CVE Feed

    Dashboard / CVE

    7.1
    High

    CVE-2024-32785

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Webangon The Pack Elementor addons allows Cross-Site Scripting (XSS).This issue affects The Pack Elementor addons: from n/a through 2.0.8.3.

    Published: 24 Apr 2024
    7.1
    High

    CVE-2024-32789

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Seers allows Cross-Site Scripting (XSS).This issue affects Seers: from n/a through 8.1.0.

    Published: 24 Apr 2024
    4.3
    Medium

    CVE-2024-32772

    Last Modified: 28 Apr 2026

    Authorization Bypass Through User-Controlled Key vulnerability in Metagauss ProfileGrid.This issue affects ProfileGrid : from n/a through 5.7.9.

    Published: 24 Apr 2024
    5.4
    Medium

    CVE-2024-32808

    Last Modified: 28 Apr 2026

    Authorization Bypass Through User-Controlled Key vulnerability in Metagauss ProfileGrid.This issue affects ProfileGrid : from n/a through 5.7.9.

    Published: 24 Apr 2024
    5.3
    Medium

    CVE-2024-32823

    Last Modified: 28 Apr 2026

    Authorization Bypass Through User-Controlled Key vulnerability in FeedbackWP Rate my Post – WP Rating System.This issue affects Rate my Post – WP Rating System: from n/a through 3.4.4.

    Published: 24 Apr 2024
    7.1
    High

    CVE-2024-32702

    Last Modified: 28 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in reputeinfosystems ARForms arforms.This issue affects ARForms: from n/a through <= 6.4.

    Published: 24 Apr 2024
    5.9
    Medium

    CVE-2024-32707

    Last Modified: 28 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in GhozyLab Image Slider Widget allows Stored XSS.This issue affects Image Slider Widget: from n/a through 1.1.125.

    Published: 24 Apr 2024
    6.5
    Medium

    CVE-2024-32711

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Saad Iqbal myCred mycred.This issue affects myCred: from n/a through <= 2.6.3.

    Published: 24 Apr 2024
    6.5
    Medium

    CVE-2024-32721

    Last Modified: 28 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jegtheme Jeg Elementor Kit allows Stored XSS.This issue affects Jeg Elementor Kit: from n/a through 2.6.3.

    Published: 24 Apr 2024
    5.9
    Medium

    CVE-2024-32722

    Last Modified: 28 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Coupon & Discount Code Reveal Button allows Stored XSS.This issue affects Coupon & Discount Code Reveal Button: from n/a through 1.2.5.

    Published: 24 Apr 2024
    6.5
    Medium

    CVE-2024-32723

    Last Modified: 28 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Code Tides Advanced Floating Content allows Stored XSS.This issue affects Advanced Floating Content: from n/a through 1.2.5.

    Published: 24 Apr 2024
    6.5
    Medium

    CVE-2024-32791

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Leap13 Premium Addons for Elementor premium-addons-for-elementor.This issue affects Premium Addons for Elementor: from n/a through <= 4.10.25.

    Published: 24 Apr 2024
    5.9
    Medium

    CVE-2024-32801

    Last Modified: 28 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ShapedPlugin Widget Post Slider allows Stored XSS.This issue affects Widget Post Slider: from n/a through 1.3.5.

    Published: 24 Apr 2024
    5.9
    Medium

    CVE-2024-32815

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jeroen Peters All-in-one Like Widget all-in-one-facebook-like-widget.This issue affects All-in-one Like Widget: from n/a through <= 2.2.7.

    Published: 24 Apr 2024
    5.9
    Medium

    CVE-2024-32833

    Last Modified: 28 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Nick Halsey List Custom Taxonomy Widget allows Stored XSS.This issue affects List Custom Taxonomy Widget: from n/a through 4.1.

    Published: 24 Apr 2024
    5.9
    Medium

    CVE-2024-32834

    Last Modified: 28 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WebToffee WooCommerce Shipping Label allows Stored XSS.This issue affects WooCommerce Shipping Label: from n/a through 2.3.8.

    Published: 24 Apr 2024
    7.1
    High

    CVE-2024-32950

    Last Modified: 28 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in DeBAAT WP Media Category Management allows Reflected XSS.This issue affects WP Media Category Management: from n/a through 2.2.

    Published: 24 Apr 2024
    7.1
    High

    CVE-2024-32952

    Last Modified: 28 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in BloomPixel Max Addons Pro for Bricks allows Reflected XSS.This issue affects Max Addons Pro for Bricks: from n/a through 1.6.1.

    Published: 24 Apr 2024
    6.5
    Medium

    CVE-2024-32956

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Rometheme RTMKit rometheme-for-elementor.This issue affects RTMKit: from n/a through <= 1.4.1.

