Latest CVE Feed
-
7.3
HIGHCVE-2024-10234
A vulnerability was found in Wildfly, where a user may perform Cross-site scripting in the Wildfly deployment system. This flaw allows an attacker or insider to execute a deployment with a malicious payload, which could trigger undesired behavior against ... Read more
- Published: Oct. 22, 2024
- Modified: Jul. 23, 2025
-
7.8
HIGHCVE-2024-9050
A flaw was found in the libreswan client plugin for NetworkManager (NetkworkManager-libreswan), where it fails to properly sanitize the VPN configuration from the local unprivileged user. In this configuration, composed by a key-value format, the plugin f... Read more
- Published: Oct. 22, 2024
- Modified: Dec. 18, 2024
-
6.1
MEDIUMCVE-2024-9231
The WP-Members Membership Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 3.4.9.5. This makes it possible for unauthe... Read more
Affected Products : wp-members- Published: Oct. 22, 2024
- Modified: Oct. 30, 2024
-
6.4
MEDIUMCVE-2024-10189
The Anchor Episodes Index (Spotify for Podcasters) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's anchor_episodes shortcode in all versions up to, and including, 2.1.10 due to insufficient input sanitization and output ... Read more
Affected Products : anchor_episodes_index- Published: Oct. 22, 2024
- Modified: Oct. 29, 2024
-
8.8
HIGHCVE-2024-9987
A post-authentication SQL Injection vulnerability within the filters parameter of the extensions/agents_modules_csv functionality. This issue affects Pandora FMS: from 700 through <777.3.... Read more
- Published: Oct. 22, 2024
- Modified: Oct. 25, 2024
-
8.8
HIGHCVE-2024-35308
A post-authentication arbitrary file read vulnerability within the server plugins section in plugin edition feature. This issue affects Pandora FMS: from 700 through <777.3.... Read more
- Published: Oct. 22, 2024
- Modified: Oct. 25, 2024
-
5.5
MEDIUMCVE-2024-9591
The Category and Taxonomy Image plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the '_category_image' parameter in versions up to, and including, 1.0.0 due to insufficient input sanitization and output escaping on user supplied attri... Read more
Affected Products : category_and_taxonomy_image- Published: Oct. 22, 2024
- Modified: Oct. 29, 2024
-
5.5
MEDIUMCVE-2024-9590
The Category and Taxonomy Meta Fields plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the image meta field value in the 'wpaft_add_meta_textinput' function in versions up to, and including, 1.0.0 due to insufficient input sanitizatio... Read more
Affected Products : category_and_taxonomy_meta_fields- Published: Oct. 22, 2024
- Modified: Oct. 29, 2024
-
5.5
MEDIUMCVE-2024-9589
The Category and Taxonomy Meta Fields plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'new_meta_name' parameter in the 'wpaft_option_page' function in versions up to, and including, 1.0.0 due to insufficient input sanitization an... Read more
Affected Products : category_and_taxonomy_meta_fields- Published: Oct. 22, 2024
- Modified: Oct. 29, 2024
-
5.4
MEDIUMCVE-2024-9588
The Category and Taxonomy Meta Fields plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.0.0. This is due to missing or incorrect nonce validation on the 'wpaft_option_page' function. This makes it possibl... Read more
Affected Products : category_and_taxonomy_meta_fields- Published: Oct. 22, 2024
- Modified: Oct. 25, 2024
-
4.3
MEDIUMCVE-2024-9541
The News Kit Elementor Addons plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.2.1 via the render function in includes/widgets/canvas-menu/canvas-menu.php. This makes it possible for authenticate... Read more
Affected Products : news_kit_elementor_addons- Published: Oct. 22, 2024
- Modified: Oct. 25, 2024
-
5.5
MEDIUMCVE-2023-52919
In the Linux kernel, the following vulnerability has been resolved: nfc: nci: fix possible NULL pointer dereference in send_acknowledge() Handle memory allocation failure from nci_skb_alloc() (calling alloc_skb()) to avoid possible NULL pointer derefere... Read more
Affected Products : linux_kernel- Published: Oct. 22, 2024
- Modified: Oct. 24, 2024
-
5.5
MEDIUMCVE-2023-52918
In the Linux kernel, the following vulnerability has been resolved: media: pci: cx23885: check cx23885_vdev_init() return cx23885_vdev_init() can return a NULL pointer, but that pointer is used in the next line without a check. Add a NULL pointer check... Read more
Affected Products : linux_kernel- Published: Oct. 22, 2024
- Modified: Oct. 24, 2024
-
8.6
HIGHCVE-2024-9627
The TeploBot - Telegram Bot for WP plugin for WordPress is vulnerable to sensitive information disclosure due to missing authorization checks on the 'service_process' function in all versions up to, and including, 1.3. This makes it possible for unauthent... Read more
Affected Products : teplobot- Published: Oct. 22, 2024
- Modified: Oct. 25, 2024
-
5.3
MEDIUMCVE-2024-8852
The All-in-One WP Migration and Backup plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 7.86 through publicly exposed log files. This makes it possible for unauthenticated attackers to view potenti... Read more
Affected Products : all-in-one_wp_migration- Published: Oct. 22, 2024
- Modified: Oct. 25, 2024
-
6.3
MEDIUMCVE-2024-10003
The Rover IDX plugin for WordPress is vulnerable to unauthorized access, modification, and loss of data due to a missing capability check on multiple functions in all versions up to, and including, 3.0.0.2903. This makes it possible for authenticated atta... Read more
Affected Products : rover_idx- Published: Oct. 22, 2024
- Modified: Oct. 25, 2024
-
8.8
HIGHCVE-2024-10002
The Rover IDX plugin for WordPress is vulnerable to Authentication Bypass in versions up to, and including, 3.0.0.2905. This is due to insufficient validation and capability check on the 'rover_idx_refresh_social_callback' function. This makes it possible... Read more
Affected Products : rover_idx- Published: Oct. 22, 2024
- Modified: Oct. 25, 2024
-
7.8
HIGHCVE-2024-9677
The insufficiently protected credentials vulnerability in the CLI command of the USG FLEX H series uOS firmware version V1.21 and earlier versions could allow an authenticated local attacker to gain privilege escalation by stealing the authentication toke... Read more
Affected Products : uos usg_flex_100h usg_flex_200h usg_flex_200hp usg_flex_500h usg_flex_700h usg_flex_700h_firmware- Published: Oct. 22, 2024
- Modified: Dec. 05, 2024
-
7.5
HIGHCVE-2024-8901
The AWS ALB Route Directive Adapter For Istio repo https://github.com/awslabs/aws-alb-route-directive-adapter-for-istio/tree/master provides an OIDC authentication mechanism that was integrated into the open source Kubeflow project. The adapter uses JWT... Read more
Affected Products :- Published: Oct. 22, 2024
- Modified: Oct. 23, 2024
-
7.5
HIGHCVE-2024-10125
The Amazon.ApplicationLoadBalancer.Identity.AspNetCore repo https://github.com/awslabs/aws-alb-identity-aspnetcore#validatetokensignature contains Middleware that can be used in conjunction with the Application Load Balancer (ALB) OpenId Connect integra... Read more
Affected Products :- Published: Oct. 22, 2024
- Modified: Oct. 23, 2024