CVE-2024-2033
Last Modified: 15 Apr 2026The Video Conferencing with Zoom plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.4.5 via the get_assign_host_id AJAX action. This makes it possible for authenticated attackers, with subscriber access or higher, to enumerate usernames, emails and IDs of all users on a site.
CVE-2024-2302
Last Modified: 8 Apr 2026The Easy Digital Downloads – Sell Digital Files & Subscriptions (eCommerce Store + Payments Made Easy) plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.2.9. This makes it possible for unauthenticated attackers to download the debug log via Directory Listing. This file may include PII.
CVE-2024-2185
Last Modified: 8 Apr 2026The Beaver Builder Addons by WPZOOM plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Image Box widget in all versions up to, and including, 1.3.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
CVE-2024-1852
Last Modified: 8 Apr 2026The WP-Members Membership Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the X-Forwarded-For header in all versions up to, and including, 3.4.9.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page which is the edit users page. This vulnerability was partially patched in version 3.4.9.2, and was fully patched in 3.4.9.3.
CVE-2024-2187
Last Modified: 8 Apr 2026The Beaver Builder Addons by WPZOOM plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Testimonials widget in all versions up to, and including, 1.3.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
CVE-2024-2918
Last Modified: 28 Mar 2025Improper input validation in PAM JIT elevation feature in Devolutions Server 2024.1.6 and earlier allows an attacker with access to the PAM JIT elevation feature to forge the displayed group in the PAM JIT elevation checkout request via a specially crafted request.
CVE-2024-31457
Last Modified: 15 Apr 2026gin-vue-admin is a backstage management system based on vue and gin, which separates the front and rear of the full stack. gin-vue-admin pseudoversion 0.0.0-20240407133540-7bc7c3051067, corresponding to version 2.6.1, has a code injection vulnerability in the backend. In the Plugin System -> Plugin Template feature, an attacker can perform directory traversal by manipulating the `plugName` parameter. They can create specific folders such as `api`, `config`, `global`, `model`, `router`, `service`, and `main.go` function within the specified traversal directory. Moreover, the Go files within these folders can have arbitrary code inserted based on a specific PoC parameter. The main reason for the existence of this vulnerability is the controllability of the PlugName field within the struct. Pseudoversion 0.0.0-20240409100909-b1b7427c6ea6, corresponding to commit b1b7427c6ea6c7a027fa188c6be557f3795e732b, contains a patch for the issue. As a workaround, one may manually use a filtering method available in the GitHub Security Advisory to rectify the directory traversal problem.
CVE-2024-25116
Last Modified: 15 Apr 2026RedisBloom adds a set of probabilistic data structures to Redis. Starting in version 2.0.0 and prior to version 2.4.7 and 2.6.10, authenticated users can use the `CF.RESERVE` command to trigger a runtime assertion and termination of the Redis server process. The problem is fixed in RedisBloom 2.4.7 and 2.6.10.
CVE-2024-25115
Last Modified: 15 Apr 2026RedisBloom adds a set of probabilistic data structures to Redis. Starting in version 2.0.0 and prior to version 2.4.7 and 2.6.10, specially crafted `CF.LOADCHUNK` commands may be used by authenticated users to perform heap overflow, which may lead to remote code execution. The problem is fixed in RedisBloom 2.4.7 and 2.6.10.
CVE-2024-22423
Last Modified: 5 Jan 2026yt-dlp is a youtube-dl fork with additional features and fixes. The patch that addressed CVE-2023-40581 attempted to prevent RCE when using `--exec` with `%q` by replacing double quotes with two double quotes. However, this escaping is not sufficient, and still allows expansion of environment variables. Support for output template expansion in `--exec`, along with this vulnerable behavior, was added to `yt-dlp` in version 2021.04.11. yt-dlp version 2024.04.09 fixes this issue by properly escaping `%`. It replaces them with `%%cd:~,%`, a variable that expands to nothing, leaving only the leading percent. It is recommended to upgrade yt-dlp to version 2024.04.09 as soon as possible. Also, always be careful when using `--exec`, because while this specific vulnerability has been patched, using unvalidated input in shell commands is inherently dangerous. For Windows users who are not able to upgrade, avoid using any output template expansion in `--exec` other than `{}` (filepath); if expansion in `--exec` is needed, verify the fields you are using do not contain `"`, `|` or `&`; and/or instead of using `--exec`, write the info json and load the fields from it instead.
CVE-2024-31454
Last Modified: 15 Apr 2026PsiTransfer is an open source, self-hosted file sharing solution. Prior to version 2.2.0, the absence of restrictions on the endpoint, which is designed for uploading files, allows an attacker who received the id of a file distribution to change the files that are in this distribution. The vulnerability allows an attacker to influence those users who come to the file distribution after them and slip the victim files with a malicious or phishing signature. Version 2.2.0 contains a patch for this issue. CVE-2024-31454 allows users to violate the integrity of a file that is uploaded by another user. In this case, additional files are not loaded into the file bucket. Violation of integrity at the level of individual files. While the vulnerability with the number CVE-2024-31453 allows users to violate the integrity of a file bucket without violating the integrity of files uploaded by other users. Thus, vulnerabilities are reproduced differently, require different security recommendations and affect different objects of the application’s business logic.
CVE-2024-27242
Last Modified: 31 Jul 2025Cross site scripting in Zoom Desktop Client for Linux before version 5.17.10 may allow an authenticated user to conduct a denial of service via network access.
