Medium
CVSS: 4.3
Yayın: 2025-01-02 15:15:19
Missing Authorization vulnerability in reputeinfosystems ARMember Premium armember allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects ARMember Premium: from n/a through
Medium
CVSS: 5.4
Yayın: 2025-01-02 15:15:18
Missing Authorization vulnerability in xtemos WoodMart woodmart allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WoodMart: from n/a through
Medium
CVSS: 5.5
Yayın: 2025-01-02 15:15:18
In the Linux kernel, the following vulnerability has been resolved:
media: s5p_cec: limit msg.len to CEC_MAX_MSG_SIZE
I expect that the hardware will have limited this to 16, but just in
case it hasn't, check for this corner case.
Medium
CVSS: 6.5
Yayın: 2025-01-02 15:15:18
Missing Authorization vulnerability in Analytify.This issue affects Analytify: from n/a through 4.2.3.
Medium
CVSS: 4.3
Yayın: 2025-01-02 15:15:18
Missing Authorization vulnerability in Daniel Söderström / Sidney van de Stouwe Subscribe to Category allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Subscribe to Category: from n/a through 2.7.4.
Medium
CVSS: 4.3
Yayın: 2025-01-02 15:15:17
Missing Authorization vulnerability in Galleryape Gallery Images Ape allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Gallery Images Ape: from n/a through 2.2.8.
Medium
CVSS: 4.3
Yayın: 2025-01-02 14:15:07
Cross-Site Request Forgery (CSRF) vulnerability in VolThemes Patricia Blog patricia-blog allows Cross Site Request Forgery.This issue affects Patricia Blog: from n/a through
Medium
CVSS: 4.3
Yayın: 2025-01-02 14:15:07
Cross-Site Request Forgery (CSRF) vulnerability in Marsian i-amaze i-amaze allows Cross Site Request Forgery.This issue affects i-amaze: from n/a through
Medium
CVSS: 4.3
Yayın: 2025-01-02 14:15:07
Cross-Site Request Forgery (CSRF) vulnerability in Creativthemes Point point allows Cross Site Request Forgery.This issue affects Point: from n/a through
Medium
CVSS: 5.4
Yayın: 2025-01-02 14:15:07
Cross-Site Request Forgery (CSRF) vulnerability in BUDDYBOSS LLC BuddyBoss Theme buddyboss-theme allows Cross Site Request Forgery.This issue affects BuddyBoss Theme: from n/a through
Medium
CVSS: 4.3
Yayın: 2025-01-02 14:15:07
Cross-Site Request Forgery (CSRF) vulnerability in MyThemeShop Schema Lite schema-lite allows Cross Site Request Forgery.This issue affects Schema Lite: from n/a through
Medium
CVSS: 5.4
Yayın: 2025-01-02 14:15:06
Cross-Site Request Forgery (CSRF) vulnerability in Uncanny Owl Uncanny Toolkit Pro for LearnDash uncanny-toolkit-pro allows Cross Site Request Forgery.This issue affects Uncanny Toolkit Pro for LearnDash: from n/a through < 4.1.4.1.
Medium
CVSS: 4.3
Yayın: 2025-01-02 14:15:06
Cross-Site Request Forgery (CSRF) vulnerability in Automattic WP Job Manager - Resume Manager wp-job-manager-resumes allows Cross Site Request Forgery.This issue affects WP Job Manager - Resume Manager: from n/a through
Medium
CVSS: 4.3
Yayın: 2025-01-02 14:15:06
Cross-Site Request Forgery (CSRF) vulnerability in fs-code FS Poster fs-poster allows Cross Site Request Forgery.This issue affects FS Poster: from n/a through
Medium
CVSS: 6.3
Yayın: 2025-01-02 14:15:06
A vulnerability classified as critical was found in Beijing Yunfan Internet Technology Yunfan Learning Examination System 1.9.2. Affected by this vulnerability is an unknown functionality of the file src/main/java/com/yf/exam/modules/sys/user/control…
Medium
CVSS: 5.3
Yayın: 2025-01-02 14:15:06
A vulnerability classified as problematic has been found in Beijing Yunfan Internet Technology Yunfan Learning Examination System 1.9.2. Affected is an unknown function of the file src/main/java/com/yf/exam/modules/paper/controller/PaperController.ja…
Medium
CVSS: 6.5
Yayın: 2025-01-02 13:15:08
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in hookandhook Post Grid Elementor Addon post-grid-elementor-addon.This issue affects Post Grid Elementor Addon: from n/a through
Medium
CVSS: 6.5
Yayın: 2025-01-02 13:15:07
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CoolPlugins Coins MarketCap coins-marketcap allows DOM-Based XSS.This issue affects Coins MarketCap: from n/a through
High
CVSS: 7.1
Yayın: 2025-01-02 13:15:07
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Markyis Cool Olivia olivia allows Reflected XSS.This issue affects Olivia: from n/a through
High
CVSS: 8.8
Yayın: 2025-01-02 13:15:07
Cross-Site Request Forgery (CSRF) vulnerability in CridioStudio ListingPro listingpro allows Authentication Bypass.This issue affects ListingPro: from n/a through