Search Results (88132 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2024-29435 1 Alldata 1 Alldata 2025-05-07 4.1 Medium
An issue discovered in Alldata v0.4.6 allows attacker to run arbitrary commands via the processId parameter.
CVE-2024-1274 1 Joedolson 1 My Calendar 2025-05-07 5.4 Medium
The My Calendar WordPress plugin before 3.4.24 does not sanitise and escape some parameters, which could allow users with a role as low as Subscriber to perform Cross-Site Scripting attacks (depending on the permissions set by the admin)
CVE-2024-31002 2 Axiosys, Bento4 2 Bento4, Bento4 2025-05-07 9.8 Critical
Buffer Overflow vulnerability in Bento4 Bento v.1.6.0-641 allows a remote attacker to execute arbitrary code via the AP4 BitReader::ReadCache() at Ap4Utils.cpp component.
CVE-2024-10704 2 10web, Photo Gallery By 10web Wordpress 2 Photo Gallery, Photo Gallery By 10web Wordpress 2025-05-07 4.8 Medium
The Photo Gallery by 10Web WordPress plugin before 1.8.31 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
CVE-2024-10980 2 Bdthemes, Element Pack Elementor Addons Wordpress 2 Element Pack, Element Pack Elementor Addons Wordpress 2025-05-07 5.4 Medium
The Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid, Carousel and Remote Arrows) WordPress plugin before 5.10.3 does not validate and escape some of its Cookie Consent block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.
CVE-2024-10551 2 Sanil, Sticky Social Icons 2 Sticky Social Icons, Sticky Social Icons 2025-05-07 4.8 Medium
The Sticky Social Icons WordPress plugin through 1.2.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
CVE-2024-11183 2 Rumspeed, Simple Side Tab 2 Simple Side Tab, Simple Side Tab 2025-05-06 4.8 Medium
The Simple Side Tab WordPress plugin before 2.2.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
CVE-2024-9651 1 Fluentforms 1 Contact Form 2025-05-06 6.1 Medium
The Fluent Forms WordPress plugin before 5.2.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
CVE-2024-45986 2 Online Voting System Project, Projectworlds 2 Online Voting System, Online Voting System Project 2025-05-06 5.4 Medium
A stored Cross-Site Scripting (XSS) vulnerability was identified in Projectworld Online Voting System 1.0 that occurs when an account is registered with a malicious javascript payload. The payload is stored and subsequently executed in the voter.php and profile.php pages whenever the account information is accessed.
CVE-2024-0166 1 Dell 1 Unity Operating Environment 2025-05-06 7.8 High
Dell Unity, versions prior to 5.4, contains an OS Command Injection Vulnerability in its svc_tcpdump utility. An authenticated attacker could potentially exploit this vulnerability, leading to the execution of arbitrary OS commands with elevated privileges.
CVE-2023-6081 1 Chartjs Project 1 Chartjs 2025-05-06 5.4 Medium
The chartjs WordPress plugin through 2023.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
CVE-2022-3420 1 Official Integration For Billingo Project 1 Official Integration For Billingo 2025-05-06 4.8 Medium
The Official Integration for Billingo WordPress plugin before 3.4.0 does not sanitise and escape some of its settings, which could allow high privilege users with a role as low as Shop Manager to perform Stored Cross-Site Scripting attacks.
CVE-2022-3408 1 Redlettuce 1 Wp Word Count 2025-05-06 4.8 Medium
The WP Word Count WordPress plugin through 3.2.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed.
CVE-2024-45967 1 Pagekit 1 Pagekit 2025-05-06 4.7 Medium
Pagekit 1.0.18 is vulnerable to Cross Site Scripting (XSS) in index.php/admin/site/widget.
CVE-2024-0170 1 Dell 1 Unity Operating Environment 2025-05-06 7.8 High
Dell Unity, versions prior to 5.4, contains an OS Command Injection Vulnerability in its svc_cava utility. An authenticated attacker could potentially exploit this vulnerability, escaping the restricted shell and execute arbitrary operating system commands with root privileges.
CVE-2024-0167 1 Dell 1 Unity Operating Environment 2025-05-06 7.8 High
Dell Unity, versions prior to 5.4, contains an OS Command Injection Vulnerability in the svc_topstats utility. An authenticated attacker could potentially exploit this vulnerability, leading to the ability to overwrite arbitrary files on the file system with root privileges.
CVE-2024-0165 1 Dell 1 Unity Operating Environment 2025-05-06 7.8 High
Dell Unity, versions prior to 5.4, contains an OS Command Injection Vulnerability in its svc_acldb_dump utility. An authenticated attacker could potentially exploit this vulnerability, leading to execution of arbitrary operating system commands with root privileges.
CVE-2024-28150 1 Jenkins 1 Html Publisher 2025-05-06 4.7 Medium
Jenkins HTML Publisher Plugin 1.32 and earlier does not escape job names, report names, and index page titles shown as part of the report frame, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.
CVE-2024-28149 2 Jenkins, Redhat 2 Html Publisher, Ocp Tools 2025-05-06 6.5 Medium
Jenkins HTML Publisher Plugin 1.16 through 1.32 (both inclusive) does not properly sanitize input, allowing attackers with Item/Configure permission to implement cross-site scripting (XSS) attacks and to determine whether a path on the Jenkins controller file system exists.
CVE-2025-28017 1 Totolink 2 A800r, A800r Firmware 2025-05-06 6.5 Medium
TOTOLINK A800R V4.1.2cu.5032_B20200408 is vulnerable to Command Injection in downloadFile.cgi via the QUERY_STRING parameter.