Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 4.3

    MEDIUM
    CVE-2024-43269

    Cross-Site Request Forgery (CSRF) vulnerability in WPBackItUp Backup and Restore WordPress.This issue affects Backup and Restore WordPress: from n/a through 1.50.... Read more

    Affected Products : backup_and_restore_wordpress
    • Published: Aug. 26, 2024
    • Modified: Sep. 12, 2024
  • 8.8

    HIGH
    CVE-2024-43135

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Themewinter WPCafe allows PHP Local File Inclusion.This issue affects WPCafe: from n/a through 2.2.28.... Read more

    Affected Products : wpcafe
    • Published: Aug. 13, 2024
    • Modified: Sep. 12, 2024
  • 4.3

    MEDIUM
    CVE-2024-43265

    Cross-Site Request Forgery (CSRF) vulnerability in Analytify.This issue affects Analytify: from n/a through 5.3.1.... Read more

    • Published: Aug. 26, 2024
    • Modified: Sep. 12, 2024
  • 7.5

    HIGH
    CVE-2024-43259

    Exposure of Sensitive Information to an Unauthorized Actor vulnerability in JEM Plugins Order Export for WooCommerce.This issue affects Order Export for WooCommerce: from n/a through 3.23.... Read more

    Affected Products : order_export_for_woocommerce
    • Published: Aug. 26, 2024
    • Modified: Sep. 12, 2024
  • 7.5

    HIGH
    CVE-2024-43258

    Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Store Locator Plus.This issue affects Store Locator Plus: from n/a through 2311.17.01.... Read more

    Affected Products : store_locator_plus
    • Published: Aug. 26, 2024
    • Modified: Sep. 12, 2024
  • 8.8

    HIGH
    CVE-2024-43138

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in MagePeople Team Event Manager for WooCommerce allows PHP Local File Inclusion.This issue affects Event Manager for WooCommerce: from n/a through 4.2.1.... Read more

    • Published: Aug. 13, 2024
    • Modified: Sep. 12, 2024
  • 6.5

    MEDIUM
    CVE-2024-43257

    Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Nouthemes Leopard - WordPress offload media.This issue affects Leopard - WordPress offload media: from n/a through 2.0.36.... Read more

    Affected Products : leopard
    • Published: Aug. 26, 2024
    • Modified: Sep. 12, 2024
  • 6.4

    MEDIUM
    CVE-2024-5502

    The Piotnet Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Image Accordion, Dual Heading, and Vertical Timeline widgets in all versions up to, and including, 2.4.30 due to insufficient input sanitiz... Read more

    Affected Products : piotnet_addons
    • Published: Aug. 23, 2024
    • Modified: Sep. 12, 2024
  • 5.8

    MEDIUM
    CVE-2024-8150

    A vulnerability was found in ContiNew Admin 3.2.0 and classified as critical. Affected by this issue is the function top.continew.starter.extension.crud.controller.BaseController#page of the file /api/system/user?deptId=1&page=1&size=10. The manipulation ... Read more

    Affected Products : admin continew_admin
    • Published: Aug. 25, 2024
    • Modified: Sep. 12, 2024
  • 8.8

    HIGH
    CVE-2024-8158

    A bug in the 9p authentication implementation within lib9p allows an attacker with an existing valid user within the configured auth server to impersonate any other valid filesystem user. This is due to lib9p not properly verifying that the uname given i... Read more

    Affected Products : lib9p
    • Published: Aug. 25, 2024
    • Modified: Sep. 12, 2024
  • 9.8

    CRITICAL
    CVE-2024-8073

    Improper Input Validation vulnerability in Hillstone Networks Hillstone Networks Web Application Firewall on 5.5R6 allows Command Injection.This issue affects Hillstone Networks Web Application Firewall: from 5.5R6-2.6.7 through 5.5R6-2.8.13.... Read more

    Affected Products : web_application_firewall
    • Published: Aug. 26, 2024
    • Modified: Sep. 12, 2024
  • 7.8

    HIGH
    CVE-2024-44941

    In the Linux kernel, the following vulnerability has been resolved: f2fs: fix to cover read extent cache access with lock syzbot reports a f2fs bug as below: BUG: KASAN: slab-use-after-free in sanity_check_extent_cache+0x370/0x410 fs/f2fs/extent_cache.... Read more

    Affected Products : linux_kernel
    • Published: Aug. 26, 2024
    • Modified: Sep. 12, 2024
  • 7.5

    HIGH
    CVE-2024-7884

    When a canister method is called via ic_cdk::call* , a new Future CallFuture is created and can be awaited by the caller to get the execution result. Internally, the state of the Future is tracked and stored in a struct called CallFutureState. A bug in ... Read more

    • Published: Sep. 05, 2024
    • Modified: Sep. 12, 2024
  • 5.0

    MEDIUM
    CVE-2024-6631

    The ImageRecycle pdf & image compression plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on several AJAX actions in all versions up to, and including, 3.1.14. This makes it possible for authenticat... Read more

    • Published: Aug. 24, 2024
    • Modified: Sep. 12, 2024
  • 5.4

    MEDIUM
    CVE-2024-43412

    Xibo is an open source digital signage platform with a web content management system (CMS). Prior to version 4.1.0, a cross-site scripting vulnerability in Xibo CMS allows authorized users to execute arbitrary JavaScript via the file preview function. Use... Read more

    Affected Products : xibo
    • Published: Sep. 03, 2024
    • Modified: Sep. 12, 2024
  • 4.8

    MEDIUM
    CVE-2024-43413

    Xibo is an open source digital signage platform with a web content management system (CMS). Prior to version 4.1.0, a cross-site scripting vulnerability in Xibo CMS allows authorized users to execute JavaScript via the DataSet functionality. Users can des... Read more

    Affected Products : xibo
    • Published: Sep. 03, 2024
    • Modified: Sep. 12, 2024
  • 6.4

    MEDIUM
    CVE-2024-45389

    Pagefind, a fully static search library, initializes its dynamic JavaScript and WebAssembly files relative to the location of the first script the user loads. This information is gathered by looking up the value of `document.currentScript.src`. Prior to P... Read more

    Affected Products : pagefinder
    • Published: Sep. 03, 2024
    • Modified: Sep. 12, 2024
  • 9.8

    CRITICAL
    CVE-2024-45390

    @blakeembrey/template is a string template library. Prior to version 1.2.0, it is possible to inject and run code within the template if the attacker has access to write the template name. Version 1.2.0 contains a patch. As a workaround, don't pass untrus... Read more

    Affected Products : template
    • Published: Sep. 03, 2024
    • Modified: Sep. 12, 2024
  • 7.5

    HIGH
    CVE-2024-45391

    Tina is an open-source content management system (CMS). Sites building with Tina CMS's command line interface (CLI) prior to version 1.6.2 that use a search token may be vulnerable to the search token being leaked via lock file (tina-lock.json). Administr... Read more

    Affected Products : tinacms tina
    • Published: Sep. 03, 2024
    • Modified: Sep. 12, 2024
  • 7.5

    HIGH
    CVE-2024-42039

    Access control vulnerability in the SystemUI module Impact: Successful exploitation of this vulnerability may affect service confidentiality.... Read more

    Affected Products : emui harmonyos
    • Published: Sep. 04, 2024
    • Modified: Sep. 12, 2024
Showing 20 of 292720 Results