5.4

CVSS3.1

CVE-2024-6136 - WP eStore < 8.5.6 - Settings Reset via CSRF

The wp-cart-for-digital-products WordPress plugin before 8.5.6 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions via CSRF attacks

πŸ“… Published: Aug. 9, 2024, 6 a.m. πŸ”„ Last Modified: May 8, 2025, 7:42 p.m.

6.5

CVSS3.1

CVE-2024-6133 - WP eStore < 8.5.6 - Reflected XSS in Customer Search

The wp-cart-for-digital-products WordPress plugin before 8.5.6 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

πŸ“… Published: Aug. 9, 2024, 6 a.m. πŸ”„ Last Modified: May 8, 2025, 7:39 p.m.

8.8

CVSS3.1

CVE-2024-7399 -

Improper limitation of a pathname to a restricted directory vulnerability in Samsung MagicINFO 9 Server version before 21.1050 allows attackers to write arbitrary file as system authority.

πŸ“… Published: Aug. 9, 2024, 4:43 a.m. πŸ”„ Last Modified: April 23, 2026, 2:09 p.m.

6.5

CVSS3.1

CVE-2024-4359 - Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arr…

The Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) plugin for WordPress is vulnerable to arbitrary file reads in all versions up to, and including, 5.7.2 via the SVG widget and a lack of sufficient file validation in the render_svg function. …

πŸ“… Published: Aug. 9, 2024, 4:29 a.m. πŸ”„ Last Modified: April 8, 2026, 7:21 p.m.

6.4

CVSS3.1

CVE-2024-4360 - Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arr…

The Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's widgets in all versions up to, and including, 5.7.6 due to insufficient input sanitization and output escapi…

πŸ“… Published: Aug. 9, 2024, 4:29 a.m. πŸ”„ Last Modified: April 8, 2026, 6:21 p.m.

6.1

CVSS3.1

CVE-2024-0115 -

NVIDIA CV-CUDA for Ubuntu 20.04, Ubuntu 22.04, and Jetpack contains a vulnerability in Python APIs where a user may cause an uncontrolled resource consumption issue by a long running CV-CUDA Python process. A successful exploit of this vulnerability may lead to denial of service and data loss.

πŸ“… Published: Aug. 9, 2024, 2:23 a.m. πŸ”„ Last Modified: Dec. 26, 2024, 7:21 p.m.

7.5

CVSS3.1

CVE-2024-0113 -

NVIDIA Mellanox OS, ONYX, Skyway, and MetroX-3 XCC contain a vulnerability in the web support, where an attacker can cause a CGI path traversal by a specially crafted URI. A successful exploit of this vulnerability might lead to escalation of privileges and information disclosure.

πŸ“… Published: Aug. 9, 2024, 2:19 a.m. πŸ”„ Last Modified: Dec. 26, 2024, 7:21 p.m.

5.1

CVSS4.0

CVE-2024-4350 - Concrete CMS version 9 below 9.3.3 and below 8.5.18 are vulnerable to Stored XSS in RSS Displayer

Concrete CMS versions 9.0.0 to 9.3.2 and below 8.5.18 are vulnerable to Stored XSS in RSS Displayer when user input is stored and later embedded into responses. A rogue administrator could inject malicious code into fields due to insufficient input validation. The Concrete CMS security team gave th…

πŸ“… Published: Aug. 9, 2024, 12:37 a.m. πŸ”„ Last Modified: Sept. 25, 2025, 7:15 p.m.

4.6

CVSS4.0

CVE-2024-7512 - Concrete CMS Stored XSS in Board instances

Concrete CMS versions 9.0.0 through 9.3.2 are affected by a stored XSS vulnerability in Board instances. A rogue administrator could inject malicious code. The Concrete CMS security team gave this vulnerability a CVSS 4.0 Score of 4.6 with vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:A/VC:L/VI:N/VA:N/SC…

πŸ“… Published: Aug. 9, 2024, 12:19 a.m. πŸ”„ Last Modified: Jan. 17, 2025, 9:15 p.m.

9.1

CVSS3.0

CVE-2024-3279 - Improper Access Control in mintplex-labs/anything-llm

An improper access control vulnerability exists in the mintplex-labs/anything-llm application, specifically within the import endpoint. This vulnerability allows an anonymous attacker, without an account in the application, to import their own database file, leading to the deletion or spoofing of t…

πŸ“… Published: Aug. 9, 2024, midnight πŸ”„ Last Modified: Oct. 15, 2025, 1:15 p.m.
Total resulsts: 349182
Page 8909 of 34,919
Β« previous page Β» next page
Filters