Latest CVE Feed
-
5.4
MEDIUMCVE-2024-28781
IBM UrbanCode Deploy (UCD) 7.0 through 7.0.5.20, 7.1 through 7.1.2.16, 7.2 through 7.2.3.9, 7.3 through 7.3.2.4, and 8.0 through 8.0.0.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web U... Read more
- Published: May. 14, 2024
- Modified: Jan. 27, 2025
-
5.4
MEDIUMCVE-2024-34899
WWBN AVideo 12.4 is vulnerable to Cross Site Scripting (XSS).... Read more
Affected Products : avideo- Published: May. 14, 2024
- Modified: Jun. 18, 2025
-
5.4
MEDIUMCVE-2024-3722
The Swift Performance Lite plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the ajax_handler() function in all versions up to, and including, 2.3.6.18. This makes it possible for authenticated attackers, with ... Read more
Affected Products :- Published: May. 14, 2024
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2024-4721
A vulnerability classified as problematic has been found in Campcodes Complete Web-Based School Management System 1.0. This affects an unknown part of the file /model/add_student_subject.php. The manipulation of the argument index leads to cross site scri... Read more
Affected Products : complete_web-based_school_management_system- Published: May. 14, 2024
- Modified: Feb. 20, 2025
-
5.4
MEDIUMCVE-2024-4729
A vulnerability was found in Campcodes Legal Case Management System 1.0. It has been rated as problematic. This issue affects some unknown processing of the file /admin/expense-type. The manipulation of the argument name leads to cross site scripting. The... Read more
Affected Products : legal_case_management_system- Published: May. 14, 2024
- Modified: Feb. 19, 2025
-
5.4
MEDIUMCVE-2024-32077
Apache Airflow version 2.9.0 has a vulnerability that allows an authenticated attacker to inject malicious data into the task instance logs. Users are recommended to upgrade to version 2.9.1, which fixes this issue.... Read more
Affected Products : airflow- Published: May. 14, 2024
- Modified: Mar. 27, 2025
-
5.4
MEDIUMCVE-2024-3241
The Ultimate Blocks WordPress plugin before 3.1.7 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cr... Read more
Affected Products : ultimate_blocks- Published: May. 14, 2024
- Modified: May. 14, 2025
-
5.4
MEDIUMCVE-2024-3189
The Gutenberg Blocks by Kadence Blocks – Page Builder Features plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'Testimonial', 'Progress Bar', 'Lottie Animations', 'Row Layout', 'Google Maps', and 'Advanced Gallery' block... Read more
Affected Products : gutenberg_blocks_with_ai- Published: May. 15, 2024
- Modified: Feb. 07, 2025
-
5.4
MEDIUMCVE-2024-34913
An arbitrary file upload vulnerability in r-pan-scaffolding v5.0 and below allows attackers to execute arbitrary code via uploading a crafted PDF file.... Read more
Affected Products : r-pan-scaffolding- Published: May. 15, 2024
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2024-9866
The Event Tickets with Ticket Scanner plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'data' parameters in all versions up to, and including, 2.4.4 due to insufficient input sanitization and output escaping and missing authorizat... Read more
Affected Products : event_tickets_with_ticket_scanner- Published: Dec. 06, 2024
- Modified: Dec. 06, 2024
-
5.4
MEDIUMCVE-2024-33527
A Stored Cross-site Scripting (XSS) vulnerability in the "Import of Users and login name of user" feature in ILIAS 7 before 7.30 and ILIAS 8 before 8.11 allows remote authenticated attackers with administrative privileges to inject arbitrary web script or... Read more
Affected Products : ilias- Published: May. 21, 2024
- Modified: Jun. 04, 2025
-
5.4
MEDIUMCVE-2024-30419
Cross-site scripting vulnerability exists in a-blog cms Ver.3.1.x series versions prior to Ver.3.1.12, Ver.3.0.x series versions prior to Ver.3.0.32, Ver.2.11.x series versions prior to Ver.2.11.61, Ver.2.10.x series versions prior to Ver.2.10.53, and Ver... Read more
Affected Products : a-blog_cms- Published: May. 22, 2024
- Modified: May. 12, 2025
-
5.4
MEDIUMCVE-2024-1446
The NextScripts: Social Networks Auto-Poster plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.4.3. This is due to missing or incorrect nonce validation on the nxssnap-reposter page. This makes it pos... Read more
Affected Products : social_networks_auto_poster- Published: May. 22, 2024
- Modified: Feb. 07, 2025
-
5.4
MEDIUMCVE-2023-6487
The LuckyWP Table of Contents plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘Header Title' field in all versions up to and including 2.1.4 due to insufficient input sanitization and output escaping. This makes it possible for a... Read more
Affected Products : luckywp_table_of_contents- Published: May. 22, 2024
- Modified: May. 28, 2025
-
5.4
MEDIUMCVE-2024-35554
idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/infoWeb_deal.php?mudi=del&dataType=newsWeb&dataTypeCN.... Read more
- Published: May. 22, 2024
- Modified: Apr. 09, 2025
-
5.4
MEDIUMCVE-2024-29392
Silverpeas Core 6.3 is vulnerable to Cross Site Scripting (XSS) via ClipboardSessionController.... Read more
Affected Products : silverpeas- Published: May. 22, 2024
- Modified: Apr. 23, 2025
-
5.4
MEDIUMCVE-2024-35197
gitoxide is a pure Rust implementation of Git. On Windows, fetching refs that clash with legacy device names reads from the devices, and checking out paths that clash with such names writes arbitrary data to the devices. This allows a repository, when clo... Read more
Affected Products :- Published: May. 23, 2024
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2024-35085
J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerability via the findPage function in ProcessDefinitionMapper.xml.... Read more
Affected Products : j2eefast- Published: May. 23, 2024
- Modified: Apr. 16, 2025
-
5.4
MEDIUMCVE-2024-5310
A vulnerability classified as problematic has been found in JFinalCMS up to 20221020. This affects an unknown part of the file /admin/content. The manipulation of the argument Title leads to cross site scripting. It is possible to initiate the attack remo... Read more
Affected Products : jfinalcms- Published: May. 24, 2024
- Modified: Jun. 05, 2025
-
5.4
MEDIUMCVE-2023-47710
IBM Security Guardium 11.4, 11.5, and 12.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure withi... Read more
Affected Products : security_guardium- Published: May. 24, 2024
- Modified: Jan. 08, 2025