Latest CVE Feed
-
9.8
CRITICALCVE-2024-7042
A vulnerability in the GraphCypherQAChain class of langchain-ai/langchainjs versions 0.2.5 and all versions with this class allows for prompt injection, leading to SQL injection. This vulnerability permits unauthorized data manipulation, data exfiltration... Read more
- Published: Oct. 29, 2024
- Modified: Oct. 31, 2024
-
4.3
MEDIUMCVE-2024-48213
RockOA v2.6.5 is vulnerable to Directory Traversal in webmain/system/beifen/beifenAction.php.... Read more
Affected Products : xinhu- Published: Oct. 23, 2024
- Modified: Oct. 31, 2024
-
5.4
MEDIUMCVE-2024-10460
The origin of an external protocol handler prompt could have been obscured using a data: URL within an `iframe`. This vulnerability affects Firefox < 132, Firefox ESR < 128.4, Thunderbird < 128.4, and Thunderbird < 132.... Read more
- Published: Oct. 29, 2024
- Modified: Oct. 31, 2024
-
7.5
HIGHCVE-2024-10459
An attacker could have caused a use-after-free when accessibility was enabled, leading to a potentially exploitable crash. This vulnerability affects Firefox < 132, Firefox ESR < 128.4, Firefox ESR < 115.17, Thunderbird < 128.4, and Thunderbird < 132.... Read more
- Published: Oct. 29, 2024
- Modified: Oct. 31, 2024
-
7.5
HIGHCVE-2024-10458
A permission leak could have occurred from a trusted site to an untrusted site via `embed` or `object` elements. This vulnerability affects Firefox < 132, Firefox ESR < 128.4, Firefox ESR < 115.17, Thunderbird < 128.4, and Thunderbird < 132.... Read more
- Published: Oct. 29, 2024
- Modified: Oct. 31, 2024
-
9.1
CRITICALCVE-2024-5823
A file overwrite vulnerability exists in gaizhenbiao/chuanhuchatgpt versions <= 20240410. This vulnerability allows an attacker to gain unauthorized access to overwrite critical configuration files within the system. Exploiting this vulnerability can lead... Read more
Affected Products : chuanhuchatgpt- Published: Oct. 29, 2024
- Modified: Oct. 31, 2024
-
7.1
HIGHCVE-2024-49645
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Ilias Gomatos Affiliate Platform allows Reflected XSS.This issue affects Affiliate Platform: from n/a through 1.4.8.... Read more
Affected Products : affiliate_platform- Published: Oct. 29, 2024
- Modified: Oct. 31, 2024
-
7.1
HIGHCVE-2024-47640
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in weDevs WP ERP allows Reflected XSS.This issue affects WP ERP: from n/a through 1.13.2.... Read more
Affected Products : wp_erp- Published: Oct. 29, 2024
- Modified: Oct. 31, 2024
-
5.5
MEDIUMCVE-2024-40680
IBM MQ 9.3 CD and 9.4 LTS/CD could allow a local user to cause a denial of service due to improper memory allocation causing a segmentation fault.... Read more
- Published: Sep. 07, 2024
- Modified: Oct. 31, 2024
-
4.9
MEDIUMCVE-2024-34537
TYPO3 before 13.3.1 allows denial of service (interface error) in the Bookmark Toolbar (ext:backend), exploitable by an administrator-level backend user account via manipulated data saved in the bookmark toolbar of the backend user interface. The fixed ve... Read more
Affected Products : typo3- Published: Oct. 28, 2024
- Modified: Oct. 31, 2024
-
6.4
MEDIUMCVE-2024-10226
The Arconix Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'box' shortcode in all versions up to, and including, 2.1.13 due to insufficient input sanitization and output escaping on user supplied attributes. ... Read more
Affected Products : arconix_shortcodes- Published: Oct. 29, 2024
- Modified: Oct. 31, 2024
-
9.8
CRITICALCVE-2022-30357
OvalEdge 5.2.8.0 and earlier is affected by an Account Takeover vulnerability via a POST request to /profile/updateProfile via the userId and email parameters. Authentication is required.... Read more
Affected Products : ovaledge- Published: Oct. 25, 2024
- Modified: Oct. 31, 2024
-
8.8
HIGHCVE-2022-30358
OvalEdge 5.2.8.0 and earlier is affected by an Account Takeover vulnerability via a POST request to /user/updatePassword via the userId and newPsw parameters. Authentication is required.... Read more
Affected Products : ovaledge- Published: Oct. 25, 2024
- Modified: Oct. 31, 2024
-
6.4
MEDIUMCVE-2024-9505
The Beaver Builder – WordPress Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Button widget in all versions up to, and including, 2.8.4.2 due to insufficient input sanitization and output escaping on user s... Read more
Affected Products : beaver_builder- Published: Oct. 29, 2024
- Modified: Oct. 31, 2024
-
6.4
MEDIUMCVE-2022-30360
OvalEdge 5.2.8.0 and earlier is affected by multiple Stored XSS (AKA Persistent or Type II) vulnerabilities via a POST request to /profile/updateProfile via the slackid or phone parameters. Authentication is required.... Read more
Affected Products : ovaledge- Published: Oct. 25, 2024
- Modified: Oct. 31, 2024
-
5.4
MEDIUMCVE-2022-30359
OvalEdge 5.2.8.0 and earlier is affected by a Sensitive Data Exposure vulnerability via a GET request to /user/getUserList. Authentication is required. The information disclosed is associated with the all registered users, including user ID, status, email... Read more
Affected Products : ovaledge- Published: Oct. 25, 2024
- Modified: Oct. 31, 2024
-
5.3
MEDIUMCVE-2022-30361
OvalEdge 5.2.8.0 and earlier is affected by a Sensitive Data Exposure vulnerability via a GET request to /user/getUserType. No authentication is required. The information disclosed is associated with the registered user ID, status, email address, role(s),... Read more
Affected Products : ovaledge- Published: Oct. 25, 2024
- Modified: Oct. 31, 2024
-
7.1
HIGHCVE-2024-49632
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Coral Web Design CWD 3D Image Gallery allows Reflected XSS.This issue affects CWD 3D Image Gallery: from n/a through 1.0.... Read more
Affected Products : cwd_3d_image_gallery- Published: Oct. 29, 2024
- Modified: Oct. 31, 2024
-
8.8
HIGHCVE-2022-30356
OvalEdge 5.2.8.0 and earlier is affected by a Privilege Escalation vulnerability via a POST request to /user/assignuserrole via the userid and role parameters . Authentication is required with OE_ADMIN role privilege.... Read more
Affected Products : ovaledge- Published: Oct. 25, 2024
- Modified: Oct. 31, 2024
-
7.1
HIGHCVE-2024-49634
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Rimon Habib BP Member Type Manager allows Reflected XSS.This issue affects BP Member Type Manager: from n/a through 1.01.... Read more
Affected Products : bp_member_type_manager- Published: Oct. 29, 2024
- Modified: Oct. 31, 2024