Latest CVE Feed
-
4.3
MEDIUMCVE-2025-22671
Missing Authorization vulnerability in Leap13 Disable Elementor Editor Translation allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Disable Elementor Editor Translation: from n/a through 1.0.2.... Read more
Affected Products :- Published: Mar. 27, 2025
- Modified: Mar. 27, 2025
- Vuln Type: Authorization
-
4.3
MEDIUMCVE-2025-24540
Cross-Site Request Forgery (CSRF) vulnerability in SeedProd Coming Soon Page, Under Construction & Maintenance Mode by SeedProd allows Cross Site Request Forgery. This issue affects Coming Soon Page, Under Construction & Maintenance Mode by SeedProd: from... Read more
Affected Products :- Published: Jan. 27, 2025
- Modified: Jan. 27, 2025
- Vuln Type: Cross-Site Request Forgery
-
4.3
MEDIUMCVE-2025-24279
This issue was addressed with improved file handling. This issue is fixed in macOS Ventura 13.7.5, macOS Sequoia 15.4, macOS Sonoma 14.7.5. An app may be able to access contacts.... Read more
Affected Products : macos- Published: Mar. 31, 2025
- Modified: Apr. 08, 2025
- Vuln Type: Information Disclosure
-
4.3
MEDIUMCVE-2025-22829
The CloudStack Quota plugin has an improper privilege management logic in version 4.20.0.0. Anyone with authenticated user-account access in CloudStack 4.20.0.0 environments, where this plugin is enabled and have access to specific APIs can enable or disa... Read more
Affected Products : cloudstack- Published: Jun. 10, 2025
- Modified: Jun. 25, 2025
- Vuln Type: Authorization
-
4.3
MEDIUMCVE-2025-22721
Missing Authorization vulnerability in Farhan Noor ApplyOnline – Application Form Builder and Manager allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects ApplyOnline – Application Form Builder and Manager: from n/a ... Read more
Affected Products : applyonline_-_application_form_builder_and_manager- Published: Jan. 21, 2025
- Modified: Jan. 21, 2025
- Vuln Type: Authorization
-
4.3
MEDIUMCVE-2025-22561
Missing Authorization vulnerability in Jason Funk Title Experiments Free allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Title Experiments Free: from n/a through 9.0.4.... Read more
Affected Products : title_experiments_free- Published: Jan. 09, 2025
- Modified: Jan. 09, 2025
- Vuln Type: Authorization
-
4.3
MEDIUMCVE-2025-22479
Dell Storage Center - Dell Storage Manager, version(s) 20.0.21, contain(s) an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability. An unauthenticated attacker with adjacent network access could potentially exploit ... Read more
Affected Products : storage_manager- Published: May. 06, 2025
- Modified: May. 13, 2025
- Vuln Type: Path Traversal
-
4.3
MEDIUMCVE-2025-24460
In JetBrains TeamCity before 2024.12.1 improper access control allowed to see Projects’ names in the agent pool... Read more
Affected Products : teamcity- Published: Jan. 21, 2025
- Modified: Jan. 30, 2025
- Vuln Type: Authorization
-
4.3
MEDIUMCVE-2025-22512
Missing Authorization vulnerability in Sprout Apps Help Scout allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Help Scout: from n/a through 6.5.1.... Read more
Affected Products :- Published: Jan. 07, 2025
- Modified: Jan. 07, 2025
- Vuln Type: Authorization
-
4.3
MEDIUMCVE-2025-22304
Missing Authorization vulnerability in osamaesh WP Visitor Statistics (Real Time Traffic) allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Visitor Statistics (Real Time Traffic): from n/a through 7.3.... Read more
Affected Products : wp_visitor_statistics- Published: Jan. 07, 2025
- Modified: Jan. 07, 2025
- Vuln Type: Authorization
-
4.3
MEDIUMCVE-2025-24402
