8.8

CVSS3.1

CVE-2024-41739 - IBM Cognos Dashboards on Cloud Pak for Data privilege escalation

IBM Cognos Dashboards 4.0.7 and 5.0.0 on Cloud Pak for Data could allow a remote attacker to perform unauthorized actions due to dependency confusion.

📅 Published: Jan. 24, 2025, 1:37 p.m. 🔄 Last Modified: Aug. 14, 2025, 6:57 p.m.

7.5

CVSS3.1

CVE-2024-13408 - Post Grid, Slider & Carousel Ultimate – with Shortcode, Gutenberg Block & Elementor Widget <= 1.6.1…

The Post Grid, Slider & Carousel Ultimate – with Shortcode, Gutenberg Block & Elementor Widget plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.6.10 via the 'theme' attribute of the `pgcu` shortcode. This makes it possible for authenticated attacker…

📅 Published: Jan. 24, 2025, 11:07 a.m. 🔄 Last Modified: April 8, 2026, 5:35 p.m.

6.4

CVSS3.1

CVE-2024-13354 - Responsive Addons for Elementor – Free Elementor Addons Plugin and Elementor Templates <= 1.6.4 - A…

The Responsive Addons for Elementor – Free Elementor Addons Plugin and Elementor Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via HTML tags in several widgets in all versions up to, and including, 1.6.4 due to insufficient input sanitization and output escaping. This …

📅 Published: Jan. 24, 2025, 11:07 a.m. 🔄 Last Modified: April 8, 2026, 5:20 p.m.

4.3

CVSS3.1

CVE-2024-13335 - Sastra Essential Addons for Elementor – Free Elementor Addons, Widgets and Templates <= 1.0.14 - Mi…

The Spexo Addons for Elementor – Free Elementor Addons, Widgets and Templates plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the tmpcoder_theme_install_func() function in all versions up to, and including, 1.0.14. This makes it possible for authentica…

📅 Published: Jan. 24, 2025, 11:07 a.m. 🔄 Last Modified: April 8, 2026, 4:51 p.m.

6.4

CVSS3.1

CVE-2024-13542 - WP Google Street View (with 360° virtual tour) & Google maps + Local SEO <= 1.1.3 - Authenticated (…

The WP Google Street View (with 360° virtual tour) & Google maps + Local SEO plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wpgsv' shortcode in all versions up to, and including, 1.1.3 due to insufficient input sanitization and output escaping on user supplied a…

📅 Published: Jan. 24, 2025, 11:07 a.m. 🔄 Last Modified: April 8, 2026, 4:50 p.m.

6.5

CVSS3.1

CVE-2024-13594 - Simple Downloads List <= 1.4.2 - Authenticated (Contributor+) SQL Injection

The Simple Downloads List plugin for WordPress is vulnerable to SQL Injection via the 'category' attribute of the 'neofix_sdl' shortcode in all versions up to, and including, 1.4.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL que…

📅 Published: Jan. 24, 2025, 11:07 a.m. 🔄 Last Modified: April 8, 2026, 4:50 p.m.

6.4

CVSS3.1

CVE-2024-13572 - Precious Metals Charts and Widgets for WordPress <= 1.2.8 - Authenticated (Contributor+) Stored Cro…

The Precious Metals Charts and Widgets for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'nfusion-widget' shortcode in all versions up to, and including, 1.2.8 due to insufficient input sanitization and output escaping on user supplied attributes. This…

📅 Published: Jan. 24, 2025, 11:07 a.m. 🔄 Last Modified: April 8, 2026, 4:48 p.m.

7.5

CVSS3.1

CVE-2024-13409 - Post Grid, Slider & Carousel Ultimate – with Shortcode, Gutenberg Block & Elementor Widget <= 1.6.1…

The Post Grid, Slider & Carousel Ultimate – with Shortcode, Gutenberg Block & Elementor Widget plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.6.10 via the 'theme' parameter of the post_type_ajax_handler() function. This makes it possible for authe…

📅 Published: Jan. 24, 2025, 11:07 a.m. 🔄 Last Modified: April 8, 2026, 4:46 p.m.

7.1

CVSS3.1

CVE-2025-22714 - WordPress MDJM Event Management Plugin <= 1.7.5.6 - Reflected Cross Site Scripting (XSS) vulnerabil…

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in MDJM Mobile DJ Manager mobile-dj-manager allows Reflected XSS.This issue affects Mobile DJ Manager: from n/a through <= 1.7.5.6.

📅 Published: Jan. 24, 2025, 10:52 a.m. 🔄 Last Modified: April 23, 2026, 3:23 p.m.

7.1

CVSS3.1

CVE-2025-23889 - WordPress FooGallery Captions Plugin <= 1.0.2 - Reflected Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in tormorten FooGallery Captions foogallery-captions allows Reflected XSS.This issue affects FooGallery Captions: from n/a through <= 1.0.2.

📅 Published: Jan. 24, 2025, 10:52 a.m. 🔄 Last Modified: April 23, 2026, 3:24 p.m.
Total resulsts: 349182
Page 6979 of 34,919
« previous page » next page
Filters