9.3

CVSS4.0

CVE-2024-1659 - Arbitrary File Upload in MegaBIP

Arbitrary File Upload vulnerability in MegaBIP software allows attacker to upload any file to the server (including a PHP code file) without an authentication. This issue affects MegaBIP software versions through 5.10.

📅 Published: June 12, 2024, 1:48 p.m. 🔄 Last Modified: Nov. 21, 2024, 8:51 a.m.

9.3

CVSS4.0

CVE-2024-1577 - Remote Code Execution in MegaBIP

Remote Code Execution vulnerability in MegaBIP software allows to execute arbitrary code on the server without requiring authentication by saving crafted by the attacker PHP code to one of the website files. This issue affects MegaBIP software versions through 5.11.2.

📅 Published: June 12, 2024, 1:47 p.m. 🔄 Last Modified: Nov. 21, 2024, 8:50 a.m.

9.3

CVSS4.0

CVE-2024-1576 - SQL Injection in MegaBIP

SQL Injection vulnerability in MegaBIP software allows attacker to obtain site administrator privileges, including access to the administration panel and the ability to change the administrator password. This issue affects MegaBIP software versions through 5.09.

📅 Published: June 12, 2024, 1:47 p.m. 🔄 Last Modified: Nov. 21, 2024, 8:50 a.m.

8.8

CVSS3.1

CVE-2024-25949 -

Dell OS10 Networking Switches, versions10.5.6.x, 10.5.5.x, 10.5.4.x and 10.5.3.x ,contain an improper authorization vulnerability. A remote authenticated attacker could potentially exploit this vulnerability leading to escalation of privileges.

📅 Published: June 12, 2024, 12:58 p.m. 🔄 Last Modified: Nov. 21, 2024, 9:01 a.m.

6.5

CVSS3.1

CVE-2024-5313 -

CWE-668: Exposure of the Resource Wrong Sphere vulnerability exists that exposes a SSH interface over the product network interface. This does not allow to directly exploit the product or make any unintended operation as the SSH interface access is protected by an authentication mechanism. Impacts …

📅 Published: June 12, 2024, 12:14 p.m. 🔄 Last Modified: Nov. 21, 2024, 9:47 a.m.

6.5

CVSS3.1

CVE-2024-5056 -

CWE-552: Files or Directories Accessible to External Parties vulnerability exists which may prevent user to update the device firmware and prevent proper behavior of the webserver when specific files or directories are removed from the filesystem.

📅 Published: June 12, 2024, 12:10 p.m. 🔄 Last Modified: Nov. 21, 2024, 9:46 a.m.

7.2

CVSS3.1

CVE-2024-5211 - Path Traversal to Arbitrary File Read/Delete/Overwrite, DoS Attack, and Admin Account Takeover in m…

A path traversal vulnerability in mintplex-labs/anything-llm allowed a manager to bypass the `normalizePath()` function, intended to defend against path traversal attacks. This vulnerability enables the manager to read, delete, or overwrite the 'anythingllm.db' database file and other files stored …

📅 Published: June 12, 2024, 11:33 a.m. 🔄 Last Modified: July 15, 2025, 3:04 p.m.

6.5

CVSS3.1

CVE-2024-5674 - Newsletter - API v1 and v2 addon for Newsletter <= 2.4.5 - Missing Authorization to Email Subscribe…

The Newsletter - API v1 and v2 addon plugin for WordPress is vulnerable to unauthorized subscribers management due to PHP type juggling issue on the check_api_key function in all versions up to, and including, 2.4.5. This makes it possible for unauthenticated attackers to list, create or delete new…

📅 Published: June 12, 2024, 11:05 a.m. 🔄 Last Modified: April 8, 2026, 7:21 p.m.

6.4

CVSS3.1

CVE-2024-3492 - Events Manager – Calendar, Bookings, Tickets, and more! <= 6.4.7.3 - Authenticated (Contributor+) S…

The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'event', 'location', and 'event_category' shortcodes in all versions up to, and including, 6.4.7.3 due to insufficient input sanitization and output escapin…

📅 Published: June 12, 2024, 11:05 a.m. 🔄 Last Modified: April 8, 2026, 7:21 p.m.

4.4

CVSS3.1

CVE-2024-1766 - Download Manager <= 3.2.86 - Authenticated (Subscriber+) Stored Self-Based Cross-Site Scripting

The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via a user's Display Name in all versions up to, and including, 3.2.86 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access …

📅 Published: June 12, 2024, 11:05 a.m. 🔄 Last Modified: April 8, 2026, 6:20 p.m.
Total resulsts: 347008
Page 9267 of 34,701
« previous page » next page
Filters