Latest CVE Feed
-
9.6
CRITICALCVE-2024-28740
Cross Site Scripting vulnerability in Koha ILS 23.05 and before allows a remote attacker to execute arbitrary code via the additonal-contents.pl component.... Read more
Affected Products : koha- Published: Aug. 06, 2024
- Modified: Aug. 21, 2024
-
9.6
CRITICALCVE-2024-34716
PrestaShop is an open source e-commerce web application. A cross-site scripting (XSS) vulnerability that only affects PrestaShops with customer-thread feature flag enabled is present starting from PrestaShop 8.1.0 and prior to PrestaShop 8.1.6. When the c... Read more
Affected Products : prestashop- Published: May. 14, 2024
- Modified: Jan. 21, 2025
-
9.6
CRITICALCVE-2024-7568
The Favicon Generator plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.5. This is due to missing or incorrect nonce validation on the output_sub_admin_page_0 function. This makes it possible for unauthen... Read more
Affected Products : favicon_generator- Published: Aug. 24, 2024
- Modified: Sep. 27, 2024
-
9.6
CRITICALCVE-2024-7982
The Registrations for the Events Calendar WordPress plugin before 2.12.4 does not sanitise and escape some parameters when accepting event registrations, which could allow unauthenticated users to perform Cross-Site Scripting attacks.... Read more
Affected Products : registrations_for_the_events_calendar- Published: Nov. 08, 2024
- Modified: May. 15, 2025
-
9.6
CRITICALCVE-2024-34359
llama-cpp-python is the Python bindings for llama.cpp. `llama-cpp-python` depends on class `Llama` in `llama.py` to load `.gguf` llama.cpp or Latency Machine Learning Models. The `__init__` constructor built in the `Llama` takes several parameters to conf... Read more
Affected Products :- Published: May. 14, 2024
- Modified: Nov. 21, 2024
-
9.6
CRITICALCVE-2020-23719
Cross site scripting (XSS) vulnerability in application/controllers/AdminController.php in xujinliang zibbs 1.0, allows attackers to execute arbitrary code via the bbsmeta parameter.... Read more
Affected Products : zibbs- EPSS Score: %0.73
- Published: Nov. 02, 2021
- Modified: Nov. 21, 2024
-
9.6
CRITICALCVE-2023-35161
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Users are able to forge an URL with a payload allowing to inject Javascript in the page (XSS). It's possible to exploit the DeleteApplication page to ... Read more
Affected Products : xwiki- EPSS Score: %3.38
- Published: Jun. 23, 2023
- Modified: Nov. 21, 2024
-
9.6
CRITICALCVE-2021-29996
Mark Text through 0.16.3 allows attackers arbitrary command execution. This could lead to Remote Code Execution (RCE) by opening .md files containing a mutation Cross Site Scripting (XSS) payload.... Read more
Affected Products : marktext- EPSS Score: %2.37
- Published: Apr. 05, 2021
- Modified: Nov. 21, 2024
-
9.6
CRITICALCVE-2024-32600
Deserialization of Untrusted Data vulnerability in Averta Master Slider.This issue affects Master Slider: from n/a through 3.9.5. ... Read more
Affected Products : master_slider- Published: Apr. 18, 2024
- Modified: May. 27, 2025
-
9.6
CRITICALCVE-2024-46367
A Stored Cross-Site Scripting (XSS) vulnerability in Webkul Krayin CRM 1.3.0 allows remote attackers to inject arbitrary JavaScript code by submitting a malicious payload within the username field. This can lead to privilege escalation when the payload is... Read more
Affected Products : krayin_crm- Published: Sep. 27, 2024
- Modified: Jul. 09, 2025
-
9.6
CRITICALCVE-2020-26902
Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects RBK752 before 3.2.15.25, RBR750 before 3.2.15.25, RBS750 before 3.2.15.25, RBK852 before 3.2.15.25, RBR850 before 3.2.15.25, and RBS850 before 3.2.15.25... Read more
