Latest CVE Feed
-
6.1
MEDIUMCVE-2024-9615
The BulkPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 0.3.5. This makes it possible for unauthenticated attackers to... Read more
Affected Products :- Published: Nov. 16, 2024
- Modified: Nov. 18, 2024
-
7.5
HIGHCVE-2024-10645
The Blogger 301 Redirect plugin for WordPress is vulnerable to blind time-based SQL Injection via the ‘br’ parameter in all versions up to, and including, 2.5.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation... Read more
Affected Products :- Published: Nov. 16, 2024
- Modified: Nov. 18, 2024
-
8.8
HIGHCVE-2024-9192
The WordPress Video Robot - The Ultimate Video Importer plugin for WordPress is vulnerable to privilege escalation due to insufficient validation on user meta that can be updated in the wpvr_rate_request_result() function in all versions up to, and includ... Read more
Affected Products :- Published: Nov. 16, 2024
- Modified: Nov. 18, 2024
-
8.8
HIGHCVE-2024-41969
A low privileged remote attacker may modify the configuration of the CODESYS V3 service through a missing authentication vulnerability which could lead to full system access and/or DoS.... Read more
Affected Products :- Published: Nov. 18, 2024
- Modified: Nov. 18, 2024
-
6.4
MEDIUMCVE-2024-9386
The Exclusive Divi – Divi Preloader, Modules for Divi & Extra Theme plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.4 due to insufficient input sanitization and output escaping... Read more
Affected Products :- Published: Nov. 16, 2024
- Modified: Nov. 18, 2024
-
9.9
CRITICALCVE-2024-52408
Unrestricted Upload of File with Dangerous Type vulnerability in Team PushAssist Push Notifications for WordPress by PushAssist allows Upload a Web Shell to a Web Server.This issue affects Push Notifications for WordPress by PushAssist: from n/a through 3... Read more
Affected Products :- Published: Nov. 16, 2024
- Modified: Nov. 18, 2024
-
5.3
MEDIUMCVE-2024-52386
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Business Directory Team by RadiusTheme Classified Listing classified-listing allows PHP Local File Inclusion.This issue affects Classi... Read more
Affected Products :- Published: Nov. 16, 2024
- Modified: Nov. 18, 2024
-
9.8
CRITICALCVE-2024-52413
Deserialization of Untrusted Data vulnerability in DMC Airin Blog allows Object Injection.This issue affects Airin Blog: from n/a through 1.6.1.... Read more
Affected Products :- Published: Nov. 16, 2024
- Modified: Nov. 18, 2024
-
6.1
MEDIUMCVE-2024-10875
The Gallery Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of remove_Query_Arg without appropriate escaping on the URL in all versions up to, and including, 1.6.58. This makes it possible for unauthenticated at... Read more
Affected Products :- Published: Nov. 16, 2024
- Modified: Nov. 18, 2024
-
6.1
MEDIUMCVE-2024-10884
The SimpleForm Contact Form Submissions plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg & remove_query_arg without appropriate escaping on the URL in all versions up to, and including, 2.1.0. This makes... Read more
Affected Products :- Published: Nov. 16, 2024
- Modified: Nov. 18, 2024
-
6.1
MEDIUMCVE-2021-1444
A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to conduct cross-site scripting (XSS) attacks aga... Read more
Affected Products : adaptive_security_appliance_software- Published: Nov. 18, 2024
- Modified: Nov. 18, 2024
-
4.3
MEDIUMCVE-2024-10786
The Simple Local Avatars plugin for WordPress is vulnerable to unauthorized modification of datadue to a missing capability check on the sla_clear_user_cache function in all versions up to, and including, 2.7.11. This makes it possible for authenticated a... Read more
Affected Products :- Published: Nov. 16, 2024
- Modified: Nov. 18, 2024
-
6.1
MEDIUMCVE-2020-3431
A vulnerability in the web-based management interface of Cisco Small Business RV042 Dual WAN VPN Routers and Cisco Small Business RV042G Dual Gigabit WAN VPN Routers could allow an unauthenticated, remote attacker to conduct a cross-site scripti... Read more
Affected Products : small_business_rv_series_router_firmware- Published: Nov. 18, 2024
- Modified: Nov. 18, 2024
-
6.4
MEDIUMCVE-2024-10147
The Steel plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's btn shortcode in all versions up to, and including, 1.3.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it po... Read more
Affected Products :- Published: Nov. 16, 2024
- Modified: Nov. 18, 2024
-
9.8
CRITICALCVE-2024-52414
Deserialization of Untrusted Data vulnerability in Anthony Carbon WDES Responsive Mobile Menu allows Object Injection.This issue affects WDES Responsive Mobile Menu: from n/a through 5.3.18.... Read more
Affected Products :- Published: Nov. 16, 2024
- Modified: Nov. 18, 2024
-
8.7
HIGHCVE-2024-8781
Execution with Unnecessary Privileges, : Improper Protection of Alternate Path vulnerability in TR7 Application Security Platform (ASP) allows Privilege Escalation, -Privilege Abuse.This issue affects Application Security Platform (ASP): v1.4.25.188.... Read more
Affected Products :- Published: Nov. 18, 2024
- Modified: Nov. 18, 2024
-
6.5
MEDIUMCVE-2024-11305
A vulnerability classified as critical was found in Altenergy Power Control Software up to 20241108. This vulnerability affects the function get_status_zigbee of the file /index.php/display/status_zigbee. The manipulation of the argument date leads to sql... Read more
Affected Products :- Published: Nov. 18, 2024
- Modified: Nov. 18, 2024
-
10.0
CRITICALCVE-2024-52416
Missing Authorization vulnerability in Eugen Bobrowski Debug Tool allows Upload a Web Shell to a Web Server.This issue affects Debug Tool: from n/a through 2.2.... Read more
Affected Products :- Published: Nov. 16, 2024
- Modified: Nov. 18, 2024
-
6.3
MEDIUMCVE-2024-10262
The The Drop Shadow Boxes plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 1.7.14. This is due to the software allowing users to execute an action that does not properly validate a value before runn... Read more
Affected Products :- Published: Nov. 16, 2024
- Modified: Nov. 18, 2024
-
9.1
CRITICALCVE-2024-52398
Unrestricted Upload of File with Dangerous Type vulnerability in Halyra CDI.This issue affects CDI: from n/a through 5.5.3.... Read more
Affected Products :- Published: Nov. 16, 2024
- Modified: Nov. 18, 2024