9.3
    Critical

    CVE-2024-50491

    Last Modified: 23 Apr 2026

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in MicahBlu RSVP ME rsvp-me allows SQL Injection.This issue affects RSVP ME: from n/a through <= 1.9.9.

    Published:28 Oct 2024
    9.8
    Critical

    CVE-2024-50490

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in lowcage PegaPoll pegapoll allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects PegaPoll: from n/a through <= 1.0.2.

    Published:29 Oct 2024
    8.8
    High

    CVE-2024-50488

    Last Modified: 23 Apr 2026

    Authentication Bypass Using an Alternate Path or Channel vulnerability in yespbs Token Login token-login allows Authentication Bypass.This issue affects Token Login: from n/a through <= 1.0.3.

    Published:28 Oct 2024
    9.8
    Critical

    CVE-2024-50485

    Last Modified: 23 Apr 2026

    Incorrect Privilege Assignment vulnerability in Udit Rawat Exam Matrix exam-matrix allows Privilege Escalation.This issue affects Exam Matrix: from n/a through <= 1.5.

    Published:29 Oct 2024
    9.8
    Critical

    CVE-2024-50483

    Last Modified: 23 Apr 2026

    Authorization Bypass Through User-Controlled Key vulnerability in Tareq Hasan Meetup meetup allows Privilege Escalation.This issue affects Meetup: from n/a through <= 0.1.

    Published:28 Oct 2024
    10
    Critical

    CVE-2024-50482

    Last Modified: 23 Apr 2026

    Unrestricted Upload of File with Dangerous Type vulnerability in Chetan Khandla Woocommerce Product Design woo-product-design allows Upload a Web Shell to a Web Server.This issue affects Woocommerce Product Design: from n/a through <= 1.0.0.

    Published:29 Oct 2024
    9.8
    Critical

    CVE-2024-50478

    Last Modified: 28 Apr 2026

    Authentication Bypass by Primary Weakness vulnerability in Swoop 1-Click Login: Passwordless Authentication allows Authentication Bypass.This issue affects 1-Click Login: Passwordless Authentication: 1.4.5.

    Published:28 Oct 2024
    9.8
    Critical

    CVE-2024-50477

    Last Modified: 8 Jul 2025

    Authentication Bypass Using an Alternate Path or Channel vulnerability in Stacks Stacks Mobile App Builder stacks-mobile-app-builder allows Authentication Bypass.This issue affects Stacks Mobile App Builder: from n/a through <= 5.2.3.

    Source:stealthcopter
    Published:28 Oct 2024
    9.8
    Critical

    CVE-2024-50476

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in GRÜN Software Group GmbH GRÜN spendino Spendenformular spendino allows Privilege Escalation.This issue affects GRÜN spendino Spendenformular: from n/a through <= 1.0.1.

    Published:29 Oct 2024
    9.8
    Critical

    CVE-2024-50475

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in Scott Gamon Signup Page signup-page allows Privilege Escalation.This issue affects Signup Page: from n/a through <= 1.0.

    Published:29 Oct 2024
    10
    Critical

    CVE-2024-50473

    Last Modified: 23 Apr 2026

    Unrestricted Upload of File with Dangerous Type vulnerability in Ajar Productions Ajar in5 Embed ajar-productions-in5-embed allows Upload a Web Shell to a Web Server.This issue affects Ajar in5 Embed: from n/a through <= 3.1.3.

    Published:29 Oct 2024
    7.3
    High

    CVE-2024-50450

    Last Modified: 23 Apr 2026

    Improper Control of Generation of Code ('Code Injection') vulnerability in RealMag777 MDTF wp-meta-data-filter-and-taxonomy-filter allows Code Injection.This issue affects MDTF: from n/a through <= 1.3.3.4.

    Published:28 Oct 2024
    9.9
    Critical

    CVE-2024-50427

    Last Modified: 23 Apr 2026

    Unrestricted Upload of File with Dangerous Type vulnerability in devsoftbaltic SurveyJS surveyjs.This issue affects SurveyJS: from n/a through <= 1.9.136.

