6.5

CVSS3.1

CVE-2024-5071 - Bookster <= 1.1.0 - Unauthenticated Appointment Status Update

The Bookster WordPress plugin through 1.1.0 allows adding sensitive parameters when validating appointments allowing attackers to manipulate the data sent when booking an appointment (the request body) to change its status from pending to approved.

πŸ“… Published: June 26, 2024, 6 a.m. πŸ”„ Last Modified: May 19, 2025, 9:02 p.m.

4.8

CVSS3.1

CVE-2024-4959 - Frontend Checklist <= 2.3.2 - Admin+ Stored XSS via Items

The Frontend Checklist WordPress plugin through 2.3.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

πŸ“… Published: June 26, 2024, 6 a.m. πŸ”„ Last Modified: April 30, 2025, 11:27 p.m.

4.3

CVSS3.1

CVE-2024-4957 - Frontend Checklist <= 2.3.2 - Admin+ Stored XSS

The Frontend Checklist WordPress plugin through 2.3.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

πŸ“… Published: June 26, 2024, 6 a.m. πŸ”„ Last Modified: April 30, 2025, 11:32 p.m.

7.6

CVSS3.1

CVE-2024-4758 - Muslim Prayer Time BD <= 2.4 - Settings Reset via CSRF

The Muslim Prayer Time BD WordPress plugin through 2.4 does not have CSRF check in place when reseting its settings, which could allow attackers to make a logged in admin reset them via a CSRF attack

πŸ“… Published: June 26, 2024, 6 a.m. πŸ”„ Last Modified: May 19, 2025, 3:05 p.m.

5.4

CVSS3.1

CVE-2024-3633 - WebP & SVG Support <= 1.4.0 - Author+ Stored XSS via SVG

The WebP & SVG Support WordPress plugin through 1.4.0 does not sanitise uploaded SVG files, which could allow users with a role as low as Author to upload a malicious SVG containing XSS payloads.

πŸ“… Published: June 26, 2024, 6 a.m. πŸ”„ Last Modified: May 19, 2025, 9:01 p.m.

6.4

CVSS3.1

CVE-2024-5332 - Exclusive Addons for Elementor <= 2.6.9.8 - Authenticated (Contibutor+) Stored Cross-Site Scripting…

The Exclusive Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Card widget in all versions up to, and including, 2.6.9.8 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenti…

πŸ“… Published: June 26, 2024, 5:40 a.m. πŸ”„ Last Modified: April 8, 2026, 7:21 p.m.

5.3

CVSS3.1

CVE-2024-4106 -

A vulnerability has been found in FAST/TOOLS and CI Server. The affected products have built-in accounts with no passwords set. Therefore, if the product is operated without a password set by default, an attacker can break into the affected product. The affected products and versions are as follows…

πŸ“… Published: June 26, 2024, 5:30 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.8

CVSS3.1

CVE-2024-4105 -

A vulnerability has been found in FAST/TOOLS and CI Server. The affected product's WEB HMI server's function to process HTTP requests has a security flaw (Reflected XSS) that allows the execution of malicious scripts. Therefore, if a client PC with inadequate security measures accesses a product UR…

πŸ“… Published: June 26, 2024, 5:25 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

3.5

CVSS3.1

CVE-2024-37141 -

Dell PowerProtect DD, versions prior to 8.0, LTS 7.13.1.0, LTS 7.10.1.30, LTS 7.7.5.40 contain an open redirect vulnerability. A remote low privileged attacker could potentially exploit this vulnerability, leading to information disclosure.

πŸ“… Published: June 26, 2024, 4 a.m. πŸ”„ Last Modified: Nov. 21, 2024, 9:23 a.m.

8.8

CVSS3.1

CVE-2024-37140 -

Dell PowerProtect DD, versions prior to 8.0, LTS 7.13.1.0, LTS 7.10.1.30, LTS 7.7.5.40 contain an OS command injection vulnerability in an admin operation. A remote low privileged attacker could potentially exploit this vulnerability, leading to the execution of arbitrary OS commands on the system …

πŸ“… Published: June 26, 2024, 3:54 a.m. πŸ”„ Last Modified: Nov. 21, 2024, 9:23 a.m.
Total resulsts: 349182
Page 9326 of 34,919
Β« previous page Β» next page
Filters