Latest CVE Feed
-
7.2
HIGHCVE-2024-12686
A vulnerability has been discovered in Privileged Remote Access (PRA) and Remote Support (RS) which can allow an attacker with existing administrative privileges to inject commands and run as a site user.... Read more
- Actively Exploited
- Published: Dec. 18, 2024
- Modified: Jan. 14, 2025
-
7.1
HIGHCVE-2024-53271
Envoy is a cloud-native high-performance edge/middle/service proxy. In affected versions envoy does not properly handle http 1.1 non-101 1xx responses. This can lead to downstream failures in networked devices. This issue has been addressed in versions 1... Read more
Affected Products : envoy- Published: Dec. 18, 2024
- Modified: Sep. 04, 2025
-
7.5
HIGHCVE-2024-53270
Envoy is a cloud-native high-performance edge/middle/service proxy. In affected versions `sendOverloadError` is going to assume the active request exists when `envoy.load_shed_points.http1_server_abort_dispatch` is configured. If `active_request` is nullp... Read more
Affected Products : envoy- Published: Dec. 18, 2024
- Modified: Sep. 04, 2025
-
7.5
HIGHCVE-2024-53269
Envoy is a cloud-native high-performance edge/middle/service proxy. When additional address are not ip addresses, then the Happy Eyeballs sorting algorithm will crash in data plane. This issue has been addressed in releases 1.32.2, 1.31.4, and 1.30.8. Use... Read more
Affected Products : envoy- Published: Dec. 18, 2024
- Modified: Aug. 28, 2025
-
5.1
MEDIUMCVE-2024-52593
Misskey is an open source, federated social media platform.In affected versions missing validation in `NoteCreateService.insertNote`, `ApPersonService.createPerson`, and `ApPersonService.updatePerson` allows an attacker to control the target of any "origi... Read more
Affected Products : misskey- Published: Dec. 18, 2024
- Modified: Dec. 18, 2024
-
6.9
MEDIUMCVE-2024-52592
Misskey is an open source, federated social media platform. In affected versions missing validation in `ApInboxService.update` allows an attacker to modify the result of polls belonging to another user. No authentication is required, except for a valid si... Read more
Affected Products : misskey- Published: Dec. 18, 2024
- Modified: Dec. 18, 2024
-
8.8
HIGHCVE-2024-52591
Misskey is an open source, federated social media platform. In affected versions missing validation in `ApRequestService.signedGet` and `HttpRequestService.getActivityJson` allows an attacker to create fake user profiles and forged notes. The spoofed user... Read more
Affected Products : misskey- Published: Dec. 18, 2024
- Modified: Dec. 18, 2024
-
8.8
HIGHCVE-2024-52590
Misskey is an open source, federated social media platform. In affected versions missing validation in `ApRequestService.signedGet` allows an attacker to create fake user profiles that appear to be from a different instance than the one where they actuall... Read more
Affected Products : misskey- Published: Dec. 18, 2024
- Modified: Dec. 18, 2024
-
6.4
MEDIUMCVE-2024-52579
Misskey is an open source, federated social media platform. Some APIs using `HttpRequestService` do not properly check the target host. This vulnerability allows an attacker to send POST or GET requests to the internal server, which may result in a SSRF a... Read more
Affected Products : misskey- Published: Dec. 18, 2024
- Modified: Dec. 18, 2024
-
6.5
MEDIUMCVE-2024-51470
IBM MQ 9.1 LTS, 9.2 LTS, 9.3 LTS, 9.3 CD, 9.4 LTS, 9.4 CD, IBM MQ Appliance 9.3 LTS, 9.3 CD, 9.4 LTS, and IBM MQ for HPE NonStop 8.1.0 through 8.1.0.25 could allow an authenticated user to cause a denial-of-service due to messages with improperly set valu... Read more
- Published: Dec. 18, 2024
- Modified: Aug. 15, 2025
-
7.4
HIGHCVE-2024-49363
Misskey is an open source, federated social media platform. In affected versions FileServerService (media proxy) in github.com/misskey-dev/misskey 2024.10.1 or earlier did not detect proxy loops, which allows remote actors to execute a self-propagating re... Read more
Affected Products : misskey- Published: Dec. 18, 2024
- Modified: Dec. 18, 2024
-
7.2
HIGHCVE-2024-36694
OpenCart 4.0.2.3 is vulnerable to Server-Side Template Injection (SSTI) via the Theme Editor Function.... Read more
Affected Products : opencart- Published: Dec. 18, 2024
- Modified: Apr. 22, 2025
-
8.4
HIGHCVE-2024-12741
A deserialization of untrusted data vulnerability exists in NI DAQExpress that may result in remote code execution. Successful exploitation requires an attacker to get a user to open a specially crafted project file. This vulnerability affects DAQExpress ... Read more
Affected Products :- Published: Dec. 18, 2024
- Modified: Dec. 18, 2024
-
9.9
CRITICALCVE-2024-56057
Unrestricted Upload of File with Dangerous Type vulnerability in VibeThemes WPLMS allows Upload a Web Shell to a Web Server.This issue affects WPLMS: from n/a before 1.9.9.5.2.... Read more
Affected Products : wordpress_learning_management_system_- Published: Dec. 18, 2024
- Modified: Dec. 18, 2024
-
8.5
HIGHCVE-2024-56055
Path Traversal: '.../...//' vulnerability in VibeThemes WPLMS allows Path Traversal.This issue affects WPLMS: from n/a before 1.9.9.5.2.... Read more
Affected Products : wordpress_learning_management_system_- Published: Dec. 18, 2024
- Modified: Dec. 18, 2024
-
9.1
CRITICALCVE-2024-56054
Unrestricted Upload of File with Dangerous Type vulnerability in VibeThemes WPLMS allows Upload a Web Shell to a Web Server.This issue affects WPLMS: from n/a before 1.9.9.5.2.... Read more
Affected Products : wordpress_learning_management_system_- Published: Dec. 18, 2024
- Modified: Dec. 18, 2024
-
7.6
HIGHCVE-2024-56053
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in VibeThemes WPLMS allows SQL Injection.This issue affects WPLMS: from n/a before 1.9.9.5.3.... Read more
Affected Products : wordpress_learning_management_system_- Published: Dec. 18, 2024
- Modified: Dec. 18, 2024
-
9.9
CRITICALCVE-2024-56052
Unrestricted Upload of File with Dangerous Type vulnerability in VibeThemes WPLMS allows Upload a Web Shell to a Web Server.This issue affects WPLMS: from n/a before 1.9.9.5.2.... Read more
Affected Products : wordpress_learning_management_system_- Published: Dec. 18, 2024
- Modified: Dec. 18, 2024
-
8.5
HIGHCVE-2024-56051
Improper Control of Generation of Code ('Code Injection') vulnerability in VibeThemes WPLMS allows Code Injection.This issue affects WPLMS: from n/a before 1.9.9.5.... Read more
Affected Products : wordpress_learning_management_system_- Published: Dec. 18, 2024
- Modified: Dec. 18, 2024
-
9.9
CRITICALCVE-2024-56050
Unrestricted Upload of File with Dangerous Type vulnerability in VibeThemes WPLMS allows Upload a Web Shell to a Web Server.This issue affects WPLMS: from n/a before 1.9.9.5.3.... Read more
Affected Products : wordpress_learning_management_system_- Published: Dec. 18, 2024
- Modified: Dec. 18, 2024