Total
9943 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2024-2395 | 1 Autopolis | 1 Bulgarisation For Woocommerce | 2026-06-17 | N/A | 7.3 HIGH |
| The Bulgarisation for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.0.14. This is due to missing or incorrect nonce validation on several functions. This makes it possible for unauthenticated attackers to generate and delete labels via a forged request granted they can trick a site administrator into performing an action such as clicking on a link. | |||||
| CVE-2024-2298 | 1 Servit | 1 Affiliate-toolkit | 2026-06-17 | N/A | 4.3 MEDIUM |
| The affiliate-toolkit – WordPress Affiliate Plugin plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the atkp_import_product() function in all versions up to, and including, 3.5.4. This makes it possible for authenticated attackers, with subscriber-level access and above, to to perform unauthorized actions such as creating importing products. | |||||
| CVE-2024-2292 | 2026-06-17 | N/A | 7.1 HIGH | ||
| Due to a lack of access control, unauthorized users are able to view and modify information pertaining to other users. | |||||
| CVE-2024-2222 | 2026-06-17 | N/A | 4.3 MEDIUM | ||
| The Advanced Classifieds & Directory Pro plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the ajax_callback_delete_attachment function in all versions up to, and including, 3.0.0. This makes it possible for authenticated attackers, with subscriber access or higher, to delete arbitrary media uploads. | |||||
| CVE-2024-2216 | 1 Jenkins | 1 Docker-build-step | 2026-06-17 | N/A | 8.8 HIGH |
| A missing permission check in an HTTP endpoint in Jenkins docker-build-step Plugin 2.11 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified TCP or Unix socket URL, and to reconfigure the plugin using the provided connection test parameters, affecting future build step executions. | |||||
| CVE-2024-2109 | 2026-06-17 | N/A | 5.3 MEDIUM | ||
| The Booster Extension plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.2.0 via the 'booster_extension_authorbox_shortcode_display' function. This makes it possible for unauthenticated attackers to extract sensitive data including user emails | |||||
| CVE-2024-2107 | 1 Blossomthemes | 1 Blossom Spa | 2026-06-17 | N/A | 5.8 MEDIUM |
| The Blossom Spa theme for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.3.3 via generated source. This makes it possible for unauthenticated attackers to extract sensitive data including contents of password-protected or scheduled posts. | |||||
| CVE-2024-2086 | 2026-06-17 | N/A | 10.0 CRITICAL | ||
| The Integrate Google Drive – Browse, Upload, Download, Embed, Play, Share, Gallery, and Manage Your Google Drive Files Into Your WordPress Site plugin for WordPress is vulnerable to unauthorized access of data, modification of data, and loss of data due to a missing capability check on multiple AJAX in all versions up to, and including, 1.3.8. This makes it possible for authenticated attackers to modify plugin settings as well as allowing full read/write/delete access to the Google Drive associated with the plugin. | |||||
| CVE-2024-2043 | 1 Theinnovs | 1 Eleforms | 2026-06-17 | N/A | 5.3 MEDIUM |
| The EleForms – All In One Form Integration including DB for Elementor plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check when downloading form submissions in all versions up to, and including, 2.9.9.7. This makes it possible for unauthenticated attackers to view form submissions. | |||||
| CVE-2024-2036 | 2026-06-17 | N/A | 4.3 MEDIUM | ||
| The ApplyOnline – Application Form Builder and Manager plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the aol_modal_box AJAX action in all versions up to, and including, 2.6.2. This makes it possible for authenticated attackers, with subscriber access or higher, to view Application submissions. | |||||
| CVE-2024-2035 | 1 Zenml | 1 Zenml | 2026-06-17 | N/A | 6.5 MEDIUM |
| An improper authorization vulnerability exists in the zenml-io/zenml repository, specifically within the API PUT /api/v1/users/id endpoint. This vulnerability allows any authenticated user to modify the information of other users, including changing the `active` status of user accounts to false, effectively deactivating them. This issue affects version 0.55.3 and was fixed in version 0.56.2. The impact of this vulnerability is significant as it allows for the deactivation of admin accounts, potentially disrupting the functionality and security of the application. | |||||
| CVE-2024-2033 | 2026-06-17 | N/A | 4.3 MEDIUM | ||
| The Video Conferencing with Zoom plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.4.5 via the get_assign_host_id AJAX action. This makes it possible for authenticated attackers, with subscriber access or higher, to enumerate usernames, emails and IDs of all users on a site. | |||||
| CVE-2024-2017 | 1 Edmonsoft | 1 Countdown Builder | 2026-06-17 | N/A | 5.4 MEDIUM |
| The Countdown, Coming Soon, Maintenance – Countdown & Clock plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the conditionsRow and switchCountdown functions in all versions up to, and including, 2.7.8. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject PHP Objects and modify the status of countdowns. | |||||
| CVE-2024-29241 | 1 Synology | 2 Diskstation Manager, Surveillance Station | 2026-06-17 | N/A | 9.9 CRITICAL |
| Missing authorization vulnerability in System webapi component in Synology Surveillance Station before 9.2.0-9289 and 9.2.0-11289 allows remote authenticated users to obtain non-sensitive information, write sensitive configurations in DSM, and reboot or shutdown NAS via unspecified vectors. | |||||
| CVE-2024-29240 | 1 Synology | 2 Diskstation Manager, Surveillance Station | 2026-06-17 | N/A | 4.3 MEDIUM |
| Missing authorization vulnerability in LayoutSave webapi component in Synology Surveillance Station before 9.2.0-11289 and 9.2.0-9289 allows remote authenticated users to conduct limited denial-of-service attacks via unspecified vectors. | |||||
| CVE-2024-29229 | 1 Synology | 2 Diskstation Manager, Surveillance Station | 2026-06-17 | N/A | 7.7 HIGH |
| Missing authorization vulnerability in GetLiveViewPath webapi component in Synology Surveillance Station before 9.2.0-9289 and 9.2.0-11289 allows remote authenticated users to obtain sensitive information via unspecified vectors. | |||||
| CVE-2024-29228 | 1 Synology | 2 Diskstation Manager, Surveillance Station | 2026-06-17 | N/A | 7.7 HIGH |
| Missing authorization vulnerability in GetStmUrlPath webapi component in Synology Surveillance Station before 9.2.0-9289 and 9.2.0-11289 allows remote authenticated users to obtain sensitive information via unspecified vectors. | |||||
| CVE-2024-28230 | 1 Jetbrains | 1 Youtrack | 2026-06-17 | N/A | 6.5 MEDIUM |
| In JetBrains YouTrack before 2024.1.25893 attaching/detaching workflow to a project was possible without project admin permissions | |||||
| CVE-2024-28216 | 1 Naver | 1 Ngrinder | 2026-06-17 | N/A | 5.4 MEDIUM |
| nGrinder before 3.5.9 allows an attacker to obtain the results of webhook requests due to lack of access control, which could be the cause of information disclosure and limited Server-Side Request Forgery. | |||||
| CVE-2024-28215 | 1 Naver | 1 Ngrinder | 2026-06-17 | N/A | 7.5 HIGH |
| nGrinder before 3.5.9 allows an attacker to create or update webhook configuration due to lack of access control, which could be the cause of information disclosure and limited Server-Side Request Forgery. | |||||
