Latest CVE Feed
-
6.5
MEDIUMCVE-2024-51681
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in CodeRevolution WP Pocket URLs allows Stored XSS.This issue affects WP Pocket URLs: from n/a through 1.0.3.... Read more
Affected Products : wp_pocket_urls- Published: Nov. 04, 2024
- Modified: Nov. 06, 2024
-
6.5
MEDIUMCVE-2024-51680
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in CrestaProject – Rizzo Andrea Cresta Addons for Elementor allows Stored XSS.This issue affects Cresta Addons for Elementor: from n/a through 1.0.9.... Read more
Affected Products : cresta_addons_for_elementor- Published: Nov. 04, 2024
- Modified: Nov. 06, 2024
-
6.5
MEDIUMCVE-2024-51678
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Marcel Pol Elo Rating Shortcode allows Stored XSS.This issue affects Elo Rating Shortcode: from n/a through 1.0.3.... Read more
Affected Products : elo_rating_shortcode- Published: Nov. 04, 2024
- Modified: Nov. 06, 2024
-
6.5
MEDIUMCVE-2024-51677
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WebberZone Knowledge Base allows Stored XSS.This issue affects Knowledge Base: from n/a through 2.2.0.... Read more
Affected Products : knowledge_base- Published: Nov. 04, 2024
- Modified: Nov. 06, 2024
-
8.8
HIGHCVE-2024-51626
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Mansur Ahamed Woocommerce Quote Calculator allows Blind SQL Injection.This issue affects Woocommerce Quote Calculator: from n/a through 1.1.... Read more
Affected Products : woocommerce_quote_calculator- Published: Nov. 04, 2024
- Modified: Nov. 06, 2024
-
8.0
HIGHCVE-2024-45893
DrayTek Vigor3900 1.5.1.3 contains a post-authentication command injection vulnerability. This vulnerability occurs when the `action` parameter in `cgi-bin/mainfunction.cgi` is set to `setSWMOption.`... Read more
- Published: Nov. 04, 2024
- Modified: Apr. 10, 2025
-
8.0
HIGHCVE-2024-45891
DrayTek Vigor3900 1.5.1.3 contains a post-authentication command injection vulnerability. This vulnerability occurs when the `action` parameter in `cgi-bin/mainfunction.cgi` is set to `delete_wlan_profile.`... Read more
- Published: Nov. 04, 2024
- Modified: Apr. 10, 2025
-
8.0
HIGHCVE-2024-45890
DrayTek Vigor3900 1.5.1.3 contains a post-authentication command injection vulnerability This vulnerability occurs when the `action` parameter in `cgi-bin/mainfunction.cgi` is set to `download_ovpn.`... Read more
- Published: Nov. 04, 2024
- Modified: Apr. 10, 2025
-
8.0
HIGHCVE-2024-45889
DrayTek Vigor3900 1.5.1.3 contains a post-authentication command injection vulnerability. This vulnerability occurs when the `action` parameter in `cgi-bin/mainfunction.cgi` is set to `commandTable.`... Read more
- Published: Nov. 04, 2024
- Modified: Apr. 10, 2025
-
8.0
HIGHCVE-2024-45888
DrayTek Vigor3900 1.5.1.3 contains a command injection vulnerability. This vulnerability occurs when the `action` parameter in `cgi-bin/mainfunction.cgi` is set to `set_ap_map_config.'... Read more
- Published: Nov. 04, 2024
- Modified: Apr. 10, 2025
-
8.0
HIGHCVE-2024-45887
DrayTek Vigor3900 1.5.1.3 contains a post-authentication command injection vulnerability. This vulnerability occurs when the `action` parameter in `cgi-bin/mainfunction.cgi` is set to `doOpenVPN.`... Read more
- Published: Nov. 04, 2024
- Modified: Apr. 10, 2025
-
8.0
HIGHCVE-2024-45885
DrayTek Vigor3900 1.5.1.3 contains a post-authentication command injection vulnerability. This vulnerability occurs when the `action` parameter in `cgi-bin/mainfunction.cgi` is set to `autodiscovery_clear.`... Read more
- Published: Nov. 04, 2024
- Modified: Apr. 10, 2025
-
8.0
HIGHCVE-2024-45884
DrayTek Vigor3900 1.5.1.3 contains a post-authentication command injection vulnerability. This vulnerability occurs when the `action` parameter in `cgi-bin/mainfunction.cgi` is set to `setSWMGroup.`... Read more
- Published: Nov. 04, 2024
- Modified: Apr. 10, 2025
-
8.0
HIGHCVE-2024-45882
DrayTek Vigor3900 1.5.1.3 contains a command injection vulnerability. This vulnerability occurs when the `action` parameter in `cgi-bin/mainfunction.cgi` is set to `delete_map_profile.`... Read more
- Published: Nov. 04, 2024
- Modified: Apr. 10, 2025
-
7.6
HIGHCVE-2024-51672
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WPDeveloper BetterLinks allows SQL Injection.This issue affects BetterLinks: from n/a through 2.1.7.... Read more
Affected Products : betterlinks- Published: Nov. 04, 2024
- Modified: Nov. 06, 2024
-
4.9
MEDIUMCVE-2024-51665
Server-Side Request Forgery (SSRF) vulnerability in Noor alam Magical Addons For Elementor allows Server Side Request Forgery.This issue affects Magical Addons For Elementor: from n/a through 1.2.1.... Read more
Affected Products : magical_addons_for_elementor- Published: Nov. 04, 2024
- Modified: Nov. 06, 2024
-
8.8
HIGHCVE-2024-51582
Path Traversal: '.../...//' vulnerability in ThimPress WP Hotel Booking allows PHP Local File Inclusion.This issue affects WP Hotel Booking: from n/a through 2.1.4.... Read more
Affected Products : wp_hotel_booking- Published: Nov. 04, 2024
- Modified: Nov. 06, 2024
-
8.5
HIGHCVE-2024-51408
AppSmith Community 1.8.3 before 1.46 allows SSRF via New DataSource for application/json requests to 169.254.169.254 to retrieve AWS metadata credentials.... Read more
Affected Products : appsmith- Published: Nov. 04, 2024
- Modified: Nov. 06, 2024
-
8.0
HIGHCVE-2024-51253
In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the doL2TP function.... Read more
- Published: Nov. 04, 2024
- Modified: Apr. 10, 2025
-
8.0
HIGHCVE-2024-51251
In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the backup function.... Read more
- Published: Nov. 04, 2024
- Modified: Apr. 10, 2025