Latest CVE Feed
-
8.8
HIGHCVE-2024-8198
Heap buffer overflow in Skia in Google Chrome prior to 128.0.6613.113 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)... Read more
- Published: Aug. 28, 2024
- Modified: Oct. 15, 2024
-
8.8
HIGHCVE-2024-7534
Heap buffer overflow in Layout in Google Chrome prior to 127.0.6533.99 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)... Read more
- Published: Aug. 06, 2024
- Modified: Oct. 15, 2024
-
9.8
CRITICALCVE-2024-46045
Tenda CH22 V1.0.0.6(468) has a stack overflow vulnerability located in the frmL7PlotForm function.... Read more
- Published: Sep. 13, 2024
- Modified: Oct. 15, 2024
-
4.4
MEDIUMCVE-2024-44096
there is a possible arbitrary read due to an insecure default value. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.... Read more
Affected Products : android- Published: Sep. 13, 2024
- Modified: Oct. 15, 2024
-
7.8
HIGHCVE-2024-44095
In ppmp_protect_mfcfw_buf of code/drm_fw.c, there is a possible corrupt memory due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitati... Read more
Affected Products : android- Published: Sep. 13, 2024
- Modified: Oct. 15, 2024
-
6.3
MEDIUMCVE-2024-9520
The UserPlus plugin for WordPress is vulnerable to unauthorized access, modification, and loss of data due to a missing capability check on multiple functions in all versions up to, and including, 2.0. This makes it possible for authenticated attackers wi... Read more
Affected Products : userplus- Published: Oct. 10, 2024
- Modified: Oct. 15, 2024
-
4.8
MEDIUMCVE-2024-25707
There is a reflected cross site scripting in Esri Portal for ArcGIS 11.1 and below on Windows and Linux x64 allows a remote authenticated attacker with administrative access to supply a crafted string which could potentially execute arbitrary JavaScript c... Read more
- Published: Oct. 04, 2024
- Modified: Oct. 15, 2024
-
7.2
HIGHCVE-2024-9022
The TS Poll – Survey, Versus Poll, Image Poll, Video Poll plugin for WordPress is vulnerable to SQL Injection via the ‘orderby’ parameter in all versions up to, and including, 2.3.9 due to insufficient escaping on the user supplied parameter and lack of s... Read more
Affected Products : ts_poll- Published: Oct. 10, 2024
- Modified: Oct. 15, 2024
-
5.4
MEDIUMCVE-2024-38039
There is an HTML injection vulnerability in Esri Portal for ArcGIS versions 11.0 and below that may allow a remote, authenticated attacker to create a crafted link which when clicked could render arbitrary HTML in the victim’s browser (no stateful change ... Read more
Affected Products : portal_for_arcgis- Published: Oct. 04, 2024
- Modified: Oct. 15, 2024
-
4.3
MEDIUMCVE-2024-9067
The Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'delete_attachment' function in all version... Read more
Affected Products : youzify- Published: Oct. 10, 2024
- Modified: Oct. 15, 2024
-
4.3
MEDIUMCVE-2024-9685
The Notification for Telegram plugin for WordPress is vulnerable to unauthorized test message sending due to a missing capability check on the 'nftb_test_action' function in versions up to, and including, 3.3.1. This makes it possible for authenticated at... Read more
Affected Products : notification_for_telegram- Published: Oct. 10, 2024
- Modified: Oct. 15, 2024
-
7.3
HIGHCVE-2024-9581
The Shortcodes AnyWhere plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 1.0.1. This is due to the software allowing users to execute an action that does not properly validate a value before running... Read more
Affected Products : shortcodes_anywhere- Published: Oct. 10, 2024
- Modified: Oct. 15, 2024
-
8.8
HIGHCVE-2024-9522
The WP Users Masquerade plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.0.0. This is due to incorrect authentication and capability checking in the 'ajax_masq_login' function. This makes it possible for auth... Read more
Affected Products : wp_users_masquerade- Published: Oct. 10, 2024
- Modified: Oct. 15, 2024
-
7.2
HIGHCVE-2024-9519
The UserPlus plugin for WordPress is vulnerable to unauthorized modification of data due to an improper capability check on the 'save_metabox_form' function in versions up to, and including, 2.0. This makes it possible for authenticated attackers, with ed... Read more
Affected Products : userplus- Published: Oct. 10, 2024
- Modified: Oct. 15, 2024
-
9.8
CRITICALCVE-2024-9518
The UserPlus plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 2.0 due to insufficient restriction on the 'form_actions' and 'userplus_update_user_profile' functions. This makes it possible for unauthenticated at... Read more
Affected Products : userplus- Published: Oct. 10, 2024
- Modified: Oct. 15, 2024
-
6.4
MEDIUMCVE-2024-9457
The WP Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 3.0.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attacker... Read more
Affected Products : wp_builder- Published: Oct. 10, 2024
- Modified: Oct. 15, 2024
-
6.1
MEDIUMCVE-2024-9377
The Products, Order & Customers Export for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg & remove_query_arg without appropriate escaping on the URL in all versions up to, and including, 2.... Read more
Affected Products : products\,_order_\&_customers_export_for_woocommerce- Published: Oct. 10, 2024
- Modified: Oct. 15, 2024
-
6.1
MEDIUMCVE-2024-9205
The Maximum Products per User for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 4.2.8. This makes it possible ... Read more
Affected Products : maximum_products_per_user_for_woocommerce- Published: Oct. 10, 2024
- Modified: Oct. 15, 2024
-
6.4
MEDIUMCVE-2024-9072
The GDPR-Extensions-com – Consent Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.0.0 due to insufficient input sanitization and output escaping. This makes it possible... Read more
Affected Products : consent_manager- Published: Oct. 10, 2024
- Modified: Oct. 15, 2024
-
6.4
MEDIUMCVE-2024-9066
The Marketing and SEO Booster plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.9.10 due to insufficient input sanitization and output escaping. This makes it possible for authen... Read more
Affected Products : marketing_and_seo_booster- Published: Oct. 10, 2024
- Modified: Oct. 15, 2024