CVE Feed

    Dashboard / CVE

    6.3
    Medium

    CVE-2024-7858

    Last Modified: 8 Apr 2026

    The Media Library Folders plugin for WordPress is vulnerable to unauthorized access due to missing capability checks on several AJAX functions in the media-library-plus.php file in all versions up to, and including, 8.2.3. This makes it possible for authenticated attackers, with subscriber-level access and above, to perform several actions related to managing media files and folder along with controlling settings.

    Published: 30 Aug 2024
    8.8
    High

    CVE-2024-8252

    Last Modified: 8 Apr 2026

    The Clean Login plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.14.5 via the 'template' attribute of the clean-login-register shortcode. This makes it possible for authenticated attackers, with Contributor-level access and above, to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where images and other “safe” file types can be uploaded and included.

    Published: 30 Aug 2024
    6.1
    Medium

    CVE-2024-8274

    Last Modified: 8 Apr 2026

    The WP Booking Calendar plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via several parameters from 'timeline_obj' in all versions up to, and including, 10.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

    Published: 30 Aug 2024
    6.4
    Medium

    CVE-2024-7122

    Last Modified: 8 Apr 2026

    The Elementor Addon Elements plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple widgets in all versions up to, and including, 1.13.6 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 30 Aug 2024
    4.3
    Medium

    CVE-2024-8319

    Last Modified: 8 Apr 2026

    The Tourfic plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.11.20. This is due to missing or incorrect nonce validation on the tf_order_status_email_resend_function, tf_visitor_details_edit_function, tf_checkinout_details_edit_function, tf_order_status_edit_function, tf_order_bulk_action_edit_function, tf_remove_room_order_ids, and tf_delete_old_review_fields functions. This makes it possible for unauthenticated attackers to resend order status emails, update visitor/order details, edit check-in/out details, edit order status, perform bulk order status updates, remove room order IDs, and delete old review fields, respectively, via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

    Published: 30 Aug 2024
    9.1
    Critical

    CVE-2024-8016

    Last Modified: 8 Apr 2026

    The Events Calendar Pro plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 7.0.2 via deserialization of untrusted input from the 'filters' parameter in widgets. This makes it possible for authenticated attackers, with administrator-level access and above, to inject a PHP Object. The additional presence of a POP chain allows attackers to execute code remotely. In certain configurations, this can be exploitable by lower level users. We confirmed that this plugin installed with Elementor makes it possible for users with contributor-level access and above to exploit this issue.

    Published: 30 Aug 2024
    3.7
    Low

    CVE-2024-39300

    Last Modified: 21 Oct 2024

    Missing authentication vulnerability exists in Telnet function of WAB-I1750-PS v1.5.10 and earlier. When Telnet function of the product is enabled, a remote attacker may login to the product without authentication and alter the product's settings.

    Published: 30 Aug 2024
    6.1
    Medium

    CVE-2024-34577

    Last Modified: 12 May 2026

    Cross-site scripting vulnerability exists in WRC-X3000GS2-B, WRC-X3000GS2-W, WRC-X3000GS2A-B and WRC-X3000GST2-B due to improper processing of input values in easysetup.cgi. If a user views a malicious web page while logged in to the product, an arbitrary script may be executed on the user's web browser.

    Published: 30 Aug 2024
    6.1
    Medium

    CVE-2024-42412

    Last Modified: 19 Sept 2025

    Cross-site scripting vulnerability exists in ELECOM wireless access points due to improper processing of input values in menu.cgi. If a user views a malicious web page while logged in to the product, an arbitrary script may be executed on the user's web browser.

    Published: 30 Aug 2024
    9.1
    Critical

    CVE-2024-3673

    Last Modified: 16 May 2025

    The Web Directory Free WordPress plugin before 1.7.3 does not validate a parameter before using it in an include(), which could lead to Local File Inclusion issues.

    Published: 30 Aug 2024
    —
    Unknown

    CVE-2024-8333

    Last Modified: 30 Aug 2024

    Test CVE

    Published: 30 Aug 2024
    6.4
    Medium

    CVE-2024-5879

    Last Modified: 8 Apr 2026

    The HubSpot – CRM, Email Marketing, Live Chat, Forms & Analytics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'url' attribute of the HubSpot Meeting Widget in all versions up to, and including, 11.1.22 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 30 Aug 2024
    8.8
    High

    CVE-2024-2694

    Last Modified: 8 Apr 2026

    The Betheme theme for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 27.5.6 via deserialization of untrusted input of the 'mfn-page-items' post meta value. This makes it possible for authenticated attackers, with contributor-level access and above, to inject a PHP Object. No known POP chain is present in the vulnerable plugin. If a POP chain is present via an additional plugin or theme installed on the target system, it could allow the attacker to delete arbitrary files, retrieve sensitive data, or execute code.

