Latest CVE Feed
-
4.3
MEDIUMCVE-2021-23953
If a user clicked into a specifically crafted PDF, the PDF reader could be confused into leaking cross-origin information, when said information is served as chunked data. This vulnerability affects Firefox < 85, Thunderbird < 78.7, and Firefox ESR < 78.7... Read more
- Published: Feb. 26, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2024-12340
The Animation Addons for Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.1.6 via the 'render' function in widgets/content-slider.php and widgets/tabs.php. This makes it possible for au... Read more
Affected Products :- Published: Dec. 18, 2024
- Modified: Dec. 18, 2024
-
4.3
MEDIUMCVE-2020-15668
A lock was missing when accessing a data structure and importing certificate information into the trust database. This vulnerability affects Firefox < 80 and Firefox for Android < 80.... Read more
Affected Products : firefox- Published: Oct. 01, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2024-13717
The Contact Form and Calls To Action by vcita plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the vcita_ajax_toggle_ae and vcita_ajax_toggle_contact functions in all versions up to, and includin... Read more
Affected Products : contact_form_and_calls_to_action_by_vcita- Published: Jan. 31, 2025
- Modified: Jan. 31, 2025
- Vuln Type: Authorization
-
4.3
MEDIUMCVE-2024-13737
The Motors – Car Dealer, Classifieds & Listing plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability checks on the motors_create_template and motors_delete_template functions in all versions up to, and includi... Read more
Affected Products : motors_-_car_dealer\,_classifieds_\&_listing- Published: Mar. 22, 2025
- Modified: Mar. 27, 2025
- Vuln Type: Authorization
-
4.3
MEDIUMCVE-2011-3686
Multiple cross-site scripting (XSS) vulnerabilities in myAddressBook.asp in Sonexis ConferenceManager 9.2.11.0 and 9.3.14.0 allow remote attackers to inject arbitrary web script or HTML via the (1) fname, (2) lname, (3) email_edit, (4) email, (5) email2, ... Read more
Affected Products : conferencemanager- Published: Sep. 27, 2011
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2010-5318
The password-reset feature in as/index.php in SweetRice CMS before 0.6.7.1 allows remote attackers to modify the administrator's password by specifying the administrator's e-mail address in the email parameter.... Read more
Affected Products : sweetrice- Published: Jan. 03, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2011-1537
Cross-site scripting (XSS) vulnerability in HP Proliant Support Pack (PSP) before 8.7 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : proliant_support_pack- Published: May. 03, 2011
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2011-3639
The mod_proxy module in the Apache HTTP Server 2.0.x through 2.0.64 and 2.2.x before 2.2.18, when the Revision 1179239 patch is in place, does not properly interact with use of (1) RewriteRule and (2) ProxyPassMatch pattern matches for configuration of a ... Read more
- Published: Nov. 30, 2011
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2024-13317
The ShipWorks Connector for Woocommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 5.2.5. This is due to missing or incorrect nonce validation on the 'shipworks-wordpress' page. This makes it pos... Read more
Affected Products :- Published: Jan. 18, 2025
- Modified: Jan. 18, 2025
- Vuln Type: Cross-Site Request Forgery
-
4.3
MEDIUMCVE-2009-5125
Comodo Internet Security before 3.9.95478.509 allows remote attackers to bypass malware detection in an RAR archive via an unspecified manipulation of the archive file format.... Read more
Affected Products : comodo_internet_security- Published: Aug. 26, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2011-1553
Use-after-free vulnerability in t1lib 5.1.2 and earlier, as used in Xpdf before 3.02pl6, teTeX, and other products, allows remote attackers to cause a denial of service (application crash) via a PDF document containing a crafted Type 1 font that triggers ... Read more
- Published: Mar. 31, 2011
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2024-12341
The Custom Skins Contact Form 7 plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'cf7cs_action_callback' function in all versions up to, and including, 1.0. This makes it possible for authent... Read more
Affected Products :- Published: Dec. 12, 2024
- Modified: Dec. 12, 2024
-
4.3
MEDIUMCVE-2011-1531
The webscan component in the Embedded Web Server (EWS) on the HP Photosmart D110 and B110; Photosmart Plus B210; Photosmart Premium C310, Fax All-in-One, and C510; and ENVY 100 D410 printers allows remote attackers to read documents on the scan surface vi... Read more
- Published: Apr. 15, 2011
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2010-3262
Cross-site scripting (XSS) vulnerability in Flock Browser 3.x before 3.0.0.4114 allows remote attackers to inject arbitrary web script or HTML via a crafted RSS feed.... Read more
Affected Products : flock- Published: Sep. 20, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2011-2313
Unspecified vulnerability in Oracle Solaris 10 allows local users to affect availability, related to ZFS, a different vulnerability than CVE-2011-2311.... Read more
- Published: Oct. 18, 2011
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2017-1283
IBM WebSphere MQ 8.0 and 9.0 could allow an authenticated user to cause a shared memory leak by MQ applications using dynamic queues, which can lead to lack of resources for other MQ applications. IBM X-Force ID: 125144.... Read more
- Published: Nov. 27, 2017
- Modified: Apr. 20, 2025
-
4.3
MEDIUMCVE-2010-5314
Cross-site scripting (XSS) vulnerability in controllers/home_controller.php in BEdita before 3.1 allows remote attackers to inject arbitrary web script or HTML via the searchstring parameter to news/index.... Read more
- Published: Jan. 03, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2010-3425
Cross-site scripting (XSS) vulnerability in UserControls/Popups/frmHelp.aspx in SmarterStats 5.3, 5.3.3819, and possibly other 5.3 versions, allows remote attackers to inject arbitrary web script or HTML via the url parameter.... Read more
Affected Products : smarterstats- Published: Sep. 16, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2020-18974
Buffer Overflow in Netwide Assembler (NASM) v2.15.xx allows attackers to cause a denial of service via 'crc64i' in the component 'nasmlib/crc64'. This issue is different than CVE-2019-7147.... Read more
Affected Products : netwide_assembler- Published: Aug. 25, 2021
- Modified: Nov. 21, 2024