Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 5.9

    MEDIUM
    CVE-2024-39660

    Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Jordy Meow Photo Engine allows Stored XSS.This issue affects Photo Engine: from n/a through 6.3.1.... Read more

    Affected Products :
    • Published: Aug. 01, 2024
    • Modified: Aug. 02, 2024
  • 6.5

    MEDIUM
    CVE-2024-38772

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Crocoblock JetWidgets for Elementor and WooCommerce allows PHP Local File Inclusion.This issue affects JetWidgets for Elementor and WooCommerce: from n/a throu... Read more

    Affected Products : jetwidgets_for_elementor
    • Published: Aug. 01, 2024
    • Modified: Aug. 02, 2024
  • 8.1

    HIGH
    CVE-2024-41956

    Soft Serve is a self-hostable Git server for the command line. Prior to 0.7.5, it is possible for a user who can commit files to a repository hosted by Soft Serve to execute arbitrary code via environment manipulation and Git. The issue is that Soft Serve... Read more

    Affected Products : soft_serve
    • Published: Aug. 01, 2024
    • Modified: Aug. 02, 2024
  • 7.1

    HIGH
    CVE-2024-38776

    Cross-Site Request Forgery (CSRF) vulnerability in Martin Gibson WP GoToWebinar allows Cross-Site Scripting (XSS).This issue affects WP GoToWebinar: from n/a through 15.7.... Read more

    Affected Products : gotowebinar
    • Published: Aug. 02, 2024
    • Modified: Aug. 02, 2024
  • 7.1

    HIGH
    CVE-2024-39652

    Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WPWeb Elite WooCommerce PDF Vouchers allows Reflected XSS.This issue affects WooCommerce PDF Vouchers: from n/a before 4.9.5.... Read more

    Affected Products :
    • Published: Aug. 01, 2024
    • Modified: Aug. 02, 2024
  • 7.1

    HIGH
    CVE-2024-39663

    Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Epsiloncool WP Fast Total Search allows Stored XSS.This issue affects WP Fast Total Search: from n/a through 1.68.232.... Read more

    Affected Products :
    • Published: Aug. 01, 2024
    • Modified: Aug. 02, 2024
  • 8.8

    HIGH
    CVE-2024-39633

    Improper Privilege Management vulnerability in IdeaBox PowerPack for Beaver Builder allows Privilege Escalation.This issue affects PowerPack for Beaver Builder: from n/a through 2.33.0.... Read more

    Affected Products : powerpack_for_beaver_builder
    • Published: Aug. 01, 2024
    • Modified: Aug. 02, 2024
  • 7.2

    HIGH
    CVE-2024-38775

    Improper Privilege Management vulnerability in WebAppick CTX Feed allows Privilege Escalation.This issue affects CTX Feed: from n/a through 6.5.6.... Read more

    Affected Products :
    • Published: Aug. 01, 2024
    • Modified: Aug. 02, 2024
  • 7.1

    HIGH
    CVE-2024-38746

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in MakeStories Team MakeStories (for Google Web Stories) allows Path Traversal, Server Side Request Forgery.This issue affects MakeStories (for Google Web Stories... Read more

    • Published: Aug. 01, 2024
    • Modified: Aug. 02, 2024
  • 6.5

    MEDIUM
    CVE-2024-39655

    Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in LiquidPoll LiquidPoll – Advanced Polls for Creators and Brands.This issue affects LiquidPoll – Advanced Polls for Creators and Brands: from n/a th... Read more

    Affected Products :
    • Published: Aug. 01, 2024
    • Modified: Aug. 02, 2024
  • 7.1

    HIGH
    CVE-2024-39656

    Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Uncanny Owl Tin Canny Reporting for LearnDash allows Reflected XSS.This issue affects Tin Canny Reporting for LearnDash: from n/a through 4.3.0.7.... Read more

    Affected Products :
    • Published: Aug. 01, 2024
    • Modified: Aug. 02, 2024
  • 8.0

    HIGH
    CVE-2024-39621

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in CridioStudio ListingPro allows PHP Local File Inclusion.This issue affects ListingPro: from n/a through 2.9.3.... Read more

    Affected Products : listingpro
    • Published: Aug. 01, 2024
    • Modified: Aug. 02, 2024
  • 5.5

    MEDIUM
    CVE-2024-39630

    Deserialization of Untrusted Data vulnerability in MotoPress Timetable and Event Schedule allows Object Injection.This issue affects Timetable and Event Schedule: from n/a through 2.4.13.... Read more

    Affected Products : timetable_and_event_schedule
    • Published: Aug. 01, 2024
    • Modified: Aug. 02, 2024
  • 9.0

    HIGH
    CVE-2024-7331

    A vulnerability was found in TOTOLINK A3300R 17.0.0cu.557_B20221024 and classified as critical. Affected by this issue is the function UploadCustomModule of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument File leads to buffer overflow. The... Read more

    Affected Products : a3300r_firmware a3300r
    • Published: Aug. 01, 2024
    • Modified: Aug. 01, 2024
  • 7.3

    HIGH
    CVE-2024-6242

    A vulnerability exists in Rockwell Automation affected products that allows a threat actor to bypass the Trusted® Slot feature in a ControlLogix® controller. If exploited on any affected module in a 1756 chassis, a threat actor could potentially execute C... Read more

    Affected Products : 1756-en4tr_firmware
    • Published: Aug. 01, 2024
    • Modified: Aug. 01, 2024
  • 8.5

    HIGH
    CVE-2024-7358

    A vulnerability was found in Point B Ltd Getscreen Agent 2.19.6 on Windows. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file getscreen.msi of the component Installation. The manipulation leads to cre... Read more

    Affected Products :
    • Published: Aug. 01, 2024
    • Modified: Aug. 01, 2024
  • 8.1

    HIGH
    CVE-2024-6873

    It is possible to crash or redirect the execution flow of the ClickHouse server process from an unauthenticated vector by sending a specially crafted request to the ClickHouse server native interface. This redirection is limited to what is available withi... Read more

    Affected Products : clickhouse
    • Published: Aug. 01, 2024
    • Modified: Aug. 01, 2024
  • 9.6

    CRITICAL
    CVE-2024-41961

    Elektra is an opinionated Openstack Dashboard for Operators and Consumers of Openstack Services. A code injection vulnerability was found in the live search functionality of the Ruby on Rails based Elektra web application. An authenticated user can craft ... Read more

    Affected Products :
    • Published: Aug. 01, 2024
    • Modified: Aug. 01, 2024
  • 7.5

    HIGH
    CVE-2024-41255

    filestash v0.4 is configured to skip TLS certificate verification when using the FTPS protocol, possibly allowing attackers to execute a man-in-the-middle attack via the Init function of index.go.... Read more

    Affected Products :
    • Published: Jul. 31, 2024
    • Modified: Aug. 01, 2024
  • 9.8

    CRITICAL
    CVE-2024-6695

    it's possible for an attacker to gain administrative access without having any kind of account on the targeted site and perform unauthorized actions. This is due to improper logic flow on the user registration process.... Read more

    Affected Products : profile_builder
    • Published: Jul. 31, 2024
    • Modified: Aug. 01, 2024
Showing 20 of 289973 Results