CVE Feed

    Dashboard / CVE

    5.3
    Medium

    CVE-2023-45009

    Last Modified: 28 Apr 2026

    Improper Restriction of Excessive Authentication Attempts vulnerability in Forge12 Interactive GmbH Captcha/Honeypot for Contact Form 7 allows Functionality Bypass.This issue affects Captcha/Honeypot for Contact Form 7: from n/a through 1.11.3.

    Published: 4 Jun 2024
    7.8
    High

    CVE-2023-5751

    Last Modified: 15 Apr 2026

    A local attacker with low privileges can read and modify any users files and cause a DoS in the working directory of the affected products due to exposure of resource to wrong sphere. 

    Published: 4 Jun 2024
    7.5
    High

    CVE-2024-5000

    Last Modified: 15 Apr 2026

    An unauthenticated remote attacker can use a malicious OPC UA client to send a crafted request to affected CODESYS products which can cause a DoS due to incorrect calculation of buffer size.

    Published: 4 Jun 2024
    6.4
    Medium

    CVE-2024-4581

    Last Modified: 8 Apr 2026

    The Slider Revolution plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Add Layer widget in all versions up to, and including, 6.7.11 due to insufficient input sanitization and output escaping on the user supplied 'class', 'id', and 'title' attributes. This makes it possible for authenticated attackers, with author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. NOTE: Successful exploitation of this vulnerability requires an Administrator to give Slider Creation privileges to Author-level users.

    Published: 4 Jun 2024
    7.1
    High

    CVE-2024-5422

    Last Modified: 15 Apr 2026

    An uncontrolled resource consumption of file descriptors in SEH Computertechnik utnserver Pro, SEH Computertechnik utnserver ProMAX, SEH Computertechnik INU-100 allows DoS via HTTP.This issue affects utnserver Pro, utnserver ProMAX, INU-100 version 20.1.22 and below.

    Published: 4 Jun 2024
    8.7
    High

    CVE-2024-5421

    Last Modified: 15 Apr 2026

    Missing input validation and OS command integration of the input in the utnserver Pro, utnserver ProMAX, INU-100 web-interface allows authenticated command injection.This issue affects utnserver Pro, utnserver ProMAX, INU-100 version 20.1.22 and below.

    Published: 4 Jun 2024
    8.3
    High

    CVE-2024-5420

    Last Modified: 15 Apr 2026

    Missing input validation in the SEH Computertechnik utnserver Pro, SEH Computertechnik utnserver ProMAX, SEH Computertechnik INU-100 web-interface allows stored Cross-Site Scripting (XSS)..This issue affects utnserver Pro, utnserver ProMAX, INU-100 version 20.1.22 and below.

    Published: 4 Jun 2024
    5.3
    Medium

    CVE-2023-44235

    Last Modified: 28 Apr 2026

    Improper Restriction of Excessive Authentication Attempts vulnerability in Devnath verma WP Captcha allows Functionality Bypass.This issue affects WP Captcha: from n/a through 2.0.0.

    Published: 4 Jun 2024
    9.1
    Critical

    CVE-2024-4253

    Last Modified: 15 Oct 2025

    A command injection vulnerability exists in the gradio-app/gradio repository, specifically within the 'test-functional.yml' workflow. The vulnerability arises due to improper neutralization of special elements used in a command, allowing for unauthorized modification of the base repository or secrets exfiltration. The issue affects versions up to and including '@gradio/[email protected]'. The flaw is present in the workflow's handling of GitHub context information, where it echoes the full name of the head repository, the head branch, and the workflow reference without adequate sanitization. This could potentially lead to the exfiltration of sensitive secrets such as 'GITHUB_TOKEN', 'COMMENT_TOKEN', and 'CHROMATIC_PROJECT_TOKEN'.

    Published: 4 Jun 2024
    9.1
    Critical

    CVE-2024-36104

    Last Modified: 1 Jul 2025

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 18.12.14. Users are recommended to upgrade to version 18.12.14, which fixes the issue.