    Published: 30 Aug 2024
    6.4
    Medium

    CVE-2024-3998

    Last Modified: 8 Apr 2026

    The Betheme theme for WordPress is vulnerable to Stored Cross-Site Scripting via several of the plugin's shortcodes in all versions up to, and including, 27.5.6 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 30 Aug 2024
    6.4
    Medium

    CVE-2024-4401

    Last Modified: 8 Apr 2026

    The Elementor Addon Elements plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘id’ and 'eae_slider_animation' parameters in all versions up to, and including, 1.13.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 30 Aug 2024
    7.1
    High

    CVE-2024-5784

    Last Modified: 8 Apr 2026

    The Tutor LMS Pro plugin for WordPress is vulnerable to unauthorized administrative actions execution due to a missing capability checks on multiple functions like treport_quiz_atttempt_delete and tutor_gc_class_action in all versions up to, and including, 2.7.2. This makes it possible for authenticated attackers, with the subscriber-level access and above, to preform an administrative actions on the site, like comments, posts or users deletion, viewing notifications, etc.

    Published: 30 Aug 2024
    6.1
    Medium

    CVE-2024-5024

    Last Modified: 8 Apr 2026

    The Memberpress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'mepr_screenname' and 'mepr_key' parameter in all versions up to, and including, 1.11.29 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

    Published: 30 Aug 2024
    6.4
    Medium

    CVE-2024-5061

    Last Modified: 8 Apr 2026

    The Enfold - Responsive Multi-Purpose Theme theme for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘wrapper_class’ and 'class' parameters in all versions up to, and including, 6.0.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 30 Aug 2024
    8.8
    High

    CVE-2024-8330

    Last Modified: 5 Sept 2024

    6SHR system from Gether Technology does not properly validate uploaded file types, allowing remote attackers with regular privileges to upload web shell scripts and use them to execute arbitrary system commands on the server.

    Published: 30 Aug 2024
    8.8
    High

    CVE-2024-8329

    Last Modified: 5 Sept 2024

    6SHR system from Gether Technology does not properly validate the specific page parameter, allowing remote attackers with regular privilege to inject SQL command to read, modify, and delete database contents.

    Published: 30 Aug 2024
    5.4
    Medium

    CVE-2024-8328

    Last Modified: 4 Sept 2024

    Easy test Online Learning and Testing Platform from HWA JIUH DIGITAL TECHNOLOGY does not properly validate a specific page parameter, allowing remote attackers with regular privilege to inject arbitrary JavaScript code and perform Reflected Cross-site scripting attacks.

    Published: 30 Aug 2024
    8.8
    High

    CVE-2024-8327

    Last Modified: 4 Sept 2024

    Easy test Online Learning and Testing Platform from HWA JIUH DIGITAL TECHNOLOGY does not properly validate a specific page parameter, allowing remote attackers with regular privilege to inject arbitrary SQL commands to read, modify, and delete database contents.

    Published: 30 Aug 2024
    7.5
    High

    CVE-2024-8234

    Last Modified: 22 Jan 2025

    ** UNSUPPORTED WHEN ASSIGNED ** A command injection vulnerability in the functions formSysCmd(), formUpgradeCert(), and formDelcert() in the Zyxel NWA1100-N firmware version 1.00(AACE.1)C0 could allow an unauthenticated attacker to execute some OS commands to access system files on an affected device.

    Published: 30 Aug 2024
    9.8
    Critical

    CVE-2024-45488

    Last Modified: 15 Apr 2026

    One Identity Safeguard for Privileged Passwords before 7.5.2 allows unauthorized access because of an issue related to cookies. This only affects virtual appliance installations (VMware or HyperV). The fixed versions are 7.0.5.1 LTS, 7.4.2, and 7.5.2.

    Published: 30 Aug 2024
    9.8
    Critical

    CVE-2024-45492

    Last Modified: 12 May 2026

    An issue was discovered in libexpat before 2.6.3. nextScaffoldPart in xmlparse.c can have an integer overflow for m_groupSize on 32-bit platforms (where UINT_MAX equals SIZE_MAX).

