7.2

CVSS3.1

CVE-2022-2440 - Theme Editor <= 2.8 - Authenticated (Admin+) PHAR Deserialization

The Theme Editor plugin for WordPress is vulnerable to deserialization of untrusted input via the 'images_array' parameter in versions up to, and including 2.8. This makes it possible for authenticated attackers with administrative privileges to call files using a PHAR wrapper that will deserialize…

πŸ“… Published: Aug. 29, 2024, 3:30 a.m. πŸ”„ Last Modified: April 8, 2026, 5:05 p.m.

5.3

CVSS3.1

CVE-2024-5857 - Interactive Contact Form and Multi Step Form Builder with Drag & Drop Editor – Funnelforms Free <= …

The Interactive Contact Form and Multi Step Form Builder with Drag & Drop Editor – Funnelforms Free plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the af2_handel_file_remove AJAX action in all versions up to, and including, 3.7.3.2. This makes i…

πŸ“… Published: Aug. 29, 2024, 3:30 a.m. πŸ”„ Last Modified: April 8, 2026, 4:55 p.m.

3.1

CVSS3.1

CVE-2024-41918 -

'Rakuten Ichiba App' for Android 12.4.0 and earlier and 'Rakuten Ichiba App' for iOS 11.7.0 and earlier are vulnerable to improper authorization in handler for custom URL scheme. An arbitrary site may be displayed on the WebView of the product via Intent from another application installed on the us…

πŸ“… Published: Aug. 29, 2024, 2:47 a.m. πŸ”„ Last Modified: Aug. 30, 2024, 4:05 p.m.

6.5

CVSS3.1

CVE-2024-7857 - Media Library Folders <= 8.2.2 - Authenticated (Subscriber+) Second-Order SQL Injection

The Media Library Folders plugin for WordPress is vulnerable to second order SQL Injection via the 'sort_type' parameter of the 'mlf_change_sort_type' AJAX action in all versions up to, and including, 8.2.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparati…

πŸ“… Published: Aug. 29, 2024, 2:31 a.m. πŸ”„ Last Modified: April 8, 2026, 7:22 p.m.

6.5

CVSS3.1

CVE-2024-44930 -

Serilog before v2.1.0 was discovered to contain a Client IP Spoofing vulnerability, which allows attackers to falsify their IP addresses by specifying an arbitrary IP as a value of X-Forwarded-For or Client-Ip headers while performing HTTP requests.

πŸ“… Published: Aug. 29, 2024, midnight πŸ”„ Last Modified: March 14, 2025, 4:15 p.m.

6.1

CVSS3.1

CVE-2024-41350 -

bjyadmin commit a560fd5 is vulnerable to Cross Site Scripting (XSS) via Public/statics/umeditor1_2_3/php/imageUp.php

πŸ“… Published: Aug. 29, 2024, midnight πŸ”„ Last Modified: Sept. 4, 2024, 4:07 p.m.

9.8

CVSS3.1

CVE-2024-45435 -

Chartist 1.x through 1.3.0 allows Prototype Pollution via the extend function.

πŸ“… Published: Aug. 29, 2024, midnight πŸ”„ Last Modified: Sept. 3, 2024, 5:23 p.m.

9.8

CVSS3.1

CVE-2024-41367 -

RPi-Jukebox-RFID v2.7.0 was discovered to contain a remote code execution (RCE) vulnerability via htdocs\api\playlist\appendFileToPlaylist.php

πŸ“… Published: Aug. 29, 2024, midnight πŸ”„ Last Modified: Sept. 4, 2024, 4:29 p.m.

9.8

CVSS3.1

CVE-2024-41370 -

Organizr v1.90 was discovered to contain a SQL injection vulnerability via chat/setlike.php.

πŸ“… Published: Aug. 29, 2024, midnight πŸ”„ Last Modified: Sept. 4, 2024, 4:08 p.m.

9.1

CVSS3.1

CVE-2024-45436 -

extractFromZipFile in model.go in Ollama before 0.1.47 can extract members of a ZIP archive outside of the parent directory.

πŸ“… Published: Aug. 29, 2024, midnight πŸ”„ Last Modified: Aug. 30, 2024, 4:08 p.m.
Total resulsts: 349182
Page 8708 of 34,919
Β« previous page Β» next page
Filters