6.5

CVSS3.1

CVE-2024-9819 - IDOR in NextGEO's NG Analyser

Authorization Bypass Through User-Controlled Key vulnerability in NextGeography NG Analyser allows Functionality Misuse.This issue affects NG Analyser: before 2.2.711.

πŸ“… Published: Dec. 17, 2024, 12:55 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

4.3

CVSS3.1

CVE-2024-10356 - ElementsReady Addons for Elementor <= 6.4.8 - Authenticated (Contributor+) Sensitive Information Ex…

The ElementsReady Addons for Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 6.4.8 in inc/Widgets/accordion/output/content.php. This makes it possible for authenticated attackers, with Contributor-level access and above, to extrac…

πŸ“… Published: Dec. 17, 2024, 12:43 p.m. πŸ”„ Last Modified: April 8, 2026, 5:15 p.m.

5.3

CVSS3.1

CVE-2024-54677 - Apache Tomcat: DoS in examples web application

Uncontrolled Resource Consumption vulnerability in the examples web application provided with Apache Tomcat leads to denial of service. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.1, from 10.1.0-M1 through 10.1.33, from 9.0.0.M1 through 9.9.97. The following versions were EOL at …

πŸ“… Published: Dec. 17, 2024, 12:35 p.m. πŸ”„ Last Modified: Nov. 3, 2025, 8:16 p.m.

9.8

CVSS3.1

CVE-2024-50379 - Apache Tomcat: RCE due to TOCTOU issue in JSP compilation

Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability during JSP compilation in Apache Tomcat permits an RCE on case insensitive file systems when the default servlet is enabled for write (non-default configuration). This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.1, from 1…

πŸ“… Published: Dec. 17, 2024, 12:34 p.m. πŸ”„ Last Modified: Nov. 3, 2025, 9:17 p.m.

5.7

CVSS3.1

CVE-2024-53240 - xen/netfront: fix crash when removing device

In the Linux kernel, the following vulnerability has been resolved: xen/netfront: fix crash when removing device When removing a netfront device directly after a suspend/resume cycle it might happen that the queues have not been setup again, causing a crash during the attempt to stop the queues a…

πŸ“… Published: Dec. 17, 2024, noon πŸ”„ Last Modified: Nov. 3, 2025, 9:17 p.m.

5.5

CVSS3.1

CVE-2024-53241 - x86/xen: don't do PV iret hypercall through hypercall page

In the Linux kernel, the following vulnerability has been resolved: x86/xen: don't do PV iret hypercall through hypercall page Instead of jumping to the Xen hypercall page for doing the iret hypercall, directly code the required sequence in xen-asm.S. This is done in preparation of no longer usi…

πŸ“… Published: Dec. 17, 2024, noon πŸ”„ Last Modified: Jan. 5, 2026, 10:55 a.m.

6.5

CVSS3.1

CVE-2024-8475 - Protection Mechanism Failure in Digital Operation Services' WiFiBurada

Authentication Bypass by Assumed-Immutable Data vulnerability in Digital Operation Services WiFiBurada allows Manipulating User-Controlled Variables.This issue affects WiFiBurada: before 1.0.5.

πŸ“… Published: Dec. 17, 2024, 11:42 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

4.3

CVSS3.1

CVE-2024-8429 - Improper Authentication in Digital Operation Services' WiFiBurada

Improper Restriction of Excessive Authentication Attempts vulnerability in Digital Operation Services WiFiBurada allows Use of Known Domain Credentials.This issue affects WiFiBurada: before 1.0.5.

πŸ“… Published: Dec. 17, 2024, 11:34 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

4.4

CVSS3.1

CVE-2024-52542 -

Dell AppSync, version 4.6.0.x, contain a Symbolic Link (Symlink) Following vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to information tampering.

πŸ“… Published: Dec. 17, 2024, 11:33 a.m. πŸ”„ Last Modified: Feb. 4, 2025, 3:56 p.m.

5.3

CVSS3.1

CVE-2024-11280 - PPWP – Password Protect Pages <= 1.9.5 - Unauthenticated Content Restriction Bypass to Sensitive In…

The PPWP – Password Protect Pages plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.9.5 via the WordPress core search feature. This makes it possible for unauthenticated attackers to extract sensitive data from posts that have been restrict…

πŸ“… Published: Dec. 17, 2024, 11:24 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 344980
Page 7014 of 34,498
Β« previous page Β» next page
Filters