6.4

CVSS3.1

CVE-2024-12443 - CRM Perks – WordPress HelpDesk Integration – Zendesk, Freshdesk, HelpScout <= 1.1.6 - Authenticated…

The CRM Perks – WordPress HelpDesk Integration – Zendesk, Freshdesk, HelpScout plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'crm-perks-tickets' shortcode in all versions up to, and including, 1.1.6 due to insufficient input sanitization and output escaping on u…

📅 Published: Dec. 16, 2024, 10:24 p.m. 🔄 Last Modified: April 8, 2026, 5:12 p.m.

7.1

CVSS3.1

CVE-2024-56017 - WordPress Stop Registration Spam Plugin <= 1.23 - CSRF to Stored XSS vulnerability

Cross-Site Request Forgery (CSRF) vulnerability in Tom Royal Stop Registration Spam allows Stored XSS.This issue affects Stop Registration Spam: from n/a through 1.23.

📅 Published: Dec. 16, 2024, 10:24 p.m. 🔄 Last Modified: July 12, 2025, 10:44 p.m.

5.3

CVSS3.1

CVE-2024-35230 - Welcome and About GeoServer pages communicate version and revision information

GeoServer is an open source software server written in Java that allows users to share and edit geospatial data. In affected versions the welcome and about page includes version and revision information about the software in use (including library and components used). This information is sensitive…

📅 Published: Dec. 16, 2024, 10:18 p.m. 🔄 Last Modified: Aug. 26, 2025, 4:48 p.m.

6.5

CVSS3.1

CVE-2024-12698 - Ose-olm-catalogd-container: incomplete fix for rapid reset (cve-2023-39325/cve-2023-44487)

An incomplete fix for ose-olm-catalogd-container was issued for the Rapid Reset Vulnerability (CVE-2023-39325/CVE-2023-44487) where only unauthenticated streams were protected, not streams created by authenticated sources.

📅 Published: Dec. 16, 2024, 8:42 p.m. 🔄 Last Modified: Nov. 20, 2025, 6:22 p.m.

4.8

CVSS4.0

CVE-2024-55951 - Metabase sandboxed users could see filter values from other sandboxed users

Metabase is an open-source data analytics platform. For new sandboxing configurations created in 1.52.0 till 1.52.2.4, sandboxed users are able to see field filter values from other sandboxed users. This is fixed in 1.52.2.5. Users on 1.52.0 or 1.52.1 or 1.5.2 should upgrade to 1.52.2.5. There are …

📅 Published: Dec. 16, 2024, 8:03 p.m. 🔄 Last Modified: July 12, 2025, 10:31 p.m.

9.3

CVSS4.0

CVE-2024-55949 - Privilege escalation in IAM import API in MinIO

MinIO is a high-performance, S3 compatible object store, open sourced under GNU AGPLv3 license. Minio is subject to a privilege escalation in IAM import API, all users are impacted since MinIO commit `580d9db85e04f1b63cc2909af50f0ed08afa965f`. This issue has been addressed in commit `f246c9053f9603…

📅 Published: Dec. 16, 2024, 8:02 p.m. 🔄 Last Modified: July 12, 2025, 10:45 p.m.

6.3

CVSS4.0

CVE-2024-12667 - InvoicePlane view session expiration

A vulnerability was found in InvoicePlane up to 1.6.1 and classified as problematic. Affected by this issue is some unknown functionality of the file /invoices/view. The manipulation leads to session expiration. The attack may be launched remotely. The complexity of an attack is rather high. The ex…

📅 Published: Dec. 16, 2024, 8 p.m. 🔄 Last Modified: Dec. 19, 2024, 3:10 p.m.

5.1

CVSS4.0

CVE-2024-12666 - ClassCMS User Management Page admin insufficient privileges

A vulnerability has been found in ClassCMS up to 4.8 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /admin?do=admin:user:editPost of the component User Management Page. The manipulation leads to improper handling of insufficient privileges. The at…

📅 Published: Dec. 16, 2024, 8 p.m. 🔄 Last Modified: Dec. 19, 2024, 3:01 p.m.

5.3

CVSS4.0

CVE-2024-12665 - ruifang-tech Rebuild Task Comment Attachment Upload cross site scripting

A vulnerability, which was classified as problematic, was found in ruifang-tech Rebuild 3.8.5. Affected is an unknown function of the component Task Comment Attachment Upload. The manipulation leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclose…

📅 Published: Dec. 16, 2024, 7:31 p.m. 🔄 Last Modified: Dec. 19, 2024, 2:55 p.m.

5.3

CVSS4.0

CVE-2024-12664 - ruifang-tech Rebuild Project Task Comment cross site scripting

A vulnerability, which was classified as problematic, has been found in ruifang-tech Rebuild 3.8.5. This issue affects some unknown processing of the component Project Task Comment Handler. The manipulation leads to cross site scripting. The attack may be initiated remotely. The exploit has been di…

📅 Published: Dec. 16, 2024, 7:31 p.m. 🔄 Last Modified: Dec. 19, 2024, 2:55 p.m.
Total resulsts: 343919
Page 6914 of 34,392
« previous page » next page
Filters