Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 7.5

    HIGH
    CVE-2024-23586

    HCL Nomad is susceptible to an insufficient session expiration vulnerability.   Under certain circumstances, an unauthenticated attacker could obtain old session information.... Read more

    • Published: Sep. 27, 2024
    • Modified: Oct. 07, 2024
  • 4.8

    MEDIUM
    CVE-2024-6889

    The Secure Copy Content Protection and Content Locking WordPress plugin before 4.1.7 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfil... Read more

    • Published: Sep. 04, 2024
    • Modified: Oct. 07, 2024
  • 9.8

    CRITICAL
    CVE-2024-6926

    The Viral Signup WordPress plugin through 2.1 does not properly sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection... Read more

    Affected Products : viral_signup
    • Published: Sep. 04, 2024
    • Modified: Oct. 07, 2024
  • 8.8

    HIGH
    CVE-2024-39275

    Cookies of authenticated Advantech ADAM-5630 users remain as active valid cookies when a session is closed. Forging requests with a legitimate cookie, even if the session was terminated, allows an unauthorized attacker to act with the same level of pri... Read more

    Affected Products : adam-5630_firmware adam-5630
    • Published: Sep. 27, 2024
    • Modified: Oct. 07, 2024
  • 8.8

    HIGH
    CVE-2024-38308

    Advantech ADAM 5550's web application includes a "logs" page where all the HTTP requests received are displayed to the user. The device doesn't correctly neutralize malicious code when parsing HTTP requests to generate page output.... Read more

    Affected Products : adam-5550 adam_5550-firmware
    • Published: Sep. 27, 2024
    • Modified: Oct. 07, 2024
  • 6.9

    MEDIUM
    CVE-2024-34542

    Advantech ADAM-5630 shares user credentials plain text between the device and the user source device during the login process.... Read more

    Affected Products : adam-5630_firmware adam-5630
    • Published: Sep. 27, 2024
    • Modified: Oct. 07, 2024
  • 6.8

    MEDIUM
    CVE-2024-37187

    Advantech ADAM-5550 share user credentials with a low level of encryption, consisting of base 64 encoding.... Read more

    Affected Products : adam-5550_firmware adam-5550
    • Published: Sep. 27, 2024
    • Modified: Oct. 07, 2024
  • 7.8

    HIGH
    CVE-2024-46811

    In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Fix index may exceed array range within fpu_update_bw_bounding_box [Why] Coverity reports OVERRUN warning. soc.num_states could be 40. But array range of bw_params->clk... Read more

    Affected Products : linux_kernel
    • Published: Sep. 27, 2024
    • Modified: Oct. 07, 2024
  • 5.5

    MEDIUM
    CVE-2024-46802

    In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: added NULL check at start of dc_validate_stream [Why] prevent invalid memory access [How] check if dc and stream are NULL... Read more

    Affected Products : linux_kernel
    • Published: Sep. 27, 2024
    • Modified: Oct. 07, 2024
  • 7.5

    HIGH
    CVE-2024-7714

    The AI ChatBot with ChatGPT and Content Generator by AYS WordPress plugin before 2.1.0 lacks sufficient access controls allowing an unauthenticated user to disconnect the AI ChatBot with ChatGPT and Content Generator by AYS WordPress plugin before 2.1.0 f... Read more

    Affected Products : chatgpt_assistant
    • Published: Sep. 27, 2024
    • Modified: Oct. 07, 2024
  • 6.1

    MEDIUM
    CVE-2024-47186

    Filament is a collection of full-stack components for Laravel development. Versions of Filament from v3.0.0 through v3.2.114 are affected by a cross-site scripting (XSS) vulnerability. If values passed to a `ColorColumn` or `ColumnEntry` are not valid and... Read more

    Affected Products : filament
    • Published: Sep. 27, 2024
    • Modified: Oct. 07, 2024
  • 8.7

    HIGH
    CVE-2024-9301

    A path traversal issue in E2Nest prior to commit 8a41948e553c89c56b14410c6ed395e9cfb9250a... Read more

    Affected Products : e2nest
    • Published: Sep. 27, 2024
    • Modified: Oct. 07, 2024
  • 6.4

    MEDIUM
    CVE-2024-8325

    The Blockspare: Gutenberg Blocks & Patterns for Blogs, Magazines, Business Sites – Post Grids, Sliders, Carousels, Counters, Page Builder & Starter Site Imports, No Coding Needed plugin for WordPress is vulnerable to Stored Cross-Site Scripting via severa... Read more

    Affected Products : blockspare
    • Published: Sep. 04, 2024
    • Modified: Oct. 07, 2024
  • 7.5

    HIGH
    CVE-2024-7870

    The PixelYourSite – Your smart PIXEL (TAG) & API Manager and the PixelYourSite PRO plugins for WordPress are vulnerable to Sensitive Information Exposure in all versions up to, and including, 9.7.1 and 10.4.2, respectively, through publicly exposed log fi... Read more

    Affected Products : pixelyoursite
    • Published: Sep. 04, 2024
    • Modified: Oct. 07, 2024
  • 7.2

    HIGH
    CVE-2024-44030

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Mestres do WP Checkout Mestres WP allows PHP Local File Inclusion.This issue affects Checkout Mestres WP: from n/a through 8.6.... Read more

    Affected Products : checkout_mestres_wp
    • Published: Oct. 02, 2024
    • Modified: Oct. 05, 2024
  • 6.4

    MEDIUM
    CVE-2024-8318

    The Attributes for Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘attributesForBlocks’ parameter in all versions up to, and including, 1.0.6 due to insufficient input sanitization and output escaping. This makes it possi... Read more

    Affected Products : attributes_for_blocks
    • Published: Sep. 04, 2024
    • Modified: Oct. 05, 2024
  • 5.7

    MEDIUM
    CVE-2024-44744

    An issue in Malwarebytes Premium Security v5.0.0.883 allows attackers to execute arbitrary code via placing crafted binaries into unspecified directories. NOTE: Malwarebytes argues that this issue requires admin privileges and that the contents cannot be ... Read more

    Affected Products :
    • Published: Oct. 01, 2024
    • Modified: Oct. 04, 2024
  • 8.8

    HIGH
    CVE-2024-8922

    The Product Enquiry for WooCommerce, WooCommerce product catalog plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.2.33.32 via deserialization of untrusted input in enquiry_detail.php. This makes it possibl... Read more

    Affected Products : product_enquiry_for_woocommerce
    • Published: Sep. 27, 2024
    • Modified: Oct. 04, 2024
  • 7.2

    HIGH
    CVE-2024-6931

    The The Events Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via RSVP name field in all versions up to, and including, 6.6.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticate... Read more

    • Published: Sep. 27, 2024
    • Modified: Oct. 04, 2024
  • 6.4

    MEDIUM
    CVE-2024-8681

    The Premium Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Media Grid widget in all versions up to, and including, 4.10.52 due to insufficient input sanitization and output escaping on user supplied... Read more

    Affected Products : premium_addons_for_elementor
    • Published: Sep. 27, 2024
    • Modified: Oct. 04, 2024
Showing 20 of 291209 Results