CVE Feed

    Dashboard / CVE

    6.3
    Medium

    CVE-2024-28961

    Last Modified: 3 Feb 2025

    Dell OpenManage Enterprise, versions 4.0.0 and 4.0.1, contains a sensitive information disclosure vulnerability. A local low privileged malicious user could potentially exploit this vulnerability to obtain credentials leading to unauthorized access with elevated privileges. This could lead to further attacks, thus Dell recommends customers to upgrade at the earliest opportunity.

    Published: 29 Apr 2024
    7.5
    High

    CVE-2024-33597

    Last Modified: 28 Apr 2026

    Missing Authorization vulnerability in ProFaceOff SSU.This issue affects SSU: from n/a through 1.5.0.

    Published: 29 Apr 2024
    7.5
    High

    CVE-2024-33635

    Last Modified: 28 Apr 2026

    Missing Authorization vulnerability in Piotnet Piotnet Addons For Elementor Pro.This issue affects Piotnet Addons For Elementor Pro: from n/a through 7.1.17.

    Published: 29 Apr 2024
    5.4
    Medium

    CVE-2024-33636

    Last Modified: 28 Apr 2026

    Missing Authorization vulnerability in Mahesh Vora WP Page Post Widget Clone.This issue affects WP Page Post Widget Clone: from n/a through 1.0.1.

    Published: 29 Apr 2024
    6.5
    Medium

    CVE-2024-33684

    Last Modified: 28 Apr 2026

    Missing Authorization vulnerability in Pdfcrowd Save as PDF plugin by Pdfcrowd allows Stored XSS.This issue affects Save as PDF plugin by Pdfcrowd: from n/a through 3.2.0.

    Published: 29 Apr 2024
    6.5
    Medium

    CVE-2024-33558

    Last Modified: 28 Apr 2026

    Missing Authorization vulnerability in 8theme XStore Core.This issue affects XStore Core: from n/a through 5.3.5.

    Published: 29 Apr 2024
    5.3
    Medium

    CVE-2024-33652

    Last Modified: 28 Apr 2026

    Missing Authorization vulnerability in Real Big Plugins Client Dash.This issue affects Client Dash: from n/a through 2.2.1.

    Published: 29 Apr 2024
    10
    Critical

    CVE-2024-33566

    Last Modified: 28 Apr 2026

    Missing Authorization vulnerability in N-Media OrderConvo allows OS Command Injection.This issue affects OrderConvo: from n/a through 12.4.

    Published: 29 Apr 2024
    5.3
    Medium

    CVE-2024-33538

    Last Modified: 28 Apr 2026

    Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Fastline Media LLC Assistant – Every Day Productivity Apps.This issue affects Assistant – Every Day Productivity Apps: from n/a through 1.4.9.1.

    Published: 29 Apr 2024
    5.3
    Medium

    CVE-2024-33575

    Last Modified: 28 Apr 2026

    Exposure of Sensitive Information to an Unauthorized Actor vulnerability in User Meta user-meta.This issue affects User Meta: from n/a through 3.0.

    Published: 29 Apr 2024
    7.5
    High

    CVE-2024-33637

    Last Modified: 28 Apr 2026

    Insertion of Sensitive Information into Log File vulnerability in Solid Plugins Solid Affiliate.This issue affects Solid Affiliate: from n/a through 1.9.1.

    Published: 29 Apr 2024
    5.4
    Medium

    CVE-2024-33634

    Last Modified: 28 Apr 2026

    Server-Side Request Forgery (SSRF) vulnerability in Piotnet Piotnet Addons For Elementor Pro.This issue affects Piotnet Addons For Elementor Pro: from n/a through 7.1.17.

    Published: 29 Apr 2024
    4.4
    Medium

    CVE-2024-33629

    Last Modified: 28 Apr 2026

    Server-Side Request Forgery (SSRF) vulnerability in Creative Motion Auto Featured Image (Auto Post Thumbnail).This issue affects Auto Featured Image (Auto Post Thumbnail): from n/a through 4.0.0.

    Published: 29 Apr 2024
    4.4
    Medium

    CVE-2024-33627

    Last Modified: 28 Apr 2026

    Server-Side Request Forgery (SSRF) vulnerability in Cusmin Absolutely Glamorous Custom Admin.This issue affects Absolutely Glamorous Custom Admin: from n/a through 7.2.2.

    Published: 29 Apr 2024
    4.7
    Medium

    CVE-2024-33584

    Last Modified: 28 Apr 2026

    URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Deepen Bajracharya Video Conferencing with Zoom.This issue affects Video Conferencing with Zoom: from n/a through 4.4.4.

    Published: 29 Apr 2024
    9
    Critical

    CVE-2024-33553

    Last Modified: 28 Apr 2026

    Deserialization of Untrusted Data vulnerability in 8theme XStore Core.This issue affects XStore Core: from n/a through 5.3.5.

    Published: 29 Apr 2024
    5.4
    Medium

    CVE-2024-33641

    Last Modified: 28 Apr 2026

    Deserialization of Untrusted Data vulnerability in Team Yoast Custom field finder.This issue affects Custom field finder: from n/a through 0.3.

