CVE Feed

    Dashboard / CVE

    5.4
    Medium

    CVE-2024-31613

    Last Modified: 10 Jun 2025

    BOSSCMS v3.10 is vulnerable to Cross Site Request Forgery (CSRF) in name="head_code" or name="foot_code."

    Published: 10 Jun 2024
    9.1
    Critical

    CVE-2024-32167

    Last Modified: 25 Mar 2025

    Sourcecodester Online Medicine Ordering System 1.0 is vulnerable to Arbitrary file deletion vulnerability as the backend settings have the function of deleting pictures to delete any files.

    Published: 10 Jun 2024
    4.3
    Medium

    CVE-2024-33850

    Last Modified: 20 Jun 2025

    Pexip Infinity before 34.1 has Improper Access Control for persons in a waiting room. They can see the conference roster list, and perform certain actions that should not be allowed before they are admitted to the meeting.

    Published: 10 Jun 2024
    6.5
    Medium

    CVE-2024-35474

    Last Modified: 15 Apr 2026

    A Directory Traversal vulnerability in iceice666 ResourcePack Server before v1.0.8 allows a remote attacker to disclose files on the server, via setPath in ResourcePackFileServer.kt.

    Published: 10 Jun 2024
    8.8
    High

    CVE-2024-36528

    Last Modified: 15 Sept 2025

    nukeviet v.4.5 and before and nukeviet-egov v.1.2.02 and before have a Deserialization vulnerability which results in code execution via /admin/extensions/download.php and /admin/extensions/upload.php.

    Published: 10 Jun 2024
    5.7
    Medium

    CVE-2024-36531

    Last Modified: 15 Sept 2025

    nukeviet v.4.5 and before and nukeviet-egov v.1.2.02 and before are vulnerable to arbitrary code execution via the /admin/extensions/upload.php component.

    Published: 10 Jun 2024
    8.1
    High

    CVE-2024-5389

    Last Modified: 21 Nov 2024

    In lunary-ai/lunary version 1.2.13, an insufficient granularity of access control vulnerability allows users to create, update, get, and delete prompt variations for datasets not owned by their organization. This issue arises due to the application not properly validating the ownership of dataset prompts and their variations against the organization or project of the requesting user. As a result, unauthorized modifications to dataset prompts can occur, leading to altered or removed dataset prompts without proper authorization. This vulnerability impacts the integrity and consistency of dataset information, potentially affecting the results of experiments.

    Published: 9 Jun 2024
    5.3
    Medium

    CVE-2024-35748

    Last Modified: 21 Nov 2024

    Missing Authorization vulnerability in OPMC WooCommerce Dropshipping.This issue affects WooCommerce Dropshipping: from n/a through 5.0.4.

    Published: 9 Jun 2024
    4.3
    Medium

    CVE-2024-32081

    Last Modified: 28 Apr 2026

    Missing Authorization vulnerability in Websupporter Filter Custom Fields & Taxonomies Light.This issue affects Filter Custom Fields & Taxonomies Light: from n/a through 1.05.

    Published: 9 Jun 2024
    5.3
    Medium

    CVE-2024-34802

    Last Modified: 21 Nov 2024

    Missing Authorization vulnerability in AdFoxly AdFoxly – Ad Manager, AdSense Ads & Ads.Txt.This issue affects AdFoxly – Ad Manager, AdSense Ads & Ads.Txt: from n/a through 1.8.5.

    Published: 9 Jun 2024
    5.3
    Medium

    CVE-2024-35661

    Last Modified: 21 Nov 2024

    Missing Authorization vulnerability in SoftLab Upload Fields for WPForms.This issue affects Upload Fields for WPForms: from n/a through 1.0.2.

    Published: 9 Jun 2024
    5.4
    Medium

    CVE-2024-35662

    Last Modified: 21 Nov 2024

    Missing Authorization vulnerability in Andreas Sofantzis Simple COD Fees for WooCommerce.This issue affects Simple COD Fees for WooCommerce: from n/a through 2.0.2.

    Published: 9 Jun 2024
    8.2
    High

    CVE-2024-31275

    Last Modified: 21 Nov 2024

    Missing Authorization vulnerability in Metagauss EventPrime.This issue affects EventPrime: from n/a through 3.3.4.

    Published: 9 Jun 2024
    5.3
    Medium

    CVE-2024-31276

    Last Modified: 21 Nov 2024

    Missing Authorization vulnerability in WPFactory Products, Order & Customers Export for WooCommerce.This issue affects Products, Order & Customers Export for WooCommerce: from n/a through 2.0.8.

    Published: 9 Jun 2024
    7.5
    High

    CVE-2024-31283

    Last Modified: 21 Nov 2024

    Missing Authorization vulnerability in zorem Advanced Local Pickup for WooCommerce.This issue affects Advanced Local Pickup for WooCommerce: from n/a through 1.6.2.

