CVE Feed

    Dashboard / CVE

    7.2
    High

    CVE-2024-8349

    Last Modified: 8 Apr 2026

    The Uncanny Groups for LearnDash plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 6.1.0.1. This is due to the plugin not properly restricting what users a group leader can edit. This makes it possible for authenticated attackers, with group leader-level access and above, to change admin account email addresses which can subsequently lead to admin account access.

    Published: 25 Sept 2024
    6.4
    Medium

    CVE-2024-9073

    Last Modified: 8 Apr 2026

    The GutenGeek Free Gutenberg Blocks for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.1.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses the SVG file.

    Published: 25 Sept 2024
    5.3
    Medium

    CVE-2024-7491

    Last Modified: 8 Apr 2026

    The HUSKY – Products Filter Professional for WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.3.6.1 via the woof_messenger_remove_subscr AJAX action due to missing validation on the 'key' user controlled key. This makes it possible for authenticated attackers, with subscriber-level access and above, to unsubscribe users from a product notification sign-ups, if they can successfully obtain or brute force the key value for users who signed up to receive notifications. This vulnerability requires the plugin's Products Messenger extension to be enabled.

    Published: 25 Sept 2024
    6.3
    Medium

    CVE-2024-6590

    Last Modified: 8 Apr 2026

    The Spreadsheet Integration – Automate Google Sheets With WordPress, WooCommerce & Most Popular Form Plugins. Also, Display Google sheet as a Table. plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on several functions in all versions up to, and including, 3.8.0. This makes it possible for authenticated attackers, with Subscriber-level access and above, to edit post status, edit Google sheet integrations, and create Google sheet integrations.

    Published: 25 Sept 2024
    4.3
    Medium

    CVE-2024-8434

    Last Modified: 8 Apr 2026

    The Easy Mega Menu Plugin for WordPress – ThemeHunk plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on several functions hooked via AJAX in all versions up to, and including, 1.0.9. This makes it possible for authenticated attackers, with subscriber-level access and above, to perform actions like updating plugin settings.

    Published: 25 Sept 2024
    9.8
    Critical

    CVE-2024-8485

    Last Modified: 8 Apr 2026

    The REST API TO MiniProgram plugin for WordPress is vulnerable to privilege escalation via account takeovr in all versions up to, and including, 4.7.1 via the updateUserInfo() due to missing validation on the 'openid' user controlled key that determines what user will be updated. This makes it possible for unauthenticated attackers to update arbitrary user's accounts, including their email to a @weixin.com email, which can the be leveraged to reset the password of the user's account, including administrators.

    Published: 25 Sept 2024
    6.4
    Medium

    CVE-2024-9024

    Last Modified: 8 Apr 2026

    The Material Design Icons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's mdi-icon shortcode in all versions up to, and including, 0.0.5 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 25 Sept 2024
    6.4
    Medium

    CVE-2024-9028

    Last Modified: 8 Apr 2026

    The WP GPX Maps plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'sgpx' shortcode in all versions up to, and including, 1.7.08 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 25 Sept 2024
    9.9
    Critical

    CVE-2024-8621

    Last Modified: 8 Apr 2026

    The Daily Prayer Time plugin for WordPress is vulnerable to SQL Injection via the 'max_word' attribute of the 'quran_verse' shortcode in all versions up to, and including, 2024.08.26 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with Contributor-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

    Published: 25 Sept 2024
    4.3
    Medium

    CVE-2024-8483

    Last Modified: 8 Apr 2026

    The MAS Static Content plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.0.8 via the static_content() function. This makes it possible for authenticated attackers, with contributor-level access and above, to extract potentially sensitive information from private static content pages.

