5.3

CVSS3.1

CVE-2024-12034 - Advanced Google reCAPTCHA <= 1.25 - Brute Force Protection IP Unblock

The Advanced Google reCAPTCHA plugin for WordPress is vulnerable to IP unblocking in all versions up to, and including, 1.25. This is due to the plugin not utilizing a strong unique key when generating an unblock request. This makes it possible for unauthenticated attackers to unblock their IP afte…

📅 Published: Dec. 24, 2024, 5:23 a.m. 🔄 Last Modified: April 8, 2026, 4:35 p.m.

5.1

CVSS4.0

CVE-2024-41887 - Arbitrary File Overwrite

Team ENVY, a Security Research TEAM has found a flaw that allows for a remote code execution on the NVR. An attacker can create an NVR log file in a directory one level higher on the system, which can be used to corrupt files in the directory. The manufacturer has released patch firmware for the fl…

📅 Published: Dec. 24, 2024, 5:20 a.m. 🔄 Last Modified: Oct. 1, 2025, 2:15 a.m.

5.4

CVSS3.1

CVE-2024-12617 - WC Price History for Omnibus <= 2.1.3 - Missing Authorization

The WC Price History for Omnibus plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on several AJAX actions in all versions up to, and including, 2.1.3. This makes it possible for authenticated attackers, with Subscriber-level access and above, to view and m…

📅 Published: Dec. 24, 2024, 4:22 a.m. 🔄 Last Modified: April 8, 2026, 5:16 p.m.

6.4

CVSS3.1

CVE-2024-12507 - Optio Dentistry <= 2.1 - Authenticated (Contributor+) Stored Cross-Site Scripting

The Optio Dentistry plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'optio-lightbox' shortcode in all versions up to, and including, 2.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticate…

📅 Published: Dec. 24, 2024, 4:22 a.m. 🔄 Last Modified: April 8, 2026, 4:48 p.m.

6.4

CVSS3.1

CVE-2024-12518 - shMapper by Teplitsa <= 1.4.18 - Authenticated (Contributor+) Stored Cross-Site Scripting

The ShMapper by Teplitsa plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'shmMap' shortcode in all versions up to, and including, 1.4.18 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticate…

📅 Published: Dec. 24, 2024, 4:22 a.m. 🔄 Last Modified: April 8, 2026, 4:37 p.m.

6.1

CVSS3.1

CVE-2024-12710 - WP-Appbox <= 4.5.3 - Reflected Cross-Site Scripting

The WP-Appbox plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'page' parameter in all versions up to, and including, 4.5.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in…

📅 Published: Dec. 24, 2024, 4:22 a.m. 🔄 Last Modified: April 8, 2026, 4:35 p.m.

6.5

CVSS3.1

CVE-2024-12266 - ELEX WooCommerce Dynamic Pricing and Discounts <= 2.1.7 - Missing Authorization

The ELEX WooCommerce Dynamic Pricing and Discounts plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the elex_dp_export_rules() and elex_dp_import_rules() functions in all versions up to, and including, 2.1.7. This makes it possible for unauthent…

📅 Published: Dec. 24, 2024, 4:22 a.m. 🔄 Last Modified: April 8, 2026, 4:33 p.m.

8.1

CVSS3.1

CVE-2024-47515 - Pagure: generate_archive() follows symbolic links in temporary clones

A vulnerability was found in Pagure. Support of symbolic links during repository archiving of repositories allows the disclosure of local files. This flaw allows a malicious user to take advantage of the Pagure instance.

📅 Published: Dec. 24, 2024, 3:26 a.m. 🔄 Last Modified: Aug. 12, 2025, 1:32 p.m.

5.4

CVSS3.1

CVE-2024-9427 - Koji: escape html tag characters in the query string

A vulnerability in Koji was found. An unsanitized input allows for an XSS attack. Javascript code from a malicious link could be reflected in the resulting web page. It is not expected to be able to submit an action or make a change in Koji due to existing XSS protections in the code

📅 Published: Dec. 24, 2024, 3:25 a.m. 🔄 Last Modified: Aug. 30, 2025, 9 p.m.

5.5

CVSS3.1

CVE-2024-53148 - comedi: Flush partial mappings in error case

In the Linux kernel, the following vulnerability has been resolved: comedi: Flush partial mappings in error case If some remap_pfn_range() calls succeeded before one failed, we still have buffer pages mapped into the userspace page tables when we drop the buffer reference with comedi_buf_map_put(…

📅 Published: Dec. 24, 2024, midnight 🔄 Last Modified: Nov. 3, 2025, 9:17 p.m.
Total resulsts: 343887
Page 6858 of 34,389
« previous page » next page
Filters