Latest CVE Feed
-
6.5
MEDIUMCVE-2024-49665
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Web Bricks Web Bricks Addons for Elementor allows Stored XSS.This issue affects Web Bricks Addons for Elementor: from n/a through 1.1.1.... Read more
Affected Products : web_bricks_addons- Published: Oct. 29, 2024
- Modified: Nov. 01, 2024
-
6.5
MEDIUMCVE-2024-49667
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in NervyThemes Local Business Addons For Elementor allows Stored XSS.This issue affects Local Business Addons For Elementor: from n/a through 1.1.5.... Read more
Affected Products : local_business_addons_for_elementor- Published: Oct. 29, 2024
- Modified: Nov. 01, 2024
-
4.3
MEDIUMCVE-2024-9361
The Bulk images optimizer: Resize, optimize, convert to webp, rename … plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'save_configuration' function in all versions up to, and including, 2.0... Read more
Affected Products : bulk_images_optimizer- Published: Oct. 18, 2024
- Modified: Nov. 01, 2024
-
9.8
CRITICALCVE-2024-10119
The wireless router WRTM326 from SECOM does not properly validate a specific parameter. An unauthenticated remote attacker could execute arbitrary system commands by sending crafted requests.... Read more
- Published: Oct. 18, 2024
- Modified: Nov. 01, 2024
-
6.9
MEDIUMCVE-2024-10448
A vulnerability, which was classified as problematic, has been found in code-projects Blood Bank Management System 1.0. Affected by this issue is some unknown functionality of the file /file/delete.php. The manipulation of the argument bid leads to cross-... Read more
- Published: Oct. 28, 2024
- Modified: Nov. 01, 2024
-
5.3
MEDIUMCVE-2024-10040
The Infinite-Scroll plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.6.2. This is due to missing or incorrect nonce validation on the process_ajax_edit and process_ajax_delete function. This makes it... Read more
Affected Products : infinite-scroll- Published: Oct. 18, 2024
- Modified: Nov. 01, 2024
-
6.5
MEDIUMCVE-2024-20472
A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software could allow an authenticated, remote attacker to conduct SQL injection attacks on an affected system. This vulnerability exists because the ... Read more
- Published: Oct. 23, 2024
- Modified: Nov. 01, 2024
-
6.5
MEDIUMCVE-2024-20471
A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software could allow an authenticated, remote attacker to conduct SQL injection attacks on an affected system. This vulnerability exists because the ... Read more
- Published: Oct. 23, 2024
- Modified: Nov. 01, 2024
-
6.5
MEDIUMCVE-2024-20474
A vulnerability in Internet Key Exchange version 2 (IKEv2) processing of Cisco Secure Client Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) of Cisco Secure Client. This vulnerability is due to an integer und... Read more
- Published: Oct. 23, 2024
- Modified: Nov. 01, 2024
-
6.5
MEDIUMCVE-2024-20473
A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software could allow an authenticated, remote attacker to conduct SQL injection attacks on an affected system. This vulnerability exists because the ... Read more
- Published: Oct. 23, 2024
- Modified: Nov. 01, 2024
-
9.9
CRITICALCVE-2024-20424
A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software, formerly Firepower Management Center Software, could allow an authenticated, remote attacker to execute arbitrary commands on the underlying o... Read more
- Published: Oct. 23, 2024
- Modified: Nov. 01, 2024
-
8.5
HIGHCVE-2024-10093
A vulnerability, which was classified as critical, was found in VSO ConvertXtoDvd 7.0.0.83. Affected is an unknown function in the library avcodec.dll of the file ConvertXtoDvd.exe. The manipulation leads to uncontrolled search path. Attacking locally is ... Read more
Affected Products : convertxtodvd- Published: Oct. 17, 2024
- Modified: Nov. 01, 2024
-
7.5
HIGHCVE-2024-21536
Versions of the package http-proxy-middleware before 2.0.7, from 3.0.0 and before 3.0.3 are vulnerable to Denial of Service (DoS) due to an UnhandledPromiseRejection error thrown by micromatch. An attacker could kill the Node.js process and crash the serv... Read more
Affected Products : http-proxy-middleware- Published: Oct. 19, 2024
- Modified: Nov. 01, 2024
-
6.5
MEDIUMCVE-2024-20340
A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software, formerly Firepower Management Center Software, could allow an authenticated, remote attacker to perform an SQL injection attack against an aff... Read more
- Published: Oct. 23, 2024
- Modified: Nov. 01, 2024
-
6.8
MEDIUMCVE-2024-20331
A vulnerability in the session authentication functionality of the Remote Access SSL VPN feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to preve... Read more
- Published: Oct. 23, 2024
- Modified: Nov. 01, 2024
-
6.1
MEDIUMCVE-2024-9219
The WordPress Social Share Buttons plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 1.19. This makes it possible for unauthen... Read more
Affected Products : social_share_buttons- Published: Oct. 19, 2024
- Modified: Nov. 01, 2024
-
6.1
MEDIUMCVE-2024-20341
A vulnerability in the VPN web client services feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack aga... Read more
- Published: Oct. 23, 2024
- Modified: Nov. 01, 2024
-
8.8
HIGHCVE-2024-43684
Cross-Site Request Forgery (CSRF) vulnerability in Microchip TimeProvider 4100 allows Cross Site Request Forgery, Cross-Site Scripting (XSS).This issue affects TimeProvider 4100: from 1.0.... Read more
- Published: Oct. 04, 2024
- Modified: Nov. 01, 2024
-
8.8
HIGHCVE-2024-10131
The `add_llm` function in `llm_app.py` in infiniflow/ragflow version 0.11.0 contains a remote code execution (RCE) vulnerability. The function uses user-supplied input `req['llm_factory']` and `req['llm_name']` to dynamically instantiate classes from vari... Read more
Affected Products : ragflow- Published: Oct. 19, 2024
- Modified: Nov. 01, 2024
-
7.1
HIGHCVE-2024-49651
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Matt Royal WooCommerce Maintenance Mode allows Reflected XSS.This issue affects WooCommerce Maintenance Mode: from n/a through 2.0.1.... Read more
Affected Products : woocommerce_maintenance_mode- Published: Oct. 29, 2024
- Modified: Nov. 01, 2024