CVE Feed

    Dashboard / CVE

    8.4
    High

    CVE-2024-35518

    Last Modified: 19 Mar 2025

    Netgear EX6120 v1.0.0.68 is vulnerable to Command Injection in genie_fix2.cgi via the wan_dns1_pri parameter.

    Published: 14 Oct 2024
    9.8
    Critical

    CVE-2024-46535

    Last Modified: 3 Jul 2025

    Jepaas v7.2.8 was discovered to contain a SQL injection vulnerability via the orderSQL parameter at /homePortal/loadUserMsg.

    Published: 14 Oct 2024
    7.3
    High

    CVE-2024-48259

    Last Modified: 2 May 2025

    Cloudlog 2.6.15 allows Oqrs.php request_form SQL injection via station_id or callsign.

    Published: 14 Oct 2024
    5.4
    Medium

    CVE-2024-48119

    Last Modified: 30 Oct 2024

    Vtiger CRM v8.2.0 has a HTML Injection vulnerability in the module parameter. Authenticated users can inject arbitrary HTML.

    Published: 14 Oct 2024
    5.4
    Medium

    CVE-2024-48120

    Last Modified: 29 Oct 2024

    X2CRM v8.5 is vulnerable to a stored Cross-Site Scripting (XSS) in the "Opportunities" module. An attacker can inject malicious JavaScript code into the "Name" field when creating a list.

    Published: 14 Oct 2024
    9.8
    Critical

    CVE-2024-48150

    Last Modified: 21 May 2025

    D-Link DIR-820L 1.05B03 has a stack overflow vulnerability in the sub_451208 function.

    Published: 14 Oct 2024
    9.8
    Critical

    CVE-2024-48168

    Last Modified: 7 May 2025

    A stack overflow vulnerability exists in the sub_402280 function of the HNAP service of D-Link DCS-960L 1.09, allowing an attacker to execute arbitrary code.

    Published: 14 Oct 2024
    9.8
    Critical

    CVE-2024-48257

    Last Modified: 16 Oct 2024

    Wavelog 1.8.5 allows Oqrs_model.php get_worked_modes station_id SQL injectioin.

    Published: 14 Oct 2024
    7.3
    High

    CVE-2024-48249

    Last Modified: 27 May 2025

    Wavelog 1.8.5 allows Gridmap_model.php get_band_confirmed SQL injection via band, sat, propagation, or mode.

    Published: 14 Oct 2024
    9.8
    Critical

    CVE-2024-48251

    Last Modified: 17 Oct 2024

    Wavelog 1.8.5 allows Activated_gridmap_model.php get_band_confirmed SQL injection via band, sat, propagation, or mode.

    Published: 14 Oct 2024
    9.8
    Critical

    CVE-2024-48253

    Last Modified: 16 Oct 2024

    Cloudlog 2.6.15 allows Oqrs.php delete_oqrs_line id SQL injection.

    Published: 14 Oct 2024
    9.8
    Critical

    CVE-2024-48255

    Last Modified: 16 Oct 2024

    Cloudlog 2.6.15 allows Oqrs.php get_station_info station_id SQL injection.

    Published: 14 Oct 2024
    7.5
    High

    CVE-2024-48789

    Last Modified: 15 Apr 2026

    An issue in INATRONIC com.inatronic.drivedeck.home 2.6.23 allows a remote attacker to obtain sensitve information via the firmware update process.

    Published: 14 Oct 2024
    7.5
    High

    CVE-2024-48791

    Last Modified: 15 Apr 2026

    An issue in Plug n Play Camera com.starvedia.mCamView.zwave 5.5.1 allows a remote attacker to obtain sensitive information via the firmware update process

    Published: 14 Oct 2024
    7.5
    High

    CVE-2024-48796

    Last Modified: 15 Apr 2026

    An issue in EQUES com.eques.plug 1.0.1 allows a remote attacker to obtain sensitive information via the firmware update process.

