Latest CVE Feed
-
5.4
MEDIUMCVE-2021-24690
The Chained Quiz WordPress plugin before 1.2.7.2 does not properly sanitize or escape inputs in the plugin's settings.... Read more
Affected Products : chained_quiz- EPSS Score: %0.25
- Published: Oct. 11, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-30959
In Apollo change requests, comments added by users could contain a javascript URI link that when rendered will result in an XSS that require user interaction.... Read more
Affected Products : apollo_autopilot- EPSS Score: %0.18
- Published: Sep. 27, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-6485
The Html5 Video Player WordPress plugin before 2.5.19 does not sanitise and escape some of its player settings, which combined with missing capability checks around the plugin could allow any authenticated users, such as low as subscribers to perform Stor... Read more
Affected Products : html5_video_player- EPSS Score: %2.45
- Published: Jan. 01, 2024
- Modified: Jun. 18, 2025
-
5.4
MEDIUMCVE-2014-4895
The Herpin Time Radio (aka com.herpin.time.radio) application 2.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.... Read more
Affected Products : herpin_time_radio- EPSS Score: %0.04
- Published: Oct. 21, 2014
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2014-4897
The Touriosity Travelmag (aka com.magzter.touriositytravelmag) application 3.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certif... Read more
Affected Products : touriosity_travelmag- EPSS Score: %0.04
- Published: Oct. 21, 2014
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2014-4899
The Indian Cement Review (aka com.magzter.indiancementreview) application 3.01 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certif... Read more
Affected Products : indian_cement_review- EPSS Score: %0.04
- Published: Oct. 21, 2014
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2024-3730
The Simple Membership plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'swpm_paypal_subscription_cancel_link' shortcode in all versions up to, and including, 4.4.3 due to insufficient input sanitization and output escapin... Read more
Affected Products : simple_membership- Published: Apr. 25, 2024
- Modified: Feb. 05, 2025
-
5.4
MEDIUMCVE-2024-37763
MachForm up to version 19 is affected by an unauthenticated stored cross-site scripting which affects users with valid sessions whom can view compiled forms results.... Read more
Affected Products : machform- Published: Jul. 01, 2024
- Modified: Apr. 30, 2025
-
5.4
MEDIUMCVE-2014-6841
The RTI INDIA (aka com.vbulletin.build_890) application 3.8.21 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.... Read more
Affected Products : rti_india- EPSS Score: %0.04
- Published: Sep. 30, 2014
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2014-6844
The ABC Song (aka com.tabtale.abcsingalong) application 1.0.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.... Read more
Affected Products : abc_song- EPSS Score: %0.04
- Published: Sep. 30, 2014
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2014-6869
The barcode scanner (aka tw.com.books.android.plus) application 2.3.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.... Read more
Affected Products : barcode_scanner- EPSS Score: %0.04
- Published: Oct. 02, 2014
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2024-38351
Pocketbase is an open source web backend written in go. In affected versions a malicious user may be able to compromise other user accounts. In order to be exploited users must have both OAuth2 and Password auth methods enabled. A possible attack scenario... Read more
Affected Products :- Published: Jun. 18, 2024
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2024-0346
A vulnerability has been found in CodeAstro Vehicle Booking System 1.0 and classified as problematic. This vulnerability affects unknown code of the file usr/user-give-feedback.php of the component Feedback Page. The manipulation of the argument My Testem... Read more
Affected Products : vehicle_booking_system- EPSS Score: %0.13
- Published: Jan. 09, 2024
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-37407
Multiple Authenticated Stored Cross-Site Scripting (XSS) vulnerabilities in WPChill Gallery PhotoBlocks plugin <= 1.2.6 at WordPress.... Read more
Affected Products : gallery_photoblocks- EPSS Score: %0.24
- Published: Sep. 09, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-24930
The WordPress Online Booking and Scheduling Plugin WordPress plugin before 20.3.1 does not escape the Staff Full Name field before outputting it back in a page, which could lead to a Stored Cross-Site Scripting issue... Read more
Affected Products : bookly- EPSS Score: %0.18
- Published: Dec. 06, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2024-38737
Missing Authorization vulnerability in Reservation Diary ReDi Restaurant Reservation allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects ReDi Restaurant Reservation: from n/a through 24.0422.... Read more
- Published: Nov. 01, 2024
- Modified: Nov. 01, 2024
-
5.4
MEDIUMCVE-2022-33075
A stored cross-site scripting (XSS) vulnerability in the Add Classification function of Zoo Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via unspecified vectors.... Read more
- EPSS Score: %0.18
- Published: Jul. 05, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2024-1641
The Accordion plugin for WordPress is vulnerable to unauthorized access of data and modification of data due to a missing capability check on the 'accordions_duplicate_post_as_draft' function in all versions up to, and including, 2.2.96. This makes it pos... Read more
Affected Products : accordion- Published: Apr. 09, 2024
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2024-1746
The Testimonial Slider WordPress plugin before 2.3.8 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallo... Read more
Affected Products : testimonial_slider_and_showcase- Published: Apr. 15, 2024
- Modified: May. 08, 2025
-
5.4
MEDIUMCVE-2014-6934
The Physics Chemistry Biology Quiz (aka com.pdevsmcqs.pcbmcqseries) application 1.8 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted c... Read more
Affected Products : physics_chemistry_biology_quiz- EPSS Score: %0.04
- Published: Oct. 11, 2014
- Modified: Apr. 12, 2025