Latest CVE Feed
-
4.3
MEDIUMCVE-2012-2586
Multiple cross-site scripting (XSS) vulnerabilities in Mailtraq 2.17.3.3150 allow remote attackers to inject arbitrary web script or HTML via an e-mail message subject with (1) a JavaScript alert function used in conjunction with the fromCharCode method o... Read more
Affected Products : mailtraq- Published: Sep. 19, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2008-6629
Cross-site scripting (XSS) vulnerability in detail.php in WEBBDOMAIN Multi Languages WebShop Online 1.02 allows remote attackers to inject arbitrary web script or HTML via the name parameter.... Read more
Affected Products : webshop_online- Published: Apr. 06, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2024-1339
The ImageRecycle pdf & image compression plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.1.13. This is due to missing or incorrect nonce validation on the reinitialize function. This makes it possib... Read more
Affected Products : imagerecycle_pdf_\&_image_compression- Published: Feb. 29, 2024
- Modified: Dec. 31, 2024
-
4.3
MEDIUMCVE-2024-38485
Dell ECS, versions prior to 3.8.0, contain(s) a Host Header Injection Vulnerability. A remote low-privileged attacker could potentially exploit this vulnerability to trigger redirections that leads to sensitive information leakage.... Read more
Affected Products : elastic_cloud_storage- Published: Dec. 09, 2024
- Modified: Feb. 04, 2025
-
4.3
MEDIUMCVE-2023-50871
In JetBrains YouTrack before 2023.3.22268 authorization check for inline comments inside thread replies was missed... Read more
Affected Products : youtrack- Published: Dec. 15, 2023
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2024-0379
The Custom Twitter Feeds – A Tweets Widget or X Feed Widget plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.2.1. This is due to missing or incorrect nonce validation on the ctf_auto_save_tokens func... Read more
Affected Products : custom_twitter_feeds- Published: Feb. 29, 2024
- Modified: Feb. 05, 2025
-
4.3
MEDIUMCVE-2012-2575
Cross-site scripting (XSS) vulnerability in NetWin SurgeMail 6.0a4 allows remote attackers to inject arbitrary web script or HTML via the SRC attribute of an IFRAME element in the body of an HTML e-mail message.... Read more
Affected Products : surgemail- Published: Sep. 17, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2024-0983
The ImageRecycle pdf & image compression plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the enableOptimization function in all versions up to, and including, 3.1.13. This makes it possible for ... Read more
Affected Products : imagerecycle_pdf_\&_image_compression- Published: Feb. 29, 2024
- Modified: Dec. 27, 2024
-
4.3
MEDIUMCVE-2012-2563
Multiple cross-site scripting (XSS) vulnerabilities in Bloxx Web Filtering before 5.0.14 allow (1) remote attackers to inject arbitrary web script or HTML via web traffic that is examined within the Bloxx Reports component, and allow (2) remote authentica... Read more
Affected Products : web_filtering- Published: Jun. 09, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2024-3072
The ACF Front End Editor plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the update_texts() function in all versions up to, and including, 2.0.2. This makes it possible for authenticated attacke... Read more
Affected Products :- Published: Apr. 30, 2024
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2023-2785
Mattermost fails to properly truncate the postgres error log message of a search query failure allowing an attacker to cause the creation of large log files which can result in Denial of Service ... Read more
- Published: Jun. 16, 2023
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2023-35800
Stormshield Endpoint Security Evolution 2.0.0 through 2.4.2 has Insecure Permissions. An ACL entry on the SES Evolution agent directory that contains the agent logs displayed in the GUI allows interactive users to read data, which could allow access to in... Read more
Affected Products : endpoint_security- Published: Jun. 27, 2023
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2021-22138
In Logstash versions after 6.4.0 and before 6.8.15 and 7.12.0 a TLS certificate validation flaw was found in the monitoring feature. When specifying a trusted server CA certificate Logstash would not properly verify the certificate returned by the monitor... Read more
- Published: May. 13, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2023-44110
Out-of-bounds access vulnerability in the audio module.Successful exploitation of this vulnerability may affect availability.... Read more
- Published: Oct. 11, 2023
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2024-5639
The User Profile Picture plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.6.1 via the 'rest_api_change_profile_image' function due to missing validation on a user controlled key. This makes it ... Read more
Affected Products : user_profile_picture- Published: Jun. 21, 2024
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2006-1204
Multiple cross-site scripting (XSS) vulnerabilities in txtForum 1.0.4-dev and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) prev, (2) next, and (3) rand5 parameters in (a) index.php; the (4) r_username and (5) r_loc par... Read more
Affected Products : txtforum- Published: Mar. 14, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2024-3410
The DN Footer Contacts WordPress plugin before 1.6.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallo... Read more
Affected Products : footer_contacts_bar- Published: Jul. 09, 2024
- Modified: May. 21, 2025
-
4.3
MEDIUMCVE-2024-37095
Missing Authorization vulnerability in Envira Gallery Team Envira Photo Gallery allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Envira Photo Gallery: from n/a through 1.8.7.3.... Read more
Affected Products :- Published: Nov. 01, 2024
- Modified: Nov. 01, 2024
-
4.3
MEDIUMCVE-2023-37856
In PHOENIX CONTACTs WP 6xxx series web panels in versions prior to 4.0.10 a remote attacker with low privileges is able to gain limited read-access to the device-filesystem through a configuration dialog within the embedded Qt browser . ... Read more
Affected Products : wp_6070-wvps_firmware wp_6101-wxps_firmware wp_6121-wxps_firmware wp_6156-whps_firmware wp_6185-whps_firmware wp_6215-whps_firmware wp_6070-wvps wp_6101-wxps wp_6121-wxps wp_6156-whps +2 more products- Published: Aug. 09, 2023
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2009-1458
Multiple cross-site scripting (XSS) vulnerabilities in admin/index.php in razorCMS before 0.4 allow remote attackers to inject arbitrary web script or HTML via (1) the slab parameter in an edit action, (2) the catname parameter in a showcats action, and (... Read more
Affected Products : razorcms- Published: Apr. 28, 2009
- Modified: Apr. 09, 2025