Latest CVE Feed
-
10.0
CRITICALCVE-2025-29813
[Spoofable identity claims] Authentication Bypass by Assumed-Immutable Data in Azure DevOps allows an unauthorized attacker to elevate privileges over a network.... Read more
Affected Products : azure_devops- Published: May. 08, 2025
- Modified: Jun. 05, 2025
- Vuln Type: Authentication
-
8.8
HIGHCVE-2024-11725
The SMS Alert Order Notifications – WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on the updateWcWarrantySettings() function in all versions up t... Read more
Affected Products : sms_alert_order_notifications- Published: Jan. 07, 2025
- Modified: Jun. 05, 2025
- Vuln Type: Authorization
-
9.9
CRITICALCVE-2025-29827
Improper Authorization in Azure Automation allows an authorized attacker to elevate privileges over a network.... Read more
Affected Products : azure_automation- Published: May. 08, 2025
- Modified: Jun. 05, 2025
- Vuln Type: Authorization
-
9.9
CRITICALCVE-2025-29972
Server-Side Request Forgery (SSRF) in Azure allows an authorized attacker to perform spoofing over a network.... Read more
- Published: May. 08, 2025
- Modified: Jun. 05, 2025
- Vuln Type: Server-Side Request Forgery
-
5.9
MEDIUMCVE-2025-3597
The Firelight Lightbox WordPress plugin before 2.3.15 does not prevent users with post writing capabilities from executing arbitrary Javascript when the jQuery Metadata library is enabled. While this feature is meant to only be available to Pro version us... Read more
Affected Products : firelight_lightbox- Published: May. 12, 2025
- Modified: Jun. 05, 2025
- Vuln Type: Cross-Site Scripting
-
6.8
MEDIUMCVE-2025-3649
The LightPress Lightbox WordPress plugin before 2.3.4 does not check download links point to valid, non-Javascript URLs, allowing users with at least the contributor role to conduct Stored XSS attacks.... Read more
Affected Products : lightbox- Published: May. 12, 2025
- Modified: Jun. 05, 2025
- Vuln Type: Cross-Site Scripting
-
7.5
HIGHCVE-2025-3875
Thunderbird parses addresses in a way that can allow sender spoofing in case the server allows an invalid From address to be used. For example, if the From header contains an (invalid) value "Spoofed Name ", Thunderbird treats [email protected] as the ... Read more
Affected Products : thunderbird- Published: May. 14, 2025
- Modified: Jun. 05, 2025
- Vuln Type: Authentication
-
6.5
MEDIUMCVE-2025-3909
Thunderbird's handling of the X-Mozilla-External-Attachment-URL header can be exploited to execute JavaScript in the file:/// context. By crafting a nested email attachment (message/rfc822) and setting its content type to application/pdf, Thunderbird may ... Read more
Affected Products : thunderbird- Published: May. 14, 2025
- Modified: Jun. 05, 2025
- Vuln Type: Cross-Site Scripting
-
6.4
MEDIUMCVE-2025-0450
The Betheme plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's custom JS functionality in all versions up to, and including, 27.6.1 due to insufficient input sanitization and output escaping on user supplied attributes. Thi... Read more
Affected Products : betheme- Published: Jan. 21, 2025
- Modified: Jun. 05, 2025
- Vuln Type: Cross-Site Scripting
-
6.5
MEDIUMCVE-2025-3932
It was possible to craft an email that showed a tracking link as an attachment. If the user attempted to open the attachment, Thunderbird automatically accessed the link. The configuration to block remote content did not prevent that. Thunderbird has been... Read more
Affected Products : thunderbird- Published: May. 14, 2025
- Modified: Jun. 05, 2025
- Vuln Type: Misconfiguration
-
6.4
MEDIUMCVE-2024-13702
The CRM and Lead Management by vcita plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'vCitaMeetingScheduler' and 'vCitaSchedulingCalendar' shortcodes in all versions up to, and including, 2.7.4 due to insufficient input ... Read more
Affected Products : crm_and_lead_management_by_vcita- Published: Mar. 26, 2025
- Modified: Jun. 05, 2025
- Vuln Type: Cross-Site Scripting
-
4.8
MEDIUMCVE-2024-13384
The Photo Gallery, Images, Slider in Rbs Image Gallery WordPress plugin before 3.2.24 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfi... Read more
Affected Products : robo_gallery- Published: May. 15, 2025
- Modified: Jun. 05, 2025
- Vuln Type: Cross-Site Scripting
-
9.8
CRITICALCVE-2022-3180
The WPGateway Plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 3.5. This allows unauthenticated attackers to create arbitrary malicious administrator accounts.... Read more
Affected Products : wpgateway- Published: Feb. 11, 2025
- Modified: Jun. 05, 2025
- Vuln Type: Authentication
-
4.8
MEDIUMCVE-2024-2869
The Easy Property Listings WordPress plugin before 3.5.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is dis... Read more
Affected Products : easy_property_listings- Published: May. 15, 2025
- Modified: Jun. 05, 2025
- Vuln Type: Cross-Site Scripting
-
6.1
MEDIUMCVE-2024-3901
The Genesis Blocks WordPress plugin through 3.1.3 does not properly escape attributes provided to some of its custom blocks, making it possible for users allowed to write posts (like those with the contributor role) to conduct Stored XSS attacks.... Read more
Affected Products : genesis_blocks- Published: May. 15, 2025
- Modified: Jun. 05, 2025
- Vuln Type: Cross-Site Scripting
-
6.1
MEDIUMCVE-2024-4002
The Carousel, Slider, Gallery by WP Carousel WordPress plugin before 2.6.9 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_htm... Read more
Affected Products : carousel\,_slider\,_gallery_by_wp_carousel- Published: May. 15, 2025
- Modified: Jun. 05, 2025
- Vuln Type: Cross-Site Scripting
-
6.1
MEDIUMCVE-2024-4091
The Responsive Gallery Grid WordPress plugin before 2.3.15 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed... Read more
Affected Products : responsive_gallery_grid- Published: May. 15, 2025
- Modified: Jun. 05, 2025
- Vuln Type: Cross-Site Scripting
-
7.5
HIGHCVE-2024-10628
The Quiz Maker Business, Developer, and Agency plugins for WordPress is vulnerable to SQL Injection via the ‘id’ parameter in all versions up to, and including, 8.8.0 (Business), up to, and including, 21.8.0 (Developer), and up to, and including, 31.8.0 (... Read more
Affected Products : quiz_maker- Published: Jan. 26, 2025
- Modified: Jun. 05, 2025
- Vuln Type: Injection
-
4.8
MEDIUMCVE-2024-6665
The KBucket: Your Curated Content in WordPress plugin before 4.1.6 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capabil... Read more
Affected Products : kbucket- Published: May. 15, 2025
- Modified: Jun. 05, 2025
- Vuln Type: Cross-Site Scripting
-
6.1
MEDIUMCVE-2024-6667
The KBucket: Your Curated Content in WordPress plugin before 4.1.5 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against admin.... Read more
Affected Products : kbucket- Published: May. 15, 2025
- Modified: Jun. 05, 2025
- Vuln Type: Cross-Site Scripting