Latest CVE Feed
-
7.5
HIGHCVE-2024-37930
Exposure of Sensitive Information to an Unauthorized Actor, Missing Authorization vulnerability in ThemeSphere SmartMag allows Excavation, Accessing Functionality Not Properly Constrained by ACLs.This issue affects SmartMag: from n/a through 9.3.0.... Read more
Affected Products : smartmag- Published: Aug. 12, 2024
- Modified: Sep. 12, 2024
-
5.4
MEDIUMCVE-2024-43299
Cross-Site Request Forgery (CSRF) vulnerability in Softaculous Team SpeedyCache.This issue affects SpeedyCache: from n/a through 1.1.8.... Read more
Affected Products : speedycache- Published: Aug. 26, 2024
- Modified: Sep. 12, 2024
-
8.8
HIGHCVE-2024-43129
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in WPDeveloper BetterDocs allows PHP Local File Inclusion.This issue affects BetterDocs: from n/a through 3.5.8.... Read more
Affected Products : betterdocs- Published: Aug. 13, 2024
- Modified: Sep. 12, 2024
-
4.3
MEDIUMCVE-2024-43295
Cross-Site Request Forgery (CSRF) vulnerability in Passionate Programmers B.V. WP Data Access.This issue affects WP Data Access: from n/a through 5.5.7.... Read more
Affected Products : wp_data_access- Published: Aug. 26, 2024
- Modified: Sep. 12, 2024
-
8.8
HIGHCVE-2024-43287
Cross-Site Request Forgery (CSRF) vulnerability in Brevo Newsletter, SMTP, Email marketing and Subscribe forms by Sendinblue.This issue affects Newsletter, SMTP, Email marketing and Subscribe forms by Sendinblue: from n/a through 3.1.82.... Read more
Affected Products : newsletter\,_smtp\,_email_marketing_and_subscribe- Published: Aug. 26, 2024
- Modified: Sep. 12, 2024
-
4.3
MEDIUMCVE-2024-43269
Cross-Site Request Forgery (CSRF) vulnerability in WPBackItUp Backup and Restore WordPress.This issue affects Backup and Restore WordPress: from n/a through 1.50.... Read more
Affected Products : backup_and_restore_wordpress- Published: Aug. 26, 2024
- Modified: Sep. 12, 2024
-
8.8
HIGHCVE-2024-43135
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Themewinter WPCafe allows PHP Local File Inclusion.This issue affects WPCafe: from n/a through 2.2.28.... Read more
Affected Products : wpcafe- Published: Aug. 13, 2024
- Modified: Sep. 12, 2024
-
4.3
MEDIUMCVE-2024-43265
Cross-Site Request Forgery (CSRF) vulnerability in Analytify.This issue affects Analytify: from n/a through 5.3.1.... Read more
Affected Products : analytify_-_google_analytics_dashboard- Published: Aug. 26, 2024
- Modified: Sep. 12, 2024
-
7.5
HIGHCVE-2024-43259
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in JEM Plugins Order Export for WooCommerce.This issue affects Order Export for WooCommerce: from n/a through 3.23.... Read more
Affected Products : order_export_for_woocommerce- Published: Aug. 26, 2024
- Modified: Sep. 12, 2024
-
7.5
HIGHCVE-2024-43258
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Store Locator Plus.This issue affects Store Locator Plus: from n/a through 2311.17.01.... Read more
Affected Products : store_locator_plus- Published: Aug. 26, 2024
- Modified: Sep. 12, 2024
-
8.8
HIGHCVE-2024-43138
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in MagePeople Team Event Manager for WooCommerce allows PHP Local File Inclusion.This issue affects Event Manager for WooCommerce: from n/a through 4.2.1.... Read more
Affected Products : event_manager_and_tickets_selling_for_woocommerce- Published: Aug. 13, 2024
- Modified: Sep. 12, 2024
-
6.5
MEDIUMCVE-2024-43257
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Nouthemes Leopard - WordPress offload media.This issue affects Leopard - WordPress offload media: from n/a through 2.0.36.... Read more
Affected Products : leopard- Published: Aug. 26, 2024
- Modified: Sep. 12, 2024
-
6.4
MEDIUMCVE-2024-5502
The Piotnet Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Image Accordion, Dual Heading, and Vertical Timeline widgets in all versions up to, and including, 2.4.30 due to insufficient input sanitiz... Read more
Affected Products : piotnet_addons- Published: Aug. 23, 2024
- Modified: Sep. 12, 2024
-
5.8
MEDIUMCVE-2024-8150
A vulnerability was found in ContiNew Admin 3.2.0 and classified as critical. Affected by this issue is the function top.continew.starter.extension.crud.controller.BaseController#page of the file /api/system/user?deptId=1&page=1&size=10. The manipulation ... Read more
- Published: Aug. 25, 2024
- Modified: Sep. 12, 2024
-
8.8
HIGHCVE-2024-8158
A bug in the 9p authentication implementation within lib9p allows an attacker with an existing valid user within the configured auth server to impersonate any other valid filesystem user. This is due to lib9p not properly verifying that the uname given i... Read more
Affected Products : lib9p- Published: Aug. 25, 2024
- Modified: Sep. 12, 2024
-
9.8
CRITICALCVE-2024-8073
Improper Input Validation vulnerability in Hillstone Networks Hillstone Networks Web Application Firewall on 5.5R6 allows Command Injection.This issue affects Hillstone Networks Web Application Firewall: from 5.5R6-2.6.7 through 5.5R6-2.8.13.... Read more
Affected Products : web_application_firewall- Published: Aug. 26, 2024
- Modified: Sep. 12, 2024
-
7.8
HIGHCVE-2024-44941
In the Linux kernel, the following vulnerability has been resolved: f2fs: fix to cover read extent cache access with lock syzbot reports a f2fs bug as below: BUG: KASAN: slab-use-after-free in sanity_check_extent_cache+0x370/0x410 fs/f2fs/extent_cache.... Read more
Affected Products : linux_kernel- Published: Aug. 26, 2024
- Modified: Sep. 12, 2024
-
7.5
HIGHCVE-2024-7884
When a canister method is called via ic_cdk::call* , a new Future CallFuture is created and can be awaited by the caller to get the execution result. Internally, the state of the Future is tracked and stored in a struct called CallFutureState. A bug in ... Read more
Affected Products : canister_developer_kit_for_the_internet_computer- Published: Sep. 05, 2024
- Modified: Sep. 12, 2024
-
5.0
MEDIUMCVE-2024-6631
The ImageRecycle pdf & image compression plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on several AJAX actions in all versions up to, and including, 3.1.14. This makes it possible for authenticat... Read more
Affected Products : imagerecycle_pdf_\&_image_compression- Published: Aug. 24, 2024
- Modified: Sep. 12, 2024
-
5.4
MEDIUMCVE-2024-43412
Xibo is an open source digital signage platform with a web content management system (CMS). Prior to version 4.1.0, a cross-site scripting vulnerability in Xibo CMS allows authorized users to execute arbitrary JavaScript via the file preview function. Use... Read more
Affected Products : xibo- Published: Sep. 03, 2024
- Modified: Sep. 12, 2024