CVE Notify
19.1K subscribers
4 photos
178K links
Alert on the latest CVEs

Partner channel: @malwr
Download Telegram
๐Ÿšจ CVE-2024-44043
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in 10Web Photo Gallery by 10Web allows Stored XSS.This issue affects Photo Gallery by 10Web: from n/a through 1.8.27.

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2024-44045
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Kevon Adonis WP Abstracts allows Stored XSS.This issue affects WP Abstracts: from n/a through 2.6.5.

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2024-44046
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Themify Themify โ€“ WooCommerce Product Filter allows Stored XSS.This issue affects Themify โ€“ WooCommerce Product Filter: from n/a through 1.5.1.

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2024-45246
Diebold Nixdorf โ€“ CWE-427: Uncontrolled Search Path Element

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2024-45247
Sonarr โ€“ CWE-601: URL Redirection to Untrusted Site ('Open Redirect')

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2024-45454
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates) allows Reflected XSS.This issue affects Unlimited Elements For Elementor (Free Widgets, Addons, Templates): from n/a through 1.5.121.

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2024-47297
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in CodePeople CP Polls allows Reflected XSS.This issue affects CP Polls: from n/a through 1.0.74.

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2024-47298
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in BoldThemes Bold Page Builder allows Stored XSS.This issue affects Bold Page Builder: from n/a through 5.1.1.

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2024-47299
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in SeedProd Coming Soon Page, Under Construction & Maintenance Mode by SeedProd allows Stored XSS.This issue affects Coming Soon Page, Under Construction & Maintenance Mode by SeedProd: from n/a through 6.17.4.

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2024-47300
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in CubeWP CubeWP Forms โ€“ All-in-One Form Builder allows Stored XSS.This issue affects CubeWP Forms โ€“ All-in-One Form Builder: from n/a through 1.1.1.

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2024-47301
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Bit Form Bit Form โ€“ Contact Form Plugin allows Stored XSS.This issue affects Bit Form โ€“ Contact Form Plugin: from n/a through 2.13.10.

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2024-47306
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Copy Content Protection Team Secure Copy Content Protection and Content Locking allows Stored XSS.This issue affects Secure Copy Content Protection and Content Locking: from n/a through 4.2.3.

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2024-47307
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Essential Plugin Meta slider and carousel with lightbox allows Stored XSS.This issue affects Meta slider and carousel with lightbox: from n/a through 2.0.1.

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2024-47310
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in ARI Soft ARI Fancy Lightbox allows Stored XSS.This issue affects ARI Fancy Lightbox: from n/a through 1.3.17.

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2024-44010
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Catch Themes Full frame allows Stored XSS.This issue affects Full frame: from n/a through 2.7.2.

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2024-44022
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Trustmary Review & testimonial widgets allows Stored XSS.This issue affects Review & testimonial widgets: from n/a through 1.0.5.

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2024-44024
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in NicheAddons Medical Addon for Elementor allows Stored XSS.This issue affects Medical Addon for Elementor: from n/a through 1.4.

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2024-44025
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Nicejob NiceJob allows Stored XSS.This issue affects NiceJob: from n/a before 3.6.5.

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2024-44026
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in NicheAddons Charity Addon for Elementor allows Stored XSS.This issue affects Charity Addon for Elementor: from n/a through 1.3.0.

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2024-44027
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in TemeGUM Gum Elementor Addon allows Stored XSS.This issue affects Gum Elementor Addon: from n/a through 1.3.6.

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2024-9555
A vulnerability, which was classified as critical, has been found in D-Link DIR-605L 2.13B01 BETA. Affected by this issue is the function formSetEasy_Wizard of the file /goform/formSetEasy_Wizard. The manipulation of the argument curTime leads to buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

๐ŸŽ–@cveNotify