Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 5.4

    MEDIUM
    CVE-2023-1871

    The YourChannel plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.2.3. This is due to missing or incorrect nonce validation on the deleteLang function. This makes it possible for unauthenticated attackers... Read more

    Affected Products : yourchannel
    • Published: Apr. 05, 2023
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2023-1879

    Cross-site Scripting (XSS) - Stored in GitHub repository thorsten/phpmyfaq prior to 3.1.12.... Read more

    Affected Products : phpmyfaq
    • Published: Apr. 05, 2023
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2023-1883

    Improper Access Control in GitHub repository thorsten/phpmyfaq prior to 3.1.12.... Read more

    Affected Products : phpmyfaq
    • Published: Apr. 05, 2023
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2023-24747

    Jfinal CMS v5.1 was discovered to contain a cross-site scripting (XSS) vulnerability via the component /system/dict/list.... Read more

    Affected Products : jfinal_cms
    • Published: Apr. 05, 2023
    • Modified: Feb. 13, 2025
  • 5.4

    MEDIUM
    CVE-2022-4827

    The WP Tiles WordPress plugin through 1.1.2 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Store... Read more

    Affected Products : wp_tiles
    • Published: Apr. 10, 2023
    • Modified: Apr. 23, 2025
  • 5.4

    MEDIUM
    CVE-2023-24721

    A cross-site scripting (XSS) vulnerability in LiveAction LiveSP v21.1.2 allows attackers to execute arbitrary web scripts or HTML.... Read more

    Affected Products : livesp
    • Published: Apr. 10, 2023
    • Modified: Feb. 11, 2025
  • 5.4

    MEDIUM
    CVE-2025-22543

    Missing Authorization vulnerability in Beautiful Templates ST Gallery WP allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects ST Gallery WP: from n/a through 1.0.8.... Read more

    Affected Products :
    • Published: Jan. 07, 2025
    • Modified: Jan. 07, 2025
    • Vuln Type: Authorization
  • 5.4

    MEDIUM
    CVE-2022-45849

    Auth. (subscriber+) Reflected Cross-Site Scripting (XSS) vulnerability in Silkalns Activello theme <= 1.4.4 versions.... Read more

    Affected Products : activello_theme
    • Published: Apr. 16, 2023
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2023-27777

    Cross-site scripting (XSS) vulnerability was discovered in Online Jewelry Shop v1.0 that allows attackers to execute arbitrary script via a crafted URL.... Read more

    Affected Products : online_jewelry_shop
    • Published: Apr. 19, 2023
    • Modified: Feb. 05, 2025
  • 5.4

    MEDIUM
    CVE-2024-56377

    A stored cross-site scripting (XSS) vulnerability in survey titles of REDCap 14.9.6 allows authenticated users to inject malicious scripts into the Survey Title field or Survey Instructions. When a user receives a survey and clicks anywhere on the survey ... Read more

    Affected Products : redcap
    • Published: Jan. 09, 2025
    • Modified: Jan. 16, 2025
    • Vuln Type: Cross-Site Scripting
  • 5.4

    MEDIUM
    CVE-2023-0424

    The MS-Reviews WordPress plugin through 1.5 does not sanitise and escape reviews, which could allow users any authenticated users, such as Subscribers to perform Stored Cross-Site Scripting attacks... Read more

    Affected Products : ms-reviews
    • Published: Apr. 24, 2023
    • Modified: Feb. 04, 2025
  • 5.4

    MEDIUM
    CVE-2022-27979

    A cross-site scripting (XSS) vulnerability in ToolJet v1.6.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Comment Body component.... Read more

    Affected Products : tooljet
    • Published: Apr. 26, 2023
    • Modified: Feb. 03, 2025
  • 5.4

    MEDIUM
    CVE-2023-2350

    A vulnerability classified as problematic was found in SourceCodester Service Provider Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /classes/Users.php. The manipulation of the argument id leads to cross sit... Read more

    • Published: Apr. 27, 2023
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2022-43871

    IBM Financial Transaction Manager for SWIFT Services 3.2.4 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials ... Read more

    • Published: Apr. 29, 2023
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2022-45801

    Apache StreamPark 1.0.0 to 2.0.0 have a LDAP injection vulnerability. LDAP Injection is an attack used to exploit web based applications that construct LDAP statements based on user input. When an application fails to properly sanitize user input, it's po... Read more

    Affected Products : streampark
    • Published: May. 01, 2023
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2023-1861

    The Limit Login Attempts WordPress plugin through 1.7.2 does not sanitize and escape usernames when outputting them back in the logs dashboard, which could allow any authenticated users, such as subscriber to perform Stored Cross-Site Scripting attacks... Read more

    Affected Products : limit_login_attempts
    • Published: May. 02, 2023
    • Modified: Jan. 30, 2025
  • 5.4

    MEDIUM
    CVE-2023-30184

    A stored cross-site scripting (XSS) vulnerability in Typecho v1.2.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the url parameter at /index.php/archives/1/comment.... Read more

    Affected Products : typecho
    • Published: May. 04, 2023
    • Modified: Jan. 29, 2025
  • 5.4

    MEDIUM
    CVE-2023-30095

    A stored cross-site scripting (XSS) vulnerability in TotalJS messenger commit b6cf1c9 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the channel description field.... Read more

    Affected Products : messenger
    • Published: May. 04, 2023
    • Modified: Jan. 29, 2025
  • 5.4

    MEDIUM
    CVE-2023-0268

    The Mega Addons For WPBakery Page Builder WordPress plugin before 4.3.0 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor rol... Read more

    • Published: May. 08, 2023
    • Modified: Jan. 28, 2025
  • 5.4

    MEDIUM
    CVE-2022-27856

    Auth. (editor+) Stored Cross-Site Scripting (XSS) vulnerability in Atlas Gondal Export All URLs plugin <= 4.1 versions.... Read more

    Affected Products : export_all_urls
    • Published: May. 10, 2023
    • Modified: Nov. 21, 2024
Showing 20 of 293435 Results