7.2

CVSS3.1

CVE-2024-10388 - WordPress GDPR <= 2.0.2 - Unauthenticated Stored Cross-Site Scripting

The WordPress GDPR plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'gdpr_firstname' and 'gdpr_lastname' parameters in all versions up to, and including, 2.0.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers t…

πŸ“… Published: Nov. 19, 2024, 7:35 a.m. πŸ”„ Last Modified: April 8, 2026, 5:19 p.m.

6.5

CVSS3.1

CVE-2024-11069 - WordPress GDPR <= 2.0.2 - Missing Authorization to Unauthenticated Arbitrary User Deletion

The WordPress GDPR plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the 'WordPress_GDPR_Data_Delete::check_action' function in all versions up to, and including, 2.0.2. This makes it possible for unauthenticated attackers to delete arbitrary users.

πŸ“… Published: Nov. 19, 2024, 7:35 a.m. πŸ”„ Last Modified: April 8, 2026, 5:12 p.m.

6.4

CVSS3.1

CVE-2024-10268 - MP3 Audio Player – Music Player, Podcast Player & Radio by Sonaar <= 5.8 - Authenticated (Contribut…

The MP3 Audio Player – Music Player, Podcast Player & Radio by Sonaar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's sonaar_audioplayer shortcode in all versions up to, and including, 5.8 due to insufficient input sanitization and output escaping on user supplied…

πŸ“… Published: Nov. 19, 2024, 7:35 a.m. πŸ”„ Last Modified: April 8, 2026, 5:04 p.m.

5.5

CVSS3.1

CVE-2024-11098 - SVG Block <= 1.1.24 - Authenticated (Administrator+) Stored Cross-Site Scripting via SVG File Upload

The SVG Block plugin for WordPress is vulnerable to Stored Cross-Site Scripting via REST API SVG File uploads in all versions up to, and including, 1.1.24 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Administrator-level access …

πŸ“… Published: Nov. 19, 2024, 7:35 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.1

CVSS3.1

CVE-2024-10103 - MailPoet < 5.3.2 - Admin+ Stored XSS

In the process of testing the MailPoet WordPress plugin before 5.3.2, a vulnerability was found that allows you to implement Stored XSS on behalf of the editor by embedding malicious script, which entails account takeover backdoor

πŸ“… Published: Nov. 19, 2024, 6 a.m. πŸ”„ Last Modified: June 12, 2025, 5:01 p.m.

7.5

CVSS3.1

CVE-2024-8403 - Denial-of-Service Vulnerability in Ethernet port on MELSEC iQ-F Ethernet Module and EtherNet/IP Mod…

Improper Validation of Specified Type of Input vulnerability in Mitsubishi Electric Corporation MELSEC iQ-F Series FX5-ENET versions 1.100 to 1.200 and FX5-ENET/IP versions 1.100 to 1.104 allows a remote attacker to cause a Denial of Service condition in Ethernet communication of the products by se…

πŸ“… Published: Nov. 19, 2024, 5:57 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.5

CVSS3.1

CVE-2024-21539 -

Versions of the package @eslint/plugin-kit before 0.2.3 are vulnerable to Regular Expression Denial of Service (ReDoS) due to improper input sanitization. An attacker can increase the CPU usage and crash the program by exploiting this vulnerability.

πŸ“… Published: Nov. 19, 2024, 5 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

0.0

CVE-2024-11397 -

This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

πŸ“… Published: Nov. 19, 2024, 2:30 a.m. πŸ”„ Last Modified: Feb. 11, 2025, 2:15 a.m.

5.5

CVSS3.1

CVE-2024-50302 - HID: core: zero-initialize the report buffer

In the Linux kernel, the following vulnerability has been resolved: HID: core: zero-initialize the report buffer Since the report buffer is used by all kinds of drivers in various ways, let's zero-initialize it during allocation to make sure that it can't be ever used to leak kernel memory via sp…

πŸ“… Published: Nov. 19, 2024, midnight πŸ”„ Last Modified: Nov. 4, 2025, 2:36 p.m.

5.5

CVSS3.1

CVE-2024-50272 - filemap: Fix bounds checking in filemap_read()

In the Linux kernel, the following vulnerability has been resolved: filemap: Fix bounds checking in filemap_read() If the caller supplies an iocb->ki_pos value that is close to the filesystem upper limit, and an iterator with a count that causes us to overflow that limit, then filemap_read() ente…

πŸ“… Published: Nov. 19, 2024, midnight πŸ”„ Last Modified: Nov. 3, 2025, 11:17 p.m.
Total resulsts: 349182
Page 7814 of 34,919
Β« previous page Β» next page
Filters