7.1

CVSS3.1

CVE-2024-39631 - WordPress Contest Gallery plugin <= 23.1.2 - Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Wasiliy Strecker / ContestGallery developer Contest Gallery contest-gallery.This issue affects Contest Gallery: from n/a through <= 23.1.2.

πŸ“… Published: Aug. 1, 2024, 10:27 p.m. πŸ”„ Last Modified: April 23, 2026, 3:18 p.m.

5.8

CVSS3.1

CVE-2024-39643 - WordPress RegistrationMagic plugin <= 6.0.0.1 - Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in RegistrationMagic Forms RegistrationMagic allows Stored XSS.This issue affects RegistrationMagic: from n/a through 6.0.0.1.

πŸ“… Published: Aug. 1, 2024, 10:24 p.m. πŸ”„ Last Modified: Sept. 11, 2024, 5:33 p.m.

6.5

CVSS3.1

CVE-2024-39644 - WordPress Black Widgets For Elementor plugin <= 1.3.5 - Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Modernaweb Studio Black Widgets For Elementor allows Stored XSS.This issue affects Black Widgets For Elementor: from n/a through 1.3.5.

πŸ“… Published: Aug. 1, 2024, 10:17 p.m. πŸ”„ Last Modified: Sept. 11, 2024, 5:31 p.m.

7.1

CVSS3.1

CVE-2024-39646 - WordPress Custom 404 Pro plugin <= 3.11.1 - Reflected Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Kunal Custom 404 Pro custom-404-pro.This issue affects Custom 404 Pro: from n/a through <= 3.11.1.

πŸ“… Published: Aug. 1, 2024, 10:11 p.m. πŸ”„ Last Modified: April 23, 2026, 3:18 p.m.

7.1

CVSS3.1

CVE-2024-39647 - WordPress Message Filter for Contact Form 7 plugin <= 1.6.1.1 - Cross Site Scripting (XSS) vulnerab…

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Kofi Mokome Message Filter for Contact Form 7 cf7-message-filter.This issue affects Message Filter for Contact Form 7: from n/a through <= 1.6.1.1.

πŸ“… Published: Aug. 1, 2024, 10:09 p.m. πŸ”„ Last Modified: April 23, 2026, 3:18 p.m.

8.1

CVSS3.1

CVE-2024-41956 - Soft Serve allows arbitrary code execution by crafting git-lfs requests

Soft Serve is a self-hostable Git server for the command line. Prior to 0.7.5, it is possible for a user who can commit files to a repository hosted by Soft Serve to execute arbitrary code via environment manipulation and Git. The issue is that Soft Serve passes all environment variables given by t…

πŸ“… Published: Aug. 1, 2024, 10:07 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

3

CVSS3.1

CVE-2024-41948 - biscuit-java vulnerable to public key confusion in third party block

biscuit-java is the java implementation of Biscuit, an authentication and authorization token for microservices architectures. Third-party blocks can be generated without transferring the whole token to the third-party authority. Instead, a ThirdPartyBlock request can be sent, providing only the ne…

πŸ“… Published: Aug. 1, 2024, 10:03 p.m. πŸ”„ Last Modified: Aug. 9, 2024, 6:38 p.m.

3

CVSS3.1

CVE-2024-41949 - biscuit-rust vulnerable to public key confusion in third party block

biscuit-rust is the Rust implementation of Biscuit, an authentication and authorization token for microservices architectures. Third-party blocks can be generated without transferring the whole token to the third-party authority. Instead, a ThirdPartyBlock request can be sent, providing only the ne…

πŸ“… Published: Aug. 1, 2024, 10:03 p.m. πŸ”„ Last Modified: Aug. 9, 2024, 6:32 p.m.

6.9

CVSS4.0

CVE-2024-7369 - SourceCodester Simple Realtime Quiz System Login ajax.php sql injection

A vulnerability was found in SourceCodester Simple Realtime Quiz System 1.0 and classified as critical. This issue affects some unknown processing of the file /ajax.php?action=login of the component Login. The manipulation of the argument username leads to sql injection. The attack may be initiated…

πŸ“… Published: Aug. 1, 2024, 10 p.m. πŸ”„ Last Modified: Aug. 7, 2024, 7:03 p.m.

6.8

CVSS3.1

CVE-2024-32862 - exacqVision CORS

Under certain circumstances the ExacqVision Web Services does not provide sufficient protection from untrusted domains.

πŸ“… Published: Aug. 1, 2024, 9:57 p.m. πŸ”„ Last Modified: Aug. 9, 2024, 6:55 p.m.
Total resulsts: 349182
Page 8971 of 34,919
Β« previous page Β» next page
Filters