CVE Feed

    Dashboard / CVE

    8.8
    High

    CVE-2024-4845

    Last Modified: 8 Apr 2026

    The Icegram Express plugin for WordPress is vulnerable to SQL Injection via the ‘options[list_id]’ parameter in all versions up to, and including, 5.7.22 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with Subscriber-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

    Published: 12 Jun 2024
    4.3
    Medium

    CVE-2023-47845

    Last Modified: 15 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Lim Kai Yang Grab & Save.This issue affects Grab & Save: from n/a through 1.0.4.

    Published: 12 Jun 2024
    7.5
    High

    CVE-2023-48280

    Last Modified: 15 Apr 2026

    Missing Authorization vulnerability in Consensu.IO Consensu.Io.This issue affects Consensu.Io: from n/a through 1.0.1.

    Published: 12 Jun 2024
    5.3
    Medium

    CVE-2023-51413

    Last Modified: 15 Apr 2026

    Missing Authorization vulnerability in Piotnet Forms.This issue affects Piotnet Forms: from n/a through 1.0.29.

    Published: 12 Jun 2024
    4.3
    Medium

    CVE-2023-47828

    Last Modified: 28 Apr 2026

    Missing Authorization vulnerability in Mandrill wpMandrill.This issue affects wpMandrill: from n/a through 1.33.

    Published: 12 Jun 2024
    4.3
    Medium

    CVE-2023-51524

    Last Modified: 21 Nov 2024

    Missing Authorization vulnerability in weForms.This issue affects weForms: from n/a through 1.6.18.

    Published: 12 Jun 2024
    4.3
    Medium

    CVE-2023-51526

    Last Modified: 15 Apr 2026

    Missing Authorization vulnerability in Brett Shumaker Simple Staff List.This issue affects Simple Staff List: from n/a through 2.2.4.

    Published: 12 Jun 2024
    5.3
    Medium

    CVE-2023-51537

    Last Modified: 21 Nov 2024

    Missing Authorization vulnerability in Awesome Support Team Awesome Support.This issue affects Awesome Support: from n/a through 6.1.5.

    Published: 12 Jun 2024
    4.3
    Medium

    CVE-2023-51670

    Last Modified: 21 Nov 2024

    Missing Authorization vulnerability in FunnelKit FunnelKit Checkout.This issue affects FunnelKit Checkout: from n/a through 3.10.3.

    Published: 12 Jun 2024
    5.4
    Medium

    CVE-2023-51671

    Last Modified: 21 Nov 2024

    Missing Authorization vulnerability in FunnelKit FunnelKit Checkout.This issue affects FunnelKit Checkout: from n/a through 3.10.3.

    Published: 12 Jun 2024
    5.4
    Medium

    CVE-2023-51679

    Last Modified: 28 Apr 2026

    Missing Authorization vulnerability in BulkGate BulkGate SMS Plugin for WooCommerce.This issue affects BulkGate SMS Plugin for WooCommerce: from n/a through 3.0.2.

    Published: 12 Jun 2024
    4.3
    Medium

    CVE-2023-51680

    Last Modified: 21 Nov 2024

    Missing Authorization vulnerability in TechnoVama Quotes for WooCommerce.This issue affects Quotes for WooCommerce: from n/a through 2.0.1.

    Published: 12 Jun 2024
    4.3
    Medium

    CVE-2023-52117

    Last Modified: 21 Nov 2024

    Missing Authorization vulnerability in Metagauss ProfileGrid.This issue affects ProfileGrid: from n/a through 5.6.6.

    Published: 12 Jun 2024
    5.4
    Medium

    CVE-2023-52177

    Last Modified: 2 Dec 2025

    Missing Authorization vulnerability in SoftLab Integrate Google Drive.This issue affects Integrate Google Drive: from n/a through 1.3.3.

    Published: 12 Jun 2024
    6.5
    Medium

    CVE-2024-5468

    Last Modified: 15 Apr 2026

    The WordPress Header Builder Plugin – Pearl plugin for WordPress is vulnerable to unauthorized site option deletion due to a missing validation and capability checks on the stm_hb_delete() function in all versions up to, and including, 1.3.7. This makes it possible for unauthenticated attackers to delete arbitrary options that can be used to perform a denial of service attack on a site.

