Vulnerabilities > High

DATE CVE VULNERABILITY TITLE RISK
2024-12-12 CVE-2024-12487 Injection vulnerability in Fabian Online Class and Exam Scheduling System 1.0
A vulnerability has been found in code-projects Online Class and Exam Scheduling System 1.0 and classified as critical.
network
low complexity
fabian CWE-74
8.8
2024-12-12 CVE-2024-12488 Unspecified vulnerability in Fabian Online Class and Exam Scheduling System 1.0
A vulnerability was found in code-projects Online Class and Exam Scheduling System 1.0 and classified as critical.
network
low complexity
fabian
8.8
2024-12-12 CVE-2024-12489 Injection vulnerability in Fabian Online Class and Exam Scheduling System 1.0
A vulnerability was found in code-projects Online Class and Exam Scheduling System 1.0.
network
low complexity
fabian CWE-74
8.8
2024-12-11 CVE-2024-10251 Incorrect Default Permissions vulnerability in Ivanti Security Controls
Under specific circumstances, insecure permissions in Ivanti Security Controls before version 2024.4.1 allows a local authenticated attacker to achieve local privilege escalation.
local
low complexity
ivanti CWE-276
7.8
2024-12-11 CVE-2024-8496 Incorrect Default Permissions vulnerability in Ivanti Workspace Control
Under specific circumstances, insecure permissions in Ivanti Workspace Control before version 10.18.40.0 allows a local authenticated attacker to achieve local privilege escalation.
local
low complexity
ivanti CWE-276
7.8
2024-12-11 CVE-2024-9845 Incorrect Default Permissions vulnerability in Ivanti Automation
Under specific circumstances, insecure permissions in Ivanti Automation before version 2024.4.0.1 allows a local authenticated attacker to achieve local privilege escalation.
local
low complexity
ivanti CWE-276
7.8
2024-12-11 CVE-2024-11840 The RapidLoad – Optimize Web Vitals Automatically plugin for WordPress is vulnerable to unauthorized access of data and modification of data due to a missing capability check on the uucss_data, update_rapidload_settings, wp_ajax_update_htaccess_file, uucss_update_rule, upload_rules, get_all_rules, update_titan_settings, preload_page, and activate_module functions in all versions up to, and including, 2.4.2.
network
low complexity
CWE-862
7.1
2024-12-10 CVE-2024-43716 Unspecified vulnerability in Adobe Experience Manager
Adobe Experience Manager versions 6.5.21 and earlier are affected by an Improper Access Control vulnerability that could result in a Security feature bypass.
network
low complexity
adobe
8.8
2024-12-10 CVE-2024-43717 Unspecified vulnerability in Adobe Experience Manager
Adobe Experience Manager versions 6.5.21 and earlier are affected by an Improper Access Control vulnerability that could result in a Security feature bypass.
network
low complexity
adobe
8.8
2024-12-10 CVE-2024-43729 Unspecified vulnerability in Adobe Experience Manager
Adobe Experience Manager versions 6.5.21 and earlier are affected by an Improper Authorization vulnerability that could result in a Security feature bypass.
network
low complexity
adobe
8.8