7.3

CVSS3.1

CVE-2024-10633 - Quiz Maker Business, Developer, and Agency <= (Multiple Versions) - Unauthenticated Arbitrary Short…

The Quiz Maker Business, Developer, and Agency plugins for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 8.8.0 (Business), up to, and including, 21.8.0 (Developer), and up to, and including, 31.8.0 (Agency). This is due to the software allowing users…

📅 Published: Jan. 26, 2025, 5:24 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

7.2

CVSS3.1

CVE-2024-10574 - Quiz Maker Business, Developer, and Agency <= (Multiple Versions) - Missing Authorization to Google…

The Quiz Maker Business, Developer, and Agency plugins for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'ays_save_google_credentials' function in all versions up to, and including, 8.8.0 (Business), up to, and including, 21.8.0 (Developer), a…

📅 Published: Jan. 26, 2025, 5:24 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

7.5

CVSS3.1

CVE-2024-10628 - Quiz Maker Business, Developer, and Agency <= (Multiple Versions) - Unauthenticated SQL Injection v…

The Quiz Maker Business, Developer, and Agency plugins for WordPress is vulnerable to SQL Injection via the ‘id’ parameter in all versions up to, and including, 8.8.0 (Business), up to, and including, 21.8.0 (Developer), and up to, and including, 31.8.0 (Agency) due to insufficient escaping on the …

📅 Published: Jan. 26, 2025, 5:24 a.m. 🔄 Last Modified: Sept. 27, 2025, 12:16 a.m.

6.1

CVSS3.1

CVE-2024-10636 - Quiz Maker Business, Developer, and Agency <= (Multiple Versions) - Reflected DOM-Based Cross-Site…

The Quiz Maker Business, Developer, and Agency plugins for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘content’ parameter in all versions up to, and including, 8.8.0 (Business), up to, and including, 21.8.0 (Developer), and up to, and including, 31.8.0 (Agency) due to insuffi…

📅 Published: Jan. 26, 2025, 5:24 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

8.1

CVSS3.1

CVE-2022-49043 - libxml: use-after-free in xmlXIncludeAddNode

xmlXIncludeAddNode in xinclude.c in libxml2 before 2.11.0 has a use-after-free.

📅 Published: Jan. 26, 2025, midnight 🔄 Last Modified: Nov. 3, 2025, 9:15 p.m.

7.1

CVSS3.1

CVE-2024-46881 -

Develocity (formerly Gradle Enterprise) before 2024.1.8 has Incorrect Access Control. Project-level access control configuration was introduced in Enterprise Config schema version 8. Migration functionality from schema version 8 to versions 9 and 10 (in affected vulnerable versions) does not includ…

📅 Published: Jan. 26, 2025, midnight 🔄 Last Modified: April 15, 2026, 12:35 a.m.

8.3

CVSS4.0

CVE-2025-24858 -

Develocity (formerly Gradle Enterprise) before 2024.3.1 allows an attacker who has network access to a Develocity server to obtain the hashed password of the system user. The hash algorithm used by Develocity was chosen according to best practices for password storage and provides some protection a…

📅 Published: Jan. 26, 2025, midnight 🔄 Last Modified: April 15, 2026, 12:35 a.m.

8.5

CVSS4.0

CVE-2025-0543 - G DATA Security Client Local privilege escalation

Local privilege escalation in G DATA Security Client due to incorrect assignment of privileges to directories. This vulnerability allows a local, unprivileged attacker to escalate privileges on affected installations by placing an arbitrary executable in a globally writable directory resulting in e…

📅 Published: Jan. 25, 2025, 4:17 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

7.3

CVSS4.0

CVE-2025-0542 - G DATA Management Server Local privilege escalation

Local privilege escalation due to incorrect assignment of privileges of temporary files in the update mechanism of G DATA Management Server. This vulnerability allows a local, unprivileged attacker to escalate privileges on affected installations by placing a crafted ZIP archive in a globally writa…

📅 Published: Jan. 25, 2025, 4:15 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS3.1

CVE-2024-35150 - IBM Maximo Application Suite log manipulation

IBM Maximo Application Suite 8.10.12, 8.11.0, 9.0.1, and 9.1.0 - Monitor Component does not neutralize output that is written to logs, which could allow an attacker to inject false log entries.

📅 Published: Jan. 25, 2025, 2:31 p.m. 🔄 Last Modified: July 8, 2025, 8:22 p.m.
Total resulsts: 349182
Page 6958 of 34,919
« previous page » next page
Filters