3.3

CVSS3.1

CVE-2024-5198 -

OpenVPN ovpn-dco for Windows version 1.1.1 allows an unprivileged local attacker to send I/O control messages with invalid data to the driver resulting in a NULL pointer dereference leading to a system halt.

๐Ÿ“… Published: Jan. 15, 2025, 12:57 p.m. ๐Ÿ”„ Last Modified: June 10, 2025, 4:12 p.m.

4.3

CVSS3.1

CVE-2024-13215 - Elementor Addon Elements <= 1.13.10 - Authenticated (Contributor+) Sensitive Information Exposure vโ€ฆ

The Elementor Addon Elements plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.13.10 via the 'render' function in modules/modal-popup/widgets/modal-popup.php. This makes it possible for authenticated attackers, with Contributor-level accessโ€ฆ

๐Ÿ“… Published: Jan. 15, 2025, 12:44 p.m. ๐Ÿ”„ Last Modified: April 8, 2026, 4:52 p.m.

5.5

CVSS3.1

CVE-2024-11029 - Freeipa: administrative user data leaked through systemd journal

A flaw was found in the FreeIPA API audit, where it sends the whole FreeIPA command line to journalctl. As a consequence, during the FreeIPA installation process, it inadvertently leaks the administrative user credentials, including the administrator password, to the journal database. In the worst-โ€ฆ

๐Ÿ“… Published: Jan. 15, 2025, noon ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.1

CVSS3.1

CVE-2025-5791 - Users: `root` appended to group listings

A flaw was found in the user's crate for Rust. This vulnerability allows privilege escalation via incorrect group listing when a user or process has fewer than exactly 1024 groups, leading to the erroneous inclusion of the root group in the access list.

๐Ÿ“… Published: Jan. 15, 2025, noon ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

4.3

CVSS3.1

CVE-2024-11851 - NitroPack <= 1.17.0 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Transient Updaโ€ฆ

The NitroPack plugin for WordPress is vulnerable to unauthorized arbitrary transient update due to a missing capability check on the nitropack_rml_notification function in all versions up to, and including, 1.17.0. This makes it possible for authenticated attackers, with subscriber access or higherโ€ฆ

๐Ÿ“… Published: Jan. 15, 2025, 11:29 a.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.4

CVSS3.1

CVE-2024-12593 - PDF for WPForms + Drag and Drop Template Builder <= 4.6.0 - Authenticated (Contributor+) Stored Croโ€ฆ

The PDF for WPForms + Drag and Drop Template Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's yeepdf_dotab shortcode in all versions up to, and including, 4.6.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makโ€ฆ

๐Ÿ“… Published: Jan. 15, 2025, 11:24 a.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.1

CVSS3.1

CVE-2024-11848 - NitroPack <= 1.17.0 - Missing Authorization to Authenticated (Subscriber+) Limited Options Update

The NitroPack plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'nitropack_dismiss_notice_forever' AJAX action in all versions up to, and including, 1.17.0. This makes it possible for authenticated attackers, with subscriber-level accesโ€ฆ

๐Ÿ“… Published: Jan. 15, 2025, 11:24 a.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.2

CVSS4.0

CVE-2025-0193 - Stored Cross-site Scripting (XSS) Vulnerability in the MGate 5121/5122/5123 Series

A stored Cross-site Scripting (XSS) vulnerability exists in the MGate 5121/5122/5123 Series firmware version v1.0 because of insufficient sanitization and encoding of user input in the "Login Message" functionality. An authenticated attacker with administrative access can exploit this vulnerabilityโ€ฆ

๐Ÿ“… Published: Jan. 15, 2025, 11:05 a.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

4.3

CVSS3.1

CVE-2025-0448 -

Inappropriate implementation in Compositing in Google Chrome prior to 132.0.6834.83 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)

๐Ÿ“… Published: Jan. 15, 2025, 10:58 a.m. ๐Ÿ”„ Last Modified: April 21, 2025, 8:53 p.m.

8.8

CVSS3.1

CVE-2025-0447 -

Inappropriate implementation in Navigation in Google Chrome prior to 132.0.6834.83 allowed a remote attacker to perform privilege escalation via a crafted HTML page. (Chromium security severity: Low)

๐Ÿ“… Published: Jan. 15, 2025, 10:58 a.m. ๐Ÿ”„ Last Modified: April 21, 2025, 8:53 p.m.
Total resulsts: 348038
Page 6990 of 34,804
ยซ previous page ยป next page
Filters