Latest CVE Feed
-
9.1
CRITICALCVE-2022-46838
Missing Authorization vulnerability in JS Help Desk JS Help Desk – Best Help Desk & Support Plugin allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects JS Help Desk – Best Help Desk & Support Plugin: from n/a through ... Read more
Affected Products : js_help_desk- Published: Dec. 13, 2024
- Modified: Dec. 13, 2024
-
4.3
MEDIUMCVE-2022-46811
Missing Authorization vulnerability in VillaTheme(villatheme.com) ALD – Dropshipping and Fulfillment for AliExpress and WooCommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects ALD – Dropshipping and Fulfillme... Read more
Affected Products : dropshipping_and_fulfillment_for_aliexpress_and_woocommerce- Published: Dec. 13, 2024
- Modified: Dec. 13, 2024
-
4.3
MEDIUMCVE-2022-46807
Missing Authorization vulnerability in Lauri Karisola / WP Trio Stock Sync for WooCommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Stock Sync for WooCommerce: from n/a through 2.3.2.... Read more
Affected Products : stock_sync_for_woocommerce- Published: Dec. 13, 2024
- Modified: Dec. 13, 2024
-
6.5
MEDIUMCVE-2022-46796
Missing Authorization vulnerability in VillaTheme CURCY allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects CURCY: from n/a through 2.1.25.... Read more
Affected Products : curcy- Published: Dec. 13, 2024
- Modified: Dec. 13, 2024
-
6.5
MEDIUMCVE-2022-46795
Missing Authorization vulnerability in Tyche Softwares Print Invoice & Delivery Notes for WooCommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Print Invoice & Delivery Notes for WooCommerce: from n/a throu... Read more
Affected Products : print_invoice_\&_delivery_notes_for_woocommerce- Published: Dec. 13, 2024
- Modified: Jun. 05, 2025
-
5.4
MEDIUMCVE-2022-45841
Missing Authorization vulnerability in RoboSoft Robo Gallery allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Robo Gallery: from n/a through 3.2.9.... Read more
Affected Products : robo_gallery- Published: Dec. 13, 2024
- Modified: Dec. 13, 2024
-
6.5
MEDIUMCVE-2022-45840
Missing Authorization vulnerability in Lucian Apostol Auto Affiliate Links allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Auto Affiliate Links: from n/a through 6.2.1.5.... Read more
- Published: Dec. 13, 2024
- Modified: Dec. 13, 2024
-
5.4
MEDIUMCVE-2022-45826
Missing Authorization vulnerability in WP Sunshine Sunshine Photo Cart allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Sunshine Photo Cart: from n/a through 2.9.13.... Read more
Affected Products : sunshine_photo_cart- Published: Dec. 13, 2024
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2022-45819
Missing Authorization vulnerability in Popup Maker Popup Maker allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Popup Maker: from n/a through 1.17.1.... Read more
Affected Products : popup_maker- Published: Dec. 13, 2024
- Modified: Apr. 11, 2025
-
9.8
CRITICALCVE-2022-45806
Missing Authorization vulnerability in Strategy11 Form Builder Team Formidable Forms allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Formidable Forms: from n/a through 5.5.4.... Read more
- Published: Dec. 13, 2024
- Modified: Feb. 05, 2025
-
5.3
MEDIUMCVE-2022-44578
Missing Authorization vulnerability in Pierre JEHAN Owl Carousel allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Owl Carousel: from n/a through 0.5.3.... Read more
Affected Products : owl_carousel- Published: Dec. 13, 2024
- Modified: Dec. 13, 2024
-
4.3
MEDIUMCVE-2022-43472
Missing Authorization vulnerability in StylemixThemes eRoom – Zoom Meetings & Webinar allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects eRoom – Zoom Meetings & Webinar: from n/a through 1.4.6.... Read more
Affected Products :- Published: Dec. 13, 2024
- Modified: Dec. 13, 2024
-
7.2
HIGHCVE-2024-55889
phpMyFAQ is an open source FAQ web application. Prior to version 3.2.10, a vulnerability exists in the FAQ Record component where a privileged attacker can trigger a file download on a victim's machine upon page visit by embedding it in an <iframe> elemen... Read more
Affected Products : phpmyfaq- Published: Dec. 13, 2024
- Modified: Aug. 14, 2025
-
6.5
MEDIUMCVE-2024-48008
Dell RecoverPoint for Virtual Machines 6.0.x contains a OS Command Injection vulnerability. An Low privileged remote attacker could potentially exploit this vulnerability leading to information disclosure ,allowing of unintended actions like reading files... Read more
Affected Products : recoverpoint_for_virtual_machines- Published: Dec. 13, 2024
- Modified: Feb. 04, 2025
-
9.8
CRITICALCVE-2024-48007
Dell RecoverPoint for Virtual Machines 6.0.x contains use of hard-coded credentials vulnerability. A Remote unauthenticated attacker could potentially exploit this vulnerability by gaining access to the source code, easily retrieving these secrets and reu... Read more
Affected Products : recoverpoint_for_virtual_machines- Published: Dec. 13, 2024
- Modified: Mar. 13, 2025
-
9.8
CRITICALCVE-2024-38488
Dell RecoverPoint for Virtual Machines 6.0.x contains a vulnerability. An improper Restriction of Excessive Authentication vulnerability where a Network attacker could potentially exploit this vulnerability, leading to a brute force attack or a dictionary... Read more
Affected Products : recoverpoint_for_virtual_machines- Published: Dec. 13, 2024
- Modified: Feb. 04, 2025
-
8.8
HIGHCVE-2024-22461
Dell RecoverPoint for Virtual Machines 6.0.x contains an OS Command injection vulnerability. A low privileged remote attacker could potentially exploit this vulnerability by running any command as root, leading to gaining of root-level access and compromi... Read more
Affected Products : recoverpoint_for_virtual_machines- Published: Dec. 13, 2024
- Modified: Feb. 04, 2025
-
9.6
CRITICALCVE-2024-11986
Improper input handling in the 'Host Header' allows an unauthenticated attacker to store a payload in web application logs. When an Administrator views the logs using the application's standard functionality, it enables the execution of the payload, resul... Read more
Affected Products :- Published: Dec. 13, 2024
- Modified: Dec. 13, 2024
-
6.1
MEDIUMCVE-2024-9608
The MyParcel plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 4.24.1. This makes it possible for unauthenticated attackers to... Read more
Affected Products :- Published: Dec. 13, 2024
- Modified: Dec. 13, 2024
-
10.0
CRITICALCVE-2024-21577
ComfyUI-Ace-Nodes is vulnerable to Code Injection. The ACE_ExpressionEval node contains an eval() in its entrypoint function that accepts arbitrary user-controlled data. A user can create a workflow that results in executing arbitrary code on the server.... Read more
Affected Products :- Published: Dec. 13, 2024
- Modified: Dec. 13, 2024