    Published: 12 Jun 2024
    6.4
    Medium

    CVE-2024-5266

    Last Modified: 8 Apr 2026

    The Download Manager Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via wpdm_user_dashboard, wpdm_package, wpdm_packages, wpdm_search_result, and wpdm_tag shortcodes in all versions up to, and including, 3.2.92 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 12 Jun 2024
    6.4
    Medium

    CVE-2024-3925

    Last Modified: 8 Apr 2026

    The Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Creative Button widget in all versions up to, and including, 5.6.11 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 12 Jun 2024
    6.1
    Medium

    CVE-2024-5739

    Last Modified: 19 Dec 2025

    The in-app browser of LINE client for iOS versions below 14.9.0 contains a Universal XSS (UXSS) vulnerability. This vulnerability allows for cross-site scripting (XSS) where arbitrary JavaScript can be executed in the top frame from an embedded iframe on any displayed web site within the in-app browser. The in-app browser is usually opened by tapping on URLs contained in chat messages, and for the attack to be successful, the victim must trigger a click event on a malicious iframe. If an iframe embedded in any website can be controlled by an attacker, this vulnerability could be exploited to capture or alter content displayed in the top frame, as well as user session information. This vulnerability affects LINE client for iOS versions below 14.9.0 and does not affect other LINE clients such as LINE client for Android. Please update LINE client for iOS to version 14.9.0 or higher.

    Published: 12 Jun 2024
    4.7
    Medium

    CVE-2024-28970

    Last Modified: 21 Nov 2024

    Dell Client BIOS contains an Out-of-bounds Write vulnerability. A local authenticated malicious user with admin privileges could potentially exploit this vulnerability, leading to platform denial of service.

    Published: 12 Jun 2024
    6.1
    Medium

    CVE-2024-4924

    Last Modified: 30 May 2025

    The Social Sharing Plugin WordPress plugin before 3.3.63 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

    Published: 12 Jun 2024
    6.4
    Medium

    CVE-2024-5892

    Last Modified: 15 Apr 2026

    The Divi Torque Lite – Divi Theme and Extra Theme plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘support_unfiltered_files_upload’ function in all versions up to, and including, 3.6.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 12 Jun 2024
    5.3
    Medium

    CVE-2024-36454

    Last Modified: 15 Apr 2026

    Use of uninitialized resource issue exists in IPCOM EX2 Series (V01L0x Series) V01L07NF0201 and earlier, and IPCOM VE2 Series V01L07NF0201 and earlier. If this vulnerability is exploited, the system may be rebooted or suspended by receiving a specially crafted packet.

    Published: 12 Jun 2024
    6.4
    Medium

    CVE-2024-3559

    Last Modified: 8 Apr 2026

    The Custom Field Suite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the the 'cfs[post_content]' parameter versions up to, and including, 2.6.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 12 Jun 2024
    6.4
    Medium

    CVE-2024-4564

    Last Modified: 15 Apr 2026

    The CoDesigner WooCommerce Builder for Elementor – Customize Checkout, Shop, Email, Products & More plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Shop Slider, Tabs Classic, and Image Comparison widgets in all versions up to, and including, 4.4.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 12 Jun 2024
    4.4
    Medium

    CVE-2024-5553

    Last Modified: 8 Apr 2026

    The Premium Addons for Elementor plugin for WordPress is vulnerable to DOM-Based Stored Cross-Site Scripting via several parameters in all versions up to, and including, 4.10.33 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses and edits an injected element, and subsequently clicks the element with the mouse scroll wheel.

    Published: 12 Jun 2024
    6.8
    Medium

    CVE-2024-0160

    Last Modified: 21 Nov 2024

    Dell Client Platform contains an incorrect authorization vulnerability. An attacker with physical access to the system could potentially exploit this vulnerability by bypassing BIOS authorization to modify settings in the BIOS.

