Latest CVE Feed
-
6.4
MEDIUMCVE-2024-9304
The LocateAndFilter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.6.14 due to insufficient input sanitization and output escaping. This makes it possible for authenticated at... Read more
Affected Products :- Published: Oct. 01, 2024
- Modified: Oct. 04, 2024
-
6.4
MEDIUMCVE-2024-8324
The XO Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘get_slider’ function in all versions up to, and including, 3.8.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated ... Read more
Affected Products :- Published: Oct. 01, 2024
- Modified: Oct. 04, 2024
-
6.8
MEDIUMCVE-2024-47071
OSS Endpoint Manager is an endpoint manager module for FreePBX. OSS Endpoint Manager module activation can allow authenticated web users unauthorized access to read system files with the permissions of the webserver process. This vulnerability is fixed in... Read more
Affected Products :- Published: Oct. 01, 2024
- Modified: Oct. 04, 2024
-
6.3
MEDIUMCVE-2024-46548
TP-Link Tapo P125M and Kasa KP125M v1.0.3 was discovered to improperly validate certificates, allowing attackers to eavesdrop on communications and access sensitive information via a man-in-the-middle attack.... Read more
Affected Products :- Published: Sep. 30, 2024
- Modified: Oct. 04, 2024
-
6.1
MEDIUMCVE-2024-8727
The DK PDF plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 1.9.6. This makes it possible for unauthenticated attackers to in... Read more
Affected Products :- Published: Oct. 01, 2024
- Modified: Oct. 04, 2024
-
6.4
MEDIUMCVE-2024-8990
The Geo Mashup plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's geo_mashup_visible_posts_list shortcode in all versions up to, and including, 1.13.13 due to insufficient input sanitization and output escaping on user supp... Read more
Affected Products :- Published: Oct. 01, 2024
- Modified: Oct. 04, 2024
-
4.3
MEDIUMCVE-2024-8675
The Soumettre.fr plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the soumettre_disconnect_gateway function in all versions up to, and including, 2.1.2. This makes it possible for authenticated a... Read more
Affected Products :- Published: Oct. 01, 2024
- Modified: Oct. 04, 2024
-
4.3
MEDIUMCVE-2024-6051
Cross Application Scripting vulnerability in Vercom S.A. Redlink SDK in specific situations allows local code injection and to manipulate the view of a vulnerable application.This issue affects Redlink SDK versions through 1.13.... Read more
Affected Products :- Published: Sep. 30, 2024
- Modified: Oct. 04, 2024
-
5.6
MEDIUMCVE-2024-44610
PCAN-Ethernet Gateway FD before 1.3.0 and PCAN-Ethernet Gateway before 2.11.0 are vulnerable to Command injection via shell metacharacters in a Software Update to processing.php.... Read more
Affected Products :- Published: Oct. 01, 2024
- Modified: Oct. 04, 2024
-
6.8
MEDIUMCVE-2023-7273
Cross site request forgery in Kiteworks OwnCloud allows an unauthenticated attacker to forge requests. If a request has no Authorization header, it is created with an empty string as value by a rewrite rule. The CSRF check is done by comparing the header ... Read more
Affected Products :- Published: Oct. 01, 2024
- Modified: Oct. 04, 2024
-
6.4
MEDIUMCVE-2024-9060
The AVIF & SVG Uploader plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in version 1.1.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-lev... Read more
Affected Products : avif_uploader- Published: Oct. 01, 2024
- Modified: Oct. 04, 2024
-
5.3
MEDIUMCVE-2024-8430
The Spice Starter Sites plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the spice_starter_sites_importer_creater function in all versions up to, and including, 1.2.5. This makes it possible for ... Read more
Affected Products : spice_starter_sites- Published: Oct. 01, 2024
- Modified: Oct. 04, 2024
-
6.1
MEDIUMCVE-2024-8718
The Gravity Forms Toolbar plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'tab' parameter in all versions up to, and including, 1.7.0 due to insufficient input sanitization and output escaping. This makes it possible for unaut... Read more
Affected Products :- Published: Oct. 01, 2024
- Modified: Oct. 04, 2024
-
6.4
MEDIUMCVE-2024-8989
The Free Responsive Testimonials, Social Proof Reviews, and Customer Reviews – Stars Testimonials plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's stars_testimonials shortcode in all versions up to, and including, 3.3.1 d... Read more
Affected Products :- Published: Oct. 01, 2024
- Modified: Oct. 04, 2024
-
7.2
HIGHCVE-2024-7869
The 123.chat - Video Chat plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 1.3.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inj... Read more
Affected Products :- Published: Oct. 01, 2024
- Modified: Oct. 04, 2024
-
4.8
MEDIUMCVE-2024-46475
A reflected cross-site scripting (XSS) vulnerability on the homepage of Metronic Admin Dashboard Template v2.0 allows attackers to execute arbitrary code in the context of a user's browser via injecting a crafted payload.... Read more
Affected Products :- Published: Sep. 30, 2024
- Modified: Oct. 04, 2024
-
4.9
MEDIUMCVE-2024-0116
NVIDIA Triton Inference Server contains a vulnerability where a user may cause an out-of-bounds read issue by releasing a shared memory region while it is in use. A successful exploit of this vulnerability may lead to denial of service.... Read more
Affected Products : triton_inference_server- Published: Oct. 01, 2024
- Modified: Oct. 04, 2024
-
6.4
MEDIUMCVE-2024-8288
The Guten Post Layout – An Advanced Post Grid Collection for WordPress Gutenberg plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘align’ attribute within the 'wp:guten-post-layout/post-grid' Gutenberg block in all versions up to,... Read more
Affected Products :- Published: Oct. 01, 2024
- Modified: Oct. 04, 2024
-
6.1
MEDIUMCVE-2024-8728
The Easy Load More plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 1.0.3. This makes it possible for unauthenticated attacke... Read more
Affected Products :- Published: Oct. 01, 2024
- Modified: Oct. 04, 2024
-
5.3
MEDIUMCVE-2024-9333
Permissions bypass in M-Files Connector for Copilot before version 24.9.3 allows authenticated user to access limited amount of documents via incorrect access control list calculation... Read more
Affected Products :- Published: Oct. 02, 2024
- Modified: Oct. 04, 2024