Latest CVE Feed
-
5.5
MEDIUMCVE-2024-35110
A reflected XSS vulnerability has been found in YzmCMS 7.1. The vulnerability exists in yzmphp/core/class/application.class.php: when logged-in users access a malicious link, their cookies can be captured by an attacker.... Read more
Affected Products : yzmcms- Published: May. 17, 2024
- Modified: Jun. 10, 2025
-
5.5
MEDIUMCVE-2024-34959
DedeCMS V5.7.113 is vulnerable to Cross Site Scripting (XSS) via sys_data_replace.php.... Read more
Affected Products : dedecms- Published: May. 17, 2024
- Modified: Apr. 01, 2025
-
5.5
MEDIUMCVE-2024-35384
An issue in Cesanta mjs 2.20.0 allows a remote attacker to cause a denial of service via the mjs_array_length function in the mjs.c file.... Read more
Affected Products : mjs- Published: May. 21, 2024
- Modified: May. 05, 2025
-
5.5
MEDIUMCVE-2024-2953
The LuckyWP Table of Contents plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple parameters in versions up to, and including, 2.1.4 due to insufficient input sanitization and output escaping. This makes it possible for authenti... Read more
Affected Products : luckywp_table_of_contents- Published: May. 22, 2024
- Modified: May. 28, 2025
-
5.5
MEDIUMCVE-2024-35557
idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/vpsApi_deal.php?mudi=rev&nohrefStr=close.... Read more
- Published: May. 22, 2024
- Modified: Apr. 09, 2025
-
5.5
MEDIUMCVE-2024-37176
SAP BW/4HANA Transformation and Data Transfer Process (DTP) allows an authenticated attacker to gain higher access levels than they should have by exploiting improper authorization checks. This results in escalation of privileges. It has no impact on the ... Read more
Affected Products : bw\/4hana- Published: Jun. 11, 2024
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2024-3815
The Newspaper theme for WordPress is vulnerable to Stored Cross-Site Scripting via attachment meta in the archive page in all versions up to, and including, 12.6.5 due to insufficient input sanitization and output escaping on user supplied attributes. Thi... Read more
Affected Products : newspaper- Published: Jun. 15, 2024
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2024-4934
The Quiz and Survey Master (QSM) WordPress plugin before 9.0.2 does not validate and escape some of its Quiz fields before outputting them back in a page/post where the Quiz is embed, which could allow users with the contributor role and above to perform... Read more
Affected Products : quiz_and_survey_master- Published: Jul. 01, 2024
- Modified: May. 01, 2025
-
5.5
MEDIUMCVE-2024-4627
The Rank Math SEO WordPress plugin before 1.0.219 does not sanitise and escape some of its settings, which could allow users with access to the General Settings (by default admin, however such access can be given to lower roles via the Role Manager featu... Read more
Affected Products : seo- Published: Jul. 02, 2024
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2024-34594
Exposure of sensitive information in proc file system prior to SMR Jul-2024 Release 1 allows local attackers to read kernel memory address.... Read more
- Published: Jul. 02, 2024
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2024-31312
In multiple locations, there is a possible information leak due to a missing permission check. This could lead to local information disclosure exposing played media with no additional execution privileges needed. User interaction is not needed for exploit... Read more
Affected Products : android- Published: Jul. 09, 2024
- Modified: Dec. 17, 2024
-
5.5
MEDIUMCVE-2015-2179
The xaviershay-dm-rails gem 0.10.3.8 for Ruby allows local users to discover MySQL credentials by listing a process and its arguments.... Read more
Affected Products : xaviershay-dm-rails- Published: Dec. 12, 2023
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2024-6625
The WP Total Branding – Complete branding solution for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.2 due to insufficient input sanitization and output escaping. Thi... Read more
Affected Products :- Published: Jul. 12, 2024
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2024-6326
An exposure of sensitive information vulnerability exists in the Rockwell Automation FactoryTalk® System Service. A malicious user could exploit this vulnerability by starting a back-up or restore process, which temporarily exposes private keys, passwords... Read more
- Published: Jul. 16, 2024
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2024-41443
A stack overflow in the function cp_dynamic() (/vendor/cute_png.h) of hicolor v0.5.0 allows attackers to cause a Denial of Service (DoS) via a crafted PNG file.... Read more
Affected Products : hicolor- Published: Jul. 30, 2024
- Modified: Mar. 19, 2025
-
5.5
MEDIUMCVE-2024-41200
A segmentation fault in KMPlayer v4.2.2.65 allows attackers to cause a Denial of Service (DoS) via a crafted AVI file.... Read more
Affected Products : kmplayer- Published: Aug. 05, 2024
- Modified: Jun. 18, 2025
-
5.5
MEDIUMCVE-2024-37403
Ivanti Docs@Work for Android, before 2.26.0 is affected by the 'Dirty Stream' vulnerability. The application fails to properly sanitize file names, resulting in a path traversal-affiliated vulnerability. This potentially enables other malicious apps on th... Read more
Affected Products : docs\@work- Published: Aug. 07, 2024
- Modified: Mar. 25, 2025
-
5.5
MEDIUMCVE-2023-31366
Improper input validation in AMD μProf could allow an attacker to perform a write to an invalid address, potentially resulting in denial of service.... Read more
Affected Products : uprof- Published: Aug. 13, 2024
- Modified: Dec. 12, 2024
-
5.5
MEDIUMCVE-2024-28050
Improper access control in some Intel(R) Arc(TM) & Iris(R) Xe Graphics software before version 31.0.101.4824 may allow an authenticated user to potentially enable denial of service via local access.... Read more
- Published: Aug. 14, 2024
- Modified: Sep. 06, 2024
-
5.5
MEDIUMCVE-2024-43915
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Dylan James Zephyr Project Manager allows Reflected XSS.This issue affects Zephyr Project Manager: from n/a through .3.102.... Read more
- Published: Aug. 26, 2024
- Modified: Aug. 28, 2024