The NVD is the U.S. government repository of standards based vulnerability management data represented using the Security Content Automation Protocol (SCAP). This data enables automation of vulnerability management, security measurement, and compliance. The NVD includes databases of security checklist references, security-related software flaws, product names, and impact metrics.
For information on how to cite the NVD, including the database's Digital Object Identifier (DOI), please consult NIST's Public Data Repository.
Legal Disclaimer:
Here is where you can read the NVD legal disclaimer.
-
CVE-2024-49659 - Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Rami Yushuvaev Coub allows Stored XSS.This issue affects Coub: from n/a through 1.4.
Published: October 29, 2024; 8:15:05 AM -0400V3.1: 5.4 MEDIUM
-
CVE-2024-49654 - Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Marian Heddesheimer Extra Privacy for Elementor allows Reflected XSS.This issue affects Extra Privacy for Elementor: from n/a through 0.1.3.
Published: October 29, 2024; 8:15:04 AM -0400V3.1: 6.1 MEDIUM
-
CVE-2024-49656 - Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Abdullah Irfan DocumentPress allows Reflected XSS.This issue affects DocumentPress: from n/a through 2.1.
Published: October 29, 2024; 8:15:05 AM -0400V3.1: 6.1 MEDIUM
-
CVE-2024-49972 - In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Deallocate DML memory if allocation fails [Why] When DC state create DML memory allocation fails, memory is not deallocated subsequently, resulting in uninitial... read CVE-2024-49972
Published: October 21, 2024; 2:15:18 PM -0400V3.1: 5.5 MEDIUM
-
CVE-2024-20300 - A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface of an affected d... read CVE-2024-20300
Published: October 23, 2024; 1:15:17 PM -0400V3.1: 5.4 MEDIUM
-
CVE-2024-49971 - In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Increase array size of dummy_boolean [WHY] dml2_core_shared_mode_support and dml_core_mode_support access the third element of dummy_boolean, i.e. hw_debug5 = &... read CVE-2024-49971
Published: October 21, 2024; 2:15:18 PM -0400V3.1: 5.5 MEDIUM
-
CVE-2024-20485 - A vulnerability in the VPN web server of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local attacker to execute arbitrary code with root-level privileges. Administ... read CVE-2024-20485
Published: October 23, 2024; 2:15:12 PM -0400V3.1: 6.7 MEDIUM
-
CVE-2024-20482 - A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software, formerly Firepower Management Center Software, could allow an authenticated, remote attacker to elevate privileges on an affected devi... read CVE-2024-20482
Published: October 23, 2024; 2:15:12 PM -0400V3.1: 6.5 MEDIUM
-
CVE-2024-6581 - A vulnerability in the discussion image upload function of the Lollms application, version v9.9, allows for the uploading of SVG files. Due to incomplete filtering in the sanitize_svg function, this can lead to cross-site scripting (XSS) vulnerabi... read CVE-2024-6581
Published: October 29, 2024; 9:15:07 AM -0400V3.1: 9.0 CRITICAL
-
CVE-2024-8309 - A vulnerability in the GraphCypherQAChain class of langchain-ai/langchain version 0.2.5 allows for SQL injection through prompt injection. This vulnerability can lead to unauthorized data manipulation, data exfiltration, denial of service (DoS) by... read CVE-2024-8309
Published: October 29, 2024; 9:15:10 AM -0400V3.1: 9.8 CRITICAL
-
CVE-2024-49660 - Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Campus Explorer Campus Explorer Widget allows Reflected XSS.This issue affects Campus Explorer Widget: from n/a through 1.4.
Published: October 29, 2024; 8:15:05 AM -0400V3.1: 6.1 MEDIUM
-
CVE-2024-49661 - Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Lew Ayotte leenk.Me allows Reflected XSS.This issue affects leenk.Me: from n/a through 2.16.0.
Published: October 29, 2024; 8:15:05 AM -0400V3.1: 6.1 MEDIUM
-
CVE-2024-49662 - Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Webgensis Simple Load More allows Reflected XSS.This issue affects Simple Load More: from n/a through 1.0.
Published: October 29, 2024; 8:15:06 AM -0400V3.1: 6.1 MEDIUM
-
CVE-2024-49663 - Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Elena Zhyvohliad uCAT – Next Story allows Reflected XSS.This issue affects uCAT – Next Story: from n/a through 2.0.0.
Published: October 29, 2024; 8:15:06 AM -0400V3.1: 6.1 MEDIUM
-
CVE-2024-49664 - Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in allows Reflected XSS.This issue affects chatplusjp: from n/a through 1.02.
Published: October 29, 2024; 8:15:06 AM -0400V3.1: 6.1 MEDIUM
-
CVE-2024-49665 - Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Web Bricks Web Bricks Addons for Elementor allows Stored XSS.This issue affects Web Bricks Addons for Elementor: from n/a through 1.1.1.
Published: October 29, 2024; 8:15:06 AM -0400V3.1: 5.4 MEDIUM
-
CVE-2024-49667 - Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in NervyThemes Local Business Addons For Elementor allows Stored XSS.This issue affects Local Business Addons For Elementor: from n/a through... read CVE-2024-49667
Published: October 29, 2024; 8:15:06 AM -0400V3.1: 5.4 MEDIUM
-
CVE-2024-9361 - The Bulk images optimizer: Resize, optimize, convert to webp, rename … plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'save_configuration' function in all versions up to, and includ... read CVE-2024-9361
Published: October 18, 2024; 1:15:06 AM -0400V3.1: 4.3 MEDIUM
-
CVE-2024-10119 - The wireless router WRTM326 from SECOM does not properly validate a specific parameter. An unauthenticated remote attacker could execute arbitrary system commands by sending crafted requests.
Published: October 18, 2024; 1:15:05 AM -0400V3.1: 9.8 CRITICAL
-
CVE-2024-10448 - A vulnerability, which was classified as problematic, has been found in code-projects Blood Bank Management System 1.0. Affected by this issue is some unknown functionality of the file /file/delete.php. The manipulation of the argument bid leads t... read CVE-2024-10448
Published: October 28, 2024; 10:15:04 AM -0400V3.1: 6.5 MEDIUM