6.6

CVSS3.1

CVE-2021-26093 -

An access of uninitialized pointer (CWE-824) vulnerability in FortiWLC versions 8.6.0, 8.5.3 and earlier may allow a local and authenticated attacker to crash the access point being managed by the controller by executing a crafted CLI command.

📅 Published: Dec. 19, 2024, 7:47 a.m. 🔄 Last Modified: Jan. 21, 2025, 8:44 p.m.

5.4

CVSS3.1

CVE-2020-12819 -

A heap-based buffer overflow vulnerability in the processing of Link Control Protocol messages in FortiGate versions 5.6.12, 6.0.10, 6.2.4 and 6.4.1 and earlier may allow a remote attacker with valid SSL VPN credentials to crash the SSL VPN daemon by sending a large LCP packet, when tunnel mode is …

📅 Published: Dec. 19, 2024, 7:40 a.m. 🔄 Last Modified: Jan. 21, 2025, 8:58 p.m.

7.8

CVSS3.1

CVE-2024-4230 -

External Control of File Name or Path vulnerability in Edgecross Basic Software for Windows versions 1.00 and later and Edgecross Basic Software for Developers versions 1.00 and later allows a malicious local attacker to execute an arbitrary malicious code, resulting in information disclosure, tamp…

📅 Published: Dec. 19, 2024, 7:23 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

7.8

CVSS3.1

CVE-2024-4229 -

Incorrect Default Permissions vulnerability in Edgecross Basic Software for Windows versions 1.00 and later and Edgecross Basic Software for Developers versions 1.00 and later allows a malicious local attacker to execute an arbitrary malicious code, resulting in information disclosure, tampering wi…

📅 Published: Dec. 19, 2024, 7:20 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

4.3

CVSS3.1

CVE-2024-12560 - Button Block – Get fully customizable & multi-functional buttons <= 1.1.5 - Authenticated (Contribu…

The Button Block – Get fully customizable & multi-functional buttons plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.1.5 via the 'btn_block_duplicate_post' function. This makes it possible for authenticated attackers, with Contributor-lev…

📅 Published: Dec. 19, 2024, 7:05 a.m. 🔄 Last Modified: April 8, 2026, 5:14 p.m.

5.3

CVSS3.1

CVE-2024-11768 - Download manager <= 3.3.03 - Improper Authorization to Unauthenticated Download of Password-Protect…

The Download Manager plugin for WordPress is vulnerable to unauthorized download of password-protected content due to improper password validation on the checkFilePassword function in all versions up to, and including, 3.3.03. This makes it possible for unauthenticated attackers to download passwor…

📅 Published: Dec. 19, 2024, 5:24 a.m. 🔄 Last Modified: April 8, 2026, 5:35 p.m.

7.3

CVSS3.1

CVE-2024-11740 - Download Manager <= 3.3.03 - Unauthenticated Arbitrary Shortcode Execution

The The Download Manager plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 3.3.03. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for …

📅 Published: Dec. 19, 2024, 5:24 a.m. 🔄 Last Modified: April 8, 2026, 4:50 p.m.

9.4

CVSS4.0

CVE-2024-11984 - SUNNET Corporate Training Management System - Unrestricted Upload of File with Dangerous Type

A unrestricted upload of file with dangerous type vulnerability in epaper draft function in Corporate Training Management System before 10.13 allows remote authenticated users to bypass file upload restrictions and perform arbitrary system commands with SYSTEM privilege via a crafted ZIP file.

📅 Published: Dec. 19, 2024, 4:01 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

5.4

CVSS3.1

CVE-2024-12121 - Broken Link Checker | Finder <= 2.5.0 - Authenticated (Author+) Blind Server-Side Request Forgery

The Broken Link Checker | Finder plugin for WordPress is vulnerable to Blind Server-Side Request Forgery in all versions up to, and including, 2.5.0 via the 'moblc_check_link' function. This makes it possible for authenticated attackers, with Author-level access and above, to make web requests to a…

📅 Published: Dec. 19, 2024, 1:45 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

6.5

CVSS3.1

CVE-2024-10548 - WP Project Manager <= 2.6.15 - Authenticated (Subscriber+) Sensitive Information Exposure via Proje…

The WP Project Manager plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.6.15 via the Project Task List ('/wp-json/pm/v2/projects/1/task-lists') REST API endpoint. This makes it possible for authenticated attackers, with Subscriber-level ac…

📅 Published: Dec. 19, 2024, 1:45 a.m. 🔄 Last Modified: April 8, 2026, 5:12 p.m.
Total resulsts: 347741
Page 7269 of 34,775
« previous page » next page
Filters