    Published: 25 Sept 2024
    7.5
    High

    CVE-2024-8484

    Last Modified: 8 Apr 2026

    The REST API TO MiniProgram plugin for WordPress is vulnerable to SQL Injection via the 'order' parameter of the /wp-json/watch-life-net/v1/comment/getcomments REST API endpoint in all versions up to, and including, 4.7.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

    Published: 25 Sept 2024
    4.3
    Medium

    CVE-2024-8476

    Last Modified: 8 Apr 2026

    The Easy PayPal Events plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.2.1. This is due to missing or incorrect nonce validation on the wpeevent_plugin_buttons() function. This makes it possible for unauthenticated attackers to delete arbitrary posts via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

    Published: 25 Sept 2024
    6.1
    Medium

    CVE-2024-8713

    Last Modified: 8 Apr 2026

    The Kodex Posts likes plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 2.5.0. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

    Published: 25 Sept 2024
    6.4
    Medium

    CVE-2024-9068

    Last Modified: 8 Apr 2026

    The OneElements – Best Elementor Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.3.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses the SVG file.

    Published: 25 Sept 2024
    7.2
    High

    CVE-2024-7617

    Last Modified: 8 Apr 2026

    The Contact Form to Any API plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Contact Form 7 form fields in all versions up to, and including, 1.2.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 25 Sept 2024
    6.4
    Medium

    CVE-2024-9069

    Last Modified: 8 Apr 2026

    The Graphicsly – The ultimate graphics plugin for WordPress website builder ( Gutenberg, Elementor, Beaver Builder, WPBakery ) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.0.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses the SVG file.

    Published: 25 Sept 2024
    6.1
    Medium

    CVE-2024-8741

    Last Modified: 8 Apr 2026

    The Beam me up Scotty – Back to Top Button plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 1.0.21. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

    Published: 25 Sept 2024
    5.3
    Medium

    CVE-2024-7426

    Last Modified: 8 Apr 2026

    The Community by PeepSo – Social Network, Membership, Registration, User Profiles plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 6.4.6.0. This is due to the plugin displaying errors and allowing direct access to the sse.php file. This makes it possible for unauthenticated attackers to retrieve the full path of the web application, which can be used to aid other attacks. The information displayed is not useful on its own, and requires another vulnerability to be present for damage to an affected website.

    Published: 25 Sept 2024
    6.4
    Medium

    CVE-2024-9027

    Last Modified: 8 Apr 2026

    The WPZOOM Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'box' shortcode in all versions up to, and including, 1.0.5 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 25 Sept 2024
    6.1
    Medium

    CVE-2024-8549

    Last Modified: 8 Apr 2026

    The Simple Calendar – Google Calendar Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 3.4.2. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

    Published: 25 Sept 2024
    7.3
    High

    CVE-2024-8481

    Last Modified: 8 Apr 2026

    The The Special Text Boxes plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 6.2.4. This is due to the plugin adding the filter add_filter('comment_text', 'do_shortcode'); which will run all shortcodes in comments. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes.

    Published: 25 Sept 2024
    4.3
    Medium

    CVE-2024-7386

    Last Modified: 8 Apr 2026

    The Premium Packages – Sell Digital Products Securely plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 5.9.1. This is due to missing nonce validation on the addRefund() function. This makes it possible for unauthenticated attackers to perform actions such as initiating refunds via a forged request granted they can trick a site administrator or shop manager into performing an action such as clicking on a link.

    Published: 25 Sept 2024
    8
    High

    CVE-2024-46461

    Last Modified: 15 Apr 2026

    VLC media player 3.0.20 and earlier is vulnerable to denial of service through an integer overflow which could be triggered with a maliciously crafted mms stream (heap based overflow). If successful, a malicious third party could trigger either a crash of VLC or an arbitrary code execution with the target user's privileges.

    Published: 25 Sept 2024
    7.3
    High

    CVE-2024-45750

    Last Modified: 15 Apr 2026

    An issue in TheGreenBow Windows Standard VPN Client 6.87.108 (and older), Windows Enterprise VPN Client 6.87.109 (and older), Windows Enterprise VPN Client 7.5.007 (and older), Android VPN Client 6.4.5 (and older) VPN Client Linux 3.4 (and older), VPN Client MacOS 2.4.10 (and older) allows a remote attacker to execute arbitrary code via the IKEv2 Authentication phase, it accepts malformed ECDSA signatures and establishes the tunnel.

