CVE Feed

    Dashboard / CVE

    5.5
    Medium

    CVE-2024-41175

    Last Modified: 12 Sept 2024

    The IPC-Diagnostics package included in TwinCAT/BSD is vulnerable to a local denial-of-service attack by a low privileged attacker.

    Published: 27 Aug 2024
    7.3
    High

    CVE-2024-41174

    Last Modified: 28 Jan 2025

    The IPC-Diagnostics package in TwinCAT/BSD is susceptible to improper input neutralization by a low-privileged local attacker.

    Published: 27 Aug 2024
    7.8
    High

    CVE-2024-41173

    Last Modified: 12 Sept 2024

    The IPC-Diagnostics package included in TwinCAT/BSD is vulnerable to a local authentication bypass by a low privileged attacker.

    Published: 27 Aug 2024
    5.9
    Medium

    CVE-2024-7608

    Last Modified: 15 Apr 2026

    An authenticated user can access the restricted files from NX, EX, FX, AX, IVX and CMS using path traversal.

    Published: 27 Aug 2024
    6.4
    Medium

    CVE-2024-8046

    Last Modified: 15 Apr 2026

    The Logo Showcase Ultimate – Logo Carousel, Logo Slider & Logo Grid plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.4.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses the SVG file.

    Published: 27 Aug 2024
    6.4
    Medium

    CVE-2024-7304

    Last Modified: 8 Apr 2026

    The Ninja Tables – Easiest Data Table Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 5.0.12 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses the SVG file.

    Published: 27 Aug 2024
    6.4
    Medium

    CVE-2024-6804

    Last Modified: 8 Apr 2026

    The Jeg Elementor Kit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 2.6.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses the SVG file.

    Published: 27 Aug 2024
    4.3
    Medium

    CVE-2024-6688

    Last Modified: 15 Apr 2026

    The Oxygen Builder plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the oxy_save_css_from_admin AJAX action in all versions up to, and including, 4.8.3. This makes it possible for authenticated attackers, with Subscriber-level access and above, to update stylesheets.

    Published: 27 Aug 2024
    7.8
    High

    CVE-2024-7125

    Last Modified: 21 Jan 2025

    Authentication Bypass vulnerability in Hitachi Ops Center Common Services.This issue affects Hitachi Ops Center Common Services: from 10.9.3-00 before 11.0.2-01.

    Published: 27 Aug 2024
    4.8
    Medium

    CVE-2022-39996

    Last Modified: 30 Aug 2024

    Cross Site Scripting vulnerability in Teldats Router RS123, RS123w allows attacker to execute arbitrary code via the cmdcookie parameter to the upgrade/query.php page.

    Published: 27 Aug 2024
    9.8
    Critical

    CVE-2024-36068

    Last Modified: 5 Sept 2024

    An incorrect access control vulnerability in Rubrik CDM versions prior to 9.1.2-p1, 9.0.3-p6 and 8.1.3-p12, allows an attacker with network access to execute arbitrary code.

    Published: 27 Aug 2024
    6.5
    Medium

    CVE-2024-40395

    Last Modified: 25 Mar 2025

    An Insecure Direct Object Reference (IDOR) in PTC ThingWorx v9.5.0 allows attackers to view sensitive information, including PII, regardless of access level.

    Published: 27 Aug 2024
    9.8
    Critical

    CVE-2024-41622

    Last Modified: 30 Aug 2024

    D-Link DIR-846W A1 FW100A43 was discovered to contain a remote command execution (RCE) vulnerability via the tomography_ping_address parameter in /HNAP1/ interface.

    Published: 27 Aug 2024
    7.8
    High

    CVE-2024-42851

    Last Modified: 30 Aug 2024

    Buffer Overflow vulnerability in open source exiftags v.1.01 allows a local attacker to execute arbitrary code via the paresetag function.

