9.8

CVSS3.1

CVE-2024-9108 - Wechat Social login <= 1.3.0 - Unauthenticated Arbitrary File Upload

The Wechat Social login plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in the 'convert_remoteimage_to_local' function in versions up to, and including, 1.3.0. This makes it possible for unauthenticated attackers to upload arbitrary files on the…

πŸ“… Published: Oct. 1, 2024, 7:30 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.1

CVSS4.0

CVE-2024-9145 - Local command injection in Wiz Code Visual Studio Code extension

Wiz Code Visual Studio Code extension in versions 1.0.0 up to 1.5.3 and Wiz (legacy) Visual Studio Code extension in versions 0.13.0 up to 0.17.8 are vulnerable to local command injection if the user opens a maliciously crafted Dockerfile located in a path that has been marked as a "trusted folder"…

πŸ“… Published: Oct. 1, 2024, 7:23 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.4

CVSS3.1

CVE-2024-8107 - Slider Revolution <= 6.7.18 - Authenticated (Author+) Stored Cross-Site Scripting via SVG File Uplo…

The Slider Revolution plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 6.7.18 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and abov…

πŸ“… Published: Oct. 1, 2024, 6:39 a.m. πŸ”„ Last Modified: April 8, 2026, 4:41 p.m.

5.3

CVSS3.1

CVE-2024-21531 -

All versions of the package git-shallow-clone are vulnerable to Command injection due to missing sanitization or mitigation flags in the process variable of the gitShallowClone function.

πŸ“… Published: Oct. 1, 2024, 5 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.2

CVSS3.1

CVE-2024-21489 - uplot: Prototype Pollution in uplot

Versions of the package uplot before 1.6.31 are vulnerable to Prototype Pollution via the uplot.assign function due to missing check if the attribute resolves to the object prototype.

πŸ“… Published: Oct. 1, 2024, 5 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

4.9

CVSS3.1

CVE-2024-0116 - triton: Denial of service

NVIDIA Triton Inference Server contains a vulnerability where a user may cause an out-of-bounds read issue by releasing a shared memory region while it is in use. A successful exploit of this vulnerability may lead to denial of service.

πŸ“… Published: Oct. 1, 2024, 4:46 a.m. πŸ”„ Last Modified: Sept. 29, 2025, 5:31 p.m.

8.1

CVSS3.1

CVE-2024-47295 -

Insecure initial password configuration issue in SEIKO EPSON Web Config allows a remote unauthenticated attacker to set an arbitrary password and operate the device with an administrative privilege. As for the details of the affected versions, see the information provided by the vendor under [Refer…

πŸ“… Published: Oct. 1, 2024, 3:16 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.9

CVSS4.0

CVE-2024-9360 - code-projects Restaurant Reservation System updatebal.php sql injection

A vulnerability was found in code-projects Restaurant Reservation System 1.0. It has been classified as critical. This affects an unknown part of the file /updatebal.php. The manipulation of the argument company leads to sql injection. It is possible to initiate the attack remotely. The exploit has…

πŸ“… Published: Oct. 1, 2024, 3 a.m. πŸ”„ Last Modified: Oct. 4, 2024, 6:53 p.m.

7.1

CVSS3.1

CVE-2024-8981 - Broken Link Checker <= 2.4.0 - Reflected Cross-Site Scripting

The Broken Link Checker plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg in /app/admin-notices/features/class-view.php without appropriate escaping on the URL in all versions up to, and including, 2.4.0. This makes it possible for unauthenticated …

πŸ“… Published: Oct. 1, 2024, 2:33 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.9

CVSS4.0

CVE-2024-9359 - code-projects Restaurant Reservation System addcompany.php sql injection

A vulnerability was found in code-projects Restaurant Reservation System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /addcompany.php. The manipulation of the argument company leads to sql injection. The attack may be launched remotely. The exploi…

πŸ“… Published: Oct. 1, 2024, 1:31 a.m. πŸ”„ Last Modified: Oct. 4, 2024, 6:54 p.m.
Total resulsts: 349182
Page 8430 of 34,919
Β« previous page Β» next page
Filters