    Published: 30 Aug 2024
    9.8
    Critical

    CVE-2024-45491

    Last Modified: 12 May 2026

    An issue was discovered in libexpat before 2.6.3. dtdCopy in xmlparse.c can have an integer overflow for nDefaultAtts on 32-bit platforms (where UINT_MAX equals SIZE_MAX).

    Published: 30 Aug 2024
    5.5
    Medium

    CVE-2024-44944

    Last Modified: 12 May 2026

    In the Linux kernel, the following vulnerability has been resolved: netfilter: ctnetlink: use helper function to calculate expect ID Delete expectation path is missing a call to the nf_expect_get_id() helper function to calculate the expectation ID, otherwise LSB of the expectation object address is leaked to userspace.

    Published: 30 Aug 2024
    6.1
    Medium

    CVE-2024-44682

    Last Modified: 14 Mar 2025

    ShopXO 6.2 is vulnerable to Cross Site Scripting (XSS) in the backend that allows attackers to execute code by changing POST parameters.

    Published: 30 Aug 2024
    6.1
    Medium

    CVE-2024-44683

    Last Modified: 20 Mar 2025

    Seacms v13 is vulnerable to Cross Site Scripting (XSS) via admin-video.php.

    Published: 30 Aug 2024
    6.1
    Medium

    CVE-2024-44684

    Last Modified: 19 Mar 2025

    TpMeCMS 1.3.3.2 is vulnerable to Cross Site Scripting (XSS) in /h.php/page?ref=addtabs via the "Title," "Images," and "Content" fields.

    Published: 30 Aug 2024
    7.2
    High

    CVE-2024-44916

    Last Modified: 28 Mar 2025

    Vulnerability in admin_ip.php in Seacms v13.1, when action=set, allows attackers to control IP parameters that are written to the data/admin/ip.php file and could result in arbitrary command execution.

    Published: 30 Aug 2024
    3.5
    Low

    CVE-2024-44918

    Last Modified: 28 Mar 2025

    A cross-site scripting (XSS) vulnerability in the component admin_datarelate.php of SeaCMS v12.9 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.

    Published: 30 Aug 2024
    7.5
    High

    CVE-2024-45490

    Last Modified: 12 May 2026

    An issue was discovered in libexpat before 2.6.3. xmlparse.c does not reject a negative length for XML_ParseBuffer.

    Published: 30 Aug 2024
    5.5
    Medium

    CVE-2022-48944

    Last Modified: 4 May 2025

    In the Linux kernel, the following vulnerability has been resolved: sched: Fix yet more sched_fork() races Where commit 4ef0c5c6b5ba ("kernel/sched: Fix sched_fork() access an invalid sched_task_group") fixed a fork race vs cgroup, it opened up a race vs syscalls by not placing the task on the runqueue before it gets exposed through the pidhash. Commit 13765de8148f ("sched/fair: Fix fault in reweight_entity") is trying to fix a single instance of this, instead fix the whole class of issues, effectively reverting this commit.

    Published: 30 Aug 2024
    6.7
    Medium

    CVE-2024-2881

    Last Modified: 4 Sept 2024

    Fault Injection vulnerability in wc_ed25519_sign_msg function in wolfssl/wolfcrypt/src/ed25519.c in WolfSSL wolfssl5.6.6 on Linux/Windows allows remote attacker co-resides in the same system with a victim process to disclose information and escalate privileges via Rowhammer fault injection to the ed25519_key structure.

    Published: 29 Aug 2024
    5.9
    Medium

    CVE-2024-1545

    Last Modified: 27 Jan 2026

    Fault Injection vulnerability in RsaPrivateDecryption function in wolfssl/wolfcrypt/src/rsa.c in WolfSSL wolfssl5.6.6 on Linux/Windows allows remote attacker co-resides in the same system with a victim process to disclose information and escalate privileges via Rowhammer fault injection to the RsaKey structure.

    Published: 29 Aug 2024
    8.8
    High

    CVE-2024-6672

    Last Modified: 4 Sept 2024

    In WhatsUp Gold versions released before 2024.0.0, a SQL Injection vulnerability allows an authenticated low-privileged attacker to achieve privilege escalation by modifying a privileged user's password.

    Published: 29 Aug 2024
    2
    Low

    CVE-2024-2502

    Last Modified: 15 Apr 2026

    An application can be configured to block boot attempts after consecutive tamper resets are detected, which may not occur as expected. This is possible because the TAMPERRSTCAUSE register may not be properly updated when a level 4 tamper event (a tamper reset) occurs. This impacts Series 2 HSE-SVH devices, including xG23B, xG24B, xG25B, and xG28B, but does not impact xG21B. To mitigate this issue, upgrade to SE Firmware version 2.2.6 or later.

