3.8

CVSS3.1

CVE-2024-5030 - CM Table Of Contents – WordPress TOC Plugin < 1.2.3 - Settings Reset via CSRF

The CM Table Of Contents WordPress plugin before 1.2.3 does not have CSRF check in place when resetting its settings, which could allow attackers to make a logged in admin perform such action via a CSRF attack

πŸ“… Published: Nov. 18, 2024, 6 a.m. πŸ”„ Last Modified: May 15, 2025, 6:02 p.m.

6.2

CVSS3.1

CVE-2024-11308 - TRCore DVC - Use of Hard-coded Cryptographic Key

The DVC from TRCore encrypts files using a hardcoded key. Attackers can use this key to decrypt the files and restore the original content.

πŸ“… Published: Nov. 18, 2024, 5:59 a.m. πŸ”„ Last Modified: Nov. 20, 2024, 3:17 p.m.

8.4

CVSS3.1

CVE-2024-43704 - GPU DDK - PowerVR: PVRSRVAcquireProcessHandleBase can cause psProcessHandleBase reuse when PIDs are…

Software installed and run as a non-privileged user may conduct improper GPU system calls to gain access to the graphics buffers of a parent process.

πŸ“… Published: Nov. 18, 2024, 4:54 a.m. πŸ”„ Last Modified: Nov. 18, 2024, 5:11 p.m.

5.3

CVSS3.1

CVE-2024-38828 - CVE-2024-38828: DoS via Spring MVC controller method with byte[] parameter

Spring MVC controller methods with an @RequestBody byte[]Β method parameter are vulnerable to a DoS attack.

πŸ“… Published: Nov. 18, 2024, 3:45 a.m. πŸ”„ Last Modified: May 9, 2025, 8:15 p.m.

6.9

CVSS4.0

CVE-2024-11306 - Altenergy Power Control Software database improper authorization

A vulnerability, which was classified as critical, has been found in Altenergy Power Control Software up to 20241108. This issue affects some unknown processing of the file /index.php/display/database/. The manipulation leads to improper authorization. The attack may be initiated remotely. The expl…

πŸ“… Published: Nov. 18, 2024, 1:31 a.m. πŸ”„ Last Modified: Nov. 19, 2024, 4:28 p.m.

5.3

CVSS4.0

CVE-2024-11305 - Altenergy Power Control Software status_zigbee get_status_zigbee sql injection

A vulnerability classified as critical was found in Altenergy Power Control Software up to 20241108. This vulnerability affects the function get_status_zigbee of the file /index.php/display/status_zigbee. The manipulation of the argument date leads to sql injection. The attack can be initiated remo…

πŸ“… Published: Nov. 18, 2024, 12:31 a.m. πŸ”„ Last Modified: Nov. 19, 2024, 4:27 p.m.

5.4

CVSS3.1

CVE-2024-52941 -

An issue was discovered in Veritas Enterprise Vault before 15.1 UPD882911, ZDI-CAN-24695. It allows an authenticated remote attacker to inject a parameter into an HTTP request, allowing for Cross-Site Scripting (XSS) while viewing archived content. This could reflect back to an authenticated user w…

πŸ“… Published: Nov. 18, 2024, midnight πŸ”„ Last Modified: July 26, 2025, 4:47 p.m.

6.5

CVSS3.1

CVE-2024-52919 -

Bitcoin Core before 22.0 has a CAddrMan nIdCount integer overflow and resultant assertion failure (and daemon exit) via a flood of addr messages.

πŸ“… Published: Nov. 18, 2024, midnight πŸ”„ Last Modified: April 30, 2025, 4:17 p.m.

7.5

CVSS3.1

CVE-2019-25220 -

Bitcoin Core before 24.0.1 allows remote attackers to cause a denial of service (daemon crash) via a flood of low-difficulty header chains (aka a "Chain Width Expansion" attack) because a node does not first verify that a presented chain has enough work before committing to store it.

πŸ“… Published: Nov. 18, 2024, midnight πŸ”„ Last Modified: May 22, 2025, 4:56 p.m.

5.5

CVSS3.1

CVE-2024-48294 -

A NULL pointer dereference in the component libPdfCore.dll of Wondershare PDF Reader v1.0.9.2544 allows attackers to cause a Denial of Service (DoS) via a crafted PDF file.

πŸ“… Published: Nov. 18, 2024, midnight πŸ”„ Last Modified: Nov. 19, 2024, 9:57 p.m.
Total resulsts: 344009
Page 7322 of 34,401
Β« previous page Β» next page
Filters