    Published: 25 Sept 2024
    6.1
    Medium

    CVE-2024-46655

    Last Modified: 2 Oct 2024

    A reflected cross-site scripting (XSS) vulnerability in Ellevo 6.2.0.38160 allows attackers to execute arbitrary code in the context of a user's browser via a crafted payload or URL.

    Published: 25 Sept 2024
    8.8
    High

    CVE-2024-46489

    Last Modified: 2 Oct 2024

    A remote command execution (RCE) vulnerability in promptr v6.0.7 allows attackers to execute arbitrary commands via a crafted URL.

    Published: 25 Sept 2024
    5.5
    Medium

    CVE-2024-46488

    Last Modified: 2 Oct 2024

    sqlite-vec v0.1.1 was discovered to contain a heap buffer overflow via the npy_token_next function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted file.

    Published: 25 Sept 2024
    6.3
    Medium

    CVE-2024-46485

    Last Modified: 27 May 2025

    dingfanzu CMS 1.0 was discovered to contain a Cross-Site Request Forgery (CSRF) via /admin/doAdminAction.php?act=addCate

    Published: 25 Sept 2024
    8
    High

    CVE-2024-44678

    Last Modified: 15 Apr 2026

    Gigastone TR1 Travel Router R101 v1.0.2 is vulnerable to Command Injection. This allows an authenticated attacker to execute arbitrary commands on the device by sending a crafted HTTP request to the ssid parameter in the request.

    Published: 25 Sept 2024
    4.7
    Medium

    CVE-2024-46600

    Last Modified: 27 May 2025

    dingfanzu CMS 1.0 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/doAdminAction.php?act=delCate&id=31

    Published: 25 Sept 2024
    7.5
    High

    CVE-2024-41708

    Last Modified: 15 Apr 2026

    An issue was discovered in AdaCore ada_web_services 20.0 allows an attacker to escalate privileges and steal sessions via the Random_String() function in the src/core/aws-utils.adb module.

    Published: 25 Sept 2024
    3.3
    Low

    CVE-2023-25189

    Last Modified: 15 Apr 2026

    BTS is affected by information disclosure vulnerability where mobile network operator personnel connected over BTS Web Element Manager, regardless of the access privileges, having a possibility to read BTS service operation details performed by Nokia Care service personnel via SSH.

    Published: 25 Sept 2024
    5.4
    Medium

    CVE-2023-51157

    Last Modified: 2 Oct 2024

    Cross Site Scripting vulnerability in ZKTeco WDMS v.5.1.3 Pro allows a remote attacker to execute arbitrary code and obtain sensitive information via a crafted script to the Emp Name parameter.

    Published: 25 Sept 2024
    7.5
    High

    CVE-2024-22893

    Last Modified: 13 Jun 2025

    OpenSlides 4.0.15 verifies passwords by comparing password hashes using a function with content-dependent runtime. This can allow attackers to obtain information about the password hash using a timing attack.

    Published: 25 Sept 2024
    7.5
    High

    CVE-2024-22892

    Last Modified: 14 Mar 2025

    OpenSlides 4.0.15 was discovered to be using a weak hashing algorithm to store passwords.

    Published: 25 Sept 2024
    6.5
    Medium

    CVE-2024-41445

    Last Modified: 25 Mar 2025

    Library MDF (mdflib) v2.1 is vulnerable to a heap-based buffer overread via a crafted mdf4 file is parsed using the ReadData function

    Published: 25 Sept 2024
    7.5
    High

    CVE-2024-44825

    Last Modified: 15 Apr 2026

    Directory Traversal vulnerability in Centro de Tecnologia da Informaco Renato Archer InVesalius3 v3.1.99995 allows attackers to write arbitrary files unto the system via a crafted .inv3 file.

    Published: 25 Sept 2024
    10
    Critical

    CVE-2024-45066

    Last Modified: 1 Oct 2024

    A specially crafted POST request to the ProGauge MAGLINK LX CONSOLE IP sub-menu can allow a remote attacker to inject arbitrary commands.

