8.7

CVSS4.0

CVE-2024-4978 - Malicious Code in Justice AV Solutions (JAVS) Viewer

Justice AV Solutions Viewer Setup 8.3.7.250-1 contains a malicious binary when executed and is signed with an unexpected authenticode signature. A remote, privileged threat actor may exploit this vulnerability to execute of unauthorized PowerShell commands.

📅 Published: May 23, 2024, 1:56 a.m. 🔄 Last Modified: Oct. 24, 2025, 1:48 p.m.

6.4

CVSS3.1

CVE-2024-3201 - WP DSGVO Tools (GDPR) <= 3.1.32 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shor…

The WP DSGVO Tools (GDPR) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'pp_link' shortcode in all versions up to, and including, 3.1.32 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authentica…

📅 Published: May 23, 2024, 1:56 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

4.4

CVSS3.1

CVE-2024-3065 - PayPal Pay Now, Buy Now, Donation and Cart Buttons Shortcode <= 1.7 - Authenticated (Admin+) Store…

The PayPal Pay Now, Buy Now, Donation and Cart Buttons Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attack…

📅 Published: May 23, 2024, 1:56 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

5

CVSS3.1

CVE-2023-6844 - iframe <= 5.0 - Authenticated(Contributor+) Stored Cross-Site Scripting via shortcode

The iframe plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to and including 5.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contribu…

📅 Published: May 23, 2024, 1:56 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

6.4

CVSS3.1

CVE-2024-4783 - jQuery T(-) Countdown Widget <= 2.3.25 - Authenticated (Contributor+) Stored Cross-Site Scripting v…

The jQuery T(-) Countdown Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's tminus shortcode in all versions up to, and including, 2.3.25 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authen…

📅 Published: May 23, 2024, 1:56 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS3.1

CVE-2024-1855 - WPCafe <= 2.2.23 - Unauthenticated Blind Server-Side Request Forgery

The WPCafe – Restaurant Menu, Online Ordering for WooCommerce, Pickup / Delivery and Table Reservation plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 2.2.23 via the wpc_check_for_submission function. This makes it possible for unauthenticated…

📅 Published: May 23, 2024, 1:56 a.m. 🔄 Last Modified: April 8, 2026, 6:20 p.m.

6.4

CVSS3.1

CVE-2024-4486 - Awesome Contact Form7 for Elementor <= 2.9 - Authenticated (Contributor+) Stored Cross-Site Scripti…

The Awesome Contact Form7 for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'AEP Contact Form 7' widget in all versions up to, and including, 2.9 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for …

📅 Published: May 23, 2024, 1:56 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

0.0

CVE-2024-3708 -

This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

📅 Published: May 23, 2024, 12:11 a.m. 🔄 Last Modified: July 9, 2024, 3:15 p.m.

8.3

CVSS3.1

CVE-2024-5274 - chromium-browser: another type Confusion in V8

Type Confusion in V8 in Google Chrome prior to 125.0.6422.112 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

📅 Published: May 23, 2024, midnight 🔄 Last Modified: Oct. 24, 2025, 2:07 p.m.

6.8

CVSS3.1

CVE-2024-36013 - Bluetooth: L2CAP: Fix slab-use-after-free in l2cap_connect()

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: Fix slab-use-after-free in l2cap_connect() Extend a critical section to prevent chan from early freeing. Also make the l2cap_connect() return type void. Nothing is using the returned value but it is ugly to retu…

📅 Published: May 23, 2024, midnight 🔄 Last Modified: May 4, 2025, 9:10 a.m.
Total resulsts: 349182
Page 9696 of 34,919
« previous page » next page
Filters