Latest CVE Feed
-
7.2
HIGHCVE-2024-47133
UD-LT1 firmware Ver.2.1.9 and earlier and UD-LT1/EX firmware Ver.2.1.9 and earlier allow a remote authenticated attacker with an administrative account to execute arbitrary OS commands.... Read more
Affected Products :- Published: Dec. 05, 2024
- Modified: Dec. 18, 2024
-
6.5
MEDIUMCVE-2024-45841
Incorrect permission assignment for critical resource issue exists in UD-LT1 firmware Ver.2.1.9 and earlier and UD-LT1/EX firmware Ver.2.1.9 and earlier. If an attacker with the guest account of the affected products accesses a specific file, the informat... Read more
Affected Products :- Published: Dec. 05, 2024
- Modified: Dec. 18, 2024
-
6.4
MEDIUMCVE-2024-11779
The WIP WooCarousel Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wip_woocarousel_products_carousel' shortcode in all versions up to, and including, 1.1.6 due to insufficient input sanitization and output escapin... Read more
Affected Products :- Published: Dec. 05, 2024
- Modified: Dec. 05, 2024
-
6.4
MEDIUMCVE-2024-11420
The Blocksy theme for WordPress is vulnerable to Stored Cross-Site Scripting via the Contact Info Block link parameter in all versions up to, and including, 2.0.77 due to insufficient input sanitization and output escaping. This makes it possible for auth... Read more
Affected Products : blocksy- Published: Dec. 05, 2024
- Modified: Feb. 03, 2025
-
4.3
MEDIUMCVE-2024-11341
The Simple Redirection plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.5. This is due to missing or incorrect nonce validation on the settings_page() function. This makes it possible for unauthentic... Read more
Affected Products :- Published: Dec. 05, 2024
- Modified: Dec. 05, 2024
-
6.1
MEDIUMCVE-2024-11324
The Accounting for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 1.6.6. This makes it possible for unauthentic... Read more
Affected Products :- Published: Dec. 05, 2024
- Modified: Dec. 05, 2024
-
6.4
MEDIUMCVE-2024-10848
The NewsMunch theme for WordPress is vulnerable to Stored Cross-Site Scripting via a malicious display name in all versions up to, and including, 1.0.35 due to insufficient input sanitization and output escaping. This makes it possible for authenticated a... Read more
Affected Products :- Published: Dec. 05, 2024
- Modified: Dec. 05, 2024
-
4.3
MEDIUMCVE-2024-10777
The AnyWhere Elementor plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.2.11 via the 'INSERT_ELEMENTOR' shortcode due to insufficient restrictions on which posts can be included. This makes it possible for... Read more
Affected Products : anywhere_elementor- Published: Dec. 05, 2024
- Modified: Dec. 05, 2024
-
6.4
MEDIUMCVE-2024-10056
The Contact Form Builder by vcita plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's livesite-pay shortcode in all versions up to, and including, 4.10.4 due to insufficient input sanitization and output escaping on user sup... Read more
Affected Products : contact_form_and_calls_to_action_by_vcita- Published: Dec. 05, 2024
- Modified: Dec. 05, 2024
-
8.3
HIGHCVE-2022-41137
Apache Hive Metastore (HMS) uses SerializationUtilities#deserializeObjectWithTypeInformation method when filtering and fetching partitions that is unsafe and can lead to Remote Code Execution (RCE) since it allows the deserialization of arbitrary data. I... Read more
Affected Products : hive- Published: Dec. 05, 2024
- Modified: Jul. 15, 2025
-
5.3
MEDIUMCVE-2024-10937
The Related Posts, Inline Related Posts, Contextual Related Posts, Related Content By PickPlugins plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.0.58 via the wp_ajax_nopriv_related_post_ajax_ge... Read more
- Published: Dec. 05, 2024
- Modified: Dec. 05, 2024
-
8.8
HIGHCVE-2024-11429
The Free Responsive Testimonials, Social Proof Reviews, and Customer Reviews – Stars Testimonials plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.3.3 via the 'stars-testimonials-with-slider-and-masonry-gr... Read more
Affected Products :- Published: Dec. 05, 2024
- Modified: Dec. 05, 2024
-
6.8
MEDIUMCVE-2024-42195
HCL DevOps Deploy / HCL Launch is vulnerable to HTML injection. This vulnerability may allow a user to embed arbitrary HTML tags in the Web UI potentially leading to sensitive information disclosure.... Read more
- Published: Dec. 05, 2024
- Modified: Apr. 21, 2025
-
6.4
MEDIUMCVE-2024-10178
The Gutentor – Gutenberg Blocks – Page Builder for Gutenberg Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Countdown widget in all versions up to, and including, 3.3.9 due to insufficient input sanitization and ... Read more
Affected Products : gutentor- Published: Dec. 05, 2024
- Modified: Jul. 09, 2025
-
6.4
MEDIUMCVE-2024-10881
The LUNA RADIO PLAYER plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'lunaradio' shortcode in versions up to, and including, 6.24.11.07 due to insufficient input sanitization and output escaping on user supplied attributes. This... Read more
Affected Products :- Published: Dec. 05, 2024
- Modified: Dec. 05, 2024
-
3.6
LOWCVE-2024-54014
Improper authorization in handler for custom URL scheme issue in 'Skylark' App for Android 6.2.13 and earlier and 'Skylark' App for iOS 6.2.13 and earlier allows an attacker to lead the application to access an arbitrary web site via another application i... Read more
Affected Products :- Published: Dec. 05, 2024
- Modified: Dec. 05, 2024
-
9.8
CRITICALCVE-2024-12188
A vulnerability was found in 1000 Projects Library Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /brains/stu.php. The manipulation of the argument useri leads to sql injecti... Read more
Affected Products : library_management_system- Published: Dec. 05, 2024
- Modified: Dec. 10, 2024
-
9.8
CRITICALCVE-2024-12187
A vulnerability was found in 1000 Projects Library Management System 1.0. It has been classified as critical. Affected is an unknown function of the file /showbook.php. The manipulation of the argument q leads to sql injection. It is possible to launch th... Read more
Affected Products : library_management_system- Published: Dec. 05, 2024
- Modified: Dec. 10, 2024
-
9.3
CRITICALCVE-2024-54221
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Roninwp FAT Services Booking.This issue affects FAT Services Booking: from n/a through 5.6.... Read more
Affected Products :- Published: Dec. 05, 2024
- Modified: Dec. 05, 2024
-
7.8
HIGHCVE-2024-12186
A vulnerability was found in code-projects Hotel Management System 1.0 and classified as problematic. This issue affects some unknown processing of the file hotelnew.c of the component Available Room Handler. The manipulation of the argument admin_entry l... Read more
Affected Products : hotel_management_system- Published: Dec. 05, 2024
- Modified: Dec. 10, 2024