Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 4.8

    MEDIUM
    CVE-2024-8283

    The Slider by 10Web WordPress plugin before 1.2.59 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallow... Read more

    Affected Products : slider
    • Published: Sep. 30, 2024
    • Modified: Oct. 07, 2024
  • 5.4

    MEDIUM
    CVE-2024-8239

    The Starbox WordPress plugin before 3.5.3 does not properly render social media profiles URLs in certain contexts, like the malicious user's profile or pages where the starbox shortcode is used, which may be abused by users with at least the contributor ... Read more

    Affected Products : starbox
    • Published: Sep. 30, 2024
    • Modified: Oct. 07, 2024
  • 4.8

    MEDIUM
    CVE-2024-8189

    The WP MultiTasking – WP Utilities plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘wpmt_menu_name’ parameter in all versions up to, and including, 0.1.17 due to insufficient input sanitization and output escaping. This makes it ... Read more

    Affected Products : wp_multitasking
    • Published: Sep. 28, 2024
    • Modified: Oct. 07, 2024
  • 4.8

    MEDIUM
    CVE-2024-7132

    The Page Builder Gutenberg Blocks WordPress plugin before 3.1.13 does not escape the content of post embed via one of its block, which could allow users with the capability to publish posts (editor and admin by default) to perform Stored Cross-Site Scrip... Read more

    Affected Products : coblocks
    • Published: Aug. 29, 2024
    • Modified: Oct. 07, 2024
  • 5.4

    MEDIUM
    CVE-2024-5417

    The Gutentor WordPress plugin before 3.3.6 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Sit... Read more

    Affected Products : gutentor
    • Published: Aug. 29, 2024
    • Modified: Oct. 07, 2024
  • 6.1

    MEDIUM
    CVE-2024-8712

    The GTM Server Side plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 2.1.19. This makes it possible for unauthenticated attac... Read more

    Affected Products : gtm_server_side
    • Published: Sep. 28, 2024
    • Modified: Oct. 07, 2024
  • 6.1

    MEDIUM
    CVE-2024-6020

    The Sign-up Sheets WordPress plugin before 2.2.13 does not escape some generated URLs, as well as the $_SERVER['REQUEST_URI'] parameter before outputting them back in attributes, which could lead to Reflected Cross-Site Scripting.... Read more

    Affected Products : sign-up_sheets
    • Published: Sep. 04, 2024
    • Modified: Oct. 07, 2024
  • 4.8

    MEDIUM
    CVE-2024-6722

    The Chatbot Support AI: Free ChatGPT Chatbot, Woocommerce Chatbot WordPress plugin through 1.0.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even wh... Read more

    Affected Products : chatbot_support_ai
    • Published: Sep. 04, 2024
    • Modified: Oct. 07, 2024
  • 4.8

    MEDIUM
    CVE-2024-6888

    The Secure Copy Content Protection and Content Locking WordPress plugin before 4.1.7 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfil... Read more

    • Published: Sep. 04, 2024
    • Modified: Oct. 07, 2024
  • 8.8

    HIGH
    CVE-2024-9293

    A vulnerability classified as critical was found in skyselang yylAdmin up to 3.0. Affected by this vulnerability is the function list of the file /app/admin/controller/file/File.php of the component Backend. The manipulation of the argument is_disable lea... Read more

    Affected Products : yyladmin
    • Published: Sep. 27, 2024
    • Modified: Oct. 07, 2024
  • 7.5

    HIGH
    CVE-2024-23586

    HCL Nomad is susceptible to an insufficient session expiration vulnerability.   Under certain circumstances, an unauthenticated attacker could obtain old session information.... Read more

    • Published: Sep. 27, 2024
    • Modified: Oct. 07, 2024
  • 4.8

    MEDIUM
    CVE-2024-6889

    The Secure Copy Content Protection and Content Locking WordPress plugin before 4.1.7 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfil... Read more

    • Published: Sep. 04, 2024
    • Modified: Oct. 07, 2024
  • 9.8

    CRITICAL
    CVE-2024-6926

    The Viral Signup WordPress plugin through 2.1 does not properly sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection... Read more

    Affected Products : viral_signup
    • Published: Sep. 04, 2024
    • Modified: Oct. 07, 2024
  • 8.8

    HIGH
    CVE-2024-39275

    Cookies of authenticated Advantech ADAM-5630 users remain as active valid cookies when a session is closed. Forging requests with a legitimate cookie, even if the session was terminated, allows an unauthorized attacker to act with the same level of pri... Read more

    Affected Products : adam-5630_firmware adam-5630
    • Published: Sep. 27, 2024
    • Modified: Oct. 07, 2024
  • 8.8

    HIGH
    CVE-2024-38308

    Advantech ADAM 5550's web application includes a "logs" page where all the HTTP requests received are displayed to the user. The device doesn't correctly neutralize malicious code when parsing HTTP requests to generate page output.... Read more

    Affected Products : adam-5550 adam_5550-firmware
    • Published: Sep. 27, 2024
    • Modified: Oct. 07, 2024
  • 6.9

    MEDIUM
    CVE-2024-34542

    Advantech ADAM-5630 shares user credentials plain text between the device and the user source device during the login process.... Read more

    Affected Products : adam-5630_firmware adam-5630
    • Published: Sep. 27, 2024
    • Modified: Oct. 07, 2024
  • 6.8

    MEDIUM
    CVE-2024-37187

    Advantech ADAM-5550 share user credentials with a low level of encryption, consisting of base 64 encoding.... Read more

    Affected Products : adam-5550_firmware adam-5550
    • Published: Sep. 27, 2024
    • Modified: Oct. 07, 2024
  • 7.8

    HIGH
    CVE-2024-46811

    In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Fix index may exceed array range within fpu_update_bw_bounding_box [Why] Coverity reports OVERRUN warning. soc.num_states could be 40. But array range of bw_params->clk... Read more

    Affected Products : linux_kernel
    • Published: Sep. 27, 2024
    • Modified: Oct. 07, 2024
  • 5.5

    MEDIUM
    CVE-2024-46802

    In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: added NULL check at start of dc_validate_stream [Why] prevent invalid memory access [How] check if dc and stream are NULL... Read more

    Affected Products : linux_kernel
    • Published: Sep. 27, 2024
    • Modified: Oct. 07, 2024
  • 7.5

    HIGH
    CVE-2024-7714

    The AI ChatBot with ChatGPT and Content Generator by AYS WordPress plugin before 2.1.0 lacks sufficient access controls allowing an unauthenticated user to disconnect the AI ChatBot with ChatGPT and Content Generator by AYS WordPress plugin before 2.1.0 f... Read more

    Affected Products : chatgpt_assistant
    • Published: Sep. 27, 2024
    • Modified: Oct. 07, 2024
Showing 20 of 291219 Results