6.4

CVSS3.1

CVE-2024-10113 - WP AdCenter – Ad Manager & Adsense Ads <= 2.5.7 - Authenticated (Contributor+) Stored Cross-Site Sc…

The WP AdCenter – Ad Manager & Adsense Ads plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wpadcenter_ad shortcode in all versions up to, and including, 2.5.7 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it pos…

📅 Published: Nov. 15, 2024, 5:30 a.m. 🔄 Last Modified: April 8, 2026, 5:17 p.m.

6.1

CVSS3.1

CVE-2024-39610 -

Cross-site scripting vulnerability exists in FitNesse releases prior to 20241026. If this vulnerability is exploited, an arbitrary script may be executed on the web browser of the user who is using the product.

📅 Published: Nov. 15, 2024, 5:26 a.m. 🔄 Last Modified: Nov. 20, 2024, 3:02 p.m.

5.3

CVSS3.1

CVE-2024-42499 -

Improper limitation of a pathname to a restricted directory ('Path Traversal') issue exists in FitNesse releases prior to 20241026. If this vulnerability is exploited, an attacker may be able to know whether a file exists at a specific path, and/or obtain some part of the file contents under specif…

📅 Published: Nov. 15, 2024, 5:26 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

6.1

CVSS3.1

CVE-2024-9609 - LearnPress Export Import – WordPress extension for LearnPress <= 4.0.4 - Reflected Cross-Site Scrip…

The LearnPress Export Import – WordPress extension for LearnPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'learnpress_import_form_server' parameter in all versions up to, and including, 4.0.4 due to insufficient input sanitization and output escaping. This makes…

📅 Published: Nov. 15, 2024, 4:29 a.m. 🔄 Last Modified: April 8, 2026, 5:21 p.m.

4.3

CVSS3.1

CVE-2024-10897 - Tutor LMS Elementor Addons <= 2.1.5 - Missing Authorization to Authenticated (Subscriber+) Limited …

The Tutor LMS Elementor Addons plugin for WordPress is vulnerable to unauthorized plugin installation due to a missing capability check on the install_etlms_dependency_plugin() function in all versions up to, and including, 2.1.5. This makes it possible for authenticated attackers, with Subscriber-…

📅 Published: Nov. 15, 2024, 4:29 a.m. 🔄 Last Modified: April 8, 2026, 5:10 p.m.

9.8

CVSS3.1

CVE-2024-10924 - Really Simple Security (Free, Pro, and Pro Multisite) 9.0.0 - 9.1.1.1 - Authentication Bypass

The Really Simple Security (Free, Pro, and Pro Multisite) plugins for WordPress are vulnerable to authentication bypass in versions 9.0.0 to 9.1.1.1. This is due to improper user check error handling in the two-factor REST API actions with the 'check_login_and_get_user' function. This makes it poss…

📅 Published: Nov. 15, 2024, 3:18 a.m. 🔄 Last Modified: Jan. 23, 2026, 4:15 p.m.

9.8

CVSS3.1

CVE-2024-11120 - GeoVision EOL devices - OS Command Injection

Certain EOL GeoVision devices have an OS Command Injection vulnerability. Unauthenticated remote attackers can exploit this vulnerability to inject and execute arbitrary system commands on the device. Moreover, this vulnerability has already been exploited by attackers, and we have received related…

📅 Published: Nov. 15, 2024, 2 a.m. 🔄 Last Modified: Oct. 30, 2025, 8:09 p.m.

6.1

CVSS3.1

CVE-2024-48068 -

A cross-site scripting (XSS) vulnerability in Shenzhen Landray Software Co.,LTD Landray EKP v16 and earlier allows attackers to execute arbitrary web scripts or HTML via a crafted payload.

📅 Published: Nov. 15, 2024, midnight 🔄 Last Modified: April 15, 2026, 12:35 a.m.

5.9

CVSS3.1

CVE-2024-24452 -

An invalid memory access when handling the ProtocolIE_ID field of E-RAB Release Indication messages in Athonet vEPC MME v11.4.0 allows attackers to cause a Denial of Service (DoS) to the cellular network by repeatedly initiating connections and sending a crafted payload.

📅 Published: Nov. 15, 2024, midnight 🔄 Last Modified: April 15, 2026, 12:35 a.m.

6.7

CVSS3.1

CVE-2024-49592 -

Trial installer for McAfee Total Protection (legacy trial installer software) 16.0.53 allows local privilege escalation because of an Uncontrolled Search Path Element. The attacker could be "an adversary or knowledgeable user" and the type of attack could be called "DLL-squatting." The issue only a…

📅 Published: Nov. 15, 2024, midnight 🔄 Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 349182
Page 7866 of 34,919
« previous page » next page
Filters