    Published: 24 Apr 2024
    8.5
    High

    CVE-2024-32706

    Last Modified: 28 Apr 2026

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in reputeinfosystems ARForms arforms.This issue affects ARForms: from n/a through <= 6.4.

    Published: 24 Apr 2024
    9.3
    Critical

    CVE-2024-32709

    Last Modified: 28 Apr 2026

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Plechev Andrey WP-Recall.This issue affects WP-Recall: from n/a through 16.26.5.

    Published: 24 Apr 2024
    3.3
    Low

    CVE-2024-28977

    Last Modified: 21 Jan 2025

    Dell Repository Manager, versions 3.4.2 through 3.4.4,contains a Path Traversal vulnerability in logger module. A local attacker with low privileges could potentially exploit this vulnerability to gain unauthorized read access to the files stored on the server filesystem with the privileges of the running web application.

    Published: 24 Apr 2024
    8.5
    High

    CVE-2024-32710

    Last Modified: 28 Apr 2026

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Plechev Andrey WP-Recall.This issue affects WP-Recall: from n/a through 16.26.5.

    Published: 24 Apr 2024
    8.8
    High

    CVE-2024-28976

    Last Modified: 21 Jan 2025

    Dell Repository Manager, versions prior to 3.4.5, contains a Path Traversal vulnerability in API module. A local attacker with low privileges could potentially exploit this vulnerability to gain unauthorized write access to the files stored on the server filesystem with the privileges of the running web application.

    Published: 24 Apr 2024
    5.3
    Medium

    CVE-2024-32716

    Last Modified: 28 Apr 2026

    Exposure of Sensitive Information to an Unauthorized Actor vulnerability in StreamWeasels StreamWeasels Twitch Integration.This issue affects StreamWeasels Twitch Integration: from n/a through 1.7.8.

    Published: 24 Apr 2024
    7.5
    High

    CVE-2024-32726

    Last Modified: 28 Apr 2026

    Exposure of Sensitive Information to an Unauthorized Actor vulnerability in vinoth06. Frontend Dashboard.This issue affects Frontend Dashboard: from n/a through 2.2.2.

    Published: 24 Apr 2024
    5.9
    Medium

    CVE-2024-32780

    Last Modified: 28 Apr 2026

    Exposure of Sensitive Information to an Unauthorized Actor vulnerability in E4J s.R.L. VikRentCar.This issue affects VikRentCar: from n/a through 1.3.2.

    Published: 24 Apr 2024
    7.5
    High

    CVE-2024-32781

    Last Modified: 28 Apr 2026

    Exposure of Sensitive Information to an Unauthorized Actor vulnerability in ThemeHigh Email Customizer for WooCommerce.This issue affects Email Customizer for WooCommerce: from n/a through 2.6.0.

    Published: 24 Apr 2024
    6.2
    Medium

    CVE-2024-28963

    Last Modified: 4 Feb 2025

    Telemetry Dashboard v1.0.0.7 for Dell ThinOS 2402 contains a sensitive information disclosure vulnerability. An unauthenticated user with local access to the device could exploit this vulnerability to read sensitive proxy settings information.

    Published: 24 Apr 2024
    4.3
    Medium

    CVE-2024-32782

    Last Modified: 23 Apr 2026

    Insertion of Sensitive Information Into Sent Data vulnerability in DevItems HT Mega ht-mega-for-elementor.This issue affects HT Mega: from n/a through <= 2.4.7.

    Published: 24 Apr 2024
    5.3
    Medium

    CVE-2024-32788

    Last Modified: 28 Apr 2026

    Insertion of Sensitive Information into Log File vulnerability in Frédéric GILLES FG Joomla to WordPress.This issue affects FG Joomla to WordPress: from n/a through 4.20.2.

    Published: 24 Apr 2024
    4.3
    Medium

    CVE-2024-32796

    Last Modified: 23 Apr 2026

    Insertion of Sensitive Information Into Sent Data vulnerability in Jack Arturo WP Fusion Lite wp-fusion-lite allows Retrieve Embedded Sensitive Data.This issue affects WP Fusion Lite: from n/a through <= 3.42.10.

    Published: 24 Apr 2024
    7.5
    High

    CVE-2024-32816

    Last Modified: 28 Apr 2026

    Exposure of Sensitive Information to an Unauthorized Actor vulnerability in PickPlugins Post Grid.This issue affects Post Grid: from n/a through 2.2.78.

    Published: 24 Apr 2024
    7.5
    High

    CVE-2024-32825

    Last Modified: 23 Apr 2026

    Insertion of Sensitive Information Into Sent Data vulnerability in Simply Static Simply Static simply-static.This issue affects Simply Static: from n/a through <= 3.1.3.

    Published: 24 Apr 2024
    7.5
    High

    CVE-2024-32953

    Last Modified: 28 Apr 2026

    Insertion of Sensitive Information into Log File vulnerability in Newsletters.This issue affects Newsletters: from n/a through 4.9.5.

