Latest CVE Feed
-
5.4
MEDIUMCVE-2019-15706
An improper neutralization of input during web page generation in the SSL VPN portal of FortiProxy version 2.0.0, version 1.2.9 and below and FortiOS version 6.2.1 and below, version 6.0.8 and below, version 5.6.12 may allow a remote authenticated attacke... Read more
- Published: Mar. 17, 2025
- Modified: Jul. 24, 2025
- Vuln Type: Cross-Site Scripting
-
5.4
MEDIUMCVE-2025-27102
Agate is central authentication server software for OBiBa epidemiology applications. Prior to version 3.3.0, when registering for an Agate account, arbitrary HTML code can be injected into a user's first and last name. This HTML is then rendered in the em... Read more
Affected Products :- Published: Mar. 17, 2025
- Modified: Mar. 17, 2025
- Vuln Type: Cross-Site Scripting
-
5.4
MEDIUMCVE-2024-10723
A stored cross-site scripting (XSS) vulnerability was discovered in phpipam/phpipam version 1.5.2. This vulnerability allows an attacker to inject malicious scripts into the destination address field of the NAT tool, which can be executed when a user inte... Read more
Affected Products : phpipam- Published: Mar. 20, 2025
- Modified: May. 28, 2025
- Vuln Type: Cross-Site Scripting
-
5.4
MEDIUMCVE-2024-10725
A stored cross-site scripting (XSS) vulnerability exists in phpipam/phpipam version 1.5.2. This vulnerability allows an attacker to inject malicious scripts into the application, which are then executed in the context of other users who view the affected ... Read more
Affected Products : phpipam- Published: Mar. 20, 2025
- Modified: May. 28, 2025
- Vuln Type: Cross-Site Scripting
-
5.4
MEDIUMCVE-2025-26393
SolarWinds Service Desk is affected by a broken access control vulnerability. The issue allows authenticated users to escalate privileges, leading to unauthorized data manipulation.... Read more
Affected Products :- Published: Mar. 17, 2025
- Modified: Mar. 17, 2025
- Vuln Type: Authorization
-
5.4
MEDIUMCVE-2024-12871
An XSS vulnerability in infiniflow/ragflow version 0.12.0 allows an attacker to upload a malicious PDF file to the knowledge base. When the file is viewed within Ragflow, the payload is executed in the context of the user's browser. This can lead to sessi... Read more
Affected Products : ragflow- Published: Mar. 20, 2025
- Modified: Apr. 01, 2025
- Vuln Type: Cross-Site Scripting
-
5.4
MEDIUMCVE-2025-2167
The Event post plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'events_list' shortcodes in all versions up to, and including, 5.9.9 due to insufficient input sanitization and output escaping on user supplied attributes. ... Read more
Affected Products : event_post- Published: Mar. 26, 2025
- Modified: Mar. 27, 2025
- Vuln Type: Cross-Site Scripting
-
5.4
MEDIUMCVE-2025-30767
Missing Authorization vulnerability in add-ons.org PDF for WPForms allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects PDF for WPForms: from n/a through 5.3.0.... Read more
Affected Products :- Published: Mar. 27, 2025
- Modified: Mar. 27, 2025
- Vuln Type: Authorization
-
5.4
MEDIUMCVE-2025-1997
IBM UrbanCode Deploy (UCD) 7.0 through 7.0.5.25, 7.1 through 7.1.2.21, 7.2 through 7.2.3.14, and 7.3 through 7.3.2.0 / IBM DevOps Deploy 8.0 through 8.0.1.4 and 8.1 through 8.1 could allow unauthorized access to other services or potential exposure of sen... Read more
- Published: Mar. 27, 2025
- Modified: Aug. 14, 2025
- Vuln Type: Authentication
-
5.4
MEDIUMCVE-2024-55072
A Broken Object Level Authorization vulnerability in the component /api/users/{user-id} of hay-kot mealie v2.2.0 allows users to edit their own profile in order to give themselves more permissions or to change their household.... Read more
