Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 6.4

    MEDIUM
    CVE-2024-8668

    The ShopLentor – WooCommerce Builder for Elementor & Gutenberg +12 Modules – All in One Solution (formerly WooLentor) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the tooltip and countdown functionality in all versions up to, and ... Read more

    • Published: Sep. 25, 2024
    • Modified: Oct. 07, 2024
  • 4.3

    MEDIUM
    CVE-2024-7892

    The adstxt Plugin WordPress plugin through 1.0.0 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack... Read more

    Affected Products : adstxt
    • Published: Sep. 25, 2024
    • Modified: Oct. 07, 2024
  • 9.8

    CRITICAL
    CVE-2024-46997

    DataEase is an open source data visualization analysis tool. Prior to version 2.10.1, an attacker can achieve remote command execution by adding a carefully constructed h2 data source connection string. The vulnerability has been fixed in v2.10.1.... Read more

    Affected Products : dataease
    • Published: Sep. 23, 2024
    • Modified: Oct. 07, 2024
  • 9.1

    CRITICAL
    CVE-2024-8892

    Vulnerability in CIRCUTOR TCP2RS+ firmware version 1.3b, which could allow an attacker to modify any configuration value, even if the device has the user/password authentication option enabled, without authentication by sending packets through the UDP pro... Read more

    Affected Products : tcp2rs\+_firmware tcp2rs\+
    • Published: Sep. 18, 2024
    • Modified: Oct. 07, 2024
  • 9.3

    CRITICAL
    CVE-2024-8889

    Vulnerability in CIRCUTOR TCP2RS+ firmware version 1.3b, which could allow an attacker to modify any configuration value, even if the device has the user/password authentication option enabled, without authentication by sending packets through the UDP pro... Read more

    Affected Products : tcp2rs\+_firmware tcp2rs\+
    • Published: Sep. 18, 2024
    • Modified: Oct. 07, 2024
  • 6.1

    MEDIUM
    CVE-2024-45803

    Wire UI is a library of components and resources to empower Laravel and Livewire application development. A potential Cross-Site Scripting (XSS) vulnerability has been identified in the `/wireui/button` endpoint, specifically through the `label` query par... Read more

    Affected Products : wireui
    • Published: Sep. 17, 2024
    • Modified: Oct. 07, 2024
  • 5.3

    MEDIUM
    CVE-2024-6845

    The Chatbot with ChatGPT WordPress plugin before 2.4.6 does not have proper authorization in one of its REST endpoint, allowing unauthenticated users to retrieve the encoded key and then decode it, thereby leaking the OpenAI API key... Read more

    Affected Products : smartsearchwp chatbot_with_chatgpt
    • Published: Sep. 25, 2024
    • Modified: Oct. 07, 2024
  • 4.8

    MEDIUM
    CVE-2024-7918

    The Pocket Widget WordPress plugin through 0.1.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed ... Read more

    Affected Products : pocket_widget
    • Published: Sep. 09, 2024
    • Modified: Oct. 07, 2024
  • 8.4

    HIGH
    CVE-2024-9158

    A stored cross site scripting vulnerability exists in Nessus Network Monitor where an authenticated, privileged local attacker could inject arbitrary code into the NNM UI via the local CLI.... Read more

    Affected Products : nessus_network_monitor
    • Published: Sep. 30, 2024
    • Modified: Oct. 07, 2024
  • 5.4

    MEDIUM
    CVE-2024-9291

    A vulnerability classified as problematic has been found in kalvinGit kvf-admin up to f12a94dc1ebb7d1c51ee978a85e4c7ed75c620ff. Affected is an unknown function of the file /ueditor/upload?configPath=ueditor/config.json&action=uploadfile of the component X... Read more

    Affected Products : kvf-admin
    • Published: Sep. 27, 2024
    • Modified: Oct. 07, 2024
  • 6.1

    MEDIUM
    CVE-2024-8793

    The Store Exporter for WooCommerce – Export Products, Export Orders, Export Subscriptions, and More plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all version... Read more

    Affected Products : store_exporter_for_woocommerce
    • Published: Oct. 01, 2024
    • Modified: Oct. 07, 2024
  • 4.8

    MEDIUM
    CVE-2024-6927

    The Viral Signup WordPress plugin through 2.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (f... Read more

    Affected Products : viral_signup
    • Published: Aug. 29, 2024
    • Modified: Oct. 07, 2024
  • 5.4

    MEDIUM
    CVE-2024-7690

    The DN Popup WordPress plugin through 1.2.2 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack... Read more

    Affected Products : dn_popup
    • Published: Sep. 02, 2024
    • Modified: Oct. 07, 2024
  • 7.2

    HIGH
    CVE-2024-8379

    The Cost Calculator Builder WordPress plugin before 3.2.29 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by users with a role as low as Admin.... Read more

    Affected Products : cost_calculator_builder
    • Published: Sep. 30, 2024
    • Modified: Oct. 07, 2024
  • 4.8

    MEDIUM
    CVE-2024-8283

    The Slider by 10Web WordPress plugin before 1.2.59 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallow... Read more

    Affected Products : slider
    • Published: Sep. 30, 2024
    • Modified: Oct. 07, 2024
  • 5.4

    MEDIUM
    CVE-2024-8239

    The Starbox WordPress plugin before 3.5.3 does not properly render social media profiles URLs in certain contexts, like the malicious user's profile or pages where the starbox shortcode is used, which may be abused by users with at least the contributor ... Read more

    Affected Products : starbox
    • Published: Sep. 30, 2024
    • Modified: Oct. 07, 2024
  • 4.8

    MEDIUM
    CVE-2024-8189

    The WP MultiTasking – WP Utilities plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘wpmt_menu_name’ parameter in all versions up to, and including, 0.1.17 due to insufficient input sanitization and output escaping. This makes it ... Read more

    Affected Products : wp_multitasking
    • Published: Sep. 28, 2024
    • Modified: Oct. 07, 2024
  • 4.8

    MEDIUM
    CVE-2024-7132

    The Page Builder Gutenberg Blocks WordPress plugin before 3.1.13 does not escape the content of post embed via one of its block, which could allow users with the capability to publish posts (editor and admin by default) to perform Stored Cross-Site Scrip... Read more

    Affected Products : coblocks
    • Published: Aug. 29, 2024
    • Modified: Oct. 07, 2024
  • 5.4

    MEDIUM
    CVE-2024-5417

    The Gutentor WordPress plugin before 3.3.6 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Sit... Read more

    Affected Products : gutentor
    • Published: Aug. 29, 2024
    • Modified: Oct. 07, 2024
  • 6.1

    MEDIUM
    CVE-2024-8712

    The GTM Server Side plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 2.1.19. This makes it possible for unauthenticated attac... Read more

    Affected Products : gtm_server_side
    • Published: Sep. 28, 2024
    • Modified: Oct. 07, 2024
Showing 20 of 291160 Results