Latest CVE Feed
-
6.1
MEDIUMCVE-2024-5283
The wp-affiliate-platform WordPress plugin before 6.5.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin... Read more
- Published: Jul. 13, 2024
- Modified: May. 19, 2025
-
6.1
MEDIUMCVE-2024-5282
The wp-affiliate-platform WordPress plugin before 6.5.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin... Read more
- Published: Jul. 13, 2024
- Modified: May. 19, 2025
-
6.1
MEDIUMCVE-2024-5281
The wp-affiliate-platform WordPress plugin before 6.5.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin... Read more
- Published: Jul. 13, 2024
- Modified: May. 19, 2025
-
4.7
MEDIUMCVE-2024-5280
The wp-affiliate-platform WordPress plugin before 6.5.1 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make non-logged in users execute an XSS payload via a CSRF attack... Read more
- Published: Jul. 13, 2024
- Modified: May. 19, 2025
-
8.1
HIGHCVE-2023-28656
NGINX Management Suite may allow an authenticated attacker to gain access to configuration objects outside of their assigned environment. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.... Read more
- Published: May. 03, 2023
- Modified: May. 19, 2025
-
6.1
MEDIUMCVE-2024-3641
The Newsletter Popup WordPress plugin through 1.2 does not sanitise and escape some parameters, which could allow unauthenticated visitors to perform Cross-Site Scripting attacks against admins... Read more
- Published: May. 16, 2024
- Modified: May. 19, 2025
-
6.9
MEDIUMCVE-2024-3642
The Newsletter Popup WordPress plugin through 1.2 does not have CSRF check when deleting subscriber, which could allow attackers to make logged in admins perform such action via a CSRF attack... Read more
- Published: May. 16, 2024
- Modified: May. 19, 2025
-
8.8
HIGHCVE-2024-3643
The Newsletter Popup WordPress plugin through 1.2 does not have CSRF check when deleting list, which could allow attackers to make logged in admins perform such action via a CSRF attack... Read more
- Published: May. 16, 2024
- Modified: May. 19, 2025
-
4.8
MEDIUMCVE-2024-3644
The Newsletter Popup WordPress plugin through 1.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed... Read more
- Published: May. 16, 2024
- Modified: May. 19, 2025
-
7.8
HIGHCVE-2023-39498
PDF-XChange Editor JPG File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is required to exploit this... Read more
- Published: May. 03, 2024
- Modified: May. 19, 2025
-
7.8
HIGHCVE-2023-39499
PDF-XChange Editor JPG File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is required to exploit this... Read more
- Published: May. 03, 2024
- Modified: May. 19, 2025
-
7.8
HIGHCVE-2023-39500
PDF-XChange Editor JPG File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is required to exploit this... Read more
- Published: May. 03, 2024
- Modified: May. 19, 2025
-
7.8
HIGHCVE-2023-39501
PDF-XChange Editor OXPS File Parsing Untrusted Pointer Dereference Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is required to e... Read more
- Published: May. 03, 2024
- Modified: May. 19, 2025
-
7.8
HIGHCVE-2023-39502
PDF-XChange Editor OXPS File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is required to exploit thi... Read more
- Published: May. 03, 2024
- Modified: May. 19, 2025
-
5.5
MEDIUMCVE-2023-39503
PDF-XChange Editor OXPS File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of PDF-XChange Editor. User interaction is required to exp... Read more
- Published: May. 03, 2024
- Modified: May. 19, 2025
-
5.5
MEDIUMCVE-2023-39504
PDF-XChange Editor OXPS File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of PDF-XChange Editor. User interaction is required to exp... Read more
- Published: May. 03, 2024
- Modified: May. 19, 2025
-
5.5
MEDIUMCVE-2023-39505
PDF-XChange Editor Net.HTTP.requests Exposed Dangerous Function Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of PDF-XChange Editor. User interaction is require... Read more
- Published: May. 03, 2024
- Modified: May. 19, 2025
-
7.8
HIGHCVE-2023-39506
PDF-XChange Editor createDataObject Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is required to exploit this... Read more
- Published: May. 03, 2024
- Modified: May. 19, 2025
-
5.5
MEDIUMCVE-2023-40468
PDF-XChange Editor EMF File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of PDF-XChange Editor. User interaction is required to expl... Read more
- Published: May. 03, 2024
- Modified: May. 19, 2025
-
5.5
MEDIUMCVE-2023-40469
PDF-XChange Editor XPS File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of PDF-XChange Editor. User interaction is required to expl... Read more
- Published: May. 03, 2024
- Modified: May. 19, 2025