Latest CVE Feed
-
2.7
LOWCVE-2024-10562
The Form Maker by 10Web WordPress plugin before 1.15.31 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is dis... Read more
Affected Products : form_maker- Published: Jan. 07, 2025
- Modified: May. 08, 2025
- Vuln Type: Cross-Site Scripting
-
4.7
MEDIUMCVE-2024-11223
The WPForms WordPress plugin before 1.9.2.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for... Read more
Affected Products : wpforms- Published: Dec. 26, 2024
- Modified: May. 08, 2025
-
5.4
MEDIUMCVE-2024-10678
The Ultimate Blocks WordPress plugin before 3.2.4 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cr... Read more
Affected Products : ultimate_blocks- Published: Dec. 13, 2024
- Modified: May. 08, 2025
-
5.4
MEDIUMCVE-2024-6136
The wp-cart-for-digital-products WordPress plugin before 8.5.6 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions via CSRF attacks... Read more
Affected Products : wp_estore- Published: Aug. 12, 2024
- Modified: May. 08, 2025
-
5.4
MEDIUMCVE-2024-6134
The wp-cart-for-digital-products WordPress plugin before 8.5.6 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin... Read more
Affected Products : wp_estore- Published: Aug. 12, 2024
- Modified: May. 08, 2025
-
6.5
MEDIUMCVE-2024-6133
The wp-cart-for-digital-products WordPress plugin before 8.5.6 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin... Read more
Affected Products : wp_estore- Published: Aug. 12, 2024
- Modified: May. 08, 2025
-
4.8
MEDIUMCVE-2024-12568
The Email Subscribers by Icegram Express WordPress plugin before 5.7.45 does not sanitise and escape some of its Workflow settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfilter... Read more
Affected Products : email_subscribers_\&_newsletters- Published: Jan. 13, 2025
- Modified: May. 08, 2025
- Vuln Type: Cross-Site Scripting
-
4.8
MEDIUMCVE-2024-12567
The Email Subscribers by Icegram Express WordPress plugin before 5.7.45 does not sanitise and escape some of its form settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_h... Read more
Affected Products : email_subscribers_\&_newsletters- Published: Jan. 13, 2025
- Modified: May. 08, 2025
- Vuln Type: Cross-Site Scripting
-
4.8
MEDIUMCVE-2024-12566
The Email Subscribers by Icegram Express WordPress plugin before 5.7.45 does not sanitise and escape some of form settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html ... Read more
Affected Products : email_subscribers_\&_newsletters- Published: Jan. 13, 2025
- Modified: May. 08, 2025
- Vuln Type: Cross-Site Scripting
-
7.5
HIGHCVE-2024-12274
The Appointment Booking Calendar Plugin and Scheduling Plugin WordPress plugin before 1.1.23 export settings functionality exports data to a public folder, with an easily guessable file name, allowing unauthenticated attackers to access the exported file... Read more
Affected Products : appointment_booking_calendar- Published: Jan. 13, 2025
- Modified: May. 08, 2025
- Vuln Type: Information Disclosure
-
4.8
MEDIUMCVE-2024-11636
The Email Subscribers by Icegram Express WordPress plugin before 5.7.45 does not sanitise and escape some of its Text Block options, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfilte... Read more
Affected Products : email_subscribers_\&_newsletters- Published: Jan. 13, 2025
- Modified: May. 08, 2025
- Vuln Type: Cross-Site Scripting
-
6.5
MEDIUMCVE-2025-29154
HTML injection vulnerability in lemeconsultoria HCM galera.app v.4.58.0 allows an attacker to execute arbitrary code via the .galera.app/ted/solicitacao_treinamento/, .galera.app/rh/metas/perspectiva_estrategica/edicao/, .galera.app/rh/cadastros/perspecti... Read more
Affected Products :- Published: May. 07, 2025
- Modified: May. 08, 2025
- Vuln Type: Cross-Site Scripting
-
5.5
MEDIUMCVE-2024-25454
Bento4 v1.6.0-640 was discovered to contain a NULL pointer dereference via the AP4_DescriptorFinder::Test() function.... Read more
Affected Products : bento4- EPSS Score: %0.02
- Published: Feb. 09, 2024
- Modified: May. 08, 2025
-
7.5
HIGHCVE-2024-25407
SteVe v3.6.0 was discovered to use predictable transaction ID's when receiving a StartTransaction request. This vulnerability can allow attackers to cause a Denial of Service (DoS) by using the predicted transaction ID's to terminate other transactions.... Read more
- EPSS Score: %0.17
- Published: Feb. 13, 2024
- Modified: May. 08, 2025
-
9.8
CRITICALCVE-2024-25302
Sourcecodester Event Student Attendance System 1.0, allows SQL Injection via the 'student' parameter.... Read more
Affected Products : event_student_attendance_system- EPSS Score: %0.18
- Published: Feb. 09, 2024
- Modified: May. 08, 2025
-
7.8
HIGHCVE-2024-25003
KiTTY versions 0.76.1.13 and before is vulnerable to a stack-based buffer overflow via the hostname, occurs due to insufficient bounds checking and input sanitization. This allows an attacker to overwrite adjacent memory, which leads to arbitrary code exe... Read more
Affected Products : kitty- EPSS Score: %0.55
- Published: Feb. 09, 2024
- Modified: May. 08, 2025
-
8.8
HIGHCVE-2024-24350
File Upload vulnerability in Software Publico e-Sic Livre v.2.0 and before allows a remote attacker to execute arbitrary code via the extension filtering component.... Read more
Affected Products : e-sic_livre- EPSS Score: %1.87
- Published: Feb. 08, 2024
- Modified: May. 08, 2025
-
4.2
MEDIUMCVE-2024-24255
A Race Condition discovered in geofence.cpp and mission_feasibility_checker.cpp in PX4 Autopilot 1.14 and earlier allows attackers to send drones on unintended missions.... Read more
Affected Products : px4_drone_autopilot- EPSS Score: %0.04
- Published: Feb. 06, 2024
- Modified: May. 08, 2025
-
9.8
CRITICALCVE-2024-24216
Zentao v18.0 to v18.10 was discovered to contain a remote code execution (RCE) vulnerability via the checkConnection method of /app/zentao/module/repo/model.php.... Read more
Affected Products : zentao- EPSS Score: %6.84
- Published: Feb. 08, 2024
- Modified: May. 08, 2025
-
9.8
CRITICALCVE-2024-24186
Jsish v3.5.0 (commit 42c694c) was discovered to contain a stack-overflow via the component IterGetKeysCallback at /jsish/src/jsiValue.c.... Read more
Affected Products : jsish- EPSS Score: %1.08
- Published: Feb. 07, 2024
- Modified: May. 08, 2025