Latest CVE Feed
-
5.4
MEDIUMCVE-2024-56313
A stored cross-site scripting (XSS) vulnerability in the Calendar feature of REDCap through 14.9.6 allows authenticated users to inject malicious scripts into the Notes field of a calendar event. When the event is viewed, the crafted payload is executed, ... Read more
Affected Products : redcap- Published: Dec. 22, 2024
- Modified: Apr. 22, 2025
-
5.4
MEDIUMCVE-2024-56512
Apache NiFi 1.10.0 through 2.0.0 are missing fine-grained authorization checking for Parameter Contexts, referenced Controller Services, and referenced Parameter Providers, when creating new Process Groups. Creating a new Process Group can include bindin... Read more
Affected Products : nifi- Published: Dec. 28, 2024
- Modified: Feb. 11, 2025
-
5.4
MEDIUMCVE-2024-50702
TeamPass before 3.1.3.1 does not properly check whether a mail_me (aka action_mail) operation is on behalf of an administrator or manager.... Read more
Affected Products : teampass- Published: Dec. 30, 2024
- Modified: Dec. 30, 2024
-
5.4
MEDIUMCVE-2024-50703
TeamPass before 3.1.3.1 does not properly prevent a user from acting with the privileges of a different user_id.... Read more
Affected Products : teampass- Published: Dec. 30, 2024
- Modified: Dec. 30, 2024
-
5.4
MEDIUMCVE-2024-56222
Cross-Site Request Forgery (CSRF) vulnerability in Codebard CodeBard Help Desk allows Cross Site Request Forgery.This issue affects CodeBard Help Desk: from n/a through 1.1.1.... Read more
Affected Products : codebard_help_desk- Published: Dec. 31, 2024
- Modified: Mar. 19, 2025
-
5.4
MEDIUMCVE-2024-13075
A vulnerability classified as problematic was found in PHPGurukul Land Record System 1.0. This vulnerability affects unknown code of the file /admin/add-propertytype.php. The manipulation of the argument Land Property Type leads to cross site scripting. T... Read more
Affected Products : land_record_system- Published: Dec. 31, 2024
- Modified: Jan. 06, 2025
-
5.4
MEDIUMCVE-2023-45828
Missing Authorization vulnerability in RumbleTalk Ltd RumbleTalk Live Group Chat allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects RumbleTalk Live Group Chat: from n/a through 6.2.5.... Read more
Affected Products :- Published: Jan. 02, 2025
- Modified: Jan. 02, 2025
- Vuln Type: Authorization
-
5.4
MEDIUMCVE-2023-47225
Missing Authorization vulnerability in KaizenCoders Short URL allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Short URL: from n/a through 1.6.8.... Read more
Affected Products : short_url- Published: Jan. 02, 2025
- Modified: Jan. 02, 2025
- Vuln Type: Authorization
-
5.4
MEDIUMCVE-2024-13083
A vulnerability classified as problematic has been found in PHPGurukul Land Record System 1.0. Affected is an unknown function of the file /admin/admin-profile.php. The manipulation of the argument Admin Name leads to cross site scripting. It is possible ... Read more
Affected Products : land_record_system- Published: Dec. 31, 2024
- Modified: Jan. 06, 2025
-
5.4
MEDIUMCVE-2024-37438
Cross-Site Request Forgery (CSRF) vulnerability in Uncanny Owl Uncanny Toolkit Pro for LearnDash allows Cross Site Request Forgery.This issue affects Uncanny Toolkit Pro for LearnDash: from n/a before 4.1.4.1.... Read more
Affected Products :- Published: Jan. 02, 2025
- Modified: Jan. 02, 2025
- Vuln Type: Cross-Site Request Forgery
-
5.4
MEDIUMCVE-2022-45811
Missing Authorization vulnerability in WeyHan Ng Post Teaser.This issue affects Post Teaser: from n/a through 4.1.5.... Read more
Affected Products :- Published: Jan. 02, 2025
- Modified: Jan. 02, 2025
- Vuln Type: Authorization
-
5.4
MEDIUMCVE-2025-21616
Plane is an open-source project management tool. A cross-site scripting (XSS) vulnerability has been identified in Plane versions prior to 0.23. The vulnerability allows authenticated users to upload SVG files containing malicious JavaScript code as profi... Read more
Affected Products : plane- Published: Jan. 06, 2025
- Modified: Jun. 20, 2025
- Vuln Type: Cross-Site Scripting
-
5.4
MEDIUMCVE-2024-12541
The Chative Live chat and Chatbot plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1. This is due to missing or incorrect nonce validation on the add_chative_widget_action() function. This makes it p... Read more
Affected Products :- Published: Jan. 07, 2025
- Modified: Jan. 07, 2025
- Vuln Type: Cross-Site Request Forgery
-
5.4
MEDIUMCVE-2024-12170
The ViewMedica 9 plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.4.15. This is due to missing or incorrect nonce validation on the 'Viewmedica-Admin' page. This makes it possible for unauthenticated... Read more
Affected Products :- Published: Jan. 07, 2025
- Modified: Jan. 07, 2025
- Vuln Type: Cross-Site Request Forgery
-
5.4
MEDIUMCVE-2025-22541
Missing Authorization vulnerability in Etruel Developments LLC WP Delete Post Copies allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Delete Post Copies: from n/a through 5.5.... Read more
Affected Products :- Published: Jan. 07, 2025
- Modified: Jan. 07, 2025
- Vuln Type: Authorization
-
5.4
MEDIUMCVE-2024-13192
A vulnerability, which was classified as problematic, was found in ZeroWdd myblog 1.0. Affected is the function update of the file src/main/java/com/wdd/myblog/controller/admin/BlogController.java. The manipulation leads to cross site scripting. It is pos... Read more
Affected Products : myblog- Published: Jan. 08, 2025
- Modified: Jun. 05, 2025
- Vuln Type: Cross-Site Scripting
-
5.4
MEDIUMCVE-2025-0348
A vulnerability was found in CampCodes DepEd Equipment Inventory System 1.0. It has been rated as problematic. This issue affects some unknown processing of the file /data/add_employee.php. The manipulation of the argument data leads to cross site scripti... Read more
Affected Products : deped_equipment_inventory_system- Published: Jan. 09, 2025
- Modified: May. 28, 2025
- Vuln Type: Cross-Site Scripting
-
5.4
MEDIUMCVE-2024-13252
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal TacJS allows Cross-Site Scripting (XSS).This issue affects TacJS: from 0.0.0 before 6.5.0.... Read more
Affected Products : tacjs- Published: Jan. 09, 2025
- Modified: Jun. 04, 2025
- Vuln Type: Cross-Site Scripting
-
5.4
MEDIUMCVE-2024-13273
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Open Social allows Cross-Site Scripting (XSS).This issue affects Open Social: from 0.0.0 before 12.3.8, from 12.4.0 before 12.4.5, from 13.0.0 bef... Read more
Affected Products : open_social- Published: Jan. 09, 2025
- Modified: Jan. 09, 2025
- Vuln Type: Cross-Site Scripting
-
5.4
MEDIUMCVE-2024-12204
The Coupon X: Discount Pop Up, Promo Code Pop Ups, Announcement Pop Up, WooCommerce Popups plugin for WordPress is vulnerable to unauthorized access due to missing capability checks on several functions in the class-cx-rest.php file in all versions up to,... Read more
Affected Products :- Published: Jan. 11, 2025
- Modified: Jan. 11, 2025
- Vuln Type: Authorization