4.3

CVSS3.1

CVE-2024-5459 - Restaurant Menu and Food Ordering <= 2.4.16 - Missing Authorization to Menu Creation

The Restaurant Menu and Food Ordering plugin for WordPress is vulnerable to unauthorized creation of data due to a missing capability check on 'add_section', 'add_menu', 'add_menu_item', and 'add_menu_page' functions in all versions up to, and including, 2.4.16. This makes it possible for authenticโ€ฆ

๐Ÿ“… Published: June 5, 2024, 12:45 p.m. ๐Ÿ”„ Last Modified: April 8, 2026, 5:19 p.m.

7.5

CVSS3.1

CVE-2024-1662 - Information Disclosure in Porty's PowerBank

Missing Authentication for Critical Function, Missing Authorization vulnerability in PORTY Smart Tech Technology Joint Stock Company PowerBank Application allows Retrieve Embedded Sensitive Data.This issue affects PowerBank Application: before 2.02.

๐Ÿ“… Published: June 5, 2024, 11:51 a.m. ๐Ÿ”„ Last Modified: Oct. 14, 2025, 1:15 p.m.

7.7

CVSS3.1

CVE-2024-5526 -

Grafana OnCall is an easy-to-use on-call management tool that will help reduce toil in on-call management through simpler workflows and interfaces that are tailored specifically for engineers. Grafana OnCall, from version 1.1.37 before 1.5.2 are vulnerable to a Server Side Request Forgery (SSRF) vโ€ฆ

๐Ÿ“… Published: June 5, 2024, 11:21 a.m. ๐Ÿ”„ Last Modified: Nov. 21, 2024, 9:47 a.m.

6.4

CVSS3.1

CVE-2024-4001 - Download Manager <= 3.2.93 - Authenticated (Contributor+) Stored Cross-Site Scripting via wpdm_modaโ€ฆ

The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wpdm_modal_login_form' shortcode in all versions up to, and including, 3.2.93 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for aโ€ฆ

๐Ÿ“… Published: June 5, 2024, 11:01 a.m. ๐Ÿ”„ Last Modified: April 8, 2026, 7:21 p.m.

6.4

CVSS3.1

CVE-2024-5536 - GamiPress โ€“ Link <= 1.1.4 - Authenticated (Contributor+) Stored Cross-Site Scripting

The GamiPress โ€“ Link plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's gamipress_link shortcode in all versions up to, and including, 1.1.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticatโ€ฆ

๐Ÿ“… Published: June 5, 2024, 9:32 a.m. ๐Ÿ”„ Last Modified: April 8, 2026, 6:22 p.m.

6.4

CVSS3.1

CVE-2024-4821 - WP Shortcodes Plugin โ€” Shortcodes Ultimate <= 7.1.6 - Authenticated (Contributor+) Stored Cross-Sitโ€ฆ

The WP Shortcodes Plugin โ€” Shortcodes Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's su_lightbox shortcode in all versions up to, and including, 7.1.6 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it pโ€ฆ

๐Ÿ“… Published: June 5, 2024, 8:33 a.m. ๐Ÿ”„ Last Modified: April 8, 2026, 7:21 p.m.

8.8

CVSS3.1

CVE-2024-4743 - LifterLMS โ€“ WordPress LMS Plugin for eLearning <= 7.6.2 - Authenticated (Contributor+) SQL Injectioโ€ฆ

The LifterLMS โ€“ WordPress LMS Plugin for eLearning plugin for WordPress is vulnerable to SQL Injection via the orderBy attribute of the lifterlms_favorites shortcode in all versions up to, and including, 7.6.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparโ€ฆ

๐Ÿ“… Published: June 5, 2024, 8:33 a.m. ๐Ÿ”„ Last Modified: April 8, 2026, 6:21 p.m.

6.4

CVSS3.1

CVE-2024-5571 - EmbedPress โ€“ Embed PDF, Google Docs, Vimeo, Wistia, Embed YouTube Videos, Audios, Maps & Embed Any โ€ฆ

The EmbedPress โ€“ Embed PDF, Google Docs, Vimeo, Wistia, Embed YouTube Videos, Audios, Maps & Embed Any Documents in Gutenberg & Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'url' attribute within the plugin's EmbedPress PDF widget in all versions up to, and inโ€ฆ

๐Ÿ“… Published: June 5, 2024, 8:33 a.m. ๐Ÿ”„ Last Modified: April 8, 2026, 6:22 p.m.

7.5

CVSS3.1

CVE-2024-1272 - Information Disclosure to Source Code in TNB Mobile Solutions' Cockpit Software

Inclusion of Sensitive Information in Source Code vulnerability in TNB Mobile Solutions Cockpit Software allows Retrieve Embedded Sensitive Data.This issue affects Cockpit Software: before v0.251.1.

๐Ÿ“… Published: June 5, 2024, 8:28 a.m. ๐Ÿ”„ Last Modified: Sept. 12, 2025, 7:15 a.m.

6.4

CVSS3.1

CVE-2024-23669 -

An improper authorization in Fortinet FortiWebManager version 7.2.0 and 7.0.0 through 7.0.4 and 6.3.0 and 6.2.3 through 6.2.4 and 6.0.2 allows attacker to execute unauthorized code or commands via HTTP requests or CLI.

๐Ÿ“… Published: June 5, 2024, 7:45 a.m. ๐Ÿ”„ Last Modified: Nov. 21, 2024, 8:58 a.m.
Total resulsts: 349182
Page 9577 of 34,919
ยซ previous page ยป next page
Filters