Latest CVE Feed
-
8.7
HIGHCVE-2024-49370
Pimcore is an open source data and experience management platform. When a PortalUserObject is connected to a PimcoreUser and "Use Pimcore Backend Password" is set to true, the change password function in Portal Profile sets the new password. Prior to Pimc... Read more
Affected Products : pimcore- Published: Oct. 23, 2024
- Modified: Nov. 06, 2024
-
8.8
HIGHCVE-2024-49675
Authentication Bypass Using an Alternate Path or Channel vulnerability in Vitalii Bryl iBryl Switch User allows Authentication Bypass.This issue affects iBryl Switch User: from n/a through 1.0.1.... Read more
Affected Products : switch_user- Published: Oct. 23, 2024
- Modified: Nov. 06, 2024
-
6.5
MEDIUMCVE-2024-51683
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Michael Gangolf Custom post type templates for Elementor allows Stored XSS.This issue affects Custom post type templates for Elementor: from n/a t... Read more
Affected Products : custom_post_type_templates_for_elementor- Published: Nov. 04, 2024
- Modified: Nov. 06, 2024
-
6.5
MEDIUMCVE-2024-51682
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in HasThemes HT Builder – WordPress Theme Builder for Elementor allows Stored XSS.This issue affects HT Builder – WordPress Theme Builder for Element... Read more
Affected Products : ht_builder- Published: Nov. 04, 2024
- Modified: Nov. 06, 2024
-
6.5
MEDIUMCVE-2024-51681
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in CodeRevolution WP Pocket URLs allows Stored XSS.This issue affects WP Pocket URLs: from n/a through 1.0.3.... Read more
Affected Products : wp_pocket_urls- Published: Nov. 04, 2024
- Modified: Nov. 06, 2024
-
6.5
MEDIUMCVE-2024-51680
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in CrestaProject – Rizzo Andrea Cresta Addons for Elementor allows Stored XSS.This issue affects Cresta Addons for Elementor: from n/a through 1.0.9.... Read more
Affected Products : cresta_addons_for_elementor- Published: Nov. 04, 2024
- Modified: Nov. 06, 2024
-
6.5
MEDIUMCVE-2024-51678
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Marcel Pol Elo Rating Shortcode allows Stored XSS.This issue affects Elo Rating Shortcode: from n/a through 1.0.3.... Read more
Affected Products : elo_rating_shortcode- Published: Nov. 04, 2024
- Modified: Nov. 06, 2024
-
6.5
MEDIUMCVE-2024-51677
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WebberZone Knowledge Base allows Stored XSS.This issue affects Knowledge Base: from n/a through 2.2.0.... Read more
Affected Products : knowledge_base- Published: Nov. 04, 2024
- Modified: Nov. 06, 2024
-
8.8
HIGHCVE-2024-51626
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Mansur Ahamed Woocommerce Quote Calculator allows Blind SQL Injection.This issue affects Woocommerce Quote Calculator: from n/a through 1.1.... Read more
Affected Products : woocommerce_quote_calculator- Published: Nov. 04, 2024
- Modified: Nov. 06, 2024
-
7.6
HIGHCVE-2024-51672
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WPDeveloper BetterLinks allows SQL Injection.This issue affects BetterLinks: from n/a through 2.1.7.... Read more
Affected Products : betterlinks- Published: Nov. 04, 2024
- Modified: Nov. 06, 2024
-
4.9
MEDIUMCVE-2024-51665
Server-Side Request Forgery (SSRF) vulnerability in Noor alam Magical Addons For Elementor allows Server Side Request Forgery.This issue affects Magical Addons For Elementor: from n/a through 1.2.1.... Read more
Affected Products : magical_addons_for_elementor- Published: Nov. 04, 2024
- Modified: Nov. 06, 2024
-
8.5
HIGHCVE-2024-51408
AppSmith Community 1.8.3 before 1.46 allows SSRF via New DataSource for application/json requests to 169.254.169.254 to retrieve AWS metadata credentials.... Read more
Affected Products : appsmith- Published: Nov. 04, 2024
- Modified: Nov. 06, 2024
-
5.1
MEDIUMCVE-2024-10122
A vulnerability was found in Topdata Inner Rep Plus WebServer 2.01. It has been classified as problematic. Affected is an unknown function of the file /InnerRepPlus.html of the component Operator Details Form. The manipulation leads to missing password fi... Read more
Affected Products : inner_rep_plus- Published: Oct. 18, 2024
- Modified: Nov. 06, 2024
-
9.8
CRITICALCVE-2024-48050
In agentscope <=v0.0.4, the file agentscope\web\workstation\workflow_utils.py has the function is_callable_expression. Within this function, the line result = eval(s) poses a security risk as it can directly execute user-provided commands.... Read more
Affected Products :- Published: Nov. 04, 2024
- Modified: Nov. 06, 2024
-
7.1
HIGHCVE-2024-49223
Cross-Site Request Forgery (CSRF) vulnerability in Shibu Lijack a.K.A CyberJack CJ Change Howdy allows Stored XSS.This issue affects CJ Change Howdy: from n/a through 3.3.1.... Read more
Affected Products : cj_change_howdy- Published: Oct. 17, 2024
- Modified: Nov. 06, 2024
-
7.1
HIGHCVE-2024-49221
Cross-Site Request Forgery (CSRF) vulnerability in Julian Weinert // cs&m cSlider allows Stored XSS.This issue affects cSlider: from n/a through 2.4.2.... Read more
Affected Products : cslider- Published: Oct. 17, 2024
- Modified: Nov. 06, 2024
-
9.8
CRITICALCVE-2024-49217
Incorrect Privilege Assignment vulnerability in Madiri Salman Aashish Adding drop down roles in registration allows Privilege Escalation.This issue affects Adding drop down roles in registration: from n/a through 1.1.... Read more
Affected Products : adding_drop_down_roles_in_registration- Published: Oct. 17, 2024
- Modified: Nov. 06, 2024
-
8.8
HIGHCVE-2024-49219
Incorrect Privilege Assignment vulnerability in themexpo RS-Members allows Privilege Escalation.This issue affects RS-Members: from n/a through 1.0.3.... Read more
Affected Products : rs-members- Published: Oct. 17, 2024
- Modified: Nov. 06, 2024
-
7.1
HIGHCVE-2024-49220
Cross-Site Request Forgery (CSRF) vulnerability in Cookie Scanner – Nikel Schubert Cookie Scanner allows Stored XSS.This issue affects Cookie Scanner: from n/a through 1.1.... Read more
Affected Products : cookie_scanner- Published: Oct. 17, 2024
- Modified: Nov. 06, 2024
-
7.1
HIGHCVE-2024-49229
Cross-Site Request Forgery (CSRF) vulnerability in Arif Nezami Better Author Bio allows Cross-Site Scripting (XSS).This issue affects Better Author Bio: from n/a through 2.7.10.11.... Read more
Affected Products : better_author_bio- Published: Oct. 17, 2024
- Modified: Nov. 06, 2024