CVE Feed

    Dashboard / CVE

    6.5
    Medium

    CVE-2024-46040

    Last Modified: 15 Apr 2026

    IoT Haat Smart Plug IH-IN-16A-S IH-IN-16A-S v5.16.1 suffers from Insufficient Session Expiration. The lack of validation of the authentication token at the IoT Haat during the Access Point Pairing mode leads the attacker to replay the Wi-Fi packets and forcefully turn off the access point after the authentication token has expired.

    Published: 7 Oct 2024
    6.1
    Medium

    CVE-2024-28709

    Last Modified: 25 Mar 2025

    Cross Site Scripting vulnerability in LimeSurvey before 6.5.12+240611 allows a remote attacker to execute arbitrary code via a crafted script to the title and comment fields.

    Published: 7 Oct 2024
    6.1
    Medium

    CVE-2024-28710

    Last Modified: 25 Mar 2025

    Cross Site Scripting vulnerability in LimeSurvey before 6.5.0+240319 allows a remote attacker to execute arbitrary code via a lack of input validation and output encoding in the Alert Widget's message component.

    Published: 7 Oct 2024
    8.1
    High

    CVE-2024-8926

    Last Modified: 3 Nov 2025

    In PHP versions 8.1.* before 8.1.30, 8.2.* before 8.2.24, 8.3.* before 8.3.12, when using a certain non-standard configurations of Windows codepages, the fixes for  CVE-2024-4577 https://github.com/advisories/GHSA-vxpp-6299-mxw3  may still be bypassed and the same command injection related to Windows "Best Fit" codepage behavior can be achieved. This may allow a malicious user to pass options to PHP binary being run, and thus reveal the source code of scripts, run arbitrary PHP code on the server, etc.

    Published: 7 Oct 2024
    7.5
    High

    CVE-2024-8927

    Last Modified: 3 Nov 2025

    In PHP versions 8.1.* before 8.1.30, 8.2.* before 8.2.24, 8.3.* before 8.3.12, HTTP_REDIRECT_STATUS variable is used to check whether or not CGI binary is being run by the HTTP server. However, in certain scenarios, the content of this variable can be controlled by the request submitter via HTTP headers, which can lead to cgi.force_redirect option not being correctly applied. In certain configurations this may lead to arbitrary file inclusion in PHP.

    Published: 7 Oct 2024
    6.1
    Medium

    CVE-2024-42831

    Last Modified: 15 Apr 2026

    A reflected cross-site scripting (XSS) vulnerability in Elaine's Realtime CRM Automation v6.18.17 allows attackers to execute arbitrary JavaScript code in the web browser of a user via injecting a crafted payload into the dialog parameter at wrapper_dialog.php.

    Published: 7 Oct 2024
    5.7
    Medium

    CVE-2024-44674

    Last Modified: 21 May 2025

    D-Link COVR-2600R FW101b05 is vulnerable to Buffer Overflow. In the function sub_24E28, the HTTP_REFERER is obtained through an environment variable, and this field is controllable, allowing it to be used as the value for src.

    Published: 7 Oct 2024
    4.8
    Medium

    CVE-2024-45932

    Last Modified: 11 Oct 2024

    Krayin CRM v1.3.0 is vulnerable to Cross Site Scripting (XSS) via the organization name field in /admin/contacts/organizations/edit/2.

    Published: 7 Oct 2024
    4.9
    Medium

    CVE-2024-45894

    Last Modified: 23 Apr 2025

    BlueCMS 1.6 suffers from Arbitrary File Deletion via the file_name parameter in an /admin/database.php?act=del request.

    Published: 7 Oct 2024
    6.5
    Medium

    CVE-2024-45919

    Last Modified: 3 Jul 2025

    A security flaw has been discovered in Solvait version 24.4.2 that allows an attacker to elevate their privileges. By manipulating the Request ID and Action Type parameters in /AssignToMe/SetAction, an attacker can bypass approval workflows leading to unauthorized access to sensitive information or approval of fraudulent requests.

    Published: 7 Oct 2024
    8.8
    High

    CVE-2024-46041

    Last Modified: 15 Apr 2026

    IoT Haat Smart Plug IH-IN-16A-S v5.16.1 is vulnerable to Authentication Bypass by Capture-replay.

    Published: 7 Oct 2024
    9.8
    Critical

    CVE-2024-46076

    Last Modified: 15 May 2025

    RuoYi v4.7.9 and before has a security flaw that allows escaping from comments within the code generation feature, enabling the injection of malicious code.

