Latest CVE Feed
-
5.5
MEDIUMCVE-2022-34708
Windows Kernel Information Disclosure Vulnerability... Read more
Affected Products : windows_10 windows_7 windows_8.1 windows_rt_8.1 windows_server_2008 windows_server_2012 windows_server_2016 windows_server_2019 windows_10_1607 windows_10_1809 +12 more products- EPSS Score: %3.88
- Published: Aug. 09, 2022
- Modified: May. 29, 2025
-
9.8
CRITICALCVE-2025-32928
Deserialization of Untrusted Data vulnerability in ThemeGoods Altair allows Object Injection.This issue affects Altair: from n/a through 5.2.2.... Read more
Affected Products : altair- Published: May. 19, 2025
- Modified: May. 29, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-32927
Deserialization of Untrusted Data vulnerability in Chimpstudio FoodBakery allows Object Injection.This issue affects FoodBakery: from n/a through 3.3.... Read more
Affected Products : foodbakery- Published: May. 19, 2025
- Modified: May. 29, 2025
- Vuln Type: Injection
-
6.5
MEDIUMCVE-2025-48256
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Xylus Themes Import Social Events allows Stored XSS. This issue affects Import Social Events: from n/a through 1.8.5.... Read more
Affected Products : import_social_events- Published: May. 19, 2025
- Modified: May. 29, 2025
- Vuln Type: Cross-Site Scripting
-
6.5
MEDIUMCVE-2025-48254
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPFactory Change Add to Cart Button Text for WooCommerce allows Stored XSS. This issue affects Change Add to Cart Button Text for WooCommerce: from n/a t... Read more
Affected Products : change_add_to_cart_button_text_for_woocommerce- Published: May. 19, 2025
- Modified: May. 29, 2025
- Vuln Type: Cross-Site Scripting
-
5.4
MEDIUMCVE-2023-48324
Missing Authorization vulnerability in Awesome Support Team Awesome Support allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Awesome Support: from n/a through 6.1.4.... Read more
Affected Products : awesome_support- Published: Dec. 09, 2024
- Modified: May. 29, 2025
-
5.4
MEDIUMCVE-2023-49757
Missing Authorization vulnerability in Awesome Support Team Awesome Support allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Awesome Support: from n/a through 6.1.10.... Read more
Affected Products : awesome_support- Published: Dec. 09, 2024
- Modified: May. 29, 2025
-
6.5
MEDIUMCVE-2023-49857
Missing Authorization vulnerability in Awesome Support Team Awesome Support allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Awesome Support: from n/a through 6.1.7.... Read more
Affected Products : awesome_support- Published: Dec. 09, 2024
- Modified: May. 29, 2025
-
8.8
HIGHCVE-2023-51356
Improper Privilege Management vulnerability in Repute Infosystems ARMember allows Privilege Escalation.This issue affects ARMember: from n/a through 4.0.10.... Read more
Affected Products : armember- Published: May. 17, 2024
- Modified: May. 29, 2025
-
8.8
HIGHCVE-2023-47837
Improper Privilege Management vulnerability in Repute Infosystems ARMember allows Privilege Escalation.This issue affects ARMember: from n/a through 4.0.10.... Read more
Affected Products : armember- Published: Jun. 04, 2024
- Modified: May. 29, 2025
-
8.8
HIGHCVE-2023-45760
Missing Authorization vulnerability in gVectors Team wpDiscuz allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects wpDiscuz: from n/a through 7.6.3.... Read more
Affected Products : wpdiscuz- Published: Jan. 02, 2025
- Modified: May. 29, 2025
- Vuln Type: Authorization
-
8.8
HIGHCVE-2024-30222
Deserialization of Untrusted Data vulnerability in Repute Infosystems ARMember.This issue affects ARMember: from n/a through 4.0.26. ... Read more
Affected Products : armember- Published: Mar. 28, 2024
- Modified: May. 29, 2025
-
9.8
CRITICALCVE-2024-30223
Deserialization of Untrusted Data vulnerability in Repute Infosystems ARMember.This issue affects ARMember: from n/a through 4.0.26. ... Read more
Affected Products : armember- Published: Mar. 28, 2024
- Modified: May. 29, 2025
-
6.1
MEDIUMCVE-2024-35283
A vulnerability in the Ignite component of Mitel MiContact Center Business through 10.0.0.4 could allow an unauthenticated attacker to conduct a stored cross-site scripting (XSS) attack due to insufficient input validation.... Read more
Affected Products : micontact_center_business- Published: May. 29, 2024
- Modified: May. 29, 2025
-
5.4
MEDIUMCVE-2024-35284
A vulnerability in the legacy chat component of Mitel MiContact Center Business through 10.0.0.4 could allow an unauthenticated attacker to conduct a reflected cross-site scripting (XSS) attack due to insufficient input validation.... Read more
Affected Products : micontact_center_business- Published: May. 29, 2024
- Modified: May. 29, 2025
-
9.8
CRITICALCVE-2024-36042
Silverpeas before 6.3.5 allows authentication bypass by omitting the Password field to AuthenticationServlet, often providing an unauthenticated user with superadmin access.... Read more
Affected Products : silverpeas- Published: Jun. 03, 2024
- Modified: May. 29, 2025
-
9.1
CRITICALCVE-2024-4180
The Events Calendar WordPress plugin before 6.4.0.1 does not properly sanitize user-submitted content when rendering some views via AJAX.... Read more
- Published: Jun. 04, 2024
- Modified: May. 29, 2025
-
4.3
MEDIUMCVE-2024-4274
The Essential Real Estate plugin for WordPress is vulnerable to unauthorized loss of data due to insufficient validation on the remove_property_attachment_ajax() function in all versions up to, and including, 4.4.2. This makes it possible for authenticate... Read more
Affected Products : essential_real_estate- Published: Jun. 04, 2024
- Modified: May. 29, 2025
-
6.1
MEDIUMCVE-2023-46310
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in gVectors Team wpDiscuz allows Code Injection.This issue affects wpDiscuz: from n/a through 7.6.10.... Read more
Affected Products : wpdiscuz- Published: Jun. 04, 2024
- Modified: May. 29, 2025
-
6.4
MEDIUMCVE-2024-4273
The Essential Real Estate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'ere_property_map' shortcode in all versions up to, and including, 4.4.2 due to insufficient input sanitization and output escaping on user suppli... Read more
Affected Products : essential_real_estate- Published: Jun. 04, 2024
- Modified: May. 29, 2025