6.5

CVSS3.1

CVE-2024-11179 - MStore API <= 4.15.7 - Authenticated (Subscriber+) SQL Injection

The MStore API – Create Native Android & iOS Apps On The Cloud plugin for WordPress is vulnerable to SQL Injection via the 'status_type' parameter in all versions up to, and including, 4.15.7 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the exist…

πŸ“… Published: Nov. 20, 2024, 9:31 a.m. πŸ”„ Last Modified: April 8, 2026, 5:16 p.m.

6.4

CVSS3.1

CVE-2024-10891 - Save as PDF Plugin by Pdfcrowd <= 4.2.1 - Authenticated (Contributor+) Stored Cross-Site Scripting

The Save as PDF Plugin by Pdfcrowd plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'save_as_pdf_pdfcrowd' shortcode in all versions up to, and including, 4.2.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it po…

πŸ“… Published: Nov. 20, 2024, 9:31 a.m. πŸ”„ Last Modified: April 8, 2026, 4:46 p.m.

5.4

CVSS3.1

CVE-2024-10665 - Yaad Sarig Payment Gateway For WC <= 2.2.4 - Missing Authorization to Authenticated (Subscriber+) L…

The Yaad Sarig Payment Gateway For WC plugin for WordPress is vulnerable to unauthorized modification & access of data due to a missing capability check on the yaadpay_view_log_callback() and yaadpay_delete_log_callback() functions in all versions up to, and including, 2.2.4. This makes it possible…

πŸ“… Published: Nov. 20, 2024, 9:31 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS4.0

CVE-2024-10126 - Local file inclusion vulnerability in M-Files Server

Local File Inclusion vulnerability in M-Files Server in versions before 24.11 (excluding 24.8 SR1, 24.2 SR3 and 23.8 SR7) allows an authenticated user to read server local files of a limited set of filetypes via document preview.

πŸ“… Published: Nov. 20, 2024, 8:37 a.m. πŸ”„ Last Modified: Feb. 23, 2026, 11:16 a.m.

9.2

CVSS4.0

CVE-2024-10127 - Support for authentication bypass condition in M-Files LDAP authentication

Authentication bypass condition in LDAP authentication in M-Files server versions before 24.11 supported usage of OpenLDAP configurations that allowed user authentication without a password when the LDAP server itself had the vulnerable configuration.

πŸ“… Published: Nov. 20, 2024, 8:36 a.m. πŸ”„ Last Modified: Feb. 23, 2026, 11:16 a.m.

5.3

CVSS4.0

CVE-2024-11176 - Incorrect evaluation of effective permissions in M-Files Aino

Improper access control vulnerability in M-Files Aino in versions before 24.10 allowed an authenticated user to access object information via incorrect evaluation of effective permissions.

πŸ“… Published: Nov. 20, 2024, 8:33 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS3.1

CVE-2024-47865 -

Missing authentication for critical function vulnerability exists in Rakuten Turbo 5G firmware version V1.3.18 and earlier. If this vulnerability is exploited, a remote unauthenticated attacker may update or downgrade the firmware on the device.

πŸ“… Published: Nov. 20, 2024, 7:30 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.8

CVSS3.1

CVE-2024-48895 -

Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in Rakuten Turbo 5G firmware version V1.3.18 and earlier. If this vulnerability is exploited, a remote authenticated attacker may execute an arbitrary OS command.

πŸ“… Published: Nov. 20, 2024, 7:30 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS3.1

CVE-2024-52033 -

Exposure of sensitive system information to an unauthorized control sphere issue exists in Rakuten Turbo 5G firmware version V1.3.18 and earlier. If this vulnerability is exploited, a remote unauthenticated attacker may obtain information of the other devices connected through the Wi-Fi.

πŸ“… Published: Nov. 20, 2024, 7:29 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

4.3

CVSS3.1

CVE-2024-10365 - The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce <…

The The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 6.0.3 via the render function in modules/widgets/tp_carousel_anything.php, modules/widgets…

πŸ“… Published: Nov. 20, 2024, 6:42 a.m. πŸ”„ Last Modified: April 8, 2026, 5:33 p.m.
Total resulsts: 346563
Page 7518 of 34,657
Β« previous page Β» next page
Filters