Latest CVE Feed
-
5.9
MEDIUMCVE-2024-50431
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Cloudways Breeze allows Stored XSS.This issue affects Breeze: from n/a through 2.1.14.... Read more
Affected Products :- Published: Oct. 28, 2024
- Modified: Oct. 29, 2024
-
8.8
HIGHCVE-2024-42028
A Local privilege escalation vulnerability found in a Self-Hosted UniFi Network Server with UniFi Network Application (Version 8.4.62 and earlier) allows a malicious actor with a local operational system user to execute high privilege actions on UniFi Net... Read more
Affected Products : unifi_network_application- Published: Oct. 28, 2024
- Modified: Oct. 29, 2024
-
3.1
LOWCVE-2024-49755
Duende IdentityServer is an OpenID Connect and OAuth 2.x framework for ASP.NET Core. IdentityServer's local API authentication handler performs insufficient validation of the cnf claim in DPoP access tokens. This allows an attacker to use leaked DPoP acce... Read more
Affected Products :- Published: Oct. 28, 2024
- Modified: Oct. 29, 2024
-
6.5
MEDIUMCVE-2024-50429
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WPBlockArt Magazine Blocks allows Stored XSS.This issue affects Magazine Blocks: from n/a through 1.3.15.... Read more
Affected Products : magazine_blocks- Published: Oct. 28, 2024
- Modified: Oct. 29, 2024
-
5.3
MEDIUMCVE-2024-49771
MPXJ is an open source library to read and write project plans from a variety of file formats and databases. The patch for the historical vulnerability CVE-2020-35460 in MPXJ is incomplete as there is still a possibility that a malicious path could be con... Read more
Affected Products :- Published: Oct. 28, 2024
- Modified: Oct. 29, 2024
-
9.8
CRITICALCVE-2024-50550
Incorrect Privilege Assignment vulnerability in LiteSpeed Technologies LiteSpeed Cache allows Privilege Escalation.This issue affects LiteSpeed Cache: from n/a through 6.5.1.... Read more
Affected Products : litespeed_cache- Published: Oct. 29, 2024
- Modified: Oct. 29, 2024
-
10.0
CRITICALCVE-2024-50494
Unrestricted Upload of File with Dangerous Type vulnerability in Amin Omer Sudan Payment Gateway for WooCommerce allows Upload a Web Shell to a Web Server.This issue affects Sudan Payment Gateway for WooCommerce: from n/a through 1.2.2.... Read more
Affected Products :- Published: Oct. 29, 2024
- Modified: Oct. 29, 2024
-
4.3
MEDIUMCVE-2024-50052
Mattermost versions 9.10.x <= 9.10.2, 9.11.x <= 9.11.1, 9.5.x <= 9.5.9 fail to check that the origin of the message in an integration action matches with the original post metadata which allows an authenticated user to delete an arbitrary post.... Read more
- Published: Oct. 29, 2024
- Modified: Oct. 29, 2024
-
5.1
MEDIUMCVE-2024-10479
A vulnerability, which was classified as problematic, was found in LinZhaoguan pb-cms up to 2.0.1. Affected is an unknown function of the file /admin#themes of the component Theme Management Module. The manipulation leads to cross site scripting. It is po... Read more
Affected Products : pb-cms- Published: Oct. 29, 2024
- Modified: Oct. 29, 2024
-
8.8
HIGHCVE-2024-10436
The WPC Smart Messages for WooCommerce plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 4.2.1 via the get_condition_value function. This makes it possible for authenticated attackers, with Subscriber-level a... Read more
Affected Products :- Published: Oct. 29, 2024
- Modified: Oct. 29, 2024
-
10.0
CRITICALCVE-2024-50493
Unrestricted Upload of File with Dangerous Type vulnerability in masterhomepage Automatic Translation allows Upload a Web Shell to a Web Server.This issue affects Automatic Translation: from n/a through 1.0.4.... Read more
Affected Products :- Published: Oct. 29, 2024
- Modified: Oct. 29, 2024
-
10.0
CRITICALCVE-2024-50420
Unrestricted Upload of File with Dangerous Type vulnerability in adirectory aDirectory allows Upload a Web Shell to a Web Server.This issue affects aDirectory: from n/a through 1.3.... Read more
Affected Products : adirectory- Published: Oct. 29, 2024
- Modified: Oct. 29, 2024
-
9.9
CRITICALCVE-2024-50427
Unrestricted Upload of File with Dangerous Type vulnerability in Devsoft Baltic OÜ SurveyJS: Drag & Drop WordPress Form Builder.This issue affects SurveyJS: Drag & Drop WordPress Form Builder: from n/a through 1.9.136.... Read more
Affected Products :- Published: Oct. 29, 2024
- Modified: Oct. 29, 2024
-
4.3
MEDIUMCVE-2024-10241
Mattermost versions 9.5.x <= 9.5.9 fail to properly filter the channel data when ElasticSearch is enabled which allows a user to get private channel names by using cmd+K/ctrl+K.... Read more
- Published: Oct. 29, 2024
- Modified: Oct. 29, 2024
-
9.8
CRITICALCVE-2024-50490
Missing Authorization vulnerability in Szabolcs Szecsenyi PegaPoll allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects PegaPoll: from n/a through 1.0.2.... Read more
Affected Products :- Published: Oct. 29, 2024
- Modified: Oct. 29, 2024
-
5.9
MEDIUMCVE-2024-50415
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Pagup Ads.Txt & App-ads.Txt Manager for WordPress allows Stored XSS.This issue affects Ads.Txt & App-ads.Txt Manager for WordPress: from n/a throu... Read more
Affected Products :- Published: Oct. 29, 2024
- Modified: Oct. 29, 2024
-
10.0
CRITICALCVE-2024-50482
Unrestricted Upload of File with Dangerous Type vulnerability in Chetan Khandla Woocommerce Product Design allows Upload a Web Shell to a Web Server.This issue affects Woocommerce Product Design: from n/a through 1.0.0.... Read more
Affected Products :- Published: Oct. 29, 2024
- Modified: Oct. 29, 2024
-
6.4
MEDIUMCVE-2024-10227
The affiliate-toolkit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's atkp_product shortcode in all versions up to, and including, 3.6.5 due to insufficient input sanitization and output escaping on user supplied attribu... Read more
Affected Products : affiliate-toolkit- Published: Oct. 29, 2024
- Modified: Oct. 29, 2024
-
6.1
MEDIUMCVE-2024-10048
The Post Status Notifier Lite and Premium plugins for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘page’ parameter in all versions up to, and including, 1.11.6 due to insufficient input sanitization and output escaping. This makes it... Read more
Affected Products : post_status_notifier_lite- Published: Oct. 29, 2024
- Modified: Oct. 29, 2024
-
9.9
CRITICALCVE-2024-50480
Unrestricted Upload of File with Dangerous Type vulnerability in azexo Marketing Automation by AZEXO allows Upload a Web Shell to a Web Server.This issue affects Marketing Automation by AZEXO: from n/a through 1.27.80.... Read more
Affected Products :- Published: Oct. 29, 2024
- Modified: Oct. 29, 2024