Latest CVE Feed
-
7.6
HIGHCVE-2024-51672
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WPDeveloper BetterLinks allows SQL Injection.This issue affects BetterLinks: from n/a through 2.1.7.... Read more
Affected Products : betterlinks- Published: Nov. 04, 2024
- Modified: Nov. 06, 2024
-
4.9
MEDIUMCVE-2024-51665
Server-Side Request Forgery (SSRF) vulnerability in Noor alam Magical Addons For Elementor allows Server Side Request Forgery.This issue affects Magical Addons For Elementor: from n/a through 1.2.1.... Read more
Affected Products : magical_addons_for_elementor- Published: Nov. 04, 2024
- Modified: Nov. 06, 2024
-
8.8
HIGHCVE-2024-51582
Path Traversal: '.../...//' vulnerability in ThimPress WP Hotel Booking allows PHP Local File Inclusion.This issue affects WP Hotel Booking: from n/a through 2.1.4.... Read more
Affected Products : wp_hotel_booking- Published: Nov. 04, 2024
- Modified: Nov. 06, 2024
-
8.5
HIGHCVE-2024-51408
AppSmith Community 1.8.3 before 1.46 allows SSRF via New DataSource for application/json requests to 169.254.169.254 to retrieve AWS metadata credentials.... Read more
Affected Products : appsmith- Published: Nov. 04, 2024
- Modified: Nov. 06, 2024
-
8.0
HIGHCVE-2024-51253
In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the doL2TP function.... Read more
- Published: Nov. 04, 2024
- Modified: Apr. 10, 2025
-
8.0
HIGHCVE-2024-51251
In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the backup function.... Read more
- Published: Nov. 04, 2024
- Modified: Apr. 10, 2025
-
8.0
HIGHCVE-2024-51249
In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the reboot function.... Read more
- Published: Nov. 04, 2024
- Modified: Apr. 11, 2025
-
8.0
HIGHCVE-2024-51246
In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the doPPTP function.... Read more
- Published: Nov. 04, 2024
- Modified: Apr. 11, 2025
-
10.0
CRITICALCVE-2024-50531
Unrestricted Upload of File with Dangerous Type vulnerability in David F. Carr RSVPMaker for Toastmasters allows Upload a Web Shell to a Web Server.This issue affects RSVPMaker for Toastmasters: from n/a through 6.2.4.... Read more
Affected Products : rsvpmaker- Published: Nov. 04, 2024
- Modified: Nov. 06, 2024
-
9.9
CRITICALCVE-2024-50530
Unrestricted Upload of File with Dangerous Type vulnerability in Myriad Solutionz Stars SMTP Mailer allows Upload a Web Shell to a Web Server.This issue affects Stars SMTP Mailer: from n/a through 1.7.... Read more
Affected Products : stars_smtp_mailer- Published: Nov. 04, 2024
- Modified: Nov. 06, 2024
-
9.9
CRITICALCVE-2024-50529
Unrestricted Upload of File with Dangerous Type vulnerability in Rudra Innnovative Software Training – Courses allows Upload a Web Shell to a Web Server.This issue affects Training – Courses: from n/a through 2.0.1.... Read more
Affected Products : training_-_courses- Published: Nov. 04, 2024
- Modified: Nov. 06, 2024
-
7.5
HIGHCVE-2024-50528
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Stacks Stacks Mobile App Builder allows Retrieve Embedded Sensitive Data.This issue affects Stacks Mobile App Builder: from n/a through 5.2.3.... Read more
Affected Products : stacks_mobile_app_builder- Published: Nov. 04, 2024
- Modified: Nov. 06, 2024
-
10.0
CRITICALCVE-2024-50527
Unrestricted Upload of File with Dangerous Type vulnerability in Stacks Stacks Mobile App Builder allows Upload a Web Shell to a Web Server.This issue affects Stacks Mobile App Builder: from n/a through 5.2.3.... Read more
Affected Products : stacks_mobile_app_builder- Published: Nov. 04, 2024
- Modified: Nov. 06, 2024
-
10.0
CRITICALCVE-2024-50526
Unrestricted Upload of File with Dangerous Type vulnerability in mahlamusa Multi Purpose Mail Form allows Upload a Web Shell to a Web Server.This issue affects Multi Purpose Mail Form: from n/a through 1.0.2.... Read more
Affected Products : multi_purpose_mail_form- Published: Nov. 04, 2024
- Modified: Nov. 06, 2024
-
10.0
CRITICALCVE-2024-50525
Unrestricted Upload of File with Dangerous Type vulnerability in Helloprint Plug your WooCommerce into the largest catalog of customized print products from Helloprint allows Upload a Web Shell to a Web Server.This issue affects Plug your WooCommerce into... Read more
Affected Products : helloprint- Published: Nov. 04, 2024
- Modified: Nov. 06, 2024
-
10.0
CRITICALCVE-2024-50523
Unrestricted Upload of File with Dangerous Type vulnerability in RainbowLink Inc. All Post Contact Form allows Upload a Web Shell to a Web Server.This issue affects All Post Contact Form: from n/a through 1.7.3.... Read more
Affected Products : all_post_contact_form- Published: Nov. 04, 2024
- Modified: Nov. 06, 2024
-
7.1
HIGHCVE-2024-45164
Akamai SIA (Secure Internet Access Enterprise) ThreatAvert, in SPS (Security and Personalization Services) before the latest 19.2.0 patch and Apps Portal before 19.2.0.3 or 19.2.0.20240814, has incorrect authorization controls for the Admin functionality ... Read more
Affected Products : secure_internet_access_enterprise_threatavert- Published: Nov. 04, 2024
- Modified: Nov. 06, 2024
-
6.9
MEDIUMCVE-2024-9147
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Bna Informatics PosPratik allows XSS Through HTTP Query Strings.This issue affects PosPratik: before v3.2.1.... Read more
Affected Products : pospratik- Published: Nov. 04, 2024
- Modified: Nov. 06, 2024
-
9.3
CRITICALCVE-2024-51561
This vulnerability exists in Aero due to improper implementation of OTP validation mechanism in certain API endpoints. An authenticated remote attacker could exploit this vulnerability by intercepting and manipulating the responses exchanged during the se... Read more
- Published: Nov. 04, 2024
- Modified: Nov. 06, 2024
-
7.1
HIGHCVE-2024-51560
This vulnerability exists in the Wave 2.0 due to improper exception handling for invalid inputs at certain API endpoint. An authenticated remote attacker could exploit this vulnerability by providing invalid inputs for “userId” parameter in the API reques... Read more
- Published: Nov. 04, 2024
- Modified: Nov. 08, 2024