Latest CVE Feed
-
6.4
MEDIUMCVE-2024-9115
The Common Tools for Site plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.0.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticat... Read more
Affected Products : common_tools_for_site- Published: Sep. 26, 2024
- Modified: Oct. 01, 2024
-
7.2
HIGHCVE-2022-4541
The WordPress Visitors plugin for WordPress is vulnerable to Stored Cross-Site Scripting via a spoofed HTTP Header value in versions up to, and including, 1.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthent... Read more
Affected Products : wordpress_visitors- Published: Sep. 26, 2024
- Modified: Oct. 01, 2024
-
5.3
MEDIUMCVE-2024-9025
The Sight – Professional Image Gallery and Portfolio plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'handler_post_title' function in all versions up to, and including, 1.1.2. This makes it possib... Read more
Affected Products : sight- Published: Sep. 26, 2024
- Modified: Oct. 01, 2024
-
6.1
MEDIUMCVE-2024-8872
The Store Hours for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 4.3.20. This makes it possible for unauthent... Read more
Affected Products : store_hours_for_woocommerce- Published: Sep. 26, 2024
- Modified: Oct. 01, 2024
-
6.4
MEDIUMCVE-2024-8861
The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 5.9.3.2 due to incorrect use of the wp_kses_allowed_html function, which allows the 'onclick' a... Read more
Affected Products : profilegrid- Published: Sep. 26, 2024
- Modified: Oct. 01, 2024
-
6.5
MEDIUMCVE-2024-9297
A vulnerability was found in SourceCodester Online Railway Reservation System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /admin/. The manipulation of the argument page with the input train... Read more
Affected Products : railway_reservation_system- Published: Sep. 28, 2024
- Modified: Oct. 01, 2024
-
5.3
MEDIUMCVE-2024-9298
A vulnerability was found in SourceCodester Online Railway Reservation System 1.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /?page=tickets of the component Ticket Handler. The manipulation of the a... Read more
Affected Products : railway_reservation_system- Published: Sep. 28, 2024
- Modified: Oct. 01, 2024
-
5.4
MEDIUMCVE-2024-9299
A vulnerability classified as problematic has been found in SourceCodester Online Railway Reservation System 1.0. This affects an unknown part of the file /?page=reserve. The manipulation of the argument First Name/Middle Name/Last Name leads to cross sit... Read more
Affected Products : railway_reservation_system- Published: Sep. 28, 2024
- Modified: Oct. 01, 2024
-
6.9
MEDIUMCVE-2024-9300
A vulnerability classified as problematic was found in SourceCodester Online Railway Reservation System 1.0. This vulnerability affects unknown code of the file contact_us.php of the component Message Us Form. The manipulation of the argument fullname/ema... Read more
Affected Products : railway_reservation_system- Published: Sep. 28, 2024
- Modified: Oct. 01, 2024
-
8.8
HIGHCVE-2024-9315
A vulnerability was found in SourceCodester Employee and Visitor Gate Pass Logging System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /admin/maintenance/manage_department.php. The manipulation of the argument... Read more
Affected Products : employee_and_visitor_gate_pass_logging_system- Published: Sep. 28, 2024
- Modified: Oct. 01, 2024
-
8.8
HIGHCVE-2024-9317
A vulnerability classified as critical was found in SourceCodester Online Eyewear Shop 1.0. Affected by this vulnerability is the function delete_category of the file /classes/Master.php?f=delete_category. The manipulation of the argument id leads to sql ... Read more
Affected Products : online_eyewear_shop- Published: Sep. 28, 2024
- Modified: Oct. 01, 2024
-
9.8
CRITICALCVE-2024-9318
A vulnerability, which was classified as critical, has been found in SourceCodester Advocate Office Management System 1.0. Affected by this issue is some unknown functionality of the file /control/activate.php. The manipulation of the argument id leads to... Read more
Affected Products : advocate_office_management_system- Published: Sep. 28, 2024
- Modified: Oct. 01, 2024
-
8.8
HIGHCVE-2024-9319
A vulnerability, which was classified as critical, was found in SourceCodester Online Timesheet App 1.0. This affects an unknown part of the file /endpoint/delete-timesheet.php. The manipulation of the argument timesheet leads to sql injection. It is poss... Read more
Affected Products : online_timesheet_app- Published: Sep. 29, 2024
- Modified: Oct. 01, 2024
-
5.4
MEDIUMCVE-2024-9320
A vulnerability has been found in SourceCodester Online Timesheet App 1.0 and classified as problematic. This vulnerability affects unknown code of the file /endpoint/add-timesheet.php of the component Add Timesheet Form. The manipulation of the argument ... Read more
Affected Products : online_timesheet_app- Published: Sep. 29, 2024
- Modified: Oct. 01, 2024
-
6.9
MEDIUMCVE-2024-9321
A vulnerability was found in SourceCodester Online Railway Reservation System 1.0 and classified as critical. This issue affects some unknown processing of the file /admin/inquiries/view_details.php. The manipulation of the argument id leads to improper a... Read more
Affected Products : railway_reservation_system- Published: Sep. 29, 2024
- Modified: Oct. 01, 2024
-
2.9
LOWCVE-2024-8443
A heap-based buffer overflow vulnerability was found in the libopensc OpenPGP driver. A crafted USB device or smart card with malicious responses to the APDUs during the card enrollment process using the `pkcs15-init` tool may lead to out-of-bound rights,... Read more
- Published: Sep. 10, 2024
- Modified: Oct. 01, 2024
-
5.4
MEDIUMCVE-2024-9323
A vulnerability was found in SourceCodester Inventory Management System 1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /app/action/add_staff.php. The manipulation leads to cross site script... Read more
- Published: Sep. 29, 2024
- Modified: Oct. 01, 2024
-
9.8
CRITICALCVE-2024-6596
An unauthenticated remote attacker can run malicious c# code included in curve files and execute commands in the users context.... Read more
- Published: Sep. 10, 2024
- Modified: Oct. 01, 2024
-
9.8
CRITICALCVE-2024-42473
OpenFGA is an authorization/permission engine. OpenFGA v1.5.7 and v1.5.8 are vulnerable to authorization bypass when calling Check API with a model that uses `but not` and `from` expressions and a userset. Users should downgrade to v1.5.6 as soon as possi... Read more
Affected Products : openfga- Published: Aug. 12, 2024
- Modified: Oct. 01, 2024
-
9.8
CRITICALCVE-2024-9296
A vulnerability was found in SourceCodester Advocate Office Management System 1.0. It has been classified as critical. Affected is an unknown function of the file /control/forgot_pass.php. The manipulation of the argument username leads to sql injection. ... Read more
Affected Products : advocate_office_management_system- Published: Sep. 28, 2024
- Modified: Oct. 01, 2024