8.5

CVSS4.0

CVE-2024-54126 - Insufficient Integrity Verification Vulnerability in TP-Link Archer C50

This vulnerability exists in the TP-Link Archer C50 due to improper signature verification mechanism in the firmware upgrade process at its web interface. An attacker with administrative privileges within the router’s Wi-Fi range could exploit this vulnerability by uploading and executing malicious…

📅 Published: Dec. 5, 2024, 12:14 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

8.2

CVSS4.0

CVE-2024-52270 - PDF Document Spoofing in DropBox Sign(HelloSign)

User Interface (UI) Misrepresentation of Critical Information vulnerability in DropBox Sign(HelloSign) allows Content Spoofing. Displayed version does not show the layer flattened version, once download, If printed (e.g. via Google Chrome -> Examine the print preview): Will render the vulnerability…

📅 Published: Dec. 5, 2024, 10:55 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

8.3

CVSS3.1

CVE-2022-41137 - Apache Hive: Deserialization of untrusted data when fetching partitions from the Metastore

Apache Hive Metastore (HMS) uses SerializationUtilities#deserializeObjectWithTypeInformation method when filtering and fetching partitions that is unsafe and can lead to Remote Code Execution (RCE) since it allows the deserialization of arbitrary data. In real deployments, the vulnerability can be…

📅 Published: Dec. 5, 2024, 10:01 a.m. 🔄 Last Modified: July 15, 2025, 4:34 p.m.

7.5

CVSS3.0

CVE-2024-52564 -

Inclusion of undocumented features or chicken bits issue exists in UD-LT1 firmware Ver.2.1.8 and earlier and UD-LT1/EX firmware Ver.2.1.8 and earlier. A remote attacker may disable the firewall function of the affected products. As a result, an arbitrary OS command may be executed and/or configurat…

📅 Published: Dec. 5, 2024, 9:41 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

7.2

CVSS3.0

CVE-2024-47133 -

UD-LT1 firmware Ver.2.1.9 and earlier and UD-LT1/EX firmware Ver.2.1.9 and earlier allow a remote authenticated attacker with an administrative account to execute arbitrary OS commands.

📅 Published: Dec. 5, 2024, 9:40 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

6.5

CVSS3.0

CVE-2024-45841 -

Incorrect permission assignment for critical resource issue exists in UD-LT1 firmware Ver.2.1.9 and earlier and UD-LT1/EX firmware Ver.2.1.9 and earlier. If an attacker with the guest account of the affected products accesses a specific file, the information containing credentials may be obtained.

📅 Published: Dec. 5, 2024, 9:39 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

6.1

CVSS3.1

CVE-2024-11324 - Accounting for WooCommerce <= 1.6.6 - Reflected Cross-Site Scripting

The Accounting for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 1.6.6. This makes it possible for unauthenticated attackers to inject arbitrary web scrip…

📅 Published: Dec. 5, 2024, 9:23 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

4.3

CVSS3.1

CVE-2024-10777 - AnyWhere Elementor <= 1.2.11 - Authenticated (Contributor+) Post Disclosure

The AnyWhere Elementor plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.2.11 via the 'INSERT_ELEMENTOR' shortcode due to insufficient restrictions on which posts can be included. This makes it possible for authenticated attackers, with Contributor-l…

📅 Published: Dec. 5, 2024, 9:23 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

6.4

CVSS3.1

CVE-2024-10056 - Contact Form Builder <= 4.10.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via lives…

The Contact Form Builder by vcita plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's livesite-pay shortcode in all versions up to, and including, 4.10.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for…

📅 Published: Dec. 5, 2024, 9:23 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

6.4

CVSS3.1

CVE-2024-11779 - WIP WooCarousel Lite <= 1.1.6 - Authenticated (Contributor+) Stored Cross-Site Scripting

The WIP WooCarousel Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wip_woocarousel_products_carousel' shortcode in all versions up to, and including, 1.1.6 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it…

📅 Published: Dec. 5, 2024, 9:23 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 346099
Page 7309 of 34,610
« previous page » next page
Filters