7.8

CVSS3.1

CVE-2024-8588 - Autodesk AutoCAD SLDPRT File Parsing Out-Of-Bounds Read Vulnerability

A maliciously crafted SLDPRT file when parsed in odxsw_dll.dll through Autodesk AutoCAD can force a Out-of-Bounds Read vulnerability. A malicious actor can leverage this vulnerability to cause a crash, write sensitive data, or execute arbitrary code in the context of the current process.

πŸ“… Published: Oct. 29, 2024, 9:06 p.m. πŸ”„ Last Modified: Aug. 26, 2025, 6:28 p.m.

7.8

CVSS3.1

CVE-2024-8587 - Autodesk AutoCAD SLDPRT File Parsing Heap-based Buffer Overflow Code Execution Vulnerability

A maliciously crafted SLDPRT file when parsed in odxsw_dll.dll through Autodesk AutoCAD can force a Heap Based Buffer Overflow vulnerability. A malicious actor can leverage this vulnerability to cause a crash, write sensitive data, or execute arbitrary code in the context of the current process.

πŸ“… Published: Oct. 29, 2024, 9:03 p.m. πŸ”„ Last Modified: Sept. 3, 2025, 5:57 p.m.

4.3

CVSS3.1

CVE-2024-50455 - WordPress SEOPress plugin <= 8.1.1 - Broken Access Control vulnerability

Missing Authorization vulnerability in Benjamin Denis SEOPress wp-seopress allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects SEOPress: from n/a through <= 8.1.1.

πŸ“… Published: Oct. 29, 2024, 9:03 p.m. πŸ”„ Last Modified: April 23, 2026, 3:19 p.m.

5.4

CVSS3.1

CVE-2024-50456 - WordPress SEOPress plugin <= 8.1.1 - Broken Access Control vulnerability

Missing Authorization vulnerability in Benjamin Denis SEOPress wp-seopress allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects SEOPress: from n/a through <= 8.1.1.

πŸ“… Published: Oct. 29, 2024, 9 p.m. πŸ”„ Last Modified: April 23, 2026, 3:19 p.m.

5.3

CVSS3.1

CVE-2024-50459 - WordPress AidWP plugin <= 3.2.3 - Broken Access Control vulnerability

Missing Authorization vulnerability in Hossni Mubarak AidWP wp-stripe-donation allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects AidWP: from n/a through <= 3.2.3.

πŸ“… Published: Oct. 29, 2024, 4:36 p.m. πŸ”„ Last Modified: April 23, 2026, 3:19 p.m.

4.3

CVSS3.1

CVE-2024-50466 - WordPress DarkMySite – Advanced Dark Mode Plugin for WordPress plugin <= 1.2.8 - Cross Site Request…

Cross-Site Request Forgery (CSRF) vulnerability in DarkMySite DarkMySite – Advanced Dark Mode Plugin for WordPress darkmysite allows Cross Site Request Forgery.This issue affects DarkMySite – Advanced Dark Mode Plugin for WordPress: from n/a through 1.2.8.

πŸ“… Published: Oct. 29, 2024, 4:34 p.m. πŸ”„ Last Modified: Nov. 6, 2024, 11:13 p.m.

9.8

CVSS3.1

CVE-2024-9989 - Crypto <= 2.18 - Authentication Bypass via log_in

The Crypto plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.18. This is due to a limited arbitrary method call to 'crypto_connect_ajax_process::log_in' function in the 'crypto_connect_ajax_process' function. This makes it possible for unauthenticated a…

πŸ“… Published: Oct. 29, 2024, 4:31 p.m. πŸ”„ Last Modified: April 8, 2026, 7:22 p.m.

8.8

CVSS3.1

CVE-2024-9990 - Crypto <= 2.15 - Cross-Site Request Forgery to Authentication Bypass

The Crypto plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.15. This is due to missing nonce validation in the 'crypto_connect_ajax_process::check' function. This makes it possible for unauthenticated attackers to log in as any existing user on th…

πŸ“… Published: Oct. 29, 2024, 4:31 p.m. πŸ”„ Last Modified: April 8, 2026, 7:22 p.m.

9.8

CVSS3.1

CVE-2024-9988 - Crypto <= 2.19 - Authentication Bypass via register

The Crypto plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.19. This is due to missing validation on the user being supplied in the 'crypto_connect_ajax_process::register' function. This makes it possible for unauthenticated attackers to log in as any …

πŸ“… Published: Oct. 29, 2024, 4:31 p.m. πŸ”„ Last Modified: April 8, 2026, 6:23 p.m.

4

CVSS3.1

CVE-2024-10491 - Preload arbitrary resources by injecting additional `Link` headers

A vulnerability has been identified in the Express response.linksΒ function, allowing for arbitrary resource injection in the LinkΒ header when unsanitized data is used. The issue arises from improper sanitization in `Link` header values, which can allow a combination of characters like `,`, `;`, an…

πŸ“… Published: Oct. 29, 2024, 4:23 p.m. πŸ”„ Last Modified: Jan. 8, 2026, 9:04 p.m.
Total resulsts: 349182
Page 8093 of 34,919
Β« previous page Β» next page
Filters