4.9

CVSS3.1

CVE-2024-9678 -

An SQL Injection vulnerability existed in DLP Extension 11.11.1.3. The vulnerability allowed an attacker to perform arbitrary SQL queries potentially leading to command execution.

πŸ“… Published: Dec. 16, 2024, 6:31 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.1

CVSS3.1

CVE-2024-12642 - Chunghwa Telecom TenderDocTransfer - Arbitrary File Write

TenderDocTransfer from Chunghwa Telecom has an Arbitrary File Write vulnerability. The application sets up a simple local web server and provides APIs for communication with the target website. Due to the lack of CSRF protection for the APIs, unauthenticated remote attackers could use these APIs th…

πŸ“… Published: Dec. 16, 2024, 6:30 a.m. πŸ”„ Last Modified: Dec. 23, 2025, 7:53 p.m.

9.6

CVSS3.1

CVE-2024-12641 - Chunghwa Telecom TenderDocTransfer - Reflected Cross-site Scripting to RCE

TenderDocTransfer from Chunghwa Telecom has a Reflected Cross-site scripting vulnerability. The application sets up a simple local web server and provides APIs for communication with the target website. Due to the lack of CSRF protection for the APIs, unauthenticated remote attackers could use spec…

πŸ“… Published: Dec. 16, 2024, 6:14 a.m. πŸ”„ Last Modified: Dec. 23, 2025, 7:54 p.m.

5.3

CVSS3.1

CVE-2024-5333 - The Events Calendar < 6.8.2.1 - Unauthenticated Password Protected Event Disclosure

The Events Calendar WordPress plugin before 6.8.2.1 is missing access checks in the REST API, allowing for unauthenticated users to access information about password protected events.

πŸ“… Published: Dec. 16, 2024, 6 a.m. πŸ”„ Last Modified: Aug. 27, 2025, noon

5.4

CVSS3.1

CVE-2024-11841 - Tithe.ly Giving Button <= 1.1 - Contributor+ Stored XSS via Shortcode

The Tithe.ly Giving Button WordPress plugin through 1.1 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

πŸ“… Published: Dec. 16, 2024, 6 a.m. πŸ”„ Last Modified: May 17, 2025, 2:19 a.m.

5.3

CVSS3.1

CVE-2024-8116 - Incorrect Authorization in GitLab

An issue has been discovered in GitLab CE/EE affecting all versions from 16.9 before 17.4.6, 17.5 before 17.5.4, and 17.6 before 17.6.2. By using a specific GraphQL query, under specific conditions an unauthorized user can retrieve branch names.

πŸ“… Published: Dec. 16, 2024, 4:31 a.m. πŸ”„ Last Modified: July 11, 2025, 8:34 p.m.

5.3

CVSS3.1

CVE-2024-8650 - Incorrect Authorization in GitLab

An issue was discovered in GitLab CE/EE affecting all versions from 15.0 prior to 17.4.6, 17.5 prior to 17.5.4, and 17.6 prior to 17.6.2 that allowed non-member users to view unresolved threads marked as internal notes in public projects merge requests.

πŸ“… Published: Dec. 16, 2024, 4:30 a.m. πŸ”„ Last Modified: July 11, 2025, 8:34 p.m.

7.5

CVSS3.1

CVE-2024-52949 - iptraf-ng: buffer overflow via ifaces.c

iptraf-ng 1.2.1 has a stack-based buffer overflow. In src/ifaces.c, the strcpy function consistently fails to control the size, and it is consequently possible to overflow memory on the stack.

πŸ“… Published: Dec. 16, 2024, midnight πŸ”„ Last Modified: Oct. 14, 2025, 5:29 p.m.

4.8

CVSS3.1

CVE-2024-55451 -

A Stored Cross-Site Scripting (XSS) vulnerability exists in authenticated SVG file upload and viewing functionality in UJCMS 9.6.3. The vulnerability arises from insufficient sanitization of embedded attributes in uploaded SVG files. When a maliciously crafted SVG file is viewed by other backend us…

πŸ“… Published: Dec. 16, 2024, midnight πŸ”„ Last Modified: April 24, 2025, 3:26 p.m.

8.8

CVSS3.1

CVE-2024-53376 -

CyberPanel before 2.3.8 allows remote authenticated users to execute arbitrary commands via shell metacharacters in the phpSelection field to the websites/submitWebsiteCreation URI.

πŸ“… Published: Dec. 16, 2024, midnight πŸ”„ Last Modified: Sept. 5, 2025, 12:33 a.m.
Total resulsts: 349182
Page 7458 of 34,919
Β« previous page Β» next page
Filters