Latest CVE Feed
-
8.3
HIGHCVE-2024-42356
Shopware is an open commerce platform. Prior to versions 6.6.5.1 and 6.5.8.13, the `context` variable is injected into almost any Twig Template and allows to access to current language, currency information. The context object allows also to switch for a ... Read more
Affected Products : shopware- Published: Aug. 08, 2024
- Modified: Aug. 12, 2024
-
9.8
CRITICALCVE-2024-42357
Shopware is an open commerce platform. Prior to versions 6.6.5.1 and 6.5.8.13, the Shopware application API contains a search functionality which enables users to search through information stored within their Shopware instance. The searches performed by ... Read more
Affected Products : shopware- Published: Aug. 08, 2024
- Modified: Aug. 12, 2024
-
5.3
MEDIUMCVE-2024-41238
A SQL injection vulnerability in /smsa/student_login.php in Kashipara Responsive School Management System v1.0 allows an attacker to execute arbitrary SQL commands via the "username" parameter.... Read more
Affected Products : responsive_school_management_system- Published: Aug. 08, 2024
- Modified: Aug. 12, 2024
-
6.4
MEDIUMCVE-2024-6639
The MDx theme for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'mdx_list_item' shortcode in all versions up to, and including, 2.0.3 due to insufficient input sanitization and output escaping on user supplied attributes. This ma... Read more
Affected Products :- Published: Aug. 12, 2024
- Modified: Aug. 12, 2024
-
9.8
CRITICALCVE-2024-41476
AMTT Hotel Broadband Operation System (HiBOS) V3.0.3.151204 and before is vulnerable to SQL Injection via /manager/card/card_detail.php.... Read more
Affected Products :- Published: Aug. 12, 2024
- Modified: Aug. 12, 2024
-
7.5
HIGHCVE-2024-42010
mod_css_styles in Roundcube through 1.5.7 and 1.6.x through 1.6.7 insufficiently filters Cascading Style Sheets (CSS) token sequences in rendered e-mail messages, allowing a remote attacker to obtain sensitive information.... Read more
Affected Products : roundcube- Published: Aug. 05, 2024
- Modified: Aug. 12, 2024
-
5.3
MEDIUMCVE-2024-7414
The PDF Builder for WPForms plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 1.2.116. This is due to the plugin allowing direct access to the composer-setup.php file which has display_errors on. This makes ... Read more
Affected Products :- Published: Aug. 12, 2024
- Modified: Aug. 12, 2024
-
8.6
HIGHCVE-2024-21881
Inadequate Encryption Strength vulnerability allow an authenticated attacker to execute arbitrary OS Commands via encrypted package upload.This issue affects Envoy: 4.x and 5.x... Read more
Affected Products : envoy_firmware- Published: Aug. 12, 2024
- Modified: Aug. 12, 2024
-
5.3
MEDIUMCVE-2024-7382
The Linkify Text plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 1.9.1. This is due to the plugin utilizing bootstrap and leaving test files with display_errors on. This makes it possible for unauthenticate... Read more
Affected Products :- Published: Aug. 12, 2024
- Modified: Aug. 12, 2024
-
5.3
MEDIUMCVE-2024-5801
Enabled IP Forwarding feature in B&R Automation Runtime versions before 6.0.2 may allow remote attack-ers to compromise network security by routing IP-based packets through the host, potentially by-passing firewall, router, or NAC filtering.... Read more
Affected Products : automation_runtime- Published: Aug. 12, 2024
- Modified: Aug. 12, 2024
-
5.3
MEDIUMCVE-2024-6562
The affiliate-toolkit – WordPress Affiliate Plugin plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 3.5.5. This is due display_errors being set to true . This makes it possible for unauthenticated attackers ... Read more
Affected Products : affiliate-toolkit- Published: Aug. 12, 2024
- Modified: Aug. 12, 2024
-
4.3
MEDIUMCVE-2024-7648
The Opal Membership plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.2.4 via the private notes functionality on payments which utilizes WordPress comments. This makes it possible for authenticate... Read more
Affected Products :- Published: Aug. 12, 2024
- Modified: Aug. 12, 2024
-
6.1
MEDIUMCVE-2024-7649
The Opal Membership plugin for WordPress is vulnerable to Stored Cross-Site Scripting via checkout form fields in all versions up to, and including, 1.2.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticat... Read more
Affected Products :- Published: Aug. 12, 2024
- Modified: Aug. 12, 2024
-
8.3
HIGHCVE-2024-5800
Diffie-Hellman groups with insufficient strength are used in the SSL/TLS stack of B&R Automation Runtime versions before 6.0.2, allowing a network attacker to decrypt the SSL/TLS communication.... Read more
Affected Products : automation_runtime- Published: Aug. 12, 2024
- Modified: Aug. 12, 2024
-
5.3
MEDIUMCVE-2024-7410
The My Custom CSS PHP & ADS plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 3.3. This is due the plugin not preventing direct access to the /my-custom-css/vendor/mobiledetect/mobiledetectlib/export/exportTo... Read more
Affected Products :- Published: Aug. 12, 2024
- Modified: Aug. 12, 2024
-
4.2
MEDIUMCVE-2024-32765
A vulnerability has been reported to affect Network & Virtual Switch. If exploited, the vulnerability could allow local authenticated administrators to gain access to and execute certain functions via unspecified vectors. We have already fixed the vulner... Read more
- Published: Aug. 12, 2024
- Modified: Aug. 12, 2024
-
5.4
MEDIUMCVE-2024-7621
The Visual Website Collaboration, Feedback & Project Management – Atarim plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the process_wpfeedback_misc_options() function in all versions up to, and... Read more
- Published: Aug. 12, 2024
- Modified: Aug. 12, 2024
-
5.3
MEDIUMCVE-2024-7413
The Obfuscate Email plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 3.8.1. This is due to the plugin allowing direct access to the bootstrap.php file which has display_errors on. This makes it possible for ... Read more
Affected Products :- Published: Aug. 12, 2024
- Modified: Aug. 12, 2024
-
8.3
HIGHCVE-2024-42370
Litestar is an Asynchronous Server Gateway Interface (ASGI) framework. In versions 2.10.0 and prior, Litestar's `docs-preview.yml` workflow is vulnerable to Environment Variable injection which may lead to secret exfiltration and repository manipulation. ... Read more
Affected Products : litestar- Published: Aug. 12, 2024
- Modified: Aug. 12, 2024
-
5.3
MEDIUMCVE-2024-7416
The Reveal Template plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 3.7. This is due to the plugin allowing direct access to the bootstrap.php file which has display_errors on. This makes it possible for un... Read more
Affected Products :- Published: Aug. 12, 2024
- Modified: Aug. 12, 2024