    Published: 9 Jun 2024
    6.5
    Medium

    CVE-2024-31284

    Last Modified: 21 Nov 2024

    Missing Authorization vulnerability in WPDeveloper EmbedPress.This issue affects EmbedPress: from n/a through 3.9.8.

    Published: 9 Jun 2024
    7.1
    High

    CVE-2024-31304

    Last Modified: 28 Apr 2026

    Missing Authorization vulnerability in MultiVendorX WC Marketplace.This issue affects WC Marketplace: from n/a through 4.1.3.

    Published: 9 Jun 2024
    6.3
    Medium

    CVE-2024-31307

    Last Modified: 28 Apr 2026

    Missing Authorization vulnerability in appscreo Easy Social Share Buttons.This issue affects Easy Social Share Buttons: from n/a through 9.4.

    Published: 9 Jun 2024
    4.3
    Medium

    CVE-2024-31347

    Last Modified: 28 Apr 2026

    Missing Authorization vulnerability in Data443 Tracking Code Manager.This issue affects Tracking Code Manager: from n/a through 2.1.0.

    Published: 9 Jun 2024
    4.3
    Medium

    CVE-2024-31350

    Last Modified: 28 Apr 2026

    Missing Authorization vulnerability in AWP Classifieds Team AWP Classifieds.This issue affects AWP Classifieds: from n/a through 4.3.1.

    Published: 9 Jun 2024
    5.3
    Medium

    CVE-2024-31352

    Last Modified: 28 Apr 2026

    Missing Authorization vulnerability in Email Subscribers & Newsletters.This issue affects Email Subscribers & Newsletters: from n/a through 5.7.13.

    Published: 9 Jun 2024
    4.3
    Medium

    CVE-2024-31359

    Last Modified: 28 Apr 2026

    Missing Authorization vulnerability in Premmerce Premmerce Product Filter for WooCommerce premmerce-woocommerce-product-filter.This issue affects Premmerce Product Filter for WooCommerce: from n/a through <= 3.7.2.

    Published: 9 Jun 2024
    4.3
    Medium

    CVE-2024-32701

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in InstaWP InstaWP Connect instawp-connect.This issue affects InstaWP Connect: from n/a through <= 0.1.0.24.

    Published: 9 Jun 2024
    7.7
    High

    CVE-2024-32703

    Last Modified: 23 Apr 2026

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in reputeinfosystems ARForms arforms.This issue affects ARForms: from n/a through <= 6.4.

    Published: 9 Jun 2024
    4.3
    Medium

    CVE-2024-31423

    Last Modified: 21 Nov 2024

    Missing Authorization vulnerability in Alex Volkov WP Accessibility Helper (WAH).This issue affects WP Accessibility Helper (WAH): from n/a through 0.6.2.5.

    Published: 9 Jun 2024
    7.1
    High

    CVE-2024-32704

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in reputeinfosystems ARForms arforms.This issue affects ARForms: from n/a through <= 6.4.

    Published: 9 Jun 2024
    7.1
    High

    CVE-2024-32705

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in reputeinfosystems ARForms arforms.This issue affects ARForms: from n/a through <= 6.4.

    Published: 9 Jun 2024
    5.4
    Medium

    CVE-2024-32713

    Last Modified: 21 Nov 2024

    Missing Authorization vulnerability in AutoWriter AI Post Generator | AutoWriter.This issue affects AI Post Generator | AutoWriter: from n/a through 3.3.

    Published: 9 Jun 2024
    4.3
    Medium

    CVE-2024-32714

    Last Modified: 29 Jan 2025

    Missing Authorization vulnerability in Academy LMS academy.This issue affects Academy LMS: from n/a through 1.9.16.

    Published: 9 Jun 2024
    7.5
    High

    CVE-2024-32715

    Last Modified: 28 Apr 2026

    Missing Authorization vulnerability in Olive Themes Olive One Click Demo Import.This issue affects Olive One Click Demo Import: from n/a through 1.1.1.

    Published: 9 Jun 2024
    5.3
    Medium

    CVE-2024-32725

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in Saleswonder Team: Tobias 5 Stars Rating Funnel 5-stars-rating-funnel.This issue affects 5 Stars Rating Funnel: from n/a through <= 1.2.67.

    Published: 9 Jun 2024
    5.3
    Medium

    CVE-2024-32727

    Last Modified: 28 Apr 2026

    Missing Authorization vulnerability in Rometheme RomethemeForm For Elementor.This issue affects RomethemeForm For Elementor: from n/a through 1.1.2.

    Published: 9 Jun 2024
    7.5
    High

    CVE-2024-32777

    Last Modified: 15 Apr 2026

    Missing Authorization vulnerability in BizSwoop a CPF Concepts, LLC Brand BizPrint.This issue affects BizPrint: from n/a through 4.3.39.

