Latest CVE Feed
-
4.3
MEDIUMCVE-2022-22107
In Daybyday CRM, versions 2.0.0 through 2.2.0 are vulnerable to Missing Authorization. An attacker that has the lowest privileges account (employee type user), can view the appointments of all users in the system including administrators. However, this ty... Read more
- Published: Jan. 05, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2021-20656
Exposure of information through directory listing in SolarView Compact SV-CPT-MC310 prior to Ver.6.5 allows an authenticated attacker to obtain the information inside the system, such as directories and/or file configurations via unspecified vectors.... Read more
- Published: Feb. 24, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2024-9503
The Maintenance & Coming Soon Redirect Animation plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'wploti_add_whitelisted_roles_option', 'wploti_remove_whitelisted_roles_option', 'wploti_add... Read more
Affected Products :- Published: Dec. 20, 2024
- Modified: Dec. 20, 2024
-
4.3
MEDIUMCVE-2024-12636
The Privacy Policy Generator, Terms & Conditions Generator WordPress Plugin : WP Legal Pages plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.2.6. This is due to missing or incorrect nonce validation... Read more
Affected Products :- Published: Dec. 25, 2024
- Modified: Dec. 25, 2024
-
4.3
MEDIUMCVE-2024-1994
The Image Watermark plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the watermark_action_ajax() function in all versions up to, and including, 1.7.3. This makes it possible for authenticated att... Read more
Affected Products :- Published: Apr. 06, 2024
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2024-12335
The Avada (Fusion) Builder plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 3.11.12 via the handle_clone_post() function and the 'fusion_blog' shortcode and due to insufficient restrictions on which posts ca... Read more
- Published: Dec. 25, 2024
- Modified: Apr. 14, 2025
-
4.3
MEDIUMCVE-2024-1467
The Starter Templates — Elementor, WordPress & Beaver Builder Templates plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 4.1.6 via the ai_api_request(). This makes it possible for authenticated attack... Read more
Affected Products :- Published: May. 14, 2024
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2024-1693
The SP Project & Document Manager plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the cdm_save_category AJAX action in all versions up to, and including, 4.70. This makes it possible for authent... Read more
Affected Products : sp_project_\&_document_manager- Published: May. 14, 2024
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2023-3366
The MultiParcels Shipping For WooCommerce WordPress plugin before 1.15.2 does not have CRSF check when deleting a shipment, allowing attackers to make any logged in user, delete arbitrary shipment via a CSRF attack... Read more
Affected Products : multiparcels_shipping_for_woocommerce- Published: Aug. 21, 2023
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2020-4725
IBM Monitoring (IBM Cloud APM 8.1.4 ) could allow an authenticated user to modify HTML content by sending a specially crafted HTTP request to the APM UI, which could mislead another user. IBM X-Force ID: 187974.... Read more
Affected Products : cloud_application_performance_management- Published: Mar. 02, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2024-31455
Minder by Stacklok is an open source software supply chain security platform. A refactoring in commit `5c381cf` added the ability to get GitHub repositories registered to a project without specifying a specific provider. Unfortunately, the SQL query for ... Read more
Affected Products : minder- Published: Apr. 09, 2024
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2024-50701
TeamPass before 3.1.3.1, when retrieving information about access rights for a folder, does not properly check whether a folder is in a user's allowed folders list that has been defined by an admin.... Read more
Affected Products : teampass- Published: Dec. 30, 2024
- Modified: Dec. 30, 2024
-
4.3
MEDIUMCVE-2024-56229
Cross-Site Request Forgery (CSRF) vulnerability in Searchiq SearchIQ.This issue affects SearchIQ: from n/a through 4.6.... Read more
Affected Products : searchiq- Published: Dec. 31, 2024
- Modified: Jun. 05, 2025
-
4.3
MEDIUMCVE-2023-6965
The Pods – Custom Content Types and Fields plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 3.0.10 (with the exception of 2.7.31.2, 2.8.23.2, 2.9.19.2). This is due to the fact that the plugin allows the us... Read more
Affected Products : pods- Published: Apr. 09, 2024
- Modified: Jan. 22, 2025
-
4.3
MEDIUMCVE-2021-21493
When a user opens manipulated Graphics Interchange Format (.GIF) format files received from untrusted sources in SAP 3D Visual Enterprise Viewer version 9, the application crashes and becomes temporarily unavailable to the user until restart of the applic... Read more
Affected Products : 3d_visual_enterprise_viewer- Published: Mar. 09, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2023-50850
Missing Authorization vulnerability in Woo WooCommerce Subscriptions allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WooCommerce Subscriptions: from n/a before 5.8.0.... Read more
Affected Products :- Published: Dec. 31, 2024
- Modified: Dec. 31, 2024
-
4.3
MEDIUMCVE-2024-32773
Cross-Site Request Forgery (CSRF) vulnerability in WP Royal Royal Elementor Kit.This issue affects Royal Elementor Kit: from n/a through 1.0.116. ... Read more
Affected Products : royal_elementor_kit- Published: Apr. 24, 2024
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2015-5016
IBM Maximo Asset Management 7.1, 7.5, and 7.6; Maximo Asset Management Essentials 7.1 and 7.5; Control Desk 7.5 and 7.6; Tivoli Asset Management for IT 7.1 and 7.2; and certain other IBM products allow remote authenticated users to bypass intended access ... Read more
- Published: Mar. 27, 2018
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2023-46080
Missing Authorization vulnerability in Farhan Noor ApplyOnline – Application Form Builder and Manager allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects ApplyOnline – Application Form Builder and Manager: from n/a t... Read more
Affected Products : applyonline_-_application_form_builder_and_manager- Published: Jan. 02, 2025
- Modified: Jan. 02, 2025
- Vuln Type: Authorization
-
4.3
MEDIUMCVE-2023-46203
Missing Authorization vulnerability in JustCoded / Alex Prokopenko Just Custom Fields allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Just Custom Fields: from n/a through 3.3.2.... Read more
Affected Products :- Published: Jan. 02, 2025
- Modified: Jan. 02, 2025
- Vuln Type: Authorization