Latest CVE Feed
-
9.8
CRITICALCVE-2024-10376
A vulnerability was found in ESAFENET CDG 5. It has been declared as critical. This vulnerability affects the function actionPassOrNotAutoSign of the file /com/esafenet/servlet/service/processsign/AutoSignService.java. The manipulation of the argument Uni... Read more
Affected Products : cdg- Published: Oct. 25, 2024
- Modified: Nov. 05, 2024
-
6.4
MEDIUMCVE-2024-8666
The Shoutcast Icecast HTML5 Radio Player plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'html5radio' shortcode in all versions up to, and including, 2.1.6 due to insufficient input sanitization and output escaping on us... Read more
Affected Products :- Published: Oct. 25, 2024
- Modified: Oct. 25, 2024
-
6.4
MEDIUMCVE-2024-10343
The Beek Widget Extention plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcodes in versions up to, and including, 0.9.5 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possib... Read more
Affected Products :- Published: Oct. 25, 2024
- Modified: Oct. 25, 2024
-
6.4
MEDIUMCVE-2024-10112
The Simple News plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'news' shortcode in all versions up to, and including, 2.8 due to insufficient input sanitization and output escaping on user supplied attributes. This make... Read more
Affected Products :- Published: Oct. 25, 2024
- Modified: Oct. 25, 2024
-
6.4
MEDIUMCVE-2024-10016
The File Upload Types by WPForms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.4.0 due to insufficient input sanitization and output escaping. This makes it possible for auth... Read more
Affected Products :- Published: Oct. 25, 2024
- Modified: Oct. 25, 2024
-
5.4
MEDIUMCVE-2024-9630
The WPS Telegram Chat plugin for WordPress is vulnerable to authorization bypass due to a missing capability check when accessing messages in versions up to, and including, 4.5.4. This makes it possible for unauthenticated attackers to view the messages t... Read more
- Published: Oct. 25, 2024
- Modified: Jan. 24, 2025
-
6.5
MEDIUMCVE-2024-9628
The WPS Telegram Chat plugin for WordPress is vulnerable to unauthorized modification of data and loss of data due to a missing capability check on the 'Wps_Telegram_Chat_Admin::checkСonnection' function in versions up to, and including, 4.5.4. This makes... Read more
- Published: Oct. 25, 2024
- Modified: Feb. 26, 2025
-
8.8
HIGHCVE-2024-9598
The AMP for WP – Accelerated Mobile Pages plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.99.1. This is due to missing or incorrect nonce validation on the 'proxy' function. This makes it possible... Read more
Affected Products : accelerated_mobile_pages- Published: Oct. 25, 2024
- Modified: Oct. 25, 2024
-
7.4
HIGHCVE-2024-47158
N-LINE 2.0.6 and prior versions contain a code injection vulnerability. If this vulnerability is exploited, arbitrary code may be executed on the instructor's browser, or the instructor may be directed to a malicious website.... Read more
Affected Products : n-line- Published: Oct. 25, 2024
- Modified: Nov. 06, 2024
-
7.5
HIGHCVE-2024-45785
MUSASI version 3 contains an issue with use of client-side authentication. If this vulnerability is exploited, other users' credential and sensitive information may be retrieved.... Read more
Affected Products : musasi- Published: Oct. 25, 2024
- Modified: Nov. 06, 2024
-
6.4
MEDIUMCVE-2024-10342
The League of Legends Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcodes in versions up to, and including, 1.0.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it... Read more
Affected Products : league_of_legends_shortcodes- Published: Oct. 25, 2024
- Modified: Nov. 05, 2024
-
6.5
MEDIUMCVE-2024-10341
The League of Legends Shortcodes plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcode in versions up to, and including, 1.0.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the e... Read more
Affected Products : league_of_legends_shortcodes- Published: Oct. 25, 2024
- Modified: Nov. 05, 2024
-
6.4
MEDIUMCVE-2024-10150
The Bamazoo – Button Generator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's dgs shortcode in all versions up to, and including, 1.0 due to insufficient input sanitization and output escaping on user supplied attribute... Read more
Affected Products : button_generator- Published: Oct. 25, 2024
- Modified: Nov. 05, 2024
-
6.1
MEDIUMCVE-2024-9607
The 10Web Social Post Feed plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 1.2.9. This makes it possible for unauthenticated... Read more
Affected Products : 10web_social_post_feed- Published: Oct. 25, 2024
- Modified: Nov. 05, 2024
-
9.8
CRITICALCVE-2024-9302
The App Builder – Create Native Android & iOS Apps On The Flight plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 5.3.7. This is due to the verify_otp_forgot_password() and update_passwo... Read more
Affected Products : app_builder- Published: Oct. 25, 2024
- Modified: Nov. 05, 2024
-
8.8
HIGHCVE-2024-9235
The Mapster WP Maps plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to an insufficient capability check on the mapster_wp_maps_set_option_from_js() function in all versions up to, and inclu... Read more
Affected Products : mapster_wp_maps- Published: Oct. 25, 2024
- Modified: Nov. 05, 2024
-
6.3
MEDIUMCVE-2024-50583
Whale browser Installer before 3.1.0.0 allows an attacker to execute a malicious DLL in the user environment due to improper permission settings.... Read more
Affected Products :- Published: Oct. 25, 2024
- Modified: Oct. 25, 2024
-
6.2
MEDIUMCVE-2024-48870
Sharp and Toshiba Tec MFPs improperly validate input data in URI data registration, resulting in a stored cross-site scripting vulnerability. If crafted input is stored by an administrative user, malicious script may be executed on the web browsers of ot... Read more
Affected Products : bp-30c25_firmware bp-30c25t_firmware bp-30c25y_firmware bp-30c25z_firmware bp-30m28_firmware bp-30m28t_firmware bp-30m31_firmware bp-30m31t_firmware bp-30m35_firmware bp-30m35t_firmware +630 more products- Published: Oct. 25, 2024
- Modified: Nov. 05, 2024
-
7.4
HIGHCVE-2024-47801
Sharp and Toshiba Tec MFPs improperly process query parameters in HTTP requests, resulting in a reflected cross-site scripting vulnerability. Accessing a crafted URL which points to an affected product may cause malicious script executed on the web brows... Read more
Affected Products : bp-30c25_firmware bp-30c25t_firmware bp-30c25y_firmware bp-30c25z_firmware bp-30m28_firmware bp-30m28t_firmware bp-30m31_firmware bp-30m31t_firmware bp-30m35_firmware bp-30m35t_firmware +630 more products- Published: Oct. 25, 2024
- Modified: Nov. 05, 2024
-
7.4
HIGHCVE-2024-47549
Sharp and Toshiba Tec MFPs improperly process query parameters in HTTP requests, which may allow contamination of unintended data to HTTP response headers. Accessing a crafted URL which points to an affected product may cause malicious script executed on... Read more
Affected Products : bp-30c25_firmware bp-30c25t_firmware bp-30c25y_firmware bp-30c25z_firmware bp-30m28_firmware bp-30m28t_firmware bp-30m31_firmware bp-30m31t_firmware bp-30m35_firmware bp-30m35t_firmware +630 more products- Published: Oct. 25, 2024
- Modified: Nov. 05, 2024