Latest CVE Feed
-
7.5
HIGHCVE-2025-25227
Insufficient state checks lead to a vector that allows to bypass 2FA checks.... Read more
- Published: Apr. 08, 2025
- Modified: Jun. 04, 2025
- Vuln Type: Authentication
-
4.8
MEDIUMCVE-2024-10144
The Photo Gallery, Images, Slider in Rbs Image Gallery WordPress plugin before 3.2.22 does not sanitise and escape some of its settings, which could allow high privilege users such as contributor to perform Stored Cross-Site Scripting attacks even when th... Read more
Affected Products : robo_gallery- Published: May. 15, 2025
- Modified: Jun. 04, 2025
- Vuln Type: Cross-Site Scripting
-
4.8
MEDIUMCVE-2024-10054
The Happyforms WordPress plugin before 1.26.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (f... Read more
Affected Products : happyforms- Published: May. 15, 2025
- Modified: Jun. 04, 2025
- Vuln Type: Cross-Site Scripting
-
4.8
MEDIUMCVE-2024-10107
The Giveaways and Contests by RafflePress WordPress plugin before 1.12.17 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html... Read more
Affected Products : rafflepress- Published: May. 15, 2025
- Modified: Jun. 04, 2025
- Vuln Type: Cross-Site Scripting
-
4.8
MEDIUMCVE-2024-10145
The Hubbub Lite WordPress plugin before 1.34.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (... Read more
Affected Products : social_pug- Published: May. 15, 2025
- Modified: Jun. 04, 2025
- Vuln Type: Cross-Site Scripting
-
5.4
MEDIUMCVE-2024-10504
The Contact Form, Survey, Quiz & Popup Form Builder WordPress plugin before 1.7.1 does not sanitise and escape some parameters when outputting them in the page, which could allow unauthenticated users to perform Cross-Site Scripting attacks.... Read more
Affected Products : arforms- Published: May. 15, 2025
- Modified: Jun. 04, 2025
- Vuln Type: Cross-Site Scripting
-
4.8
MEDIUMCVE-2024-11109
The WP Google Review Slider WordPress plugin before 15.6 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is dis... Read more
Affected Products : wp_google_review_slider- Published: May. 15, 2025
- Modified: Jun. 04, 2025
- Vuln Type: Cross-Site Scripting
-
6.1
MEDIUMCVE-2024-3996
The Smart Post Show WordPress plugin before 2.4.28 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallow... Read more
Affected Products : smart_post_show- Published: May. 15, 2025
- Modified: Jun. 04, 2025
- Vuln Type: Cross-Site Scripting
-
6.5
MEDIUMCVE-2020-27298
Philips Interventional Workspot (Release 1.3.2, 1.4.0, 1.4.1, 1.4.3, 1.4.5), Coronary Tools/Dynamic Coronary Roadmap/Stentboost Live (Release 1.0), ViewForum (Release 6.3V1L10). The software constructs all or part of an OS command using externally influen... Read more
Affected Products : coronary_tools dynamic_coronary_roadmap interventional_workspot stentboost_live viewforum- Published: Jan. 26, 2021
- Modified: Jun. 04, 2025
-
4.3
MEDIUMCVE-2020-14506
Philips Clinical Collaboration Platform, Versions 12.2.1 and prior. The product receives input or data, but it does not validate or incorrectly validates that the input has the properties required to process the data safely and correctly.... Read more
Affected Products : clinical_collaboration_platform- Published: Sep. 18, 2020
- Modified: Jun. 04, 2025
-
7.5
HIGHCVE-2024-13613
The Wise Chat plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.3.3 via the 'uploads' directory. This makes it possible for unauthenticated attackers to extract sensitive data stored insecurely in... Read more
- Published: May. 17, 2025
- Modified: Jun. 04, 2025
- Vuln Type: Information Disclosure
-
8.8
HIGHCVE-2025-33103
IBM i 7.2, 7.3, 7.4, 7.5, and 7.6 product IBM TCP/IP Connectivity Utilities for i contains a privilege escalation vulnerability. A malicious actor with command line access to the host operating system can elevate privileges to gain root access to the host... Read more
- Published: May. 17, 2025
- Modified: Jun. 04, 2025
- Vuln Type: Authorization
-
8.1
HIGHCVE-2025-4839
A vulnerability has been found in itwanger paicoding 1.0.0/1.0.1/1.0.2/1.0.3 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /paicoding-core/src/main/java/com/github/paicoding/forum/core/util/CrossUtil... Read more
Affected Products : paicoding- Published: May. 17, 2025
- Modified: Jun. 04, 2025
- Vuln Type: Misconfiguration
-
9.8
CRITICALCVE-2025-4842
A vulnerability was found in D-Link DCS-932L 2.18.01. It has been declared as critical. This vulnerability affects the function isUCPCameraNameChanged of the file /sbin/ucp. The manipulation of the argument CameraName leads to stack-based buffer overflow.... Read more
- Published: May. 17, 2025
- Modified: Jun. 04, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2025-4843
A vulnerability was found in D-Link DCS-932L 2.18.01. It has been classified as critical. This affects the function SubUPnPCSInit of the file /sbin/udev. The manipulation of the argument CameraName leads to stack-based buffer overflow. It is possible to i... Read more
- Published: May. 18, 2025
- Modified: Jun. 04, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2025-4844
A vulnerability classified as critical was found in FreeFloat FTP Server 1.0. Affected by this vulnerability is an unknown functionality of the component CD Command Handler. The manipulation leads to buffer overflow. The attack can be launched remotely. T... Read more
- Published: May. 18, 2025
- Modified: Jun. 04, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2025-4845
A vulnerability, which was classified as critical, has been found in FreeFloat FTP Server 1.0. Affected by this issue is some unknown functionality of the component TRACE Command Handler. The manipulation leads to buffer overflow. The attack may be launch... Read more
- Published: May. 18, 2025
- Modified: Jun. 04, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2025-4847
A vulnerability has been found in FreeFloat FTP Server 1.0 and classified as critical. This vulnerability affects unknown code of the component MLS Command Handler. The manipulation leads to buffer overflow. The attack can be initiated remotely. The explo... Read more
- Published: May. 18, 2025
- Modified: Jun. 04, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2025-4848
A vulnerability was found in FreeFloat FTP Server 1.0 and classified as critical. This issue affects some unknown processing of the component RECV Command Handler. The manipulation leads to buffer overflow. The attack may be initiated remotely. The exploi... Read more
- Published: May. 18, 2025
- Modified: Jun. 04, 2025
- Vuln Type: Memory Corruption
-
4.8
MEDIUMCVE-2025-4852
A vulnerability, which was classified as problematic, has been found in TOTOLINK A3002R 2.1.1-B20230720.1011. This issue affects some unknown processing of the component VPN Page. The manipulation of the argument Comment leads to cross site scripting. The... Read more
- Published: May. 18, 2025
- Modified: Jun. 04, 2025
- Vuln Type: Cross-Site Scripting