Latest CVE Feed
-
4.3
MEDIUMCVE-2025-32201
Missing Authorization vulnerability in Xpro Xpro Theme Builder allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Xpro Theme Builder: from n/a through 1.2.8.3.... Read more
Affected Products :- Published: Apr. 04, 2025
- Modified: Apr. 07, 2025
- Vuln Type: Authorization
-
4.3
MEDIUMCVE-2024-6824
The Premium Addons for Elementor plugin for WordPress is vulnerable to unauthorized modification and loss of data due to a missing capability check on the 'check_temp_validity' and 'update_template_title' functions in all versions up to, and including, 4.... Read more
Affected Products : premium_addons_for_elementor- Published: Aug. 08, 2024
- Modified: Jan. 08, 2025
-
4.3
MEDIUMCVE-2025-39425
Cross-Site Request Forgery (CSRF) vulnerability in pixelgrade Style Manager allows Cross Site Request Forgery. This issue affects Style Manager: from n/a through 2.2.7.... Read more
Affected Products :- Published: Apr. 17, 2025
- Modified: Apr. 17, 2025
-
4.3
MEDIUMCVE-2025-32227
Authentication Bypass by Spoofing vulnerability in Asgaros Asgaros Forum allows Identity Spoofing. This issue affects Asgaros Forum: from n/a through 3.0.0.... Read more
Affected Products : asgaros_forum- Published: Apr. 10, 2025
- Modified: Apr. 11, 2025
- Vuln Type: Authentication
-
4.3
MEDIUMCVE-2025-3880
The Poll, Survey & Quiz Maker Plugin by Opinion Stage plugin for WordPress is vulnerable to unauthorized modification of data due to a misconfigured capability check on several functions in all versions up to, and including, 19.9.0. This makes it possible... Read more
Affected Products : poll\,_survey_\&_quiz_maker- Published: Jun. 17, 2025
- Modified: Jul. 09, 2025
- Vuln Type: Authorization
-
4.3
MEDIUMCVE-2025-32791
The Backstage Scaffolder plugin houses types and utilities for building scaffolder-related modules. A vulnerability in the Backstage permission plugin backend allows callers to extract some information about the conditional decisions returned by the permi... Read more
Affected Products : backstage- Published: Apr. 16, 2025
- Modified: Apr. 17, 2025
- Vuln Type: Information Disclosure
-
4.3
MEDIUMCVE-2024-22316
IBM Sterling File Gateway 6.0.0.0 through 6.1.2.5 and 6.2.0.0 through 6.2.0.1 could allow an authenticated user to perform unauthorized actions to another user's data due to improper access controls.... Read more
Affected Products : sterling_file_gateway- Published: Jan. 27, 2025
- Modified: Jan. 27, 2025
- Vuln Type: Authorization
-
4.3
MEDIUMCVE-2025-32269
Cross-Site Request Forgery (CSRF) vulnerability in CRM Perks WP Zendesk for Contact Form 7, WPForms, Elementor, Formidable and Ninja Forms allows Cross Site Request Forgery. This issue affects WP Zendesk for Contact Form 7, WPForms, Elementor, Formidable ... Read more
Affected Products :- Published: Apr. 04, 2025
- Modified: Apr. 07, 2025
- Vuln Type: Cross-Site Request Forgery
-
4.3
MEDIUMCVE-2024-6857
The WP MultiTasking WordPress plugin through 0.1.12 does not have CSRF check when updating its Header, Footer and Body Script Settings, which could allow attackers to make logged admins perform such action via a CSRF attack... Read more
Affected Products : wp_multitasking- Published: Apr. 09, 2025
- Modified: Apr. 22, 2025
- Vuln Type: Cross-Site Request Forgery
-
4.3
MEDIUMCVE-2025-2197
Browser is affected by type confusion vulnerability, successful exploitation of this vulnerability may affect service availability.... Read more
Affected Products : baidu- Published: Apr. 17, 2025
- Modified: Jul. 11, 2025
- Vuln Type: Denial of Service
-
4.3
MEDIUMCVE-2025-36625
In Nessus versions prior to 10.8.4, a non-authenticated attacker could alter Nessus logging entries by manipulating http requests to the application.... Read more
Affected Products : nessus- Published: Apr. 18, 2025
- Modified: Apr. 21, 2025
- Vuln Type: Authentication
-
4.3
MEDIUMCVE-2024-6685
An issue was discovered in GitLab CE/EE affecting all versions starting from 16.7 prior to 17.1.7, 17.2 prior to 17.2.5, and 17.3 prior to 17.3.2, where group runners information was disclosed to unauthorised group members.... Read more
Affected Products : gitlab- Published: Sep. 16, 2024
- Modified: Sep. 24, 2024
-
4.3
MEDIUMCVE-2025-2104
The Page Builder: Pagelayer – Drag and Drop website builder plugin for WordPress is vulnerable to unauthorized post publication due to insufficient validation on the pagelayer_save_content() function in all versions up to, and including, 1.9.8. This makes... Read more
Affected Products : pagelayer- Published: Mar. 13, 2025
- Modified: May. 26, 2025
- Vuln Type: Authorization
-
4.3
MEDIUMCVE-2025-39351
Cross-Site Request Forgery (CSRF) vulnerability in ThemeGoods Grand Restaurant WordPress allows Cross Site Request Forgery.This issue affects Grand Restaurant WordPress: from n/a through 7.0.... Read more
Affected Products : grand_restaurant- Published: May. 19, 2025
- Modified: May. 21, 2025
- Vuln Type: Cross-Site Request Forgery
-
4.3
MEDIUMCVE-2024-52813
matrix-rust-sdk is an implementation of a Matrix client-server library in Rust. Versions of the matrix-sdk-crypto Rust crate before 0.8.0 lack a dedicated mechanism to notify that a user's cryptographic identity has changed from a verified to an unverifie... Read more
Affected Products : matrix-rust-sdk- Published: Jan. 07, 2025
- Modified: Jan. 07, 2025
- Vuln Type: Misconfiguration
-
4.3
MEDIUMCVE-2002-1893
Cross-site scripting (XSS) vulnerability in ArGoSoft Mail Server Pro 1.8.1.9 allows remote attackers to inject arbitrary web script or HTML via the e-mail message.... Read more
Affected Products : argosoft_mail_server- Published: Dec. 31, 2002
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2025-25045
IBM InfoSphere Information 11.7 Server authenticated user to obtain sensitive information when a detailed technical error message is returned in a request. This information could be used in further attacks against the system.... Read more
- Published: Apr. 23, 2025
- Modified: Jul. 08, 2025
- Vuln Type: Information Disclosure
-
4.3
MEDIUMCVE-2025-25143
Cross-Site Request Forgery (CSRF) vulnerability in ibasit GlobalQuran allows Cross Site Request Forgery. This issue affects GlobalQuran: from n/a through 1.0.... Read more
Affected Products :- Published: Feb. 07, 2025
- Modified: Feb. 07, 2025
- Vuln Type: Cross-Site Request Forgery
-
4.3
MEDIUMCVE-2025-36599
Dell PowerFlex Manager VM, versions prior to 4.6.2.1, contains an Insertion of Sensitive Information into Log File vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to the disclosure of certa... Read more
Affected Products :- Published: Jul. 09, 2025
- Modified: Jul. 10, 2025
- Vuln Type: Information Disclosure
-
4.3
MEDIUMCVE-2025-36026
IBM Datacap 9.1.7, 9.1.8, and 9.1.9 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user goes to. The... Read more
- Published: Jun. 28, 2025
- Modified: Jul. 01, 2025
- Vuln Type: Authentication