Latest CVE Feed
-
5.4
MEDIUMCVE-2024-13541
The aDirectory – WordPress Directory Listing Plugin plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the adqs_delete_listing() function in all versions up to, and including, 2.3. This makes it possible f... Read more
Affected Products : adirectory- Published: Feb. 12, 2025
- Modified: Feb. 25, 2025
- Vuln Type: Authorization
-
5.4
MEDIUMCVE-2022-21398
Vulnerability in the Oracle Communications Operations Monitor product of Oracle Communications (component: Mediation Engine). Supported versions that are affected are 3.4, 4.2, 4.3, 4.4 and 5.0. Easily exploitable vulnerability allows low privileged attac... Read more
Affected Products : communications_operations_monitor- Published: Jan. 19, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2024-24397
Cross Site Scripting vulnerability in Stimulsoft GmbH Stimulsoft Dashboard.JS before v.2024.1.2 allows a remote attacker to execute arbitrary code via a crafted payload to the ReportName field.... Read more
Affected Products : dashboards.js- Published: Feb. 05, 2024
- Modified: May. 15, 2025
-
5.4
MEDIUMCVE-2024-1775
The Nextend Social Login and Register plugin for WordPress is vulnerable to a self-based Reflected Cross-Site Scripting via the ‘error_description’ parameter in all versions up to, and including, 3.1.12 due to insufficient input sanitization and output es... Read more
Affected Products : nextend_social_login- Published: Mar. 02, 2024
- Modified: Jan. 16, 2025
-
5.4
MEDIUMCVE-2024-24705
Cross-Site Request Forgery (CSRF) vulnerability in Octa Code Accessibility.This issue affects Accessibility: from n/a through 1.0.6. ... Read more
Affected Products : accessibility- Published: Feb. 28, 2024
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2014-7330
The XtendCU Mobile (aka com.metova.cuae.xtend) application 1.0.28 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.... Read more
Affected Products : xtendcu_mobile- Published: Oct. 19, 2014
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2022-39207
Onedev is an open source, self-hosted Git Server with CI/CD and Kanban. During CI/CD builds, it is possible to save build artifacts for later retrieval. They can be accessed through OneDev's web UI after the successful run of a build. These artifact files... Read more
Affected Products : onedev- Published: Sep. 13, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2014-5535
The Baby Get Up - Kids Care (aka air.brown.jordansa.getup) application 1.0.3 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certific... Read more
Affected Products : baby_get_up_-_kids_care- Published: Sep. 09, 2014
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2014-5551
The Alphabet & Spelling Kids Games (aka air.com.tribalnova.ilearnwith.ipad.App1En) application 1.4.2 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive informatio... Read more
Affected Products : alphabet_\&_spelling_kids_games- Published: Sep. 09, 2014
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2021-25935
In OpenNMS Horizon, versions opennms-17.0.0-1 through opennms-27.1.0-1; OpenNMS Meridian, versions meridian-foundation-2015.1.0-1 through meridian-foundation-2019.1.18-1; meridian-foundation-2020.1.0-1 through meridian-foundation-2020.1.7-1 are vulnerable... Read more
- Published: May. 25, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2024-21734
SAP Marketing (Contacts App) - version 160, allows an attacker with low privileges to trick a user to open malicious page which could lead to a very convincing phishing attack with low impact on confidentiality and integrity of the application. ... Read more
Affected Products : marketing- Published: Jan. 09, 2024
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-22116
In Directus, versions 9.0.0-alpha.4 through 9.4.1 are vulnerable to stored Cross-Site Scripting (XSS) vulnerability via SVG file upload in media upload functionality. A low privileged attacker can inject arbitrary javascript code which will be executed in... Read more
- Published: Jan. 10, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2024-22494
A stored XSS vulnerability exists in JFinalcms 5.0.0 via the /gusetbook/save mobile parameter, which allows remote attackers to inject arbitrary web script or HTML.... Read more
Affected Products : jfinalcms- Published: Jan. 12, 2024
- Modified: Jun. 03, 2025
-
5.4
MEDIUMCVE-2024-2252
The Droit Elementor Addons – Widgets, Blocks, Templates Library For Elementor Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's widgets in all versions up to, and including, 3.1.5 due to insufficient input sanitiza... Read more
Affected Products : droit_elementor_addons- Published: Mar. 13, 2024
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2024-22559
LightCMS v2.0 is vulnerable to Cross Site Scripting (XSS) in the Content Management - Articles field.... Read more
Affected Products : lightcms- Published: Jan. 29, 2024
- Modified: May. 29, 2025
-
5.4
MEDIUMCVE-2024-4645
A vulnerability was found in SourceCodester Prison Management System 1.0 and classified as problematic. This issue affects some unknown processing of the file /Admin/changepassword.php. The manipulation of the argument txtold_password/txtnew_password/txtc... Read more
- Published: May. 08, 2024
- Modified: Feb. 10, 2025
-
5.4
MEDIUMCVE-2014-5588
The Free eBooks (aka com.bmfapps.freekindlebooks) application 14 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.... Read more
Affected Products : free_ebooks- Published: Sep. 09, 2014
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2022-4005
The Donation Button WordPress plugin through 4.0.0 does not sanitize and escapes some parameters, which could allow users with a role as low as Contributor to perform Cross-Site Scripting attacks.... Read more
Affected Products : donation_button- Published: Dec. 12, 2022
- Modified: Apr. 22, 2025
-
5.4
MEDIUMCVE-2022-40002
Cross Site Scripting (XSS) vulnerability in FeehiCMS-2.1.1 allows remote attackers to run arbirtary code via the callback parameter to /cms/notify.... Read more
Affected Products : feehicms- Published: Dec. 15, 2022
- Modified: Apr. 21, 2025
-
5.4
MEDIUMCVE-2014-5607
The Where's My Water? Free (aka com.disney.WMWLite) application 1.9.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.... Read more
Affected Products : where\'s_my_water\?_free- Published: Sep. 09, 2014
- Modified: Apr. 12, 2025