4.7

CVSS3.1

CVE-2024-8968 - MaxButtons < 9.8.1 - Admin+ Stored XSS via Text Color

The WordPress Button Plugin MaxButtons WordPress plugin before 9.8.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisit…

πŸ“… Published: Dec. 20, 2024, 6 a.m. πŸ”„ Last Modified: May 14, 2025, 4:19 p.m.

5.4

CVSS3.1

CVE-2024-11108 - Serious Slider < 1.2.7 - Contributor+ Stored XSS via Shortcode

The Serious Slider WordPress plugin before 1.2.7 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

πŸ“… Published: Dec. 20, 2024, 6 a.m. πŸ”„ Last Modified: May 14, 2025, 4:28 p.m.

4.8

CVSS3.1

CVE-2024-10706 - Download Manager < 3.3.03 - Admin+ Stored XSS

The Download Manager WordPress plugin before 3.3.03 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

πŸ“… Published: Dec. 20, 2024, 6 a.m. πŸ”„ Last Modified: April 17, 2025, 1:52 a.m.

4.8

CVSS3.1

CVE-2024-10555 - MaxButtons < 9.8.1 - Admin+ Stored XSS via Button Width

The WordPress Button Plugin MaxButtons WordPress plugin before 9.8.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisit…

πŸ“… Published: Dec. 20, 2024, 6 a.m. πŸ”„ Last Modified: May 14, 2025, 4:41 p.m.

5.4

CVSS3.1

CVE-2024-5955 -

Cross-site scripting vulnerability in Trellix ePolicy Orchestrator prior to ePO 5.10 Service Pack 1 Update 3 allows a remote authenticated attacker to craft requests causing arbitrary content to be injected into the response when accessing the epolicy Orchestrator.

πŸ“… Published: Dec. 20, 2024, 5:53 a.m. πŸ”„ Last Modified: Dec. 20, 2024, 5:37 p.m.

7.7

CVSS4.0

CVE-2024-21549 -

Versions of the package spatie/browsershot before 5.0.3 are vulnerable to Improper Input Validation due to improper URL validation through the setUrl method. An attacker can exploit this vulnerability by utilizing view-source:file://, which allows for arbitrary file reading on a local file. **Note…

πŸ“… Published: Dec. 20, 2024, 5 a.m. πŸ”„ Last Modified: Oct. 1, 2025, 10:57 a.m.

5.5

CVSS3.1

CVE-2024-44298 -

A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in macOS Sequoia 15.1. An app may be able to access information about a user's contacts.

πŸ“… Published: Dec. 20, 2024, 4:06 a.m. πŸ”„ Last Modified: April 2, 2026, 6:22 p.m.

5.5

CVSS3.1

CVE-2024-44293 -

A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in macOS Sequoia 15.1. A user may be able to view sensitive user information.

πŸ“… Published: Dec. 20, 2024, 4:06 a.m. πŸ”„ Last Modified: April 2, 2026, 6:22 p.m.

7.5

CVSS3.1

CVE-2024-44211 -

This issue was addressed with improved validation of symlinks. This issue is fixed in macOS Sequoia 15.1. An app may be able to access user-sensitive data.

πŸ“… Published: Dec. 20, 2024, 4:06 a.m. πŸ”„ Last Modified: April 2, 2026, 6:21 p.m.

7.5

CVSS3.1

CVE-2024-44231 -

This issue was addressed through improved state management. This issue is fixed in macOS Sequoia 15.1. A person with physical access to a Mac may be able to bypass Login Window during a software update.

πŸ“… Published: Dec. 20, 2024, 4:06 a.m. πŸ”„ Last Modified: April 2, 2026, 6:20 p.m.
Total resulsts: 343968
Page 6882 of 34,397
Β« previous page Β» next page
Filters