    Published:29 Oct 2024
    6.8
    Medium

    CVE-2024-50404

    Last Modified: 10 Dec 2025

    A link following vulnerability has been reported to affect Qsync Central. If exploited, the vulnerability could allow remote attackers who have gained user access to traverse the file system to unintended locations. We have already fixed the vulnerability in the following versions: Qsync Central 4.4.0.16_20240819 ( 2024/08/19 ) and later

    Published:6 Dec 2024
    6.9
    Medium

    CVE-2024-50395

    Last Modified: 8 Dec 2025

    An authorization bypass through user-controlled key vulnerability has been reported to affect Media Streaming add-on. If exploited, the vulnerability could allow local network attackers to gain privilege. We have already fixed the vulnerability in the following version: Media Streaming add-on 500.1.1.6 ( 2024/08/02 ) and later

    Published:22 Nov 2024
    9.8
    Critical

    CVE-2024-50379

    Last Modified: 3 Nov 2025

    Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability during JSP compilation in Apache Tomcat permits an RCE on case insensitive file systems when the default servlet is enabled for write (non-default configuration). This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.1, from 10.1.0-M1 through 10.1.33, from 9.0.0.M1 through 9.0.97. The following versions were EOL at the time the CVE was created but are known to be affected: 8.5.0 though 8.5.100. Other, older, EOL versions may also be affected. Users are recommended to upgrade to version 11.0.2, 10.1.34 or 9.0.98, which fixes the issue.

    Published:17 Dec 2024
    7.3
    High

    CVE-2024-50340

    Last Modified: 15 Apr 2026

    symfony/runtime is a module for the Symphony PHP framework which enables decoupling PHP applications from global state. When the `register_argv_argc` php directive is set to `on` , and users call any URL with a special crafted query string, they are able to change the environment or debug mode used by the kernel when handling the request. As of versions 5.4.46, 6.4.14, and 7.1.7 the `SymfonyRuntime` now ignores the `argv` values for non-SAPI PHP runtimes. All users are advised to upgrade. There are no known workarounds for this vulnerability.

    Published:6 Nov 2024
    4.9
    Medium

    CVE-2024-50335

    Last Modified: 8 Nov 2024

    SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. The "Publish Key" field in SuiteCRM's Edit Profile page is vulnerable to Reflected Cross-Site Scripting (XSS), allowing an attacker to inject malicious JavaScript code. This can be exploited to steal CSRF tokens and perform unauthorized actions, such as creating new administrative users without proper authentication. The vulnerability arises due to insufficient input validation and sanitization of the Publish Key field within the SuiteCRM application. When an attacker injects a malicious script, it gets executed within the context of an authenticated user's session. The injected script (o.js) then leverages the captured CSRF token to forge requests that create new administrative users, effectively compromising the integrity and security of the CRM instance. This issue has been addressed in versions 7.14.6 and 8.7.1. Users are advised to upgrade. There are no known workarounds for this vulnerability.

    Published:5 Nov 2024
    9.8
    Critical

    CVE-2024-50330

    Last Modified: 23 Apr 2025

    SQL injection in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allows a remote unauthenticated attacker to achieve remote code execution.

    Published:12 Nov 2024
    6.2
    Medium

    CVE-2024-50251

    Last Modified: 12 May 2026

    In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_payload: sanitize offset and length before calling skb_checksum() If access to offset + length is larger than the skbuff length, then skb_checksum() triggers BUG_ON(). skb_checksum() internally subtracts the length parameter while iterating over skbuff, BUG_ON(len) at the end of it checks that the expected length to be included in the checksum calculation is fully consumed.

    Published:9 Nov 2024
    6.3
    Medium

    CVE-2024-50050

    Last Modified: 15 Apr 2026

    Llama Stack prior to revision 7a8aa775e5a267cf8660d83140011a0b7f91e005 used pickle as a serialization format for socket communication, potentially allowing for remote code execution. Socket communication has been changed to use JSON instead.

