Latest CVE Feed
-
8.4
HIGHCVE-2024-28813
An issue was discovered in Infinera hiT 7300 5.60.50. Undocumented privileged functions in the @CT management application allow an attacker to activate remote SSH access to the appliance via an unexpected network interface.... Read more
- Published: Sep. 30, 2024
- Modified: May. 30, 2025
-
6.5
MEDIUMCVE-2024-28807
An issue was discovered in Infinera hiT 7300 5.60.50. Cleartext storage of sensitive information in the memory of the @CT desktop management application allows guest OS administrators to obtain various users' passwords by accessing memory dumps of the des... Read more
- Published: Sep. 30, 2024
- Modified: May. 30, 2025
-
2.7
LOWCVE-2024-28808
An issue was discovered in Infinera hiT 7300 5.60.50. Hidden functionality in the web interface allows a remote authenticated attacker to access reserved information by accessing undocumented web applications.... Read more
- Published: Sep. 30, 2024
- Modified: May. 30, 2025
-
8.8
HIGHCVE-2025-48136
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Estatik Mortgage Calculator Estatik allows PHP Local File Inclusion. This issue affects Mortgage Calculator Estatik: from n/a through ... Read more
- Published: May. 16, 2025
- Modified: May. 30, 2025
- Vuln Type: Path Traversal
-
8.5
HIGHCVE-2025-48137
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in proxymis Interview allows SQL Injection. This issue affects Interview: from n/a through 1.01.... Read more
Affected Products : interview- Published: May. 16, 2025
- Modified: May. 30, 2025
- Vuln Type: Injection
-
6.5
MEDIUMCVE-2025-48135
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in aptivadadev Aptivada for WP allows DOM-Based XSS. This issue affects Aptivada for WP: from n/a through 2.0.0.... Read more
Affected Products : aptivada_for_wp- Published: May. 16, 2025
- Modified: May. 30, 2025
- Vuln Type: Cross-Site Scripting
-
7.2
HIGHCVE-2025-48134
Deserialization of Untrusted Data vulnerability in ShapedPlugin LLC WP Tabs allows Object Injection. This issue affects WP Tabs: from n/a through 2.2.11.... Read more
Affected Products : wp_tabs- Published: May. 16, 2025
- Modified: May. 30, 2025
- Vuln Type: Injection
-
6.5
MEDIUMCVE-2025-48132
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in pencilwp X Addons for Elementor allows Stored XSS. This issue affects X Addons for Elementor: from n/a through 1.0.14.... Read more
Affected Products : x_addons_for_elementor- Published: May. 16, 2025
- Modified: May. 30, 2025
- Vuln Type: Cross-Site Scripting
-
6.1
MEDIUMCVE-2023-30394
The MoveIt framework 1.1.11 for ROS allows cross-site scripting (XSS) via the API authentication function. NOTE: this issue is disputed by the original reporter because it has "no impact."... Read more
Affected Products : moveit- EPSS Score: %0.26
- Published: May. 11, 2023
- Modified: May. 30, 2025
-
8.8
HIGHCVE-2024-35388
TOTOLINK NR1800X v9.1.0u.6681_B20230703 was discovered to contain a stack overflow via the password parameter in the function urldecode... Read more
- Published: May. 24, 2024
- Modified: May. 30, 2025
-
8.1
HIGHCVE-2024-33377
LB-LINK BL-W1210M v2.0 was discovered to contain a clickjacking vulnerability via the Administrator login page. Attackers can cause victim users to perform arbitrary operations via interaction with crafted elements on the web page.... Read more
- Published: Jun. 14, 2024
- Modified: May. 30, 2025
-
9.8
CRITICALCVE-2024-33375
LB-LINK BL-W1210M v2.0 was discovered to store user credentials in plaintext within the router's firmware.... Read more
- Published: Jun. 14, 2024
- Modified: May. 30, 2025
-
8.8
HIGHCVE-2024-3767
A vulnerability classified as critical was found in PHPGurukul News Portal 4.1. This vulnerability affects unknown code of the file /admin/edit-post.php. The manipulation of the argument posttitle/category leads to sql injection. The attack can be initiat... Read more
- Published: Apr. 15, 2024
- Modified: May. 30, 2025
-
9.8
CRITICALCVE-2025-4226
A vulnerability classified as critical has been found in PHPGurukul/Campcodes Cyber Cafe Management System 1.0. This affects an unknown part of the file /add-computer.php. The manipulation of the argument compname/comploc leads to sql injection. It is pos... Read more
Affected Products : cyber_cafe_management_system- Published: May. 03, 2025
- Modified: May. 30, 2025
- Vuln Type: Injection
-
8.8
HIGHCVE-2025-4695
A vulnerability was found in PHPGurukul/Campcodes Cyber Cafe Management System 1.0. It has been classified as critical. Affected is an unknown function of the file /add-users.php. The manipulation of the argument uadd leads to sql injection. It is possibl... Read more
Affected Products : cyber_cafe_management_system- Published: May. 15, 2025
- Modified: May. 30, 2025
- Vuln Type: Injection
-
8.1
HIGHCVE-2024-42514
A vulnerability in the legacy chat component of Mitel MiContact Center Business through 10.1.0.4 could allow an unauthenticated attacker to conduct an unauthorized access attack due to inadequate access control checks. A successful exploit requires user i... Read more
Affected Products : micontact_center_business- Published: Oct. 01, 2024
- Modified: May. 30, 2025
-
9.8
CRITICALCVE-2025-44881
A command injection vulnerability in the component /cgi-bin/qos.cgi of Wavlink WL-WN579A3 v1.0 allows attackers to execute arbitrary commands via a crafted input.... Read more
- Published: May. 20, 2025
- Modified: May. 30, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-44880
A command injection vulnerability in the component /cgi-bin/adm.cgi of Wavlink WL-WN579A3 v1.0 allows attackers to execute arbitrary commands via a crafted input.... Read more
- Published: May. 20, 2025
- Modified: May. 30, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-44882
A command injection vulnerability in the component /cgi-bin/firewall.cgi of Wavlink WL-WN579A3 v1.0 allows attackers to execute arbitrary commands via a crafted input.... Read more
- Published: May. 20, 2025
- Modified: May. 30, 2025
- Vuln Type: Injection
-
8.8
HIGHCVE-2025-33136
IBM Aspera Faspex 5.0.0 through 5.0.12 could allow an authenticated user to obtain sensitive information or perform unauthorized actions on behalf of another user due to improper protection of assumed immutable data.... Read more
- Published: May. 22, 2025
- Modified: May. 30, 2025
- Vuln Type: Authorization