Vulnerabilities (CVE)

Total 258583 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-51671 1 Funnelkit 1 Funnelkit Checkout 2024-07-18 N/A 5.4 MEDIUM
Missing Authorization vulnerability in FunnelKit FunnelKit Checkout.This issue affects FunnelKit Checkout: from n/a through 3.10.3.
CVE-2023-51670 1 Funnelkit 1 Funnelkit Checkout 2024-07-18 N/A 4.3 MEDIUM
Missing Authorization vulnerability in FunnelKit FunnelKit Checkout.This issue affects FunnelKit Checkout: from n/a through 3.10.3.
CVE-2023-35859 1 Moderncampus 1 Omni Cms 2024-07-18 N/A 6.1 MEDIUM
A Reflected Cross-Site Scripting (XSS) vulnerability in the blog function of Modern Campus - Omni CMS 2023.1 allows a remote attacker to inject arbitrary scripts or HTML via multiple parameters.
CVE-2023-51376 1 Brainstormforce 1 Surefeedback 2024-07-18 N/A 4.3 MEDIUM
Missing Authorization vulnerability in Brainstorm Force ProjectHuddle Client Site.This issue affects ProjectHuddle Client Site: from n/a through 1.0.34.
CVE-2024-35428 1 Zkteco 1 Zkbio Cvsecurity 2024-07-18 N/A 7.1 HIGH
ZKTeco ZKBio CVSecurity 6.1.1 is vulnerable to Directory Traversal via BaseMediaFile. An authenticated user can delete local files from the server which can lead to DoS.
CVE-2024-24885 1 Levantoan 1 Woocommerce Vietnam Checkout 2024-07-18 N/A 5.4 MEDIUM
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Lê V?n To?n Woocommerce Vietnam Checkout allows Stored XSS.This issue affects Woocommerce Vietnam Checkout: from n/a through 2.0.7.
CVE-2024-35349 1 Dino Physics School Assistant Project 1 Dino Physics School Assistant 2024-07-18 N/A 9.8 CRITICAL
A vulnerability has been discovered in Diño Physics School Assistant version 2.3. The vulnerability impacts an unidentified code within the file /admin/category/view_category.php. Manipulating the argument id can result in SQL injection.
CVE-2024-35359 1 Dino Physics School Assistant Project 1 Dino Physics School Assistant 2024-07-18 N/A 9.8 CRITICAL
A vulnerability has been discovered in Diño Physics School Assistant version 2.3. The vulnerability impacts an unidentified code within the file /classes/Master.php?f=view_item. Manipulating the argument id can result in SQL injection.
CVE-2024-35429 1 Zkteco 1 Zkbio Cvsecurity 2024-07-18 N/A 6.5 MEDIUM
ZKTeco ZKBio CVSecurity 6.1.1 is vulnerable to Directory Traversal via eventRecord.
CVE-2024-34008 1 Moodle 1 Moodle 2024-07-18 N/A 8.8 HIGH
Actions in the admin management of analytics models did not include the necessary token to prevent a CSRF risk.
CVE-2024-4711 1 Connekthq 1 Ajax Load More 2024-07-18 N/A 5.4 MEDIUM
The WordPress Infinite Scroll – Ajax Load More plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ajax_load_more shortcode in versions up to, and including, 7.1.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
CVE-2024-35736 1 Themeisle 1 Visualizer 2024-07-18 N/A 8.8 HIGH
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Themeisle Visualizer.This issue affects Visualizer: from n/a through 3.11.1.
CVE-2024-35734 1 Codepeople 1 Wp Time Slots Booking Form 2024-07-18 N/A 6.1 MEDIUM
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in CodePeople WP Time Slots Booking Form allows Stored XSS.This issue affects WP Time Slots Booking Form: from n/a through 1.2.10.
CVE-2024-35733 1 Richardlerma 1 Auto Coupons For Woocommerce 2024-07-18 N/A 6.1 MEDIUM
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in RLDD Auto Coupons for WooCommerce allows Reflected XSS.This issue affects Auto Coupons for WooCommerce: from n/a through 3.0.14.
CVE-2024-35732 1 Yithemes 1 Yith Custom Login 2024-07-18 N/A 4.8 MEDIUM
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in YITH YITH Custom Login allows Stored XSS.This issue affects YITH Custom Login: from n/a through 1.7.0.
CVE-2024-5003 1 Jankarres 1 Wp Stacker 2024-07-18 N/A 5.4 MEDIUM
The WP Stacker WordPress plugin through 1.8.5 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack
CVE-2024-5953 2024-07-18 N/A 5.7 MEDIUM
A denial of service vulnerability was found in the 389-ds-base LDAP server. This issue may allow an authenticated user to cause a server denial of service while attempting to log in with a user with a malformed hash in their password.
CVE-2024-3657 2024-07-18 N/A 7.5 HIGH
A flaw was found in 389-ds-base. A specially-crafted LDAP query can potentially cause a failure on the directory server, leading to a denial of service
CVE-2024-2199 2024-07-18 N/A 5.7 MEDIUM
A denial of service vulnerability was found in 389-ds-base ldap server. This issue may allow an authenticated user to cause a server crash while modifying `userPassword` using malformed input.
CVE-2024-1062 2024-07-18 N/A 5.5 MEDIUM
A heap overflow flaw was found in 389-ds-base. This issue leads to a denial of service when writing a value larger than 256 chars in log_entry_attr.