4.9

CVSS3.1

CVE-2024-9678 -

An SQL Injection vulnerability existed in DLP Extension 11.11.1.3. The vulnerability allowed an attacker to perform arbitrary SQL queries potentially leading to command execution.

πŸ“… Published: Dec. 16, 2024, 6:31 a.m. πŸ”„ Last Modified: Dec. 16, 2024, 4:32 p.m.

8.1

CVSS3.1

CVE-2024-12642 - Chunghwa Telecom TenderDocTransfer - Arbitrary File Write

TenderDocTransfer from Chunghwa Telecom has an Arbitrary File Write vulnerability. The application sets up a simple local web server and provides APIs for communication with the target website. Due to the lack of CSRF protection for the APIs, unauthenticated remote attackers could use these APIs th…

πŸ“… Published: Dec. 16, 2024, 6:30 a.m. πŸ”„ Last Modified: Dec. 23, 2025, 7:53 p.m.

9.6

CVSS3.1

CVE-2024-12641 - Chunghwa Telecom TenderDocTransfer - Reflected Cross-site Scripting to RCE

TenderDocTransfer from Chunghwa Telecom has a Reflected Cross-site scripting vulnerability. The application sets up a simple local web server and provides APIs for communication with the target website. Due to the lack of CSRF protection for the APIs, unauthenticated remote attackers could use spec…

πŸ“… Published: Dec. 16, 2024, 6:14 a.m. πŸ”„ Last Modified: Dec. 23, 2025, 7:54 p.m.

5.3

CVSS3.1

CVE-2024-5333 - The Events Calendar < 6.8.2.1 - Unauthenticated Password Protected Event Disclosure

The Events Calendar WordPress plugin before 6.8.2.1 is missing access checks in the REST API, allowing for unauthenticated users to access information about password protected events.

πŸ“… Published: Dec. 16, 2024, 6 a.m. πŸ”„ Last Modified: Aug. 27, 2025, noon

5.4

CVSS3.1

CVE-2024-11841 - Tithe.ly Giving Button <= 1.1 - Contributor+ Stored XSS via Shortcode

The Tithe.ly Giving Button WordPress plugin through 1.1 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

πŸ“… Published: Dec. 16, 2024, 6 a.m. πŸ”„ Last Modified: May 17, 2025, 2:19 a.m.

5.3

CVSS3.1

CVE-2024-8116 - Incorrect Authorization in GitLab

An issue has been discovered in GitLab CE/EE affecting all versions from 16.9 before 17.4.6, 17.5 before 17.5.4, and 17.6 before 17.6.2. By using a specific GraphQL query, under specific conditions an unauthorized user can retrieve branch names.

πŸ“… Published: Dec. 16, 2024, 4:31 a.m. πŸ”„ Last Modified: July 11, 2025, 8:34 p.m.

5.3

CVSS3.1

CVE-2024-8650 - Incorrect Authorization in GitLab

An issue was discovered in GitLab CE/EE affecting all versions from 15.0 prior to 17.4.6, 17.5 prior to 17.5.4, and 17.6 prior to 17.6.2 that allowed non-member users to view unresolved threads marked as internal notes in public projects merge requests.

πŸ“… Published: Dec. 16, 2024, 4:30 a.m. πŸ”„ Last Modified: July 11, 2025, 8:34 p.m.

7.5

CVSS3.1

CVE-2024-52949 - iptraf-ng: buffer overflow via ifaces.c

iptraf-ng 1.2.1 has a stack-based buffer overflow. In src/ifaces.c, the strcpy function consistently fails to control the size, and it is consequently possible to overflow memory on the stack.

πŸ“… Published: Dec. 16, 2024, midnight πŸ”„ Last Modified: Oct. 14, 2025, 5:29 p.m.

5.9

CVSS3.1

CVE-2024-56085 -

An issue was discovered in Logpoint before 7.5.0. Authenticated users can inject payloads while creating Search Template Dashboard. These are executed, leading to Server-Side Template Injection.

πŸ“… Published: Dec. 16, 2024, midnight πŸ”„ Last Modified: April 17, 2025, 1:48 a.m.

7.1

CVSS3.1

CVE-2024-56084 -

An issue was discovered in Logpoint UniversalNormalizer before 5.7.0. Authenticated users can inject payloads while creating Universal Normalizer. These are executed, leading to Remote Code Execution.

πŸ“… Published: Dec. 16, 2024, midnight πŸ”„ Last Modified: June 20, 2025, 6:47 p.m.
Total resulsts: 343921
Page 6932 of 34,393
Β« previous page Β» next page
Filters