Latest CVE Feed
-
5.5
MEDIUMCVE-2022-48504
The issue was addressed with improved handling of caches. This issue is fixed in macOS Ventura 13. An app may be able to access user-sensitive data.... Read more
Affected Products : macos- EPSS Score: %0.14
- Published: Jan. 10, 2024
- Modified: Jun. 03, 2025
-
7.8
HIGH- EPSS Score: %0.12
- Published: Jan. 08, 2024
- Modified: Jun. 03, 2025
-
9.8
CRITICALCVE-2022-39009
The WLAN module has a vulnerability in permission verification. Successful exploitation of this vulnerability may cause third-party apps to affect WLAN functions.... Read more
- EPSS Score: %0.13
- Published: Sep. 16, 2022
- Modified: Jun. 03, 2025
-
4.9
MEDIUMCVE-2020-26627
A Time-Based SQL Injection vulnerability was discovered in Hospital Management System V4.0 which can allow an attacker to dump database information via a crafted payload entered into the 'Admin Remark' parameter under the 'Contact Us Queries -> Unread Que... Read more
- EPSS Score: %0.12
- Published: Jan. 10, 2024
- Modified: Jun. 03, 2025
-
3.8
LOWCVE-2020-26623
SQL Injection vulnerability discovered in Gila CMS 1.15.4 and earlier allows a remote attacker to execute arbitrary web scripts via the Area parameter under the Administration>Widget tab after the login portal.... Read more
Affected Products : gila_cms- EPSS Score: %0.26
- Published: Jan. 02, 2024
- Modified: Jun. 03, 2025
-
9.8
CRITICALCVE-2018-25095
The Duplicator WordPress plugin before 1.3.0 does not properly escape values when its installer script replaces values in WordPress configuration files. If this installer script is left on the site after use, it could be use to run arbitrary code on the s... Read more
Affected Products : duplicator- EPSS Score: %0.66
- Published: Jan. 08, 2024
- Modified: Jun. 03, 2025
-
4.7
MEDIUMCVE-2024-22776
Wallos 0.9 is vulnerable to Cross Site Scripting (XSS) in all text-based input fields without proper validation, excluding those requiring specific formats like date fields.... Read more
Affected Products : wallos- Published: Feb. 23, 2024
- Modified: Jun. 03, 2025
-
8.1
HIGHCVE-2024-29320
Wallos before 1.15.3 is vulnerable to SQL Injection via the category and payment parameters to /subscriptions/get.php.... Read more
Affected Products : wallos- Published: Apr. 30, 2024
- Modified: Jun. 03, 2025
-
9.8
CRITICALCVE-2024-55371
Wallos <= 2.38.2 has a file upload vulnerability in the restore backup function, which allows authenticated users to restore backups by uploading a ZIP file. The contents of the ZIP file are extracted on the server. This functionality enables an authentic... Read more
Affected Products : wallos- Published: Apr. 16, 2025
- Modified: Jun. 03, 2025
- Vuln Type: Misconfiguration
-
9.8
CRITICALCVE-2024-55372
Wallos <=2.38.2 has a file upload vulnerability in the restore database function, which allows unauthenticated users to restore database by uploading a ZIP file. The contents of the ZIP file are extracted on the server. This functionality enables an unaut... Read more
Affected Products : wallos- Published: Apr. 16, 2025
- Modified: Jun. 03, 2025
- Vuln Type: Misconfiguration
-
4.8
MEDIUMCVE-2024-51508
Tiki through 27.0 allows users who have certain permissions to insert a "Create/Edit External Wiki" stored XSS payload in the Index.... Read more
- Published: Oct. 28, 2024
- Modified: Jun. 03, 2025
-
4.8
MEDIUMCVE-2024-51509
Tiki through 27.0 allows users who have certain permissions to insert a "Modules" (aka tiki-admin_modules.php) stored XSS payload in the Name.... Read more
- Published: Oct. 28, 2024
- Modified: Jun. 03, 2025
-
4.8
MEDIUMCVE-2024-51507
Tiki through 27.0 allows users who have certain permissions to insert a "Create/Edit External Wiki" stored XSS payload in the Name.... Read more
- Published: Oct. 28, 2024
- Modified: Jun. 03, 2025
-
4.8
MEDIUMCVE-2024-51506
Tiki through 27.0 allows users who have certain permissions to insert a "Create a Wiki Pages" stored XSS payload in the description.... Read more
- Published: Oct. 28, 2024
- Modified: Jun. 03, 2025
-
5.0
MEDIUMCVE-2025-47226
Grokability Snipe-IT before 8.1.0 has incorrect authorization for accessing asset information.... Read more
Affected Products : snipe-it- Published: May. 02, 2025
- Modified: Jun. 03, 2025
- Vuln Type: Authorization
-
9.8
CRITICALCVE-2020-16165
The DAO/DTO implementation in SpringBlade through 2.7.1 allows SQL Injection in an ORDER BY clause. This is related to the /api/blade-log/api/list ascs and desc parameters.... Read more
- EPSS Score: %0.24
- Published: Jul. 30, 2020
- Modified: Jun. 03, 2025
-
7.5
HIGHCVE-2024-33332
An issue discovered in SpringBlade 3.7.1 allows attackers to obtain sensitive information via crafted GET request to api/blade-system/tenant.... Read more
Affected Products : springblade- Published: Apr. 30, 2024
- Modified: Jun. 03, 2025
-
8.8
HIGHCVE-2024-43033
JPress through 5.1.1 on Windows has an arbitrary file upload vulnerability that could cause arbitrary code execution via ::$DATA to AttachmentController, such as a .jsp::$DATA file to io.jpress.web.commons.controller.AttachmentController#upload. NOTE: thi... Read more
- Published: Aug. 22, 2024
- Modified: Jun. 03, 2025
-
7.5
HIGHCVE-2024-32358
An issue in Jpress v.5.1.0 allows a remote attacker to execute arbitrary code via a crafted script to the custom plug-in module function, a different vulnerability than CVE-2024-43033.... Read more
Affected Products : jpress- Published: Apr. 25, 2024
- Modified: Jun. 03, 2025
-
6.2
MEDIUMCVE-2024-51058
Local File Inclusion (LFI) vulnerability has been discovered in TCPDF 6.7.5. This vulnerability enables a user to read arbitrary files from the server's file system through <img> src tag, potentially exposing sensitive information.... Read more
Affected Products : tcpdf- Published: Nov. 26, 2024
- Modified: Jun. 03, 2025