4.4

CVSS3.1

CVE-2024-5258 - Authorization Bypass Through User-Controlled Key in GitLab

An authorization vulnerability exists within GitLab from versions 16.10 before 16.10.6, 16.11 before 16.11.3, and 17.0 before 17.0.1 where an authenticated attacker could utilize a crafted naming convention to bypass pipeline authorization logic.

πŸ“… Published: May 23, 2024, 11:02 a.m. πŸ”„ Last Modified: Dec. 13, 2024, 5:09 p.m.

6.5

CVSS3.1

CVE-2024-5165 - Eclipse Ditto User Interface vulnerable to XSS due to Improper Neutralization of Input

In Eclipse Ditto versions 3.0.0 to 3.5.5, the user input of several input fields of the Eclipse Ditto Explorer User Interface https://eclipse.dev/ditto/user-interface.html was not properly neutralized and thus vulnerable to both Reflected and Stored XSS (Cross Site Scripting). Several inputs…

πŸ“… Published: May 23, 2024, 9:56 a.m. πŸ”„ Last Modified: Jan. 31, 2025, 2:46 p.m.

8.8

CVSS3.1

CVE-2024-4779 - Unlimited Elements for Elementor <= 1.5.107 - Authenticated (Contributor+) SQL Injection via data[p…

The Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin for WordPress is vulnerable to SQL Injection via the β€˜data[post_ids][0]’ parameter in all versions up to, and including, 1.5.107 due to insufficient escaping on the user supplied parameter and lack of sufficient preparati…

πŸ“… Published: May 23, 2024, 9:32 a.m. πŸ”„ Last Modified: April 8, 2026, 7:21 p.m.

6.4

CVSS3.1

CVE-2024-2861 - ProfilePress <= 4.15.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via ProfilePress …

The ProfilePress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ProfilePress User Panel widget in all versions up to, and including, 4.15.8 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated att…

πŸ“… Published: May 23, 2024, 9:32 a.m. πŸ”„ Last Modified: April 8, 2026, 6:21 p.m.

8.8

CVSS3.1

CVE-2024-35186 - gix traversal outside working tree enables arbitrary code execution

gitoxide is a pure Rust implementation of Git. During checkout, `gix-worktree-state` does not verify that paths point to locations in the working tree. A specially crafted repository can, when cloned, place new files anywhere writable by the application. This vulnerability leads to a major loss of …

πŸ“… Published: May 23, 2024, 8:55 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS3.1

CVE-2024-35223 - Dapr API Token Exposure

Dapr is a portable, event-driven, runtime for building distributed applications across cloud and edge. Dapr sends the app token of the invoker app instead of the app token of the invoked app. This causes of a leak of the application token of the invoker app to the invoked app when using Dapr as a g…

πŸ“… Published: May 23, 2024, 8:47 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.9

CVSS3.1

CVE-2024-5264 - Network Key Transfer with AES KHT vulnerability in Luna EFT

Network Transfer with AES KHT in Thales Luna EFT 2.1 and above allows a user with administrative console access to access backups taken via offline analysis

πŸ“… Published: May 23, 2024, 8:40 a.m. πŸ”„ Last Modified: Nov. 21, 2024, 9:47 a.m.

7.8

CVSS3.1

CVE-2024-30279 - ZDI-CAN-22887: Adobe Acrobat Reader DC JPEG2000 File Parsing Out-Of-Bounds Write Remote Code Execut…

Acrobat Reader versions 20.005.30574, 24.002.20736 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

πŸ“… Published: May 23, 2024, 8:29 a.m. πŸ”„ Last Modified: Dec. 2, 2024, 9:22 p.m.

7.8

CVSS3.1

CVE-2024-30280 - ZDI-CAN-22867: Adobe Acrobat Pro DC AcroForm Annotation Out-Of-Bounds Read Remote Code Execution Vu…

Acrobat Reader versions 20.005.30574, 24.002.20736 and earlier are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this vulnerability to execute code in the context of…

πŸ“… Published: May 23, 2024, 8:29 a.m. πŸ”„ Last Modified: Dec. 2, 2024, 9:07 p.m.

2.7

CVSS3.1

CVE-2024-32969 - vantage6 collaboration admins can extend their influence by expanding the collaboration

vantage6 is an open-source infrastructure for privacy preserving analysis. Collaboration administrators can add extra organizations to their collaboration that can extend their influence. For example, organizations that they include can then create new users for which they know the passwords, and u…

πŸ“… Published: May 23, 2024, 8:22 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 346515
Page 9425 of 34,652
Β« previous page Β» next page
Filters