Latest CVE Feed
-
4.3
MEDIUMCVE-2015-4725
Cross-site scripting (XSS) vulnerability in forgot.php in AudioShare 2.0.2 allows remote attackers to inject arbitrary web script or HTML via the email parameter.... Read more
Affected Products : audioshare- Published: Jun. 23, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2024-33925
Missing Authorization vulnerability in Adrian Mörchen Embed Google Fonts.This issue affects Embed Google Fonts: from n/a through 3.1.0. ... Read more
Affected Products :- Published: May. 03, 2024
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2024-40723
The specific API in HWATAIServiSign Windows Version from CHANGING Information Technology does not properly validate the length of server-side inputs. When a user visits a spoofed website, unauthenticated remote attackers can cause a stack-based buffer ove... Read more
Affected Products : hwatai_servisign- Published: Aug. 02, 2024
- Modified: Aug. 09, 2024
-
4.3
MEDIUMCVE-2025-9228
MiR software versions prior to version 3.0.0 have insufficient authorization controls when creating text notes, allowing low-privilege users to create notes which are intended only for administrative users.... Read more
Affected Products :- Published: Aug. 20, 2025
- Modified: Aug. 20, 2025
- Vuln Type: Authorization
-
4.3
MEDIUMCVE-2024-12414
The Themify Store Locator plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1.9. This is due to missing or incorrect nonce validation on the setting_page() function. This makes it possible for unauthe... Read more
Affected Products : store_locator- Published: Dec. 13, 2024
- Modified: May. 06, 2025
-
4.3
MEDIUMCVE-2024-9758
Tungsten Automation Power PDF AcroForm Annotation Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Tungsten Automation Power PDF. User intera... Read more
Affected Products : power_pdf- Published: Nov. 22, 2024
- Modified: Nov. 26, 2024
-
4.3
MEDIUMCVE-2014-1906
Multiple cross-site scripting (XSS) vulnerabilities in the VideoWhisper Live Streaming Integration plugin before 4.29.5 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) m parameter to lb_status.php; (2) msg parameter... Read more
- Published: Mar. 06, 2014
- Modified: Aug. 20, 2025
-
4.3
MEDIUMCVE-2023-5314
The WP EXtra plugin for WordPress is vulnerable to unauthorized access to restricted functionality due to a missing capability check on the 'test-email' section of the register() function in versions up to, and including, 6.2. This makes it possible for a... Read more
Affected Products : wp_extra- Published: Nov. 22, 2023
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2010-0349
Cross-site scripting (XSS) vulnerability in C3 Corp. WebCalenderC3 0.32 and earlier allows remote attackers to inject arbitrary web script or HTML via unknown vectors. NOTE: this issue could not be reproduced by the vendor, but a patch was provided anywa... Read more
Affected Products : webcalenderc3- Published: Jan. 15, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2024-5665
The Login/Signup Popup ( Inline Form + Woocommerce ) plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the ‘export_settings’ function in versions 2.7.1 to 2.7.2. This makes it possible for authenticated... Read more
Affected Products : login\/signup_popup- Published: Jun. 06, 2024
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2025-50897
A vulnerability exists in riscv-boom SonicBOOM 1.2 (BOOMv1.2) processor implementation, where valid virtual-to-physical address translations configured with write permissions (PTE_W) in SV39 mode may incorrectly trigger a Store/AMO access fault during sto... Read more
Affected Products :- Published: Aug. 19, 2025
- Modified: Aug. 20, 2025
- Vuln Type: Misconfiguration
-
4.3
MEDIUMCVE-2021-32787
Sourcegraph is a code search and navigation engine. Sourcegraph before version 3.30.0 has two potential information leaks. The site-admin area can be accessed by regular users and all information and features are properly protected except for daily usage ... Read more
Affected Products : sourcegraph- Published: Aug. 02, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2025-0807
The CITS Support svg, webp Media and TTF,OTF File Upload, Use Custom Fonts plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.2. This is due to missing or incorrect nonce validation on the cits_setting... Read more
Affected Products :- Published: Mar. 22, 2025
- Modified: Mar. 22, 2025
- Vuln Type: Cross-Site Request Forgery
-
4.3
MEDIUMCVE-2021-38372
In KDE Trojita 0.7, man-in-the-middle attackers can create new folders because untagged responses from an IMAP server are accepted before STARTTLS.... Read more
- Published: Aug. 10, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2024-24710
Missing Authorization vulnerability in SlickRemix Feed Them Social.This issue affects Feed Them Social: from n/a through 4.2.0. ... Read more
Affected Products : feed_them_social- Published: May. 03, 2024
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2015-1562
Multiple cross-site scripting (XSS) vulnerabilities in Saurus CMS 4.7.0 allow remote attackers to inject arbitrary web script or HTML via the (1) search parameter to admin/user_management.php, (2) data_search parameter to /admin/profile_data.php, or (3) f... Read more
Affected Products : saurus_cms- Published: Feb. 09, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2011-3853
Cross-site scripting (XSS) vulnerability in the Hybrid theme before 0.10 for WordPress allows remote attackers to inject arbitrary web script or HTML via the cpage parameter.... Read more
- Published: Sep. 28, 2011
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2024-5770
The WP Force SSL & HTTPS SSL Redirect plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'ajax_save_setting' function in versions up to, and including, 1.66. This makes it possible for authenti... Read more
Affected Products : wp_force_ssl- Published: Jun. 08, 2024
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2014-4331
Cross-site scripting (XSS) vulnerability in admin/viewer.php in OctavoCMS allows remote attackers to inject arbitrary web script or HTML via the src parameter.... Read more
Affected Products : octavocms- Published: Jul. 19, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2023-3957
The ACF Photo Gallery Field plugin for WordPress is vulnerable to unauthorized modification of data due to an insufficient restriction on the 'apg_profile_update' function in versions up to, and including, 1.9. This makes it possible for authenticated att... Read more
Affected Products : acf_photo_gallery_field- Published: Jul. 27, 2023
- Modified: Nov. 21, 2024