Latest CVE Feed
-
4.3
MEDIUMCVE-2022-2275
The WP Edit Menu WordPress plugin before 1.5.0 does not have CSRF in an AJAX action, which could allow attackers to make a logged in admin delete arbitrary posts/pages from the blog via a CSRF attack... Read more
Affected Products : wp_edit_menu- Published: Aug. 22, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2024-25270
An issue in Mirapolis LMS 4.6.XX allows authenticated users to exploit an Insecure Direct Object Reference (IDOR) vulnerability by manipulating the ID parameter and increment STEP parameter, leading to the exposure of sensitive user data.... Read more
Affected Products : lms- Published: Sep. 12, 2024
- Modified: Mar. 25, 2025
-
4.3
MEDIUMCVE-2024-37898
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. When a user has view but not edit right on a page in XWiki, that user can delete the page and replace it by a page with new content without having del... Read more
Affected Products : xwiki- Published: Jul. 31, 2024
- Modified: Sep. 06, 2024
-
4.3
MEDIUMCVE-2024-31402
Incorrect authorization vulnerability in Cybozu Garoon 5.0.0 to 5.15.2 allows a remote authenticated attacker to delete the data of Shared To-Dos.... Read more
Affected Products : garoon- Published: Jun. 11, 2024
- Modified: Mar. 28, 2025
-
4.3
MEDIUMCVE-2024-43397
Apollo is a configuration management system. A vulnerability exists in the synchronization configuration feature that allows users to craft specific requests to bypass permission checks. This exploit enables them to modify a namespace without the necessar... Read more
Affected Products : apollo- Published: Aug. 20, 2024
- Modified: Aug. 26, 2024
-
4.3
MEDIUMCVE-2024-35168
Missing Authorization vulnerability in Discourse WP Discourse.This issue affects WP Discourse: from n/a through 2.5.1.... Read more
Affected Products :- Published: Jun. 11, 2024
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2024-45193
An issue was discovered in Matrix libolm through 3.2.16. There is Ed25519 signature malleability due to lack of validation criteria (does not ensure that S < n). This refers to the libolm implementation of Olm. NOTE: This vulnerability only affects produc... Read more
Affected Products : olm- Published: Aug. 22, 2024
- Modified: Jun. 17, 2025
-
4.3
MEDIUMCVE-2022-1349
The WPQA Builder Plugin WordPress plugin before 5.2, used as a companion plugin for the Discy and Himer , does not validate that the value passed to the image_id parameter of the ajax action wpqa_remove_image belongs to the requesting user, allowing any u... Read more
Affected Products : wpqa_builder- Published: May. 16, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2024-45103
A valid, authenticated LXCA user may be able to unmanage an LXCA managed device in through the LXCA web interface without sufficient privileges.... Read more
- Published: Sep. 13, 2024
- Modified: Dec. 13, 2024
-
4.3
MEDIUMCVE-2022-39284
CodeIgniter is a PHP full-stack web framework. In versions prior to 4.2.7 setting `$secure` or `$httponly` value to `true` in `Config\Cookie` is not reflected in `set_cookie()` or `Response::setCookie()`. As a result cookie values are erroneously exposed ... Read more
Affected Products : codeigniter- Published: Oct. 06, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2023-51670
Missing Authorization vulnerability in FunnelKit FunnelKit Checkout.This issue affects FunnelKit Checkout: from n/a through 3.10.3.... Read more
Affected Products : funnelkit_checkout- Published: Jun. 12, 2024
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2024-4875
The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to unauthorized modification of data|loss of data due to a missing capability check on the 'ajax_dismiss' function in versions up to, and including, 2.5.2. This makes it possib... Read more
- Published: May. 21, 2024
- Modified: Jan. 28, 2025
-
4.3
MEDIUMCVE-2024-2023
The Folders and Folders Pro plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 3.0 in Folders and 3.0.2 in Folders Pro via the 'handle_folders_file_upload' function. This makes it possible for authenticated att... Read more
Affected Products : folders- Published: Jun. 14, 2024
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2022-42724
app/Controller/UsersController.php in MISP before 2.4.164 allows attackers to discover role names (this is information that only the site admin should have).... Read more
Affected Products : malware_information_sharing_platform- Published: Oct. 10, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2023-44234
Missing Authorization vulnerability in Bastianon Massimo WP GPX Map.This issue affects WP GPX Map: from n/a through 1.7.08.... Read more
Affected Products : wp_gpx_maps- Published: Jun. 12, 2024
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2024-5858
The AI Infographic Maker plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the qcld_openai_title_generate_desc AJAX action in all versions up to, and including, 4.7.4. This makes it possible for a... Read more
Affected Products :- Published: Jun. 15, 2024
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2024-5489
The Wbcom Designs – Custom Font Uploader plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the 'cfu_delete_customfont' function in all versions up to, and including, 2.3.4. This makes it possible for auth... Read more
Affected Products : custom_font_uploader- Published: Jun. 06, 2024
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2023-47788
Missing Authorization vulnerability in Automattic Jetpack.This issue affects Jetpack: from n/a before 12.7.... Read more
Affected Products : jetpack- Published: Jun. 19, 2024
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2016-1474
Cisco Prime Infrastructure 2.2(2) does not properly restrict use of IFRAME elements, which makes it easier for remote attackers to conduct clickjacking attacks and unspecified other attacks via a crafted web site, related to a "cross-frame scripting (XFS)... Read more
Affected Products : prime_infrastructure- Published: Aug. 08, 2016
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2022-1606
Incorrect privilege assignment in M-Files Server versions before 22.3.11164.0 and before 22.3.11237.1 allows user to read unmanaged objects.... Read more
Affected Products : m-files_server- Published: Nov. 30, 2022
- Modified: Nov. 21, 2024