Latest CVE Feed
-
4.3
MEDIUMCVE-2024-31419
An information disclosure flaw was found in OpenShift Virtualization. The DownwardMetrics feature was introduced to expose host metrics to virtual machine guests and is enabled by default. This issue could expose limited host metrics of a node to any gues... Read more
Affected Products :- Published: Apr. 03, 2024
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2025-53669
Jenkins VAddy Plugin 1.2.8 and earlier does not mask Vaddy API Auth Keys displayed on the job configuration form, increasing the potential for attackers to observe and capture them.... Read more
Affected Products : vaddy- Published: Jul. 09, 2025
- Modified: Jul. 18, 2025
- Vuln Type: Information Disclosure
-
4.3
MEDIUMCVE-2025-30467
The issue was addressed with improved checks. This issue is fixed in Safari 18.4, iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4. Visiting a malicious website may lead to address bar spoofing.... Read more
- Published: Mar. 31, 2025
- Modified: Apr. 04, 2025
-
4.3
MEDIUMCVE-2024-22155
Cross-Site Request Forgery (CSRF) vulnerability in Automattic WooCommerce.This issue affects WooCommerce: from n/a through 8.5.2. ... Read more
Affected Products : woocommerce- Published: Apr. 07, 2024
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2025-53657
Jenkins ReadyAPI Functional Testing Plugin 1.11 and earlier does not mask SLM License Access Keys, client secrets, and passwords displayed on the job configuration form, increasing the potential for attackers to observe and capture them.... Read more
Affected Products : readyapi_functional_testing- Published: Jul. 09, 2025
- Modified: Jul. 18, 2025
- Vuln Type: Information Disclosure
-
4.3
MEDIUMCVE-2024-0872
The Watu Quiz plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.4.1 via the watu-userinfo shortcode. This makes it possible for authenticated attackers, with contributor-level access and above, to... Read more
Affected Products : watu_quiz- Published: Apr. 09, 2024
- Modified: Aug. 26, 2025
-
4.3
MEDIUMCVE-2025-30881
Missing Authorization vulnerability in ThemeHunk Big Store allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Big Store: from n/a through 2.0.8.... Read more
Affected Products :- Published: Mar. 27, 2025
- Modified: Mar. 27, 2025
- Vuln Type: Authorization
-
4.3
MEDIUMCVE-2024-6352
A malformed packet can cause a buffer overflow in the APS layer of the Ember ZNet stack and lead to an assert... Read more
Affected Products :- Published: Jan. 13, 2025
- Modified: Aug. 27, 2025
- Vuln Type: Memory Corruption
-
4.3
MEDIUMCVE-2025-30874
Missing Authorization vulnerability in Jose Specific Content For Mobile allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Specific Content For Mobile: from n/a through 0.5.3.... Read more
Affected Products :- Published: Mar. 27, 2025
- Modified: Mar. 27, 2025
- Vuln Type: Authorization
-
4.3
MEDIUMCVE-2025-53665
Jenkins Apica Loadtest Plugin 1.10 and earlier does not mask Apica Loadtest LTP authentication tokens displayed on the job configuration form, increasing the potential for attackers to observe and capture them.... Read more
Affected Products : apica_loadtest- Published: Jul. 09, 2025
- Modified: Jul. 18, 2025
- Vuln Type: Information Disclosure
-
4.3
MEDIUMCVE-2025-7822
The WP Wallcreeper plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the admin_notices hook in all versions up to, and including, 1.6.1. This makes it possible for authenticated attackers, with Su... Read more
Affected Products :- Published: Jul. 24, 2025
- Modified: Jul. 25, 2025
- Vuln Type: Authorization
-
4.3
MEDIUMCVE-2025-6434
The exception page for the HTTPS-Only feature, displayed when a website is opened via HTTP, lacked an anti-clickjacking delay, potentially allowing an attacker to trick a user into granting an exception and loading a webpage over HTTP. This vulnerability ... Read more
- Published: Jun. 24, 2025
- Modified: Jul. 14, 2025
- Vuln Type: Misconfiguration
-
4.3
MEDIUMCVE-2025-6425
An attacker who enumerated resources from the WebCompat extension could have obtained a persistent UUID that identified the browser, and persisted between containers and normal/private browsing mode, but not profiles. This vulnerability affects Firefox < ... Read more
- Published: Jun. 24, 2025
- Modified: Jul. 03, 2025
- Vuln Type: Information Disclosure
-
4.3
MEDIUMCVE-2025-25026
IBM Security Guardium 12.0 could allow an authenticated user to obtain sensitive information due to an incorrect authentication check.... Read more
Affected Products : security_guardium- Published: May. 28, 2025
- Modified: Jun. 04, 2025
- Vuln Type: Authentication
-
4.3
MEDIUMCVE-2025-30851
Missing Authorization vulnerability in Tickera Tickera allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Tickera: from n/a through 3.5.5.2.... Read more
Affected Products :- Published: Mar. 27, 2025
- Modified: Mar. 27, 2025
- Vuln Type: Authorization
-
4.3
MEDIUMCVE-2025-0951
Multiple plugins and/or themes for WordPress by LiquidThemes are vulnerable to unauthorized access due to a missing capability check on the liquid_reset_wordpress_before AJAX in various versions. This makes it possible for authenticated attackers, with Su... Read more
Affected Products :- Published: Aug. 28, 2025
- Modified: Aug. 29, 2025
- Vuln Type: Authorization
-
4.3
MEDIUMCVE-2025-5925
The Bunny’s Print CSS plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 0.95. This is due to missing or incorrect nonce validation on the pcss_options_subpanel() function. This makes it possible for una... Read more
Affected Products :- Published: Jun. 10, 2025
- Modified: Jun. 12, 2025
- Vuln Type: Cross-Site Request Forgery
-
4.3
MEDIUMCVE-2025-45525
A NULL pointer dereference vulnerability has been identified in the JavaScript library microlight version 0.0.7, a lightweight syntax highlighting library. When processing elements with non-standard CSS color values, the library fails to validate the resu... Read more
Affected Products :- Published: Jun. 17, 2025
- Modified: Aug. 26, 2025
- Vuln Type: Denial of Service
-
4.3
MEDIUMCVE-2025-6059
The Seraphinite Accelerator plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.27.21. This is due to missing or incorrect nonce validation on the 'OnAdminApi_CacheOpBegin' function. This makes it possi... Read more
Affected Products : seraphinite_accelerator- Published: Jun. 14, 2025
- Modified: Jun. 16, 2025
- Vuln Type: Cross-Site Request Forgery
-
4.3
MEDIUMCVE-2025-5816
The Plugin Pengiriman WooCommerce Kurir Reguler, Instan, Kargo – Biteship plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 3.2.0 via the get_order_detail() due to missing validation on a user con... Read more
Affected Products :- Published: Jul. 18, 2025
- Modified: Jul. 22, 2025
- Vuln Type: Authorization