5.4

CVSS3.1

CVE-2024-6175 - Booking Ultra Pro <= 1.1.13 - Missing Authorization to Authenticated (Subscriber+) Plugin Settings …

The Booking Ultra Pro Appointments Booking Calendar Plugin plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the multiple functions called via AJAX like save_fields_settings, bup_delete_user_avatar, bup_crop_avatar_user_profile_image, and …

πŸ“… Published: July 18, 2024, 2:03 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.5

CVSS3.1

CVE-2024-40898 - Apache HTTP Server: SSRF with mod_rewrite in server/vhost context on Windows

SSRF in Apache HTTP Server on Windows with mod_rewrite in server/vhost context, allows to potentially leak NTML hashes to a malicious server via SSRF and malicious requests. Users are recommended to upgrade to version 2.4.62 which fixes this issue.Β 

πŸ“… Published: July 18, 2024, midnight πŸ”„ Last Modified: Nov. 21, 2024, 9:31 a.m.

6.1

CVSS3.1

CVE-2024-5321 - Incorrect permissions on Windows containers logs

A security issue was discovered in Kubernetes clusters with Windows nodes where BUILTIN\UsersΒ may be able to read container logs and NT AUTHORITY\Authenticated UsersΒ may be able to modify container logs.

πŸ“… Published: July 18, 2024, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

9.8

CVSS3.1

CVE-2024-41184 - keepalived: Integer overflow vulnerability in vrrp_ipsets_handler

In the vrrp_ipsets_handler handler (fglobal_parser.c) of keepalived through 2.3.1, an integer overflow can occur. NOTE: this CVE Record might not be worthwhile because an empty ipset name must be configured by the user.

πŸ“… Published: July 18, 2024, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.8

CVSS3.1

CVE-2024-41011 - drm/amdkfd: don't allow mapping the MMIO HDP page with large pages

In the Linux kernel, the following vulnerability has been resolved: drm/amdkfd: don't allow mapping the MMIO HDP page with large pages We don't get the right offset in that case. The GPU has an unused 4K area of the register BAR space into which you can remap registers. We remap the HDP flush r…

πŸ“… Published: July 18, 2024, midnight πŸ”„ Last Modified: Nov. 3, 2025, 10:17 p.m.

6.1

CVSS3.1

CVE-2024-39090 -

The PHPGurukul Online Shopping Portal Project version 2.0 contains a vulnerability that allows Cross-Site Request Forgery (CSRF) to lead to Stored Cross-Site Scripting (XSS). An attacker can exploit this vulnerability to execute arbitrary JavaScript code in the context of a user's session, potentia…

πŸ“… Published: July 18, 2024, midnight πŸ”„ Last Modified: April 5, 2025, 12:12 a.m.

9.8

CVSS3.1

CVE-2024-39173 -

calculator-boilerplate v1.0 was discovered to contain a remote code execution (RCE) vulnerability via the eval function at /routes/calculator.js. This vulnerability allows attackers to execute arbitrary code via a crafted payload injected into the input field.

πŸ“… Published: July 18, 2024, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.4

CVSS3.1

CVE-2024-39682 - WordPress Cooked Plugin - Authenticated (Contributor+) HTML Injection via Recipe Excerpt

Cooked is a recipe plugin for WordPress. The Cooked plugin for WordPress is vulnerable to HTML Injection in versions up to, and including, 1.7.15.4 due to insufficient input sanitization and output escaping. This vulnerability allows authenticated attackers with contributor-level access and above t…

πŸ“… Published: July 17, 2024, 11:47 p.m. πŸ”„ Last Modified: Feb. 10, 2025, 3:37 p.m.

5.4

CVSS3.1

CVE-2024-39681 - WordPress Cooked Plugin - Cross-Site Request Forgery to Apply Template to All Recipes

Cooked is a recipe plugin for WordPress. The Cooked plugin for WordPress is vulnerable to Cross-Site Request Forgery (CSRF) in versions up to, and including, 1.7.15.4 due to missing or incorrect nonce validation on the AJAX action handler. This vulnerability could allow an attacker to trick users i…

πŸ“… Published: July 17, 2024, 11:47 p.m. πŸ”„ Last Modified: Feb. 10, 2025, 3:44 p.m.

5.4

CVSS3.1

CVE-2024-39680 - WordPress Cooked Plugin - Cross-Site Request Forgery to Default Recipe Template Save

Cooked is a recipe plugin for WordPress. The Cooked plugin for WordPress is vulnerable to Cross-Site Request Forgery (CSRF) in versions up to, and including, 1.7.15.4 due to missing or incorrect nonce validation on the AJAX action handler. This vulnerability could allow an attacker to trick users i…

πŸ“… Published: July 17, 2024, 11:47 p.m. πŸ”„ Last Modified: Feb. 10, 2025, 3:46 p.m.
Total resulsts: 349182
Page 9110 of 34,919
Β« previous page Β» next page
Filters