Latest CVE Feed
-
7.5
HIGHCVE-2024-52797
Opencast is free and open source software for automated video capture and distribution. First noticed in Opencast 13 and 14, Opencast's Elasticsearch integration may generate syntactically invalid Elasticsearch queries in relation to previously acceptable... Read more
Affected Products : opencast- Published: Nov. 21, 2024
- Modified: Aug. 26, 2025
-
6.9
MEDIUMCVE-2024-52067
Apache NiFi 1.16.0 through 1.28.0 and 2.0.0-M1 through 2.0.0-M4 include optional debug logging of Parameter Context values during the flow synchronization process. An authorized administrator with access to change logging levels could enable debug logging... Read more
Affected Products : nifi- Published: Nov. 21, 2024
- Modified: Feb. 11, 2025
-
7.5
HIGHCVE-2024-45663
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.1, 11.5, and 12.1 is vulnerable to a denial of service as the server may crash under certain conditions with a specially crafted query.... Read more
Affected Products : db2- Published: Nov. 21, 2024
- Modified: Aug. 08, 2025
-
9.1
CRITICALCVE-2024-30896
InfluxDB OSS 2.x through 2.7.11 stores the administrative operator token under the default organization which allows authorized users with read access to the authorization resource of the default organization to retrieve the operator token. InfluxDB OSS 1... Read more
Affected Products : influxdb- Published: Nov. 21, 2024
- Modified: Dec. 03, 2024
-
7.8
HIGHCVE-2024-11596
ECMP dissector crash in Wireshark 4.4.0 to 4.4.1 and 4.2.0 to 4.2.8 allows denial of service via packet injection or crafted capture file... Read more
Affected Products : wireshark- Published: Nov. 21, 2024
- Modified: May. 07, 2025
-
7.8
HIGHCVE-2024-11595
FiveCo RAP dissector infinite loop in Wireshark 4.4.0 to 4.4.1 and 4.2.0 to 4.2.8 allows denial of service via packet injection or crafted capture file... Read more
Affected Products : wireshark- Published: Nov. 21, 2024
- Modified: May. 07, 2025
-
6.1
MEDIUMCVE-2024-11456
The Run Contests, Raffles, and Giveaways with ContestsWP plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 2.0.3. This makes i... Read more
Affected Products :- Published: Nov. 21, 2024
- Modified: Nov. 21, 2024
-
6.4
MEDIUMCVE-2024-11455
The Include Mastodon Feed plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'include-mastodon-feed' shortcode in all versions up to, and including, 1.9.5 due to insufficient input sanitization and output escaping on user s... Read more
Affected Products :- Published: Nov. 21, 2024
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2024-11447
The Community by PeepSo – Download from PeepSo.com plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘filter’ parameter in all versions up to, and including, 7.0.3.0 due to insufficient input sanitization and output escaping. Th... Read more
Affected Products :- Published: Nov. 21, 2024
- Modified: Apr. 14, 2025
-
6.4
MEDIUMCVE-2024-11440
The Grey Owl Lightbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'gol_button' shortcode in all versions up to, and including, 1.6.1 due to insufficient input sanitization and output escaping on user supplied attribu... Read more
Affected Products :- Published: Nov. 21, 2024
- Modified: Nov. 21, 2024
-
6.4
MEDIUMCVE-2024-11438
The StreamWeasels Online Status Bar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'sw-status-bar' shortcode in all versions up to, and including, 2.1.9 due to insufficient input sanitization and output escaping on user... Read more
Affected Products :- Published: Nov. 21, 2024
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2024-11435
The salavat counter Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'page' parameter in all versions up to, and including, 0.9.1 due to insufficient input sanitization and output escaping. This makes it possible for una... Read more
Affected Products :- Published: Nov. 21, 2024
- Modified: Nov. 21, 2024
-
6.4
MEDIUMCVE-2024-11432
The SuevaFree Essential Kit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'counter' shortcode in all versions up to, and including, 1.1.3 due to insufficient input sanitization and output escaping on user supplied attr... Read more
Affected Products :- Published: Nov. 21, 2024
- Modified: Nov. 21, 2024
-
6.4
MEDIUMCVE-2024-11428
The Lazy load videos and sticky control plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'lazy-load-videos-and-sticky-control' shortcode in all versions up to, and including, 3.0.0 due to insufficient input sanitization a... Read more
Affected Products :- Published: Nov. 21, 2024
- Modified: Nov. 21, 2024
-
6.4
MEDIUMCVE-2024-11424
The Slick Sitemap plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'slick-sitemap' shortcode in all versions up to, and including, 2.0.0 due to insufficient input sanitization and output escaping on user supplied attribut... Read more
Affected Products :- Published: Nov. 21, 2024
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2024-11416
The WIP Incoming Lite plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1.1. This is due to missing or incorrect nonce validation on the save_option() function. This makes it possible for unauthentica... Read more
Affected Products :- Published: Nov. 21, 2024
- Modified: Nov. 21, 2024
-
6.4
MEDIUMCVE-2024-11414
The RecipePress Reloaded plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Recipe Ingredients in all versions up to, and including, 2.12.0 due to insufficient input sanitization and output escaping. This makes it possible for authentic... Read more
Affected Products :- Published: Nov. 21, 2024
- Modified: Nov. 21, 2024
-
6.4
MEDIUMCVE-2024-11412
The Shine PDF Embeder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'shinepdf' shortcode in all versions up to, and including, 1.0 due to insufficient input sanitization and output escaping on user supplied attributes.... Read more
Affected Products :- Published: Nov. 21, 2024
- Modified: Nov. 21, 2024
-
7.2
HIGHCVE-2024-11409
The Grid View Gallery plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.0 via deserialization of untrusted input from cs_all_photos_details parameter. This makes it possible for authenticated attackers, wit... Read more
Affected Products :- Published: Nov. 21, 2024
- Modified: Nov. 21, 2024
-
6.4
MEDIUMCVE-2024-11388
The Dino Game – Embed Google Chrome Dinosaur Game in WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'dino-game' shortcode in all versions up to, and including, 1.1.0 due to insufficient input sanitization and ... Read more
Affected Products : dino_game- Published: Nov. 21, 2024
- Modified: Nov. 26, 2024