8.2

CVSS3.1

CVE-2023-24011 - Data Distribution Service (DDS) Chain of Trust (CoT) violation vulnerability in Cyclone DDS

An attacker can arbitrarily craft malicious DDS Participants (or ROS 2 Nodes) with valid certificates to compromise and get full control of the attacked secure DDS databus system by exploiting vulnerable attributes in the configuration of PKCS#7 certificate’s validation. This is caused by a non-com…

📅 Published: Jan. 9, 2025, 2:36 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

8.2

CVSS3.1

CVE-2023-24010 - Data Distribution Service (DDS) Chain of Trust (CoT) violation in Fast DDS

An attacker can arbitrarily craft malicious DDS Participants (or ROS 2 Nodes) with valid certificates to compromise and get full control of the attacked secure DDS databus system by exploiting vulnerable attributes in the configuration of PKCS#7 certificate’s validation. This is caused by a non-com…

📅 Published: Jan. 9, 2025, 2:36 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

5.5

CVSS3.1

CVE-2022-22491 - IBM App Connect Enterprise Certified Container denial of service

IBM App Connect Enterprise Certified Container 7.1, 7.2, 8.0, 8.1, 8.2, 9.0, 9.1, 9.2, 10.0, 10.1, 11.0, 11.1, 11.2, 11.3, 11.4, 11.5, 11.6, 12.0, 12.1, 12.2, 12.3, and 12.4 operands running in Red Hat OpenShift do not restrict writing to the local filesystem, which may result in exhausting the ava…

📅 Published: Jan. 9, 2025, 2:11 p.m. 🔄 Last Modified: June 20, 2025, 5:54 p.m.

5.4

CVSS3.1

CVE-2024-43176 - IBM OpenPages information disclosure

IBM OpenPages 9.0 could allow an authenticated user to obtain sensitive information such as configurations that should only be available to privileged users.

📅 Published: Jan. 9, 2025, 2:03 p.m. 🔄 Last Modified: Sept. 29, 2025, 10:26 p.m.

6.4

CVSS3.1

CVE-2024-6155 - Greenshift – animation and page builder blocks <= 9.0.0 - Missing Authorization to Authenticated (S…

The Greenshift – animation and page builder blocks plugin for WordPress is vulnerable to Authenticated (Subscriber+) Server-Side Request Forgery and Stored Cross Site Scripting in all versions up to, and including, 9.0.0 due to a missing capability check in the greenshift_download_file_localy funct…

📅 Published: Jan. 9, 2025, 11:11 a.m. 🔄 Last Modified: April 8, 2026, 5:35 p.m.

6.4

CVSS3.1

CVE-2024-12514 - 3DVieweronline <= 2.2.2 - Authenticated (Contributor+) Stored Cross-Site Scripting

The 3DVieweronline plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's '3Dvo-model' shortcode in all versions up to, and including, 2.2.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated a…

📅 Published: Jan. 9, 2025, 11:11 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

6.1

CVSS3.1

CVE-2024-12394 - Action Network <= 1.4.4 - Reflected Cross-Site Scripting

The Action Network plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'page' parameter in all versions up to, and including, 1.4.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scrip…

📅 Published: Jan. 9, 2025, 11:11 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

8.6

CVSS3.1

CVE-2024-12542 - linkID <= 0.1.2 - Missing Authorization to Unauthenticated Sensitive Information Exposure

The linkID plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check when including the 'phpinfo' function in all versions up to, and including, 0.1.2. This makes it possible for unauthenticated attackers to read configuration settings and predefined variab…

📅 Published: Jan. 9, 2025, 11:11 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

9.8

CVSS3.1

CVE-2024-11642 - Post Grid Master <= 3.4.12 - Missing Authorization to Unauthenticated Local PHP File Inclusion

The Post Grid Master – Custom Post Types, Taxonomies & Ajax Filter Everything with Infinite Scroll, Load More, Pagination & Shortcode Builder plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.4.12 via the 'locate_template' function. This makes it pos…

📅 Published: Jan. 9, 2025, 11:11 a.m. 🔄 Last Modified: April 8, 2026, 7:19 p.m.

4.3

CVSS3.1

CVE-2024-12616 - Bitly's WordPress Plugin <= 2.7.3 - Missing Authorization to Authenticated (Subscriber+) Settings U…

The Bitly&#039;s WordPress Plugin plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on several AJAX actions in all versions up to, and including, 2.7.3. This makes it possible for authenticated attackers, with Subscriber-level access and above…

📅 Published: Jan. 9, 2025, 11:11 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 346556
Page 6946 of 34,656
« previous page » next page
Filters