Latest CVE Feed
-
7.5
HIGHCVE-2024-38699
Missing Authorization vulnerability in WP Swings Wallet System for WooCommerce allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Wallet System for WooCommerce: from n/a through 2.5.13.... Read more
Affected Products : wallet_system_for_woocommerce- Published: Aug. 13, 2024
- Modified: Aug. 13, 2024
-
5.9
MEDIUMCVE-2024-43137
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WappPress Team WappPress allows Stored XSS.This issue affects WappPress: from n/a through 6.0.4.... Read more
Affected Products :- Published: Aug. 12, 2024
- Modified: Aug. 13, 2024
-
7.1
HIGHCVE-2024-43217
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Pierre Lebedel Kodex Posts likes allows Reflected XSS.This issue affects Kodex Posts likes: from n/a through 2.5.0.... Read more
Affected Products : kodex_posts_likes- Published: Aug. 12, 2024
- Modified: Aug. 13, 2024
-
7.8
HIGHCVE-2024-41908
A vulnerability has been identified in NX (All versions < V2406.3000). The affected applications contains an out of bounds read vulnerability while parsing specially crafted PRT files. This could allow an attacker to crash the application or execute code ... Read more
Affected Products : nx- Published: Aug. 13, 2024
- Modified: Aug. 13, 2024
-
6.5
MEDIUMCVE-2024-43164
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Blockspare allows Stored XSS.This issue affects Blockspare: from n/a through 3.2.0.... Read more
Affected Products :- Published: Aug. 12, 2024
- Modified: Aug. 13, 2024
-
6.8
MEDIUMCVE-2024-6768
A Denial of Service in CLFS.sys in Microsoft Windows 10, Windows 11, Windows Server 2016, Windows Server 2019, and Windows Server 2022 allows a malicious authenticated low-privilege user to cause a Blue Screen of Death via a forced call to the KeBugCheckE... Read more
- Published: Aug. 12, 2024
- Modified: Aug. 13, 2024
-
6.5
MEDIUMCVE-2024-38752
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Zoho Campaigns allows Cross-Site Scripting (XSS).This issue affects Zoho Campaigns: from n/a through 2.0.8.... Read more
Affected Products : zoho_campaigns- Published: Aug. 13, 2024
- Modified: Aug. 13, 2024
-
6.5
MEDIUMCVE-2024-43155
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in PickPlugins ComboBlocks allows Stored XSS.This issue affects ComboBlocks: from n/a through 2.2.86.... Read more
Affected Products : comboblocks- Published: Aug. 12, 2024
- Modified: Aug. 13, 2024
-
6.5
MEDIUMCVE-2024-43139
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Antoine Hurkmans Football Pool allows Stored XSS.This issue affects Football Pool: from n/a through 2.11.9.... Read more
Affected Products :- Published: Aug. 12, 2024
- Modified: Aug. 13, 2024
-
5.3
MEDIUMCVE-2024-38756
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Weblizar Coming Soon allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Coming Soon: from n/a through 1.6.3.... Read more
Affected Products :- Published: Aug. 13, 2024
- Modified: Aug. 13, 2024
-
6.4
MEDIUMCVE-2024-2259
This vulnerability exists in InstaRISPACS software due to insufficient validation of user supplied input for the loginTo parameter in user login module of the web interface of the application. A remote attacker could exploit this vulnerability by sending ... Read more
Affected Products :- Published: Aug. 13, 2024
- Modified: Aug. 13, 2024
-
6.5
MEDIUMCVE-2024-43227
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WPDeveloper BetterDocs allows Stored XSS.This issue affects BetterDocs: from n/a through 3.5.8.... Read more
Affected Products : betterdocs- Published: Aug. 12, 2024
- Modified: Aug. 13, 2024
-
6.5
MEDIUMCVE-2024-43224
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Yuri Baranov YaMaps for WordPress allows Stored XSS.This issue affects YaMaps for WordPress: from n/a through 0.6.27.... Read more
Affected Products : yamaps- Published: Aug. 12, 2024
- Modified: Aug. 13, 2024
-
5.9
MEDIUMCVE-2024-43161
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Averta Depicter Slider allows Stored XSS.This issue affects Depicter Slider: from n/a through 3.1.2.... Read more
Affected Products : depicter- Published: Aug. 12, 2024
- Modified: Aug. 13, 2024
-
5.3
MEDIUMCVE-2024-37924
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wp2speed WP2Speed Faster allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects WP2Speed Faster: from n/a through 1.0.1.... Read more
Affected Products :- Published: Aug. 12, 2024
- Modified: Aug. 13, 2024
-
7.5
HIGHCVE-2024-37935
Missing Authorization vulnerability in anhvnit Woocommerce OpenPos allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Woocommerce OpenPos: from n/a through 6.4.4.... Read more
Affected Products :- Published: Aug. 13, 2024
- Modified: Aug. 13, 2024
-
8.1
HIGHCVE-2024-40479
A SQL injection vulnerability in "/admin/quizquestion.php" in Kashipara Online Exam System v1.0 allows remote attackers to execute arbitrary SQL commands via the "eid" parameter.... Read more
Affected Products :- Published: Aug. 12, 2024
- Modified: Aug. 13, 2024
-
6.5
MEDIUMCVE-2024-34788
An improper authentication vulnerability in web component of EPMM prior to 12.1.0.1 allows a remote malicious user to access potentially sensitive information... Read more
Affected Products : endpoint_manager_mobile- Published: Aug. 07, 2024
- Modified: Aug. 12, 2024
-
7.7
HIGHCVE-2024-42347
matrix-react-sdk is a react-based SDK for inserting a Matrix chat/voip client into a web page. A malicious homeserver could manipulate a user's account data to cause the client to enable URL previews in end-to-end encrypted rooms, in which case any URLs ... Read more
- Published: Aug. 06, 2024
- Modified: Aug. 12, 2024
-
6.3
MEDIUMCVE-2024-41677
Qwik is a performance focused javascript framework. A potential mutation XSS vulnerability exists in Qwik for versions up to but not including 1.6.0. Qwik improperly escapes HTML on server-side rendering. It converts strings according to the rules found i... Read more
Affected Products : qwik- Published: Aug. 06, 2024
- Modified: Aug. 12, 2024