Latest CVE Feed
-
6.1
MEDIUMCVE-2024-9438
The SEUR Oficial plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'change_service' parameter in all versions up to, and including, 2.2.11 due to insufficient input sanitization and output escaping. This makes it possible for un... Read more
Affected Products :- Published: Oct. 29, 2024
- Modified: Oct. 29, 2024
-
5.9
MEDIUMCVE-2024-50413
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in codection Import and export users and customers allows Stored XSS.This issue affects Import and export users and customers: from n/a through 1.27.... Read more
Affected Products : import_and_export_users_and_customers- Published: Oct. 29, 2024
- Modified: Oct. 29, 2024
-
4.3
MEDIUMCVE-2024-10241
Mattermost versions 9.5.x <= 9.5.9 fail to properly filter the channel data when ElasticSearch is enabled which allows a user to get private channel names by using cmd+K/ctrl+K.... Read more
- Published: Oct. 29, 2024
- Modified: Oct. 29, 2024
-
6.1
MEDIUMCVE-2024-10048
The Post Status Notifier Lite and Premium plugins for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘page’ parameter in all versions up to, and including, 1.11.6 due to insufficient input sanitization and output escaping. This makes it... Read more
Affected Products : post_status_notifier_lite- Published: Oct. 29, 2024
- Modified: Oct. 29, 2024
-
6.4
MEDIUMCVE-2024-10185
The StreamWeasels YouTube Integration plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's sw-youtube-embed shortcode in all versions up to, and including, 1.3.2 due to insufficient input sanitization and output escaping on u... Read more
Affected Products :- Published: Oct. 29, 2024
- Modified: Oct. 29, 2024
-
7.1
HIGHCVE-2024-49646
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in ioannup Code Generate allows Reflected XSS.This issue affects Code Generate: from n/a through 1.0.... Read more
Affected Products :- Published: Oct. 29, 2024
- Modified: Oct. 29, 2024
-
8.8
HIGHCVE-2024-10436
The WPC Smart Messages for WooCommerce plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 4.2.1 via the get_condition_value function. This makes it possible for authenticated attackers, with Subscriber-level a... Read more
Affected Products :- Published: Oct. 29, 2024
- Modified: Oct. 29, 2024
-
10.0
CRITICALCVE-2024-50420
Unrestricted Upload of File with Dangerous Type vulnerability in adirectory aDirectory allows Upload a Web Shell to a Web Server.This issue affects aDirectory: from n/a through 1.3.... Read more
Affected Products : adirectory- Published: Oct. 29, 2024
- Modified: Oct. 29, 2024
-
10.0
CRITICALCVE-2024-50493
Unrestricted Upload of File with Dangerous Type vulnerability in masterhomepage Automatic Translation allows Upload a Web Shell to a Web Server.This issue affects Automatic Translation: from n/a through 1.0.4.... Read more
Affected Products :- Published: Oct. 29, 2024
- Modified: Oct. 29, 2024
-
4.3
MEDIUMCVE-2024-50052
Mattermost versions 9.10.x <= 9.10.2, 9.11.x <= 9.11.1, 9.5.x <= 9.5.9 fail to check that the origin of the message in an integration action matches with the original post metadata which allows an authenticated user to delete an arbitrary post.... Read more
- Published: Oct. 29, 2024
- Modified: Oct. 29, 2024
-
10.0
CRITICALCVE-2024-50484
Unrestricted Upload of File with Dangerous Type vulnerability in mahlamusa Multi Purpose Mail Form allows Upload a Web Shell to a Web Server.This issue affects Multi Purpose Mail Form: from n/a through 1.0.2.... Read more
Affected Products :- Published: Oct. 29, 2024
- Modified: Oct. 29, 2024
-
7.1
HIGHCVE-2024-49678
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Jinwen js allows Reflected XSS.This issue affects js paper: from n/a through 2.5.7.... Read more
Affected Products :- Published: Oct. 29, 2024
- Modified: Oct. 29, 2024
-
6.5
MEDIUMCVE-2024-50418
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Time Slot Booking Time Slot allows Stored XSS.This issue affects Time Slot: from n/a through 1.3.6.... Read more
Affected Products :- Published: Oct. 29, 2024
- Modified: Oct. 29, 2024
-
7.1
HIGHCVE-2024-49650
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in xarbo BuddyPress Greeting Message allows Reflected XSS.This issue affects BuddyPress Greeting Message: from n/a through 1.0.3.... Read more
Affected Products :- Published: Oct. 29, 2024
- Modified: Oct. 29, 2024
-
9.8
CRITICALCVE-2024-45656
IBM Flexible Service Processor (FSP) FW860.00 through FW860.B3, FW950.00 through FW950.C0, FW1030.00 through FW1030.61, FW1050.00 through FW1050.21, and FW1060.00 through FW1060.10 has static credentials which may allow network users to gain service privi... Read more
Affected Products : power9_system_firmware- Published: Oct. 29, 2024
- Modified: Oct. 29, 2024
-
6.4
MEDIUMCVE-2024-10266
The Premium Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Video Box widget in all versions up to, and including, 4.10.60 due to insufficient input sanitization and output escaping on user supplied ... Read more
Affected Products : premium_addons_for_elementor- Published: Oct. 29, 2024
- Modified: Oct. 29, 2024
-
7.1
HIGHCVE-2024-49648
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in rafasashi SVG Captcha allows Reflected XSS.This issue affects SVG Captcha: from n/a through 1.0.11.... Read more
Affected Products :- Published: Oct. 29, 2024
- Modified: Oct. 29, 2024
-
5.9
MEDIUMCVE-2024-50414
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in VirusTran Button contact VR allows Stored XSS.This issue affects Button contact VR: from n/a through 4.7.9.1.... Read more
Affected Products : call_\/_chat_\/_contact_button- Published: Oct. 29, 2024
- Modified: Oct. 29, 2024
-
7.1
HIGHCVE-2024-49647
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Carl Alberto Simple Custom Admin allows Reflected XSS.This issue affects Simple Custom Admin: from n/a through 1.2.... Read more
Affected Products :- Published: Oct. 29, 2024
- Modified: Oct. 29, 2024
-
10.0
CRITICALCVE-2024-50473
Unrestricted Upload of File with Dangerous Type vulnerability in Ajar Productions Ajar in5 Embed allows Upload a Web Shell to a Web Server.This issue affects Ajar in5 Embed: from n/a through 3.1.3.... Read more
Affected Products :- Published: Oct. 29, 2024
- Modified: Oct. 29, 2024