Latest CVE Feed
-
4.3
MEDIUMCVE-2022-36075
Nextcloud files access control is a nextcloud app to manage access control for files. Users with limited access can see file names in certain cases where they do not have privilege to do so. This issue has been addressed and it is recommended that the Nex... Read more
- Published: Sep. 15, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2024-10689
The XLTab – Accordions and Tabs for Elementor Page Builder plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.4 via the 'XLTAB_INSERT_TPL' shortcode due to insufficient restrictions on which posts can be inc... Read more
Affected Products :- Published: Dec. 06, 2024
- Modified: Dec. 06, 2024
-
4.3
MEDIUMCVE-2021-34421
The Keybase Client for Android before version 5.8.0 and the Keybase Client for iOS before version 5.8.0 fails to properly remove exploded messages initiated by a user if the receiving user places the chat session in the background while the sending user e... Read more
Affected Products : keybase- Published: Nov. 11, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2024-31972
EnGenius ESR580 A8J-EMR5000 devices allow a remote attacker to conduct stored XSS attacks that could lead to arbitrary JavaScript code execution (under the context of the user's session) via the Wi-Fi SSID input fields. Web scripts embedded into the vulne... Read more
Affected Products :- Published: Oct. 30, 2024
- Modified: Nov. 01, 2024
-
4.3
MEDIUMCVE-2024-9705
The Ultimate Coming Soon & Maintenance plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'ucsm_update_template_name_lite' function in all versions up to, and including, 1.0.9. This makes it po... Read more
Affected Products : ultimate_coming_soon_\&_maintenance- Published: Dec. 06, 2024
- Modified: Jun. 05, 2025
-
4.3
MEDIUMCVE-2025-49286
Cross-Site Request Forgery (CSRF) vulnerability in WP Table Builder WP Table Builder allows Cross Site Request Forgery. This issue affects WP Table Builder: from n/a through 2.0.6.... Read more
Affected Products : wp_table_builder- Published: Jun. 06, 2025
- Modified: Jun. 06, 2025
- Vuln Type: Cross-Site Request Forgery
-
4.3
MEDIUMCVE-2024-13420
Multiple plugins and/or themes for WordPress are vulnerable to unauthorized access due to a missing capability check on several AJAX actions like 'gsf_reset_section_options', 'gsf_reset_section_options', 'gsf_create_preset_options' and more in various ver... Read more
- Published: May. 02, 2025
- Modified: May. 06, 2025
- Vuln Type: Authorization
-
4.3
MEDIUMCVE-2025-49238
Cross-Site Request Forgery (CSRF) vulnerability in everestthemes Everest Backup allows Cross Site Request Forgery. This issue affects Everest Backup: from n/a through 2.3.3.... Read more
Affected Products : everest_backup- Published: Jun. 06, 2025
- Modified: Jun. 06, 2025
- Vuln Type: Cross-Site Request Forgery
-
4.3
MEDIUMCVE-2021-42062
SAP ERP HCM Portugal does not perform necessary authorization checks for a report that reads the payroll data of employees in a certain area. Since the affected report only reads the payroll information, the attacker can neither modify any information nor... Read more
- Published: Nov. 10, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2024-43930
Cross-Site Request Forgery (CSRF) vulnerability in eyecix JobSearch allows Cross Site Request Forgery.This issue affects JobSearch: from n/a through 2.5.3.... Read more
Affected Products :- Published: Oct. 31, 2024
- Modified: Nov. 01, 2024
-
4.3
MEDIUMCVE-2021-44448
A vulnerability has been identified in JT Utilities (All versions < V13.0.3.0), JTTK (All versions < V11.0.3.0). JTTK library in affected products is vulnerable to an out of bounds read past the end of an allocated buffer when parsing JT files. An attacke... Read more
- Published: Dec. 14, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2022-38731
Qaelum DOSE 18.08 through 21.1 before 21.2 allows Directory Traversal via the loadimages name parameter. It allows a user to specify an arbitrary location on the server's filesystem from which to load an image. (Only images are displayed to the attacker. ... Read more
Affected Products : dose- Published: Feb. 16, 2023
- Modified: Mar. 19, 2025
-
4.3
MEDIUMCVE-2024-12110
The Gold Addons for Elementor plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the activate() and deactivate() functions in all versions up to, and including, 1.3.2. This makes it possible for au... Read more
Affected Products :- Published: Dec. 06, 2024
- Modified: Dec. 06, 2024
-
4.3
MEDIUMCVE-2024-8552
The Download Monitor plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the enable_shop() function in all versions up to, and including, 5.0.9. This makes it possible for authenticated attackers, w... Read more
Affected Products : download_monitor- Published: Sep. 26, 2024
- Modified: Oct. 02, 2024
-
4.3
MEDIUMCVE-2022-2382
The Product Slider for WooCommerce WordPress plugin before 2.5.7 has flawed CSRF checks and lack authorisation in some of its AJAX actions, allowing any authenticated users, such as subscriber to call them. One in particular could allow them to delete arb... Read more
Affected Products : product_slider_for_woocommerce- Published: Aug. 22, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2025-2168
The Ultimate Store Kit Elementor Addons, Woocommerce Builder, EDD Builder, Elementor Store Builder, Product Grid, Product Table, Woocommerce Slider plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.4.... Read more
Affected Products : ultimate_store_kit- Published: May. 01, 2025
- Modified: May. 12, 2025
- Vuln Type: Cross-Site Request Forgery
-
4.3
MEDIUMCVE-2024-38221
Microsoft Edge (Chromium-based) Spoofing Vulnerability... Read more
Affected Products : edge_chromium- Published: Sep. 19, 2024
- Modified: Sep. 23, 2024
-
4.3
MEDIUMCVE-2024-53707
Cross-Site Request Forgery (CSRF) vulnerability in Ahmet İmamoğlu Ahmeti Wp Güzel Sözler allows Cross Site Request Forgery.This issue affects Ahmeti Wp Güzel Sözler: from n/a through 4.0.... Read more
Affected Products :- Published: Dec. 02, 2024
- Modified: Dec. 02, 2024
-
4.3
MEDIUMCVE-2020-5355
The Dell Isilon OneFS versions 8.2.2 and earlier SSHD process improperly allows Transmission Control Protocol (TCP) and stream forwarding. This provides the remotesupport user and users with restricted shells more access than is intended.... Read more
Affected Products : emc_isilon_onefs- Published: Oct. 21, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2022-1793
The Private Files WordPress plugin through 0.40 is missing CSRF check when disabling the protection, which could allow attackers to make a logged in admin perform such action via a CSRF attack and make the blog public... Read more
Affected Products : private_files- Published: Jun. 13, 2022
- Modified: Nov. 21, 2024