Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 3.8

    LOW
    CVE-2024-13116

    The Crelly Slider WordPress plugin before 1.4.7 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (... Read more

    Affected Products : crelly_slider
    • Published: Jan. 27, 2025
    • Modified: May. 13, 2025
  • 4.8

    MEDIUM
    CVE-2024-13095

    The WP Triggers Lite WordPress plugin through 2.5.3 does not sanitize and escape a parameter before using it in a SQL statement, allowing admins to perform SQL injection attacks... Read more

    Affected Products : wp_triggers_lite
    • Published: Jan. 27, 2025
    • Modified: May. 05, 2025
  • 7.1

    HIGH
    CVE-2024-13094

    The WP Triggers Lite WordPress plugin through 2.5.3 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.... Read more

    Affected Products : wp_triggers_lite
    • Published: Jan. 27, 2025
    • Modified: May. 07, 2025
  • 7.1

    HIGH
    CVE-2024-13057

    The Dyn Business Panel WordPress plugin through 1.0.0 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack.... Read more

    Affected Products : dyn_business_panel
    • Published: Jan. 27, 2025
    • Modified: May. 07, 2025
  • 7.1

    HIGH
    CVE-2024-13056

    The Dyn Business Panel WordPress plugin through 1.0.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.... Read more

    Affected Products : dyn_business_panel
    • Published: Jan. 27, 2025
    • Modified: May. 07, 2025
  • 7.1

    HIGH
    CVE-2024-13055

    The Dyn Business Panel WordPress plugin through 1.0.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.... Read more

    Affected Products : dyn_business_panel
    • Published: Jan. 27, 2025
    • Modified: May. 07, 2025
  • 7.1

    HIGH
    CVE-2024-13052

    The Dental Optimizer Patient Generator App WordPress plugin through 1.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as ad... Read more

    • Published: Jan. 27, 2025
    • Modified: May. 13, 2025
  • 6.5

    MEDIUM
    CVE-2024-12774

    The Altra Side Menu WordPress plugin through 2.0 does not have CSRF checks in some places, which could allow attackers to make logged in admins delete arbitrary menu via a CSRF attack... Read more

    Affected Products : altra_side_menu
    • Published: Jan. 27, 2025
    • Modified: May. 07, 2025
  • 7.2

    HIGH
    CVE-2024-12773

    The Altra Side Menu WordPress plugin through 2.0 does not sanitize and escape a parameter before using it in a SQL statement, allowing admins to perform SQL injection attacks... Read more

    Affected Products : altra_side_menu
    • Published: Jan. 27, 2025
    • Modified: May. 07, 2025
  • 4.3

    MEDIUM
    CVE-2024-12436

    The WP Customer Area WordPress plugin through 8.2.4 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions via CSRF attacks... Read more

    Affected Products : wp_customer_area
    • Published: Jan. 27, 2025
    • Modified: May. 08, 2025
  • 7.1

    HIGH
    CVE-2024-12321

    The WC Affiliate WordPress plugin through 2.3.9 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.... Read more

    Affected Products : wc_affiliate
    • Published: Jan. 27, 2025
    • Modified: May. 13, 2025
  • 4.3

    MEDIUM
    CVE-2024-12280

    The WP Customer Area WordPress plugin through 8.2.4 does not have CSRF check in place when deleting its logs, which could allow attackers to make a logged in to delete them via a CSRF attack... Read more

    Affected Products : wp_customer_area
    • Published: Jan. 27, 2025
    • Modified: May. 08, 2025
  • 6.5

    MEDIUM
    CVE-2024-28771

    IBM Security Directory Integrator 7.2.0 and IBM Security Verify Directory Integrator 10.0.0 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or... Read more

    • Published: Jan. 27, 2025
    • Modified: Jul. 14, 2025
  • 6.5

    MEDIUM
    CVE-2024-28770

    IBM Security Directory Integrator 7.2.0 and IBM Security Verify Directory Integrator 10.0.0 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or... Read more

    • Published: Jan. 27, 2025
    • Modified: Jul. 14, 2025
  • 7.5

    HIGH
    CVE-2024-28766

    IBM Security Directory Integrator 7.2.0 and IBM Security Verify Directory Integrator 10.0.0 could disclose sensitive information about directory contents that could aid in further attacks against the system.... Read more

    • Published: Jan. 27, 2025
    • Modified: Jul. 14, 2025
  • 5.4

    MEDIUM
    CVE-2023-46187

    IBM InfoSphere Master Data Management 11.6, 12.0, and 14.0 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to crede... Read more

    • Published: Jan. 27, 2025
    • Modified: Aug. 18, 2025
  • 7.2

    HIGH
    CVE-2025-0722

    A vulnerability classified as critical was found in needyamin image_gallery 1.0. This vulnerability affects unknown code of the file /admin/gallery.php of the component Cover Image Handler. The manipulation of the argument image leads to unrestricted uplo... Read more

    Affected Products : image_gallery_management_system
    • Published: Jan. 27, 2025
    • Modified: Feb. 25, 2025
  • 6.1

    MEDIUM
    CVE-2025-0721

    A vulnerability classified as problematic has been found in needyamin image_gallery 1.0. This affects the function image_gallery of the file /view.php. The manipulation of the argument Username leads to cross site scripting. It is possible to initiate the... Read more

    Affected Products : image_gallery_management_system
    • Published: Jan. 27, 2025
    • Modified: Apr. 16, 2025
  • 4.8

    MEDIUM
    CVE-2025-0720

    A vulnerability was found in Microword eScan Antivirus 7.0.32 on Linux. It has been rated as problematic. Affected by this issue is the function removeExtraSlashes of the file /opt/MicroWorld/sbin/rtscanner of the component Folder Watch List Handler. The ... Read more

    Affected Products : escan_anti-virus
    • Published: Jan. 26, 2025
    • Modified: Jan. 26, 2025
  • 6.3

    MEDIUM
    CVE-2017-20196

    A vulnerability was found in Itechscripts School Management Software 2.75. It has been classified as critical. This affects an unknown part of the file /notice-edit.php. The manipulation of the argument aid leads to sql injection. It is possible to initia... Read more

    Affected Products :
    • Published: Jan. 26, 2025
    • Modified: Jan. 28, 2025
Showing 20 of 291141 Results