9.8

CVSS3.1

CVE-2025-0890 -

**UNSUPPORTED WHEN ASSIGNED** Insecure default credentials for the Telnet function in the legacy DSL CPE Zyxel VMG4325-B10A firmware version 1.00(AAFR.4)C0_20170615 could allow an attacker to log in to the management interface if the administrators have the option to change the default credentials …

📅 Published: Feb. 4, 2025, 10:06 a.m. 🔄 Last Modified: Dec. 15, 2025, 9:02 p.m.

8.8

CVSS3.1

CVE-2024-40891 -

**UNSUPPORTED WHEN ASSIGNED** A post-authentication command injection vulnerability in the management commands of the legacy DSL CPE Zyxel VMG4325-B10A firmware version 1.00(AAFR.4)C0_20170615 could allow an authenticated attacker to execute operating system (OS) commands on an affected device via …

📅 Published: Feb. 4, 2025, 10:02 a.m. 🔄 Last Modified: Oct. 27, 2025, 5:04 p.m.

8.8

CVSS3.1

CVE-2024-40890 -

**UNSUPPORTED WHEN ASSIGNED** A post-authentication command injection vulnerability in the CGI program of the legacy DSL CPE Zyxel VMG4325-B10A firmware version 1.00(AAFR.4)C0_20170615 could allow an authenticated attacker to execute operating system (OS) commands on an affected device by sending a…

📅 Published: Feb. 4, 2025, 9:55 a.m. 🔄 Last Modified: Oct. 27, 2025, 5:04 p.m.

8.8

CVSS3.1

CVE-2025-23015 - Apache Cassandra: User with MODIFY permission on ALL KEYSPACES can escalate privileges to superuser…

Privilege Defined With Unsafe Actions vulnerability in Apache Cassandra. An user with MODIFY permission ON ALL KEYSPACES can escalate privileges to superuser within a targeted Cassandra cluster via unsafe actions to a system resource. Operators granting data MODIFY permission on all keyspaces on af…

📅 Published: Feb. 4, 2025, 9:37 a.m. 🔄 Last Modified: July 14, 2025, 12:44 p.m.

6.5

CVSS3.1

CVE-2024-13529 - SocialV - Social Network and Community BuddyPress Theme <= 2.0.15 - Missing Authorization to Arbitr…

The SocialV - Social Network and Community BuddyPress Theme theme for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'socialv_send_download_file' function in all versions up to, and including, 2.0.15. This makes it possible for authenticated attacker…

📅 Published: Feb. 4, 2025, 9:21 a.m. 🔄 Last Modified: April 8, 2026, 5:23 p.m.

6.1

CVSS3.1

CVE-2024-13510 - ShopSite <= 1.5.10 - Cross-Site Request Forgery to Stored Cross-Site Scripting

The ShopSite plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.5.10. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to update settings and inject malicious web scripts vi…

📅 Published: Feb. 4, 2025, 9:21 a.m. 🔄 Last Modified: April 8, 2026, 5:20 p.m.

6.4

CVSS3.1

CVE-2024-13733 - SKT Blocks – Gutenberg based Page Builder <= 1.7 - Authenticated (Contributor+) Stored Cross-Site S…

The SKT Blocks – Gutenberg based Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's skt-blocks/post-carousel block in all versions up to, and including, 1.7 due to insufficient input sanitization and output escaping on user supplied attributes. This make…

📅 Published: Feb. 4, 2025, 9:21 a.m. 🔄 Last Modified: April 8, 2026, 7:20 p.m.

6.5

CVSS3.1

CVE-2024-13356 - DSGVO All in one for WP <= 4.6 - Cross-Site Request Forgery to Account Deletion

The DSGVO All in one for WP plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.6. This is due to missing or incorrect nonce validation in the user_remove_form.php file. This makes it possible for unauthenticated attackers to delete admin user ac…

📅 Published: Feb. 4, 2025, 9:21 a.m. 🔄 Last Modified: April 8, 2026, 4:44 p.m.

6.4

CVSS3.1

CVE-2024-13403 - WPForms Lite <= 1.9.3.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via fieldHTML Pa…

The WPForms – Easy Form Builder for WordPress – Contact Forms, Payment Forms, Surveys, & More plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘fieldHTML’ parameter in all versions up to, and including, 1.9.3.1 due to insufficient input sanitization and output escaping. Thi…

📅 Published: Feb. 4, 2025, 8:21 a.m. 🔄 Last Modified: April 8, 2026, 5:09 p.m.

7.2

CVSS3.1

CVE-2024-10239 - fld->used_bytes without sanity check causes stack overflow

A security issue in the firmware image verification implementation at Supermicro MBD-X12DPG-OA6 . An attacker with administrator privileges can upload a specially crafted image, which can cause a stack overflow due to the unchecked fat->fsd.max_fld.

📅 Published: Feb. 4, 2025, 8:02 a.m. 🔄 Last Modified: Feb. 4, 2025, 2:25 p.m.
Total resulsts: 344032
Page 6341 of 34,404
« previous page » next page
Filters