    Published: 14 Oct 2024
    7.5
    High

    CVE-2024-48798

    Last Modified: 15 Apr 2026

    An issue in Hubble Connected (com.hubbleconnected.vervelife) 2.00.81 allows a remote attacker to obtain sensitive information via the firmware update process.

    Published: 14 Oct 2024
    7.5
    High

    CVE-2024-48799

    Last Modified: 15 Apr 2026

    An issue in LOREX TECHNOLOGY INC com.lorexcorp.lorexping 1.4.22 allows a remote attacker to obtain sensitive information via the firmware update process.

    Published: 14 Oct 2024
    9.8
    Critical

    CVE-2024-7099

    Last Modified: 30 Jul 2025

    netease-youdao/qanything version 1.4.1 contains a vulnerability where unsafe data obtained from user input is concatenated in SQL queries, leading to SQL injection. The affected functions include `get_knowledge_base_name`, `from_status_to_status`, `delete_files`, and `get_file_by_status`. An attacker can exploit this vulnerability to execute arbitrary SQL queries, potentially stealing information from the database. The issue is fixed in version 1.4.2.

    Published: 13 Oct 2024
    5.1
    Medium

    CVE-2024-9918

    Last Modified: 19 Oct 2024

    A vulnerability has been found in HuangDou UTCMS V9 and classified as critical. This vulnerability affects the function RunSql of the file app/modules/ut-data/admin/sql.php. The manipulation of the argument sql leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 13 Oct 2024
    8.5
    High

    CVE-2024-8070

    Last Modified: 15 Apr 2026

    CWE-312: Cleartext Storage of Sensitive Information vulnerability exists that exposes test credentials in the firmware binary

    Published: 13 Oct 2024
    5.3
    Medium

    CVE-2024-9917

    Last Modified: 19 Oct 2024

    A vulnerability, which was classified as critical, was found in HuangDou UTCMS V9. This affects an unknown part of the file app/modules/ut-template/admin/template_creat.php. The manipulation of the argument content leads to deserialization. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 13 Oct 2024
    6.9
    Medium

    CVE-2024-9916

    Last Modified: 16 Oct 2024

    A vulnerability, which was classified as critical, has been found in HuangDou UTCMS V9. Affected by this issue is some unknown functionality of the file app/modules/ut-cac/admin/cli.php. The manipulation of the argument o leads to os command injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 13 Oct 2024
    8.7
    High

    CVE-2024-9915

    Last Modified: 16 Oct 2024

    A vulnerability classified as critical was found in D-Link DIR-619L B1 2.06. Affected by this vulnerability is the function formVirtualServ of the file /goform/formVirtualServ. The manipulation of the argument curTime leads to buffer overflow. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

    Published: 13 Oct 2024
    8.7
    High

    CVE-2024-9914

    Last Modified: 16 Oct 2024

    A vulnerability classified as critical has been found in D-Link DIR-619L B1 2.06. Affected is the function formSetWizardSelectMode of the file /goform/formSetWizardSelectMode. The manipulation of the argument curTime leads to buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

    Published: 13 Oct 2024
    8.7
    High

    CVE-2024-9913

    Last Modified: 16 Oct 2024

    A vulnerability was found in D-Link DIR-619L B1 2.06. It has been rated as critical. This issue affects the function formSetRoute of the file /goform/formSetRoute. The manipulation of the argument curTime leads to buffer overflow. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

    Published: 13 Oct 2024
    8.7
    High

    CVE-2024-9912

    Last Modified: 16 Oct 2024

    A vulnerability was found in D-Link DIR-619L B1 2.06. It has been declared as critical. This vulnerability affects the function formSetQoS of the file /goform/formSetQoS. The manipulation of the argument curTime leads to buffer overflow. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

    Published: 13 Oct 2024
    8.7
    High

    CVE-2024-9911

    Last Modified: 16 Oct 2024

    A vulnerability was found in D-Link DIR-619L B1 2.06. It has been classified as critical. This affects the function formSetPortTr of the file /goform/formSetPortTr. The manipulation of the argument curTime leads to buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

