| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2024-54422 | WordPress Evernote Sync plugin <= 3.0.0 - Reflected Cross Site Scripting (XSS) vulnerability | tgw365 | Evernote Sync | High | 7.1 | 2024-12-16 14:31:24 | Deep Dive |
| CVE-2023-40001 | WordPress iThemes Sync plugin <= 2.1.13 - Broken Access Control vulnerability | StellarWP | iThemes Sync | Medium | 4.3 | 2024-12-13 14:24:02 | Deep Dive |
| CVE-2022-46807 | WordPress Stock Sync for WooCommerce plugin <= 2.3.2 - Broken Access Control | WP Trio | Stock Sync for WooCommerce | Medium | 4.3 | 2024-12-13 14:22:07 | Deep Dive |
| CVE-2024-50388 | HBS 3 Hybrid Backup Sync | QNAP Systems Inc. | HBS 3 Hybrid Backup Sync | 超危 | - | 2024-12-06 16:35:07 | Deep Dive |
| CVE-2024-53820 | WordPress Captivate Sync plugin <= 2.0.22 - Cross Site Scripting (XSS) vulnerability | captivateaudio | Captivate Sync | Medium | 6.5 | 2024-12-06 13:07:32 | Deep Dive |
| CVE-2024-11368 | Splash Sync <= 2.0.7 - Reflected Cross-Site Scripting | nanard33 | Splash Sync | Medium | 6.1 | 2024-12-06 08:24:53 | Deep Dive |
| CVE-2024-6049 | Unauthenticated Path Traversal | Lawo AG | vsm LTC Time Sync (vTimeSync) | - | - | 2024-10-24 07:47:40 | Deep Dive |
| CVE-2022-4974 | Freemius SDK <= 2.4.2 - Missing Authorization Checks | dashlabsltd | YASR – Yet Another Star Rating Plugin for WordPress | Medium | 6.3 | 2024-10-16 06:43:30 | Deep Dive |
| CVE-2024-7647 | OTA Sync Booking Engine Widget 1.2.7 - Cross-Site Request Forgery to Stored Cross-Site Scripting | otasync | OTA Sync Booking Engine Widget | Medium | 6.1 | 2024-08-21 05:30:23 | Deep Dive |
| CVE-2024-6532 | Sheet to Table Live Sync for Google Sheet <= 1.0.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via STWT_Sheet_Table Shortcode | codersaiful | Sheet to Table Live Sync for Google Sheet | Medium | 6.4 | 2024-08-14 09:29:59 | Deep Dive |
| CVE-2024-6709 | Sync Post With Other Site <= 1.6 - Missing Authorization to Authenticated (Subscriber+) Post Creation and Update | kp4coder | Sync Post With Other Site | Medium | 4.3 | 2024-08-03 11:37:38 | Deep Dive |
| CVE-2024-35253 | Microsoft Azure File Sync Elevation of Privilege Vulnerability | Microsoft | Azure File Sync | Medium | 4.4 | 2024-06-11 17:00:08 | Deep Dive |
| CVE-2023-49575 | XSS vulnerability in VX Search Enterprise | Flexense | VX Search Enterprise | High | 7.1 | 2024-05-24 12:40:24 | Deep Dive |
| CVE-2024-34375 | WordPress Sheets to WP Table Live Sync plugin <= 3.7.0 - Cross Site Scripting (XSS) vulnerability | WPPOOL | Sheets To WP Table Live Sync | Medium | 5.9 | 2024-05-06 18:28:15 | Deep Dive |
| CVE-2024-32082 | WordPress Sync Post With Other Site plugin <= 1.9.1 - Cross Site Request Forgery (CSRF) to XSS vulnerability | Kamlesh Parmar | Sync Post With Other Site | High | 7.1 | 2024-04-15 07:42:35 | Deep Dive |
| CVE-2024-31851 | CData Sync 安全漏洞 | CData | Sync | High | 8.6 | 2024-04-05 17:43:11 | Deep Dive |
| CVE-2024-27959 | WordPress APIExperts Square for WooCommerce plugin <= 4.2.9 - Cross Site Scripting (XSS) vulnerability | Wpexpertsio | WC Shop Sync – Integrate Square and WooCommerce for Seamless Shop Management | High | 7.1 | 2024-03-17 16:27:35 | Deep Dive |
| CVE-2024-21397 | Microsoft Azure File Sync Elevation of Privilege Vulnerability | Microsoft | Azure File Sync | Medium | 5.3 | 2024-02-13 18:02:46 | Deep Dive |
| CVE-2024-0325 | Command Injection in Helix Sync | Helix | Sync | Low | 3.6 | 2024-02-01 22:03:57 | Deep Dive |
| CVE-2023-26535 | WordPress Sheets To WP Table Live Sync Plugin <= 2.12.15 is vulnerable to Cross Site Request Forgery (CSRF) | WPPOOL | Sheets To WP Table Live Sync | Medium | 5.4 | 2023-11-22 14:05:27 | Deep Dive |