U.S. flag   An official website of the United States government
Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Https

Secure .gov websites use HTTPS
A lock (Dot gov) or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites.

Search Results (Refine Search)

Search Parameters:
There are 261,653 matching records.
Displaying matches 761 through 780.
Vuln ID Summary CVSS Severity
CVE-2024-37274

Cross-Site Request Forgery (CSRF) vulnerability in Freshlight Lab WP Mobile Menu allows Cross Site Request Forgery.This issue affects WP Mobile Menu: from n/a through 2.8.4.3.

Published: January 02, 2025; 7:15:18 AM -0500
V4.0:(not available)
V3.x:(not available)
V2.0:(not available)
CVE-2024-37272

Cross-Site Request Forgery (CSRF) vulnerability in WP Travel Engine Travel Monster allows Cross Site Request Forgery.This issue affects Travel Monster: from n/a through 1.1.2.

Published: January 02, 2025; 7:15:18 AM -0500
V4.0:(not available)
V3.x:(not available)
V2.0:(not available)
CVE-2024-37243

Cross-Site Request Forgery (CSRF) vulnerability in Blossom Themes Vandana Lite allows Cross Site Request Forgery.This issue affects Vandana Lite: from n/a through 1.1.9.

Published: January 02, 2025; 7:15:18 AM -0500
V4.0:(not available)
V3.x:(not available)
V2.0:(not available)
CVE-2024-37242

Cross-Site Request Forgery (CSRF) vulnerability in Automattic Newspack Newsletters allows Cross Site Request Forgery.This issue affects Newspack Newsletters: from n/a through 2.13.2.

Published: January 02, 2025; 7:15:18 AM -0500
V4.0:(not available)
V3.x:(not available)
V2.0:(not available)
CVE-2024-37240

Cross-Site Request Forgery (CSRF) vulnerability in Faboba Falang multilanguage allows Cross Site Request Forgery.This issue affects Falang multilanguage: from n/a through 1.3.51.

Published: January 02, 2025; 7:15:18 AM -0500
V4.0:(not available)
V3.x:(not available)
V2.0:(not available)
CVE-2024-37238

Cross-Site Request Forgery (CSRF) vulnerability in Greg Winiarski WPAdverts – Classifieds Plugin allows Cross Site Request Forgery.This issue affects WPAdverts – Classifieds Plugin: from n/a through 2.1.2.

Published: January 02, 2025; 7:15:18 AM -0500
V4.0:(not available)
V3.x:(not available)
V2.0:(not available)
CVE-2024-37236

Cross-Site Request Forgery (CSRF) vulnerability in Tim Whitlock Loco Translate allows Cross Site Request Forgery.This issue affects Loco Translate: from n/a through 2.6.9.

Published: January 02, 2025; 7:15:18 AM -0500
V4.0:(not available)
V3.x:(not available)
V2.0:(not available)
CVE-2024-37235

Cross-Site Request Forgery (CSRF) vulnerability in Groundhogg Inc. Groundhogg allows Cross Site Request Forgery.This issue affects Groundhogg: from n/a through 3.4.2.3.

Published: January 02, 2025; 7:15:17 AM -0500
V4.0:(not available)
V3.x:(not available)
V2.0:(not available)
CVE-2024-37104

Cross-Site Request Forgery (CSRF) vulnerability in Rara Theme Chic Lite allows Cross Site Request Forgery.This issue affects Chic Lite: from n/a through 1.1.3.

Published: January 02, 2025; 7:15:17 AM -0500
V4.0:(not available)
V3.x:(not available)
V2.0:(not available)
CVE-2024-37103

Cross-Site Request Forgery (CSRF) vulnerability in Rara Theme Education Zone allows Cross Site Request Forgery.This issue affects Education Zone: from n/a through 1.3.4.

Published: January 02, 2025; 7:15:17 AM -0500
V4.0:(not available)
V3.x:(not available)
V2.0:(not available)
CVE-2024-37102

Cross-Site Request Forgery (CSRF) vulnerability in Blossom Themes Vilva allows Cross Site Request Forgery.This issue affects Vilva: from n/a through 1.2.2.

Published: January 02, 2025; 7:15:17 AM -0500
V4.0:(not available)
V3.x:(not available)
V2.0:(not available)
CVE-2024-37093

Cross-Site Request Forgery (CSRF) vulnerability in StylemixThemes MasterStudy LMS allows Cross Site Request Forgery.This issue affects MasterStudy LMS: from n/a through 3.2.1.

Published: January 02, 2025; 7:15:17 AM -0500
V4.0:(not available)
V3.x:(not available)
V2.0:(not available)
CVE-2024-13107

A vulnerability was found in D-Link DIR-816 A2 1.10CNB05_R1B011D88210. It has been classified as critical. This affects an unknown part of the file /goform/form2LocalAclEditcfg.cgi of the component ACL Handler. The manipulation leads to improper access controls. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

Published: January 02, 2025; 7:15:17 AM -0500
V4.0:(not available)
V3.x:(not available)
V2.0:(not available)
CVE-2024-13106

A vulnerability was found in D-Link DIR-816 A2 1.10CNB05_R1B011D88210 and classified as critical. Affected by this issue is some unknown functionality of the file /goform/form2IPQoSTcAdd of the component IP QoS Handler. The manipulation leads to improper access controls. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

Published: January 02, 2025; 7:15:16 AM -0500
V4.0:(not available)
V3.x:(not available)
V2.0:(not available)
CVE-2023-47693

Missing Authorization vulnerability in Themefic Ultimate Addons for Contact Form 7 allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Ultimate Addons for Contact Form 7: from n/a through 3.2.6.

Published: January 02, 2025; 7:15:16 AM -0500
V4.0:(not available)
V3.x:(not available)
V2.0:(not available)
CVE-2023-47692

Missing Authorization vulnerability in Flothemes Flo Forms allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Flo Forms: from n/a through 1.0.41.

Published: January 02, 2025; 7:15:16 AM -0500
V4.0:(not available)
V3.x:(not available)
V2.0:(not available)
CVE-2023-47689

Missing Authorization vulnerability in Toast Plugins Animator allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Animator: from n/a through 3.0.10.

Published: January 02, 2025; 7:15:16 AM -0500
V4.0:(not available)
V3.x:(not available)
V2.0:(not available)
CVE-2023-47661

Missing Authorization vulnerability in Dragfy Dragfy Addons for Elementor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Dragfy Addons for Elementor: from n/a through 1.0.2.

Published: January 02, 2025; 7:15:16 AM -0500
V4.0:(not available)
V3.x:(not available)
V2.0:(not available)
CVE-2023-47648

Missing Authorization vulnerability in spider-themes EazyDocs allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects EazyDocs: from n/a through 2.3.5.

Published: January 02, 2025; 7:15:16 AM -0500
V4.0:(not available)
V3.x:(not available)
V2.0:(not available)
CVE-2023-47647

Missing Authorization vulnerability in LearningTimes BadgeOS allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects BadgeOS: from n/a through 3.7.1.6.

Published: January 02, 2025; 7:15:16 AM -0500
V4.0:(not available)
V3.x:(not available)
V2.0:(not available)