9.3

CVSS3.1

CVE-2024-47331 - WordPress Multi Step for Contact Form plugin <= 2.7.7 - Unauthenticated SQL Injection vulnerability

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Ninja Team Multi Step for Contact Form cf7-multi-step allows SQL Injection.This issue affects Multi Step for Contact Form: from n/a through <= 2.7.7.

πŸ“… Published: Oct. 11, 2024, 6:20 p.m. πŸ”„ Last Modified: April 23, 2026, 3:19 p.m.

8.5

CVSS3.1

CVE-2024-48020 - WordPress Backup and Staging by WP Time Capsule plugin <= 1.22.21 - SQL Injection vulnerability

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in revmakx Backup and Staging by WP Time Capsule wp-time-capsule allows SQL Injection.This issue affects Backup and Staging by WP Time Capsule: from n/a through <= 1.22.21.

πŸ“… Published: Oct. 11, 2024, 6:15 p.m. πŸ”„ Last Modified: April 23, 2026, 3:19 p.m.

4.7

CVSS3.1

CVE-2024-47353 - WordPress ElementsReady Addons for Elementor plugin <= 6.4.2 - Open Redirection vulnerability

URL Redirection to Untrusted Site ('Open Redirect') vulnerability in quomodosoft ElementsReady Addons for Elementor element-ready-lite.This issue affects ElementsReady Addons for Elementor: from n/a through 6.4.2.

πŸ“… Published: Oct. 11, 2024, 6:12 p.m. πŸ”„ Last Modified: April 23, 2026, 3:19 p.m.

5.7

CVSS4.0

CVE-2024-9539 -

An information disclosure vulnerability was identified in GitHub Enterprise Server via attacker uploaded asset URL allowing the attacker to retrieve metadata information of a user who clicks on the URL and further exploit it to create a convincing phishing page. This required the attacker to upload…

πŸ“… Published: Oct. 11, 2024, 5:52 p.m. πŸ”„ Last Modified: Nov. 15, 2024, 5:15 p.m.

5.5

CVSS3.1

CVE-2024-44157 -

A stack buffer overflow was addressed through improved input validation. This issue is fixed in Apple TV 1.5.0.152 for Windows, iTunes 12.13.3 for Windows. Parsing a maliciously crafted video file may lead to unexpected system termination.

πŸ“… Published: Oct. 11, 2024, 5:26 p.m. πŸ”„ Last Modified: April 2, 2026, 6:16 p.m.

6.9

CVSS4.0

CVE-2024-47877 - Extract has insufficient checks allowing attacker to create symlinks outside the extraction directo…

Extract is aA Go library to extract archives in zip, tar.gz or tar.bz2 formats. A maliciously crafted archive may allow an attacker to create a symlink outside the extraction target directory. This vulnerability is fixed in 4.0.0. If you're using the Extractor.FS interface, then upgrading to /v4 wi…

πŸ“… Published: Oct. 11, 2024, 4:36 p.m. πŸ”„ Last Modified: Nov. 22, 2024, 7:30 p.m.

8.8

CVSS3.1

CVE-2024-9859 -

Type confusion in WebAssembly in Google Chrome prior to 126.0.6478.126 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)

πŸ“… Published: Oct. 11, 2024, 4:32 p.m. πŸ”„ Last Modified: Jan. 2, 2025, 4:01 p.m.

6.9

CVSS4.0

CVE-2024-47507 - Junos OS and Junos OS Evolved: BGP update message containing aggregator attribute with an ASN value…

An Improper Check for Unusual or Exceptional Conditions vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated, network-based attacker to cause an integrity impact to the downstream devices. When a peer sends a BGP update mess…

πŸ“… Published: Oct. 11, 2024, 3:38 p.m. πŸ”„ Last Modified: Jan. 26, 2026, 6:29 p.m.

4.4

CVSS3.1

CVE-2024-6985 - Path Traversal in api open_personality_folder in parisneo/lollms-webui

A path traversal vulnerability exists in the api open_personality_folder endpoint of parisneo/lollms-webui. This vulnerability allows an attacker to read any folder in the personality_folder on the victim's computer, even though sanitize_path is set. The issue arises due to improper sanitization of…

πŸ“… Published: Oct. 11, 2024, 3:38 p.m. πŸ”„ Last Modified: Nov. 15, 2024, 5:10 p.m.

8.2

CVSS4.0

CVE-2024-47506 - Junos OS: SRX Series: A large amount of traffic being processed by ATP Cloud can lead to a PFE crash

A Deadlock vulnerability in the packet forwarding engine (PFE) of Juniper Networks Junos OS on SRX Series allows an unauthenticated, network-based attacker to cause a Denial of Service (DoS). When a large amount of traffic is processed by ATP Cloud inspection, a deadlock can occur which will resul…

πŸ“… Published: Oct. 11, 2024, 3:37 p.m. πŸ”„ Last Modified: Jan. 26, 2026, 6:28 p.m.
Total resulsts: 349182
Page 8310 of 34,919
Β« previous page Β» next page
Filters