Latest CVE Feed
-
8.8
HIGHCVE-2024-9598
The AMP for WP – Accelerated Mobile Pages plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.99.1. This is due to missing or incorrect nonce validation on the 'proxy' function. This makes it possible... Read more
Affected Products : accelerated_mobile_pages- Published: Oct. 25, 2024
- Modified: Oct. 25, 2024
-
7.4
HIGHCVE-2024-47158
N-LINE 2.0.6 and prior versions contain a code injection vulnerability. If this vulnerability is exploited, arbitrary code may be executed on the instructor's browser, or the instructor may be directed to a malicious website.... Read more
Affected Products : n-line- Published: Oct. 25, 2024
- Modified: Nov. 06, 2024
-
7.5
HIGHCVE-2024-45785
MUSASI version 3 contains an issue with use of client-side authentication. If this vulnerability is exploited, other users' credential and sensitive information may be retrieved.... Read more
Affected Products : musasi- Published: Oct. 25, 2024
- Modified: Nov. 06, 2024
-
6.4
MEDIUMCVE-2024-10342
The League of Legends Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcodes in versions up to, and including, 1.0.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it... Read more
Affected Products : league_of_legends_shortcodes- Published: Oct. 25, 2024
- Modified: Nov. 05, 2024
-
6.5
MEDIUMCVE-2024-10341
The League of Legends Shortcodes plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcode in versions up to, and including, 1.0.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the e... Read more
Affected Products : league_of_legends_shortcodes- Published: Oct. 25, 2024
- Modified: Nov. 05, 2024
-
6.4
MEDIUMCVE-2024-10150
The Bamazoo – Button Generator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's dgs shortcode in all versions up to, and including, 1.0 due to insufficient input sanitization and output escaping on user supplied attribute... Read more
Affected Products : button_generator- Published: Oct. 25, 2024
- Modified: Nov. 05, 2024
-
6.1
MEDIUMCVE-2024-9607
The 10Web Social Post Feed plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 1.2.9. This makes it possible for unauthenticated... Read more
Affected Products : 10web_social_post_feed- Published: Oct. 25, 2024
- Modified: Nov. 05, 2024
-
9.8
CRITICALCVE-2024-9302
The App Builder – Create Native Android & iOS Apps On The Flight plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 5.3.7. This is due to the verify_otp_forgot_password() and update_passwo... Read more
Affected Products : app_builder- Published: Oct. 25, 2024
- Modified: Nov. 05, 2024
-
8.8
HIGHCVE-2024-9235
The Mapster WP Maps plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to an insufficient capability check on the mapster_wp_maps_set_option_from_js() function in all versions up to, and inclu... Read more
Affected Products : mapster_wp_maps- Published: Oct. 25, 2024
- Modified: Nov. 05, 2024
-
6.3
MEDIUMCVE-2024-50583
Whale browser Installer before 3.1.0.0 allows an attacker to execute a malicious DLL in the user environment due to improper permission settings.... Read more
Affected Products :- Published: Oct. 25, 2024
- Modified: Oct. 25, 2024
-
6.2
MEDIUMCVE-2024-48870
Sharp and Toshiba Tec MFPs improperly validate input data in URI data registration, resulting in a stored cross-site scripting vulnerability. If crafted input is stored by an administrative user, malicious script may be executed on the web browsers of ot... Read more
Affected Products : bp-30c25_firmware bp-30c25t_firmware bp-30c25y_firmware bp-30c25z_firmware bp-30m28_firmware bp-30m28t_firmware bp-30m31_firmware bp-30m31t_firmware bp-30m35_firmware bp-30m35t_firmware +630 more products- Published: Oct. 25, 2024
- Modified: Nov. 05, 2024
-
7.4
HIGHCVE-2024-47801
Sharp and Toshiba Tec MFPs improperly process query parameters in HTTP requests, resulting in a reflected cross-site scripting vulnerability. Accessing a crafted URL which points to an affected product may cause malicious script executed on the web brows... Read more
Affected Products : bp-30c25_firmware bp-30c25t_firmware bp-30c25y_firmware bp-30c25z_firmware bp-30m28_firmware bp-30m28t_firmware bp-30m31_firmware bp-30m31t_firmware bp-30m35_firmware bp-30m35t_firmware +630 more products- Published: Oct. 25, 2024
