7.2

CVSS3.1

CVE-2024-5211 - Path Traversal to Arbitrary File Read/Delete/Overwrite, DoS Attack, and Admin Account Takeover in m…

A path traversal vulnerability in mintplex-labs/anything-llm allowed a manager to bypass the `normalizePath()` function, intended to defend against path traversal attacks. This vulnerability enables the manager to read, delete, or overwrite the 'anythingllm.db' database file and other files stored …

πŸ“… Published: June 12, 2024, 11:33 a.m. πŸ”„ Last Modified: July 15, 2025, 3:04 p.m.

6.5

CVSS3.1

CVE-2024-5674 - Newsletter - API v1 and v2 addon for Newsletter <= 2.4.5 - Missing Authorization to Email Subscribe…

The Newsletter - API v1 and v2 addon plugin for WordPress is vulnerable to unauthorized subscribers management due to PHP type juggling issue on the check_api_key function in all versions up to, and including, 2.4.5. This makes it possible for unauthenticated attackers to list, create or delete new…

πŸ“… Published: June 12, 2024, 11:05 a.m. πŸ”„ Last Modified: April 8, 2026, 7:21 p.m.

6.4

CVSS3.1

CVE-2024-3492 - Events Manager – Calendar, Bookings, Tickets, and more! <= 6.4.7.3 - Authenticated (Contributor+) S…

The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'event', 'location', and 'event_category' shortcodes in all versions up to, and including, 6.4.7.3 due to insufficient input sanitization and output escapin…

πŸ“… Published: June 12, 2024, 11:05 a.m. πŸ”„ Last Modified: April 8, 2026, 7:21 p.m.

4.4

CVSS3.1

CVE-2024-1766 - Download Manager <= 3.2.86 - Authenticated (Subscriber+) Stored Self-Based Cross-Site Scripting

The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via a user's Display Name in all versions up to, and including, 3.2.86 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access …

πŸ“… Published: June 12, 2024, 11:05 a.m. πŸ”„ Last Modified: April 8, 2026, 6:20 p.m.

9.8

CVSS3.1

CVE-2024-4898 - InstaWP Connect – 1-click WP Staging & Migration <= 0.1.0.38 - Missing Authorization to Unauthentic…

The InstaWP Connect – 1-click WP Staging & Migration plugin for WordPress is vulnerable to arbitrary option updates due to a missing authorization checks on the REST API calls in all versions up to, and including, 0.1.0.38. This makes it possible for unauthenticated attackers to connect the site to…

πŸ“… Published: June 12, 2024, 11:05 a.m. πŸ”„ Last Modified: April 8, 2026, 6:21 p.m.

0.0

CVE-2024-5900 -

This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

πŸ“… Published: June 12, 2024, 10:30 a.m. πŸ”„ Last Modified: July 5, 2025, 11:15 p.m.

6.5

CVSS3.1

CVE-2023-40209 - WordPress Highcompress Image Compressor plugin <= 6.0.0 - Broken Access Control vulnerability

Missing Authorization vulnerability in Himalaya Saxena Highcompress Image Compressor.This issue affects Highcompress Image Compressor: from n/a through 6.0.0.

πŸ“… Published: June 12, 2024, 9:53 a.m. πŸ”„ Last Modified: April 28, 2026, 4:08 p.m.

5.3

CVSS3.1

CVE-2023-40603 - WordPress Simple Org Chart plugin <= 2.3.4 - Broken Access Control vulnerability

Missing Authorization vulnerability in Gangesh Matta Simple Org Chart.This issue affects Simple Org Chart: from n/a through 2.3.4.

πŸ“… Published: June 12, 2024, 9:51 a.m. πŸ”„ Last Modified: Nov. 21, 2024, 8:19 a.m.

5.3

CVSS3.1

CVE-2023-41240 - WordPress Pricing Deals for WooCommercePricing Deals for WooCommerce plugin <= 2.0.3.2 - Broken Acc…

Missing Authorization vulnerability in Vark Pricing Deals for WooCommerce.This issue affects Pricing Deals for WooCommerce: from n/a through 2.0.3.2.

πŸ“… Published: June 12, 2024, 9:49 a.m. πŸ”„ Last Modified: Nov. 21, 2024, 8:20 a.m.

4.3

CVSS3.1

CVE-2023-44234 - WordPress WP GPX Maps plugin <= 1.7.08 - Broken Access Control vulnerability

Missing Authorization vulnerability in Bastianon Massimo WP GPX Map.This issue affects WP GPX Map: from n/a through 1.7.08.

πŸ“… Published: June 12, 2024, 9:47 a.m. πŸ”„ Last Modified: Nov. 21, 2024, 8:25 a.m.
Total resulsts: 349182
Page 9485 of 34,919
Β« previous page Β» next page
Filters