9.8

CVSS3.1

CVE-2024-4443 - Business Directory Plugin – Easy Listing Directories for WordPress <= 6.4.2 - Unauthenticated SQL I…

The Business Directory Plugin – Easy Listing Directories for WordPress plugin for WordPress is vulnerable to time-based SQL Injection via the ‘listingfields’ parameter in all versions up to, and including, 6.4.2 due to insufficient escaping on the user supplied parameter and lack of sufficient prep…

📅 Published: May 22, 2024, 5:32 a.m. 🔄 Last Modified: April 8, 2026, 6:21 p.m.

6.4

CVSS3.1

CVE-2024-5092 - Elegant Addons for elementor <= 1.0.8 - Authenticated (Contributor+) Stored Cross-Site Scripting vi…

The Elegant Addons for elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Switcher, Slider, and Iconbox widgets in all versions up to, and including, 1.0.8 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it…

📅 Published: May 22, 2024, 5:32 a.m. 🔄 Last Modified: April 8, 2026, 6:21 p.m.

6.4

CVSS3.1

CVE-2024-3611 - Toolbar Extras for Elementor & More – WordPress Admin Bar Enhanced <= 1.4.9 - Authenticated (Contri…

The Toolbar Extras for Elementor & More – WordPress Admin Bar Enhanced plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'tbex-version' shortcode in all versions up to, and including, 1.4.9 due to insufficient input sanitization and output escaping on user supplied …

📅 Published: May 22, 2024, 5:32 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

6.4

CVSS3.1

CVE-2024-4971 - LearnPress – WordPress LMS Plugin <= 4.2.6.6 - Authenticated (Contributor+) Stored Cross-Site Scrip…

The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘id’ parameter in all versions up to, and including, 4.2.6.6 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject …

📅 Published: May 22, 2024, 5:32 a.m. 🔄 Last Modified: April 8, 2026, 5:18 p.m.

6.5

CVSS3.1

CVE-2024-35162 -

Path traversal vulnerability exists in Download Plugins and Themes from Dashboard versions prior to 1.8.6. If this vulnerability is exploited, a remote authenticated attacker with "switch_themes" privilege may obtain arbitrary files on the server.

📅 Published: May 22, 2024, 5:30 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

4.8

CVSS3.1

CVE-2024-31340 -

TP-Link Tether versions prior to 4.5.13 and TP-Link Tapo versions prior to 3.3.6 do not properly validate certificates, which may allow a remote unauthenticated attacker to eavesdrop on an encrypted communication via a man-in-the-middle attack.

📅 Published: May 22, 2024, 5:29 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

6.6

CVSS3.1

CVE-2024-31396 -

Code injection vulnerability exists in a-blog cms Ver.3.1.x series versions prior to Ver.3.1.12 and Ver.3.0.x series versions prior to Ver.3.0.32. If this vulnerability is exploited, a user with an administrator or higher privilege who can log in to the product may execute an arbitrary command on t…

📅 Published: May 22, 2024, 4:35 a.m. 🔄 Last Modified: May 12, 2025, 2:23 p.m.

6.1

CVSS3.1

CVE-2024-31395 -

Cross-site scripting vulnerability exists in a-blog cms Ver.3.1.x series versions prior to Ver.3.1.12, Ver.3.0.x series versions prior to Ver.3.0.32, Ver.2.11.x series versions prior to Ver.2.11.61, Ver.2.10.x series versions prior to Ver.2.10.53, and Ver.2.9 and earlier versions. If this vulnerabi…

📅 Published: May 22, 2024, 4:35 a.m. 🔄 Last Modified: May 12, 2025, 2:23 p.m.

6.5

CVSS3.1

CVE-2024-31394 -

Directory traversal vulnerability exists in a-blog cms Ver.3.1.x series versions prior to Ver.3.1.12, Ver.3.0.x series versions prior to Ver.3.0.32, Ver.2.11.x series versions prior to Ver.2.11.61, Ver.2.10.x series versions prior to Ver.2.10.53, and Ver.2.9 and earlier versions. If this vulnerabil…

📅 Published: May 22, 2024, 4:35 a.m. 🔄 Last Modified: May 12, 2025, 2:23 p.m.

4.4

CVSS3.1

CVE-2024-30420 -

Server-side request forgery (SSRF) vulnerability exists in a-blog cms Ver.3.1.x series versions prior to Ver.3.1.12 and Ver.3.0.x series versions prior to Ver.3.0.32. If this vulnerability is exploited, a user with an administrator or higher privilege who can log in to the product may obtain arbitr…

📅 Published: May 22, 2024, 4:35 a.m. 🔄 Last Modified: May 12, 2025, 2:23 p.m.
Total resulsts: 349182
Page 9707 of 34,919
« previous page » next page
Filters