Latest CVE Feed
-
6.6
MEDIUMCVE-2024-28810
An issue was discovered in Infinera hiT 7300 5.60.50. Sensitive information inside diagnostic files (exported by the @CT application) allows an attacker to achieve loss of confidentiality by analyzing these files.... Read more
- Published: Sep. 30, 2024
- Modified: May. 30, 2025
-
3.3
LOWCVE-2024-28811
An issue was discovered in Infinera hiT 7300 5.60.50. A web application allows a remote privileged attacker to execute applications contained in a specific OS directory via HTTP invocations.... Read more
- Published: Sep. 30, 2024
- Modified: May. 30, 2025
-
8.8
HIGHCVE-2024-28812
An issue was discovered in Infinera hiT 7300 5.60.50. A hidden SSH service (on the local management network interface) with hardcoded credentials allows attackers to access the appliance operating system (with highest privileges) via an SSH connection.... Read more
- Published: Sep. 30, 2024
- Modified: May. 30, 2025
-
8.4
HIGHCVE-2024-28813
An issue was discovered in Infinera hiT 7300 5.60.50. Undocumented privileged functions in the @CT management application allow an attacker to activate remote SSH access to the appliance via an unexpected network interface.... Read more
- Published: Sep. 30, 2024
- Modified: May. 30, 2025
-
6.5
MEDIUMCVE-2024-28807
An issue was discovered in Infinera hiT 7300 5.60.50. Cleartext storage of sensitive information in the memory of the @CT desktop management application allows guest OS administrators to obtain various users' passwords by accessing memory dumps of the des... Read more
- Published: Sep. 30, 2024
- Modified: May. 30, 2025
-
2.7
LOWCVE-2024-28808
An issue was discovered in Infinera hiT 7300 5.60.50. Hidden functionality in the web interface allows a remote authenticated attacker to access reserved information by accessing undocumented web applications.... Read more
- Published: Sep. 30, 2024
- Modified: May. 30, 2025
-
8.8
HIGHCVE-2025-48136
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Estatik Mortgage Calculator Estatik allows PHP Local File Inclusion. This issue affects Mortgage Calculator Estatik: from n/a through ... Read more
- Published: May. 16, 2025
- Modified: May. 30, 2025
- Vuln Type: Path Traversal
-
8.5
HIGHCVE-2025-48137
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in proxymis Interview allows SQL Injection. This issue affects Interview: from n/a through 1.01.... Read more
Affected Products : interview- Published: May. 16, 2025
- Modified: May. 30, 2025
- Vuln Type: Injection
-
6.5
MEDIUMCVE-2025-48135
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in aptivadadev Aptivada for WP allows DOM-Based XSS. This issue affects Aptivada for WP: from n/a through 2.0.0.... Read more
Affected Products : aptivada_for_wp- Published: May. 16, 2025
- Modified: May. 30, 2025
- Vuln Type: Cross-Site Scripting
-
7.2
HIGHCVE-2025-48134
Deserialization of Untrusted Data vulnerability in ShapedPlugin LLC WP Tabs allows Object Injection. This issue affects WP Tabs: from n/a through 2.2.11.... Read more
Affected Products : wp_tabs- Published: May. 16, 2025
- Modified: May. 30, 2025
- Vuln Type: Injection
-
6.5
MEDIUMCVE-2025-48132
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in pencilwp X Addons for Elementor allows Stored XSS. This issue affects X Addons for Elementor: from n/a through 1.0.14.... Read more
Affected Products : x_addons_for_elementor- Published: May. 16, 2025
- Modified: May. 30, 2025
- Vuln Type: Cross-Site Scripting
-
6.1
MEDIUMCVE-2023-30394
The MoveIt framework 1.1.11 for ROS allows cross-site scripting (XSS) via the API authentication function. NOTE: this issue is disputed by the original reporter because it has "no impact."... Read more
Affected Products : moveit- EPSS Score: %0.26
- Published: May. 11, 2023
- Modified: May. 30, 2025
-
8.8
HIGHCVE-2024-35388
TOTOLINK NR1800X v9.1.0u.6681_B20230703 was discovered to contain a stack overflow via the password parameter in the function urldecode... Read more
- Published: May. 24, 2024
- Modified: May. 30, 2025
-
8.1
HIGHCVE-2024-33377
LB-LINK BL-W1210M v2.0 was discovered to contain a clickjacking vulnerability via the Administrator login page. Attackers can cause victim users to perform arbitrary operations via interaction with crafted elements on the web page.... Read more
- Published: Jun. 14, 2024
- Modified: May. 30, 2025
-
9.8
CRITICALCVE-2024-33375
LB-LINK BL-W1210M v2.0 was discovered to store user credentials in plaintext within the router's firmware.... Read more
- Published: Jun. 14, 2024
- Modified: May. 30, 2025
-
8.8
HIGHCVE-2024-3767
A vulnerability classified as critical was found in PHPGurukul News Portal 4.1. This vulnerability affects unknown code of the file /admin/edit-post.php. The manipulation of the argument posttitle/category leads to sql injection. The attack can be initiat... Read more
- Published: Apr. 15, 2024
- Modified: May. 30, 2025
-
9.8
CRITICALCVE-2025-4226
A vulnerability classified as critical has been found in PHPGurukul/Campcodes Cyber Cafe Management System 1.0. This affects an unknown part of the file /add-computer.php. The manipulation of the argument compname/comploc leads to sql injection. It is pos... Read more
Affected Products : cyber_cafe_management_system- Published: May. 03, 2025
- Modified: May. 30, 2025
- Vuln Type: Injection
-
8.8
HIGHCVE-2025-4695
A vulnerability was found in PHPGurukul/Campcodes Cyber Cafe Management System 1.0. It has been classified as critical. Affected is an unknown function of the file /add-users.php. The manipulation of the argument uadd leads to sql injection. It is possibl... Read more
Affected Products : cyber_cafe_management_system- Published: May. 15, 2025
- Modified: May. 30, 2025
- Vuln Type: Injection
-
8.1
HIGHCVE-2024-42514
A vulnerability in the legacy chat component of Mitel MiContact Center Business through 10.1.0.4 could allow an unauthenticated attacker to conduct an unauthorized access attack due to inadequate access control checks. A successful exploit requires user i... Read more
Affected Products : micontact_center_business- Published: Oct. 01, 2024
- Modified: May. 30, 2025
-
9.8
CRITICALCVE-2025-44881
A command injection vulnerability in the component /cgi-bin/qos.cgi of Wavlink WL-WN579A3 v1.0 allows attackers to execute arbitrary commands via a crafted input.... Read more
- Published: May. 20, 2025
- Modified: May. 30, 2025
- Vuln Type: Injection