4.3

CVSS3.1

CVE-2024-4661 - WP Reset <= 2.02 - Missing Authorization to License Key Modification

The WP Reset plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the save_ajax function in all versions up to, and including, 2.02. This makes it possible for authenticated attackers, with subscriber-level access and above, to modify the valu…

πŸ“… Published: June 8, 2024, 5:44 a.m. πŸ”„ Last Modified: April 8, 2026, 5:18 p.m.

4.2

CVSS3.1

CVE-2024-5770 - WP Force SSL & HTTPS SSL Redirect <= 1.66 - Missing Authorization to Settings Update

The WP Force SSL & HTTPS SSL Redirect plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'ajax_save_setting' function in versions up to, and including, 1.66. This makes it possible for authenticated attackers, subscriber-level permission…

πŸ“… Published: June 8, 2024, 4:32 a.m. πŸ”„ Last Modified: April 8, 2026, 7:22 p.m.

8.8

CVSS3.1

CVE-2024-3668 - PowerPack Pro for Elementor <= 2.10.17 - Authenticated (Contributor+) Privilege Escalation

The PowerPack Pro for Elementor plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 2.10.17. This is due to the plugin not restricting low privileged users from setting a default role for a registration form. This makes it possible for authenticated atta…

πŸ“… Published: June 8, 2024, 4:32 a.m. πŸ”„ Last Modified: April 8, 2026, 5:18 p.m.

6.4

CVSS3.1

CVE-2024-5663 - Cards for Beaver Builder <= 1.1.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via Ca…

The Cards for Beaver Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Cards widget in all versions up to, and including, 1.1.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated a…

πŸ“… Published: June 8, 2024, 2:35 a.m. πŸ”„ Last Modified: April 8, 2026, 6:22 p.m.

9.1

CVSS3.1

CVE-2024-37407 - libarchive: Out of bounds access in slurp_central_directory at archive_read_support_format_zip.c

Libarchive before 3.7.4 allows name out-of-bounds access when a ZIP archive has an empty-name file and mac-ext is enabled. This occurs in slurp_central_directory in archive_read_support_format_zip.c.

πŸ“… Published: June 8, 2024, midnight πŸ”„ Last Modified: April 29, 2025, 4:35 p.m.

5.5

CVSS3.1

CVE-2024-36969 - drm/amd/display: Fix division by zero in setup_dsc_config

In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Fix division by zero in setup_dsc_config When slice_height is 0, the division by slice_height in the calculation of the number of slices will cause a division by zero driver crash. This leaves the kernel in a sta…

πŸ“… Published: June 8, 2024, midnight πŸ”„ Last Modified: July 11, 2025, 5:19 p.m.

7.3

CVSS3.1

CVE-2024-37408 - fprintd: unexpected actions might be authorized with fingerprint reader

fprintd through 1.94.3 lacks a security attention mechanism, and thus unexpected actions might be authorized by "auth sufficient pam_fprintd.so" for Sudo. NOTE: the supplier disputes this because they believe issue resolution would involve modifying the PAM configuration to restrict pam_fprintd.so …

πŸ“… Published: June 8, 2024, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.5

CVSS3.1

CVE-2024-36966 - erofs: reliably distinguish block based and fscache mode

In the Linux kernel, the following vulnerability has been resolved: erofs: reliably distinguish block based and fscache mode When erofs_kill_sb() is called in block dev based mode, s_bdev may not have been initialised yet, and if CONFIG_EROFS_FS_ONDEMAND is enabled, it will be mistaken for fscach…

πŸ“… Published: June 8, 2024, midnight πŸ”„ Last Modified: Oct. 1, 2025, 2:43 p.m.

5.5

CVSS3.1

CVE-2024-36967 - KEYS: trusted: Fix memory leak in tpm2_key_encode()

In the Linux kernel, the following vulnerability has been resolved: KEYS: trusted: Fix memory leak in tpm2_key_encode() 'scratch' is never freed. Fix this by calling kfree() in the success, and in the error case.

πŸ“… Published: June 8, 2024, midnight πŸ”„ Last Modified: May 4, 2025, 9:13 a.m.

5.5

CVSS3.1

CVE-2024-36965 - remoteproc: mediatek: Make sure IPI buffer fits in L2TCM

In the Linux kernel, the following vulnerability has been resolved: remoteproc: mediatek: Make sure IPI buffer fits in L2TCM The IPI buffer location is read from the firmware that we load to the System Companion Processor, and it's not granted that both the SRAM (L2TCM) size that is defined in th…

πŸ“… Published: June 8, 2024, midnight πŸ”„ Last Modified: May 4, 2025, 9:12 a.m.
Total resulsts: 349182
Page 9547 of 34,919
Β« previous page Β» next page
Filters