Latest CVE Feed
-
6.1
MEDIUMCVE-2024-3996
The Smart Post Show WordPress plugin before 2.4.28 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallow... Read more
Affected Products : smart_post_show- Published: May. 15, 2025
- Modified: Jun. 04, 2025
- Vuln Type: Cross-Site Scripting
-
6.5
MEDIUMCVE-2020-27298
Philips Interventional Workspot (Release 1.3.2, 1.4.0, 1.4.1, 1.4.3, 1.4.5), Coronary Tools/Dynamic Coronary Roadmap/Stentboost Live (Release 1.0), ViewForum (Release 6.3V1L10). The software constructs all or part of an OS command using externally influen... Read more
Affected Products : coronary_tools dynamic_coronary_roadmap interventional_workspot stentboost_live viewforum- Published: Jan. 26, 2021
- Modified: Jun. 04, 2025
-
4.3
MEDIUMCVE-2020-14506
Philips Clinical Collaboration Platform, Versions 12.2.1 and prior. The product receives input or data, but it does not validate or incorrectly validates that the input has the properties required to process the data safely and correctly.... Read more
Affected Products : clinical_collaboration_platform- Published: Sep. 18, 2020
- Modified: Jun. 04, 2025
-
7.5
HIGHCVE-2024-13613
The Wise Chat plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.3.3 via the 'uploads' directory. This makes it possible for unauthenticated attackers to extract sensitive data stored insecurely in... Read more
- Published: May. 17, 2025
- Modified: Jun. 04, 2025
- Vuln Type: Information Disclosure
-
8.8
HIGHCVE-2025-33103
IBM i 7.2, 7.3, 7.4, 7.5, and 7.6 product IBM TCP/IP Connectivity Utilities for i contains a privilege escalation vulnerability. A malicious actor with command line access to the host operating system can elevate privileges to gain root access to the host... Read more
- Published: May. 17, 2025
- Modified: Jun. 04, 2025
- Vuln Type: Authorization
-
8.1
HIGHCVE-2025-4839
A vulnerability has been found in itwanger paicoding 1.0.0/1.0.1/1.0.2/1.0.3 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /paicoding-core/src/main/java/com/github/paicoding/forum/core/util/CrossUtil... Read more
Affected Products : paicoding- Published: May. 17, 2025
- Modified: Jun. 04, 2025
- Vuln Type: Misconfiguration
-
9.8
CRITICALCVE-2025-4842
A vulnerability was found in D-Link DCS-932L 2.18.01. It has been declared as critical. This vulnerability affects the function isUCPCameraNameChanged of the file /sbin/ucp. The manipulation of the argument CameraName leads to stack-based buffer overflow.... Read more
- Published: May. 17, 2025
- Modified: Jun. 04, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2025-4843
A vulnerability was found in D-Link DCS-932L 2.18.01. It has been classified as critical. This affects the function SubUPnPCSInit of the file /sbin/udev. The manipulation of the argument CameraName leads to stack-based buffer overflow. It is possible to i... Read more
- Published: May. 18, 2025
- Modified: Jun. 04, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2025-4844
A vulnerability classified as critical was found in FreeFloat FTP Server 1.0. Affected by this vulnerability is an unknown functionality of the component CD Command Handler. The manipulation leads to buffer overflow. The attack can be launched remotely. T... Read more
- Published: May. 18, 2025
- Modified: Jun. 04, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2025-4845
A vulnerability, which was classified as critical, has been found in FreeFloat FTP Server 1.0. Affected by this issue is some unknown functionality of the component TRACE Command Handler. The manipulation leads to buffer overflow. The attack may be launch... Read more
- Published: May. 18, 2025
- Modified: Jun. 04, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2025-4847
A vulnerability has been found in FreeFloat FTP Server 1.0 and classified as critical. This vulnerability affects unknown code of the component MLS Command Handler. The manipulation leads to buffer overflow. The attack can be initiated remotely. The explo... Read more
- Published: May. 18, 2025
- Modified: Jun. 04, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2025-4848
A vulnerability was found in FreeFloat FTP Server 1.0 and classified as critical. This issue affects some unknown processing of the component RECV Command Handler. The manipulation leads to buffer overflow. The attack may be initiated remotely. The exploi... Read more
- Published: May. 18, 2025
- Modified: Jun. 04, 2025
- Vuln Type: Memory Corruption
-
4.8
MEDIUMCVE-2025-4852
A vulnerability, which was classified as problematic, has been found in TOTOLINK A3002R 2.1.1-B20230720.1011. This issue affects some unknown processing of the component VPN Page. The manipulation of the argument Comment leads to cross site scripting. The... Read more
- Published: May. 18, 2025
- Modified: Jun. 04, 2025
- Vuln Type: Cross-Site Scripting
-
6.4
MEDIUMCVE-2025-3527
The EventON Pro plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check in the 'assets/lib/settings/settings.js' file in all versions up to, and including, 4.9.6. This makes it possible for authenticated a... Read more
Affected Products : eventon- Published: May. 17, 2025
- Modified: Jun. 04, 2025
- Vuln Type: Cross-Site Scripting
-
5.4
MEDIUMCVE-2024-6668
The ProfilePro WordPress plugin through 1.3 does not sanitise and escape some parameters and lacks proper access controls, which could allow users with a role as low as subscriber to perform Cross-Site Scripting attacks... Read more
Affected Products : profilepro- Published: May. 15, 2025
- Modified: Jun. 04, 2025
- Vuln Type: Cross-Site Scripting
-
6.4
MEDIUMCVE-2025-3888
The Jupiter X Core plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File inclusion in all versions up to, and including, 4.8.12 due to insufficient input sanitization and output escaping. This makes it possible for authenticated a... Read more
Affected Products : jupiter_x_core- Published: May. 17, 2025
- Modified: Jun. 04, 2025
- Vuln Type: Cross-Site Scripting
-
6.4
MEDIUMCVE-2025-4669
The WP Booking Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wpbc shortcode in all versions up to, and including, 10.11.1 due to insufficient input sanitization and output escaping on user supplied attributes.... Read more
Affected Products : wp_booking_calendar- Published: May. 17, 2025
- Modified: Jun. 04, 2025
- Vuln Type: Cross-Site Scripting
-
4.8
MEDIUMCVE-2024-6708
The User Profile Builder WordPress plugin before 3.12.2 does not sanitise and escape some parameters before outputting its content on the admin area, which allows Admin+ users to perform Cross-Site Scripting attacks.... Read more
Affected Products : profile_builder- Published: May. 15, 2025
- Modified: Jun. 04, 2025
- Vuln Type: Cross-Site Scripting
-
6.1
MEDIUMCVE-2024-6711
The Event Tickets with Ticket Scanner WordPress plugin before 2.3.8 does not sanitise and escape some parameters, which could allow users with a role as low as admin to perform Cross-Site Scripting attacks... Read more
Affected Products : event_tickets_with_ticket_scanner- Published: May. 15, 2025
- Modified: Jun. 04, 2025
- Vuln Type: Cross-Site Scripting
-
4.8
MEDIUMCVE-2024-7758
The Stylish Price List WordPress plugin before 7.1.8 does not sanitise and escape some of its settings, which could allow high privilege users of contributor and above to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capabilit... Read more
Affected Products : stylish_price_list- Published: May. 15, 2025
- Modified: Jun. 04, 2025
- Vuln Type: Cross-Site Scripting