7.5

CVSS3.1

CVE-2024-11322 - CyberPower PowerPanel Business Unauthenticated Restart DoS

A denial-of-service vulnerability exists in CyberPower PowerPanel Business (PPB) 4.11.0. An unauthenticated remote attacker can restart the ppbd.exe process via the PowerPanel Business Service Watchdog service listening on TCP port 2003. The attacker can repeatedly restart ppbd.exe to render it unโ€ฆ

๐Ÿ“… Published: Jan. 15, 2025, 2:03 p.m. ๐Ÿ”„ Last Modified: Jan. 15, 2025, 2:27 p.m.

3.3

CVSS3.1

CVE-2024-5198 -

OpenVPN ovpn-dco for Windows version 1.1.1 allows an unprivileged local attacker to send I/O control messages with invalid data to the driver resulting in a NULL pointer dereference leading to a system halt.

๐Ÿ“… Published: Jan. 15, 2025, 12:57 p.m. ๐Ÿ”„ Last Modified: June 10, 2025, 4:12 p.m.

4.3

CVSS3.1

CVE-2024-13215 - Elementor Addon Elements <= 1.13.10 - Authenticated (Contributor+) Sensitive Information Exposure vโ€ฆ

The Elementor Addon Elements plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.13.10 via the 'render' function in modules/modal-popup/widgets/modal-popup.php. This makes it possible for authenticated attackers, with Contributor-level accessโ€ฆ

๐Ÿ“… Published: Jan. 15, 2025, 12:44 p.m. ๐Ÿ”„ Last Modified: April 8, 2026, 4:52 p.m.

7.1

CVSS3.1

CVE-2025-5791 - Users: `root` appended to group listings

A flaw was found in the user's crate for Rust. This vulnerability allows privilege escalation via incorrect group listing when a user or process has fewer than exactly 1024 groups, leading to the erroneous inclusion of the root group in the access list.

๐Ÿ“… Published: Jan. 15, 2025, noon ๐Ÿ”„ Last Modified: Nov. 20, 2025, 7:41 a.m.

5.5

CVSS3.1

CVE-2024-11029 - Freeipa: administrative user data leaked through systemd journal

A flaw was found in the FreeIPA API audit, where it sends the whole FreeIPA command line to journalctl. As a consequence, during the FreeIPA installation process, it inadvertently leaks the administrative user credentials, including the administrator password, to the journal database. In the worst-โ€ฆ

๐Ÿ“… Published: Jan. 15, 2025, noon ๐Ÿ”„ Last Modified: Nov. 20, 2025, 6:21 p.m.

4.3

CVSS3.1

CVE-2024-11851 - NitroPack <= 1.17.0 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Transient Updaโ€ฆ

The NitroPack plugin for WordPress is vulnerable to unauthorized arbitrary transient update due to a missing capability check on the nitropack_rml_notification function in all versions up to, and including, 1.17.0. This makes it possible for authenticated attackers, with subscriber access or higherโ€ฆ

๐Ÿ“… Published: Jan. 15, 2025, 11:29 a.m. ๐Ÿ”„ Last Modified: April 8, 2026, 5:05 p.m.

6.4

CVSS3.1

CVE-2024-12593 - PDF for WPForms + Drag and Drop Template Builder <= 4.6.0 - Authenticated (Contributor+) Stored Croโ€ฆ

The PDF for WPForms + Drag and Drop Template Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's yeepdf_dotab shortcode in all versions up to, and including, 4.6.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makโ€ฆ

๐Ÿ“… Published: Jan. 15, 2025, 11:24 a.m. ๐Ÿ”„ Last Modified: April 8, 2026, 5:03 p.m.

8.1

CVSS3.1

CVE-2024-11848 - NitroPack <= 1.17.0 - Missing Authorization to Authenticated (Subscriber+) Limited Options Update

The NitroPack plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'nitropack_dismiss_notice_forever' AJAX action in all versions up to, and including, 1.17.0. This makes it possible for authenticated attackers, with subscriber-level accesโ€ฆ

๐Ÿ“… Published: Jan. 15, 2025, 11:24 a.m. ๐Ÿ”„ Last Modified: April 8, 2026, 4:40 p.m.

5.2

CVSS4.0

CVE-2025-0193 - Stored Cross-site Scripting (XSS) Vulnerability in the MGate 5121/5122/5123 Series

A stored Cross-site Scripting (XSS) vulnerability exists in the MGate 5121/5122/5123 Series firmware version v1.0 because of insufficient sanitization and encoding of user input in the "Login Message" functionality. An authenticated attacker with administrative access can exploit this vulnerabilityโ€ฆ

๐Ÿ“… Published: Jan. 15, 2025, 11:05 a.m. ๐Ÿ”„ Last Modified: Jan. 15, 2025, 2:35 p.m.

4.3

CVSS3.1

CVE-2025-0448 -

Inappropriate implementation in Compositing in Google Chrome prior to 132.0.6834.83 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)

๐Ÿ“… Published: Jan. 15, 2025, 10:58 a.m. ๐Ÿ”„ Last Modified: April 21, 2025, 8:53 p.m.
Total resulsts: 344058
Page 6592 of 34,406
ยซ previous page ยป next page
Filters