    Published:23 Oct 2024
    7.8
    High

    CVE-2024-49882

    Last Modified: 12 May 2026

    In the Linux kernel, the following vulnerability has been resolved: ext4: fix double brelse() the buffer of the extents path In ext4_ext_try_to_merge_up(), set path[1].p_bh to NULL after it has been released, otherwise it may be released twice. An example of what triggers this is as follows: split2 map split1 |--------|-------|--------| ext4_ext_map_blocks ext4_ext_handle_unwritten_extents ext4_split_convert_extents // path->p_depth == 0 ext4_split_extent // 1. do split1 ext4_split_extent_at |ext4_ext_insert_extent | ext4_ext_create_new_leaf | ext4_ext_grow_indepth | le16_add_cpu(&neh->eh_depth, 1) | ext4_find_extent | // return -ENOMEM |// get error and try zeroout |path = ext4_find_extent | path->p_depth = 1 |ext4_ext_try_to_merge | ext4_ext_try_to_merge_up | path->p_depth = 0 | brelse(path[1].p_bh) ---> not set to NULL here |// zeroout success // 2. update path ext4_find_extent // 3. do split2 ext4_split_extent_at ext4_ext_insert_extent ext4_ext_create_new_leaf ext4_ext_grow_indepth le16_add_cpu(&neh->eh_depth, 1) ext4_find_extent path[0].p_bh = NULL; path->p_depth = 1 read_extent_tree_block ---> return err // path[1].p_bh is still the old value ext4_free_ext_path ext4_ext_drop_refs // path->p_depth == 1 brelse(path[1].p_bh) ---> brelse a buffer twice Finally got the following WARRNING when removing the buffer from lru: ============================================ VFS: brelse: Trying to free free buffer WARNING: CPU: 2 PID: 72 at fs/buffer.c:1241 __brelse+0x58/0x90 CPU: 2 PID: 72 Comm: kworker/u19:1 Not tainted 6.9.0-dirty #716 RIP: 0010:__brelse+0x58/0x90 Call Trace: <TASK> __find_get_block+0x6e7/0x810 bdev_getblk+0x2b/0x480 __ext4_get_inode_loc+0x48a/0x1240 ext4_get_inode_loc+0xb2/0x150 ext4_reserve_inode_write+0xb7/0x230 __ext4_mark_inode_dirty+0x144/0x6a0 ext4_ext_insert_extent+0x9c8/0x3230 ext4_ext_map_blocks+0xf45/0x2dc0 ext4_map_blocks+0x724/0x1700 ext4_do_writepages+0x12d6/0x2a70 [...] ============================================

    Published:21 Oct 2024
    Unknown

    CVE-2024-49746

    https://github.com/michalbednarski/ThisSeemsWrong

    8.8
    High

    CVE-2024-49699

    Last Modified: 23 Apr 2026

    Deserialization of Untrusted Data vulnerability in reputeinfosystems ARPrice arprice allows Object Injection.This issue affects ARPrice: from n/a through <= 4.1.3.

    Published:21 Jan 2025
    9.3
    Critical

    CVE-2024-49681

    Last Modified: 23 Apr 2026

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in activity-log.com WP Sessions Time Monitoring Full Automatic activitytime allows SQL Injection.This issue affects WP Sessions Time Monitoring Full Automatic: from n/a through <= 1.0.9.

    Published:24 Oct 2024
    10
    Critical

    CVE-2024-49668

    Last Modified: 23 Apr 2026

    Unrestricted Upload of File with Dangerous Type vulnerability in christopherdewese1099 Verbalize WP verbalize-wp allows Upload a Web Shell to a Web Server.This issue affects Verbalize WP: from n/a through <= 1.0.

    Published:23 Oct 2024
    9.9
    Critical

    CVE-2024-49653

    Last Modified: 23 Apr 2026

    Unrestricted Upload of File with Dangerous Type vulnerability in james-eggers Portfolleo portfolleo allows Upload a Web Shell to a Web Server.This issue affects Portfolleo: from n/a through <= 1.2.

    Published:23 Oct 2024
    10
    Critical

    CVE-2024-49607

    Last Modified: 23 Apr 2026

    Unrestricted Upload of File with Dangerous Type vulnerability in redhopit WP Dropbox Dropins wp-dropbox-dropins allows Upload a Web Shell to a Web Server.This issue affects WP Dropbox Dropins: from n/a through <= 1.0.

