9.8

CVSS3.1

CVE-2015-20111 -

miniupnp before 4c90b87, as used in Bitcoin Core before 0.12 and other products, lacks checks for snprintf return values, leading to a buffer overflow and significant data leak, a different vulnerability than CVE-2019-12107. In Bitcoin Core before 0.12, remote code execution was possible in conjunc…

πŸ“… Published: Nov. 18, 2024, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

9.8

CVSS3.1

CVE-2023-43091 - Gnome-maps: gnome maps is vulnerable to a code injection attack (similar to xss) via its service.j…

A flaw was found in GNOME Maps, which is vulnerable to a code injection attack via its service.json configuration file. If the configuration file is malicious, it may execute arbitrary code.

πŸ“… Published: Nov. 17, 2024, 12:25 p.m. πŸ”„ Last Modified: Aug. 6, 2025, 12:46 p.m.

8.1

CVSS3.1

CVE-2024-52867 -

guix-daemon in GNU Guix before 5ab3c4c allows privilege escalation because build outputs are accessible by local users before file metadata concerns (e.g., for setuid and setgid programs) are properly addressed. The vulnerability can be remediated within the product via certain pull, reconfigure, a…

πŸ“… Published: Nov. 17, 2024, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.5

CVSS3.1

CVE-2024-52876 -

Holy Stone Remote ID Module HSRID01, firmware distributed with the Drone Go2 mobile application before 1.1.8, allows unauthenticated "remote power off" actions (in broadcast mode) via multiple read operations on the ASTM Remote ID (0xFFFA) GATT.

πŸ“… Published: Nov. 17, 2024, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.5

CVSS3.1

CVE-2024-52871 -

In Flagsmith before 2.134.1, it is possible to bypass the ALLOW_REGISTRATION_WITHOUT_INVITE setting.

πŸ“… Published: Nov. 17, 2024, midnight πŸ”„ Last Modified: July 7, 2025, 6:01 p.m.

7.5

CVSS3.1

CVE-2024-52872 -

In Flagsmith before 2.134.1, the get_document endpoint is not correctly protected by permissions.

πŸ“… Published: Nov. 17, 2024, midnight πŸ”„ Last Modified: July 7, 2025, 5:59 p.m.

0.0

CVE-2024-52397 - WordPress Convert Docx2post plugin <= 1.4 - Arbitrary File Upload vulnerability

Unrestricted Upload of File with Dangerous Type vulnerability in Davor Zeljkovic Convert Docx2post convert-docx2post allows Upload a Web Shell to a Web Server.This issue affects Convert Docx2post: from n/a through <= 1.4.

πŸ“… Published: Nov. 16, 2024, 10:10 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

0.0

CVE-2024-52398 - WordPress CDI plugin <= 5.5.3 - Arbitrary File Upload vulnerability

Unrestricted Upload of File with Dangerous Type vulnerability in Halyra CDI collect-and-deliver-interface-for-woocommerce.This issue affects CDI: from n/a through <= 5.5.3.

πŸ“… Published: Nov. 16, 2024, 10:08 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

0.0

CVE-2024-52399 - WordPress Writer Helper plugin <= 3.1.6 - Arbitrary File Upload vulnerability

Unrestricted Upload of File with Dangerous Type vulnerability in Clarisse K. Writer Helper writer-helper allows Upload a Web Shell to a Web Server.This issue affects Writer Helper: from n/a through <= 3.1.6.

πŸ“… Published: Nov. 16, 2024, 10:06 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

0.0

CVE-2024-52400 - WordPress Gallerio plugin <= 1.01 - Arbitrary File Upload vulnerability

Unrestricted Upload of File with Dangerous Type vulnerability in Subhasis Laha Gallerio gallerio allows Upload a Web Shell to a Web Server.This issue affects Gallerio: from n/a through <= 1.01.

πŸ“… Published: Nov. 16, 2024, 10:04 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 346099
Page 7535 of 34,610
Β« previous page Β» next page
Filters