6.5

CVSS3.1

CVE-2024-1747 - WooCommerce Customers Manager < 30.2 - Subscriber+ Stored XSS

The WooCommerce Customers Manager WordPress plugin before 30.2 does not have authorisation and CSRF in various AJAX actions, allowing any authenticated users, such as subscriber, to call them and update/delete/create customer metadata, also leading to Stored Cross-Site Scripting due to the lack of …

πŸ“… Published: Aug. 1, 2024, 6 a.m. πŸ”„ Last Modified: May 29, 2025, 5:23 p.m.

5.3

CVSS4.0

CVE-2024-7343 - Baidu UEditor cross site scripting

A vulnerability was found in Baidu UEditor 1.4.2. It has been declared as problematic. This vulnerability affects unknown code of the file /ueditor142/php/controller.php?action=catchimage. The manipulation of the argument source[] leads to cross site scripting. The attack can be initiated remotely.…

πŸ“… Published: Aug. 1, 2024, 5 a.m. πŸ”„ Last Modified: Aug. 15, 2024, 6:40 p.m.

5.3

CVSS4.0

CVE-2024-7342 - Baidu UEditor unrestricted upload

A vulnerability was found in Baidu UEditor 1.4.3.3. It has been classified as problematic. This affects an unknown part of the file /ueditor/php/controller.php?action=uploadfile&encode=utf-8. The manipulation of the argument upfile leads to unrestricted upload. It is possible to initiate the attack…

πŸ“… Published: Aug. 1, 2024, 4:31 a.m. πŸ”„ Last Modified: Aug. 15, 2024, 6:40 p.m.

6.4

CVSS3.1

CVE-2024-2090 - Remote Content Shortcode <= 1.5 - Authenticated (Contributor+) Server-Side Request Forgery

The Remote Content Shortcode plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.5 via the remote_content shortcode. This makes it possible for authenticated attackers, with contributor-level access and above, to make web requests to arbitrary l…

πŸ“… Published: Aug. 1, 2024, 4:29 a.m. πŸ”„ Last Modified: April 8, 2026, 5:31 p.m.

6.9

CVSS4.0

CVE-2024-7339 - TVT DVR TD-2104TS-CL queryDevInfo information disclosure

A vulnerability has been found in TVT DVR TD-2104TS-CL, DVR TD-2108TS-HP, Provision-ISR DVR SH-4050A5-5L(MM) and AVISION DVR AV108T and classified as problematic. This vulnerability affects unknown code of the file /queryDevInfo. The manipulation leads to information disclosure. The attack can be i…

πŸ“… Published: Aug. 1, 2024, 4 a.m. πŸ”„ Last Modified: Dec. 20, 2024, 5:37 p.m.

0.0

CVE-2024-1715 -

** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2024-34802. Reason: This candidate is a duplicate of CVE-2024-34802. Notes: All CVE users should reference CVE-2024-34802 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accident…

πŸ“… Published: Aug. 1, 2024, 3:49 a.m. πŸ”„ Last Modified: Aug. 2, 2024, 3:16 p.m.

8.7

CVSS4.0

CVE-2024-7338 - TOTOLINK EX1200L cstecgi.cgi setParentalRules buffer overflow

A vulnerability, which was classified as critical, was found in TOTOLINK EX1200L 9.3.5u.6146_B20201023. This affects the function setParentalRules of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument week/sTime/eTime leads to buffer overflow. It is possible to initiate the attack remo…

πŸ“… Published: Aug. 1, 2024, 3:31 a.m. πŸ”„ Last Modified: Aug. 9, 2024, 2:51 p.m.

8.8

CVSS3.1

CVE-2024-6698 - FundEngine – Donation and Crowdfunding Platform <= 1.7.0 - Authenticated (Subscriber+) Privilege Es…

The FundEngine plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.7.0. This is due to the plugin not properly verifying user meta updated through the update_user_meta function. This makes it possible for authenticated attackers, with subscriber-level …

πŸ“… Published: Aug. 1, 2024, 3:29 a.m. πŸ”„ Last Modified: April 8, 2026, 4:44 p.m.

8.7

CVSS4.0

CVE-2024-7337 - TOTOLINK EX1200L cstecgi.cgi loginauth buffer overflow

A vulnerability, which was classified as critical, has been found in TOTOLINK EX1200L 9.3.5u.6146_B20201023. Affected by this issue is the function loginauth of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument http_host leads to buffer overflow. The attack may be launched remotely. T…

πŸ“… Published: Aug. 1, 2024, 3 a.m. πŸ”„ Last Modified: Aug. 9, 2024, 2:15 p.m.

8.7

CVSS4.0

CVE-2024-7336 - TOTOLINK EX200 cstecgi.cgi loginauth buffer overflow

A vulnerability classified as critical was found in TOTOLINK EX200 4.0.3c.7646_B20201211. Affected by this vulnerability is the function loginauth of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument http_host leads to buffer overflow. The attack can be launched remotely. The exploit …

πŸ“… Published: Aug. 1, 2024, 2:31 a.m. πŸ”„ Last Modified: Aug. 9, 2024, 2:38 p.m.
Total resulsts: 349182
Page 8981 of 34,919
Β« previous page Β» next page
Filters