Latest CVE Feed
-
7.5
HIGHCVE-2024-43131
Incorrect Authorization vulnerability in WPWeb Docket (WooCommerce Collections / Wishlist / Watchlist) allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Docket (WooCommerce Collections / Wishlist / Watchlist): from n/a bef... Read more
Affected Products :- Published: Aug. 13, 2024
- Modified: Aug. 13, 2024
-
10.0
CRITICALCVE-2024-43160
Unrestricted Upload of File with Dangerous Type vulnerability in BerqWP allows Code Injection.This issue affects BerqWP: from n/a through 1.7.6.... Read more
Affected Products :- Published: Aug. 13, 2024
- Modified: Aug. 13, 2024
-
9.8
CRITICALCVE-2024-43141
Deserialization of Untrusted Data vulnerability in Roland Barker, xnau webdesign Participants Database allows Object Injection.This issue affects Participants Database: from n/a through 2.5.9.2.... Read more
Affected Products : participants_database- Published: Aug. 13, 2024
- Modified: Aug. 13, 2024
-
6.4
MEDIUMCVE-2024-2259
This vulnerability exists in InstaRISPACS software due to insufficient validation of user supplied input for the loginTo parameter in user login module of the web interface of the application. A remote attacker could exploit this vulnerability by sending ... Read more
Affected Products :- Published: Aug. 13, 2024
- Modified: Aug. 13, 2024
-
7.5
HIGHCVE-2024-37935
Missing Authorization vulnerability in anhvnit Woocommerce OpenPos allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Woocommerce OpenPos: from n/a through 6.4.4.... Read more
Affected Products :- Published: Aug. 13, 2024
- Modified: Aug. 13, 2024
-
5.3
MEDIUMCVE-2024-37924
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wp2speed WP2Speed Faster allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects WP2Speed Faster: from n/a through 1.0.1.... Read more
Affected Products :- Published: Aug. 12, 2024
- Modified: Aug. 13, 2024
-
5.9
MEDIUMCVE-2024-43161
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Averta Depicter Slider allows Stored XSS.This issue affects Depicter Slider: from n/a through 3.1.2.... Read more
Affected Products : depicter- Published: Aug. 12, 2024
- Modified: Aug. 13, 2024
-
6.5
MEDIUMCVE-2024-43224
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Yuri Baranov YaMaps for WordPress allows Stored XSS.This issue affects YaMaps for WordPress: from n/a through 0.6.27.... Read more
Affected Products : yamaps- Published: Aug. 12, 2024
- Modified: Aug. 13, 2024
-
5.3
MEDIUMCVE-2024-38756
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Weblizar Coming Soon allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Coming Soon: from n/a through 1.6.3.... Read more
Affected Products :- Published: Aug. 13, 2024
- Modified: Aug. 13, 2024
-
6.5
MEDIUMCVE-2024-43218
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Mediavine Mediavine Control Panel allows Stored XSS.This issue affects Mediavine Control Panel: from n/a through 2.10.4.... Read more
Affected Products : mediavine_control_panel- Published: Aug. 12, 2024
- Modified: Aug. 13, 2024
-
5.1
MEDIUMCVE-2024-39922
A vulnerability has been identified in LOGO! 12/24RCE (6ED1052-1MD08-0BA1) (All versions), LOGO! 12/24RCEo (6ED1052-2MD08-0BA1) (All versions), LOGO! 230RCE (6ED1052-1FB08-0BA1) (All versions), LOGO! 230RCEo (6ED1052-2FB08-0BA1) (All versions), LOGO! 24CE... Read more
Affected Products :- Published: Aug. 13, 2024
- Modified: Aug. 13, 2024
-
7.1
HIGHCVE-2024-43163
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Parcel Panel ParcelPanel allows Reflected XSS.This issue affects ParcelPanel: from n/a through 4.3.2.... Read more
Affected Products :- Published: Aug. 12, 2024
- Modified: Aug. 13, 2024
-
6.5
MEDIUMCVE-2024-43164
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Blockspare allows Stored XSS.This issue affects Blockspare: from n/a through 3.2.0.... Read more
Affected Products :- Published: Aug. 12, 2024
- Modified: Aug. 13, 2024
-
7.5
HIGHCVE-2024-38747
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in HitPay Payment Solutions Pte Ltd HitPay Payment Gateway for WooCommerce allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects HitPay Payment Gateway f... Read more
Affected Products :- Published: Aug. 13, 2024
- Modified: Aug. 13, 2024
-
7.8
HIGHCVE-2024-41908
A vulnerability has been identified in NX (All versions < V2406.3000). The affected applications contains an out of bounds read vulnerability while parsing specially crafted PRT files. This could allow an attacker to crash the application or execute code ... Read more
Affected Products : nx- Published: Aug. 13, 2024
- Modified: Aug. 13, 2024
-
6.5
MEDIUMCVE-2024-43227
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WPDeveloper BetterDocs allows Stored XSS.This issue affects BetterDocs: from n/a through 3.5.8.... Read more
Affected Products : betterdocs- Published: Aug. 12, 2024
- Modified: Aug. 13, 2024
-
7.8
HIGHCVE-2023-7066
The affected applications contain an out of bounds read past the end of an allocated structure while parsing specially crafted PDF files. This could allow an attacker to execute code in the context of the current process.... Read more
- Published: Aug. 12, 2024
- Modified: Aug. 13, 2024
-
7.5
HIGHCVE-2024-38699
Missing Authorization vulnerability in WP Swings Wallet System for WooCommerce allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Wallet System for WooCommerce: from n/a through 2.5.13.... Read more
Affected Products : wallet_system_for_woocommerce- Published: Aug. 13, 2024
- Modified: Aug. 13, 2024
-
7.1
HIGHCVE-2024-43217
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Pierre Lebedel Kodex Posts likes allows Reflected XSS.This issue affects Kodex Posts likes: from n/a through 2.5.0.... Read more
Affected Products : kodex_posts_likes- Published: Aug. 12, 2024
- Modified: Aug. 13, 2024
-
5.3
MEDIUMCVE-2024-38742
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in MBE Worldwide S.P.A. MBE eShip allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects MBE eShip: from n/a through 2.1.2.... Read more
Affected Products :- Published: Aug. 13, 2024
- Modified: Aug. 13, 2024