    Published: 4 Jun 2024
    5.3
    Medium

    CVE-2023-41134

    Last Modified: 15 Apr 2026

    Authentication Bypass by Spoofing vulnerability in pluginkollektiv Antispam Bee allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Antispam Bee: from n/a through 2.11.3.

    Published: 4 Jun 2024
    6.5
    Medium

    CVE-2023-40673

    Last Modified: 15 Apr 2026

    : Improper Control of Interaction Frequency vulnerability in cartpauj Cartpauj Register Captcha allows Functionality Misuse.This issue affects Cartpauj Register Captcha: from n/a through 1.0.02.

    Published: 4 Jun 2024
    5.4
    Medium

    CVE-2023-40557

    Last Modified: 15 Apr 2026

    Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in PickPlugins Tabs & Accordion allows Code Injection.This issue affects Tabs & Accordion: from n/a through 1.3.10.

    Published: 4 Jun 2024
    5.3
    Medium

    CVE-2023-40332

    Last Modified: 28 Apr 2026

    Improper Control of Interaction Frequency vulnerability in Lester ‘GaMerZ’ Chan WP-PostRatings allows Functionality Misuse.This issue affects WP-PostRatings: from n/a through 1.91.

    Published: 4 Jun 2024
    5.4
    Medium

    CVE-2023-39161

    Last Modified: 15 Apr 2026

    Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in WP Discussion Board Discussion Board allows Content Spoofing, Cross-Site Scripting (XSS).This issue affects Discussion Board: from n/a through 2.4.8.

    Published: 4 Jun 2024
    6.5
    Medium

    CVE-2023-38520

    Last Modified: 15 Apr 2026

    External Control of Assumed-Immutable Web Parameter vulnerability in PINPOINT.WORLD Pinpoint Booking System allows Functionality Misuse.This issue affects Pinpoint Booking System: from n/a through 2.9.9.3.4.

    Published: 4 Jun 2024
    5.3
    Medium

    CVE-2023-37865

    Last Modified: 12 Aug 2025

    Authentication Bypass by Spoofing vulnerability in IP2Location Download IP2Location Country Blocker allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Download IP2Location Country Blocker: from n/a through 2.29.1.

    Published: 4 Jun 2024
    5.3
    Medium

    CVE-2023-34001

    Last Modified: 30 Jun 2025

    Improper Restriction of Excessive Authentication Attempts vulnerability in WPPlugins – WordPress Security Plugins Hide My WP Ghost allows Functionality Bypass.This issue affects Hide My WP Ghost: from n/a through 5.0.25.

    Published: 4 Jun 2024
    9.1
    Critical

    CVE-2023-33930

    Last Modified: 5 Feb 2025

    Unrestricted Upload of File with Dangerous Type vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates) allows Code Injection.This issue affects Unlimited Elements For Elementor (Free Widgets, Addons, Templates): from n/a through 1.5.66.

    Published: 4 Jun 2024
    4.3
    Medium

    CVE-2023-28494

    Last Modified: 12 Jul 2025

    Missing Authorization vulnerability in CodePeople Contact Form Email allows Functionality Misuse.This issue affects Contact Form Email: from n/a through 1.3.31.

    Published: 4 Jun 2024
    6.2
    Medium

    CVE-2024-20887

    Last Modified: 14 Jan 2026

    Arbitrary directory creation in GalaxyBudsManager PC prior to version 2.1.240315.51 allows attacker to create arbitrary directory.

    Published: 4 Jun 2024
    6.2
    Medium

    CVE-2024-20886

    Last Modified: 15 Apr 2026

    Arbitrary directory creation in Samsung Live Wallpaper PC prior to version 3.3.8.0 allows attacker to create arbitrary directory.

