Latest CVE Feed
-
6.5
MEDIUMCVE-2025-47497
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in themepoints Logo Showcase allows DOM-Based XSS. This issue affects Logo Showcase: from n/a through 3.0.4.... Read more
Affected Products :- Published: May. 07, 2025
- Modified: May. 29, 2025
- Vuln Type: Cross-Site Scripting
-
6.5
MEDIUMCVE-2020-15187
In Helm before versions 2.16.11 and 3.3.2, a Helm plugin can contain duplicates of the same entry, with the last one always used. If a plugin is compromised, this lowers the level of access that an attacker needs to modify a plugin's install hooks, causin... Read more
Affected Products : helm- EPSS Score: %0.33
- Published: Sep. 17, 2020
- Modified: May. 29, 2025
-
5.1
MEDIUMCVE-2025-30224
MyDumper is a MySQL Logical Backup Tool. The MySQL C client library (libmysqlclient) allows authenticated remote actors to read arbitrary files from client systems via a crafted server response to LOAD LOCAL INFILE query, leading to sensitive information ... Read more
Affected Products :- Published: Apr. 01, 2025
- Modified: May. 29, 2025
- Vuln Type: Information Disclosure
-
9.8
CRITICALCVE-2025-39349
Deserialization of Untrusted Data vulnerability in Potenzaglobalsolutions CiyaShop allows Object Injection.This issue affects CiyaShop: from n/a through 4.18.0.... Read more
Affected Products : ciyashop- Published: May. 19, 2025
- Modified: May. 29, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-39348
Deserialization of Untrusted Data vulnerability in ThemeGoods Grand Restaurant WordPress allows Object Injection.This issue affects Grand Restaurant WordPress: from n/a through 7.0.... Read more
Affected Products : grand_restaurant- Published: May. 19, 2025
- Modified: May. 29, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2022-34715
Windows Network File System Remote Code Execution Vulnerability... Read more
Affected Products : windows_server_2022- EPSS Score: %58.37
- Published: Aug. 09, 2022
- Modified: May. 29, 2025
-
8.1
HIGHCVE-2022-34714
Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability... Read more
Affected Products : windows_10 windows_7 windows_8.1 windows_rt_8.1 windows_server_2008 windows_server_2012 windows_server_2016 windows_server_2019 windows_10_1607 windows_10_1809 +12 more products- EPSS Score: %1.03
- Published: Aug. 09, 2022
- Modified: May. 29, 2025
-
5.5
MEDIUMCVE-2022-34712
Windows Defender Credential Guard Information Disclosure Vulnerability... Read more
- EPSS Score: %4.76
- Published: Aug. 09, 2022
- Modified: May. 29, 2025
-
5.5
MEDIUMCVE-2022-34710
Windows Defender Credential Guard Information Disclosure Vulnerability... Read more
Affected Products : windows_10 windows_server_2016 windows_server_2019 windows_10_1607 windows_10_1809 windows_10_20h2 windows_10_21h2 windows_server_2022 windows_11_21h2 windows_11 +4 more products- EPSS Score: %4.68
- Published: Aug. 09, 2022
- Modified: May. 29, 2025
-
6.0
MEDIUMCVE-2022-34709
Windows Defender Credential Guard Security Feature Bypass Vulnerability... Read more
Affected Products : windows_10 windows_server_2016 windows_server_2019 windows_10_1607 windows_10_1809 windows_10_20h2 windows_10_21h2 windows_server_2022 windows_11_21h2 windows_11 +4 more products- EPSS Score: %3.08
- Published: Aug. 09, 2022
- Modified: May. 29, 2025
-
5.5
MEDIUMCVE-2022-34708
Windows Kernel Information Disclosure Vulnerability... Read more
Affected Products : windows_10 windows_7 windows_8.1 windows_rt_8.1 windows_server_2008 windows_server_2012 windows_server_2016 windows_server_2019 windows_10_1607 windows_10_1809 +12 more products- EPSS Score: %3.88
- Published: Aug. 09, 2022
- Modified: May. 29, 2025
-
9.8
CRITICALCVE-2025-32928
Deserialization of Untrusted Data vulnerability in ThemeGoods Altair allows Object Injection.This issue affects Altair: from n/a through 5.2.2.... Read more
Affected Products : altair- Published: May. 19, 2025
- Modified: May. 29, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-32927
Deserialization of Untrusted Data vulnerability in Chimpstudio FoodBakery allows Object Injection.This issue affects FoodBakery: from n/a through 3.3.... Read more
Affected Products : foodbakery- Published: May. 19, 2025
- Modified: May. 29, 2025
- Vuln Type: Injection
-
6.5
MEDIUMCVE-2025-48256
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Xylus Themes Import Social Events allows Stored XSS. This issue affects Import Social Events: from n/a through 1.8.5.... Read more
Affected Products : import_social_events- Published: May. 19, 2025
- Modified: May. 29, 2025
- Vuln Type: Cross-Site Scripting
-
6.5
MEDIUMCVE-2025-48254
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPFactory Change Add to Cart Button Text for WooCommerce allows Stored XSS. This issue affects Change Add to Cart Button Text for WooCommerce: from n/a t... Read more
Affected Products : change_add_to_cart_button_text_for_woocommerce- Published: May. 19, 2025
- Modified: May. 29, 2025
- Vuln Type: Cross-Site Scripting
-
5.4
MEDIUMCVE-2023-48324
Missing Authorization vulnerability in Awesome Support Team Awesome Support allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Awesome Support: from n/a through 6.1.4.... Read more
Affected Products : awesome_support- Published: Dec. 09, 2024
- Modified: May. 29, 2025
-
5.4
MEDIUMCVE-2023-49757
Missing Authorization vulnerability in Awesome Support Team Awesome Support allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Awesome Support: from n/a through 6.1.10.... Read more
Affected Products : awesome_support- Published: Dec. 09, 2024
- Modified: May. 29, 2025
-
6.5
MEDIUMCVE-2023-49857
Missing Authorization vulnerability in Awesome Support Team Awesome Support allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Awesome Support: from n/a through 6.1.7.... Read more
Affected Products : awesome_support- Published: Dec. 09, 2024
- Modified: May. 29, 2025
-
8.8
HIGHCVE-2023-51356
Improper Privilege Management vulnerability in Repute Infosystems ARMember allows Privilege Escalation.This issue affects ARMember: from n/a through 4.0.10.... Read more
Affected Products : armember- Published: May. 17, 2024
- Modified: May. 29, 2025
-
8.8
HIGHCVE-2023-47837
Improper Privilege Management vulnerability in Repute Infosystems ARMember allows Privilege Escalation.This issue affects ARMember: from n/a through 4.0.10.... Read more
Affected Products : armember- Published: Jun. 04, 2024
- Modified: May. 29, 2025