6.4

CVSS3.1

CVE-2024-11091 - Support SVG – Upload svg files in wordpress without hassle <= 1.1.0 - Authenticated (Author+) Stor…

The Support SVG – Upload svg files in wordpress without hassle plugin for WordPress is vulnerable to Stored Cross-Site Scripting via REST API SVG File uploads in all versions up to, and including, 1.1.0 due to insufficient input sanitization and output escaping. This makes it possible for authentic…

📅 Published: Nov. 26, 2024, 8:31 a.m. 🔄 Last Modified: April 8, 2026, 5:27 p.m.

6.4

CVSS3.1

CVE-2024-11192 - Spotify Play Button for WordPress <= 2.11 - Authenticated (Contributor+) Stored Cross-Site Scriptin…

The Spotify Play Button for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's spotifyplaybutton shortcode in all versions up to, and including, 2.11 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possi…

📅 Published: Nov. 26, 2024, 8:31 a.m. 🔄 Last Modified: April 8, 2026, 5:13 p.m.

6.4

CVSS3.1

CVE-2024-11119 - BNE Gallery Extended <= 1.2.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via galler…

The BNE Gallery Extended plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'gallery' shortcode in all versions up to, and including, 1.2.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticate…

📅 Published: Nov. 26, 2024, 8:31 a.m. 🔄 Last Modified: April 8, 2026, 4:41 p.m.

5.5

CVSS3.1

CVE-2024-9170 - Booster for WooCommerce <= 7.2.3 - Authenticated (ShopManager+) Stored Cross-Site Scripting via wcj…

The Booster for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wcj_product_meta shortcode in all versions up to, and including, 7.2.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for au…

📅 Published: Nov. 26, 2024, 8:31 a.m. 🔄 Last Modified: April 8, 2026, 4:34 p.m.

7.5

CVSS3.1

CVE-2024-36254 -

Out-of-bounds read vulnerability exists in Sharp Corporation and Toshiba Tec Corporation multiple MFPs (multifunction printers), which may lead to a denial-of-service (DoS) condition.

📅 Published: Nov. 26, 2024, 7:38 a.m. 🔄 Last Modified: Nov. 26, 2024, 2:48 p.m.

7.5

CVSS3.1

CVE-2024-36251 -

The web interface of the affected devices process some crafted HTTP requests improperly, leading to a device crash. More precisely, a crafted parameter to billcodedef_sub_sel.html is not processed properly and device-crash happens. As for the details of affected product names, model numbers, and ve…

📅 Published: Nov. 26, 2024, 7:38 a.m. 🔄 Last Modified: Nov. 4, 2025, 6:16 p.m.

7.4

CVSS3.1

CVE-2024-36249 -

Cross-site scripting vulnerability exists in Sharp Corporation and Toshiba Tech Corporation multiple MFPs (multifunction printers). If this vulnerability is exploited, an arbitrary script may be executed on the administrative page of the affected MFPs. As for the details of affected product names, …

📅 Published: Nov. 26, 2024, 7:38 a.m. 🔄 Last Modified: Nov. 26, 2024, 2:09 p.m.

9.1

CVSS3.1

CVE-2024-36248 -

API keys for some cloud services are hardcoded in the "main" binary. As for the details of affected product names, model numbers, and versions, refer to the information provided by the respective vendors listed under [References].

📅 Published: Nov. 26, 2024, 7:38 a.m. 🔄 Last Modified: Nov. 4, 2025, 6:16 p.m.

9.1

CVSS3.1

CVE-2024-35244 -

There are several hidden accounts. Some of them are intended for maintenance engineers, and with the knowledge of their passwords (e.g., by examining the coredump), these accounts can be used to re-configure the device. As for the details of affected product names, model numbers, and versions, refe…

📅 Published: Nov. 26, 2024, 7:38 a.m. 🔄 Last Modified: Nov. 4, 2025, 6:16 p.m.

5.3

CVSS3.1

CVE-2024-34162 -

The web interface of the affected devices is designed to hide the LDAP credentials even for administrative users. But configuring LDAP authentication to "SIMPLE", the device communicates with the LDAP server in clear-text. The LDAP password can be retrieved from this clear-text communication. As fo…

📅 Published: Nov. 26, 2024, 7:37 a.m. 🔄 Last Modified: Nov. 4, 2025, 6:16 p.m.
Total resulsts: 343748
Page 7159 of 34,375
« previous page » next page
Filters