    Published: 13 Oct 2024
    8.7
    High

    CVE-2024-9910

    Last Modified: 16 Oct 2024

    A vulnerability was found in D-Link DIR-619L B1 2.06 and classified as critical. Affected by this issue is the function formSetPassword of the file /goform/formSetPassword. The manipulation of the argument curTime leads to buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

    Published: 13 Oct 2024
    8.7
    High

    CVE-2024-9909

    Last Modified: 16 Oct 2024

    A vulnerability has been found in D-Link DIR-619L B1 2.06 and classified as critical. Affected by this vulnerability is the function formSetMuti of the file /goform/formSetMuti. The manipulation of the argument curTime leads to buffer overflow. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

    Published: 13 Oct 2024
    7.1
    High

    CVE-2024-6959

    Last Modified: 3 Nov 2024

    A vulnerability in parisneo/lollms-webui version 9.8 allows for a Denial of Service (DOS) attack when uploading an audio file. If an attacker appends a large number of characters to the end of a multipart boundary, the system will continuously process each character, rendering lollms-webui inaccessible. This issue is exacerbated by the lack of Cross-Site Request Forgery (CSRF) protection, enabling remote exploitation. The vulnerability leads to service disruption, resource exhaustion, and extended downtime.

    Published: 13 Oct 2024
    5.1
    Medium

    CVE-2024-9908

    Last Modified: 16 Oct 2024

    A vulnerability, which was classified as critical, was found in D-Link DIR-619L B1 2.06. Affected is the function formSetMACFilter of the file /goform/formSetMACFilter. The manipulation of the argument curTime leads to buffer overflow. The exploit has been disclosed to the public and may be used.

    Published: 13 Oct 2024
    6.3
    Medium

    CVE-2024-9907

    Last Modified: 15 Apr 2026

    A vulnerability classified as problematic was found in QileCMS up to 1.1.3. This vulnerability affects the function sendEmail of the file /qilecms/user/controller/Forget.php of the component Verification Code Handler. The manipulation leads to weak password recovery. The attack can be initiated remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 13 Oct 2024
    5.3
    Medium

    CVE-2024-9906

    Last Modified: 16 Oct 2024

    A vulnerability, which was classified as problematic, was found in SourceCodester Online Eyewear Shop 1.0. Affected is an unknown function of the file /admin/?page=inventory/view_inventory&id=2. The manipulation of the argument Code leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

    Published: 13 Oct 2024
    5.3
    Medium

    CVE-2024-9905

    Last Modified: 17 Oct 2024

    A vulnerability, which was classified as critical, has been found in SourceCodester Online Eyewear Shop 1.0. This issue affects some unknown processing of the file /admin/?page=inventory/view_inventory&id=2. The manipulation of the argument id leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

    Published: 13 Oct 2024
    5.1
    Medium

    CVE-2024-9904

    Last Modified: 30 Jul 2025

    A vulnerability classified as critical was found in 07FLYCMS, 07FLY-CMS and 07FlyCRM up to 1.2.0. This vulnerability affects the function pictureUpload of the file /admin/File/pictureUpload. The manipulation of the argument file leads to unrestricted upload. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The affected product is known with different names like 07FLYCMS, 07FLY-CMS, and 07FlyCRM. It was not possible to reach out to the vendor before assigning a CVE due to a not working mail address.

    Published: 13 Oct 2024
    5.1
    Medium

    CVE-2024-9903

    Last Modified: 30 Jul 2025

    A vulnerability classified as critical has been found in 07FLYCMS, 07FLY-CMS and 07FlyCRM up to 1.2.0. This affects the function fileUpload of the file /admin/File/fileUpload. The manipulation of the argument file leads to unrestricted upload. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The affected product is known with different names like 07FLYCMS, 07FLY-CMS, and 07FlyCRM. It was not possible to reach out to the vendor before assigning a CVE due to a not working mail address.

