Latest CVE Feed
-
6.1
MEDIUMCVE-2024-12166
The Shortcodes Blocks Creator Ultimate plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'page' parameter in all versions up to, and including, 2.2.0 due to insufficient input sanitization and output escaping. This makes it poss... Read more
Affected Products : shortcodes_blocks_creator_ultimate- Published: Dec. 07, 2024
- Modified: Jul. 14, 2025
-
6.1
MEDIUMCVE-2024-12165
The Mollie for Contact Form 7 plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'page' parameter in all versions up to, and including, 5.0.0 due to insufficient input sanitization and output escaping. This makes it possible for ... Read more
Affected Products :- Published: Dec. 07, 2024
- Modified: Dec. 07, 2024
-
4.3
MEDIUMCVE-2024-12115
The Poll Maker – Versus Polls, Anonymous Polls, Image Polls plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 5.5.4. This is due to missing or incorrect nonce validation on the duplicate_poll() function... Read more
Affected Products : poll_maker- Published: Dec. 07, 2024
- Modified: May. 28, 2025
-
4.3
MEDIUMCVE-2024-12026
The Message Filter for Contact Form 7 plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the saveFilter() function in all versions up to, and including, 1.6.3. This makes it possible for authentica... Read more
Affected Products : message_filter_for_contact_form_7- Published: Dec. 07, 2024
- Modified: Dec. 07, 2024
-
6.1
MEDIUMCVE-2024-11943
The 워드프레스 결제 심플페이 – 우커머스 결제 플러그인 plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 5.2.2. This makes it possible for unauthent... Read more
Affected Products :- Published: Dec. 07, 2024
- Modified: Dec. 07, 2024
-
6.4
MEDIUMCVE-2024-11904
The 코드엠샵 소셜톡 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'msntt_add_plus_talk' shortcode in all versions up to, and including, 1.2.0 due to insufficient input sanitization and output escaping on user supplied attribu... Read more
Affected Products :- Published: Dec. 07, 2024
- Modified: Dec. 07, 2024
-
6.4
MEDIUMCVE-2024-11451
The Zooom plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'zooom' shortcode in all versions up to, and including, 1.1.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes i... Read more
Affected Products :- Published: Dec. 07, 2024
- Modified: Dec. 07, 2024
-
6.1
MEDIUMCVE-2024-11436
The Drag & Drop Builder, Human Face Detector, Pre-built Templates, Spam Protection, User Email Notifications & more! plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'page' parameter in all versions up to, and including, 1.4.19... Read more
Affected Products : drag_\&_drop_builder- Published: Dec. 07, 2024
- Modified: Dec. 07, 2024
-
4.3
MEDIUMCVE-2024-11353
The SMS for Lead Capture Forms plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the delete_message() function in all versions up to, and including, 1.1.0. This makes it possible for authenticated... Read more
Affected Products :- Published: Dec. 07, 2024
- Modified: Dec. 07, 2024
-
6.1
MEDIUMCVE-2024-11329
The Comfino Payment Gateway plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg & remove_query_arg without appropriate escaping on the URL in all versions up to, and including, 4.1.1. This makes it possible... Read more
Affected Products :- Published: Dec. 07, 2024
- Modified: Dec. 07, 2024
-
6.1
MEDIUMCVE-2024-10046
The افزونه پیامک ووکامرس Persian WooCommerce SMS plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of remove_query_arg without appropriate escaping on the URL in all versions up to, and including, 7.0.5. This makes it pos... Read more
Affected Products : persian_woocommerce_sms- Published: Dec. 07, 2024
- Modified: Dec. 07, 2024
-
6.9
MEDIUMCVE-2024-54138
NuGet Gallery is a package repository that powers nuget.org. The NuGetGallery has a security vulnerability related to its handling of autolinks in Markdown content. While the platform properly filters out JavaScript from standard links, it does not adequa... Read more
Affected Products : nugetgallery- Published: Dec. 06, 2024
- Modified: Dec. 06, 2024
-
7.5
HIGHCVE-2024-44856
Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble was discovered to contain a NULL pointer dereference via the component nav2_smac_planner().... Read more
- Published: Dec. 06, 2024
- Modified: Dec. 13, 2024
-
7.5
HIGHCVE-2024-44855
Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble was discovered to contain a NULL pointer dereference via the component nav2_navfn_planner().... Read more
- Published: Dec. 06, 2024
- Modified: Dec. 13, 2024
-
7.5
HIGHCVE-2024-44854
Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble was discovered to contain a NULL pointer dereference via the component smoothPlan().... Read more
- Published: Dec. 06, 2024
- Modified: Dec. 13, 2024
-
7.5
HIGHCVE-2024-44853
Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble was discovered to contain a NULL pointer dereference via the component computeControl().... Read more
- Published: Dec. 06, 2024
- Modified: Dec. 13, 2024
-
9.8
CRITICALCVE-2024-44852
Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble was discovered to contain a segmentation violation via the component theta_star::ThetaStar::isUnsafeToPlan().... Read more
- Published: Dec. 06, 2024
- Modified: Dec. 17, 2024
-
9.8
CRITICALCVE-2024-41650
Insecure Permissions vulnerability in Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble allows an attacker to execute arbitrary code via a crafted script to the nav2_costmap_2d.... Read more
- Published: Dec. 06, 2024
- Modified: Dec. 13, 2024
-
9.8
CRITICALCVE-2024-41649
Insecure Permissions vulnerability in Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble allows an attacker to execute arbitrary code via a crafted script to the executor_thread_.... Read more
- Published: Dec. 06, 2024
- Modified: Dec. 13, 2024
-
9.8
CRITICALCVE-2024-41648
Insecure Permissions vulnerability in Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble allows an attacker to execute arbitrary code via a crafted script to the nav2_regulated_pure_pursuit_controller.... Read more
- Published: Dec. 06, 2024
- Modified: Dec. 13, 2024