Latest CVE Feed
-
7.5
HIGHCVE-2024-44013
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Innate Images LLC VR Calendar allows PHP Local File Inclusion.This issue affects VR Calendar: from n/a through 2.4.0.... Read more
Affected Products :- Published: Oct. 05, 2024
- Modified: Oct. 07, 2024
-
6.1
MEDIUMCVE-2024-9417
The Hash Form – Drag & Drop Form Builder plugin for WordPress is vulnerable to limited file uploads due to a misconfigured file type validation in the 'handleUpload' function in all versions up to, and including, 1.1.9. This makes it possible for unauthen... Read more
Affected Products : hash_form- Published: Oct. 05, 2024
- Modified: Oct. 07, 2024
-
7.5
HIGHCVE-2024-44015
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Users Control allows PHP Local File Inclusion.This issue affects Users Control: from n/a through 1.0.16.... Read more
Affected Products :- Published: Oct. 05, 2024
- Modified: Oct. 07, 2024
-
4.9
MEDIUMCVE-2024-9146
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in James Low CSS JS Files allows Path Traversal.This issue affects CSS JS Files: from n/a through 1.5.0.... Read more
Affected Products :- Published: Oct. 05, 2024
- Modified: Oct. 07, 2024
-
7.5
HIGHCVE-2024-47324
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Ex-Themes WP Timeline – Vertical and Horizontal timeline plugin allows PHP Local File Inclusion.This issue affects WP Timeline – Vertical and Horizontal timeli... Read more
Affected Products :- Published: Oct. 05, 2024
- Modified: Oct. 07, 2024
-
8.1
HIGHCVE-2024-44023
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in ABCApp Creator allows PHP Local File Inclusion.This issue affects ABCApp Creator: from n/a through 1.1.2.... Read more
Affected Products :- Published: Oct. 05, 2024
- Modified: Oct. 07, 2024
-
7.5
HIGHCVE-2024-44016
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Mark Steadman Podiant allows PHP Local File Inclusion.This issue affects Podiant: from n/a through 1.1.... Read more
Affected Products :- Published: Oct. 05, 2024
- Modified: Oct. 07, 2024
-
7.5
HIGHCVE-2024-44034
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Martin Greenwood WPSPX allows PHP Local File Inclusion.This issue affects WPSPX: from n/a through 1.0.2.... Read more
Affected Products :- Published: Oct. 05, 2024
- Modified: Oct. 07, 2024
-
7.5
HIGHCVE-2024-44018
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Istmo Plugins Instant Chat Floating Button for WordPress Websites allows PHP Local File Inclusion.This issue affects Instant Chat Floating Button for WordPress... Read more
Affected Products :- Published: Oct. 05, 2024
- Modified: Oct. 07, 2024
-
9.6
CRITICALCVE-2024-44014
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Vmaxstudio Vmax Project Manager allows PHP Local File Inclusion, Code Injection.This issue affects Vmax Project Manager: from n/a through 1.0.... Read more
Affected Products :- Published: Oct. 05, 2024
- Modified: Oct. 07, 2024
-
6.4
MEDIUMCVE-2024-9455
The WP Cleanup and Basic Functions plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 2.2.1 due to insufficient input sanitization and output escaping. This makes it possible for au... Read more
Affected Products :- Published: Oct. 05, 2024
- Modified: Oct. 07, 2024
-
8.0
HIGHCVE-2024-47319
Unrestricted Upload of File with Dangerous Type vulnerability in Bit Apps Bit Form – Contact Form Plugin allows Code Injection.This issue affects Bit Form – Contact Form Plugin: from n/a through 2.13.10.... Read more
Affected Products : bit_form- Published: Oct. 05, 2024
- Modified: Oct. 07, 2024
-
7.1
HIGHCVE-2024-47339
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in James Ward WP Mail Catcher allows Reflected XSS.This issue affects WP Mail Catcher: from n/a through 2.1.9.... Read more
Affected Products :- Published: Oct. 06, 2024
- Modified: Oct. 07, 2024
-
6.5
MEDIUMCVE-2024-44035
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in TemeGUM Gum Elementor Addon allows Stored XSS.This issue affects Gum Elementor Addon: from n/a through 1.3.7.... Read more
Affected Products :- Published: Oct. 06, 2024
- Modified: Oct. 07, 2024
-
4.3
MEDIUMCVE-2024-45250
ZKteco – CWE 200 Exposure of Sensitive Information to an Unauthorized Actor... Read more
Affected Products :- Published: Oct. 06, 2024
- Modified: Oct. 07, 2024
-
7.3
HIGHCVE-2024-45246
Diebold Nixdorf – CWE-427: Uncontrolled Search Path Element... Read more
Affected Products :- Published: Oct. 06, 2024
- Modified: Oct. 07, 2024
-
7.1
HIGHCVE-2024-47374
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in LiteSpeed Technologies LiteSpeed Cache allows Stored XSS.This issue affects LiteSpeed Cache: from n/a through 6.5.0.2.... Read more
Affected Products : litespeed_cache- Published: Oct. 05, 2024
- Modified: Oct. 07, 2024
-
5.9
MEDIUMCVE-2024-47372
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in ThemeNcode LLC TNC PDF viewer allows Stored XSS.This issue affects TNC PDF viewer: from n/a through 3.1.0.... Read more
Affected Products : tnc_pdf_viewer- Published: Oct. 05, 2024
- Modified: Oct. 07, 2024
-
8.8
HIGHCVE-2024-27458
A potential security vulnerability has been identified in the HP Hotkey Support software, which might allow local escalation of privilege. HP is releasing mitigation for the potential vulnerability. Customers using HP Programmable Key are recommended to u... Read more
Affected Products :- Published: Oct. 07, 2024
- Modified: Oct. 07, 2024
-
6.5
MEDIUMCVE-2024-47629
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in BdThemes Ultimate Store Kit Elementor Addons allows Stored XSS.This issue affects Ultimate Store Kit Elementor Addons: from n/a through 2.0.5.... Read more
Affected Products : ultimate_store_kit- Published: Oct. 05, 2024
- Modified: Oct. 07, 2024