Latest CVE Feed
-
8.7
HIGHCVE-2024-52004
MediaCMS is an open source video and media CMS, written in Python/Django and React, featuring a REST API. MediaCMS has been prone to vulnerabilities that upon special cases can lead to remote code execution. All versions before v4.1.0 are susceptible, and... Read more
Affected Products :- Published: Nov. 08, 2024
- Modified: Nov. 12, 2024
-
5.4
MEDIUMCVE-2024-52312
Due to inconsistent authorization permissions, data.all may allow an external actor with an authenticated account to perform restricted operations against DataSets and Environments.... Read more
Affected Products :- Published: Nov. 09, 2024
- Modified: Nov. 12, 2024
-
6.3
MEDIUMCVE-2024-52311
Authentication tokens issued via Cognito in data.all are not invalidated on log out, allowing for previously authenticated user to continue execution of authorized API Requests until token is expired.... Read more
Affected Products :- Published: Nov. 09, 2024
- Modified: Nov. 12, 2024
-
8.6
HIGHCVE-2024-52007
HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. XSLT parsing performed by various components are vulnerable to XML external entity injections. A processed XML file with a malicious DTD tag ( <!DOCTY... Read more
Affected Products :- Published: Nov. 08, 2024
- Modified: Nov. 12, 2024
-
9.8
CRITICALCVE-2024-10586
The Debug Tool plugin for WordPress is vulnerable to arbitrary file creation due to a missing capability check on the dbt_pull_image() function and missing file type validation in all versions up to, and including, 2.2. This makes it possible for unauthen... Read more
Affected Products :- Published: Nov. 09, 2024
- Modified: Nov. 12, 2024
-
5.3
MEDIUMCVE-2024-10953
An authenticated data.all user is able to perform mutating UPDATE operations on persisted Notification records in data.all for group notifications that their user is not a member of.... Read more
Affected Products :- Published: Nov. 09, 2024
- Modified: Nov. 12, 2024
-
8.1
HIGHCVE-2024-51997
Trustee is a set of tools and components for attesting confidential guests and providing secrets to them. The ART (**Attestation Results Token**) token, generated by AS, could be manipulated by MITM attacker, but the verifier (CoCo Verification Demander l... Read more
Affected Products :- Published: Nov. 08, 2024
- Modified: Nov. 12, 2024
-
7.1
HIGHCVE-2024-51716
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Gopi.R Twitter real time search scrolling allows Reflected XSS.This issue affects Twitter real time search scrolling: from n/a through 7.0.... Read more
Affected Products :- Published: Nov. 09, 2024
- Modified: Nov. 12, 2024
-
8.5
HIGHCVE-2024-51623
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Mehrdad Farahani WP EIS allows SQL Injection.This issue affects WP EIS: from n/a through 1.3.3.... Read more
Affected Products :- Published: Nov. 09, 2024
- Modified: Nov. 12, 2024
-
6.5
MEDIUMCVE-2024-51628
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in EzyOnlineBookings EzyOnlineBookings Online Booking System Widget allows DOM-Based XSS.This issue affects EzyOnlineBookings Online Booking System W... Read more
Affected Products :- Published: Nov. 09, 2024
- Modified: Nov. 12, 2024
-
9.8
CRITICALCVE-2024-10470
The WPLMS Learning Management System for WordPress, WordPress LMS theme for WordPress is vulnerable to arbitrary file read and deletion due to insufficient file path validation and permissions checks in the readfile and unlink functions in all versions up... Read more
Affected Products : wordpress_learning_management_system_- Published: Nov. 09, 2024
- Modified: Nov. 12, 2024
-
6.1
MEDIUMCVE-2024-10876
The Charitable – Donation Plugin for WordPress – Fundraising with Recurring Donations & More plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg & remove_query_arg without appropriate escaping on the URL in... Read more
Affected Products : charitable- Published: Nov. 09, 2024
- Modified: Nov. 12, 2024
-
7.1
HIGHCVE-2024-51713
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in TRe Technology And Research S.R.L HQ60 Fidelity Card allows Reflected XSS.This issue affects HQ60 Fidelity Card: from n/a through 1.8.... Read more
Affected Products :- Published: Nov. 09, 2024
- Modified: Nov. 12, 2024
-
7.1
HIGHCVE-2024-51695
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Fabrica Fabrica Synced Pattern Instances allows Reflected XSS.This issue affects Fabrica Synced Pattern Instances: from n/a through 1.0.8.... Read more
Affected Products :- Published: Nov. 09, 2024
- Modified: Nov. 12, 2024
-
6.5
MEDIUMCVE-2024-51622
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WP Experts Team WP EASY RECIPE allows Stored XSS.This issue affects WP EASY RECIPE: from n/a through 1.6.... Read more
Affected Products :- Published: Nov. 09, 2024
- Modified: Nov. 12, 2024
-
8.5
HIGHCVE-2024-50539
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Lodgix Lodgix.Com Vacation Rental Website Builder allows SQL Injection.This issue affects Lodgix.Com Vacation Rental Website Builder: from n/a through 3.... Read more
Affected Products :- Published: Nov. 09, 2024
- Modified: Nov. 12, 2024
-
7.1
HIGHCVE-2024-51630
Cross-Site Request Forgery (CSRF) vulnerability in Lars Schenk Responsive Flickr Gallery allows Stored XSS.This issue affects Responsive Flickr Gallery: from n/a through 1.3.1.... Read more
Affected Products :- Published: Nov. 09, 2024
- Modified: Nov. 12, 2024
-
6.5
MEDIUMCVE-2024-51627
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Kaedinger Audio Comparison Lite audio-comparison-lite allows Stored XSS.This issue affects Audio Comparison Lite: from n/a through 3.4.... Read more
Affected Products :- Published: Nov. 09, 2024
- Modified: Nov. 12, 2024
-
7.1
HIGHCVE-2024-51782
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Sanjaysolutions Loginplus allows Stored XSS.This issue affects Loginplus: from n/a through 1.2.... Read more
Affected Products :- Published: Nov. 09, 2024
- Modified: Nov. 12, 2024
-
4.4
MEDIUMCVE-2024-51785
Server-Side Request Forgery (SSRF) vulnerability in I Thirteen Web Solution Responsive Filterable Portfolio allows Server Side Request Forgery.This issue affects Responsive Filterable Portfolio: from n/a through 1.0.22.... Read more
Affected Products :- Published: Nov. 09, 2024
- Modified: Nov. 12, 2024