Latest CVE Feed
-
4.8
MEDIUMCVE-2024-8189
The WP MultiTasking – WP Utilities plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘wpmt_menu_name’ parameter in all versions up to, and including, 0.1.17 due to insufficient input sanitization and output escaping. This makes it ... Read more
Affected Products : wp_multitasking- Published: Sep. 28, 2024
- Modified: Oct. 07, 2024
-
4.8
MEDIUMCVE-2024-7132
The Page Builder Gutenberg Blocks WordPress plugin before 3.1.13 does not escape the content of post embed via one of its block, which could allow users with the capability to publish posts (editor and admin by default) to perform Stored Cross-Site Scrip... Read more
Affected Products : coblocks- Published: Aug. 29, 2024
- Modified: Oct. 07, 2024
-
5.4
MEDIUMCVE-2024-5417
The Gutentor WordPress plugin before 3.3.6 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Sit... Read more
Affected Products : gutentor- Published: Aug. 29, 2024
- Modified: Oct. 07, 2024
-
6.1
MEDIUMCVE-2024-8712
The GTM Server Side plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 2.1.19. This makes it possible for unauthenticated attac... Read more
Affected Products : gtm_server_side- Published: Sep. 28, 2024
- Modified: Oct. 07, 2024
-
6.1
MEDIUMCVE-2024-6020
The Sign-up Sheets WordPress plugin before 2.2.13 does not escape some generated URLs, as well as the $_SERVER['REQUEST_URI'] parameter before outputting them back in attributes, which could lead to Reflected Cross-Site Scripting.... Read more
Affected Products : sign-up_sheets- Published: Sep. 04, 2024
- Modified: Oct. 07, 2024
-
4.8
MEDIUMCVE-2024-6722
The Chatbot Support AI: Free ChatGPT Chatbot, Woocommerce Chatbot WordPress plugin through 1.0.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even wh... Read more
Affected Products : chatbot_support_ai- Published: Sep. 04, 2024
- Modified: Oct. 07, 2024
-
4.8
MEDIUMCVE-2024-6888
The Secure Copy Content Protection and Content Locking WordPress plugin before 4.1.7 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfil... Read more
Affected Products : secure_copy_content_protection_and_content_locking- Published: Sep. 04, 2024
- Modified: Oct. 07, 2024
-
8.8
HIGHCVE-2024-9293
A vulnerability classified as critical was found in skyselang yylAdmin up to 3.0. Affected by this vulnerability is the function list of the file /app/admin/controller/file/File.php of the component Backend. The manipulation of the argument is_disable lea... Read more
Affected Products : yyladmin- Published: Sep. 27, 2024
- Modified: Oct. 07, 2024
-
7.5
HIGHCVE-2024-23586
HCL Nomad is susceptible to an insufficient session expiration vulnerability. Under certain circumstances, an unauthenticated attacker could obtain old session information.... Read more
- Published: Sep. 27, 2024
- Modified: Oct. 07, 2024
-
4.8
MEDIUMCVE-2024-6889
The Secure Copy Content Protection and Content Locking WordPress plugin before 4.1.7 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfil... Read more
Affected Products : secure_copy_content_protection_and_content_locking- Published: Sep. 04, 2024
- Modified: Oct. 07, 2024
-
9.8
CRITICALCVE-2024-6926
The Viral Signup WordPress plugin through 2.1 does not properly sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection... Read more
Affected Products : viral_signup- Published: Sep. 04, 2024
- Modified: Oct. 07, 2024
-
8.8
HIGHCVE-2024-39275
Cookies of authenticated Advantech ADAM-5630 users remain as active valid cookies when a session is closed. Forging requests with a legitimate cookie, even if the session was terminated, allows an unauthorized attacker to act with the same level of pri... Read more
- Published: Sep. 27, 2024
- Modified: Oct. 07, 2024
-
8.8
HIGHCVE-2024-38308
Advantech ADAM 5550's web application includes a "logs" page where all the HTTP requests received are displayed to the user. The device doesn't correctly neutralize malicious code when parsing HTTP requests to generate page output.... Read more
- Published: Sep. 27, 2024
- Modified: Oct. 07, 2024
-
6.9
MEDIUMCVE-2024-34542
Advantech ADAM-5630 shares user credentials plain text between the device and the user source device during the login process.... Read more
- Published: Sep. 27, 2024
- Modified: Oct. 07, 2024
-
6.8
MEDIUMCVE-2024-37187
Advantech ADAM-5550 share user credentials with a low level of encryption, consisting of base 64 encoding.... Read more
- Published: Sep. 27, 2024
- Modified: Oct. 07, 2024
-
7.8
HIGHCVE-2024-46811
In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Fix index may exceed array range within fpu_update_bw_bounding_box [Why] Coverity reports OVERRUN warning. soc.num_states could be 40. But array range of bw_params->clk... Read more
Affected Products : linux_kernel- Published: Sep. 27, 2024
- Modified: Oct. 07, 2024
-
5.5
MEDIUMCVE-2024-46802
In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: added NULL check at start of dc_validate_stream [Why] prevent invalid memory access [How] check if dc and stream are NULL... Read more
Affected Products : linux_kernel- Published: Sep. 27, 2024
- Modified: Oct. 07, 2024
-
7.5
HIGHCVE-2024-7714
The AI ChatBot with ChatGPT and Content Generator by AYS WordPress plugin before 2.1.0 lacks sufficient access controls allowing an unauthenticated user to disconnect the AI ChatBot with ChatGPT and Content Generator by AYS WordPress plugin before 2.1.0 f... Read more
Affected Products : chatgpt_assistant- Published: Sep. 27, 2024
- Modified: Oct. 07, 2024
-
6.1
MEDIUMCVE-2024-47186
Filament is a collection of full-stack components for Laravel development. Versions of Filament from v3.0.0 through v3.2.114 are affected by a cross-site scripting (XSS) vulnerability. If values passed to a `ColorColumn` or `ColumnEntry` are not valid and... Read more
Affected Products : filament- Published: Sep. 27, 2024
- Modified: Oct. 07, 2024
-
8.7
HIGHCVE-2024-9301
A path traversal issue in E2Nest prior to commit 8a41948e553c89c56b14410c6ed395e9cfb9250a... Read more
Affected Products : e2nest- Published: Sep. 27, 2024
- Modified: Oct. 07, 2024