5.3

CVSS3.1

CVE-2024-12104 - Visual Website Collaboration, Feedback & Project Management – Atarim <= 4.0.9 - Missing Authorizati…

The Visual Website Collaboration, Feedback & Project Management – Atarim plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the wpf_delete_file and wpf_delete_file functions in all versions up to, and including, 4.0.9. This makes it possible for una…

πŸ“… Published: Jan. 21, 2025, 9:21 a.m. πŸ”„ Last Modified: April 8, 2026, 6:19 p.m.

6.1

CVSS3.1

CVE-2024-12005 - WP-BibTeX <= 3.0.1 - Cross-Site Request Forgery to Stored and Reflected Cross-Site Scripting

The WP-BibTeX plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.0.1. This is due to missing or incorrect nonce validation on the wp_bibtex_option_page() function. This makes it possible for unauthenticated attackers to inject malicious web scri…

πŸ“… Published: Jan. 21, 2025, 9:21 a.m. πŸ”„ Last Modified: April 8, 2026, 4:33 p.m.

6.4

CVSS3.1

CVE-2025-0371 - Jet Elements <= 2.7.2.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Multiple Wid…

The JetElements plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several widgets in all versions up to, and including, 2.7.2.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contri…

πŸ“… Published: Jan. 21, 2025, 8:21 a.m. πŸ”„ Last Modified: April 22, 2026, 4:30 a.m.

8.8

CVSS3.1

CVE-2024-10936 - String Locator <= 2.6.6 - Unauthenticated PHP Object Injection

The String locator plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.6.6 via deserialization of untrusted input in the 'recursive_unserialize_replace' function. This makes it possible for unauthenticated attackers to inject a PHP Object. No known POP…

πŸ“… Published: Jan. 21, 2025, 8:21 a.m. πŸ”„ Last Modified: April 8, 2026, 4:36 p.m.

6.1

CVSS3.1

CVE-2025-23086 -

On most desktop platforms, Brave Browser versions 1.70.x-1.73.x included a feature to show a site's origin on the OS-provided file selector dialog when a site prompts the user to upload or download a file. However the origin was not correctly inferred in some cases. When combined with an open redir…

πŸ“… Published: Jan. 21, 2025, 4:26 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS3.1

CVE-2024-13536 - 1003 Mortgage Application <= 1.87 - Unauthenticated Full Path Disclosure

The 1003 Mortgage Application plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 1.87. This is due the /inc/class/fnm/export.php file being publicly accessible with error logging enabled. This makes it possible for unauthenticated attackers to retrieve …

πŸ“… Published: Jan. 21, 2025, 4:20 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.2

CVSS3.1

CVE-2024-45091 - IBM UrbanCode Deploy information disclosure

IBM UrbanCode Deploy (UCD) 7.0 through 7.0.5.24, 7.1 through 7.1.2.10, and 7.2 through 7.2.3.13 stores potentially sensitive information in log files that could be read by a local user with access to HTTP request logs.

πŸ“… Published: Jan. 21, 2025, 12:41 a.m. πŸ”„ Last Modified: Jan. 29, 2025, 9:12 p.m.

5.5

CVSS3.1

CVE-2024-57360 - binutils: nm: potential segmentation fault when displaying symbols without version info

https://www.gnu.org/software/binutils/ nm >=2.43 is affected by: Incorrect Access Control. The type of exploitation is: local. The component is: `nm --without-symbol-version` function.

πŸ“… Published: Jan. 21, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.5

CVSS3.1

CVE-2024-24428 -

A reachable assertion in the oai_nas_5gmm_decode function of Open5GS <= 2.6.4 allows attackers to cause a Denial of Service (DoS) via a crafted NGAP packet.

πŸ“… Published: Jan. 21, 2025, midnight πŸ”„ Last Modified: Jan. 24, 2025, 6:44 p.m.

6.5

CVSS3.1

CVE-2023-37033 -

A Null pointer dereference vulnerability in the Mobile Management Entity (MME) in Magma <= 1.8.0 (fixed in v1.9 commit 08472ba98b8321f802e95f5622fa90fec2dea486) allows network-adjacent attackers to crash the MME via an S1AP `Initial UE Message` packet missing an expected `EUTRAN_CGI` field.

πŸ“… Published: Jan. 21, 2025, midnight πŸ”„ Last Modified: March 20, 2025, 2:15 p.m.
Total resulsts: 349182
Page 7032 of 34,919
Β« previous page Β» next page
Filters