Latest CVE Feed
-
9.8
CRITICALCVE-2017-20189
In Clojure before 1.9.0, classes can be used to construct a serialized object that executes arbitrary code upon deserialization. This is relevant if a server deserializes untrusted objects.... Read more
Affected Products : clojure- EPSS Score: %3.01
- Published: Jan. 22, 2024
- Modified: May. 30, 2025
-
8.8
HIGHCVE-2024-28809
An issue was discovered in Infinera hiT 7300 5.60.50. Cleartext storage of sensitive password in firmware update packages allows attackers to access various appliance services via hardcoded credentials.... Read more
- Published: Sep. 30, 2024
- Modified: May. 30, 2025
-
6.6
MEDIUMCVE-2024-28810
An issue was discovered in Infinera hiT 7300 5.60.50. Sensitive information inside diagnostic files (exported by the @CT application) allows an attacker to achieve loss of confidentiality by analyzing these files.... Read more
- Published: Sep. 30, 2024
- Modified: May. 30, 2025
-
3.3
LOWCVE-2024-28811
An issue was discovered in Infinera hiT 7300 5.60.50. A web application allows a remote privileged attacker to execute applications contained in a specific OS directory via HTTP invocations.... Read more
- Published: Sep. 30, 2024
- Modified: May. 30, 2025
-
8.8
HIGHCVE-2024-28812
An issue was discovered in Infinera hiT 7300 5.60.50. A hidden SSH service (on the local management network interface) with hardcoded credentials allows attackers to access the appliance operating system (with highest privileges) via an SSH connection.... Read more
- Published: Sep. 30, 2024
- Modified: May. 30, 2025
-
8.4
HIGHCVE-2024-28813
An issue was discovered in Infinera hiT 7300 5.60.50. Undocumented privileged functions in the @CT management application allow an attacker to activate remote SSH access to the appliance via an unexpected network interface.... Read more
- Published: Sep. 30, 2024
- Modified: May. 30, 2025
-
6.5
MEDIUMCVE-2024-28807
An issue was discovered in Infinera hiT 7300 5.60.50. Cleartext storage of sensitive information in the memory of the @CT desktop management application allows guest OS administrators to obtain various users' passwords by accessing memory dumps of the des... Read more
- Published: Sep. 30, 2024
- Modified: May. 30, 2025
-
2.7
LOWCVE-2024-28808
An issue was discovered in Infinera hiT 7300 5.60.50. Hidden functionality in the web interface allows a remote authenticated attacker to access reserved information by accessing undocumented web applications.... Read more
- Published: Sep. 30, 2024
- Modified: May. 30, 2025
-
8.8
HIGHCVE-2025-48136
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Estatik Mortgage Calculator Estatik allows PHP Local File Inclusion. This issue affects Mortgage Calculator Estatik: from n/a through ... Read more
- Published: May. 16, 2025
- Modified: May. 30, 2025
- Vuln Type: Path Traversal
-
8.5
HIGHCVE-2025-48137
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in proxymis Interview allows SQL Injection. This issue affects Interview: from n/a through 1.01.... Read more
Affected Products : interview- Published: May. 16, 2025
- Modified: May. 30, 2025
- Vuln Type: Injection
-
6.5
MEDIUMCVE-2025-48135
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in aptivadadev Aptivada for WP allows DOM-Based XSS. This issue affects Aptivada for WP: from n/a through 2.0.0.... Read more
Affected Products : aptivada_for_wp- Published: May. 16, 2025
- Modified: May. 30, 2025
- Vuln Type: Cross-Site Scripting
-
7.2
HIGHCVE-2025-48134
Deserialization of Untrusted Data vulnerability in ShapedPlugin LLC WP Tabs allows Object Injection. This issue affects WP Tabs: from n/a through 2.2.11.... Read more
Affected Products : wp_tabs- Published: May. 16, 2025
- Modified: May. 30, 2025
- Vuln Type: Injection
-
6.5
MEDIUMCVE-2025-48132
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in pencilwp X Addons for Elementor allows Stored XSS. This issue affects X Addons for Elementor: from n/a through 1.0.14.... Read more
Affected Products : x_addons_for_elementor- Published: May. 16, 2025
- Modified: May. 30, 2025
- Vuln Type: Cross-Site Scripting
-
6.1
MEDIUMCVE-2023-30394
The MoveIt framework 1.1.11 for ROS allows cross-site scripting (XSS) via the API authentication function. NOTE: this issue is disputed by the original reporter because it has "no impact."... Read more
Affected Products : moveit- EPSS Score: %0.26
- Published: May. 11, 2023
- Modified: May. 30, 2025
-
8.8
HIGHCVE-2024-35388
TOTOLINK NR1800X v9.1.0u.6681_B20230703 was discovered to contain a stack overflow via the password parameter in the function urldecode... Read more
- Published: May. 24, 2024
- Modified: May. 30, 2025
-
8.1
HIGHCVE-2024-33377
LB-LINK BL-W1210M v2.0 was discovered to contain a clickjacking vulnerability via the Administrator login page. Attackers can cause victim users to perform arbitrary operations via interaction with crafted elements on the web page.... Read more
- Published: Jun. 14, 2024
- Modified: May. 30, 2025
-
9.8
CRITICALCVE-2024-33375
LB-LINK BL-W1210M v2.0 was discovered to store user credentials in plaintext within the router's firmware.... Read more
- Published: Jun. 14, 2024
- Modified: May. 30, 2025
-
8.8
HIGHCVE-2024-3767
A vulnerability classified as critical was found in PHPGurukul News Portal 4.1. This vulnerability affects unknown code of the file /admin/edit-post.php. The manipulation of the argument posttitle/category leads to sql injection. The attack can be initiat... Read more
- Published: Apr. 15, 2024
- Modified: May. 30, 2025
-
9.8
CRITICALCVE-2025-4226
A vulnerability classified as critical has been found in PHPGurukul/Campcodes Cyber Cafe Management System 1.0. This affects an unknown part of the file /add-computer.php. The manipulation of the argument compname/comploc leads to sql injection. It is pos... Read more
Affected Products : cyber_cafe_management_system- Published: May. 03, 2025
- Modified: May. 30, 2025
- Vuln Type: Injection
-
8.8
HIGHCVE-2025-4695
A vulnerability was found in PHPGurukul/Campcodes Cyber Cafe Management System 1.0. It has been classified as critical. Affected is an unknown function of the file /add-users.php. The manipulation of the argument uadd leads to sql injection. It is possibl... Read more
Affected Products : cyber_cafe_management_system- Published: May. 15, 2025
- Modified: May. 30, 2025
- Vuln Type: Injection