    Published: 7 Oct 2024
    8.7
    High

    CVE-2024-9563

    Last Modified: 8 Oct 2024

    A vulnerability, which was classified as critical, has been found in D-Link DIR-605L 2.13B01 BETA. This issue affects the function formWlanSetup_Wizard of the file /goform/formWlanSetup_Wizard. The manipulation of the argument webpage leads to buffer overflow. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

    Published: 6 Oct 2024
    8.7
    High

    CVE-2024-9562

    Last Modified: 8 Oct 2024

    A vulnerability classified as critical was found in D-Link DIR-605L 2.13B01 BETA. This vulnerability affects the function formSetWizard1/formSetWizard2. The manipulation of the argument curTime leads to buffer overflow. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

    Published: 6 Oct 2024
    8.7
    High

    CVE-2024-9561

    Last Modified: 8 Oct 2024

    A vulnerability classified as critical has been found in D-Link DIR-605L 2.13B01 BETA. This affects the function formSetWAN_Wizard51/formSetWAN_Wizard52. The manipulation of the argument curTime leads to buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

    Published: 6 Oct 2024
    5.3
    Medium

    CVE-2024-9560

    Last Modified: 5 Nov 2024

    A vulnerability was found in ESAFENET CDG V5. It has been rated as critical. Affected by this issue is the function delCatelogs of the file /CDGServer3/document/Catelogs;logindojojs?command=DelCatelogs. The manipulation of the argument id leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

    Published: 6 Oct 2024
    8.7
    High

    CVE-2024-9559

    Last Modified: 8 Oct 2024

    A vulnerability was found in D-Link DIR-605L 2.13B01 BETA. It has been classified as critical. Affected is the function formWlanSetup of the file /goform/formWlanSetup. The manipulation of the argument webpage leads to buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

    Published: 6 Oct 2024
    8.7
    High

    CVE-2024-9558

    Last Modified: 8 Oct 2024

    A vulnerability was found in D-Link DIR-605L 2.13B01 BETA and classified as critical. This issue affects the function formSetWanPPTP of the file /goform/formSetWanPPTP. The manipulation of the argument webpage leads to buffer overflow. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

    Published: 6 Oct 2024
    8.7
    High

    CVE-2024-9557

    Last Modified: 8 Oct 2024

    A vulnerability has been found in D-Link DIR-605L 2.13B01 BETA and classified as critical. This vulnerability affects the function formSetWanPPPoE of the file /goform/formSetWanPPPoE. The manipulation of the argument webpage leads to buffer overflow. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

    Published: 6 Oct 2024
    8.7
    High

    CVE-2024-9556

    Last Modified: 8 Oct 2024

    A vulnerability, which was classified as critical, was found in D-Link DIR-605L 2.13B01 BETA. This affects the function formSetEnableWizard of the file /goform/formSetEnableWizard. The manipulation of the argument curTime leads to buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

    Published: 6 Oct 2024
    8.7
    High

    CVE-2024-9555

    Last Modified: 8 Oct 2024

    A vulnerability, which was classified as critical, has been found in D-Link DIR-605L 2.13B01 BETA. Affected by this issue is the function formSetEasy_Wizard of the file /goform/formSetEasy_Wizard. The manipulation of the argument curTime leads to buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

    Published: 6 Oct 2024
    8.5
    High

    CVE-2024-47338

    Last Modified: 23 Apr 2026

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Saad Iqbal WPExperts Square For GiveWP wpexperts-square-for-give allows SQL Injection.This issue affects WPExperts Square For GiveWP: from n/a through <= 1.3.

    Published: 6 Oct 2024
    9.3
    Critical

    CVE-2024-47350

    Last Modified: 23 Apr 2026

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in YITHEMES YITH WooCommerce Ajax Search yith-woocommerce-ajax-search.This issue affects YITH WooCommerce Ajax Search: from n/a through <= 2.8.0.

    Published: 6 Oct 2024
    6.5
    Medium

    CVE-2024-47650

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Axton WP-WebAuthn wp-webauthn allows Stored XSS.This issue affects WP-WebAuthn: from n/a through <= 1.3.1.

    Published: 6 Oct 2024
    5.1
    Medium

    CVE-2024-44010

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in catchthemes Full frame full-frame allows Stored XSS.This issue affects Full frame: from n/a through <= 2.7.2.

    Published: 6 Oct 2024
    6.5
    Medium

    CVE-2024-44022

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Trustmary Review & testimonial widgets trustmary allows Stored XSS.This issue affects Review & testimonial widgets: from n/a through <= 1.0.5.

    Published: 6 Oct 2024
    6.5
    Medium

    CVE-2024-44024

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in nicheaddons Medical Addon for Elementor medical-addon-for-elementor allows Stored XSS.This issue affects Medical Addon for Elementor: from n/a through <= 1.6.4.

    Published: 6 Oct 2024
    6.5
    Medium

    CVE-2024-44025

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in nicejob NiceJob nicejob allows Stored XSS.This issue affects NiceJob: from n/a through < 3.6.5.

    Published: 6 Oct 2024
    6.5
    Medium

    CVE-2024-44026

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in nicheaddons Charity Addon for Elementor charity-addon-for-elementor allows Stored XSS.This issue affects Charity Addon for Elementor: from n/a through <= 1.3.0.

