading 0 bytes and when the order of the elliptic curve's base point is smaller than the hash, because of an _truncateToN anomaly. This leads to valid signatures being rejected. Legitimate transactions or communications may be incorrectly flagged as invalid.

    Published: 15 Oct 2024
    7.5
    High

    CVE-2024-44775

    Last Modified: 3 Apr 2026

    kmqtt v0.2.7 is vulnerable to Denial of Service (DoS) due to a Null Pointer Exception. A remote attacker can cause the broker to crash by sending a specially crafted MQTT CONNECT packet that triggers an unhandled null reference, leading to an immediate process termination.

    Published: 15 Oct 2024
    8.1
    High

    CVE-2024-41311

    Last Modified: 24 Mar 2025

    In Libheif 1.17.6, insufficient checks in ImageOverlay::parse() decoding a heif file containing an overlay image with forged offsets can lead to an out-of-bounds read and write.

    Published: 15 Oct 2024
    7.6
    High

    CVE-2024-48279

    Last Modified: 31 Mar 2025

    A HTML Injection vulnerability was found in /search-result.php of PHPGurukul User Registration & Login and User Management System 3.2. This vulnerability allows remote attackers to execute arbitrary HTML code via the searchkey parameter in a POST HTTP request.

    Published: 15 Oct 2024
    7.6
    High

    CVE-2024-48280

    Last Modified: 31 Mar 2025

    A SQL Injection vulnerability was found in /search-result.php of PHPGurukul User Registration & Login and User Management System 3.2, which allows remote attackers to execute arbitrary SQL command via the fromdate parameter in a POST HTTP request.

    Published: 15 Oct 2024
    6.5
    Medium

    CVE-2024-48713

    Last Modified: 21 May 2025

    In TP-Link TL-WDR7660 1.0, the wacWhitelistJsonToBin function handles the parameter string name without checking it, which can lead to stack overflow vulnerabilities.

    Published: 15 Oct 2024
    6.5
    Medium

    CVE-2024-48714

    Last Modified: 21 May 2025

    In TP-Link TL-WDR7660 v1.0, the guestRuleJsonToBin function handles the parameter string name without checking it, which can lead to stack overflow vulnerabilities.

    Published: 15 Oct 2024
    9.8
    Critical

    CVE-2024-48781

    Last Modified: 15 Apr 2026

    An issue in Wanxing Technology Yitu Project Management Kirin Edition 2.3.6 allows a remote attacker to execute arbitrary code via a specially constructed so file/opt/EdrawProj-2/plugins/imageformat.

    Published: 15 Oct 2024
    8.8
    High

    CVE-2024-35584

    Last Modified: 17 Jul 2025

    SQL injection vulnerabilities were discovered in Ajax.php, ForWindow.php, ForExport.php, Modules.php, functions/HackingLogFnc.php in OpenSis Community Edition 9.1 to 8.0, and possibly earlier versions. It is possible for an authenticated user to perform SQL Injection due to the lack to sanitisation. The application takes arbitrary value from "X-Forwarded-For" header and appends it to a SQL INSERT statement directly, leading to SQL Injection.

    Published: 15 Oct 2024
    4.9
    Medium

    CVE-2024-31955

    Last Modified: 15 Apr 2026

    An issue was discovered in Samsung eMMC with KLMAG2GE4A and KLM8G1WEMB firmware. Code bypass through Electromagnetic Fault Injection allows an attacker to successfully authenticate and write to the RPMB (Replay Protected Memory Block) area without possessing secret information.

    Published: 15 Oct 2024
    7.5
    High

    CVE-2024-41344

    Last Modified: 1 Aug 2025

    A Cross-Site Request Forgery (CSRF) in Codeigniter 3.1.13 allows attackers to arbitrarily change the Administrator password and escalate privileges.

    Published: 15 Oct 2024
    5.5
    Medium

    CVE-2024-48278

    Last Modified: 31 Mar 2025

    Phpgurukul User Registration & Login and User Management System 3.2 is vulnerable to Cross Site Request Forgery (CSRF) via /edit-profile.php.

