Latest CVE Feed
-
4.3
MEDIUMCVE-2022-31032
Tuleap is a Free & Open Source Suite to improve management of software developments and collaboration. In versions prior to 13.9.99.58 authorizations are not properly verified when creating projects or trackers from projects marked as templates. Users can... Read more
Affected Products : tuleap- Published: Jun. 29, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2022-29858
Silverstripe silverstripe/assets through 1.10 is vulnerable to improper access control that allows protected images to be published by changing an existing image short code on website content.... Read more
Affected Products : assets- Published: Jun. 28, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2021-46028
In mblog <= 3.5.0 there is a CSRF vulnerability in the background article management. The attacker constructs a CSRF load. Once the administrator clicks a malicious link, the article will be deleted.... Read more
Affected Products : mblog- Published: Jan. 20, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2024-8059
IPMI credentials may be captured in XCC audit log entries when the account username length is 16 characters.... Read more
Affected Products :- Published: Sep. 13, 2024
- Modified: Sep. 14, 2024
-
4.3
MEDIUMCVE-2021-22035
VMware vRealize Log Insight (8.x prior to 8.6) contains a CSV(Comma Separated Value) injection vulnerability in interactive analytics export function. An authenticated malicious actor with non-administrative privileges may be able to embed untrusted data ... Read more
- Published: Oct. 13, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2024-49321
Missing Authorization vulnerability in Colorlib Simple Custom Post Order allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Simple Custom Post Order: from n/a through 2.5.7.... Read more
Affected Products : simple_custom_post_order- Published: Oct. 21, 2024
- Modified: Oct. 29, 2024
-
4.3
MEDIUMCVE-2024-8157
The Alphabetical List WordPress plugin through 1.0.3 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack... Read more
Affected Products : alphabetical_list- Published: Nov. 21, 2024
- Modified: May. 15, 2025
-
4.3
MEDIUMCVE-2024-10854
The Buy one click WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the buy_one_click_import_options AJAX action in all versions up to, and including, 2.2.9. This makes it possible for... Read more
Affected Products : buy_one_click_woocommerce- Published: Nov. 13, 2024
- Modified: Jan. 17, 2025
-
4.3
MEDIUMCVE-2024-10664
The Knowledge Base documentation & wiki plugin – BasePress Docs plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the basepress_db_posts_update() function in all versions up to, and including, 2.1... Read more
Affected Products :- Published: Dec. 04, 2024
- Modified: Dec. 04, 2024
-
4.3
MEDIUMCVE-2021-46602
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Bentley MicroStation CONNECT 10.16.0.80. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or... Read more
- Published: Feb. 18, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2024-52420
Cross-Site Request Forgery (CSRF) vulnerability in Creative Motion Disable Admin Notices individually allows Cross Site Request Forgery.This issue affects Disable Admin Notices individually: from n/a through 1.3.5.... Read more
Affected Products :- Published: Nov. 19, 2024
- Modified: Nov. 19, 2024
-
4.3
MEDIUMCVE-2024-10593
The WPForms – Easy Form Builder for WordPress – Contact Forms, Payment Forms, Surveys, & More plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.9.1.6. This is due to missing or incorrect nonce validat... Read more
Affected Products : wpforms- Published: Nov. 13, 2024
- Modified: Jul. 10, 2025
-
4.3
MEDIUMCVE-2022-23996
Unprotected component vulnerability in StTheaterModeReceiver in Wear OS 3.0 prior to Firmware update Feb-2022 Release allows untrusted applications to enable bedtime mode without a proper permission.... Read more
Affected Products : wear_os- Published: Feb. 11, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2024-11355
The Ultimate YouTube Video & Shorts Player With Vimeo plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the get_setting() function in all versions up to, and including, 3.3. This makes it possible for a... Read more
Affected Products : ultimate_youtube_video_\&_shorts_player_with_vimeo- Published: Nov. 22, 2024
- Modified: Nov. 22, 2024
-
4.3
MEDIUMCVE-2022-0334
A flaw was found in Moodle in versions 3.11 to 3.11.4, 3.10 to 3.10.8, 3.9 to 3.9.11 and earlier unsupported versions. Insufficient capability checks could lead to users accessing their grade report for courses where they did not have the required gradere... Read more
Affected Products : moodle- Published: Jan. 25, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2024-11014
Cross-site request forgery (CSRF) vulnerability in NEC Corporation UNIVERGE IX from Ver9.2 to Ver10.10.21, for Ver10.8 up to Ver10.8.27 and for Ver10.9 up to Ver10.9.14 allows a attacker to hijack the authentication of screens on the device via the manage... Read more
Affected Products :- Published: Nov. 29, 2024
- Modified: Jul. 23, 2025
-
4.3
MEDIUMCVE-2024-6987
The Orchid Store theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'orchid_store_activate_plugin' function in all versions up to, and including, 1.5.6. This makes it possible for authenticated ... Read more
Affected Products : orchid_store- Published: Aug. 08, 2024
- Modified: Mar. 01, 2025
-
4.3
MEDIUMCVE-2022-0634
The ThirstyAffiliates WordPress plugin before 3.10.5 lacks authorization checks in the ta_insert_external_image action, allowing a low-privilege user (with a role as low as Subscriber) to add an image from an external URL to an affiliate link. Further the... Read more
Affected Products : thirstyaffiliates_affiliate_link_manager- Published: Apr. 25, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2020-20943
A Cross-Site Request Forgery (CSRF) in /member/post.php?job=postnew&step=post of Qibosoft v7 allows attackers to force victim users into arbitrarily publishing new articles via a crafted URL.... Read more
Affected Products : qibosoft- Published: Dec. 27, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2024-7648
The Opal Membership plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.2.4 via the private notes functionality on payments which utilizes WordPress comments. This makes it possible for authenticate... Read more
Affected Products :- Published: Aug. 12, 2024
- Modified: Aug. 12, 2024