    Published: 12 Jun 2024
    6.3
    Medium

    CVE-2024-0427

    Last Modified: 28 May 2025

    The ARForms - Premium WordPress Form Builder Plugin WordPress plugin before 6.4.1 does not properly escape user-controlled input when it is reflected in some of its AJAX actions.

    Published: 12 Jun 2024
    8.1
    High

    CVE-2024-5543

    Last Modified: 15 Apr 2026

    The Slideshow Gallery LITE plugin for WordPress is vulnerable to time-based SQL Injection via the id parameter in all versions up to, and including, 1.8.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with Contributor-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

    Published: 12 Jun 2024
    6.4
    Medium

    CVE-2024-4892

    Last Modified: 8 Apr 2026

    The BuddyPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘display_name’ parameter in versions up to, and including, 12.4.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 12 Jun 2024
    9.1
    Critical

    CVE-2024-4315

    Last Modified: 15 Apr 2026

    parisneo/lollms version 9.5 is vulnerable to Local File Inclusion (LFI) attacks due to insufficient path sanitization. The `sanitize_path_from_endpoint` function fails to properly sanitize Windows-style paths (backward slash `\`), allowing attackers to perform directory traversal attacks on Windows systems. This vulnerability can be exploited through various routes, including `personalities` and `/del_preset`, to read or delete any file on the Windows filesystem, compromising the system's availability.

    Published: 12 Jun 2024
    6.8
    Medium

    CVE-2024-36103

    Last Modified: 15 Apr 2026

    OS command injection vulnerability in WRC-X5400GS-B v1.0.10 and earlier, and WRC-X5400GSA-B v1.0.10 and earlier allows a network-adjacent attacker with an administrative privilege to execute arbitrary OS commands by sending a specially crafted request to the product.

    Published: 12 Jun 2024
    9.1
    Critical

    CVE-2024-36840

    Last Modified: 15 Apr 2026

    SQL Injection vulnerability in Boelter Blue System Management v.1.3 allows a remote attacker to execute arbitrary code and obtain sensitive information via the id parameter to news_details.php and location_details.php; and the section parameter to services.php.

    Published: 12 Jun 2024
    6.3
    Medium

    CVE-2024-36691

    Last Modified: 15 Apr 2026

    Insecure permissions in the AdminController.AjaxSave() method of PPGo_Jobs v2.8.0 allows authenticated attackers to arbitrarily modify users' account information.

    Published: 12 Jun 2024
    3.7
    Low

    CVE-2023-49559

    Last Modified: 15 Apr 2026

    An issue in vektah gqlparser open-source-library v.2.5.10 allows a remote attacker to cause a denial of service via a crafted script to the parserDirectives function.

    Published: 12 Jun 2024
    7.5
    High

    CVE-2024-36856

    Last Modified: 15 Apr 2026

    RMQTT Broker 0.4.0 is vulnerable to Denial of Service (DoS) due to improper session resource management. An attacker can exhaust system memory and crash the daemon by establishing and maintaining a vast number of long-lived malicious publish/subscribe sessions.

    Published: 12 Jun 2024
    2.6
    Low

    CVE-2024-5798

    Last Modified: 4 Nov 2025

    Vault and Vault Enterprise did not properly validate the JSON Web Token (JWT) role-bound audience claim when using the Vault JWT auth method. This may have resulted in Vault validating a JWT the audience and role-bound claims do not match, allowing an invalid login to succeed when it should have been rejected. This vulnerability, CVE-2024-5798, was fixed in Vault and Vault Enterprise 1.17.0, 1.16.3, and 1.15.9

    Published: 12 Jun 2024
    6.1
    Medium

    CVE-2024-37629

    Last Modified: 7 Oct 2025

    SummerNote v0.9.1 is vulnerable to Cross Site Scripting (XSS) via the Code View Function.

    Published: 12 Jun 2024
    5.4
    Medium

    CVE-2024-22855

    Last Modified: 27 Mar 2025

    A cross-site scripting (XSS) vulnerability in the User Maintenance section of ITSS iMLog v1.307 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Last Name parameter.

