Latest CVE Feed
-
5.4
MEDIUMCVE-2023-32066
Time Tracker is an open source time tracking system. The week view plugin in Time Tracker versions 1.22.11.5782 and prior was not escaping titles for notes in week view table. Because of that, it was possible for a logged in user to enter notes with eleme... Read more
Affected Products : time_tracker- EPSS Score: %0.08
- Published: May. 09, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2024-31544
A stored cross-site scripting (XSS) vulnerability in Computer Laboratory Management System v1.0 allows attackers to execute arbitrary JavaScript code by including malicious payloads into “remarks”, “borrower_name”, “faculty_department” parameters in /clas... Read more
Affected Products : computer_laboratory_management_system- Published: Apr. 09, 2024
- Modified: Apr. 11, 2025
-
5.4
MEDIUMCVE-2014-5915
The Tigo Copa Mundial FIFA 2014 (aka com.fwc2014.millicom.and) application 3.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certif... Read more
Affected Products : tigo_copa_mundial_fifa_2014- EPSS Score: %0.04
- Published: Sep. 17, 2014
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2024-33231
Cross Site Scripting vulnerability in Ferozo Email version 1.1 allows a local attacker to execute arbitrary code via a crafted payload to the PDF preview component.... Read more
Affected Products :- Published: Nov. 18, 2024
- Modified: Nov. 19, 2024
-
5.4
MEDIUMCVE-2014-5966
The Dreamland Super Theme GO Gold (aka com.gau.go.launcherex.viptheme.dreamland.gold) application 1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information... Read more
Affected Products : dreamland_super_theme_go_gold- EPSS Score: %0.04
- Published: Sep. 19, 2014
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2024-33588
Missing Authorization vulnerability in codeSavory Knowledge Base documentation & wiki plugin – BasePress.This issue affects Knowledge Base documentation & wiki plugin – BasePress: from n/a through 2.16.1. ... Read more
Affected Products :- Published: Apr. 29, 2024
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2024-26490
A cross-site scripting (XSS) vulnerability in the Addon JD Simple module of flusity-CMS v2.33 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Title text field.... Read more
Affected Products : flusity- Published: Feb. 22, 2024
- Modified: Mar. 25, 2025
-
5.4
MEDIUMCVE-2024-56234
Missing Authorization vulnerability in VW THEMES VW Automobile Lite allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects VW Automobile Lite: from n/a through 2.1.... Read more
Affected Products :- Published: Dec. 31, 2024
- Modified: Dec. 31, 2024
-
5.4
MEDIUMCVE-2024-28965
Dell SCG, versions prior to 5.24.00.00, contain an Improper Access Control vulnerability in the SCG exposed for an internal enable REST API (if enabled by Admin user from UI). A remote low privileged attacker could potentially exploit this vulnerability, ... Read more
Affected Products : secure_connect_gateway- Published: Jun. 13, 2024
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2024-2997
A vulnerability was found in Bdtask Multi-Store Inventory Management System up to 20240320. It has been declared as problematic. Affected by this vulnerability is an unknown functionality. The manipulation of the argument Category Name/Model Name/Brand Na... Read more
- Published: Mar. 27, 2024
- Modified: Jun. 12, 2025
-
5.4
MEDIUMCVE-2014-5987
The My3 - by 3HK (aka com.my3) application @7F0A0001 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.... Read more
Affected Products : my3- EPSS Score: %0.04
- Published: Sep. 20, 2014
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2024-35561
idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/ca_deal.php?mudi=add&nohrefStr=close.... Read more
- Published: May. 22, 2024
- Modified: Apr. 09, 2025
-
5.4
MEDIUMCVE-2022-25611
Authenticated Stored Cross-Site Scripting (XSS) in Simple Event Planner plugin <= 1.5.4 allows attackers with contributor or higher user roles to inject the malicious script by using vulnerable parameter &custom[add_seg][].... Read more
Affected Products : simple_event_planner- EPSS Score: %0.17
- Published: Mar. 25, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2024-3570
A stored Cross-Site Scripting (XSS) vulnerability exists in the chat functionality of the mintplex-labs/anything-llm repository, allowing attackers to execute arbitrary JavaScript in the context of a user's session. By manipulating the ChatBot responses, ... Read more
Affected Products : anythingllm- Published: Apr. 10, 2024
- Modified: Jul. 09, 2025
-
5.4
MEDIUMCVE-2024-31369
Cross-Site Request Forgery (CSRF) vulnerability in PenciDesign Soledad.This issue affects Soledad: from n/a through 8.4.2. ... Read more
Affected Products : soledad- Published: Apr. 09, 2024
- Modified: Jul. 02, 2025
-
5.4
MEDIUMCVE-2024-31403
Incorrect authorization vulnerability in Cybozu Garoon 5.0.0 to 6.0.0 allows a remote authenticated attacker to alter and/or obtain the data of Memo.... Read more
Affected Products : garoon- Published: Jun. 11, 2024
- Modified: May. 28, 2025
-
5.4
MEDIUMCVE-2023-28499
Auth. (author+) Stored Cross-Site Scripting (XSS) vulnerability in simonpedge Slide Anything – Responsive Content / HTML Slider and Carousel plugin <= 2.4.9 versions.... Read more
Affected Products : slide_anything-responsive_content\/html_slider_and_carousel- EPSS Score: %0.22
- Published: Nov. 07, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2024-3695
A vulnerability has been found in SourceCodester Computer Laboratory Management System 1.0 and classified as problematic. This vulnerability affects unknown code of the file /classes/Users.php. The manipulation of the argument id leads to cross site scrip... Read more
- Published: Apr. 12, 2024
- Modified: Jan. 21, 2025
-
5.4
MEDIUMCVE-2023-5534
The AI ChatBot plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.8.9 and 4.9.2. This is due to missing or incorrect nonce validation on the corresponding functions. This makes it possible for unauthentica... Read more
- EPSS Score: %0.06
- Published: Oct. 20, 2023
- Modified: May. 12, 2025
-
5.4
MEDIUMCVE-2024-37799
CodeProjects Restaurant Reservation System v1.0 was discovered to contain a SQL injection vulnerability via the reserv_id parameter at view_reservations.php.... Read more
Affected Products : restaurant_reservation_system- Published: Jun. 18, 2024
- Modified: Apr. 30, 2025