Affected Products : rbk752_firmware rbr750_firmware rbs750_firmware rbk852_firmware rbr850_firmware rbs850_firmware rbk752 rbr750 rbs750 rbk852 +2 more products- EPSS Score: %1.77
- Published: Oct. 09, 2020
- Modified: Nov. 21, 2024
-
9.6
CRITICALCVE-2023-38055
A BOLA vulnerability in GET, PUT, DELETE /services/{serviceId} allows a low privileged user to fetch, modify or delete the services of any user (including admin). This results in unauthorized access and unauthorized data manipulation.... Read more
Affected Products : easyappointments- Published: Jul. 09, 2024
- Modified: Nov. 21, 2024
-
9.6
CRITICALCVE-2022-47877
A Stored cross-site scripting vulnerability in Jedox 2020.2.5 allows remote, authenticated users to inject arbitrary web script or HTML in the Logs page via the log module 'log'.... Read more
Affected Products : jedox- EPSS Score: %1.34
- Published: May. 02, 2023
- Modified: Jan. 30, 2025
-
9.6
CRITICALCVE-2021-40909
Cross site scripting (XSS) vulnerability in sourcecodester PHP CRUD without Refresh/Reload using Ajax and DataTables Tutorial v1 by oretnom23, allows remote attackers to execute arbitrary code via the first_name, last_name, and email parameters to /ajax_c... Read more
Affected Products : php_crud_without_refresh\/reload_using_ajax_and_datatables_tutorial- EPSS Score: %1.40
- Published: Jan. 24, 2022
- Modified: Nov. 21, 2024
-
9.6
CRITICALCVE-2018-1000639
LatexDraw version <=4.0 contains a XML External Entity (XXE) vulnerability in SVG parsing functionality that can result in disclosure of data, server side request forgery, port scanning, possible rce. This attack appear to be exploitable via Specially cra... Read more
Affected Products : latexdraw- EPSS Score: %0.32
- Published: Aug. 20, 2018
- Modified: Nov. 21, 2024
-
9.6
CRITICALCVE-2020-28149
myDBR 5.8.3/4262 is affected by: Cross Site Scripting (XSS). The impact is: execute arbitrary code (remote). The component is: CSRF Token. The attack vector is: CSRF token injection to XSS.... Read more
Affected Products : mydbr- EPSS Score: %0.34
- Published: Mar. 15, 2021
- Modified: Nov. 21, 2024
-
9.6
CRITICALCVE-2022-25069
Mark Text v0.16.3 was discovered to contain a DOM-based cross-site scripting (XSS) vulnerability which allows attackers to perform remote code execution (RCE) via injecting a crafted payload into /lib/contentState/pasteCtrl.js.... Read more
Affected Products : marktext- EPSS Score: %1.34
- Published: Mar. 05, 2022
- Modified: Nov. 21, 2024
-
9.6
CRITICALCVE-2021-32454
SITEL CAP/PRX firmware version 5.2.01 makes use of a hardcoded password. An attacker with access to the device could modify these credentials, leaving the administrators of the device without access.... Read more
- EPSS Score: %0.09
- Published: May. 17, 2021
- Modified: Nov. 21, 2024
-
9.6
CRITICALCVE-2024-23629
An authentication bypass vulnerability exists in the web component of the Motorola MR2600. An attacker can exploit this vulnerability to access protected URLs and retrieve sensitive information. ... Read more
- EPSS Score: %0.06
- Published: Jan. 26, 2024
- Modified: Nov. 21, 2024
-
9.6
CRITICALCVE-2021-1264
A vulnerability in the Command Runner tool of Cisco DNA Center could allow an authenticated, remote attacker to perform a command injection attack. The vulnerability is due to insufficient input validation by the Command Runner tool. An attacker could exp... Read more
- EPSS Score: %0.91
- Published: Jan. 20, 2021
- Modified: Jul. 23, 2025