4.3

CVSS3.1

CVE-2024-39679 - WordPress Cooked Plugin - Cross-Site Request Forgery to Recipe Template Reset

Cooked is a recipe plugin for WordPress. The Cooked plugin for WordPress is vulnerable to Cross-Site Request Forgery (CSRF) in versions up to, and including, 1.7.15.4 due to missing or incorrect nonce validation on the AJAX action handler. This vulnerability could allow an attacker to trick users i…

πŸ“… Published: July 17, 2024, 11:47 p.m. πŸ”„ Last Modified: Feb. 10, 2025, 3:51 p.m.

4.3

CVSS3.1

CVE-2024-39678 - WordPress Cooked Plugin - Cross-Site Request Forgery to Get Recipe IDs

Cooked is a recipe plugin for WordPress. The Cooked plugin is vulnerable to Cross-Site Request Forgery (CSRF) in versions up to, and including, 1.7.15.4 due to missing or incorrect nonce validation on the AJAX action handler. This vulnerability could allow an attacker to trick users into performing…

πŸ“… Published: July 17, 2024, 11:43 p.m. πŸ”„ Last Modified: Feb. 10, 2025, 3:53 p.m.

0.0

CVE-2024-6865 -

This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

πŸ“… Published: July 17, 2024, 8:50 p.m. πŸ”„ Last Modified: Aug. 5, 2024, 2:15 p.m.

5.4

CVSS3.1

CVE-2024-32981 - Cross-site Scripting vulnerability with encoded payload in silverstripe/framework

Silverstripe framework is the PHP framework forming the base for the Silverstripe CMS. In affected versions a bad actor with access to edit content in the CMS could add send a specifically crafted encoded payload to the server, which could be used to inject a JavaScript payload on the front end of …

πŸ“… Published: July 17, 2024, 7:36 p.m. πŸ”„ Last Modified: Sept. 4, 2025, 3:21 p.m.

4.3

CVSS3.1

CVE-2024-29885 - Reports are still accessible even when `canView()` returns false in silverstripe/reports

silverstripe/reports is an API for creating backend reports in the Silverstripe Framework. In affected versions reports can be accessed by their direct URL by any user who has access to view the reports admin section, even if the `canView()` method for that report returns `false`. This issue has be…

πŸ“… Published: July 17, 2024, 7:35 p.m. πŸ”„ Last Modified: Sept. 4, 2025, 2:56 p.m.

6.4

CVSS3.1

CVE-2024-28796 -

IBM ClearQuest (CQ) 9.1 through 9.1.0.6 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 2…

πŸ“… Published: July 17, 2024, 6:14 p.m. πŸ”„ Last Modified: Nov. 21, 2024, 9:06 a.m.

5.3

CVSS3.1

CVE-2024-40633 - Customer data leak via adjustments API endpoint in Sylius

Sylius is an Open Source eCommerce Framework on Symfony. A security vulnerability was discovered in the `/api/v2/shop/adjustments/{id}` endpoint, which retrieves order adjustments based on incremental integer IDs. The vulnerability allows an attacker to enumerate valid adjustment IDs and retrieve o…

πŸ“… Published: July 17, 2024, 5:51 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS3.1

CVE-2024-40636 - Basic Auth Credential Leakage to Logs After Fetch Registry Error in Steeltoe.Discovery.Eureka with …

Steeltoe is an open source project that provides a collection of libraries that helps users build production-grade cloud-native applications using externalized configuration, service discovery, distributed tracing, application management, and more. When utilizing multiple Eureka server service URLs…

πŸ“… Published: July 17, 2024, 5:48 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

0.0

CVE-2024-40639 -

This CVE is a duplicate of another CVE.

πŸ“… Published: July 17, 2024, 5:42 p.m. πŸ”„ Last Modified: July 17, 2024, 8:15 p.m.

7.4

CVSS3.1

CVE-2024-40641 - Unsigned code template execution through workflows in projectdiscovery/nuclei

Nuclei is a fast and customizable vulnerability scanner based on simple YAML based DSL. In affected versions it a way to execute code template without -code option and signature has been discovered. Some web applications inherit from Nuclei and allow users to edit and execute workflow files. In th…

πŸ“… Published: July 17, 2024, 5:34 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 349182
Page 9111 of 34,919
Β« previous page Β» next page
Filters