Latest CVE Feed
-
6.4
MEDIUMCVE-2025-4127
The WP SEO Structured Data Schema plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘Price Range’ parameter in all versions up to, and including, 2.7.11 due to insufficient input sanitization and output escaping. This makes it poss... Read more
Affected Products : wp_seo_structured_data_schema- Published: May. 08, 2025
- Modified: Jun. 04, 2025
- Vuln Type: Cross-Site Scripting
-
7.5
HIGHCVE-2025-3419
The Event Manager, Events Calendar, Tickets, Registrations – Eventin plugin for WordPress is vulnerable to arbitrary file read in all versions up to, and including, 4.0.26 via the proxy_image() function. This makes it possible for unauthenticated attacker... Read more
Affected Products : eventin- Published: May. 08, 2025
- Modified: Jun. 04, 2025
- Vuln Type: Information Disclosure
-
7.3
HIGHCVE-2024-13793
The Wolmart | Multi-Vendor Marketplace WooCommerce Theme theme for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 1.8.11. This is due to the software allowing users to execute an action that does not properl... Read more
Affected Products : wolmart- Published: May. 08, 2025
- Modified: Jun. 04, 2025
- Vuln Type: Authentication
-
7.5
HIGHCVE-2025-4204
The Ultimate Auction Pro plugin for WordPress is vulnerable to SQL Injection via the ‘auction_id’ parameter in all versions up to, and including, 1.5.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the e... Read more
Affected Products : ultimate_wordpress_auction_plugin- Published: May. 02, 2025
- Modified: Jun. 04, 2025
- Vuln Type: Injection
-
6.4
MEDIUMCVE-2025-3077
The Betheme theme for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Button shortcode and Custom CSS field in all versions up to, and including, 28.0.3 due to insufficient input sanitization and output escaping on user supplied at... Read more
Affected Products : betheme- Published: Apr. 16, 2025
- Modified: Jun. 04, 2025
- Vuln Type: Cross-Site Scripting
-
6.4
MEDIUMCVE-2025-3276
The SKT Blocks – Gutenberg based Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Post Carousel block in all versions up to, and including, 1.9 due to insufficient input sanitization and output escaping. This makes it... Read more
Affected Products : skt_blocks- Published: Apr. 12, 2025
- Modified: Jun. 04, 2025
- Vuln Type: Cross-Site Scripting
-
7.5
HIGHCVE-2025-3431
The ZoomSounds - WordPress Wave Audio Player with Playlist plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 6.91 via the 'dzsap_download' action. This makes it possible for unauthenticated attackers to read t... Read more
Affected Products : zoomsounds- Published: Apr. 08, 2025
- Modified: Jun. 04, 2025
- Vuln Type: Information Disclosure
-
6.5
MEDIUMCVE-2025-2789
The MultiVendorX – Empower Your WooCommerce Store with a Dynamic Multivendor Marketplace – Build the Next Amazon, eBay, Etsy plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the delete_table_rate_shippin... Read more
Affected Products : multivendorx- Published: Apr. 05, 2025
- Modified: Jun. 04, 2025
- Vuln Type: Authorization
-
6.4
MEDIUMCVE-2025-0839
The ZoomSounds plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcodes in versions up to, and including, 6.91 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authe... Read more
Affected Products : zoomsounds- Published: Apr. 05, 2025
- Modified: Jun. 04, 2025
- Vuln Type: Cross-Site Scripting
-
8.1
HIGHCVE-2024-13776
The ZoomSounds - WordPress Wave Audio Player with Playlist plugin for WordPress is vulnerable to unauthorized modification of data that can lead to a denial of service due to a missing capability check on the 'dzsap_delete_notice' AJAX action in all versi... Read more
Affected Products : zoomsounds- Published: Apr. 05, 2025
- Modified: Jun. 04, 2025
- Vuln Type: Authorization
-
9.8
CRITICALCVE-2022-23088
The 802.11 beacon handling routine failed to validate the length of an IEEE 802.11s Mesh ID before copying it to a heap-allocated buffer. While a FreeBSD Wi-Fi client is in scanning mode (i.e., not associated with a SSID) a malicious beacon frame may ove... Read more
Affected Products : freebsd- EPSS Score: %8.55
- Published: Feb. 15, 2024
- Modified: Jun. 04, 2025
-
9.8
CRITICALCVE-2024-22922
An issue in Projectworlds Vistor Management Systemin PHP v.1.0 allows a remtoe attacker to escalate privileges via a crafted script to the login page in the POST/index.php... Read more
Affected Products : visitor_management_system_in_php- EPSS Score: %0.69
- Published: Jan. 25, 2024
- Modified: Jun. 04, 2025
-
8.8
HIGHCVE-2024-22903
Vinchin Backup & Recovery v7.2 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the deleteUpdateAPK function.... Read more
Affected Products : vinchin_backup_and_recovery- EPSS Score: %2.02
- Published: Feb. 02, 2024
- Modified: Jun. 04, 2025
-
9.8
CRITICALCVE-2024-22729
NETIS SYSTEMS MW5360 V1.0.1.3031 was discovered to contain a command injection vulnerability via the password parameter on the login page.... Read more
- EPSS Score: %90.81
- Published: Jan. 25, 2024
- Modified: Jun. 04, 2025
-
6.1
MEDIUMCVE-2024-22725
Orthanc versions before 1.12.2 are affected by a reflected cross-site scripting (XSS) vulnerability. The vulnerability was present in the server's error reporting.... Read more
Affected Products : orthanc- EPSS Score: %0.46
- Published: Jan. 24, 2024
- Modified: Jun. 04, 2025
-
7.2
HIGHCVE-2024-22625
Complete Supplier Management System v1.0 is vulnerable to SQL Injection via /Supply_Management_System/admin/edit_category.php?id=.... Read more
Affected Products : supplier_management_system- EPSS Score: %0.11
- Published: Jan. 16, 2024
- Modified: Jun. 04, 2025
-
9.8
CRITICALCVE-2024-22529
TOTOLINK X2000R_V2 V2.0.0-B20230727.10434 has a command injection vulnerability in the sub_449040 (handle function of formUploadFile) of /bin/boa.... Read more
- EPSS Score: %2.74
- Published: Jan. 25, 2024
- Modified: Jun. 04, 2025
-
6.1
MEDIUMCVE-2024-22048
govuk_tech_docs versions from 2.0.2 to before 3.3.1 are vulnerable to a cross-site scripting vulnerability. Malicious JavaScript may be executed in the user's browser if a malicious search result is displayed on the search page. ... Read more
Affected Products : govuk_tech_docs- EPSS Score: %1.18
- Published: Jan. 04, 2024
- Modified: Jun. 04, 2025
-
7.1
HIGHCVE-2020-16247
Philips Clinical Collaboration Platform, Versions 12.2.1 and prior, exposes a resource to the wrong control sphere, providing unintended actors with inappropriate access to the resource.... Read more
Affected Products : clinical_collaboration_platform- EPSS Score: %0.05
- Published: Sep. 18, 2020
- Modified: Jun. 04, 2025
-
6.3
MEDIUMCVE-2020-16241
Philips SureSigns VS4, A.07.107 and prior does not restrict or incorrectly restricts access to a resource from an unauthorized actor.... Read more
- EPSS Score: %0.05
- Published: Aug. 21, 2020
- Modified: Jun. 04, 2025