7.5

CVSS3.1

CVE-2024-38486 -

Dell SmartFabric OS10 Software, version(s) 10.5.5.4 through 10.5.5.10 and 10.5.6.x , contain(s) an Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to…

πŸ“… Published: Sept. 6, 2024, 4:06 a.m. πŸ”„ Last Modified: Sept. 13, 2024, 8:36 p.m.

8.8

CVSS3.1

CVE-2024-8247 - Newsletters <= 4.9.9.2 - Authenticated Privilege Escalation

The Newsletters plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 4.9.9.2. This is due to the plugin not restricting what user meta can be updated as screen options. This makes it possible for authenticated attackers, with subscriber-level access and a…

πŸ“… Published: Sept. 6, 2024, 3:30 a.m. πŸ”„ Last Modified: April 8, 2026, 4:42 p.m.

8.8

CVSS3.1

CVE-2024-8480 - Image Optimizer, Resizer and CDN – Sirv <= 7.2.7 - Missing Authorization to Authenticated (Contribu…

The Image Optimizer, Resizer and CDN – Sirv plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'sirv_save_prevented_sizes' function in all versions up to, and including, 7.2.7. This makes it possible for authenticated attackers, with Con…

πŸ“… Published: Sept. 6, 2024, 3:30 a.m. πŸ”„ Last Modified: April 8, 2026, 4:40 p.m.

5.3

CVSS3.1

CVE-2024-7415 - Remember Me Controls <= 2.0.1 - Unauthenticated Full Path Disclosure

The Remember Me Controls plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 2.0.1. This is due to the plugin allowing direct access to the bootstrap.php file which has display_errors on. This makes it possible for unauthenticated attackers to retrieve t…

πŸ“… Published: Sept. 6, 2024, 3:30 a.m. πŸ”„ Last Modified: April 8, 2026, 4:32 p.m.

5.3

CVSS3.1

CVE-2024-40865 -

The issue was addressed by suspending Persona when the virtual keyboard is active. This issue is fixed in visionOS 1.3. Inputs to the virtual keyboard may be inferred from Persona.

πŸ“… Published: Sept. 6, 2024, 1:23 a.m. πŸ”„ Last Modified: April 2, 2026, 6:23 p.m.

7.5

CVSS3.1

CVE-2024-8509 - Migration toolkit for virtualization: forklift-controller: empty bearer token may perform authentic…

A vulnerability was found in Forklift Controller.Β  There is no verification against the authorization header except to ensure it uses bearer authentication. Without an Authorization header and some form of a Bearer token, a 401 error occurs. The presence of a token value provides a 200 response wit…

πŸ“… Published: Sept. 6, 2024, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.5

CVSS3.1

CVE-2024-44408 -

D-Link DIR-823G v1.0.2B05_20181207 is vulnerable to Information Disclosure. The device allows unauthorized configuration file downloads, and the downloaded configuration files contain plaintext user passwords.

πŸ“… Published: Sept. 6, 2024, midnight πŸ”„ Last Modified: Sept. 10, 2024, 5:01 p.m.

5.5

CVSS3.1

CVE-2023-52915 - media: dvb-usb-v2: af9035: Fix null-ptr-deref in af9035_i2c_master_xfer

In the Linux kernel, the following vulnerability has been resolved: media: dvb-usb-v2: af9035: Fix null-ptr-deref in af9035_i2c_master_xfer In af9035_i2c_master_xfer, msg is controlled by user. When msg[i].buf is null and msg[i].len is zero, former checks on msg[i].buf would be passed. Malicious …

πŸ“… Published: Sept. 6, 2024, midnight πŸ”„ Last Modified: Jan. 5, 2026, 10:17 a.m.

9.8

CVSS3.1

CVE-2024-45771 -

RapidCMS v1.3.1 was discovered to contain a SQL injection vulnerability via the password parameter at /resource/runlogin.php.

πŸ“… Published: Sept. 6, 2024, midnight πŸ”„ Last Modified: April 22, 2025, 2:03 p.m.

5.4

CVSS3.1

CVE-2024-44837 -

A cross-site scripting (XSS) vulnerability in the component \bean\Manager.java of Drug v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the user parameter.

πŸ“… Published: Sept. 6, 2024, midnight πŸ”„ Last Modified: Sept. 12, 2024, 4:17 p.m.
Total resulsts: 349182
Page 8646 of 34,919
Β« previous page Β» next page
Filters