8.6

CVSS3.1

CVE-2024-45294 - `org.hl7.fhir.core` XXE vulnerability in XSLT transforms

The HL7 FHIR Core Artifacts repository provides the java core object handling code, with utilities (including validator), for the Fast Healthcare Interoperability Resources (FHIR) specification. Prior to version 6.3.23, XSLT transforms performed by various components are vulnerable to XML external …

📅 Published: Sept. 6, 2024, 3:46 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS3.1

CVE-2024-25584 -

Dovecot accepts dot LF DOT LF symbol as end of DATA command. RFC requires that it should always be CR LF DOT CR LF. This causes Dovecot to convert single mail with LF DOT LF in middle, into two emails when relaying to SMTP. Dovecot will split mail with LF DOT LF into two mails. Upgrade to latest re…

📅 Published: Sept. 6, 2024, 3:02 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

6.4

CVSS3.1

CVE-2024-7611 - Enter Addons – Ultimate Template Builder for Elementor <= 2.1.8 - Authenticated (Contributor+) Stor…

The Enter Addons – Ultimate Template Builder for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'tag' attribute of the Events Card widget in all versions up to, and including, 2.1.8 due to insufficient input sanitization and output escaping on user supplied attr…

📅 Published: Sept. 6, 2024, 1:55 p.m. 🔄 Last Modified: April 8, 2026, 7:22 p.m.

9.8

CVSS3.1

CVE-2024-7493 - WPCOM Member <= 1.5.2.1 - Unauthenticated Privilege Escalation via User Meta

The WPCOM Member plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.5.2.1. This is due to the plugin allowing arbitrary data to be passed to wp_insert_user() during registration. This makes it possible for unauthenticated attackers to update their rol…

📅 Published: Sept. 6, 2024, 1:55 p.m. 🔄 Last Modified: April 8, 2026, 7:22 p.m.

8.8

CVSS3.1

CVE-2024-8428 - ForumWP – Forum & Discussion Board Plugin <= 2.0.2 - Insecure Direct Object Reference to Authentica…

The ForumWP – Forum & Discussion Board Plugin plugin for WordPress is vulnerable to Privilege Escalation via Insecure Direct Object Reference in all versions up to, and including, 2.0.2 via the submit_form_handler due to missing validation on the 'user_id' user controlled key. This makes it possibl…

📅 Published: Sept. 6, 2024, 1:55 p.m. 🔄 Last Modified: April 8, 2026, 7:22 p.m.

6.4

CVSS3.1

CVE-2024-7599 - Advanced Sermons <= 3.3 - Authenticated (Contributor+) Stored Cross-Site Scripting

The Advanced Sermons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘sermon_video_embed’ parameter in all versions up to, and including, 3.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-le…

📅 Published: Sept. 6, 2024, 1:55 p.m. 🔄 Last Modified: April 8, 2026, 4:48 p.m.

4.3

CVSS3.1

CVE-2024-7622 - Revision Manager TMC <= 2.8.19 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Ema…

The Revision Manager TMC plugin for WordPress is vulnerable to unauthorized arbitrary email sending due to a missing capability check on the _a_ajaxQuickEmailTestCallback() function in all versions up to, and including, 2.8.19. This makes it possible for authenticated attackers, with subscriber-lev…

📅 Published: Sept. 6, 2024, 1:55 p.m. 🔄 Last Modified: April 8, 2026, 4:43 p.m.

10

CVSS4.0

CVE-2024-6445 - Authenticated Local File Inclusion (LFI) in DataFlowX's DataDiodeX

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in DataFlowX Technology DataDiodeX allows Path Traversal.This issue affects DataDiodeX: from v3.0.0 before v3.1.7.

📅 Published: Sept. 6, 2024, 1:33 p.m. 🔄 Last Modified: Sept. 12, 2024, 4:14 p.m.

6

CVSS3.1

CVE-2024-45405 - gix-path improperly resolves configuration path reported by Git

`gix-path` is a crate of the `gitoxide` project (an implementation of `git` written in Rust) dealing paths and their conversions. Prior to version 0.10.11, `gix-path` runs `git` to find the path of a configuration file associated with the `git` installation, but improperly resolves paths containing…

📅 Published: Sept. 6, 2024, 1:10 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

7.5

CVSS3.1

CVE-2024-45300 - Bypassing promo code limitations with race conditions

alf.io is an open source ticket reservation system for conferences, trade shows, workshops, and meetups. Prior to version 2.0-M5, a race condition allows the user to bypass the limit on the number of promo codes and use the discount coupon multiple times. In "alf.io", an event organizer can apply p…

📅 Published: Sept. 6, 2024, 1:02 p.m. 🔄 Last Modified: Sept. 29, 2024, 12:08 a.m.
Total resulsts: 349182
Page 8644 of 34,919
« previous page » next page
Filters