Latest CVE Feed
-
8.8
HIGHCVE-2020-20124
Wuzhi CMS v4.1.0 contains a remote code execution (RCE) vulnerability in \attachment\admin\index.php.... Read more
- Published: Sep. 28, 2021
- Modified: May. 05, 2025
-
6.1
MEDIUMCVE-2020-19897
A reflected Cross Site Scripting (XSS) in wuzhicms v4.1.0 allows remote attackers to execute arbitrary web script or HTML via the imgurl parameter.... Read more
- Published: Jun. 28, 2022
- Modified: May. 05, 2025
-
5.4
MEDIUMCVE-2020-19770
A cross-site scripting (XSS) vulnerability in the system bulletin component of WUZHI CMS v4.1.0 allows attackers to steal the admin's cookie.... Read more
- Published: Dec. 21, 2021
- Modified: May. 05, 2025
-
6.1
MEDIUMCVE-2019-9110
XSS exists in WUZHI CMS 4.1.0 via index.php?m=content&f=postinfo&v=listing&set_iframe=[XSS] to coreframe/app/content/postinfo.php.... Read more
- Published: Feb. 25, 2019
- Modified: May. 05, 2025
-
8.8
HIGHCVE-2018-18712
An issue was discovered in WUZHI CMS 4.1.0. There is a CSRF vulnerability that can change the super administrator's username via index.php?m=member&f=index&v=edit&uid=1.... Read more
- Published: Oct. 29, 2018
- Modified: May. 05, 2025
-
5.4
MEDIUMCVE-2018-17426
WUZHI CMS 4.1.0 has stored XSS via the "Extension module" "SMS in station" field under the index.php?m=core URI.... Read more
- Published: Mar. 07, 2019
- Modified: May. 05, 2025
-
5.4
MEDIUMCVE-2018-11549
An issue was discovered in WUZHI CMS 4.1.0 There is a Stored XSS Vulnerability in "Account Settings -> Member Centre -> Chinese information -> Ordinary member" via a QQ number, as demonstrated by a form[qq_10]= substring.... Read more
- Published: May. 29, 2018
- Modified: May. 05, 2025
-
8.8
HIGHCVE-2018-11493
An issue was discovered in WUZHI CMS 4.1.0. There is a CSRF vulnerability that can add a friendship link via index.php?m=link&f=index&v=add.... Read more
- Published: May. 26, 2018
- Modified: May. 05, 2025
-
4.8
MEDIUMCVE-2018-10368
An issue was discovered in WUZHI CMS 4.1.0. The "Extension Module -> System Announcement" feature has Stored XSS via an announcement.... Read more
- Published: Apr. 25, 2018
- Modified: May. 05, 2025
-
4.8
MEDIUMCVE-2018-10367
An issue was discovered in WUZHI CMS 4.1.0. The content-management feature has Stored XSS via the title or content section.... Read more
- Published: Apr. 25, 2018
- Modified: May. 05, 2025
-
6.5
MEDIUMCVE-2018-10248
An issue was discovered in WUZHI CMS 4.1.0. There is a CSRF vulnerability that can delete any article via index.php?m=content&f=content&v=recycle_delete.... Read more
- Published: Apr. 20, 2018
- Modified: May. 05, 2025
-
6.1
MEDIUMCVE-2024-1331
The Team Members WordPress plugin before 5.3.2 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the author role and above to perform Stored ... Read more
Affected Products : team_members- Published: Mar. 18, 2024
- Modified: May. 05, 2025
-
5.4
MEDIUMCVE-2024-1333
The Responsive Pricing Table WordPress plugin before 5.1.11 does not validate and escape some of its Pricing Table options before outputting them back in a page/post where the related shortcode is embed, which could allow users with the author role and ab... Read more
Affected Products : responsive_pricing_table- Published: Mar. 18, 2024
- Modified: May. 05, 2025
-
5.4
MEDIUMCVE-2024-1658
The Grid Shortcodes WordPress plugin before 1.1.1 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform... Read more
Affected Products : grid_shortcodes- Published: Mar. 18, 2024
- Modified: May. 05, 2025
-
5.4
MEDIUMCVE-2023-7085
The Scalable Vector Graphics (SVG) WordPress plugin through 3.4 does not sanitize uploaded SVG files, which could allow users with a role as low as Author to upload a malicious SVG containing XSS payloads.... Read more
Affected Products : scalable_vector_graphics_\(svg\)- Published: Mar. 18, 2024
- Modified: May. 05, 2025
-
4.7
MEDIUMCVE-2023-7236
The Backup Bolt WordPress plugin through 1.3.0 is vulnerable to Information Exposure via the unprotected access of debug logs. This makes it possible for unauthenticated attackers to retrieve the debug log which may contain information like system errors ... Read more
Affected Products : backup_bolt- Published: Mar. 18, 2024
- Modified: May. 05, 2025
-
5.9
MEDIUMCVE-2024-20019
In wlan driver, there is a possible memory leak due to improper input handling. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00351241; Issue ID:... Read more
- Published: Mar. 04, 2024
- Modified: May. 05, 2025
-
8.8
HIGHCVE-2024-28424
zenml v0.55.4 was discovered to contain an arbitrary file upload vulnerability in the load function at /materializers/cloudpickle_materializer.py. This vulnerability allows attackers to execute arbitrary code via uploading a crafted file.... Read more
Affected Products : zenml- Published: Mar. 14, 2024
- Modified: May. 05, 2025
-
4.3
MEDIUMCVE-2021-47208
The Mojolicious module before 9.11 for Perl has a bug in format detection that can potentially be exploited for denial of service.... Read more
Affected Products : mojolicious- Published: Apr. 08, 2024
- Modified: May. 05, 2025
-
9.8
CRITICALCVE-2024-20017
In wlan service, there is a possible out of bounds write due to improper input validation. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation Patch ID: WCNCR00350938; Is... Read more
- Published: Mar. 04, 2024
- Modified: May. 05, 2025