7.7

CVSS3.1

CVE-2024-43428 - Moodle: cache poisoning via injection into storage

To address a cache poisoning risk in Moodle, additional validation for local storage was required.

๐Ÿ“… Published: Nov. 7, 2024, 1:24 p.m. ๐Ÿ”„ Last Modified: May 1, 2025, 4:01 p.m.

7.5

CVSS3.1

CVE-2024-43426 - Moodle: arbitrary file read risk through pdftex

A flaw was found in pdfTeX. Insufficient sanitizing in the TeX notation filter resulted in an arbitrary file read risk on sites where pdfTeX is available, such as those with TeX Live installed.

๐Ÿ“… Published: Nov. 7, 2024, 1:22 p.m. ๐Ÿ”„ Last Modified: Aug. 5, 2025, 6:33 p.m.

8.1

CVSS3.1

CVE-2024-43425 - Moodle: remote code execution via calculated question types

A flaw was found in Moodle. Additional restrictions are required to avoid a remote code execution risk in calculated question types. Note: This requires the capability to add/update questions.

๐Ÿ“… Published: Nov. 7, 2024, 1:21 p.m. ๐Ÿ”„ Last Modified: May 1, 2025, 4:01 p.m.

6.4

CVSS3.1

CVE-2024-8442 - Prime Slider - Addons For Elementor (Revolution of a slider, Hero Slider, Ecommerce Slider <= 3.15.โ€ฆ

The Prime Slider โ€“ Addons For Elementor (Revolution of a slider, Hero Slider, Ecommerce Slider) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Blog widget in all versions up to, and including, 3.15.18 due to insufficient input sanitization and output escaping on โ€ฆ

๐Ÿ“… Published: Nov. 7, 2024, 12:30 p.m. ๐Ÿ”„ Last Modified: April 8, 2026, 5:32 p.m.

8

CVSS3.1

CVE-2024-24914 -

Authenticated Gaia users can inject code or commands by global variables through special HTTP requests. A Security fix that mitigates this vulnerability is available.

๐Ÿ“… Published: Nov. 7, 2024, 11:25 a.m. ๐Ÿ”„ Last Modified: Aug. 26, 2025, 4:40 p.m.

8.6

CVSS4.0

CVE-2024-10526 - Rapid7 Velociraptor Local Privilege Escalation In Windows Velociraptor Service

Rapid7 Velociraptor MSI Installer versions below 0.73.3 suffer from a vulnerability whereby it creates the installation directory with WRITE_DACL permission to the BUILTIN\\Users group. This allows local users who are not administrators to grant themselves the Full Control permission on Velociraptoโ€ฆ

๐Ÿ“… Published: Nov. 7, 2024, 10:18 a.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

9.1

CVSS3.1

CVE-2024-51504 - Apache ZooKeeper: Authentication bypass with IP-based authentication in Admin Server

When using IPAuthenticationProvider in ZooKeeper Admin Server there is a possibility of Authentication Bypass by Spoofing -- this only impacts IP based authentication implemented in ZooKeeper Admin Server. Default configuration of client's IP address detection inย IPAuthenticationProvider, which useโ€ฆ

๐Ÿ“… Published: Nov. 7, 2024, 9:52 a.m. ๐Ÿ”„ Last Modified: June 24, 2025, 12:27 p.m.

7

CVSS3.1

CVE-2024-10203 - Agent Arbitrary File Deletion

Zohocorp ManageEngine EndPoint Central versions 11.3.2416.21 and below, 11.3.2428.9 and below are vulnerable to Arbitrary File Deletion in the agent installed machines.

๐Ÿ“… Published: Nov. 7, 2024, 9:20 a.m. ๐Ÿ”„ Last Modified: Nov. 21, 2025, 7:13 p.m.

3.8

CVSS3.1

CVE-2024-30142 - HCL BigFix Compliance is affected by a missing secure flag on a cookie

HCL BigFix Compliance is affected by a missing secure flag on a cookie. If a secure flag is not set, cookies may be stolen by an attacker using XSS, resulting in unauthorized access or session cookies could be transferred over an unencrypted channel.

๐Ÿ“… Published: Nov. 7, 2024, 8:58 a.m. ๐Ÿ”„ Last Modified: June 17, 2025, 9:03 p.m.

4.7

CVSS3.1

CVE-2024-30141 - HCL BigFix Compliance is vulnerable to the generation of error messages containing sensitive informโ€ฆ

HCL BigFix Compliance is vulnerable to the generation of error messages containing sensitive information. Detailed error messages can provide enticement information or expose information about its environment, users, or associated data.

๐Ÿ“… Published: Nov. 7, 2024, 8:36 a.m. ๐Ÿ”„ Last Modified: June 17, 2025, 9:03 p.m.
Total resulsts: 349182
Page 7993 of 34,919
ยซ previous page ยป next page
Filters