Latest CVE Feed
-
5.4
MEDIUMCVE-2022-40373
Cross Site Scripting (XSS) vulnerability in FeehiCMS 2.1.1 allows remote attackers to run arbitrary code via upload of crafted XML file.... Read more
Affected Products : feehicms- Published: Dec. 15, 2022
- Modified: Apr. 21, 2025
-
5.9
MEDIUMCVE-2022-3590
WordPress is affected by an unauthenticated blind SSRF in the pingback feature. Because of a TOCTOU race condition between the validation checks and the HTTP request, attackers can reach internal hosts that are explicitly forbidden.... Read more
Affected Products : wordpress- Published: Dec. 14, 2022
- Modified: Apr. 21, 2025
-
5.5
MEDIUMCVE-2022-20513
In decrypt_1_2 of CryptoPlugin.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Produ... Read more
Affected Products : android- Published: Dec. 16, 2022
- Modified: Apr. 21, 2025
-
7.8
HIGHCVE-2022-20512
In navigateUpTo of Task.java, there is a possible way to launch an intent handler with a mismatched intent due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction ... Read more
Affected Products : android- Published: Dec. 16, 2022
- Modified: Apr. 21, 2025
-
5.5
MEDIUMCVE-2022-20511
In getNearbyAppStreamingPolicy of DevicePolicyManagerService.java, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product... Read more
Affected Products : android- Published: Dec. 16, 2022
- Modified: Apr. 21, 2025
-
9.8
CRITICALCVE-2021-31650
A SQL injection vulnerability in Sourcecodester Online Grading System 1.0 allows remote attackers to execute arbitrary SQL commands via the uname parameter.... Read more
Affected Products : online_grading_system- Published: Dec. 16, 2022
- Modified: Apr. 21, 2025
-
8.1
HIGHCVE-2021-25094
The Tatsu WordPress plugin before 3.3.12 add_custom_font action can be used without prior authentication to upload a rogue zip file which is uncompressed under the WordPress's upload directory. By adding a PHP shell with a filename starting with a dot "."... Read more
Affected Products : tatsu- Published: Apr. 25, 2022
- Modified: Apr. 21, 2025
-
10.0
HIGHCVE-2015-5119
Use-after-free vulnerability in the ByteArray class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.x through 13.0.0.296 and 14.x through 18.0.0.194 on Windows and OS X and 11.x through 11.2.202.468 on Linux allows remote attackers to ... Read more
- Actively Exploited
- Published: Jul. 08, 2015
- Modified: Apr. 21, 2025
-
6.8
MEDIUMCVE-2024-53260
Autolab is a course management service that enables auto-graded programming assignments. A user can modify their first and or last name to include a valid excel / spreadsheet formula. When an instructor downloads their course's roster and opens, this name... Read more
Affected Products : autolab- Published: Nov. 27, 2024
- Modified: Apr. 21, 2025
-
6.4
MEDIUMCVE-2024-8236
The Elementor Website Builder – More than Just a Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘url’ parameter of the Icon widget in all versions up to, and including, 3.25.7 due to insufficient input sanitization ... Read more
Affected Products : website_builder- Published: Nov. 26, 2024
- Modified: Apr. 21, 2025
-
4.7
MEDIUMCVE-2024-43005
A reflected cross-site scripting (XSS) vulnerability in the component dl_liuyan_save.php of ZZCMS v2023 allows attackers to execute arbitrary code in the context of a user's browser via injecting a crafted payload.... Read more
Affected Products : zzcms- Published: Aug. 16, 2024
- Modified: Apr. 21, 2025
-
5.4
MEDIUMCVE-2024-43006
A stored cross-site scripting (XSS) vulnerability exists in ZZCMS2023 in the ask/show.php file at line 21. An attacker can exploit this vulnerability by sending a specially crafted POST request to /user/ask_edit.php?action=add, which includes malicious Ja... Read more
- Published: Aug. 16, 2024
- Modified: Apr. 21, 2025
-
4.7
MEDIUMCVE-2024-43009
A reflected cross-site scripting (XSS) vulnerability exists in user/login.php at line 24 in ZZCMS 2023 and earlier. The application directly inserts the value of the HTTP_REFERER header into the HTML response without proper sanitization. An attacker can e... Read more
Affected Products : zzcms- Published: Aug. 16, 2024
- Modified: Apr. 21, 2025
-
4.9
MEDIUMCVE-2024-43011
An arbitrary file deletion vulnerability exists in the admin/del.php file at line 62 in ZZCMS 2023 and earlier. Due to insufficient validation and sanitization of user input for file paths, an attacker can exploit this vulnerability by using directory tra... Read more
Affected Products : zzcms- Published: Aug. 16, 2024
- Modified: Apr. 21, 2025
-
8.8
HIGHCVE-2024-42612
Pligg CMS v2.0.2 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/domain_management.php?whitelist_add... Read more
Affected Products : pligg_cms- Published: Aug. 20, 2024
- Modified: Apr. 21, 2025
-
8.8
HIGHCVE-2024-42619
Pligg CMS v2.0.2 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/domain_management.php?id=0&list=whitelist&remove=pligg.com... Read more
- Published: Aug. 20, 2024
- Modified: Apr. 21, 2025
-
7.2
HIGHCVE-2024-42523
publiccms V4.0.202302.e and before is vulnerable to Any File Upload via publiccms/admin/cmsTemplate/saveMetaData... Read more
Affected Products : publiccms- Published: Aug. 23, 2024
- Modified: Apr. 21, 2025
-
9.1
CRITICALCVE-2024-42914
A host header injection vulnerability exists in the forgot password functionality of ArrowCMS version 1.0.0. By sending a specially crafted host header in the forgot password request, it is possible to send password reset links to users which, once clicke... Read more
Affected Products : arrowcms- Published: Aug. 23, 2024
- Modified: Apr. 21, 2025
-
4.8
MEDIUMCVE-2024-40111
A persistent (stored) cross-site scripting (XSS) vulnerability has been identified in Automad 2.0.0-alpha.4. This vulnerability enables an attacker to inject malicious JavaScript code into the template body. The injected code is stored within the flat fil... Read more
Affected Products : automad- Published: Aug. 23, 2024
- Modified: Apr. 21, 2025
-
8.2
HIGHCVE-2023-43650
JumpServer is an open source bastion host. The verification code for resetting user's password is vulnerable to brute-force attacks due to the absence of rate limiting. JumpServer provides a feature allowing users to reset forgotten passwords. Affected us... Read more
Affected Products : jumpserver- Published: Sep. 27, 2023
- Modified: Apr. 21, 2025