5.3
CVE-2024-10535 - Video Gallery for WooCommerce <= 1.31 - Missing Authorization to Unauthenticated Limited File Deletβ¦
The Video Gallery for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the remove_unused_thumbnails() function in all versions up to, and including, 1.31. This makes it possible for unauthenticated attackers to delete thumbnailβ¦
9.9
CVE-2024-9307 - mFolio Lite <= 1.2.1 - Missing Authorization to Authenticated (Author+) File Upload via EXE and SVGβ¦
The mFolio Lite plugin for WordPress is vulnerable to file uploads due to a missing capability check in all versions up to, and including, 1.2.1. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenevβ¦
6.3
CVE-2024-9902 - Ansible-core: ansible-core user may read/write unauthorized content
A flaw was found in Ansible. The ansible-core `user` module can allow an unprivileged user to silently create or replace the contents of any file on any system path and take ownership of it when a privileged user executes the `user` module against the unprivileged user's home directory. If the unprβ¦
6.1
CVE-2024-9934 - Wp-ImageZoom <= 1.1.0 - Reflected XSS
The Wp-ImageZoom WordPress plugin through 1.1.0 does not sanitise and escape some parameters before outputting them back in a page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin
4.8
CVE-2024-7879 - WP ULike < 4.7.5 - Admin+ Stored XSS via Widgets
The WP ULike WordPress plugin before 4.7.5 does not sanitise and escape some of its settings, which could allow high privilege users such as editors to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed
0.0
CVE-2025-20110 -
This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused
6.4
CVE-2024-49409 -
Out-of-bounds write in Battery Full Capacity node prior to Firmware update Sep-2024 Release on Galaxy S24 allows local attackers to write out-of-bounds memory. System privilege is required for triggering this vulnerability.
6.4
CVE-2024-49408 -
Out-of-bounds write in usb driver prior to Firmware update Sep-2024 Release on Galaxy S24 allows local attackers to write out-of-bounds memory. System privilege is required for triggering this vulnerability.
4.6
CVE-2024-49407 -
Improper access control in Samsung Flow prior to version 4.9.15.7 allows physical attackers to access data across multiple user profiles.
6.7
CVE-2024-49406 -
Improper validation of integrity check value in Blockchain Keystore prior to version 1.3.16 allows local attackers to modify transaction. Root privilege is required for triggering this vulnerability.