Latest CVE Feed
-
5.4
MEDIUMCVE-2024-11085
The WP Log Viewer plugin for WordPress is vulnerable to unauthorized use of functionality due to a missing capability check on several AJAX actions in all versions up to, and including, 1.2.1. This makes it possible for authenticated attackers, with Subsc... Read more
Affected Products :- Published: Nov. 16, 2024
- Modified: Nov. 18, 2024
-
8.8
HIGHCVE-2024-41969
A low privileged remote attacker may modify the configuration of the CODESYS V3 service through a missing authentication vulnerability which could lead to full system access and/or DoS.... Read more
Affected Products :- Published: Nov. 18, 2024
- Modified: Nov. 18, 2024
-
7.2
HIGHCVE-2024-50324
Path traversal in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allows a remote authenticated attacker with admin privileges to achieve remote code execution.... Read more
Affected Products : endpoint_manager- Published: Nov. 12, 2024
- Modified: Nov. 18, 2024
-
5.9
MEDIUMCVE-2024-51664
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Mark Kinchin Beds24 Online Booking allows Stored XSS.This issue affects Beds24 Online Booking: from n/a through 2.0.25.... Read more
Affected Products : online_booking- Published: Nov. 09, 2024
- Modified: Nov. 18, 2024
-
5.9
MEDIUMCVE-2024-51663
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Bricksable Bricksable for Bricks Builder allows Stored XSS.This issue affects Bricksable for Bricks Builder: from n/a through 1.6.59.... Read more
Affected Products : bricksable_for_bricks_builder- Published: Nov. 09, 2024
- Modified: Nov. 18, 2024
-
5.9
MEDIUMCVE-2024-51668
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Mark Tilly MyCurator Content Curation allows Stored XSS.This issue affects MyCurator Content Curation: from n/a through 3.78.... Read more
Affected Products : mycurator_content_curation- Published: Nov. 09, 2024
- Modified: Nov. 18, 2024
-
6.5
MEDIUMCVE-2024-51586
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in BRAFT Elementary Addons allows Stored XSS.This issue affects Elementary Addons: from n/a through 2.0.4.... Read more
Affected Products : elementary_addons- Published: Nov. 09, 2024
- Modified: Nov. 18, 2024
-
6.5
MEDIUMCVE-2024-51590
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Hoosoft Hoo Addons for Elementor allows DOM-Based XSS.This issue affects Hoo Addons for Elementor: from n/a through 1.0.6.... Read more
Affected Products : hoo_addons_for_elementor- Published: Nov. 09, 2024
- Modified: Nov. 18, 2024
-
7.2
HIGHCVE-2024-50826
A SQL Injection vulnerability was found in /admin/add_content.php in kashipara E-learning Management System Project 1.0 via the title and content parameters.... Read more
Affected Products : e-learning_management_system- Published: Nov. 14, 2024
- Modified: Nov. 18, 2024
-
7.2
HIGHCVE-2024-50825
A SQL Injection vulnerability was found in /admin/school_year.php in kashipara E-learning Management System Project 1.0 via the school_year parameter.... Read more
Affected Products : e-learning_management_system- Published: Nov. 14, 2024
- Modified: Nov. 18, 2024
-
7.2
HIGHCVE-2024-50824
A SQL Injection vulnerability was found in /admin/class.php in kashipara E-learning Management System Project 1.0 via the class_name parameter.... Read more
Affected Products : e-learning_management_system- Published: Nov. 14, 2024
- Modified: Nov. 18, 2024
-
9.8
CRITICALCVE-2024-50823
A SQL Injection vulnerability was found in /admin/login.php in kashipara E-learning Management System Project 1.0 via the username and password parameters.... Read more
Affected Products : e-learning_management_system- Published: Nov. 14, 2024
- Modified: Nov. 18, 2024
-
7.2
HIGHCVE-2024-50835
A SQL Injection vulnerability was found in /admin/edit_student.php in KASHIPARA E-learning Management System Project 1.0 via the cys, un, ln, fn, and id parameters.... Read more
Affected Products : e-learning_management_system- Published: Nov. 14, 2024
- Modified: Nov. 18, 2024
-
7.2
HIGHCVE-2024-50834
A SQL Injection was found in /admin/teachers.php in KASHIPARA E-learning Management System Project 1.0 via the firstname and lastname parameters.... Read more
Affected Products : e-learning_management_system- Published: Nov. 14, 2024
- Modified: Nov. 18, 2024
-
9.8
CRITICALCVE-2024-50833
A SQL Injection vulnerability was found in /login.php in KASHIPARA E-learning Management System Project 1.0 via the username and password parameters.... Read more
Affected Products : e-learning_management_system- Published: Nov. 14, 2024
- Modified: Nov. 18, 2024
-
6.5
MEDIUMCVE-2024-51598
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Kendysond Selar.Co Widget allows DOM-Based XSS.This issue affects Selar.Co Widget: from n/a through 1.2.... Read more
Affected Products : selar.co_widget- Published: Nov. 09, 2024
- Modified: Nov. 18, 2024
-
7.2
HIGHCVE-2024-50832
A SQL Injection vulnerability was found in /admin/edit_class.php in kashipara E-learning Management System Project 1.0 via the class_name parameter.... Read more
Affected Products : e-learning_management_system- Published: Nov. 14, 2024
- Modified: Nov. 18, 2024
-
7.2
HIGHCVE-2024-50831
A SQL Injection was found in /admin/admin_user.php in kashipara E-learning Management System Project 1.0 via the username and password parameters.... Read more
Affected Products : e-learning_management_system- Published: Nov. 14, 2024
- Modified: Nov. 18, 2024
-
7.2
HIGHCVE-2024-50830
A SQL Injection vulnerability was found in /admin/calendar_of_events.php in kashipara E-learning Management System Project 1.0 via the date_start, date_end, and title parameters.... Read more
Affected Products : e-learning_management_system- Published: Nov. 14, 2024
- Modified: Nov. 18, 2024
-
7.2
HIGHCVE-2024-50829
A SQL Injection vulnerability was found in /admin/edit_subject.php in kashipara E-learning Management System Project 1.0 via the unit parameter.... Read more
Affected Products : e-learning_management_system- Published: Nov. 14, 2024
- Modified: Nov. 18, 2024