    Published: 24 Apr 2024
    4.4
    Medium

    CVE-2024-32817

    Last Modified: 23 Apr 2026

    Deserialization of Untrusted Data vulnerability in Javier Carazo Import and export users and customers import-users-from-csv-with-meta.This issue affects Import and export users and customers: from n/a through <= 1.26.2.

    Published: 24 Apr 2024
    5.4
    Medium

    CVE-2024-32835

    Last Modified: 28 Apr 2026

    Deserialization of Untrusted Data vulnerability in WebToffee Import Export WordPress Users.This issue affects Import Export WordPress Users: from n/a through 2.5.3.

    Published: 24 Apr 2024
    9.1
    Critical

    CVE-2024-32836

    Last Modified: 23 Apr 2026

    Unrestricted Upload of File with Dangerous Type vulnerability in WP Lab WP-Lister Lite for eBay wp-lister-for-ebay.This issue affects WP-Lister Lite for eBay: from n/a through <= 3.5.11.

    Published: 24 Apr 2024
    4.9
    Medium

    CVE-2024-32718

    Last Modified: 28 Apr 2026

    Server-Side Request Forgery (SSRF) vulnerability in Webangon The Pack Elementor.This issue affects The Pack Elementor addons: from n/a through 2.0.8.2.

    Published: 24 Apr 2024
    4.9
    Medium

    CVE-2024-32775

    Last Modified: 28 Apr 2026

    Server-Side Request Forgery (SSRF) vulnerability in Pavex Embed Google Photos album.This issue affects Embed Google Photos album: from n/a through 2.1.9.

    Published: 24 Apr 2024
    6.4
    Medium

    CVE-2024-32803

    Last Modified: 28 Apr 2026

    Server-Side Request Forgery (SSRF) vulnerability in 2day.Sk, Webikon SuperFaktura WooCommerce.This issue affects SuperFaktura WooCommerce: from n/a through 1.40.3.

    Published: 24 Apr 2024
    5.4
    Medium

    CVE-2024-32812

    Last Modified: 28 Apr 2026

    Server-Side Request Forgery (SSRF) vulnerability in Podlove Podlove Podcast Publisher.This issue affects Podlove Podcast Publisher: from n/a through 4.0.11.

    Published: 24 Apr 2024
    4.9
    Medium

    CVE-2024-32819

    Last Modified: 28 Apr 2026

    Server-Side Request Forgery (SSRF) vulnerability in Culqi.This issue affects Culqi: from n/a through 3.0.14.

    Published: 24 Apr 2024
    4.9
    Medium

    CVE-2024-32955

    Last Modified: 28 Apr 2026

    Server-Side Request Forgery (SSRF) vulnerability in Foliovision FV Flowplayer Video Player.This issue affects FV Flowplayer Video Player: from n/a through 7.5.43.7212.

    Published: 24 Apr 2024
    9.1
    Critical

    CVE-2024-32948

    Last Modified: 28 Apr 2026

    Missing Authorization vulnerability in Repute Infosystems ARMember.This issue affects ARMember: from n/a through 4.0.28.

    Published: 24 Apr 2024
    6.5
    Medium

    CVE-2024-32951

    Last Modified: 28 Apr 2026

    Missing Authorization vulnerability in BloomPixel Max Addons Pro for Bricks.This issue affects Max Addons Pro for Bricks: from n/a through 1.6.1.

    Published: 24 Apr 2024
    4.9
    Medium

    CVE-2024-32879

    Last Modified: 15 Apr 2026

    Python Social Auth is a social authentication/registration mechanism. Prior to version 5.4.1, due to default case-insensitive collation in MySQL or MariaDB databases, third-party authentication user IDs are not case-sensitive and could cause different IDs to match. This issue has been addressed by a fix released in version 5.4.1. An immediate workaround would be to change collation of the affected field.

    Published: 24 Apr 2024
    8.8
    High

    CVE-2024-31406

    Last Modified: 15 Apr 2026

    Active debug code vulnerability exists in RoamWiFi R10 prior to 4.8.45. If this vulnerability is exploited, a network-adjacent unauthenticated attacker with access to the device may perform unauthorized operations.

    Published: 24 Apr 2024
    6.5
    Medium

    CVE-2024-32051

    Last Modified: 15 Apr 2026

    Insertion of sensitive information into log file issue exists in RoamWiFi R10 prior to 4.8.45. If this vulnerability is exploited, a network-adjacent unauthenticated attacker with access to the device may obtain sensitive information.

    Published: 24 Apr 2024
    4.8
    Medium

    CVE-2024-3261

    Last Modified: 8 May 2025

    The Strong Testimonials WordPress plugin before 3.1.12 does not validate and escape some of its Testimonial fields before outputting them back in a page/post, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks. The attack requires a specific view to be performed

    Published: 24 Apr 2024