Latest CVE Feed
-
4.3
MEDIUMCVE-2024-10789
The WP User Profile Avatar plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.5. This is due to missing or incorrect nonce validation on the wpupa_user_admin() function. This makes it possible for un... Read more
Affected Products :- Published: Jan. 16, 2025
- Modified: Jan. 16, 2025
- Vuln Type: Cross-Site Request Forgery
-
4.3
MEDIUMCVE-2025-30894
Missing Authorization vulnerability in Epsiloncool WP Fast Total Search allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects WP Fast Total Search: from n/a through 1.79.262.... Read more
Affected Products :- Published: Mar. 27, 2025
- Modified: Mar. 27, 2025
- Vuln Type: Authorization
-
4.3
MEDIUMCVE-2023-0761
The Clock In Portal- Staff & Attendance Management WordPress plugin through 2.1 does not have CSRF check when deleting Staff members, which could allow attackers to make logged in admins delete arbitrary Staff via a CSRF attack... Read more
Affected Products : clock_in_portal-_staff_\&_attendance_management- Published: May. 15, 2023
- Modified: Jan. 24, 2025
-
4.3
MEDIUMCVE-2023-27481
Directus is a real-time API and App dashboard for managing SQL database content. In versions prior to 9.16.0 users with read access to the `password` field in `directus_users` can extract the argon2 password hashes by brute forcing the export functionalit... Read more
Affected Products : directus- Published: Mar. 07, 2023
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2024-8772
51l3nc3, member of the AXIS OS Bug Bounty Program, has found that the VAPIX API managedoverlayimages.cgi was vulnerable to a race condition attack allowing for an attacker to block access to the overlay configuration page in the web interface of the Axis ... Read more
Affected Products : axis_os- Published: Nov. 26, 2024
- Modified: Nov. 26, 2024
-
4.3
MEDIUMCVE-2012-4267
Cross-site scripting (XSS) vulnerability in user/register in Sockso 1.5 and earlier allows remote attackers to inject arbitrary web script or HTML via the name parameter.... Read more
Affected Products : sockso- Published: Aug. 13, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2012-1046
Cross-site scripting (XSS) vulnerability in TM1 Web in IBM Cognos TM1 9.5.2 FP1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2012-0696.... Read more
Affected Products : cognos_tm1- Published: Feb. 10, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2011-3309
Cisco Adaptive Security Appliances (ASA) 5500 series devices with software 8.2 through 8.4 process IKE requests despite a vpnclient mode configuration, which allows remote attackers to obtain potentially sensitive information by reading IKE responder traf... Read more
- Published: May. 02, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2022-40130
Auth. (subscriber+) Race Condition vulnerability in WP-Polls plugin <= 2.76.0 on WordPress.... Read more
Affected Products : wp-polls- Published: Nov. 18, 2022
- Modified: Feb. 20, 2025
-
4.3
MEDIUMCVE-2024-47168
Gradio is an open-source Python package designed for quick prototyping. This vulnerability involves data exposure due to the enable_monitoring flag not properly disabling monitoring when set to False. Even when monitoring is supposedly disabled, an attack... Read more
Affected Products : gradio- Published: Oct. 10, 2024
- Modified: Oct. 17, 2024
-
4.3
MEDIUMCVE-2024-0067
Marinus Pfund, member of the AXIS OS Bug Bounty Program, has found the VAPIX API ledlimit.cgi was vulnerable for path traversal attacks allowing to list folder/file names on the local file system of the Axis device. Axis has released patched AXIS OS ver... Read more
Affected Products : axis_os- Published: Sep. 10, 2024
- Modified: Nov. 08, 2024
-
4.3
MEDIUMCVE-2024-8801
The Happy Addons for Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.12.2 via the Content Switcher widget. This makes it possible for authenticated attackers, with Contributor-level ac... Read more
Affected Products : happy_addons_for_elementor- Published: Sep. 25, 2024
- Modified: Sep. 30, 2024
-
4.3
MEDIUMCVE-2024-3869
The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'woocommerce_json_search_coupons' function . This makes it possible for attackers with subscriber level access ... Read more
Affected Products : customer_reviews_for_woocommerce- Published: Apr. 16, 2024
- Modified: Feb. 05, 2025
-
4.3
MEDIUMCVE-2023-33182
Contacts app for Nextcloud easily syncs contacts from various devices with your Nextcloud and allows editing. The unsanitized SVG is converted to a JavaScript blob (in memory data) that the Avatar can't render. Due to this constellation the missing saniti... Read more
- Published: May. 30, 2023
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2015-2976
Multiple cross-site scripting (XSS) vulnerabilities in Research Artisan Lite before 1.18 allow remote attackers to inject arbitrary web script or HTML via (1) a crafted HTML document or (2) a crafted URL that is mishandled during access-log analysis.... Read more
Affected Products : research_artisan_lite- Published: Jul. 25, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2024-13601
The Majestic Support – The Leading-Edge Help Desk & Customer Support Plugin plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.0.5 via the 'exportusereraserequest' function due to missing validat... Read more
Affected Products : majestic_support- Published: Feb. 12, 2025
- Modified: Feb. 18, 2025
- Vuln Type: Authorization
-
4.3
MEDIUMCVE-2025-48925
The TeleMessage service through 2025-05-05 relies on the client side (e.g., the TM SGNL app) to do MD5 hashing, and then accepts the hash as the authentication credential.... Read more
Affected Products : telemessage- Published: May. 28, 2025
- Modified: Jul. 01, 2025
- Vuln Type: Authentication
-
4.3
MEDIUMCVE-2024-37543
Cross-Site Request Forgery (CSRF) vulnerability in Nitesh Singh Ultimate Auction allows Cross Site Request Forgery.This issue affects Ultimate Auction : from n/a through 4.2.5.... Read more
Affected Products : ultimate_wordpress_auction_plugin- Published: Jan. 02, 2025
- Modified: Jan. 02, 2025
-
4.3
MEDIUMCVE-2020-27831
A flaw was found in Red Hat Quay, where it does not properly protect the authorization token when authorizing email addresses for repository email notifications. This flaw allows an attacker to add email addresses they do not own to repository notificatio... Read more
Affected Products : quay- Published: May. 27, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2022-22384
IBM Security Verify Privilege On-Premises 11.5 could allow an attacker to modify messages returned from the server due to hazardous input validation. IBM X-Force ID: 221961. ... Read more
- Published: Oct. 17, 2023
- Modified: Nov. 21, 2024