9

CVSS3.1

CVE-2024-0087 - CVE

NVIDIA Triton Inference Server for Linux contains a vulnerability where a user can set the logging location to an arbitrary file. If this file exists, logs are appended to the file. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges,…

📅 Published: May 9, 2024, 9:51 p.m. 🔄 Last Modified: Sept. 19, 2025, 1:17 p.m.

5.3

CVSS4.0

CVE-2024-4688 - Campcodes Complete Web-Based School Management System conversation_history_admin.php cross site scr…

A vulnerability classified as problematic was found in Campcodes Complete Web-Based School Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /view/conversation_history_admin.php. The manipulation of the argument conversation_id leads to cross site scripti…

📅 Published: May 9, 2024, 9:31 p.m. 🔄 Last Modified: Feb. 19, 2025, 6:40 p.m.

5.3

CVSS4.0

CVE-2024-4687 - Campcodes Complete Web-Based School Management System create_events.php cross site scripting

A vulnerability classified as problematic has been found in Campcodes Complete Web-Based School Management System 1.0. Affected is an unknown function of the file /view/create_events.php. The manipulation of the argument my_index leads to cross site scripting. It is possible to launch the attack re…

📅 Published: May 9, 2024, 9 p.m. 🔄 Last Modified: Feb. 19, 2025, 6:39 p.m.

5.9

CVSS3.1

CVE-2024-32985 - Stellar-core's Overlay - security fix for DDoS mitigation

Stellar-core is a reference implementation for the peer-to-peer agent that manages the Stellar network. Prior to 20.4.0, core nodes could be randomly crashed due to a race condition with a 3rd party library. The likelihood of affecting the network is low since crashed nodes come back up online righ…

📅 Published: May 9, 2024, 8:54 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS4.0

CVE-2024-4686 - Campcodes Complete Web-Based School Management System emarks_range_grade_update_form.php cross site…

A vulnerability was found in Campcodes Complete Web-Based School Management System 1.0. It has been rated as problematic. This issue affects some unknown processing of the file /view/emarks_range_grade_update_form.php. The manipulation of the argument grade leads to cross site scripting. The attack…

📅 Published: May 9, 2024, 8:31 p.m. 🔄 Last Modified: Feb. 19, 2025, 6:39 p.m.

8.8

CVSS3.1

CVE-2024-3808 - Porto Theme - Functionality <= 3.1.0 - Authenticated (Contributor+) Local File Inclusion via Shortc…

The Porto Theme - Functionality plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.1.0 via the 'porto_portfolios' shortcode 'portfolio_layout' attribute. This makes it possible for authenticated attackers, with contributor-level and above permissions,…

📅 Published: May 9, 2024, 8:03 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

7.2

CVSS3.1

CVE-2024-2290 - Advanced Ads – Ad Manager & AdSense <= 1.52.1 - Authenticated (Admin+) PHP Object Injection

The Advanced Ads plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.52.1 via deserialization of untrusted input in the 'placement_slug' parameter. This makes it possible for authenticated attackers to inject a PHP Object. No POP chain is present in th…

📅 Published: May 9, 2024, 8:03 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

8.8

CVSS3.1

CVE-2024-3809 - Porto Theme - Functionality <= 3.0.9 - Authenticated (Contributor+) Local File Inclusion via Post M…

The Porto Theme - Functionality plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.0.9 via the 'slideshow_type' post meta. This makes it possible for authenticated attackers, with contributor-level and above permissions, to include and execute arbitra…

📅 Published: May 9, 2024, 8:03 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

8.8

CVSS3.1

CVE-2024-4397 - LearnPress – WordPress LMS Plugin <= 4.2.6.5 - Authenticated (Instructor+) Arbitrary File Upload

The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'save_post_materials' function in versions up to, and including, 4.2.6.5. This makes it possible for authenticated attackers, with Instructor-level permissio…

📅 Published: May 9, 2024, 8:03 p.m. 🔄 Last Modified: April 8, 2026, 7:21 p.m.

6.1

CVSS3.1

CVE-2024-4104 - ADFO – Custom data in admin dashboard <= 1.9.0 - Reflected Cross-Site Scripting

The ADFO – Custom data in admin dashboard plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'dbp_id' parameter in all versions up to, and including, 1.9.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to i…

📅 Published: May 9, 2024, 8:03 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 349182
Page 9915 of 34,919
« previous page » next page
Filters