6

CVSS4.0

CVE-2025-24961 - Insecure path traversal in filesystem and filesystem-nio2 storage backends in org.gaul S3Proxy

org.gaul S3Proxy implements the S3 API and proxies requests. Users of the filesystem and filesystem-nio2 storage backends could unintentionally expose local files to users. This issue has been addressed in version 2.6.0. Users are advised to upgrade. There are no known workarounds for this vulnerab…

πŸ“… Published: Feb. 3, 2025, 8:29 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.6

CVSS3.1

CVE-2024-12511 - SMB/FTP Address Book Scan Pass-back attack

With address book access, SMB/FTP settings could be modified, redirecting scans and possibly capturing credentials. This requires enabled scan functions and printer access.

πŸ“… Published: Feb. 3, 2025, 7:23 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.8

CVSS3.1

CVE-2024-12859 - BoomBox Theme Extensions <= 1.8.0 - Authenticated (Contributor+) Local File Inclusion via Shortcode

The BoomBox Theme Extensions plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.8.0 via the 'boombox_listing' shortcode 'type' attribute. This makes it possible for authenticated attackers, with contributor-level and above permissions, to include and …

πŸ“… Published: Feb. 3, 2025, 7:22 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

4.3

CVSS3.1

CVE-2024-11134 - Eventer <= 3.9.9 - Missing Authorization to Authenticated (Subscriber+) Bookings Export

The Eventer plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'eventer_export_bookings_csv' function in all versions up to, and including, 3.9.9. This makes it possible for authenticated attackers with subscriber-level permissions or above, t…

πŸ“… Published: Feb. 3, 2025, 7:22 p.m. πŸ”„ Last Modified: April 8, 2026, 4:50 p.m.

6.4

CVSS3.1

CVE-2024-11132 - Eventer <= 3.9.9.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode

The Eventer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcodes in versions up to, and including, 3.9.9.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level an…

πŸ“… Published: Feb. 3, 2025, 7:22 p.m. πŸ”„ Last Modified: April 8, 2026, 5:17 p.m.

5.3

CVSS3.1

CVE-2024-11133 - Eventer <= 3.9.9.5 - Missing Authorization to Unauthenticated Event Ticket Download

The Eventer plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'handle_pdf_download_request' function in all versions up to, and including, 3.9.9.5. This makes it possible for unauthenticated attackers to download event tickets.

πŸ“… Published: Feb. 3, 2025, 7:22 p.m. πŸ”„ Last Modified: April 8, 2026, 5:17 p.m.

6.7

CVSS3.1

CVE-2024-12510 - LDAP Authentication Sever Pass-back attack

If LDAP settings are accessed, authentication could be redirected to another server, potentially exposing credentials. This requires admin access and an active LDAP setup.

πŸ“… Published: Feb. 3, 2025, 6:52 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.3

CVSS4.0

CVE-2025-24898 - rust openssl ssl::select_next_proto use after free

rust-openssl is a set of OpenSSL bindings for the Rust programming language. In affected versions `ssl::select_next_proto` can return a slice pointing into the `server` argument's buffer but with a lifetime bound to the `client` argument. In situations where the `sever` buffer's lifetime is shorter…

πŸ“… Published: Feb. 3, 2025, 5:57 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.2

CVSS3.1

CVE-2024-56161 - kernel: hw:amd: Vulnerability in guest VM protected by SEV when loading malicious firmware

Improper signature verification in AMD CPU ROM microcode patch loader may allow an attacker with local administrator privilege to load malicious CPU microcode resulting in loss of confidentiality and integrity of a confidential guest running under AMD SEV-SNP.

πŸ“… Published: Feb. 3, 2025, 5:24 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.8

CVSS3.1

CVE-2024-49843 - Improper Validation of Array Index in Graphics_Linux

Memory corruption while processing IOCTL from user space to handle GPU AHB bus error.

πŸ“… Published: Feb. 3, 2025, 4:51 p.m. πŸ”„ Last Modified: Feb. 5, 2025, 4:02 p.m.
Total resulsts: 349182
Page 6864 of 34,919
Β« previous page Β» next page
Filters