6.1

CVSS3.1

CVE-2024-13512 - Wonder FontAwesome <= 0.8 - Cross-Site Request Forgery to Stored Cross-Site Scripting

The Wonder FontAwesome plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 0.8. This is due to missing or incorrect nonce validation on one of its functions. This makes it possible for unauthenticated attackers to update settings and inject malicioโ€ฆ

๐Ÿ“… Published: Jan. 30, 2025, 1:41 p.m. ๐Ÿ”„ Last Modified: Jan. 31, 2025, 6:08 p.m.

6.4

CVSS3.1

CVE-2024-13661 - Table Editor <= 1.5.1 - Authenticated (Contributor+) Stored Cross-Site Scripting

The Table Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wptableeditor_vtabs' shortcode in all versions up to, and including, 1.5.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authentiโ€ฆ

๐Ÿ“… Published: Jan. 30, 2025, 1:41 p.m. ๐Ÿ”„ Last Modified: Jan. 31, 2025, 6:08 p.m.

6.4

CVSS3.1

CVE-2024-13700 - Embed Swagger UI <= 1.0.0 - Authenticated (Contributor+) Stored Cross-Site Scripting

The Embed Swagger UI plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wpsgui' shortcode in all versions up to, and including, 1.0.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attโ€ฆ

๐Ÿ“… Published: Jan. 30, 2025, 1:41 p.m. ๐Ÿ”„ Last Modified: Jan. 31, 2025, 4:49 p.m.

6.4

CVSS3.1

CVE-2024-12444 - WP Dispensary <= 4.5.0 - Authenticated (Contributor+) Stored Cross-Site Scripting

The WP Dispensary plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wpd_menu' shortcode in all versions up to, and including, 4.5.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attaโ€ฆ

๐Ÿ“… Published: Jan. 30, 2025, 1:41 p.m. ๐Ÿ”„ Last Modified: Jan. 31, 2025, 6:45 p.m.

4.3

CVSS3.1

CVE-2024-11583 - Borderless โ€“ Widgets, Elements, Templates and Toolkit for Elementor & Gutenberg <= 1.5.9 - Missing โ€ฆ

The Borderless โ€“ Widgets, Elements, Templates and Toolkit for Elementor & Gutenberg plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the 'remove_zipped_font' function in all versions up to, and including, 1.5.9. This makes it possible for authentiโ€ฆ

๐Ÿ“… Published: Jan. 30, 2025, 1:41 p.m. ๐Ÿ”„ Last Modified: Jan. 31, 2025, 8:03 p.m.

6.3

CVSS4.0

CVE-2025-0870 - Axiomatic Bento4 Ap4DataBuffer.h GetData heap-based overflow

A vulnerability was found in Axiomatic Bento4 up to 1.6.0-641. It has been rated as critical. Affected by this issue is the function AP4_DataBuffer::GetData in the library Ap4DataBuffer.h. The manipulation leads to heap-based buffer overflow. The attack may be launched remotely. The complexity of aโ€ฆ

๐Ÿ“… Published: Jan. 30, 2025, 1 p.m. ๐Ÿ”„ Last Modified: Feb. 28, 2025, 10:16 p.m.

5.3

CVSS4.0

CVE-2025-0869 - Cianet ONU GW24AC Login cross site scripting

A vulnerability was found in Cianet ONU GW24AC up to 20250127. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the component Login. The manipulation of the argument browserLang leads to cross site scripting. The attack can be launched remotely. Theโ€ฆ

๐Ÿ“… Published: Jan. 30, 2025, 1 p.m. ๐Ÿ”„ Last Modified: Feb. 7, 2025, 5:15 p.m.

6.4

CVSS3.1

CVE-2024-13466 - Automatically Hierarchic Categories in Menu <= 2.0.7 - Authenticated (Contributor+) Stored Cross-Siโ€ฆ

The Automatically Hierarchic Categories in Menu plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'autocategorymenu' shortcode in all versions up to, and including, 2.0.7 due to insufficient input sanitization and output escaping on user supplied attributes. This maโ€ฆ

๐Ÿ“… Published: Jan. 30, 2025, 12:22 p.m. ๐Ÿ”„ Last Modified: July 13, 2025, 11:22 a.m.

6.4

CVSS3.1

CVE-2024-13380 - Alex Reservations: Smart Restaurant Booking <= 2.0.5 - Authenticated (Contributor+) Stored Cross-Siโ€ฆ

The Alex Reservations: Smart Restaurant Booking plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'rr_form' shortcode in all versions up to, and including, 2.0.5 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it poโ€ฆ

๐Ÿ“… Published: Jan. 30, 2025, 12:22 p.m. ๐Ÿ”„ Last Modified: Feb. 18, 2025, 7:15 p.m.

6.8

CVSS3.1

CVE-2022-43916 - IBM App Connect Enterprise Certified Container improper communications restriction

IBM App Connect Enterprise Certified Container 7.1, 7.2, 8.0, 8.1, 8.2, 9.0, 9.1, 9.2, 10.0, 10.1, 11.0, 11.1, 11.2, 11.3, 11.4, 11.5, 11.6, 12.0, 12.1, 12.2, 12.3, 12.4, 12.5, 12.6, and 12.7 Pods do not restrict network egress for Pods that are used for internal infrastructure.

๐Ÿ“… Published: Jan. 30, 2025, 12:04 p.m. ๐Ÿ”„ Last Modified: Aug. 13, 2025, 5:50 p.m.
Total resulsts: 343048
Page 6297 of 34,305
ยซ previous page ยป next page
Filters