381
|
5.3 |
MEDIUM
Network
-
|
-
|
The WordPress Contact Forms by Cimatti plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the accua_forms_download_submitted_file() function in all…
|
CWE-862
Missing Authorization
|
CVE-2024-12184
|
2025-02-1 13:15 |
2025-02-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
382
|
8.8 |
HIGH
Network
|
-
|
-
|
The ELEX WordPress HelpDesk & Customer Ticketing System plugin for WordPress is vulnerable to privilege escalation due to a missing capability check on the 'eh_crm_agent_add_user' AJAX action in all …
|
CWE-862
Missing Authorization
|
CVE-2024-12171
|
2025-02-1 13:15 |
2025-02-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
383
|
6.4 |
MEDIUM
Network
|
-
|
-
|
The Site Search 360 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'ss360-resultblock' shortcode in all versions up to, and including, 2.1.6 due to insufficient in…
|
CWE-79
Cross-site Scripting
|
CVE-2024-11780
|
2025-02-1 13:15 |
2025-02-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
384
|
- |
|
-
|
-
|
Dumb Drop is a file upload application. Users with permission to upload to the service are able to exploit a path traversal vulnerability to overwrite arbitrary system files. As the container runs as…
|
CWE-22 CWE-276
Path Traversal Incorrect Default Permissions
|
CVE-2025-24891
|
2025-02-1 08:15 |
2025-02-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
385
|
7.5 |
HIGH
Network
apple
|
macos safari
|
A logging issue was addressed with improved data redaction. This issue is fixed in macOS Sequoia 15.3, Safari 18.3. A malicious app may be able to bypass browser extension authentication.
|
NVD-CWE-Other
|
CVE-2025-24169
|
2025-02-1 07:15 |
2025-01-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
386
|
5.5 |
MEDIUM
Local
|
apple
|
macos
|
The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.3. An app may be able to cause unexpected system termination or corrupt kernel memory.
|
NVD-CWE-noinfo
|
CVE-2025-24152
|
2025-02-1 07:15 |
2025-01-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
387
|
4.3 |
MEDIUM
Network
|
apple
|
macos ipados iphone_os safari visionos
|
The issue was addressed with improved UI. This issue is fixed in macOS Sequoia 15.3, Safari 18.3, iOS 18.3 and iPadOS 18.3, visionOS 2.3. Visiting a malicious website may lead to user interface spoof…
|
NVD-CWE-noinfo
|
CVE-2025-24113
|
2025-02-1 07:15 |
2025-01-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
388
|
7.5 |
HIGH
Network
apple
|
macos
|
A logic issue was addressed with improved restrictions. This issue is fixed in macOS Sonoma 14.7.2, macOS Sequoia 15.2, macOS Ventura 13.7.2. An attacker may gain access to protected parts of the fil…
|
NVD-CWE-noinfo
|
CVE-2024-54557
|
2025-02-1 07:15 |
2025-01-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
389
|
5.5 |
MEDIUM
Local
|
apple
|
macos
|
The issue was addressed with improved validation of environment variables. This issue is fixed in macOS Sequoia 15.2. An app may be able to edit NVRAM variables.
|
NVD-CWE-noinfo
|
CVE-2024-54536
|
2025-02-1 07:15 |
2025-01-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
390
|
3.3 |
LOW
Local
|
apple
|
macos
|
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sonoma 14.7.2, macOS Sequoia 15.2. An app may be able to approve a launch daemon without user consent.
|
NVD-CWE-noinfo
|
CVE-2024-54516
|
2025-02-1 07:15 |
2025-01-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|