6.1

CVSS3.1

CVE-2024-3032 - Themify Builder < 7.5.8 - Open Redirect

Themify Builder WordPress plugin before 7.5.8 does not validate a parameter before redirecting the user to its value, leading to an Open Redirect issue

πŸ“… Published: June 13, 2024, 6 a.m. πŸ”„ Last Modified: March 17, 2025, 6:15 p.m.

6.3

CVSS3.1

CVE-2024-2762 - FooGallery < 2.4.15 - Author+ Stored XSS

The FooGallery WordPress plugin before 2.4.15, foogallery-premium WordPress plugin before 2.4.15 does not validate and escape some of its Gallery settings before outputting them back in the page, which could allow users with a role as low as Author to perform Stored Cross-Site Scripting attacks wh…

πŸ“… Published: June 13, 2024, 6 a.m. πŸ”„ Last Modified: Nov. 21, 2024, 9:10 a.m.

6

CVSS3.1

CVE-2024-5661 - Potential Denial of Service affecting XenServer and Citrix Hypervisor

An issue has been identified in both XenServer 8 and Citrix Hypervisor 8.2 CU1 LTSR which may allow a malicious administrator of a guest VM to cause the host to become slow and/or unresponsive.

πŸ“… Published: June 13, 2024, 5:58 a.m. πŸ”„ Last Modified: Nov. 21, 2024, 9:48 a.m.

6.4

CVSS3.1

CVE-2024-5787 - PowerPack Addons for Elementor (Free Widgets, Extensions and Templates) <= 2.7.20 - Authenticated (…

The PowerPack Addons for Elementor (Free Widgets, Extensions and Templates) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'url' attribute within the plugin's Link Effects widget in all versions up to, and including, 2.7.20 due to insufficient input sanitization and outpu…

πŸ“… Published: June 13, 2024, 5:34 a.m. πŸ”„ Last Modified: April 8, 2026, 7:22 p.m.

6.4

CVSS3.1

CVE-2024-5757 - Elementor Header & Footer Builder <= 1.6.35 - Authenticated (Contributor+) Stored Cross-Site Script…

The Elementor Header & Footer Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the url attribute within the plugin's Site Title widget in all versions up to, and including, 1.6.35 due to insufficient input sanitization and output escaping. This makes it possible for au…

πŸ“… Published: June 13, 2024, 5:34 a.m. πŸ”„ Last Modified: April 8, 2026, 7:22 p.m.

7.5

CVSS3.1

CVE-2024-2098 - Download Manager <= 3.2.89 - Improper Authorization via protectMediaLibrary

The Download Manager plugin for WordPress is vulnerable to unauthorized access of data due to an improper authorization check on the 'protectMediaLibrary' function in all versions up to, and including, 3.2.89. This makes it possible for unauthenticated attackers to download password-protected files.

πŸ“… Published: June 13, 2024, 5:34 a.m. πŸ”„ Last Modified: April 8, 2026, 4:36 p.m.

10

CVSS3.1

CVE-2024-3922 - Dokan Pro <= 3.10.3 - Unauthenticated SQL Injection

The Dokan Pro plugin for WordPress is vulnerable to SQL Injection via the 'code' parameter in all versions up to, and including, 3.10.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticat…

πŸ“… Published: June 13, 2024, 2:05 a.m. πŸ”„ Last Modified: April 8, 2026, 7:21 p.m.

9.8

CVSS3.1

CVE-2024-37849 -

A SQL Injection vulnerability in itsourcecode Billing System 1.0 allows a local attacker to execute arbitrary code in process.php via the username parameter.

πŸ“… Published: June 13, 2024, midnight πŸ”„ Last Modified: Nov. 21, 2024, 9:24 a.m.

5.3

CVSS3.1

CVE-2023-35858 -

XPath Injection vulnerabilities in the blog and RSS functions of Modern Campus - Omni CMS 2023.1 allow a remote, unauthenticated attacker to obtain application information.

πŸ“… Published: June 13, 2024, midnight πŸ”„ Last Modified: June 18, 2025, 5:21 p.m.

8.8

CVSS3.1

CVE-2024-38294 -

ALCASAR before 3.6.1 allows email_registration_back.php remote code execution.

πŸ“… Published: June 13, 2024, midnight πŸ”„ Last Modified: March 13, 2025, 6:20 p.m.
Total resulsts: 349182
Page 9476 of 34,919
Β« previous page Β» next page
Filters