6.4

CVSS3.1

CVE-2024-4160 - Download Manager <= 3.2.90 - Authenticated (Contributor+) Stored Cross-Site Scripting via wpdm-all-…

The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wpdm-all-packages' shortcode in all versions up to, and including, 3.2.90 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authe…

πŸ“… Published: May 31, 2024, 9:31 a.m. πŸ”„ Last Modified: April 8, 2026, 6:21 p.m.

6.4

CVSS3.1

CVE-2024-5347 - Happy Addons for Elementor <= 3.10.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via…

The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'arrow' attribute within the plugin's Post Navigation widget in all versions up to, and including, 3.10.9 due to insufficient input sanitization and output escaping on user supplied attributes. …

πŸ“… Published: May 31, 2024, 9:31 a.m. πŸ”„ Last Modified: April 8, 2026, 6:22 p.m.

7.3

CVSS4.0

CVE-2024-5436 - Type Confusion in Snapchat Lenscore

Type confusion in Snapchat LensCore could lead to denial of service or arbitrary code execution prior to version 12.88. We recommend upgrading to version 12.88 or above.

πŸ“… Published: May 31, 2024, 8:11 a.m. πŸ”„ Last Modified: July 22, 2025, 8:19 p.m.

8.3

CVSS3.1

CVE-2024-5525 - Improper privilege management vulnerability in Astrotalks

Improper privilege management vulnerability in Astrotalks affecting version 10/03/2023. This vulnerability allows a local user to access the application as an administrator without any provided credentials, allowing the attacker to perform administrative actions.

πŸ“… Published: May 31, 2024, 7:35 a.m. πŸ”„ Last Modified: Oct. 23, 2025, 12:24 p.m.

5.3

CVSS3.1

CVE-2024-5524 - Information exposure vulnerability in Astrotalks

Information exposure vulnerability in Astrotalks affecting version 10/03/2023. This vulnerability allows unregistered users to access all internal links of the application without providing any credentials.

πŸ“… Published: May 31, 2024, 7:33 a.m. πŸ”„ Last Modified: Oct. 23, 2025, 12:23 p.m.

8.8

CVSS3.1

CVE-2024-5523 - SQL injection vulnerability in Astrotalks

SQL injection vulnerability in Astrotalks affecting version 10/03/2023. This vulnerability could allow an authenticated local user to send a specially crafted SQL query to the 'searchString' parameter and retrieve all information stored in the database.

πŸ“… Published: May 31, 2024, 7:32 a.m. πŸ”„ Last Modified: Oct. 23, 2025, 12:27 p.m.

6.4

CVSS3.1

CVE-2024-5427 - WPCafe – Online Food Ordering, Restaurant Menu, Delivery, and Reservations for WooCommerce <= 2.2.2…

The WPCafe – Online Food Ordering, Restaurant Menu, Delivery, and Reservations for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Reservation Form shortcode in all versions up to, and including, 2.2.24 due to insufficient input sanitization and output…

πŸ“… Published: May 31, 2024, 6:40 a.m. πŸ”„ Last Modified: April 8, 2026, 6:22 p.m.

9.8

CVSS3.1

CVE-2024-36246 -

Missing authorization vulnerability exists in Unifier and Unifier Cast. If this vulnerability is exploited, arbitrary code may be executed with LocalSystem privilege. As a result, a malicious program may be installed, data may be altered or deleted.

πŸ“… Published: May 31, 2024, 6:11 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.9

CVSS3.1

CVE-2024-23847 -

Incorrect default permissions issue exists in Unifier and Unifier Cast. If this vulnerability is exploited, arbitrary code may be executed with LocalSystem privilege. As a result, a malicious program may be installed, data may be altered or deleted.

πŸ“… Published: May 31, 2024, 6:11 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.5

CVSS3.1

CVE-2024-4469 - Migration Backup Restore < 3.5.0 - Admin+ SSRF

The WP STAGING WordPress Backup Plugin WordPress plugin before 3.5.0 does not prevent users with the administrator role from pinging conducting SSRF attacks, which may be a problem in multisite configurations.

πŸ“… Published: May 31, 2024, 6 a.m. πŸ”„ Last Modified: May 21, 2025, 7:09 p.m.
Total resulsts: 349182
Page 9620 of 34,919
Β« previous page Β» next page
Filters