6.4

CVSS3.1

CVE-2024-9655 - Gutenberg Blocks with AI by Kadence WP – Page Builder Features <= 3.3.1 - Authenticated (Contributo…

The Gutenberg Blocks with AI by Kadence WP – Page Builder Features plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Icon widget in all versions up to, and including, 6.6.2 due to insufficient input sanitization and output escaping on user supplied attributes. This …

πŸ“… Published: Nov. 1, 2024, 7:33 a.m. πŸ”„ Last Modified: April 8, 2026, 5:25 p.m.

5.4

CVSS3.1

CVE-2024-7424 - Multiple Page Generator Plugin – MPG <= 4.0.1 - Missing Authorization

The Multiple Page Generator Plugin – MPG plugin for WordPress is vulnerable to unauthorized modification of and access to data due to a missing capability check on several functions in all versions up to, and including, 4.0.1. This makes it possible for authenticated attackers, with Subscriber-leve…

πŸ“… Published: Nov. 1, 2024, 7:33 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.7

CVSS3.1

CVE-2024-0106 -

NVIDIA ConnectX Host Firmware for the BlueField Data Processing Unit (DPU) contains a vulnerability where an attacker may cause an improper handling of insufficient privileges issue. A successful exploit of this vulnerability may lead to denial of service, data tampering, and limited information di…

πŸ“… Published: Nov. 1, 2024, 5:53 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.9

CVSS3.1

CVE-2024-0105 -

NVIDIA ConnectX Firmware contains a vulnerability where an attacker may cause an improper handling of insufficient privileges issue. A successful exploit of this vulnerability may lead to denial of service, data tampering, and limited information disclosure.

πŸ“… Published: Nov. 1, 2024, 5:36 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.4

CVSS3.1

CVE-2024-21510 - sinatra: Open Redirect Vulnerability in Sinatra via X-Forwarded-Host Header

Versions of the package sinatra from 0.0.0 are vulnerable to Reliance on Untrusted Inputs in a Security Decision via the X-Forwarded-Host (XFH) header. When making a request to a method with redirect applied, it is possible to trigger an Open Redirect Attack by inserting an arbitrary address into t…

πŸ“… Published: Nov. 1, 2024, 5 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.9

CVSS4.0

CVE-2024-10620 - knightliao Disconf Configuration Center list improper authentication

A vulnerability was found in knightliao Disconf 2.6.36. It has been classified as critical. This affects an unknown part of the file /api/config/list of the component Configuration Center. The manipulation leads to improper authentication. It is possible to initiate the attack remotely. The exploit…

πŸ“… Published: Nov. 1, 2024, 4:31 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.7

CVSS3.0

CVE-2024-47939 -

Stack-based buffer overflow vulnerability exists in multiple laser printers and MFPs which implement Ricoh Web Image Monitor. If this vulnerability is exploited, receiving a specially crafted request created and sent by an attacker may lead to arbitrary code execution and/or a denial-of-service (Do…

πŸ“… Published: Nov. 1, 2024, 4:29 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.7

CVSS3.0

CVE-2024-49501 -

Sysmac Studio provided by OMRON Corporation contains an incorrect authorization vulnerability. If this vulnerability is exploited, an attacker may access the program which is protected by Data Protection function.

πŸ“… Published: Nov. 1, 2024, 4:07 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS4.0

CVE-2024-10619 - Tongda OA 2017 next_detail.php sql injection

A vulnerability, which was classified as critical, was found in Tongda OA 2017 up to 11.10. Affected is an unknown function of the file /pda/reportshop/next_detail.php. The manipulation of the argument repid leads to sql injection. It is possible to launch the attack remotely. The exploit has been …

πŸ“… Published: Nov. 1, 2024, 4 a.m. πŸ”„ Last Modified: Nov. 4, 2024, 3:11 p.m.

5.3

CVSS4.0

CVE-2024-10618 - Tongda OA 2017 record_detail.php sql injection

A vulnerability, which was classified as critical, has been found in Tongda OA 2017 up to 11.10. This issue affects some unknown processing of the file /pda/reportshop/record_detail.php. The manipulation of the argument repid leads to sql injection. The attack may be initiated remotely. The exploit…

πŸ“… Published: Nov. 1, 2024, 3:31 a.m. πŸ”„ Last Modified: Nov. 4, 2024, 3:11 p.m.
Total resulsts: 345143
Page 7665 of 34,515
Β« previous page Β» next page
Filters