Affected Products : mealie- Published: Mar. 27, 2025
- Modified: Apr. 30, 2025
- Vuln Type: Authorization
-
5.4
MEDIUMCVE-2025-27567
Cross-site scripting vulnerability exists in the NickName registration screen of HGW-BL1500HM Ver 002.002.003 and earlier. If this vulnerability is exploited, an arbitrary script may be executed on the web browser of the user who is using the configuratio... Read more
Affected Products :- Published: Mar. 28, 2025
- Modified: Mar. 28, 2025
- Vuln Type: Cross-Site Scripting
-
5.4
MEDIUMCVE-2024-39311
Publify is a self hosted Web publishing platform on Rails. Prior to version 10.0.1 of Publify, corresponding to versions prior to 10.0.2 of the `publify_core` rubygem, publisher on a `publify` application is able to perform a cross-site scripting (XSS) at... Read more
- Published: Mar. 28, 2025
- Modified: Apr. 14, 2025
-
5.4
MEDIUMCVE-2025-31555
Missing Authorization vulnerability in ContentMX ContentMX Content Publisher allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects ContentMX Content Publisher: from n/a through 1.0.6.... Read more
Affected Products :- Published: Mar. 31, 2025
- Modified: Apr. 01, 2025
- Vuln Type: Authorization
-
5.4
MEDIUMCVE-2025-31603
Missing Authorization vulnerability in moshensky CF7 Spreadsheets allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects CF7 Spreadsheets: from n/a through 2.3.2.... Read more
Affected Products :- Published: Mar. 31, 2025
- Modified: Apr. 01, 2025
- Vuln Type: Authorization
-
5.4
MEDIUMCVE-2025-3004
A vulnerability has been found in Sayski ForestBlog up to 20250321 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /search. The manipulation of the argument keywords leads to cross site scripting. The ... Read more
Affected Products : forestblog- Published: Mar. 31, 2025
- Modified: Jun. 12, 2025
- Vuln Type: Cross-Site Scripting
-
5.4
MEDIUMCVE-2025-31757
Missing Authorization vulnerability in BinaryCarpenter Free Woocommerce Product Table View allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Free Woocommerce Product Table View: from n/a through 1.78.... Read more
Affected Products :- Published: Apr. 01, 2025
- Modified: Apr. 01, 2025
- Vuln Type: Authorization
-
5.4
MEDIUMCVE-2025-31796
Server-Side Request Forgery (SSRF) vulnerability in TheInnovs Team ElementsCSS Addons for Elementor allows Server Side Request Forgery. This issue affects ElementsCSS Addons for Elementor: from n/a through 1.0.8.7.... Read more
Affected Products :- Published: Apr. 01, 2025
- Modified: Apr. 01, 2025
- Vuln Type: Server-Side Request Forgery
-
5.4
MEDIUMCVE-2025-31867
Authorization Bypass Through User-Controlled Key vulnerability in JoomSky JS Job Manager allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects JS Job Manager: from n/a through 2.0.2.... Read more
Affected Products : js_job_manager- Published: Apr. 01, 2025
- Modified: Apr. 01, 2025
- Vuln Type: Authorization
-
5.4
MEDIUMCVE-2025-26056
A command injection vulnerability exists in the Infinxt iEdge 100 2.1.32 in the Troubleshoot module "MTR" functionality. The vulnerability is due to improper validation of user-supplied input in the mtrIp parameter. An attacker can exploit this flaw to ex... Read more
Affected Products :- Published: Apr. 01, 2025
- Modified: Apr. 14, 2025
- Vuln Type: Injection
-
5.4
MEDIUMCVE-2025-32248
Cross-Site Request Forgery (CSRF) vulnerability in SwiftXR SwiftXR (3D/AR/VR) Viewer allows Cross Site Request Forgery. This issue affects SwiftXR (3D/AR/VR) Viewer: from n/a through 1.0.7.... Read more
Affected Products :- Published: Apr. 04, 2025
- Modified: Apr. 07, 2025
- Vuln Type: Cross-Site Request Forgery