Latest CVE Feed
-
4.3
MEDIUMCVE-2024-10677
The BTEV WordPress plugin through 2.0.2 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack... Read more
Affected Products : blue_trait_event_viewer- Published: May. 15, 2025
- Modified: Jun. 12, 2025
- Vuln Type: Cross-Site Request Forgery
-
4.3
MEDIUMCVE-2024-10634
The Nokaut Offers Box WordPress plugin through 1.4.0 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin reset the Nokaut Offers Box WordPress plugin through 1.4.0 via a CSRF attack... Read more
Affected Products : nokaut_offers_box- Published: May. 15, 2025
- Modified: Jun. 09, 2025
- Vuln Type: Cross-Site Request Forgery
-
4.3
MEDIUMCVE-2024-13560
The Subscriptions & Memberships for PayPal plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1.6. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthe... Read more
Affected Products :- Published: Feb. 26, 2025
- Modified: Feb. 26, 2025
- Vuln Type: Cross-Site Request Forgery
-
4.3
MEDIUMCVE-2025-46519
Missing Authorization vulnerability in Michael Revellin-Clerc Media Library Downloader allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Media Library Downloader: from n/a through 1.3.1.... Read more
Affected Products :- Published: Apr. 24, 2025
- Modified: Apr. 29, 2025
- Vuln Type: Authorization
-
4.3
MEDIUMCVE-2025-46513
Cross-Site Request Forgery (CSRF) vulnerability in Codebangers All in One Time Clock Lite allows Cross Site Request Forgery. This issue affects All in One Time Clock Lite: from n/a through 1.3.324.... Read more
Affected Products : all_in_one_time_clock_lite- Published: Apr. 24, 2025
- Modified: Apr. 29, 2025
- Vuln Type: Cross-Site Request Forgery
-
4.3
MEDIUMCVE-2023-7195
The WP-Reply Notify WordPress plugin through 1.1 does not have a CSRF check in place when updating its settings, which could allow attackers to make a logged-in admin change them via a CSRF attack.... Read more
Affected Products : wp-reply_notify- Published: May. 15, 2025
- Modified: Jun. 11, 2025
- Vuln Type: Cross-Site Request Forgery
-
4.3
MEDIUMCVE-2008-1560
Multiple cross-site scripting (XSS) vulnerabilities in Digiappz DigiDomain 2.2 allow remote attackers to inject arbitrary web script or HTML via the (1) domain parameter to lookup_result.asp, and the (2) word1 and (3) word2 parameters to suggest_result.as... Read more
Affected Products : digidomain- Published: Mar. 31, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2005-4670
Cross-site scripting (XSS) vulnerability in message.php in CityPost Automated Link Exchange (LNKX) allows remote attackers to inject arbitrary web script or HTML via the msg parameter.... Read more
Affected Products : php_lnkx- Published: Dec. 31, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2025-2527
Mattermost versions 10.5.x <= 10.5.2, 9.11.x <= 9.11.11 failed to properly verify a user's permissions when accessing groups, which allows an attacker to view group information via an API request.... Read more
Affected Products : mattermost_server- Published: May. 15, 2025
- Modified: Aug. 22, 2025
- Vuln Type: Authorization
-
4.3
MEDIUMCVE-2008-1722
Multiple integer overflows in (1) filter/image-png.c and (2) filter/image-zoom.c in CUPS 1.3 allow attackers to cause a denial of service (crash) and trigger memory corruption, as demonstrated via a crafted PNG image.... Read more
Affected Products : cups- Published: Apr. 10, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2008-1428
Multiple cross-site scripting (XSS) vulnerabilities in the Ubercart 5.x before 5.x-1.0-beta7 module for Drupal allow remote attackers to inject arbitrary web script or HTML via a text attribute value for a product.... Read more
- Published: Mar. 20, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2024-13716
The Forex Calculators plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the ajax_settings_callback() function in all versions up to, and including, 1.3.5. This makes it possible for authenticated ... Read more
Affected Products : forex_calculators- Published: Feb. 28, 2025
- Modified: Feb. 28, 2025
- Vuln Type: Authorization
-
4.3
MEDIUMCVE-2008-1212
Cross-site scripting (XSS) vulnerability in set_permissions.php in Podcast Generator 0.96.2 allows remote attackers to inject arbitrary web script or HTML via the scriptlang parameter. NOTE: the provenance of this information is unknown; the details are ... Read more
Affected Products : podcast_generator- Published: Mar. 08, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2025-4664
Insufficient policy enforcement in Loader in Google Chrome prior to 136.0.7103.113 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)... Read more
- Actively Exploited
- Published: May. 14, 2025
- Modified: Jun. 06, 2025
- Vuln Type: Information Disclosure
-
4.3
MEDIUMCVE-2008-1326
Cross-site scripting (XSS) vulnerability in search.php in Gallarific allows remote attackers to inject arbitrary web script or HTML via the query parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third p... Read more
Affected Products : gallarific- Published: Mar. 13, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2005-4732
Multiple cross-site scripting (XSS) vulnerabilities in index.php in Tux Racer TuxBank 0.7x and 0.8 allow remote attackers to inject arbitrary web script or HTML via the (1) name and (2) description parameters.... Read more
Affected Products : tuxbank- Published: Dec. 31, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2008-1698
Cross-site scripting (XSS) vulnerability in gallery.php in Simple Gallery 2.2 allows remote attackers to inject arbitrary web script or HTML via the album parameter to index.php. NOTE: the provenance of this information is unknown; the details are obtain... Read more
Affected Products : simple_gallery- Published: Apr. 08, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2008-1708
IBM solidDB 06.00.1018 and earlier does not validate a certain field that specifies an amount of memory to allocate, which allows remote attackers to cause a denial of service (daemon exit) via a packet with a large value in this field.... Read more
Affected Products : soliddb- Published: Apr. 09, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2024-25066
RSA Authentication Manager before 8.7 SP2 Patch 1 allows XML External Entity (XXE) attacks via a license file, resulting in attacker-controlled files being stored on the product's server. Data exfiltration cannot occur.... Read more
Affected Products : authentication_manager- Published: Feb. 17, 2025
- Modified: Feb. 17, 2025
- Vuln Type: XML External Entity
-
4.3
MEDIUMCVE-2024-13740
The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.9.4.2 via the pm_messenger_show_messages function due to missing validation on a user co... Read more
Affected Products : profilegrid- Published: Feb. 18, 2025
- Modified: Feb. 24, 2025
- Vuln Type: Authorization