9.8

CVSS3.1

CVE-2024-37385 -

Roundcube Webmail before 1.5.7 and 1.6.x before 1.6.7 on Windows allows command injection via im_convert_path and im_identify_path. NOTE: this issue exists because of an incomplete fix for CVE-2020-12641.

πŸ“… Published: June 7, 2024, 3:24 a.m. πŸ”„ Last Modified: Feb. 6, 2026, 5:48 p.m.

6.4

CVSS3.1

CVE-2024-1988 - Post Grid, Form Maker, Popup Maker, WooCommerce Blocks, Post Blocks, Post Carousel – Combo Blocks <…

The Post Grid, Form Maker, Popup Maker, WooCommerce Blocks, Post Blocks, Post Carousel – Combo Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'tag' attribute in blocks in all versions up to, and including, 2.2.80 due to insufficient input sanitization and output es…

πŸ“… Published: June 7, 2024, 3:21 a.m. πŸ”„ Last Modified: April 8, 2026, 7:20 p.m.

6.4

CVSS3.1

CVE-2024-5425 - WP jQuery Lightbox <= 1.5.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via title At…

The WP jQuery Lightbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the β€˜title’ attribute in all versions up to, and including, 1.5.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level acces…

πŸ“… Published: June 7, 2024, 3:21 a.m. πŸ”„ Last Modified: April 8, 2026, 7:21 p.m.

7.5

CVSS3.1

CVE-2024-4887 - Qi Addons For Elementor <= 1.7.2 - Authenticated (Contributor+) Local File Inclusion

The Qi Addons For Elementor plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.7.2 via the 'behavior' attributes found in the qi_addons_for_elementor_blog_list shortcode. This makes it possible for authenticated attackers, with Contributor-level acces…

πŸ“… Published: June 7, 2024, 3:21 a.m. πŸ”„ Last Modified: April 8, 2026, 5:18 p.m.

5.4

CVSS3.1

CVE-2024-5607 - GDPR CCPA Compliance & Cookie Consent Banner <= 2.7.0 - Missing Authorization to Settings Update an…

The GDPR CCPA Compliance & Cookie Consent Banner plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on several functions named ajaxUpdateSettings() in all versions up to, and including, 2.7.0. This makes it possible for authenticated attackers,…

πŸ“… Published: June 7, 2024, 2:39 a.m. πŸ”„ Last Modified: April 8, 2026, 7:21 p.m.

5.4

CVSS3.1

CVE-2024-3987 - WP Mobile Menu – The Mobile-Friendly Responsive Menu <= 2.8.4.2 - Authenticated (Contributor+) Stor…

The WP Mobile Menu – The Mobile-Friendly Responsive Menu plugin for WordPress is vulnerable to Stored Cross-Site Scripting via image alt text in all versions up to, and including, 2.8.4.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers,…

πŸ“… Published: June 7, 2024, 2:39 a.m. πŸ”„ Last Modified: April 8, 2026, 6:21 p.m.

6.4

CVSS3.1

CVE-2024-1768 - Clever Fox <= 25.2.0 - Authenticated (Contributor+) Stored Cross-Site Scripting

The Clever Fox plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's info box block in all versions up to, and including, 25.2.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers wi…

πŸ“… Published: June 7, 2024, 2:39 a.m. πŸ”„ Last Modified: April 8, 2026, 5:18 p.m.

7.6

CVSS3.1

CVE-2023-32475 -

Dell BIOS contains a missing support for integrity check vulnerability. An attacker with physical access to the system could potentially bypass security mechanisms to run arbitrary code on the system.

πŸ“… Published: June 7, 2024, 2:13 a.m. πŸ”„ Last Modified: Nov. 21, 2024, 8:03 a.m.

5.4

CVSS3.1

CVE-2023-6876 - Clever Fox – One Click Website Importer by Nayra Themes <= 25.2.0 - Missing Authorization to arbitr…

The Clever Fox – One Click Website Importer by Nayra Themes plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'clever-fox-activate-theme' function in all versions up to, and including, 25.2.0. This makes it possible for authenticated at…

πŸ“… Published: June 7, 2024, 2:02 a.m. πŸ”„ Last Modified: April 8, 2026, 6:18 p.m.

4.3

CVSS3.1

CVE-2024-1689 - WooCommerce Tools <= 1.2.9 - Missing Authorization to Authenticated (Subscriber+) Plugin Module De…

The WooCommerce Tools plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the woocommerce_tool_toggle_module() function in all versions up to, and including, 1.2.9. This makes it possible for authenticated attackers, with subscriber-level acc…

πŸ“… Published: June 7, 2024, 2:02 a.m. πŸ”„ Last Modified: April 8, 2026, 6:20 p.m.
Total resulsts: 349182
Page 9553 of 34,919
Β« previous page Β» next page
Filters