Latest CVE Feed
-
6.5
MEDIUMCVE-2024-50432
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in PickPlugins Post Grid and Gutenberg Blocks allows Stored XSS.This issue affects Post Grid and Gutenberg Blocks: from n/a through 2.2.93.... Read more
Affected Products : post_grid- Published: Oct. 28, 2024
- Modified: Oct. 29, 2024
-
8.8
HIGHCVE-2024-42028
A Local privilege escalation vulnerability found in a Self-Hosted UniFi Network Server with UniFi Network Application (Version 8.4.62 and earlier) allows a malicious actor with a local operational system user to execute high privilege actions on UniFi Net... Read more
Affected Products : unifi_network_application- Published: Oct. 28, 2024
- Modified: Oct. 29, 2024
-
6.5
MEDIUMCVE-2024-50429
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WPBlockArt Magazine Blocks allows Stored XSS.This issue affects Magazine Blocks: from n/a through 1.3.15.... Read more
Affected Products : magazine_blocks- Published: Oct. 28, 2024
- Modified: Oct. 29, 2024
-
7.5
HIGHCVE-2024-50434
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Theme Horse NewsCard.This issue affects NewsCard: from n/a through 1.3.... Read more
Affected Products :- Published: Oct. 28, 2024
- Modified: Oct. 29, 2024
-
3.1
LOWCVE-2024-49755
Duende IdentityServer is an OpenID Connect and OAuth 2.x framework for ASP.NET Core. IdentityServer's local API authentication handler performs insufficient validation of the cnf claim in DPoP access tokens. This allows an attacker to use leaked DPoP acce... Read more
Affected Products :- Published: Oct. 28, 2024
- Modified: Oct. 29, 2024
-
1.8
LOWCVE-2024-5532
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in OpenText™ Operations Agent. The XSS vulnerability could allow an attacker with local admin permissions to manipulate the content of the internal... Read more
Affected Products :- Published: Oct. 28, 2024
- Modified: Oct. 29, 2024
-
5.4
MEDIUMCVE-2024-9825
The Chef Habitat builder-api on-prem-builder package with any version lower than habitat/builder-api/10315/20240913162802 is vulnerable to indirect object reference (IDOR) by un-authorized deletion of personal token. Habitat builder consumes builder-api... Read more
Affected Products :- Published: Oct. 28, 2024
- Modified: Oct. 29, 2024
-
5.3
MEDIUMCVE-2024-49771
MPXJ is an open source library to read and write project plans from a variety of file formats and databases. The patch for the historical vulnerability CVE-2020-35460 in MPXJ is incomplete as there is still a possibility that a malicious path could be con... Read more
Affected Products :- Published: Oct. 28, 2024
- Modified: Oct. 29, 2024
-
10.0
CRITICALCVE-2024-50493
Unrestricted Upload of File with Dangerous Type vulnerability in masterhomepage Automatic Translation allows Upload a Web Shell to a Web Server.This issue affects Automatic Translation: from n/a through 1.0.4.... Read more
Affected Products :- Published: Oct. 29, 2024
- Modified: Oct. 29, 2024
-
7.1
HIGHCVE-2024-49646
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in ioannup Code Generate allows Reflected XSS.This issue affects Code Generate: from n/a through 1.0.... Read more
Affected Products :- Published: Oct. 29, 2024
- Modified: Oct. 29, 2024
-
5.1
MEDIUMCVE-2024-10479
A vulnerability, which was classified as problematic, was found in LinZhaoguan pb-cms up to 2.0.1. Affected is an unknown function of the file /admin#themes of the component Theme Management Module. The manipulation leads to cross site scripting. It is po... Read more
Affected Products : pb-cms- Published: Oct. 29, 2024
- Modified: Oct. 29, 2024
-
10.0
CRITICALCVE-2024-50420
Unrestricted Upload of File with Dangerous Type vulnerability in adirectory aDirectory allows Upload a Web Shell to a Web Server.This issue affects aDirectory: from n/a through 1.3.... Read more
Affected Products : adirectory- Published: Oct. 29, 2024
- Modified: Oct. 29, 2024
-
9.9
CRITICALCVE-2024-50427
Unrestricted Upload of File with Dangerous Type vulnerability in Devsoft Baltic OÜ SurveyJS: Drag & Drop WordPress Form Builder.This issue affects SurveyJS: Drag & Drop WordPress Form Builder: from n/a through 1.9.136.... Read more
Affected Products :- Published: Oct. 29, 2024
- Modified: Oct. 29, 2024
-
9.8
CRITICALCVE-2024-50490
Missing Authorization vulnerability in Szabolcs Szecsenyi PegaPoll allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects PegaPoll: from n/a through 1.0.2.... Read more
Affected Products :- Published: Oct. 29, 2024
- Modified: Oct. 29, 2024
-
5.9
MEDIUMCVE-2024-50415
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Pagup Ads.Txt & App-ads.Txt Manager for WordPress allows Stored XSS.This issue affects Ads.Txt & App-ads.Txt Manager for WordPress: from n/a throu... Read more
Affected Products :- Published: Oct. 29, 2024
- Modified: Oct. 29, 2024
-
9.8
CRITICALCVE-2024-45656
IBM Flexible Service Processor (FSP) FW860.00 through FW860.B3, FW950.00 through FW950.C0, FW1030.00 through FW1030.61, FW1050.00 through FW1050.21, and FW1060.00 through FW1060.10 has static credentials which may allow network users to gain service privi... Read more
Affected Products : power9_system_firmware- Published: Oct. 29, 2024
- Modified: Oct. 29, 2024
-
7.1
HIGHCVE-2024-49650
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in xarbo BuddyPress Greeting Message allows Reflected XSS.This issue affects BuddyPress Greeting Message: from n/a through 1.0.3.... Read more
Affected Products :- Published: Oct. 29, 2024
- Modified: Oct. 29, 2024
-
6.4
MEDIUMCVE-2024-10266
The Premium Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Video Box widget in all versions up to, and including, 4.10.60 due to insufficient input sanitization and output escaping on user supplied ... Read more
Affected Products : premium_addons_for_elementor- Published: Oct. 29, 2024
- Modified: Oct. 29, 2024
-
7.1
HIGHCVE-2024-49648
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in rafasashi SVG Captcha allows Reflected XSS.This issue affects SVG Captcha: from n/a through 1.0.11.... Read more
Affected Products :- Published: Oct. 29, 2024
- Modified: Oct. 29, 2024
-
6.5
MEDIUMCVE-2024-50418
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Time Slot Booking Time Slot allows Stored XSS.This issue affects Time Slot: from n/a through 1.3.6.... Read more
Affected Products :- Published: Oct. 29, 2024
- Modified: Oct. 29, 2024