Latest CVE Feed
-
6.4
MEDIUMCVE-2024-1842
The wpbakery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Custom Heading tag attribute in all versions up to, and including, 7.5 due to insufficient input sanitization and output escaping. This makes it possible for authentica... Read more
- Published: May. 02, 2024
- Modified: May. 28, 2025
-
7.5
HIGHCVE-2024-22871
An issue in Clojure versions 1.20 to 1.12.0-alpha5 allows an attacker to cause a denial of service (DoS) via the clojure.core$partial$fn__5920 function.... Read more
- Published: Feb. 29, 2024
- Modified: May. 28, 2025
-
6.1
MEDIUMCVE-2023-50378
Lack of proper input validation and constraint enforcement in Apache Ambari prior to 2.7.8 Impact : As it will be stored XSS, Could be exploited to perform unauthorized actions, varying from data access to session hijacking and delivering malicious pa... Read more
Affected Products : ambari- Published: Mar. 01, 2024
- Modified: May. 28, 2025
-
7.5
HIGHCVE-2024-27138
** UNSUPPORTED WHEN ASSIGNED ** Incorrect Authorization vulnerability in Apache Archiva. Apache Archiva has a setting to disable user registration, however this restriction can be bypassed. As Apache Archiva has been retired, we do not expect to release ... Read more
Affected Products : archiva- Published: Mar. 01, 2024
- Modified: May. 28, 2025
-
7.5
HIGHCVE-2024-27139
** UNSUPPORTED WHEN ASSIGNED ** Incorrect Authorization vulnerability in Apache Archiva: a vulnerability in Apache Archiva allows an unauthenticated attacker to modify account data, potentially leading to account takeover. This issue affects Apache Arch... Read more
Affected Products : archiva- Published: Mar. 01, 2024
- Modified: May. 28, 2025
-
5.4
MEDIUMCVE-2024-27140
** UNSUPPORTED WHEN ASSIGNED ** Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache Archiva. This issue affects Apache Archiva: from 2.0.0. As this project is retired, we do not plan to release a... Read more
Affected Products : archiva- Published: Mar. 01, 2024
- Modified: May. 28, 2025
-
7.5
HIGHCVE-2024-24766
CasaOS-UserService provides user management functionalities to CasaOS. Starting in version 0.4.4.3 and prior to version 0.4.7, the Casa OS Login page disclosed the username enumeration vulnerability in the login page. An attacker can enumerate the CasaOS ... Read more
- Published: Mar. 06, 2024
- Modified: May. 28, 2025
-
8.8
HIGHCVE-2024-5709
The WPBakery Visual Composer plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 7.7 via the 'layout_name' parameter. This makes it possible for authenticated attackers, with Author-level access and above, and ... Read more
- Published: Aug. 06, 2024
- Modified: May. 28, 2025
-
6.1
MEDIUMCVE-2024-7082
The Easy Table of Contents WordPress plugin before 2.0.68 does not sanitise and escape some parameters, which could allow users with a role as low as Editor to perform Cross-Site Scripting attacks.... Read more
Affected Products : easy_table_of_contents- Published: Aug. 06, 2024
- Modified: May. 28, 2025
-
4.8
MEDIUMCVE-2024-7084
The Ajax Search Lite WordPress plugin before 4.12.1 does not sanitise and escape some parameters, which could allow users with a role as low as Admin+ to perform Cross-Site Scripting attacks.... Read more
- Published: Aug. 06, 2024
- Modified: May. 28, 2025
-
4.8
MEDIUMCVE-2024-3973
The House Manager WordPress plugin through 1.0.8.4 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin... Read more
Affected Products : house_manager- Published: Aug. 07, 2024
- Modified: May. 28, 2025
-
4.8
MEDIUMCVE-2024-6481
The Search & Filter Pro WordPress plugin before 2.5.18 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disal... Read more
Affected Products : search_\&_filter- Published: Aug. 08, 2024
- Modified: May. 28, 2025
-
7.5
HIGHCVE-2024-7704
A vulnerability was found in Weaver e-cology 8. It has been classified as problematic. Affected is an unknown function of the file /cloudstore/ecode/setup/ecology_dev.zip of the component Source Code Handler. The manipulation leads to information disclosu... Read more
Affected Products : e-cology- Published: Aug. 12, 2024
- Modified: May. 28, 2025
-
9.8
CRITICALCVE-2025-3242
A vulnerability has been found in PHPGurukul e-Diary Management System 1.0 and classified as critical. This vulnerability affects unknown code of the file /search-result.php. The manipulation of the argument id/searchdata leads to sql injection. The attac... Read more
Affected Products : e-diary_management_system- Published: Apr. 04, 2025
- Modified: May. 28, 2025
- Vuln Type: Injection
-
7.5
HIGHCVE-2025-3211
A vulnerability classified as critical has been found in code-projects Patient Record Management System 1.0. This affects an unknown part of the file /birthing_print.php. The manipulation of the argument itr_no/birth_id leads to sql injection. It is possi... Read more
- Published: Apr. 04, 2025
- Modified: May. 28, 2025
- Vuln Type: Injection
-
7.8
HIGHCVE-2025-4501
A vulnerability, which was classified as critical, was found in code-projects Album Management System 1.0. This affects the function searchalbum of the component Search Albums. The manipulation leads to stack-based buffer overflow. Local access is require... Read more
Affected Products : album_management_system- Published: May. 10, 2025
- Modified: May. 28, 2025
- Vuln Type: Memory Corruption
-
7.8
HIGHCVE-2025-4499
A vulnerability classified as critical was found in code-projects Simple Hospital Management System 1.0. Affected by this vulnerability is the function Add of the component Add Information. The manipulation of the argument x[i].name/x[i].disease leads to ... Read more
Affected Products : simple_hospital_management_system- Published: May. 10, 2025
- Modified: May. 28, 2025
- Vuln Type: Memory Corruption
-
7.8
HIGHCVE-2025-4498
A vulnerability classified as critical has been found in code-projects Simple Bus Reservation System 1.0. Affected is the function a::install of the component Install Bus. The manipulation of the argument bus leads to stack-based buffer overflow. It is po... Read more
Affected Products : simple_bus_reservation_system- Published: May. 10, 2025
- Modified: May. 28, 2025
- Vuln Type: Memory Corruption
-
7.5
HIGHCVE-2024-57698
An issue in modernwms v.1.0 allows an attacker view the MD5 hash of the administrator password and other attributes without authentication, even after initial configuration and password change. This happens due to excessive exposure of information and the... Read more
Affected Products : modernwms- Published: Apr. 29, 2025
- Modified: May. 28, 2025
- Vuln Type: Information Disclosure
-
7.5
HIGHCVE-2025-46560
vLLM is a high-throughput and memory-efficient inference and serving engine for LLMs. Versions starting from 0.8.0 and prior to 0.8.5 are affected by a critical performance vulnerability in the input preprocessing logic of the multimodal tokenizer. The co... Read more
Affected Products : vllm- Published: Apr. 30, 2025
- Modified: May. 28, 2025
- Vuln Type: Denial of Service