Latest CVE Feed
-
5.4
MEDIUMCVE-2025-1454
The Ninja Pages WordPress plugin through 1.4.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (f... Read more
Affected Products : ninja_pages- Published: May. 15, 2025
- Modified: Jun. 12, 2025
- Vuln Type: Cross-Site Scripting
-
5.4
MEDIUMCVE-2025-1231
Improper password reset in PAM Module in Devolutions Server 2024.3.10.0 and earlier allows an authenticated user to reuse the oracle user password after check-in due to crash in the password reset functionality.... Read more
Affected Products : devolutions_server- Published: Feb. 11, 2025
- Modified: Mar. 28, 2025
- Vuln Type: Authentication
-
5.4
MEDIUMCVE-2025-1142
IBM Edge Application Manager 4.5 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks.... Read more
Affected Products : edge_application_manager- Published: Aug. 20, 2025
- Modified: Sep. 03, 2025
- Vuln Type: Server-Side Request Forgery
-
5.4
MEDIUMCVE-2025-1195
A vulnerability, which was classified as problematic, has been found in code-projects Real Estate Property Management System 1.0. This issue affects some unknown processing of the file /Admin/EditCategory. The manipulation of the argument CategoryId leads... Read more
- Published: Feb. 12, 2025
- Modified: Feb. 20, 2025
- Vuln Type: Cross-Site Scripting
-
5.4
MEDIUMCVE-2025-1015
The Thunderbird Address Book URI fields contained unsanitized links. This could be used by an attacker to create and export an address book containing a malicious payload in a field. For example, in the “Other” field of the Instant Messaging section. If a... Read more
Affected Products : thunderbird- Published: Feb. 04, 2025
- Modified: Mar. 10, 2025
- Vuln Type: Cross-Site Scripting
-
5.4
MEDIUMCVE-2025-0513
In affected versions of Octopus Server error messages were handled unsafely on the error page. If an adversary could control any part of the error message they could embed code which may impact the user viewing the error message.... Read more
- Published: Feb. 11, 2025
- Modified: Jul. 02, 2025
- Vuln Type: Cross-Site Scripting
-
5.4
MEDIUMCVE-2025-0445
Use after free in V8 in Google Chrome prior to 133.0.6943.53 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)... Read more
- Published: Feb. 04, 2025
- Modified: Apr. 08, 2025
- Vuln Type: Memory Corruption
-
5.4
MEDIUMCVE-2025-0237
The WebChannel API, which is used to transport various information across processes, did not check the sending principal but rather accepted the principal being sent. This could have led to privilege escalation attacks. This vulnerability affects Firefox ... Read more
- Published: Jan. 07, 2025
- Modified: Apr. 03, 2025
- Vuln Type: Authorization
-
5.4
MEDIUMCVE-2024-9969
NewType WebEIP v3.0 does not properly validate user input, allowing a remote attacker with regular privileges to insert JavaScript into specific parameters, resulting in a Reflected Cross-site Scripting (XSS) attack. The affected product is no longer main... Read more
Affected Products : webeip- Published: Oct. 15, 2024
- Modified: Oct. 19, 2024
-
5.4
MEDIUMCVE-2024-9879
The Melapress File Monitor WordPress plugin before 2.1.1 does not sanitize and escape a parameter before using it in a SQL statement, allowing admins to perform SQL injection attacks... Read more
Affected Products : melapress_file_monitor- Published: May. 15, 2025
- Modified: Jun. 12, 2025
- Vuln Type: Injection
-
5.4
MEDIUMCVE-2024-9906
A vulnerability, which was classified as problematic, was found in SourceCodester Online Eyewear Shop 1.0. Affected is an unknown function of the file /admin/?page=inventory/view_inventory&id=2. The manipulation of the argument Code leads to cross site sc... Read more
Affected Products : online_eyewear_shop- Published: Oct. 13, 2024
- Modified: Oct. 16, 2024
-
5.4
MEDIUMCVE-2024-41447
A stored cross-site scripting (XSS) vulnerability in Alkacon OpenCMS v17.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the author parameter under the Create/Modify article function.... Read more
Affected Products : opencms- Published: Apr. 18, 2025
- Modified: Apr. 23, 2025
-
5.4
MEDIUMCVE-2024-9868
The Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Age Gate Widget 'url' parameter in all versions up to, and including, 5.1... Read more
Affected Products : element_pack- Published: Nov. 02, 2024
- Modified: Nov. 04, 2024
-
5.4
MEDIUMCVE-2024-9805
A vulnerability was found in code-projects Blood Bank System 1.0. It has been rated as problematic. This issue affects some unknown processing of the file /admin/campsdetails.php. The manipulation of the argument hospital/address/city/contact leads to cro... Read more
- Published: Oct. 10, 2024
- Modified: Oct. 15, 2024
-
5.4
MEDIUMCVE-2024-9662
The CYAN Backup WordPress plugin before 2.5.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (fo... Read more
Affected Products : cyan_backup- Published: May. 15, 2025
- Modified: Jun. 12, 2025
- Vuln Type: Cross-Site Scripting
-
5.4
MEDIUMCVE-2024-9599
The Popup Box WordPress plugin before 4.7.8 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for... Read more
- Published: May. 15, 2025
- Modified: Jun. 04, 2025
- Vuln Type: Cross-Site Scripting
-
5.4
MEDIUMCVE-2024-9629
The Contact Form 7 + Telegram plugin for WordPress is vulnerable to unauthorized modification of data and loss of data due to a missing capability check on the 'wpcf7_Telegram::ajax' function in versions up to, and including, 0.8.5. This makes it possible... Read more
Affected Products :- Published: Oct. 28, 2024
- Modified: Oct. 29, 2024
-
5.4
MEDIUMCVE-2024-9709
The EKC Tournament Manager WordPress plugin before 2.2.2 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack... Read more
Affected Products : ekc_tournament_manager- Published: May. 15, 2025
- Modified: May. 28, 2025
- Vuln Type: Cross-Site Request Forgery
-
5.4
MEDIUMCVE-2024-9663
The CYAN Backup WordPress plugin before 2.5.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (fo... Read more
Affected Products : cyan_backup- Published: May. 15, 2025
- Modified: Jun. 12, 2025
- Vuln Type: Cross-Site Scripting
-
5.4
MEDIUMCVE-2024-9588
The Category and Taxonomy Meta Fields plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.0.0. This is due to missing or incorrect nonce validation on the 'wpaft_option_page' function. This makes it possibl... Read more
Affected Products : category_and_taxonomy_meta_fields- Published: Oct. 22, 2024
- Modified: Oct. 25, 2024