Latest CVE Feed
-
6.5
MEDIUMCVE-2024-49234
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in themeworm Plexx Elementor Extension allows Stored XSS.This issue affects Plexx Elementor Extension: from n/a through 1.3.4.... Read more
Affected Products : plexx_elementor_extension- Published: Oct. 18, 2024
- Modified: Oct. 21, 2024
-
6.5
MEDIUMCVE-2024-49236
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Hafiz Uddin Ahmed Crazy Call To Action Box allows Stored XSS.This issue affects Crazy Call To Action Box: from n/a through 1.0.5.... Read more
Affected Products : crazy_call_to_action_box- Published: Oct. 18, 2024
- Modified: Oct. 21, 2024
-
8.1
HIGHCVE-2024-49361
ACON is a widely-used library of tools for machine learning that focuses on adaptive correlation optimization. A potential vulnerability has been identified in the input validation process, which could lead to arbitrary code execution if exploited. This i... Read more
Affected Products :- Published: Oct. 18, 2024
- Modified: Oct. 21, 2024
-
9.1
CRITICALCVE-2024-37404
Improper Input Validation in the admin portal of Ivanti Connect Secure before 22.7R2.1 and 9.1R18.9, or Ivanti Policy Secure before 22.7R1.1 allows a remote authenticated attacker to achieve remote code execution.... Read more
- Published: Oct. 18, 2024
- Modified: Oct. 21, 2024
-
8.7
HIGHCVE-2024-48930
secp256k1-node is a Node.js binding for an Optimized C library for EC operations on curve secp256k1. In `elliptic`-based version, `loadUncompressedPublicKey` has a check that the public key is on the curve. Prior to versions 5.0.1, 4.0.4, and 3.8.1, howev... Read more
Affected Products :- Published: Oct. 21, 2024
- Modified: Oct. 21, 2024
-
7.1
HIGHCVE-2024-49238
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in M. Konieczny, DH9SB ADIF Log Search Widget allows Reflected XSS.This issue affects ADIF Log Search Widget: from n/a through 1.0f.... Read more
Affected Products : adif_log_search_widget- Published: Oct. 18, 2024
- Modified: Oct. 21, 2024
-
6.5
MEDIUMCVE-2024-49231
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Peter CyClop WordPress Video allows Stored XSS.This issue affects WordPress Video: from n/a through 1.0.... Read more
Affected Products : wordpress_video- Published: Oct. 18, 2024
- Modified: Oct. 21, 2024
-
6.5
MEDIUMCVE-2024-49230
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Harpreet Singh Ajax Custom CSS/JS allows Reflected XSS.This issue affects Ajax Custom CSS/JS: from n/a through 2.0.4.... Read more
Affected Products : ajax_custom_css\/js- Published: Oct. 18, 2024
- Modified: Oct. 21, 2024
-
6.5
MEDIUMCVE-2024-49228
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in CrossedCode bVerse Convert allows Stored XSS.This issue affects bVerse Convert: from n/a through 1.3.7.1.... Read more
Affected Products : bverse_convert- Published: Oct. 18, 2024
- Modified: Oct. 21, 2024
-
6.5
MEDIUMCVE-2024-49225
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Swebdeveloper wpPricing Builder allows Stored XSS.This issue affects wpPricing Builder: from n/a through 1.5.0.... Read more
Affected Products : wppricing_builder- Published: Oct. 18, 2024
- Modified: Oct. 21, 2024
-
7.1
HIGHCVE-2024-49224
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Mahesh Patel Mitm Bug Tracker allows Reflected XSS.This issue affects Mitm Bug Tracker: from n/a through 1.0.... Read more
Affected Products : mitm_bug_tracker- Published: Oct. 18, 2024
- Modified: Oct. 21, 2024
-
6.5
MEDIUMCVE-2024-21262
Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/ODBC). Supported versions that are affected are 9.0.0 and prior. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protoco... Read more
- Published: Oct. 15, 2024
- Modified: Oct. 21, 2024
-
7.1
HIGHCVE-2024-49239
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Nikhil Vaghela Add Categories Post Footer allows Reflected XSS.This issue affects Add Categories Post Footer: from n/a through 2.2.2.... Read more
Affected Products : add_categories_post_footer- Published: Oct. 18, 2024
- Modified: Oct. 21, 2024
-
7.1
HIGHCVE-2024-49240
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Agustin Berasategui AB Categories Search Widget allows Reflected XSS.This issue affects AB Categories Search Widget: from n/a through 0.2.5.... Read more
Affected Products : ab_categories_search_widget- Published: Oct. 18, 2024
- Modified: Oct. 21, 2024
-
6.5
MEDIUMCVE-2024-49241
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Tady Walsh Tito allows DOM-Based XSS.This issue affects Tito: from n/a through 2.3.... Read more
Affected Products : tito- Published: Oct. 18, 2024
- Modified: Oct. 21, 2024
-
3.5
LOWCVE-2024-21242
Vulnerability in the XML Database component of Oracle Database Server. Supported versions that are affected are 19.3-19.24, 21.3-21.15 and 23.4-23.5. Easily exploitable vulnerability allows low privileged attacker having Create Session privilege with ne... Read more
- Published: Oct. 15, 2024
- Modified: Oct. 21, 2024
-
5.4
MEDIUMCVE-2024-21286
Vulnerability in the PeopleSoft Enterprise ELM Enterprise Learning Management product of Oracle PeopleSoft (component: Enterprise Learning Management). The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged... Read more
- Published: Oct. 15, 2024
- Modified: Oct. 21, 2024
-
2.4
LOWCVE-2024-4211
Improper Validation of Specified Quantity in Input vulnerability in OpenText OpenText Application Automation Tools allows Exploiting Incorrectly Configured Access Control Security Levels. Multiple missing permission checks - ALM job config has been disc... Read more
Affected Products : application_automation_tools- Published: Oct. 16, 2024
- Modified: Oct. 21, 2024
-
7.5
HIGHCVE-2024-21272
Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/Python). Supported versions that are affected are 9.0.0 and prior. Difficult to exploit vulnerability allows low privileged attacker with network access via multiple prot... Read more
- Published: Oct. 15, 2024
- Modified: Oct. 21, 2024
-
8.1
HIGHCVE-2024-21283
Vulnerability in the PeopleSoft Enterprise HCM Global Payroll Core product of Oracle PeopleSoft (component: Global Payroll for Core). Supported versions that are affected are 9.2.48-9.2.50. Easily exploitable vulnerability allows low privileged attacker ... Read more
- Published: Oct. 15, 2024
- Modified: Oct. 21, 2024