Latest CVE Feed
-
8.8
HIGHCVE-2024-7717
The WP Events Manager plugin for WordPress is vulnerable to time-based SQL Injection via the ‘order’ parameter in all versions up to, and including, 2.1.11 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on t... Read more
Affected Products : wp_events_manager- Published: Aug. 31, 2024
- Modified: Sep. 20, 2024
-
5.3
MEDIUMCVE-2022-4100
The WP Cerber Security plugin for WordPress is vulnerable to IP Protection bypass in versions up to, and including 9.4 due to the plugin improperly checking for a visitor's IP address. This makes it possible for an attacker whose IP address has been block... Read more
- Published: Aug. 31, 2024
- Modified: Sep. 20, 2024
-
7.8
HIGHCVE-2024-38210
Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability... Read more
Affected Products : edge_chromium- Published: Aug. 22, 2024
- Modified: Sep. 19, 2024
-
7.8
HIGHCVE-2024-38209
Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability... Read more
Affected Products : edge_chromium- Published: Aug. 22, 2024
- Modified: Sep. 19, 2024
-
6.1
MEDIUM- Published: Aug. 22, 2024
- Modified: Sep. 19, 2024
-
6.3
MEDIUMCVE-2024-38207
Microsoft Edge (HTML-based) Memory Corruption Vulnerability... Read more
Affected Products : edge_chromium- Published: Aug. 23, 2024
- Modified: Sep. 19, 2024
-
6.4
MEDIUMCVE-2024-1384
The Premium Portfolio Features for Phlox theme plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'aux_recent_portfolios_grid' shortcode in all versions up to, and including, 2.3.3 due to insufficient input sanitization and... Read more
Affected Products : auxinportfolio- Published: Aug. 29, 2024
- Modified: Sep. 19, 2024
-
7.5
HIGHCVE-2024-3679
The Premium SEO Pack – WP SEO Plugin plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.6.001. This makes it possible for unauthenticated attackers to view limited information from password protect... Read more
Affected Products : wp_seo_plugin- Published: Aug. 29, 2024
- Modified: Sep. 19, 2024
-
6.4
MEDIUMCVE-2024-1056
The FunnelKit Funnel Builder Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'allow_iframe_tag_in_post' function which uses the 'wp_kses_allowed_html' filter to globally allow script and iframe tags in posts in all versions u... Read more
Affected Products : funnel_builder- Published: Aug. 29, 2024
- Modified: Sep. 19, 2024
-
9.8
CRITICALCVE-2024-8302
A vulnerability was found in dingfanzu CMS up to 29d67d9044f6f93378e6eb6ff92272217ff7225c. It has been rated as critical. Affected by this issue is some unknown functionality of the file /ajax/chpwd.php. The manipulation of the argument username leads to ... Read more
- Published: Aug. 29, 2024
- Modified: Sep. 19, 2024
-
9.8
CRITICALCVE-2024-43144
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in StylemixThemes Cost Calculator Builder allows SQL Injection.This issue affects Cost Calculator Builder: from n/a through 3.2.15.... Read more
Affected Products : cost_calculator_builder- Published: Aug. 29, 2024
- Modified: Sep. 19, 2024
-
9.8
CRITICALCVE-2024-43917
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in TemplateInvaders TI WooCommerce Wishlist allows SQL Injection.This issue affects TI WooCommerce Wishlist: from n/a through 2.8.2.... Read more
Affected Products : ti_woocommerce_wishlist- Published: Aug. 29, 2024
- Modified: Sep. 19, 2024
-
9.8
CRITICALCVE-2024-43922
Improper Control of Generation of Code ('Code Injection') vulnerability in NitroPack Inc. NitroPack allows Code Injection.This issue affects NitroPack: from n/a through 1.16.7.... Read more
Affected Products : nitropack- Published: Aug. 29, 2024
- Modified: Sep. 19, 2024
-
8.8
HIGHCVE-2024-45696
Certain models of D-Link wireless routers contain hidden functionality. By sending specific packets to the web service, the attacker can forcibly enable the telnet service and log in using hard-coded credentials. The telnet service enabled through this me... Read more
- Published: Sep. 16, 2024
- Modified: Sep. 19, 2024
-
9.8
CRITICALCVE-2024-45697
Certain models of D-Link wireless routers have a hidden functionality where the telnet service is enabled when the WAN port is plugged in. Unauthorized remote attackers can log in and execute OS commands using hard-coded credentials.... Read more
- Published: Sep. 16, 2024
- Modified: Sep. 19, 2024
-
8.8
HIGHCVE-2024-34344
Nuxt is a free and open-source framework to create full-stack web applications and websites with Vue.js. Due to the insufficient validation of the `path` parameter in the NuxtTestComponentWrapper, an attacker can execute arbitrary JavaScript on the server... Read more
Affected Products : nuxt- Published: Aug. 05, 2024
- Modified: Sep. 19, 2024
-
8.6
HIGHCVE-2024-42352
Nuxt is a free and open-source framework to create full-stack web applications and websites with Vue.js. `nuxt/icon` provides an API to allow client side icon lookup. This endpoint is at `/api/_nuxt_icon/[name]`. The proxied request path is improperly par... Read more
Affected Products : nuxt- Published: Aug. 05, 2024
- Modified: Sep. 19, 2024
-
6.5
MEDIUMCVE-2024-45457
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Spiffy Plugins Spiffy Calendar allows Stored XSS.This issue affects Spiffy Calendar: from n/a through 4.9.13.... Read more
Affected Products : spiffy_calendar- Published: Sep. 15, 2024
- Modified: Sep. 19, 2024
-
7.8
HIGHCVE-2024-7553
Incorrect validation of files loaded from a local untrusted directory may allow local privilege escalation if the underlying operating systems is Windows. This may result in the application executing arbitrary behaviour determined by the contents of untru... Read more
Affected Products : windows_server_2016 windows_server_2019 windows_10_1607 windows_10_1809 windows_10_20h2 windows_10_21h2 windows_10_22h2 windows_server_2022 windows_11_21h2 windows_11_22h2 +14 more products- Published: Aug. 07, 2024
- Modified: Sep. 19, 2024
-
7.6
HIGHCVE-2024-41959
mailcow: dockerized is an open source groupware/email suite based on docker. An unauthenticated attacker can inject a JavaScript payload into the API logs. This payload is executed whenever the API logs page is viewed, potentially allowing an attacker to ... Read more
Affected Products : mailcow\- Published: Aug. 05, 2024
- Modified: Sep. 19, 2024