Latest CVE Feed
-
4.3
MEDIUMCVE-2019-14828
A vulnerability was found in Moodle affecting 3.7 to 3.7.1, 3.6 to 3.6.5, 3.5 to 3.5.7 and earlier unsupported versions, where users with the capability to create courses were assigned as a teacher in those courses, regardless of whether they had the capa... Read more
Affected Products : moodle- Published: Mar. 19, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2024-1214
The Easy Social Feed – Social Photos Gallery – Post Feed – Like Box plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 6.5.4. This is due to missing or incorrect nonce validation on the save_groups_list ... Read more
Affected Products : easy_social_feed- Published: Mar. 21, 2024
- Modified: Jan. 29, 2025
-
4.3
MEDIUMCVE-2016-10236
An information disclosure vulnerability in the Qualcomm USB driver. Product: Android. Versions: Android kernel. Android ID: A-33280689. References: QC-CR#1102418.... Read more
Affected Products : android- Published: Apr. 04, 2018
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2024-12263
The Child Theme Creator by Orbisius plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the cloud_delete() and cloud_update() functions in all versions up to, and including, 1.5.5. This makes it pos... Read more
Affected Products : child_theme_creator- Published: Dec. 12, 2024
- Modified: Dec. 12, 2024
-
4.3
MEDIUMCVE-2024-1995
The Smart Custom Fields plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the relational_posts_search() function in all versions up to, and including, 4.2.2. This makes it possible for authenticated att... Read more
Affected Products :- Published: Mar. 20, 2024
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2023-47727
IBM Cloud Pak for Security 1.10.0.0 through 1.10.11.0 and IBM QRadar Suite Software 1.10.12.0 through 1.10.20.0 could allow an authenticated user to modify dashboard parameters due to improper input validation. IBM X-Force ID: 272089.... Read more
- Published: May. 02, 2024
- Modified: Aug. 13, 2025
-
4.3
MEDIUMCVE-2021-28133
Zoom through 5.5.4 sometimes allows attackers to read private information on a participant's screen, even though the participant never attempted to share the private part of their screen. When a user shares a specific application window via the Share Scre... Read more
Affected Products : zoom- Published: Mar. 18, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2024-2384
The WooCommerce POS plugin for WordPress is vulnerable to information disclosure in all versions up to, and including, 1.4.11. This is due to the plugin not properly verifying the authentication and authorization of the current user This makes it possible... Read more
Affected Products :- Published: Mar. 20, 2024
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2024-0847
The 5280 Bootstrap Modal Contact Form plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0. This is due to missing or incorrect nonce validation in class-sbmm-list-table.php. This makes it possible for... Read more
Affected Products :- Published: May. 02, 2024
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2016-8784
Huawei CloudEngine 12800 V100R003C00, V100R003C10, V100R005C00, V100R005C10, V100R006C00 have a memory leak vulnerability. An unauthenticated attacker may send specific Label Distribution Protocol (LDP) packets to the devices. When the values of some para... Read more
- Published: Mar. 09, 2018
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2020-27290
In Hamilton Medical AG,T1-Ventillator versions 2.2.3 and prior, an information disclosure vulnerability in the ventilator allows attackers with physical access to the configuration interface's logs to get valid checksums for tampered configuration files.... Read more
- Published: Mar. 15, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2020-24740
An issue was discovered in Pluck 4.7.10-dev2. There is a CSRF vulnerability that can editpage via a /admin.php?action=editpage... Read more
Affected Products : pluck- Published: May. 18, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2024-34387
Missing Authorization vulnerability in AF themes WP Post Author.This issue affects WP Post Author: from n/a through 3.6.4. ... Read more
Affected Products : wp_post_author- Published: May. 06, 2024
- Modified: Feb. 06, 2025
-
4.3
MEDIUMCVE-2023-4941
The BEAR for WordPress is vulnerable to Missing Authorization in versions up to, and including, 1.1.3.3. This is due to a missing capability check on the woobe_bulkoperations_swap function. This makes it possible for authenticated attackers (subscriber or... Read more
Affected Products : bear_-_woocommerce_bulk_editor_and_products_manager_professional- Published: Oct. 20, 2023
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2024-12132
The WP Job Portal – A Complete Recruitment System for Company or Job Board website plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.2.4 due to missing validation on a user controlled key. This ... Read more
Affected Products : wp_job_portal- Published: Jan. 03, 2025
- Modified: Feb. 05, 2025
- Vuln Type: Authorization
-
4.3
MEDIUMCVE-2023-47778
Missing Authorization vulnerability in LuckyWP LuckyWP Scripts Control allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects LuckyWP Scripts Control: from n/a through 1.2.1.... Read more
Affected Products :- Published: Jan. 02, 2025
- Modified: Jan. 02, 2025
- Vuln Type: Authorization
-
4.3
MEDIUMCVE-2024-38732
Cross-Site Request Forgery (CSRF) vulnerability in VolThemes Patricia Blog allows Cross Site Request Forgery.This issue affects Patricia Blog: from n/a through 1.2.... Read more
Affected Products :- Published: Jan. 02, 2025
- Modified: Jan. 02, 2025
- Vuln Type: Cross-Site Request Forgery
-
4.3
MEDIUMCVE-2024-28148
An authenticated user could potentially access metadata for a datasource they are not authorized to view by submitting a targeted REST API request.This issue affects Apache Superset: before 3.1.2. Users are recommended to upgrade to version 3.1.2 or abov... Read more
Affected Products : superset- Published: May. 07, 2024
- Modified: Feb. 11, 2025
-
4.3
MEDIUMCVE-2024-12447
The Get Post Content Shortcode plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 0.4 via the 'post-content' shortcode due to missing validation on a user controlled key. This makes it possible for... Read more
Affected Products :- Published: Dec. 14, 2024
- Modified: Dec. 14, 2024
-
4.3
MEDIUMCVE-2022-0334
A flaw was found in Moodle in versions 3.11 to 3.11.4, 3.10 to 3.10.8, 3.9 to 3.9.11 and earlier unsupported versions. Insufficient capability checks could lead to users accessing their grade report for courses where they did not have the required gradere... Read more
Affected Products : moodle- Published: Jan. 25, 2022
- Modified: Nov. 21, 2024