- Modified: Nov. 05, 2024
-
7.4
HIGHCVE-2024-47549
Sharp and Toshiba Tec MFPs improperly process query parameters in HTTP requests, which may allow contamination of unintended data to HTTP response headers. Accessing a crafted URL which points to an affected product may cause malicious script executed on... Read more
Affected Products : bp-30c25_firmware bp-30c25t_firmware bp-30c25y_firmware bp-30c25z_firmware bp-30m28_firmware bp-30m28t_firmware bp-30m31_firmware bp-30m31t_firmware bp-30m35_firmware bp-30m35t_firmware +630 more products- Published: Oct. 25, 2024
- Modified: Nov. 05, 2024
-
9.8
CRITICALCVE-2024-47406
Sharp and Toshiba Tec MFPs improperly process HTTP authentication requests, resulting in an authentication bypass vulnerability.... Read more
Affected Products : bp-30c25_firmware bp-30c25t_firmware bp-30c25y_firmware bp-30c25z_firmware bp-30m28_firmware bp-30m28t_firmware bp-30m31_firmware bp-30m31t_firmware bp-30m35_firmware bp-30m35t_firmware +630 more products- Published: Oct. 25, 2024
- Modified: Nov. 05, 2024
-
8.1
HIGHCVE-2024-47005
Sharp and Toshiba Tec MFPs provide configuration related APIs. They are expected to be called by administrative users only, but insufficiently restricted. A non-administrative user may execute some configuration APIs.... Read more
Affected Products : bp-30c25_firmware bp-30c25t_firmware bp-30c25y_firmware bp-30c25z_firmware bp-30m28_firmware bp-30m28t_firmware bp-30m31_firmware bp-30m31t_firmware bp-30m35_firmware bp-30m35t_firmware +630 more products- Published: Oct. 25, 2024
- Modified: Nov. 05, 2024
-
5.3
MEDIUMCVE-2024-45842
Sharp and Toshiba Tec MFPs improperly process URI data in HTTP PUT requests resulting in a path Traversal vulnerability. Unintended internal files may be retrieved when processing crafted HTTP requests.... Read more
Affected Products : bp-30c25_firmware bp-30c25t_firmware bp-30c25y_firmware bp-30c25z_firmware bp-30m28_firmware bp-30m28t_firmware bp-30m31_firmware bp-30m31t_firmware bp-30m35_firmware bp-30m35t_firmware +630 more products- Published: Oct. 25, 2024
- Modified: Nov. 05, 2024
-
7.5
HIGHCVE-2024-45829
Sharp and Toshiba Tec MFPs provide the web page to download data, where query parameters in HTTP requests are improperly processed and resulting in an Out-of-bounds Read vulnerability. Crafted HTTP requests may cause affected products crashed.... Read more
Affected Products : bp-30c25_firmware bp-30c25t_firmware bp-30c25y_firmware bp-30c25z_firmware bp-30m28_firmware bp-30m28t_firmware bp-30m31_firmware bp-30m31t_firmware bp-30m35_firmware bp-30m35t_firmware +630 more products- Published: Oct. 25, 2024
- Modified: Nov. 05, 2024
-
7.5
HIGHCVE-2024-43424
Sharp and Toshiba Tec MFPs improperly process HTTP request headers, resulting in an Out-of-bounds Read vulnerability. Crafted HTTP requests may cause affected products crashed.... Read more
Affected Products : bp-30c25_firmware bp-30c25t_firmware bp-30c25y_firmware bp-30c25z_firmware bp-30m28_firmware bp-30m28t_firmware bp-30m31_firmware bp-30m31t_firmware bp-30m35_firmware bp-30m35t_firmware +630 more products- Published: Oct. 25, 2024
- Modified: Nov. 05, 2024
-
7.5
HIGHCVE-2024-42420
Sharp and Toshiba Tec MFPs contain multiple Out-of-bounds Read vulnerabilities, due to improper processing of keyword search input and improper processing of SOAP messages. Crafted HTTP requests may cause affected products crashed.... Read more
Affected Products : bp-30c25_firmware bp-30c25t_firmware bp-30c25y_firmware bp-30c25z_firmware bp-30m28_firmware bp-30m28t_firmware bp-30m31_firmware bp-30m31t_firmware bp-30m35_firmware bp-30m35t_firmware +630 more products- Published: Oct. 25, 2024
- Modified: Nov. 05, 2024
-
6.4
MEDIUMCVE-2024-10148
The Awesome buttons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's btn2 shortcode in all versions up to, and including, 1.0 due to insufficient input sanitization and output escaping on user supplied attributes. This ma... Read more
Affected Products : awesome_buttons- Published: Oct. 25, 2024
- Modified: Nov. 06, 2024