    Published: 6 Oct 2024
    6.5
    Medium

    CVE-2024-44027

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Atawai Gum Elementor Addon gum-elementor-addon allows Stored XSS.This issue affects Gum Elementor Addon: from n/a through <= 1.3.6.

    Published: 6 Oct 2024
    7.1
    High

    CVE-2024-44028

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in nicejob NiceJob nicejob allows Stored XSS.This issue affects NiceJob: from n/a through < 3.6.5.

    Published: 6 Oct 2024
    7.1
    High

    CVE-2024-44029

    Last Modified: 28 Apr 2026

    Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in David Garlitz viala allows Reflected XSS.This issue affects viala: from n/a through 1.3.1.

    Published: 6 Oct 2024
    6.5
    Medium

    CVE-2024-44032

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in nicheaddons Restaurant & Cafe Addon for Elementor restaurant-cafe-addon-for-elementor allows Stored XSS.This issue affects Restaurant & Cafe Addon for Elementor: from n/a through <= 1.5.5.

    Published: 6 Oct 2024
    9.8
    Critical

    CVE-2024-45252

    Last Modified: 15 Apr 2026

    Elsight – CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

    Published: 6 Oct 2024
    9.8
    Critical

    CVE-2024-45251

    Last Modified: 15 Apr 2026

    Elsight – CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

    Published: 6 Oct 2024
    4.3
    Medium

    CVE-2024-45250

    Last Modified: 15 Apr 2026

    ZKteco – CWE 200 Exposure of Sensitive Information to an Unauthorized Actor

    Published: 6 Oct 2024
    9.8
    Critical

    CVE-2024-45249

    Last Modified: 16 May 2025

    Cavok – CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

    Published: 6 Oct 2024
    7.5
    High

    CVE-2024-45248

    Last Modified: 15 Apr 2026

    Multi-DNC – CWE-35: Path Traversal: '.../...//'

    Published: 6 Oct 2024
    6.5
    Medium

    CVE-2024-44033

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in nicheaddons Primary Addon for Elementor primary-addon-for-elementor allows Stored XSS.This issue affects Primary Addon for Elementor: from n/a through <= 1.5.7.

    Published: 6 Oct 2024
    6.5
    Medium

    CVE-2024-44035

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Atawai Gum Elementor Addon gum-elementor-addon allows Stored XSS.This issue affects Gum Elementor Addon: from n/a through <= 1.3.7.

    Published: 6 Oct 2024
    5.9
    Medium

    CVE-2024-44036

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Pierre Lebedel Kodex Posts likes kodex-posts-likes allows Stored XSS.This issue affects Kodex Posts likes: from n/a through <= 2.5.0.

    Published: 6 Oct 2024
    5.9
    Medium

    CVE-2024-44037

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in magepeopleteam Multipurpose Ticket Booking Manager bus-booking-manager allows Stored XSS.This issue affects Multipurpose Ticket Booking Manager: from n/a through <= 4.2.2.

    Published: 6 Oct 2024
    5.9
    Medium

    CVE-2024-44039

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Travel WP Travel wp-travel allows Stored XSS.This issue affects WP Travel: from n/a through <= 9.3.1.

    Published: 6 Oct 2024
    5.9
    Medium

    CVE-2024-44040

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in plainware ShiftController Employee Shift Scheduling shiftcontroller allows Stored XSS.This issue affects ShiftController Employee Shift Scheduling: from n/a through <= 4.9.64.

    Published: 6 Oct 2024
    5.9
    Medium

    CVE-2024-44041

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Northern Beaches Websites IdeaPush ideapush allows Stored XSS.This issue affects IdeaPush: from n/a through <= 8.66.

    Published: 6 Oct 2024
    5.9
    Medium

    CVE-2024-44042

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Fahad Mahmood WP Datepicker wp-datepicker allows Stored XSS.This issue affects WP Datepicker: from n/a through <= 2.1.1.

    Published: 6 Oct 2024
    5.9
    Medium

    CVE-2024-44043

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in 10Web Photo Gallery by 10Web photo-gallery allows Stored XSS.This issue affects Photo Gallery by 10Web: from n/a through <= 1.8.27.

    Published: 6 Oct 2024
    5.9
    Medium

    CVE-2024-44045

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Kevon Adonis WP Abstracts wp-abstracts-manuscripts-manager allows Stored XSS.This issue affects WP Abstracts: from n/a through <= 2.6.5.

    Published: 6 Oct 2024
    6.1
    Medium

    CVE-2024-45247

    Last Modified: 15 Apr 2026

    Sonarr – CWE-601: URL Redirection to Untrusted Site ('Open Redirect')

    Published: 6 Oct 2024
    7.3
    High

    CVE-2024-45246

    Last Modified: 15 Apr 2026

    Diebold Nixdorf – CWE-427: Uncontrolled Search Path Element

    Published: 6 Oct 2024