Latest CVE Feed
-
4.4
MEDIUMCVE-2024-20116
In cmdq, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS09057438; Issue ID: MSV-... Read more
- Published: Dec. 02, 2024
- Modified: Apr. 22, 2025
-
3.7
LOWCVE-2024-11856
A security vulnerability in HPE IceWall products could be exploited remotely to cause Unauthorized Data Modification.... Read more
Affected Products :- Published: Dec. 02, 2024
- Modified: Dec. 02, 2024
-
7.5
HIGHCVE-2024-53605
Incorrect access control in the component content://com.handcent.messaging.provider.MessageProvider/ of Handcent NextSMS v10.9.9.7 allows attackers to access sensitive data.... Read more
Affected Products :- Published: Dec. 02, 2024
- Modified: Dec. 04, 2024
-
9.8
CRITICALCVE-2024-12007
A vulnerability, which was classified as critical, was found in code-projects Farmacia 1.0. This affects an unknown part of the file /visualizar-produto.php. The manipulation of the argument id leads to sql injection. It is possible to initiate the attack... Read more
- Published: Dec. 01, 2024
- Modified: Dec. 11, 2024
-
6.5
MEDIUMCVE-2024-53752
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Berg Informatik Stripe Donation allows Stored XSS.This issue affects Stripe Donation: from n/a through 1.2.5.... Read more
Affected Products :- Published: Dec. 01, 2024
- Modified: Dec. 01, 2024
-
7.1
HIGHCVE-2024-53750
Cross-Site Request Forgery (CSRF) vulnerability in Maeve Lander PayPal Responder allows Stored XSS.This issue affects PayPal Responder: from n/a through 1.2.... Read more
Affected Products :- Published: Dec. 01, 2024
- Modified: Dec. 01, 2024
-
6.5
MEDIUMCVE-2024-53749
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Plugin Devs Post Carousel Slider for Elementor allows Stored XSS.This issue affects Post Carousel Slider for Elementor: from n/a through 1.4.0.... Read more
Affected Products : post_carousel_slider_for_elementor- Published: Dec. 01, 2024
- Modified: Dec. 01, 2024
-
6.5
MEDIUMCVE-2024-53748
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Terry Lin WP Mermaid allows Stored XSS.This issue affects WP Mermaid: from n/a through 1.0.2.... Read more
Affected Products :- Published: Dec. 01, 2024
- Modified: Dec. 01, 2024
-
6.5
MEDIUMCVE-2024-53747
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NuttTaro Video Player for WPBakery allows Stored XSS.This issue affects Video Player for WPBakery: from n/a through 1.0.1.... Read more
Affected Products :- Published: Dec. 01, 2024
- Modified: Dec. 01, 2024
-
6.5
MEDIUMCVE-2024-53746
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in FlickDevs Elementor Button Plus allows Stored XSS.This issue affects Elementor Button Plus: from n/a through 1.3.3.... Read more
Affected Products :- Published: Dec. 01, 2024
- Modified: Dec. 01, 2024
-
6.5
MEDIUMCVE-2024-53745
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in 코스모스팜 – Cosmosfarm 소셜 공유 버튼 By 코스모스팜 allows Stored XSS.This issue affects 소셜 공유 버튼 By 코스모스팜: from n/a through 1.9.... Read more
Affected Products :- Published: Dec. 01, 2024
- Modified: Dec. 01, 2024
-
6.5
MEDIUMCVE-2024-53744
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Skybootstrap Elementor Image Gallery Plugin allows Stored XSS.This issue affects Elementor Image Gallery Plugin: from n/a through 1.0.3.... Read more
Affected Products :- Published: Dec. 01, 2024
- Modified: Dec. 01, 2024
-
6.5
MEDIUMCVE-2024-53743
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in FlickDevs Countdown Timer for Elementor allows Stored XSS.This issue affects Countdown Timer for Elementor: from n/a through 1.3.6.... Read more
Affected Products : countdown_timer_for_elementor- Published: Dec. 01, 2024
- Modified: Dec. 01, 2024
-
7.1
HIGHCVE-2024-53742
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Prism I.T. Systems Multilevel Referral Affiliate Plugin for WooCommerce allows Reflected XSS.This issue affects Multilevel Referral Affiliate Plugin for ... Read more
Affected Products :- Published: Dec. 01, 2024
- Modified: Dec. 01, 2024
-
7.5
HIGHCVE-2024-45520
WithSecure Atlant (formerly F-Secure Atlant) 1.0.35-1 allows a remote Denial of Service because of memory corruption during scanning of a PE32 file.... Read more
Affected Products : atlant- Published: Dec. 01, 2024
- Modified: Dec. 02, 2024
-
6.5
MEDIUMCVE-2024-53786
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Codeless Cowidgets – Elementor Addons allows Stored XSS.This issue affects Cowidgets – Elementor Addons: from n/a through 1.2.0.... Read more
- Published: Nov. 30, 2024
- Modified: Feb. 05, 2025
-
7.1
HIGHCVE-2024-53778
Cross-Site Request Forgery (CSRF) vulnerability in Essential Marketer Essential Breadcrumbs allows Stored XSS.This issue affects Essential Breadcrumbs: from n/a through 1.1.1.... Read more
Affected Products :- Published: Nov. 30, 2024
- Modified: Nov. 30, 2024
-
6.5
MEDIUMCVE-2024-53774
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Sparkle WP Sparkle Elementor Kit allows DOM-Based XSS.This issue affects Sparkle Elementor Kit: from n/a through 2.0.9.... Read more
Affected Products :- Published: Nov. 30, 2024
- Modified: Nov. 30, 2024
-
6.5
MEDIUMCVE-2024-53773
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Praca.Pl sp. Z o.O. Znajdź Pracę z Praca.Pl allows DOM-Based XSS.This issue affects Znajdź Pracę z Praca.Pl: from n/a through 2.2.3.... Read more
Affected Products :- Published: Nov. 30, 2024
- Modified: Nov. 30, 2024
-
6.5
MEDIUMCVE-2024-53772
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PickPlugins Mail Picker allows DOM-Based XSS.This issue affects Mail Picker: from n/a through 1.0.14.... Read more
Affected Products :- Published: Nov. 30, 2024
- Modified: Nov. 30, 2024