| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2024-35636 | WordPress Uploadcare File Uploader and Adaptive Delivery plugin <= 3.0.11 - Cross Site Request Forgery (CSRF) vulnerability | Uploadcare | Uploadcare File Uploader and Adaptive Delivery (beta) | Medium | 4.3 | 2024-06-01 09:07:30 | Deep Dive |
| CVE-2024-23692 | Rejetto HTTP File Server 2.3m Unauthenticated RCE | Rejetto | HTTP File Server | Critical | 9.8 | 2024-05-31 09:36:29 | Deep Dive |
| CVE-2024-3744 | Kubernetes azure-file-csi-driver in versions before 1.29.4 and 1.30.1 discloses service account tokens in logs | Kubernetes | azure-file-csi-driver | Medium | 6.5 | 2024-05-15 00:42:37 | Deep Dive |
| CVE-2024-3868 | Folders Pro <= 3.0.2 - Authenticated (Subscriber+) Stored Cross-Site Scripting via User First Name and Last Name | premio | Folders – Unlimited Folders to Organize Media Library Folder, Pages, Posts, File Manager | Medium | 5.4 | 2024-05-04 02:31:35 | Deep Dive |
| CVE-2024-2328 | Real Media Library <= 4.22.11 - Authenticated (Author+) Stored Cross-Site Scripting | devowl | Real Media Library: Media Library Folder & File Manager | Medium | 6.4 | 2024-05-02 16:52:43 | Deep Dive |
| CVE-2024-2346 | FileBird – WordPress Media Library Folders & File Manager <= 5.6.3 - Authenticated (Author+) Insecure Direct Object Reference | ninjateam | FileBird – WordPress Media Library Folders & File Manager | Medium | 5.4 | 2024-05-02 16:52:19 | Deep Dive |
| CVE-2024-3717 | Drag and Drop Multiple File Upload – Contact Form 7 <= 1.3.7.7 - Sensitive Information Exposure | glenwpcoder | Drag and Drop Multiple File Upload for Contact Form 7 | Medium | 5.3 | 2024-05-02 16:51:48 | Deep Dive |
| CVE-2024-2345 | FileBird – WordPress Media Library Folders & File Manager <= 5.6.3 - Authenticated (Author+) Stored Cross-Site Scripting | ninjateam | FileBird – WordPress Media Library Folders & File Manager | Medium | 6.4 | 2024-05-02 16:51:47 | Deep Dive |
| CVE-2024-33697 | WordPress CF7 File Download plugin <= 2.0 - Cross Site Scripting (XSS) vulnerability | Rimes Gold | CF7 File Download – File Download for CF7 | Medium | 5.9 | 2024-04-26 12:40:10 | Deep Dive |
| CVE-2023-44227 | WordPress Simple File List Plugin <= 6.1.9 is vulnerable to Arbitrary File Deletion | Mitchell Bennis | Simple File List | High | 7.5 | 2024-04-17 09:26:29 | Deep Dive |
| CVE-2024-32539 | WordPress WP File Download Light plugin <= 1.3.3 - Cross Site Scripting (XSS) vulnerability | JoomUnited | WP File Download Light | Medium | 6.5 | 2024-04-17 08:32:51 | Deep Dive |
| CVE-2023-47714 | IBM Sterling File Gateway cross-site scripting | IBM | Sterling File Gateway | Medium | 4.8 | 2024-04-12 12:17:20 | Deep Dive |
| CVE-2024-31939 | WordPress Import any XML or CSV File to WordPress plugin <= 3.7.3 - Cross Site Request Forgery (CSRF) vulnerability | Soflyy | Import any XML or CSV File to WordPress | Medium | 4.3 | 2024-04-10 19:17:54 | Deep Dive |
| CVE-2024-2654 | File Manager <= 7.2.5 - Authenticated (Administrator+) Directory Traversal | mndpsingh287 | File Manager | Medium | 6.8 | 2024-04-09 18:59:22 | Deep Dive |
| CVE-2024-2847 | WordPress File Upload <= 4.24.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode | nickboss | Iptanus File Upload | Medium | 6.4 | 2024-04-09 18:59:10 | Deep Dive |
| CVE-2024-2027 | Real Media Library: Media Library Folder & File Manager <= 4.22.7 - Authenticated (Contributor+) Stored Cross-Site Scripting | devowl | Real Media Library: Media Library Folder & File Manager | Medium | 6.4 | 2024-04-09 18:58:53 | Deep Dive |
| CVE-2014-125110 | wp-file-upload Plugin wfu_ajaxactions.php wfu_ajax_action_callback cross site scripting | - | wp-file-upload Plugin | Low | 3.5 | 2024-03-31 23:31:05 | Deep Dive |
| CVE-2023-23656 | WordPress MainWP File Uploader Extension Plugin <= 4.1 - Unauthenticated Arbitrary File Upload Vulnerability | MainWP | MainWP File Uploader Extension | Critical | 10.0 | 2024-03-26 19:51:57 | Deep Dive |
| CVE-2024-2849 | SourceCodester Simple File Manager unrestricted upload | SourceCodester | Simple File Manager | Medium | 6.3 | 2024-03-23 17:31:05 | Deep Dive |
| CVE-2024-1538 | File Manager <= 7.2.4 - Cross-Site Request Forgery to Local JS File Inclusion | mndpsingh287 | File Manager | High | 8.8 | 2024-03-21 03:32:43 | Deep Dive |