Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 5.4

    MEDIUM
    CVE-2024-33636

    Missing Authorization vulnerability in Mahesh Vora WP Page Post Widget Clone.This issue affects WP Page Post Widget Clone: from n/a through 1.0.1. ... Read more

    Affected Products :
    • Published: Apr. 29, 2024
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2024-31649

    A cross-site scripting (XSS) in Cosmetics and Beauty Product Online Store v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Product Name parameter.... Read more

    • Published: Apr. 15, 2024
    • Modified: Apr. 10, 2025
  • 5.4

    MEDIUM
    CVE-2024-29865

    Logpoint before 7.1.0 allows Self-XSS on the LDAP authentication page via the username to the LDAP login form.... Read more

    Affected Products : siem
    • Published: Mar. 22, 2024
    • Modified: Apr. 16, 2025
  • 5.4

    MEDIUM
    CVE-2024-31213

    InstantCMS is a free and open source content management system. An open redirect was found in the ICMS2 application version 2.16.2 when being redirected after modifying one's own user profile. An attacker could trick a victim into visiting their web appli... Read more

    Affected Products : instantcms
    • Published: Apr. 05, 2024
    • Modified: Jan. 17, 2025
  • 5.4

    MEDIUM
    CVE-2023-28418

    Auth. (subscriber+) Reflected Cross-Site Scripting (XSS) vulnerability in Yudlee themes Mediciti Lite theme <= 1.3.0 versions.... Read more

    Affected Products : mediciti_lite
    • Published: Jun. 22, 2023
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2024-37345

    There is a cross-site scripting vulnerability in the Secure Access administrative UI of Absolute Secure Access prior to version 13.06. Attackers can pass a limited-length script to the administrative UI which is then stored where an administrator can acce... Read more

    Affected Products : secure_access
    • Published: Jun. 20, 2024
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2024-7200

    A vulnerability, which was classified as problematic, has been found in SourceCodester Complaints Report Management System 1.0. This issue affects some unknown processing of the file /admin/ajax.php?action=save_settings. The manipulation of the argument n... Read more

    • Published: Jul. 29, 2024
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2024-7285

    A vulnerability has been found in SourceCodester Establishment Billing Management System 1.0 and classified as problematic. This vulnerability affects unknown code of the file /admin/ajax.php?action=save_settings. The manipulation of the argument name lea... Read more

    • Published: Jul. 31, 2024
    • Modified: Aug. 12, 2024
  • 5.4

    MEDIUM
    CVE-2024-7916

    A vulnerability classified as problematic was found in nafisulbari/itsourcecode Insurance Management System 1.0. Affected by this vulnerability is an unknown functionality of the file addNominee.php of the component Add Nominee Page. The manipulation of t... Read more

    • Published: Aug. 18, 2024
    • Modified: Apr. 22, 2025
  • 5.4

    MEDIUM
    CVE-2024-8092

    The Accordion Image Menu WordPress plugin through 3.1.3 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack.... Read more

    Affected Products : accordion_image_menu
    • Published: Sep. 17, 2024
    • Modified: Sep. 27, 2024
  • 5.4

    MEDIUM
    CVE-2024-8142

    A vulnerability was found in SourceCodester Daily Calories Monitoring Tool 1.0. It has been declared as problematic. This vulnerability affects unknown code of the file /endpoint/delete-calorie.php. The manipulation of the argument calorie leads to cross ... Read more

    Affected Products : daily_calories_monitoring_tool
    • Published: Aug. 25, 2024
    • Modified: Aug. 26, 2024
  • 5.4

    MEDIUM
    CVE-2023-3311

    A vulnerability, which was classified as problematic, was found in PuneethReddyHC online-shopping-system-advanced 1.0. This affects an unknown part of the file addsuppliers.php. The manipulation of the argument First name leads to cross site scripting. It... Read more

    Affected Products : online-shopping-system-advanced
    • Published: Jun. 18, 2023
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2024-34815

    Missing Authorization vulnerability in Codection Import and export users and customers.This issue affects Import and export users and customers: from n/a through 1.26.5.... Read more

    • Published: Jun. 11, 2024
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2023-33185

    Django-SES is a drop-in mail backend for Django. The django_ses library implements a mail backend for Django using AWS Simple Email Service. The library exports the `SESEventWebhookView class` intended to receive signed requests from AWS to handle email b... Read more

    Affected Products : django-ses
    • Published: May. 26, 2023
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2023-3183

    A vulnerability was found in SourceCodester Performance Indicator System 1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /admin/addproduct.php. The manipulation of the argument prodname lead... Read more

    Affected Products : performance_indicator_system
    • Published: Jun. 09, 2023
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2024-8783

    A vulnerability classified as problematic has been found in OpenTibiaBR MyAAC up to 0.8.16. Affected is an unknown function of the file system/pages/forum/new_post.php of the component Post Reply Handler. The manipulation of the argument post_topic leads ... Read more

    Affected Products : myaac
    • Published: Sep. 13, 2024
    • Modified: Sep. 19, 2024
  • 5.4

    MEDIUM
    CVE-2024-35657

    Cross-Site Request Forgery (CSRF) vulnerability in Plechev Andrey WP-Recall.This issue affects WP-Recall: from n/a through 16.26.6.... Read more

    Affected Products :
    • Published: Jun. 08, 2024
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2024-54951

    Monica 4.1.2 is vulnerable to Cross Site Scripting (XSS). A malicious user can create a malformed contact and use that contact in the "HOW YOU MET" customization options to trigger the XSS.... Read more

    Affected Products : monica
    • Published: Feb. 13, 2025
    • Modified: Aug. 14, 2025
    • Vuln Type: Cross-Site Scripting
  • 5.4

    MEDIUM
    CVE-2024-6754

    The Social Auto Poster plugin for WordPress is vulnerable to unauthorized modification of data to a missing capability check on the ‘wpw_auto_poster_update_tweet_template’ function in all versions up to, and including, 5.3.14. This makes it possible for a... Read more

    Affected Products : social_auto_poster
    • Published: Jul. 24, 2024
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2024-6942

    A vulnerability, which was classified as problematic, was found in ThinkSAAS 3.7.0. Affected is an unknown function of the file app/system/action/anti.php of the component Admin Panel Security Center. The manipulation of the argument ip/email/phone leads ... Read more

    Affected Products : thinksaas
    • Published: Jul. 21, 2024
    • Modified: Nov. 21, 2024
Showing 20 of 293509 Results