Latest CVE Feed
-
6.5
MEDIUMCVE-2024-51681
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in CodeRevolution WP Pocket URLs allows Stored XSS.This issue affects WP Pocket URLs: from n/a through 1.0.3.... Read more
Affected Products : wp_pocket_urls- Published: Nov. 04, 2024
- Modified: Nov. 06, 2024
-
6.5
MEDIUMCVE-2024-51680
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in CrestaProject – Rizzo Andrea Cresta Addons for Elementor allows Stored XSS.This issue affects Cresta Addons for Elementor: from n/a through 1.0.9.... Read more
Affected Products : cresta_addons_for_elementor- Published: Nov. 04, 2024
- Modified: Nov. 06, 2024
-
6.5
MEDIUMCVE-2024-51678
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Marcel Pol Elo Rating Shortcode allows Stored XSS.This issue affects Elo Rating Shortcode: from n/a through 1.0.3.... Read more
Affected Products : elo_rating_shortcode- Published: Nov. 04, 2024
- Modified: Nov. 06, 2024
-
6.5
MEDIUMCVE-2024-51677
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WebberZone Knowledge Base allows Stored XSS.This issue affects Knowledge Base: from n/a through 2.2.0.... Read more
Affected Products : knowledge_base- Published: Nov. 04, 2024
- Modified: Nov. 06, 2024
-
8.8
HIGHCVE-2024-51626
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Mansur Ahamed Woocommerce Quote Calculator allows Blind SQL Injection.This issue affects Woocommerce Quote Calculator: from n/a through 1.1.... Read more
Affected Products : woocommerce_quote_calculator- Published: Nov. 04, 2024
- Modified: Nov. 06, 2024
-
7.6
HIGHCVE-2024-51672
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WPDeveloper BetterLinks allows SQL Injection.This issue affects BetterLinks: from n/a through 2.1.7.... Read more
Affected Products : betterlinks- Published: Nov. 04, 2024
- Modified: Nov. 06, 2024
-
4.9
MEDIUMCVE-2024-51665
Server-Side Request Forgery (SSRF) vulnerability in Noor alam Magical Addons For Elementor allows Server Side Request Forgery.This issue affects Magical Addons For Elementor: from n/a through 1.2.1.... Read more
Affected Products : magical_addons_for_elementor- Published: Nov. 04, 2024
- Modified: Nov. 06, 2024
-
8.5
HIGHCVE-2024-51408
AppSmith Community 1.8.3 before 1.46 allows SSRF via New DataSource for application/json requests to 169.254.169.254 to retrieve AWS metadata credentials.... Read more
Affected Products : appsmith- Published: Nov. 04, 2024
- Modified: Nov. 06, 2024
-
5.1
MEDIUMCVE-2024-10122
A vulnerability was found in Topdata Inner Rep Plus WebServer 2.01. It has been classified as problematic. Affected is an unknown function of the file /InnerRepPlus.html of the component Operator Details Form. The manipulation leads to missing password fi... Read more
Affected Products : inner_rep_plus- Published: Oct. 18, 2024
- Modified: Nov. 06, 2024
-
9.8
CRITICALCVE-2024-48050
In agentscope <=v0.0.4, the file agentscope\web\workstation\workflow_utils.py has the function is_callable_expression. Within this function, the line result = eval(s) poses a security risk as it can directly execute user-provided commands.... Read more
Affected Products :- Published: Nov. 04, 2024
- Modified: Nov. 06, 2024
-
7.1
HIGHCVE-2024-49223
Cross-Site Request Forgery (CSRF) vulnerability in Shibu Lijack a.K.A CyberJack CJ Change Howdy allows Stored XSS.This issue affects CJ Change Howdy: from n/a through 3.3.1.... Read more
Affected Products : cj_change_howdy- Published: Oct. 17, 2024
- Modified: Nov. 06, 2024
-
7.1
HIGHCVE-2024-49221
Cross-Site Request Forgery (CSRF) vulnerability in Julian Weinert // cs&m cSlider allows Stored XSS.This issue affects cSlider: from n/a through 2.4.2.... Read more
Affected Products : cslider- Published: Oct. 17, 2024
- Modified: Nov. 06, 2024
-
9.8
CRITICALCVE-2024-49217
Incorrect Privilege Assignment vulnerability in Madiri Salman Aashish Adding drop down roles in registration allows Privilege Escalation.This issue affects Adding drop down roles in registration: from n/a through 1.1.... Read more
Affected Products : adding_drop_down_roles_in_registration- Published: Oct. 17, 2024
- Modified: Nov. 06, 2024
-
8.8
HIGHCVE-2024-49219
Incorrect Privilege Assignment vulnerability in themexpo RS-Members allows Privilege Escalation.This issue affects RS-Members: from n/a through 1.0.3.... Read more
Affected Products : rs-members- Published: Oct. 17, 2024
- Modified: Nov. 06, 2024
-
7.1
HIGHCVE-2024-49220
Cross-Site Request Forgery (CSRF) vulnerability in Cookie Scanner – Nikel Schubert Cookie Scanner allows Stored XSS.This issue affects Cookie Scanner: from n/a through 1.1.... Read more
Affected Products : cookie_scanner- Published: Oct. 17, 2024
- Modified: Nov. 06, 2024
-
7.1
HIGHCVE-2024-49229
Cross-Site Request Forgery (CSRF) vulnerability in Arif Nezami Better Author Bio allows Cross-Site Scripting (XSS).This issue affects Better Author Bio: from n/a through 2.7.10.11.... Read more
Affected Products : better_author_bio- Published: Oct. 17, 2024
- Modified: Nov. 06, 2024
-
6.5
MEDIUMCVE-2024-31880
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to a denial of service, under specific configurations, as the server may crash when using a specially crafted SQL statement by an authenticated user.... Read more
- Published: Oct. 23, 2024
- Modified: Nov. 06, 2024
-
6.5
MEDIUMCVE-2024-51362
The LSC Smart Connect Indoor IP Camera V7.6.32 is vulnerable to an information disclosure issue where live camera footage can be accessed through the RTSP protocol on port 8554 without requiring authentication. This allows unauthorized users with network ... Read more
Affected Products :- Published: Nov. 05, 2024
- Modified: Nov. 06, 2024
-
8.0
HIGHCVE-2024-51240
An issue in the luci-mod-rpc package in OpenWRT Luci LTS allows for privilege escalation from an admin account to root via the JSON-RPC-API, which is exposed by the luci-mod-rpc package... Read more
Affected Products :- Published: Nov. 05, 2024
- Modified: Nov. 06, 2024
-
9.8
CRITICALCVE-2024-51132
An XML External Entity (XXE) vulnerability in HAPI FHIR before v6.4.0 allows attackers to access sensitive information or execute arbitrary code via supplying a crafted request containing malicious XML entities.... Read more
Affected Products :- Published: Nov. 05, 2024
- Modified: Nov. 06, 2024