5.3

CVSS3.1

CVE-2024-35692 - WordPress GDPR/CCPA Cookie Consent Banner plugin <= 3.2 - Broken Access Control vulnerability

Missing Authorization vulnerability in Termly Cookie Consent.This issue affects Cookie Consent: from n/a through 3.2.

πŸ“… Published: June 11, 2024, 9:21 a.m. πŸ”„ Last Modified: Nov. 21, 2024, 9:20 a.m.

6.5

CVSS3.1

CVE-2024-35716 - WordPress Copymatic plugin <= 1.9 - Broken Access Control vulnerability

Missing Authorization vulnerability in Copymatic Copymatic – AI Content Writer & Generator.This issue affects Copymatic – AI Content Writer & Generator: from n/a through 1.9.

πŸ“… Published: June 11, 2024, 9:19 a.m. πŸ”„ Last Modified: Nov. 21, 2024, 9:20 a.m.

4.3

CVSS3.1

CVE-2023-33922 - WordPress Elementor plugin <= 3.13.2 - Broken Access Control vulnerability

Missing Authorization vulnerability in Elementor Elementor Website Builder.This issue affects Elementor Website Builder: from n/a through 3.13.2.

πŸ“… Published: June 11, 2024, 9:17 a.m. πŸ”„ Last Modified: Nov. 21, 2024, 8:06 a.m.

5.3

CVSS3.1

CVE-2023-28775 - WordPress Yoast SEO Premium plugin <= 20.4 - Unauthenticated Zapier API Key Reset vulnerability

Missing Authorization vulnerability in Yoast Yoast SEO Premium.This issue affects Yoast SEO Premium: from n/a through 20.4.

πŸ“… Published: June 11, 2024, 9:16 a.m. πŸ”„ Last Modified: Nov. 21, 2024, 7:55 a.m.

8.3

CVSS3.1

CVE-2023-25799 - WordPress Tutor LMS plugin <= 2.1.8 - Multiple Broken Access Control vulnerabilities

Missing Authorization vulnerability in Themeum Tutor LMS.This issue affects Tutor LMS: from n/a through 2.1.8.

πŸ“… Published: June 11, 2024, 9:15 a.m. πŸ”„ Last Modified: Nov. 21, 2024, 7:50 a.m.

6.4

CVSS3.1

CVE-2024-5531 - Ocean Extra <= 2.2.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via Flickr Widget

The Ocean Extra plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Flickr widget in all versions up to, and including, 2.2.8 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contri…

πŸ“… Published: June 11, 2024, 8:32 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS3.1

CVE-2024-4266 - MetForm – Contact Form, Survey, Quiz, & Custom Form Builder for Elementor <= 3.8.8 - Unauthenticate…

The MetForm – Contact Form, Survey, Quiz, & Custom Form Builder for Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 3.8.8 via the 'handle_file' function. This can allow unauthenticated attackers to extract sensitive data, such as Pers…

πŸ“… Published: June 11, 2024, 7:32 a.m. πŸ”„ Last Modified: April 8, 2026, 6:21 p.m.

6.5

CVSS3.1

CVE-2020-11843 - Potential information leakage in administrator enabled debug mode

This allows the information exposure to unauthorized users.Β This issue affects NetIQ Access Manager using version 4.5 or before

πŸ“… Published: June 11, 2024, 7:23 a.m. πŸ”„ Last Modified: Nov. 21, 2024, 4:58 a.m.

9.9

CVSS3.1

CVE-2024-3549 - Blog2Social: Social Media Auto Post & Scheduler <= 7.4.1 - Authenticated (Subscriber+) SQL Injection

The Blog2Social: Social Media Auto Post & Scheduler plugin for WordPress is vulnerable to SQL Injection via the 'b2sSortPostType' parameter in all versions up to, and including, 7.4.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL …

πŸ“… Published: June 11, 2024, 6:44 a.m. πŸ”„ Last Modified: April 8, 2026, 6:21 p.m.

8.2

CVSS3.1

CVE-2022-23829 - hw: amd: SPI protection feature may result in a potential arbitrary code execution.

A potential weakness in AMD SPI protection features may allow a malicious attacker with Ring0 (kernel mode) access to bypass the native System Management Mode (SMM) ROM protections.

πŸ“… Published: June 11, 2024, 6:30 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 349182
Page 9508 of 34,919
Β« previous page Β» next page
Filters