    Published: 15 Oct 2024
    7.6
    High

    CVE-2024-48282

    Last Modified: 31 Mar 2025

    A SQL Injection vulnerability was found in /password-recovery.php of PHPGurukul User Registration & Login and User Management System 3.2, which allows remote attackers to execute arbitrary SQL commands to get unauthorized database access via the femail parameter in a POST HTTP request.

    Published: 15 Oct 2024
    9.8
    Critical

    CVE-2024-48283

    Last Modified: 4 Apr 2025

    Phpgurukul User Registration & Login and User Management System 3.2 is vulnerable to SQL Injection in /admin//search-result.php via the searchkey parameter.

    Published: 15 Oct 2024
    9.8
    Critical

    CVE-2024-48411

    Last Modified: 17 May 2025

    itsourcecode Online Tours and Travels Management System v1.0 is vulnerable to SQL Injection (SQLI) via a crafted payload to the val-email parameter in forget_password.php.

    Published: 15 Oct 2024
    6.6
    Medium

    CVE-2024-48622

    Last Modified: 6 May 2025

    A cross-site scripting (XSS) issue in DomainMOD below v4.12.0 allows remote attackers to inject JavaScript code via admin/domain-fields/edit.php and the cdfid parameter.

    Published: 15 Oct 2024
    5.3
    Medium

    CVE-2024-48623

    Last Modified: 6 May 2025

    In queue\index.php of DomainMOD below v4.12.0, the list_id and domain_id parameters in the GET request can be exploited to cause a reflected Cross Site Scripting (XSS).

    Published: 15 Oct 2024
    5.3
    Medium

    CVE-2024-48624

    Last Modified: 6 May 2025

    In segments\edit.php of DomainMOD below v4.12.0, the segid parameter in the GET request can be exploited to cause a reflected Cross Site Scripting (XSS) vulnerability.

    Published: 15 Oct 2024
    6.5
    Medium

    CVE-2024-48710

    Last Modified: 21 May 2025

    In TP-Link TL-WDR7660 1.0, the wlanTimerRuleJsonToBin function handles the parameter string name without checking it, which can lead to stack overflow vulnerabilities.

    Published: 15 Oct 2024
    6.5
    Medium

    CVE-2024-48712

    Last Modified: 21 May 2025

    In TP-Link TL-WDR7660 1.0, the rtRuleJsonToBin function handles the parameter string name without checking it, which can lead to stack overflow vulnerabilities.

    Published: 15 Oct 2024
    9.8
    Critical

    CVE-2024-48779

    Last Modified: 15 Apr 2026

    An issue in Wanxing Technology's Yitu project Management Software 3.2.2 allows a remote attacker to execute arbitrary code via the platformpluginpath parameter to specify that the qt plugin loads the directory.

    Published: 15 Oct 2024
    9.8
    Critical

    CVE-2024-48782

    Last Modified: 15 Apr 2026

    File Upload vulnerability in DYCMS Open-Source Version v2.0.9.41 allows a remote attacker to execute arbitrary code via the application only detecting the extension of image files in the front-end.

    Published: 15 Oct 2024
    7.5
    High

    CVE-2024-48783

    Last Modified: 4 Dec 2024

    An issue in Ruijie NBR3000D-E Gateway allows a remote attacker to obtain sensitive information via the /tool/shell/postgresql.conf component.

    Published: 15 Oct 2024
    7.2
    High

    CVE-2024-9548

    Last Modified: 8 Apr 2026

    The SlimStat Analytics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the resource parameter in all versions up to, and including, 5.2.6 due to insufficient input sanitization and output escaping when logging visitor requests. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 14 Oct 2024
    5.3
    Medium

    CVE-2024-9546

    Last Modified: 8 Apr 2026

    The WPIDE – File Manager & Code Editor plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 3.4.9. This is due to the plugin utilizing the PHP-Parser library, which outputs parser rebuild command execution results. This makes it possible for unauthenticated attackers to retrieve the full path of the web application, which can be used to aid other attacks. The information displayed is not useful on its own, and requires another vulnerability to be present for damage to an affected website.

