4.7

CVSS3.1

CVE-2024-8499 - Checkout Field Editor (Checkout Manager) for WooCommerce <= 2.0.3 - Reflected Cross-Site Scripting …

The Checkout Field Editor (Checkout Manager) for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the β€˜render_review_request_notice’ function in all versions up to, and including, 2.0.3 due to insufficient input sanitization and output escaping. This makes it pos…

πŸ“… Published: Oct. 4, 2024, 12:46 p.m. πŸ”„ Last Modified: Feb. 17, 2026, 7:59 p.m.

8.7

CVSS4.0

CVE-2024-47790 - Missing Authorization Vulnerability

** UNSUPPORTED WHEN ASSIGNED ** This vulnerability exists in D3D Security IP Camera D8801 due to usage of insecure Real-Time Streaming Protocol (RTSP) version for live video streaming. A remote attacker could exploit this vulnerability by crafting a RTSP packet leading to unauthorized access to li…

πŸ“… Published: Oct. 4, 2024, 12:46 p.m. πŸ”„ Last Modified: Oct. 14, 2024, 11:15 a.m.

5.1

CVSS3.1

CVE-2024-9484 -

An null-pointer-derefrence in the engine module in AVG/Avast Antivirus signature <24092400 released on 24/Sep/2024 on MacOS allows a malformed xar file to crash the application during file processing.

πŸ“… Published: Oct. 4, 2024, 12:44 p.m. πŸ”„ Last Modified: Nov. 8, 2024, 8:55 p.m.

8.7

CVSS4.0

CVE-2024-47789 - Credential Leakage Vulnerability

** UNSUPPORTED WHEN ASSIGNED ** This vulnerability exists in D3D Security IP Camera D8801 due to usage of weak authentication scheme of the HTTP header protocol where authorization tag contain a Base-64 encoded username and password. A remote attacker could exploit this vulnerability by crafting a …

πŸ“… Published: Oct. 4, 2024, 12:43 p.m. πŸ”„ Last Modified: Oct. 14, 2024, 11:15 a.m.

6.3

CVSS4.0

CVE-2024-9513 - Netadmin Software NetAdmin IAM HTTP POST Request ReturnUserQuestionsFilled information exposure

A vulnerability was found in Netadmin Software NetAdmin IAM up to 3.5 and classified as problematic. Affected by this issue is some unknown functionality of the file /controller/api/Answer/ReturnUserQuestionsFilled of the component HTTP POST Request Handler. The manipulation of the argument usernam…

πŸ“… Published: Oct. 4, 2024, 12:31 p.m. πŸ”„ Last Modified: Nov. 13, 2024, 9:57 p.m.

7.1

CVSS4.0

CVE-2024-47657 - Improper Access Control Vulnerability

This vulnerability exists in the Shilpi Net Back Office due to improper access controls on certain API endpoints. An authenticated remote attacker could exploit this vulnerability by manipulating a parameter dfclientid through API request URLs which could lead to unauthorized access to sensitive in…

πŸ“… Published: Oct. 4, 2024, 12:30 p.m. πŸ”„ Last Modified: Oct. 16, 2024, 3:44 p.m.

5.1

CVSS3.1

CVE-2024-9483 - Uninitialized variable in digital signiture verification may crash the application

A null-pointer-dereference in the signature verification module in AVG/Avast Antivirus signature <24092400 released on 24/Sep/2024 on MacOS may allow a malformed xar file to crash the application during processing.

πŸ“… Published: Oct. 4, 2024, 12:29 p.m. πŸ”„ Last Modified: Nov. 8, 2024, 8:54 p.m.

9.3

CVSS4.0

CVE-2024-47656 - User Enumeration vulnerability

This vulnerability exists in Shilpi Client Dashboard due to missing restrictions for incorrect login attempts on its API based login. A remote attacker could exploit this vulnerability by conducting a brute force attack on password, which could lead to gain unauthorized access to other user account…

πŸ“… Published: Oct. 4, 2024, 12:24 p.m. πŸ”„ Last Modified: Oct. 16, 2024, 3:32 p.m.

5.1

CVSS3.1

CVE-2024-9482 - Out of Bounds write on scan of malformed Mach-O file may crash the application

An out-of-bounds write in the engine module in AVG/Avast Antivirus signature <24092400 released on 24/Sep/2024 on MacOS allows a malformed Mach-O file to crash the application during file processing.

πŸ“… Published: Oct. 4, 2024, 12:22 p.m. πŸ”„ Last Modified: Nov. 8, 2024, 8:49 p.m.

8.6

CVSS4.0

CVE-2024-47655 - Unrestricted File Upload Vulnerability

This vulnerability exists in the Shilpi Client Dashboard due to improper validation of files being uploaded other than the specified extension. An authenticated remote attacker could exploit this vulnerability by uploading malicious file, which could lead to remote code execution on targeted applic…

πŸ“… Published: Oct. 4, 2024, 12:21 p.m. πŸ”„ Last Modified: Oct. 16, 2024, 3:26 p.m.
Total resulsts: 342311
Page 7715 of 34,232
Β« previous page Β» next page
Filters