7.9

CVSS3.1

CVE-2024-8038 -

Vulnerable juju introspection abstract UNIX domain socket. An abstract UNIX domain socket responsible for introspection is available without authentication locally to network namespace users. This enables denial of service attacks.

πŸ“… Published: Oct. 2, 2024, 10:12 a.m. πŸ”„ Last Modified: Aug. 26, 2025, 5:44 p.m.

6.5

CVSS3.1

CVE-2024-8037 -

Vulnerable juju hook tool abstract UNIX domain socket. When combined with an attack of JUJU_CONTEXT_ID, any user on the local system with access to the default network namespace may connect to the @/var/lib/juju/agents/unit-xxxx-yyyy/agent.socket and perform actions that are normally reserved to a …

πŸ“… Published: Oct. 2, 2024, 10:12 a.m. πŸ”„ Last Modified: Aug. 26, 2025, 5:48 p.m.

6.5

CVSS3.1

CVE-2024-35294 - Schneider Elektronik Series 700 prone to missing authentication for traffic capture function

An unauthenticated remote attacker may use the devices traffic capture without authentication to grab plaintext administrative credentials.

πŸ“… Published: Oct. 2, 2024, 10:07 a.m. πŸ”„ Last Modified: Oct. 4, 2024, 1:50 p.m.

8.7

CVSS3.1

CVE-2024-7558 -

JUJU_CONTEXT_ID is a predictable authentication secret. On a Juju machine (non-Kubernetes) or Juju charm container (on Kubernetes), an unprivileged user in the same network namespace can connect to an abstract domain socket and guess the JUJU_CONTEXT_ID value. This gives the unprivileged user acces…

πŸ“… Published: Oct. 2, 2024, 10:06 a.m. πŸ”„ Last Modified: Aug. 26, 2025, 5:42 p.m.

9.1

CVSS3.1

CVE-2024-35293 - Schneider Elektronik Series 700 prone to missing authentication for critical reset function

An unauthenticated remote attacker may use a missing authentication for critical function vulnerability to reboot or erase the affected devices resulting in data loss and/or a DoS.

πŸ“… Published: Oct. 2, 2024, 9:51 a.m. πŸ”„ Last Modified: Oct. 4, 2024, 1:50 p.m.

6.4

CVSS3.1

CVE-2024-8505 - WordPress Infinite Scroll - Ajax Load More <= 7.1.2 - Authenticated (Contributor+) Stored Cross-Sit…

The WordPress Infinite Scroll – Ajax Load More plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the β€˜button_label’ parameter in all versions up to, and including, 7.1.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attacker…

πŸ“… Published: Oct. 2, 2024, 9:31 a.m. πŸ”„ Last Modified: Oct. 7, 2024, 7:26 p.m.

6.4

CVSS3.1

CVE-2024-8282 - Ibtana – WordPress Website Builder <= 1.2.4.4 - Authenticated (Contributor+) Stored Cross-Site Scri…

The Ibtana – WordPress Website Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the β€˜align’ attribute within the 'wp:ive/ive-productscarousel' Gutenberg block in all versions up to, and including, 1.2.4.4 due to insufficient input sanitization and output escaping. This …

πŸ“… Published: Oct. 2, 2024, 9:31 a.m. πŸ”„ Last Modified: Oct. 7, 2024, 8:11 p.m.

0.0

CVE-2024-44017 - WordPress MH Board plugin <= 1.3.2.1 - Local File Inclusion vulnerability

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in MinHyeong Lim MH Board mh-board allows PHP Local File Inclusion.This issue affects MH Board: from n/a through <= 1.3.2.1.

πŸ“… Published: Oct. 2, 2024, 9:26 a.m. πŸ”„ Last Modified: April 1, 2026, 4:17 p.m.

0.0

CVE-2024-44030 - WordPress Checkout Mestres WP plugin <= 8.6 - Local File Inclusion vulnerability

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Mestres do WP Checkout Mestres WP checkout-mestres-wp allows Absolute Path Traversal.This issue affects Checkout Mestres WP: from n/a through <= 8.6.

πŸ“… Published: Oct. 2, 2024, 9:19 a.m. πŸ”„ Last Modified: April 1, 2026, 4:17 p.m.

6.1

CVSS3.1

CVE-2024-9218 - Magazine Blocks – Blog Designer, Magazine & Newspaper Website Builder, Page Builder with Posts Bloc…

The Magazine Blocks – Blog Designer, Magazine & Newspaper Website Builder, Page Builder with Posts Blocks, Post Grid plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 1.3…

πŸ“… Published: Oct. 2, 2024, 8:31 a.m. πŸ”„ Last Modified: Oct. 8, 2024, 3:33 p.m.
Total resulsts: 342218
Page 7723 of 34,222
Β« previous page Β» next page
Filters