7.3

CVSS3.1

CVE-2024-11740 - Download Manager <= 3.3.03 - Unauthenticated Arbitrary Shortcode Execution

The The Download Manager plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 3.3.03. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for …

πŸ“… Published: Dec. 19, 2024, 5:24 a.m. πŸ”„ Last Modified: April 8, 2026, 4:50 p.m.

9.4

CVSS4.0

CVE-2024-11984 - SUNNET Corporate Training Management System - Unrestricted Upload of File with Dangerous Type

A unrestricted upload of file with dangerous type vulnerability in epaper draft function in Corporate Training Management System before 10.13 allows remote authenticated users to bypass file upload restrictions and perform arbitrary system commands with SYSTEM privilege via a crafted ZIP file.

πŸ“… Published: Dec. 19, 2024, 4:01 a.m. πŸ”„ Last Modified: Dec. 20, 2024, 6:15 p.m.

5.4

CVSS3.1

CVE-2024-12121 - Broken Link Checker | Finder <= 2.5.0 - Authenticated (Author+) Blind Server-Side Request Forgery

The Broken Link Checker | Finder plugin for WordPress is vulnerable to Blind Server-Side Request Forgery in all versions up to, and including, 2.5.0 via the 'moblc_check_link' function. This makes it possible for authenticated attackers, with Author-level access and above, to make web requests to a…

πŸ“… Published: Dec. 19, 2024, 1:45 a.m. πŸ”„ Last Modified: April 8, 2026, 5:34 p.m.

6.5

CVSS3.1

CVE-2024-10548 - WP Project Manager <= 2.6.15 - Authenticated (Subscriber+) Sensitive Information Exposure via Proje…

The WP Project Manager plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.6.15 via the Project Task List ('/wp-json/pm/v2/projects/1/task-lists') REST API endpoint. This makes it possible for authenticated attackers, with Subscriber-level ac…

πŸ“… Published: Dec. 19, 2024, 1:45 a.m. πŸ”„ Last Modified: April 8, 2026, 5:12 p.m.

7.1

CVSS3.1

CVE-2024-51532 -

Dell PowerStore contains an Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to modification of arbitrary system files.

πŸ“… Published: Dec. 19, 2024, 1:40 a.m. πŸ”„ Last Modified: Jan. 29, 2025, 9:06 p.m.

7.8

CVSS3.1

CVE-2022-27595 - QVPN Device Client

An insecure library loading vulnerability has been reported to affect QVPN Device Client. If exploited, the vulnerability could allow local attackers who have gained user access to execute unauthorized code or commands. We have already fixed the vulnerability in the following versions: QVPN Window…

πŸ“… Published: Dec. 19, 2024, 1:39 a.m. πŸ”„ Last Modified: Dec. 8, 2025, 6:48 p.m.

6.8

CVSS3.1

CVE-2022-27600 - QTS, QuTS hero, QuTScloud

An uncontrolled resource consumption vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers to launch a denial-of-service (DoS) attack. We have already fixed the vulnerability in the following versions: QTS 5.0…

πŸ“… Published: Dec. 19, 2024, 1:39 a.m. πŸ”„ Last Modified: Dec. 8, 2025, 6:46 p.m.

7.3

CVSS3.1

CVE-2023-23354 - QuLog Center

A cross-site scripting (XSS) vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have gained user access to bypass security mechanisms or read application data. We have already fixed the vulnerability in…

πŸ“… Published: Dec. 19, 2024, 1:39 a.m. πŸ”„ Last Modified: Jan. 20, 2026, 9:59 p.m.

5.5

CVSS3.1

CVE-2023-23356 - QuFirewall

A command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have gained administrator access to execute arbitrary commands. We have already fixed the vulnerability in the following versions: …

πŸ“… Published: Dec. 19, 2024, 1:39 a.m. πŸ”„ Last Modified: Sept. 24, 2025, 7:35 p.m.

4.8

CVSS3.1

CVE-2023-23357 - QuLog Center

A cross-site scripting (XSS) vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have gained administrator access to bypass security mechanisms or read application data. We have already fixed the vulnera…

πŸ“… Published: Dec. 19, 2024, 1:39 a.m. πŸ”„ Last Modified: Jan. 20, 2026, 9:56 p.m.
Total resulsts: 344064
Page 6902 of 34,407
Β« previous page Β» next page
Filters