Latest CVE Feed
-
8.8
HIGHCVE-2024-3238
The WordPress Menu Plugin — Superfly Responsive Menu plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 5.0.29. This is due to missing or incorrect nonce validation on the ajax_handle_delete_icons() func... Read more
Affected Products :- Published: Aug. 02, 2024
- Modified: Aug. 02, 2024
-
5.3
MEDIUMCVE-2024-6567
The Ebook Store plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 5.8001. This is due to the plugin utilizing fpdi-protection and not preventing direct access to test files that have display_errors set to tru... Read more
Affected Products : ebook_store- Published: Aug. 02, 2024
- Modified: Aug. 02, 2024
-
6.5
MEDIUMCVE-2024-39661
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in ExtendThemes Kubio AI Page Builder.This issue affects Kubio AI Page Builder: from n/a through 2.2.4.... Read more
Affected Products :- Published: Aug. 01, 2024
- Modified: Aug. 02, 2024
-
8.0
HIGHCVE-2023-52209
Improper Privilege Management vulnerability in WPForms, LLC. WPForms User Registration allows Privilege Escalation.This issue affects WPForms User Registration: from n/a through 2.1.0.... Read more
Affected Products :- Published: Aug. 01, 2024
- Modified: Aug. 02, 2024
-
8.8
HIGHCVE-2024-39634
Improper Privilege Management vulnerability in IdeaBox PowerPack Pro for Elementor allows Privilege Escalation.This issue affects PowerPack Pro for Elementor: from n/a through 2.10.14.... Read more
Affected Products :- Published: Aug. 01, 2024
- Modified: Aug. 02, 2024
-
7.1
HIGHCVE-2024-39656
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Uncanny Owl Tin Canny Reporting for LearnDash allows Reflected XSS.This issue affects Tin Canny Reporting for LearnDash: from n/a through 4.3.0.7.... Read more
Affected Products :- Published: Aug. 01, 2024
- Modified: Aug. 02, 2024
-
8.8
HIGHCVE-2024-39633
Improper Privilege Management vulnerability in IdeaBox PowerPack for Beaver Builder allows Privilege Escalation.This issue affects PowerPack for Beaver Builder: from n/a through 2.33.0.... Read more
Affected Products : powerpack_for_beaver_builder- Published: Aug. 01, 2024
- Modified: Aug. 02, 2024
-
6.5
MEDIUMCVE-2024-38772
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Crocoblock JetWidgets for Elementor and WooCommerce allows PHP Local File Inclusion.This issue affects JetWidgets for Elementor and WooCommerce: from n/a throu... Read more
Affected Products : jetwidgets_for_elementor- Published: Aug. 01, 2024
- Modified: Aug. 02, 2024
-
5.5
MEDIUMCVE-2024-39630
Deserialization of Untrusted Data vulnerability in MotoPress Timetable and Event Schedule allows Object Injection.This issue affects Timetable and Event Schedule: from n/a through 2.4.13.... Read more
Affected Products : timetable_and_event_schedule- Published: Aug. 01, 2024
- Modified: Aug. 02, 2024
-
8.1
HIGHCVE-2024-41956
Soft Serve is a self-hostable Git server for the command line. Prior to 0.7.5, it is possible for a user who can commit files to a repository hosted by Soft Serve to execute arbitrary code via environment manipulation and Git. The issue is that Soft Serve... Read more
Affected Products : soft_serve- Published: Aug. 01, 2024
- Modified: Aug. 02, 2024
-
6.5
MEDIUMCVE-2024-39655
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in LiquidPoll LiquidPoll – Advanced Polls for Creators and Brands.This issue affects LiquidPoll – Advanced Polls for Creators and Brands: from n/a th... Read more
Affected Products :- Published: Aug. 01, 2024
- Modified: Aug. 02, 2024
-
7.1
HIGHCVE-2024-39663
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Epsiloncool WP Fast Total Search allows Stored XSS.This issue affects WP Fast Total Search: from n/a through 1.68.232.... Read more
Affected Products :- Published: Aug. 01, 2024
- Modified: Aug. 02, 2024
-
7.1
HIGHCVE-2024-39652
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WPWeb Elite WooCommerce PDF Vouchers allows Reflected XSS.This issue affects WooCommerce PDF Vouchers: from n/a before 4.9.5.... Read more
Affected Products :- Published: Aug. 01, 2024
- Modified: Aug. 02, 2024
-
5.9
MEDIUMCVE-2024-39660
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Jordy Meow Photo Engine allows Stored XSS.This issue affects Photo Engine: from n/a through 6.3.1.... Read more
Affected Products :- Published: Aug. 01, 2024
- Modified: Aug. 02, 2024
-
8.0
HIGHCVE-2024-39621
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in CridioStudio ListingPro allows PHP Local File Inclusion.This issue affects ListingPro: from n/a through 2.9.3.... Read more
Affected Products : listingpro- Published: Aug. 01, 2024
- Modified: Aug. 02, 2024
-
8.3
HIGHCVE-2024-39636
Deserialization of Untrusted Data vulnerability in CodeSolz Better Find and Replace.This issue affects Better Find and Replace: from n/a through 1.6.1.... Read more
Affected Products :- Published: Aug. 01, 2024
- Modified: Aug. 02, 2024
-
9.8
CRITICALCVE-2024-39619
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in CridioStudio ListingPro allows PHP Local File Inclusion.This issue affects ListingPro: from n/a through 2.9.3.... Read more
Affected Products : listingpro- Published: Aug. 01, 2024
- Modified: Aug. 02, 2024
-
9.0
HIGHCVE-2024-7331
A vulnerability was found in TOTOLINK A3300R 17.0.0cu.557_B20221024 and classified as critical. Affected by this issue is the function UploadCustomModule of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument File leads to buffer overflow. The... Read more
- Published: Aug. 01, 2024
- Modified: Aug. 01, 2024
-
7.3
HIGHCVE-2024-6242
A vulnerability exists in Rockwell Automation affected products that allows a threat actor to bypass the Trusted® Slot feature in a ControlLogix® controller. If exploited on any affected module in a 1756 chassis, a threat actor could potentially execute C... Read more
Affected Products : 1756-en4tr_firmware- Published: Aug. 01, 2024
- Modified: Aug. 01, 2024
-
9.6
CRITICALCVE-2024-41961
Elektra is an opinionated Openstack Dashboard for Operators and Consumers of Openstack Services. A code injection vulnerability was found in the live search functionality of the Ruby on Rails based Elektra web application. An authenticated user can craft ... Read more
Affected Products :- Published: Aug. 01, 2024
- Modified: Aug. 01, 2024