Latest CVE Feed
-
9.8
CRITICALCVE-2024-9087
A vulnerability, which was classified as critical, was found in code-projects Vehicle Management 1.0. This affects an unknown part of the file /edit1.php. The manipulation of the argument sno leads to sql injection. It is possible to initiate the attack r... Read more
- Published: Sep. 22, 2024
- Modified: Sep. 26, 2024
-
6.4
MEDIUMCVE-2024-5628
The Avada | Website Builder For WordPress & eCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's fusion_button shortcode in all versions up to, and including, 3.11.9 due to insufficient input sanitization and output... Read more
Affected Products : avada- Published: Sep. 13, 2024
- Modified: Sep. 26, 2024
-
4.3
MEDIUMCVE-2024-3163
The Easy Property Listings WordPress plugin before 3.5.4 does not have CSRF check when deleting contacts in bulk, which could allow attackers to make a logged in admin delete them via a CSRF attack... Read more
Affected Products : easy_property_listings- Published: Sep. 12, 2024
- Modified: Sep. 26, 2024
-
6.1
MEDIUMCVE-2024-8656
The WPFactory Helper plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 1.7.0. This makes it possible for unauthenticated attac... Read more
Affected Products : wpfactory_helper- Published: Sep. 13, 2024
- Modified: Sep. 26, 2024
-
6.1
MEDIUMCVE-2024-8622
The amCharts: Charts and Maps plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'amcharts_javascript' parameter in all versions up to, and including, 1.4.4 due to the ability to supply arbitrary JavaScript a lack of nonce valida... Read more
Affected Products : amcharts\- Published: Sep. 12, 2024
- Modified: Sep. 26, 2024
-
5.9
MEDIUMCVE-2022-45856
An improper certificate validation vulnerability [CWE-295] in FortiClientWindows 6.4 all versions, 7.0.0 through 7.0.7, FortiClientMac 6.4 all versions, 7.0 all versions, 7.2.0 through 7.2.4, FortiClientLinux 6.4 all versions, 7.0 all versions, 7.2.0 thro... Read more
- Published: Sep. 10, 2024
- Modified: Sep. 26, 2024
-
9.8
CRITICALCVE-2024-8277
The WooCommerce Photo Reviews Premium plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 1.3.13.2. This is due to the plugin not properly validating what user transient is being used in the login() function a... Read more
Affected Products : woocommerce_photo_reviews- Published: Sep. 11, 2024
- Modified: Sep. 26, 2024
-
5.4
MEDIUMCVE-2024-5416
The Elementor Website Builder – More than Just a Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the url parameter of multiple widgets in all versions up to, and including, 3.23.4 due to insufficient input sanitization a... Read more
Affected Products : website_builder- Published: Sep. 11, 2024
- Modified: Sep. 26, 2024
-
8.0
HIGHCVE-2024-44678
Gigastone TR1 Travel Router R101 v1.0.2 is vulnerable to Command Injection. This allows an authenticated attacker to execute arbitrary commands on the device by sending a crafted HTTP request to the ssid parameter in the request.... Read more
Affected Products :- Published: Sep. 25, 2024
- Modified: Sep. 26, 2024
-
7.5
HIGHCVE-2024-41708
An issue was discovered in AdaCore ada_web_services 20.0 allows an attacker to escalate privileges and steal sessions via the Random_String() function in the src/core/aws-utils.adb module.... Read more
Affected Products :- Published: Sep. 25, 2024
- Modified: Sep. 26, 2024
-
8.8
HIGHCVE-2024-8246
The Post Form – Registration Form – Profile Form for User Profiles – Frontend Content Forms for User Submissions (UGC) plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 2.8.11. This is due to plugin not prope... Read more
Affected Products : buddyforms- Published: Sep. 14, 2024
- Modified: Sep. 26, 2024
-
9.3
CRITICALCVE-2024-5959
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Eliz Software Panel allows Stored XSS.This issue affects Panel: before v2.3.24.... Read more
Affected Products : panel- Published: Sep. 18, 2024
- Modified: Sep. 26, 2024
-
9.1
CRITICALCVE-2019-25212
The video carousel slider with lightbox plugin for WordPress is vulnerable to SQL Injection via the 'id' parameter in all versions up to, and including, 1.0.6 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation o... Read more
Affected Products : video_carousel_slider_with_lightbox- Published: Sep. 11, 2024
- Modified: Sep. 26, 2024
-
7.6
HIGHCVE-2024-46639
A cross-site scripting (XSS) vulnerability in HelpDeskZ v2.0.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name text field of Custom Fields message box.... Read more
Affected Products :- Published: Sep. 23, 2024
- Modified: Sep. 26, 2024
-
6.1
MEDIUMCVE-2024-42697
Cross Site Scripting vulnerability in Leotheme Leo Product Search Module v.2.1.6 and earlier allows a remote attacker to execute arbitrary code via the q parameter of the product search function.... Read more
Affected Products :- Published: Sep. 20, 2024
- Modified: Sep. 26, 2024
-
9.8
CRITICALCVE-2024-45489
Arc before 2024-08-26 allows remote code execution in JavaScript boosts. Boosts that run JavaScript cannot be shared by default; however (because of misconfigured Firebase ACLs), it is possible to create or update a boost using another user's ID. This ins... Read more
Affected Products :- Published: Sep. 20, 2024
- Modified: Sep. 26, 2024
-
0.0
NACVE-2022-48945
In the Linux kernel, the following vulnerability has been resolved: media: vivid: fix compose size exceed boundary syzkaller found a bug: BUG: unable to handle page fault for address: ffffc9000a3b1000 #PF: supervisor write access in kernel mode #PF:... Read more
Affected Products : linux_kernel- Published: Sep. 23, 2024
- Modified: Sep. 26, 2024
-
9.9
CRITICALCVE-2024-9014
pgAdmin versions 8.11 and earlier are vulnerable to a security flaw in OAuth2 authentication. This vulnerability allows an attacker to potentially obtain the client ID and secret, leading to unauthorized access to user data.... Read more
Affected Products : pgadmin- Published: Sep. 23, 2024
- Modified: Sep. 26, 2024
-
7.6
HIGHCVE-2024-41228
A symlink following vulnerability in the pouch cp function of AliyunContainerService pouch v1.3.1 allows attackers to escalate privileges and write arbitrary files.... Read more
Affected Products :- Published: Sep. 23, 2024
- Modified: Sep. 26, 2024
-
8.3
HIGHCVE-2024-47061
Plate is a javascript toolkit that makes it easier for you to develop with Slate, a popular framework for building text editors. One longstanding feature of Plate is the ability to add custom DOM attributes to any element or leaf using the `attributes` pr... Read more
Affected Products : plate- Published: Sep. 20, 2024
- Modified: Sep. 26, 2024