5.3

CVSS3.1

CVE-2023-27283 - IBM Aspera Orchestrator information disclosure

IBM Aspera Orchestrator 4.0.1 could allow a remote attacker to enumerate usernames due to observable response discrepancies. IBM X-Force ID: 248545.

πŸ“… Published: May 4, 2024, 1:16 p.m. πŸ”„ Last Modified: Jan. 7, 2025, 9:08 p.m.

4.3

CVSS3.1

CVE-2024-1050 - Import and export users and customers <= 1.26.5 - Missing Authorization

The Import and export users and customers plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the ajax_force_reset_password_delete_metas() function in all versions up to, and including, 1.26.5. This makes it possible for authenticated attacke…

πŸ“… Published: May 4, 2024, 7:36 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.4

CVSS3.1

CVE-2023-7065 - Stop Spammers Security | Block Spam Users, Comments, Forms <= 2024.4 - Cross-Site Request Forgery (…

The Stop Spammers Security | Block Spam Users, Comments, Forms plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2024.4. This is due to missing or incorrect nonce validation on the sfs_process AJAX action. This makes it possible for unauthenticat…

πŸ“… Published: May 4, 2024, 7:36 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.8

CVSS3.1

CVE-2024-3240 - ConvertPlug <= 3.5.25 - Authenticated (Contributor+) PHP Object Injection

The ConvertPlug plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.5.25 via deserialization of untrusted input from the 'settings_encoded' attribute of the 'smile_info_bar' shortcode. This makes it possible for authenticated attackers, with contributo…

πŸ“… Published: May 4, 2024, 3:31 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.4

CVSS3.1

CVE-2024-3237 - ConvertPlug <= 3.5.25 - Missing Authorization to Authenticated (Subscriber+) Limited Arbitrary Opti…

The ConvertPlug plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the cp_dismiss_notice() function in all versions up to, and including, 3.5.25. This makes it possible for authenticated attackers, with subscriber-level access and above, to …

πŸ“… Published: May 4, 2024, 3:31 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.4

CVSS3.1

CVE-2024-3868 - Folders Pro <= 3.0.2 - Authenticated (Subscriber+) Stored Cross-Site Scripting via User First Name …

The Folders Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via a user's First Name and Last Name in all versions up to, and including, 3.0.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level a…

πŸ“… Published: May 4, 2024, 2:31 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.1

CVSS3.1

CVE-2024-34468 -

Rukovoditel before 3.5.3 allows XSS via user_photo to My Page.

πŸ“… Published: May 4, 2024, midnight πŸ”„ Last Modified: June 17, 2025, 3:01 p.m.

7.1

CVSS3.1

CVE-2024-34469 -

Rukovoditel before 3.5.3 allows XSS via user_photo to index.php?module=users/registration&action=save.

πŸ“… Published: May 4, 2024, midnight πŸ”„ Last Modified: June 17, 2025, 2:57 p.m.

6.1

CVSS3.1

CVE-2024-34467 -

ThinkPHP 8.0.3 allows remote attackers to exploit XSS due to inadequate filtering of function argument values in think_exception.tpl.

πŸ“… Published: May 4, 2024, midnight πŸ”„ Last Modified: June 17, 2025, 3:02 p.m.

5.3

CVSS3.1

CVE-2024-34473 -

An issue was discovered in appmgr in O-RAN Near-RT RIC I-Release. An attacker could register an unintended RMR message type during xApp registration to disrupt other service components.

πŸ“… Published: May 4, 2024, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 349182
Page 9986 of 34,919
Β« previous page Β» next page
Filters