Latest CVE Feed
-
5.4
MEDIUMCVE-2024-9033
A vulnerability has been found in SourceCodester Best House Rental Management System 1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /ajax.php?action=save_category. The manipulation of the argument... Read more
Affected Products : best_house_rental_management_system- Published: Sep. 20, 2024
- Modified: Sep. 27, 2024
-
6.1
MEDIUMCVE-2024-8724
The Waitlist Woocommerce ( Back in stock notifier ) plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 2.7.5. This makes it pos... Read more
Affected Products : waitlist_woocommerce- Published: Sep. 14, 2024
- Modified: Sep. 27, 2024
-
9.8
CRITICALCVE-2024-9094
A vulnerability classified as critical was found in code-projects Blood Bank System 1.0. This vulnerability affects unknown code of the file /admin/blood/update/o-.php. The manipulation of the argument bloodname leads to sql injection. The attack can be i... Read more
- Published: Sep. 23, 2024
- Modified: Sep. 27, 2024
-
5.5
MEDIUMCVE-2024-9040
A vulnerability, which was classified as problematic, was found in code-projects Blood Bank Management System 1.0. This affects an unknown part of the component Password Handler. The manipulation leads to cleartext storage in a file or on disk. An attack ... Read more
- Published: Sep. 20, 2024
- Modified: Sep. 27, 2024
-
6.5
MEDIUMCVE-2024-44062
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Hiroaki Miyashita Custom Field Template allows Stored XSS.This issue affects Custom Field Template: from n/a through 2.6.5.... Read more
Affected Products : custom_field_template- Published: Sep. 15, 2024
- Modified: Sep. 27, 2024
-
6.5
MEDIUMCVE-2024-44059
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in MediaRon LLC Custom Query Blocks allows Stored XSS.This issue affects Custom Query Blocks: from n/a through 5.3.1.... Read more
Affected Products : custom_query_blocks- Published: Sep. 15, 2024
- Modified: Sep. 27, 2024
-
7.1
HIGHCVE-2024-44053
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Mohammad Arif Opor Ayam allows Reflected XSS.This issue affects Opor Ayam: from n/a through 1.8.... Read more
Affected Products : opor_ayam- Published: Sep. 15, 2024
- Modified: Sep. 27, 2024
-
4.8
MEDIUMCVE-2024-47058
With access to edit a Mautic form, the attacker can add Cross-Site Scripting stored in the html filed. This could be used to steal sensitive information from the user's current session.... Read more
Affected Products : mautic- Published: Sep. 18, 2024
- Modified: Sep. 27, 2024
-
6.1
MEDIUMCVE-2024-47050
Prior to this patch being applied, Mautic's tracking was vulnerable to Cross-Site Scripting through the Page URL variable.... Read more
Affected Products : mautic- Published: Sep. 18, 2024
- Modified: Sep. 27, 2024
-
9.1
CRITICALCVE-2024-0005
A condition exists in FlashArray and FlashBlade Purity whereby a malicious user could execute arbitrary commands remotely through a specifically crafted SNMP configuration.... Read more
- Published: Sep. 23, 2024
- Modified: Sep. 27, 2024
-
7.3
HIGHCVE-2021-27917
Prior to this patch, a stored XSS vulnerability existed in the contact tracking and page hits report.... Read more
Affected Products : mautic- Published: Sep. 18, 2024
- Modified: Sep. 27, 2024
-
5.9
MEDIUMCVE-2024-45460
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Manu225 Flipping Cards allows Stored XSS.This issue affects Flipping Cards: from n/a through 1.30.... Read more
Affected Products : flipping_cards- Published: Sep. 15, 2024
- Modified: Sep. 27, 2024
-
7.1
HIGHCVE-2024-45459
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in PickPlugins Product Slider for WooCommerce allows Reflected XSS.This issue affects Product Slider for WooCommerce: from n/a through 1.13.50.... Read more
Affected Products : product_slider_for_woocommerce- Published: Sep. 15, 2024
- Modified: Sep. 27, 2024
-
8.8
HIGHCVE-2024-37779
WoodWing Elvis DAM v6.98.1 was discovered to contain an authenticated remote command execution (RCE) vulnerability via the Apache Ant script functionality.... Read more
Affected Products :- Published: Sep. 23, 2024
- Modified: Sep. 27, 2024
-
6.5
MEDIUMCVE-2024-44063
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Happyforms allows Stored XSS.This issue affects Happyforms: from n/a through 1.26.0.... Read more
Affected Products : happyforms- Published: Sep. 15, 2024
- Modified: Sep. 27, 2024
-
9.1
CRITICALCVE-2024-0004
A condition exists in FlashArray Purity whereby an user with array admin role can execute arbitrary commands remotely to escalate privilege on the array.... Read more
Affected Products : purity\/\/fa- Published: Sep. 23, 2024
- Modified: Sep. 27, 2024
-
9.1
CRITICALCVE-2024-0003
A condition exists in FlashArray Purity whereby a malicious user could use a remote administrative service to create an account on the array allowing privileged access.... Read more
Affected Products : purity\/\/fa- Published: Sep. 23, 2024
- Modified: Sep. 27, 2024
-
10.0
CRITICALCVE-2024-0002
A condition exists in FlashArray Purity whereby an attacker can employ a privileged account allowing remote access to the array.... Read more
Affected Products : purity\/\/fa- Published: Sep. 23, 2024
- Modified: Sep. 27, 2024
-
10.0
CRITICALCVE-2024-0001
A condition exists in FlashArray Purity whereby a local account intended for initial array configuration remains active potentially allowing a malicious actor to gain elevated privileges.... Read more
Affected Products : purity\/\/fa- Published: Sep. 23, 2024
- Modified: Sep. 27, 2024
-
7.1
HIGHCVE-2024-44060
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Jennifer Hall Filmix allows Reflected XSS.This issue affects Filmix: from n/a through 1.1.... Read more
Affected Products : filmix- Published: Sep. 15, 2024
- Modified: Sep. 27, 2024