Latest CVE Feed
-
4.3
MEDIUMCVE-2024-24978
Denial-of-service (DoS) vulnerability exists in TvRock 0.9t8a. Receiving a specially crafted request by a remote attacker or having a user of TvRock click a specially crafted request may lead to ABEND (abnormal end). Note that the developer was unreachabl... Read more
Affected Products :- Published: May. 01, 2024
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2024-25064
Due to insufficient server-side validation, an attacker with login privileges could access certain resources that the attacker should not have access to by changing parameter values.... Read more
Affected Products : hikcentral_professional- Published: Mar. 02, 2024
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2009-2999
The com.android.phone process in Android 1.5 CRBxx allows remote attackers to cause a denial of service (application restart and network disconnection) via an SMS message containing a malformed WAP Push message that triggers an ArrayIndexOutOfBoundsExcept... Read more
Affected Products : android- Published: Oct. 14, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2024-32828
Missing Authorization vulnerability in Octolize Flexible Shipping.This issue affects Flexible Shipping: from n/a through 4.24.15. ... Read more
Affected Products :- Published: Apr. 26, 2024
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2020-10905
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PhantomPDF 9.7.1.29511. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a mal... Read more
- Published: Apr. 22, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2015-4725
Cross-site scripting (XSS) vulnerability in forgot.php in AudioShare 2.0.2 allows remote attackers to inject arbitrary web script or HTML via the email parameter.... Read more
Affected Products : audioshare- Published: Jun. 23, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2015-0950
Cross-site scripting (XSS) vulnerability in admin.php in X-Cart 5.1.6 through 5.1.10 allows remote attackers to inject arbitrary web script or HTML via the substring parameter.... Read more
Affected Products : x-cart- Published: Apr. 05, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2024-33688
Cross-Site Request Forgery (CSRF) vulnerability in Extend Themes Teluro.This issue affects Teluro: from n/a through 1.0.31. ... Read more
Affected Products :- Published: Apr. 26, 2024
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2024-43340
Cross-Site Request Forgery (CSRF) vulnerability in Nasirahmed Advanced Form Integration.This issue affects Advanced Form Integration: from n/a through 1.89.4.... Read more
Affected Products : advanced_form_integration- Published: Aug. 26, 2024
- Modified: Aug. 27, 2024
-
4.3
MEDIUMCVE-2024-23518
Missing Authorization vulnerability in Navneil Naicker ACF Photo Gallery Field.This issue affects ACF Photo Gallery Field: from n/a through 2.6.... Read more
Affected Products :- Published: Jun. 11, 2024
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2023-21902
Vulnerability in the Oracle Financial Services Behavior Detection Platform product of Oracle Financial Services Applications (component: Application). The supported version that is affected is 8.0.8.1. Easily exploitable vulnerability allows low privile... Read more
Affected Products : financial_services_behavior_detection_platform- Published: Apr. 18, 2023
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2012-1912
Cross-site scripting (XSS) vulnerability in preferences.php in PHP Address Book 7.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the from parameter. NOTE: the index.php vector is already covered by CVE-2008-2566.... Read more
Affected Products : php_address_book- Published: Sep. 09, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2025-49240
Missing Authorization vulnerability in nK DocsPress allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects DocsPress: from n/a through 2.5.2.... Read more
Affected Products :- Published: Jun. 06, 2025
- Modified: Jun. 06, 2025
- Vuln Type: Authorization
-
4.3
MEDIUMCVE-2024-31942
Cross-Site Request Forgery (CSRF) vulnerability in Typps Calendarista Basic Edition.This issue affects Calendarista Basic Edition: from n/a through 3.0.2. ... Read more
Affected Products : calendarista- Published: Apr. 15, 2024
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2019-1003010
A cross-site request forgery vulnerability exists in Jenkins Git Plugin 3.9.1 and earlier in src/main/java/hudson/plugins/git/GitTagAction.java that allows attackers to create a Git tag in a workspace and attach corresponding metadata to a build record.... Read more
- Published: Feb. 06, 2019
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2025-26925
Cross-Site Request Forgery (CSRF) vulnerability in Required Admin Menu Manager allows Cross Site Request Forgery.This issue affects Admin Menu Manager: from n/a through 1.0.3.... Read more
Affected Products :- Published: Feb. 26, 2025
- Modified: Feb. 26, 2025
- Vuln Type: Cross-Site Request Forgery
-
4.3
MEDIUMCVE-2012-0895
Cross-site scripting (XSS) vulnerability in map/map.php in the Count Per Day module before 3.1.1 for WordPress allows remote attackers to inject arbitrary web script or HTML via the map parameter.... Read more
- Published: Jan. 20, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2013-5916
Cross-site scripting (XSS) vulnerability in falha.php in the Bradesco Gateway plugin 2.0 for Wordpress, as used in the WP e-Commerce plugin, allows remote attackers to inject arbitrary web script or HTML via the QUERY_STRING.... Read more
Affected Products : bradesco_gateway- Published: May. 08, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2024-27707
Server Side Request Forgery (SSRF) vulnerability in hcengineering Huly Platform v.0.6.202 allows attackers to run arbitrary code via upload of crafted SVG file.... Read more
Affected Products :- Published: Mar. 07, 2024
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2010-1742
Cross-site scripting (XSS) vulnerability in projects.php in Scratcher allows remote attackers to inject arbitrary web script or HTML via the show parameter.... Read more
Affected Products : scratcher- Published: May. 06, 2010
- Modified: Apr. 11, 2025