8.8

CVSS3.1

CVE-2024-11075 - SICK Incoming Goods Suite privilege escalation vulnerability

A vulnerability in the Incoming Goods Suite allows a user with unprivileged access to the underlying system (e.g. local or via SSH) a privilege escalation to the administrative level due to the usage of component vendor Docker images running with root permissions. Exploiting this misconfiguration l…

📅 Published: Nov. 19, 2024, 1:13 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

6.1

CVSS3.1

CVE-2024-9777 - Ashe <= 2.243 - Reflected Cross-Site Scripting via add_query_arg Parameter

The Ashe theme for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 2.243. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execut…

📅 Published: Nov. 19, 2024, 12:45 p.m. 🔄 Last Modified: April 8, 2026, 5:24 p.m.

6.1

CVSS3.1

CVE-2024-9830 - Bard <= 2.216 - Reflected Cross-Site Scripting via add_query_arg Parameter

The Bard theme for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 2.216. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execut…

📅 Published: Nov. 19, 2024, 12:45 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

6.4

CVSS3.1

CVE-2024-11198 - GD Rating System <= 3.6.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via extra_clas…

The GD Rating System plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘extra_class’ parameter in all versions up to, and including, 3.6.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level a…

📅 Published: Nov. 19, 2024, 12:45 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

6.4

CVSS3.1

CVE-2024-11224 - Parallax Image <= 1.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via position Param…

The Parallax Image plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘position’ parameter in all versions up to, and including, 1.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access a…

📅 Published: Nov. 19, 2024, 12:45 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

8.8

CVSS3.1

CVE-2024-11194 - Classified Listing – Classified ads & Business Directory Plugin <= 3.1.15.1 - Authenticated (Subscr…

The Classified Listing – Classified ads & Business Directory Plugin plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a misconfigured check on the 'rtcl_import_settings' function in all versions up to, and including, 3.1.15.1. This …

📅 Published: Nov. 19, 2024, 11:32 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

6.4

CVSS3.1

CVE-2024-11195 - Email Subscription Popup <= 1.2.22 - Authenticated (Contributor+) Stored Cross-Site Scripting via p…

The Email Subscription Popup plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's print_email_subscribe_form shortcode in all versions up to, and including, 1.2.22 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it pos…

📅 Published: Nov. 19, 2024, 11:02 a.m. 🔄 Last Modified: April 8, 2026, 5:34 p.m.

7.3

CVSS3.1

CVE-2024-11036 - GamiPress – The #1 gamification plugin to reward points, achievements, badges & ranks in WordPress …

The The GamiPress – The #1 gamification plugin to reward points, achievements, badges & ranks in WordPress plugin for WordPress is vulnerable to arbitrary shortcode execution via gamipress_get_user_earnings AJAX action in all versions up to, and including, 7.1.5. This is due to the software allowin…

📅 Published: Nov. 19, 2024, 11:02 a.m. 🔄 Last Modified: April 8, 2026, 5:18 p.m.

7.3

CVSS3.1

CVE-2024-11038 - WPB Popup for Contact Form 7 – Showing The Contact Form 7 Popup on Button Click – CF7 Popup <= 1.7.…

The The WPB Popup for Contact Form 7 – Showing The Contact Form 7 Popup on Button Click – CF7 Popup plugin for WordPress is vulnerable to arbitrary shortcode execution via wpb_pcf_fire_contact_form AJAX action in all versions up to, and including, 1.7.5. This is due to the software allowing users t…

📅 Published: Nov. 19, 2024, 11:02 a.m. 🔄 Last Modified: April 8, 2026, 5:13 p.m.

6.5

CVSS3.1

CVE-2024-31141 - Apache Kafka Clients: Privilege escalation to filesystem read-access via automatic ConfigProvider

Files or Directories Accessible to External Parties, Improper Privilege Management vulnerability in Apache Kafka Clients. Apache Kafka Clients accept configuration data for customizing behavior, and includes ConfigProvider plugins in order to manipulate these configurations. Apache Kafka also prov…

📅 Published: Nov. 19, 2024, 8:40 a.m. 🔄 Last Modified: July 15, 2025, 4:42 p.m.
Total resulsts: 349182
Page 7813 of 34,919
« previous page » next page
Filters