Latest CVE Feed
-
5.4
MEDIUMCVE-2025-47871
Mattermost versions 10.5.x <= 10.5.5, 9.11.x <= 9.11.15, 10.8.x <= 10.8.0, 10.7.x <= 10.7.2, 10.6.x <= 10.6.5 fail to properly validate channel membership when retrieving playbook run metadata, allowing authenticated users who are playbook members but not... Read more
Affected Products : mattermost_server- Published: Jun. 30, 2025
- Modified: Jul. 08, 2025
-
5.4
MEDIUMCVE-2025-36056
IBM System Storage Virtualization Engine TS7700 3957 VED R5.4 8.54.2.17, R6.0 8.60.0.115, 3948 VED R5.4 8.54.2.17, R6.0 8.60.0.115, and 3948 VEF R6.0 8.60.0.115 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embe... Read more
Affected Products :- Published: Jul. 01, 2025
- Modified: Jul. 03, 2025
-
5.4
MEDIUMCVE-2025-5072
Resource leak vulnerability in ASR180x、ASR190x in con_mgr allows Resource Leak Exposure.This issue affects Falcon_Linux、Kestrel、Lapwing_Linux: before v1536.... Read more
Affected Products :- Published: Jul. 01, 2025
- Modified: Jul. 03, 2025
-
5.4
MEDIUMCVE-2025-49489
Improper Resource Shutdown or Release vulnerability in ASR Falcon_Linux、Kestrel、Lapwing_Linux on Linux (con_mgr components) allows Resource Leak Exposure. This vulnerability is associated with program files con_mgr/dialer_task.C. This issue affects Fal... Read more
Affected Products :- Published: Jul. 01, 2025
- Modified: Jul. 03, 2025
-
5.4
MEDIUMCVE-2025-49481
Improper Resource Shutdown or Release vulnerability in ASR180x 、ASR190x in router modules allows Resource Leak Exposure. This vulnerability is associated with program files router/phonebook/pbwork-queue.C. This issue affects Falcon_Linux、Kestrel、Lapwing_... Read more
Affected Products :- Published: Jul. 01, 2025
- Modified: Jul. 03, 2025
-
5.4
MEDIUMCVE-2025-49482
Improper Resource Shutdown or Release vulnerability in ASR180x 、ASR190x in tr069 modules allows Resource Leak Exposure. This vulnerability is associated with program files tr069/tr098.c. This issue affects Falcon_Linux、Kestrel、Lapwing_Linux: before v1536... Read more
Affected Products :- Published: Jul. 01, 2025
- Modified: Jul. 03, 2025
-
5.4
MEDIUMCVE-2025-49483
Improper Resource Shutdown or Release vulnerability in ASR180x 、ASR190x in tr069 modules allows Resource Leak Exposure. This vulnerability is associated with program files tr069/tr069_uci.c. This issue affects Falcon_Linux、Kestrel、Lapwing_Linux: before ... Read more
Affected Products :- Published: Jul. 01, 2025
- Modified: Jul. 03, 2025
-
5.4
MEDIUMCVE-2025-46259
Missing Authorization vulnerability in POSIMYTH Innovation The Plus Addons for Elementor Pro allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects The Plus Addons for Elementor Pro: from n/a before 6.3.7.... Read more
Affected Products : the_plus_addons_for_elementor- Published: Jul. 01, 2025
- Modified: Jul. 03, 2025
-
5.4
MEDIUMCVE-2025-7112
A vulnerability was found in Portabilis i-Educar 2.9.0 and classified as problematic. This issue affects some unknown processing of the file /intranet/educar_funcao_det.php?cod_funcao=COD&ref_cod_instituicao=COD of the component Function Management Module... Read more
Affected Products : i-educar- Published: Jul. 07, 2025
- Modified: Aug. 13, 2025
-
5.4
MEDIUMCVE-2025-7133
A vulnerability classified as problematic has been found in CodeAstro Online Movie Ticket Booking System 1.0. This affects an unknown part. The manipulation leads to cross-site request forgery. It is possible to initiate the attack remotely. The exploit h... Read more
Affected Products : online_movie_ticket_booking_system- Published: Jul. 07, 2025
- Modified: Jul. 09, 2025
-
5.4
MEDIUMCVE-2025-7057
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation Mediawiki - Quiz Extension allows Stored XSS.This issue affects Mediawiki - Quiz Extension: from 1.39.X before 1.39.13, from ... Read more
Affected Products :- Published: Jul. 07, 2025
- Modified: Jul. 08, 2025
-
5.4
MEDIUMCVE-2025-53491
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation Mediawiki - FlaggedRevs Extension allows Cross-Site Scripting (XSS).This issue affects Mediawiki - FlaggedRevs Extension: fro... Read more
Affected Products :- Published: Jul. 07, 2025
- Modified: Jul. 08, 2025
-
5.4
MEDIUMCVE-2025-53497
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation Mediawiki - RelatedArticles Extension allows Stored XSS.This issue affects Mediawiki - RelatedArticles Extension: from 1.43.X... Read more
Affected Products :- Published: Jul. 07, 2025
- Modified: Jul. 08, 2025
-
5.4
MEDIUMCVE-2025-7139
A vulnerability was found in SourceCodester Best Salon Management System 1.0. It has been rated as problematic. This issue affects some unknown processing of the file /panel/edit-customer-detailed.php of the component Update Customer Details Page. The man... Read more
Affected Products : best_salon_management_system- Published: Jul. 07, 2025
- Modified: Jul. 09, 2025
-
5.4
MEDIUMCVE-2025-53478
The CheckUser extension’s Special:Investigate interface is vulnerable to reflected XSS due to improper escaping of certain internationalized system messages rendered on the “IPs and User agents” tab. This issue affects Mediawiki - CheckUser extension:... Read more
Affected Products :- Published: Jul. 07, 2025
- Modified: Jul. 08, 2025
-
5.4
MEDIUMCVE-2025-7140
A vulnerability classified as problematic has been found in SourceCodester Best Salon Management System 1.0. Affected is an unknown function of the file /panel/edit-staff.php of the component Update Staff Page. The manipulation of the argument Staff Name ... Read more
Affected Products : best_salon_management_system- Published: Jul. 07, 2025
- Modified: Jul. 09, 2025
-
5.4
MEDIUMCVE-2025-7141
A vulnerability classified as problematic was found in SourceCodester Best Salon Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /panel/edit_plan.php of the component Update Staff Page. The manipulation leads ... Read more
Affected Products : best_salon_management_system- Published: Jul. 07, 2025
- Modified: Jul. 09, 2025
-
5.4
MEDIUMCVE-2025-53496
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation Mediawiki - MediaSearch Extension allows Stored XSS.This issue affects Mediawiki - MediaSearch Extension: from 1.42.X before ... Read more
Affected Products :- Published: Jul. 07, 2025
- Modified: Jul. 08, 2025
-
5.4
MEDIUMCVE-2025-7142
A vulnerability, which was classified as problematic, has been found in SourceCodester Best Salon Management System 1.0. Affected by this issue is some unknown functionality of the file /panel/search-appointment.php. The manipulation leads to cross site s... Read more
Affected Products : best_salon_management_system- Published: Jul. 07, 2025
- Modified: Jul. 09, 2025
-
5.4
MEDIUMCVE-2025-7143
A vulnerability, which was classified as problematic, was found in SourceCodester Best Salon Management System 1.0. This affects an unknown part of the file /panel/edit-tax.php of the component Update Tax Page. The manipulation of the argument Tax Name le... Read more
Affected Products : best_salon_management_system- Published: Jul. 07, 2025
- Modified: Jul. 09, 2025