5.4

CVSS3.1

CVE-2024-9860 - Bridge Core <= 3.3 - Missing Authorization to Authenticated (Subscriber+) Demo Import

The Bridge Core plugin for WordPress is vulnerable to unauthorized modification of data or loss of data due to a missing capability check on the 'import_action' and 'install_plugin_per_demo' functions in versions up to, and including, 3.3. This makes it possible for authenticated attackers with sub…

πŸ“… Published: Oct. 12, 2024, 2:05 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.1

CVSS3.1

CVE-2024-9592 - Easy PayPal Gift Certificate <= 1.2.3 - Cross-Site Request Forgery to Stored Cross-Site Scripting v…

The Easy PayPal Gift Certificate plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.2.3. This is due to missing or incorrect nonce validation on the 'wpppgc_plugin_options' function. This makes it possible for unauthenticated attackers to update the…

πŸ“… Published: Oct. 12, 2024, 2:05 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

0.0

CVE-2024-9899 -

** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2023-2143. Reason: This candidate is a reservation duplicate of CVE-2023-2143. Notes: All CVE users should reference CVE-2023-2143 instead of this candidate. All references and descriptions in this candidate have been removed to prevent…

πŸ“… Published: Oct. 12, 2024, 12:39 a.m. πŸ”„ Last Modified: Oct. 23, 2024, 9:15 p.m.

7.5

CVSS3.1

CVE-2024-49193 -

Zendesk before 2024-07-02 allows remote attackers to read ticket history via e-mail spoofing, because Cc fields are extracted from incoming e-mail messages and used to grant additional authorization for ticket viewing, the mechanism for detecting spoofed e-mail messages is insufficient, and the sup…

πŸ“… Published: Oct. 12, 2024, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.4

CVSS3.1

CVE-2024-38365 - btcd did not correctly re-implement Bitcoin Core's "FindAndDelete()" functionality

btcd is an alternative full node bitcoin implementation written in Go (golang). The btcd Bitcoin client (versions 0.10 to 0.24) did not correctly re-implement Bitcoin Core's "FindAndDelete()" functionality. This logic is consensus-critical: the difference in behavior with the other Bitcoin clients …

πŸ“… Published: Oct. 11, 2024, 7:32 p.m. πŸ”„ Last Modified: Aug. 20, 2025, 7:23 p.m.

2.4

CVSS4.0

CVE-2024-47884 - Insecure Temporary File in `foxmarks`

foxmarks is a CLI read-only interface for Firefox's bookmarks and history. A temporary file was created under the /tmp directory with read permissions for all users containing a copy of Firefox's database of bookmarks, history, input history, visits counter, use counter, view counter and more confi…

πŸ“… Published: Oct. 11, 2024, 7:15 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.5

CVSS3.1

CVE-2024-48041 - WordPress CM Tooltip Glossary plugin <= 4.3.9 - Stored Cross-Site Scripting vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CreativeMindsSolutions CM Tooltip Glossary enhanced-tooltipglossary allows Stored XSS.This issue affects CM Tooltip Glossary: from n/a through <= 4.3.9.

πŸ“… Published: Oct. 11, 2024, 6:27 p.m. πŸ”„ Last Modified: April 23, 2026, 3:19 p.m.

8.5

CVSS3.1

CVE-2024-48040 - WordPress Tainacan plugin <= 0.21.8 - SQL Injection vulnerability

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in tainacan Tainacan tainacan allows SQL Injection.This issue affects Tainacan: from n/a through <= 0.21.8.

πŸ“… Published: Oct. 11, 2024, 6:25 p.m. πŸ”„ Last Modified: April 23, 2026, 3:19 p.m.

8.9

CVSS4.0

CVE-2024-8912 - HTTP Request Smuggling in Looker

An HTTP Request Smuggling vulnerability in Looker allowed an unauthorized attacker to capture HTTP responses destined for legitimate users. There are two Looker versions that are hosted by Looker: * Looker (Google Cloud core) was found to be vulnerable. This issue has already been mitigated an…

πŸ“… Published: Oct. 11, 2024, 6:22 p.m. πŸ”„ Last Modified: July 30, 2025, 3:23 p.m.

9.8

CVSS3.1

CVE-2024-48033 - WordPress Talkback plugin <= 1.0 - PHP Object Injection vulnerability

Deserialization of Untrusted Data vulnerability in baptiste.gourdin Talkback talkback-secure-linkback-protocol allows Object Injection.This issue affects Talkback: from n/a through <= 1.0.

πŸ“… Published: Oct. 11, 2024, 6:22 p.m. πŸ”„ Last Modified: April 23, 2026, 3:19 p.m.
Total resulsts: 349182
Page 8309 of 34,919
Β« previous page Β» next page
Filters