    Published: 12 Oct 2024
    5.3
    Medium

    CVE-2024-9894

    Last Modified: 16 Oct 2024

    A vulnerability, which was classified as critical, was found in code-projects Blood Bank System 1.0. Affected is an unknown function of the file reset.php. The manipulation of the argument useremail leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

    Published: 12 Oct 2024
    5.3
    Medium

    CVE-2024-9979

    Last Modified: 15 Apr 2026

    A flaw was found in PyO3. This vulnerability causes a use-after-free issue, potentially leading to memory corruption or crashes via unsound borrowing from weak Python references.

    Published: 12 Oct 2024
    7.2
    High

    CVE-2024-8757

    Last Modified: 15 Apr 2026

    The WP Post Author – Boost Your Blog's Engagement with Author Box, Social Links, Co-Authors, Guest Authors, Post Rating System, and Custom User Registration Form Builder plugin for WordPress is vulnerable to time-based SQL Injection via the linked_user_id parameter in all versions up to, and including, 3.8.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with Administrator-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

    Published: 12 Oct 2024
    4.3
    Medium

    CVE-2024-8902

    Last Modified: 8 Apr 2026

    The Elementor Addon Elements plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.13.8 via the render_column function in modules/data-table/widgets/data-table.php. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract sensitive private, pending, and draft template data.

    Published: 12 Oct 2024
    6.4
    Medium

    CVE-2024-9595

    Last Modified: 8 Apr 2026

    The TablePress – Tables in WordPress made easy plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the table cell content in all versions up to, and including, 2.4.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 12 Oct 2024
    6.4
    Medium

    CVE-2024-9696

    Last Modified: 8 Apr 2026

    The Rescue Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'rescue_tab' shortcode in all versions up to, and including, 2.8 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 12 Oct 2024
    5.3
    Medium

    CVE-2024-8760

    Last Modified: 15 Apr 2026

    The Stackable – Page Builder Gutenberg Blocks plugin for WordPress is vulnerable to CSS Injection in all versions up to, and including, 3.13.6. This makes it possible for unauthenticated attackers to embed untrusted style information into comments resulting in a possibility of data exfiltration such as admin nonces with limited impact. These nonces could be used to perform CSRF attacks within a limited time window. The presence of other plugins may make additional nonces available, which may pose a risk in plugins that don't perform capability checks to protect AJAX actions or other actions reachable by lower-privileged users.

    Published: 12 Oct 2024
    6.4
    Medium

    CVE-2024-8915

    Last Modified: 15 Apr 2026

    The Category Icon plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.0.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses the SVG file.

    Published: 12 Oct 2024
    6.4
    Medium

    CVE-2024-9704

    Last Modified: 8 Apr 2026

    The Social Sharing (by Danny) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'dvk_social_sharing' shortcode in all versions up to, and including, 1.3.7 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 12 Oct 2024
    9.8
    Critical

    CVE-2024-9047

    Last Modified: 8 Apr 2026

    The WordPress File Upload plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 4.24.11 via wfu_file_downloader.php. This makes it possible for unauthenticated attackers to read or delete files outside of the originally intended directory. Successful exploitation requires the targeted WordPress installation to be using PHP 7.4 or earlier.

    Published: 12 Oct 2024
    4.3
    Medium

    CVE-2024-9756

    Last Modified: 25 Nov 2024

    The Order Attachments for WooCommerce plugin for WordPress is vulnerable to unauthorized limited arbitrary file uploads due to a missing capability check on the wcoa_add_attachment AJAX action in versions 2.0 to 2.4.1. This makes it possible for authenticated attackers, with subscriber-level access and above, to upload limited file types.

    Published: 12 Oct 2024
    6.1
    Medium

    CVE-2024-9670

    Last Modified: 15 Apr 2026

    The 2D Tag Cloud plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 6.0.2. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

    Published: 12 Oct 2024
    6.4
    Medium

    CVE-2024-9656

    Last Modified: 15 Apr 2026

    The Mynx Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 0.27.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses the SVG file.

    Published: 12 Oct 2024
    4.4
    Medium

    CVE-2024-9776

    Last Modified: 8 Apr 2026

    The ImagePress – Image Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.2.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.

    Published: 12 Oct 2024