8.3

CVSS3.1

CVE-2024-22064 - Configuration error Vulnerability in ZTE ZXUN-ePDG

ZTE ZXUN-ePDG product, which serves as the network node of the VoWifi system, under by default configuration, uses a set of non-unique cryptographic keys during establishing a secure connection(IKE) with the mobile devices connecting over the internet . If the set of keys are leaked or cracked, the…

πŸ“… Published: May 10, 2024, 12:28 p.m. πŸ”„ Last Modified: Jan. 28, 2025, 4:12 p.m.

5.3

CVSS4.0

CVE-2024-4715 - Campcodes Complete Web-Based School Management System update_grade.php cross site scripting

A vulnerability, which was classified as problematic, was found in Campcodes Complete Web-Based School Management System 1.0. This affects an unknown part of the file /model/update_grade.php. The manipulation of the argument name leads to cross site scripting. It is possible to initiate the attack …

πŸ“… Published: May 10, 2024, noon πŸ”„ Last Modified: Feb. 19, 2025, 6:51 p.m.

6.4

CVSS3.1

CVE-2024-4490 - Elegant Themes Divi Theme, Extra Theme, Divi Page Builder <= 4.25.0 - Authenticated (Contributor+) …

The Elegant Themes Divi theme, Extra theme, and Divi Page Builder plugin for WordPress are vulnerable to DOM-Based Stored Cross-Site Scripting via the β€˜title’ parameter in versions up to, and including, 4.25.0 due to insufficient input sanitization and output escaping. This makes it possible for au…

πŸ“… Published: May 10, 2024, 11:03 a.m. πŸ”„ Last Modified: April 8, 2026, 7:21 p.m.

5.3

CVSS4.0

CVE-2024-4714 - Campcodes Complete Web-Based School Management System update_subject.php cross site scripting

A vulnerability, which was classified as problematic, has been found in Campcodes Complete Web-Based School Management System 1.0. Affected by this issue is some unknown functionality of the file /model/update_subject.php. The manipulation of the argument name leads to cross site scripting. The att…

πŸ“… Published: May 10, 2024, 11 a.m. πŸ”„ Last Modified: Feb. 19, 2025, 6:57 p.m.

5.3

CVSS4.0

CVE-2024-4713 - Campcodes Complete Web-Based School Management System all_teacher.php cross site scripting

A vulnerability classified as problematic was found in Campcodes Complete Web-Based School Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /view/all_teacher.php. The manipulation of the argument page leads to cross site scripting. The attack can be laun…

πŸ“… Published: May 10, 2024, 10 a.m. πŸ”„ Last Modified: Feb. 19, 2025, 6:58 p.m.

6.5

CVSS3.1

CVE-2024-4039 - Orders Tracking for WooCommerce <= 1.2.10 - Unauthenticated Arbitrary Shortcode Execution

The The Orders Tracking for WooCommerce plugin for WordPress for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 1.2.10. This is due to the plugin allowing users to execute an action that does not properly validate a value before running do_shortcode. …

πŸ“… Published: May 10, 2024, 9:32 a.m. πŸ”„ Last Modified: April 8, 2026, 6:21 p.m.

6.4

CVSS3.1

CVE-2024-4277 - LearnPress – WordPress LMS Plugin <= 4.2.6.5 - Authenticated (Contributor+) Stored Cross-Site Scrip…

The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the β€˜layout_html’ parameter in all versions up to, and including, 4.2.6.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with …

πŸ“… Published: May 10, 2024, 9:32 a.m. πŸ”„ Last Modified: April 8, 2026, 6:21 p.m.

6.5

CVSS3.1

CVE-2024-32776 - WordPress AppPresser plugin <= 4.3.0 - Broken Access Control vulnerability

Missing Authorization vulnerability in AppPresser Team AppPresser.This issue affects AppPresser: from n/a through 4.3.0.

πŸ“… Published: May 10, 2024, 8:43 a.m. πŸ”„ Last Modified: June 9, 2025, 8:52 p.m.

7.1

CVSS3.1

CVE-2024-34818 - WordPress Webinar plugin <= 1.33.17 - Cross Site Request Forgery (CSRF) vulnerability

Cross-Site Request Forgery (CSRF) vulnerability in WebinarPress.This issue affects WebinarPress: from n/a through 1.33.17.

πŸ“… Published: May 10, 2024, 8:40 a.m. πŸ”„ Last Modified: July 12, 2025, 4:01 p.m.

5.4

CVSS3.1

CVE-2024-34814 - WordPress Unyson plugin <=2.7.29 - Cross Site Request Forgery (CSRF) vulnerability

Cross-Site Request Forgery (CSRF) vulnerability in Unyson Unyson unyson.This issue affects Unyson: from n/a through <= 2.7.29.

πŸ“… Published: May 10, 2024, 8:38 a.m. πŸ”„ Last Modified: April 1, 2026, 4:17 p.m.
Total resulsts: 343968
Page 9389 of 34,397
Β« previous page Β» next page
Filters