Latest CVE Feed
-
4.3
MEDIUMCVE-2024-1690
The TeraWallet – Best WooCommerce Wallet System With Cashback Rewards, Partial Payment, Wallet Refunds plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the terawallet_export_user_search() function in a... Read more
Affected Products : terawallet- Published: Mar. 13, 2024
- Modified: Feb. 05, 2025
-
4.3
MEDIUMCVE-2020-10502
CSRF in admin/manage-comments.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to approve any comment, given the id, via a crafted request.... Read more
Affected Products : phpkb- Published: Mar. 12, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2024-1649
The Categorify plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the categorifyAjaxDeleteCategory function in all versions up to, and including, 1.0.7.4. This makes it possible for authenticated a... Read more
Affected Products : categorify- Published: Feb. 27, 2024
- Modified: Jan. 07, 2025
-
4.3
MEDIUMCVE-2024-47170
Agnai is an artificial-intelligence-agnostic multi-user, mult-bot roleplaying chat system. A vulnerability in versions prior to 1.0.330 permits attackers to read arbitrary JSON files at attacker-chosen locations on the server. This issue can lead to unaut... Read more
Affected Products : agnai- Published: Sep. 26, 2024
- Modified: Oct. 29, 2024
-
4.3
MEDIUMCVE-2020-6340
SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated PCX file received from untrusted sources which results in crashing of the application and becoming temporarily unavailable until the user restarts the application, this is cau... Read more
Affected Products : 3d_visual_enterprise_viewer- Published: Sep. 09, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2014-9230
Cross-site scripting (XSS) vulnerability in the administration console in the Enforce Server in Symantec Data Loss Prevention (DLP) before 12.5.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : data_loss_prevention- Published: Jun. 28, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2014-9352
Cross-site scripting (XSS) vulnerability in the mail administration login panel in Scalix Web Access 11.4.6.12377 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : web_access- Published: Dec. 09, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2013-3962
Cross-site scripting (XSS) vulnerability in Grandstream GXV3501, GXV3504, GXV3601, GXV3601HD/LL, GXV3611HD/LL, GXV3615W/P, GXV3651FHD, GXV3662HD, GXV3615WP_HD, GXV3500, and possibly other camera models before firmware 1.0.4.44, allows remote attackers to ... Read more
Affected Products : gxv_device_firmware gxv3500 gxv3501 gxv3504 gxv3601 gxv3601hd\/ll gxv3611hd\/ll gxv3615w\/p gxv3615wp_hd gxv3651fhd +1 more products- Published: Oct. 01, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2011-5192
Cross-site scripting (XSS) vulnerability in pretty-bar.php in Pretty Link Lite plugin before 1.5.6 for WordPress allows remote attackers to inject arbitrary web script or HTML via the slug parameter, a different vulnerability than CVE-2011-5191.... Read more
- Published: Sep. 23, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2024-7836
The Themify Builder plugin for WordPress is vulnerable to unauthorized post duplication due to missing checks on the duplicate_page_ajaxify function in all versions up to, and including, 7.6.1. This makes it possible for authenticated attackers, with Cont... Read more
- Published: Aug. 22, 2024
- Modified: Nov. 20, 2024
-
4.3
MEDIUMCVE-2013-4045
Cross-site scripting (XSS) vulnerability in the Portal application in IBM SPSS Collaboration and Deployment Services 4.2.1 before 4.2.1.3 IF3 and 5.0 before FP3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : spss_collaboration_and_deployment_services- Published: Dec. 21, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2010-3418
Multiple cross-site scripting (XSS) vulnerabilities in NetArt Media Car Portal 2.0 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) car_id parameter to index.php and (2) y parameter to include/images.php.... Read more
Affected Products : car_portal- Published: Sep. 16, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2008-0335
Cross-site scripting (XSS) vulnerability in BugTracker.NET before 2.7.2 allows remote attackers to inject arbitrary web script or HTML via an arbitrary custom text field.... Read more
Affected Products : bugtracker.net- Published: Jan. 17, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2015-6969
Cross-site scripting (XSS) vulnerability in js/2k11.min.js in the 2k11 theme in Serendipity before 2.0.2 allows remote attackers to inject arbitrary web script or HTML via a user name in a comment, which is not properly handled in a Reply link.... Read more
Affected Products : serendipity- Published: Sep. 16, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2013-7141
Cross-site scripting (XSS) vulnerability in Open-Xchange (OX) AppSuite 7.4.1 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors related to crafted "<%" tags.... Read more
Affected Products : open-xchange_appsuite- Published: Jan. 26, 2014
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2025-28940
Cross-Site Request Forgery (CSRF) vulnerability in arkapravamajumder Back To Top allows Cross Site Request Forgery. This issue affects Back To Top: from n/a through 2.0.... Read more
Affected Products :- Published: Mar. 11, 2025
- Modified: Mar. 11, 2025
- Vuln Type: Cross-Site Request Forgery
-
4.3
MEDIUMCVE-2023-4242
The FULL - Customer plugin for WordPress is vulnerable to Information Disclosure via the /health REST route in versions up to, and including, 2.2.3 due to improper authorization. This allows authenticated attackers with subscriber-level permissions and ab... Read more
Affected Products : full_-_customer- Published: Aug. 09, 2023
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2014-4946
Multiple cross-site scripting (XSS) vulnerabilities in Horde Internet Mail Program (IMP) before 6.1.8, as used in Horde Groupware Webmail Edition before 5.1.5, allow remote attackers to inject arbitrary web script or HTML via (1) unspecified flags or (2) ... Read more
- Published: Jul. 14, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2014-5345
Cross-site scripting (XSS) vulnerability in upgrade.php in the Disqus Comment System plugin before 2.76 for WordPress allows remote attackers to inject arbitrary web script or HTML via the step parameter.... Read more
Affected Products : disqus_comment_system- Published: Aug. 19, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2007-3842
Cross-site scripting (XSS) vulnerability in the 8e6 R3000 Enterprise Filter before 2.0.05 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. NOTE: this may be the same as CVE-2007-2970.... Read more
Affected Products : r3000_enterprise_filter- Published: Jul. 17, 2007
- Modified: Apr. 09, 2025