    Published: 27 Aug 2024
    8.8
    High

    CVE-2024-44340

    Last Modified: 30 Aug 2024

    D-Link DIR-846W A1 FW100A43 was discovered to contain a remote command execution (RCE) vulnerability via keys smartqos_express_devices and smartqos_normal_devices in SetSmartQoSSettings.

    Published: 27 Aug 2024
    9.8
    Critical

    CVE-2024-44341

    Last Modified: 30 Aug 2024

    D-Link DIR-846W A1 FW100A43 was discovered to contain a remote command execution (RCE) vulnerability via the lan(0)_dhcps_staticlist parameter. This vulnerability is exploited via a crafted POST request.

    Published: 27 Aug 2024
    9.8
    Critical

    CVE-2024-44342

    Last Modified: 30 Aug 2024

    D-Link DIR-846W A1 FW100A43 was discovered to contain a remote command execution (RCE) vulnerability via the wl(0).(0)_ssid parameter. This vulnerability is exploited via a crafted POST request.

    Published: 27 Aug 2024
    8.8
    High

    CVE-2024-45264

    Last Modified: 30 Aug 2024

    A cross-site request forgery (CSRF) vulnerability in the admin panel in SkySystem Arfa-CMS before 5.1.3124 allows remote attackers to add a new administrator, leading to escalation of privileges.

    Published: 27 Aug 2024
    8.1
    High

    CVE-2024-45321

    Last Modified: 5 Dec 2024

    The App::cpanminus package through 1.7047 for Perl downloads code via insecure HTTP, enabling code execution for network attackers.

    Published: 27 Aug 2024
    5.9
    Medium

    CVE-2024-8285

    Last Modified: 20 Nov 2025

    A flaw was found in Kroxylicious. When establishing the connection with the upstream Kafka server using a TLS secured connection, Kroxylicious fails to properly verify the server's hostname, resulting in an insecure connection. For a successful attack to be performed, the attacker needs to perform a Man-in-the-Middle attack or compromise any external systems, such as DNS or network routing configuration. This issue is considered a high complexity attack, with additional high privileges required, as the attack would need access to the Kroxylicious configuration or a peer system. The result of a successful attack impacts both data integrity and confidentiality.

    Published: 27 Aug 2024
    8
    High

    CVE-2022-39997

    Last Modified: 15 Apr 2026

    A weak password requirement issue was discovered in Teldats Router RS123, RS123w allows a remote attacker to escalate privileges

    Published: 27 Aug 2024
    4.3
    Medium

    CVE-2024-45036

    Last Modified: 15 Apr 2026

    Tophat is a mobile applications testing harness. An Improper Access Control vulnerability can expose the `TOPHAT_APP_TOKEN` token stored in `~/.tophatrc` through use of a malicious Tophat URL controlled by the attacker. The vulnerability allows Tophat to send this token to the attacker's server without any checks to ensure that the server is trusted. This token can then be used to access internal build artifacts, for mobile applications, not intended to be public. The issue has been patched as of version 1.10.0. The ability to request artifacts using a Tophat API has been deprecated as this flow was inherently insecure. Systems that have implemented this kind of endpoint should cease use and invalidate the token immediately. There are no workarounds and all users should update as soon as possible.

    Published: 26 Aug 2024
    8.6
    High

    CVE-2024-43798

    Last Modified: 15 Apr 2026

    Chisel is a fast TCP/UDP tunnel, transported over HTTP, secured via SSH. The Chisel server doesn't ever read the documented `AUTH` environment variable used to set credentials, which allows any unauthenticated user to connect, even if credentials were set. Anyone running the Chisel server that is using the `AUTH` environment variable to specify credentials to authenticate against is affected by this vulnerability. Chisel is often used to provide an entrypoint to a private network, which means services that are gated by Chisel may be affected. Additionally, Chisel is often used for exposing services to the internet. An attacker could MITM requests by connecting to a Chisel server and requesting to forward traffic from a remote port. This issue has been addressed in release version 1.10.0. All users are advised to upgrade. There are no known workarounds for this vulnerability.

