Latest CVE Feed
-
9.8
CRITICALCVE-2025-4359
A vulnerability classified as critical was found in itsourcecode Gym Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /ajax.php?action=delete_member. The manipulation of the argument ID leads to sql injection. ... Read more
Affected Products : gym_management_system- Published: May. 06, 2025
- Modified: May. 28, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-4360
A vulnerability, which was classified as critical, has been found in itsourcecode Gym Management System 1.0. Affected by this issue is some unknown functionality of the file /view_member.php. The manipulation of the argument ID leads to sql injection. The... Read more
Affected Products : gym_management_system- Published: May. 06, 2025
- Modified: May. 28, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-4362
A vulnerability classified as critical was found in itsourcecode Gym Management System 1.0. This vulnerability affects unknown code of the file /ajax.php?action=save_membership. The manipulation of the argument member_id leads to sql injection. The attack... Read more
Affected Products : gym_management_system- Published: May. 06, 2025
- Modified: May. 28, 2025
- Vuln Type: Injection
-
8.8
HIGHCVE-2025-4372
Use after free in WebAudio in Google Chrome prior to 136.0.7103.92 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)... Read more
- Published: May. 06, 2025
- Modified: May. 28, 2025
- Vuln Type: Memory Corruption
-
5.4
MEDIUMCVE-2023-6487
The LuckyWP Table of Contents plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘Header Title' field in all versions up to and including 2.1.4 due to insufficient input sanitization and output escaping. This makes it possible for a... Read more
Affected Products : luckywp_table_of_contents- Published: May. 22, 2024
- Modified: May. 28, 2025
-
6.1
MEDIUMCVE-2024-2119
The LuckyWP Table of Contents plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the attrs parameter in all versions up to, and including, 2.1.4 due to insufficient input sanitization and output escaping. This makes it possible for u... Read more
Affected Products : luckywp_table_of_contents- Published: May. 22, 2024
- Modified: May. 28, 2025
-
5.5
MEDIUMCVE-2024-2953
The LuckyWP Table of Contents plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple parameters in versions up to, and including, 2.1.4 due to insufficient input sanitization and output escaping. This makes it possible for authenti... Read more
Affected Products : luckywp_table_of_contents- Published: May. 22, 2024
- Modified: May. 28, 2025
-
9.8
CRITICALCVE-2024-35409
WeBid 1.1.2 is vulnerable to SQL Injection via admin/tax.php.... Read more
Affected Products : webid- Published: May. 22, 2024
- Modified: May. 28, 2025
-
6.4
MEDIUMCVE-2024-1805
The wpbakery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the button onclick attribute in all versions up to, and including, 7.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated ... Read more
- Published: May. 02, 2024
- Modified: May. 28, 2025
-
6.4
MEDIUMCVE-2024-1840
The wpbakery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Post Author tag attribute in all versions up to, and including, 7.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated... Read more
- Published: May. 02, 2024
- Modified: May. 28, 2025
-
6.4
MEDIUMCVE-2024-1841
The wpbakery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Post Title tag attribute in all versions up to, and including, 7.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated ... Read more
- Published: May. 02, 2024
- Modified: May. 28, 2025
-
6.4
MEDIUMCVE-2024-1842
The wpbakery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Custom Heading tag attribute in all versions up to, and including, 7.5 due to insufficient input sanitization and output escaping. This makes it possible for authentica... Read more
- Published: May. 02, 2024
- Modified: May. 28, 2025
-
7.5
HIGHCVE-2024-22871
An issue in Clojure versions 1.20 to 1.12.0-alpha5 allows an attacker to cause a denial of service (DoS) via the clojure.core$partial$fn__5920 function.... Read more
- Published: Feb. 29, 2024
- Modified: May. 28, 2025
-
6.1
MEDIUMCVE-2023-50378
Lack of proper input validation and constraint enforcement in Apache Ambari prior to 2.7.8 Impact : As it will be stored XSS, Could be exploited to perform unauthorized actions, varying from data access to session hijacking and delivering malicious pa... Read more
Affected Products : ambari- Published: Mar. 01, 2024
- Modified: May. 28, 2025
-
7.5
HIGHCVE-2024-27138
** UNSUPPORTED WHEN ASSIGNED ** Incorrect Authorization vulnerability in Apache Archiva. Apache Archiva has a setting to disable user registration, however this restriction can be bypassed. As Apache Archiva has been retired, we do not expect to release ... Read more
Affected Products : archiva- Published: Mar. 01, 2024
- Modified: May. 28, 2025
-
7.5
HIGHCVE-2024-27139
** UNSUPPORTED WHEN ASSIGNED ** Incorrect Authorization vulnerability in Apache Archiva: a vulnerability in Apache Archiva allows an unauthenticated attacker to modify account data, potentially leading to account takeover. This issue affects Apache Arch... Read more
Affected Products : archiva- Published: Mar. 01, 2024
- Modified: May. 28, 2025
-
5.4
MEDIUMCVE-2024-27140
** UNSUPPORTED WHEN ASSIGNED ** Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache Archiva. This issue affects Apache Archiva: from 2.0.0. As this project is retired, we do not plan to release a... Read more
Affected Products : archiva- Published: Mar. 01, 2024
- Modified: May. 28, 2025
-
7.5
HIGHCVE-2024-24766
CasaOS-UserService provides user management functionalities to CasaOS. Starting in version 0.4.4.3 and prior to version 0.4.7, the Casa OS Login page disclosed the username enumeration vulnerability in the login page. An attacker can enumerate the CasaOS ... Read more
- Published: Mar. 06, 2024
- Modified: May. 28, 2025
-
8.8
HIGHCVE-2024-5709
The WPBakery Visual Composer plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 7.7 via the 'layout_name' parameter. This makes it possible for authenticated attackers, with Author-level access and above, and ... Read more
- Published: Aug. 06, 2024
- Modified: May. 28, 2025
-
6.1
MEDIUMCVE-2024-7082
The Easy Table of Contents WordPress plugin before 2.0.68 does not sanitise and escape some parameters, which could allow users with a role as low as Editor to perform Cross-Site Scripting attacks.... Read more
Affected Products : easy_table_of_contents- Published: Aug. 06, 2024
- Modified: May. 28, 2025