7.2

CVSS3.1

CVE-2024-13704 - Super Testimonials <= 4.0.1 - Unauthenticated Stored Cross-Site Scripting

The Super Testimonials plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'st_user_title' parameter in all versions up to, and including, 4.0.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary…

πŸ“… Published: Feb. 18, 2025, 7:28 a.m. πŸ”„ Last Modified: April 8, 2026, 4:41 p.m.

6.1

CVSS3.1

CVE-2024-11376 - s2Member – Excellent for All Kinds of Memberships, Content Restriction Paywalls & Member Access Sub…

The s2Member – Excellent for All Kinds of Memberships, Content Restriction Paywalls & Member Access Subscriptions plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 241114…

πŸ“… Published: Feb. 18, 2025, 7:28 a.m. πŸ”„ Last Modified: April 8, 2026, 4:34 p.m.

6.1

CVSS3.1

CVE-2024-13523 - MemorialDay <= 1.0.4 - Cross-Site Request Forgery to Stored Cross-Site Scripting

The MemorialDay plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.4. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to update settings and inject malicious web scripts …

πŸ“… Published: Feb. 18, 2025, 7:02 a.m. πŸ”„ Last Modified: April 8, 2026, 5:10 p.m.

7.3

CVSS3.1

CVE-2024-57964 - Insecure Loading of Dynamic Link Libraries in HVAC Energy Saving Program

Insecure Loading of Dynamic Link Libraries have been discovered in HVAC Energy Saving Program, which could allow local attackers to potentially disclose information or execute arbitray code on affected systems. This issue affects HVAC Energy Saving Program:.

πŸ“… Published: Feb. 18, 2025, 6:33 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.3

CVSS3.1

CVE-2024-57963 - Insecure Loading of Dynamic Link Libraries in USB-CONVERTERCABLE DRIVER

Insecure Loading of Dynamic Link Libraries have been discovered in USB-CONVERTERCABLE DRIVER, which could allow local attackers to potentially disclose information or execute arbitray code on affected systems. This issue affects USB-CONVERTERCABLE DRIVER:.

πŸ“… Published: Feb. 18, 2025, 6:33 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.8

CVSS3.1

CVE-2024-13315 - Shopwarden – Automated WooCommerce monitoring & testing <= 1.0.11 - Cross-Site Request Forgery to A…

The Shopwarden – Automated WooCommerce monitoring & testing plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.11. This is due to missing or incorrect nonce validation on the save_setting() function. This makes it possible for unauthenticated …

πŸ“… Published: Feb. 18, 2025, 5:22 a.m. πŸ”„ Last Modified: April 8, 2026, 5:16 p.m.

8.1

CVSS3.1

CVE-2024-13556 - Affiliate Links: WordPress Plugin for Link Cloaking and Link Management <= 3.0.1 - Missing Authoriz…

The Affiliate Links: WordPress Plugin for Link Cloaking and Link Management plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.0.1 via deserialization of untrusted input from an file export. This makes it possible for unauthenticated attackers to inje…

πŸ“… Published: Feb. 18, 2025, 5:22 a.m. πŸ”„ Last Modified: April 8, 2026, 4:43 p.m.

4.3

CVSS3.1

CVE-2024-13438 - SpeedSize Image & Video AI-Optimizer <= 1.5.1 - Cross-Site Request Forgery to Clear Cache

The SpeedSize Image & Video AI-Optimizer plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.5.1. This is due to missing or incorrect nonce validation on the 'speedsize_clear_css_cache_action' function. This makes it possible for unauthenticated …

πŸ“… Published: Feb. 18, 2025, 5:22 a.m. πŸ”„ Last Modified: April 8, 2026, 4:36 p.m.

6.5

CVSS3.0

CVE-2024-45320 -

Out-of-bounds write vulnerability exists in DocuPrint CP225w 01.22.01 and earlier, DocuPrint CP228w 01.22.01 and earlier, DocuPrint CM225fw 01.10.01 and earlier, and DocuPrint CM228fw 01.10.01 and earlier. If an affected MFP processes a specially crafted printer job file, a denial-of-service (DoS) …

πŸ“… Published: Feb. 18, 2025, 5:20 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.4

CVSS3.1

CVE-2024-13582 - Simple Pricing Tables For WPBakery Page Builder(Formerly Visual Composer) <= 1.0 - Authenticated (C…

The Simple Pricing Tables For WPBakery Page Builder(Formerly Visual Composer) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wdo_simple_pricing_table_free' shortcode in all versions up to, and including, 1.0 due to insufficient input sanitization and output esca…

πŸ“… Published: Feb. 18, 2025, 4:21 a.m. πŸ”„ Last Modified: April 8, 2026, 5:27 p.m.
Total resulsts: 348618
Page 6646 of 34,862
Β« previous page Β» next page
Filters