    Published: 12 Jun 2024
    5.5
    Medium

    CVE-2024-24051

    Last Modified: 25 Mar 2025

    Improper input validation of printing files in Monoprice Select Mini V2 V37.115.32 allows attackers to instruct the device's movable parts to destinations that exceed the devices' maximum coordinates via the printing of a malicious .gcode file.

    Published: 12 Jun 2024
    6.5
    Medium

    CVE-2024-36523

    Last Modified: 13 Jun 2025

    An access control issue in Wvp GB28181 Pro 2.0 allows users to continue to access information in the application after deleting their own or administrator accounts. This is provided that the users do not log out of their deleted accounts.

    Published: 12 Jun 2024
    0
    Low

    CVE-2024-36699

    Last Modified: 14 Jun 2024

    DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

    Published: 12 Jun 2024
    9.8
    Critical

    CVE-2024-36761

    Last Modified: 23 May 2025

    naga v0.14.0 was discovered to contain a stack overflow via the component /wgsl/parse/mod.rs.

    Published: 12 Jun 2024
    8.8
    High

    CVE-2024-37665

    Last Modified: 13 Jun 2025

    An access control issue in Wvp GB28181 Pro 2.0 allows authenticated attackers to escalate privileges to Administrator via a crafted POST request.

    Published: 12 Jun 2024
    6.1
    Medium

    CVE-2024-37878

    Last Modified: 13 Mar 2025

    Cross Site Scripting vulnerability in TWCMS v.2.0.3 allows a remote attacker to execute arbitrary code via the /TWCMS-gh-pages/twcms/runtime/twcms_view/default,index.htm.php" PHP directly echoes parameters input from external sources

    Published: 12 Jun 2024
    9.6
    Critical

    CVE-2024-35225

    Last Modified: 10 Apr 2025

    Jupyter Server Proxy allows users to run arbitrary external processes alongside their notebook server and provide authenticated web access to them. Versions of 3.x prior to 3.2.4 and 4.x prior to 4.2.0 have a reflected cross-site scripting (XSS) issue. The `/proxy` endpoint accepts a `host` path segment in the format `/proxy/<host>`. When this endpoint is called with an invalid `host` value, `jupyter-server-proxy` replies with a response that includes the value of `host`, without sanitization [2]. A third-party actor can leverage this by sending a phishing link with an invalid `host` value containing custom JavaScript to a user. When the user clicks this phishing link, the browser renders the response of `GET /proxy/<host>`, which runs the custom JavaScript contained in `host` set by the actor. As any arbitrary JavaScript can be run after the user clicks on a phishing link, this issue permits extensive access to the user's JupyterLab instance for an actor. Patches are included in versions 4.2.0 and 3.2.4. As a workaround, server operators who are unable to upgrade can disable the `jupyter-server-proxy` extension.

    Published: 11 Jun 2024
    —
    Unknown

    CVE-2024-5886

    Last Modified: 20 Jun 2024

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

    Published: 11 Jun 2024
    8.8
    High

    CVE-2024-5847

    Last Modified: 13 Feb 2025

    Use after free in PDFium in Google Chrome prior to 126.0.6478.54 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file. (Chromium security severity: Medium)

    Published: 11 Jun 2024
    8.8
    High

    CVE-2024-5846

    Last Modified: 13 Feb 2025

    Use after free in PDFium in Google Chrome prior to 126.0.6478.54 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file. (Chromium security severity: Medium)

    Published: 11 Jun 2024
    8.8
    High

    CVE-2024-5845

    Last Modified: 13 Feb 2025

    Use after free in Audio in Google Chrome prior to 126.0.6478.54 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file. (Chromium security severity: Medium)

    Published: 11 Jun 2024
    8.8
    High

    CVE-2024-5844

    Last Modified: 13 Mar 2025

    Heap buffer overflow in Tab Strip in Google Chrome prior to 126.0.6478.54 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: Medium)

    Published: 11 Jun 2024