    Published: 26 Aug 2024
    5.4
    Medium

    CVE-2024-39628

    Last Modified: 9 Jan 2025

    Cross-Site Request Forgery (CSRF) vulnerability in Saturday Drive Ninja Forms allows Cross Site Request Forgery.This issue affects Ninja Forms: from n/a through 3.8.6.

    Published: 26 Aug 2024
    4.3
    Medium

    CVE-2024-39641

    Last Modified: 18 Sept 2024

    Cross-Site Request Forgery (CSRF) vulnerability in ThimPress LearnPress.This issue affects LearnPress: from n/a through 4.2.6.8.2.

    Published: 26 Aug 2024
    5.4
    Medium

    CVE-2024-39645

    Last Modified: 18 Sept 2024

    Cross-Site Request Forgery (CSRF) vulnerability in Themeum Tutor LMS.This issue affects Tutor LMS: from n/a through 2.7.2.

    Published: 26 Aug 2024
    4.3
    Medium

    CVE-2024-39657

    Last Modified: 18 Sept 2024

    Cross-Site Request Forgery (CSRF) vulnerability in Sender Sender – Newsletter, SMS and Email Marketing Automation for WooCommerce.This issue affects Sender – Newsletter, SMS and Email Marketing Automation for WooCommerce: from n/a through 2.6.18.

    Published: 26 Aug 2024
    4.3
    Medium

    CVE-2024-43116

    Last Modified: 18 Sept 2024

    Cross-Site Request Forgery (CSRF) vulnerability in 10up Simple Local Avatars.This issue affects Simple Local Avatars: from n/a through 2.7.10.

    Published: 26 Aug 2024
    4.3
    Medium

    CVE-2024-43117

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in WPMU DEV - Your All-in-One WordPress Platform Hummingbird hummingbird-performance.This issue affects Hummingbird: from n/a through <= 3.9.1.

    Published: 26 Aug 2024
    4.3
    Medium

    CVE-2024-43265

    Last Modified: 12 Sept 2024

    Cross-Site Request Forgery (CSRF) vulnerability in Analytify.This issue affects Analytify: from n/a through 5.3.1.

    Published: 26 Aug 2024
    4.3
    Medium

    CVE-2024-43269

    Last Modified: 12 Sept 2024

    Cross-Site Request Forgery (CSRF) vulnerability in WPBackItUp Backup and Restore WordPress.This issue affects Backup and Restore WordPress: from n/a through 1.50.

    Published: 26 Aug 2024
    4.3
    Medium

    CVE-2024-43287

    Last Modified: 12 Sept 2024

    Cross-Site Request Forgery (CSRF) vulnerability in Brevo Newsletter, SMTP, Email marketing and Subscribe forms by Sendinblue.This issue affects Newsletter, SMTP, Email marketing and Subscribe forms by Sendinblue: from n/a through 3.1.82.

    Published: 26 Aug 2024
    4.3
    Medium

    CVE-2024-43295

    Last Modified: 12 Sept 2024

    Cross-Site Request Forgery (CSRF) vulnerability in Passionate Programmers B.V. WP Data Access.This issue affects WP Data Access: from n/a through 5.5.7.

    Published: 26 Aug 2024
    5.4
    Medium

    CVE-2024-43299

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Softaculous SpeedyCache speedycache.This issue affects SpeedyCache: from n/a through <= 1.1.8.

    Published: 26 Aug 2024
    7.1
    High

    CVE-2024-43301

    Last Modified: 23 Jan 2025

    Cross-Site Request Forgery (CSRF) vulnerability in Fonts Plugin Fonts allows Stored XSS.This issue affects Fonts: from n/a through 3.7.7.

    Published: 26 Aug 2024
    5.3
    Medium

    CVE-2024-43316

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Checkout Plugins Stripe Payments For WooCommerce by Checkout.This issue affects Stripe Payments For WooCommerce by Checkout: from n/a through 1.9.1.

