4.3

CVSS3.1

CVE-2024-10312 - Exclusive Addons for Elementor <= 2.7.4 - Authenticated (Contributor+) Sensitive Information Exposu…

The Exclusive Addons for Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.7.4 via the render function in elements/tabs/tabs.php. This makes it possible for authenticated attackers, with Contributor-level access and above, to extr…

πŸ“… Published: Oct. 29, 2024, 7:30 a.m. πŸ”„ Last Modified: April 8, 2026, 5:27 p.m.

6.4

CVSS3.1

CVE-2024-10000 - Masteriyo LMS – eLearning and Online Course Builder for WordPress <= 1.13.3 - Authenticated (Studen…

The Masteriyo LMS – eLearning and Online Course Builder for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the question's content parameter in all versions up to, and including, 1.13.3 due to insufficient input sanitization and output escaping. This makes it possibl…

πŸ“… Published: Oct. 29, 2024, 5:32 a.m. πŸ”„ Last Modified: April 8, 2026, 4:54 p.m.

8.8

CVSS3.1

CVE-2024-10008 - Masteriyo LMS – eLearning and Online Course Builder for WordPress <= 1.13.3 - Authenticated (Studen…

The Masteriyo LMS – eLearning and Online Course Builder for WordPress plugin for WordPress is vulnerable to unauthorized user profile modification due to missing authorization checks on the /wp-json/masteriyo/v1/users/$id REST API endpoint in all versions up to, and including, 1.13.3. This makes it…

πŸ“… Published: Oct. 29, 2024, 5:32 a.m. πŸ”„ Last Modified: April 8, 2026, 4:35 p.m.

6.8

CVSS3.1

CVE-2024-22065 - ZTE MF258 Pro product has a OS Command injection vulnerability

There is a command injection vulnerability in ZTE MF258 Pro product. Due to insufficient validation of Ping Diagnosis interface parameter, an authenticated attacker could use the vulnerability to execute arbitrary commands.

πŸ“… Published: Oct. 29, 2024, 1:58 a.m. πŸ”„ Last Modified: Jan. 28, 2025, 5:13 p.m.

5.1

CVSS4.0

CVE-2024-10479 - LinZhaoguan pb-cms Theme Management Module admin#themes cross site scripting

A vulnerability, which was classified as problematic, was found in LinZhaoguan pb-cms up to 2.0.1. Affected is an unknown function of the file /admin#themes of the component Theme Management Module. The manipulation leads to cross site scripting. It is possible to launch the attack remotely. The ex…

πŸ“… Published: Oct. 29, 2024, 1 a.m. πŸ”„ Last Modified: Sept. 29, 2025, 2:51 p.m.

9.8

CVSS3.1

CVE-2024-45656 - IBM Flexible Service Processor hard coded credentials

IBM Flexible Service Processor (FSP) FW860.00 through FW860.B3, FW950.00 through FW950.C0, FW1030.00 through FW1030.61, FW1050.00 through FW1050.21, and FW1060.00 through FW1060.10 has static credentials which may allow network users to gain service privileges to the FSP.

πŸ“… Published: Oct. 29, 2024, 12:37 a.m. πŸ”„ Last Modified: Dec. 3, 2025, 6:14 p.m.

5.1

CVSS4.0

CVE-2024-10478 - LinZhaoguan pb-cms Edit Article edit cross site scripting

A vulnerability, which was classified as problematic, has been found in LinZhaoguan pb-cms up to 2.0.1. This issue affects some unknown processing of the file /admin#article/edit?id=2 of the component Edit Article Handler. The manipulation leads to cross site scripting. The attack may be initiated …

πŸ“… Published: Oct. 29, 2024, 12:31 a.m. πŸ”„ Last Modified: Sept. 29, 2025, 2:53 p.m.

5.1

CVSS4.0

CVE-2024-10477 - LinZhaoguan pb-cms Permission Management Page admin#permissions cross site scripting

A vulnerability classified as problematic was found in LinZhaoguan pb-cms up to 2.0.1. This vulnerability affects unknown code of the file /admin#permissions of the component Permission Management Page. The manipulation leads to cross site scripting. The attack can be initiated remotely. The exploi…

πŸ“… Published: Oct. 29, 2024, 12:31 a.m. πŸ”„ Last Modified: Sept. 29, 2025, 3 p.m.

7.5

CVSS3.1

CVE-2024-44080 -

In Jitsi Meet before 2.0.9779, the functionality to share an image using giphy was implemented in an insecure way, resulting in clients loading GIFs from any arbitrary URL if a message from another participant contains a URL encoded in the expected format.

πŸ“… Published: Oct. 29, 2024, midnight πŸ”„ Last Modified: July 10, 2025, 7:33 p.m.

5.5

CVSS3.1

CVE-2024-50078 - Bluetooth: Call iso_exit() on module unload

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: Call iso_exit() on module unload If iso_init() has been called, iso_exit() must be called on module unload. Without that, the struct proto that iso_init() registered with proto_register() becomes invalid, which could c…

πŸ“… Published: Oct. 29, 2024, midnight πŸ”„ Last Modified: Nov. 3, 2025, 11:16 p.m.
Total resulsts: 349182
Page 8106 of 34,919
Β« previous page Β» next page
Filters