8.8

CVSS3.1

CVE-2024-10074 - Liteos_a has an use after free vulnerability

in OpenHarmony v4.1.1 and prior versions allow a local attacker cause the common permission is upgraded to root through use after free.

๐Ÿ“… Published: Dec. 3, 2024, 12:15 p.m. ๐Ÿ”„ Last Modified: Dec. 11, 2024, 3:51 a.m.

6.1

CVSS3.1

CVE-2024-11326 - Campaign Monitor Forms by Optin Cat <= 2.5.7 - Reflected Cross-Site Scripting

The Campaign Monitor Forms by Optin Cat plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 2.5.7. This makes it possible for unauthenticated attackers to inject arbitrary โ€ฆ

๐Ÿ“… Published: Dec. 3, 2024, 11:04 a.m. ๐Ÿ”„ Last Modified: April 8, 2026, 5:10 p.m.

7.8

CVSS3.1

CVE-2024-47476 -

Dell NetWorker Management Console, version(s) 19.11, contain(s) an Improper Verification of Cryptographic Signature vulnerability. An unauthenticated attacker with local access could potentially exploit this vulnerability, leading to Code execution.

๐Ÿ“… Published: Dec. 3, 2024, 9:59 a.m. ๐Ÿ”„ Last Modified: Feb. 3, 2025, 2:48 p.m.

6.4

CVSS3.1

CVE-2024-11782 - WP Mailster <= 1.8.17.0 - Authenticated (Contributor+) Stored Cross-Site Scripting

The WP Mailster plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'mst_subscribe' shortcode in all versions up to, and including, 1.8.17.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticateโ€ฆ

๐Ÿ“… Published: Dec. 3, 2024, 9:32 a.m. ๐Ÿ”„ Last Modified: April 8, 2026, 5:06 p.m.

4.3

CVSS3.1

CVE-2024-12062 - Charity Addon for Elementor <= 1.3.3 - Authenticated (Contributor+) Post Disclosure

The Charity Addon for Elementor plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.3.3 via the 'nacharity_elementor_template' shortcode due to insufficient restrictions on which posts can be included. This makes it possible for authenticated attackersโ€ฆ

๐Ÿ“… Published: Dec. 3, 2024, 9:32 a.m. ๐Ÿ”„ Last Modified: April 8, 2026, 6:19 p.m.

5.2

CVSS3.1

CVE-2024-11325 - AWeber Forms by Optin Cat <= 2.5.7 - Reflected Cross-Site Scripting

The AWeber Forms by Optin Cat plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 2.5.7. This makes it possible for unauthenticated attackers to inject arbitrary web scriptโ€ฆ

๐Ÿ“… Published: Dec. 3, 2024, 9:32 a.m. ๐Ÿ”„ Last Modified: April 8, 2026, 4:41 p.m.

8.1

CVSS3.1

CVE-2024-45106 - Apache Ozone: Improper authentication when generating S3 secrets

Improper authentication of an HTTP endpoint in the S3 Gateway of Apache Ozone 1.4.0 allows any authenticated Kerberos user to revoke and regenerate the S3 secrets of any other user. This is only possible if: * ozone.s3g.secret.http.enabled is set to true. The default value of this configuration โ€ฆ

๐Ÿ“… Published: Dec. 3, 2024, 9:06 a.m. ๐Ÿ”„ Last Modified: July 1, 2025, 8:29 p.m.

6.4

CVSS3.1

CVE-2024-11866 - BMLT Tabbed Map <= 1.1.8 - Authenticated (Contributor+) Stored Cross-Site Scripting

The BMLT Tabbed Map plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'bmlt_tabbed_map' shortcode in all versions up to, and including, 1.1.8 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticโ€ฆ

๐Ÿ“… Published: Dec. 3, 2024, 8:32 a.m. ๐Ÿ”„ Last Modified: April 8, 2026, 4:50 p.m.

4.3

CVSS3.1

CVE-2024-11844 - IdeaPush <= 8.71 - Missing Authorization to Board Term Deletion

The IdeaPush plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the idea_push_taxonomy_save_routine function in all versions up to, and including, 8.71. This makes it possible for authenticated attackers, with Subscriber-level access and aboโ€ฆ

๐Ÿ“… Published: Dec. 3, 2024, 8:32 a.m. ๐Ÿ”„ Last Modified: April 8, 2026, 4:45 p.m.

6.5

CVSS3.1

CVE-2024-11732 - BP Profile Shortcodes Extra <= 2.6.0 - Authenticated (Contributor+) SQL Injection via tab Parameter

The BP Profile Shortcodes Extra plugin for WordPress is vulnerable to time-based SQL Injection via the โ€˜tabโ€™ parameter in all versions up to, and including, 2.6.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes itโ€ฆ

๐Ÿ“… Published: Dec. 3, 2024, 7:35 a.m. ๐Ÿ”„ Last Modified: April 8, 2026, 5:26 p.m.
Total resulsts: 344670
Page 7188 of 34,467
ยซ previous page ยป next page
Filters