4.3

CVSS3.1

CVE-2024-5804 - Conditional Fields for Contact Form 7 <= 2.4.13 - Cross-Site Request Forgery to Plugin Setting Reset

The Conditional Fields for Contact Form 7 plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.4.13. This is due to missing or incorrect nonce validation on the wpcf7cf_admin_init function. This makes it possible for unauthenticated attackers to reset…

πŸ“… Published: July 20, 2024, 2:02 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.2

CVSS3.1

CVE-2024-40348 -

An issue in the component /api/swaggerui/static of Bazaar v1.4.3 allows unauthenticated attackers to execute a directory traversal.

πŸ“… Published: July 20, 2024, midnight πŸ”„ Last Modified: July 8, 2025, 2:31 p.m.

6.1

CVSS3.1

CVE-2024-40347 -

A reflected cross-site scripting (XSS) vulnerability in Hyland Alfresco Platform 23.2.1-r96 allows attackers to execute arbitrary code in the context of a user's browser via injecting a crafted payload into the parameter htmlid.

πŸ“… Published: July 20, 2024, midnight πŸ”„ Last Modified: March 18, 2025, 3:15 p.m.

7.5

CVSS3.1

CVE-2024-41122 - Custom environment variables allow to alter execution flow of plugins in Woodpecker

Woodpecker is a simple yet powerful CI/CD engine with great extensibility. The server allow to create any user who can trigger a pipeline run malicious workflows: 1. Those workflows can either lead to a host takeover that runs the agent executing the workflow. 2. Or allow to extract the secrets who…

πŸ“… Published: July 19, 2024, 7:58 p.m. πŸ”„ Last Modified: Nov. 21, 2024, 9:32 a.m.

8.8

CVSS3.1

CVE-2024-41121 - Custom workspace allow to overwrite plugin entrypoint executable in Woodpecker

Woodpecker is a simple yet powerful CI/CD engine with great extensibility. The server allow to create any user who can trigger a pipeline run malicious workflows: 1. Those workflows can either lead to a host takeover that runs the agent executing the workflow. 2. Or allow to extract the secrets who…

πŸ“… Published: July 19, 2024, 7:57 p.m. πŸ”„ Last Modified: Nov. 21, 2024, 9:32 a.m.

8.4

CVSS3.1

CVE-2024-39906 - Remote code execution in Haven IndieAuthClient (GHSL-2024-093)

A command injection vulnerability was found in the IndieAuth functionality of the Ruby on Rails based Haven blog web application. The affected functionality requires authentication, but an attacker can craft a link that they can pass to a logged in administrator of the blog software. This leads to …

πŸ“… Published: July 19, 2024, 7:50 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.3

CVSS3.1

CVE-2024-41124 - Puncia Cleartext Transmission of Sensitive Information via HTTP urls in `API_URLS`

Puncia is the Official CLI utility for Subdomain Center & Exploit Observer. `API_URLS` is utilizing HTTP instead of HTTPS for communication that can lead to issues like Eavesdropping, Data Tampering, Unauthorized Data Access & MITM Attacks. This issue has been addressed in release version 0.21 by u…

πŸ“… Published: July 19, 2024, 7:45 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.5

CVSS3.1

CVE-2024-29080 -

Potential vulnerabilities have been identified in the HP Display Control software component within the HP Application Enabling Software Driver which might allow escalation of privilege.

πŸ“… Published: July 19, 2024, 4:51 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.5

CVSS3.1

CVE-2024-24970 -

Potential vulnerabilities have been identified in the HP Display Control software component within the HP Application Enabling Software Driver which might allow escalation of privilege.

πŸ“… Published: July 19, 2024, 4:50 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6

CVSS4.0

CVE-2024-6908 - Admin Can Escalate Privileges to SuperAdmin Using Manual PUT Request

Improper privilege management in Yugabyte Platform allows authenticated admin users to escalate privileges to SuperAdmin via a crafted PUT HTTP request, potentially leading to unauthorized access to sensitive system functions and data.

πŸ“… Published: July 19, 2024, 2:57 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 349182
Page 9100 of 34,919
Β« previous page Β» next page
Filters