Latest CVE Feed
-
5.4
MEDIUMCVE-2024-3288
The Logo Slider WordPress plugin before 4.0.0 does not validate and escape some of its Slider Settings before outputting them back in attributes, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks... Read more
- Published: Jun. 07, 2024
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2024-54936
A Stored Cross-Site Scripting (XSS) vulnerability was found in /send_message.php of Kashipara E-learning Management System v1.0. This vulnerability allows remote attackers to execute arbitrary scripts via the my_message parameter.... Read more
Affected Products : e-learning_management_system- Published: Dec. 09, 2024
- Modified: Dec. 10, 2024
-
5.4
MEDIUMCVE-2014-5963
The Halieutics (aka com.corn.Halieutics) application 21.40.5 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.... Read more
Affected Products : halieutics- Published: Sep. 19, 2014
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2024-13077
A vulnerability, which was classified as problematic, was found in PHPGurukul Land Record System 1.0. Affected is an unknown function of the file /admin/add-property.php. The manipulation of the argument Land Subtype leads to cross site scripting. It is p... Read more
Affected Products : land_record_system- Published: Dec. 31, 2024
- Modified: Jan. 06, 2025
-
5.4
MEDIUMCVE-2024-33636
Missing Authorization vulnerability in Mahesh Vora WP Page Post Widget Clone.This issue affects WP Page Post Widget Clone: from n/a through 1.0.1. ... Read more
Affected Products :- Published: Apr. 29, 2024
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2024-31649
A cross-site scripting (XSS) in Cosmetics and Beauty Product Online Store v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Product Name parameter.... Read more
Affected Products : cosmetics_and_beauty_product_online_store cosmetics_and_beauty_product_online_store- Published: Apr. 15, 2024
- Modified: Apr. 10, 2025
-
5.4
MEDIUMCVE-2024-29865
Logpoint before 7.1.0 allows Self-XSS on the LDAP authentication page via the username to the LDAP login form.... Read more
Affected Products : siem- Published: Mar. 22, 2024
- Modified: Apr. 16, 2025
-
5.4
MEDIUMCVE-2024-31213
InstantCMS is a free and open source content management system. An open redirect was found in the ICMS2 application version 2.16.2 when being redirected after modifying one's own user profile. An attacker could trick a victim into visiting their web appli... Read more
Affected Products : instantcms- Published: Apr. 05, 2024
- Modified: Jan. 17, 2025
-
5.4
MEDIUMCVE-2023-28418
Auth. (subscriber+) Reflected Cross-Site Scripting (XSS) vulnerability in Yudlee themes Mediciti Lite theme <= 1.3.0 versions.... Read more
Affected Products : mediciti_lite- Published: Jun. 22, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2024-37345
There is a cross-site scripting vulnerability in the Secure Access administrative UI of Absolute Secure Access prior to version 13.06. Attackers can pass a limited-length script to the administrative UI which is then stored where an administrator can acce... Read more
Affected Products : secure_access- Published: Jun. 20, 2024
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2024-7200
A vulnerability, which was classified as problematic, has been found in SourceCodester Complaints Report Management System 1.0. This issue affects some unknown processing of the file /admin/ajax.php?action=save_settings. The manipulation of the argument n... Read more
Affected Products : complaints_report_management_system- Published: Jul. 29, 2024
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2024-7285
A vulnerability has been found in SourceCodester Establishment Billing Management System 1.0 and classified as problematic. This vulnerability affects unknown code of the file /admin/ajax.php?action=save_settings. The manipulation of the argument name lea... Read more
Affected Products : establishment_billing_management_system- Published: Jul. 31, 2024
- Modified: Aug. 12, 2024
-
5.4
MEDIUMCVE-2024-7916
A vulnerability classified as problematic was found in nafisulbari/itsourcecode Insurance Management System 1.0. Affected by this vulnerability is an unknown functionality of the file addNominee.php of the component Add Nominee Page. The manipulation of t... Read more
- Published: Aug. 18, 2024
- Modified: Apr. 22, 2025
-
5.4
MEDIUMCVE-2024-8092
The Accordion Image Menu WordPress plugin through 3.1.3 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack.... Read more
Affected Products : accordion_image_menu- Published: Sep. 17, 2024
- Modified: Sep. 27, 2024
-
5.4
MEDIUMCVE-2024-8142
A vulnerability was found in SourceCodester Daily Calories Monitoring Tool 1.0. It has been declared as problematic. This vulnerability affects unknown code of the file /endpoint/delete-calorie.php. The manipulation of the argument calorie leads to cross ... Read more
Affected Products : daily_calories_monitoring_tool- Published: Aug. 25, 2024
- Modified: Aug. 26, 2024
-
5.4
MEDIUMCVE-2023-3311
A vulnerability, which was classified as problematic, was found in PuneethReddyHC online-shopping-system-advanced 1.0. This affects an unknown part of the file addsuppliers.php. The manipulation of the argument First name leads to cross site scripting. It... Read more
Affected Products : online-shopping-system-advanced- Published: Jun. 18, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2024-34815
Missing Authorization vulnerability in Codection Import and export users and customers.This issue affects Import and export users and customers: from n/a through 1.26.5.... Read more
Affected Products : import_and_export_users_and_customers- Published: Jun. 11, 2024
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-33185
Django-SES is a drop-in mail backend for Django. The django_ses library implements a mail backend for Django using AWS Simple Email Service. The library exports the `SESEventWebhookView class` intended to receive signed requests from AWS to handle email b... Read more
Affected Products : django-ses- Published: May. 26, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-3183
A vulnerability was found in SourceCodester Performance Indicator System 1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /admin/addproduct.php. The manipulation of the argument prodname lead... Read more
Affected Products : performance_indicator_system- Published: Jun. 09, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2024-8783
A vulnerability classified as problematic has been found in OpenTibiaBR MyAAC up to 0.8.16. Affected is an unknown function of the file system/pages/forum/new_post.php of the component Post Reply Handler. The manipulation of the argument post_topic leads ... Read more
Affected Products : myaac- Published: Sep. 13, 2024
- Modified: Sep. 19, 2024