Latest CVE Feed
-
8.8
HIGHCVE-2025-4372
Use after free in WebAudio in Google Chrome prior to 136.0.7103.92 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)... Read more
- Published: May. 06, 2025
- Modified: May. 28, 2025
- Vuln Type: Memory Corruption
-
5.4
MEDIUMCVE-2023-6487
The LuckyWP Table of Contents plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘Header Title' field in all versions up to and including 2.1.4 due to insufficient input sanitization and output escaping. This makes it possible for a... Read more
Affected Products : luckywp_table_of_contents- Published: May. 22, 2024
- Modified: May. 28, 2025
-
6.1
MEDIUMCVE-2024-2119
The LuckyWP Table of Contents plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the attrs parameter in all versions up to, and including, 2.1.4 due to insufficient input sanitization and output escaping. This makes it possible for u... Read more
Affected Products : luckywp_table_of_contents- Published: May. 22, 2024
- Modified: May. 28, 2025
-
5.5
MEDIUMCVE-2024-2953
The LuckyWP Table of Contents plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple parameters in versions up to, and including, 2.1.4 due to insufficient input sanitization and output escaping. This makes it possible for authenti... Read more
Affected Products : luckywp_table_of_contents- Published: May. 22, 2024
- Modified: May. 28, 2025
-
9.8
CRITICALCVE-2024-35409
WeBid 1.1.2 is vulnerable to SQL Injection via admin/tax.php.... Read more
Affected Products : webid- Published: May. 22, 2024
- Modified: May. 28, 2025
-
6.4
MEDIUMCVE-2024-1805
The wpbakery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the button onclick attribute in all versions up to, and including, 7.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated ... Read more
- Published: May. 02, 2024
- Modified: May. 28, 2025
-
6.4
MEDIUMCVE-2024-1840
The wpbakery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Post Author tag attribute in all versions up to, and including, 7.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated... Read more
- Published: May. 02, 2024
- Modified: May. 28, 2025
-
6.4
MEDIUMCVE-2024-1841
The wpbakery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Post Title tag attribute in all versions up to, and including, 7.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated ... Read more
- Published: May. 02, 2024
- Modified: May. 28, 2025
-
6.4
MEDIUMCVE-2024-1842
The wpbakery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Custom Heading tag attribute in all versions up to, and including, 7.5 due to insufficient input sanitization and output escaping. This makes it possible for authentica... Read more
- Published: May. 02, 2024
- Modified: May. 28, 2025
-
7.5
HIGHCVE-2024-22871
An issue in Clojure versions 1.20 to 1.12.0-alpha5 allows an attacker to cause a denial of service (DoS) via the clojure.core$partial$fn__5920 function.... Read more
- Published: Feb. 29, 2024
- Modified: May. 28, 2025
-
6.1
MEDIUMCVE-2023-50378
Lack of proper input validation and constraint enforcement in Apache Ambari prior to 2.7.8 Impact : As it will be stored XSS, Could be exploited to perform unauthorized actions, varying from data access to session hijacking and delivering malicious pa... Read more
Affected Products : ambari- Published: Mar. 01, 2024
- Modified: May. 28, 2025
-
7.5
HIGHCVE-2024-27138
** UNSUPPORTED WHEN ASSIGNED ** Incorrect Authorization vulnerability in Apache Archiva. Apache Archiva has a setting to disable user registration, however this restriction can be bypassed. As Apache Archiva has been retired, we do not expect to release ... Read more
Affected Products : archiva- Published: Mar. 01, 2024
- Modified: May. 28, 2025
-
7.5
HIGHCVE-2024-27139
** UNSUPPORTED WHEN ASSIGNED ** Incorrect Authorization vulnerability in Apache Archiva: a vulnerability in Apache Archiva allows an unauthenticated attacker to modify account data, potentially leading to account takeover. This issue affects Apache Arch... Read more
Affected Products : archiva- Published: Mar. 01, 2024
- Modified: May. 28, 2025
-
5.4
MEDIUMCVE-2024-27140
** UNSUPPORTED WHEN ASSIGNED ** Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache Archiva. This issue affects Apache Archiva: from 2.0.0. As this project is retired, we do not plan to release a... Read more
Affected Products : archiva- Published: Mar. 01, 2024
- Modified: May. 28, 2025
-
7.5
HIGHCVE-2024-24766
CasaOS-UserService provides user management functionalities to CasaOS. Starting in version 0.4.4.3 and prior to version 0.4.7, the Casa OS Login page disclosed the username enumeration vulnerability in the login page. An attacker can enumerate the CasaOS ... Read more
- Published: Mar. 06, 2024
- Modified: May. 28, 2025
-
8.8
HIGHCVE-2024-5709
The WPBakery Visual Composer plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 7.7 via the 'layout_name' parameter. This makes it possible for authenticated attackers, with Author-level access and above, and ... Read more
- Published: Aug. 06, 2024
- Modified: May. 28, 2025
-
6.1
MEDIUMCVE-2024-7082
The Easy Table of Contents WordPress plugin before 2.0.68 does not sanitise and escape some parameters, which could allow users with a role as low as Editor to perform Cross-Site Scripting attacks.... Read more
Affected Products : easy_table_of_contents- Published: Aug. 06, 2024
- Modified: May. 28, 2025
-
4.8
MEDIUMCVE-2024-7084
The Ajax Search Lite WordPress plugin before 4.12.1 does not sanitise and escape some parameters, which could allow users with a role as low as Admin+ to perform Cross-Site Scripting attacks.... Read more
- Published: Aug. 06, 2024
- Modified: May. 28, 2025
-
4.8
MEDIUMCVE-2024-3973
The House Manager WordPress plugin through 1.0.8.4 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin... Read more
Affected Products : house_manager- Published: Aug. 07, 2024
- Modified: May. 28, 2025
-
4.8
MEDIUMCVE-2024-6481
The Search & Filter Pro WordPress plugin before 2.5.18 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disal... Read more
Affected Products : search_\&_filter- Published: Aug. 08, 2024
- Modified: May. 28, 2025