Total
395963 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2024-3491 | 2026-06-17 | N/A | 6.4 MEDIUM | ||
| The Schema & Structured Data for WP & AMP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's "How To" and "FAQ" Blocks in all versions up to, and including, 1.29 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. | |||||
| CVE-2024-3490 | 1 Bootstrapped | 1 Wp Recipe Maker | 2026-06-17 | N/A | 6.4 MEDIUM |
| The WP Recipe Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wprm-recipe-roundup-item shortcode in all versions up to, and including, 9.3.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. | |||||
| CVE-2024-3489 | 1 Exclusiveaddons | 1 Exclusive Addons For Elementor | 2026-06-17 | N/A | 6.4 MEDIUM |
| The Exclusive Addons for Elementor plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the Countdown Expired Title in all versions up to, and including, 2.6.9.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link. | |||||
| CVE-2024-3488 | 1 Microfocus | 1 Imanager | 2026-06-17 | N/A | 5.6 MEDIUM |
| File Upload vulnerability in unauthenticated session found in OpenText™ iManager 3.2.6.0200. The vulnerability could allow ant attacker to upload a file without authentication. | |||||
| CVE-2024-3487 | 1 Microfocus | 1 Imanager | 2026-06-17 | N/A | 3.5 LOW |
| Broken Authentication vulnerability discovered in OpenText™ iManager 3.2.6.0200. This vulnerability allows an attacker to manipulate certain parameters to bypass authentication. | |||||
| CVE-2024-3486 | 1 Microfocus | 1 Imanager | 2026-06-17 | N/A | 7.8 HIGH |
| XML External Entity injection vulnerability found in OpenText™ iManager 3.2.6.0200. This could lead to information disclosure and remote code execution. | |||||
| CVE-2024-3485 | 1 Microfocus | 1 Imanager | 2026-06-17 | N/A | 5.3 MEDIUM |
| Server Side Request Forgery vulnerability has been discovered in OpenText™ iManager 3.2.6.0200. This could lead to senstive information disclosure. | |||||
| CVE-2024-3484 | 1 Microfocus | 1 Imanager | 2026-06-17 | N/A | 5.7 MEDIUM |
| Path Traversal found in OpenText™ iManager 3.2.6.0200. This can lead to privilege escalation or file disclosure. | |||||
| CVE-2024-3483 | 1 Microfocus | 1 Imanager | 2026-06-17 | N/A | 7.8 HIGH |
| Remote Code Execution has been discovered in OpenText™ iManager 3.2.6.0200. The vulnerability can trigger command injection and insecure deserialization issues. | |||||
| CVE-2024-3482 | 2026-06-17 | N/A | 8.7 HIGH | ||
| A Stored Cross-Site Scripting (XSS) vulnerability has been identified in OpenText ArcSight Enterprise Security Manager and ArcSight Platform. The vulnerability could be remotely exploited. | |||||
| CVE-2024-3481 | 1 Wow-company | 1 Counter Box | 2026-06-17 | N/A | 5.2 MEDIUM |
| The Counter Box WordPress plugin before 1.2.4 does not have CSRF checks in some bulk actions, which could allow attackers to make logged in admins perform unwanted actions, such deleting counters via CSRF attacks | |||||
| CVE-2024-3480 | 2026-06-17 | N/A | 2.8 LOW | ||
| An Implicit intent vulnerability was reported in the Motorola framework that could allow an attacker to read telephony-related data. | |||||
| CVE-2024-3479 | 2026-06-17 | N/A | 2.8 LOW | ||
| An improper export vulnerability was reported in the Motorola Enterprise MotoDpms Provider (com.motorola.server.enterprise.MotoDpmsProvider) that could allow a local attacker to read local data. | |||||
| CVE-2024-3478 | 1 Wow-company | 1 Herd Effects | 2026-06-17 | N/A | 6.1 MEDIUM |
| The Herd Effects WordPress plugin before 5.2.7 does not have CSRF checks in some bulk actions, which could allow attackers to make logged in admins perform unwanted actions, such as deleting effects via CSRF attacks | |||||
| CVE-2024-3477 | 1 Wow-company | 1 Popup Box | 2026-06-17 | N/A | 4.3 MEDIUM |
| The Popup Box WordPress plugin before 2.2.7 does not have CSRF checks in some bulk actions, which could allow attackers to make logged in admins perform unwanted actions, such as deleting popups via CSRF attacks | |||||
| CVE-2024-3476 | 1 Wow-company | 1 Side Menu Lite | 2026-06-17 | N/A | 8.8 HIGH |
| The Side Menu Lite WordPress plugin before 4.2.1 does not have CSRF checks in some bulk actions, which could allow attackers to make logged in admins perform unwanted actions, such as deleting buttons via CSRF attacks | |||||
| CVE-2024-3475 | 1 Wow-company | 1 Sticky Buttons | 2026-06-17 | N/A | 7.5 HIGH |
| The Sticky Buttons WordPress plugin before 3.2.4 does not have CSRF checks in some bulk actions, which could allow attackers to make logged in admins perform unwanted actions, such as deleting buttons via CSRF attacks | |||||
| CVE-2024-3474 | 1 Wow-company | 1 Wow Skype Buttons | 2026-06-17 | N/A | 8.8 HIGH |
| The Wow Skype Buttons WordPress plugin before 4.0.4 does not have CSRF checks in some bulk actions, which could allow attackers to make logged in admins perform unwanted actions, such as deleting buttons via CSRF attacks | |||||
| CVE-2024-3473 | 2026-06-17 | N/A | 6.1 MEDIUM | ||
| The Header Footer Code Manager Pro plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the message parameter in all versions up to, and including, 1.0.16 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link. | |||||
| CVE-2024-3472 | 1 Wow-company | 1 Modal Window | 2026-06-17 | N/A | 5.9 MEDIUM |
| The Modal Window WordPress plugin before 5.3.10 does not have CSRF check in place when bulk deleting modals, which could allow attackers to make a logged in admin delete them via a CSRF attack | |||||