    Published:20 Oct 2024
    5.3
    Medium

    CVE-2024-49379

    Last Modified: 15 Apr 2026

    Umbrel is a home server OS for self-hosting. The login functionality of Umbrel before version 1.2.2 contains a reflected cross-site scripting (XSS) vulnerability in use-auth.tsx. An attacker can specify a malicious redirect query parameter to trigger the vulnerability. If a JavaScript URL is passed to the redirect parameter the attacker provided JavaScript will be executed after the user entered their password and clicked on login. This vulnerability is fixed in 1.2.2.

    Published:13 Nov 2024
    9.1
    Critical

    CVE-2024-49375

    Last Modified: 15 Apr 2026

    Open source machine learning framework. A vulnerability has been identified in Rasa that enables an attacker who has the ability to load a maliciously crafted model remotely into a Rasa instance to achieve Remote Code Execution. The prerequisites for this are: 1. The HTTP API must be enabled on the Rasa instance eg with `--enable-api`. This is not the default configuration. 2. For unauthenticated RCE to be exploitable, the user must not have configured any authentication or other security controls recommended in our documentation. 3. For authenticated RCE, the attacker must posses a valid authentication token or JWT to interact with the Rasa API. This issue has been addressed in rasa version 3.6.21 and all users are advised to upgrade. Users unable to upgrade should ensure that they require authentication and that only trusted users are given access.

    Published:14 Jan 2025
    9.8
    Critical

    CVE-2024-49369

    Last Modified: 26 Nov 2025

    Icinga is a monitoring system which checks the availability of network resources, notifies users of outages, and generates performance data for reporting. The TLS certificate validation in all Icinga 2 versions starting from 2.4.0 was flawed, allowing an attacker to impersonate both trusted cluster nodes as well as any API users that use TLS client certificates for authentication (ApiUser objects with the client_cn attribute set). This vulnerability has been fixed in v2.14.3, v2.13.10, v2.12.11, and v2.11.12.

    Published:12 Nov 2024
    8.9
    High

    CVE-2024-49368

    Last Modified: 6 Nov 2024

    Nginx UI is a web user interface for the Nginx web server. Prior to version 2.0.0-beta.36, when Nginx UI configures logrotate, it does not verify the input and directly passes it to exec.Command, causing arbitrary command execution. Version 2.0.0-beta.36 fixes this issue.

    Published:21 Oct 2024
    9.8
    Critical

    CVE-2024-49328

    Last Modified: 23 Apr 2026

    Authentication Bypass Using an Alternate Path or Channel vulnerability in vivek2tamrakar WP REST API FNS rest-api-fns allows Authentication Bypass.This issue affects WP REST API FNS: from n/a through <= 1.0.0.

    Published:20 Oct 2024
    7.8
    High

    CVE-2024-49138

    Last Modified: 22 Apr 2025

    Windows Common Log File System Driver Elevation of Privilege Vulnerability

    Source:Milad karimi
    Published:10 Dec 2024
    8.8
    High

    CVE-2024-49117

    Last Modified: 9 Jun 2026

    Windows Hyper-V Remote Code Execution Vulnerability

    Published:10 Dec 2024
    7.5
    High

    CVE-2024-49113

    Last Modified: 9 Jun 2026

    Windows Lightweight Directory Access Protocol (LDAP) Denial of Service Vulnerability

    Published:10 Dec 2024
    9.8
    Critical

    CVE-2024-49112

    Last Modified: 9 Jun 2026

    Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability

    Published:10 Dec 2024
    8.8
    High

    CVE-2024-49039

    Last Modified: 28 Oct 2025

    Windows Task Scheduler Elevation of Privilege Vulnerability

    Published:12 Nov 2024
    7.8
    High

    CVE-2024-49019

    Last Modified: 8 Jul 2025

    Active Directory Certificate Services Elevation of Privilege Vulnerability

    Published:12 Nov 2024
    7.8
    High

    CVE-2024-48990

    Last Modified: 3 Nov 2025

    Qualys discovered that needrestart, before version 3.8, allows local attackers to execute arbitrary code as root by tricking needrestart into running the Python interpreter with an attacker-controlled PYTHONPATH environment variable.

