7.8

CVSS3.1

CVE-2024-5998 - Deserialization of Untrusted Data in langchain-ai/langchain

A vulnerability in the FAISS.deserialize_from_bytes function of langchain-ai/langchain allows for pickle deserialization of untrusted data. This can lead to the execution of arbitrary commands via the os.system function. The issue affects the latest version of the product.

πŸ“… Published: Sept. 17, 2024, 11:50 a.m. πŸ”„ Last Modified: July 30, 2025, 4:22 p.m.

9.9

CVSS3.0

CVE-2024-8767 -

Sensitive data disclosure and manipulation due to unnecessary privileges assignment. The following products are affected: Acronis Backup plugin for cPanel & WHM (Linux) before build 619, Acronis Backup extension for Plesk (Linux) before build 555, Acronis Backup plugin for DirectAdmin (Linux) befor…

πŸ“… Published: Sept. 17, 2024, 8:51 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.2

CVSS3.1

CVE-2024-8761 - Share This Image <= 2.03 - Open Redirect via link Parameter

The Share This Image plugin for WordPress is vulnerable to Open Redirect in all versions up to, and including, 2.03. This is due to insufficient validation on the redirect url supplied via the link parameter. This makes it possible for unauthenticated attackers to redirect users to potentially mali…

πŸ“… Published: Sept. 17, 2024, 8:30 a.m. πŸ”„ Last Modified: April 8, 2026, 4:40 p.m.

8.8

CVSS3.1

CVE-2024-8490 - PropertyHive <= 2.0.19 - Cross-Site Request Forgery via save_account_details

The PropertyHive plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.0.19. This is due to missing or incorrect nonce validation on the 'save_account_details' function. This makes it possible for unauthenticated attackers to edit the name, email a…

πŸ“… Published: Sept. 17, 2024, 7:33 a.m. πŸ”„ Last Modified: April 8, 2026, 4:37 p.m.

4.8

CVSS3.1

CVE-2024-8093 - Posts reminder <= 0.20 - Settings Update via CSRF

The Posts reminder WordPress plugin through 0.20 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack

πŸ“… Published: Sept. 17, 2024, 6 a.m. πŸ”„ Last Modified: Sept. 27, 2024, 6:16 p.m.

5.4

CVSS3.1

CVE-2024-8092 - Accordion Image Menu <= 3.1.3 - Stored XSS via CSRF

The Accordion Image Menu WordPress plugin through 3.1.3 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack.

πŸ“… Published: Sept. 17, 2024, 6 a.m. πŸ”„ Last Modified: Sept. 27, 2024, 6:17 p.m.

4.8

CVSS3.1

CVE-2024-8091 - Enhanced Search Box <= 0.6.1 - Settings Update via CSRF

The Enhanced Search Box WordPress plugin through 0.6.1 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack

πŸ“… Published: Sept. 17, 2024, 6 a.m. πŸ”„ Last Modified: Sept. 27, 2024, 6:17 p.m.

4.8

CVSS3.1

CVE-2024-8052 - Review Ratings <= 1.6 - Stored XSS via CSRF

The Review Ratings WordPress plugin through 1.6 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack.

πŸ“… Published: Sept. 17, 2024, 6 a.m. πŸ”„ Last Modified: Sept. 27, 2024, 4:55 p.m.

5.7

CVSS3.1

CVE-2024-8051 - Special Feed Items <= 1.0.1 - Stored XSS via CSRF

The Special Feed Items WordPress plugin through 1.0.1 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack.

πŸ“… Published: Sept. 17, 2024, 6 a.m. πŸ”„ Last Modified: Sept. 27, 2024, 6:19 p.m.

5.7

CVSS3.1

CVE-2024-8047 - Visual Sound (old) <= 1.06 - Settings Update via CSRF

The Visual Sound (old) WordPress plugin through 1.06 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack

πŸ“… Published: Sept. 17, 2024, 6 a.m. πŸ”„ Last Modified: Jan. 23, 2026, 7:29 p.m.
Total resulsts: 349182
Page 8543 of 34,919
Β« previous page Β» next page
Filters