    Published: 14 Oct 2024
    2.5
    Low

    CVE-2024-30117

    Last Modified: 17 Oct 2024

    A dynamic search for a prerequisite library could allow the possibility for an attacker to replace the correct file under some circumstances.

    Published: 14 Oct 2024
    4.9
    Medium

    CVE-2024-9953

    Last Modified: 20 Mar 2025

    A potential denial-of-service (DoS) vulnerability exists in CERT VINCE software versions prior to 3.0.8. An authenticated administrative user can inject an arbitrary pickle object into a user’s profile, which may lead to a DoS condition when the profile is accessed. While the Django server restricts unpickling to prevent server crashes, this vulnerability could still disrupt operations.

    Published: 14 Oct 2024
    8.7
    High

    CVE-2024-6207

    Last Modified: 21 Oct 2024

    CVE 2021-22681 https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.PN1550.html  and send a specially crafted CIP message to the device. If exploited, a threat actor could help prevent access to the legitimate user and end connections to connected devices including the workstation. To recover the controllers, a download is required which ends any process that the controller is running.

    Published: 14 Oct 2024
    5.8
    Medium

    CVE-2024-48911

    Last Modified: 17 Oct 2024

    OpenCanary, a multi-protocol network honeypot, directly executed commands taken from its config file. Prior to version 0.9.4, where the config file is stored in an unprivileged user directory but the daemon is executed by root, it’s possible for the unprivileged user to change the config file and escalate permissions when root later runs the daemon. Version 0.9.4 contains a fix for the issue.

    Published: 14 Oct 2024
    2
    Low

    CVE-2024-48909

    Last Modified: 17 Oct 2024

    SpiceDB is an open source database for scalably storing and querying fine-grained authorization data. Starting in version 1.35.0 and prior to version 1.37.1, clients that have enabled `LookupResources2` and have caveats in the evaluation path for their requests can return a permissionship of `CONDITIONAL` with context marked as missing, even then the context was supplied. LookupResources2 is the new default in SpiceDB 1.37.0 and has been opt-in since SpiceDB 1.35.0. The bug is patched as part of SpiceDB 1.37.1. As a workaround, disable LookupResources2 via the `--enable-experimental-lookup-resources` flag by setting it to `false`.

    Published: 14 Oct 2024
    5.9
    Medium

    CVE-2024-47885

    Last Modified: 25 Nov 2025

    The Astro web framework has a DOM Clobbering gadget in the client-side router starting in version 3.0.0 and prior to version 4.16.1. It can lead to cross-site scripting (XSS) in websites enables Astro's client-side routing and has *stored* attacker-controlled scriptless HTML elements (i.e., `iframe` tags with unsanitized `name` attributes) on the destination pages. This vulnerability can result in cross-site scripting (XSS) attacks on websites that built with Astro that enable the client-side routing with `ViewTransitions` and store the user-inserted scriptless HTML tags without properly sanitizing the `name` attributes on the page. Version 4.16.1 contains a patch for this issue.

    Published: 14 Oct 2024
    5.9
    Medium

    CVE-2024-47831

    Last Modified: 8 Nov 2024

    Next.js is a React Framework for the Web. Cersions on the 10.x, 11.x, 12.x, 13.x, and 14.x branches before version 14.2.7 contain a vulnerability in the image optimization feature which allows for a potential Denial of Service (DoS) condition which could lead to excessive CPU consumption. Neither the `next.config.js` file that is configured with `images.unoptimized` set to `true` or `images.loader` set to a non-default value nor the Next.js application that is hosted on Vercel are affected. This issue was fully patched in Next.js `14.2.7`. As a workaround, ensure that the `next.config.js` file has either `images.unoptimized`, `images.loader` or `images.loaderFile` assigned.

    Published: 14 Oct 2024