Latest CVE Feed
-
4.3
MEDIUMCVE-2024-8427
The Frontend Post Submission Manager Lite – Frontend Posting WordPress Plugin plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the save_global_settings and process_form_edit functions in all vers... Read more
Affected Products : frontend_post_submission_manager- Published: Sep. 06, 2024
- Modified: Sep. 11, 2024
-
4.3
MEDIUMCVE-2024-42164
Insufficiently random values for generating password reset token in FIWARE Keyrock <= 8.4 allow attackers to disable two factor authorization of any user by predicting the token for the disable_2fa link.... Read more
Affected Products : keyrock- Published: Aug. 12, 2024
- Modified: Aug. 29, 2024
-
4.3
MEDIUMCVE-2024-42487
Cilium is a networking, observability, and security solution with an eBPF-based dataplane. In the 1.15 branch prior to 1.15.8 and the 1.16 branch prior to 1.16.1, Gateway API HTTPRoutes and GRPCRoutes do not follow the match precedence specified in the Ga... Read more
Affected Products : cilium- Published: Aug. 15, 2024
- Modified: Sep. 30, 2024
-
4.3
MEDIUMCVE-2024-11911
The WP Crowdfunding plugin for WordPress is vulnerable to unauthorized plugin installation due to a missing capability check on the install_woocommerce_plugin() function action in all versions up to, and including, 2.1.12. This makes it possible for authe... Read more
Affected Products : wp_crowdfunding- Published: Dec. 13, 2024
- Modified: Feb. 11, 2025
-
4.3
MEDIUMCVE-2024-1649
The Categorify plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the categorifyAjaxDeleteCategory function in all versions up to, and including, 1.0.7.4. This makes it possible for authenticated a... Read more
Affected Products : categorify- Published: Feb. 27, 2024
- Modified: Jan. 07, 2025
-
4.3
MEDIUMCVE-2025-27339
Cross-Site Request Forgery (CSRF) vulnerability in Will Anderson Minimum Password Strength allows Cross Site Request Forgery. This issue affects Minimum Password Strength: from n/a through 1.2.0.... Read more
Affected Products :- Published: Feb. 24, 2025
- Modified: Feb. 24, 2025
- Vuln Type: Cross-Site Request Forgery
-
4.3
MEDIUMCVE-2024-47170
Agnai is an artificial-intelligence-agnostic multi-user, mult-bot roleplaying chat system. A vulnerability in versions prior to 1.0.330 permits attackers to read arbitrary JSON files at attacker-chosen locations on the server. This issue can lead to unaut... Read more
Affected Products : agnai- Published: Sep. 26, 2024
- Modified: Oct. 29, 2024
-
4.3
MEDIUMCVE-2024-43157
Missing Authorization vulnerability in nCrafts FormCraft allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects FormCraft: from n/a through 1.2.10.... Read more
Affected Products : formcraft- Published: Nov. 01, 2024
- Modified: Nov. 01, 2024
-
4.3
MEDIUMCVE-2024-43319
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in bPlugins LLC Flash & HTML5 Video.This issue affects Flash & HTML5 Video: from n/a through 2.5.31.... Read more
Affected Products : html5_video_player- Published: Aug. 26, 2024
- Modified: Aug. 26, 2024
-
4.3
MEDIUMCVE-2024-40598
An issue was discovered in the CheckUser extension for MediaWiki through 1.42.1. The API can expose suppressed information for log events. (The log_deleted attribute is not applied to entries.)... Read more
Affected Products : mediawiki- Published: Jul. 07, 2024
- Modified: Mar. 25, 2025
-
4.3
MEDIUMCVE-2023-37856
In PHOENIX CONTACTs WP 6xxx series web panels in versions prior to 4.0.10 a remote attacker with low privileges is able to gain limited read-access to the device-filesystem through a configuration dialog within the embedded Qt browser . ... Read more
Affected Products : wp_6070-wvps_firmware wp_6101-wxps_firmware wp_6121-wxps_firmware wp_6156-whps_firmware wp_6185-whps_firmware wp_6215-whps_firmware wp_6070-wvps wp_6101-wxps wp_6121-wxps wp_6156-whps +2 more products- Published: Aug. 09, 2023
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2024-12114
The FooGallery – Responsive Photo Gallery, Image Viewer, Justified, Masonry & Carousel plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.4.29 via the foogallery_attachment_modal_save AJAX action... Read more
Affected Products : foogallery- Published: Mar. 08, 2025
- Modified: Mar. 12, 2025
- Vuln Type: Authorization
-
4.3
MEDIUMCVE-2023-1068
The Download Read More Excerpt Link plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.6.0. This is due to missing or incorrect nonce validation on the read_more_excerpt_link_menu_options() function. This ... Read more
Affected Products : read_more_excerpt_link- Published: Feb. 27, 2023
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2024-43933
Cross-Site Request Forgery (CSRF) vulnerability in WPMobile.App allows Stored XSS.This issue affects WPMobile.App: from n/a through 11.48.... Read more
Affected Products : wpmobile.app- Published: Oct. 31, 2024
- Modified: Nov. 01, 2024
-
4.3
MEDIUMCVE-2024-9530
The Qi Addons For Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.8.0 via private templates. This makes it possible for authenticated attackers, with Contributor-level access and above... Read more
Affected Products : qi_addons_for_elementor- Published: Oct. 23, 2024
- Modified: Oct. 25, 2024
-
4.3
MEDIUMCVE-2024-13439
The Team – Team Members Showcase Plugin plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the response() function in all versions up to, and including, 4.4.9. This makes it possible for authenticated attackers,... Read more
Affected Products : team- Published: Feb. 15, 2025
- Modified: Feb. 24, 2025
- Vuln Type: Authorization
-
4.3
MEDIUMCVE-2023-27525
An authenticated user with Gamma role authorization could have access to metadata information using non trivial methods in Apache Superset up to and including 2.0.1 ... Read more
Affected Products : superset- Published: Apr. 17, 2023
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2022-38482
A link-manipulation issue was discovered in Mega HOPEX 15.2.0.6110 before V5CP4.... Read more
Affected Products : hopex- Published: Jan. 10, 2023
- Modified: May. 30, 2025
-
4.3
MEDIUMCVE-2012-4015
Cross-site scripting (XSS) vulnerability in the management screen in myLittleTools myLittleAdmin for SQL Server 2000 allows remote attackers to inject arbitrary web script or HTML via vectors that trigger a crafted database entry.... Read more
- Published: Sep. 25, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2012-1036
Cross-site scripting (XSS) vulnerability in the telerik HTML editor in DotNetNuke before 5.6.4 and 6.x before 6.1.0 allows remote attackers to inject arbitrary web script or HTML via a message.... Read more
Affected Products : dotnetnuke- Published: Apr. 11, 2012
- Modified: Apr. 11, 2025