Latest CVE Feed
-
5.4
MEDIUMCVE-2023-5534
The AI ChatBot plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.8.9 and 4.9.2. This is due to missing or incorrect nonce validation on the corresponding functions. This makes it possible for unauthentica... Read more
- EPSS Score: %0.06
- Published: Oct. 20, 2023
- Modified: May. 12, 2025
-
5.4
MEDIUMCVE-2024-37799
CodeProjects Restaurant Reservation System v1.0 was discovered to contain a SQL injection vulnerability via the reserv_id parameter at view_reservations.php.... Read more
Affected Products : restaurant_reservation_system- Published: Jun. 18, 2024
- Modified: Apr. 30, 2025
-
5.4
MEDIUMCVE-2014-6191
Cross-site scripting (XSS) vulnerability in IBM Curam Social Program Management 6.0 SP2, 6.0.4, and 6.0.5 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. IBM X-Force ID: 98568.... Read more
Affected Products : curam_social_program_management- EPSS Score: %0.15
- Published: Sep. 19, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2023-5651
The WP Hotel Booking WordPress plugin before 2.0.8 does not have authorisation and CSRF checks, as well as does not ensure that the package to be deleted is a package, allowing any authenticated users, such as subscriber to delete arbitrary posts... Read more
Affected Products : wp_hotel_booking- EPSS Score: %0.05
- Published: Nov. 20, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2024-33592
Server-Side Request Forgery (SSRF) vulnerability in SoftLab Radio Player.This issue affects Radio Player: from n/a through 2.0.73. ... Read more
Affected Products : radio_player- Published: Apr. 25, 2024
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2024-33638
Cross-Site Request Forgery (CSRF) vulnerability in Brijesh Kothari Smart Maintenance Mode.This issue affects Smart Maintenance Mode: from n/a through 1.4.4. ... Read more
Affected Products : smart_maintenance_mode- Published: Apr. 26, 2024
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-41472
74cmsSE v3.12.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the component /apiadmin/notice/add. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Title field.... Read more
Affected Products : 74cmsse- EPSS Score: %0.10
- Published: Oct. 17, 2022
- Modified: May. 14, 2025
-
5.4
MEDIUMCVE-2024-7844
A vulnerability has been found in SourceCodester Online Graduate Tracer System 1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /tracking/admin/add_acc.php. The manipulation of the argument name/use... Read more
Affected Products : online_graduate_tracer_system online_graduate_tracer_system online_graduate_tracer_system- Published: Aug. 15, 2024
- Modified: Feb. 18, 2025
-
5.4
MEDIUMCVE-2023-5738
The WordPress Backup & Migration WordPress plugin before 1.4.4 does not sanitise and escape some parameters, which could allow users with a role as low as Subscriber to perform Cross-Site Scripting attacks.... Read more
Affected Products : backup_and_migration- EPSS Score: %0.11
- Published: Nov. 27, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2024-8337
A vulnerability, which was classified as problematic, has been found in SourceCodester Contact Manager with Export to VCF 1.0. Affected by this issue is some unknown functionality of the file index.html. The manipulation of the argument contact_name leads... Read more
- Published: Aug. 30, 2024
- Modified: Nov. 22, 2024
-
5.4
MEDIUMCVE-2024-8554
A vulnerability was found in SourceCodester Clinics Patient Management System 2.0 and classified as problematic. This issue affects some unknown processing of the file /users.php. The manipulation of the argument message leads to cross site scripting. The... Read more
- Published: Sep. 07, 2024
- Modified: Sep. 10, 2024
-
5.4
MEDIUMCVE-2024-8583
A vulnerability was found in SourceCodester Online Bank Management System and Online Bank Management System - 1.0. It has been classified as problematic. This affects an unknown part of the file /mfeedback.php of the component Feedback Handler. The manipu... Read more
Affected Products : online_bank_management_system- Published: Sep. 08, 2024
- Modified: Sep. 10, 2024
-
5.4
MEDIUMCVE-2023-5903
Cross-site Scripting (XSS) - Stored in GitHub repository pkp/pkp-lib prior to 3.3.0-16.... Read more
Affected Products : pkp_web_application_library- EPSS Score: %0.32
- Published: Nov. 07, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-5904
Cross-site Scripting (XSS) - Stored in GitHub repository pkp/pkp-lib prior to 3.3.0-16.... Read more
Affected Products : pkp_web_application_library- EPSS Score: %0.32
- Published: Nov. 07, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2024-34804
Missing Authorization vulnerability in Tagembed.This issue affects Tagembed: from n/a through 5.8.... Read more
Affected Products :- Published: Jun. 11, 2024
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-5942
The Medialist WordPress plugin before 1.4.1 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Store... Read more
Affected Products : medialist- EPSS Score: %0.12
- Published: Nov. 27, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2024-6368
A vulnerability was found in LabVantage LIMS 2017. It has been rated as problematic. This issue affects some unknown processing of the file /labvantage/rc?command=page of the component POST Request Handler. The manipulation of the argument param1 leads to... Read more
- Published: Jun. 27, 2024
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-33408
Minical 1.0.0 is vulnerable to Cross Site Scripting (XSS). The vulnerability exists due to insufficient input validation in the application's user input handling in the security_helper.php file.... Read more
Affected Products : minical- EPSS Score: %0.21
- Published: Jun. 05, 2023
- Modified: Jan. 08, 2025
-
5.4
MEDIUMCVE-2023-33438
A stored Cross-site scripting (XSS) vulnerability in Wolters Kluwer TeamMate+ 35.0.11.0 allows remote attackers to inject arbitrary web script or HTML.... Read more
Affected Products : teammate\+- EPSS Score: %0.05
- Published: Jun. 16, 2023
- Modified: Dec. 12, 2024
-
5.4
MEDIUMCVE-2023-29247
Task instance details page in the UI is vulnerable to a stored XSS.This issue affects Apache Airflow: before 2.6.0. ... Read more
Affected Products : airflow- EPSS Score: %1.54
- Published: May. 08, 2023
- Modified: Nov. 21, 2024