Latest CVE Feed
-
9.8
CRITICALCVE-2024-50475
Missing Authorization vulnerability in Scott Gamon Signup Page allows Privilege Escalation.This issue affects Signup Page: from n/a through 1.0.... Read more
Affected Products :- Published: Oct. 29, 2024
- Modified: Oct. 29, 2024
-
9.8
CRITICALCVE-2024-50485
: Incorrect Privilege Assignment vulnerability in Udit Rawat Exam Matrix allows Privilege Escalation.This issue affects Exam Matrix: from n/a through 1.5.... Read more
Affected Products :- Published: Oct. 29, 2024
- Modified: Oct. 29, 2024
-
8.8
HIGHCVE-2024-50481
Incorrect Privilege Assignment vulnerability in Stack Themes Bstone Demo Importer allows Privilege Escalation.This issue affects Bstone Demo Importer: from n/a through 1.0.1.... Read more
Affected Products :- Published: Oct. 29, 2024
- Modified: Oct. 29, 2024
-
9.9
CRITICALCVE-2024-50480
Unrestricted Upload of File with Dangerous Type vulnerability in azexo Marketing Automation by AZEXO allows Upload a Web Shell to a Web Server.This issue affects Marketing Automation by AZEXO: from n/a through 1.27.80.... Read more
Affected Products :- Published: Oct. 29, 2024
- Modified: Oct. 29, 2024
-
6.4
MEDIUMCVE-2024-10184
The StreamWeasels Kick Integration plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's sw-kick-embed shortcode in all versions up to, and including, 1.1.1 due to insufficient input sanitization and output escaping on user su... Read more
Affected Products :- Published: Oct. 29, 2024
- Modified: Oct. 29, 2024
-
6.4
MEDIUMCVE-2024-10185
The StreamWeasels YouTube Integration plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's sw-youtube-embed shortcode in all versions up to, and including, 1.3.2 due to insufficient input sanitization and output escaping on u... Read more
Affected Products :- Published: Oct. 29, 2024
- Modified: Oct. 29, 2024
-
10.0
CRITICALCVE-2024-50420
Unrestricted Upload of File with Dangerous Type vulnerability in adirectory aDirectory allows Upload a Web Shell to a Web Server.This issue affects aDirectory: from n/a through 1.3.... Read more
Affected Products : adirectory- Published: Oct. 29, 2024
- Modified: Oct. 29, 2024
-
7.1
HIGHCVE-2024-49678
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Jinwen js allows Reflected XSS.This issue affects js paper: from n/a through 2.5.7.... Read more
Affected Products :- Published: Oct. 29, 2024
- Modified: Oct. 29, 2024
-
10.0
CRITICALCVE-2024-50484
Unrestricted Upload of File with Dangerous Type vulnerability in mahlamusa Multi Purpose Mail Form allows Upload a Web Shell to a Web Server.This issue affects Multi Purpose Mail Form: from n/a through 1.0.2.... Read more
Affected Products :- Published: Oct. 29, 2024
- Modified: Oct. 29, 2024
-
10.0
CRITICALCVE-2024-50473
Unrestricted Upload of File with Dangerous Type vulnerability in Ajar Productions Ajar in5 Embed allows Upload a Web Shell to a Web Server.This issue affects Ajar in5 Embed: from n/a through 3.1.3.... Read more
Affected Products :- Published: Oct. 29, 2024
- Modified: Oct. 29, 2024
-
5.9
MEDIUMCVE-2024-50414
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in VirusTran Button contact VR allows Stored XSS.This issue affects Button contact VR: from n/a through 4.7.9.1.... Read more
Affected Products : call_\/_chat_\/_contact_button- Published: Oct. 29, 2024
- Modified: Oct. 29, 2024
-
7.1
HIGHCVE-2024-49647
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Carl Alberto Simple Custom Admin allows Reflected XSS.This issue affects Simple Custom Admin: from n/a through 1.2.... Read more
Affected Products :- Published: Oct. 29, 2024
- Modified: Oct. 29, 2024
-
5.1
MEDIUMCVE-2024-10478
A vulnerability, which was classified as problematic, has been found in LinZhaoguan pb-cms up to 2.0.1. This issue affects some unknown processing of the file /admin#article/edit?id=2 of the component Edit Article Handler. The manipulation leads to cross ... Read more
Affected Products : pb-cms- Published: Oct. 29, 2024
- Modified: Oct. 29, 2024
-
6.4
MEDIUMCVE-2024-9376
The Kata Plus – Addons for Elementor – Widgets, Extensions and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.4.7 due to insufficient input sanitization and output e... Read more
Affected Products :- Published: Oct. 29, 2024
- Modified: Oct. 29, 2024
-
9.8
CRITICALCVE-2024-50476
Missing Authorization vulnerability in GRÜN Software Group GmbH GRÜN spendino Spendenformular allows Privilege Escalation.This issue affects GRÜN spendino Spendenformular: from n/a through 1.0.1.... Read more
Affected Products :- Published: Oct. 29, 2024
- Modified: Oct. 29, 2024
-
4.3
MEDIUMCVE-2024-10437
The WPC Smart Messages for WooCommerce plugin for WordPress is vulnerable to unauthorized Smar Message activation/deactivation due to a missing capability check on the ajax_enable function in all versions up to, and including, 4.2.1. This makes it possibl... Read more
Affected Products :- Published: Oct. 29, 2024
- Modified: Oct. 29, 2024
-
4.3
MEDIUMCVE-2024-47401
Mattermost versions 9.10.x <= 9.10.2, 9.11.x <= 9.11.1 and 9.5.x <= 9.5.9 fail to prevent detailed error messages from being displayed in Playbooks which allows an attacker to generate a large response and cause an amplified GraphQL response which in turn... Read more
- Published: Oct. 29, 2024
- Modified: Oct. 29, 2024
-
5.9
MEDIUMCVE-2024-50413
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in codection Import and export users and customers allows Stored XSS.This issue affects Import and export users and customers: from n/a through 1.27.... Read more
Affected Products : import_and_export_users_and_customers- Published: Oct. 29, 2024
- Modified: Oct. 29, 2024
-
5.1
MEDIUMCVE-2024-10479
A vulnerability, which was classified as problematic, was found in LinZhaoguan pb-cms up to 2.0.1. Affected is an unknown function of the file /admin#themes of the component Theme Management Module. The manipulation leads to cross site scripting. It is po... Read more
Affected Products : pb-cms- Published: Oct. 29, 2024
- Modified: Oct. 29, 2024
-
5.1
MEDIUMCVE-2024-10477
A vulnerability classified as problematic was found in LinZhaoguan pb-cms up to 2.0.1. This vulnerability affects unknown code of the file /admin#permissions of the component Permission Management Page. The manipulation leads to cross site scripting. The ... Read more
Affected Products : pb-cms- Published: Oct. 29, 2024
- Modified: Oct. 29, 2024