7.1

CVSS3.1

CVE-2024-43304 - WordPress Cryptocurrency Widgets plugin <= 2.8.0 - Reflected Cross Site Scripting (XSS) vulnerabiliโ€ฆ

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Cool Plugins Cryptocurrency Widgets โ€“ Price Ticker & Coins List allows Reflected XSS.This issue affects Cryptocurrency Widgets โ€“ Price Ticker & Coins List: from n/a through 2.8.0.

๐Ÿ“… Published: Aug. 18, 2024, 9:07 p.m. ๐Ÿ”„ Last Modified: March 18, 2025, 3:29 p.m.

5.3

CVSS4.0

CVE-2024-7911 - SourceCodester Simple Online Bidding System index.php file inclusion

A vulnerability was found in SourceCodester Simple Online Bidding System 1.0. It has been classified as critical. This affects an unknown part of the file /simple-online-bidding-system/bidding/index.php. The manipulation of the argument page leads to file inclusion. It is possible to initiate the aโ€ฆ

๐Ÿ“… Published: Aug. 18, 2024, 7:31 p.m. ๐Ÿ”„ Last Modified: Aug. 19, 2024, 6:48 p.m.

7.5

CVSS3.1

CVE-2024-6221 - Improper Access Control in corydolphin/flask-cors

A vulnerability in corydolphin/flask-cors version 4.0.1 allows the `Access-Control-Allow-Private-Network` CORS header to be set to true by default. This behavior can expose private network resources to unauthorized external access, leading to significant security risks such as data breaches, unauthโ€ฆ

๐Ÿ“… Published: Aug. 18, 2024, 6:58 p.m. ๐Ÿ”„ Last Modified: April 7, 2025, 3:15 p.m.

5.1

CVSS4.0

CVE-2024-7910 - CodeAstro Online Railway Reservation System Profile Photo Update emp-profile-avatar.php unrestricteโ€ฆ

A vulnerability was found in CodeAstro Online Railway Reservation System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /admin/emp-profile-avatar.php of the component Profile Photo Update Handler. The manipulation leads to unrestricted upload. The aโ€ฆ

๐Ÿ“… Published: Aug. 18, 2024, 6:31 p.m. ๐Ÿ”„ Last Modified: Aug. 19, 2024, 6:49 p.m.

8.7

CVSS4.0

CVE-2024-7909 - TOTOLINK EX1200L cstecgi.cgi setLanguageCfg stack-based overflow

A vulnerability has been found in TOTOLINK EX1200L 9.3.5u.6146_B20201023 and classified as critical. Affected by this vulnerability is the function setLanguageCfg of the file /www/cgi-bin/cstecgi.cgi. The manipulation of the argument langType leads to stack-based buffer overflow. The attack can be โ€ฆ

๐Ÿ“… Published: Aug. 18, 2024, 6 p.m. ๐Ÿ”„ Last Modified: Aug. 21, 2024, 7:15 p.m.

8.7

CVSS4.0

CVE-2024-7908 - TOTOLINK EX1200L cstecgi.cgi setDefResponse stack-based overflow

A vulnerability, which was classified as critical, was found in TOTOLINK EX1200L 9.3.5u.6146_B20201023. Affected is the function setDefResponse of the file /www/cgi-bin/cstecgi.cgi. The manipulation of the argument IpAddress leads to stack-based buffer overflow. It is possible to launch the attack โ€ฆ

๐Ÿ“… Published: Aug. 18, 2024, 5 p.m. ๐Ÿ”„ Last Modified: Aug. 19, 2024, 6:51 p.m.

5.3

CVSS4.0

CVE-2024-7907 - TOTOLINK X6000R cstecgi.cgi setSyslogCfg command injection

A vulnerability, which was classified as critical, has been found in TOTOLINK X6000R 9.4.0cu.852_20230719. This issue affects the function setSyslogCfg of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument rtLogServer leads to command injection. The attack may be initiated remotely. Thโ€ฆ

๐Ÿ“… Published: Aug. 18, 2024, 4 p.m. ๐Ÿ”„ Last Modified: Aug. 19, 2024, 6:53 p.m.

6.5

CVSS3.1

CVE-2024-43305 - WordPress Custom Layouts โ€“ Post + Product grids made easy plugin <= 1.4.11 - Cross Site Scripting (โ€ฆ

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Code Amp Custom Layouts โ€“ Post + Product grids made easy allows Stored XSS.This issue affects Custom Layouts โ€“ Post + Product grids made easy: from n/a through 1.4.11.

๐Ÿ“… Published: Aug. 18, 2024, 2:23 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.1

CVSS3.1

CVE-2024-43306 - WordPress WP-Lister Lite for eBay plugin <= 3.6.0 - Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Lab WP-Lister Lite for eBay wp-lister-for-ebay.This issue affects WP-Lister Lite for eBay: from n/a through <= 3.6.0.

๐Ÿ“… Published: Aug. 18, 2024, 2:22 p.m. ๐Ÿ”„ Last Modified: April 23, 2026, 3:18 p.m.

6.5

CVSS3.1

CVE-2024-43307 - WordPress Structured Content (JSON-LD) #wpsc plugin <= 1.6.2 - Cross Site Scripting (XSS) vulnerabiโ€ฆ

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Gordon Bรถhme, Antonio Leutsch Structured Content allows Stored XSS.This issue affects Structured Content: from n/a through 1.6.2.

๐Ÿ“… Published: Aug. 18, 2024, 2:20 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 349182
Page 8810 of 34,919
ยซ previous page ยป next page
Filters