5.4

CVSS3.1

CVE-2024-3026 - WordPress Button Plugin MaxButtons < 9.7.8 - Editor+ Stored XSS

The WordPress Button Plugin MaxButtons WordPress plugin before 9.7.8 does not sanitise and escape some parameters, which could allow users with a role as low as editor to perform Cross-Site Scripting attacks

πŸ“… Published: July 13, 2024, 6 a.m. πŸ”„ Last Modified: May 15, 2025, 6:46 p.m.

6.1

CVSS3.1

CVE-2024-2870 - Swift Framework < 2024.04.30 - Reflected XSS

The socialdriver-framework WordPress plugin before 2024.04.30 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

πŸ“… Published: July 13, 2024, 6 a.m. πŸ”„ Last Modified: June 4, 2025, 4:16 p.m.

5.3

CVSS3.1

CVE-2024-6574 - Laposta <= 1.12 - Unauthenticated Full Path Disclosure

The Laposta plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 1.12. This is due to the plugin not preventing direct access to several test files. This makes it possible for unauthenticated attackers to retrieve the full path of the web application, whi…

πŸ“… Published: July 13, 2024, 5:38 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.2

CVSS3.1

CVE-2024-5902 - UserFeedback Lite <= 1.0.15 - Unauthenticated Stored Cross-Site Scripting via Name Parameter

The User Feedback – Create Interactive Feedback Form, User Surveys, and Polls in Seconds plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the name parameter in all versions up to, and including, 1.0.15 due to insufficient input sanitization and output escaping. This makes it po…

πŸ“… Published: July 12, 2024, 9:30 p.m. πŸ”„ Last Modified: April 8, 2026, 7:22 p.m.

0.0

CVE-2024-6721 -

** REJECT ** DO NOT USE THIS CVE RECORD. Consult IDs: CVE-2024-5324. Reason: This record is a reservation duplicate of CVE-2024-5324. Notes: All CVE users should referenceΒ CVE-2024-5324 instead of this record. All references and descriptions in this record have been removed to prevent accidental u…

πŸ“… Published: July 12, 2024, 8:30 p.m. πŸ”„ Last Modified: July 15, 2024, 4:15 p.m.

3.1

CVSS3.1

CVE-2023-41093 - Loss of confidentiality due to potential race condition in Bluetooth controller Connection_Handle r…

Use After Free vulnerability in Silicon Labs Bluetooth SDK on 32 bit, ARM may allow an attacker with precise timing capabilities to intercept a small number of packets intended for a recipient that has left the network.This issue affects Silabs Bluetooth SDK: through 8.0.0.

πŸ“… Published: July 12, 2024, 7:56 p.m. πŸ”„ Last Modified: Sept. 25, 2025, 8:25 p.m.

5.4

CVSS3.1

CVE-2024-40690 - IBM InfoSphere Server cross-site scripting

IBM InfoSphere Server 11.7 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 29772…

πŸ“… Published: July 12, 2024, 5:47 p.m. πŸ”„ Last Modified: Nov. 21, 2024, 9:31 a.m.

6.5

CVSS3.0

CVE-2024-37405 -

Livechat messages can be leaked by combining two NoSQL injections affecting livechat:loginByToken (pre-authentication) and livechat:loadHistory.

πŸ“… Published: July 12, 2024, 3:41 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.2

CVSS3.1

CVE-2024-39917 - xrdp allows an ininite number of login attempts

xrdp is an open source RDP server. xrdp versions prior to 0.10.0 have a vulnerability that allows attackers to make an infinite number of login attempts. The number of max login attempts is supposed to be limited by a configuration parameter `MaxLoginRetry` in `/etc/xrdp/sesman.ini`. However, this…

πŸ“… Published: July 12, 2024, 3:24 p.m. πŸ”„ Last Modified: Nov. 3, 2025, 8:16 p.m.

9.1

CVSS3.1

CVE-2024-38736 - WordPress Realtyna Organic IDX plugin <= 4.14.13 - Arbitrary File Upload vulnerability

Unrestricted Upload of File with Dangerous Type vulnerability in Realtyna Realtyna Organic IDX plugin allows Code Injection.This issue affects Realtyna Organic IDX plugin: from n/a through 4.14.13.

πŸ“… Published: July 12, 2024, 3:21 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 344690
Page 8710 of 34,469
Β« previous page Β» next page
Filters