4.3

CVSS3.1

CVE-2024-5997 - Duplica <= 0.6 - Authenticated (Subscriber+) Missing Authorization to Users/Posts Duplicates Creati…

The Duplica – Duplicate Posts, Pages, Custom Posts or Users plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the duplicate_user and duplicate_post functions in all versions up to, and including, 0.6. This makes it possible for authenticate…

πŸ“… Published: July 18, 2024, 9:32 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS3.1

CVE-2024-6455 - ElementsKit Elementor addons <= 3.2.0 - Unauthenticated Information Exposure via ekit_widgetarea_co…

The ElementsKit Elementor addons plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 3.2.0 due to a missing capability checks on ekit_widgetarea_content function. This makes it possible for unauthenticated attackers to view any item created in Elementor,…

πŸ“… Published: July 18, 2024, 8:32 p.m. πŸ”„ Last Modified: April 8, 2026, 5:02 p.m.

4.7

CVSS3.1

CVE-2024-30126 - HCL BigFix Compliance is affected by a missing X-Frame-Options Header vulnerability

HCL BigFix Compliance is affected by a missing X-Frame-Options HTTP header which can allow an attacker to create a malicious website that embeds the target website in a frame or iframe, tricking users into performing actions on the target website without their knowledge.

πŸ“… Published: July 18, 2024, 7:17 p.m. πŸ”„ Last Modified: June 17, 2025, 9:02 p.m.

3.9

CVSS3.1

CVE-2024-38806 - UAA Failure to Remove Shadow User’s Access

Failure to properly synchronize user's permissions in UAA in Cloud Foundry Foundation v40.17.0 https://github.com/cloudfoundry/cf-deployment/releases/tag/v40.17.0 , potentially resulting in users retaining access rights they should not have. This can allow them to perform operations beyond thei…

πŸ“… Published: July 18, 2024, 6:41 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.2

CVSS3.1

CVE-2024-30125 - HCL BigFix Compliance is affected by an internal server error

HCL BigFix Compliance server can respond with an HTTP status of 500, indicating a server-side error that may cause the server process to die.

πŸ“… Published: July 18, 2024, 5:59 p.m. πŸ”„ Last Modified: June 17, 2025, 9:02 p.m.

9.8

CVSS3.1

CVE-2024-0857 - SQLi in Universal Software's FlexWater Corporate Water Management

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Universal Software Inc. FlexWater Corporate Water Management allows SQL Injection.This issue affects FlexWater Corporate Water Management: before 5.452.0.

πŸ“… Published: July 18, 2024, 5:32 p.m. πŸ”„ Last Modified: Nov. 21, 2024, 8:47 a.m.

6.5

CVSS3.1

CVE-2024-5625 - XML External Entity Injection in PruvaSoft Informatics' Apinizer Management Console

Improper Restriction of XML External Entity Reference vulnerability in PruvaSoft Informatics Apinizer Management Console allows Data Serialization External Entities Blowup.This issue affects Apinizer Management Console: before 2024.05.1.

πŸ“… Published: July 18, 2024, 5:12 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

10

CVSS3.1

CVE-2024-40628 - Arbitrary File Read in Ansible Playbooks in Jumpserver

JumpServer is an open-source Privileged Access Management (PAM) tool that provides DevOps and IT teams with on-demand and secure access to SSH, RDP, Kubernetes, Database and RemoteApp endpoints through a web browser. An attacker can exploit the ansible playbook to read arbitrary files in the celery…

πŸ“… Published: July 18, 2024, 5:05 p.m. πŸ”„ Last Modified: March 25, 2025, 8:15 p.m.

10

CVSS3.1

CVE-2024-40629 - Arbitrary File Write in Ansible Playbooks leads to RCE in Jumpserver

JumpServer is an open-source Privileged Access Management (PAM) tool that provides DevOps and IT teams with on-demand and secure access to SSH, RDP, Kubernetes, Database and RemoteApp endpoints through a web browser. An attacker can exploit the Ansible playbook to write arbitrary files, leading to …

πŸ“… Published: July 18, 2024, 5:04 p.m. πŸ”„ Last Modified: March 25, 2025, 8:15 p.m.

6.5

CVSS3.1

CVE-2024-5620 - Authentication Bypass in PruvaSoft Informatics' Apinizer Management Console

Authentication Bypass Using an Alternate Path or Channel vulnerability in PruvaSoft Informatics Apinizer Management Console allows Authentication Bypass.This issue affects Apinizer Management Console: before 2024.05.1.

πŸ“… Published: July 18, 2024, 5 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 349182
Page 9106 of 34,919
Β« previous page Β» next page
Filters