Click to open the Alert Filter

 
Year Month
Severity
Categories
Search by Alert Name
Page(s) : 1 ... 1323 1324 1325 1326 1327 1328 1329 1330 1331 1332 [1333] 1334 1335 1336 1337 1338 1339 1340 1341 1342 1343 ... Result(s) : 328055

Alerts Feed Alerts

DATE NAME CATEGORIES DETAIL
6.1 2025-01-07 CVE-2024-12383 cve The Binary MLM Woocommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.0. This is due to missing or incorrect nonce ...
6.1 2025-01-07 CVE-2024-12384 cve The Binary MLM Woocommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'page’ parameter in all versions up to, and including, 2.0 due to in...
6.1 2025-01-07 CVE-2024-12438 cve The WooCommerce Digital Content Delivery (incl. DRM) – FlickRocket plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'start_date’ and 'end_d...
6.4 2025-01-07 CVE-2024-12439 cve The Marketplace Items plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'marketplace' shortcode in all versions up to, and includ...
6.4 2025-01-07 CVE-2024-12440 cve The Candifly plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'candifly' shortcode in all versions up to, and including, 1.0.6 d...
6.4 2025-01-07 CVE-2024-12464 cve The Chatroll Live Chat plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'chatroll' shortcode in all versions up to, and includin...
8.8 2025-01-07 CVE-2024-12471 cve The Post Saint: ChatGPT, GPT4, DALL-E, Stable Diffusion, Pexels, Dezgo AI Text & Image Generator plugin for WordPress is vulnerable to arbitrary files uploads due to a missing c...
8.6 2025-01-07 CVE-2024-12535 cve The Host PHP Info plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check when including the 'phpinfo' function in all vers...
7.1 2025-01-07 CVE-2024-12633 cve The JoomSport – for Sports: Team & League, Football, Hockey & more plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘page parameter in all versions u...
7.5 2025-01-07 CVE-2024-12849 cve The Error Log Viewer By WP Guru plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 1.0.1.3 via the wp_ajax_nopriv_elvwp_log_download...
N/A 2025-01-07 CVE-2024-7696 cve Seth Fogie, member of AXIS Camera Station Pro Bug Bounty Program, has found that it is possible for an authenticated malicious client to tamper with audit log creation in AXIS C...
N/A 2025-01-07 CVE-2024-8855 cve The WordPress Auction Plugin WordPress plugin through 3.7 does not sanitize and escape a parameter before using it in a SQL statement, allowing editors and above to perform SQL ...
N/A 2025-01-07 CVE-2024-8857 cve The WordPress Auction Plugin WordPress plugin through 3.7 does not sanitise and escape some of its settings, which could allow high privilege users such as editors to perform St...
N/A 2025-01-07 CVE-2024-9638 cve The Category Posts Widget WordPress plugin before 4.9.18 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Store...
5.3 2025-01-07 CVE-2024-9697 cve The Social Rocket – Social Sharing Plugin plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the tweet_settings_save() ...
5.4 2025-01-07 CVE-2024-9702 cve The Social Rocket – Social Sharing Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'socialrocket-floating' shortcode in ...
7.5 2025-01-07 CVE-2024-11282 cve The Passster – Password Protect Pages and Content plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.2.10 via the WordP...
8.8 2025-01-07 CVE-2024-11725 cve The SMS Alert Order Notifications – WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing ca...
6.4 2025-01-07 CVE-2024-11764 cve The Solar Wizard Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'solar_wizard' shortcode in all versions up to, and inclu...
6.4 2025-01-07 CVE-2024-12437 cve The Marketplace Items plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'envato' shortcode in all versions up to, and including, ...
Page(s) : 1 ... 1323 1324 1325 1326 1327 1328 1329 1330 1331 1332 [1333] 1334 1335 1336 1337 1338 1339 1340 1341 1342 1343 ... Result(s) : 328055