0.0

CVE-2024-6349 -

This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

πŸ“… Published: June 26, 2024, 12:29 p.m. πŸ”„ Last Modified: June 26, 2024, 3:15 p.m.

4.4

CVSS3.1

CVE-2024-37098 - WordPress BlossomThemes Email Newsletter plugin <= 2.2.6 - Server Side Request Forgery (SSRF) vulne…

Server-Side Request Forgery (SSRF) vulnerability in Blossom Themes BlossomThemes Email Newsletter.This issue affects BlossomThemes Email Newsletter: from n/a through 2.2.6.

πŸ“… Published: June 26, 2024, 10:54 a.m. πŸ”„ Last Modified: Jan. 7, 2026, 7:30 p.m.

4.8

CVSS4.0

CVE-2024-6344 - ZKTeco ZKBio CVSecurity V5000 Push Configuration Section cross site scripting

A vulnerability, which was classified as problematic, was found in ZKTeco ZKBio CVSecurity V5000 4.1.0. This affects an unknown part of the component Push Configuration Section. The manipulation of the argument Configuration Name leads to cross site scripting. It is possible to initiate the attack …

πŸ“… Published: June 26, 2024, 10:31 a.m. πŸ”„ Last Modified: July 10, 2025, 7:15 a.m.

9.3

CVSS3.1

CVE-2024-37252 - WordPress Email Subscribers by Icegram Express plugin <= 5.7.25 - SQL Injection vulnerability

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Icegram Email Subscribers & Newsletters allows SQL Injection.This issue affects Email Subscribers & Newsletters: from n/a through 5.7.25.

πŸ“… Published: June 26, 2024, 10:13 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

2.7

CVSS3.1

CVE-2024-28830 - Automation user secrets written to audit log

Insertion of Sensitive Information into Log File in Checkmk GmbH's Checkmk versions <2.3.0p7, <2.2.0p28, <2.1.0p45 and <=2.0.0p39 (EOL) causes automation user secrets to be written to audit log files accessible to administrators.

πŸ“… Published: June 26, 2024, 7:56 a.m. πŸ”„ Last Modified: Dec. 4, 2024, 4:12 p.m.

6.4

CVSS3.1

CVE-2024-5215 - HT Mega – Absolute Addons For Elementor <= 2.5.5 - Authenticated (Contributor+) Stored Cross-Site S…

The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple widgets in all versions up to, and including, 2.5.5 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authentic…

πŸ“… Published: June 26, 2024, 6:56 a.m. πŸ”„ Last Modified: April 8, 2026, 6:22 p.m.

5.9

CVSS3.1

CVE-2024-5573 - Easy Table of Contents < 2.0.66 - Admin+ Stored XSS

The Easy Table of Contents WordPress plugin before 2.0.66 does not sanitise and escape some of its settings, which could allow high privilege users such as editors to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed

πŸ“… Published: June 26, 2024, 6 a.m. πŸ”„ Last Modified: May 19, 2025, 9:03 p.m.

4.0

CVSS3.1

CVE-2024-5473 - Simple Photoswipe <= 0.1 - Admin+ Stored XSS

The Simple Photoswipe WordPress plugin through 0.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

πŸ“… Published: June 26, 2024, 6 a.m. πŸ”„ Last Modified: May 19, 2025, 9:02 p.m.

6.1

CVSS3.1

CVE-2024-5199 - Spotify Play Button <= 1.0 - Contributor+ Stored XSS

The Spotify Play Button WordPress plugin through 1.0 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

πŸ“… Published: June 26, 2024, 6 a.m. πŸ”„ Last Modified: Nov. 21, 2024, 9:47 a.m.

4.8

CVSS3.1

CVE-2024-5169 - Video Widget <= 1.2.3 - Admin+ Stored XSS via Widget

The Video Widget WordPress plugin through 1.2.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

πŸ“… Published: June 26, 2024, 6 a.m. πŸ”„ Last Modified: Nov. 21, 2024, 9:47 a.m.
Total resulsts: 349182
Page 9325 of 34,919
Β« previous page Β» next page
Filters