7.2

CVSS3.1

CVE-2024-22264 - VMware Avi Load Balancer updates address multiple vulnerabilities

VMware Avi Load Balancer contains a privilege escalation vulnerability.Β A malicious actor with admin privileges on VMware Avi Load Balancer can create, modify, execute and delete files as a root user on the host system.

πŸ“… Published: May 8, 2024, 3:57 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.4

CVSS3.1

CVE-2024-32674 -

Heateor Social Login WordPress prior to 1.1.32 contains a cross-site scripting vulnerability. If this vulnerability is exploited, an arbitrary script may be executed on the web browser of the user who accessed the website using the product.

πŸ“… Published: May 8, 2024, 3:37 a.m. πŸ”„ Last Modified: June 4, 2025, 5:23 p.m.

9.8

CVSS3.1

CVE-2024-4393 - Social Connect <= 1.2 - Authentication Bypass

The Social Connect plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 1.2. This is due to insufficient verification on the OpenID server being supplied during the social login through the plugin. This makes it possible for unauthenticated attackers to log …

πŸ“… Published: May 8, 2024, 3:02 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

4.4

CVSS3.1

CVE-2024-4162 - KW Watcher Vulnerability ALlows Malicious Read Access to Memory

A buffer error in Panasonic KW Watcher versions 1.00 through 2.83 may allow attackers malicious read access to memory.

πŸ“… Published: May 8, 2024, 2:57 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.8

CVSS3.1

CVE-2024-2746 - Incomplete fix for CVE-2024-1929

Incomplete fix for CVE-2024-1929 The problem with CVE-2024-1929 was that the dnf5 D-Bus daemon accepted arbitrary configuration parameters from unprivileged users, which allowed a local root exploit by tricking the daemon into loading a user controlled "plugin". All of this happened before Polkit …

πŸ“… Published: May 8, 2024, 1:55 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.5

CVSS3.1

CVE-2024-1929 - Local Root Exploit via Configuration Dictionary

Local Root Exploit via Configuration Dictionary in dnf5daemon-serverΒ before 5.1.17 allows a malicious user to impact Confidentiality and Integrity via Configuration Dictionary. There are issues with the D-Bus interface long before Polkit is invoked. The `org.rpm.dnf.v0.SessionManager.open_session…

πŸ“… Published: May 8, 2024, 1:53 a.m. πŸ”„ Last Modified: Aug. 25, 2025, 1:46 p.m.

6.5

CVSS3.1

CVE-2024-1930 - No Limit on Number of Open Sessions / Bad Session Close Behaviour

No Limit on Number of Open Sessions / Bad Session Close Behaviour in dnf5daemon-server before 5.1.17 allows a malicious user to impact Availability viaΒ No Limit on Number of Open Sessions. There is no limit on how many sessions D-Bus clients may create using the `open_session()` D-Bus method.Β For…

πŸ“… Published: May 8, 2024, 1:52 a.m. πŸ”„ Last Modified: Aug. 7, 2025, 5:21 p.m.

7.8

CVSS3.1

CVE-2024-2860 -

The PostgreSQL implementation in Brocade SANnav versions before 2.3.0a is vulnerable to an incorrect local authentication flaw. An attacker accessing the VM where the Brocade SANnav is installed can gain access to sensitive data inside the PostgreSQL database.

πŸ“… Published: May 8, 2024, 1:01 a.m. πŸ”„ Last Modified: Feb. 6, 2025, 5:54 p.m.

4.1

CVSS3.1

CVE-2024-4456 -

In affected versions of Octopus Server with certain access levels it was possible to embed a Cross-Site Scripting payload on the audit page.

πŸ“… Published: May 8, 2024, 12:46 a.m. πŸ”„ Last Modified: June 30, 2025, 6:04 p.m.

9.8

CVSS3.1

CVE-2024-25519 -

RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the idlist parameter at /WorkFlow/wf_work_print.aspx.

πŸ“… Published: May 8, 2024, midnight πŸ”„ Last Modified: April 17, 2025, 5:20 p.m.
Total resulsts: 349182
Page 9944 of 34,919
Β« previous page Β» next page
Filters