9.8

CVSS3.1

CVE-2024-12287 - Biagiotti Membership <= 1.0.2 - Authentication Bypass via biagiotti_membership_check_facebook_user

The Biagiotti Membership plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 1.0.2. This is due to the plugin not properly verifying a user's identity prior to authenticating them. This makes it possible for unauthenticated attackers to log in as other โ€ฆ

๐Ÿ“… Published: Dec. 18, 2024, 7:02 a.m. ๐Ÿ”„ Last Modified: April 8, 2026, 4:36 p.m.

7.2

CVSS3.1

CVE-2024-54457 -

Inclusion of undocumented features or chicken bits issue exists in AE1021 firmware versions 2.0.10 and earlier and AE1021PE firmware versions 2.0.10 and earlier, which may allow a logged-in user to enable telnet service.

๐Ÿ“… Published: Dec. 18, 2024, 6:37 a.m. ๐Ÿ”„ Last Modified: Dec. 18, 2024, 3:28 p.m.

7.2

CVSS3.1

CVE-2024-53688 -

Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in AE1021 firmware versions 2.0.10 and earlier and AE1021PE firmware versions 2.0.10 and earlier, which may allow a logged-in user to execute an arbitrary OS command using a crafted HTTP request.

๐Ÿ“… Published: Dec. 18, 2024, 6:36 a.m. ๐Ÿ”„ Last Modified: Dec. 18, 2024, 2:50 p.m.

7.5

CVSS3.1

CVE-2024-47397 -

Weak authentication issue exists in AE1021 firmware versions 2.0.10 and earlier and AE1021PE firmware versions 2.0.10 and earlier. If this vulnerability is exploited, the authentication may be bypassed with an undocumented specific string.

๐Ÿ“… Published: Dec. 18, 2024, 6:35 a.m. ๐Ÿ”„ Last Modified: Dec. 18, 2024, 2:58 p.m.

8.7

CVSS4.0

CVE-2024-1610 - OPPO Store app include remote account token hijacking and sensitive information leakage

In OPPO Store APP, there's a possible escalation of privilege due to improper input validation.

๐Ÿ“… Published: Dec. 18, 2024, 6:18 a.m. ๐Ÿ”„ Last Modified: Dec. 18, 2024, 4:15 p.m.

8.7

CVSS4.0

CVE-2024-21547 -

Versions of the package spatie/browsershot before 5.0.2 are vulnerable to Directory Traversal due to URI normalisation in the browser where the file:// check can be bypassed with file:\\. An attacker could read any file on the server by exploiting the normalization of \ into /.

๐Ÿ“… Published: Dec. 18, 2024, 6:06 a.m. ๐Ÿ”„ Last Modified: July 12, 2025, 11:06 p.m.

7.7

CVSS4.0

CVE-2024-21548 -

Versions of the package bun after 0.0.12 and before 1.1.30 are vulnerable to Prototype Pollution due to improper input sanitization. An attacker can exploit this vulnerability through Bun's APIs that accept objects. **Note:** This issue relates to the widely known and actively developed 'Bun' Javaโ€ฆ

๐Ÿ“… Published: Dec. 18, 2024, 6:06 a.m. ๐Ÿ”„ Last Modified: July 24, 2025, 7:15 a.m.

9.3

CVSS4.0

CVE-2024-21546 -

Versions of the package unisharp/laravel-filemanager before 2.9.1 are vulnerable to Remote Code Execution (RCE) through using a valid mimetype and inserting the . character after the php file extension. This allows the attacker to execute malicious code.

๐Ÿ“… Published: Dec. 18, 2024, 6:06 a.m. ๐Ÿ”„ Last Modified: Aug. 28, 2025, 2:36 p.m.

7.5

CVSS3.1

CVE-2024-4464 -

Authorization bypass through user-controlled key vulnerability in streaming service in Synology Media Server before 1.4-2680, 2.0.5-3152 and 2.2.0-3325 allows remote attackers to read specific files via unspecified vectors.

๐Ÿ“… Published: Dec. 18, 2024, 6 a.m. ๐Ÿ”„ Last Modified: Jan. 29, 2026, 5:47 p.m.

5.4

CVSS3.1

CVE-2024-10892 - Cost Calculator Builder < 3.2.43 - Settings update via CSRF

The Cost Calculator Builder WordPress plugin before 3.2.43 does not have CSRF checks in some AJAX actions, which could allow attackers to make logged in users perform unwanted actions via CSRF attacks.

๐Ÿ“… Published: Dec. 18, 2024, 6 a.m. ๐Ÿ”„ Last Modified: May 14, 2025, 8:14 p.m.
Total resulsts: 343928
Page 6901 of 34,393
ยซ previous page ยป next page
Filters