    Published: 26 Aug 2024
    4.3
    Medium

    CVE-2024-43325

    Last Modified: 12 Sept 2024

    Cross-Site Request Forgery (CSRF) vulnerability in Naiche Dark Mode for WP Dashboard.This issue affects Dark Mode for WP Dashboard: from n/a through 1.2.3.

    Published: 26 Aug 2024
    4.3
    Medium

    CVE-2024-43336

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in WP User Manager WP User Manager wp-user-manager.This issue affects WP User Manager: from n/a through <= 2.9.10.

    Published: 26 Aug 2024
    4.3
    Medium

    CVE-2024-43337

    Last Modified: 27 Aug 2024

    Cross-Site Request Forgery (CSRF) vulnerability in Brave Brave Popup Builder.This issue affects Brave Popup Builder: from n/a through 0.7.0.

    Published: 26 Aug 2024
    4.3
    Medium

    CVE-2024-43340

    Last Modified: 27 Aug 2024

    Cross-Site Request Forgery (CSRF) vulnerability in Nasirahmed Advanced Form Integration.This issue affects Advanced Form Integration: from n/a through 1.89.4.

    Published: 26 Aug 2024
    5.5
    Medium

    CVE-2024-43915

    Last Modified: 28 Aug 2024

    Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Dylan James Zephyr Project Manager allows Reflected XSS.This issue affects Zephyr Project Manager: from n/a through .3.102.

    Published: 26 Aug 2024
    4.3
    Medium

    CVE-2024-43356

    Last Modified: 27 Aug 2024

    Cross-Site Request Forgery (CSRF) vulnerability in bobbingwide.This issue affects oik: from n/a through 4.12.0.

    Published: 26 Aug 2024
    7.1
    High

    CVE-2024-43255

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in zookatron MyBookTable Bookstore mybooktable.This issue affects MyBookTable Bookstore: from n/a through <= 3.3.9.

    Published: 26 Aug 2024
    5.4
    Medium

    CVE-2024-43339

    Last Modified: 27 Aug 2024

    Cross-Site Request Forgery (CSRF) vulnerability in WebinarPress allows Cross-Site Scripting (XSS).This issue affects WebinarPress: from n/a through 1.33.20.

    Published: 26 Aug 2024
    4.3
    Medium

    CVE-2024-43916

    Last Modified: 12 Sept 2024

    Authorization Bypass Through User-Controlled Key vulnerability in Dylan James Zephyr Project Manager.This issue affects Zephyr Project Manager: from n/a through 3.3.102.

    Published: 26 Aug 2024
    5.3
    Medium

    CVE-2024-43214

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in Saad Iqbal myCred mycred.This issue affects myCred: from n/a through <= 2.7.2.

    Published: 26 Aug 2024
    5.3
    Medium

    CVE-2024-43230

    Last Modified: 23 Apr 2026

    Insertion of Sensitive Information Into Sent Data vulnerability in Anssi Laitila Shared Files shared-files.This issue affects Shared Files: from n/a through <= 1.7.28.

    Published: 26 Aug 2024
    6.5
    Medium

    CVE-2024-43251

    Last Modified: 17 Sept 2024

    Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Bit Apps Bit Form Pro.This issue affects Bit Form Pro: from n/a through 2.6.4.

    Published: 26 Aug 2024
    6.5
    Medium

    CVE-2024-43257

    Last Modified: 12 Sept 2024

    Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Nouthemes Leopard - WordPress offload media.This issue affects Leopard - WordPress offload media: from n/a through 2.0.36.

    Published: 26 Aug 2024
    5.3
    Medium

    CVE-2024-43258

    Last Modified: 12 Sept 2024

    Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Store Locator Plus.This issue affects Store Locator Plus: from n/a through 2311.17.01.

    Published: 26 Aug 2024