6.4

CVSS3.1

CVE-2024-6804 - Jeg Elementor Kit <= 2.6.7 - Authenticated (Author+) Stored Cross-Site Scripting via SVG File

The Jeg Elementor Kit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 2.6.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and aboveโ€ฆ

๐Ÿ“… Published: Aug. 27, 2024, 6:48 a.m. ๐Ÿ”„ Last Modified: April 8, 2026, 4:53 p.m.

4.3

CVSS3.1

CVE-2024-6688 - Oxygen Builder <= 4.8.3 - Missing Authorization to Authenticated (Subscriber+) Stylesheet Update

The Oxygen Builder plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the oxy_save_css_from_admin AJAX action in all versions up to, and including, 4.8.3. This makes it possible for authenticated attackers, with Subscriber-level access and aโ€ฆ

๐Ÿ“… Published: Aug. 27, 2024, 4:29 a.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.8

CVSS3.1

CVE-2024-7125 - Authentication Bypass Vulnerability in Hitachi Ops Center Common Services

Authentication Bypass vulnerability in Hitachi Ops Center Common Services.This issue affects Hitachi Ops Center Common Services: from 10.9.3-00 before 11.0.2-01.

๐Ÿ“… Published: Aug. 27, 2024, 4:15 a.m. ๐Ÿ”„ Last Modified: Jan. 21, 2025, 7:10 p.m.

5.9

CVSS3.1

CVE-2024-8285 - Kroxylicious: missing upstream kafka tls hostname verification

A flaw was found in Kroxylicious. When establishing the connection with the upstream Kafka server using a TLS secured connection, Kroxylicious fails to properly verify the server's hostname, resulting in an insecure connection. For a successful attack to be performed, the attacker needs to perform โ€ฆ

๐Ÿ“… Published: Aug. 27, 2024, midnight ๐Ÿ”„ Last Modified: Nov. 20, 2025, 8:57 p.m.

8.8

CVSS3.1

CVE-2024-44341 -

D-Link DIR-846W A1 FW100A43 was discovered to contain a remote command execution (RCE) vulnerability via the lan(0)_dhcps_staticlist parameter. This vulnerability is exploited via a crafted POST request.

๐Ÿ“… Published: Aug. 27, 2024, midnight ๐Ÿ”„ Last Modified: Aug. 30, 2024, 2:57 p.m.

7.5

CVSS3.1

CVE-2024-36068 -

An incorrect access control vulnerability in Rubrik CDM versions prior to 9.1.2-p1, 9.0.3-p6 and 8.1.3-p12, allows an attacker with network access to execute arbitrary code.

๐Ÿ“… Published: Aug. 27, 2024, midnight ๐Ÿ”„ Last Modified: Sept. 5, 2024, 8:27 p.m.

6.5

CVSS3.1

CVE-2024-40395 -

An Insecure Direct Object Reference (IDOR) in PTC ThingWorx v9.5.0 allows attackers to view sensitive information, including PII, regardless of access level.

๐Ÿ“… Published: Aug. 27, 2024, midnight ๐Ÿ”„ Last Modified: March 25, 2025, 5:15 p.m.

8.4

CVSS3.1

CVE-2024-42851 -

Buffer Overflow vulnerability in open source exiftags v.1.01 allows a local attacker to execute arbitrary code via the paresetag function.

๐Ÿ“… Published: Aug. 27, 2024, midnight ๐Ÿ”„ Last Modified: Aug. 30, 2024, 3:30 p.m.

4.8

CVSS3.1

CVE-2022-39996 -

Cross Site Scripting vulnerability in Teldats Router RS123, RS123w allows attacker to execute arbitrary code via the cmdcookie parameter to the upgrade/query.php page.

๐Ÿ“… Published: Aug. 27, 2024, midnight ๐Ÿ”„ Last Modified: Aug. 30, 2024, 3:17 p.m.

8.8

CVSS3.1

CVE-2024-44342 -

D-Link DIR-846W A1 FW100A43 was discovered to contain a remote command execution (RCE) vulnerability via the wl(0).(0)_ssid parameter. This vulnerability is exploited via a crafted POST request.

๐Ÿ“… Published: Aug. 27, 2024, midnight ๐Ÿ”„ Last Modified: Aug. 30, 2024, 2:57 p.m.
Total resulsts: 347742
Page 8581 of 34,775
ยซ previous page ยป next page
Filters