Latest CVE Feed
-
6.4
MEDIUMCVE-2024-11884
The Wp photo text slider 50 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wp-photo-slider' shortcode in all versions up to, and including, 8.1 due to insufficient input sanitization and output escaping on user supplie... Read more
Affected Products : wp_photo_text_slider_50- Published: Dec. 14, 2024
- Modified: Dec. 14, 2024
-
6.4
MEDIUMCVE-2024-11883
The Connatix Video Embed plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'cnx_script_code' shortcode in all versions up to, and including, 1.0.5 due to insufficient input sanitization and output escaping on user supplied... Read more
Affected Products :- Published: Dec. 14, 2024
- Modified: Dec. 14, 2024
-
6.4
MEDIUMCVE-2024-11877
The Cricket Live Score plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'cricket_score' shortcode in all versions up to, and including, 2.0.2 due to insufficient input sanitization and output escaping on user supplied att... Read more
Affected Products :- Published: Dec. 14, 2024
- Modified: Dec. 14, 2024
-
6.4
MEDIUMCVE-2024-11876
The Kredeum NFTs, the easiest way to sell your NFTs directly on your WordPress site plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'kredeum_opensky' shortcode in all versions up to, and including, 1.6.9 due to insuffici... Read more
Affected Products :- Published: Dec. 14, 2024
- Modified: Dec. 14, 2024
-
6.4
MEDIUMCVE-2024-11873
The glomex oEmbed plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'glomex_integration' shortcode in all versions up to, and including, 0.9.1 due to insufficient input sanitization and output escaping on user supplied att... Read more
Affected Products :- Published: Dec. 14, 2024
- Modified: Dec. 14, 2024
-
6.4
MEDIUMCVE-2024-11869
The Buk for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'buk' shortcode in all versions up to, and including, 1.0.7 due to insufficient input sanitization and output escaping on user supplied attributes. Th... Read more
Affected Products :- Published: Dec. 14, 2024
- Modified: Dec. 14, 2024
-
6.4
MEDIUMCVE-2024-11867
The Companion Portfolio – Responsive Portfolio Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'companion-portfolio' shortcode in all versions up to, and including, 2.4.0.1 due to insufficient input sanitization a... Read more
Affected Products :- Published: Dec. 14, 2024
- Modified: Dec. 14, 2024
-
6.4
MEDIUMCVE-2024-11865
The Tabs Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.0 due to insufficient input sanitization and output escaping on tab descriptions. This makes it possible for authenticated attackers, with... Read more
Affected Products :- Published: Dec. 14, 2024
- Modified: Dec. 14, 2024
-
6.4
MEDIUMCVE-2024-11855
The Koalendar – Events & Appointments Booking Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘height’ parameter in all versions up to, and including, 1.0.2 due to insufficient input sanitization and output escaping. Thi... Read more
Affected Products :- Published: Dec. 14, 2024
- Modified: Dec. 14, 2024
-
6.4
MEDIUMCVE-2024-11770
The Post Carousel & Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'post-cs' shortcode in all versions up to, and including, 1.0.4 due to insufficient input sanitization and output escaping on user supplied attri... Read more
Affected Products :- Published: Dec. 14, 2024
- Modified: Dec. 14, 2024
-
6.4
MEDIUMCVE-2024-11763
The Plezi plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'plezi' shortcode in all versions up to, and including, 1.0.6 due to insufficient input sanitization and output escaping on user supplied attributes. This makes i... Read more
Affected Products : plezi- Published: Dec. 14, 2024
- Modified: Dec. 14, 2024
-
6.4
MEDIUMCVE-2024-11759
The Bukza plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'bukza' shortcode in all versions up to, and including, 2.0.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes i... Read more
Affected Products :- Published: Dec. 14, 2024
- Modified: Dec. 14, 2024
-
6.4
MEDIUMCVE-2024-11755
The IMS Countdown plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Countdown post settings in all versions up to, and including, 1.3.4 due to insufficient input sanitization and output escaping. This makes it possible for authenti... Read more
Affected Products :- Published: Dec. 14, 2024
- Modified: Dec. 14, 2024
-
6.4
MEDIUMCVE-2024-11751
The TCBD Popover plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'tcbd-popover-image ' shortcode in all versions up to, and including, 1.2 due to insufficient input sanitization and output escaping on user supplied attri... Read more
Affected Products :- Published: Dec. 14, 2024
- Modified: Dec. 14, 2024
-
6.1
MEDIUMCVE-2024-11462
The Filestack Official plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'fstab' and 'filestack_options' parameters in all versions up to, and including, 2.0.0 due to insufficient input sanitization and output escaping. This mak... Read more
Affected Products :- Published: Dec. 14, 2024
- Modified: Dec. 14, 2024
-
6.4
MEDIUMCVE-2024-11095
The Visualmodo Elements plugin for WordPress is vulnerable to Stored Cross-Site Scripting via REST API SVG File uploads in all versions up to, and including, 1.0.2 due to insufficient input sanitization and output escaping. This makes it possible for auth... Read more
Affected Products :- Published: Dec. 14, 2024
- Modified: Dec. 14, 2024
-
9.1
CRITICALCVE-2023-29476
In Menlo On-Premise Appliance before 2.88, web policy may not be consistently applied properly to intentionally malformed client requests. This is fixed in 2.88.2+, 2.89.1+, and 2.90.1+.... Read more
Affected Products :- Published: Dec. 14, 2024
- Modified: Dec. 16, 2024
-
6.5
MEDIUMCVE-2024-12553
GeoVision GV-ASManager Missing Authorization Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of GeoVision GV-ASManager. Although authentication is required to exp... Read more
Affected Products : gv-asmanager- Published: Dec. 13, 2024
- Modified: Aug. 14, 2025
-
7.8
HIGHCVE-2024-12552
Wacom Center WTabletServicePro Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Wacom Center. An attacker must first obtain the ability to execute low-pr... Read more
Affected Products : center- Published: Dec. 13, 2024
- Modified: Aug. 14, 2025
-
9.8
CRITICALCVE-2024-55956
In Cleo Harmony before 5.8.0.24, VLTrader before 5.8.0.24, and LexiCom before 5.8.0.24, an unauthenticated user can import and execute arbitrary Bash or PowerShell commands on the host system by leveraging the default settings of the Autorun directory.... Read more
- Actively Exploited
- Published: Dec. 13, 2024
- Modified: Mar. 14, 2025