9.8

CVSS3.1

CVE-2024-4552 - Social Login Lite For WooCommerce <= 1.6.0 - Authentication Bypass

The Social Login Lite For WooCommerce plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 1.6.0. This is due to insufficient verification on the user being supplied during the social login through the plugin. This makes it possible for unauthenticated attac…

📅 Published: June 4, 2024, 2 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

7.2

CVSS3.1

CVE-2024-4870 - Frontend Registration – Contact Form 7 <= 5.1 - Authenticated (Editor+) Privilege Escalation

The Frontend Registration – Contact Form 7 plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 5.1 due to insufficient restriction on the '_cf7frr_' post meta. This makes it possible for authenticated attackers, with editor-level access and above, to modify …

📅 Published: June 4, 2024, 2 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

6.5

CVSS3.1

CVE-2024-29976 -

** UNSUPPORTED WHEN ASSIGNED ** The improper privilege management vulnerability in the command “show_allsessions” in Zyxel NAS326 firmware versions before V5.21(AAZF.17)C0 and NAS542 firmware versions before V5.21(ABAG.14)C0 could allow an authenticated attacker to obtain a logged-in administrator’…

📅 Published: June 4, 2024, 1:47 a.m. 🔄 Last Modified: Jan. 22, 2025, 10:49 p.m.

6.7

CVSS3.1

CVE-2024-29975 -

** UNSUPPORTED WHEN ASSIGNED ** The improper privilege management vulnerability in the SUID executable binary in Zyxel NAS326 firmware versions before V5.21(AAZF.17)C0 and NAS542 firmware versions before V5.21(ABAG.14)C0 could allow an authenticated local attacker with administrator privileges to e…

📅 Published: June 4, 2024, 1:43 a.m. 🔄 Last Modified: Jan. 22, 2025, 10:48 p.m.

9.8

CVSS3.1

CVE-2024-29974 -

** UNSUPPORTED WHEN ASSIGNED ** The remote code execution vulnerability in the CGI program “file_upload-cgi” in Zyxel NAS326 firmware versions before V5.21(AAZF.17)C0 and NAS542 firmware versions before V5.21(ABAG.14)C0 could allow an unauthenticated attacker to execute arbitrary code by uploading …

📅 Published: June 4, 2024, 1:34 a.m. 🔄 Last Modified: Jan. 22, 2025, 10:40 p.m.

9.8

CVSS3.1

CVE-2024-29973 -

** UNSUPPORTED WHEN ASSIGNED ** The command injection vulnerability in the “setCookie” parameter in Zyxel NAS326 firmware versions before V5.21(AAZF.17)C0 and NAS542 firmware versions before V5.21(ABAG.14)C0 could allow an unauthenticated attacker to execute some operating system (OS) commands by s…

📅 Published: June 4, 2024, 1:29 a.m. 🔄 Last Modified: Jan. 22, 2025, 10:40 p.m.

9.8

CVSS3.1

CVE-2024-29972 -

** UNSUPPORTED WHEN ASSIGNED ** The command injection vulnerability in the CGI program "remote_help-cgi" in Zyxel NAS326 firmware versions before V5.21(AAZF.17)C0 and NAS542 firmware versions before V5.21(ABAG.14)C0 could allow an unauthenticated attacker to execute some operating system (OS) comma…

📅 Published: June 4, 2024, 1:24 a.m. 🔄 Last Modified: Jan. 22, 2025, 10:39 p.m.

5.9

CVSS3.1

CVE-2024-29152 -

An issue was discovered in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, Exynos 990, Exynos 1080, Exynos 2100, Exynos 2200, Exynos 1280, Exynos 1380, Exynos 1330, Exynos 2400, Exynos Modem 5123, and Exynos Modem 5300. The baseband software does not properly check states specif…

📅 Published: June 4, 2024, midnight 🔄 Last Modified: Aug. 27, 2025, 4:15 p.m.

5.9

CVSS3.1

CVE-2024-34362 - Envoy affected by a crash (use-after-free) in EnvoyQuicServerStream

Envoy is a cloud-native, open source edge and service proxy. There is a use-after-free in `HttpConnectionManager` (HCM) with `EnvoyQuicServerStream` that can crash Envoy. An attacker can exploit this vulnerability by sending a request without `FIN`, then a `RESET_STREAM` frame, and then after recei…

📅 Published: June 4, 2024, midnight 🔄 Last Modified: Nov. 21, 2024, 9:18 a.m.

7.5

CVSS3.1

CVE-2024-32976 - Envoy can enter an endless loop while decompressing Brotli data with extra input

Envoy is a cloud-native, open source edge and service proxy. Envoyproxy with a Brotli filter can get into an endless loop during decompression of Brotli data with extra input.

📅 Published: June 4, 2024, midnight 🔄 Last Modified: Nov. 21, 2024, 9:16 a.m.
Total resulsts: 347752
Page 9455 of 34,776
« previous page » next page
Filters