    Published: 9 Jun 2024
    7.7
    High

    CVE-2024-32778

    Last Modified: 23 Apr 2026

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Wasiliy Strecker / ContestGallery developer Contest Gallery contest-gallery.This issue affects Contest Gallery: from n/a through <= 21.3.4.

    Published: 9 Jun 2024
    5.3
    Medium

    CVE-2024-32779

    Last Modified: 15 Apr 2026

    Missing Authorization vulnerability in Avirtum Vision Interactive.This issue affects Vision Interactive: from n/a through 1.7.1.

    Published: 9 Jun 2024
    4.3
    Medium

    CVE-2024-32783

    Last Modified: 15 Apr 2026

    Missing Authorization vulnerability in wpcreativeidea Advanced Testimonial Carousel for Elementor.This issue affects Advanced Testimonial Carousel for Elementor: from n/a through 3.0.0.

    Published: 9 Jun 2024
    4.3
    Medium

    CVE-2024-32784

    Last Modified: 28 Apr 2026

    Missing Authorization vulnerability in CookieHub.This issue affects CookieHub: from n/a through 1.1.0.

    Published: 9 Jun 2024
    4.3
    Medium

    CVE-2024-32787

    Last Modified: 15 Apr 2026

    Missing Authorization vulnerability in Copy Content Protection Team Secure Copy Content Protection and Content Locking.This issue affects Secure Copy Content Protection and Content Locking: from n/a through 3.7.1.

    Published: 9 Jun 2024
    4.3
    Medium

    CVE-2024-32792

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in WPMU DEV - Your All-in-One WordPress Platform Hummingbird hummingbird-performance.This issue affects Hummingbird: from n/a through <= 3.7.3.

    Published: 9 Jun 2024
    5.4
    Medium

    CVE-2024-32797

    Last Modified: 15 Apr 2026

    Missing Authorization vulnerability in Martin Gibson WP LinkedIn Auto Publish.This issue affects WP LinkedIn Auto Publish: from n/a through 8.11.

    Published: 9 Jun 2024
    7.5
    High

    CVE-2024-32798

    Last Modified: 10 Feb 2025

    Missing Authorization vulnerability in WP Travel Engine.This issue affects WP Travel Engine: from n/a through 5.8.0.

    Published: 9 Jun 2024
    5.3
    Medium

    CVE-2024-32799

    Last Modified: 5 Feb 2025

    Missing Authorization vulnerability in Merv Barrett Easy Property Listings.This issue affects Easy Property Listings: from n/a through 3.5.3.

    Published: 9 Jun 2024
    4.3
    Medium

    CVE-2024-32804

    Last Modified: 15 Apr 2026

    Missing Authorization vulnerability in Martin Gibson WP GoToWebinar.This issue affects WP GoToWebinar: from n/a through 14.46.

    Published: 9 Jun 2024
    6.5
    Medium

    CVE-2024-32805

    Last Modified: 15 Apr 2026

    Missing Authorization vulnerability in Social Snap.This issue affects Social Snap: from n/a through 1.3.5.

    Published: 9 Jun 2024
    5.3
    Medium

    CVE-2024-32811

    Last Modified: 15 Apr 2026

    Insertion of Sensitive Information into Log File vulnerability in Octolize USPS Shipping for WooCommerce – Live Rates.This issue affects USPS Shipping for WooCommerce – Live Rates: from n/a through 1.9.4.

    Published: 9 Jun 2024
    5.3
    Medium

    CVE-2024-32813

    Last Modified: 15 Apr 2026

    Missing Authorization vulnerability in SoftLab Integrate Google Drive.This issue affects Integrate Google Drive: from n/a through 1.3.9.

    Published: 9 Jun 2024
    5.3
    Medium

    CVE-2024-32814

    Last Modified: 15 Apr 2026

    Missing Authorization vulnerability in Zorem Advanced Local Pickup for WooCommerce.This issue affects Advanced Local Pickup for WooCommerce: from n/a through 1.6.1.

    Published: 9 Jun 2024
    4.3
    Medium

    CVE-2024-32818

    Last Modified: 26 Feb 2025

    Missing Authorization vulnerability in realmag777 WordPress Meta Data and Taxonomies Filter (MDTF).This issue affects WordPress Meta Data and Taxonomies Filter (MDTF): from n/a through 1.3.3.

    Published: 9 Jun 2024
    5.3
    Medium

    CVE-2024-32820

    Last Modified: 15 Apr 2026

    Missing Authorization vulnerability in Social Share Pro Social Share Icons & Social Share Buttons.This issue affects Social Share Icons & Social Share Buttons: from n/a through 3.6.2.

    Published: 9 Jun 2024
    4.3
    Medium

    CVE-2024-32821

    Last Modified: 15 Apr 2026

    Missing Authorization vulnerability in TotalSuite Total Poll Lite.This issue affects Total Poll Lite: from n/a through 4.9.9.

    Published: 9 Jun 2024