Latest CVE Feed
-
7.5
HIGHCVE-2024-11585
The WP Hide & Security Enhancer plugin for WordPress is vulnerable to arbitrary file contents deletion due to a missing authorization and insufficient file path validation in the file-process.php in all versions up to, and including, 2.5.1. This makes it ... Read more
Affected Products : wp_hide_\&_security_enhancer- Published: Dec. 06, 2024
- Modified: Dec. 06, 2024
-
6.4
MEDIUMCVE-2024-11201
The myCred – Loyalty Points and Rewards plugin for WordPress and WooCommerce – Give Points, Ranks, Badges, Cashback, WooCommerce rewards, and WooCommerce credits for Gamification plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the pl... Read more
Affected Products :- Published: Dec. 06, 2024
- Modified: Dec. 06, 2024
-
8.8
HIGHCVE-2024-10578
The Pubnews theme for WordPress is vulnerable to unauthorized arbitrary plugin installation due to a missing capability check on the pubnews_importer_plugin_action_for_notice() function in all versions up to, and including, 1.0.7. This makes it possible f... Read more
Affected Products :- Published: Dec. 06, 2024
- Modified: Dec. 06, 2024
-
4.8
MEDIUMCVE-2024-10551
The Sticky Social Icons WordPress plugin through 1.2.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disal... Read more
Affected Products : sticky_social_icons- Published: Dec. 06, 2024
- Modified: May. 07, 2025
-
4.3
MEDIUMCVE-2024-10480
The 3DPrint Lite WordPress plugin before 2.1 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack.... Read more
Affected Products : 3dprint_lite- Published: Dec. 06, 2024
- Modified: May. 17, 2025
-
6.1
MEDIUMCVE-2024-11379
The Broadcast plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'do_check' parameter in all versions up to, and including, 51.01 due to insufficient input sanitization and output escaping. This makes it possible for unauthentica... Read more
Affected Products :- Published: Dec. 06, 2024
- Modified: Dec. 06, 2024
-
4.8
MEDIUMCVE-2024-9769
The Video Gallery – Best WordPress YouTube Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 2.4.1 due to insufficient input sanitization and output escaping. This makes it p... Read more
Affected Products : video_gallery- Published: Dec. 06, 2024
- Modified: Jul. 09, 2025
-
6.1
MEDIUMCVE-2024-10836
The Flixita theme for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘id’ parameter in all versions up to, and including, 1.0.82 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated atta... Read more
Affected Products :- Published: Dec. 06, 2024
- Modified: Dec. 06, 2024
-
7.2
HIGHCVE-2024-10247
The Video Gallery – Best WordPress YouTube Gallery Plugin plugin for WordPress is vulnerable to time-based SQL Injection via the orderby parameter in all versions up to, and including, 2.4.2 due to insufficient escaping on the user supplied parameter and ... Read more
Affected Products : video_gallery- Published: Dec. 06, 2024
- Modified: Jul. 09, 2025
-
4.3
MEDIUMCVE-2024-49041
Microsoft Edge (Chromium-based) Spoofing Vulnerability... Read more
Affected Products : edge_chromium- Published: Dec. 06, 2024
- Modified: Jan. 08, 2025
-
7.9
HIGHCVE-2024-11149
In OpenBSD 7.4 before errata 014, vmm(4) did not restore GDTR limits properly on Intel (VMX) CPUs.... Read more
- Published: Dec. 06, 2024
- Modified: Dec. 06, 2024
-
3.8
LOWCVE-2024-6219
Mark Laing discovered in LXD's PKI mode, until version 5.21.1, that a restricted certificate could be added to the trust store with its restrictions not honoured.... Read more
Affected Products : lxd- Published: Dec. 06, 2024
- Modified: Aug. 28, 2025
-
3.8
LOWCVE-2024-6156
Mark Laing discovered that LXD's PKI mode, until version 5.21.2, could be bypassed if the client's certificate was present in the trust store.... Read more
Affected Products : lxd- Published: Dec. 06, 2024
- Modified: Aug. 26, 2025
-
7.7
HIGHCVE-2024-52798
path-to-regexp turns path strings into a regular expressions. In certain cases, path-to-regexp will output a regular expression that can be exploited to cause poor performance. The regular expression that is vulnerable to backtracking can be generated in ... Read more
Affected Products :- Published: Dec. 05, 2024
- Modified: Jan. 24, 2025
-
9.1
CRITICALCVE-2024-38920
Open Robotics Robotic Operating System 2 (ROS2) and Nav2 humble versions were discovered to contain a use-after-free via the nav2_amcl process. This vulnerability is triggerd via remotely sending a request for change the value of dynamic-parameter`/amcl m... Read more
Affected Products :- Published: Dec. 05, 2024
- Modified: Dec. 06, 2024
-
7.5
HIGHCVE-2024-38910
Open Robotics Robotic Operating System 2 (ROS2) and Nav2 humble version was discovered to contain a use-after-free in the nav2_amcl process. This vulnerability is triggered via sending a request to change dynamic parameters.... Read more
Affected Products :- Published: Dec. 05, 2024
- Modified: Dec. 06, 2024
-
9.8
CRITICALCVE-2024-37863
Open Robotics Robotic Operating System 2 (ROS2) and Nav2 humble versions were discovered to contain a buffer overflow via the nav2_amcl process. This vulnerability is triggered via sending a crafted .yaml file.... Read more
Affected Products :- Published: Dec. 05, 2024
- Modified: Dec. 06, 2024
-
7.3
HIGHCVE-2024-37862
Buffer Overflow vulnerability in Open Robotic Robotic Operating System 2 ROS2 navigation2- ROS2-humble&& navigation2-humble allows a local attacker to execute arbitrary code via a crafted .yaml file to the nav2_planner process.... Read more
Affected Products :- Published: Dec. 05, 2024
- Modified: Dec. 06, 2024
-
9.8
CRITICALCVE-2024-37861
Open Robotics Robotic Operating System 2 (ROS2) and Nav2 humble versions were discovered to contain a buffer overflow via the nav2_amcl process. This vulnerability is triggered via sending a crafted .yaml file.... Read more
Affected Products :- Published: Dec. 05, 2024
- Modified: Dec. 06, 2024
-
7.3
HIGHCVE-2024-37860
Buffer Overflow vulnerability in Open Robotic Operating System 2 ROS2 navigation2- ROS2-humble&& navigation2-humble allows a local attacker to execute arbitrary code via a crafted .yaml file to the nav2_amcl process... Read more
Affected Products :- Published: Dec. 05, 2024
- Modified: Dec. 06, 2024