9.3

CVSS4.0

CVE-2024-21546 -

Versions of the package unisharp/laravel-filemanager before 2.9.1 are vulnerable to Remote Code Execution (RCE) through using a valid mimetype and inserting the . character after the php file extension. This allows the attacker to execute malicious code.

πŸ“… Published: Dec. 18, 2024, 6:06 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.5

CVSS3.1

CVE-2024-4464 -

Authorization bypass through user-controlled key vulnerability in streaming service in Synology Media Server before 1.4-2680, 2.0.5-3152 and 2.2.0-3325 allows remote attackers to read specific files via unspecified vectors.

πŸ“… Published: Dec. 18, 2024, 6 a.m. πŸ”„ Last Modified: Jan. 29, 2026, 5:47 p.m.

5.4

CVSS3.1

CVE-2024-10892 - Cost Calculator Builder < 3.2.43 - Settings update via CSRF

The Cost Calculator Builder WordPress plugin before 3.2.43 does not have CSRF checks in some AJAX actions, which could allow attackers to make logged in users perform unwanted actions via CSRF attacks.

πŸ“… Published: Dec. 18, 2024, 6 a.m. πŸ”„ Last Modified: May 14, 2025, 8:14 p.m.

4.3

CVSS3.1

CVE-2024-12061 - Events Addon for Elementor <= 2.2.3 - Authenticated (Contributor+) Post Disclosure

The Events Addon for Elementor plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 2.2.3 via the naevents_elementor_template shortcode due to insufficient restrictions on which posts can be included. This makes it possible for authenticated attackers, wi…

πŸ“… Published: Dec. 18, 2024, 3:22 a.m. πŸ”„ Last Modified: April 8, 2026, 5:33 p.m.

5.3

CVSS3.1

CVE-2024-12250 - Accept Authorize.NET Payments Using Contact Form 7 <= 2.2 - Unauthenticated Information Exposure

The Accept Authorize.NET Payments Using Contact Form 7 plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 2.2 via the cf7adn-info.php file. This makes it possible for unauthenticated attackers to extract configuration data which can be used to aid in ot…

πŸ“… Published: Dec. 18, 2024, 3:22 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.4

CVSS3.1

CVE-2024-12449 - Video Share VOD – Turnkey Video Site Builder Script <= 2.6.30 - Authenticated (Contributor+) Stored…

The Video Share VOD – Turnkey Video Site Builder Script plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'videowhisper_player_html' shortcode in all versions up to, and including, 2.6.30 due to insufficient input sanitization and output escaping on user supplied at…

πŸ“… Published: Dec. 18, 2024, 3:22 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

4.3

CVSS3.1

CVE-2024-12596 - LifterLMS – WP LMS for eLearning, Online Courses, & Quizzes <= 7.8.5 - Missing Authorization to Aut…

The LifterLMS – WP LMS for eLearning, Online Courses, & Quizzes plugin for WordPress is vulnerable to arbitrary post deletion due to a missing capability check on the 'llms_delete_cert' action in all versions up to, and including, 7.8.5. This makes it possible for authenticated attackers, with Subs…

πŸ“… Published: Dec. 18, 2024, 3:22 a.m. πŸ”„ Last Modified: April 8, 2026, 5:06 p.m.

8.8

CVSS3.1

CVE-2024-12259 - CRM WordPress Plugin – RepairBuddy <= 3.8120 - Missing Authorization to Account Takeover/Privilege …

The CRM WordPress Plugin – RepairBuddy plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 3.8120. This is due to the plugin not properly validating a user's identity prior to updating their email through the wc_update_user_data AJAX…

πŸ“… Published: Dec. 18, 2024, 3:22 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.1

CVSS3.1

CVE-2024-11254 - AMP for WP – Accelerated Mobile Pages <= 1.1.1 - Reflected Cross-Site Scripting

The AMP for WP – Accelerated Mobile Pages plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the disqus_name parameter in all versions up to, and including, 1.1.1 due to insufficient input validation. This makes it possible for unauthenticated attackers to inject arbitrary web…

πŸ“… Published: Dec. 18, 2024, 3:22 a.m. πŸ”„ Last Modified: April 8, 2026, 4:55 p.m.

7.5

CVSS3.1

CVE-2024-12025 - Collapsing Categories <= 3.0.8 - Unauthenticated SQL Injection

The Collapsing Categories plugin for WordPress is vulnerable to SQL Injection via the 'taxonomy' parameter of the /wp-json/collapsing-categories/v1/get REST API in all versions up to, and including, 3.0.8 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation…

πŸ“… Published: Dec. 18, 2024, 3:22 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 347572
Page 7266 of 34,758
Β« previous page Β» next page
Filters