CVE Notify
19.1K subscribers
4 photos
178K links
Alert on the latest CVEs

Partner channel: @malwr
Download Telegram
๐Ÿšจ CVE-2024-9553
A vulnerability classified as critical has been found in D-Link DIR-605L 2.13B01 BETA. This affects the function formdumpeasysetup of the file /goform/formdumpeasysetup. The manipulation of the argument curTime leads to buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2024-44041
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Martin Gibson IdeaPush allows Stored XSS.This issue affects IdeaPush: from n/a through 8.66.

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2024-44042
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Fahad Mahmood WP Datepicker allows Stored XSS.This issue affects WP Datepicker: from n/a through 2.1.1.

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2024-44043
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in 10Web Photo Gallery by 10Web allows Stored XSS.This issue affects Photo Gallery by 10Web: from n/a through 1.8.27.

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2024-44045
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Kevon Adonis WP Abstracts allows Stored XSS.This issue affects WP Abstracts: from n/a through 2.6.5.

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2024-44046
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Themify Themify โ€“ WooCommerce Product Filter allows Stored XSS.This issue affects Themify โ€“ WooCommerce Product Filter: from n/a through 1.5.1.

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2024-45246
Diebold Nixdorf โ€“ CWE-427: Uncontrolled Search Path Element

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2024-45247
Sonarr โ€“ CWE-601: URL Redirection to Untrusted Site ('Open Redirect')

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2024-45454
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates) allows Reflected XSS.This issue affects Unlimited Elements For Elementor (Free Widgets, Addons, Templates): from n/a through 1.5.121.

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2024-47297
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in CodePeople CP Polls allows Reflected XSS.This issue affects CP Polls: from n/a through 1.0.74.

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2024-47298
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in BoldThemes Bold Page Builder allows Stored XSS.This issue affects Bold Page Builder: from n/a through 5.1.1.

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2024-47299
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in SeedProd Coming Soon Page, Under Construction & Maintenance Mode by SeedProd allows Stored XSS.This issue affects Coming Soon Page, Under Construction & Maintenance Mode by SeedProd: from n/a through 6.17.4.

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2024-47300
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in CubeWP CubeWP Forms โ€“ All-in-One Form Builder allows Stored XSS.This issue affects CubeWP Forms โ€“ All-in-One Form Builder: from n/a through 1.1.1.

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2024-47301
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Bit Form Bit Form โ€“ Contact Form Plugin allows Stored XSS.This issue affects Bit Form โ€“ Contact Form Plugin: from n/a through 2.13.10.

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2024-47306
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Copy Content Protection Team Secure Copy Content Protection and Content Locking allows Stored XSS.This issue affects Secure Copy Content Protection and Content Locking: from n/a through 4.2.3.

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2024-47307
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Essential Plugin Meta slider and carousel with lightbox allows Stored XSS.This issue affects Meta slider and carousel with lightbox: from n/a through 2.0.1.

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2024-47310
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in ARI Soft ARI Fancy Lightbox allows Stored XSS.This issue affects ARI Fancy Lightbox: from n/a through 1.3.17.

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2024-44010
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Catch Themes Full frame allows Stored XSS.This issue affects Full frame: from n/a through 2.7.2.

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2024-44022
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Trustmary Review & testimonial widgets allows Stored XSS.This issue affects Review & testimonial widgets: from n/a through 1.0.5.

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2024-44024
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in NicheAddons Medical Addon for Elementor allows Stored XSS.This issue affects Medical Addon for Elementor: from n/a through 1.4.

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2024-44025
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Nicejob NiceJob allows Stored XSS.This issue affects NiceJob: from n/a before 3.6.5.

๐ŸŽ–@cveNotify