Latest CVE Feed
-
4.3
MEDIUMCVE-2024-10770
The Envo Extra plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.9.3 via the 'elementor-template' shortcode due to insufficient restrictions on which posts can be included. This makes it possible for authen... Read more
Affected Products : envo_extra- Published: Nov. 09, 2024
- Modified: Jan. 29, 2025
-
4.3
MEDIUMCVE-2020-9784
A logic issue was addressed with improved restrictions. This issue is fixed in Safari 13.1. A malicious iframe may use another website’s download settings.... Read more
Affected Products : safari- Published: Apr. 01, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2020-16197
An issue was discovered in Octopus Deploy 3.4. A deployment target can be configured with an Account or Certificate that is outside the scope of the deployment target. An authorised user can potentially use a certificate that they are not in scope to use.... Read more
- Published: Aug. 25, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2025-24420
Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by an Incorrect Authorization vulnerability that could result in a security feature bypass. A low-privileged attacker could exploit this vulnerability t... Read more
- Published: Feb. 11, 2025
- Modified: Apr. 16, 2025
- Vuln Type: Authorization
-
4.3
MEDIUMCVE-2024-21994
StorageGRID (formerly StorageGRID Webscale) versions prior to 11.9 are susceptible to a Denial of Service (DoS) vulnerability. Successful exploit by an authenticated attacker could lead to a service crash.... Read more
Affected Products : storagegrid- Published: Nov. 08, 2024
- Modified: Nov. 12, 2024
-
4.3
MEDIUMCVE-2024-8685
Path-Traversal vulnerability in Revolution Pi version 2022-07-28-revpi-buster from KUNBUS GmbH. This vulnerability could allow an authenticated attacker to list device directories via the ‘/pictory/php/getFileList.php’ endpoint in the ‘dir’ parameter.... Read more
Affected Products :- Published: Feb. 10, 2025
- Modified: Feb. 10, 2025
- Vuln Type: Path Traversal
-
4.3
MEDIUMCVE-2024-12046
The Medical Addon for Elementor plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.6.2 via the 'namedical_elementor_template' shortcode due to missing validation on a user controlled key. This ma... Read more
Affected Products :- Published: Feb. 04, 2025
- Modified: Feb. 04, 2025
- Vuln Type: Authorization
-
4.3
MEDIUMCVE-2020-11646
A log information disclosure vulnerability in B&R GateManager 4260 and 9250 versions <9.0.20262 and GateManager 8250 versions <9.2.620236042 allows authenticated users to view log information reserved for other users.... Read more
- Published: Oct. 15, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2020-15794
A vulnerability has been identified in Desigo Insight (All versions). Some error messages in the web application show the absolute path to the requested resource. This could allow an authenticated attacker to retrieve additional information about the host... Read more
Affected Products : desigo_insight- Published: Oct. 15, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2020-12700
The direct_mail extension through 5.2.3 for TYPO3 allows Information Disclosure via a newsletter subscriber data Special Query.... Read more
Affected Products : direct_mail- Published: May. 13, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2024-13425
The WP Job Portal – A Complete Recruitment System for Company or Job Board website plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.2.6 via the enforcedelete() function due to missing validatio... Read more
Affected Products : wp_job_portal- Published: Feb. 01, 2025
- Modified: Feb. 05, 2025
- Vuln Type: Authorization
-
4.3
MEDIUMCVE-2024-13424
The Ni Sales Commission For WooCommerce plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the 'niwoosc_ajax' AJAX endpoint in all versions up to, and including, 1.2.4. This makes it possible for authenticated a... Read more
Affected Products :- Published: Jan. 31, 2025
- Modified: Jan. 31, 2025
- Vuln Type: Authorization
-
4.3
MEDIUMCVE-2024-37482
Missing Authorization vulnerability in Post Grid Team by RadiusTheme The Post Grid allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects The Post Grid: from n/a through 7.7.4.... Read more
Affected Products :- Published: Nov. 01, 2024
- Modified: Nov. 01, 2024
-
4.3
MEDIUMCVE-2024-13652
The ECPay Ecommerce for WooCommerce plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the 'clear_ecpay_debug_log' AJAX action in all versions up to, and including, 1.1.2411060. This makes it possible for ... Read more
Affected Products : ecpay_ecommerce_for_woocommerce- Published: Jan. 30, 2025
- Modified: Jan. 31, 2025
- Vuln Type: Authorization
-
4.3
MEDIUMCVE-2023-50346
HCL DRYiCE MyXalytics is impacted by an information disclosure vulnerability. Certain endpoints within the application disclose detailed file information. ... Read more
Affected Products : dryice_myxalytics- Published: Jan. 03, 2024
- Modified: Jun. 18, 2025
-
4.3
MEDIUMCVE-2025-0754
The vulnerability was found in OpenShift Service Mesh 2.6.3 and 2.5.6. This issue occurs due to improper sanitization of HTTP headers by Envoy, particularly the x-forwarded-for header. This lack of sanitization can allow attackers to inject malicious payl... Read more
Affected Products :- Published: Jan. 28, 2025
- Modified: Jan. 28, 2025
- Vuln Type: Injection
-
4.3
MEDIUMCVE-2024-12113
The Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the delete_user_review() and delete_review() functions ... Read more
Affected Products : youzify- Published: Jan. 25, 2025
- Modified: May. 28, 2025
- Vuln Type: Authorization
-
4.3
MEDIUMCVE-2025-24751
Missing Authorization vulnerability in GoDaddy CoBlocks allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects CoBlocks: from n/a through 3.1.13.... Read more
Affected Products : coblocks- Published: Jan. 24, 2025
- Modified: Jan. 24, 2025
- Vuln Type: Authorization
-
4.3
MEDIUMCVE-2025-24679
Missing Authorization vulnerability in webraketen Internal Links Manager allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Internal Links Manager: from n/a through 2.5.2.... Read more
Affected Products :- Published: Jan. 24, 2025
- Modified: Jan. 24, 2025
- Vuln Type: Authorization
-
4.3
MEDIUMCVE-2025-24613
Missing Authorization vulnerability in Foliovision FV Thoughtful Comments allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects FV Thoughtful Comments: from n/a through 0.3.5.... Read more
Affected Products :- Published: Jan. 24, 2025
- Modified: Jan. 24, 2025
- Vuln Type: Authorization