4.3

CVSS3.1

CVE-2024-5942 - Page and Post Clone <= 6.0 - Insecure Direct Object Reference to Authenticated (Author+) Sensitive …

The Page and Post Clone plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 6.0 via the 'content_clone' function due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with Author-level access …

πŸ“… Published: June 29, 2024, 4:33 a.m. πŸ”„ Last Modified: April 8, 2026, 5:19 p.m.

6.1

CVSS3.1

CVE-2024-6405 - Floating Social Buttons <= 1.5 - Cross-Site Request Forgery

The Floating Social Buttons plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.5. This is due to missing or incorrect nonce validation on the floating_social_buttons_option() function. This makes it possible for unauthenticated attackers to upda…

πŸ“… Published: June 29, 2024, 2:02 a.m. πŸ”„ Last Modified: April 8, 2026, 7:22 p.m.

9.1

CVSS3.1

CVE-2024-39848 -

Internet2 Grouper before 5.6 allows authentication bypass when LDAP authentication is used in certain ways. This is related to internet2.middleware.grouper.ws.security.WsGrouperLdapAuthentication and the use of the UyY29r password for the M3vwHr account. This also affects "Grouper for Web Services"…

πŸ“… Published: June 29, 2024, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

3.5

CVSS3.1

CVE-2024-39846 -

NewPass before 1.2.0 stores passwords (rather than password hashes) directly, which makes it easier to obtain unauthorized access to sensitive information. NOTE: in each case, data at rest is encrypted, but is decrypted within process memory during use.

πŸ“… Published: June 29, 2024, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.8

CVSS3.1

CVE-2024-39840 -

Factorio before 1.1.101 allows a crafted server to execute arbitrary code on clients via a custom map that leverages the ability of certain Lua base module functions to execute bytecode and generate fake objects.

πŸ“… Published: June 29, 2024, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

0.0

CVE-2024-6413 -

** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2023-2414. Reason: This candidate is a reservation duplicate of CVE-2023-2414. Notes: All CVE users should reference CVE-2023-2414 instead of this candidate. All references and descriptions in this candidate have been removed to preven…

πŸ“… Published: June 28, 2024, 9:47 p.m. πŸ”„ Last Modified: Nov. 15, 2024, 4:15 p.m.

7.1

CVSS3.1

CVE-2024-38532 - TEST_KEY used in example dcp_tool reference implementation

The NXP Data Co-Processor (DCP) is a built-in hardware module for specific NXP SoCsΒΉ that implements a dedicated AES cryptographic engine for encryption/decryption operations. The dcp_tool reference implementation included in the repository selected the test key, regardless of its `-t` argument. Th…

πŸ“… Published: June 28, 2024, 9:25 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.5

CVSS3.1

CVE-2024-38533 - ZKsync Era invalid stack addressing conversion

ZKsync Era is a layer 2 rollup that uses zero-knowledge proofs to scale Ethereum. There is possible invalid stack access due to the addresses used to access the stack not properly being converted to cells. This issue has been patched in version 1.5.0.

πŸ“… Published: June 28, 2024, 9:18 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.5

CVSS3.1

CVE-2024-38525 - dd-trace-cpp malformed unicode header values may cause crash

dd-trace-cpp is the Datadog distributed tracing for C++. When the library fails to extract trace context due to malformed unicode, it logs the list of audited headers and their values using the `nlohmann` JSON library. However, due to the way the JSON library is invoked, it throws an uncaught excep…

πŸ“… Published: June 28, 2024, 9:10 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

3.7

CVSS3.1

CVE-2024-39302 - Some bbb-record-core files installed with wrong file permission

BigBlueButton is an open-source virtual classroom designed to help teachers teach and learners learn. An attacker may be able to exploit the overly elevated file permissions in the `/usr/local/bigbluebutton/core/vendor/bundle/ruby/2.7.0/gems/resque-2.6.0` directory with the goal of privilege escala…

πŸ“… Published: June 28, 2024, 8:51 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 349182
Page 9303 of 34,919
Β« previous page Β» next page
Filters