Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 5.4

    MEDIUM
    CVE-2023-33394

    skycaiji v2.5.4 is vulnerable to Cross Site Scripting (XSS). Attackers can achieve backend XSS by deploying malicious JSON data.... Read more

    Affected Products : skycaiji
    • EPSS Score: %0.08
    • Published: May. 26, 2023
    • Modified: Jan. 15, 2025
  • 5.4

    MEDIUM
    CVE-2024-56923

    Stored Cross-Site Scripting (XSS) Vulnerability in the Categorization Option of My Subscriptions Functionality in Silverpeas Core 6.3.1 <= 6.4.1 allows a remote attacker to execute arbitrary JavaScript code. This is achieved by injecting a malicious paylo... Read more

    Affected Products : silverpeas
    • Published: Jan. 22, 2025
    • Modified: May. 28, 2025
  • 5.4

    MEDIUM
    CVE-2023-32340

    IBM Sterling B2B Integrator 6.0.0.0 through 6.1.2.5 and 6.2.0.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credent... Read more

    Affected Products : sterling_b2b_integrator
    • Published: Jan. 23, 2025
    • Modified: Mar. 04, 2025
  • 5.4

    MEDIUM
    CVE-2022-36244

    Shop Beat Solutions (Pty) LTD Shop Beat Media Player 2.5.95 up to 3.2.57 suffers from Multiple Stored Cross-Site Scripting (XSS) vulnerabilities via Shop Beat Control Panel found at www.shopbeat.co.za controlpanel.shopbeat.co.za.... Read more

    Affected Products : shop_beat_media_player
    • EPSS Score: %0.08
    • Published: May. 30, 2023
    • Modified: Jan. 13, 2025
  • 5.4

    MEDIUM
    CVE-2025-24712

    Cross-Site Request Forgery (CSRF) vulnerability in RadiusTheme Radius Blocks allows Cross Site Request Forgery. This issue affects Radius Blocks: from n/a through 2.1.2.... Read more

    Affected Products :
    • Published: Jan. 24, 2025
    • Modified: Jan. 24, 2025
  • 5.4

    MEDIUM
    CVE-2025-24715

    Cross-Site Request Forgery (CSRF) vulnerability in Wow-Company Counter Box allows Cross Site Request Forgery. This issue affects Counter Box: from n/a through 2.0.5.... Read more

    Affected Products : counter_box
    • Published: Jan. 24, 2025
    • Modified: Jun. 09, 2025
  • 5.4

    MEDIUM
    CVE-2025-24720

    Cross-Site Request Forgery (CSRF) vulnerability in Wow-Company Sticky Buttons allows Cross Site Request Forgery. This issue affects Sticky Buttons: from n/a through 4.1.1.... Read more

    Affected Products : sticky_buttons
    • Published: Jan. 24, 2025
    • Modified: Jan. 24, 2025
  • 5.4

    MEDIUM
    CVE-2025-24724

    Cross-Site Request Forgery (CSRF) vulnerability in Wow-Company Side Menu Lite allows Cross Site Request Forgery. This issue affects Side Menu Lite: from n/a through 5.3.1.... Read more

    Affected Products :
    • Published: Jan. 24, 2025
    • Modified: Jan. 24, 2025
  • 5.4

    MEDIUM
    CVE-2024-35112

    IBM Control Center 6.2.1 and 6.3.1 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system.... Read more

    Affected Products : control_center
    • Published: Jan. 25, 2025
    • Modified: Mar. 04, 2025
  • 5.4

    MEDIUM
    CVE-2023-3035

    A vulnerability has been found in Guangdong Pythagorean OA Office System up to 4.50.31 and classified as problematic. Affected by this vulnerability is an unknown functionality of the component Schedule Handler. The manipulation of the argument descriptio... Read more

    Affected Products : pythagorean_oa_office_system
    • EPSS Score: %0.07
    • Published: Jun. 01, 2023
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2025-24533

    Cross-Site Request Forgery (CSRF) vulnerability in MetaSlider Responsive Slider by MetaSlider allows Cross Site Request Forgery. This issue affects Responsive Slider by MetaSlider: from n/a through 3.92.0.... Read more

    Affected Products : slider\,_gallery\,_and_carousel
    • Published: Jan. 27, 2025
    • Modified: Jan. 27, 2025
  • 5.4

    MEDIUM
    CVE-2025-24538

    Cross-Site Request Forgery (CSRF) vulnerability in slaFFik BuddyPress Groups Extras allows Cross Site Request Forgery. This issue affects BuddyPress Groups Extras: from n/a through 3.6.10.... Read more

    Affected Products :
    • Published: Jan. 27, 2025
    • Modified: Jan. 27, 2025
  • 5.4

    MEDIUM
    CVE-2025-22917

    A reflected cross-site scripting (XSS) vulnerability in Audemium ERP <=0.9.0 allows remote attackers to execute an arbitrary JavaScript payload in the web browser of a user by including a malicious payload into the 'type' parameter of list.php.... Read more

    Affected Products :
    • Published: Jan. 28, 2025
    • Modified: Jan. 29, 2025
  • 5.4

    MEDIUM
    CVE-2024-57438

    Insecure permissions in RuoYi v4.8.0 allows authenticated attackers to escalate privileges by assigning themselves higher level roles.... Read more

    Affected Products : ruoyi
    • Published: Jan. 29, 2025
    • Modified: May. 14, 2025
  • 5.4

    MEDIUM
    CVE-2019-25143

    The GDPR Cookie Compliance plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the gdpr_cookie_compliance_reset_settings AJAX action in versions up to, and including, 4.0.2. This makes it possible for authentica... Read more

    Affected Products : gdpr_cookie_compliance
    • EPSS Score: %0.03
    • Published: Jun. 07, 2023
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2023-3143

    A vulnerability classified as problematic has been found in SourceCodester Online Discussion Forum Site 1.0. Affected is an unknown function of the file admin\posts\manage_post.php. The manipulation of the argument content leads to cross site scripting. I... Read more

    • EPSS Score: %0.07
    • Published: Jun. 07, 2023
    • Modified: Apr. 22, 2025
  • 5.4

    MEDIUM
    CVE-2024-10867

    The Borderless – Widgets, Elements, Templates and Toolkit for Elementor & Gutenberg plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.5.9 due to insufficient input sanitization a... Read more

    Affected Products : borderless
    • Published: Jan. 31, 2025
    • Modified: Mar. 25, 2025
  • 5.4

    MEDIUM
    CVE-2024-13101

    The WP MediaTagger WordPress plugin through 4.1.1 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform... Read more

    Affected Products : wp_mediatagger
    • Published: Jan. 31, 2025
    • Modified: May. 11, 2025
  • 5.4

    MEDIUM
    CVE-2023-2031

    The Locatoraid Store Locator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in versions up to, and including, 3.9.14 due to insufficient input sanitization and output escaping on user supplied attributes. T... Read more

    Affected Products : locatoraid locatoraid_store_locator
    • EPSS Score: %0.09
    • Published: Jun. 09, 2023
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2023-2414

    The Online Booking & Scheduling Calendar for WordPress by vcita plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the vcita_save_settings_callback function in versions up to, and including, 4.4.6.... Read more

    • EPSS Score: %0.06
    • Published: Jun. 09, 2023
    • Modified: Mar. 20, 2025
Showing 20 of 290958 Results