Latest CVE Feed
-
5.3
MEDIUMCVE-2024-43376
Umbraco is an ASP.NET CMS. Some endpoints in the Management API can return stack trace information, even when Umbraco is not in debug mode. This vulnerability is fixed in 14.1.2.... Read more
Affected Products : umbraco_cms- Published: Aug. 20, 2024
- Modified: Aug. 26, 2024
-
8.7
HIGHCVE-2024-7782
The Contact Form by Bit Form: Multi Step Form, Calculation Contact Form, Payment Contact Form & Custom Contact Form builder plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the iconRemove function i... Read more
Affected Products : contact_form_builder- Published: Aug. 20, 2024
- Modified: Aug. 26, 2024
-
7.2
HIGHCVE-2024-7780
The Contact Form by Bit Form: Multi Step Form, Calculation Contact Form, Payment Contact Form & Custom Contact Form builder plugin for WordPress is vulnerable to generic SQL Injection via the id parameter in versions 2.0 to 2.13.9 due to insufficient esca... Read more
Affected Products : contact_form_builder- Published: Aug. 20, 2024
- Modified: Aug. 26, 2024
-
9.0
CRITICALCVE-2024-7777
The Contact Form by Bit Form: Multi Step Form, Calculation Contact Form, Payment Contact Form & Custom Contact Form builder plugin for WordPress is vulnerable to arbitrary file read and deletion due to insufficient file path validation in multiple functio... Read more
Affected Products : contact_form_builder- Published: Aug. 20, 2024
- Modified: Aug. 26, 2024
-
5.5
MEDIUMCVE-2024-7775
The Contact Form by Bit Form: Multi Step Form, Calculation Contact Form, Payment Contact Form & Custom Contact Form builder plugin for WordPress is vulnerable to arbitrary JavaScript file uploads due to missing input validation in the addCustomCode functi... Read more
Affected Products : contact_form_builder- Published: Aug. 20, 2024
- Modified: Aug. 26, 2024
-
7.2
HIGHCVE-2024-7702
The Contact Form by Bit Form: Multi Step Form, Calculation Contact Form, Payment Contact Form & Custom Contact Form builder plugin for WordPress is vulnerable to generic SQL Injection via the entryID parameter in versions 2.0 to 2.13.9 due to insufficient... Read more
Affected Products : contact_form_builder- Published: Aug. 20, 2024
- Modified: Aug. 26, 2024
-
5.4
MEDIUMCVE-2024-5941
The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to unauthorized access and deletion of data due to a missing capability check on the 'handle_request' function in all versions up to, and including, 3.14.1. This make... Read more
Affected Products : givewp- Published: Aug. 20, 2024
- Modified: Aug. 26, 2024
-
6.5
MEDIUMCVE-2024-5940
The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'handle_request' function in all versions up to, and including, 3.13.0. This makes it po... Read more
Affected Products : givewp- Published: Aug. 20, 2024
- Modified: Aug. 26, 2024
-
5.3
MEDIUMCVE-2024-5939
The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'setup_wizard' function in all versions up to, and including, 3.13.0. This makes it possible f... Read more
Affected Products : givewp- Published: Aug. 20, 2024
- Modified: Aug. 26, 2024
-
5.4
MEDIUMCVE-2024-42766
Kashipara Bus Ticket Reservation System v1.0 0 is vulnerable to Incorrect Access Control via /deleteTicket.php.... Read more
Affected Products : bus_ticket_reservation_system- Published: Aug. 23, 2024
- Modified: Aug. 26, 2024
-
7.5
HIGHCVE-2024-45241
A traversal vulnerability in GeneralDocs.aspx in CentralSquare CryWolf (False Alarm Management) through 2024-08-09 allows unauthenticated attackers to read files outside of the working web directory via the rpt parameter, leading to the disclosure of sens... Read more
Affected Products :- Published: Aug. 26, 2024
- Modified: Aug. 26, 2024
-
4.9
MEDIUMCVE-2024-43442
Improper Neutralization of Input done by an attacker with admin privileges ('Cross-site Scripting') in OTRS (System Configuration modules) and ((OTRS)) Community Edition allows Cross-Site Scripting (XSS) within the System Configuration targeting other ad... Read more
Affected Products : otrs- Published: Aug. 26, 2024
- Modified: Aug. 26, 2024
-
7.5
HIGHCVE-2024-41996
Validating the order of the public keys in the Diffie-Hellman Key Agreement Protocol, when an approved safe prime is used, allows remote attackers (from the client side) to trigger unnecessarily expensive server-side DHE modular-exponentiation calculation... Read more
Affected Products :- Published: Aug. 26, 2024
- Modified: Aug. 26, 2024
-
8.1
HIGHCVE-2024-39344
An issue was discovered in the Docusign API package 8.142.14 for Salesforce. The Apttus_DocuApi__DocusignAuthentication__mdt object is installed via the marketplace from this package and stores some configuration information in a manner that could be comp... Read more
Affected Products :- Published: Aug. 21, 2024
- Modified: Aug. 26, 2024
-
7.8
HIGHCVE-2024-7980
Insufficient data validation in Installer in Google Chrome on Windows prior to 128.0.6613.84 allowed a local attacker to perform privilege escalation via a crafted symbolic link. (Chromium security severity: Medium)... Read more
- Published: Aug. 21, 2024
- Modified: Aug. 26, 2024
-
7.8
HIGHCVE-2024-7979
Insufficient data validation in Installer in Google Chrome on Windows prior to 128.0.6613.84 allowed a local attacker to perform privilege escalation via a crafted symbolic link. (Chromium security severity: Medium)... Read more
- Published: Aug. 21, 2024
- Modified: Aug. 26, 2024
-
8.8
HIGHCVE-2024-7972
Inappropriate implementation in V8 in Google Chrome prior to 128.0.6613.84 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page. (Chromium security severity: Medium)... Read more
- Published: Aug. 21, 2024
- Modified: Aug. 26, 2024
-
8.8
HIGHCVE-2024-42786
A SQL injection vulnerability in "/music/view_user.php" in Kashipara Music Management System v1.0 allows an attacker to execute arbitrary SQL commands via the "id" parameter of View User Profile Page.... Read more
Affected Products : music_management_system- Published: Aug. 21, 2024
- Modified: Aug. 26, 2024
-
8.8
HIGHCVE-2024-42785
A SQL injection vulnerability in /music/index.php?page=view_playlist in Kashipara Music Management System v1.0 allows an attacker to execute arbitrary SQL commands via the "id" parameter.... Read more
Affected Products : music_management_system- Published: Aug. 21, 2024
- Modified: Aug. 26, 2024
-
9.8
CRITICALCVE-2024-42784
A SQL injection vulnerability in "/music/controller.php?page=view_music" in Kashipara Music Management System v1.0 allows an attacker to execute arbitrary SQL commands via the "id" parameter.... Read more
Affected Products : music_management_system- Published: Aug. 21, 2024
- Modified: Aug. 26, 2024