5.3

CVSS3.1

CVE-2024-10535 - Video Gallery for WooCommerce <= 1.31 - Missing Authorization to Unauthenticated Limited File Delet…

The Video Gallery for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the remove_unused_thumbnails() function in all versions up to, and including, 1.31. This makes it possible for unauthenticated attackers to delete thumbnail…

πŸ“… Published: Nov. 6, 2024, 6:43 a.m. πŸ”„ Last Modified: April 8, 2026, 4:52 p.m.

9.9

CVSS3.1

CVE-2024-9307 - mFolio Lite <= 1.2.1 - Missing Authorization to Authenticated (Author+) File Upload via EXE and SVG…

The mFolio Lite plugin for WordPress is vulnerable to file uploads due to a missing capability check in all versions up to, and including, 1.2.1. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenev…

πŸ“… Published: Nov. 6, 2024, 6:43 a.m. πŸ”„ Last Modified: April 8, 2026, 6:22 p.m.

6.3

CVSS3.1

CVE-2024-9902 - Ansible-core: ansible-core user may read/write unauthorized content

A flaw was found in Ansible. The ansible-core `user` module can allow an unprivileged user to silently create or replace the contents of any file on any system path and take ownership of it when a privileged user executes the `user` module against the unprivileged user's home directory. If the unpr…

πŸ“… Published: Nov. 6, 2024, 6:11 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.1

CVSS3.1

CVE-2024-9934 - Wp-ImageZoom <= 1.1.0 - Reflected XSS

The Wp-ImageZoom WordPress plugin through 1.1.0 does not sanitise and escape some parameters before outputting them back in a page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

πŸ“… Published: Nov. 6, 2024, 6 a.m. πŸ”„ Last Modified: May 17, 2025, 1:46 a.m.

4.8

CVSS3.1

CVE-2024-7879 - WP ULike < 4.7.5 - Admin+ Stored XSS via Widgets

The WP ULike WordPress plugin before 4.7.5 does not sanitise and escape some of its settings, which could allow high privilege users such as editors to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed

πŸ“… Published: Nov. 6, 2024, 6 a.m. πŸ”„ Last Modified: April 11, 2025, 3:06 p.m.

0.0

CVE-2025-20110 -

This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

πŸ“… Published: Nov. 6, 2024, 4 a.m. πŸ”„ Last Modified: Feb. 13, 2026, 6:11 p.m.

6.4

CVSS3.1

CVE-2024-49409 -

Out-of-bounds write in Battery Full Capacity node prior to Firmware update Sep-2024 Release on Galaxy S24 allows local attackers to write out-of-bounds memory. System privilege is required for triggering this vulnerability.

πŸ“… Published: Nov. 6, 2024, 2:17 a.m. πŸ”„ Last Modified: Nov. 13, 2024, 12:51 a.m.

6.4

CVSS3.1

CVE-2024-49408 -

Out-of-bounds write in usb driver prior to Firmware update Sep-2024 Release on Galaxy S24 allows local attackers to write out-of-bounds memory. System privilege is required for triggering this vulnerability.

πŸ“… Published: Nov. 6, 2024, 2:17 a.m. πŸ”„ Last Modified: Nov. 13, 2024, 12:51 a.m.

4.6

CVSS3.1

CVE-2024-49407 -

Improper access control in Samsung Flow prior to version 4.9.15.7 allows physical attackers to access data across multiple user profiles.

πŸ“… Published: Nov. 6, 2024, 2:17 a.m. πŸ”„ Last Modified: Nov. 13, 2024, 12:53 a.m.

6.7

CVSS3.1

CVE-2024-49406 -

Improper validation of integrity check value in Blockchain Keystore prior to version 1.3.16 allows local attackers to modify transaction. Root privilege is required for triggering this vulnerability.

πŸ“… Published: Nov. 6, 2024, 2:17 a.m. πŸ”„ Last Modified: Nov. 13, 2024, 12:54 a.m.
Total resulsts: 346538
Page 7743 of 34,654
Β« previous page Β» next page
Filters