CVE编号 | 漏洞名称 | 漏洞类型 | 披露时间 | CVSS评分 |
---|---|---|---|---|
CVE-2024-8096 | OCSP stapling bypass with GnuTLS (CVE-2024-8096) | 2024-09-11 | ||
CVE-2024-45327 | N/A | 2024-09-11 | ||
CVE-2024-8277 | WooCommerce Photo Reviews Premium <= 1.3.13.2 - Authentication Bypass to Account Takeover and Privilege Escalation (CVE-2024-8277) | 2024-09-11 | ||
CVE-2019-25212 | video carousel slider with lightbox <= 1.0.6 - Authenticated (Admin+) SQL Injection (CVE-2019-25212) | 2024-09-11 | ||
CVE-2024-8045 | Advanced WordPress Backgrounds <= 1.12.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via imageTag Parameter (CVE-2024-8045) | 2024-09-11 | ||
CVE-2024-7626 | WP Delicious – Recipe Plugin for Food Bloggers (formerly Delicious Recipes) <= 1.6.9 - Improper Path Validation to Authenticated (Subscriber+) Arbitrary File Move and Read (CVE-2024-7626) | 2024-09-11 | ||
CVE-2024-8440 | Essential Addons for Elementor -- Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 6.0.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via Fancy Text Widget (CVE-2024-8440) | 2024-09-11 | ||
CVE-2024-7716 | GS Logo Slider Lite < 3.6.9 - Admin+ Stored XSS (CVE-2024-7716) | 2024-09-11 | ||
CVE-2024-3899 | Envira Gallery < 1.8.15 - Author+ Stored XSS (CVE-2024-3899) | 2024-09-11 | ||
CVE-2024-7727 | HTML5 Video Player – mp4 Video Player Plugin and Block <= 2.5.32 - Missing Authorization in multiple functions via h5vp_ajax_handler (CVE-2024-7727) | 2024-09-11 | ||
CVE-2024-7721 | HTML5 Video Player – mp4 Video Player Plugin and Block <= 2.5.34 - Missing Authorization to Authenticated (Subscriber+) Limited Options Update (CVE-2024-7721) | 2024-09-11 | ||
CVE-2024-43690 | N/A | 2024-09-11 | ||
CVE-2024-21529 | N/A | 2024-09-11 | ||
CVE-2024-1656 | N/A | 2024-09-11 | ||
CVE-2024-8253 | Post Grid 和 Gutenberg Blocks 2.2.87 - 2.2.90 - 经过身份验证 (Subscriber+) 权限提升 (CVE-2024-8253) | 2024-09-11 | ||
CVE-2024-39808 | N/A | 2024-09-11 | ||
CVE-2024-24972 | N/A | 2024-09-11 | ||
CVE-2024-23906 | N/A | 2024-09-11 | ||
CVE-2024-40662 | N/A | 2024-09-11 | ||
CVE-2024-40659 | N/A | 2024-09-11 | ||
CVE-2024-40658 | N/A | 2024-09-11 | ||
CVE-2024-40657 | N/A | 2024-09-11 | ||
CVE-2024-40656 | N/A | 2024-09-11 | ||
CVE-2024-40655 | N/A | 2024-09-11 | ||
CVE-2024-40654 | N/A | 2024-09-11 | ||
CVE-2024-40652 | N/A | 2024-09-11 | ||
CVE-2024-40650 | N/A | 2024-09-11 | ||
CVE-2024-31336 | N/A | 2024-09-11 | ||
CVE-2024-23716 | N/A | 2024-09-11 | ||
CVE-2024-45597 | Pluto 的 http.request 允许在标头值中使用 CR 和 LF(CVE-2024-45597) | 2024-09-11 |