8.8

CVSS3.1

CVE-2024-29737 - Apache StreamPark (incubating): maven build params could trigger remote command execution

In streampark, the project module integrates Maven's compilation capabilities. The input parameter validation is not strict, allowing attackers to insert commands for remote command execution, The prerequisite for a successful attack is that the user needs to log in to the streampark system and hav…

📅 Published: July 17, 2024, 8:21 a.m. 🔄 Last Modified: Feb. 13, 2025, 6:17 p.m.

8.8

CVSS3.1

CVE-2023-52291 - Apache StreamPark (incubating): Unchecked maven build params could trigger remote command execution

In streampark, the project module integrates Maven's compilation capabilities. The input parameter validation is not strict, allowing attackers to insert commands for remote command execution, The prerequisite for a successful attack is that the user needs to log in to the streampark system and hav…

📅 Published: July 17, 2024, 8:16 a.m. 🔄 Last Modified: Feb. 13, 2025, 6:15 p.m.

8.8

CVSS3.1

CVE-2024-39877 - Apache Airflow: DAG Author Code Execution possibility in airflow-scheduler

Apache Airflow 2.4.0, and versions before 2.9.3, has a vulnerability that allows authenticated DAG authors to craft a doc_md parameter in a way that could execute arbitrary code in the scheduler context, which should be forbidden according to the Airflow Security model. Users should upgrade to vers…

📅 Published: July 17, 2024, 7:54 a.m. 🔄 Last Modified: Nov. 21, 2024, 9:28 a.m.

5.4

CVSS3.1

CVE-2024-39863 - Apache Airflow: Potential XSS Vulnerability

Apache Airflow versions before 2.9.3 have a vulnerability that allows an authenticated attacker to inject a malicious link when installing a provider. Users are recommended to upgrade to version 2.9.3, which fixes this issue.

📅 Published: July 17, 2024, 7:53 a.m. 🔄 Last Modified: Nov. 21, 2024, 9:28 a.m.

6.4

CVSS3.1

CVE-2024-5582 - Schema & Structured Data for WP & AMP <= 1.33 - Authenticated (Contributor+) Stored Cross-Site Scri…

The Schema & Structured Data for WP & AMP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'url' attribute within the Q&A Block widget in all versions up to, and including, 1.33 due to insufficient input sanitization and output escaping on user supplied attributes.…

📅 Published: July 17, 2024, 7:32 a.m. 🔄 Last Modified: April 8, 2026, 7:21 p.m.

9.8

CVSS3.1

CVE-2024-6220 - 简数采集器 (Keydatas) <= 2.5.2 - Unauthenticated Arbitrary File Upload

The 简数采集器 (Keydatas) plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the keydatas_downloadImages function in all versions up to, and including, 2.5.2. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected s…

📅 Published: July 17, 2024, 7:32 a.m. 🔄 Last Modified: April 8, 2026, 6:22 p.m.

4.3

CVSS3.1

CVE-2024-5703 - Icegram Express - Email Subscribers, Newsletters and Marketing Automation Plugin <= 5.7.26 - Missin…

The Email Subscribers by Icegram Express – Email Marketing, Newsletters, Automation for WordPress & WooCommerce plugin for WordPress is vulnerable to unauthorized API access due to a missing capability check in all versions up to, and including, 5.7.26. This makes it possible for authenticated atta…

📅 Published: July 17, 2024, 7:32 a.m. 🔄 Last Modified: April 8, 2026, 4:41 p.m.

6.4

CVSS3.1

CVE-2024-5251 - Ultimate Addons for WPBakery Page Builder <= 3.19.20 - Authenticated (Contributor+) Stored Cross-Si…

The Ultimate Addons for WPBakery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's ultimate_pricing shortcode in all versions up to, and including, 3.19.20 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possibl…

📅 Published: July 17, 2024, 6:45 a.m. 🔄 Last Modified: April 8, 2026, 7:21 p.m.

8.8

CVSS3.1

CVE-2024-6467 - BookingPress Appointment Booking <= 1.1.5 - Authenticated (Subscriber+) Arbitrary File Read to Arbi…

The BookingPress – Appointment Booking Calendar Plugin and Online Scheduling Plugin plugin for WordPress is vulnerable to Arbitrary File Read to Arbitrary File Creation in all versions up to, and including, 1.1.5 via the 'bookingpress_save_lite_wizard_settings_func' function. This makes it possible…

📅 Published: July 17, 2024, 6:45 a.m. 🔄 Last Modified: April 8, 2026, 7:22 p.m.

5.5

CVSS3.1

CVE-2024-6669 - AI ChatBot for WordPress – WPBot <= 5.5.7 - Authenticated (Administrator+) Stored Cross-Site Script…

The AI ChatBot for WordPress – WPBot plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 5.5.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-le…

📅 Published: July 17, 2024, 6:45 a.m. 🔄 Last Modified: April 8, 2026, 7:22 p.m.
Total resulsts: 349182
Page 9116 of 34,919
« previous page » next page
Filters