Latest CVE Feed
-
4.3
MEDIUMCVE-2024-37254
Missing Authorization vulnerability in mndpsingh287 File Manager allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects File Manager: from n/a through 7.2.7.... Read more
Affected Products : file_manager- Published: Nov. 01, 2024
- Modified: Nov. 01, 2024
-
4.3
MEDIUMCVE-2023-5902
Cross-Site Request Forgery (CSRF) in GitHub repository pkp/pkp-lib prior to 3.3.0-16.... Read more
Affected Products : pkp_web_application_library- Published: Nov. 07, 2023
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2008-1368
CRLF injection vulnerability in Microsoft Internet Explorer 5 and 6 allows remote attackers to execute arbitrary FTP commands via an ftp:// URL that contains a URL-encoded CRLF (%0D%0A) before the FTP command, which causes the commands to be inserted into... Read more
Affected Products : internet_explorer- Published: Mar. 18, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2024-3072
The ACF Front End Editor plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the update_texts() function in all versions up to, and including, 2.0.2. This makes it possible for authenticated attacke... Read more
Affected Products :- Published: Apr. 30, 2024
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2025-30542
Cross-Site Request Forgery (CSRF) vulnerability in wpsolutions SoundCloud Ultimate allows Cross Site Request Forgery. This issue affects SoundCloud Ultimate: from n/a through 1.5.... Read more
Affected Products :- Published: Mar. 24, 2025
- Modified: Mar. 27, 2025
- Vuln Type: Cross-Site Request Forgery
-
4.3
MEDIUMCVE-2023-51380
An incorrect authorization vulnerability was identified in GitHub Enterprise Server that allowed issue comments to be read with an improperly scoped token. This vulnerability affected all versions of GitHub Enterprise Server since 3.7 and was fixed in ver... Read more
Affected Products : enterprise_server- Published: Dec. 21, 2023
- Modified: Dec. 16, 2024
-
4.3
MEDIUMCVE-2024-8476
The Easy PayPal Events plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.2.1. This is due to missing or incorrect nonce validation on the wpeevent_plugin_buttons() function. This makes it possible for... Read more
Affected Products : easy_paypal_events- Published: Sep. 25, 2024
- Modified: Oct. 02, 2024
-
4.3
MEDIUMCVE-2024-54357
Cross-Site Request Forgery (CSRF) vulnerability in ThemeFusion Avada.This issue affects Avada: from n/a through 7.11.10.... Read more
Affected Products : avada- Published: Dec. 16, 2024
- Modified: Apr. 14, 2025
-
4.3
MEDIUMCVE-2024-3243
The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to unauthorized email sending due to a missing capability check on the send_test_email() function in all versions up to, and including, 5.46.0. This makes it possible for authenticate... Read more
Affected Products : customer_reviews_for_woocommerce- Published: Apr. 16, 2024
- Modified: Feb. 05, 2025
-
4.3
MEDIUMCVE-2014-0337
Cross-site scripting (XSS) vulnerability in the web interface on Huawei Echo Life HG8247 routers with software before V100R006C00SPC127 allows remote attackers to inject arbitrary web script or HTML via an invalid TELNET connection attempt with a crafted ... Read more
- Published: Apr. 05, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2024-3869
The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'woocommerce_json_search_coupons' function . This makes it possible for attackers with subscriber level access ... Read more
Affected Products : customer_reviews_for_woocommerce- Published: Apr. 16, 2024
- Modified: Feb. 05, 2025
-
4.3
MEDIUMCVE-2024-34803
Missing Authorization vulnerability in Fastly.This issue affects Fastly: from n/a through 1.2.25.... Read more
Affected Products :- Published: Jun. 03, 2024
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2023-50871
In JetBrains YouTrack before 2023.3.22268 authorization check for inline comments inside thread replies was missed... Read more
Affected Products : youtrack- Published: Dec. 15, 2023
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2023-4935
The BEAR for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.3.3. This is due to missing or incorrect nonce validation on the create_profile function. This makes it possible for unauthenticated attackers to crea... Read more
Affected Products : bear_-_woocommerce_bulk_editor_and_products_manager_professional- Published: Oct. 20, 2023
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2024-10216
The WP User Manager – User Profile Builder & Membership plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'add_sidebar' and 'remove_sidebar' functions in all versions up to, and including, 2.9... Read more
Affected Products : wp_user_manager- Published: Nov. 23, 2024
- Modified: Feb. 07, 2025
-
4.3
MEDIUMCVE-2022-1960
The MyCSS WordPress plugin through 1.1 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack... Read more
Affected Products : mycss- Published: Jun. 27, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2024-54127
This vulnerability exists in the TP-Link Archer C50 due to presence of terminal access on a serial interface without proper access control. An attacker with physical access could exploit this by accessing the UART shell on the vulnerable device. Successfu... Read more
Affected Products :- Published: Dec. 05, 2024
- Modified: Dec. 05, 2024
-
4.3
MEDIUMCVE-2022-42130
The Dynamic Data Mapping module in Liferay Portal 7.1.0 through 7.4.3.4, and Liferay DXP 7.1 before fix pack 27, 7.2 before fix pack 19, 7.3 before update 4, and 7.4 GA does not properly check permission of form entries, which allows remote authenticated ... Read more
- Published: Nov. 15, 2022
- Modified: Apr. 30, 2025
-
4.3
MEDIUMCVE-2024-32450
Cross-Site Request Forgery (CSRF) vulnerability in MagePeople Team WpTravelly.This issue affects WpTravelly: from n/a through 1.6.0. ... Read more
Affected Products :- Published: Apr. 15, 2024
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2024-43269
Cross-Site Request Forgery (CSRF) vulnerability in WPBackItUp Backup and Restore WordPress.This issue affects Backup and Restore WordPress: from n/a through 1.50.... Read more
Affected Products : backup_and_restore_wordpress- Published: Aug. 26, 2024
- Modified: Sep. 12, 2024