CVE Severity Distribution (Last 30 Days)
Found 11 CVEs in the last 30 days.
CVE-2024-12342
MEDIUM
CVSS: 6.5
EPSS: 9.3%
ExploitDB
CWE-404
A vulnerability was found in TP-Link VN020 F3v(T) TT_V6.2.1021. It has been rated as critical. This issue affects some unknown processing of the file /control/WANIPConnection of the component Incomplete SOAP Request Handler. The manipulation leads to denial of service. The attack can only be initiated within the local network. The exploit has been disclosed to the public and may be used.
Published: 2024-12-08
CVE-2024-12343
MEDIUM
CVSS: 6.5
EPSS: 5.0%
CWE-119
CWE-120
T1203
A vulnerability classified as critical has been found in TP-Link VN020 F3v(T) TT_V6.2.1021. Affected is an unknown function of the file /control/WANIPConnection of the component SOAP Request Handler. The manipulation of the argument NewConnectionType leads to buffer overflow. The attack needs to be done within the local network. The exploit has been disclosed to the public and may be used.
Published: 2024-12-08
CVE-2024-1234
MEDIUM
CVSS: 6.4
EPSS: 1.6%
ExploitDB
CWE-79
CWE-79
T1189
The Exclusive Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via data attribute in all versions up to, and including, 2.6.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor access or higher, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Published: 2024-03-13
CVE-2024-12344
MEDIUM
CVSS: 6.3
EPSS: 1.9%
ExploitDB
CWE-119
CWE-787
T1203
A vulnerability, which was classified as critical, was found in TP-Link VN020 F3v(T) TT_V6.2.1021. This affects an unknown part of the component FTP USER Command Handler. The manipulation leads to memory corruption. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
Published: 2024-12-08
CVE-2024-12347
MEDIUM
CVSS: 5.3
EPSS: 0.6%
CWE-266
CWE-285
T1068
A vulnerability was found in Guangzhou Huayi Intelligent Technology Jeewms up to 1.0.0 and classified as critical. This issue affects some unknown processing of the file /jeewms_war/webpage/system/druid/index.html of the component Druid Monitoring Interface. The manipulation leads to improper authorization. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Published: 2024-12-09
CVE-2024-12345
MEDIUM
CVSS: 4.4
EPSS: 0.3%
CWE-400
CWE-404
T1499
A vulnerability classified as problematic was found in INW Krbyyyzo 25.2002. Affected by this vulnerability is an unknown functionality of the file /gbo.aspx of the component Daily Huddle Site. The manipulation of the argument s leads to resource consumption. It is possible to launch the attack on the local host. Other endpoints might be affected as well.
Published: 2025-01-27
CVE-2024-12340
MEDIUM
CVSS: 4.3
EPSS: 0.3%
CWE-200
T1005
T1083
The Animation Addons for Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.1.6 via the 'render' function in widgets/content-slider.php and widgets/tabs.php. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract sensitive private, pending, and draft Elementor template data.
Published: 2024-12-18
CVE-2024-12341
MEDIUM
CVSS: 4.3
EPSS: 0.4%
CWE-862
T1078
The Custom Skins Contact Form 7 plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'cf7cs_action_callback' function in all versions up to, and including, 1.0. This makes it possible for authenticated attackers, with Subscriber-level access and above, to update the content of any post and create new skins.
Published: 2024-12-12
CVE-2024-12349
MEDIUM
CVSS: 4.3
EPSS: 0.4%
CWE-352
CWE-862
CWE-352
T1078
T1189
A vulnerability was found in JFinalCMS 1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /admin/tag/save. The manipulation leads to cross-site request forgery. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
Published: 2024-12-09
CVE-2024-12346
LOW
CVSS: 3.5
EPSS: 0.4%
CWE-79
CWE-94
T1059
T1189
A vulnerability has been found in Talentera up to 20241128 and classified as problematic. This vulnerability affects unknown code of the file /app/control/byt_cv_manager. The manipulation of the argument redirect_url leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The provided PoC only works in Mozilla Firefox. The vendor was contacted early about this disclosure but did not respond in any way.
Published: 2024-12-09
CVE-2024-12348
LOW
CVSS: 3.5
EPSS: 0.4%
CWE-79
CWE-94
T1059
T1189
A vulnerability was found in Guizhou Xiaoma Technology jpress 5.1.2. It has been classified as problematic. Affected is the function AttachmentUtils.isUnSafe of the file /commons/attachment/upload of the component Attachment Upload Handler. The manipulation of the argument files[] leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
Published: 2024-12-09