8.8

CVSS3.1

CVE-2024-23938 - Silicon Labs Gecko OS Debug Interface Stack-based Buffer Overflow Remote Code Execution Vulnerabiliโ€ฆ

Silicon Labs Gecko OS Debug Interface Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Silicon Labs Gecko OS. Authentication is not required to exploit this vulnerability. Thโ€ฆ

๐Ÿ“… Published: Sept. 28, 2024, 6:06 a.m. ๐Ÿ”„ Last Modified: Oct. 3, 2024, 5:29 p.m.

6.1

CVSS3.1

CVE-2024-8715 - Simple LDAP Login <= 1.6.0 - Reflected Cross-Site Scripting

The Simple LDAP Login plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 1.6.0. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pagโ€ฆ

๐Ÿ“… Published: Sept. 28, 2024, 2:31 a.m. ๐Ÿ”„ Last Modified: April 8, 2026, 5:23 p.m.

5.3

CVSS3.1

CVE-2024-9189 - EU/UK VAT Manager for WooCommerce <= 2.12.12 - Missing Authorization

The EU/UK VAT Manager for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the alg_wc_eu_vat_exempt_vat_from_admin() function in all versions up to, and including, 2.12.12. This makes it possible for unauthenticated attackers tโ€ฆ

๐Ÿ“… Published: Sept. 28, 2024, 2:04 a.m. ๐Ÿ”„ Last Modified: April 8, 2026, 5:21 p.m.

9.8

CVSS3.1

CVE-2024-8353 - GiveWP โ€“ Donation Plugin and Fundraising Platform <= 3.16.1 - Unauthenticated PHP Object Injection

The GiveWP โ€“ Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.16.1 via deserialization of untrusted input via several parameters like 'give_title' and 'card_address'. This makes it possible for unauthenticateโ€ฆ

๐Ÿ“… Published: Sept. 28, 2024, 2:04 a.m. ๐Ÿ”„ Last Modified: April 8, 2026, 7:22 p.m.

6.4

CVSS3.1

CVE-2024-9023 - WP-WebAuthn <= 1.3.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via wwa_login_form โ€ฆ

The WP-WebAuthn plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wwa_login_form shortcode in all versions up to, and including, 1.3.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated atโ€ฆ

๐Ÿ“… Published: Sept. 28, 2024, 2:04 a.m. ๐Ÿ”„ Last Modified: April 8, 2026, 6:22 p.m.

6.1

CVSS3.1

CVE-2024-8788 - EU/UK VAT Manager for WooCommerce <= 2.12.12 - Reflected Cross-Site Scripting

The EU/UK VAT Manager for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 2.12.11. This makes it possible for unauthenticated attackers to inject arbitrary โ€ฆ

๐Ÿ“… Published: Sept. 28, 2024, 2:04 a.m. ๐Ÿ”„ Last Modified: April 8, 2026, 4:49 p.m.

6.4

CVSS3.1

CVE-2024-8547 - Simple Popup Plugin <= 4.5 - Authenticated (Contributor+) Stored Cross-Site Scripting

The Simple Popup Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's [popup] shortcode in all versions up to, and including, 4.5 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attโ€ฆ

๐Ÿ“… Published: Sept. 28, 2024, 2:04 a.m. ๐Ÿ”„ Last Modified: April 8, 2026, 5:19 p.m.

5.9

CVSS3.1

CVE-2024-38796 - Integer overflow in PeCoffLoaderRelocateImage

EDK2 contains a vulnerability in the PeCoffLoaderRelocateImage(). An Attacker may cause memory corruption due to an overflow via an adjacent network. A successful exploit of this vulnerability may lead to a loss of Confidentiality, Integrity, and/or Availability.

๐Ÿ“… Published: Sept. 27, 2024, 9:45 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS4.0

CVE-2024-9294 - dingfanzu CMS saveNewPwd.php sql injection

A vulnerability, which was classified as critical, has been found in dingfanzu CMS up to 29d67d9044f6f93378e6eb6ff92272217ff7225c. Affected by this issue is some unknown functionality of the file saveNewPwd.php. The manipulation of the argument username leads to sql injection. The attack may be lauโ€ฆ

๐Ÿ“… Published: Sept. 27, 2024, 9:31 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS3.1

CVE-2024-23586 - An insufficient session timeout vulnerability affects HCL Nomad server on Domino

HCL Nomad is susceptible to an insufficient session expiration vulnerability. ย  Under certain circumstances, an unauthenticated attacker could obtain old session information.

๐Ÿ“… Published: Sept. 27, 2024, 9:20 p.m. ๐Ÿ”„ Last Modified: Oct. 7, 2024, 3:30 p.m.
Total resulsts: 349182
Page 8444 of 34,919
ยซ previous page ยป next page
Filters