    Published: 29 Apr 2024
    6.7
    Medium

    CVE-2024-3196

    Last Modified: 11 Apr 2025

    A vulnerability was found in MailCleaner up to 2023.03.14. It has been declared as critical. This vulnerability affects the function getStats/Services_silentDump/Services_stopStartMTA/Config_saveDateTime/Config_hostid/Logs_StartGetStat/dumpConfiguration of the component SOAP Service. The manipulation leads to os command injection. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue. The identifier of this vulnerability is VDB-262312.

    Published: 29 Apr 2024
    4.7
    Medium

    CVE-2024-3195

    Last Modified: 10 Apr 2025

    A vulnerability was found in MailCleaner up to 2023.03.14. It has been classified as critical. This affects an unknown part of the component Admin Endpoints. The manipulation leads to path traversal. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue. The associated identifier of this vulnerability is VDB-262311.

    Published: 29 Apr 2024
    4.3
    Medium

    CVE-2024-3194

    Last Modified: 11 Apr 2025

    A vulnerability was found in MailCleaner up to 2023.03.14 and classified as problematic. Affected by this issue is some unknown functionality of the component Log File Endpoint. The manipulation leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue. VDB-262310 is the identifier assigned to this vulnerability.

    Published: 29 Apr 2024
    8.8
    High

    CVE-2024-3193

    Last Modified: 10 Apr 2025

    A vulnerability has been found in MailCleaner up to 2023.03.14 and classified as critical. Affected by this vulnerability is an unknown functionality of the component Admin Endpoints. The manipulation leads to os command injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue. The identifier VDB-262309 was assigned to this vulnerability.

    Published: 29 Apr 2024
    4.3
    Medium

    CVE-2024-3192

    Last Modified: 10 Apr 2025

    A vulnerability, which was classified as problematic, was found in MailCleaner up to 2023.03.14. Affected is an unknown function of the component Admin Interface. The manipulation as part of Mail Message leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue. The identifier of this vulnerability is VDB-262308.

    Published: 29 Apr 2024
    9.8
    Critical

    CVE-2024-3191

    Last Modified: 11 Apr 2025

    A vulnerability, which was classified as critical, has been found in MailCleaner up to 2023.03.14. This issue affects some unknown processing of the component Email Handler. The manipulation leads to os command injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue. The associated identifier of this vulnerability is VDB-262307.

    Published: 29 Apr 2024
    9.3
    Critical

    CVE-2024-33544

    Last Modified: 28 Apr 2026

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in AA-Team WZone allows SQL Injection.This issue affects WZone: from n/a through 14.0.10.

    Published: 29 Apr 2024
    9.6
    Critical

    CVE-2024-33546

    Last Modified: 28 Apr 2026

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in AA-Team WZone allows SQL Injection.This issue affects WZone: from n/a through 14.0.10.

    Published: 29 Apr 2024
    9.3
    Critical

    CVE-2024-33551

    Last Modified: 28 Apr 2026

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in 8theme XStore Core allows SQL Injection.This issue affects XStore Core: from n/a through 5.3.5.

    Published: 29 Apr 2024
    9.3
    Critical

    CVE-2024-33559

    Last Modified: 28 Apr 2026

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in 8theme XStore allows SQL Injection.This issue affects XStore: from n/a through 9.3.5.

    Published: 29 Apr 2024
    4.3
    Medium

    CVE-2024-33542

    Last Modified: 29 Sept 2025

    Authorization Bypass Through User-Controlled Key vulnerability in Fabio Rinaldi Crelly Slider.This issue affects Crelly Slider: from n/a through 1.4.5.

    Published: 29 Apr 2024
    7.1
    High

    CVE-2024-33681

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Sandor Kovacs Regenerate post permalink allows Cross-Site Scripting (XSS).This issue affects Regenerate post permalink: from n/a through 1.0.3.

    Published: 29 Apr 2024
    8.1
    High

    CVE-2024-2505

    Last Modified: 8 May 2025

    The GamiPress WordPress plugin before 6.8.9's access control mechanism fails to properly restrict access to its settings, permitting Authors to manipulate requests and extend access to lower privileged users, like Subscribers, despite initial settings prohibiting such access. This vulnerability resembles broken access control, enabling unauthorized users to modify critical GamiPress WordPress plugin before 6.8.9 configurations.

    Published: 29 Apr 2024
    5.9
    Medium

    CVE-2024-1905

    Last Modified: 8 Apr 2025

    The Smart Forms WordPress plugin before 2.6.96 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

    Published: 29 Apr 2024
    5.4
    Medium

    CVE-2024-33632

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Piotnet Piotnet Addons For Elementor Pro.This issue affects Piotnet Addons For Elementor Pro: from n/a through 7.1.17.

