Latest CVE Feed
-
8.8
HIGHCVE-2024-12349
A vulnerability was found in JFinalCMS 1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /admin/tag/save. The manipulation leads to cross-site request forgery. The attack can be launched remot... Read more
- Published: Dec. 09, 2024
- Modified: Dec. 11, 2024
-
6.1
MEDIUMCVE-2024-12348
A vulnerability was found in Guizhou Xiaoma Technology jpress 5.1.2. It has been classified as problematic. Affected is the function AttachmentUtils.isUnSafe of the file /commons/attachment/upload of the component Attachment Upload Handler. The manipulati... Read more
Affected Products : jpress- Published: Dec. 09, 2024
- Modified: Jun. 04, 2025
-
6.9
MEDIUMCVE-2024-12347
A vulnerability was found in Guangzhou Huayi Intelligent Technology Jeewms up to 1.0.0 and classified as critical. This issue affects some unknown processing of the file /jeewms_war/webpage/system/druid/index.html of the component Druid Monitoring Interfa... Read more
Affected Products : jeewms- Published: Dec. 09, 2024
- Modified: Dec. 09, 2024
-
5.3
MEDIUMCVE-2024-12346
A vulnerability has been found in Talentera up to 20241128 and classified as problematic. This vulnerability affects unknown code of the file /app/control/byt_cv_manager. The manipulation of the argument redirect_url leads to cross site scripting. The att... Read more
Affected Products :- Published: Dec. 09, 2024
- Modified: Dec. 09, 2024
-
9.8
CRITICALCVE-2024-55560
MailCleaner before 28d913e has default values of ssh_host_dsa_key, ssh_host_rsa_key, and ssh_host_ed25519_key that persist after installation.... Read more
Affected Products : mailcleaner- Published: Dec. 08, 2024
- Modified: Dec. 09, 2024
-
9.8
CRITICALCVE-2024-12344
A vulnerability, which was classified as critical, was found in TP-Link VN020 F3v(T) TT_V6.2.1021. This affects an unknown part of the component FTP USER Command Handler. The manipulation leads to memory corruption. It is possible to initiate the attack r... Read more
- Published: Dec. 08, 2024
- Modified: Dec. 10, 2024
-
8.8
HIGHCVE-2024-12343
A vulnerability classified as critical has been found in TP-Link VN020 F3v(T) TT_V6.2.1021. Affected is an unknown function of the file /control/WANIPConnection of the component SOAP Request Handler. The manipulation of the argument NewConnectionType lead... Read more
- Published: Dec. 08, 2024
- Modified: Dec. 10, 2024
-
7.1
HIGHCVE-2024-12342
A vulnerability was found in TP-Link VN020 F3v(T) TT_V6.2.1021. It has been rated as critical. This issue affects some unknown processing of the file /control/WANIPConnection of the component Incomplete SOAP Request Handler. The manipulation leads to deni... Read more
Affected Products :- Published: Dec. 08, 2024
- Modified: Dec. 08, 2024
-
9.8
CRITICALCVE-2024-12209
The WP Umbrella: Update Backup Restore & Monitoring plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.17.0 via the 'filename' parameter of the 'umbrella-restore' action. This makes it possible for unauthent... Read more
Affected Products :- Published: Dec. 08, 2024
- Modified: Dec. 08, 2024
-
7.5
HIGHCVE-2024-53473
WeGIA 3.2.0 before 3998672 does not verify permission to change a password.... Read more
Affected Products : wegia- Published: Dec. 07, 2024
- Modified: Apr. 09, 2025
-
6.4
MEDIUMCVE-2024-47107
IBM QRadar SIEM 7.5 is vulnerable to stored cross-site scripting. This vulnerability allows authenticated users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within ... Read more
- Published: Dec. 07, 2024
- Modified: Jul. 25, 2025
-
6.5
MEDIUMCVE-2024-41762
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to a denial of service as the server may crash under certain conditions with a specially crafted query.... Read more
Affected Products : db2- Published: Dec. 07, 2024
- Modified: Jan. 31, 2025
-
7.8
HIGHCVE-2024-47115
IBM AIX 7.2, 7.3 and VIOS 3.1 and 4.1 could allow a local user to execute arbitrary commands on the system due to improper neutralization of input.... Read more
- Published: Dec. 07, 2024
- Modified: Jan. 21, 2025
-
6.5
MEDIUMCVE-2024-37071
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 could allow an authenticated user to cause a denial of service with a specially crafted query due to improper memory allocation.... Read more
Affected Products : db2- Published: Dec. 07, 2024
- Modified: Aug. 09, 2025
-
8.8
HIGHCVE-2024-11501
The Gallery plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.3 via deserialization of untrusted input from wd_gallery_$id parameter. This makes it possible for authenticated attackers, with Contributor-lev... Read more
Affected Products :- Published: Dec. 07, 2024
- Modified: Dec. 07, 2024
-
6.1
MEDIUMCVE-2024-11464
The Easy Code Snippets plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'page' parameter in all versions up to, and including, 1.0.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthe... Read more
Affected Products :- Published: Dec. 07, 2024
- Modified: Dec. 07, 2024
-
6.1
MEDIUMCVE-2024-11457
The Feedpress Generator – External RSS Frontend Customizer plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'tab' parameter in all versions up to, and including, 1.2.1 due to insufficient input sanitization and output escaping.... Read more
Affected Products :- Published: Dec. 07, 2024
- Modified: Dec. 07, 2024
-
6.4
MEDIUMCVE-2024-11380
The Mini Program API plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'qvideo' shortcode in all versions up to, and including, 1.4.5 due to insufficient input sanitization and output escaping on user supplied attributes. ... Read more
Affected Products :- Published: Dec. 07, 2024
- Modified: Dec. 07, 2024
-
7.5
HIGHCVE-2024-12270
The Beautiful taxonomy filters plugin for WordPress is vulnerable to SQL Injection via the 'selects[0][term]' parameter in all versions up to, and including, 2.4.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparat... Read more
Affected Products :- Published: Dec. 07, 2024
- Modified: Dec. 07, 2024
-
5.4
MEDIUMCVE-2024-12253
The Simple Ecommerce Shopping Cart Plugin- Sell products through Paypal plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the 'save_settings', 'export_csv', and 'simpleecommcart-action' actions in all versions ... Read more
Affected Products : simple-e-commerce-shopping-cart- Published: Dec. 07, 2024
- Modified: Dec. 07, 2024