Latest CVE Feed
-
5.4
MEDIUMCVE-2023-6326
The Master Slider – Responsive Touch Slider plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.9.3. This is due to missing or incorrect nonce validation on the 'process_bulk_action' function. This make... Read more
Affected Products : master_slider- Published: Mar. 02, 2024
- Modified: Jan. 07, 2025
-
5.4
MEDIUMCVE-2023-6473
A vulnerability, which was classified as problematic, was found in SourceCodester Online Quiz System 1.0. This affects an unknown part of the file take-quiz.php. The manipulation of the argument quiz_taker/year_section leads to cross site scripting. It is... Read more
Affected Products : online_quiz_system- Published: Dec. 02, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2014-4896
The Parque Imperial (aka com.a792139893520606f84b2188a.a23428594a) application 1.02 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted c... Read more
Affected Products : parque_imperial- Published: Oct. 21, 2014
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2024-37343
There is a cross-site scripting vulnerability in the Secure Access administrative console of Absolute Secure Access prior to version 13.06. Attackers with valid tunnel credentials can pass a limited-length script to the administrative console which is the... Read more
Affected Products : secure_access- Published: Jun. 20, 2024
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2024-37389
Apache NiFi 1.10.0 through 1.26.0 and 2.0.0-M1 through 2.0.0-M3 support a description field in the Parameter Context configuration that is vulnerable to cross-site scripting. An authenticated user, authorized to configure a Parameter Context, can enter ar... Read more
Affected Products : nifi- Published: Jul. 08, 2024
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2024-37844
A stored cross-site scripting (XSS) vulnerability in MangoOS before 5.2.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.... Read more
Affected Products : mango- Published: Oct. 25, 2024
- Modified: Nov. 05, 2024
-
5.4
MEDIUMCVE-2023-7083
The Voting Record WordPress plugin through 2.0 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack... Read more
Affected Products : voting_record- Published: Jan. 16, 2024
- Modified: Jun. 02, 2025
-
5.4
MEDIUMCVE-2021-24834
The YOP Poll WordPress plugin before 6.3.1 is affected by a stored Cross-Site Scripting vulnerability which exists in the Create Poll - Options module where a user with a role as low as author is allowed to execute arbitrary script code within the context... Read more
Affected Products : yop_poll- Published: Nov. 17, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2024-12536
A vulnerability, which was classified as problematic, has been found in SourceCodester Kortex Lite Advocate Office Management System 1.0. Affected by this issue is some unknown functionality of the file /control/client_data.php. The manipulation of the ar... Read more
Affected Products : advocate_office_management_system- Published: Dec. 12, 2024
- Modified: Dec. 13, 2024
-
5.4
MEDIUMCVE-2020-28961
Perfex CRM v2.4.4 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the component ./clients/client via the company name parameter.... Read more
Affected Products : perfex_crm- Published: Oct. 22, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2024-0895
The PDF Flipbook, 3D Flipbook – DearFlip plugin for WordPress is vulnerable to Stored Cross-Site Scripting via outline settings in all versions up to, and including, 2.2.26 due to insufficient input sanitization and output escaping on user supplied data. ... Read more
Affected Products : pdf_flipbook\,_3d_flipbook- Published: Feb. 03, 2024
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2024-3426
A vulnerability, which was classified as problematic, has been found in SourceCodester Online Courseware 1.0. Affected by this issue is some unknown functionality of the file editt.php. The manipulation of the argument id leads to cross site scripting. Th... Read more
Affected Products : online_courseware- Published: Apr. 07, 2024
- Modified: Jan. 17, 2025
-
5.4
MEDIUMCVE-2024-40690
IBM InfoSphere Server 11.7 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure withi... Read more
Affected Products : infosphere_information_server- Published: Jul. 12, 2024
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2024-11675
A vulnerability has been found in CodeAstro Hospital Management System 1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /backend/admin/his_admin_register_patient.php of the component Add Patient Det... Read more
- Published: Nov. 26, 2024
- Modified: Dec. 04, 2024
-
5.4
MEDIUMCVE-2014-6972
The Kazakhstan Radio (aka com.wordbox.kazakhstanRadio) application 2.5 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.... Read more
Affected Products : kazakhstan_radio- Published: Oct. 16, 2014
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2024-11841
The Tithe.ly Giving Button WordPress plugin through 1.1 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to p... Read more
Affected Products : tithe.ly_giving_button- Published: Dec. 16, 2024
- Modified: May. 17, 2025
-
5.4
MEDIUMCVE-2022-38256
TastyIgniter v3.5.0 was discovered to contain a cross-site scripting (XSS) vulnerability which allows attackers to execute arbitrary web scripts or HTML via a crafted payload.... Read more
Affected Products : tastyigniter- Published: Sep. 08, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2024-4410
The IgnitionDeck Crowdfunding Platform plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 1.9.8. This is due to missing capability checks on various functions called via AJAX actions in the ~/classes/class-idf-wi... Read more
Affected Products :- Published: Jul. 27, 2024
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2024-1333
The Responsive Pricing Table WordPress plugin before 5.1.11 does not validate and escape some of its Pricing Table options before outputting them back in a page/post where the related shortcode is embed, which could allow users with the author role and ab... Read more
Affected Products : responsive_pricing_table- Published: Mar. 18, 2024
- Modified: May. 05, 2025
-
5.4
MEDIUMCVE-2024-23191
Upsell advertisement information of an account can be manipulated to execute script code in the context of the users browser session. To exploit this an attacker would require temporary access to a users account or an successful social engineering attack ... Read more
- Published: Apr. 08, 2024
- Modified: Nov. 21, 2024