5.1

CVSS4.0

CVE-2024-9855 - 07FLYCMS/07FLY-CMS/07FlyCRM Module Plug-In sysmodule_1 uploadFile unrestricted upload

A vulnerability was found in 07FLYCMS, 07FLY-CMS and 07FlyCRM 1.3.8. It has been declared as critical. Affected by this vulnerability is the function uploadFile of the file /admin/SysModule/upload/ajaxmodel/upload/uploadfilepath/sysmodule_1 of the component Module Plug-In Handler. The manipulation …

πŸ“… Published: Oct. 11, 2024, 12:31 p.m. πŸ”„ Last Modified: July 30, 2025, 3:44 p.m.

8.2

CVSS3.1

CVE-2024-8970 - Incorrect Authorization in GitLab

An issue was discovered in GitLab CE/EE affecting all versions starting from 11.6 prior to 17.2.9, starting from 17.3 prior to 17.3.5, and starting from 17.4 prior to 17.4.2, which allows an attacker to trigger a pipeline as another user under certain circumstances.

πŸ“… Published: Oct. 11, 2024, 12:30 p.m. πŸ”„ Last Modified: Dec. 13, 2024, 1:20 a.m.

4.4

CVSS3.1

CVE-2024-6971 - Path Traversal in parisneo/lollms-webui

A path traversal vulnerability exists in the parisneo/lollms-webui repository, specifically in the `lollms_file_system.py` file. The functions `add_rag_database`, `toggle_mount_rag_database`, and `vectorize_folder` do not implement security measures such as `sanitize_path_from_endpoint` or `sanitiz…

πŸ“… Published: Oct. 11, 2024, 12:14 p.m. πŸ”„ Last Modified: Aug. 15, 2025, 8:38 p.m.

6.7

CVSS3.1

CVE-2023-42133 -

PAX Android based POS devices allow for escalation of privilege via improperly configured scripts. An attacker must have shell access with system account privileges in order to exploit this vulnerability. A patch addressing this issue was included in firmware version PayDroid_8.1.0_Sagittarius_V11…

πŸ“… Published: Oct. 11, 2024, 12:01 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

4.3

CVSS3.1

CVE-2024-5005 - Incorrect Provision of Specified Functionality in GitLab

An issue has been discovered discovered in GitLab EE/CE affecting all versions starting from 11.4 before 17.2.9, all versions starting from 17.3 before 17.3.5, all versions starting from 17.4 before 17.4.2 It was possible for guest users to disclose project templates using the API.

πŸ“… Published: Oct. 11, 2024, 11:30 a.m. πŸ”„ Last Modified: Dec. 12, 2024, 7:55 p.m.

9.6

CVSS3.1

CVE-2024-9164 - Missing Authentication for Critical Function in GitLab

An issue was discovered in GitLab EE affecting all versions starting from 12.5 prior to 17.2.9, starting from 17.3, prior to 17.3.5, and starting from 17.4 prior to 17.4.2, which allows running pipelines on arbitrary branches.

πŸ“… Published: Oct. 11, 2024, 11:30 a.m. πŸ”„ Last Modified: Dec. 13, 2024, 4:33 p.m.

4.3

CVSS3.1

CVE-2024-9538 - ShopLentor <= 2.9.8 - Authenticated (Contributor+) Sensitive Information Exposure via WL: FAQ Widge…

The ShopLentor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.9.8 via the 'render' function in includes/addons/wl_faq.php. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract sensitive …

πŸ“… Published: Oct. 11, 2024, 11:01 a.m. πŸ”„ Last Modified: April 8, 2026, 4:58 p.m.

4.3

CVSS3.1

CVE-2024-8913 - The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce <…

The The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 5.6.11 via the render function in modules/widgets/tp_accordion.php. This makes it possible…

πŸ“… Published: Oct. 11, 2024, 8:30 a.m. πŸ”„ Last Modified: April 8, 2026, 4:49 p.m.

6.5

CVSS3.1

CVE-2024-7514 - WordPress Comments Import & Export <= 2.3.7 - Authenticated (Author+) Arbitrary File Read via Direc…

The WordPress Comments Import & Export plugin for WordPress is vulnerable to to arbitrary file read due to insufficient file path validation during the comments import process, in versions up to, and including, 2.3.7. This makes it possible for authenticated attackers, with Author-level access and …

πŸ“… Published: Oct. 11, 2024, 8:30 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.5

CVSS3.1

CVE-2024-45317 -

A Server-Side Request Forgery (SSRF) vulnerability in SMA1000 appliance firmware versions 12.4.3-02676 and earlier allows a remote, unauthenticated attacker to cause the SMA1000 server-side application to make requests to an unintended IP address.

πŸ“… Published: Oct. 11, 2024, 8:30 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 349182
Page 8316 of 34,919
Β« previous page Β» next page
Filters