    Published: 29 Aug 2024
    9.8
    Critical

    CVE-2024-6671

    Last Modified: 25 Sept 2024

    In WhatsUp Gold versions released before 2024.0.0, if the application is configured with only a single user, a SQL Injection vulnerability allows an unauthenticated attacker to retrieve the users encrypted password.

    Published: 29 Aug 2024
    9.8
    Critical

    CVE-2024-6670

    Last Modified: 31 Oct 2025

    In WhatsUp Gold versions released before 2024.0.0, a SQL Injection vulnerability allows an unauthenticated attacker to retrieve the users encrypted password.

    Published: 29 Aug 2024
    6.1
    Medium

    CVE-2024-45302

    Last Modified: 1 Oct 2024

    RestSharp is a Simple REST and HTTP API Client for .NET. The second argument to `RestRequest.AddHeader` (the header value) is vulnerable to CRLF injection. The same applies to `RestRequest.AddOrUpdateHeader` and `RestClient.AddDefaultHeader`. The way HTTP headers are added to a request is via the `HttpHeaders.TryAddWithoutValidation` method which does not check for CRLF characters in the header value. This means that any headers from a `RestSharp.RequestHeaders` object are added to the request in such a way that they are vulnerable to CRLF-injection. In general, CRLF-injection into a HTTP header (when using HTTP/1.1) means that one can inject additional HTTP headers or smuggle whole HTTP requests. If an application using the RestSharp library passes a user-controllable value through to a header, then that application becomes vulnerable to CRLF-injection. This is not necessarily a security issue for a command line application like the one above, but if such code were present in a web application then it becomes vulnerable to request splitting (as shown in the PoC) and thus Server Side Request Forgery. Strictly speaking this is a potential vulnerability in applications using RestSharp, not in RestSharp itself, but I would argue that at the very least there needs to be a warning about this behaviour in the RestSharp documentation. RestSharp has addressed this issue in version 112.0.0. All users are advised to upgrade. There are no known workarounds for this vulnerability.

    Published: 29 Aug 2024
    5.5
    Medium

    CVE-2024-34018

    Last Modified: 12 Sept 2024

    Sensitive information disclosure due to insecure folder permissions. The following products are affected: Acronis Snap Deploy (Windows) before build 4569.

    Published: 29 Aug 2024
    7.3
    High

    CVE-2024-34017

    Last Modified: 12 Sept 2024

    Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis Snap Deploy (Windows) before build 4569.

    Published: 29 Aug 2024
    7.3
    High

    CVE-2024-34019

    Last Modified: 12 Sept 2024

    Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis Snap Deploy (Windows) before build 4569.

    Published: 29 Aug 2024
    4.1
    Medium

    CVE-2024-1543

    Last Modified: 4 Sept 2024

    The side-channel protected T-Table implementation in wolfSSL up to version 5.6.5 protects against a side-channel attacker with cache-line resolution. In a controlled environment such as Intel SGX, an attacker can gain a per instruction sub-cache-line resolution allowing them to break the cache-line-level protection. For details on the attack refer to: https://doi.org/10.46586/tches.v2024.i1.457-500

    Published: 29 Aug 2024
    5.4
    Medium

    CVE-2024-43947

    Last Modified: 16 Jan 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Dinesh Karki WP Armour Extended.This issue affects WP Armour Extended: from n/a through 1.26.

    Published: 29 Aug 2024
    6.5
    Medium

    CVE-2024-43920

    Last Modified: 4 Sept 2024

    Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Jegstudio Gutenverse allows Stored XSS.This issue affects Gutenverse: from n/a through 1.9.4.

    Published: 29 Aug 2024
    7.1
    High

    CVE-2024-43921

    Last Modified: 4 Sept 2024

    Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Magic Post Thumbnail allows Reflected XSS.This issue affects Magic Post Thumbnail: from n/a through 5.2.9.

    Published: 29 Aug 2024
    7.1
    High

    CVE-2024-43926

    Last Modified: 2 Jan 2025

    Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in The Beaver Builder Team Beaver Builder allows Reflected XSS.This issue affects Beaver Builder: from n/a through 2.8.3.2.

    Published: 29 Aug 2024
    6.5
    Medium

    CVE-2024-43934

    Last Modified: 3 Sept 2024

    Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Robert Felty Collapsing Archives allows Stored XSS.This issue affects Collapsing Archives: from n/a through 3.0.5.

    Published: 29 Aug 2024