4.3

CVSS3.1

CVE-2024-49411 -

Path Traversal in ThemeCenter prior to SMR Dec-2024 Release 1 allows physical attackers to copy apk files to arbitrary path with ThemeCenter privilege.

📅 Published: Dec. 3, 2024, 5:47 a.m. 🔄 Last Modified: Feb. 10, 2025, 11:16 p.m.

5.9

CVSS3.1

CVE-2024-49410 -

Out-of-bounds write in libswmfextractor.so prior to SMR Dec-2024 Release 1 allows local attackers to execute arbitrary code.

📅 Published: Dec. 3, 2024, 5:47 a.m. 🔄 Last Modified: Feb. 10, 2025, 10:14 p.m.

6.4

CVSS3.1

CVE-2024-10484 - Spectra – WordPress Gutenberg Blocks <= 2.16.2 - Authenticated (Contributor+) Stored Cross-Site Scr…

The Spectra – WordPress Gutenberg Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'Team' widget in all versions up to, and including, 2.16.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for a…

📅 Published: Dec. 3, 2024, 5:33 a.m. 🔄 Last Modified: April 8, 2026, 5:20 p.m.

7.1

CVSS3.1

CVE-2024-45068 - Authentication credentials leakage vulnerability in Hitachi Ops Center Common Services within Hitac…

Authentication credentials leakage vulnerability in Hitachi Ops Center Common Services within Hitachi Ops Center OVA. This issue affects Hitachi Ops Center Common Services: from 10.9.3-00 before 11.0.3-00; Hitachi Ops Center OVA: from 10.9.3-00 before 11.0.2-01.

📅 Published: Dec. 3, 2024, 2:32 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

6.4

CVSS3.1

CVE-2024-9694 - CMSMasters Elementor Addon <= 1.14.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via…

The CMSMasters Elementor Addon plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple widgets in all versions up to, and including, 1.14.7 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attacke…

📅 Published: Dec. 3, 2024, 2:05 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

7.2

CVSS3.1

CVE-2024-9200 -

A post-authentication command injection vulnerability in the "host" parameter of the diagnostic function in Zyxel VMG4005-B50A firmware versions through V5.15(ABQA.2.2)C0 could allow an authenticated attacker with administrator privileges to execute operating system (OS) commands on a vulnerable de…

📅 Published: Dec. 3, 2024, 1:33 a.m. 🔄 Last Modified: Jan. 21, 2025, 9:13 p.m.

4.9

CVSS3.1

CVE-2024-9197 -

A post-authentication buffer overflow vulnerability in the parameter "action" of the CGI program in Zyxel VMG3625-T50B firmware versions through V5.50(ABPM.9.2)C0 could allow an authenticated attacker with administrator privileges to cause a temporary denial of service (DoS) condition against the w…

📅 Published: Dec. 3, 2024, 1:24 a.m. 🔄 Last Modified: Jan. 21, 2025, 9:18 p.m.

7.5

CVSS3.1

CVE-2024-8748 -

A buffer overflow vulnerability in the packet parser of the third-party library "libclinkc" in Zyxel VMG8825-T50K firmware versions through V5.50(ABOM.8.4)C0 could allow an attacker to cause a temporary denial of service (DoS) condition against the web management interface by sending a crafted HTTP…

📅 Published: Dec. 3, 2024, 1:15 a.m. 🔄 Last Modified: Jan. 21, 2025, 9:20 p.m.

5.5

CVSS3.1

CVE-2018-9449 -

In process_service_search_attr_rsp of sdp_discovery.cc, there is a possible out of bound read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

📅 Published: Dec. 3, 2024, 12:08 a.m. 🔄 Last Modified: Dec. 18, 2024, 8:10 p.m.

5.5

CVSS3.1

CVE-2018-9441 -

In sdp_copy_raw_data of sdp_discovery.cc, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.

📅 Published: Dec. 3, 2024, 12:02 a.m. 🔄 Last Modified: Dec. 18, 2024, 8 p.m.
Total resulsts: 349182
Page 7642 of 34,919
« previous page » next page
Filters