Latest CVE Feed
-
6.4
MEDIUMCVE-2024-8318
The Attributes for Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘attributesForBlocks’ parameter in all versions up to, and including, 1.0.6 due to insufficient input sanitization and output escaping. This makes it possi... Read more
Affected Products : attributes_for_blocks- Published: Sep. 04, 2024
- Modified: Oct. 05, 2024
-
5.7
MEDIUMCVE-2024-44744
An issue in Malwarebytes Premium Security v5.0.0.883 allows attackers to execute arbitrary code via placing crafted binaries into unspecified directories. NOTE: Malwarebytes argues that this issue requires admin privileges and that the contents cannot be ... Read more
Affected Products :- Published: Oct. 01, 2024
- Modified: Oct. 04, 2024
-
8.8
HIGHCVE-2024-8922
The Product Enquiry for WooCommerce, WooCommerce product catalog plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.2.33.32 via deserialization of untrusted input in enquiry_detail.php. This makes it possibl... Read more
Affected Products : product_enquiry_for_woocommerce- Published: Sep. 27, 2024
- Modified: Oct. 04, 2024
-
7.2
HIGHCVE-2024-6931
The The Events Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via RSVP name field in all versions up to, and including, 6.6.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticate... Read more
- Published: Sep. 27, 2024
- Modified: Oct. 04, 2024
-
6.4
MEDIUMCVE-2024-8681
The Premium Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Media Grid widget in all versions up to, and including, 4.10.52 due to insufficient input sanitization and output escaping on user supplied... Read more
Affected Products : premium_addons_for_elementor- Published: Sep. 27, 2024
- Modified: Oct. 04, 2024
-
6.4
MEDIUMCVE-2024-8965
The Absolute Reviews plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Name' field of a custom post criteria in all versions up to, and including, 1.1.3 due to insufficient input sanitization and output escaping. This makes it pos... Read more
Affected Products : absolute_reviews- Published: Sep. 27, 2024
- Modified: Oct. 04, 2024
-
8.8
HIGHCVE-2024-28948
Advantech ADAM-5630 contains a cross-site request forgery (CSRF) vulnerability. It allows an attacker to partly circumvent the same origin policy, which is designed to prevent different websites from interfering with each other.... Read more
- Published: Sep. 27, 2024
- Modified: Oct. 04, 2024
-
6.4
MEDIUMCVE-2024-8991
The OSM – OpenStreetMap plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's osm_map and osm_map_v3 shortcodes in all versions up to, and including, 6.1.0 due to insufficient input sanitization and output escaping on user sup... Read more
Affected Products : openstreetmap- Published: Sep. 27, 2024
- Modified: Oct. 04, 2024
-
9.8
CRITICALCVE-2024-9359
A vulnerability was found in code-projects Restaurant Reservation System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /addcompany.php. The manipulation of the argument company leads to sql injection. The... Read more
Affected Products : restaurant_reservation_system- Published: Oct. 01, 2024
- Modified: Oct. 04, 2024
-
9.8
CRITICALCVE-2024-9360
A vulnerability was found in code-projects Restaurant Reservation System 1.0. It has been classified as critical. This affects an unknown part of the file /updatebal.php. The manipulation of the argument company leads to sql injection. It is possible to i... Read more
Affected Products : restaurant_reservation_system- Published: Oct. 01, 2024
- Modified: Oct. 04, 2024
-
6.4
MEDIUMCVE-2024-9049
The Beaver Builder – WordPress Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Button Group module in all versions up to, and including, 2.8.3.6 due to insufficient input sanitization and output escaping on ... Read more
- Published: Sep. 27, 2024
- Modified: Oct. 04, 2024
-
7.5
HIGHCVE-2024-47182
Dozzle is a realtime log viewer for docker containers. Before version 8.5.3, the app uses sha-256 as the hash for passwords, which leaves users susceptible to rainbow table attacks. The app switches to bcrypt, a more appropriate hash for passwords, in ver... Read more
Affected Products : dozzle- Published: Sep. 27, 2024
- Modified: Oct. 04, 2024
-
8.8
HIGHCVE-2024-7149
The Event Manager, Events Calendar, Tickets, Registrations – Eventin plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 4.0.8 via multiple style parameters. This makes it possible for authenticated attackers, ... Read more
Affected Products : eventin- Published: Sep. 27, 2024
- Modified: Oct. 04, 2024
-
6.1
MEDIUMCVE-2024-47184
Ampache is a web based audio/video streaming application and file manager. Prior to version 6.6.0, the Democratic Playlist Name is vulnerable to a stored cross-site scripting. Version 6.6.0 fixes this issue.... Read more
Affected Products : ampache- Published: Sep. 27, 2024
- Modified: Oct. 04, 2024
-
9.8
CRITICALCVE-2024-9280
A vulnerability has been found in kalvinGit kvf-admin up to f12a94dc1ebb7d1c51ee978a85e4c7ed75c620ff and classified as critical. This vulnerability affects the function fileUpload of the file FileUploadKit.java. The manipulation of the argument file leads... Read more
Affected Products : kvf-admin- Published: Sep. 27, 2024
- Modified: Oct. 04, 2024
-
7.8
HIGHCVE-2024-46804
In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Add array index check for hdcp ddc access [Why] Coverity reports OVERRUN warning. Do not check if array index valid. [How] Check msg_id valid and valid array index.... Read more
Affected Products : linux_kernel- Published: Sep. 27, 2024
- Modified: Oct. 04, 2024
-
5.5
MEDIUMCVE-2024-46803
In the Linux kernel, the following vulnerability has been resolved: drm/amdkfd: Check debug trap enable before write dbg_ev_file In interrupt context, write dbg_ev_file will be run by work queue. It will cause write dbg_ev_file execution after debug_tra... Read more
Affected Products : linux_kernel- Published: Sep. 27, 2024
- Modified: Oct. 04, 2024
-
5.5
MEDIUMCVE-2024-46810
In the Linux kernel, the following vulnerability has been resolved: drm/bridge: tc358767: Check if fully initialized before signalling HPD event via IRQ Make sure the connector is fully initialized before signalling any HPD events via drm_kms_helper_hot... Read more
Affected Products : linux_kernel- Published: Sep. 27, 2024
- Modified: Oct. 04, 2024
-
5.5
MEDIUMCVE-2024-46807
In the Linux kernel, the following vulnerability has been resolved: drm/amd/amdgpu: Check tbo resource pointer Validate tbo resource pointer, skip if NULL... Read more
Affected Products : linux_kernel- Published: Sep. 27, 2024
- Modified: Oct. 04, 2024
-
5.3
MEDIUMCVE-2024-4099
An issue has been discovered in GitLab EE affecting all versions starting from 16.0 prior to 17.2.8, from 17.3 prior to 17.3.4, and from 17.4 prior to 17.4.1. An AI feature was found to read unsanitized content in a way that could have allowed an attacker... Read more
Affected Products : gitlab- Published: Sep. 26, 2024
- Modified: Oct. 04, 2024