4.2

CVSS3.1

CVE-2024-5053 - Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder <= 5.1.18 - …

The Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder plugin for WordPress is vulnerable to unauthorized Malichimp API key update due to an insufficient capability check on the verifyRequest function in all versions up to, and including, 5.1.18. This makes it pos…

πŸ“… Published: Sept. 1, 2024, 10:58 a.m. πŸ”„ Last Modified: April 8, 2026, 5:03 p.m.

6.9

CVSS4.0

CVE-2024-8368 - code-projects Hospital Management System Login index.php sql injection

A vulnerability was found in code-projects Hospital Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file index.php of the component Login. The manipulation of the argument username leads to sql injection. The attack may be launched r…

πŸ“… Published: Sept. 1, 2024, 5 a.m. πŸ”„ Last Modified: Oct. 23, 2025, 8:06 p.m.

5.1

CVSS4.0

CVE-2024-8367 - HM Courts & Tribunals Service Probate Back Office Markdown NotificationService.java injection

A vulnerability was found in HM Courts & Tribunals Service Probate Back Office up to c1afe0cdb2b2766d9e24872c4e827f8b82a6cd31. It has been classified as problematic. Affected is an unknown function of the file src/main/java/uk/gov/hmcts/probate/service/NotificationService.java of the component Mark…

πŸ“… Published: Sept. 1, 2024, 4 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

9.1

CVSS3.1

CVE-2024-45522 -

Linen before cd37c3e does not verify that the domain is linen.dev or www.linen.dev when resetting a password. This occurs in create in apps/web/pages/api/forgot-password/index.ts.

πŸ“… Published: Sept. 1, 2024, midnight πŸ”„ Last Modified: Sept. 5, 2024, 2:29 p.m.

9.8

CVSS3.1

CVE-2024-45508 -

HTMLDOC before 1.9.19 has an out-of-bounds write in parse_paragraph in ps-pdf.cxx because of an attempt to strip leading whitespace from a whitespace-only node.

πŸ“… Published: Sept. 1, 2024, midnight πŸ”„ Last Modified: Sept. 4, 2024, 4:44 p.m.

9.8

CVSS3.1

CVE-2024-45509 -

In MISP through 2.4.196, app/Controller/BookmarksController.php does not properly restrict access to bookmarks data in the case where the user is not an org admin.

πŸ“… Published: Sept. 1, 2024, midnight πŸ”„ Last Modified: Sept. 4, 2024, 4:45 p.m.

6.9

CVSS4.0

CVE-2024-8366 - code-projects Pharmacy Management System Update My Profile Page index.php cross site scripting

A vulnerability was found in code-projects Pharmacy Management System 1.0. It has been classified as problematic. This affects an unknown part of the file /index.php?id=userProfileEdit of the component Update My Profile Page. The manipulation of the argument fname/lname/email with the input <script…

πŸ“… Published: Aug. 31, 2024, 6 p.m. πŸ”„ Last Modified: Sept. 4, 2024, 11:26 a.m.

5.3

CVSS3.1

CVE-2022-4539 - Web Application Firewall <= 2.1.2 - IP Address Spoofing to Protection Mechanism Bypass

The Web Application Firewall plugin for WordPress is vulnerable to IP Address Spoofing in versions up to, and including, 2.1.2. This is due to insufficient restrictions on where the IP Address information is being retrieved for request logging and login restrictions. Attackers can supply the X-Forw…

πŸ“… Published: Aug. 31, 2024, 9:35 a.m. πŸ”„ Last Modified: April 8, 2026, 4:35 p.m.

8.8

CVSS3.1

CVE-2024-7717 - WP Events Manager <= 2.1.11 - Authenticated (Subscriber+) Time-Based SQL Injection

The WP Events Manager plugin for WordPress is vulnerable to time-based SQL Injection via the β€˜order’ parameter in all versions up to, and including, 2.1.11 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possib…

πŸ“… Published: Aug. 31, 2024, 8:35 a.m. πŸ”„ Last Modified: April 8, 2026, 5:05 p.m.

5.3

CVSS3.1

CVE-2022-4536 - IP Vault – WP Firewall <= 1.1 - IP Address Spoofing to Protection Mechanism Bypass

The IP Vault – WP Firewall plugin for WordPress is vulnerable to IP Address Spoofing in versions up to, and including, 1.1. This is due to insufficient restrictions on where the IP Address information is being retrieved for request logging and login restrictions. Attackers can supply the X-Forwarde…

πŸ“… Published: Aug. 31, 2024, 8:35 a.m. πŸ”„ Last Modified: April 8, 2026, 4:58 p.m.
Total resulsts: 349182
Page 8689 of 34,919
Β« previous page Β» next page
Filters