Latest CVE Feed
-
6.4
MEDIUMCVE-2024-9442
The F4 Improvements plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.9.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated att... Read more
Affected Products : f4_improvements- Published: Nov. 21, 2024
- Modified: Nov. 22, 2024
-
6.1
MEDIUMCVE-2024-9371
The Branda – White Label & Branding, Custom Login Page Customizer plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of remove_query_arg without appropriate escaping on the URL in all versions up to, and including, 3.4.19.... Read more
Affected Products :- Published: Nov. 21, 2024
- Modified: Nov. 21, 2024
-
6.4
MEDIUMCVE-2024-9111
The Product Designer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.0.35 due to insufficient input sanitization and output escaping. This makes it possible for authenticated a... Read more
Affected Products : product_designer- Published: Nov. 21, 2024
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2024-8157
The Alphabetical List WordPress plugin through 1.0.3 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack... Read more
Affected Products : alphabetical_list- Published: Nov. 21, 2024
- Modified: May. 15, 2025
-
8.5
HIGHCVE-2024-7517
A command injection vulnerability in Brocade Fabric OS before 9.2.0c, and 9.2.1 through 9.2.1a on IP extension platforms could allow a local authenticated attacker to perform a privileged escalation via crafted use of the portcfg command. This specific e... Read more
- Published: Nov. 21, 2024
- Modified: Nov. 21, 2024
-
4.8
MEDIUMCVE-2024-5029
The CM Table Of Contents WordPress plugin before 1.2.4 does not have CSRF check when updating its settings, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack.... Read more
Affected Products : cm_table_of_contents- Published: Nov. 21, 2024
- Modified: May. 15, 2025
-
7.5
HIGHCVE-2024-52797
Opencast is free and open source software for automated video capture and distribution. First noticed in Opencast 13 and 14, Opencast's Elasticsearch integration may generate syntactically invalid Elasticsearch queries in relation to previously acceptable... Read more
Affected Products : opencast- Published: Nov. 21, 2024
- Modified: Aug. 26, 2025
-
6.9
MEDIUMCVE-2024-52067
Apache NiFi 1.16.0 through 1.28.0 and 2.0.0-M1 through 2.0.0-M4 include optional debug logging of Parameter Context values during the flow synchronization process. An authorized administrator with access to change logging levels could enable debug logging... Read more
Affected Products : nifi- Published: Nov. 21, 2024
- Modified: Feb. 11, 2025
-
7.5
HIGHCVE-2024-45663
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.1, 11.5, and 12.1 is vulnerable to a denial of service as the server may crash under certain conditions with a specially crafted query.... Read more
Affected Products : db2- Published: Nov. 21, 2024
- Modified: Aug. 08, 2025
-
9.1
CRITICALCVE-2024-30896
InfluxDB OSS 2.x through 2.7.11 stores the administrative operator token under the default organization which allows authorized users with read access to the authorization resource of the default organization to retrieve the operator token. InfluxDB OSS 1... Read more
Affected Products : influxdb- Published: Nov. 21, 2024
- Modified: Dec. 03, 2024
-
7.8
HIGHCVE-2024-11596
ECMP dissector crash in Wireshark 4.4.0 to 4.4.1 and 4.2.0 to 4.2.8 allows denial of service via packet injection or crafted capture file... Read more
Affected Products : wireshark- Published: Nov. 21, 2024
- Modified: May. 07, 2025
-
7.8
HIGHCVE-2024-11595
FiveCo RAP dissector infinite loop in Wireshark 4.4.0 to 4.4.1 and 4.2.0 to 4.2.8 allows denial of service via packet injection or crafted capture file... Read more
Affected Products : wireshark- Published: Nov. 21, 2024
- Modified: May. 07, 2025
-
6.1
MEDIUMCVE-2024-11456
The Run Contests, Raffles, and Giveaways with ContestsWP plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 2.0.3. This makes i... Read more
Affected Products :- Published: Nov. 21, 2024
- Modified: Nov. 21, 2024
-
6.4
MEDIUMCVE-2024-11455
The Include Mastodon Feed plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'include-mastodon-feed' shortcode in all versions up to, and including, 1.9.5 due to insufficient input sanitization and output escaping on user s... Read more
Affected Products :- Published: Nov. 21, 2024
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2024-11447
The Community by PeepSo – Download from PeepSo.com plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘filter’ parameter in all versions up to, and including, 7.0.3.0 due to insufficient input sanitization and output escaping. Th... Read more
Affected Products :- Published: Nov. 21, 2024
- Modified: Apr. 14, 2025
-
6.4
MEDIUMCVE-2024-11440
The Grey Owl Lightbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'gol_button' shortcode in all versions up to, and including, 1.6.1 due to insufficient input sanitization and output escaping on user supplied attribu... Read more
Affected Products :- Published: Nov. 21, 2024
- Modified: Nov. 21, 2024
-
6.4
MEDIUMCVE-2024-11438
The StreamWeasels Online Status Bar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'sw-status-bar' shortcode in all versions up to, and including, 2.1.9 due to insufficient input sanitization and output escaping on user... Read more
Affected Products :- Published: Nov. 21, 2024
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2024-11435
The salavat counter Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'page' parameter in all versions up to, and including, 0.9.1 due to insufficient input sanitization and output escaping. This makes it possible for una... Read more
Affected Products :- Published: Nov. 21, 2024
- Modified: Nov. 21, 2024
-
6.4
MEDIUMCVE-2024-11432
The SuevaFree Essential Kit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'counter' shortcode in all versions up to, and including, 1.1.3 due to insufficient input sanitization and output escaping on user supplied attr... Read more
Affected Products :- Published: Nov. 21, 2024
- Modified: Nov. 21, 2024
-
6.4
MEDIUMCVE-2024-11428
The Lazy load videos and sticky control plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'lazy-load-videos-and-sticky-control' shortcode in all versions up to, and including, 3.0.0 due to insufficient input sanitization a... Read more
Affected Products :- Published: Nov. 21, 2024
- Modified: Nov. 21, 2024