Latest CVE Feed
-
4.8
MEDIUMCVE-2024-8670
The Photo Gallery by 10Web WordPress plugin before 1.8.29 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is d... Read more
Affected Products : photo_gallery- Published: May. 15, 2025
- Modified: Jun. 04, 2025
- Vuln Type: Cross-Site Scripting
-
7.5
HIGHCVE-2024-8700
The Event Calendar WordPress plugin through 1.0.4 does not check for authorization on delete actions, allowing unauthenticated users to delete arbitrary calendars.... Read more
Affected Products : event_calendar- Published: May. 15, 2025
- Modified: Jun. 04, 2025
- Vuln Type: Authorization
-
9.8
CRITICALCVE-2025-4578
The File Provider WordPress plugin through 1.2.3 does not properly sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection... Read more
Affected Products : file_provider- Published: Jun. 04, 2025
- Modified: Jun. 04, 2025
- Vuln Type: Injection
-
4.3
MEDIUMCVE-2024-9233
The Logo Slider WordPress plugin before 3.7.1 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack... Read more
- Published: May. 15, 2025
- Modified: Jun. 04, 2025
- Vuln Type: Cross-Site Request Forgery
-
4.8
MEDIUMCVE-2024-9390
The RegistrationMagic WordPress plugin before 6.0.2.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disal... Read more
Affected Products : registrationmagic- Published: May. 15, 2025
- Modified: Jun. 04, 2025
- Vuln Type: Cross-Site Scripting
-
6.5
MEDIUMCVE-2024-9450
The Free Booking Plugin for Hotels, Restaurants and Car Rentals WordPress plugin before 1.3.15 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in subscriber change them via a CSRF attack... Read more
Affected Products : free_booking_plugin_for_hotels\,_restaurant_and_car_rental- Published: May. 15, 2025
- Modified: Jun. 04, 2025
- Vuln Type: Cross-Site Request Forgery
-
5.4
MEDIUMCVE-2024-9599
The Popup Box WordPress plugin before 4.7.8 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for... Read more
- Published: May. 15, 2025
- Modified: Jun. 04, 2025
- Vuln Type: Cross-Site Scripting
-
5.4
MEDIUMCVE-2024-9645
The Post Grid, Posts Slider, Posts Carousel, Post Filter, Post Masonry WordPress plugin before 2.2.93 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with ... Read more
Affected Products : post_grid- Published: May. 15, 2025
- Modified: Jun. 04, 2025
- Vuln Type: Cross-Site Scripting
-
4.3
MEDIUMCVE-2025-4580
The File Provider WordPress plugin through 1.2.3 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack... Read more
Affected Products : file_provider- Published: Jun. 04, 2025
- Modified: Jun. 04, 2025
- Vuln Type: Cross-Site Request Forgery
-
5.4
MEDIUMCVE-2025-2247
The WP-PManager WordPress plugin through 1.2 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack... Read more
Affected Products : wp-pmanager- Published: May. 15, 2025
- Modified: Jun. 04, 2025
- Vuln Type: Cross-Site Request Forgery
-
5.4
MEDIUMCVE-2025-2248
The WP-PManager WordPress plugin through 1.2 does not sanitize and escape a parameter before using it in a SQL statement, allowing admins to perform SQL injection attacks... Read more
Affected Products : wp-pmanager- Published: May. 15, 2025
- Modified: Jun. 04, 2025
- Vuln Type: Injection
-
4.3
MEDIUMCVE-2025-1138
IBM InfoSphere Information Server 11.7 could disclose sensitive information to an authenticated user that could aid in further attacks against the system through a directory listing.... Read more
- Published: May. 15, 2025
- Modified: Jun. 04, 2025
- Vuln Type: Information Disclosure
-
6.1
MEDIUMCVE-2024-51475
IBM Content Navigator 3.0.11, 3.0.15, and 3.1.0 is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the victim's Web browser within the security context of the hosting site.... Read more
Affected Products : content_navigator- Published: May. 16, 2025
- Modified: Jun. 04, 2025
- Vuln Type: Cross-Site Scripting
-
9.1
CRITICALCVE-2025-48174
In libavif before 1.3.0, makeRoom in stream.c has an integer overflow and resultant buffer overflow in stream->offset+size.... Read more
Affected Products : libavif- Published: May. 16, 2025
- Modified: Jun. 04, 2025
- Vuln Type: Memory Corruption
-
7.0
HIGHCVE-2025-27703
CVE-2025-27703 is a privilege escalation vulnerability in the management console of Absolute Secure Access prior to version 13.54. Attackers with administrative access to a specific subset of privileged features in the console can elevate their permiss... Read more
Affected Products : secure_access- Published: May. 28, 2025
- Modified: Jun. 04, 2025
- Vuln Type: Authorization
-
4.6
MEDIUMCVE-2025-27706
CVE-2025-27706 is a cross-site scripting vulnerability in the management console of Absolute Secure Access prior to version 13.54. Attackers with system administrator permissions can interfere with another system administrator’s use of the management c... Read more
Affected Products : secure_access- Published: May. 28, 2025
- Modified: Jun. 04, 2025
- Vuln Type: Cross-Site Scripting
-
5.3
MEDIUMCVE-2025-46078
HuoCMS V3.5.1 and before is vulnerable to file upload, which allows attackers to take control of the target server... Read more
Affected Products : huocms- Published: May. 29, 2025
- Modified: Jun. 04, 2025
- Vuln Type: Misconfiguration
-
5.3
MEDIUMCVE-2025-46080
HuoCMS V3.5.1 has a File Upload Vulnerability. An attacker can exploit this flaw to bypass whitelist restrictions and craft malicious files with specific suffixes, thereby gaining control of the server.... Read more
Affected Products : huocms- Published: May. 29, 2025
- Modified: Jun. 04, 2025
- Vuln Type: Misconfiguration
-
7.2
HIGHCVE-2025-41385
An OS Command Injection issue exists in wivia 5 all versions. If this vulnerability is exploited, an arbitrary OS command may be executed by a logged-in administrative user.... Read more
- Published: May. 30, 2025
- Modified: Jun. 04, 2025
- Vuln Type: Injection
-
6.1
MEDIUMCVE-2025-41406
Cross-site scripting vulnerability exists in wivia 5 all versions. If exploited, when a user connects to the affected device with a specific operation, an arbitrary script may be executed on the web browser of the moderator user.... Read more
- Published: May. 30, 2025
- Modified: Jun. 04, 2025
- Vuln Type: Cross-Site Scripting