6.1

CVSS3.1

CVE-2024-10851 - Razorpay Payment Button <= 2.4.6 - Reflected Cross-Site Scripting

The Razorpay Payment Button Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg & remove_query_arg without appropriate escaping on the URL in all versions up to, and including, 2.4.6. This makes it possible for unauthenticated attackers to injโ€ฆ

๐Ÿ“… Published: Nov. 13, 2024, 2:02 a.m. ๐Ÿ”„ Last Modified: April 8, 2026, 6:19 p.m.

6.4

CVSS3.1

CVE-2024-8985 - Social Proof (Testimonials) Slider <= 2.2.4 - Authenticated (Contributor+) Stored Cross-Site Scriptโ€ฆ

The Social Proof (Testimonial) Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's spslider-block shortcode in all versions up to, and including, 2.2.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possiblโ€ฆ

๐Ÿ“… Published: Nov. 13, 2024, 2:02 a.m. ๐Ÿ”„ Last Modified: April 8, 2026, 4:50 p.m.

5.3

CVSS3.1

CVE-2024-9578 - Hide Links <= 1.4.2 - Unauthenticated Shortcode Execution

The Hide Links plugin for WordPress is vulnerable to unauthorized shortcode execution due to do_shortcode being hooked through the comment_text filter in all versions up to and including 1.4.2. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes available on the tarโ€ฆ

๐Ÿ“… Published: Nov. 13, 2024, 2:02 a.m. ๐Ÿ”„ Last Modified: April 8, 2026, 4:48 p.m.

4.3

CVSS3.1

CVE-2024-10852 - Buy one click WooCommerce <= 2.2.9 - Missing Authorization to Authenticated (Subscriber+) Settings โ€ฆ

The Buy one click WooCommerce plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the buy_one_click_export_options AJAX action in all versions up to, and including, 2.2.9. This makes it possible for authenticated attackers, with Subscriber-level acโ€ฆ

๐Ÿ“… Published: Nov. 13, 2024, 2:02 a.m. ๐Ÿ”„ Last Modified: April 8, 2026, 4:41 p.m.

4.3

CVSS3.1

CVE-2024-10778 - BuddyPress Builder for Elementor โ€“ BuddyBuilder <= 1.7.4 - Authenticated (Contributor+) Post Discloโ€ฆ

The BuddyPress Builder for Elementor โ€“ BuddyBuilder plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.7.4 via the 'elementor-template' shortcode due to insufficient restrictions on which posts can be included. This makes it possible for authenticatedโ€ฆ

๐Ÿ“… Published: Nov. 13, 2024, 2:02 a.m. ๐Ÿ”„ Last Modified: April 8, 2026, 5:17 p.m.

7.2

CVSS3.1

CVE-2024-38655 -

Argument injection in Ivanti Connect Secure before version 22.7R2.1 and 9.1R18.9 and Ivanti Policy Secure before version 22.7R1.1 and 9.1R18.9 allows a remote authenticated attacker with admin privileges to achieve remote code execution.

๐Ÿ“… Published: Nov. 13, 2024, 1:54 a.m. ๐Ÿ”„ Last Modified: June 27, 2025, 6:43 p.m.

7.2

CVSS3.1

CVE-2024-34784 -

SQL injection in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allows a remote authenticated attacker with admin privileges to achieve remote code execution.

๐Ÿ“… Published: Nov. 13, 2024, 1:54 a.m. ๐Ÿ”„ Last Modified: May 1, 2025, 6:01 p.m.

7.2

CVSS3.1

CVE-2024-34780 -

SQL injection in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allows a remote authenticated attacker with admin privileges to achieve remote code execution.

๐Ÿ“… Published: Nov. 13, 2024, 1:54 a.m. ๐Ÿ”„ Last Modified: April 23, 2025, 7:18 p.m.

4.7

CVSS3.1

CVE-2024-29211 -

A race condition in Ivanti Secure Access Client before version 22.7R4 allows a local authenticated attacker to modify sensitive configuration files.

๐Ÿ“… Published: Nov. 13, 2024, 1:54 a.m. ๐Ÿ”„ Last Modified: Nov. 14, 2024, 7:09 p.m.

9.1

CVSS3.0

CVE-2024-39712 -

Argument injection in Ivanti Connect Secure before version 22.7R2.1 and 9.1R18.7 and Ivanti Policy Secure before version 22.7R1.1 allows a remote authenticated attacker with admin privileges to achieve remote code execution.

๐Ÿ“… Published: Nov. 13, 2024, 1:54 a.m. ๐Ÿ”„ Last Modified: July 11, 2025, 1:53 p.m.
Total resulsts: 343887
Page 7375 of 34,389
ยซ previous page ยป next page
Filters