5.3

CVSS3.1

CVE-2024-6088 - LearnPress – WordPress LMS Plugin <= 4.2.6.8.1 - Missing Authorization to Unauthenticated User Regi…

The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to unauthorized user registration due to a missing capability check on the 'register' function in all versions up to, and including, 4.2.6.8.1. This makes it possible for unauthenticated attackers to bypass disabled user regis…

πŸ“… Published: July 2, 2024, 11:01 a.m. πŸ”„ Last Modified: April 8, 2026, 4:33 p.m.

6.4

CVSS3.1

CVE-2024-4268 - Ultimate Blocks – WordPress Blocks Plugin <= 3.1.9 - Authenticated(Contributor+) Stored Cross-Site …

The Ultimate Blocks – WordPress Blocks Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's blocks in all versions up to, and including, 3.1.9 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for auth…

πŸ“… Published: July 2, 2024, 11:01 a.m. πŸ”„ Last Modified: April 8, 2026, 5:18 p.m.

5.3

CVSS4.0

CVE-2024-6440 - SourceCodester Home Owners Collection Management System sql injection

A vulnerability was found in SourceCodester Home Owners Collection Management System 1.0. It has been classified as critical. Affected is an unknown function of the file /classes/Master.php?f=delete_category. The manipulation of the argument id leads to sql injection. It is possible to launch the a…

πŸ“… Published: July 2, 2024, 11 a.m. πŸ”„ Last Modified: Nov. 21, 2024, 9:49 a.m.

5.3

CVSS4.0

CVE-2024-6439 - SourceCodester Home Owners Collection Management System unrestricted upload

A vulnerability was found in SourceCodester Home Owners Collection Management System 1.0 and classified as critical. This issue affects some unknown processing of the file /classes/Users.php?f=save. The manipulation of the argument img leads to unrestricted upload. The attack may be initiated remot…

πŸ“… Published: July 2, 2024, 11 a.m. πŸ”„ Last Modified: Nov. 21, 2024, 9:49 a.m.

5.3

CVSS4.0

CVE-2024-6438 - Hitout Carsale OrderController.java sql injection

A vulnerability has been found in Hitout Carsale 1.0 and classified as critical. This vulnerability affects unknown code of the file OrderController.java. The manipulation of the argument orderBy leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the pub…

πŸ“… Published: July 2, 2024, 10:31 a.m. πŸ”„ Last Modified: Nov. 21, 2024, 9:49 a.m.

4.3

CVSS3.1

CVE-2024-6012 - Cost Calculator Builder <= 3.2.12 - Missing Authorization to Authenticated (Subscriber+) Arbitrary …

The Cost Calculator Builder plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'embed-create-page' and 'embed-insert-pages' functions in all versions up to, and including, 3.2.12. This makes it possible for authenticated attackers, with …

πŸ“… Published: July 2, 2024, 9:32 a.m. πŸ”„ Last Modified: April 8, 2026, 7:22 p.m.

4.4

CVSS3.1

CVE-2024-6011 - Cost Calculator Builder <= 3.2.12 - Authenticated (Administrator+) Stored Cross-Site Scripting

The Cost Calculator Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the β€˜textarea.description’ parameter in all versions up to, and including, 3.2.12 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Ad…

πŸ“… Published: July 2, 2024, 9:32 a.m. πŸ”„ Last Modified: April 8, 2026, 4:32 p.m.

5.9

CVSS3.1

CVE-2024-34601 -

Improper verification of intent by broadcast receiver vulnerability in GalaxyStore prior to version 4.5.81.0 allows local attackers to launch unexported activities of GalaxyStore.

πŸ“… Published: July 2, 2024, 9:23 a.m. πŸ”„ Last Modified: Jan. 3, 2025, 7:15 p.m.

4.4

CVSS3.1

CVE-2024-34600 -

Improper verification of intent by broadcast receiver vulnerability in Samsung Flow prior to version 4.9.13.0 allows local attackers to copy image files to external storage.

πŸ“… Published: July 2, 2024, 9:23 a.m. πŸ”„ Last Modified: Nov. 21, 2024, 9:19 a.m.

4

CVSS3.1

CVE-2024-34599 -

Improper input validation in Tips prior to version 6.2.9.4 in Android 14 allows local attacker to send broadcast with Tips&#39; privilege.

πŸ“… Published: July 2, 2024, 9:23 a.m. πŸ”„ Last Modified: Nov. 21, 2024, 9:19 a.m.
Total resulsts: 347752
Page 9134 of 34,776
Β« previous page Β» next page
Filters