Latest CVE Feed
-
7.2
HIGHCVE-2024-7780
The Contact Form by Bit Form: Multi Step Form, Calculation Contact Form, Payment Contact Form & Custom Contact Form builder plugin for WordPress is vulnerable to generic SQL Injection via the id parameter in versions 2.0 to 2.13.9 due to insufficient esca... Read more
Affected Products : contact_form_builder- Published: Aug. 20, 2024
- Modified: Aug. 26, 2024
-
9.0
CRITICALCVE-2024-7777
The Contact Form by Bit Form: Multi Step Form, Calculation Contact Form, Payment Contact Form & Custom Contact Form builder plugin for WordPress is vulnerable to arbitrary file read and deletion due to insufficient file path validation in multiple functio... Read more
Affected Products : contact_form_builder- Published: Aug. 20, 2024
- Modified: Aug. 26, 2024
-
5.5
MEDIUMCVE-2024-7775
The Contact Form by Bit Form: Multi Step Form, Calculation Contact Form, Payment Contact Form & Custom Contact Form builder plugin for WordPress is vulnerable to arbitrary JavaScript file uploads due to missing input validation in the addCustomCode functi... Read more
Affected Products : contact_form_builder- Published: Aug. 20, 2024
- Modified: Aug. 26, 2024
-
7.2
HIGHCVE-2024-7702
The Contact Form by Bit Form: Multi Step Form, Calculation Contact Form, Payment Contact Form & Custom Contact Form builder plugin for WordPress is vulnerable to generic SQL Injection via the entryID parameter in versions 2.0 to 2.13.9 due to insufficient... Read more
Affected Products : contact_form_builder- Published: Aug. 20, 2024
- Modified: Aug. 26, 2024
-
5.4
MEDIUMCVE-2024-5941
The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to unauthorized access and deletion of data due to a missing capability check on the 'handle_request' function in all versions up to, and including, 3.14.1. This make... Read more
Affected Products : givewp- Published: Aug. 20, 2024
- Modified: Aug. 26, 2024
-
6.5
MEDIUMCVE-2024-5940
The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'handle_request' function in all versions up to, and including, 3.13.0. This makes it po... Read more
Affected Products : givewp- Published: Aug. 20, 2024
- Modified: Aug. 26, 2024
-
5.3
MEDIUMCVE-2024-5939
The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'setup_wizard' function in all versions up to, and including, 3.13.0. This makes it possible f... Read more
Affected Products : givewp- Published: Aug. 20, 2024
- Modified: Aug. 26, 2024
-
5.4
MEDIUMCVE-2024-42766
Kashipara Bus Ticket Reservation System v1.0 0 is vulnerable to Incorrect Access Control via /deleteTicket.php.... Read more
Affected Products : bus_ticket_reservation_system- Published: Aug. 23, 2024
- Modified: Aug. 26, 2024
-
7.5
HIGHCVE-2024-45241
A traversal vulnerability in GeneralDocs.aspx in CentralSquare CryWolf (False Alarm Management) through 2024-08-09 allows unauthenticated attackers to read files outside of the working web directory via the rpt parameter, leading to the disclosure of sens... Read more
Affected Products :- Published: Aug. 26, 2024
- Modified: Aug. 26, 2024
-
4.9
MEDIUMCVE-2024-43442
Improper Neutralization of Input done by an attacker with admin privileges ('Cross-site Scripting') in OTRS (System Configuration modules) and ((OTRS)) Community Edition allows Cross-Site Scripting (XSS) within the System Configuration targeting other ad... Read more
Affected Products : otrs- Published: Aug. 26, 2024
- Modified: Aug. 26, 2024
-
7.5
HIGHCVE-2024-41996
Validating the order of the public keys in the Diffie-Hellman Key Agreement Protocol, when an approved safe prime is used, allows remote attackers (from the client side) to trigger unnecessarily expensive server-side DHE modular-exponentiation calculation... Read more
Affected Products :- Published: Aug. 26, 2024
- Modified: Aug. 26, 2024
-
8.1
HIGHCVE-2024-39344
An issue was discovered in the Docusign API package 8.142.14 for Salesforce. The Apttus_DocuApi__DocusignAuthentication__mdt object is installed via the marketplace from this package and stores some configuration information in a manner that could be comp... Read more
Affected Products :- Published: Aug. 21, 2024
- Modified: Aug. 26, 2024
-
7.8
HIGHCVE-2024-7980
Insufficient data validation in Installer in Google Chrome on Windows prior to 128.0.6613.84 allowed a local attacker to perform privilege escalation via a crafted symbolic link. (Chromium security severity: Medium)... Read more
- Published: Aug. 21, 2024
- Modified: Aug. 26, 2024
-
7.8
HIGHCVE-2024-7979
Insufficient data validation in Installer in Google Chrome on Windows prior to 128.0.6613.84 allowed a local attacker to perform privilege escalation via a crafted symbolic link. (Chromium security severity: Medium)... Read more
- Published: Aug. 21, 2024
- Modified: Aug. 26, 2024
-
8.8
HIGHCVE-2024-7972
Inappropriate implementation in V8 in Google Chrome prior to 128.0.6613.84 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page. (Chromium security severity: Medium)... Read more
- Published: Aug. 21, 2024
- Modified: Aug. 26, 2024
-
8.8
HIGHCVE-2024-42786
A SQL injection vulnerability in "/music/view_user.php" in Kashipara Music Management System v1.0 allows an attacker to execute arbitrary SQL commands via the "id" parameter of View User Profile Page.... Read more
Affected Products : music_management_system- Published: Aug. 21, 2024
- Modified: Aug. 26, 2024
-
8.8
HIGHCVE-2024-42785
A SQL injection vulnerability in /music/index.php?page=view_playlist in Kashipara Music Management System v1.0 allows an attacker to execute arbitrary SQL commands via the "id" parameter.... Read more
Affected Products : music_management_system- Published: Aug. 21, 2024
- Modified: Aug. 26, 2024
-
9.8
CRITICALCVE-2024-42784
A SQL injection vulnerability in "/music/controller.php?page=view_music" in Kashipara Music Management System v1.0 allows an attacker to execute arbitrary SQL commands via the "id" parameter.... Read more
Affected Products : music_management_system- Published: Aug. 21, 2024
- Modified: Aug. 26, 2024
-
4.1
MEDIUMCVE-2024-41849
Adobe Experience Manager versions 6.5.20 and earlier are affected by an Improper Input Validation vulnerability that could lead to a security feature bypass. An low-privileged attacker could leverage this vulnerability to slightly affect the integrity of ... Read more
- Published: Aug. 23, 2024
- Modified: Aug. 26, 2024
-
5.4
MEDIUMCVE-2024-41848
Adobe Experience Manager versions 6.5.20 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. If an attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be execut... Read more
- Published: Aug. 23, 2024
- Modified: Aug. 26, 2024