Latest CVE Feed
-
4.3
MEDIUMCVE-2024-54306
Cross-Site Request Forgery (CSRF) vulnerability in KCT AIKCT Engine Chatbot, ChatGPT, Gemini, GPT-4o Best AI Chatbot allows Cross Site Request Forgery.This issue affects AIKCT Engine Chatbot, ChatGPT, Gemini, GPT-4o Best AI Chatbot: from n/a through 1.6.2... Read more
Affected Products :- Published: Dec. 13, 2024
- Modified: Dec. 13, 2024
-
7.1
HIGHCVE-2024-54305
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in woocs J&T Express Malaysia allows Reflected XSS.This issue affects J&T Express Malaysia: from n/a through 2.0.13.... Read more
Affected Products :- Published: Dec. 13, 2024
- Modified: Dec. 13, 2024
-
8.5
HIGHCVE-2024-54304
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Hive Support Hive Support – WordPress Help Desk allows SQL Injection.This issue affects Hive Support – WordPress Help Desk: from n/a through 1.1.2.... Read more
Affected Products :- Published: Dec. 13, 2024
- Modified: Dec. 13, 2024
-
7.1
HIGHCVE-2024-54303
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ido Kobelkowsky / yalla ya! Simple Payment allows Reflected XSS.This issue affects Simple Payment: from n/a through 2.3.7.... Read more
Affected Products :- Published: Dec. 13, 2024
- Modified: Dec. 13, 2024
-
7.1
HIGHCVE-2024-54302
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Vikas Ratudi VForm allows Reflected XSS.This issue affects VForm: from n/a through 3.0.0.... Read more
Affected Products : lifetime_free_drag_\&_drop_contact_form_builder- Published: Dec. 13, 2024
- Modified: Dec. 13, 2024
-
7.1
HIGHCVE-2024-54301
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in FormFacade FormFacade allows Reflected XSS.This issue affects FormFacade: from n/a through 1.3.6.... Read more
Affected Products : formfacade- Published: Dec. 13, 2024
- Modified: Jun. 05, 2025
-
4.3
MEDIUMCVE-2024-54300
Cross-Site Request Forgery (CSRF) vulnerability in Neuralabz LTD. AutoWP allows Cross Site Request Forgery.This issue affects AutoWP: from n/a through 2.0.8.... Read more
Affected Products :- Published: Dec. 13, 2024
- Modified: Dec. 13, 2024
-
7.1
HIGHCVE-2024-54299
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Revi Revi.io allows Reflected XSS.This issue affects Revi.io: from n/a through 5.7.3.... Read more
Affected Products :- Published: Dec. 13, 2024
- Modified: Dec. 13, 2024
-
4.3
MEDIUMCVE-2024-54298
Missing Authorization vulnerability in Bill Minozzi Car Dealer allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Car Dealer: from n/a through 4.46.... Read more
Affected Products : car_dealer- Published: Dec. 13, 2024
- Modified: Dec. 13, 2024
-
9.8
CRITICALCVE-2024-54297
Authentication Bypass Using an Alternate Path or Channel vulnerability in www.vbsso.com vBSSO-lite allows Authentication Bypass.This issue affects vBSSO-lite: from n/a through 1.4.3.... Read more
Affected Products :- Published: Dec. 13, 2024
- Modified: Dec. 13, 2024
-
9.8
CRITICALCVE-2024-54296
Authentication Bypass Using an Alternate Path or Channel vulnerability in Codexpert, Inc CoSchool LMS allows Authentication Bypass.This issue affects CoSchool LMS: from n/a through 1.2.... Read more
Affected Products :- Published: Dec. 13, 2024
- Modified: Dec. 13, 2024
-
9.8
CRITICALCVE-2024-54295
Authentication Bypass Using an Alternate Path or Channel vulnerability in InspireUI ListApp Mobile Manager allows Authentication Bypass.This issue affects ListApp Mobile Manager: from n/a through 1.7.7.... Read more
Affected Products :- Published: Dec. 13, 2024
- Modified: Dec. 13, 2024
-
9.8
CRITICALCVE-2024-54294
Authentication Bypass Using an Alternate Path or Channel vulnerability in appgenixinfotech Firebase OTP Authentication allows Authentication Bypass.This issue affects Firebase OTP Authentication: from n/a through 1.0.1.... Read more
Affected Products :- Published: Dec. 13, 2024
- Modified: Dec. 13, 2024
-
9.8
CRITICALCVE-2024-54293
Incorrect Privilege Assignment vulnerability in CE21 CE21 Suite allows Privilege Escalation.This issue affects CE21 Suite: from n/a through 2.2.0.... Read more
Affected Products : ce21_suite- Published: Dec. 13, 2024
- Modified: Dec. 13, 2024
-
9.3
CRITICALCVE-2024-54292
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Appsplate Appsplate allows SQL Injection.This issue affects Appsplate: from n/a through 2.1.3.... Read more
Affected Products :- Published: Dec. 13, 2024
- Modified: Dec. 13, 2024
-
7.1
HIGHCVE-2024-54290
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Justin Fletcher Role Includer allows Reflected XSS.This issue affects Role Includer: from n/a through 1.6.... Read more
Affected Products :- Published: Dec. 13, 2024
- Modified: Dec. 13, 2024
-
6.5
MEDIUMCVE-2024-54289
Missing Authorization vulnerability in Awesome Support Team Awesome Support allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Awesome Support: from n/a through 6.3.0.... Read more
Affected Products : awesome_support- Published: Dec. 13, 2024
- Modified: Dec. 13, 2024
-
7.1
HIGHCVE-2024-54288
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LDD Web Design LDD Directory Lite allows Reflected XSS.This issue affects LDD Directory Lite: from n/a through 3.3.... Read more
Affected Products :- Published: Dec. 13, 2024
- Modified: Dec. 13, 2024
-
6.5
MEDIUMCVE-2024-54287
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Best Wp Developer Advanced Blog Post Block allows Stored XSS.This issue affects Advanced Blog Post Block: from n/a through 1.0.4.... Read more
Affected Products :- Published: Dec. 13, 2024
- Modified: Dec. 13, 2024
-
6.5
MEDIUMCVE-2024-54286
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Sendsmaily LLC Smaily for WP allows Stored XSS.This issue affects Smaily for WP: from n/a through 3.1.2.... Read more
Affected Products :- Published: Dec. 13, 2024
- Modified: Dec. 13, 2024