Latest CVE Feed
-
5.3
MEDIUMCVE-2024-34162
The web interface of the affected devices is designed to hide the LDAP credentials even for administrative users. But configuring LDAP authentication to "SIMPLE", the device communicates with the LDAP server in clear-text. The LDAP password can be retriev... Read more
Affected Products :- Published: Nov. 26, 2024
- Modified: Nov. 26, 2024
-
5.3
MEDIUMCVE-2024-33616
Admin authentication can be bypassed with some specific invalid credentials, which allows logging in with an administrative privilege. Sharp Corporation states the telnet feature is implemented on older models only, and is planning to provide the firmware... Read more
Affected Products :- Published: Nov. 26, 2024
- Modified: Dec. 10, 2024
-
9.1
CRITICALCVE-2024-33610
"sessionlist.html" and "sys_trayentryreboot.html" are accessible with no authentication. "sessionlist.html" provides logged-in users' session information including session cookies, and "sys_trayentryreboot.html" allows to reboot the device. As for the det... Read more
Affected Products :- Published: Nov. 26, 2024
- Modified: Nov. 26, 2024
-
7.5
HIGHCVE-2024-33605
Improper processing of some parameters of installed_emanual_list.html leads to a path traversal vulnerability. As for the details of affected product names, model numbers, and versions, refer to the information provided by the respective vendors listed un... Read more
Affected Products :- Published: Nov. 26, 2024
- Modified: Nov. 26, 2024
-
5.9
MEDIUMCVE-2024-32151
User passwords are decrypted and stored on memory before any user logged in. Those decrypted passwords can be retrieved from the coredump file. As for the details of affected product names, model numbers, and versions, refer to the information provided by... Read more
Affected Products :- Published: Nov. 26, 2024
- Modified: Nov. 26, 2024
-
5.9
MEDIUMCVE-2024-29978
User passwords are decrypted and stored on memory before any user logged in. Those decrypted passwords can be retrieved from the coredump file. As for the details of affected product names, model numbers, and versions, refer to the information provided by... Read more
Affected Products :- Published: Nov. 26, 2024
- Modified: Nov. 26, 2024
-
5.9
MEDIUMCVE-2024-29146
User passwords are decrypted and stored on memory before any user logged in. Those decrypted passwords can be retrieved from the coredump file. As for the details of affected product names, model numbers, and versions, refer to the information provided by... Read more
Affected Products :- Published: Nov. 26, 2024
- Modified: Nov. 26, 2024
-
5.9
MEDIUMCVE-2024-28955
Affected devices create coredump files when crashed, storing them with world-readable permission. Any local user of the device can examine the coredump files, and research the memory contents. As for the details of affected product names, model numbers, a... Read more
Affected Products :- Published: Nov. 26, 2024
- Modified: Nov. 26, 2024
-
9.0
CRITICALCVE-2024-28038
The web interface of the affected devices processes a cookie value improperly, leading to a stack buffer overflow. More precisely, giving too long character string to MFPSESSIONID parameter results in a stack buffer overflow. As for the details of affecte... Read more
Affected Products :- Published: Nov. 26, 2024
- Modified: Nov. 26, 2024
-
6.1
MEDIUMCVE-2024-11202
Multiple plugins for WordPress are vulnerable to Reflected Cross-Site Scripting via the cminds_free_guide shortcode in various versions due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inj... Read more
Affected Products :- Published: Nov. 26, 2024
- Modified: Nov. 26, 2024
-
6.3
MEDIUMCVE-2024-6749
Seth Fogie, member of the AXIS Camera Station Pro Bug Bounty Program, has found that the Incident report feature may expose sensitive credentials on the AXIS Camera Station windows client. If Incident report is not being used with credentials configured t... Read more
Affected Products :- Published: Nov. 26, 2024
- Modified: Nov. 26, 2024
-
4.2
MEDIUMCVE-2024-6476
Gee-netics, member of the AXIS Camera Station Pro Bug Bounty Program has found that it is possible for a non-admin user to gain system privileges by redirecting a file deletion upon service restart. Axis has released patched versions for the highlighted... Read more
Affected Products :- Published: Nov. 26, 2024
- Modified: Nov. 26, 2024
-
6.3
MEDIUMCVE-2024-11002
The The InPost Gallery plugin for WordPress is vulnerable to arbitrary shortcode execution via the inpost_gallery_get_shortcode_template AJAX action in all versions up to, and including, 2.1.4.2. This is due to the software allowing users to execute an ac... Read more
Affected Products : inpost_gallery- Published: Nov. 26, 2024
- Modified: Jul. 09, 2025
-
6.5
MEDIUMCVE-2024-10857
The Product Input Fields for WooCommerce plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.9 via the handle_downloads() function due to insufficient file path validation/sanitization. This makes it possible ... Read more
Affected Products : product_input_fields_for_woocommerce- Published: Nov. 26, 2024
- Modified: Jul. 09, 2025
-
8.1
HIGHCVE-2024-10781
The Spam protection, Anti-Spam, FireWall by CleanTalk plugin for WordPress is vulnerable to unauthorized Arbitrary Plugin Installation due to an missing empty value check on the 'api_key' value in the 'perform' function in all versions up to, and includin... Read more
- Published: Nov. 26, 2024
- Modified: Jul. 12, 2025
-
7.5
HIGHCVE-2024-10570
The Security & Malware scan by CleanTalk plugin for WordPress is vulnerable to unauthorized SQL Injection due to an authorization bypass via reverse DNS spoofing on the checkWithoutToken function in all versions up to, and including, 2.145, as well as ins... Read more
Affected Products : security_\&_malware_scan- Published: Nov. 26, 2024
- Modified: Nov. 26, 2024
-
9.8
CRITICALCVE-2024-10542
The Spam protection, Anti-Spam, FireWall by CleanTalk plugin for WordPress is vulnerable to unauthorized Arbitrary Plugin Installation due to an authorization bypass via reverse DNS spoofing on the checkWithoutToken function in all versions up to, and inc... Read more
- Published: Nov. 26, 2024
- Modified: Jul. 12, 2025
-
4.8
MEDIUMCVE-2024-10471
The Everest Forms WordPress plugin before 3.0.4.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowe... Read more
Affected Products : everest_forms- Published: Nov. 26, 2024
- Modified: May. 15, 2025
-
4.8
MEDIUMCVE-2024-53278
Cross-site scripting vulnerability exists in WP Admin UI Customize versions prior to ver 1.5.14. If a malicious admin user customizes the admin screen with some malicious contents, an arbitrary script may be executed on the web browser of the other users ... Read more
Affected Products : wp_admin_ui_customize- Published: Nov. 26, 2024
- Modified: Nov. 26, 2024
-
7.5
HIGHCVE-2024-49353
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data 4.0.0 through 5.0.2 does not properly check inputs to resources that are used concurrently, which might lead to unexpected states, possibly resulting in a crash.... Read more
Affected Products : watson_assistant_for_ibm_cloud_pak_for_data- Published: Nov. 26, 2024
- Modified: Aug. 15, 2025