9.3

CVSS4.0

CVE-2024-7395 - Insufficient Authentication

An authentication bypass vulnerability in Korenix JetPort 5601v3 allows an attacker to access functionality on the device without specifying a password.This issue affects JetPort 5601v3: through 1.2.

πŸ“… Published: Aug. 5, 2024, 1:16 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.8

CVSS3.1

CVE-2024-4607 - Mali GPU Kernel Driver allows improper GPU memory processing operations

Use After Free vulnerability in Arm Ltd Bifrost GPU Kernel Driver, Arm Ltd Valhall GPU Kernel Driver, Arm Ltd Arm 5th Gen GPU Architecture Kernel Driver allows a local non-privileged user to make improper GPU memory processing operations to gain access to already freed memory.This issue affects Bif…

πŸ“… Published: Aug. 5, 2024, 11:33 a.m. πŸ”„ Last Modified: Sept. 30, 2024, 4:09 p.m.

7.8

CVSS3.1

CVE-2024-2937 - Mali GPU Kernel Driver allows improper GPU memory processing operations

Use After Free vulnerability in Arm Ltd Bifrost GPU Kernel Driver, Arm Ltd Valhall GPU Kernel Driver, Arm Ltd Arm 5th Gen GPU Architecture Kernel Driver allows a local non-privileged user to make improper GPU memory processing operations to gain access to already freed memory.This issue affects Bif…

πŸ“… Published: Aug. 5, 2024, 11:31 a.m. πŸ”„ Last Modified: Sept. 30, 2024, 3:56 p.m.

7.3

CVSS3.1

CVE-2024-36448 - Apache IoTDB Workbench: SSRF Vulnerability (EOL)

** UNSUPPORTED WHEN ASSIGNED ** Server-Side Request Forgery (SSRF) vulnerability in Apache IoTDB Workbench. This issue affects Apache IoTDB Workbench: from 0.13.0. As this project is retired, we do not plan to release a version that fixes this issue. Users are recommended to find an alternative o…

πŸ“… Published: Aug. 5, 2024, 9:53 a.m. πŸ”„ Last Modified: March 13, 2025, 3:15 p.m.

8.1

CVSS3.1

CVE-2024-38856 - Apache OFBiz: Unauthenticated endpoint could allow execution of screen rendering code

Incorrect Authorization vulnerability in Apache OFBiz. This issue affects Apache OFBiz: through 18.12.14. Users are recommended to upgrade to version 18.12.15, which fixes the issue. Unauthenticated endpoints could allow execution of screen rendering code of screens if some preconditions are met…

πŸ“… Published: Aug. 5, 2024, 8:20 a.m. πŸ”„ Last Modified: Oct. 23, 2025, 2:49 p.m.

9.8

CVSS3.1

CVE-2024-42447 - Apache Airflow Providers FAB: FAB provider 1.2.1 and 1.2.0 did not let user to logout for Airflow

Insufficient Session Expiration vulnerability in Apache Airflow Providers FAB. This issue affects Apache Airflow Providers FAB: 1.2.1 (when used with Apache Airflow 2.9.3) and FAB 1.2.0 for all Airflow versions. The FAB provider prevented the user from logging out.Β Β  * FAB provider 1.2.1 only aff…

πŸ“… Published: Aug. 5, 2024, 8:02 a.m. πŸ”„ Last Modified: March 19, 2025, 3:15 p.m.

5.4

CVSS3.1

CVE-2024-6710 - Ditty < 3.1.45 - Author+ Stored XSS

The Ditty WordPress plugin before 3.1.45 does not sanitise and escape some parameters, which could allow users with a role as low as Contributor to perform Cross-Site Scripting attacks.

πŸ“… Published: Aug. 5, 2024, 6 a.m. πŸ”„ Last Modified: Sept. 5, 2024, 3:30 p.m.

4.8

CVSS3.1

CVE-2024-6498 - CollectChat < 2.4.4 - Admin+ XSS

The Chatbot for WordPress by Collect.chat ⚑️ WordPress plugin before 2.4.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed

πŸ“… Published: Aug. 5, 2024, 6 a.m. πŸ”„ Last Modified: Sept. 6, 2024, 5:35 p.m.

4.8

CVSS3.1

CVE-2024-6270 - Community Events < 1.5.1 - Admin+ Stored XSS

The Community Events WordPress plugin before 1.5.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

πŸ“… Published: Aug. 5, 2024, 6 a.m. πŸ”„ Last Modified: June 12, 2025, 4:59 p.m.

6.1

CVSS3.1

CVE-2024-5081 - WP eMember <= v10.7.0 - Stored XSS via CSRF

The wp-eMember WordPress plugin before v10.7.0 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack

πŸ“… Published: Aug. 5, 2024, 6 a.m. πŸ”„ Last Modified: June 9, 2025, 9:29 p.m.
Total resulsts: 349182
Page 8956 of 34,919
Β« previous page Β» next page
Filters