4.3

CVSS3.1

CVE-2024-10356 - ElementsReady Addons for Elementor <= 6.4.8 - Authenticated (Contributor+) Sensitive Information Ex…

The ElementsReady Addons for Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 6.4.8 in inc/Widgets/accordion/output/content.php. This makes it possible for authenticated attackers, with Contributor-level access and above, to extrac…

πŸ“… Published: Dec. 17, 2024, 12:43 p.m. πŸ”„ Last Modified: April 8, 2026, 5:15 p.m.

5.3

CVSS3.1

CVE-2024-54677 - Apache Tomcat: DoS in examples web application

Uncontrolled Resource Consumption vulnerability in the examples web application provided with Apache Tomcat leads to denial of service. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.1, from 10.1.0-M1 through 10.1.33, from 9.0.0.M1 through 9.9.97. The following versions were EOL at …

πŸ“… Published: Dec. 17, 2024, 12:35 p.m. πŸ”„ Last Modified: Nov. 3, 2025, 8:16 p.m.

9.8

CVSS3.1

CVE-2024-50379 - Apache Tomcat: RCE due to TOCTOU issue in JSP compilation

Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability during JSP compilation in Apache Tomcat permits an RCE on case insensitive file systems when the default servlet is enabled for write (non-default configuration). This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.1, from 1…

πŸ“… Published: Dec. 17, 2024, 12:34 p.m. πŸ”„ Last Modified: Nov. 3, 2025, 9:17 p.m.

5.7

CVSS3.1

CVE-2024-53240 - xen/netfront: fix crash when removing device

In the Linux kernel, the following vulnerability has been resolved: xen/netfront: fix crash when removing device When removing a netfront device directly after a suspend/resume cycle it might happen that the queues have not been setup again, causing a crash during the attempt to stop the queues a…

πŸ“… Published: Dec. 17, 2024, noon πŸ”„ Last Modified: Nov. 3, 2025, 9:17 p.m.

5.5

CVSS3.1

CVE-2024-53241 - x86/xen: don't do PV iret hypercall through hypercall page

In the Linux kernel, the following vulnerability has been resolved: x86/xen: don't do PV iret hypercall through hypercall page Instead of jumping to the Xen hypercall page for doing the iret hypercall, directly code the required sequence in xen-asm.S. This is done in preparation of no longer usi…

πŸ“… Published: Dec. 17, 2024, noon πŸ”„ Last Modified: Jan. 5, 2026, 10:55 a.m.

6.5

CVSS3.1

CVE-2024-8475 - Protection Mechanism Failure in Digital Operation Services' WiFiBurada

Authentication Bypass by Assumed-Immutable Data vulnerability in Digital Operation Services WiFiBurada allows Manipulating User-Controlled Variables.This issue affects WiFiBurada: before 1.0.5.

πŸ“… Published: Dec. 17, 2024, 11:42 a.m. πŸ”„ Last Modified: Dec. 17, 2024, 2:33 p.m.

4.3

CVSS3.1

CVE-2024-8429 - Improper Authentication in Digital Operation Services' WiFiBurada

Improper Restriction of Excessive Authentication Attempts vulnerability in Digital Operation Services WiFiBurada allows Use of Known Domain Credentials.This issue affects WiFiBurada: before 1.0.5.

πŸ“… Published: Dec. 17, 2024, 11:34 a.m. πŸ”„ Last Modified: Dec. 17, 2024, 2:31 p.m.

4.4

CVSS3.1

CVE-2024-52542 -

Dell AppSync, version 4.6.0.x, contain a Symbolic Link (Symlink) Following vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to information tampering.

πŸ“… Published: Dec. 17, 2024, 11:33 a.m. πŸ”„ Last Modified: Feb. 4, 2025, 3:56 p.m.

5.3

CVSS3.1

CVE-2024-11280 - PPWP – Password Protect Pages <= 1.9.5 - Unauthenticated Content Restriction Bypass to Sensitive In…

The PPWP – Password Protect Pages plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.9.5 via the WordPress core search feature. This makes it possible for unauthenticated attackers to extract sensitive data from posts that have been restrict…

πŸ“… Published: Dec. 17, 2024, 11:24 a.m. πŸ”„ Last Modified: April 8, 2026, 5:27 p.m.

3.7

CVSS3.1

CVE-2024-9654 - Easy Digital Downloads 3.1 - 3.3.4 - Improper Authorization to Paywall Bypass

The Easy Digital Downloads plugin for WordPress is vulnerable to Improper Authorization in versions 3.1 through 3.3.4. This is due to a lack of sufficient validation checks within the 'verify_guest_email' function to ensure the requesting user is the intended recipient of the purchase receipt. This…

πŸ“… Published: Dec. 17, 2024, 11:10 a.m. πŸ”„ Last Modified: Feb. 7, 2025, 5:08 p.m.
Total resulsts: 343968
Page 6913 of 34,397
Β« previous page Β» next page
Filters