Latest CVE Feed
-
4.3
MEDIUMCVE-2024-40598
An issue was discovered in the CheckUser extension for MediaWiki through 1.42.1. The API can expose suppressed information for log events. (The log_deleted attribute is not applied to entries.)... Read more
Affected Products : mediawiki- Published: Jul. 07, 2024
- Modified: Mar. 25, 2025
-
4.3
MEDIUMCVE-2025-39376
Missing Authorization vulnerability in QuanticaLabs Car Park Booking System for WordPress.This issue affects Car Park Booking System for WordPress: from n/a through 2.6.... Read more
Affected Products :- Published: May. 19, 2025
- Modified: May. 21, 2025
- Vuln Type: Authorization
-
4.3
MEDIUMCVE-2022-4385
The Intuitive Custom Post Order WordPress plugin before 3.1.4 does not check for authorization in the update-menu-order ajax action, allowing any logged in user (with roles as low as Subscriber) to update the menu order... Read more
Affected Products : intuitive_custom_post_order- Published: Feb. 21, 2023
- Modified: Mar. 12, 2025
-
4.3
MEDIUMCVE-2014-8293
Cross-site scripting (XSS) vulnerability in Voice Of Web AllMyGuests 0.4.1 allows remote attackers to inject arbitrary web script or HTML via the AMG_signin_topic parameter to index.php.... Read more
Affected Products : voice_of_web_allmyguests- Published: Oct. 15, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2024-47168
Gradio is an open-source Python package designed for quick prototyping. This vulnerability involves data exposure due to the enable_monitoring flag not properly disabling monitoring when set to False. Even when monitoring is supposedly disabled, an attack... Read more
Affected Products : gradio- Published: Oct. 10, 2024
- Modified: Oct. 17, 2024
-
4.3
MEDIUMCVE-2011-5042
Cross-site scripting (XSS) vulnerability in inc/lib/lib.base.php in SASHA 0.2.0 allows remote attackers to inject arbitrary web script or HTML via the instructors parameter. NOTE: the original disclosure also mentions the section_title parameter, but thi... Read more
Affected Products : sasha- Published: Dec. 30, 2011
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2011-5048
Multiple cross-site scripting (XSS) vulnerabilities in IBM Web Experience Factory (aka WEF, formerly WebSphere Portlet Factory) 7.0 and 7.0.1 allow remote attackers to inject arbitrary web script or HTML via a (1) text INPUT element or (2) TEXTAREA elemen... Read more
Affected Products : web_experience_factory- Published: Jan. 03, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2007-6465
Multiple cross-site scripting (XSS) vulnerabilities in ganglia-web in Ganglia before 3.0.6 allow remote attackers to inject arbitrary web script or HTML via the (1) c and (2) h parameters to (a) web/host_gmetrics.php; the (3) G, (4) me, (5) x, (6) n, (7) ... Read more
Affected Products : ganglia- Published: Dec. 20, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2023-37950
A missing permission check in Jenkins mabl Plugin 0.0.46 and earlier allows attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.... Read more
Affected Products : mabl- Published: Jul. 12, 2023
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2024-12114
The FooGallery – Responsive Photo Gallery, Image Viewer, Justified, Masonry & Carousel plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.4.29 via the foogallery_attachment_modal_save AJAX action... Read more
Affected Products : foogallery- Published: Mar. 08, 2025
- Modified: Mar. 12, 2025
- Vuln Type: Authorization
-
4.3
MEDIUMCVE-2024-1339
The ImageRecycle pdf & image compression plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.1.13. This is due to missing or incorrect nonce validation on the reinitialize function. This makes it possib... Read more
Affected Products : imagerecycle_pdf_\&_image_compression- Published: Feb. 29, 2024
- Modified: Dec. 31, 2024
-
4.3
MEDIUMCVE-2007-6463
Multiple cross-site scripting (XSS) vulnerabilities in the admin panel in PHP Real Estate Classifieds allow remote attackers to inject arbitrary web script or HTML via unspecified "text areas/boxes."... Read more
Affected Products : classifieds- Published: Dec. 20, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2025-30529
Cross-Site Request Forgery (CSRF) vulnerability in Sébastien Dumont Auto Load Next Post allows Cross Site Request Forgery. This issue affects Auto Load Next Post: from n/a through 1.5.14.... Read more
Affected Products :- Published: Mar. 24, 2025
- Modified: Mar. 27, 2025
- Vuln Type: Cross-Site Request Forgery
-
4.3
MEDIUMCVE-2007-2308
Cross-site scripting (XSS) vulnerability in cas.php in FloweRS 2.0 allows remote attackers to inject arbitrary web script or HTML via the rok parameter.... Read more
Affected Products : flowers- Published: Apr. 26, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2007-0529
Cross-site scripting (XSS) vulnerability in index.html (aka the administration page) in PHP Link Directory (phpLD) 3.0.6 and earlier allows remote attackers to inject arbitrary web script or HTML via a crafted link, which is triggered when the administrat... Read more
Affected Products : php_link_directory- Published: Jan. 26, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2024-32369
SQL Injection vulnerability in HSC Cybersecurity HC Mailinspector 5.2.17-3 through 5.2.18 allows a remote attacker to obtain sensitive information via a crafted payload to the start and limit parameter in the mliWhiteList.php component.... Read more
Affected Products : mailinspector- Published: May. 07, 2024
- Modified: Jun. 17, 2025
-
4.3
MEDIUMCVE-2024-47581
SAP HCM Approve Timesheets Version 4 application does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges.There is low impact on integrity of the application. Confidentiality and availibility are not... Read more
Affected Products :- Published: Dec. 10, 2024
- Modified: Dec. 10, 2024
-
4.3
MEDIUMCVE-2012-2586
Multiple cross-site scripting (XSS) vulnerabilities in Mailtraq 2.17.3.3150 allow remote attackers to inject arbitrary web script or HTML via an e-mail message subject with (1) a JavaScript alert function used in conjunction with the fromCharCode method o... Read more
Affected Products : mailtraq- Published: Sep. 19, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2024-13601
The Majestic Support – The Leading-Edge Help Desk & Customer Support Plugin plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.0.5 via the 'exportusereraserequest' function due to missing validat... Read more
Affected Products : majestic_support- Published: Feb. 12, 2025
- Modified: Feb. 18, 2025
- Vuln Type: Authorization
-
4.3
MEDIUMCVE-2025-48925
The TeleMessage service through 2025-05-05 relies on the client side (e.g., the TM SGNL app) to do MD5 hashing, and then accepts the hash as the authentication credential.... Read more
Affected Products : telemessage- Published: May. 28, 2025
- Modified: Jul. 01, 2025
- Vuln Type: Authentication