6.4

CVSS3.1

CVE-2024-10055 - Click to Chat – WP Support All-in-One Floating Widget <= 2.3.3 - Authenticated (Contributor+) Store…

The Click to Chat – WP Support All-in-One Floating Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wpsaio_snapchat shortcode in all versions up to, and including, 2.3.3 due to insufficient input sanitization and output escaping on user supplied attributes. …

📅 Published: Oct. 18, 2024, 7:35 a.m. 🔄 Last Modified: April 8, 2026, 7:19 p.m.

6.4

CVSS3.1

CVE-2024-10080 - WP Easy Post Types <= 1.4.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via Post Meta

The WP Easy Post Types plugin for WordPress is vulnerable to Stored Cross-Site Scripting via post meta in versions up to, and including, 1.4.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-…

📅 Published: Oct. 18, 2024, 7:35 a.m. 🔄 Last Modified: April 8, 2026, 4:38 p.m.

8.6

CVSS4.0

CVE-2023-6056 - Insecure Trust of Self-Signed Certificates in Bitdefender Total Security HTTPS Scanning (VA-11164)

A vulnerability has been discovered in Bitdefender Total Security HTTPS scanning functionality that results in the improper trust of self-signed certificates. The product is found to trust certificates signed with the RIPEMD-160 hashing algorithm without proper validation, allowing an attacker to e…

📅 Published: Oct. 18, 2024, 7:31 a.m. 🔄 Last Modified: Oct. 22, 2024, 4:38 p.m.

8.6

CVSS4.0

CVE-2023-6055 - Improper Certificate Validation in Bitdefender Total Security HTTPS Scanning (VA-11158)

A vulnerability has been identified in Bitdefender Total Security HTTPS scanning functionality where the software fails to properly validate website certificates. Specifically, if a site certificate lacks the "Server Authentication" specification in the Extended Key Usage extension, the product doe…

📅 Published: Oct. 18, 2024, 7:17 a.m. 🔄 Last Modified: Oct. 22, 2024, 4:39 p.m.

6.4

CVSS3.1

CVE-2024-9703 - Arconix Shortcodes <= 2.1.12 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortco…

The Arconix Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'button' shortcode in all versions up to, and including, 2.1.12 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated …

📅 Published: Oct. 18, 2024, 6:51 a.m. 🔄 Last Modified: April 8, 2026, 5:31 p.m.

6.1

CVSS3.1

CVE-2024-9206 - MAS Companies For WP Job Manager <= 1.0.13 - Reflected Cross-Site Scripting

The MAS Companies For WP Job Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 1.0.13. This makes it possible for unauthenticated attackers to inject arbitrary we…

📅 Published: Oct. 18, 2024, 6:51 a.m. 🔄 Last Modified: April 8, 2026, 5:27 p.m.

5.4

CVSS3.1

CVE-2024-47793 -

Stored cross-site scripting vulnerability exists in Exment v6.1.4 and earlier and Exment v5.0.11 and earlier. When accessing the edit screen containing custom columns (column type: images or files), an arbitrary script may be executed on the web browser of the user.

📅 Published: Oct. 18, 2024, 6:05 a.m. 🔄 Last Modified: Oct. 21, 2024, 9:25 p.m.

3.8

CVSS3.1

CVE-2024-46897 -

Incorrect permission assignment for critical resource issue exists in Exment v6.1.4 and earlier and Exment v5.0.11 and earlier. A logged-in user with the permission of table management may obtain and/or alter the information of the unauthorized table.

📅 Published: Oct. 18, 2024, 6:03 a.m. 🔄 Last Modified: Oct. 22, 2024, 2:09 p.m.

3.1

CVSS3.1

CVE-2024-38820 - CVE-2024-38820: Spring Framework DataBinder Case Sensitive Match Exception

The fix for CVE-2022-22968 made disallowedFields patterns in DataBinder case insensitive. However, String.toLowerCase() has some Locale dependent exceptions that could potentially result in fields not protected as expected.

📅 Published: Oct. 18, 2024, 5:39 a.m. 🔄 Last Modified: Nov. 29, 2024, 12:15 p.m.

6.4

CVSS3.1

CVE-2024-9366 - Easy Menu Manager | WPZest <= 1.0.1 - Authenticated (Author+) Stored Cross-Site Scripting via SVG F…

The Easy Menu Manager | WPZest plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.0.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access …

📅 Published: Oct. 18, 2024, 4:32 a.m. 🔄 Last Modified: April 8, 2026, 5:33 p.m.
Total resulsts: 349182
Page 8241 of 34,919
« previous page » next page
Filters