5.3

CVSS3.1

CVE-2024-3933 - Eclipse Open J9 With -Xgc:concurrentScavenge on IBM Z, could write/read outside of a buffer

In Eclipse OpenJ9 release versions prior to 0.44.0 and after 0.13.0, when running with JVM option -Xgc:concurrentScavenge, the sequence generated for System.arrayCopy on the IBM Z platform with hardware and software support for guarded storage [1], could allow access to a buffer with an incorrect lโ€ฆ

๐Ÿ“… Published: May 27, 2024, 6:08 a.m. ๐Ÿ”„ Last Modified: Jan. 9, 2025, 6 p.m.

8.8

CVSS3.1

CVE-2024-4535 - KKProgressbar2 Free <= 1.1.4.2 - Progress Bar Deletion via CSRF

The KKProgressbar2 Free WordPress plugin through 1.1.4.2 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions via CSRF attacks

๐Ÿ“… Published: May 27, 2024, 6 a.m. ๐Ÿ”„ Last Modified: May 19, 2025, 6:29 p.m.

6.1

CVSS3.1

CVE-2024-4534 - KKProgressbar2 Free <= 1.1.4.2 - Stored XSS via CSRF

The KKProgressbar2 Free WordPress plugin through 1.1.4.2 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack

๐Ÿ“… Published: May 27, 2024, 6 a.m. ๐Ÿ”„ Last Modified: May 19, 2025, 6:29 p.m.

6.5

CVSS3.1

CVE-2024-4533 - KKProgressbar2 Free <= 1.1.4.2 - Admin+ SQL Injection

The KKProgressbar2 Free WordPress plugin through 1.1.4.2 does not sanitize and escape a parameter before using it in a SQL statement, allowing admin users to perform SQL injection attacks

๐Ÿ“… Published: May 27, 2024, 6 a.m. ๐Ÿ”„ Last Modified: May 19, 2025, 6:29 p.m.

6.4

CVSS3.1

CVE-2024-4532 - Business Card <= 1.0.0 - Arbitrary Card Deletion via CSRF

The Business Card WordPress plugin through 1.0.0 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions such as deleting cards via CSRF attacks

๐Ÿ“… Published: May 27, 2024, 6 a.m. ๐Ÿ”„ Last Modified: May 1, 2025, 2:06 p.m.

7.1

CVSS3.1

CVE-2024-4531 - Business Card <= 1.0.0 - Card Edit via CSRF

The Business Card WordPress plugin through 1.0.0 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions such as editing cards via CSRF attacks

๐Ÿ“… Published: May 27, 2024, 6 a.m. ๐Ÿ”„ Last Modified: May 1, 2025, 2:09 p.m.

6.3

CVSS3.1

CVE-2024-4530 - Business Card <= 1.0.0 - Category Edit via CSRF

The Business Card WordPress plugin through 1.0.0 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions such as editing card categories via CSRF attacks

๐Ÿ“… Published: May 27, 2024, 6 a.m. ๐Ÿ”„ Last Modified: May 1, 2025, 2:10 p.m.

5.0

CVSS3.1

CVE-2024-4529 - Business Card <= 1.0.0 - Category Deletion via CSRF

The Business Card WordPress plugin through 1.0.0 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions such as deleting card categories via CSRF attacks

๐Ÿ“… Published: May 27, 2024, 6 a.m. ๐Ÿ”„ Last Modified: May 1, 2025, 2:13 p.m.

5.4

CVSS3.1

CVE-2024-3939 - Ditty < 3.1.36 - Author+ Stored XSS

The Ditty WordPress plugin before 3.1.36 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

๐Ÿ“… Published: May 27, 2024, 6 a.m. ๐Ÿ”„ Last Modified: May 21, 2025, 7:05 p.m.

8.8

CVSS3.1

CVE-2024-5400 - Openfind Mail2000 - OS Command Injection

Openfind Mail2000 does not properly filter parameters of specific CGI. Remote attackers with regular privileges can exploit this vulnerability to execute arbitrary system commands on the remote server.

๐Ÿ“… Published: May 27, 2024, 5:36 a.m. ๐Ÿ”„ Last Modified: Jan. 26, 2026, 1:42 p.m.
Total resulsts: 349182
Page 9663 of 34,919
ยซ previous page ยป next page
Filters