Latest CVE Feed
-
4.3
MEDIUMCVE-2021-23266
An anonymous user can craft a URL with text that ends up in the log viewer as is. The text can then include textual messages to mislead the administrator.... Read more
- Published: May. 16, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2023-48714
Silverstripe Framework is the framework that forms the base of the Silverstripe content management system. Prior to versions 4.13.39 and 5.1.11, if a user should not be able to see a record, but that record can be added to a `GridField` using the `GridFie... Read more
Affected Products : framework- Published: Jan. 23, 2024
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2008-7035
Cross-site scripting (XSS) vulnerability in an unspecified component in Simple Machines phpRaider 1.0.7 allows remote attackers to inject arbitrary web script or HTML via the resistance field. NOTE: the provenance of this information is unknown; the deta... Read more
- Published: Aug. 24, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2023-5522
Mattermost Mobile fails to limit the maximum number of Markdown elements in a post allowing an attacker to send a post with hundreds of emojis to a channel and freeze the mobile app of users when viewing that particular channel. ... Read more
- Published: Oct. 17, 2023
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2021-25451
A PendingIntent hijacking in NetworkPolicyManagerService prior to SMR Sep-2021 Release 1 allows attackers to get IMSI data.... Read more
- Published: Sep. 09, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2024-30546
Cross-Site Request Forgery (CSRF) vulnerability in Pixelite Login With Ajax.This issue affects Login With Ajax: from n/a through 4.1. ... Read more
Affected Products :- Published: Apr. 15, 2024
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2025-1880
A vulnerability was found in i-Drive i11 and i12 up to 20250227. It has been classified as problematic. Affected is an unknown function of the component Device Pairing. The manipulation leads to authentication bypass by primary weakness. It is possible to... Read more
- Published: Mar. 03, 2025
- Modified: Mar. 03, 2025
- Vuln Type: Authentication
-
4.3
MEDIUMCVE-2021-43961
Sonatype Nexus Repository Manager 3.36.0 allows HTML Injection.... Read more
Affected Products : nexus_repository_manager- Published: Mar. 17, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2024-5770
The WP Force SSL & HTTPS SSL Redirect plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'ajax_save_setting' function in versions up to, and including, 1.66. This makes it possible for authenti... Read more
Affected Products : wp_force_ssl- Published: Jun. 08, 2024
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2023-2281
When archiving a team, Mattermost fails to sanitize the related Websocket event sent to currently connected clients. This allows the clients to see the name, display name, description, and other data about the archived team. ... Read more
- Published: Apr. 25, 2023
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2020-27358
An issue was discovered in REDCap 8.11.6 through 9.x before 10. The messenger's CSV feature (that allows users to export their conversation threads as CSV) allows non-privileged users to export one another's conversation threads by changing the thread_id ... Read more
- Published: Nov. 02, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2024-34809
Cross-Site Request Forgery (CSRF) vulnerability in Extend Themes EmpowerWP.This issue affects EmpowerWP: from n/a through 1.0.21.... Read more
Affected Products :- Published: May. 17, 2024
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2024-1053
The Event Tickets and Registration plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'email' action in all versions up to, and including, 5.8.1. This makes it possible for authenticated attackers, w... Read more
- Published: Feb. 22, 2024
- Modified: Feb. 07, 2025
-
4.3
MEDIUMCVE-2006-0779
Cross-site scripting (XSS) vulnerability in u2u.php in XMB Forums 1.9.3 and earlier allows remote attackers to inject arbitrary web script or HTML via the username parameter, as demonstrated using a URL-encoded iframe tag.... Read more
Affected Products : xmb- Published: Feb. 19, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2023-6493
The Depicter Slider – Responsive Image Slider, Video Slider & Post Slider plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.0.6. This is due to missing or incorrect nonce validation on the 'save' func... Read more
Affected Products : depicter_slider- Published: Jan. 05, 2024
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2024-11154
The PublishPress Revisions: Duplicate Posts, Submit, Approve and Schedule Content Changes plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.5.15 via the 'actAjaxRevisionDiffs' function. This makes... Read more
Affected Products :- Published: Nov. 20, 2024
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2024-11143
The Kognetiks Chatbot for WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.1.8. This is due to missing or incorrect nonce validation on the update_assistant, add_new_assistant, and delete_a... Read more
Affected Products : kognetiks_chatbot- Published: Nov. 13, 2024
- Modified: Nov. 18, 2024
-
4.3
MEDIUMCVE-2023-6625
The Product Enquiry for WooCommerce WordPress plugin before 3.1 does not have a CSRF check in place when deleting inquiries, which could allow attackers to make a logged in admin delete them via a CSRF attack... Read more
- Published: Jan. 22, 2024
- Modified: Jun. 20, 2025
-
4.3
MEDIUMCVE-2022-2080
The Sensei LMS WordPress plugin before 4.5.2 does not ensure that the sender of a private message is either the teacher or the original sender, allowing any authenticated user to send messages to arbitrary private conversation via a IDOR attack. Note: Att... Read more
Affected Products : sensei_lms- Published: Aug. 29, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2024-32447
Cross-Site Request Forgery (CSRF) vulnerability in AWP Classifieds Team AWP Classifieds.This issue affects AWP Classifieds: from n/a through 4.3.1. ... Read more
Affected Products : awp_classifieds- Published: Apr. 15, 2024
- Modified: Nov. 21, 2024