Latest CVE Feed
-
6.1
MEDIUMCVE-2024-10049
The Edit WooCommerce Templates plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘page’ parameter in all versions up to, and including, 1.1.2 due to insufficient input sanitization and output escaping. This makes it possible for... Read more
- Published: Oct. 18, 2024
- Modified: Oct. 29, 2024
-
6.1
MEDIUMCVE-2024-8740
The GetResponse Forms by Optin Cat plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 2.5.6. This makes it possible for unauthe... Read more
Affected Products : getresponse_forms- Published: Oct. 18, 2024
- Modified: Oct. 29, 2024
-
6.1
MEDIUMCVE-2024-8790
The Social Share With Floating Bar plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 1.0.3. This makes it possible for unauthe... Read more
Affected Products : social_share_with_floating_bar- Published: Oct. 18, 2024
- Modified: Oct. 29, 2024
-
6.4
MEDIUMCVE-2024-8916
The Suki Sites Import plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.2.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated a... Read more
Affected Products : suki_sites_import- Published: Oct. 18, 2024
- Modified: Oct. 29, 2024
-
5.9
MEDIUMCVE-2024-50431
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Cloudways Breeze allows Stored XSS.This issue affects Breeze: from n/a through 2.1.14.... Read more
Affected Products :- Published: Oct. 28, 2024
- Modified: Oct. 29, 2024
-
6.5
MEDIUMCVE-2024-50429
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WPBlockArt Magazine Blocks allows Stored XSS.This issue affects Magazine Blocks: from n/a through 1.3.15.... Read more
Affected Products : magazine_blocks- Published: Oct. 28, 2024
- Modified: Oct. 29, 2024
-
8.8
HIGHCVE-2024-42028
A Local privilege escalation vulnerability found in a Self-Hosted UniFi Network Server with UniFi Network Application (Version 8.4.62 and earlier) allows a malicious actor with a local operational system user to execute high privilege actions on UniFi Net... Read more
Affected Products : unifi_network_application- Published: Oct. 28, 2024
- Modified: Oct. 29, 2024
-
6.5
MEDIUMCVE-2024-50464
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Pierre Lebedel Kodex Posts likes allows Stored XSS.This issue affects Kodex Posts likes: from n/a through 2.5.0.... Read more
Affected Products :- Published: Oct. 28, 2024
- Modified: Oct. 29, 2024
-
6.5
MEDIUMCVE-2024-50432
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in PickPlugins Post Grid and Gutenberg Blocks allows Stored XSS.This issue affects Post Grid and Gutenberg Blocks: from n/a through 2.2.93.... Read more
Affected Products : post_grid- Published: Oct. 28, 2024
- Modified: Oct. 29, 2024
-
6.5
MEDIUMCVE-2024-50468
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Michael Robinson Raptor Editor allows DOM-Based XSS.This issue affects Raptor Editor: from n/a through 1.0.20.... Read more
Affected Products :- Published: Oct. 28, 2024
- Modified: Oct. 29, 2024
-
3.1
LOWCVE-2024-49755
Duende IdentityServer is an OpenID Connect and OAuth 2.x framework for ASP.NET Core. IdentityServer's local API authentication handler performs insufficient validation of the cnf claim in DPoP access tokens. This allows an attacker to use leaked DPoP acce... Read more
Affected Products :- Published: Oct. 28, 2024
- Modified: Oct. 29, 2024
-
5.3
MEDIUMCVE-2024-49771
MPXJ is an open source library to read and write project plans from a variety of file formats and databases. The patch for the historical vulnerability CVE-2020-35460 in MPXJ is incomplete as there is still a possibility that a malicious path could be con... Read more
Affected Products :- Published: Oct. 28, 2024
- Modified: Oct. 29, 2024
-
5.4
MEDIUMCVE-2024-9629
The Contact Form 7 + Telegram plugin for WordPress is vulnerable to unauthorized modification of data and loss of data due to a missing capability check on the 'wpcf7_Telegram::ajax' function in versions up to, and including, 0.8.5. This makes it possible... Read more
Affected Products :- Published: Oct. 28, 2024
- Modified: Oct. 29, 2024
-
7.5
HIGHCVE-2024-50436
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Theme Horse Clean Retina.This issue affects Clean Retina: from n/a through 3.0.6.... Read more
Affected Products :- Published: Oct. 28, 2024
- Modified: Oct. 29, 2024
-
6.5
MEDIUMCVE-2024-50467
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WebXApp Scrollbar by webxapp – Best vertical/horizontal scrollbars plugin allows Stored XSS.This issue affects Scrollbar by webxapp – Best vertica... Read more
Affected Products :- Published: Oct. 28, 2024
- Modified: Oct. 29, 2024
-
7.5
HIGHCVE-2024-50457
: Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Qode Interactive Qode Essential Addons.This issue affects Qode Essential Addons: from n/a through 1.6.3.... Read more
Affected Products :- Published: Oct. 28, 2024
- Modified: Oct. 29, 2024
-
6.5
MEDIUMCVE-2024-50469
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Team Bright Vessel Textboxes allows DOM-Based XSS.This issue affects Textboxes: from n/a through 0.1.3.1.... Read more
Affected Products :- Published: Oct. 28, 2024
- Modified: Oct. 29, 2024
-
7.5
HIGHCVE-2024-50434
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Theme Horse NewsCard.This issue affects NewsCard: from n/a through 1.3.... Read more
Affected Products :- Published: Oct. 28, 2024
- Modified: Oct. 29, 2024
-
7.5
HIGHCVE-2024-50435
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Theme Horse Meta News.This issue affects Meta News: from n/a through 1.1.7.... Read more
Affected Products :- Published: Oct. 28, 2024
- Modified: Oct. 29, 2024
-
6.5
MEDIUMCVE-2024-50462
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Fla-shop Interactive World Map allows Stored XSS.This issue affects Interactive World Map: from n/a through 3.4.4.... Read more
Affected Products :- Published: Oct. 28, 2024
- Modified: Oct. 29, 2024