8.7

CVSS4.0

CVE-2024-47085 - Parameter Manipulation Vulnerability

This vulnerability exists in Apex Softcell LD DP Back Office due to improper validation of certain parameters (cCdslClicentcode and cLdClientCode) in the API endpoint. An authenticated remote attacker could exploit this vulnerability by manipulating parameters in the API request body leading to expโ€ฆ

๐Ÿ“… Published: Sept. 19, 2024, 5:56 a.m. ๐Ÿ”„ Last Modified: Sept. 26, 2024, 3:30 p.m.

6.4

CVSS3.1

CVE-2024-8364 - WP Custom Fields Search <= 1.2.35 - Authenticated (Contributor+) Stored Cross-Site Scripting via wpโ€ฆ

The WP Custom Fields Search plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wpcfs-preset shortcode in all versions up to, and including, 1.2.35 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for autheโ€ฆ

๐Ÿ“… Published: Sept. 19, 2024, 3:59 a.m. ๐Ÿ”„ Last Modified: April 8, 2026, 5:31 p.m.

5.3

CVSS3.1

CVE-2022-4533 - Limit Login Attempts Plus <= 1.1.0 - IP Address Spoofing to Protection Mechanism Bypass

The Limit Login Attempts Plus plugin for WordPress is vulnerable to IP Address Spoofing in versions up to, and including, 1.1.0. This is due to insufficient restrictions on where the IP Address information is being retrieved for request logging and login restrictions. Attackers can supply the X-Forโ€ฆ

๐Ÿ“… Published: Sept. 19, 2024, 3:59 a.m. ๐Ÿ”„ Last Modified: April 8, 2026, 5:15 p.m.

6.1

CVSS3.1

CVE-2024-8850 - MC4WP: Mailchimp for WordPress 4.9.9 - 4.9.16 - Reflected Cross-Site Scripting

The MC4WP: Mailchimp for WordPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'email' parameter when a placeholder such as {email} is used for the field in versions 4.9.9 to 4.9.16 due to insufficient input sanitization and output escaping. This makes it possible fโ€ฆ

๐Ÿ“… Published: Sept. 19, 2024, 3:59 a.m. ๐Ÿ”„ Last Modified: Sept. 25, 2024, 6:49 p.m.

8.7

CVSS4.0

CVE-2024-7254 - Stack overflow in Protocol Buffers Java Lite

Any project that parses untrusted Protocol Buffers dataย containing an arbitrary number of nested groups / series of SGROUPย tags can corrupted by exceeding the stack limit i.e. StackOverflow. Parsing nested groups as unknown fields with DiscardUnknownFieldsParser or Java Protobuf Lite parser, or agaโ€ฆ

๐Ÿ“… Published: Sept. 19, 2024, 12:18 a.m. ๐Ÿ”„ Last Modified: Sept. 26, 2025, 5:10 p.m.

8

CVSS3.1

CVE-2024-46394 -

FrogCMS v0.9.5 was discovered to contain a Cross-Site Request Forgery (CSRF) via /admin/?/user/add

๐Ÿ“… Published: Sept. 19, 2024, midnight ๐Ÿ”„ Last Modified: Sept. 25, 2024, 4:55 p.m.

9.8

CVSS3.1

CVE-2024-31570 -

libfreeimage in FreeImage 3.4.0 through 3.18.0 has a stack-based buffer overflow in the PluginXPM.cpp Load function via an XPM file.

๐Ÿ“… Published: Sept. 19, 2024, midnight ๐Ÿ”„ Last Modified: Sept. 25, 2024, 2:57 p.m.

6.5

CVSS3.1

CVE-2024-46382 -

A SQL injection vulnerability in linlinjava litemall 1.8.0 allows a remote attacker to obtain sensitive information via the goodsId, goodsSn, and name parameters in AdminOrderController.java.

๐Ÿ“… Published: Sept. 19, 2024, midnight ๐Ÿ”„ Last Modified: April 29, 2026, 10:32 a.m.

6.1

CVSS3.1

CVE-2024-25673 -

Couchbase Server 7.6.x before 7.6.2, 7.2.x before 7.2.6, and all earlier versions allows HTTP Host header injection.

๐Ÿ“… Published: Sept. 19, 2024, midnight ๐Ÿ”„ Last Modified: March 19, 2025, 9:15 p.m.

8.5

CVSS3.1

CVE-2024-45752 -

logiops through 0.3.4, in its default configuration, allows any unprivileged user to configure its logid daemon via an unrestricted D-Bus service, including setting malicious keyboard macros. This allows for privilege escalation with minimal user interaction.

๐Ÿ“… Published: Sept. 19, 2024, midnight ๐Ÿ”„ Last Modified: Sept. 25, 2024, 4:54 p.m.
Total resulsts: 349182
Page 8509 of 34,919
ยซ previous page ยป next page
Filters