    Published:19 Nov 2024
    8.1
    High

    CVE-2024-48955

    Last Modified: 15 Apr 2026

    Broken access control in NetAdmin 4.030319 returns data with functionalities on the endpoint that "assembles" the functionalities menus, the return of this call is not encrypted and as the system does not validate the session authorization, an attacker can copy the content of the browser of a user with greater privileges having access to the functionalities of the user that the code was copied.

    Published:29 Oct 2024
    9.1
    Critical

    CVE-2024-48914

    Last Modified: 15 Apr 2026

    Vendure is an open-source headless commerce platform. Prior to versions 3.0.5 and 2.3.3, a vulnerability in Vendure's asset server plugin allows an attacker to craft a request which is able to traverse the server file system and retrieve the contents of arbitrary files, including sensitive data such as configuration files, environment variables, and other critical data stored on the server. In the same code path is an additional vector for crashing the server via a malformed URI. Patches are available in versions 3.0.5 and 2.3.3. Some workarounds are also available. One may use object storage rather than the local file system, e.g. MinIO or S3, or define middleware which detects and blocks requests with urls containing `/../`.

    Published:15 Oct 2024
    9.1
    Critical

    CVE-2024-48910

    Last Modified: 3 Nov 2025

    DOMPurify is a DOM-only, super-fast, uber-tolerant XSS sanitizer for HTML, MathML and SVG. DOMPurify was vulnerable to prototype pollution. This vulnerability is fixed in 2.4.2.

    Published:31 Oct 2024
    9.3
    Critical

    CVE-2024-48887

    Last Modified: 26 Feb 2026

    A unverified password change vulnerability in Fortinet FortiSwitch GUI may allow a remote unauthenticated attacker to change admin passwords via a specially crafted request

    Published:8 Apr 2025
    6.9
    Medium

    CVE-2024-48852

    Last Modified: 11 Apr 2025

    Insertion of Sensitive Information into Log File vulnerability observed in FLEXON. Some information may be improperly disclosed through https access. This issue affects FLXEON through <= 9.3.4.

    Source:LiquidWorm
    Published:29 Jan 2025
    8.8
    High

    CVE-2024-48849

    Last Modified: 11 Apr 2025

    Missing Origin Validation in WebSockets vulnerability in FLXEON. Session management was not sufficient to prevent unauthorized HTTPS requests. This issue affects FLXEON: through <= 9.3.4.

    Source:LiquidWorm
    Published:29 Jan 2025
    7.1
    High

    CVE-2024-48846

    Last Modified: 16 Apr 2025

    Cross Site Request Forgery vulnerabilities where found providing a potiential for exposing sensitive information or changing system settings.  Affected products: ABB ASPECT - Enterprise v3.08.02; NEXUS Series v3.08.02; MATRIX Series v3.08.02

    Source:LiquidWorm
    Published:5 Dec 2024
    9.3
    Critical

    CVE-2024-48845

    Last Modified: 15 Apr 2025

    Weak Password Reset Rules vulnerabilities where found providing a potiential for the storage of weak passwords that could facilitate unauthorized admin/application access.  Affected products: ABB ASPECT - Enterprise v3.07.02; NEXUS Series v3.07.02; MATRIX Series v3.07.02

    Source:LiquidWorm
    Published:5 Dec 2024
    7.2
    High

    CVE-2024-48844

    Last Modified: 15 Apr 2025

    Denial of Service vulnerabilities where found providing a potiential for device service disruptions.  Affected products: ABB ASPECT - Enterprise v3.08.02; NEXUS Series v3.08.02; MATRIX Series v3.08.02

    Source:LiquidWorm
    Published:5 Dec 2024
    10
    Critical

    CVE-2024-48841

    Last Modified: 11 Apr 2025

    Network access can be used to execute arbitrary code with elevated privileges. This issue affects FLXEON 9.3.4 and older.

    Source:LiquidWorm
    Published:27 Jan 2025
    Items Per Page