Latest CVE Feed
-
7.5
HIGHCVE-2025-2917
A vulnerability, which was classified as problematic, was found in ChestnutCMS up to 1.5.3. Affected is the function readFile of the file /dev-api/cms/file/read. The manipulation of the argument filePath leads to path traversal. It is possible to launch t... Read more
- Published: Mar. 28, 2025
- Modified: Jun. 09, 2025
- Vuln Type: Path Traversal
-
7.5
HIGHCVE-2024-24304
In the module "Mailjet" (mailjet) from Mailjet for PrestaShop before versions 3.5.1, a guest can download technical information without restriction.... Read more
Affected Products : mailjet- Published: Feb. 07, 2024
- Modified: Jun. 09, 2025
-
9.8
CRITICALCVE-2024-24188
Jsish v3.5.0 was discovered to contain a heap-buffer-overflow in ./src/jsiUtils.c.... Read more
Affected Products : jsish- Published: Feb. 07, 2024
- Modified: Jun. 09, 2025
-
9.8
CRITICALCVE-2024-24021
A SQL injection vulnerability exists in Novel-Plus v4.3.0-RC1 and prior. An attacker can pass specially crafted offset, limit, and sort parameters to perform SQL injection via /novel/userFeedback/list.... Read more
Affected Products : novel-plus- Published: Feb. 08, 2024
- Modified: Jun. 09, 2025
-
5.6
MEDIUMCVE-2024-11616
Netskope was made aware of a security vulnerability in Netskope Endpoint DLP’s Content Control Driver where a double-fetch issue leads to heap overflow. The vulnerability arises from the fact that the NumberOfBytes argument to ExAllocatePoolWithTag, and t... Read more
Affected Products :- Published: Dec. 19, 2024
- Modified: Jun. 09, 2025
-
6.4
MEDIUMCVE-2023-42983
Processing a file may lead to a denial-of-service or potentially disclose memory contents. This issue is fixed in macOS 14. The issue was addressed with improved checks.... Read more
Affected Products : macos- Published: Apr. 11, 2025
- Modified: Jun. 09, 2025
- Vuln Type: Denial of Service
-
8.1
HIGHCVE-2024-22873
Tencent Blueking CMDB v3.2.x to v3.9.x was discovered to contain a Server-Side Request Forgery (SSRF) via the event subscription function (/service/subscription.go). This vulnerability allows attackers to access internal requests via a crafted POST reques... Read more
- Published: Feb. 26, 2024
- Modified: Jun. 09, 2025
-
5.9
MEDIUMCVE-2024-27995
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Repute Infosystems ARMember – Membership Plugin, Content Restriction, Member Levels, User Profile & User signup allows Stored XSS.This issue affects ARMe... Read more
Affected Products : armember- Published: Mar. 21, 2024
- Modified: Jun. 09, 2025
-
9.8
CRITICALCVE-2025-32926
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in ThemeGoods Grand Restaurant WordPress allows Path Traversal.This issue affects Grand Restaurant WordPress: from n/a through 7.0.... Read more
Affected Products : grand_restaurant- Published: May. 19, 2025
- Modified: Jun. 09, 2025
- Vuln Type: Path Traversal
-
9.8
CRITICALCVE-2025-32925
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in FantasticPlugins SUMO Reward Points allows PHP Local File Inclusion.This issue affects SUMO Reward Points: from n/a through 30.7.0.... Read more
Affected Products : sumo_reward_points- Published: May. 19, 2025
- Modified: Jun. 09, 2025
- Vuln Type: Path Traversal
-
6.5
MEDIUMCVE-2024-3963
The Giveaways and Contests by RafflePress WordPress plugin before 1.12.14 does not sanitise and escape some parameters, which could allow users with a role as low as editor to perform Cross-Site Scripting attacks... Read more
Affected Products : giveaways_and_contests_by_rafflepress rafflepress giveaways_and_contests rafflepress- Published: Jul. 13, 2024
- Modified: Jun. 09, 2025
-
8.5
HIGHCVE-2025-32924
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in roninwp Revy allows SQL Injection.This issue affects Revy: from n/a through 2.1.... Read more
Affected Products : revy- Published: May. 19, 2025
- Modified: Jun. 09, 2025
- Vuln Type: Injection
-
4.3
MEDIUMCVE-2025-47543
Cross-Site Request Forgery (CSRF) vulnerability in themetechmount TrueBooker allows Cross Site Request Forgery. This issue affects TrueBooker: from n/a through 1.0.7.... Read more
Affected Products : truebooker- Published: May. 07, 2025
- Modified: Jun. 09, 2025
- Vuln Type: Cross-Site Request Forgery
-
4.3
MEDIUMCVE-2025-47542
Cross-Site Request Forgery (CSRF) vulnerability in Michael Simple calendar for Elementor allows Cross Site Request Forgery. This issue affects Simple calendar for Elementor: from n/a through 1.6.5.... Read more
Affected Products : simple_calendar_for_elementor- Published: May. 07, 2025
- Modified: Jun. 09, 2025
- Vuln Type: Cross-Site Request Forgery
-
7.5
HIGHCVE-2025-47540
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in weDevs weMail allows Retrieve Embedded Sensitive Data. This issue affects weMail: from n/a through 1.14.13.... Read more
- Published: May. 07, 2025
- Modified: Jun. 09, 2025
- Vuln Type: Information Disclosure
-
7.6
HIGHCVE-2025-47538
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in wpdever Cart tracking for WooCommerce allows SQL Injection. This issue affects Cart tracking for WooCommerce: from n/a through 1.0.17.... Read more
Affected Products : cart_tracking_for_woocommerce- Published: May. 07, 2025
- Modified: Jun. 09, 2025
- Vuln Type: Injection
-
7.1
HIGHCVE-2025-47517
Cross-Site Request Forgery (CSRF) vulnerability in Scott Paterson Accept Donations with PayPal allows Stored XSS. This issue affects Accept Donations with PayPal: from n/a through 1.4.5.... Read more
Affected Products : accept_donations_with_paypal- Published: May. 07, 2025
- Modified: Jun. 09, 2025
- Vuln Type: Cross-Site Request Forgery
-
6.5
MEDIUMCVE-2025-39528
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Rescue Themes Rescue Shortcodes allows Stored XSS. This issue affects Rescue Shortcodes: from n/a through 3.1.... Read more
Affected Products : rescue_shortcodes- Published: Apr. 16, 2025
- Modified: Jun. 09, 2025
- Vuln Type: Cross-Site Scripting
-
6.6
MEDIUMCVE-2024-9422
The GEO my WP WordPress plugin before 4.5, gmw-premium-settings WordPress plugin before 3.1 does not sufficiently validate files to be uploaded, which could allow attackers to upload arbitrary files such as PHP on the server.... Read more
- Published: Nov. 22, 2024
- Modified: Jun. 09, 2025
-
5.5
MEDIUMCVE-2025-25946
An issue in Bento4 v1.6.0-641 allows an attacker to cause a memory leak via Ap4Marlin.cpp and Ap4Processor.cpp, specifically in AP4_MarlinIpmpEncryptingProcessor::Initialize and AP4_Processor::Process, during the execution of mp4encrypt with a specially c... Read more
Affected Products : bento4- Published: Feb. 19, 2025
- Modified: Jun. 09, 2025
- Vuln Type: Memory Corruption