5.4

CVSS3.1

CVE-2021-3741 - Stored Cross-site Scripting (XSS) in chatwoot/chatwoot

A stored cross-site scripting (XSS) vulnerability was discovered in chatwoot/chatwoot, affecting all versions prior to 2.6. The vulnerability occurs when a user uploads an SVG file containing a malicious XSS payload in the profile settings. When the avatar is opened in a new page, the custom JavaSc…

📅 Published: Nov. 15, 2024, 10:51 a.m. 🔄 Last Modified: Nov. 20, 2024, 10:36 p.m.

5.3

CVSS4.0

CVE-2024-11182 - Stored XSS vulnerability in MDaemon Email Server

An XSS issue was discovered in MDaemon Email Server before version 24.5.1c. An attacker can send an HTML e-mail message with JavaScript in an img tag. This could allow a remote attacker to load arbitrary JavaScript code in the context of a webmail user's browser window.

📅 Published: Nov. 15, 2024, 10:43 a.m. 🔄 Last Modified: Oct. 30, 2025, 8:11 p.m.

9.8

CVSS3.1

CVE-2024-10443 -

Improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability in Task Manager component in Synology BeePhotos before 1.0.2-10026 and 1.1.0-10053 and Synology Photos before 1.6.2-0720 and 1.7.0-0795 allows remote attackers to execute arbitrary code via unsp…

📅 Published: Nov. 15, 2024, 10:23 a.m. 🔄 Last Modified: Sept. 16, 2025, 6:16 a.m.

7.5

CVSS3.1

CVE-2024-10311 - External Database Based Actions <= 0.1 - Authenticated (Subscriber+) Authentication Bypass

The External Database Based Actions plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 0.1. This is due to a missing capability check in the 'edba_admin_handle' function. This makes it possible for authenticated attackers, with subscriber-level permissions…

📅 Published: Nov. 15, 2024, 9:29 a.m. 🔄 Last Modified: April 8, 2026, 5:25 p.m.

5.7

CVSS3.1

CVE-2024-8978 - Essential Addons for Elementor – Best Elementor Addon, Templates, Widgets, Kits & WooCommerce Build…

The Essential Addons for Elementor – Best Elementor Addon, Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 6.0.9 via the 'init_content_register_user_email_controls' function. This makes it pos…

📅 Published: Nov. 15, 2024, 9:29 a.m. 🔄 Last Modified: April 8, 2026, 5:18 p.m.

8

CVSS3.1

CVE-2024-8979 - Essential Addons for Elementor – Best Elementor Addon, Templates, Widgets, Kits & WooCommerce Build…

The Essential Addons for Elementor – Best Elementor Addon, Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 6.0.9 via the 'init_content_lostpassword_user_email_controls' function. This makes it…

📅 Published: Nov. 15, 2024, 9:29 a.m. 🔄 Last Modified: April 8, 2026, 4:45 p.m.

7.5

CVSS3.1

CVE-2024-45784 - Apache Airflow: Sensitive configuration values are not masked in the logs by default

Apache Airflow versions before 2.10.3 contain a vulnerability that could expose sensitive configuration variables in task logs. This vulnerability allows DAG authors to unintentionally or intentionally log sensitive configuration variables. Unauthorized users could access these logs, potentially ex…

📅 Published: Nov. 15, 2024, 8:20 a.m. 🔄 Last Modified: June 3, 2025, 9:12 p.m.

6.1

CVSS3.1

CVE-2024-10825 - Hide My WP Ghost – Security & Firewall <= 5.3.01 - Reflected Cross-Site Scripting via URL

The Hide My WP Ghost – Security & Firewall plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the URL in all versions up to, and including, 5.3.01 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitra…

📅 Published: Nov. 15, 2024, 6:48 a.m. 🔄 Last Modified: April 8, 2026, 5:20 p.m.

6.4

CVSS3.1

CVE-2024-8961 - Essential Addons for Elementor – Best Elementor Addon, Templates, Widgets, Kits & WooCommerce Build…

The Essential Addons for Elementor – Best Elementor Addon, Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘nomore_items_text’ parameter in all versions up to, and including, 6.0.7 due to insufficient input sanitization and o…

📅 Published: Nov. 15, 2024, 6:48 a.m. 🔄 Last Modified: April 8, 2026, 4:49 p.m.

6.6

CVSS3.1

CVE-2024-9529 - Secure Custom Fields < 6.3.6.3 - Admin+ Remote Code Execution

The Secure Custom Fields WordPress plugin before 6.3.9, Secure Custom Fields WordPress plugin before 6.3.6.3, Advanced Custom Fields Pro WordPress plugin before 6.3.9 does not prevent users from running arbitrary functions through its setting import functionalities, which could allow high privilege…

📅 Published: Nov. 15, 2024, 6 a.m. 🔄 Last Modified: June 11, 2025, 1:58 p.m.
Total resulsts: 343996
Page 7346 of 34,400
« previous page » next page
Filters