Latest CVE Feed
-
9.8
CRITICALCVE-2024-9263
The WP Timetics- AI-powered Appointment Booking Calendar and Online Scheduling Plugin plugin for WordPress is vulnerable to Account Takeover/Privilege Escalation via Insecure Direct Object Reference in all versions up to, and including, 1.0.25 via the sav... Read more
Affected Products :- Published: Oct. 17, 2024
- Modified: Oct. 18, 2024
-
8.1
HIGHCVE-2024-48918
RDS Light is a simplified version of the Reflective Dialogue System (RDS), a self-reflecting AI framework. Versions prior to 1.1.0 contain a vulnerability that involves a lack of input validation within the RDS AI framework, specifically within the user i... Read more
Affected Products :- Published: Oct. 16, 2024
- Modified: Oct. 18, 2024
-
6.1
MEDIUMCVE-2024-9347
The The Ultimate WordPress Toolkit – WP Extended plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'wpext-export' parameter in all versions up to, and including, 3.0.9 due to insufficient input sanitization and output escaping. ... Read more
Affected Products : wp_extended- Published: Oct. 17, 2024
- Modified: Oct. 18, 2024
-
8.8
HIGHCVE-2024-9215
The Co-Authors, Multiple Authors and Guest Authors in an Author Box with PublishPress Authors plugin for WordPress is vulnerable to Insecure Direct Object Reference to Privilege Escalation/Account Takeover in all versions up to, and including, 4.7.1 via t... Read more
Affected Products :- Published: Oct. 17, 2024
- Modified: Oct. 18, 2024
-
6.6
MEDIUMCVE-2024-47887
Action Pack is a framework for handling and responding to web requests. Starting in version 4.0.0 and prior to versions 6.1.7.9, 7.0.8.5, 7.1.4.1, and 7.2.1.1, there is a possible ReDoS vulnerability in Action Controller's HTTP Token authentication. For a... Read more
Affected Products : rails- Published: Oct. 16, 2024
- Modified: Oct. 18, 2024
-
6.6
MEDIUMCVE-2024-41128
Action Pack is a framework for handling and responding to web requests. Starting in version 3.1.0 and prior to versions 6.1.7.9, 7.0.8.5, 7.1.4.1, and 7.2.1.1, there is a possible ReDoS vulnerability in the query parameter filtering routines of Action Dis... Read more
Affected Products : rails- Published: Oct. 16, 2024
- Modified: Oct. 18, 2024
-
6.1
MEDIUMCVE-2024-8719
The Flexmls® IDX Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via several parameters like 'MaxBeds' and 'MinBeds' in all versions up to, and including, 3.14.22 due to insufficient input sanitization and output escaping. This... Read more
Affected Products :- Published: Oct. 17, 2024
- Modified: Oct. 18, 2024
-
4.3
MEDIUMCVE-2024-47836
Admidio is an open-source user management solution. Prior to version 4.3.12, an unsafe deserialization vulnerability allows any unauthenticated user to execute arbitrary code on the server. Version 4.3.12 fixes this issue.... Read more
Affected Products : admidio- Published: Oct. 16, 2024
- Modified: Oct. 18, 2024
-
5.3
MEDIUMCVE-2023-32266
Untrusted Search Path vulnerability in OpenText™ Application Lifecycle Management (ALM),Quality Center allows Code Inclusion. The vulnerability allows a user to archive a malicious DLLs on the system prior to the installation. This issue affects Applic... Read more
Affected Products :- Published: Oct. 16, 2024
- Modified: Oct. 18, 2024
-
7.1
HIGHCVE-2024-48048
Cross-Site Request Forgery (CSRF) vulnerability in WSIFY – Sales can fly Wsify Widget allows Stored XSS.This issue affects Wsify Widget: from n/a through 1.0.... Read more
Affected Products :- Published: Oct. 17, 2024
- Modified: Oct. 18, 2024
-
7.5
HIGHCVE-2024-49287
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Marco Heine PDF-Rechnungsverwaltung allows PHP Local File Inclusion.This issue affects PDF-Rechnungsverwaltung: from n/a through 0.0.1.... Read more
Affected Products :- Published: Oct. 17, 2024
- Modified: Oct. 18, 2024
-
7.6
HIGHCVE-2024-49299
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Surfer allows SQL Injection.This issue affects Surfer: from n/a through 1.5.0.502.... Read more
Affected Products :- Published: Oct. 17, 2024
- Modified: Oct. 18, 2024
-
7.1
HIGHCVE-2024-49313
Cross-Site Request Forgery (CSRF) vulnerability in RudeStan VKontakte Wall Post allows Stored XSS.This issue affects VKontakte Wall Post: from n/a through 2.0.... Read more
Affected Products :- Published: Oct. 17, 2024
- Modified: Oct. 18, 2024
-
5.9
MEDIUMCVE-2024-3184
Multiple CWE-476 NULL Pointer Dereference vulnerabilities were found in GoAhead Web Server up to version 6.0.0 when compiled with the ME_GOAHEAD_REPLACE_MALLOC flag. Without a memory notifier for allocation failures, remote attackers can exploit these vul... Read more
Affected Products : goahead- Published: Oct. 17, 2024
- Modified: Oct. 18, 2024
-
7.5
HIGHCVE-2024-49317
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ZIPANG Point Maker allows PHP Local File Inclusion.This issue affects Point Maker: from n/a through 0.1.4.... Read more
Affected Products :- Published: Oct. 17, 2024
- Modified: Oct. 18, 2024
-
6.5
MEDIUMCVE-2024-49292
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Exclusive Addons Exclusive Addons Elementor allows Stored XSS.This issue affects Exclusive Addons Elementor: from n/a through 2.7.1.... Read more
Affected Products : exclusive_addons_for_elementor- Published: Oct. 17, 2024
- Modified: Oct. 18, 2024
-
6.5
MEDIUMCVE-2024-49298
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Pepro Dev. Group PeproDev Ultimate Invoice allows Stored XSS.This issue affects PeproDev Ultimate Invoice: from n/a through 2.0.6.... Read more
Affected Products : peprodev_ultimate_invoice- Published: Oct. 17, 2024
- Modified: Oct. 18, 2024
-
5.9
MEDIUMCVE-2024-3187
This issue tracks two CWE-416 Use After Free (UAF) and one CWE-415 Double Free vulnerabilities in Goahead versions <= 6.0.0. These are caused by JST values not being nulled when freed during parsing of JST templates. If the ME_GOAHEAD_JAVASCRIPT flag is e... Read more
Affected Products : goahead- Published: Oct. 17, 2024
- Modified: Oct. 18, 2024
-
6.5
MEDIUMCVE-2024-49301
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Sinan Yorulmaz G Meta Keywords allows Stored XSS.This issue affects G Meta Keywords: from n/a through 1.4.... Read more
Affected Products :- Published: Oct. 17, 2024
- Modified: Oct. 18, 2024
-
6.5
MEDIUMCVE-2024-49302
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Portfoliohub WordPress Portfolio Builder – Portfolio Gallery allows Stored XSS.This issue affects WordPress Portfolio Builder – Portfolio Gallery:... Read more
- Published: Oct. 17, 2024
- Modified: Oct. 18, 2024