Latest CVE Feed
-
4.3
MEDIUMCVE-2011-4540
Multiple cross-site scripting (XSS) vulnerabilities in AtMail Open (aka AtMail Open-Source edition) 1.04 allow remote attackers to inject arbitrary web script or HTML via the func parameter to (1) ldap.php or (2) search.php.... Read more
Affected Products : atmail_open- Published: Dec. 01, 2011
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2022-1251
The Ask me WordPress theme before 6.8.4 does not perform nonce checks when processing POST requests to the Edit Profile page, allowing an attacker to trick a user to change their profile information by sending a crafted request.... Read more
Affected Products : ask_me- Published: Aug. 22, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2024-4205
The Premium Addons for Elementor plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the get_template_content() function in all versions up to, and including, 4.10.31. This makes it possible for authentic... Read more
Affected Products : premium_addons_for_elementor- Published: May. 31, 2024
- Modified: Jan. 15, 2025
-
4.3
MEDIUMCVE-2024-45838
The goTenna Pro ATAK Plugin does not encrypt callsigns in messages. It is advised to not use sensitive information in callsigns when using this and previous versions of the plugin. Update to current plugin version which uses AES-256 encryption for call... Read more
- Published: Sep. 26, 2024
- Modified: Oct. 17, 2024
-
4.3
MEDIUMCVE-2024-37241
Cross-Site Request Forgery (CSRF) vulnerability in Automattic WP Job Manager - Resume Manager allows Cross Site Request Forgery.This issue affects WP Job Manager - Resume Manager: from n/a through 2.1.0.... Read more
Affected Products :- Published: Jan. 02, 2025
- Modified: Jan. 02, 2025
-
4.3
MEDIUMCVE-2024-43316
Cross-Site Request Forgery (CSRF) vulnerability in Checkout Plugins Stripe Payments For WooCommerce by Checkout.This issue affects Stripe Payments For WooCommerce by Checkout: from n/a through 1.9.1.... Read more
Affected Products : stripe_payments_for_woocommerce- Published: Aug. 26, 2024
- Modified: Sep. 12, 2024
-
4.3
MEDIUMCVE-2024-11444
The CLUEVO LMS, E-Learning Platform plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.13.2. This is due to missing or incorrect nonce validation on the cluevo_render_module_ui() function. This makes i... Read more
Affected Products : learning_management_system- Published: Dec. 06, 2024
- Modified: Dec. 06, 2024
-
4.3
MEDIUMCVE-2024-21761
An improper authorization vulnerability [CWE-285] in FortiPortal version 7.2.0, and versions 7.0.6 and below reports may allow a user to download other organizations reports via modification in the request payload.... Read more
Affected Products : fortiportal- Published: Mar. 12, 2024
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2023-22083
Vulnerability in the Oracle Enterprise Session Border Controller product of Oracle Communications (component: Web UI). Supported versions that are affected are 9.0-9.2. Easily exploitable vulnerability allows unauthenticated attacker with network access ... Read more
- Published: Oct. 17, 2023
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2022-2123
The WP Opt-in WordPress plugin through 1.4.1 is vulnerable to CSRF which allows changed plugin settings and can be used for sending spam emails.... Read more
Affected Products : wp_opt-in- Published: Jul. 11, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2024-29225
WRC-X3200GST3-B v1.25 and earlier, and WRC-G01-W v1.24 and earlier allow a network-adjacent unauthenticated attacker to obtain the configuration file containing sensitive information by sending a specially crafted request.... Read more
- Published: Apr. 04, 2024
- Modified: Mar. 27, 2025
-
4.3
MEDIUMCVE-2012-1103
emacs/notmuch-mua.el in Notmuch before 0.11.1, when using the Emacs interface, allows user-assisted remote attackers to read arbitrary files via crafted MML tags, which are not properly quoted in an email reply cna cause the files to be attached to the me... Read more
- Published: Sep. 25, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2024-1319
The Events Tickets Plus WordPress plugin before 5.9.1 does not prevent users with at least the contributor role from leaking the attendees list on any post type regardless of status. (e.g. draft, private, pending review, password-protected, and trashed po... Read more
Affected Products : event_tickets- Published: Mar. 04, 2024
- Modified: Apr. 24, 2025
-
4.3
MEDIUMCVE-2006-2181
Multiple cross-site scripting (XSS) vulnerabilities in Albinator 2.0.8 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) cid parameter to dlisting.php or (2) preloadSlideShow parameter to showpic.php.... Read more
Affected Products : albinator- Published: May. 04, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2024-34371
Missing Authorization vulnerability in Hamid Alinia – idehweb Login with phone number.This issue affects Login with phone number: from n/a through 1.7.18. ... Read more
Affected Products : login_with_phone_number- Published: May. 06, 2024
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2006-5457
Multiple cross-site scripting (XSS) vulnerabilities in the registration form in Casinosoft Casino Script (Masvet) 3.2 allow remote attackers to inject arbitrary web script or HTML via the (1) name or (2) surname field.... Read more
Affected Products : casino_script- Published: Oct. 23, 2006
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2009-2377
Buffer overflow in the Avax Vector ActiveX control in avPreview.ocx in AVAX-software Avax Vector ActiveX 1.3 allows remote attackers to cause a denial of service (application crash) via a long PrinterName property.... Read more
Affected Products : avax_vector_activex- Published: Jul. 08, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2024-3928
A vulnerability was found in Dromara open-capacity-platform 2.0.1. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /actuator/heapdump of the component auth-server. The manipulation leads to infor... Read more
Affected Products :- Published: Apr. 18, 2024
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2024-6709
The Sync Post With Other Site plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'sps_add_update_post' function in all versions up to, and including, 1.6. This makes it possible for authenticat... Read more
Affected Products : sync_post_with_other_site- Published: Aug. 03, 2024
- Modified: Mar. 01, 2025
-
4.3
MEDIUMCVE-2023-7048
The My Sticky Bar plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.6.6. This is due to missing or incorrect nonce validation in mystickymenu-contact-leads.php. This makes it possible for unauthentica... Read more
Affected Products : my_sticky_bar- Published: Jan. 11, 2024
- Modified: Jun. 03, 2025