Total
36333 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2024-1347 | 1 Gitlab | 1 Gitlab | 2026-06-17 | N/A | 4.3 MEDIUM |
| An issue has been discovered in GitLab CE/EE affecting all versions before 16.9.6, all versions starting from 16.10 before 16.10.4, all versions starting from 16.11 before 16.11.1. Under certain conditions, an attacker through a crafted email address may be able to bypass domain based restrictions on an instance or a group. | |||||
| CVE-2024-1343 | 1 Laborofficefree | 1 Laborofficefree | 2026-06-17 | N/A | 4.7 MEDIUM |
| A weak permission was found in the backup directory in LaborOfficeFree affecting version 19.10. This vulnerability allows any authenticated user to read backup files in the directory '%programfiles(x86)% LaborOfficeFree BackUp'. | |||||
| CVE-2024-1330 | 1 Kadencewp | 1 Kadence Blocks Pro | 2026-06-17 | N/A | 4.3 MEDIUM |
| The kadence-blocks-pro WordPress plugin before 2.3.8 does not prevent users with at least the contributor role using some of its shortcode's functionalities to leak arbitrary options from the database. | |||||
| CVE-2024-1321 | 1 Metagauss | 1 Eventprime | 2026-06-17 | N/A | 5.3 MEDIUM |
| The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to payment bypass in all versions up to, and including, 3.4.2. This is due to the plugin allowing unauthenticated users to update the status of order payments. This makes it possible for unauthenticated attackers to book events for free. | |||||
| CVE-2024-1319 | 1 Liquidweb | 1 Event Tickets | 2026-06-17 | N/A | 4.3 MEDIUM |
| The Events Tickets Plus WordPress plugin before 5.9.1 does not prevent users with at least the contributor role from leaking the attendees list on any post type regardless of status. (e.g. draft, private, pending review, password-protected, and trashed posts). | |||||
| CVE-2024-1316 | 1 Liquidweb | 1 Event Tickets | 2026-06-17 | N/A | 6.5 MEDIUM |
| The Event Tickets and Registration WordPress plugin before 5.8.1, Events Tickets Plus WordPress plugin before 5.9.1 does not prevent users with at least the contributor role from leaking the existence of certain events they shouldn't have access to. (e.g. draft, private, pending review, pw-protected, and trashed events). | |||||
| CVE-2024-1309 | 1 Honeywell | 1 Niagara Framework | 2026-06-17 | N/A | 6.5 MEDIUM |
| Uncontrolled Resource Consumption vulnerability in Honeywell Niagara Framework on Windows, Linux, QNX allows Content Spoofing.This issue affects Niagara Framework: before Niagara AX 3.8.1, before Niagara 4.1. | |||||
| CVE-2024-1302 | 1 Badgermeter | 1 Monitool | 2026-06-17 | N/A | 7.3 HIGH |
| Information exposure vulnerability in Badger Meter Monitool affecting versions up to 4.6.3 and earlier. A local attacker could change the application's file parameter to a log file obtaining all sensitive information such as database credentials. | |||||
| CVE-2024-1299 | 1 Gitlab | 1 Gitlab | 2026-06-17 | N/A | 6.5 MEDIUM |
| A privilege escalation vulnerability was discovered in GitLab affecting versions 16.8 prior to 16.8.4 and 16.9 prior to 16.9.2. It was possible for a user with custom role of `manage_group_access_tokens` to rotate group access tokens with owner privileges. | |||||
| CVE-2024-1294 | 1 Sunshinephotocart | 1 Sunshine Photo Cart | 2026-06-17 | N/A | 5.3 MEDIUM |
| The Sunshine Photo Cart: Free Client Galleries for Photographers plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.0.24 via the 'invoice'. This makes it possible for unauthenticated attackers to extract sensitive data including customer email and physical addresses. | |||||
| CVE-2024-1290 | 1 Strategy11 | 1 User Registration Forms | 2026-06-17 | N/A | 6.5 MEDIUM |
| The User Registration WordPress plugin before 2.12 does not prevent users with at least the contributor role from rendering sensitive shortcodes, allowing them to generate, and leak, valid password reset URLs, which they can use to take over any accounts. | |||||
| CVE-2024-1286 | 1 Strangerstudios | 1 Paid Memberships Pro | 2026-06-17 | N/A | 4.9 MEDIUM |
| The pmpro-membership-maps WordPress plugin before 0.7 does not prevent users with at least the contributor role from leaking sensitive information about users with a membership on the site. | |||||
| CVE-2024-1279 | 1 Strangerstudios | 1 Paid Memberships Pro | 2026-06-17 | N/A | 4.3 MEDIUM |
| The Paid Memberships Pro WordPress plugin before 2.12.9 does not prevent user with at least the contributor role from leaking other users' sensitive metadata. | |||||
| CVE-2024-1250 | 1 Gitlab | 1 Gitlab | 2026-06-17 | N/A | 6.5 MEDIUM |
| An issue has been discovered in GitLab EE affecting all versions starting from 16.8 before 16.8.2. When a user is assigned a custom role with manage_group_access_tokens permission, they may be able to create group access tokens with Owner privileges, which may lead to privilege escalation. | |||||
| CVE-2024-1243 | 1 Wazuh | 1 Wazuh | 2026-06-17 | N/A | 7.2 HIGH |
| Improper input validation in the Wazuh agent for Windows prior to version 4.8.0 allows an attacker with control over the Wazuh server or agent key to configure the agent to connect to a malicious UNC path. This results in the leakage of the machine account NetNTLMv2 hash, which can be relayed for remote code execution or used to escalate privileges to SYSTEM via AD CS certificate forging and other similar attacks. | |||||
| CVE-2024-1218 | 1 Kaliforms | 1 Contact Form Builder | 2026-06-17 | N/A | 4.3 MEDIUM |
| The Contact Form builder with drag & drop for WordPress – Kali Forms plugin for WordPress is vulnerable to unauthorized access and modification of data via API due to an inconsistent capability check on several REST endpoints in all versions up to, and including, 2.3.41. This makes it possible for authenticated attackers, with contributor access and higher, to obtain access to or modify forms or entries. | |||||
| CVE-2024-1217 | 1 Kaliforms | 1 Contact Form Builder | 2026-06-17 | N/A | 7.6 HIGH |
| The Contact Form builder with drag & drop for WordPress – Kali Forms plugin for WordPress is vulnerable to unauthorized plugin deactivation due to a missing capability check on the await_plugin_deactivation function in all versions up to, and including, 2.3.41. This makes it possible for authenticated attackers, with subscriber access or higher, to deactivate any active plugins. | |||||
| CVE-2024-1210 | 1 Learndash | 1 Learndash | 2026-06-17 | N/A | 5.3 MEDIUM |
| The LearnDash LMS plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.10.1 via API. This makes it possible for unauthenticated attackers to obtain access to quizzes. | |||||
| CVE-2024-1209 | 1 Learndash | 1 Learndash | 2026-06-17 | N/A | 5.3 MEDIUM |
| The LearnDash LMS plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.10.1 via direct file access due to insufficient protection of uploaded assignments. This makes it possible for unauthenticated attackers to obtain those uploads. | |||||
| CVE-2024-1208 | 1 Learndash | 1 Learndash | 2026-06-17 | N/A | 5.3 MEDIUM |
| The LearnDash LMS plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.10.2 via API. This makes it possible for unauthenticated attackers to obtain access to quiz questions. | |||||