    Published: 24 Sept 2024
    10
    Critical

    CVE-2024-43693

    Last Modified: 1 Oct 2024

    A specially crafted POST request to the ProGauge MAGLINK LX CONSOLE UTILITY sub-menu can allow a remote attacker to inject arbitrary commands.

    Published: 24 Sept 2024
    8.7
    High

    CVE-2024-45373

    Last Modified: 1 Oct 2024

    Once logged in to ProGauge MAGLINK LX4 CONSOLE, a valid user can change their privileges to administrator.

    Published: 24 Sept 2024
    9.3
    Critical

    CVE-2024-43423

    Last Modified: 1 Oct 2024

    The web application for ProGauge MAGLINK LX4 CONSOLE contains an administrative-level user account with a password that cannot be changed.

    Published: 24 Sept 2024
    9.3
    Critical

    CVE-2024-43692

    Last Modified: 1 Oct 2024

    An attacker can directly request the ProGauge MAGLINK LX CONSOLE resource sub page with full privileges by requesting the URL directly.

    Published: 24 Sept 2024
    8.7
    High

    CVE-2024-41725

    Last Modified: 30 Sept 2024

    ProGauge MAGLINK LX CONSOLE does not have sufficient filtering on input fields that are used to render pages which may allow cross site scripting.

    Published: 24 Sept 2024
    8.7
    High

    CVE-2024-8497

    Last Modified: 15 Apr 2026

    Franklin Fueling Systems TS-550 EVO versions prior to 2.26.4.8967 possess a file that can be read arbitrarily that could allow an attacker obtain administrator credentials.

    Published: 24 Sept 2024
    —
    Unknown

    CVE-2024-9171

    Last Modified: 27 Sept 2024

    ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All references and descriptions in this candidate have been removed to prevent accidental usage.

    Published: 24 Sept 2024
    4.6
    Medium

    CVE-2024-7398

    Last Modified: 21 Jan 2025

    Concrete CMS versions 9 through 9.3.3 and versions below 8.5.19 are vulnerable to stored XSS in the calendar event addition feature because the calendar event name was not sanitized on output. Users or groups with permission to create event calendars can embed scripts, and users or groups with permission to modify event calendars can execute scripts. The Concrete CMS Security Team gave this vulnerability a CVSS v4 score of 4.6 with vector CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:A/VC:N/VI:N/VA:N/SC:L/SI:N/SA:N Thank you, Yusuke Uchida for reporting. CNA updated this risk rank on 20 Jan 2025 by lowering the AC based on CVSS 4.0 documentation that access privileges should not be considered for AC)

    Published: 24 Sept 2024
    5.1
    Medium

    CVE-2024-8291

    Last Modified: 17 Jan 2025

    Concrete CMS versions 9.0.0 to 9.3.3 and below 8.5.19 are vulnerable to Stored XSS in Image Editor Background Color.  A rogue admin could add malicious code to the Thumbnails/Add-Type. The Concrete CMS Security Team gave this a CVSS v4 score of 5.1 with vector https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:H/AT:N/PR:H/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N. Thanks,  Alexey Solovyev for reporting. (CNA updated this risk rank on 17 Jan 2025 by lowering the AC based on CVSS 4.0 documentation that access privileges should not be considered for AC).

    Published: 24 Sept 2024
    —
    Unknown

    CVE-2024-9168

    Last Modified: 14 Apr 2026

    ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All references and descriptions in this candidate have been removed to prevent accidental usage.

    Published: 24 Sept 2024
    8.8
    High

    CVE-2024-9123

    Last Modified: 20 Nov 2025

    Integer overflow in Skia in Google Chrome prior to 129.0.6668.70 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: High)

    Published: 24 Sept 2024
    8.8
    High

    CVE-2024-9122

    Last Modified: 2 Jan 2025

    Type Confusion in V8 in Google Chrome prior to 129.0.6668.70 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High)

    Published: 24 Sept 2024