9.8

CVSS3.1

CVE-2024-35361 -

MTab Bookmark v1.9.5 has an SQL injection vulnerability in /LinkStore/getIcon. An attacker can execute arbitrary SQL statements through this vulnerability without requiring any user rights.

📅 Published: May 21, 2024, 12:17 p.m. 🔄 Last Modified: Feb. 13, 2025, 3:58 p.m.

6.8

CVSS4.0

CVE-2024-4420 - Denial of Service in Tink-cc

There exists a Denial of service vulnerability in Tink-cc in versions prior to 2.1.3.  * An adversary can crash binaries using the crypto::tink::JsonKeysetReader in tink-cc by providing an input that is not an encoded JSON object, but still a valid encoded JSON element, for example a number or an…

📅 Published: May 21, 2024, 11:52 a.m. 🔄 Last Modified: June 5, 2025, 2:41 p.m.

5.3

CVSS3.1

CVE-2024-3268 - YouTube Video Gallery by YouTube Showcase – Video Gallery Plugin for WordPress <= 3.3.6 - Missing A…

The YouTube Video Gallery by YouTube Showcase – Video Gallery Plugin for WordPress plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the emd_form_builder_lite_submit_form function in all versions up to, and including, 3.3.6. This makes it p…

📅 Published: May 21, 2024, 11:33 a.m. 🔄 Last Modified: April 8, 2026, 4:35 p.m.

6.4

CVSS3.1

CVE-2024-4619 - Elementor Website Builder – More than Just a Page Builder <= 3.21.5 - Authenticated (Contributor+) …

The Elementor Website Builder – More than Just a Page Builder plugin for WordPress is vulnerable to DOM-Based Stored Cross-Site Scripting via the ‘hover_animation’ parameter in versions up to, and including, 3.21.5 due to insufficient input sanitization and output escaping. This makes it possible f…

📅 Published: May 21, 2024, 11:02 a.m. 🔄 Last Modified: April 8, 2026, 7:21 p.m.

6.4

CVSS3.1

CVE-2024-4361 - Page Builder by SiteOrigin <= 2.29.15 - Authenticated (Contributor+) Stored Cross-Site Scripting vi…

The Page Builder by SiteOrigin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'siteorigin_widget' shortcode in all versions up to, and including, 2.29.15 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possibl…

📅 Published: May 21, 2024, 11:02 a.m. 🔄 Last Modified: April 8, 2026, 7:21 p.m.

6.4

CVSS3.1

CVE-2024-4876 - HT Mega – Absolute Addons For Elementor <= 2.5.2 - Authenticated (Contributor+) Stored Cross-Site S…

The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘popover_header_text’ parameter in versions up to, and including, 2.5.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attacker…

📅 Published: May 21, 2024, 11:02 a.m. 🔄 Last Modified: April 8, 2026, 6:21 p.m.

10

CVSS3.1

CVE-2023-3941 - Multiple arbitrary file writes in ZkTeco-based OEM devices

Relative Path Traversal vulnerability in ZkTeco-based OEM devices allows an attacker to write any file on the system with root privileges. This issue affects ZkTeco-based OEM devices (ZkTeco ProFace X, Smartec ST-FR043, Smartec ST-FR041ME and possibly others) with the ZAM170-NF-1.8.25-7354-Ve…

📅 Published: May 21, 2024, 10:20 a.m. 🔄 Last Modified: Nov. 21, 2024, 8:18 a.m.

7.5

CVSS3.1

CVE-2023-3940 - Multiple arbitrary file reads in ZkTeco-based OEM devices

Relative Path Traversal vulnerability in ZkTeco-based OEM devices allows an attacker to access any file on the system. This issue affects ZkTeco-based OEM devices (ZkTeco ProFace X, Smartec ST-FR043, Smartec ST-FR041ME and possibly others) with the ZAM170-NF-1.8.25-7354-Ver1.0.0 and possibly …

📅 Published: May 21, 2024, 10:15 a.m. 🔄 Last Modified: Nov. 21, 2024, 8:18 a.m.

7.5

CVSS3.1

CVE-2024-4988 - Improper permission control in com.transsion.videocallenhancer

The mobile application (com.transsion.videocallenhancer) interface has improper permission control, which can lead to the risk of private file leakage.

📅 Published: May 21, 2024, 10:04 a.m. 🔄 Last Modified: Nov. 21, 2024, 9:44 a.m.

10

CVSS3.1

CVE-2023-3939 - Multiple command injection in ZkTeco-based OEM devices

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in ZkTeco-based OEM devices allows OS Command Injection. Since all the found command implementations are executed from the superuser, their impact is the maximum possible. This issue affects…

📅 Published: May 21, 2024, 9:45 a.m. 🔄 Last Modified: Nov. 21, 2024, 8:18 a.m.
Total resulsts: 343926
Page 9194 of 34,393
« previous page » next page
Filters