6.4

CVSS3.1

CVE-2024-11945 - Email Reminders <= 2.0.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via id Parameter

The Email Reminders plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘id’ parameter in all versions up to, and including, 2.0.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and …

📅 Published: Dec. 10, 2024, 9:24 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

6.1

CVSS3.1

CVE-2024-11973 - Quran multilanguage Text & Audio <= 2.3.21 - Reflected Cross-Site Scripting via sourate and lang Pa…

The Quran multilanguage Text & Audio plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'sourate' and 'lang' parameter in all versions up to, and including, 2.3.21 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attack…

📅 Published: Dec. 10, 2024, 9:24 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

5.9

CVSS4.0

CVE-2024-8256 - Incorrect Permission Assignment in RutOS based routers and TSWOS based managed switches

In Teltonika Networks RUTOS devices, running on versions 7.0 to 7.8 (excluding) and TSWOS devices running on versions 1.0 to 1.3 (excluding), due to incorrect permission handling a vulnerability exists which allows a lower privileged user with default permissions to access critical device resources…

📅 Published: Dec. 10, 2024, 8:56 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

6.4

CVSS3.1

CVE-2024-11940 - Property Hive Mortgage Calculator <= 1.0.6 - Authenticated (Contributor+) Stored Cross-Site Scripti…

The Property Hive Mortgage Calculator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘price’ parameter in all versions up to, and including, 1.0.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contribu…

📅 Published: Dec. 10, 2024, 8:23 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS3.1

CVE-2024-45709 - SolarWinds Web Help Desk Local File Read Vulnerability

SolarWinds Web Help Desk was susceptible to a local file read vulnerability. This vulnerability requires the software be installed on Linux and configured to use non-default development/test mode making exposure to the vulnerability very limited.

📅 Published: Dec. 10, 2024, 8:20 a.m. 🔄 Last Modified: Feb. 25, 2025, 5:20 p.m.

7.2

CVSS3.1

CVE-2024-47946 - OS Command Execution through Arbitrary File Upload

If the attacker has access to a valid Poweruser session, remote code execution is possible because specially crafted valid PNG files with injected PHP content can be uploaded as desktop backgrounds or lock screens. After the upload, the PHP script is available in the web root. The PHP code executes…

📅 Published: Dec. 10, 2024, 7:48 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

7.3

CVSS3.1

CVE-2024-28138 - OS Command Injection

An unauthenticated attacker with network access to the affected device's web interface can execute any system command via the "msg_events.php" script as the www-data user. The HTTP GET parameter "data" is not properly sanitized.

📅 Published: Dec. 10, 2024, 7:35 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

6.1

CVSS3.1

CVE-2024-11107 - System Dashboard < 2.8.15 - Unauthenticated Stored XSS

The System Dashboard WordPress plugin before 2.8.15 does not sanitise and escape some parameters when outputting them in the page, which could allow unauthenticated users to perform Cross-Site Scripting attacks.

📅 Published: Dec. 10, 2024, 6 a.m. 🔄 Last Modified: May 17, 2025, 2:02 a.m.

4.9

CVSS3.1

CVE-2024-10708 - System Dashboard < 2.8.15 - Admin+ Path Traversal

The System Dashboard WordPress plugin before 2.8.15 does not validate user input used in a path, which could allow high privilege users such as admin to perform path traversal attacks an read arbitrary files on the server

📅 Published: Dec. 10, 2024, 6 a.m. 🔄 Last Modified: May 17, 2025, 2 a.m.

7.7

CVSS3.1

CVE-2023-6947 - Best WordPress Gallery Plugin – FooGallery <= 2.4.16 - Authenticated (Contributor+) Directory Trave…

The Best WordPress Gallery Plugin – FooGallery plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.4.26. This makes it possible for authenticated attackers, with contributor level or higher to read the contents of arbitrary folders on the server, which …

📅 Published: Dec. 10, 2024, 5:24 a.m. 🔄 Last Modified: April 8, 2026, 4:58 p.m.
Total resulsts: 349182
Page 7556 of 34,919
« previous page » next page
Filters