Latest CVE Feed
-
5.9
MEDIUMCVE-2024-39660
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Jordy Meow Photo Engine allows Stored XSS.This issue affects Photo Engine: from n/a through 6.3.1.... Read more
Affected Products :- Published: Aug. 01, 2024
- Modified: Aug. 02, 2024
-
6.5
MEDIUMCVE-2024-38772
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Crocoblock JetWidgets for Elementor and WooCommerce allows PHP Local File Inclusion.This issue affects JetWidgets for Elementor and WooCommerce: from n/a throu... Read more
Affected Products : jetwidgets_for_elementor- Published: Aug. 01, 2024
- Modified: Aug. 02, 2024
-
8.1
HIGHCVE-2024-41956
Soft Serve is a self-hostable Git server for the command line. Prior to 0.7.5, it is possible for a user who can commit files to a repository hosted by Soft Serve to execute arbitrary code via environment manipulation and Git. The issue is that Soft Serve... Read more
Affected Products : soft_serve- Published: Aug. 01, 2024
- Modified: Aug. 02, 2024
-
7.1
HIGHCVE-2024-38776
Cross-Site Request Forgery (CSRF) vulnerability in Martin Gibson WP GoToWebinar allows Cross-Site Scripting (XSS).This issue affects WP GoToWebinar: from n/a through 15.7.... Read more
Affected Products : gotowebinar- Published: Aug. 02, 2024
- Modified: Aug. 02, 2024
-
7.1
HIGHCVE-2024-39652
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WPWeb Elite WooCommerce PDF Vouchers allows Reflected XSS.This issue affects WooCommerce PDF Vouchers: from n/a before 4.9.5.... Read more
Affected Products :- Published: Aug. 01, 2024
- Modified: Aug. 02, 2024
-
7.1
HIGHCVE-2024-39663
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Epsiloncool WP Fast Total Search allows Stored XSS.This issue affects WP Fast Total Search: from n/a through 1.68.232.... Read more
Affected Products :- Published: Aug. 01, 2024
- Modified: Aug. 02, 2024
-
8.8
HIGHCVE-2024-39633
Improper Privilege Management vulnerability in IdeaBox PowerPack for Beaver Builder allows Privilege Escalation.This issue affects PowerPack for Beaver Builder: from n/a through 2.33.0.... Read more
Affected Products : powerpack_for_beaver_builder- Published: Aug. 01, 2024
- Modified: Aug. 02, 2024
-
7.2
HIGHCVE-2024-38775
Improper Privilege Management vulnerability in WebAppick CTX Feed allows Privilege Escalation.This issue affects CTX Feed: from n/a through 6.5.6.... Read more
Affected Products :- Published: Aug. 01, 2024
- Modified: Aug. 02, 2024
-
7.1
HIGHCVE-2024-38746
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in MakeStories Team MakeStories (for Google Web Stories) allows Path Traversal, Server Side Request Forgery.This issue affects MakeStories (for Google Web Stories... Read more
Affected Products : makestories_\(for_google_web_stories\)- Published: Aug. 01, 2024
- Modified: Aug. 02, 2024
-
6.5
MEDIUMCVE-2024-39655
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in LiquidPoll LiquidPoll – Advanced Polls for Creators and Brands.This issue affects LiquidPoll – Advanced Polls for Creators and Brands: from n/a th... Read more
Affected Products :- Published: Aug. 01, 2024
- Modified: Aug. 02, 2024
-
7.1
HIGHCVE-2024-39656
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Uncanny Owl Tin Canny Reporting for LearnDash allows Reflected XSS.This issue affects Tin Canny Reporting for LearnDash: from n/a through 4.3.0.7.... Read more
Affected Products :- Published: Aug. 01, 2024
- Modified: Aug. 02, 2024
-
8.0
HIGHCVE-2024-39621
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in CridioStudio ListingPro allows PHP Local File Inclusion.This issue affects ListingPro: from n/a through 2.9.3.... Read more
Affected Products : listingpro- Published: Aug. 01, 2024
- Modified: Aug. 02, 2024
-
5.5
MEDIUMCVE-2024-39630
Deserialization of Untrusted Data vulnerability in MotoPress Timetable and Event Schedule allows Object Injection.This issue affects Timetable and Event Schedule: from n/a through 2.4.13.... Read more
Affected Products : timetable_and_event_schedule- Published: Aug. 01, 2024
- Modified: Aug. 02, 2024
-
9.0
HIGHCVE-2024-7331
A vulnerability was found in TOTOLINK A3300R 17.0.0cu.557_B20221024 and classified as critical. Affected by this issue is the function UploadCustomModule of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument File leads to buffer overflow. The... Read more
- Published: Aug. 01, 2024
- Modified: Aug. 01, 2024
-
7.3
HIGHCVE-2024-6242
A vulnerability exists in Rockwell Automation affected products that allows a threat actor to bypass the Trusted® Slot feature in a ControlLogix® controller. If exploited on any affected module in a 1756 chassis, a threat actor could potentially execute C... Read more
Affected Products : 1756-en4tr_firmware- Published: Aug. 01, 2024
- Modified: Aug. 01, 2024
-
8.5
HIGHCVE-2024-7358
A vulnerability was found in Point B Ltd Getscreen Agent 2.19.6 on Windows. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file getscreen.msi of the component Installation. The manipulation leads to cre... Read more
Affected Products :- Published: Aug. 01, 2024
- Modified: Aug. 01, 2024
-
8.1
HIGHCVE-2024-6873
It is possible to crash or redirect the execution flow of the ClickHouse server process from an unauthenticated vector by sending a specially crafted request to the ClickHouse server native interface. This redirection is limited to what is available withi... Read more
Affected Products : clickhouse- Published: Aug. 01, 2024
- Modified: Aug. 01, 2024
-
9.6
CRITICALCVE-2024-41961
Elektra is an opinionated Openstack Dashboard for Operators and Consumers of Openstack Services. A code injection vulnerability was found in the live search functionality of the Ruby on Rails based Elektra web application. An authenticated user can craft ... Read more
Affected Products :- Published: Aug. 01, 2024
- Modified: Aug. 01, 2024
-
7.5
HIGHCVE-2024-41255
filestash v0.4 is configured to skip TLS certificate verification when using the FTPS protocol, possibly allowing attackers to execute a man-in-the-middle attack via the Init function of index.go.... Read more
Affected Products :- Published: Jul. 31, 2024
- Modified: Aug. 01, 2024
-
9.8
CRITICALCVE-2024-6695
it's possible for an attacker to gain administrative access without having any kind of account on the targeted site and perform unauthorized actions. This is due to improper logic flow on the user registration process.... Read more
Affected Products : profile_builder- Published: Jul. 31, 2024
- Modified: Aug. 01, 2024