Latest CVE Feed
-
6.1
MEDIUMCVE-2024-9417
The Hash Form – Drag & Drop Form Builder plugin for WordPress is vulnerable to limited file uploads due to a misconfigured file type validation in the 'handleUpload' function in all versions up to, and including, 1.1.9. This makes it possible for unauthen... Read more
Affected Products : hash_form- Published: Oct. 05, 2024
- Modified: Oct. 07, 2024
-
9.0
HIGHCVE-2024-9532
A vulnerability has been found in D-Link DIR-605L 2.13B01 BETA and classified as critical. This vulnerability affects the function formAdvanceSetup of the file /goform/formAdvanceSetup. The manipulation of the argument webpage leads to buffer overflow. Th... Read more
- Published: Oct. 05, 2024
- Modified: Oct. 09, 2024
-
6.4
MEDIUMCVE-2024-8486
The Shortcodes and extra features for Phlox theme plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘url’ parameter in the Modern Heading and Icon Picker widgets all versions up to, and including, 2.16.3 due to insufficient input s... Read more
- Published: Oct. 05, 2024
- Modified: May. 22, 2025
-
6.8
MEDIUMCVE-2024-8743
The Bit File Manager – 100% Free & Open Source File Manager and Code Editor for WordPress plugin for WordPress is vulnerable to Limited JavaScript File Upload in all versions up to, and including, 6.5.7. This is due to a lack of proper checks on allowed f... Read more
Affected Products : file_manager- Published: Oct. 05, 2024
- Modified: Oct. 07, 2024
-
4.9
MEDIUMCVE-2024-9528
The Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via form label fields in all versions up to, and including, 5.1.19 due to insufficient input saniti... Read more
Affected Products : contact_form- Published: Oct. 05, 2024
- Modified: Feb. 06, 2025
-
6.4
MEDIUMCVE-2024-9455
The WP Cleanup and Basic Functions plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 2.2.1 due to insufficient input sanitization and output escaping. This makes it possible for au... Read more
Affected Products :- Published: Oct. 05, 2024
- Modified: Oct. 07, 2024
-
6.1
MEDIUMCVE-2024-9385
The Themify Builder plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 7.6.2. This makes it possible for unauthenticated attack... Read more
- Published: Oct. 05, 2024
- Modified: Feb. 07, 2025
-
7.5
HIGHCVE-2024-47841
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in The Wikimedia Foundation Mediawiki - CSS Extension allows Path Traversal.This issue affects Mediawiki - CSS Extension: from 1.42.X before 1.42.2, from 1.41.X b... Read more
Affected Products : wikimedia-extensions-css- Published: Oct. 05, 2024
- Modified: Oct. 16, 2024
-
9.8
CRITICALCVE-2024-47849
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in The Wikimedia Foundation Mediawiki - Cargo allows SQL Injection.This issue affects Mediawiki - Cargo: from 3.6.X before 3.6.1.... Read more
Affected Products : cargo- Published: Oct. 05, 2024
- Modified: Oct. 16, 2024
-
6.9
MEDIUMCVE-2024-47847
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in The Wikimedia Foundation Mediawiki - Cargo allows Cross-Site Scripting (XSS).This issue affects Mediawiki - Cargo: from 3.6.X before 3.6.1.... Read more
- Published: Oct. 05, 2024
- Modified: Oct. 16, 2024
-
8.8
HIGHCVE-2024-47846
Cross-Site Request Forgery (CSRF) vulnerability in The Wikimedia Foundation Mediawiki - Cargo allows Cross Site Request Forgery.This issue affects Mediawiki - Cargo: from 3.6.X before 3.6.1.... Read more
Affected Products : cargo- Published: Oct. 05, 2024
- Modified: Oct. 16, 2024
-
8.2
HIGHCVE-2024-47845
Improper Encoding or Escaping of Output vulnerability in The Wikimedia Foundation Mediawiki - CSS Extension allows Code Injection.This issue affects Mediawiki - CSS Extension: from 1.39.X before 1.39.9, from 1.41.X before 1.41.3, from 1.42.X before 1.42.2... Read more
Affected Products : wikimedia-extensions-css- Published: Oct. 05, 2024
- Modified: Oct. 23, 2024
-
6.9
MEDIUMCVE-2024-47840
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in The Wikimedia Foundation Mediawiki - Apex skin allows Stored XSS.This issue affects Mediawiki - Apex skin: from 1.39.X before 1.39.9, from 1.41.X ... Read more
Affected Products : apex- Published: Oct. 05, 2024
- Modified: Oct. 16, 2024
-
6.9
MEDIUMCVE-2024-47848
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in The Wikimedia Foundation Mediawiki - PageTriage allows Authentication Bypass.This issue affects Mediawiki - PageTriage: from 1.39.X before 1.39.9, from 1.41.X before 1.41.3, from ... Read more
Affected Products :- Published: Oct. 05, 2024
- Modified: Oct. 07, 2024
-
5.3
MEDIUMCVE-2024-47913
An issue was discovered in the AbuseFilter extension for MediaWiki before 1.39.9, 1.40.x and 1.41.x before 1.41.3, and 1.42.x before 1.42.2. An API caller can match a filter condition against AbuseFilter logs even if the caller is not authorized to view t... Read more
- Published: Oct. 04, 2024
- Modified: Jun. 17, 2025
-
7.2
HIGHCVE-2024-47911
In SonarSource SonarQube 10.4 through 10.5 before 10.6, a vulnerability was discovered in the authorizations/group-memberships API endpoint that allows SonarQube users with the administrator role to inject blind SQL commands.... Read more
Affected Products : sonarqube- Published: Oct. 04, 2024
- Modified: Sep. 04, 2025
-
7.2
HIGHCVE-2024-47910
An issue was discovered in SonarSource SonarQube before 9.9.5 LTA and 10.x before 10.5. A SonarQube user with the Administrator role can modify an existing configuration of a GitHub integration to exfiltrate a pre-signed JWT.... Read more
Affected Products :- Published: Oct. 04, 2024
- Modified: Oct. 07, 2024
-
8.8
HIGHCVE-2024-37869
File Upload vulnerability in Itsourcecode Online Discussion Forum Project v.1.0 allows a remote attacker to execute arbitrary code via the "poster.php" file, and the uploaded file was received using the "$- FILES" variable... Read more
Affected Products : online_discussion_forum- Published: Oct. 04, 2024
- Modified: Oct. 08, 2024
-
8.8
HIGHCVE-2024-37868
File Upload vulnerability in Itsourcecode Online Discussion Forum Project v.1.0 allows a remote attacker to execute arbitrary code via the "sendreply.php" file, and the uploaded file was received using the "$- FILES" variable.... Read more
Affected Products : online_discussion_forum- Published: Oct. 04, 2024
- Modified: Oct. 08, 2024
-
8.8
HIGHCVE-2024-9054
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection'), Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Microchip TimeProvider 4100 (Configuration modules) allows Command Injection.This issue... Read more
- Published: Oct. 04, 2024
- Modified: Aug. 29, 2025