8.7

CVSS3.1

CVE-2024-47002 -

A html code injection vulnerability exists in the vlan management part of Observium CE 24.4.13528. A specially crafted HTTP request can lead to an arbitrary html code. An authenticated user would need to click a malicious link provided by the attacker.

πŸ“… Published: Jan. 15, 2025, 2:59 p.m. πŸ”„ Last Modified: Aug. 22, 2025, 4:22 p.m.

8.7

CVSS3.1

CVE-2024-45061 -

A cross-site scripting (xss) vulnerability exists in the weather map editor functionality of Observium CE 24.4.13528. A specially crafted HTTP request can lead to a arbitrary javascript code execution. An authenticated user would need to click a malicious link provided by the attacker.

πŸ“… Published: Jan. 15, 2025, 2:59 p.m. πŸ”„ Last Modified: Aug. 22, 2025, 4:25 p.m.

7.5

CVSS3.1

CVE-2024-11322 - CyberPower PowerPanel Business Unauthenticated Restart DoS

A denial-of-service vulnerability exists in CyberPower PowerPanel Business (PPB) 4.11.0. An unauthenticated remote attacker can restart the ppbd.exe process via the PowerPanel Business Service Watchdog service listening on TCP port 2003. The attacker can repeatedly restart ppbd.exe to render it un…

πŸ“… Published: Jan. 15, 2025, 2:03 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

3.3

CVSS3.1

CVE-2024-5198 -

OpenVPN ovpn-dco for Windows version 1.1.1 allows an unprivileged local attacker to send I/O control messages with invalid data to the driver resulting in a NULL pointer dereference leading to a system halt.

πŸ“… Published: Jan. 15, 2025, 12:57 p.m. πŸ”„ Last Modified: June 10, 2025, 4:12 p.m.

4.3

CVSS3.1

CVE-2024-13215 - Elementor Addon Elements <= 1.13.10 - Authenticated (Contributor+) Sensitive Information Exposure v…

The Elementor Addon Elements plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.13.10 via the 'render' function in modules/modal-popup/widgets/modal-popup.php. This makes it possible for authenticated attackers, with Contributor-level access…

πŸ“… Published: Jan. 15, 2025, 12:44 p.m. πŸ”„ Last Modified: April 8, 2026, 4:52 p.m.

5.5

CVSS3.1

CVE-2024-11029 - Freeipa: administrative user data leaked through systemd journal

A flaw was found in the FreeIPA API audit, where it sends the whole FreeIPA command line to journalctl. As a consequence, during the FreeIPA installation process, it inadvertently leaks the administrative user credentials, including the administrator password, to the journal database. In the worst-…

πŸ“… Published: Jan. 15, 2025, noon πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.1

CVSS3.1

CVE-2025-5791 - Users: `root` appended to group listings

A flaw was found in the user's crate for Rust. This vulnerability allows privilege escalation via incorrect group listing when a user or process has fewer than exactly 1024 groups, leading to the erroneous inclusion of the root group in the access list.

πŸ“… Published: Jan. 15, 2025, noon πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

4.3

CVSS3.1

CVE-2024-11851 - NitroPack <= 1.17.0 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Transient Upda…

The NitroPack plugin for WordPress is vulnerable to unauthorized arbitrary transient update due to a missing capability check on the nitropack_rml_notification function in all versions up to, and including, 1.17.0. This makes it possible for authenticated attackers, with subscriber access or higher…

πŸ“… Published: Jan. 15, 2025, 11:29 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.4

CVSS3.1

CVE-2024-12593 - PDF for WPForms + Drag and Drop Template Builder <= 4.6.0 - Authenticated (Contributor+) Stored Cro…

The PDF for WPForms + Drag and Drop Template Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's yeepdf_dotab shortcode in all versions up to, and including, 4.6.0 due to insufficient input sanitization and output escaping on user supplied attributes. This mak…

πŸ“… Published: Jan. 15, 2025, 11:24 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.1

CVSS3.1

CVE-2024-11848 - NitroPack <= 1.17.0 - Missing Authorization to Authenticated (Subscriber+) Limited Options Update

The NitroPack plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'nitropack_dismiss_notice_forever' AJAX action in all versions up to, and including, 1.17.0. This makes it possible for authenticated attackers, with subscriber-level acces…

πŸ“… Published: Jan. 15, 2025, 11:24 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 347981
Page 6984 of 34,799
Β« previous page Β» next page
Filters