    Published: 4 Jun 2024
    5.1
    Medium

    CVE-2024-20885

    Last Modified: 10 Feb 2025

    Improper component protection vulnerability in Samsung Dialer prior to SMR May-2024 Release 1 allows local attackers to make a call without proper permission.

    Published: 4 Jun 2024
    6.2
    Medium

    CVE-2024-20884

    Last Modified: 10 Feb 2025

    Incorrect use of privileged API vulnerability in getSemBatteryUsageStats in BatteryStatsService prior to SMR Jun-2024 Release 1 allows local attackers to use privileged API.

    Published: 4 Jun 2024
    6.2
    Medium

    CVE-2024-20883

    Last Modified: 10 Feb 2025

    Incorrect use of privileged API vulnerability in registerBatteryStatsCallback in BatteryStatsService prior to SMR Jun-2024 Release 1 allows local attackers to use privileged API.

    Published: 4 Jun 2024
    4.6
    Medium

    CVE-2024-20882

    Last Modified: 10 Feb 2025

    Out-of-bounds read vulnerability in bootloader prior to SMR June-2024 Release 1 allows physical attackers to arbitrary data access.

    Published: 4 Jun 2024
    6.4
    Medium

    CVE-2024-20881

    Last Modified: 10 Feb 2025

    Improper input validation vulnerability in chnactiv TA prior to SMR Jun-2024 Release 1 allows local privileged attackers lead to potential arbitrary code execution.

    Published: 4 Jun 2024
    6.4
    Medium

    CVE-2024-20880

    Last Modified: 10 Feb 2025

    Stack-based buffer overflow vulnerability in bootloader prior to SMR Jun-2024 Release 1 allows physical attackers to overwrite memory.

    Published: 4 Jun 2024
    4
    Medium

    CVE-2024-20879

    Last Modified: 10 Feb 2025

    Improper input validation vulnerability in libsavscmn.so prior to SMR Jun-2024 Release 1 allows local attackers to write out-of-bounds memory.

    Published: 4 Jun 2024
    7.3
    High

    CVE-2024-20878

    Last Modified: 10 Feb 2025

    Heap out-of-bound write vulnerability in parsing grid image in libsavscmn.so prior to SMR June-2024 Release 1 allows local attackers to execute arbitrary code.

    Published: 4 Jun 2024
    7.3
    High

    CVE-2024-20877

    Last Modified: 10 Feb 2025

    Heap out-of-bound write vulnerability in parsing grid image header in libsavscmn.so prior to SMR Jun-2024 Release 1 allows local attackers to execute arbitrary code.

    Published: 4 Jun 2024
    6.1
    Medium

    CVE-2024-20876

    Last Modified: 10 Feb 2025

    Improper input validation in libsheifdecadapter.so prior to SMR Jun-2024 Release 1 allows local attackers to lead to memory corruption.

    Published: 4 Jun 2024
    4
    Medium

    CVE-2024-20875

    Last Modified: 10 Feb 2025

    Improper caller verification vulnerability in SemClipboard prior to SMR June-2024 Release 1 allows local attackers to access arbitrary files.

    Published: 4 Jun 2024
    7.9
    High

    CVE-2024-20874

    Last Modified: 10 Feb 2025

    Improper access control vulnerability in SmartManagerCN prior to SMR Jun-2024 Release 1 allows local attackers to launch privileged activities.

    Published: 4 Jun 2024
    4.2
    Medium

    CVE-2024-20873

    Last Modified: 10 Feb 2025

    Improper input validation vulnerability in caminfo driver prior to SMR Jun-2024 Release 1 allows local privileged attackers to write out-of-bounds memory.

