Latest CVE Feed
-
4.3
MEDIUMCVE-2022-0377
Users of the LearnPress WordPress plugin before 4.1.5 can upload an image as a profile avatar after the registration. After this process the user crops and saves the image. Then a "POST" request that contains user supplied name of the image is sent to th... Read more
Affected Products : learnpress- Published: Feb. 28, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2024-47836
Admidio is an open-source user management solution. Prior to version 4.3.12, an unsafe deserialization vulnerability allows any unauthenticated user to execute arbitrary code on the server. Version 4.3.12 fixes this issue.... Read more
Affected Products : admidio- Published: Oct. 16, 2024
- Modified: Oct. 18, 2024
-
4.3
MEDIUMCVE-2024-48047
Cross-Site Request Forgery (CSRF) vulnerability in Razon Komar Pal Linked Variation for WooCommerce allows Cross Site Request Forgery.This issue affects Linked Variation for WooCommerce: from n/a through 1.0.5.... Read more
Affected Products :- Published: Oct. 17, 2024
- Modified: Oct. 18, 2024
-
4.3
MEDIUMCVE-2022-24446
An issue was discovered in Zoho ManageEngine Key Manager Plus 6.1.6. A user, with the level Operator, can see all SSH servers (and user information) even if no SSH server or user is associated to the operator.... Read more
Affected Products : manageengine_key_manager_plus- Published: Mar. 01, 2022
- Modified: May. 30, 2025
-
4.3
MEDIUMCVE-2024-40090
Vilo 5 Mesh WiFi System <= 5.16.1.33 is vulnerable to Information Disclosure. An information leak in the Boa webserver allows remote, unauthenticated attackers to leak memory addresses of uClibc and the stack via sending a GET request to the index page.... Read more
- Published: Oct. 21, 2024
- Modified: Jul. 07, 2025
-
4.3
MEDIUMCVE-2021-1410
A vulnerability in the distribution list feature of Cisco Webex Meetings could allow an authenticated, remote attacker to modify a distribution list that belongs to another user of their organization. The vulnerability is due to insufficient authori... Read more
Affected Products : webex_meetings- Published: Nov. 18, 2024
- Modified: Aug. 05, 2025
-
4.3
MEDIUMCVE-2024-52420
Cross-Site Request Forgery (CSRF) vulnerability in Creative Motion Disable Admin Notices individually allows Cross Site Request Forgery.This issue affects Disable Admin Notices individually: from n/a through 1.3.5.... Read more
Affected Products :- Published: Nov. 19, 2024
- Modified: Nov. 19, 2024
-
4.3
MEDIUMCVE-2022-3995
The TeraWallet plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 1.4.3. This is due to insufficient validation of the user-controlled key on the lock_unlock_terawallet AJAX action. This makes it poss... Read more
Affected Products : terawallet- Published: Nov. 29, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2021-41809
SSRF vulnerability in M-Files Server products with versions before 22.1.11017.1, in a preview function allowed making queries from the server with certain document types referencing external entities.... Read more
Affected Products : m-files_server- Published: Jan. 18, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2024-37249
Missing Authorization vulnerability in WPEngine Inc. Advanced Custom Fields PRO allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Advanced Custom Fields PRO: from n/a through 6.3.1.... Read more
Affected Products :- Published: Nov. 01, 2024
- Modified: Nov. 01, 2024
-
4.3
MEDIUMCVE-2024-1955
The Hide Dashboard Notifications plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'warning_notices_settings' function in all versions up to, and including, 1.3. This makes it possible for aut... Read more
Affected Products : hide_dashboard_notifications- Published: Jun. 21, 2024
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2024-37204
Missing Authorization vulnerability in PropertyHive PropertyHive allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects PropertyHive: from n/a through 2.0.9.... Read more
Affected Products : propertyhive- Published: Nov. 01, 2024
- Modified: Jan. 29, 2025
-
4.3
MEDIUMCVE-2024-43930
Cross-Site Request Forgery (CSRF) vulnerability in eyecix JobSearch allows Cross Site Request Forgery.This issue affects JobSearch: from n/a through 2.5.3.... Read more
Affected Products :- Published: Oct. 31, 2024
- Modified: Nov. 01, 2024
-
4.3
MEDIUMCVE-2023-6243
The EventON PRO - WordPress Virtual Event Calendar Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.6.8. This is due to missing or incorrect nonce validation on the admin_test_email function. ... Read more
Affected Products : eventon-lite- Published: Oct. 19, 2024
- Modified: Nov. 01, 2024
-
4.3
MEDIUMCVE-2023-29116
Under certain conditions, through a request directed to the Waybox Enel X web management application, information like Waybox OS version or service configuration details could be obtained.... Read more
- Published: Nov. 05, 2024
- Modified: Nov. 08, 2024
-
4.3
MEDIUMCVE-2022-45306
Insecure permissions in Chocolatey Azure-Pipelines-Agent package v2.211.1 and below grants all users in the Authenticated Users group write privileges for the subfolder C:\agent and all files located in that folder.... Read more
Affected Products : chocolatey_azure-pipelines-agent- Published: Nov. 29, 2022
- Modified: Apr. 25, 2025
-
4.3
MEDIUMCVE-2024-31972
EnGenius ESR580 A8J-EMR5000 devices allow a remote attacker to conduct stored XSS attacks that could lead to arbitrary JavaScript code execution (under the context of the user's session) via the Wi-Fi SSID input fields. Web scripts embedded into the vulne... Read more
Affected Products :- Published: Oct. 30, 2024
- Modified: Nov. 01, 2024
-
4.3
MEDIUMCVE-2021-44448
A vulnerability has been identified in JT Utilities (All versions < V13.0.3.0), JTTK (All versions < V11.0.3.0). JTTK library in affected products is vulnerable to an out of bounds read past the end of an allocated buffer when parsing JT files. An attacke... Read more
- Published: Dec. 14, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2024-8059
IPMI credentials may be captured in XCC audit log entries when the account username length is 16 characters.... Read more
Affected Products :- Published: Sep. 13, 2024
- Modified: Sep. 14, 2024
-
4.3
MEDIUMCVE-2021-46028
In mblog <= 3.5.0 there is a CSRF vulnerability in the background article management. The attacker constructs a CSRF load. Once the administrator clicks a malicious link, the article will be deleted.... Read more
Affected Products : mblog- Published: Jan. 20, 2022
- Modified: Nov. 21, 2024