Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 6.1

    MEDIUM
    CVE-2024-5283

    The wp-affiliate-platform WordPress plugin before 6.5.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin... Read more

    • Published: Jul. 13, 2024
    • Modified: May. 19, 2025
  • 6.1

    MEDIUM
    CVE-2024-5282

    The wp-affiliate-platform WordPress plugin before 6.5.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin... Read more

    • Published: Jul. 13, 2024
    • Modified: May. 19, 2025
  • 6.1

    MEDIUM
    CVE-2024-5281

    The wp-affiliate-platform WordPress plugin before 6.5.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin... Read more

    • Published: Jul. 13, 2024
    • Modified: May. 19, 2025
  • 4.7

    MEDIUM
    CVE-2024-5280

    The wp-affiliate-platform WordPress plugin before 6.5.1 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make non-logged in users execute an XSS payload via a CSRF attack... Read more

    • Published: Jul. 13, 2024
    • Modified: May. 19, 2025
  • 8.1

    HIGH
    CVE-2023-28656

    NGINX Management Suite may allow an authenticated attacker to gain access to configuration objects outside of their assigned environment.   Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.... Read more

    • Published: May. 03, 2023
    • Modified: May. 19, 2025
  • 6.1

    MEDIUM
    CVE-2024-3641

    The Newsletter Popup WordPress plugin through 1.2 does not sanitise and escape some parameters, which could allow unauthenticated visitors to perform Cross-Site Scripting attacks against admins... Read more

    Affected Products : newsletter_popup newsletter_popup
    • Published: May. 16, 2024
    • Modified: May. 19, 2025
  • 6.9

    MEDIUM
    CVE-2024-3642

    The Newsletter Popup WordPress plugin through 1.2 does not have CSRF check when deleting subscriber, which could allow attackers to make logged in admins perform such action via a CSRF attack... Read more

    Affected Products : newsletter_popup newsletter_popup
    • Published: May. 16, 2024
    • Modified: May. 19, 2025
  • 8.8

    HIGH
    CVE-2024-3643

    The Newsletter Popup WordPress plugin through 1.2 does not have CSRF check when deleting list, which could allow attackers to make logged in admins perform such action via a CSRF attack... Read more

    Affected Products : newsletter_popup newsletter_popup
    • Published: May. 16, 2024
    • Modified: May. 19, 2025
  • 4.8

    MEDIUM
    CVE-2024-3644

    The Newsletter Popup WordPress plugin through 1.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed... Read more

    Affected Products : newsletter_popup newsletter_popup
    • Published: May. 16, 2024
    • Modified: May. 19, 2025
  • 7.8

    HIGH
    CVE-2023-39498

    PDF-XChange Editor JPG File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is required to exploit this... Read more

    • Published: May. 03, 2024
    • Modified: May. 19, 2025
  • 7.8

    HIGH
    CVE-2023-39499

    PDF-XChange Editor JPG File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is required to exploit this... Read more

    • Published: May. 03, 2024
    • Modified: May. 19, 2025
  • 7.8

    HIGH
    CVE-2023-39500

    PDF-XChange Editor JPG File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is required to exploit this... Read more

    • Published: May. 03, 2024
    • Modified: May. 19, 2025
  • 7.8

    HIGH
    CVE-2023-39501

    PDF-XChange Editor OXPS File Parsing Untrusted Pointer Dereference Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is required to e... Read more

    • Published: May. 03, 2024
    • Modified: May. 19, 2025
  • 7.8

    HIGH
    CVE-2023-39502

    PDF-XChange Editor OXPS File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is required to exploit thi... Read more

    • Published: May. 03, 2024
    • Modified: May. 19, 2025
  • 5.5

    MEDIUM
    CVE-2023-39503

    PDF-XChange Editor OXPS File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of PDF-XChange Editor. User interaction is required to exp... Read more

    • Published: May. 03, 2024
    • Modified: May. 19, 2025
  • 5.5

    MEDIUM
    CVE-2023-39504

    PDF-XChange Editor OXPS File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of PDF-XChange Editor. User interaction is required to exp... Read more

    • Published: May. 03, 2024
    • Modified: May. 19, 2025
  • 5.5

    MEDIUM
    CVE-2023-39505

    PDF-XChange Editor Net.HTTP.requests Exposed Dangerous Function Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of PDF-XChange Editor. User interaction is require... Read more

    • Published: May. 03, 2024
    • Modified: May. 19, 2025
  • 7.8

    HIGH
    CVE-2023-39506

    PDF-XChange Editor createDataObject Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is required to exploit this... Read more

    • Published: May. 03, 2024
    • Modified: May. 19, 2025
  • 5.5

    MEDIUM
    CVE-2023-40468

    PDF-XChange Editor EMF File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of PDF-XChange Editor. User interaction is required to expl... Read more

    • Published: May. 03, 2024
    • Modified: May. 19, 2025
  • 5.5

    MEDIUM
    CVE-2023-40469

    PDF-XChange Editor XPS File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of PDF-XChange Editor. User interaction is required to expl... Read more

    • Published: May. 03, 2024
    • Modified: May. 19, 2025
Showing 20 of 293304 Results