Latest CVE Feed
-
6.5
MEDIUMCVE-2024-50449
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in RedefiningTheWeb PDF Generator Addon for Elementor Page Builder allows Stored XSS.This issue affects PDF Generator Addon for Elementor Page Builde... Read more
Affected Products : pdf_generator_addon_for_elementor_page_builder- Published: Oct. 28, 2024
- Modified: Nov. 08, 2024
-
7.1
HIGHCVE-2024-50448
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in YITH YITH WooCommerce Product Add-Ons allows Reflected XSS.This issue affects YITH WooCommerce Product Add-Ons: from n/a through 4.14.1.... Read more
Affected Products : yith_woocommerce_product_add-ons- Published: Oct. 28, 2024
- Modified: Nov. 08, 2024
-
5.5
MEDIUMCVE-2024-50111
In the Linux kernel, the following vulnerability has been resolved: LoongArch: Enable IRQ if do_ale() triggered in irq-enabled context Unaligned access exception can be triggered in irq-enabled context such as user mode, in this case do_ale() may call g... Read more
Affected Products : linux_kernel- Published: Nov. 05, 2024
- Modified: Nov. 08, 2024
-
6.4
MEDIUMCVE-2024-8323
The Pricing Tables WordPress Plugin – Easy Pricing Tables plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘fontFamily’ attribute in all versions up to, and including, 3.2.6 due to insufficient input sanitization and output escapi... Read more
Affected Products : easy_pricing_tables- Published: Nov. 06, 2024
- Modified: Nov. 08, 2024
-
6.4
MEDIUMCVE-2024-10168
The Active Products Tables for WooCommerce. Use constructor to create tables plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's woot_button shortcode in all versions up to, and including, 1.0.6.4 due to insufficient input s... Read more
- Published: Nov. 06, 2024
- Modified: Nov. 08, 2024
-
6.4
MEDIUMCVE-2024-10715
The MapPress Maps for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Map block in all versions up to, and including, 2.94.1 due to insufficient input sanitization and output escaping on user supplied attribute... Read more
Affected Products : mappress- Published: Nov. 06, 2024
- Modified: Nov. 08, 2024
-
10.0
CRITICALCVE-2024-8615
The JobSearch WP Job Board plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the jobsearch_location_load_excel_file_callback() function in all versions up to, and including, 2.6.7. This makes it possible f... Read more
Affected Products : jobsearch_wp_job_board- Published: Nov. 06, 2024
- Modified: Nov. 08, 2024
-
9.9
CRITICALCVE-2024-8614
The JobSearch WP Job Board plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the jobsearch_wp_handle_upload() function in all versions up to, and including, 2.6.7. This makes it possible for authenticated ... Read more
Affected Products : jobsearch_wp_job_board- Published: Nov. 06, 2024
- Modified: Nov. 08, 2024
-
6.9
MEDIUMCVE-2024-10916
A vulnerability classified as problematic has been found in D-Link DNS-320, DNS-320LW, DNS-325 and DNS-340L up to 20241028. This affects an unknown part of the file /xml/info.xml of the component HTTP GET Request Handler. The manipulation leads to informa... Read more
Affected Products : dns-320_firmware dns-320 dns-320lw_firmware dns-320lw dns-325_firmware dns-325 dns-340l_firmware dns-340l- Published: Nov. 06, 2024
- Modified: Nov. 08, 2024
-
9.8
CRITICALCVE-2024-10915
A vulnerability was found in D-Link DNS-320, DNS-320LW, DNS-325 and DNS-340L up to 20241028. It has been rated as critical. Affected by this issue is the function cgi_user_add of the file /cgi-bin/account_mgr.cgi?cmd=cgi_user_add. The manipulation of the ... Read more
Affected Products : dns-320_firmware dns-320 dns-320lw_firmware dns-320lw dns-325_firmware dns-325 dns-340l_firmware dns-340l- Published: Nov. 06, 2024
- Modified: Nov. 08, 2024
-
6.5
MEDIUMCVE-2024-50447
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in EnvoThemes Envo's Elementor Templates & Widgets for WooCommerce allows Stored XSS.This issue affects Envo's Elementor Templates & Widgets for WooC... Read more
Affected Products : envo\'s_elementor_templates_\&_widgets_for_woocommerce- Published: Oct. 28, 2024
- Modified: Nov. 08, 2024
-
7.1
HIGHCVE-2024-50123
In the Linux kernel, the following vulnerability has been resolved: bpf: Add the missing BPF_LINK_TYPE invocation for sockmap There is an out-of-bounds read in bpf_link_show_fdinfo() for the sockmap link fd. Fix it by adding the missing BPF_LINK_TYPE in... Read more
Affected Products : linux_kernel- Published: Nov. 05, 2024
- Modified: Nov. 08, 2024
-
8.7
HIGHCVE-2024-50334
Scoold is a Q&A and a knowledge sharing platform for teams. A semicolon path injection vulnerability was found on the /api;/config endpoint. By appending a semicolon in the URL, attackers can bypass authentication and gain unauthorised access to sensitive... Read more
Affected Products : scoold- Published: Oct. 29, 2024
- Modified: Nov. 08, 2024
-
5.4
MEDIUMCVE-2024-10318
A session fixation issue was discovered in the NGINX OpenID Connect reference implementation, where a nonce was not checked at login time. This flaw allows an attacker to fix a victim's session to an attacker-controlled account. As a result, although the ... Read more
- Published: Nov. 06, 2024
- Modified: Nov. 08, 2024
-
7.1
HIGHCVE-2024-50128
In the Linux kernel, the following vulnerability has been resolved: net: wwan: fix global oob in wwan_rtnl_policy The variable wwan_rtnl_link_ops assign a *bigger* maxtype which leads to a global out-of-bounds read when parsing the netlink attributes. E... Read more
Affected Products : linux_kernel- Published: Nov. 05, 2024
- Modified: Nov. 08, 2024
-
2.7
LOWCVE-2024-47190
Northern.tech Hosted Mender before 2024.07.11 allows SSRF.... Read more
Affected Products :- Published: Nov. 08, 2024
- Modified: Nov. 08, 2024
-
6.5
MEDIUMCVE-2024-46947
Northern.tech Mender before 3.6.6 and 3.7.x before 3.7.7 allows SSRF.... Read more
Affected Products : mender- Published: Nov. 08, 2024
- Modified: Nov. 08, 2024
-
6.4
MEDIUMCVE-2024-10186
The Event post plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's events_cal shortcode in all versions up to, and including, 5.9.6 due to insufficient input sanitization and output escaping on user supplied attributes. This... Read more
Affected Products : event_post- Published: Nov. 06, 2024
- Modified: Nov. 08, 2024
-
5.5
MEDIUMCVE-2024-50116
In the Linux kernel, the following vulnerability has been resolved: nilfs2: fix kernel bug due to missing clearing of buffer delay flag Syzbot reported that after nilfs2 reads a corrupted file system image and degrades to read-only, the BUG_ON check for... Read more
Affected Products : linux_kernel- Published: Nov. 05, 2024
- Modified: Nov. 08, 2024
-
7.1
HIGHCVE-2024-50115
In the Linux kernel, the following vulnerability has been resolved: KVM: nSVM: Ignore nCR3[4:0] when loading PDPTEs from memory Ignore nCR3[4:0] when loading PDPTEs from memory for nested SVM, as bits 4:0 of CR3 are ignored when PAE paging is used, and ... Read more
Affected Products : linux_kernel- Published: Nov. 05, 2024
- Modified: Nov. 08, 2024