A cross-site request forgery (CSRF) vulnerability in Jenkins Azure Service Fabric Plugin 1.6 and earlier allows attackers to connect to a Service Fabric URL using attacker-specified credentials IDs obtained through another method.... Read more
Affected Products :- Published: Jan. 22, 2025
- Modified: Jan. 23, 2025
- Vuln Type: Cross-Site Request Forgery
-
4.3
MEDIUMCVE-2025-32236
Missing Authorization vulnerability in Vagonic Woocommerce Products Reorder Drag Drop Multiple Sort – Sortable, Rearrange Products Vagonic. This issue affects Woocommerce Products Reorder Drag Drop Multiple Sort – Sortable, Rearrange Products Vagonic: fro... Read more
Affected Products :- Published: Apr. 10, 2025
- Modified: Apr. 11, 2025
- Vuln Type: Authorization
-
4.3
MEDIUMCVE-2025-22129
Tuleap is an Open Source Suite to improve management of software developments and collaboration. In affected versions an unauthorized user might get access to restricted information. This issue has been addressed in Tuleap Community Edition 16.3.99.173624... Read more
Affected Products : tuleap- Published: Feb. 03, 2025
- Modified: Aug. 22, 2025
- Vuln Type: Information Disclosure
-
4.3
MEDIUMCVE-2025-22215
VMware Aria Automation contains a server-side request forgery (SSRF) vulnerability. A malicious actor with "Organization Member" access to Aria Automation may exploit this vulnerability enumerate internal services running on the host/network.... Read more
Affected Products : aria_automation- Published: Jan. 08, 2025
- Modified: Jan. 08, 2025
- Vuln Type: Server-Side Request Forgery
-
4.3
MEDIUMCVE-2025-24435
Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by an Improper Access Control vulnerability that could result in Privilege escalation. A low-privileged attacker could leverage this vulnerability to by... Read more
- Published: Feb. 11, 2025
- Modified: Feb. 27, 2025
- Vuln Type: Authorization
-
4.3
MEDIUMCVE-2025-24649
Missing Authorization vulnerability in wpase.com Admin and Site Enhancements (ASE) allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Admin and Site Enhancements (ASE): from n/a through 7.6.2.... Read more
Affected Products :- Published: Jan. 24, 2025
- Modified: Jan. 24, 2025
- Vuln Type: Authorization
-
4.3
MEDIUMCVE-2025-24739
Cross-Site Request Forgery (CSRF) vulnerability in FluentSMTP & WPManageNinja Team FluentSMTP allows Cross Site Request Forgery. This issue affects FluentSMTP: from n/a through 2.2.80.... Read more
Affected Products : fluentsmtp- Published: Jan. 24, 2025
- Modified: Jan. 24, 2025
- Vuln Type: Cross-Site Request Forgery
-
4.3
MEDIUMCVE-2025-32263
Cross-Site Request Forgery (CSRF) vulnerability in BeRocket Sequential Order Numbers for WooCommerce allows Cross Site Request Forgery. This issue affects Sequential Order Numbers for WooCommerce: from n/a through 3.6.2.... Read more
Affected Products :- Published: Apr. 04, 2025
- Modified: Apr. 07, 2025
- Vuln Type: Cross-Site Request Forgery
-
4.3
MEDIUMCVE-2025-24653
Missing Authorization vulnerability in NotFound Admin and Site Enhancements (ASE) Pro allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Admin and Site Enhancements (ASE) Pro: from n/a through 7.6.1.1.... Read more
Affected Products :- Published: Jan. 27, 2025
- Modified: Jan. 27, 2025
- Vuln Type: Authorization
-
4.3
MEDIUMCVE-2023-1924
The WP Fastest Cache plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.2. This is due to missing or incorrect nonce validation on the wpfc_toolbar_save_settings_callback function. This makes it possible... Read more
Affected Products : wp_fastest_cache- Published: Apr. 06, 2023
- Modified: Nov. 21, 2024