CVE-2024-27247
Last Modified: 31 Jul 2025Improper privilege management in the installer for Zoom Desktop Client for macOS before version 5.17.10 may allow a privileged user to conduct an escalation of privilege via local access.
CVE-2024-24694
Last Modified: 31 Jul 2025Improper privilege management in the installer for Zoom Desktop Client for Windows before version 5.17.10 may allow an authenticated user to conduct an escalation of privilege via local access.
CVE-2024-31453
Last Modified: 15 Apr 2026PsiTransfer is an open source, self-hosted file sharing solution. Prior to version 2.2.0, the absence of restrictions on the endpoint, which allows users to create a path for uploading a file in a file distribution, allows an attacker to add arbitrary files to the distribution. The vulnerability allows an attacker to influence those users who come to the file distribution after them and slip the victim files with a malicious or phishing signature. Version 2.2.0 contains a patch for the issue. CVE-2024-31453 allows users to violate the integrity of a file bucket and upload new files there, while the vulnerability with the number CVE-2024-31454 allows users to violate the integrity of a single file that is uploaded by another user by writing data there and not allows you to upload new files to the bucket. Thus, vulnerabilities are reproduced differently, require different security recommendations and affect different objects of the application’s business logic.
CVE-2024-29993
Last Modified: 3 May 2025Azure CycleCloud Elevation of Privilege Vulnerability
CVE-2024-29992
Last Modified: 24 Sept 2026Azure Identity Library for .NET Information Disclosure Vulnerability
CVE-2024-29989
Last Modified: 3 May 2025Azure Monitor Agent Elevation of Privilege Vulnerability
CVE-2024-29985
Last Modified: 3 May 2025Microsoft OLE DB Driver for SQL Server Remote Code Execution Vulnerability
CVE-2024-29984
Last Modified: 3 May 2025Microsoft OLE DB Driver for SQL Server Remote Code Execution Vulnerability
CVE-2024-29983
Last Modified: 3 May 2025Microsoft OLE DB Driver for SQL Server Remote Code Execution Vulnerability
CVE-2024-29982
Last Modified: 3 May 2025Microsoft OLE DB Driver for SQL Server Remote Code Execution Vulnerability
CVE-2024-20670
Last Modified: 3 May 2025Outlook for Windows Spoofing Vulnerability
CVE-2024-29062
Last Modified: 3 May 2025Secure Boot Security Feature Bypass Vulnerability
CVE-2024-29061
Last Modified: 3 May 2025Secure Boot Security Feature Bypass Vulnerability
CVE-2024-29056
Last Modified: 3 May 2025Windows Authentication Elevation of Privilege Vulnerability
CVE-2024-29054
Last Modified: 3 May 2025Microsoft Defender for IoT Elevation of Privilege Vulnerability
CVE-2024-29055
Last Modified: 3 May 2025Microsoft Defender for IoT Elevation of Privilege Vulnerability
CVE-2024-29053
Last Modified: 3 May 2025Microsoft Defender for IoT Remote Code Execution Vulnerability
CVE-2024-29052
Last Modified: 27 Aug 2025Windows Storage Elevation of Privilege Vulnerability
CVE-2024-29048
Last Modified: 3 May 2025Microsoft OLE DB Driver for SQL Server Remote Code Execution Vulnerability
CVE-2024-29046
Last Modified: 3 May 2025Microsoft OLE DB Driver for SQL Server Remote Code Execution Vulnerability
CVE-2024-29044
Last Modified: 3 May 2025Microsoft OLE DB Driver for SQL Server Remote Code Execution Vulnerability
CVE-2024-28944
Last Modified: 3 May 2025Microsoft OLE DB Driver for SQL Server Remote Code Execution Vulnerability
CVE-2024-28943
Last Modified: 3 May 2025Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability
CVE-2024-28941
Last Modified: 3 May 2025Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability
CVE-2024-28940
Last Modified: 3 May 2025Microsoft OLE DB Driver for SQL Server Remote Code Execution Vulnerability
CVE-2024-28938
Last Modified: 3 May 2025Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability
CVE-2024-28937
Last Modified: 3 May 2025Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability
CVE-2024-28935
Last Modified: 3 May 2025Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability
CVE-2024-28934
Last Modified: 3 May 2025Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability
CVE-2024-28933
Last Modified: 3 May 2025Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability
CVE-2024-28930
Last Modified: 3 May 2025Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability
CVE-2024-28927
Last Modified: 3 May 2025Microsoft OLE DB Driver for SQL Server Remote Code Execution Vulnerability
CVE-2024-28926
Last Modified: 3 May 2025Microsoft OLE DB Driver for SQL Server Remote Code Execution Vulnerability
CVE-2024-28917
Last Modified: 3 May 2025Azure Arc-enabled Kubernetes Extension Cluster-Scope Elevation of Privilege Vulnerability
CVE-2024-28907
Last Modified: 3 May 2025Microsoft Brokering File System Elevation of Privilege Vulnerability
CVE-2024-28904
Last Modified: 3 May 2025Microsoft Brokering File System Elevation of Privilege Vulnerability
CVE-2024-28900
Last Modified: 3 May 2025Windows Remote Access Connection Manager Information Disclosure Vulnerability
CVE-2024-28897
Last Modified: 3 May 2025Secure Boot Security Feature Bypass Vulnerability
