CVE Severity Distribution (Last 30 Days)
Found 11 CVEs in the last 30 days.
CVE-2024-37212
HIGH
CVSS: 8.3
EPSS: 0.2%
CWE-352
T1189
Cross-Site Request Forgery (CSRF) vulnerability in Ali2Woo Ali2Woo Lite.This issue affects Ali2Woo Lite: from n/a through 3.3.5.
Published: 2024-06-21
CVE-2024-37211
HIGH
CVSS: 7.1
EPSS: 0.3%
CWE-79
T1189
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Ali2Woo Team Ali2Woo Lite allows Reflected XSS.This issue affects Ali2Woo Lite: from n/a through 3.3.5.
Published: 2024-07-22
CVE-2024-37210
MEDIUM
CVSS: 6.5
EPSS: 0.3%
CWE-862
T1078
Missing Authorization vulnerability in ali2woo AliNext allows Exploiting Incorrectly Configured Access Control Security Levels.
This issue affects AliNext: from n/a through 3.3.5.
Published: 2026-06-17
CVE-2024-37214
MEDIUM
CVSS: 6.5
EPSS: 0.3%
CWE-862
T1078
Missing Authorization vulnerability in Dropshipping Guru Ali2Woo Lite Exploiting Incorrectly Configured Access Control Security Levels, Stored XSS.This issue affects Ali2Woo Lite: from n/a through 3.3.5.
Published: 2024-11-01
CVE-2024-37216
MEDIUM
CVSS: 6.5
EPSS: 0.3%
CWE-79
T1189
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Rami Yushuvaev Sketchfab Embed allows Stored XSS.This issue affects Sketchfab Embed: from n/a through 1.5.
Published: 2024-07-22
CVE-2024-37217
MEDIUM
CVSS: 6.5
EPSS: 0.3%
CWE-79
T1189
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in ProWCPlugins Empty Cart Button for WooCommerce allows Stored XSS.This issue affects Empty Cart Button for WooCommerce: from n/a through 1.3.8.
Published: 2024-07-22
CVE-2024-37219
MEDIUM
CVSS: 6.5
EPSS: 0.3%
CWE-79
T1189
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in PBN Hosting SL Page Builder Sandwich – Front-End Page Builder allows Stored XSS.This issue affects Page Builder Sandwich – Front-End Page Builder: from n/a through 5.1.0.
Published: 2024-07-22
CVE-2024-3721
MEDIUM
CVSS: 6.3
EPSS: 86.5%
VulnCheck KEV
PoC Available
CWE-78
T1059
A vulnerability was found in TBK DVR-4104 and DVR-4216 up to 20240412 and classified as critical. This issue affects some unknown processing of the file /device.rsp?opt=sys&cmd=___S_O_S_T_R_E_A_MAX___. The manipulation of the argument mdb/mdc leads to os command injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-260573 was assigned to this vulnerability.
Published: 2024-04-13
CVE-2024-37215
MEDIUM
CVSS: 5.9
EPSS: 0.3%
CWE-79
T1189
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in creativeinteractivemedia Transition Slider – Responsive Image Slider and Gallery allows Stored XSS.This issue affects Transition Slider – Responsive Image Slider and Gallery: from n/a through 2.20.3.
Published: 2024-07-22
CVE-2024-37218
MEDIUM
CVSS: 4.3
EPSS: 0.3%
CWE-862
T1078
Missing Authorization vulnerability in WordPress Page Builder Sandwich Team Page Builder Sandwich – Front-End Page Builder allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Page Builder Sandwich – Front-End Page Builder: from n/a through 5.1.0.
Published: 2024-11-01
CVE-2024-37213
UNKNOWN
EPSS: 0.2%
Cross-Site Request Forgery (CSRF) vulnerability in guru-aliexpress AliNext ali2woo-lite allows Cross Site Request Forgery.This issue affects AliNext: from n/a through <= 3.4.6.
Published: 2024-07-12