5.3

CVSS3.1

CVE-2024-10040 - Infinite-Scroll <= 2.6.2 - Cross-Site Request Forgery to Plugin Settings Update

The Infinite-Scroll plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.6.2. This is due to missing or incorrect nonce validation on the process_ajax_edit and process_ajax_delete function. This makes it possible for unauthenticated attackers to m…

πŸ“… Published: Oct. 18, 2024, 4:32 a.m. πŸ”„ Last Modified: April 8, 2026, 4:48 p.m.

6.1

CVSS3.1

CVE-2024-10049 - Edit WooCommerce Templates <= 1.1.2 - Reflected Cross-Site Scripting via page

The Edit WooCommerce Templates plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the β€˜page’ parameter in all versions up to, and including, 1.1.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitra…

πŸ“… Published: Oct. 18, 2024, 4:32 a.m. πŸ”„ Last Modified: April 8, 2026, 4:46 p.m.

6.1

CVSS3.1

CVE-2024-8790 - Social Share With Floating Bar <= 1.0.3 - Reflected Cross-Site Scripting

The Social Share With Floating Bar plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 1.0.3. This makes it possible for unauthenticated attackers to inject arbitrary web s…

πŸ“… Published: Oct. 18, 2024, 4:32 a.m. πŸ”„ Last Modified: April 8, 2026, 4:44 p.m.

6.4

CVSS3.1

CVE-2024-8916 - Suki Sites Import <= 1.2.1 - Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload

The Suki Sites Import plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.2.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above…

πŸ“… Published: Oct. 18, 2024, 4:32 a.m. πŸ”„ Last Modified: April 8, 2026, 4:39 p.m.

6.4

CVSS3.1

CVE-2024-9848 - Product Customizer Light <= 1.0.0 - Authenticated (Author+) Stored Cross-Site Scripting via SVG Fil…

The Product Customizer Light plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.0.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access an…

πŸ“… Published: Oct. 18, 2024, 4:32 a.m. πŸ”„ Last Modified: April 8, 2026, 4:37 p.m.

9.8

CVSS3.1

CVE-2024-10119 - SECOM WRTM326 - OS Command Injection

The wireless router WRTM326 from SECOM does not properly validate a specific parameter. An unauthenticated remote attacker could execute arbitrary system commands by sending crafted requests.

πŸ“… Published: Oct. 18, 2024, 4:09 a.m. πŸ”„ Last Modified: Nov. 1, 2024, 6:40 p.m.

9.8

CVSS3.1

CVE-2024-10118 - SECOM WRTR-304GN-304TW-UPSC - OS Command Injection

SECOM WRTR-304GN-304TW-UPSC does not properly filter user input in the specific functionality. Unauthenticated remote attackers can exploit this vulnerability to inject and execute arbitrary system commands on the device.

πŸ“… Published: Oct. 18, 2024, 4:03 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

9.4

CVSS4.0

CVE-2024-9264 - Grafana SQL Expressions allow for remote code execution

The SQL Expressions experimental feature of Grafana allows for the evaluation of `duckdb` queries containing user input. These queries are insufficiently sanitized before being passed to `duckdb`, leading to a command injection and local file inclusion vulnerability. Any user with the VIEWER or hig…

πŸ“… Published: Oct. 18, 2024, 3:20 a.m. πŸ”„ Last Modified: March 14, 2025, 10:15 a.m.

4.7

CVSS3.1

CVE-2024-10041 - Pam: libpam: libpam vulnerable to read hashed password

A vulnerability was found in PAM. The secret information is stored in memory, where the attacker can trigger the victim program to execute by sending characters to its standard input (stdin). As this occurs, the attacker can train the branch predictor to execute an ROP chain speculatively. This fla…

πŸ“… Published: Oct. 18, 2024, midnight πŸ”„ Last Modified: Nov. 20, 2025, 6:11 p.m.

9.8

CVSS3.1

CVE-2024-45944 -

In J2eeFAST <=2.7, the backend function has unsafe filtering, which allows an attacker to trigger certain sensitive functions resulting in arbitrary code execution.

πŸ“… Published: Oct. 18, 2024, midnight πŸ”„ Last Modified: April 16, 2025, 3:04 p.m.
Total resulsts: 349182
Page 8243 of 34,919
Β« previous page Β» next page
Filters