Latest CVE Feed
-
4.3
MEDIUMCVE-2024-9705
The Ultimate Coming Soon & Maintenance plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'ucsm_update_template_name_lite' function in all versions up to, and including, 1.0.9. This makes it po... Read more
Affected Products : ultimate_coming_soon_\&_maintenance- Published: Dec. 06, 2024
- Modified: Jun. 05, 2025
-
6.4
MEDIUMCVE-2024-10885
The SearchIQ – The Search Solution plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'siq_searchbox' shortcode in all versions up to, and including, 4.6 due to insufficient input sanitization and output escaping on user su... Read more
Affected Products : searchiq- Published: Dec. 04, 2024
- Modified: Jun. 05, 2025
-
7.5
HIGHCVE-2024-11391
The Advanced File Manager plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation via the 'class_fma_connector.php' file in all versions up to, and including, 5.2.10. This makes it possible for authenticated attack... Read more
Affected Products : advanced_file_manager- Published: Dec. 03, 2024
- Modified: Jun. 05, 2025
-
4.3
MEDIUMCVE-2024-11844
The IdeaPush plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the idea_push_taxonomy_save_routine function in all versions up to, and including, 8.71. This makes it possible for authenticated att... Read more
Affected Products : ideapush- Published: Dec. 03, 2024
- Modified: Jun. 05, 2025
-
6.4
MEDIUMCVE-2024-11898
The Scratch & Win – Giveaways and Contests. Boost subscribers, traffic, repeat visits, referrals, sales and more plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'swin-campaign' shortcode in all versions up to, and inclu... Read more
- Published: Dec. 03, 2024
- Modified: Jun. 05, 2025
-
5.5
MEDIUMCVE-2024-47156
Some Honor products are affected by information leak vulnerability, successful exploitation could cause the information leak.... Read more
Affected Products : magicos- Published: Dec. 26, 2024
- Modified: Jun. 05, 2025
-
5.5
MEDIUMCVE-2024-47148
Some Honor products are affected by incorrect privilege assignment vulnerability, successful exploitation could cause device service exceptions.... Read more
- Published: Dec. 26, 2024
- Modified: Jun. 05, 2025
-
6.2
MEDIUMCVE-2024-47153
Some Honor products are affected by information leak vulnerability, successful exploitation could cause the information leak.... Read more
- Published: Dec. 26, 2024
- Modified: Jun. 05, 2025
-
5.5
MEDIUMCVE-2024-47154
Some Honor products are affected by information leak vulnerability, successful exploitation could cause the information leak.... Read more
- Published: Dec. 26, 2024
- Modified: Jun. 05, 2025
-
5.5
MEDIUMCVE-2024-47157
Some Honor products are affected by incorrect privilege assignment vulnerability, successful exploitation could cause device service exceptions.... Read more
- Published: Dec. 26, 2024
- Modified: Jun. 05, 2025
-
7.5
HIGHCVE-2024-11282
The Passster – Password Protect Pages and Content plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.2.10 via the WordPress core search feature. This makes it possible for unauthenticated attackers... Read more
- Published: Jan. 07, 2025
- Modified: Jun. 05, 2025
- Vuln Type: Information Disclosure
-
5.5
MEDIUMCVE-2024-47155
Some Honor products are affected by information leak vulnerability, successful exploitation could cause the information leak.... Read more
- Published: Dec. 26, 2024
- Modified: Jun. 05, 2025
-
5.5
MEDIUMCVE-2024-8992
Some Honor products are affected by information leak vulnerability, successful exploitation could cause the information leak.... Read more
- Published: Dec. 26, 2024
- Modified: Jun. 05, 2025
-
6.2
MEDIUMCVE-2024-8993
Some Honor products are affected by information leak vulnerability, successful exploitation could cause the information leak.... Read more
- Published: Dec. 26, 2024
- Modified: Jun. 05, 2025
-
6.2
MEDIUMCVE-2024-8994
Some Honor products are affected by information leak vulnerability, successful exploitation could cause the information leak.... Read more
- Published: Dec. 26, 2024
- Modified: Jun. 05, 2025
-
6.4
MEDIUMCVE-2024-12073
The Meteor Slides plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'slide_url_value' parameter in all versions up to, and including, 1.5.7 due to insufficient input sanitization and output escaping. This makes it possible for auth... Read more
Affected Products : meteor_slides- Published: Jan. 07, 2025
- Modified: Jun. 05, 2025
- Vuln Type: Cross-Site Scripting
-
6.1
MEDIUMCVE-2024-12290
The Infility Global plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘set_type’ parameter in all versions up to, and including, 2.9.8 due to insufficient input sanitization and output escaping. This makes it possible for unauth... Read more
Affected Products : infility_global- Published: Jan. 07, 2025
- Modified: Jun. 05, 2025
- Vuln Type: Cross-Site Scripting
-
6.5
MEDIUMCVE-2024-11496
The Infility Global plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the infility_global_ajax function in all versions up to, and including, 2.9.8. This makes it possible for authenticated attack... Read more
Affected Products : infility_global- Published: Jan. 07, 2025
- Modified: Jun. 05, 2025
- Vuln Type: Authorization
-
5.5
MEDIUMCVE-2024-47150
Some Honor products are affected by information leak vulnerability, successful exploitation could cause the information leak.... Read more
- Published: Dec. 26, 2024
- Modified: Jun. 05, 2025
-
5.5
MEDIUMCVE-2024-47149
Some Honor products are affected by incorrect privilege assignment vulnerability, successful exploitation could cause device service exceptions.... Read more
- Published: Dec. 26, 2024
- Modified: Jun. 05, 2025