6.5

CVSS3.1

CVE-2024-35162 -

Path traversal vulnerability exists in Download Plugins and Themes from Dashboard versions prior to 1.8.6. If this vulnerability is exploited, a remote authenticated attacker with "switch_themes" privilege may obtain arbitrary files on the server.

📅 Published: May 22, 2024, 5:30 a.m. 🔄 Last Modified: Nov. 21, 2024, 9:19 a.m.

4.8

CVSS3.1

CVE-2024-31340 -

TP-Link Tether versions prior to 4.5.13 and TP-Link Tapo versions prior to 3.3.6 do not properly validate certificates, which may allow a remote unauthenticated attacker to eavesdrop on an encrypted communication via a man-in-the-middle attack.

📅 Published: May 22, 2024, 5:29 a.m. 🔄 Last Modified: March 28, 2025, 8:15 p.m.

6.6

CVSS3.1

CVE-2024-31396 -

Code injection vulnerability exists in a-blog cms Ver.3.1.x series versions prior to Ver.3.1.12 and Ver.3.0.x series versions prior to Ver.3.0.32. If this vulnerability is exploited, a user with an administrator or higher privilege who can log in to the product may execute an arbitrary command on t…

📅 Published: May 22, 2024, 4:35 a.m. 🔄 Last Modified: May 12, 2025, 2:23 p.m.

6.1

CVSS3.1

CVE-2024-31395 -

Cross-site scripting vulnerability exists in a-blog cms Ver.3.1.x series versions prior to Ver.3.1.12, Ver.3.0.x series versions prior to Ver.3.0.32, Ver.2.11.x series versions prior to Ver.2.11.61, Ver.2.10.x series versions prior to Ver.2.10.53, and Ver.2.9 and earlier versions. If this vulnerabi…

📅 Published: May 22, 2024, 4:35 a.m. 🔄 Last Modified: May 12, 2025, 2:23 p.m.

6.5

CVSS3.1

CVE-2024-31394 -

Directory traversal vulnerability exists in a-blog cms Ver.3.1.x series versions prior to Ver.3.1.12, Ver.3.0.x series versions prior to Ver.3.0.32, Ver.2.11.x series versions prior to Ver.2.11.61, Ver.2.10.x series versions prior to Ver.2.10.53, and Ver.2.9 and earlier versions. If this vulnerabil…

📅 Published: May 22, 2024, 4:35 a.m. 🔄 Last Modified: May 12, 2025, 2:23 p.m.

4.4

CVSS3.1

CVE-2024-30420 -

Server-side request forgery (SSRF) vulnerability exists in a-blog cms Ver.3.1.x series versions prior to Ver.3.1.12 and Ver.3.0.x series versions prior to Ver.3.0.32. If this vulnerability is exploited, a user with an administrator or higher privilege who can log in to the product may obtain arbitr…

📅 Published: May 22, 2024, 4:35 a.m. 🔄 Last Modified: May 12, 2025, 2:23 p.m.

5.4

CVSS3.1

CVE-2024-30419 -

Cross-site scripting vulnerability exists in a-blog cms Ver.3.1.x series versions prior to Ver.3.1.12, Ver.3.0.x series versions prior to Ver.3.0.32, Ver.2.11.x series versions prior to Ver.2.11.61, Ver.2.10.x series versions prior to Ver.2.10.53, and Ver.2.9 and earlier versions. If this vulnerabi…

📅 Published: May 22, 2024, 4:35 a.m. 🔄 Last Modified: May 12, 2025, 2:23 p.m.

6.4

CVSS3.1

CVE-2024-4980 - WPKoi Templates for Elementor <= 2.5.9 - Authenticated (Contributor+) Stored Cross-Site Scripting v…

The WPKoi Templates for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'id', 'mixColor', 'backgroundColor', 'saveInCookies', and 'autoMatchOsTheme' parameters in all versions up to, and including, 2.5.9 due to insufficient input sanitization and output escaping. Thi…

📅 Published: May 22, 2024, 4:30 a.m. 🔄 Last Modified: April 8, 2026, 6:21 p.m.

5

CVSS3.1

CVE-2024-0453 - AI ChatBot <= 5.3.4 - Missing Authorization via openai_file_delete_callback

The AI ChatBot plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the openai_file_delete_callback function in all versions up to, and including, 5.3.4. This makes it possible for authenticated attackers, with subscriber-level access and abov…

📅 Published: May 22, 2024, 3:17 a.m. 🔄 Last Modified: April 8, 2026, 6:18 p.m.

5

CVSS3.1

CVE-2024-0452 - AI ChatBot <= 5.3.4 - Missing Authorization via openai_file_upload_callback

The AI ChatBot plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the openai_file_upload_callback function in all versions up to, and including, 5.3.4. This makes it possible for authenticated attackers, with subscriber-level access and abov…

📅 Published: May 22, 2024, 3:17 a.m. 🔄 Last Modified: April 8, 2026, 4:45 p.m.
Total resulsts: 343968
Page 9186 of 34,397
« previous page » next page
Filters