Latest CVE Feed
-
4.3
MEDIUMCVE-2023-5900
Cross-Site Request Forgery in GitHub repository pkp/pkp-lib prior to 3.3.0-16. ... Read more
Affected Products : pkp_web_application_library- Published: Nov. 07, 2023
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2022-36048
Zulip is an open-source team collaboration tool with topic-based threading that combines email and chat. When displaying messages with embedded remote images, Zulip normally loads the image preview via a go-camo proxy server. However, an attacker who can ... Read more
- Published: Aug. 31, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2025-1880
A vulnerability was found in i-Drive i11 and i12 up to 20250227. It has been classified as problematic. Affected is an unknown function of the component Device Pairing. The manipulation leads to authentication bypass by primary weakness. It is possible to... Read more
- Published: Mar. 03, 2025
- Modified: Mar. 03, 2025
- Vuln Type: Authentication
-
4.3
MEDIUMCVE-2024-31385
Cross-Site Request Forgery (CSRF) vulnerability in Reservation Diary ReDi Restaurant Reservation.This issue affects ReDi Restaurant Reservation: from n/a through 24.0128. ... Read more
- Published: Apr. 15, 2024
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2023-6493
The Depicter Slider – Responsive Image Slider, Video Slider & Post Slider plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.0.6. This is due to missing or incorrect nonce validation on the 'save' func... Read more
Affected Products : depicter_slider- Published: Jan. 05, 2024
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2022-3962
A content spoofing vulnerability was found in Kiali. It was discovered that Kiali does not implement error handling when the page or endpoint being accessed cannot be found. This issue allows an attacker to perform arbitrary text injection when an error r... Read more
- Published: Sep. 23, 2023
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2022-21179
Cross-site request forgery (CSRF) vulnerability in EC-CUBE plugin 'Mail Magazine Management Plugin' ver4.0.0 to 4.1.1 (for EC-CUBE 4 series) and ver1.0.0 to 1.0.4 (for EC-CUBE 3 series) allows a remote unauthenticated attacker to hijack the authentication... Read more
Affected Products : e-mail_newsletter_management- Published: Feb. 24, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2022-43698
OX App Suite before 7.10.6-rev30 allows SSRF because changing a POP3 account disregards the deny-list.... Read more
Affected Products : ox_app_suite- Published: Apr. 15, 2023
- Modified: Feb. 06, 2025
-
4.3
MEDIUMCVE-2023-6625
The Product Enquiry for WooCommerce WordPress plugin before 3.1 does not have a CSRF check in place when deleting inquiries, which could allow attackers to make a logged in admin delete them via a CSRF attack... Read more
- Published: Jan. 22, 2024
- Modified: Jun. 20, 2025
-
4.3
MEDIUMCVE-2024-32447
Cross-Site Request Forgery (CSRF) vulnerability in AWP Classifieds Team AWP Classifieds.This issue affects AWP Classifieds: from n/a through 4.3.1. ... Read more
Affected Products : awp_classifieds- Published: Apr. 15, 2024
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2024-4233
Missing Authorization vulnerability in Tyche Softwares Print Invoice & Delivery Notes for WooCommerce, Tyche Softwares Arconix Shortcodes, Tyche Softwares Arconix FAQ.This issue affects Print Invoice & Delivery Notes for WooCommerce: from n/a through 4.8.... Read more
- Published: May. 08, 2024
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2014-4540
Cross-site scripting (XSS) vulnerability in oleggo-twitter/twitter_login_form.php in the Oleggo LiveStream plugin 0.2.6 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the msg parameter.... Read more
Affected Products : oleggo_livestream- Published: Jul. 02, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2012-1729
Unspecified vulnerability in the Hyperion BI+ component in Oracle Hyperion 11.1.1.3 and earlier allows remote attackers to affect integrity via unknown vectors related to UI and Visualization.... Read more
Affected Products : hyperion- Published: Jul. 17, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2022-0164
The Coming soon and Maintenance mode WordPress plugin before 3.5.3 does not have authorisation and CSRF checks in its coming_soon_send_mail AJAX action, allowing any authenticated users, with a role as low as subscriber to send arbitrary emails to all sub... Read more
Affected Products : coming_soon_and_maintenance_mode- Published: Feb. 21, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2024-11918
The Image Alt Text plugin for WordPress is vulnerable to unauthorized modification of data| due to a missing capability check on the iat_add_alt_txt_action and iat_update_alt_txt_action AJAX actions in all versions up to, and including, 2.0.0. This makes ... Read more
Affected Products :- Published: Nov. 28, 2024
- Modified: Nov. 28, 2024
-
4.3
MEDIUMCVE-2022-22108
In Daybyday CRM, versions 2.0.0 through 2.2.0 are vulnerable to Missing Authorization. An attacker that has the lowest privileges account (employee type user), can view the absences of all users in the system including administrators. This type of user is... Read more
- Published: Jan. 05, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2014-4569
Cross-site scripting (XSS) vulnerability in ls/vv_login.php in the VideoWhisper Live Streaming Integration plugin 4.27.2 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the room_name parameter.... Read more
- Published: Jul. 01, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2023-7019
The LightStart – Maintenance Mode, Coming Soon and Landing Page Builder plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the insert_template function in all versions up to, and including, 2.6.8. ... Read more
Affected Products : lightstart- Published: Jan. 11, 2024
- Modified: Jun. 03, 2025
-
4.3
MEDIUMCVE-2023-50900
Cross-Site Request Forgery (CSRF) vulnerability in Averta Master Slider.This issue affects Master Slider: from n/a through 3.9.10.... Read more
Affected Products : master_slider- Published: Jun. 19, 2024
- Modified: May. 27, 2025
-
4.3
MEDIUMCVE-2008-7035
Cross-site scripting (XSS) vulnerability in an unspecified component in Simple Machines phpRaider 1.0.7 allows remote attackers to inject arbitrary web script or HTML via the resistance field. NOTE: the provenance of this information is unknown; the deta... Read more
- Published: Aug. 24, 2009
- Modified: Apr. 09, 2025