Latest CVE Feed
-
9.8
CRITICALCVE-2024-50459
Missing Authorization vulnerability in HM Plugin WordPress Stripe Donation and Payment Plugin allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WordPress Stripe Donation and Payment Plugin: from n/a through 3.2.3.... Read more
Affected Products : aidwp- Published: Oct. 29, 2024
- Modified: Nov. 06, 2024
-
5.3
MEDIUMCVE-2024-10491
A vulnerability has been identified in the Express response.links function, allowing for arbitrary resource injection in the Link header when unsanitized data is used. The issue arises from improper sanitization in `Link` header values, which can allow a... Read more
Affected Products : express- Published: Oct. 29, 2024
- Modified: Nov. 06, 2024
-
4.9
MEDIUMCVE-2023-5816
The Code Explorer plugin for WordPress is vulnerable to arbitrary external file reading in all versions up to, and including, 1.4.5. This is due to the fact that the plugin does not restrict accessing files to those outside of the WordPress instance, thou... Read more
Affected Products : code_explorer- Published: Oct. 30, 2024
- Modified: Nov. 06, 2024
-
6.4
MEDIUMCVE-2024-8627
The Ultimate TinyMCE plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'field' shortcode in all versions up to, and including, 5.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated... Read more
Affected Products : ultimate_tinymce- Published: Oct. 30, 2024
- Modified: Nov. 06, 2024
-
5.5
MEDIUMCVE-2024-45086
IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A privileged user could exploit this vulnerability to expose sensitive information or consume memory resources.... Read more
Affected Products : websphere_application_server- Published: Nov. 04, 2024
- Modified: Nov. 06, 2024
-
5.4
MEDIUMCVE-2024-21264
Vulnerability in the PeopleSoft Enterprise CC Common Application Objects product of Oracle PeopleSoft (component: Activity Guide Composer). The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker wi... Read more
- Published: Oct. 15, 2024
- Modified: Nov. 06, 2024
-
5.3
MEDIUMCVE-2024-21258
Vulnerability in the Oracle Installed Base product of Oracle E-Business Suite (component: User Interface). Supported versions that are affected are 12.2.3-12.2.14. Easily exploitable vulnerability allows unauthenticated attacker with network access via H... Read more
Affected Products : installed_base- Published: Oct. 15, 2024
- Modified: Nov. 06, 2024
-
3.0
LOWCVE-2024-21257
Vulnerability in the Oracle Hyperion BI+ product of Oracle Hyperion (component: UI and Visualization). The supported version that is affected is 11.2.18.0.000. Easily exploitable vulnerability allows low privileged attacker with access to the physical c... Read more
Affected Products : hyperion_bi\+- Published: Oct. 15, 2024
- Modified: Nov. 06, 2024
-
8.1
HIGHCVE-2024-21250
Vulnerability in the Oracle Process Manufacturing Product Development product of Oracle E-Business Suite (component: Quality Manager Specification). Supported versions that are affected are 12.2.13-12.2.14. Easily exploitable vulnerability allows low pri... Read more
Affected Products : process_manufacturing_product_development- Published: Oct. 15, 2024
- Modified: Nov. 06, 2024
-
4.3
MEDIUMCVE-2024-21249
Vulnerability in the PeopleSoft Enterprise FIN Expenses product of Oracle PeopleSoft (component: Expenses). The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to co... Read more
Affected Products : peoplesoft_enterprise_fin_expenses- Published: Oct. 15, 2024
- Modified: Nov. 06, 2024
-
8.0
HIGHCVE-2024-10841
A vulnerability classified as critical was found in romadebrian WEB-Sekolah 1.0. Affected by this vulnerability is an unknown functionality of the file /Proses_Kirim.php of the component Mail Handler. The manipulation of the argument Name leads to sql inj... Read more
Affected Products : web-sekolah- Published: Nov. 05, 2024
- Modified: Nov. 06, 2024
-
5.1
MEDIUMCVE-2024-10840
A vulnerability classified as problematic has been found in romadebrian WEB-Sekolah 1.0. Affected is an unknown function of the file /Admin/akun_edit.php of the component Backend. The manipulation of the argument kode leads to cross site scripting. It is ... Read more
Affected Products : web-sekolah- Published: Nov. 05, 2024
- Modified: Nov. 06, 2024
-
5.1
MEDIUMCVE-2024-10842
A vulnerability, which was classified as problematic, has been found in romadebrian WEB-Sekolah 1.0. Affected by this issue is some unknown functionality of the file /Admin/Proses_Edit_Akun.php of the component Backend. The manipulation of the argument Us... Read more
Affected Products : web-sekolah- Published: Nov. 05, 2024
- Modified: Nov. 06, 2024
-
9.8
CRITICALCVE-2024-10844
A vulnerability, which was classified as critical, was found in 1000 Projects Bookstore Management System 1.0. This affects an unknown part of the file search.php. The manipulation of the argument s leads to sql injection. It is possible to initiate the a... Read more
- Published: Nov. 05, 2024
- Modified: Nov. 06, 2024
-
9.8
CRITICALCVE-2024-10845
A vulnerability has been found in 1000 Projects Bookstore Management System 1.0 and classified as critical. This vulnerability affects unknown code of the file book_detail.php. The manipulation of the argument id leads to sql injection. The attack can be ... Read more
- Published: Nov. 05, 2024
- Modified: Nov. 06, 2024
-
8.7
HIGHCVE-2024-49370
Pimcore is an open source data and experience management platform. When a PortalUserObject is connected to a PimcoreUser and "Use Pimcore Backend Password" is set to true, the change password function in Portal Profile sets the new password. Prior to Pimc... Read more
Affected Products : pimcore- Published: Oct. 23, 2024
- Modified: Nov. 06, 2024
-
8.8
HIGHCVE-2024-49675
Authentication Bypass Using an Alternate Path or Channel vulnerability in Vitalii Bryl iBryl Switch User allows Authentication Bypass.This issue affects iBryl Switch User: from n/a through 1.0.1.... Read more
Affected Products : switch_user- Published: Oct. 23, 2024
- Modified: Nov. 06, 2024
-
6.5
MEDIUMCVE-2024-51683
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Michael Gangolf Custom post type templates for Elementor allows Stored XSS.This issue affects Custom post type templates for Elementor: from n/a t... Read more
Affected Products : custom_post_type_templates_for_elementor- Published: Nov. 04, 2024
- Modified: Nov. 06, 2024
-
6.5
MEDIUMCVE-2024-51682
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in HasThemes HT Builder – WordPress Theme Builder for Elementor allows Stored XSS.This issue affects HT Builder – WordPress Theme Builder for Element... Read more
Affected Products : ht_builder- Published: Nov. 04, 2024
- Modified: Nov. 06, 2024
-
6.5
MEDIUMCVE-2024-51681
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in CodeRevolution WP Pocket URLs allows Stored XSS.This issue affects WP Pocket URLs: from n/a through 1.0.3.... Read more
Affected Products : wp_pocket_urls- Published: Nov. 04, 2024
- Modified: Nov. 06, 2024