8.8

CVSS3.1

CVE-2024-7486 - MultiPurpose <= 1.2.0 - Authenticated (Contributor+) PHP Object Injection

The MultiPurpose theme for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.2.0 via deserialization of untrusted input through the 'wpeden_post_meta' post meta. This makes it possible for authenticated attackers, with Contributor-level access and above, to inj…

πŸ“… Published: Aug. 8, 2024, 1:50 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.2

CVSS3.1

CVE-2024-7560 - News Flash <= 1.1.0 - Authenticated (Editor+) PHP Object Injection

The News Flash theme for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.1.0 via deserialization of untrusted input from the newsflash_post_meta meta value. This makes it possible for authenticated attackers, with Editor-level access and above, to inject a PH…

πŸ“… Published: Aug. 8, 2024, 1:50 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.8

CVSS3.1

CVE-2024-7561 - The Next <= 1.1.0 - Authenticated (Contributor+) PHP Object Injection

The The Next theme for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.1.0 via deserialization of untrusted input from the wpeden_post_meta post meta value. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject…

πŸ“… Published: Aug. 8, 2024, 1:50 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.8

CVSS3.1

CVE-2024-7348 - PostgreSQL relation replacement during pg_dump executes arbitrary SQL

Time-of-check Time-of-use (TOCTOU) race condition in pg_dump in PostgreSQL allows an object creator to execute arbitrary SQL functions as the user running pg_dump, which is often a superuser. The attack involves replacing another relation type with a view or foreign table. The attack requires waiti…

πŸ“… Published: Aug. 8, 2024, midnight πŸ”„ Last Modified: Nov. 21, 2024, 9:51 a.m.

7.6

CVSS3.1

CVE-2024-40487 -

A Stored Cross Site Scripting (XSS) vulnerability was found in "/view_type.php" of Kashipara Live Membership System v1.0, which allows remote attackers to execute arbitrary code via membershipType parameter.

πŸ“… Published: Aug. 8, 2024, midnight πŸ”„ Last Modified: April 28, 2025, 2:28 p.m.

6.8

CVSS3.1

CVE-2023-24064 -

Diebold Nixdorf Vynamic Security Suite (VSS) before 3.3.0 SR4 fails to validate /etc/initab during the Pre-Boot Authorization (PBA) process. This can be exploited by a physical attacker who is able to manipulate the contents of the system's hard disk.

πŸ“… Published: Aug. 8, 2024, midnight πŸ”„ Last Modified: March 13, 2025, 6:44 p.m.

6.8

CVSS3.1

CVE-2023-24063 -

Diebold Nixdorf Vynamic Security Suite (VSS) before 3.3.0 SR10 fails to validate /etc/mtab during the Pre-Boot Authorization (PBA) process. This can be exploited by a physical attacker who is able to manipulate the contents of the system's hard disk.

πŸ“… Published: Aug. 8, 2024, midnight πŸ”„ Last Modified: March 27, 2025, 4:15 p.m.

5.5

CVSS3.1

CVE-2024-42251 - mm: page_ref: remove folio_try_get_rcu()

In the Linux kernel, the following vulnerability has been resolved: mm: page_ref: remove folio_try_get_rcu() The below bug was reported on a non-SMP kernel: [ 275.267158][ T4335] ------------[ cut here ]------------ [ 275.267949][ T4335] kernel BUG at include/linux/page_ref.h:275! [ 275.26852…

πŸ“… Published: Aug. 8, 2024, midnight πŸ”„ Last Modified: May 4, 2025, 9:25 a.m.

6.8

CVSS3.1

CVE-2023-24062 -

Diebold Nixdorf Vynamic Security Suite (VSS) before 3.3.0 SR12, 4.0.0 SR04, 4.1.0 SR02, and 4.2.0 SR01 fails to validate the directory structure of the root file system during the Pre-Boot Authorization (PBA) process. This can be exploited by a physical attacker who is able to manipulate the conten…

πŸ“… Published: Aug. 8, 2024, midnight πŸ”„ Last Modified: March 18, 2025, 7:15 p.m.

6.3

CVSS3.1

CVE-2024-37382 -

An issue discovered in import host feature in Ab Initio Metadata Hub and Authorization Gateway before 4.3.1.1 allows attackers to run arbitrary code via crafted modification of server configuration.

πŸ“… Published: Aug. 8, 2024, midnight πŸ”„ Last Modified: Aug. 29, 2024, 2:29 p.m.
Total resulsts: 349182
Page 8919 of 34,919
Β« previous page Β» next page
Filters