Latest CVE Feed
-
5.9
CVSS31CVE-2025-47520
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Syed Balkhi Charitable allows Stored XSS. This issue affects Charitable: from n/a through 1.8.5.1.... Read more
Affected Products : charitable- Published: May. 07, 2025
- Modified: May. 08, 2025
-
5.9
CVSS31CVE-2025-47518
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Scott Paterson Contact Form 7 – PayPal & Stripe Add-on allows Stored XSS. This issue affects Contact Form 7 – PayPal & Stripe Add-on: from n/a through 2.... Read more
Affected Products : paypal_\&_stripe_add-on- Published: May. 07, 2025
- Modified: May. 08, 2025
-
5.8
CVSS31CVE-2025-47423
Personal Weather Station Dashboard 12_lts allows unauthenticated remote attackers to read arbitrary files via ../ directory traversal in the test parameter to /others/_test.php, as demonstrated by reading the server's private SSL key in cleartext.... Read more
Affected Products :- Published: May. 07, 2025
- Modified: May. 08, 2025
-
5.5
CVSS31CVE-2025-30102
Dell PowerScale OneFS, versions 9.4.0.0 through 9.10.1.0, contains an out-of-bounds write vulnerability. A local low privileged attacker could potentially exploit this vulnerability, leading to denial of service.... Read more
Affected Products : powerscale_onefs- Published: May. 08, 2025
- Modified: May. 08, 2025
-
5.5
CVSS31CVE-2025-47635
Server-Side Request Forgery (SSRF) vulnerability in WPWebinarSystem WebinarPress allows Server Side Request Forgery. This issue affects WebinarPress: from n/a through 1.33.27.... Read more
Affected Products : webinarpress- Published: May. 07, 2025
- Modified: May. 08, 2025
-
5.5
CVSS31CVE-2025-20213
A vulnerability in the CLI of Cisco Catalyst SD-WAN Manager, formerly Cisco SD-WAN vManage, could allow an authenticated, local attacker to overwrite arbitrary files on the local file system of an affected device. To exploit this vulnerability, the attack... Read more
Affected Products : catalyst_sd-wan_manager- Published: May. 07, 2025
- Modified: May. 08, 2025
-
5.5
CVSS31CVE-2025-47691
Improper Control of Generation of Code ('Code Injection') vulnerability in Ultimate Member Ultimate Member allows Code Injection. This issue affects Ultimate Member: from n/a through 2.10.3.... Read more
Affected Products : ultimate_member- Published: May. 07, 2025
- Modified: May. 08, 2025
-
5.4
CVSS31CVE-2025-47466
Cross-Site Request Forgery (CSRF) vulnerability in Rustaurius Ultimate WP Mail allows Cross Site Request Forgery. This issue affects Ultimate WP Mail: from n/a through 1.3.4.... Read more
Affected Products :- Published: May. 07, 2025
- Modified: May. 08, 2025
-
5.4
CVSS31CVE-2025-47472
Missing Authorization vulnerability in codepeople Music Player for WooCommerce allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Music Player for WooCommerce: from n/a through 1.5.1.... Read more
Affected Products :- Published: May. 07, 2025
- Modified: May. 08, 2025
-
5.4
CVSS31CVE-2025-47612
Missing Authorization vulnerability in flowdee ClickWhale allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects ClickWhale: from n/a through 2.4.6.... Read more
Affected Products :- Published: May. 07, 2025
- Modified: May. 08, 2025
-
5.4
CVSS31CVE-2025-47469
Missing Authorization vulnerability in slui Media Hygiene allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Media Hygiene: from n/a through 4.0.0.... Read more
Affected Products :- Published: May. 07, 2025
- Modified: May. 08, 2025
-
5.4
CVSS31CVE-2025-47473
Cross-Site Request Forgery (CSRF) vulnerability in pimwick PW WooCommerce Bulk Edit allows Cross Site Request Forgery. This issue affects PW WooCommerce Bulk Edit: from n/a through 2.134.... Read more
Affected Products :- Published: May. 07, 2025
- Modified: May. 08, 2025
-
5.4
CVSS31CVE-2025-47480
Missing Authorization vulnerability in Iqonic Design Graphina allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Graphina: from n/a through 3.0.4.... Read more
Affected Products :- Published: May. 07, 2025
- Modified: May. 08, 2025
-
5.4
CVSS31CVE-2025-20194
A vulnerability in the web-based management interface of Cisco IOS XE Software could allow an authenticated, low-privileged, remote attacker to perform an injection attack against an affected device. This vulnerability is due to insufficient input val... Read more
Affected Products : ios_xe- Published: May. 07, 2025
- Modified: May. 08, 2025
-
5.4
CVSS31CVE-2025-47526
Missing Authorization vulnerability in GS Plugins GS Variation Swatches for WooCommerce allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects GS Variation Swatches for WooCommerce: from n/a through 3.0.4.... Read more
Affected Products :- Published: May. 07, 2025
- Modified: May. 08, 2025
-
5.4
CVSS31CVE-2025-47602
Missing Authorization vulnerability in ammarahmad786 Calculate Prices based on Distance For WooCommerce allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Calculate Prices based on Distance For WooCommerce: from n/... Read more
Affected Products :- Published: May. 07, 2025
- Modified: May. 08, 2025
-
5.4
CVSS31CVE-2025-20147
A vulnerability in the web-based management interface of Cisco Catalyst SD-WAN Manager, formerly Cisco SD-WAN vManage, could allow an authenticated, remote attacker to conduct a stored cross-site scripting attack (XSS) on an affected system. This... Read more
Affected Products : catalyst_sd-wan_manager- Published: May. 07, 2025
- Modified: May. 08, 2025
-
5.4
CVSS31CVE-2025-47548
Server-Side Request Forgery (SSRF) vulnerability in Varun Dubey Wbcom Designs - Activity Link Preview For BuddyPress allows Server Side Request Forgery. This issue affects Wbcom Designs - Activity Link Preview For BuddyPress: from n/a through 1.4.4.... Read more
Affected Products :- Published: May. 07, 2025
- Modified: May. 08, 2025
-
5.4
CVSS31CVE-2025-29153
SQL Injection vulnerability in lemeconsultoria HCM galera.app v.4.58.0 allows an attacker to execute arbitrary code via the Data export, filters functions.... Read more
Affected Products :- Published: May. 07, 2025
- Modified: May. 08, 2025
-
5.4
CVSS31CVE-2025-47661
Cross-Site Request Forgery (CSRF) vulnerability in codemstory 워드프레스 결제 심플페이 allows Cross Site Request Forgery. This issue affects 워드프레스 결제 심플페이: from n/a through 5.2.11.... Read more
Affected Products :- Published: May. 07, 2025
- Modified: May. 08, 2025