7.5

CVSS3.1

CVE-2024-4844 -

Hardcoded credentials vulnerability in Trellix ePolicy Orchestrator (ePO) on Premise prior to 5.10 Service Pack 1 Update 2 allows an attacker with admin privileges on the ePO server to read the contents of the orion.keystore file, allowing them to access the ePO database encryption key. This was p…

πŸ“… Published: May 16, 2024, 6:19 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

4.3

CVSS3.1

CVE-2024-4843 -

ePO doesn't allow a regular privileged user to delete tasks or assignments. Insecure direct object references that allow a least privileged user to manipulate the client task and client task assignments, hence escalating his/her privilege.

πŸ“… Published: May 16, 2024, 6:04 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS4.0

CVE-2024-4961 - D-Link DAR-7000-40 onlineuser.php unrestricted upload

** UNSUPPORTED WHEN ASSIGNED ** A vulnerability classified as critical was found in D-Link DAR-7000-40 V31R02B1413C. Affected by this vulnerability is an unknown functionality of the file /user/onlineuser.php. The manipulation of the argument file_upload leads to unrestricted upload. The attack can…

πŸ“… Published: May 16, 2024, 6 a.m. πŸ”„ Last Modified: July 16, 2025, 2:33 p.m.

4.8

CVSS3.1

CVE-2024-3644 - Newsletter Popup <= 1.2 - Admin+ Stored XSS

The Newsletter Popup WordPress plugin through 1.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

πŸ“… Published: May 16, 2024, 6 a.m. πŸ”„ Last Modified: May 19, 2025, 2:32 p.m.

8.8

CVSS3.1

CVE-2024-3643 - Newsletter Popup <= 1.2 - List Deletion via CSRF

The Newsletter Popup WordPress plugin through 1.2 does not have CSRF check when deleting list, which could allow attackers to make logged in admins perform such action via a CSRF attack

πŸ“… Published: May 16, 2024, 6 a.m. πŸ”„ Last Modified: Jan. 9, 2026, 9:16 p.m.

6.9

CVSS3.1

CVE-2024-3642 - Newsletter Popup <= 1.2 - Subscriber Deletion via CSRF

The Newsletter Popup WordPress plugin through 1.2 does not have CSRF check when deleting subscriber, which could allow attackers to make logged in admins perform such action via a CSRF attack

πŸ“… Published: May 16, 2024, 6 a.m. πŸ”„ Last Modified: May 19, 2025, 2:33 p.m.

6.1

CVSS3.1

CVE-2024-3641 - Newsletter Popup <= 1.2 - Unauthenticated Stored XSS

The Newsletter Popup WordPress plugin through 1.2 does not sanitise and escape some parameters, which could allow unauthenticated visitors to perform Cross-Site Scripting attacks against admins

πŸ“… Published: May 16, 2024, 6 a.m. πŸ”„ Last Modified: May 19, 2025, 2:33 p.m.

8.8

CVSS3.1

CVE-2024-4318 - Tutor LMS <= 2.7.0 - Authenticated (Instructor+) SQL Injection

The Tutor LMS plugin for WordPress is vulnerable to time-based SQL Injection via the β€˜question_id’ parameter in versions up to, and including, 2.7.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for …

πŸ“… Published: May 16, 2024, 5:33 a.m. πŸ”„ Last Modified: April 8, 2026, 6:21 p.m.

6.4

CVSS3.1

CVE-2024-4635 - Menu Icons by ThemeIsle <= 0.13.13 - Authenticated (Author+) Stored Cross-Site Scripting via SVG Up…

The Menu Icons by ThemeIsle plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the β€˜add_mime_type’ function in versions up to, and including, 0.13.13 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with author-level …

πŸ“… Published: May 16, 2024, 5:33 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.5

CVSS3.1

CVE-2024-4279 - Tutor LMS – eLearning and online course solution <= 2.7.0 - Authenticated (Instructor+) Insecure Di…

The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to Insecure Direct Object Reference to Arbitrary Course Deletion in versions up to, and including, 2.7.0 via the 'tutor_course_delete' function due to missing validation on a user controlled key. This can allow …

πŸ“… Published: May 16, 2024, 5:33 a.m. πŸ”„ Last Modified: April 8, 2026, 6:21 p.m.
Total resulsts: 349182
Page 9840 of 34,919
Β« previous page Β» next page
Filters