Latest CVE Feed
-
4.3
MEDIUMCVE-2025-22779
Missing Authorization vulnerability in Ugur CELIK WP News Sliders allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP News Sliders: from n/a through 1.0.... Read more
Affected Products :- Published: Jan. 15, 2025
- Modified: Jan. 15, 2025
- Vuln Type: Authorization
-
4.3
MEDIUMCVE-2025-0476
Mattermost Mobile Apps versions <=2.22.0 fail to properly handle specially crafted attachment names, which allows an attacker to crash the mobile app for any user who opened a channel containing the specially crafted attachment... Read more
- Published: Jan. 16, 2025
- Modified: Jan. 16, 2025
- Vuln Type: Denial of Service
-
4.3
MEDIUMCVE-2023-1336
The RapidLoad Power-Up for Autoptimize plugin for WordPress is vulnerable to unauthorized settings update due to a missing capability check on the ajax_deactivate function in versions up to, and including, 1.7.1. This makes it possible for authenticated a... Read more
- Published: Mar. 10, 2023
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2025-24589
Missing Authorization vulnerability in JS Morisset JSM Show Post Metadata allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects JSM Show Post Metadata: from n/a through 4.6.0.... Read more
Affected Products :- Published: Jan. 24, 2025
- Modified: Jan. 24, 2025
- Vuln Type: Authorization
-
4.3
MEDIUMCVE-2025-30624
Missing Authorization vulnerability in WordLift WordLift allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects WordLift: from n/a through 3.54.4.... Read more
Affected Products : wordlift- Published: Jun. 06, 2025
- Modified: Jun. 06, 2025
- Vuln Type: Authorization
-
4.3
MEDIUMCVE-2023-1375
The WP Fastest Cache plugin for WordPress is vulnerable to unauthorized cache deletion in versions up to, and including, 1.1.2 due to a missing capability check in the deleteCacheToolbar function . This makes it possible for authenticated attackers, with ... Read more
Affected Products : wp_fastest_cache- Published: Jun. 09, 2023
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2025-24743
Missing Authorization vulnerability in Rometheme RomethemeKit For Elementor. This issue affects RomethemeKit For Elementor: from n/a through 1.5.2.... Read more
Affected Products : romethemekit_for_elementor- Published: Jan. 27, 2025
- Modified: Jan. 27, 2025
- Vuln Type: Authorization
-
4.3
MEDIUMCVE-2025-24784
kubewarden-controller is a Kubernetes controller that allows you to dynamically register Kubewarden admission policies. The policy group feature, added to by the 1.17.0 release. By being namespaced, the AdmissionPolicyGroup has a well constrained impact o... Read more
Affected Products :- Published: Jan. 30, 2025
- Modified: Jan. 30, 2025
- Vuln Type: Information Disclosure
-
4.3
MEDIUMCVE-2025-23423
Missing Authorization vulnerability in Smackcoders SendGrid for WordPress allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects SendGrid for WordPress: from n/a through 1.4.... Read more
Affected Products : sendgrid- Published: Jan. 16, 2025
- Modified: Jan. 16, 2025
- Vuln Type: Authorization
-
4.3
MEDIUMCVE-2023-1232
Insufficient policy enforcement in Resource Timing in Google Chrome prior to 111.0.5563.64 allowed a remote attacker to obtain potentially sensitive information from API via a crafted HTML page. (Chromium security severity: Low)... Read more
- Published: Mar. 07, 2023
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2025-24696
Cross-Site Request Forgery (CSRF) vulnerability in WP Attire Attire Blocks allows Cross Site Request Forgery. This issue affects Attire Blocks: from n/a through 1.9.6.... Read more
Affected Products : attire_blocks- Published: Jan. 24, 2025
- Modified: Jan. 24, 2025
- Vuln Type: Cross-Site Request Forgery
-
4.3
MEDIUMCVE-2025-21404
Microsoft Edge (Chromium-based) Spoofing Vulnerability... Read more
Affected Products : edge_chromium- Published: Feb. 06, 2025
- Modified: Feb. 11, 2025
-
4.3
MEDIUMCVE-2025-24693
Missing Authorization vulnerability in Yehi Advanced Notifications allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Advanced Notifications: from n/a through 1.2.7.... Read more
Affected Products :- Published: Jan. 24, 2025
- Modified: Jan. 24, 2025
- Vuln Type: Authorization
-
4.3
MEDIUMCVE-2025-24736
Missing Authorization vulnerability in Metaphor Creations Post Duplicator allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Post Duplicator: from n/a through 2.35.... Read more
Affected Products : post_duplicator- Published: Jan. 24, 2025
- Modified: Jun. 09, 2025
- Vuln Type: Authorization
-
4.3
MEDIUMCVE-2023-1204
An issue has been discovered in GitLab CE/EE affecting all versions starting from 10.1 before 15.10.8, all versions starting from 15.11 before 15.11.7, all versions starting from 16.0 before 16.0.2. A user could use an unverified email as a public email a... Read more
Affected Products : gitlab- Published: May. 03, 2023
- Modified: Jan. 30, 2025
-
4.3
MEDIUMCVE-2025-23407
Incorrect privilege assignment vulnerability in the WEB UI (the setting page) exists in Wi-Fi AP UNIT 'AC-WPS-11ac series'. If exploited, a remote attacker who can log in to the product may alter the settings without appropriate privileges.... Read more
Affected Products :- Published: Apr. 09, 2025
- Modified: Apr. 09, 2025
- Vuln Type: Authorization
-
4.3
MEDIUMCVE-2025-30535
Cross-Site Request Forgery (CSRF) vulnerability in muro External image replace allows Cross Site Request Forgery. This issue affects External image replace: from n/a through 1.0.8.... Read more
Affected Products :- Published: Mar. 24, 2025
- Modified: Mar. 27, 2025
- Vuln Type: Cross-Site Request Forgery
-
4.3
MEDIUMCVE-2025-24738
Cross-Site Request Forgery (CSRF) vulnerability in NowButtons.com Call Now Button allows Cross Site Request Forgery. This issue affects Call Now Button: from n/a through 1.4.13.... Read more
Affected Products : call_now_button- Published: Jan. 24, 2025
- Modified: Jan. 24, 2025
- Vuln Type: Cross-Site Request Forgery
-
4.3
MEDIUMCVE-2025-21528
Vulnerability in the Primavera P6 Enterprise Project Portfolio Management product of Oracle Construction and Engineering (component: Web Access). Supported versions that are affected are 20.12.1.0-20.12.21.5, 21.12.1.0-21.12.20.0, 22.12.1.0-22.12.16.0 an... Read more
Affected Products : primavera_p6_enterprise_project_portfolio_management- Published: Jan. 21, 2025
- Modified: Jun. 18, 2025
- Vuln Type: Authentication
-
4.3
MEDIUMCVE-2023-1402
The course participation report required additional checks to prevent roles being displayed which the user did not have access to view.... Read more
Affected Products : moodle- Published: Mar. 23, 2023
- Modified: Nov. 21, 2024