Latest CVE Feed
-
5.3
MEDIUMCVE-2024-9065
The WP Helper Premium plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'whp_smtp_send_mail_test' function in all versions up to, and including, 4.6.1. This makes it possible for unauthenticat... Read more
Affected Products : wp_helper_premium- Published: Oct. 10, 2024
- Modified: Oct. 15, 2024
-
6.4
MEDIUMCVE-2024-9064
The Elementor Inline SVG plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.2.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticate... Read more
Affected Products : elementor_inline_svg- Published: Oct. 10, 2024
- Modified: Oct. 15, 2024
-
6.4
MEDIUMCVE-2024-9057
The Curator.io: Show all your social media posts in a beautiful feed. plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘feed_id’ attribute in all versions up to, and including, 1.9 due to insufficient input sanitization and output... Read more
Affected Products : curator.io- Published: Oct. 10, 2024
- Modified: Oct. 15, 2024
-
6.4
MEDIUMCVE-2024-8987
The Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's youzify_media shortcode in all versions up to, and including, 1.3.0 due t... Read more
Affected Products : youzify- Published: Oct. 10, 2024
- Modified: Oct. 15, 2024
-
6.1
MEDIUMCVE-2024-8729
The Easy Social Share Buttons plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 1.4.5. This makes it possible for unauthentica... Read more
Affected Products : easy_social_share_buttons- Published: Oct. 10, 2024
- Modified: Oct. 15, 2024
-
5.3
MEDIUMCVE-2024-8513
The QA Analytics – Web Analytics Tool with Heatmaps & Session Replay Across All Pages plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the ajax_save_plugin_config() function in all versions up to... Read more
Affected Products : qa_analytics- Published: Oct. 10, 2024
- Modified: Oct. 15, 2024
-
6.3
MEDIUMCVE-2024-7048
In version v0.3.8 of open-webui, an improper privilege management vulnerability exists in the API endpoints GET /api/v1/documents/ and POST /rag/api/v1/doc. This vulnerability allows a lower-privileged user to access and overwrite files managed by a highe... Read more
Affected Products : open_webui- Published: Oct. 10, 2024
- Modified: Jul. 29, 2025
-
7.8
HIGHCVE-2024-48958
execute_filter_delta in archive_read_support_format_rar.c in libarchive before 3.7.5 allows out-of-bounds access via a crafted archive file because src can move beyond dst.... Read more
Affected Products : libarchive- Published: Oct. 10, 2024
- Modified: Aug. 29, 2025
-
7.8
HIGHCVE-2024-48957
execute_filter_audio in archive_read_support_format_rar.c in libarchive before 3.7.5 allows out-of-bounds access via a crafted archive file because src can move beyond dst.... Read more
Affected Products : libarchive- Published: Oct. 10, 2024
- Modified: Aug. 29, 2025
-
9.1
CRITICALCVE-2024-48949
The verify function in lib/elliptic/eddsa/index.js in the Elliptic package before 6.5.6 for Node.js omits "sig.S().gte(sig.eddsa.curve.n) || sig.S().isNeg()" validation.... Read more
- Published: Oct. 10, 2024
- Modified: Mar. 25, 2025
-
9.1
CRITICALCVE-2024-48942
The Syracom Secure Login (2FA) plugin for Jira, Confluence, and Bitbucket through 3.1.4.5 allows remote attackers to easily brute-force the 2FA PIN via the plugins/servlet/twofactor/public/pinvalidation endpoint. The last 30 and the next 30 tokens are val... Read more
Affected Products : secure_login- Published: Oct. 10, 2024
- Modified: Oct. 11, 2024
-
9.1
CRITICALCVE-2024-48941
The Syracom Secure Login (2FA) plugin for Jira, Confluence, and Bitbucket through 3.1.4.5 allows remote attackers to bypass 2FA by interacting with the /rest endpoint of Jira, Confluence, or Bitbucket. In the default configuration, /rest is allowlisted.... Read more
Affected Products : secure_login- Published: Oct. 10, 2024
- Modified: Oct. 11, 2024
-
5.5
MEDIUMCVE-2024-8264
Fortra's Robot Schedule Enterprise Agent prior to version 3.05 writes FTP username and password information to the agent log file when detailed logging is enabled.... Read more
Affected Products : robot_schedule- Published: Oct. 09, 2024
- Modified: Oct. 17, 2024
-
6.1
MEDIUMCVE-2024-48933
A cross-site scripting (XSS) vulnerability in LemonLDAP::NG before 2.19.3 allows remote attackers to inject arbitrary web script or HTML into the login page via a username if userControl has been set to a non-default value that allows special HTML charact... Read more
Affected Products : lemonldap\- Published: Oct. 09, 2024
- Modified: Oct. 15, 2024
-
6.5
MEDIUMCVE-2024-7041
An Insecure Direct Object Reference (IDOR) vulnerability exists in open-webui/open-webui version v0.3.8. The vulnerability occurs in the API endpoint `http://0.0.0.0:3000/api/v1/memories/{id}/update`, where the decentralization design is flawed, allowing ... Read more
Affected Products : open_webui- Published: Oct. 09, 2024
- Modified: Jul. 29, 2025
-
7.2
HIGHCVE-2024-7037
In version v0.3.8 of open-webui/open-webui, the endpoint /api/pipelines/upload is vulnerable to arbitrary file write and delete due to unsanitized file.filename concatenation with CACHE_DIR. This vulnerability allows attackers to overwrite and delete syst... Read more
Affected Products : open_webui- Published: Oct. 09, 2024
- Modified: Jul. 29, 2025
-
8.7
HIGHCVE-2024-39525
An Improper Handling of Exceptional Conditions vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated network-based attacker sending a specific BGP packet to cause rpd to crash and re... Read more
- Published: Oct. 09, 2024
- Modified: Oct. 10, 2024
-
8.7
HIGHCVE-2024-39516
An Out-of-Bounds Read vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated network-based attacker sending a specifically malformed BGP packet to cause rpd to crash and restart, ... Read more
- Published: Oct. 09, 2024
- Modified: Oct. 16, 2024
-
8.7
HIGHCVE-2024-39515
An Improper Validation of Consistency within Input vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated network-based attacker sending a specifically malformed BGP packet to cause r... Read more
- Published: Oct. 09, 2024
- Modified: Oct. 10, 2024
-
6.7
MEDIUMCVE-2024-38818
VMware NSX contains a local privilege escalation vulnerability. An authenticated malicious actor may exploit this vulnerability to obtain permissions from a separate group role than previously assigned.... Read more
- Published: Oct. 09, 2024
- Modified: Oct. 10, 2024