9.6

CVSS3.1

CVE-2024-12626 - AutomatorWP <= 5.0.9 - Reflected Cross-Site Scripting via a-0-o-search_field_value

The AutomatorWP – Automator plugin for no-code automations, webhooks & custom integrations in WordPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘a-0-o-search_field_value’ parameter in all versions up to, and including, 5.0.9 due to insufficient input sanitizatio…

📅 Published: Dec. 19, 2024, 11:14 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

4.3

CVSS3.1

CVE-2024-12331 - File Manager Pro – Filester <= 1.8.6 - Missing Authorization to Authenticated (Subscriber+) Filebir…

The File Manager Pro – Filester plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'ajax_install_plugin' function in all versions up to, and including, 1.8.6. This makes it possible for authenticated attackers, with Subscriber-level acce…

📅 Published: Dec. 19, 2024, 11:14 a.m. 🔄 Last Modified: April 8, 2026, 4:55 p.m.

7.6

CVSS3.1

CVE-2021-26115 -

An OS command injection (CWE-78) vulnerability in FortiWAN version 4.5.7 and below Command Line Interface may allow a local, authenticated and unprivileged attacker to escalate their privileges to root via executing a specially-crafted command.An OS command injection (CWE-78) vulnerability in Forti…

📅 Published: Dec. 19, 2024, 10:57 a.m. 🔄 Last Modified: Jan. 21, 2025, 8:30 p.m.

8.6

CVSS3.1

CVE-2020-15934 -

An execution with unnecessary privileges vulnerability in the VCM engine of FortiClient for Linux versions 6.2.7 and below, version 6.4.0. may allow local users to elevate their privileges to root by creating a malicious script or program on the target machine.

📅 Published: Dec. 19, 2024, 10:57 a.m. 🔄 Last Modified: Jan. 21, 2025, 8:38 p.m.

5.4

CVSS3.1

CVE-2020-12820 -

Under non-default configuration, a stack-based buffer overflow in FortiOS version 6.0.10 and below, version 5.6.12 and below may allow a remote attacker authenticated to the SSL VPN to crash the FortiClient NAC daemon (fcnacd) and potentially execute arbitrary code via requesting a large FortiClien…

📅 Published: Dec. 19, 2024, 10:57 a.m. 🔄 Last Modified: Jan. 21, 2025, 8:42 p.m.

5.6

CVSS4.0

CVE-2024-11616 - Double-fetch heap overflow

Netskope was made aware of a security vulnerability in Netskope Endpoint DLP’s Content Control Driver where a double-fetch issue leads to heap overflow. The vulnerability arises from the fact that the NumberOfBytes argument to ExAllocatePoolWithTag, and the Length argument for RtlCopyMemory, both i…

📅 Published: Dec. 19, 2024, 9:46 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

10

CVSS3.1

CVE-2023-4617 - Gaining remote control over Govee devices

Incorrect authorization vulnerability in HTTP POST method in Govee Home application on Android and iOS allows remote attacker to control devices owned by other users via changing "device", "sku" and "type" fields' values.  This issue affects Govee Home applications on Android and iOS in versions be…

📅 Published: Dec. 19, 2024, 9:39 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

5.2

CVSS4.0

CVE-2024-12569 - Sensitive Information in Driver’s Log File

Disclosure of sensitive information in a Milestone XProtect Device Pack driver’s log file for third-party cameras, allows an attacker to read camera credentials stored in the Recording Server under specific conditions.

📅 Published: Dec. 19, 2024, 8:41 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

6.6

CVSS3.1

CVE-2021-26093 -

An access of uninitialized pointer (CWE-824) vulnerability in FortiWLC versions 8.6.0, 8.5.3 and earlier may allow a local and authenticated attacker to crash the access point being managed by the controller by executing a crafted CLI command.

📅 Published: Dec. 19, 2024, 7:47 a.m. 🔄 Last Modified: Jan. 21, 2025, 8:44 p.m.

5.4

CVSS3.1

CVE-2020-12819 -

A heap-based buffer overflow vulnerability in the processing of Link Control Protocol messages in FortiGate versions 5.6.12, 6.0.10, 6.2.4 and 6.4.1 and earlier may allow a remote attacker with valid SSL VPN credentials to crash the SSL VPN daemon by sending a large LCP packet, when tunnel mode is …

📅 Published: Dec. 19, 2024, 7:40 a.m. 🔄 Last Modified: Jan. 21, 2025, 8:58 p.m.
Total resulsts: 347679
Page 7262 of 34,768
« previous page » next page
Filters