7.6

CVSS3.1

CVE-2024-4337 - Mรบltiple vulnerabilities on Adive Framework

Adive Framework 2.0.8, does not sufficiently encode user-controlled inputs, resulting in a persistent Cross-Site Scripting (XSS) vulnerability via the /adive/admin/nav/add, in multiple parameters. This vulnerability allows an attacker to retrieve the session details of an authenticated user.

๐Ÿ“… Published: April 30, 2024, 9:33 a.m. ๐Ÿ”„ Last Modified: Oct. 15, 2025, 2:13 p.m.

8.3

CVSS3.1

CVE-2024-2663 - ZD YouTube FLV Player <= 1.2.6 - Server-Side Request Forgery

The ZD YouTube FLV Player plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.2.6 via the $_GET['image'] parameter. This makes it possible for unauthenticated attackers to make web requests to arbitrary locations originating from the web applicaโ€ฆ

๐Ÿ“… Published: April 30, 2024, 8:32 a.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.1

CVSS3.1

CVE-2024-4185 - Customer Email Verification for WooCommerce <= 2.7.4 - Email Verification and Authentication Bypassโ€ฆ

The Customer Email Verification for WooCommerce plugin for WordPress is vulnerable to Email Verification and Authentication Bypass in all versions up to, and including, 2.7.4 via the use of insufficiently random activation code. This makes it possible for unauthenticated attackers to bypass the emaโ€ฆ

๐Ÿ“… Published: April 30, 2024, 8:32 a.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

4.3

CVSS3.1

CVE-2024-3072 - ACF Front End Editor <= 2.0.2 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Contโ€ฆ

The ACF Front End Editor plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the update_texts() function in all versions up to, and including, 2.0.2. This makes it possible for authenticated attackers, with subscriber-level access and above, โ€ฆ

๐Ÿ“… Published: April 30, 2024, 8:32 a.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.5

CVSS3.1

CVE-2024-1895 - Event Monster <= 1.3.9 - Authenticated(Contributor+) PHP Object Injection via Custom Meta

The Event Monster โ€“ Event Management, Tickets Booking, Upcoming Event plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.3.9 via deserialization via shortcode of untrusted input from a custom meta value. This makes it possible for authenticated attackโ€ฆ

๐Ÿ“… Published: April 30, 2024, 8:32 a.m. ๐Ÿ”„ Last Modified: April 8, 2026, 6:20 p.m.

7.6

CVSS3.1

CVE-2024-4225 - NGDIN_ST v2.0D.0062 - Multiple Vulnerabilities

Multiple security vulnerabilities has been discovered in web interface of NetGuardian DIN Remote Telemetry Unit (RTU), by DPS Telecom. Attackers can exploit those security vulnerabilities to perform critical actions such as escalate user's privilege, steal user's credential, Cross Site Scripting (Xโ€ฆ

๐Ÿ“… Published: April 30, 2024, 6:47 a.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.5

CVSS3.1

CVE-2024-1371 - LeadConnector <= 1.7 - Missing Authorization to Unauthenticated Arbitrary Post Deletion

The LeadConnector plugin for WordPress is vulnerable to unauthorized modification & loss of data due to a missing capability check on the lc_public_api_proxy() function in all versions up to, and including, 1.7. This makes it possible for unauthenticated attackers to delete arbitrary posts. CVE-202โ€ฆ

๐Ÿ“… Published: April 30, 2024, 2:35 a.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.4

CVSS3.1

CVE-2024-0216 - Google Doc Embedder <= 2.6.4 - Authenticated (Contributor+) Blind Server Side Request Forgery

The Google Doc Embedder plugin for WordPress is vulnerable to Server Side Request Forgery via the 'gview' shortcode in versions up to, and including, 2.6.4. This can allow authenticated attackers with contributor-level permissions or above to make web requests to arbitrary locations originating froโ€ฆ

๐Ÿ“… Published: April 30, 2024, 1:54 a.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

3.5

CVSS3.1

CVE-2024-4226 -

It was identified that in certain versions of Octopus Server, that a user created with no permissions could view all users, user roles and permissions. This functionality was removed in versions of Octopus Server after the fixed versions listed.

๐Ÿ“… Published: April 30, 2024, 1:53 a.m. ๐Ÿ”„ Last Modified: June 27, 2025, 2:42 p.m.

3.5

CVSS3.1

CVE-2024-4327 - Apryse WebViewer PDF Document cross site scripting

A vulnerability was found in Apryse WebViewer up to 10.8.0. It has been classified as problematic. This affects an unknown part of the component PDF Document Handler. The manipulation leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to thโ€ฆ

๐Ÿ“… Published: April 30, 2024, 1 a.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 349182
Page 10123 of 34,919
ยซ previous page ยป next page
Filters