Latest CVE Feed
-
5.4
MEDIUMCVE-2024-2688
The EmbedPress – Embed PDF, Google Docs, Vimeo, Wistia, Embed YouTube Videos, Audios, Maps & Embed Any Documents in Gutenberg & Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the EmbedPress document widget in all versions ... Read more
Affected Products : embedpress- Published: Mar. 23, 2024
- Modified: Jan. 07, 2025
-
5.4
MEDIUMCVE-2022-45351
Missing Authorization vulnerability in Muffingroup Betheme.This issue affects Betheme: from n/a through 26.6.1. ... Read more
Affected Products : betheme- Published: Mar. 25, 2024
- Modified: Jan. 31, 2025
-
5.4
MEDIUMCVE-2024-29233
Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in Emap.Delete webapi component in Synology Surveillance Station before 9.2.0-9289 and 9.2.0-11289 allows remote authenticated users to read database contai... Read more
- Published: Mar. 28, 2024
- Modified: Aug. 04, 2025
-
5.4
MEDIUMCVE-2024-31138
In JetBrains TeamCity before 2024.03 xSS was possible via Agent Distribution settings... Read more
Affected Products : teamcity- Published: Mar. 28, 2024
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2024-1858
The Lightbox slider – Responsive Lightbox Gallery plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.9.9 via deserialization of untrusted input through post meta data. This makes it possible for authenticate... Read more
Affected Products :- Published: Mar. 29, 2024
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2024-2108
The Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via an image title embedded into a form in all versions up to, and including, 3.8.0 due to insufficient input san... Read more
Affected Products : ninja_forms- Published: Mar. 29, 2024
- Modified: Jan. 23, 2025
-
5.4
MEDIUMCVE-2024-30521
Cross-Site Request Forgery (CSRF) vulnerability in Landingi Landingi Landing Pages.This issue affects Landingi Landing Pages: from n/a through 3.1.1. ... Read more
Affected Products :- Published: Mar. 29, 2024
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2024-31100
Cross-Site Request Forgery (CSRF) vulnerability in Festi-Team Popup Cart Lite for WooCommerce.This issue affects Popup Cart Lite for WooCommerce: from n/a through 1.1. ... Read more
Affected Products :- Published: Mar. 31, 2024
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2024-20302
A vulnerability in the tenant security implementation of Cisco Nexus Dashboard Orchestrator (NDO) could allow an authenticated, remote attacker to modify or delete tenant templates on an affected system. This vulnerability is due to improper access c... Read more
Affected Products : nexus_dashboard_orchestrator- Published: Apr. 03, 2024
- Modified: Apr. 11, 2025
-
5.4
MEDIUMCVE-2024-3357
A vulnerability classified as problematic has been found in SourceCodester Aplaya Beach Resort Online Reservation System 1.0. This affects an unknown part of the file admin/mod_reports/index.php. The manipulation of the argument end leads to cross site sc... Read more
Affected Products : aplaya_beach_resort_online_reservation_system- Published: Apr. 05, 2024
- Modified: Feb. 11, 2025
-
5.4
MEDIUMCVE-2024-27665
Unifiedtransform v2.X is vulnerable to Stored Cross-Site Scripting (XSS) via file upload feature in Syllabus module.... Read more
Affected Products :- Published: Apr. 09, 2024
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2024-3525
A vulnerability, which was classified as problematic, was found in Campcodes Online Event Management System 1.0. Affected is an unknown function of the file /views/index.php. The manipulation of the argument msg leads to cross site scripting. It is possib... Read more
Affected Products : online_event_management_system- Published: Apr. 10, 2024
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-27607
Missing Authorization vulnerability in WP Swings Points and Rewards for WooCommerce.This issue affects Points and Rewards for WooCommerce: from n/a through 1.5.0. ... Read more
Affected Products :- Published: Apr. 11, 2024
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2024-3763
A vulnerability was found in Emlog Pro 2.2.10. It has been rated as problematic. This issue affects some unknown processing of the file /admin/tag.php of the component Post Tag Handler. The manipulation leads to cross site scripting. The attack may be ini... Read more
- Published: Apr. 14, 2024
- Modified: Mar. 05, 2025
-
5.4
MEDIUMCVE-2024-32452
Cross-Site Request Forgery (CSRF) vulnerability in WP EasyCart.This issue affects WP EasyCart: from n/a through 5.5.19. ... Read more
Affected Products :- Published: Apr. 15, 2024
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2024-31434
Cross-Site Request Forgery (CSRF) vulnerability in Stefano Lissa & The Newsletter Team Newsletter.This issue affects Newsletter: from n/a through 8.0.6. ... Read more
Affected Products : newsletter- Published: Apr. 15, 2024
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2024-32506
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in SoftLab Radio Player.This issue affects Radio Player: from n/a through 2.0.73. ... Read more
Affected Products : radio_player- Published: Apr. 17, 2024
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2024-32142
Missing Authorization vulnerability in Ovic Team Ovic Responsive WPBakery.This issue affects Ovic Responsive WPBakery: from n/a through 1.3.0. ... Read more
Affected Products :- Published: Apr. 18, 2024
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2024-27752
Cross Site Scripting vulnerability in CSZ CMS v.1.3.0 allows a remote attacker to execute arbitrary code via the Default Keyword field in the settings function.... Read more
Affected Products : csz_cms- Published: Apr. 19, 2024
- Modified: May. 21, 2025
-
5.4
MEDIUMCVE-2024-1730
The Prime Slider – Addons For Elementor (Revolution of a slider, Hero Slider, Media Slider, Drag Drop Slider, Video Slider, Product Slider, Ecommerce Slider) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via urls in link fields, images... Read more
Affected Products : prime_slider- Published: Apr. 20, 2024
- Modified: Feb. 05, 2025