Latest CVE Feed
-
4.3
MEDIUMCVE-2024-37543
Cross-Site Request Forgery (CSRF) vulnerability in Nitesh Singh Ultimate Auction allows Cross Site Request Forgery.This issue affects Ultimate Auction : from n/a through 4.2.5.... Read more
Affected Products : ultimate_wordpress_auction_plugin- Published: Jan. 02, 2025
- Modified: Jan. 02, 2025
-
4.3
MEDIUMCVE-2020-27290
In Hamilton Medical AG,T1-Ventillator versions 2.2.3 and prior, an information disclosure vulnerability in the ventilator allows attackers with physical access to the configuration interface's logs to get valid checksums for tampered configuration files.... Read more
- Published: Mar. 15, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2024-30536
Cross-Site Request Forgery (CSRF) vulnerability in WPFactory Slugs Manager.This issue affects Slugs Manager: from n/a through 2.6.7. ... Read more
Affected Products :- Published: Mar. 31, 2024
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2023-33998
Missing Authorization vulnerability in cybernetikz Easy Social Icons allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Easy Social Icons: from n/a through 3.2.5.... Read more
Affected Products : easy_social_icons- Published: Dec. 13, 2024
- Modified: Dec. 13, 2024
-
4.3
MEDIUMCVE-2021-33330
Liferay Portal 7.2.0 through 7.3.2, and Liferay DXP 7.2 before fix pack 9, allows access to Cross-origin resource sharing (CORS) protected resources if the user is only authenticated using the portal session authentication, which allows remote attackers t... Read more
- Published: Aug. 03, 2021
- Modified: May. 13, 2025
-
4.3
MEDIUMCVE-2024-33851
phpecc, as used in paragonie/phpecc before 2.0.1, has a branch-based timing leak in Point addition. (This is related to phpecc/phpecc on GitHub, and the Matyas Danter ECC library.)... Read more
Affected Products :- Published: Apr. 27, 2024
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2023-33995
Missing Authorization vulnerability in Photo Gallery Team Photo Gallery by 10Web allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Photo Gallery by 10Web: from n/a through 1.8.15.... Read more
Affected Products : photo_gallery- Published: Dec. 13, 2024
- Modified: Dec. 13, 2024
-
4.3
MEDIUMCVE-2024-3602
The Pop ups, Exit intent popups, email popups, banners, bars, countdowns and cart savers – Promolayer plugin for WordPress is vulnerable to unauthorized plugin settings update due to a missing capability check on the disconnect_promolayer function in all ... Read more
Affected Products : popup_builder- Published: Jun. 20, 2024
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2023-50850
Missing Authorization vulnerability in Woo WooCommerce Subscriptions allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WooCommerce Subscriptions: from n/a before 5.8.0.... Read more
Affected Products :- Published: Dec. 31, 2024
- Modified: Dec. 31, 2024
-
4.3
MEDIUMCVE-2024-4873
The Replace Image plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.1.10 via the image replacement functionality due to missing validation on a user controlled key. This makes it possible for au... Read more
Affected Products :- Published: Jun. 19, 2024
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2024-56229
Cross-Site Request Forgery (CSRF) vulnerability in Searchiq SearchIQ.This issue affects SearchIQ: from n/a through 4.6.... Read more
Affected Products : searchiq- Published: Dec. 31, 2024
- Modified: Jun. 05, 2025
-
4.3
MEDIUMCVE-2021-21493
When a user opens manipulated Graphics Interchange Format (.GIF) format files received from untrusted sources in SAP 3D Visual Enterprise Viewer version 9, the application crashes and becomes temporarily unavailable to the user until restart of the applic... Read more
Affected Products : 3d_visual_enterprise_viewer- Published: Mar. 09, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2024-30518
Cross-Site Request Forgery (CSRF) vulnerability in ThemeLocation Custom WooCommerce Checkout Fields Editor.This issue affects Custom WooCommerce Checkout Fields Editor: from n/a through 1.3.0. ... Read more
Affected Products : custom_woocommerce_checkout_fields_editor- Published: Mar. 29, 2024
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2023-34387
Missing Authorization vulnerability in Constant Contact Constant Contact Forms allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Constant Contact Forms: from n/a through 2.0.3.... Read more
Affected Products : constant_contact_forms- Published: Dec. 13, 2024
- Modified: Dec. 13, 2024
-
4.3
MEDIUMCVE-2024-4541
The Custom Product List Table plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.0.0. This is due to missing or incorrect nonce validation when modifying products. This makes it possible for unauthenti... Read more
Affected Products :- Published: Jun. 19, 2024
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2018-25007
Missing check in UIDL request handler in com.vaadin:flow-server versions 1.0.0 through 1.0.5 (Vaadin 10.0.0 through 10.0.7, and 11.0.0 through 11.0.2) allows attacker to update element property values via crafted synchronization message.... Read more
- Published: Apr. 23, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2024-31859
Mattermost versions 9.5.x <= 9.5.3, 9.6.x <= 9.6.1 and 8.1.x <= 8.1.12 fail to perform proper authorization checks which allows a member running a playbook in an existing channel to be promoted to a channel admin... Read more
- Published: May. 26, 2024
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2024-30638
Tenda F1202 v1.2.0.20(408) has a stack overflow vulnerability via the entrys parameter in the fromAddressNat function.... Read more
- Published: Mar. 29, 2024
- Modified: Mar. 13, 2025
-
4.3
MEDIUMCVE-2024-56255
Missing Authorization vulnerability in AyeCode AyeCode Connect allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects AyeCode Connect: from n/a through 1.3.8.... Read more
Affected Products :- Published: Jan. 02, 2025
- Modified: Jan. 02, 2025
- Vuln Type: Authorization
-
4.3
MEDIUMCVE-2006-2000
Cross-site scripting (XSS) vulnerability in /lms/a2z.jsp in logMethods 0.9 allows remote attackers to inject arbitrary web script or HTML via the kwd parameter.... Read more
Affected Products : logmethods- Published: Apr. 25, 2006
- Modified: Apr. 03, 2025