Latest CVE Feed
-
4.3
MEDIUMCVE-2025-49440
Cross-Site Request Forgery (CSRF) vulnerability in Vuong Nguyen WP Security Master allows Cross Site Request Forgery. This issue affects WP Security Master: from n/a through 1.0.2.... Read more
Affected Products :- Published: Jun. 06, 2025
- Modified: Jun. 06, 2025
- Vuln Type: Cross-Site Request Forgery
-
4.3
MEDIUMCVE-2025-31887
Missing Authorization vulnerability in zookatron MyBookProgress by Stormhill Media allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects MyBookProgress by Stormhill Media: from n/a through 1.0.8.... Read more
Affected Products :- Published: Apr. 01, 2025
- Modified: Apr. 01, 2025
- Vuln Type: Authorization
-
4.3
MEDIUMCVE-2024-45354
A code execution vulnerability exists in the Xiaomi shop applicationproduct. The vulnerability is caused by improper input validation and can be exploited by attackers to execute malicious code.... Read more
Affected Products :- Published: Mar. 27, 2025
- Modified: Mar. 27, 2025
- Vuln Type: Injection
-
4.3
MEDIUMCVE-2008-0848
Cross-site scripting (XSS) vulnerability in lostsheep.php in Crafty Syntax Live Help (CSLH) before 2.14.16, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. NOTE: the versions claimed by the original researcher are ... Read more
Affected Products : crafty_syntax_live_help- Published: Feb. 21, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2008-0834
Cross-site scripting (XSS) vulnerability in Lotus Quickr for i5/OS before 8.0.0.2 Hotfix 11, when anonymous access is disabled on HTTP ports, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : lotus_quickr- Published: Feb. 20, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2008-0877
Multiple cross-site scripting (XSS) vulnerabilities in Jinzora Media Jukebox 2.7.5 allow remote attackers to inject arbitrary web script or HTML via the (1) frontend, (2) set_frontend, (3) jz_path, (4) theme, and (5) set_theme parameters to (a) index.php;... Read more
Affected Products : media_jukebox- Published: Feb. 21, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2003-1307
The mod_php module for the Apache HTTP Server allows local users with write access to PHP scripts to send signals to the server's process group and use the server's file descriptors, as demonstrated by sending a STOP signal, then intercepting incoming con... Read more
Affected Products : http_server- Published: Dec. 31, 2003
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2025-2564
Mattermost versions 10.5.x <= 10.5.1, 10.4.x <= 10.4.3, 9.11.x <= 9.11.9 fail to properly enforce the 'Allow users to view/update archived channels' System Console setting, which allows authenticated users to view members and member information of archive... Read more
Affected Products : mattermost_server- Published: Apr. 16, 2025
- Modified: Apr. 17, 2025
- Vuln Type: Authorization
-
4.3
MEDIUMCVE-2025-31525
Missing Authorization vulnerability in WP Messiah WP Mobile Bottom Menu allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects WP Mobile Bottom Menu: from n/a through 1.2.9.... Read more
Affected Products :- Published: Apr. 01, 2025
- Modified: Apr. 02, 2025
- Vuln Type: Authorization
-
4.3
MEDIUMCVE-2025-31753
Cross-Site Request Forgery (CSRF) vulnerability in Animesh Kumar Advanced Speed Increaser. This issue affects Advanced Speed Increaser: from n/a through 2.2.1.... Read more
Affected Products :- Published: Apr. 01, 2025
- Modified: Apr. 02, 2025
- Vuln Type: Cross-Site Request Forgery
-
4.3
MEDIUMCVE-2024-13216
The HT Event – WordPress Event Manager Plugin for Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.4.7 via the 'render' function in /includes/widgets/htevent_sponsor.php. This makes it ... Read more
Affected Products : ht_event- Published: Jan. 31, 2025
- Modified: Jan. 31, 2025
- Vuln Type: Information Disclosure
-
4.3
MEDIUMCVE-2024-45654
IBM Security ReaQta 3.12 could allow an authenticated user to perform unauthorized actions due to reliance on untrusted inputs.... Read more
- Published: Jan. 19, 2025
- Modified: Jul. 16, 2025
- Vuln Type: Authorization
-
4.3
MEDIUMCVE-2025-1408
The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the pm_decline_join_group_request and pm_approve_join_group_request functions in all versi... Read more
Affected Products : profilegrid- Published: Mar. 22, 2025
- Modified: Mar. 27, 2025
- Vuln Type: Authorization
-
4.3
MEDIUMCVE-2025-2842
A flaw was found in the Tempo Operator. When the Jaeger UI Monitor Tab functionality is enabled in a Tempo instance managed by the Tempo Operator, the Operator creates a ClusterRoleBinding for the Service Account of the Tempo instance to grant the cluster... Read more
Affected Products :- Published: Apr. 02, 2025
- Modified: Apr. 09, 2025
- Vuln Type: Authorization
-
4.3
MEDIUMCVE-2025-8595
The Zakra theme for WordPress is vulnerable to unauthorized data modification due to a missing capability check on the welcome_notice_import_handler() function in all versions up to, and including, 4.1.5. This makes it possible for authenticated attackers... Read more
Affected Products :- Published: Aug. 06, 2025
- Modified: Aug. 06, 2025
- Vuln Type: Authorization
-
4.3
MEDIUMCVE-2025-24972
Discourse is an open-source discussion platform. Prior to versions `3.3.4` on the `stable` branch and `3.4.0.beta5` on the `beta` branch, in specific circumstances, users could be added to group direct messages despite disabling direct messaging in their ... Read more
Affected Products : discourse- Published: Mar. 26, 2025
- Modified: Mar. 27, 2025
- Vuln Type: Authorization
-
4.3
MEDIUMCVE-2025-24808
Discourse is an open-source discussion platform. Prior to versions `3.3.4` on the `stable` branch and `3.4.0.beta5` on the `beta` branch, someone who is about to reach the limit of users in a group DM may send requests to add new users in parallel. The re... Read more
Affected Products : discourse- Published: Mar. 26, 2025
- Modified: Aug. 26, 2025
- Vuln Type: Race Condition
-
4.3
MEDIUMCVE-2008-1006
Cross-site scripting (XSS) vulnerability in WebCore, as used in Apple Safari before 3.1, allows remote attackers to inject arbitrary web script or HTML by using the window.open function to change the security context of a web page.... Read more
Affected Products : safari- Published: Mar. 19, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2008-0299
common.py in Paramiko 1.7.1 and earlier, when using threads or forked processes, does not properly use RandomPool, which allows one session to obtain sensitive information from another session by predicting the state of the pool.... Read more
- Published: Jan. 16, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2008-1011
Cross-site scripting (XSS) vulnerability in WebKit, as used in Apple Safari before 3.1, allows remote attackers to inject arbitrary web script or HTML via a frame that calls a method instance in another frame.... Read more
Affected Products : safari- Published: Mar. 19, 2008
- Modified: Apr. 09, 2025