Latest CVE Feed
-
6.5
MEDIUMCVE-2024-48743
Cross Site Scripting vulnerability in Sentry v.6.0.9 allows a remote attacker to execute arbitrary code via the z parameter.... Read more
Affected Products : sentry- Published: Oct. 25, 2024
- Modified: May. 01, 2025
-
4.3
MEDIUMCVE-2023-7198
The WP Dashboard Notes WordPress plugin before 1.0.11 is vulnerable to Insecure Direct Object References (IDOR) in post_id= parameter. Authenticated users are able to delete private notes associated with different user accounts. This poses a significant s... Read more
Affected Products : wp_dashboard_notes- Published: Feb. 27, 2024
- Modified: May. 01, 2025
-
6.5
MEDIUMCVE-2025-3474
Missing Authentication for Critical Function vulnerability in Drupal Panels allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Panels: from 0.0.0 before 4.9.0.... Read more
Affected Products : panels- Published: Apr. 09, 2025
- Modified: May. 01, 2025
-
6.1
MEDIUMCVE-2024-10276
A vulnerability has been found in Telestream Sentry 6.0.9 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /?page=reports of the component Reports Page. The manipulation of the argument z leads to cross... Read more
Affected Products : sentry- Published: Oct. 23, 2024
- Modified: May. 01, 2025
-
7.5
HIGHCVE-2025-31692
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Drupal AI (Artificial Intelligence) allows OS Command Injection.This issue affects AI (Artificial Intelligence): from 0.0.0 before 1.0.5.... Read more
- Published: Mar. 31, 2025
- Modified: May. 01, 2025
-
7.5
HIGHCVE-2025-31674
Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Drupal core allows Object Injection.This issue affects Drupal core: from 8.0.0 before 10.3.13, from 10.4.0 before 10.4.3, from 11.0.0 before 11.0.12, fr... Read more
Affected Products : drupal- Published: Mar. 31, 2025
- Modified: May. 01, 2025
-
7.8
HIGHCVE-2024-30202
In Emacs before 29.3, arbitrary Lisp code is evaluated as part of turning on Org mode. This affects Org Mode before 9.6.23.... Read more
- Published: Mar. 25, 2024
- Modified: May. 01, 2025
-
5.5
MEDIUM- Published: Mar. 25, 2024
- Modified: May. 01, 2025
-
2.8
LOWCVE-2024-30204
In Emacs before 29.3, LaTeX preview is enabled by default for e-mail attachments.... Read more
- Published: Mar. 25, 2024
- Modified: May. 01, 2025
-
7.1
HIGHCVE-2024-30205
In Emacs before 29.3, Org mode considers contents of remote files to be trusted. This affects Org Mode before 9.6.23.... Read more
- Published: Mar. 25, 2024
- Modified: May. 01, 2025
-
6.1
MEDIUMCVE-2023-7202
The Fatal Error Notify WordPress plugin before 1.5.3 does not have authorisation and CSRF checks in its test_error AJAX action, allowing any authenticated users, such as subscriber to call it and spam the admin email address with error messages. The issue... Read more
Affected Products : fatal_error_notify- Published: Feb. 27, 2024
- Modified: May. 01, 2025
-
8.8
HIGHCVE-2024-42586
A Cross-Site Request Forgery (CSRF) in the component categorie.php of Warehouse Inventory System v2.0 allows attackers to escalate privileges.... Read more
Affected Products : warehouse_inventory_system- Published: Aug. 20, 2024
- Modified: May. 01, 2025
-
8.8
HIGHCVE-2024-42585
A Cross-Site Request Forgery (CSRF) in the component delete_media.php of Warehouse Inventory System v2.0 allows attackers to escalate privileges.... Read more
Affected Products : warehouse_inventory_system- Published: Aug. 20, 2024
- Modified: May. 01, 2025
-
8.0
HIGHCVE-2024-42578
A Cross-Site Request Forgery (CSRF) in the component edit_product.php of Warehouse Inventory System v2.0 allows attackers to escalate privileges.... Read more
- Published: Aug. 20, 2024
- Modified: May. 01, 2025
-
8.8
HIGHCVE-2024-42576
A Cross-Site Request Forgery (CSRF) in the component edit_categorie.php of Warehouse Inventory System v2.0 allows attackers to escalate privileges.... Read more
Affected Products : warehouse_inventory_system- Published: Aug. 20, 2024
- Modified: May. 01, 2025
-
6.5
MEDIUMCVE-2025-28145
Edimax AC1200 Wave 2 Dual-Band Gigabit Router BR-6478AC V3 1.0.15 was discovered to contain a command injection vulnerability via partition in /boafrm/formDiskFormat.... Read more
- Published: Apr. 15, 2025
- Modified: May. 01, 2025
-
6.5
MEDIUMCVE-2025-28143
Edimax AC1200 Wave 2 Dual-Band Gigabit Router BR-6478AC V3_1.0.15 was discovered to contain a command injection vulnerability via the groupname at the /boafrm/formDiskCreateGroup.... Read more
- Published: Apr. 15, 2025
- Modified: May. 01, 2025
-
6.5
MEDIUMCVE-2025-28142
Edimax AC1200 Wave 2 Dual-Band Gigabit Router BR-6478AC V3_1.0.15 was discovered to contain a command injection vulnerability via the foldername in /boafrm/formDiskCreateShare.... Read more
- Published: Apr. 15, 2025
- Modified: May. 01, 2025
-
7.5
HIGHCVE-2024-52884
An issue was discovered in AudioCodes Mediant Session Border Controller (SBC) before 7.40A.501.841. Due to the use of weak password obfuscation/encryption, an attacker with access to configuration exports (INI) is able to decrypt the passwords.... Read more
Affected Products : mediant_session_border_controller- Published: Feb. 07, 2025
- Modified: May. 01, 2025
-
5.3
MEDIUMCVE-2024-0855
The Spiffy Calendar WordPress plugin before 4.9.9 doesn't check the event_author parameter, and allows any user to alter it when creating an event, leading to deceiving users/admins that a page was created by a Contributor+.... Read more
Affected Products : spiffy_calendar- Published: Feb. 27, 2024
- Modified: May. 01, 2025