U.S. flag   An official website of the United States government
Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Https

Secure .gov websites use HTTPS
A lock (Dot gov) or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites.

Search Results (Refine Search)

Search Parameters:
There are 232,259 matching records.
Displaying matches 21 through 40.
Vuln ID Summary CVSS Severity
CVE-2024-32689

Missing Authorization vulnerability in GenialSouls WP Social Comments.This issue affects WP Social Comments: from n/a through 1.7.3.

Published: April 18, 2024; 7:15:39 AM -0400
V3.x:(not available)
V2.0:(not available)
CVE-2024-32686

Insertion of Sensitive Information into Log File vulnerability in Inisev Backup Migration.This issue affects Backup Migration: from n/a through 1.4.3.

Published: April 18, 2024; 7:15:38 AM -0400
V3.x:(not available)
V2.0:(not available)
CVE-2024-32602

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in OnTheGoSystems WooCommerce Multilingual & Multicurrency.This issue affects WooCommerce Multilingual & Multicurrency: from n/a through 5.3.3.1.

Published: April 18, 2024; 7:15:38 AM -0400
V3.x:(not available)
V2.0:(not available)
CVE-2024-32600

Deserialization of Untrusted Data vulnerability in Averta Master Slider.This issue affects Master Slider: from n/a through 3.9.5.

Published: April 18, 2024; 7:15:38 AM -0400
V3.x:(not available)
V2.0:(not available)
CVE-2024-32553

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in looks_awesome Superfly Menu allows Stored XSS.This issue affects Superfly Menu: from n/a through 5.0.25.

Published: April 18, 2024; 7:15:38 AM -0400
V3.x:(not available)
V2.0:(not available)
CVE-2024-32552

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Tagbox Taggbox allows Stored XSS.This issue affects Taggbox: from n/a through 3.2.

Published: April 18, 2024; 7:15:38 AM -0400
V3.x:(not available)
V2.0:(not available)
CVE-2024-32551

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Smartypants SP Project & Document Manager.This issue affects SP Project & Document Manager : from n/a through 4.71.

Published: April 18, 2024; 7:15:37 AM -0400
V3.x:(not available)
V2.0:(not available)
CVE-2024-32126

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jeroen Peters Navigation menu as Dropdown Widget allows Stored XSS.This issue affects Navigation menu as Dropdown Widget: from n/a through 1.3.4.

Published: April 18, 2024; 7:15:37 AM -0400
V3.x:(not available)
V2.0:(not available)
CVE-2024-31229

Server-Side Request Forgery (SSRF) vulnerability in Really Simple Plugins Really Simple SSL.This issue affects Really Simple SSL: from n/a through 7.2.3.

Published: April 18, 2024; 7:15:37 AM -0400
V3.x:(not available)
V2.0:(not available)
CVE-2023-6897

The EAN for WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 4.9.2 via the the 'alg_wc_ean_product_meta' shortcode due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with contributor-level access and above, to expose potentially sensitive post metadata.

Published: April 18, 2024; 7:15:37 AM -0400
V3.x:(not available)
V2.0:(not available)
CVE-2023-6892

The EAN for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'alg_wc_ean_product_meta' shortcode in all versions up to, and including, 4.8.7 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

Published: April 18, 2024; 7:15:37 AM -0400
V3.x:(not available)
V2.0:(not available)
CVE-2023-50885

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in AGILELOGIX Store Locator WordPress.This issue affects Store Locator WordPress: from n/a through 1.4.14.

Published: April 18, 2024; 7:15:37 AM -0400
V3.x:(not available)
V2.0:(not available)
CVE-2023-49768

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in FormAssembly / Drew Buschhorn WP-FormAssembly allows Stored XSS.This issue affects WP-FormAssembly: from n/a through 2.0.10.

Published: April 18, 2024; 7:15:36 AM -0400
V3.x:(not available)
V2.0:(not available)
CVE-2023-47843

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Zachary Segal CataBlog.This issue affects CataBlog: from n/a through 1.7.0.

Published: April 18, 2024; 7:15:36 AM -0400
V3.x:(not available)
V2.0:(not available)
CVE-2023-3675

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Secomea GateManager (Web GUI) allows Reading Data from System Resources.This issue affects GateManager: from 11.0.623074018 before 11.0.623373051.

Published: April 18, 2024; 7:15:36 AM -0400
V3.x:(not available)
V2.0:(not available)
CVE-2024-32586

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Munir Kamal Gutenberg Block Editor Toolkit allows Stored XSS.This issue affects Gutenberg Block Editor Toolkit: from n/a through 1.40.4.

Published: April 18, 2024; 6:15:14 AM -0400
V3.x:(not available)
V2.0:(not available)
CVE-2024-32585

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in extendWP Import Content in WordPress & WooCommerce with Excel allows Reflected XSS.This issue affects Import Content in WordPress & WooCommerce with Excel: from n/a through 4.2.

Published: April 18, 2024; 6:15:14 AM -0400
V3.x:(not available)
V2.0:(not available)
CVE-2024-32584

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in StandaloneTech TeraWallet – For WooCommerce allows Stored XSS.This issue affects TeraWallet – For WooCommerce: from n/a through 1.5.0.

Published: April 18, 2024; 6:15:14 AM -0400
V3.x:(not available)
V2.0:(not available)
CVE-2024-32583

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Photo Gallery Team Photo Gallery by 10Web allows Reflected XSS.This issue affects Photo Gallery by 10Web: from n/a through 1.8.21.

Published: April 18, 2024; 6:15:13 AM -0400
V3.x:(not available)
V2.0:(not available)
CVE-2024-32582

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Bowo Debug Log Manager allows Stored XSS.This issue affects Debug Log Manager: from n/a through 2.3.1.

Published: April 18, 2024; 6:15:13 AM -0400
V3.x:(not available)
V2.0:(not available)