5.4

CVSS3.1

CVE-2024-10896 - Logo Slider < 4.5.0 - Contributor+ Stored XSS

The Logo Slider WordPress plugin before 4.5.0 does not sanitise and escape some of its Logo and Slider settings, which could allow high privilege users such as Contributor to perform Stored Cross-Site Scripting

πŸ“… Published: Nov. 28, 2024, 6 a.m. πŸ”„ Last Modified: May 15, 2025, 5:35 p.m.

4.8

CVSS3.1

CVE-2024-10510 - adBuddy+ (AdBlocker Detection) by NetfunkDesign <= 1.1.3 - Admin+ Stored XSS

The adBuddy+ (AdBlocker Detection) by NetfunkDesign WordPress plugin through 1.1.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for examp…

πŸ“… Published: Nov. 28, 2024, 6 a.m. πŸ”„ Last Modified: June 9, 2025, 9:17 p.m.

5.4

CVSS3.1

CVE-2024-10493 - Element Pack Elementor Addons < 5.10.3 - Contributor+ Stored XSS

The Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) WordPress plugin before 5.10.3 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the con…

πŸ“… Published: Nov. 28, 2024, 6 a.m. πŸ”„ Last Modified: May 15, 2025, 5:37 p.m.

5.4

CVSS3.1

CVE-2024-10473 - Logo Slider < 4.5.0 - Author+ Stored XSS

The Logo Slider WordPress plugin before 4.5.0 does not sanitise and escape some of its Logo Settings when outputing them in pages where the Logo Slider shortcode is embed, which could allow users with a role as low as Author to perform Cross-Site Scripting attacks.

πŸ“… Published: Nov. 28, 2024, 6 a.m. πŸ”„ Last Modified: May 15, 2025, 5:39 p.m.

4.3

CVSS3.1

CVE-2024-11918 - Image Alt Text <= 2.0.0 - Missing Authorization to Authenticated (Subscriber+) Image Alt Text Update

The Image Alt Text plugin for WordPress is vulnerable to unauthorized modification of data| due to a missing capability check on the iat_add_alt_txt_action and iat_update_alt_txt_action AJAX actions in all versions up to, and including, 2.0.0. This makes it possible for authenticated attackers, wit…

πŸ“… Published: Nov. 28, 2024, 5:57 a.m. πŸ”„ Last Modified: April 8, 2026, 4:41 p.m.

2.4

CVSS4.0

CVE-2024-46939 - Game Extension Engine Path Traversal Vulnerability

The game extension engine of versions 1.2.7.0 and earlier exposes some components, and attackers can construct parameters to perform path traversal attacks, which can overwriteΒ local specific files

πŸ“… Published: Nov. 28, 2024, 3:26 a.m. πŸ”„ Last Modified: Dec. 2, 2024, 11:19 a.m.

7.8

CVSS3.1

CVE-2024-38658 -

There is an Out-of-bounds read vulnerability in V-Server (v4.0.19.0 and earlier) and V-Server Lite (v4.0.19.0 and earlier). If a user opens a specially crafted file, information may be disclosed and/or arbitrary code may be executed.

πŸ“… Published: Nov. 28, 2024, 2:11 a.m. πŸ”„ Last Modified: Nov. 29, 2024, 9:15 p.m.

7.8

CVSS3.1

CVE-2024-38389 -

There is an Out-of-bounds read vulnerability in TELLUS (v4.0.19.0 and earlier) and TELLUS Lite (v4.0.19.0 and earlier). If a user opens a specially crafted file, information may be disclosed and/or arbitrary code may be executed.

πŸ“… Published: Nov. 28, 2024, 2:11 a.m. πŸ”„ Last Modified: Nov. 29, 2024, 9:15 p.m.

5.3

CVSS3.1

CVE-2024-53008 - HAProxy: HTTP request smuggling in HAProxy

Inconsistent interpretation of HTTP requests ('HTTP Request/Response Smuggling') issue exists in HAProxy. If this vulnerability is exploited, a remote attacker may access a path that is restricted by ACL (Access Control List) set on the product. As a result, the attacker may obtain sensitive infor…

πŸ“… Published: Nov. 28, 2024, 2:10 a.m. πŸ”„ Last Modified: Nov. 29, 2024, 8:55 p.m.

7.8

CVSS3.1

CVE-2024-38309 -

There are multiple stack-based buffer overflow vulnerabilities in V-SFT (v6.2.2.0 and earlier), TELLUS (v4.0.19.0 and earlier), and TELLUS Lite (v4.0.19.0 and earlier). If a user opens a specially crafted file, information may be disclosed and/or arbitrary code may be executed.

πŸ“… Published: Nov. 28, 2024, 2:10 a.m. πŸ”„ Last Modified: Nov. 29, 2024, 9:15 p.m.
Total resulsts: 343944
Page 7158 of 34,395
Β« previous page Β» next page
Filters