3.1

CVSS3.1

CVE-2023-23472 - IBM InfoSphere Information Server information disclosure

IBM InfoSphere DataStage Flow Designer (InfoSphere Information Server 11.7) could allow an authenticated user to obtain sensitive information that could aid in further attacks against the system.

πŸ“… Published: Dec. 11, 2024, 12:14 p.m. πŸ”„ Last Modified: March 11, 2025, 5:24 p.m.

6.1

CVSS3.1

CVE-2024-12325 - Waymark <= 1.4.1 - Reflected Cross-Site Scripting via 'content'

The Waymark plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the β€˜content’ parameter in all versions up to, and including, 1.4.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts i…

πŸ“… Published: Dec. 11, 2024, 11:24 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS3.1

CVE-2024-12294 - Last Viewed Posts by WPBeginner <= 1.0.1 - Unauthenticated Sensitive Information Exposure

The Last Viewed Posts by WPBeginner plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.0.1 via the 'get_legacy_cookies' function. This makes it possible for unauthenticated attackers to extract sensitive data including titles and permalinks …

πŸ“… Published: Dec. 11, 2024, 10:57 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.1

CVSS3.1

CVE-2024-11840 - RapidLoad – Optimize Web Vitals Automatically <= 2.4.2 - Missing Authorization to Authenticated (Su…

The RapidLoad – Optimize Web Vitals Automatically plugin for WordPress is vulnerable to unauthorized access of data and modification of data due to a missing capability check on the uucss_data, update_rapidload_settings, wp_ajax_update_htaccess_file, uucss_update_rule, upload_rules, get_all_rules, …

πŸ“… Published: Dec. 11, 2024, 10:57 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS3.1

CVE-2024-11008 - Members <= 3.2.10 - Unauthenticated Content Restriction Bypass to Sensitive Information Exposure

The Members – Membership & User Role Editor Plugin plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.2.10 via the WordPress core search feature. This makes it possible for unauthenticated attackers to extract sensitive data from posts that …

πŸ“… Published: Dec. 11, 2024, 10:57 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS4.0

CVE-2024-11401 - Rapid7 Insight Platform Privilege Escalation Vulnerability

Rapid7 Insight Platform versions prior to November 13th 2024, suffer from a privilege escalation vulnerability whereby, due to a lack of authorization checks, an attacker can successfully update the password policy in the platform settings as a standard user by crafting an API (the functionality wa…

πŸ“… Published: Dec. 11, 2024, 9:46 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

9.3

CVSS4.0

CVE-2024-11737 -

CWE-20: Improper Input Validation vulnerability exists that could lead to a denial of service and a loss of confidentiality, integrity of the controller when an unauthenticated crafted Modbus packet is sent to the device.

πŸ“… Published: Dec. 11, 2024, 9:36 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

4.3

CVSS3.1

CVE-2024-54269 - WordPress Notibar plugin <= 2.1.4 - Broken Access Control vulnerability

Missing Authorization vulnerability in Ninja Team Notibar notibar allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Notibar: from n/a through <= 2.1.4.

πŸ“… Published: Dec. 11, 2024, 9:34 a.m. πŸ”„ Last Modified: April 23, 2026, 3:22 p.m.

7.1

CVSS3.1

CVE-2024-12363 - Insufficient permissions in the TeamViewer Patch & Asset Management component

Insufficient permissions in the TeamViewer Patch & Asset Management component prior to version 24.12 on Windows allows a local authenticated user to delete arbitrary files.Β TeamViewer Patch & Asset Management is part of TeamViewer Remote Management.

πŸ“… Published: Dec. 11, 2024, 9:32 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.3

CVSS4.0

CVE-2024-10511 -

CWE-287: Improper Authentication vulnerability exists that could cause Denial of access to the web interface when someone on the local network repeatedly requests the /accessdenied URL.

πŸ“… Published: Dec. 11, 2024, 9:04 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 349182
Page 7525 of 34,919
Β« previous page Β» next page
Filters