8.8

CVSS3.1

CVE-2024-3242 - Brizy โ€“ Page Builder <= 2.4.44 - Authenticated (Contributor+) Arbitrary File Upload

The Brizy โ€“ Page Builder plugin for WordPress is vulnerable to arbitrary file uploads due to missing file extension validation in the validateImageContent function called via storeImages in all versions up to, and including, 2.4.43. This makes it possible for authenticated attackers, with contributโ€ฆ

๐Ÿ“… Published: July 18, 2024, 8:33 a.m. ๐Ÿ”„ Last Modified: April 8, 2026, 7:21 p.m.

6.4

CVSS3.1

CVE-2024-5554 - Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrโ€ฆ

The Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the โ€˜onclick_eventโ€™ parameter in all versions up to, and including, 5.6.11 due to insufficient input sanitization and outโ€ฆ

๐Ÿ“… Published: July 18, 2024, 8:33 a.m. ๐Ÿ”„ Last Modified: April 8, 2026, 6:22 p.m.

7.5

CVSS3.1

CVE-2024-40764 -

Heap-based buffer overflow vulnerability in the SonicOS IPSec VPN allows an unauthenticated remote attacker to cause Denial of Service (DoS).

๐Ÿ“… Published: July 18, 2024, 7:42 a.m. ๐Ÿ”„ Last Modified: Nov. 21, 2024, 9:31 a.m.

7.1

CVSS3.1

CVE-2024-29014 -

Vulnerability in SonicWall SMA100 NetExtender Windows (32 and 64-bit) client 10.2.339 and earlier versions allows an attacker to arbitrary code execution when processing an EPC Client update.

๐Ÿ“… Published: July 18, 2024, 7:37 a.m. ๐Ÿ”„ Last Modified: Nov. 27, 2024, 4:55 a.m.

9.8

CVSS3.1

CVE-2024-6164 - Filter & Grids < 2.8.33 - Unauthenticated LFI

The Filter & Grids WordPress plugin before 2.8.33 is vulnerable to Local File Inclusion via the post_layout parameter. This makes it possible for an unauthenticated attacker to include and execute PHP files on the server, allowing the execution of any PHP code in those files.

๐Ÿ“… Published: July 18, 2024, 6 a.m. ๐Ÿ”„ Last Modified: Nov. 21, 2024, 9:49 a.m.

5.4

CVSS3.1

CVE-2023-6708 - SVG Support <= 2.5.7 - Authenticated (Author+) Cross-Site Scripting via SVG

The SVG Support plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the SVG upload feature in all versions up to, and including, 2.5.7 due to insufficient input sanitization and output escaping, even when the 'Sanitize SVG while uploading' feature is enabled. This makes it possiblโ€ฆ

๐Ÿ“… Published: July 18, 2024, 2:38 a.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

4.3

CVSS3.1

CVE-2024-6599 - Meks Video Importer <= 1.0.12 - Missing Authorization to Authenticated (Subscriber+) API Keys Modifโ€ฆ

The Meks Video Importer plugin for WordPress is vulnerable to unauthorized API key modification due to a missing capability check on the ajax_save_settings function in all versions up to, and including, 1.0.12. This makes it possible for authenticated attackers, with Subscriber-level access and aboโ€ฆ

๐Ÿ“… Published: July 18, 2024, 2:03 a.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.5

CVSS3.1

CVE-2024-6705 - RegLevel <= 1.2.1 - Authenticated (Administrator+) Stored Cross-Site Scripting

The RegLevel plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.2.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and abovโ€ฆ

๐Ÿ“… Published: July 18, 2024, 2:03 a.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.4

CVSS3.1

CVE-2024-5964 - Zenon Lite <= 1.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via Button Shortcode

The Zenon Lite theme for WordPress is vulnerable to Stored Cross-Site Scripting via the โ€˜urlโ€™ parameter within the theme's Button shortcode in all versions up to, and including, 1.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with โ€ฆ

๐Ÿ“… Published: July 18, 2024, 2:03 a.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.8

CVSS3.1

CVE-2024-5726 - Timeline Event History <= 3.1 - Authenticated (Contributor+) PHP Object Injection

The Timeline Event History plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.1 via deserialization of untrusted input 'timelines-data' parameter. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject aโ€ฆ

๐Ÿ“… Published: July 18, 2024, 2:03 a.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 349182
Page 9109 of 34,919
ยซ previous page ยป next page
Filters