    Published: 29 Apr 2024
    8.8
    High

    CVE-2024-4303

    Last Modified: 15 Apr 2026

    ArmorX Android APP's multi-factor authentication (MFA) for the login function is not properly implemented. Remote attackers who obtain user credentials can bypass MFA, allowing them to successfully log into the APP.

    Published: 29 Apr 2024
    4.3
    Medium

    CVE-2024-33686

    Last Modified: 28 Apr 2026

    Missing Authorization vulnerability in Extend Themes Pathway, Extend Themes Hugo WP, Extend Themes Althea WP, Extend Themes Elevate WP, Extend Themes Brite, Extend Themes Colibri WP, Extend Themes Vertice.This issue affects Pathway: from n/a through 1.0.15; Hugo WP: from n/a through 1.0.8; Althea WP: from n/a through 1.0.13; Elevate WP: from n/a through 1.0.15; Brite: from n/a through 1.0.11; Colibri WP: from n/a through 1.0.94; Vertice: from n/a through 1.0.7.

    Published: 29 Apr 2024
    6.1
    Medium

    CVE-2024-4302

    Last Modified: 15 Apr 2026

    Super 8 Live Chat online customer service platform fails to properly filter user input, allowing unauthenticated remote attackers to insert JavaScript code into the chat box. When the message recipient views the message, they become susceptible to Cross-site Scripting (XSS) attacks.

    Published: 29 Apr 2024
    6.5
    Medium

    CVE-2024-33537

    Last Modified: 28 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Theme Horse WP Portfolio allows Stored XSS.This issue affects WP Portfolio: from n/a through 2.4.

    Published: 29 Apr 2024
    6.5
    Medium

    CVE-2024-33539

    Last Modified: 28 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPZOOM WPZOOM Addons for Elementor (Templates, Widgets) allows Stored XSS.This issue affects WPZOOM Addons for Elementor (Templates, Widgets): from n/a through 1.1.35.

    Published: 29 Apr 2024
    6.5
    Medium

    CVE-2024-33540

    Last Modified: 28 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThemeGrill ColorNews allows Stored XSS.This issue affects ColorNews: from n/a through 1.2.6.

    Published: 29 Apr 2024
    7.1
    High

    CVE-2024-33548

    Last Modified: 28 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in AA-Team WZone allows Reflected XSS.This issue affects WZone: from n/a through 14.0.10.

    Published: 29 Apr 2024
    7.1
    High

    CVE-2024-33554

    Last Modified: 28 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in 8theme XStore Core allows Reflected XSS.This issue affects XStore Core: from n/a through 5.3.5.

    Published: 29 Apr 2024
    7.1
    High

    CVE-2024-33562

    Last Modified: 28 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in 8theme XStore allows Reflected XSS.This issue affects XStore: from n/a through 9.3.5.

    Published: 29 Apr 2024
    7.1
    High

    CVE-2024-33571

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Infomaniak Network VOD Infomaniak vod-infomaniak.This issue affects VOD Infomaniak: from n/a through <= 1.5.6.

    Published: 29 Apr 2024
    6.5
    Medium

    CVE-2024-33630

    Last Modified: 28 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Piotnet Piotnet Addons For Elementor allows Stored XSS.This issue affects Piotnet Addons For Elementor: from n/a through 2.4.26.

    Published: 29 Apr 2024
    6.5
    Medium

    CVE-2024-33631

    Last Modified: 28 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Piotnet Piotnet Addons For Elementor Pro allows Stored XSS.This issue affects Piotnet Addons For Elementor Pro: from n/a through 7.1.17.

    Published: 29 Apr 2024
    7.1
    High

    CVE-2024-33633

    Last Modified: 28 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Piotnet Piotnet Addons For Elementor Pro allows Reflected XSS.This issue affects Piotnet Addons For Elementor Pro: from n/a through 7.1.17.

    Published: 29 Apr 2024
    6.5
    Medium

    CVE-2024-33640

    Last Modified: 28 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LBell Pretty Google Calendar allows Stored XSS.This issue affects Pretty Google Calendar: from n/a through 1.7.2.

    Published: 29 Apr 2024
    5.9
    Medium

    CVE-2024-33643

    Last Modified: 28 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Kailey Lampert Advanced Most Recent Posts Mod allows Stored XSS.This issue affects Advanced Most Recent Posts Mod: from n/a through 1.6.5.2.

    Published: 29 Apr 2024
    7.1
    High

    CVE-2024-33645

    Last Modified: 28 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Eftakhairul Islam & Sirajus Salayhin Easy Set Favicon allows Reflected XSS.This issue affects Easy Set Favicon: from n/a through 1.1.

    Published: 29 Apr 2024
    7.1
    High

    CVE-2024-33646

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Toast Plugins Sticky Anything allows Cross-Site Scripting (XSS).This issue affects Sticky Anything: from n/a through 2.1.5.

    Published: 29 Apr 2024
    6.5
    Medium

    CVE-2024-33648

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Kemory Grubb Recencio Book Reviews recencio-book-reviews allows DOM-Based XSS.This issue affects Recencio Book Reviews: from n/a through <= 1.66.0.

    Published: 29 Apr 2024