6.5

CVSS3.1

CVE-2024-11430 - SQL Chart Builder <= 2.3.6 - Authenticated (Contributor+) SQL Injection

The SQL Chart Builder plugin for WordPress is vulnerable to SQL Injection via the 'arg1' arg of the 'gvn_schart_2' shortcode in all versions up to, and including, 2.3.6 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This ma…

πŸ“… Published: Dec. 12, 2024, 3:23 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

4.3

CVSS3.1

CVE-2024-12341 - Custom Skins Contact Form 7 <= 1.0 - Missing Authorization to Authenticated (Subscriber+) Arbitrary…

The Custom Skins Contact Form 7 plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'cf7cs_action_callback' function in all versions up to, and including, 1.0. This makes it possible for authenticated attackers, with Subscriber-level acce…

πŸ“… Published: Dec. 12, 2024, 3:23 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.4

CVSS3.1

CVE-2024-11442 - Horizontal scroll image slideshow <= 10.1 - Authenticated (Contributor+) Stored Cross-Site Scripting

The Horizontal scroll image slideshow plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'horizontal-scroll-image-slideshow' shortcode in all versions up to, and including, 10.1 due to insufficient input sanitization and output escaping on user supplied attributes. T…

πŸ“… Published: Dec. 12, 2024, 3:23 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.5

CVSS3.1

CVE-2024-42407 -

Insertion of Sensitive Information into Log File (CWE-532) in the Gallagher Command Centre Alarm Transmitter feature could allow an authenticated Operator to view some security sensitive information to which they have not been granted access. This issue affects: Command Centre Server 9.10 prior t…

πŸ“… Published: Dec. 12, 2024, 1:36 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

4.6

CVSS3.1

CVE-2024-41146 -

Use of Multiple Resources with Duplicate Identifier (CWE-694) in the Controller 6000 and Controller 7000 Platforms could allow an attacker with physical access to HBUS communication cabling to perform a Denial-of-Service attack against HBUS connected devices, require a device reboot to resolve. T…

πŸ“… Published: Dec. 12, 2024, 1:35 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS4.0

CVE-2024-12536 - SourceCodester Kortex Lite Advocate Office Management System client_data.php cross site scripting

A vulnerability, which was classified as problematic, has been found in SourceCodester Kortex Lite Advocate Office Management System 1.0. Affected by this issue is some unknown functionality of the file /control/client_data.php. The manipulation of the argument id leads to cross site scripting. The…

πŸ“… Published: Dec. 12, 2024, 1 a.m. πŸ”„ Last Modified: Dec. 13, 2024, 5:14 p.m.

5.1

CVSS4.0

CVE-2024-12503 - ClassCMS Model Management Page admin cross site scripting

A vulnerability classified as problematic was found in ClassCMS 4.8. Affected by this vulnerability is an unknown functionality of the file /index.php/admin of the component Model Management Page. The manipulation of the argument URL leads to cross site scripting. The attack can be launched remotel…

πŸ“… Published: Dec. 12, 2024, midnight πŸ”„ Last Modified: Dec. 13, 2024, 5:13 p.m.

9.8

CVSS3.1

CVE-2024-54842 -

A SQL injection vulnerability was found in phpgurukul Online Nurse Hiring System v1.0 in /admin/password-recovery.php via the mobileno parameter.

πŸ“… Published: Dec. 12, 2024, midnight πŸ”„ Last Modified: April 3, 2025, 4:32 p.m.

9.8

CVSS3.1

CVE-2024-54810 -

A SQL Injection vulnerability was found in /preschool/admin/password-recovery.php in PHPGurukul Pre-School Enrollment System Project v1.0, which allows remote attackers to execute arbitrary code via the mobileno parameter.

πŸ“… Published: Dec. 12, 2024, midnight πŸ”„ Last Modified: April 3, 2025, 4:31 p.m.

6.3

CVSS3.1

CVE-2024-31670 -

rizin before v0.6.3 is vulnerable to Buffer Overflow via create_cache_bins, read_cache_accel, and rz_dyldcache_new_buf functions in librz/bin/format/mach0/dyldcache.c.

πŸ“… Published: Dec. 12, 2024, midnight πŸ”„ Last Modified: July 2, 2025, 8:05 p.m.
Total resulsts: 346560
Page 7248 of 34,656
Β« previous page Β» next page
Filters