Latest CVE Feed
-
9.8
CRITICALCVE-2024-43141
Deserialization of Untrusted Data vulnerability in Roland Barker, xnau webdesign Participants Database allows Object Injection.This issue affects Participants Database: from n/a through 2.5.9.2.... Read more
Affected Products : participants_database- Published: Aug. 13, 2024
- Modified: Aug. 13, 2024
-
7.5
HIGHCVE-2024-43131
Incorrect Authorization vulnerability in WPWeb Docket (WooCommerce Collections / Wishlist / Watchlist) allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Docket (WooCommerce Collections / Wishlist / Watchlist): from n/a bef... Read more
Affected Products :- Published: Aug. 13, 2024
- Modified: Aug. 13, 2024
-
7.1
HIGHCVE-2024-38724
Cross-Site Request Forgery (CSRF), Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Muhammad Rehman Contact Form 7 Summary and Print allows Stored XSS.This issue affects Contact Form 7 Summary an... Read more
Affected Products :- Published: Aug. 13, 2024
- Modified: Aug. 13, 2024
-
7.5
HIGHCVE-2024-37935
Missing Authorization vulnerability in anhvnit Woocommerce OpenPos allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Woocommerce OpenPos: from n/a through 6.4.4.... Read more
Affected Products :- Published: Aug. 13, 2024
- Modified: Aug. 13, 2024
-
4.0
MEDIUMCVE-2024-7388
The WP Bannerize Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via banner alt data in all versions up to, and including, 1.9.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated att... Read more
Affected Products :- Published: Aug. 13, 2024
- Modified: Aug. 13, 2024
-
7.1
HIGHCVE-2024-43220
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in 10Web Form Builder Team Form Maker by 10Web allows Reflected XSS.This issue affects Form Maker by 10Web: from n/a through 1.15.26.... Read more
Affected Products : form_maker- Published: Aug. 12, 2024
- Modified: Aug. 13, 2024
-
7.1
HIGHCVE-2024-43233
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in BannerSky BSK Forms Blacklist allows Reflected XSS.This issue affects BSK Forms Blacklist: from n/a through 3.8.... Read more
Affected Products : bsk_forms_blacklist- Published: Aug. 12, 2024
- Modified: Aug. 13, 2024
-
6.5
MEDIUMCVE-2024-43224
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Yuri Baranov YaMaps for WordPress allows Stored XSS.This issue affects YaMaps for WordPress: from n/a through 0.6.27.... Read more
Affected Products : yamaps- Published: Aug. 12, 2024
- Modified: Aug. 13, 2024
-
5.3
MEDIUMCVE-2024-37924
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wp2speed WP2Speed Faster allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects WP2Speed Faster: from n/a through 1.0.1.... Read more
Affected Products :- Published: Aug. 12, 2024
- Modified: Aug. 13, 2024
-
6.5
MEDIUMCVE-2024-43150
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Xpro Xpro Elementor Addons allows Stored XSS.This issue affects Xpro Elementor Addons: from n/a through 1.4.4.2.... Read more
Affected Products : xpro_addons_for_elementor- Published: Aug. 12, 2024
- Modified: Aug. 13, 2024
-
5.9
MEDIUMCVE-2024-43148
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in bPlugins StreamCast allows Stored XSS.This issue affects StreamCast: from n/a through 2.2.3.... Read more
Affected Products :- Published: Aug. 12, 2024
- Modified: Aug. 13, 2024
-
6.5
MEDIUMCVE-2024-43123
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Techeshta Card Elements for Elementor allows Stored XSS.This issue affects Card Elements for Elementor: from n/a through 1.2.2.... Read more
Affected Products : card_elements_for_elementor- Published: Aug. 12, 2024
- Modified: Aug. 13, 2024
-
6.5
MEDIUMCVE-2024-43133
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Themify Themify Shortcodes allows Stored XSS.This issue affects Themify Shortcodes: from n/a through 2.1.1.... Read more
- Published: Aug. 12, 2024
- Modified: Aug. 13, 2024
-
6.5
MEDIUMCVE-2024-43216
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Patrick Posner Filr – Secure document library allows Stored XSS.This issue affects Filr – Secure document library: from n/a through 1.2.4.... Read more
Affected Products :- Published: Aug. 12, 2024
- Modified: Aug. 13, 2024
-
6.4
MEDIUMCVE-2024-2259
This vulnerability exists in InstaRISPACS software due to insufficient validation of user supplied input for the loginTo parameter in user login module of the web interface of the application. A remote attacker could exploit this vulnerability by sending ... Read more
Affected Products :- Published: Aug. 13, 2024
- Modified: Aug. 13, 2024
-
7.1
HIGHCVE-2024-43213
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in MultiVendorX WC Marketplace allows Reflected XSS.This issue affects WC Marketplace: from n/a through 4.1.17.... Read more
Affected Products : multivendorx- Published: Aug. 12, 2024
- Modified: Aug. 13, 2024
-
8.1
HIGHCVE-2024-40479
A SQL injection vulnerability in "/admin/quizquestion.php" in Kashipara Online Exam System v1.0 allows remote attackers to execute arbitrary SQL commands via the "eid" parameter.... Read more
Affected Products :- Published: Aug. 12, 2024
- Modified: Aug. 13, 2024
-
6.5
MEDIUMCVE-2024-34788
An improper authentication vulnerability in web component of EPMM prior to 12.1.0.1 allows a remote malicious user to access potentially sensitive information... Read more
Affected Products : endpoint_manager_mobile- Published: Aug. 07, 2024
- Modified: Aug. 12, 2024
-
7.7
HIGHCVE-2024-42347
matrix-react-sdk is a react-based SDK for inserting a Matrix chat/voip client into a web page. A malicious homeserver could manipulate a user's account data to cause the client to enable URL previews in end-to-end encrypted rooms, in which case any URLs ... Read more
- Published: Aug. 06, 2024
- Modified: Aug. 12, 2024
-
6.3
MEDIUMCVE-2024-41677
Qwik is a performance focused javascript framework. A potential mutation XSS vulnerability exists in Qwik for versions up to but not including 1.6.0. Qwik improperly escapes HTML on server-side rendering. It converts strings according to the rules found i... Read more
Affected Products : qwik- Published: Aug. 06, 2024
- Modified: Aug. 12, 2024