Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 9.9

    CRITICAL
    CVE-2024-8624

    The MDTF – Meta Data and Taxonomies Filter plugin for WordPress is vulnerable to SQL Injection via the 'meta_key' attribute of the 'mdf_select_title' shortcode in all versions up to, and including, 1.3.3.3 due to insufficient escaping on the user supplied... Read more

    • Published: Sep. 24, 2024
    • Modified: Sep. 26, 2024
  • 6.4

    MEDIUM
    CVE-2024-7611

    The Enter Addons – Ultimate Template Builder for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'tag' attribute of the Events Card widget in all versions up to, and including, 2.1.8 due to insufficient input sanitizati... Read more

    Affected Products : enter_addons
    • Published: Sep. 06, 2024
    • Modified: Sep. 26, 2024
  • 5.4

    MEDIUM
    CVE-2024-8628

    The Popup, Optin Form & Email Newsletters for Mailchimp, HubSpot, AWeber – MailOptin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'post-meta' shortcode in all versions up to, and including, 1.2.70.3 due to insufficien... Read more

    Affected Products : mailoptin
    • Published: Sep. 24, 2024
    • Modified: Sep. 26, 2024
  • 9.1

    CRITICAL
    CVE-2024-8671

    The WooEvents - Calendar and Event Booking plugin for WordPress is vulnerable to arbitrary file overwrite due to insufficient file path validation in the inc/barcode.php file in all versions up to, and including, 4.1.2. This makes it possible for unauthen... Read more

    Affected Products : wooevents
    • Published: Sep. 24, 2024
    • Modified: Sep. 26, 2024
  • 6.4

    MEDIUM
    CVE-2024-6849

    The Preloader Plus – WordPress Loading Screen Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 2.2.1 due to insufficient input sanitization and output escaping. This makes ... Read more

    Affected Products : preloader_plus
    • Published: Sep. 07, 2024
    • Modified: Sep. 26, 2024
  • 7.5

    HIGH
    CVE-2024-44825

    Directory Traversal vulnerability in Centro de Tecnologia da Informaco Renato Archer InVesalius3 v3.1.99995 allows attackers to write arbitrary files unto the system via a crafted .inv3 file.... Read more

    Affected Products :
    • Published: Sep. 25, 2024
    • Modified: Sep. 26, 2024
  • 9.8

    CRITICAL
    CVE-2024-9080

    A vulnerability was found in code-projects Student Record System 1.0. It has been classified as critical. Affected is an unknown function of the file /pincode-verification.php. The manipulation of the argument pincode leads to sql injection. It is possibl... Read more

    Affected Products : student_record_system
    • Published: Sep. 22, 2024
    • Modified: Sep. 26, 2024
  • 9.8

    CRITICAL
    CVE-2024-9079

    A vulnerability was found in code-projects Student Record System 1.0 and classified as critical. This issue affects some unknown processing of the file /marks.php. The manipulation of the argument coursename leads to sql injection. The attack may be initi... Read more

    Affected Products : student_record_system
    • Published: Sep. 22, 2024
    • Modified: Sep. 26, 2024
  • 9.8

    CRITICAL
    CVE-2024-9078

    A vulnerability has been found in code-projects Student Record System 1.0 and classified as critical. This vulnerability affects unknown code of the file /course.php. The manipulation of the argument coursename leads to sql injection. The attack can be in... Read more

    Affected Products : student_record_system
    • Published: Sep. 22, 2024
    • Modified: Sep. 26, 2024
  • 4.3

    MEDIUM
    CVE-2024-8538

    The Big File Uploads – Increase Maximum File Upload Size plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 2.1.2. This is due the plugin not sanitizing a file path in an error message. This makes it possible ... Read more

    Affected Products : big_file_uploads
    • Published: Sep. 07, 2024
    • Modified: Sep. 26, 2024
  • 9.8

    CRITICAL
    CVE-2024-8791

    The Donation Forms by Charitable – Donations Plugin & Fundraising Platform for WordPress plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.8.1.14. This is due to the plugin not properly verifying a user's i... Read more

    Affected Products : charitable charitable
    • Published: Sep. 24, 2024
    • Modified: Sep. 26, 2024
  • 5.3

    MEDIUM
    CVE-2024-8794

    The BA Book Everything plugin for WordPress is vulnerable to arbitrary password reset in all versions up to, and including, 1.6.20. This is due to the reset_user_password() function not verifying a user's identity prior to setting a password. This makes i... Read more

    Affected Products : ba_book_everything
    • Published: Sep. 24, 2024
    • Modified: Sep. 26, 2024
  • 7.2

    HIGH
    CVE-2024-1596

    The Ninja Forms - File Uploads plugin for WordPress is vulnerable to Stored Cross-Site Scripting via an uploaded file (e.g. RTX file) in all versions up to, and including, 3.3.16 due to insufficient input sanitization and output escaping. This makes it po... Read more

    Affected Products : ninja_forms_file_uploads
    • Published: Sep. 07, 2024
    • Modified: Sep. 26, 2024
  • 5.4

    MEDIUM
    CVE-2024-6282

    The Master Addons – Free Widgets, Hover Effects, Toggle, Conditions, Animations for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the data-jltma-wrapper-link element in all versions up to, and including 2.0.6.4 due to ins... Read more

    Affected Products : master_addons
    • Published: Sep. 10, 2024
    • Modified: Sep. 26, 2024
  • 8.8

    HIGH
    CVE-2024-8268

    The Frontend Dashboard plugin for WordPress is vulnerable to unauthorized code execution due to insufficient filtering on callable methods/functions via the ajax_request() function in all versions up to, and including, 2.2.4. This makes it possible for au... Read more

    Affected Products : frontend_dashboard
    • Published: Sep. 10, 2024
    • Modified: Sep. 26, 2024
  • 9.8

    CRITICAL
    CVE-2024-46957

    Mellium mellium.im/xmpp 0.0.1 through 0.21.4 allows response spoofing if the implementation uses predictable IDs because the stanza type is not checked. This is fixed in 0.22.0.... Read more

    Affected Products :
    • Published: Sep. 25, 2024
    • Modified: Sep. 26, 2024
  • 8.8

    HIGH
    CVE-2024-7112

    The Pinpoint Booking System – #1 WordPress Booking Plugin plugin for WordPress is vulnerable to SQL Injection via the ‘schedule’ parameter in all versions up to, and including, 2.9.9.5.0 due to insufficient escaping on the user supplied parameter and lack... Read more

    Affected Products : pinpoint_booking_system
    • Published: Sep. 07, 2024
    • Modified: Sep. 26, 2024
  • 7.3

    HIGH
    CVE-2024-8478

    The The Affiliate Super Assistent plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 1.5.3. This is due to the software allowing users to supply arbitrary shortcodes in comments when the 'Parse commen... Read more

    Affected Products : affiliate_super_assistent
    • Published: Sep. 10, 2024
    • Modified: Sep. 26, 2024
  • 5.3

    MEDIUM
    CVE-2024-8369

    The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to unauthorized access to Private or Password-protected events due to missing authorization checks in all versions up to, and including, 4.0.4.3. This makes it possi... Read more

    Affected Products : eventprime
    • Published: Sep. 10, 2024
    • Modified: Sep. 26, 2024
  • 9.4

    CRITICAL
    CVE-2024-5958

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Eliz Software Panel allows Command Line Execution through SQL Injection.This issue affects Panel: before v2.3.24.... Read more

    Affected Products : panel
    • Published: Sep. 18, 2024
    • Modified: Sep. 26, 2024
Showing 20 of 291058 Results