8.1

CVSS3.1

CVE-2024-11601 - Sky Addons for Elementor (Free Templates Library, Live Copy, Animations, Post Grid, Post Carousel, …

The Sky Addons for Elementor (Free Templates Library, Live Copy, Animations, Post Grid, Post Carousel, Particles, Sliders, Chart, Blog, Video Gallery) plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.6.1. This is due to missing or incorrect no…

πŸ“… Published: Nov. 22, 2024, 5:33 a.m. πŸ”„ Last Modified: April 8, 2026, 4:55 p.m.

4.3

CVSS3.1

CVE-2024-11355 - Ultimate YouTube Video & Shorts Player With Vimeo <= 3.3 - Missing Authorization to Authenticated (…

The Ultimate YouTube Video & Shorts Player With Vimeo plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the get_setting() function in all versions up to, and including, 3.3. This makes it possible for authenticated attackers, with Subscriber-leve…

πŸ“… Published: Nov. 22, 2024, 5:33 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.1

CVSS3.1

CVE-2024-11104 - Sky Addons for Elementor (Free Templates Library, Live Copy, Animations, Post Grid, Post Carousel, …

The Sky Addons for Elementor (Free Templates Library, Live Copy, Animations, Post Grid, Post Carousel, Particles, Sliders, Chart, Blogs) plugin for WordPress is vulnerable to unauthorized modification of data that can lead to a denial of service due to a missing capability check on the save_options…

πŸ“… Published: Nov. 22, 2024, 5:33 a.m. πŸ”„ Last Modified: April 8, 2026, 4:43 p.m.

6.4

CVSS3.1

CVE-2024-11381 - Control horas <= 1.0.1 - Authenticated (Contributor+) Stored Cross-Site Scripting

The Control horas plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'ch_registro' shortcode in all versions up to, and including, 1.0.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated a…

πŸ“… Published: Nov. 22, 2024, 5:33 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.7

CVSS3.1

CVE-2024-38296 -

Dell Edge Gateway 3200, versions prior to 15.40.30.2879, and Edge Gateway 5200, versions prior to 12.0.94.2380, contain an Exposure of Sensitive Information in Shared Microarchitectural Structures during Transient Execution vulnerability. A high privileged attacker with local access could potential…

πŸ“… Published: Nov. 22, 2024, 2:58 a.m. πŸ”„ Last Modified: Feb. 4, 2025, 4:05 p.m.

5.5

CVSS3.0

CVE-2024-47142 -

AIPHONE IXG SYSTEM IXG-2C7 firmware Ver.2.03 and earlier and IXG-2C7-L firmware Ver.2.03 and earlier contain an issue with insufficiently protected credentials, which may allow a network-adjacent authenticated attacker to perform unintended operations.

πŸ“… Published: Nov. 22, 2024, 12:14 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.4

CVSS3.0

CVE-2024-45837 -

Use of hard-coded cryptographic key issue exists in AIPHONE IX SYSTEM, IXG SYSTEM, and System Support Software. A network-adjacent unauthenticated attacker may log in to SFTP service and obtain and/or manipulate unauthorized files.

πŸ“… Published: Nov. 22, 2024, 12:13 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.5

CVSS3.0

CVE-2024-39290 -

Insufficiently protected credentials issue exists in AIPHONE IX SYSTEM and IXG SYSTEM. A network-adjacent unauthenticated attacker may obtain sensitive information such as a username and its password in the address book.

πŸ“… Published: Nov. 22, 2024, 12:11 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8

CVSS3.0

CVE-2024-31408 -

OS command injection vulnerability exists in AIPHONE IX SYSTEM and IXG SYSTEM. A network-adjacent authenticated attacker may execute an arbitrary OS command with root privileges by sending a specially crafted request.

πŸ“… Published: Nov. 22, 2024, 12:10 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.7

CVSS3.1

CVE-2024-51073 -

An issue in KIA Seltos vehicle instrument cluster with software and hardware v1.0 allows attackers to control or disrupt CAN communication between the instrument cluster and CAN bus. NOTE: this is disputed by the Supplier because the findings came from a potentially unrealistic test environment (an…

πŸ“… Published: Nov. 22, 2024, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 346649
Page 7504 of 34,665
Β« previous page Β» next page
Filters