4.3

CVSS3.1

CVE-2024-5864 - Easy Affiliate Links <= 3.7.3 - Missing Authorization to Authenticated (Subscriber+) Settings Reset

The Easy Affiliate Links plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the eafl_reset_settings AJAX action in all versions up to, and including, 3.7.3. This makes it possible for authenticated attackers, with Subscriber-level access and…

πŸ“… Published: June 28, 2024, 3:29 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.4

CVSS3.1

CVE-2024-5863 - Easy Image Collage <= 1.13.5 - Missing Authorization to Authenticated (Contributor+) Data Clearance

The Easy Image Collage plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the ajax_image_collage() function in all versions up to, and including, 1.13.5. This makes it possible for authenticated attackers, with Contributor-level access and above, to…

πŸ“… Published: June 28, 2024, 3:29 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

3.8

CVSS3.1

CVE-2024-37137 -

Dell Key Trust Platform, v3.0.6 and prior, contains Use of a Cryptographic Primitive with a Risky Implementation vulnerability. A local privileged attacker could potentially exploit this vulnerability, leading to privileged information disclosure.

πŸ“… Published: June 28, 2024, 1:33 a.m. πŸ”„ Last Modified: Feb. 3, 2025, 3:26 p.m.

7.8

CVSS3.1

CVE-2024-27629 -

An issue in dc2niix before v.1.0.20240202 allows a local attacker to execute arbitrary code via the generated file name is not properly escaped and injected into a system call when certain types of compression are used.

πŸ“… Published: June 28, 2024, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

9.8

CVSS3.1

CVE-2024-39704 -

Soft Circle French-Bread Melty Blood: Actress Again: Current Code through 1.07 Rev. 1.4.0 allows a remote attacker to execute arbitrary code on a client's machine via a crafted packet on TCP port 46318.

πŸ“… Published: June 28, 2024, midnight πŸ”„ Last Modified: March 20, 2025, 9:15 p.m.

6.1

CVSS3.1

CVE-2024-39828 -

R74n Sandboxels 1.9 through 1.9.5 allows XSS via a message in a modified saved-game file. This was fixed in a hotfix to 1.9.5 on 2024-06-29.

πŸ“… Published: June 28, 2024, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.5

CVSS3.1

CVE-2024-38374 - Improper Restriction of XML External Entity Reference in org.cyclonedx:cyclonedx-core-java

The CycloneDX core module provides a model representation of the SBOM along with utilities to assist in creating, validating, and parsing SBOMs. Before deserializing CycloneDX Bill of Materials in XML format, _cyclonedx-core-java_ leverages XPath expressions to determine the schema version of the B…

πŸ“… Published: June 28, 2024, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.1

CVSS3.1

CVE-2024-27628 -

Buffer Overflow vulnerability in DCMTK v.3.6.8 allows an attacker to execute arbitrary code via the EctEnhancedCT method component.

πŸ“… Published: June 28, 2024, midnight πŸ”„ Last Modified: June 11, 2025, 3:22 p.m.

9.1

CVSS3.1

CVE-2019-25211 - github.com/gin-contrib/cors: Gin mishandles a wildcard in the origin string in github.com/gin-contr…

parseWildcardRules in Gin-Gonic CORS middleware before 1.6.0 mishandles a wildcard at the end of an origin string, e.g., https://example.community/* is allowed when the intention is that only https://example.com/* should be allowed, and http://localhost.example.com/* is allowed when the intention i…

πŸ“… Published: June 28, 2024, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.4

CVSS3.1

CVE-2024-37741 -

OpenPLC 3 through 9cd8f1b allows XSS via an SVG document as a profile picture.

πŸ“… Published: June 28, 2024, midnight πŸ”„ Last Modified: Nov. 21, 2024, 9:24 a.m.
Total resulsts: 349182
Page 9310 of 34,919
Β« previous page Β» next page
Filters