Latest CVE Feed
-
7.3
HIGHCVE-2024-9839
The The Uix Slideshow plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 1.6.5. This is due to the software allowing users to execute an action that does not properly validate a value before running d... Read more
Affected Products :- Published: Nov. 16, 2024
- Modified: Nov. 18, 2024
-
4.3
MEDIUMCVE-2024-10533
The WP Chat App plugin for WordPress is vulnerable to unauthorized plugin installation due to a missing capability check on the ajax_install_plugin() function in all versions up to, and including, 3.6.8. This makes it possible for authenticated attackers,... Read more
Affected Products : wp_chat_app- Published: Nov. 16, 2024
- Modified: Nov. 18, 2024
-
6.1
MEDIUMCVE-2024-10883
The SimpleForm – Contact form made simple plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg & remove_query_arg without appropriate escaping on the URL in all versions up to, and including, 2.2.0. This mak... Read more
Affected Products :- Published: Nov. 16, 2024
- Modified: Nov. 18, 2024
-
4.3
MEDIUMCVE-2024-10795
The Popularis Extra plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.2.7 via the 'elementor-template' shortcode due to insufficient restrictions on which posts can be included. This makes it possible for a... Read more
Affected Products :- Published: Nov. 16, 2024
- Modified: Nov. 18, 2024
-
9.8
CRITICALCVE-2024-52411
Deserialization of Untrusted Data vulnerability in Flowcraft UX Design Studio Advanced Personalization allows Object Injection.This issue affects Advanced Personalization: from n/a through 1.1.2.... Read more
Affected Products :- Published: Nov. 16, 2024
- Modified: Nov. 18, 2024
-
7.5
HIGHCVE-2020-25720
A vulnerability was found in Samba where a delegated administrator with permission to create objects in Active Directory can write to all attributes of the newly created object, including security-sensitive attributes, even after the object's creation. Th... Read more
Affected Products : samba- Published: Nov. 17, 2024
- Modified: Nov. 18, 2024
-
6.9
MEDIUMCVE-2024-11306
A vulnerability, which was classified as critical, has been found in Altenergy Power Control Software up to 20241108. This issue affects some unknown processing of the file /index.php/display/database/. The manipulation leads to improper authorization. Th... Read more
Affected Products :- Published: Nov. 18, 2024
- Modified: Nov. 18, 2024
-
7.2
HIGHCVE-2024-50324
Path traversal in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allows a remote authenticated attacker with admin privileges to achieve remote code execution.... Read more
Affected Products : endpoint_manager- Published: Nov. 12, 2024
- Modified: Nov. 18, 2024
-
5.9
MEDIUMCVE-2024-51664
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Mark Kinchin Beds24 Online Booking allows Stored XSS.This issue affects Beds24 Online Booking: from n/a through 2.0.25.... Read more
Affected Products : online_booking- Published: Nov. 09, 2024
- Modified: Nov. 18, 2024
-
5.9
MEDIUMCVE-2024-51663
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Bricksable Bricksable for Bricks Builder allows Stored XSS.This issue affects Bricksable for Bricks Builder: from n/a through 1.6.59.... Read more
Affected Products : bricksable_for_bricks_builder- Published: Nov. 09, 2024
- Modified: Nov. 18, 2024
-
5.9
MEDIUMCVE-2024-51668
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Mark Tilly MyCurator Content Curation allows Stored XSS.This issue affects MyCurator Content Curation: from n/a through 3.78.... Read more
Affected Products : mycurator_content_curation- Published: Nov. 09, 2024
- Modified: Nov. 18, 2024
-
6.5
MEDIUMCVE-2024-51586
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in BRAFT Elementary Addons allows Stored XSS.This issue affects Elementary Addons: from n/a through 2.0.4.... Read more
Affected Products : elementary_addons- Published: Nov. 09, 2024
- Modified: Nov. 18, 2024
-
6.5
MEDIUMCVE-2024-51590
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Hoosoft Hoo Addons for Elementor allows DOM-Based XSS.This issue affects Hoo Addons for Elementor: from n/a through 1.0.6.... Read more
Affected Products : hoo_addons_for_elementor- Published: Nov. 09, 2024
- Modified: Nov. 18, 2024
-
7.2
HIGHCVE-2024-50826
A SQL Injection vulnerability was found in /admin/add_content.php in kashipara E-learning Management System Project 1.0 via the title and content parameters.... Read more
Affected Products : e-learning_management_system- Published: Nov. 14, 2024
- Modified: Nov. 18, 2024
-
7.2
HIGHCVE-2024-50825
A SQL Injection vulnerability was found in /admin/school_year.php in kashipara E-learning Management System Project 1.0 via the school_year parameter.... Read more
Affected Products : e-learning_management_system- Published: Nov. 14, 2024
- Modified: Nov. 18, 2024
-
7.2
HIGHCVE-2024-50824
A SQL Injection vulnerability was found in /admin/class.php in kashipara E-learning Management System Project 1.0 via the class_name parameter.... Read more
Affected Products : e-learning_management_system- Published: Nov. 14, 2024
- Modified: Nov. 18, 2024
-
9.8
CRITICALCVE-2024-50823
A SQL Injection vulnerability was found in /admin/login.php in kashipara E-learning Management System Project 1.0 via the username and password parameters.... Read more
Affected Products : e-learning_management_system- Published: Nov. 14, 2024
- Modified: Nov. 18, 2024
-
7.2
HIGHCVE-2024-50835
A SQL Injection vulnerability was found in /admin/edit_student.php in KASHIPARA E-learning Management System Project 1.0 via the cys, un, ln, fn, and id parameters.... Read more
Affected Products : e-learning_management_system- Published: Nov. 14, 2024
- Modified: Nov. 18, 2024
-
7.2
HIGHCVE-2024-50834
A SQL Injection was found in /admin/teachers.php in KASHIPARA E-learning Management System Project 1.0 via the firstname and lastname parameters.... Read more
Affected Products : e-learning_management_system- Published: Nov. 14, 2024
- Modified: Nov. 18, 2024
-
9.8
CRITICALCVE-2024-50833
A SQL Injection vulnerability was found in /login.php in KASHIPARA E-learning Management System Project 1.0 via the username and password parameters.... Read more
Affected Products : e-learning_management_system- Published: Nov. 14, 2024
- Modified: Nov. 18, 2024