Latest CVE Feed
-
7.8
HIGHCVE-2024-21111
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 7.0.16. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where... Read more
- Published: Apr. 16, 2024
- Modified: May. 09, 2025
-
6.4
MEDIUMCVE-2024-13860
The Buddyboss Platform plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘bbp_topic_title’ parameter in all versions up to, and including, 2.8.50 due to insufficient input sanitization and output escaping. This makes it possible fo... Read more
Affected Products : buddyboss_platform- Published: May. 02, 2025
- Modified: May. 09, 2025
- Vuln Type: Cross-Site Scripting
-
6.4
MEDIUMCVE-2024-13859
The Buddyboss Platform plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘bp_nouveau_ajax_media_save’ function in all versions up to, and including, 2.8.50 due to insufficient input sanitization and output escaping. This makes it p... Read more
Affected Products : buddyboss_platform- Published: May. 02, 2025
- Modified: May. 09, 2025
- Vuln Type: Cross-Site Scripting
-
5.5
MEDIUMCVE-2022-33180
A vulnerability in Brocade Fabric OS CLI before Brocade Fabric OS v9.1.0, 9.0.1e, 8.2.3c, 8.2.0cbn5 could allow a local authenticated attacker to export out sensitive files with “seccryptocfg”, “configupload”.... Read more
Affected Products : fabric_operating_system- EPSS Score: %0.06
- Published: Oct. 25, 2022
- Modified: May. 09, 2025
-
8.8
HIGHCVE-2022-33179
A vulnerability in Brocade Fabric OS CLI before Brocade Fabric OS v9.1.0, 9.0.1e, 8.2.3c, and 7.4.2j could allow a local authenticated user to break out of restricted shells with “set context” and escalate privileges.... Read more
Affected Products : fabric_operating_system- EPSS Score: %0.04
- Published: Oct. 25, 2022
- Modified: May. 09, 2025
-
6.7
MEDIUMCVE-2024-20012
In keyInstall, there is a possible escalation of privilege due to type confusion. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08358566; Issue ID: ... Read more
- EPSS Score: %0.02
- Published: Feb. 05, 2024
- Modified: May. 09, 2025
-
6.1
MEDIUMCVE-2022-31468
OX App Suite through 8.2 allows XSS via an attachment or OX Drive content when a client uses the len or off parameter.... Read more
Affected Products : ox_app_suite- EPSS Score: %0.15
- Published: Oct. 25, 2022
- Modified: May. 09, 2025
-
6.5
MEDIUMCVE-2022-28170
Brocade Fabric OS Web Application services before Brocade Fabric v9.1.0, v9.0.1e, v8.2.3c, v7.4.2j store server and user passwords in the debug statements. This could allow a local user to extract the passwords from a debug file.... Read more
Affected Products : fabric_operating_system- EPSS Score: %0.06
- Published: Oct. 25, 2022
- Modified: May. 09, 2025
-
8.8
HIGHCVE-2022-28169
Brocade Webtools in Brocade Fabric OS versions before Brocade Fabric OS versions v9.1.1, v9.0.1e, and v8.2.3c could allow a low privilege webtools, user, to gain elevated admin rights, or privileges, beyond what is intended or entitled for that user. By e... Read more
Affected Products : fabric_operating_system- EPSS Score: %0.16
- Published: Oct. 25, 2022
- Modified: May. 09, 2025
-
6.1
MEDIUMCVE-2024-0239
The Contact Form 7 Connector WordPress plugin before 1.2.3 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against administrators.... Read more
Affected Products : contact_form_7_connector- EPSS Score: %0.26
- Published: Jan. 16, 2024
- Modified: May. 09, 2025
-
4.8
MEDIUMCVE-2022-23179
The Contact Form & Lead Form Elementor Builder WordPress plugin before 1.7.0 does not escape some of its form fields before outputting them in attributes, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfilte... Read more
Affected Products : contact_form_\&_lead_form_elementor_builder- EPSS Score: %0.15
- Published: Jan. 16, 2024
- Modified: May. 09, 2025
-
7.5
HIGHCVE-2013-4253
The deployment script in the unsupported "OpenShift Extras" set of add-on scripts, in Red Hat Openshift 1, installs a default public key in the root user's authorized_keys file.... Read more
Affected Products : openshift- EPSS Score: %0.06
- Published: Oct. 19, 2022
- Modified: May. 09, 2025
-
5.4
MEDIUMCVE-2024-0881
The Post Grid, Form Maker, Popup Maker, WooCommerce Blocks, Post Blocks, Post Carousel WordPress plugin before 2.2.76 does not have proper authorization, resulting in password protected posts to be displayed in the result of some unauthenticated AJAX act... Read more
Affected Products : post_grid- Published: Apr. 11, 2024
- Modified: May. 09, 2025
-
3.8
LOWCVE-2024-3628
The EasyEvent WordPress plugin through 1.0.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed... Read more
Affected Products : easyevent- Published: May. 07, 2024
- Modified: May. 09, 2025
-
6.5
MEDIUMCVE-2022-43023
OpenCATS v0.9.6 was discovered to contain a SQL injection vulnerability via the importID parameter in the Import viewerrors function.... Read more
Affected Products : opencats- EPSS Score: %0.08
- Published: Oct. 19, 2022
- Modified: May. 09, 2025
-
6.5
MEDIUMCVE-2022-43022
OpenCATS v0.9.6 was discovered to contain a SQL injection vulnerability via the tag_id variable in the Tag deletion function.... Read more
Affected Products : opencats- EPSS Score: %0.08
- Published: Oct. 19, 2022
- Modified: May. 09, 2025
-
6.5
MEDIUMCVE-2022-43021
OpenCATS v0.9.6 was discovered to contain a SQL injection vulnerability via the entriesPerPage variable.... Read more
Affected Products : opencats- EPSS Score: %0.08
- Published: Oct. 19, 2022
- Modified: May. 09, 2025
-
6.5
MEDIUMCVE-2022-43020
OpenCATS v0.9.6 was discovered to contain a SQL injection vulnerability via the tag_id variable in the Tag update function.... Read more
Affected Products : opencats- EPSS Score: %0.08
- Published: Oct. 19, 2022
- Modified: May. 09, 2025
-
9.8
CRITICALCVE-2022-43019
OpenCATS v0.9.6 was discovered to contain a remote code execution (RCE) vulnerability via the getDataGridPager's ajax functionality.... Read more
Affected Products : opencats- EPSS Score: %7.97
- Published: Oct. 19, 2022
- Modified: May. 09, 2025
-
6.1
MEDIUMCVE-2022-43018
OpenCATS v0.9.6 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the email parameter in the Check Email function.... Read more
Affected Products : opencats- EPSS Score: %9.94
- Published: Oct. 19, 2022
- Modified: May. 09, 2025