8.8

CVSS3.1

CVE-2024-6756 - Social Auto Poster <= 5.3.14 - Authenticated (Contributor+) Arbitrary File Upload

The Social Auto Poster plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'wpw_auto_poster_get_image_path' function in all versions up to, and including, 5.3.14. This makes it possible for authenticated attackers, with Contributor-level and aboveโ€ฆ

๐Ÿ“… Published: July 24, 2024, 2:33 a.m. ๐Ÿ”„ Last Modified: April 8, 2026, 4:42 p.m.

5.5

CVSS3.1

CVE-2024-40137 -

Dolibarr ERP CRM before 19.0.2-php8.2 was discovered to contain a remote code execution (RCE) vulnerability via the Computed field parameter under the Users Module Setup function.

๐Ÿ“… Published: July 24, 2024, midnight ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.2

CVSS3.1

CVE-2024-31970 -

AdTran SRG 834-5 HDC17600021F1 devices (with SmartOS 11.1.1.1 and fixed in Version 12.1.3.1) have SSH enabled by default, accessible both over the LAN and the Internet. During a window of time when the device is being set up, it uses a default username and password combination of admin/admin with rโ€ฆ

๐Ÿ“… Published: July 24, 2024, midnight ๐Ÿ”„ Last Modified: Nov. 21, 2024, 9:14 a.m.

7.2

CVSS3.1

CVE-2024-39345 -

AdTran 834-5 HDC17600021F1 (SmartOS 11.1.1.1) devices enable the SSH service by default and have a hidden, undocumented, hard-coded support account whose password is based on the devices MAC address. All of the devices internet interfaces share a similar MAC address that only varies in their final โ€ฆ

๐Ÿ“… Published: July 24, 2024, midnight ๐Ÿ”„ Last Modified: Nov. 21, 2024, 9:27 a.m.

8

CVSS3.1

CVE-2024-40495 -

A vulnerability was discovered in Linksys Router E2500 with firmware 2.0.00, allows authenticated attackers to execute arbitrary code via the hnd_parentalctrl_unblock function.

๐Ÿ“… Published: July 24, 2024, midnight ๐Ÿ”„ Last Modified: Jan. 2, 2026, 8:21 p.m.

8.8

CVSS3.1

CVE-2024-36541 -

Insecure permissions in logging-operator v4.6.0 allows attackers to access sensitive data and escalate privileges by obtaining the service account's token.

๐Ÿ“… Published: July 24, 2024, midnight ๐Ÿ”„ Last Modified: Nov. 21, 2024, 9:22 a.m.

9.8

CVSS3.1

CVE-2024-36539 -

Insecure permissions in contour v1.28.3 allows attackers to access sensitive data and escalate privileges by obtaining the service account's token.

๐Ÿ“… Published: July 24, 2024, midnight ๐Ÿ”„ Last Modified: June 27, 2025, 4:50 p.m.

9.1

CVSS3.1

CVE-2024-40422 -

The snapshot_path parameter in the /api/get-browser-snapshot endpoint in stitionai devika v1 is susceptible to a path traversal attack. An attacker can manipulate the snapshot_path parameter to traverse directories and access sensitive files on the server. This can potentially lead to unauthorized โ€ฆ

๐Ÿ“… Published: July 24, 2024, midnight ๐Ÿ”„ Last Modified: Jan. 29, 2025, 10:15 p.m.

9.8

CVSS3.1

CVE-2024-41461 -

Tenda FH1201 v1.2.0.14 was discovered to contain a stack-based buffer overflow vulnerability via the list1 parameter at ip/goform/DhcpListClient.

๐Ÿ“… Published: July 24, 2024, midnight ๐Ÿ”„ Last Modified: Nov. 21, 2024, 9:32 a.m.

8.4

CVSS3.1

CVE-2024-36534 -

Insecure permissions in hwameistor v0.14.3 allows attackers to access sensitive data and escalate privileges by obtaining the service account's token.

๐Ÿ“… Published: July 24, 2024, midnight ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 349182
Page 9063 of 34,919
ยซ previous page ยป next page
Filters