Latest CVE Feed
-
9.8
CRITICALCVE-2024-55636
Deserialization of Untrusted Data vulnerability in Drupal Core allows Object Injection.This issue affects Drupal Core: from 8.0.0 before 10.2.11, from 10.3.0 before 10.3.9, from 11.0.0 before 11.0.8. Drupal core contains a chain of methods that is exploi... Read more
Affected Products : drupal- Published: Dec. 10, 2024
- Modified: Jun. 02, 2025
-
6.1
MEDIUMCVE-2024-55635
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Drupal Core allows Cross-Site Scripting (XSS).This issue affects Drupal Core: from 7.0 before 7.102.... Read more
Affected Products : drupal- Published: Dec. 10, 2024
- Modified: Jun. 02, 2025
-
8.1
HIGHCVE-2024-55634
A vulnerability in Drupal Core allows Privilege Escalation.This issue affects Drupal Core: from 8.0.0 before 10.2.11, from 10.3.0 before 10.3.9, from 11.0.0 before 11.0.8.... Read more
Affected Products : drupal- Published: Dec. 10, 2024
- Modified: Jun. 02, 2025
-
5.4
MEDIUMCVE-2024-12393
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Drupal Core allows Cross-Site Scripting (XSS).This issue affects Drupal Core: from 8.8.0 before 10.2.11, from 10.3.0 before 10.3.9, from 11.0.0 be... Read more
Affected Products : drupal- Published: Dec. 10, 2024
- Modified: Jun. 02, 2025
-
5.9
MEDIUMCVE-2024-11942
A vulnerability in Drupal Core allows File Manipulation.This issue affects Drupal Core: from 10.0.0 before 10.2.10.... Read more
Affected Products : drupal- Published: Dec. 05, 2024
- Modified: Jun. 02, 2025
-
7.5
HIGHCVE-2024-11941
A vulnerability in Drupal Core allows Excessive Allocation.This issue affects Drupal Core: from 10.2.0 before 10.2.2, from 10.1.0 before 10.1.8.... Read more
Affected Products : drupal- Published: Dec. 05, 2024
- Modified: Jun. 02, 2025
-
7.2
HIGHCVE-2024-22628
Budget and Expense Tracker System v1.0 is vulnerable to SQL Injection via /expense_budget/admin/?page=reports/budget&date_start=2023-12-28&date_end=... Read more
Affected Products : budget_and_expense_tracker_system- EPSS Score: %0.14
- Published: Jan. 16, 2024
- Modified: Jun. 02, 2025
-
8.8
HIGHCVE-2024-21672
This High severity Remote Code Execution (RCE) vulnerability was introduced in version 2.1.0 of Confluence Data Center and Server. Remote Code Execution (RCE) vulnerability, with a CVSS Score of 8.3 and a CVSS Vector of CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:C/C... Read more
- EPSS Score: %4.27
- Published: Jan. 16, 2024
- Modified: Jun. 02, 2025
-
7.5
HIGHCVE-2023-52116
Permission management vulnerability in the multi-screen interaction module. Successful exploitation of this vulnerability may cause service exceptions of the device.... Read more
- EPSS Score: %0.07
- Published: Jan. 16, 2024
- Modified: Jun. 02, 2025
-
7.5
HIGHCVE-2023-52109
Vulnerability of trust relationships being inaccurate in distributed scenarios. Successful exploitation of this vulnerability may affect service confidentiality.... Read more
- EPSS Score: %0.07
- Published: Jan. 16, 2024
- Modified: Jun. 02, 2025
-
7.5
HIGHCVE-2023-52108
Vulnerability of process priorities being raised in the ActivityManagerService module. Successful exploitation of this vulnerability will affect availability.... Read more
- EPSS Score: %0.06
- Published: Jan. 16, 2024
- Modified: Jun. 02, 2025
-
7.5
HIGHCVE-2023-52104
Vulnerability of parameters being not verified in the WMS module. Successful exploitation of this vulnerability may affect service confidentiality.... Read more
- EPSS Score: %0.18
- Published: Jan. 16, 2024
- Modified: Jun. 02, 2025
-
7.5
HIGHCVE-2023-52100
The Celia Keyboard module has a vulnerability in access control. Successful exploitation of this vulnerability may affect availability.... Read more
Affected Products : harmonyos- EPSS Score: %0.14
- Published: Jan. 16, 2024
- Modified: Jun. 02, 2025
-
9.8
CRITICALCVE-2023-49351
A stack-based buffer overflow vulnerability in /bin/webs binary in Edimax BR6478AC V2 firmware veraion v1.23 allows attackers to overwrite other values located on the stack due to an incorrect use of the strcpy() function.... Read more
- EPSS Score: %0.28
- Published: Jan. 16, 2024
- Modified: Jun. 02, 2025
-
5.3
MEDIUMCVE-2023-48926
An issue in 202 ecommerce Advanced Loyalty Program: Loyalty Points before v2.3.4 for PrestaShop allows unauthenticated attackers to arbitrarily change an order status.... Read more
Affected Products : advanced_loyalty_program- EPSS Score: %0.20
- Published: Jan. 16, 2024
- Modified: Jun. 02, 2025
-
4.3
MEDIUMCVE-2023-3178
The POST SMTP Mailer WordPress plugin before 2.5.7 does not have proper CSRF checks in some AJAX actions, which could allow attackers to make logged in users with the manage_postman_smtp capability delete arbitrary logs via a CSRF attack.... Read more
- EPSS Score: %0.16
- Published: Jan. 16, 2024
- Modified: Jun. 02, 2025
-
9.8
CRITICALCVE-2023-39691
An issue discovered in kodbox through 1.43 allows attackers to arbitrarily add Administrator accounts via crafted GET request.... Read more
Affected Products : kodbox- EPSS Score: %0.24
- Published: Jan. 16, 2024
- Modified: Jun. 02, 2025
-
7.2
HIGHCVE-2023-2655
The Contact Form by WD WordPress plugin through 1.13.23 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by high privilege users such as admin... Read more
Affected Products : contact_form_maker- EPSS Score: %0.72
- Published: Jan. 16, 2024
- Modified: Jun. 02, 2025
-
5.4
MEDIUMCVE-2023-0079
The Customer Reviews for WooCommerce WordPress plugin before 5.17.0 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role an... Read more
Affected Products : customer_reviews_for_woocommerce- EPSS Score: %0.11
- Published: Jan. 16, 2024
- Modified: Jun. 02, 2025
-
8.1
HIGHCVE-2022-3899
The 3dprint WordPress plugin before 3.5.6.9 does not protect against CSRF attacks in the modified version of Tiny File Manager included with the plugin, allowing an attacker to craft a malicious request that will delete any number of files or directories ... Read more
Affected Products : 3dprint- EPSS Score: %0.17
- Published: Jan. 16, 2024
- Modified: Jun. 02, 2025