    Published: 4 Jun 2024
    6.4
    Medium

    CVE-2024-5485

    Last Modified: 15 Apr 2026

    The SureTriggers – Connect All Your Plugins, Apps, Tools & Automate Everything! plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Trigger Link shortcode in all versions up to, and including, 1.0.47 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 4 Jun 2024
    6.1
    Medium

    CVE-2024-4857

    Last Modified: 6 May 2025

    The FS Product Inquiry WordPress plugin through 1.1.1 does not sanitise and escape some form submissions, which could allow unauthenticated users to perform Stored Cross-Site Scripting attacks

    Published: 4 Jun 2024
    8.2
    High

    CVE-2024-4856

    Last Modified: 6 May 2025

    The FS Product Inquiry WordPress plugin through 1.1.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin or unauthenticated users

    Published: 4 Jun 2024
    5.3
    Medium

    CVE-2024-4750

    Last Modified: 30 Jun 2025

    The buddyboss-platform WordPress plugin before 2.6.0 contains an IDOR vulnerability that allows a user to like a private post by manipulating the ID included in the request

    Published: 4 Jun 2024
    8.3
    High

    CVE-2024-4749

    Last Modified: 17 Jun 2025

    The wp-eMember WordPress plugin before 10.3.9 does not sanitize and escape the "fieldId" parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting.

    Published: 4 Jun 2024
    9.1
    Critical

    CVE-2024-4180

    Last Modified: 29 May 2025

    The Events Calendar WordPress plugin before 6.4.0.1 does not properly sanitize user-submitted content when rendering some views via AJAX.

    Published: 4 Jun 2024
    6.1
    Medium

    CVE-2024-4057

    Last Modified: 21 May 2025

    The Gutenberg Blocks with AI by Kadence WP WordPress plugin before 3.2.37 does not validate and escape some of its block attributes before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

    Published: 4 Jun 2024
    5.4
    Medium

    CVE-2024-2470

    Last Modified: 9 Jan 2026

    The Simple Ajax Chat WordPress plugin before 20240412 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

    Published: 4 Jun 2024
    4.4
    Medium

    CVE-2024-4462

    Last Modified: 15 Apr 2026

    The Nafeza Prayer Time plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.2.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.

    Published: 4 Jun 2024
    5.3
    Medium

    CVE-2024-4997

    Last Modified: 15 Apr 2026

    The WPUpper Share Buttons plugin for WordPress is vulnerable to unauthorized access of data when preparing sharing links for posts and pages in all versions up to, and including, 3.43. This makes it possible for unauthenticated attackers to obtain the contents of password protected posts and pages.

    Published: 4 Jun 2024
    6.4
    Medium

    CVE-2024-4273

    Last Modified: 8 Apr 2026

    The Essential Real Estate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'ere_property_map' shortcode in all versions up to, and including, 4.4.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 4 Jun 2024
    6.4
    Medium

    CVE-2024-4697

    Last Modified: 8 Apr 2026

    The Cowidgets – Elementor Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘heading_tag’ parameter in all versions up to, and including, 1.1.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CVE-2024-35782 is likely a duplicate of this issue.

    Published: 4 Jun 2024
    4.3
    Medium

    CVE-2024-4274

    Last Modified: 8 Apr 2026

    The Essential Real Estate plugin for WordPress is vulnerable to unauthorized loss of data due to insufficient validation on the remove_property_attachment_ajax() function in all versions up to, and including, 4.4.2. This makes it possible for authenticated attackers, with subscriber-level access and above, to delete arbitrary attachments.

    Published: 4 Jun 2024
    6.4
    Medium

    CVE-2024-3230

    Last Modified: 15 Apr 2026

    The Download Attachments plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'download-attachments' shortcode in all versions up to, and including, 1.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 4 Jun 2024
    5.3
    Medium

    CVE-2024-2382

    Last Modified: 15 Apr 2026

    The Authorize.net Payment Gateway For WooCommerce plugin for WordPress is vulnerable to payment bypass in all versions up to, and including, 8.0. This is due to the plugin not properly verifying the authenticity of the request that updates a orders payment status. This makes it possible for unauthenticated attackers to update order payment statuses to paid bypassing any payment.

    Published: 4 Jun 2024