Latest CVE Feed
-
4.3
MEDIUMCVE-2025-28941
Cross-Site Request Forgery (CSRF) vulnerability in ohtan Spam Byebye allows Cross Site Request Forgery. This issue affects Spam Byebye: from n/a through 2.2.4.... Read more
Affected Products : spam-byebye- Published: Mar. 11, 2025
- Modified: Mar. 11, 2025
- Vuln Type: Cross-Site Request Forgery
-
4.3
MEDIUMCVE-2024-31383
Cross-Site Request Forgery (CSRF) vulnerability in Pagelayer PopularFX.This issue affects PopularFX: from n/a through 1.2.4. ... Read more
Affected Products :- Published: Apr. 15, 2024
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2024-13703
The CRM and Lead Management by vcita plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the vcita_ajax_toggle_ae() function in all versions up to, and including, 2.7.1. This makes it possible for a... Read more
Affected Products : crm_and_lead_management_by_vcita- Published: Mar. 13, 2025
- Modified: May. 26, 2025
- Vuln Type: Authorization
-
4.3
MEDIUMCVE-2006-2000
Cross-site scripting (XSS) vulnerability in /lms/a2z.jsp in logMethods 0.9 allows remote attackers to inject arbitrary web script or HTML via the kwd parameter.... Read more
Affected Products : logmethods- Published: Apr. 25, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2025-32262
Cross-Site Request Forgery (CSRF) vulnerability in Robert D Payne RDP Wiki Embed allows Cross Site Request Forgery. This issue affects RDP Wiki Embed: from n/a through 1.2.20.... Read more
Affected Products :- Published: Apr. 04, 2025
- Modified: Apr. 07, 2025
- Vuln Type: Cross-Site Request Forgery
-
4.3
MEDIUMCVE-2024-9541
The News Kit Elementor Addons plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.2.1 via the render function in includes/widgets/canvas-menu/canvas-menu.php. This makes it possible for authenticate... Read more
Affected Products : news_kit_elementor_addons- Published: Oct. 22, 2024
- Modified: Oct. 25, 2024
-
4.3
MEDIUMCVE-2025-32277
Missing Authorization vulnerability in Ateeq Rafeeq RepairBuddy allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects RepairBuddy: from n/a through 3.8211.... Read more
Affected Products : computer_repair_shop- Published: Apr. 04, 2025
- Modified: Apr. 07, 2025
- Vuln Type: Authorization
-
4.3
MEDIUMCVE-2025-0361
During an annual penetration test conducted on behalf of Axis Communications, Truesec discovered a flaw in the VAPIX Device Configuration framework that allowed for unauthenticated username enumeration through the VAPIX Device Configuration SSH Management... Read more
Affected Products : axis_os- Published: Apr. 08, 2025
- Modified: Apr. 08, 2025
- Vuln Type: Authentication
-
4.3
MEDIUMCVE-2025-32279
Missing Authorization vulnerability in Shahjada Live Forms. This issue affects Live Forms: from n/a through 4.8.5.... Read more
Affected Products : live_forms- Published: Apr. 08, 2025
- Modified: Apr. 08, 2025
- Vuln Type: Authorization
-
4.3
MEDIUMCVE-2024-31219
Discourse-reactions is a plugin that allows user to add their reactions to the post. When whispers are enabled on a site via `whispers_allowed_groups` and reactions are made on whispers on public topics, the contents of the whisper and the reaction data a... Read more
Affected Products : discourse_reactions- Published: Apr. 15, 2024
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2024-10312
The Exclusive Addons for Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.7.4 via the render function in elements/tabs/tabs.php. This makes it possible for authenticated attackers, with... Read more
Affected Products : exclusive_addons_for_elementor- Published: Oct. 29, 2024
- Modified: Jan. 24, 2025
-
4.3
MEDIUMCVE-2024-32109
Cross-Site Request Forgery (CSRF) vulnerability in Julien Berthelot / MPEmbed.Com WP Matterport Shortcode allows Cross Site Request Forgery.This issue affects WP Matterport Shortcode: from n/a through 2.1.9. ... Read more
Affected Products :- Published: Apr. 11, 2024
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2024-32105
Cross-Site Request Forgery (CSRF) vulnerability in ELEXtensions ELEX WooCommerce Dynamic Pricing and Discounts.This issue affects ELEX WooCommerce Dynamic Pricing and Discounts: from n/a through 2.1.2. ... Read more
Affected Products :- Published: Apr. 11, 2024
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2017-16639
Tor Browser on Windows before 8.0 allows remote attackers to bypass the intended anonymity feature and discover a client IP address, a different vulnerability than CVE-2017-16541. User interaction is required to trigger this vulnerability.... Read more
- Published: Sep. 14, 2018
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2023-3178
The POST SMTP Mailer WordPress plugin before 2.5.7 does not have proper CSRF checks in some AJAX actions, which could allow attackers to make logged in users with the manage_postman_smtp capability delete arbitrary logs via a CSRF attack.... Read more
- Published: Jan. 16, 2024
- Modified: Jun. 02, 2025
-
4.3
MEDIUMCVE-2023-6292
The Ecwid Ecommerce Shopping Cart WordPress plugin before 6.12.5 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack.... Read more
Affected Products : ecwid_ecommerce_shopping_cart- Published: Jan. 16, 2024
- Modified: Jun. 02, 2025
-
4.3
MEDIUMCVE-2023-23935
Discourse is an open-source messaging platform. In versions 3.0.1 and prior on the `stable` branch and versions 3.1.0.beta2 and prior on the `beta` and `tests-passed` branches, the count of personal messages displayed for a tag is a count of all personal ... Read more
Affected Products : discourse- Published: Mar. 16, 2023
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2006-2473
Cross-site scripting (XSS) vulnerability in ow.asp in OpenWiki 0.78 allows remote attackers to inject arbitrary web script or HTML via the p parameter. NOTE: this issue has been disputed by the vendor and a third party who is affiliated with the product.... Read more
Affected Products : openwiki- Published: May. 19, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2023-6741
The WP Customer Area WordPress plugin before 8.2.1 does not properly validate users capabilities in some of its AJAX actions, allowing malicious users to edit other users' account address.... Read more
Affected Products : wp_customer_area- Published: Jan. 16, 2024
- Modified: Jun. 20, 2025
-
4.3
MEDIUMCVE-2022-45854
An improper check for unusual conditions in Zyxel NWA110AX firmware verisons prior to 6.50(ABTG.0)C0, which could allow a LAN attacker to cause a temporary denial-of-service (DoS) by sending crafted VLAN frames if the MAC address of the vulnerable AP were... Read more
Affected Products : nwa110ax_firmware nwa210ax_firmware wax510d_firmware wax610d_firmware wax630s_firmware wax650s_firmware nwa110ax nwa210ax wax510d wax610d +2 more products- Published: Feb. 07, 2023
- Modified: Nov. 21, 2024