Latest CVE Feed
-
4.3
MEDIUMCVE-2024-2033
The Video Conferencing with Zoom plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.4.5 via the get_assign_host_id AJAX action. This makes it possible for authenticated attackers, with subscriber a... Read more
Affected Products : video_conferencing_with_zoom- Published: Apr. 09, 2024
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2024-30588
Tenda FH1202 v1.2.0.14(408) has a stack overflow vulnerability in the schedStartTime parameter of the setSchedWifi function.... Read more
- Published: Mar. 28, 2024
- Modified: Mar. 13, 2025
-
4.3
MEDIUMCVE-2024-5639
The User Profile Picture plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.6.1 via the 'rest_api_change_profile_image' function due to missing validation on a user controlled key. This makes it ... Read more
Affected Products : user_profile_picture- Published: Jun. 21, 2024
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2024-7892
The adstxt Plugin WordPress plugin through 1.0.0 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack... Read more
Affected Products : adstxt- Published: Sep. 25, 2024
- Modified: Oct. 07, 2024
-
4.3
MEDIUMCVE-2024-34807
Cross-Site Request Forgery (CSRF) vulnerability in CodeBard Fast Custom Social Share by CodeBard.This issue affects Fast Custom Social Share by CodeBard: from n/a through 1.1.2.... Read more
Affected Products : fast_custom_social_share- Published: May. 17, 2024
- Modified: Mar. 11, 2025
-
4.3
MEDIUMCVE-2023-30476
Missing Authorization vulnerability in Sparkle Themes Blogger Buzz allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Blogger Buzz: from n/a through 1.2.2.... Read more
Affected Products :- Published: Dec. 09, 2024
- Modified: Dec. 09, 2024
-
4.3
MEDIUMCVE-2015-5625
Cross-site scripting (XSS) vulnerability in OpenDocMan before 1.3.4 allows remote attackers to inject arbitrary web script or HTML via the redirection parameter.... Read more
Affected Products : opendocman- Published: Sep. 07, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2024-3410
The DN Footer Contacts WordPress plugin before 1.6.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallo... Read more
Affected Products : footer_contacts_bar- Published: Jul. 09, 2024
- Modified: May. 21, 2025
-
4.3
MEDIUMCVE-2024-11911
The WP Crowdfunding plugin for WordPress is vulnerable to unauthorized plugin installation due to a missing capability check on the install_woocommerce_plugin() function action in all versions up to, and including, 2.1.12. This makes it possible for authe... Read more
Affected Products : wp_crowdfunding- Published: Dec. 13, 2024
- Modified: Feb. 11, 2025
-
4.3
MEDIUMCVE-2014-1607
Cross-site scripting (XSS) vulnerability in the EventCalendar module for Drupal 7.14 allows remote attackers to inject arbitrary web script or HTML via the year parameter to eventcalander/. NOTE: this issue has been disputed by the Drupal Security Team; i... Read more
Affected Products : drupal- Published: Jan. 26, 2014
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2012-5057
CRLF injection vulnerability in ownCloud Server before 4.0.8 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via the url path parameter.... Read more
- Published: Jun. 04, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2024-8427
The Frontend Post Submission Manager Lite – Frontend Posting WordPress Plugin plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the save_global_settings and process_form_edit functions in all vers... Read more
Affected Products : frontend_post_submission_manager- Published: Sep. 06, 2024
- Modified: Sep. 11, 2024
-
4.3
MEDIUMCVE-2014-0337
Cross-site scripting (XSS) vulnerability in the web interface on Huawei Echo Life HG8247 routers with software before V100R006C00SPC127 allows remote attackers to inject arbitrary web script or HTML via an invalid TELNET connection attempt with a crafted ... Read more
- Published: Apr. 05, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2006-4856
Multiple cross-site scripting (XSS) vulnerabilities in Roller WebLogger 2.3 allow remote attackers to inject arbitrary web script or HTML via the (1) name, (2) email, or (3) url parameters; (4) certain content parameters in the preview method; or (5) the ... Read more
Affected Products : roller_weblogger- Published: Sep. 19, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2022-4549
The Tickera WordPress plugin before 3.5.1.0 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged-in admin change them via a CSRF attack.... Read more
Affected Products : tickera- Published: Jan. 16, 2023
- Modified: Apr. 04, 2025
-
4.3
MEDIUMCVE-2013-4595
The Secure Pages module 6.x-2.x before 6.x-2.0 for Drupal does not properly match URLs, which causes HTTP to be used instead of HTTPS and makes it easier for remote attackers to obtain sensitive information via a crafted web page.... Read more
Affected Products : secure_pages- Published: Jun. 09, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2019-4743
IBM Financial Transaction Manager 3.0 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user goes to. The... Read more
- Published: Dec. 20, 2019
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2023-1911
The Blocksy Companion WordPress plugin before 1.8.82 does not ensure that posts to be accessed via a shortcode are already public and can be viewed, allowing any authenticated users, such as subscriber to access draft posts for example... Read more
Affected Products : blocksy_companion- Published: May. 02, 2023
- Modified: Jan. 30, 2025
-
4.3
MEDIUMCVE-2022-29417
Plugin Settings Update vulnerability in ShortPixel's ShortPixel Adaptive Images plugin <= 3.3.1 at WordPress allows an attacker with a low user role like a subscriber or higher to change the plugin settings.... Read more
Affected Products : shortpixel_adaptive_images- Published: Apr. 25, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2013-3775
Unspecified vulnerability in the Oracle iLearning component in Oracle iLearning 5.2.1 and 6.0 allows remote attackers to affect integrity via unknown vectors related to Learner Pages.... Read more
Affected Products : ilearning- Published: Jul. 17, 2013
- Modified: Apr. 11, 2025