Latest CVE Feed
-
7.1
HIGHCVE-2023-6279
The Woostify Sites Library WordPress plugin before 1.4.8 does not have authorisation in an AJAX action, allowing any authenticated users, such as subscriber to update arbitrary blog options and set them to 'activated' which could lead to DoS when using a ... Read more
Affected Products : sites_library- EPSS Score: %0.11
- Published: Jan. 29, 2024
- Modified: Jun. 02, 2025
-
7.6
HIGHCVE-2023-50854
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Squirrly Squirrly SEO - Advanced Pack.This issue affects Squirrly SEO - Advanced Pack: from n/a before 2.4.02.... Read more
Affected Products : seo_plugin_by_squirrly_seo- EPSS Score: %0.14
- Published: Dec. 28, 2023
- Modified: Jun. 02, 2025
-
7.5
HIGHCVE-2023-46838
Transmit requests in Xen's virtual network protocol can consist of multiple parts. While not really useful, except for the initial part any of them may be of zero length, i.e. carry no data at all. Besides a certain initial portion of the to be transfer... Read more
- EPSS Score: %0.09
- Published: Jan. 29, 2024
- Modified: Jun. 02, 2025
-
9.8
CRITICALCVE-2025-31681
Missing Authorization vulnerability in Drupal Authenticator Login allows Forceful Browsing.This issue affects Authenticator Login: from 0.0.0 before 2.0.6.... Read more
- Published: Mar. 31, 2025
- Modified: Jun. 02, 2025
- Vuln Type: Authorization
-
3.9
LOWCVE-2024-41511
A Path Traversal (Local File Inclusion) vulnerability in "BinaryFileRedirector.ashx" in CADClick v1.11.0 and before allows remote attackers to retrieve arbitrary local files via the "path" parameter.... Read more
Affected Products : cadclick- Published: Oct. 04, 2024
- Modified: Jun. 02, 2025
-
8.8
HIGHCVE-2024-41512
A SQL Injection vulnerability in "ccHandler.aspx" in all versions of CADClick v.1.11.0 and before allows remote attackers to execute arbitrary SQL commands via the "bomid" parameter.... Read more
Affected Products : cadclick- Published: Oct. 04, 2024
- Modified: Jun. 02, 2025
-
5.4
MEDIUMCVE-2024-41513
A reflected cross-site scripting (XSS) vulnerability in "Artikel.aspx" in CADClick v1.11.0 and before allows remote attackers to inject arbitrary web script or HTML via the "searchindex" parameter.... Read more
Affected Products : cadclick- Published: Oct. 04, 2024
- Modified: Jun. 02, 2025
-
5.4
MEDIUMCVE-2024-41514
A reflected cross-site scripting (XSS) vulnerability in "PrevPgGroup.aspx" in CADClick v1.11.0 and before allows remote attackers to inject arbitrary web script or HTML via the "wer" parameter.... Read more
Affected Products : cadclick- Published: Oct. 04, 2024
- Modified: Jun. 02, 2025
-
5.4
MEDIUMCVE-2024-41515
A reflected cross-site scripting (XSS) vulnerability in "ccHandlerResource.ashx" in CADClick <= 1.11.0 allows remote attackers to inject arbitrary web script or HTML via the "res_url" parameter.... Read more
Affected Products : cadclick- Published: Oct. 04, 2024
- Modified: Jun. 02, 2025
-
5.4
MEDIUMCVE-2024-41516
A Reflected cross-site scripting (XSS) vulnerability in "ccHandler.aspx" CADClick <= 1.11.0 allows remote attackers to inject arbitrary web script or HTML via the "bomid" parameter.... Read more
Affected Products : cadclick- Published: Oct. 04, 2024
- Modified: Jun. 02, 2025
-
5.5
MEDIUMCVE-2024-46325
TP-Link WR740N V6 has a stack overflow vulnerability via the ssid parameter in /userRpm/popupSiteSurveyRpm.htm url.... Read more
- Published: Oct. 07, 2024
- Modified: Jun. 02, 2025
-
8.5
HIGHCVE-2025-2502
An improper default permissions vulnerability was reported in Lenovo PC Manager that could allow a local attacker to elevate privileges.... Read more
Affected Products : pc_manager- Published: May. 30, 2025
- Modified: Jun. 02, 2025
-
5.3
MEDIUMCVE-2025-5377
A vulnerability was found in Astun Technology iShare Maps 5.4.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the file historic1.asp. The manipulation of the argument Zoom leads to cross site scripting. The att... Read more
Affected Products :- Published: May. 31, 2025
- Modified: Jun. 02, 2025
- Vuln Type: Cross-Site Scripting
-
6.5
MEDIUMCVE-2025-5380
A vulnerability, which was classified as critical, has been found in ashinigit 天青一白 XueShengZhuSu 学生住宿管理系统 up to 4d3f0ada0e71482c1e51fd5f5615e5a3d8bcbfbb. This issue affects some unknown processing of the file /upload/ of the component Image File Upload. ... Read more
Affected Products :- Published: May. 31, 2025
- Modified: Jun. 02, 2025
- Vuln Type: Path Traversal
-
6.5
MEDIUMCVE-2025-5385
A vulnerability was found in JeeWMS up to 20250504. It has been declared as critical. This vulnerability affects the function doAdd of the file /cgformTemplateController.do?doAdd. The manipulation leads to path traversal. The attack can be initiated remot... Read more
Affected Products :- Published: May. 31, 2025
- Modified: Jun. 02, 2025
- Vuln Type: Path Traversal
-
6.5
MEDIUMCVE-2025-5390
A vulnerability, which was classified as critical, was found in JeeWMS up to 20250504. This affects the function filedeal of the file /systemController/filedeal.do of the component File Handler. The manipulation leads to improper access controls. It is po... Read more
Affected Products :- Published: May. 31, 2025
- Modified: Jun. 02, 2025
- Vuln Type: Authorization
-
5.1
MEDIUMCVE-2025-5405
A vulnerability, which was classified as problematic, has been found in chaitak-gorai Blogbook up to 92f5cf90f8a7e6566b576fe0952e14e1c6736513. This issue affects some unknown processing of the file /post.php. The manipulation of the argument comment_autho... Read more
Affected Products :- Published: Jun. 01, 2025
- Modified: Jun. 02, 2025
- Vuln Type: Cross-Site Scripting
-
5.1
MEDIUMCVE-2025-5412
A vulnerability classified as problematic has been found in Mist Community Edition up to 4.7.1. Affected is the function Login of the file src/mist/api/views.py of the component Authentication Endpoint. The manipulation of the argument return_to leads to ... Read more
Affected Products :- Published: Jun. 02, 2025
- Modified: Jun. 02, 2025
- Vuln Type: Cross-Site Scripting
-
6.5
MEDIUMCVE-2025-5433
A vulnerability was found in Fengoffice Feng Office 3.5.1.5 and classified as critical. Affected by this issue is some unknown functionality of the file /index.php?c=account&a=set_timezone. The manipulation of the argument tz_offset leads to sql injection... Read more
Affected Products : feng_office- Published: Jun. 02, 2025
- Modified: Jun. 02, 2025
- Vuln Type: Injection
-
4.3
MEDIUMCVE-2025-0325
A Guard Tour VAPIX API parameter allowed the use of arbitrary values and can be incorrectly called, allowing an attacker to block access to the guard tour configuration page in the web interface of the Axis device.... Read more
Affected Products : axis_os- Published: Jun. 02, 2025
- Modified: Jun. 02, 2025
- Vuln Type: Denial of Service