Latest CVE Feed
-
7.2
HIGHCVE-2024-50358
A CWE-15 "External Control of System or Configuration Setting" was discovered affecting the following devices manufactured by Advantech: EKI-6333AC-2G (<= 1.6.3), EKI-6333AC-2GD (<= v1.6.3) and EKI-6333AC-1GPO (<= v1.2.1). The vulnerability can be exploit... Read more
Affected Products :- Published: Nov. 26, 2024
- Modified: Nov. 26, 2024
-
9.8
CRITICALCVE-2024-11024
The AppPresser – Mobile App Framework plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 4.4.6. This is due to the plugin not properly validating a user's password reset code prior to upda... Read more
Affected Products : apppresser- Published: Nov. 26, 2024
- Modified: Jun. 05, 2025
-
4.3
MEDIUMCVE-2024-10579
The Hustle – Email Marketing, Lead Generation, Optins, Popups plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the preview_module() function in all versions up to, and including, 7.8.5. This makes it p... Read more
- Published: Nov. 26, 2024
- Modified: Nov. 26, 2024
-
6.4
MEDIUMCVE-2024-10308
The Jeg Elementor Kit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's JKit - Countdown widget in all versions up to, and including, 2.6.9 due to insufficient input sanitization and output escaping on user supplied attrib... Read more
Affected Products : jeg_elementor_kit- Published: Nov. 26, 2024
- Modified: Jan. 09, 2025
-
9.8
CRITICALCVE-2024-11680
ProjectSend versions prior to r1720 are affected by an improper authentication vulnerability. Remote, unauthenticated attackers can exploit this flaw by sending crafted HTTP requests to options.php, enabling unauthorized modification of the application's ... Read more
Affected Products : projectsend- Actively Exploited
- Published: Nov. 26, 2024
- Modified: Dec. 06, 2024
-
6.1
MEDIUMCVE-2024-11032
The Parsi Date plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 5.1.1. This makes it possible for unauthenticated attackers t... Read more
Affected Products :- Published: Nov. 26, 2024
- Modified: Nov. 26, 2024
-
5.5
MEDIUMCVE-2024-9170
The Booster for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wcj_product_meta shortcode in all versions up to, and including, 7.2.3 due to insufficient input sanitization and output escaping on user suppli... Read more
Affected Products : booster_for_woocommerce- Published: Nov. 26, 2024
- Modified: Feb. 05, 2025
-
6.4
MEDIUMCVE-2024-11192
The Spotify Play Button for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's spotifyplaybutton shortcode in all versions up to, and including, 2.11 due to insufficient input sanitization and output escaping on u... Read more
Affected Products : spotify-play-button-for-wordpress- Published: Nov. 26, 2024
- Modified: Nov. 26, 2024
-
6.4
MEDIUMCVE-2024-11119
The BNE Gallery Extended plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'gallery' shortcode in all versions up to, and including, 1.2.1 due to insufficient input sanitization and output escaping on user supplied attribu... Read more
Affected Products :- Published: Nov. 26, 2024
- Modified: Nov. 26, 2024
-
6.4
MEDIUMCVE-2024-11091
The Support SVG – Upload svg files in wordpress without hassle plugin for WordPress is vulnerable to Stored Cross-Site Scripting via REST API SVG File uploads in all versions up to, and including, 1.1.0 due to insufficient input sanitization and output es... Read more
Affected Products :- Published: Nov. 26, 2024
- Modified: Nov. 26, 2024
-
8.4
HIGHCVE-2018-11952
An image with a version lower than the fuse version may potentially be booted lead to improper authentication.... Read more
Affected Products : sd_450_firmware sd_625_firmware sd_820_firmware sd_820a_firmware sd_835_firmware mdm9650_firmware msm8909w_firmware mdm9206_firmware mdm9607_firmware mdm9640_firmware +36 more products- Published: Nov. 26, 2024
- Modified: Jan. 09, 2025
-
9.8
CRITICALCVE-2018-11922
Wrong configuration in Touch Pal application can collect user behavior data without awareness by the user.... Read more
Affected Products : sd_450_firmware sd_625_firmware mdm9650_firmware sdx20_firmware mdm9206_firmware mdm9607_firmware mdm9640_firmware sda660_firmware 215_firmware sdm439_firmware +34 more products- Published: Nov. 26, 2024
- Modified: Jan. 09, 2025
-
8.4
HIGHCVE-2017-18153
A race condition exists in a driver potentially leading to a use-after-free condition.... Read more
- Published: Nov. 26, 2024
- Modified: Jan. 09, 2025
-
9.8
CRITICALCVE-2017-17772
In multiple functions that process 802.11 frames, out-of-bounds reads can occur due to insufficient validation.... Read more
Affected Products : sd_450_firmware sd_625_firmware sd_820_firmware sd_820a_firmware sd_835_firmware sd_845_firmware sd_850_firmware sd_625 sd_820 sd_835 +4 more products- Published: Nov. 26, 2024
- Modified: Jan. 09, 2025
-
8.4
HIGHCVE-2017-15832
Buffer overwrite in the WLAN host driver by leveraging a compromised WLAN FW... Read more
Affected Products : sd_835_firmware mdm9206_firmware mdm9607_firmware sd_845_firmware sd_850_firmware mdm9206 mdm9607 sd_835 sd_845 sd_850- Published: Nov. 26, 2024
- Modified: Jan. 09, 2025
-
9.8
CRITICALCVE-2017-11076
On some hardware revisions where VP9 decoding is hardware-accelerated, the frame size is not programmed correctly into the decoder hardware which can lead to an invalid memory access by the decoder.... Read more
Affected Products : sdm660_firmware msm8996au_firmware sd_450_firmware sd_625_firmware sd_820_firmware sd_820a_firmware sd_835_firmware msm8909w_firmware sdm710_firmware sdm630_firmware +44 more products- Published: Nov. 26, 2024
- Modified: Jan. 09, 2025
-
8.4
HIGHCVE-2016-10394
Initial xbl_sec revision does not have all the debug policy features and critical checks.... Read more
Affected Products : sd_835_firmware mdm9206_firmware mdm9607_firmware sd_845_firmware sd_850_firmware mdm9206 mdm9607 sd_835 sd_845 sd_850- Published: Nov. 26, 2024
- Modified: Jan. 09, 2025
-
7.2
HIGHCVE-2024-9504
The Booking calendar, Appointment Booking System plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 3.2.15 due to insufficient input sanitization and output escaping. This makes it ... Read more
Affected Products : booking_calendar- Published: Nov. 26, 2024
- Modified: Nov. 26, 2024
-
4.3
MEDIUMCVE-2024-8772
51l3nc3, member of the AXIS OS Bug Bounty Program, has found that the VAPIX API managedoverlayimages.cgi was vulnerable to a race condition attack allowing for an attacker to block access to the overlay configuration page in the web interface of the Axis ... Read more
Affected Products : axis_os- Published: Nov. 26, 2024
- Modified: Nov. 26, 2024
-
3.8
LOWCVE-2024-8160
Erik de Jong, member of the AXIS OS Bug Bounty Program, has found that the VAPIX API ftptest.cgi did not have a sufficient input validation allowing for a possible command injection leading to being able to transfer files from/to the Axis device. This fla... Read more
Affected Products : axis_os- Published: Nov. 26, 2024
- Modified: Nov. 26, 2024