Latest CVE Feed
-
6.5
MEDIUMCVE-2024-28771
IBM Security Directory Integrator 7.2.0 and IBM Security Verify Directory Integrator 10.0.0 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or... Read more
- Published: Jan. 27, 2025
- Modified: Jul. 14, 2025
- Vuln Type: Misconfiguration
-
6.5
MEDIUMCVE-2024-28770
IBM Security Directory Integrator 7.2.0 and IBM Security Verify Directory Integrator 10.0.0 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or... Read more
- Published: Jan. 27, 2025
- Modified: Jul. 14, 2025
- Vuln Type: Misconfiguration
-
7.5
HIGHCVE-2024-28766
IBM Security Directory Integrator 7.2.0 and IBM Security Verify Directory Integrator 10.0.0 could disclose sensitive information about directory contents that could aid in further attacks against the system.... Read more
- Published: Jan. 27, 2025
- Modified: Jul. 14, 2025
- Vuln Type: Information Disclosure
-
5.4
MEDIUMCVE-2023-46187
IBM InfoSphere Master Data Management 11.6, 12.0, and 14.0 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to crede... Read more
- Published: Jan. 27, 2025
- Modified: Aug. 18, 2025
- Vuln Type: Cross-Site Scripting
-
7.2
HIGHCVE-2025-0722
A vulnerability classified as critical was found in needyamin image_gallery 1.0. This vulnerability affects unknown code of the file /admin/gallery.php of the component Cover Image Handler. The manipulation of the argument image leads to unrestricted uplo... Read more
Affected Products : image_gallery_management_system- Published: Jan. 27, 2025
- Modified: Feb. 25, 2025
- Vuln Type: Authentication
-
6.1
MEDIUMCVE-2025-0721
A vulnerability classified as problematic has been found in needyamin image_gallery 1.0. This affects the function image_gallery of the file /view.php. The manipulation of the argument Username leads to cross site scripting. It is possible to initiate the... Read more
Affected Products : image_gallery_management_system- Published: Jan. 27, 2025
- Modified: Apr. 16, 2025
- Vuln Type: Cross-Site Scripting
-
4.8
MEDIUMCVE-2025-0720
A vulnerability was found in Microword eScan Antivirus 7.0.32 on Linux. It has been rated as problematic. Affected by this issue is the function removeExtraSlashes of the file /opt/MicroWorld/sbin/rtscanner of the component Folder Watch List Handler. The ... Read more
Affected Products : escan_anti-virus- Published: Jan. 26, 2025
- Modified: Jan. 26, 2025
- Vuln Type: Memory Corruption
-
6.3
MEDIUMCVE-2017-20196
A vulnerability was found in Itechscripts School Management Software 2.75. It has been classified as critical. This affects an unknown part of the file /notice-edit.php. The manipulation of the argument aid leads to sql injection. It is possible to initia... Read more
Affected Products :- Published: Jan. 26, 2025
- Modified: Jan. 28, 2025
- Vuln Type: Injection
-
6.5
MEDIUMCVE-2023-50946
IBM Common Licensing 9.0 could allow an authenticated user to modify a configuration file that they should not have access to due to a broken authorization mechanism.... Read more
- Published: Jan. 26, 2025
- Modified: Mar. 11, 2025
- Vuln Type: Authorization
-
6.2
MEDIUMCVE-2023-50945
IBM Common Licensing 9.0 stores user credentials in plain clear text which can be read by a local user.... Read more
- Published: Jan. 26, 2025
- Modified: Mar. 11, 2025
- Vuln Type: Information Disclosure
-
5.9
MEDIUMCVE-2023-38009
IBM Cognos Mobile Client 1.1 iOS may be vulnerable to information disclosure through man in the middle techniques due to the lack of certificate pinning.... Read more
- Published: Jan. 26, 2025
- Modified: Aug. 18, 2025
- Vuln Type: Information Disclosure
-
6.2
MEDIUMCVE-2024-31906
IBM Automation Decision Services 23.0.2 allows web pages to be stored locally which can be read by another user on the system.... Read more
Affected Products : automation_decision_services- Published: Jan. 26, 2025
- Modified: Aug. 14, 2025
- Vuln Type: Information Disclosure
-
5.5
MEDIUMCVE-2024-13505
The Survey Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘ays_sections[5][questions][8][title]’ parameter in all versions up to, and including, 5.1.3.3 due to insufficient input sanitization and output escaping. This make... Read more
Affected Products : survey_maker- Published: Jan. 26, 2025
- Modified: Feb. 04, 2025
- Vuln Type: Cross-Site Scripting
-
6.1
MEDIUMCVE-2024-12334
The WC Affiliate – A Complete WooCommerce Affiliate Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via any parameter in all versions up to, and including, 2.4 due to insufficient input sanitization and output escaping. This ma... Read more
Affected Products : wc_affiliate- Published: Jan. 26, 2025
- Modified: Feb. 04, 2025
- Vuln Type: Cross-Site Scripting
-
8.8
HIGHCVE-2024-11936
The Zox News theme for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on the 'backup_options' and 'restore_options' function in all versions up to, and including, 3.16.0... Read more
Affected Products : zox_news- Published: Jan. 26, 2025
- Modified: Feb. 04, 2025
- Vuln Type: Authorization
-
8.8
HIGHCVE-2024-11641
The VikBooking Hotel Booking Engine & PMS plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.7.2. This is due to missing or incorrect nonce validation on the 'save' function. This makes it possible for... Read more
Affected Products : vikbooking_hotel_booking_engine_\&_pms- Published: Jan. 26, 2025
- Modified: Feb. 04, 2025
- Vuln Type: Cross-Site Request Forgery
-
7.1
HIGHCVE-2024-46881
Develocity (formerly Gradle Enterprise) before 2024.1.8 has Incorrect Access Control. Project-level access control configuration was introduced in Enterprise Config schema version 8. Migration functionality from schema version 8 to versions 9 and 10 (in a... Read more
Affected Products : enterprise- Published: Jan. 26, 2025
- Modified: Jan. 26, 2025
- Vuln Type: Authorization
-
7.5
HIGHCVE-2024-11090
The Membership Plugin – Restrict Content plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.2.13 via the WordPress core search feature. This makes it possible for unauthenticated attackers to extra... Read more
- Published: Jan. 26, 2025
- Modified: Feb. 04, 2025
- Vuln Type: Information Disclosure
-
8.1
HIGHCVE-2024-10705
The Multiple Page Generator Plugin – MPG plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 4.0.5 via the 'mpg_download_file_by_link' function. This makes it possible for authenticated attackers, with e... Read more
Affected Products : multiple_page_generator- Published: Jan. 26, 2025
- Modified: Feb. 04, 2025
- Vuln Type: Server-Side Request Forgery
-
8.3
HIGHCVE-2025-24858
Develocity (formerly Gradle Enterprise) before 2024.3.1 allows an attacker who has network access to a Develocity server to obtain the hashed password of the system user. The hash algorithm used by Develocity was chosen according to best practices for pas... Read more
Affected Products : enterprise- Published: Jan. 26, 2025
- Modified: Jan. 26, 2025
- Vuln Type: Information Disclosure