Latest CVE Feed
-
4.3
MEDIUMCVE-2021-46602
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Bentley MicroStation CONNECT 10.16.0.80. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or... Read more
- Published: Feb. 18, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2024-36122
Discourse is an open-source discussion platform. Prior to version 3.2.3 on the `stable` branch and version 3.3.0.beta4 on the `beta` and `tests-passed` branches, moderators using the review queue to review users may see a users email address even when the... Read more
Affected Products : discourse- Published: Jul. 03, 2024
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2021-39016
IBM Engineering Lifecycle Optimization - Publishing 6.0.6, 6.0.6.1, 7.0, 7.0.1, and 7.0.2 does not sufficiently monitor or control transmitted network traffic volume, so that an actor can cause the software to transmit more traffic than should be allowed ... Read more
- Published: Jul. 14, 2022
- Modified: Mar. 25, 2025
-
4.3
MEDIUMCVE-2024-4543
The Snippet Shortcodes plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.1.4. This is due to missing or incorrect nonce validation when adding or editing shortcodes. This makes it possible for unauthe... Read more
Affected Products : snippet_shortcodes- Published: Jul. 03, 2024
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2020-21056
Directory Traversal vulnerability exists in FusionPBX 4.5.7, which allows a remote malicious user to create folders via the folder variale to app\edit\foldernew.php.... Read more
Affected Products : fusionpbx- Published: May. 20, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2024-3602
The Pop ups, Exit intent popups, email popups, banners, bars, countdowns and cart savers – Promolayer plugin for WordPress is vulnerable to unauthorized plugin settings update due to a missing capability check on the disconnect_promolayer function in all ... Read more
Affected Products : popup_builder- Published: Jun. 20, 2024
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2024-6757
The Elementor Website Builder – More than Just a Page Builder plugin for WordPress is vulnerable to Basic Information Exposure in all versions up to, and including, 3.23.5 via the get_image_alt function. This makes it possible for authenticated attackers,... Read more
Affected Products : website_builder- Published: Oct. 15, 2024
- Modified: Oct. 17, 2024
-
4.3
MEDIUMCVE-2024-49382
Excessive attack surface in archive-server service due to binding to an unrestricted IP address. The following products are affected: Acronis Cyber Protect 16 (Linux, Windows) before build 38690.... Read more
- Published: Oct. 15, 2024
- Modified: Feb. 04, 2025
-
4.3
MEDIUMCVE-2024-4873
The Replace Image plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.1.10 via the image replacement functionality due to missing validation on a user controlled key. This makes it possible for au... Read more
Affected Products :- Published: Jun. 19, 2024
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2024-1693
The SP Project & Document Manager plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the cdm_save_category AJAX action in all versions up to, and including, 4.70. This makes it possible for authent... Read more
Affected Products : sp_project_\&_document_manager- Published: May. 14, 2024
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2024-33679
Cross-Site Request Forgery (CSRF) vulnerability in FameThemes FameTheme Demo Importer.This issue affects FameTheme Demo Importer: from n/a through 1.1.5.... Read more
Affected Products :- Published: Apr. 26, 2024
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2024-1467
The Starter Templates — Elementor, WordPress & Beaver Builder Templates plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 4.1.6 via the ai_api_request(). This makes it possible for authenticated attack... Read more
Affected Products :- Published: May. 14, 2024
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2024-33689
Cross-Site Request Forgery (CSRF) vulnerability in Tony Zeoli, Tony Hayes Radio Station.This issue affects Radio Station: from n/a through 2.5.7. ... Read more
Affected Products :- Published: Apr. 26, 2024
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2024-4541
The Custom Product List Table plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.0.0. This is due to missing or incorrect nonce validation when modifying products. This makes it possible for unauthenti... Read more
Affected Products :- Published: Jun. 19, 2024
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2021-33330
Liferay Portal 7.2.0 through 7.3.2, and Liferay DXP 7.2 before fix pack 9, allows access to Cross-origin resource sharing (CORS) protected resources if the user is only authenticated using the portal session authentication, which allows remote attackers t... Read more
- Published: Aug. 03, 2021
- Modified: May. 13, 2025
-
4.3
MEDIUMCVE-2024-33650
Cross-Site Request Forgery (CSRF) vulnerability in Cryout Creations Serious Slider.This issue affects Serious Slider: from n/a through 1.2.4. ... Read more
Affected Products : serious_slider- Published: Apr. 26, 2024
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2024-3508
A flaw was found in Bombastic, which allows authenticated users to upload compressed (bzip2 or zstd) SBOMs. The API endpoint verifies the presence of some fields and values in the JSON. To perform this verification, the uploaded file must first be decompr... Read more
Affected Products : trusted_profile_analyzer- Published: Apr. 25, 2024
- Modified: Jun. 18, 2025
-
4.3
MEDIUMCVE-2024-33942
Missing Authorization vulnerability in Eric Alli Google Typography.This issue affects Google Typography: from n/a through 1.1.2. ... Read more
Affected Products :- Published: May. 14, 2024
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2024-33851
phpecc, as used in paragonie/phpecc before 2.0.1, has a branch-based timing leak in Point addition. (This is related to phpecc/phpecc on GitHub, and the Matyas Danter ECC library.)... Read more
Affected Products :- Published: Apr. 27, 2024
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2024-34223
Insecure permission vulnerability in /hrm/leaverequest.php in SourceCodester Human Resource Management System 1.0 allow attackers to approve or reject leave ticket.... Read more
Affected Products : human_resource_management_system- Published: May. 14, 2024
- Modified: Apr. 18, 2025