Latest CVE Feed
-
9.8
CRITICALCVE-2023-27168
An arbitrary file upload vulnerability in Xpand IT Write-back Manager v2.3.1 allows attackers to execute arbitrary code via a crafted jsp file.... Read more
Affected Products : write-back_manager- EPSS Score: %0.24
- Published: Jan. 19, 2024
- Modified: Jun. 02, 2025
-
6.1
MEDIUMCVE-2023-0769
The hiWeb Migration Simple WordPress plugin through 2.0.0.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high-privilege users such as admins.... Read more
Affected Products : migration_simple- EPSS Score: %0.28
- Published: Jan. 16, 2024
- Modified: Jun. 02, 2025
-
5.4
MEDIUMCVE-2023-0376
The Qubely WordPress plugin before 1.8.5 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site S... Read more
Affected Products : qubely- EPSS Score: %0.23
- Published: Jan. 16, 2024
- Modified: Jun. 02, 2025
-
6.5
MEDIUMCVE-2024-21726
Inadequate content filtering leads to XSS vulnerabilities in various components.... Read more
Affected Products : joomla\!- Published: Feb. 29, 2024
- Modified: Jun. 02, 2025
-
6.4
MEDIUMCVE-2023-50726
Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. "Local sync" is an Argo CD feature that allows developers to temporarily override an Application's manifests with locally-defined manifests. Use of the feature should generally be l... Read more
- Published: Mar. 13, 2024
- Modified: Jun. 02, 2025
-
8.8
HIGHCVE-2024-25228
Vinchin Backup and Recovery 7.2 and Earlier is vulnerable to Authenticated Remote Code Execution (RCE) via the getVerifydiyResult function in ManoeuvreHandler.class.php.... Read more
Affected Products : vinchin_backup_and_recovery- Published: Mar. 14, 2024
- Modified: Jun. 02, 2025
-
7.5
HIGHCVE-2024-28069
A vulnerability in the legacy chat component of Mitel MiContact Center Business through 10.0.0.4 could allow an unauthenticated attacker to conduct an information disclosure attack due to improper configuration. A successful exploit could allow an attacke... Read more
Affected Products : micontact_center_business- Published: Mar. 16, 2024
- Modified: Jun. 02, 2025
-
6.8
MEDIUMCVE-2024-28070
A vulnerability in the legacy chat component of Mitel MiContact Center Business through 10.0.0.4 could allow an unauthenticated attacker to conduct a reflected cross-site scripting (XSS) attack due to insufficient input validation. A successful exploit co... Read more
Affected Products : micontact_center_business- Published: Mar. 16, 2024
- Modified: Jun. 02, 2025
-
9.8
CRITICALCVE-2024-28123
Wasmi is an efficient and lightweight WebAssembly interpreter with a focus on constrained and embedded systems. In the WASMI Interpreter, an Out-of-bounds Buffer Write will arise if the host calls or resumes a Wasm function with more parameters than the d... Read more
Affected Products : wasmi- Published: Mar. 21, 2024
- Modified: Jun. 02, 2025
-
7.5
HIGHCVE-2024-28286
In mz-automation libiec61850 v1.4.0, a NULL Pointer Dereference was detected in the mmsServer_handleFileCloseRequest.c function of src/mms/iso_mms/server/mms_file_service.c. The vulnerability manifests as SEGV and causes the application to crash... Read more
Affected Products : libiec61850- Published: Mar. 21, 2024
- Modified: Jun. 02, 2025
-
6.1
MEDIUMCVE-2024-26468
A DOM based cross-site scripting (XSS) vulnerability in the component index.html of jstrieb/urlpages before commit 035b647 allows attackers to execute arbitrary Javascript via sending a crafted URL.... Read more
Affected Products : url_pages- Published: Feb. 26, 2024
- Modified: Jun. 02, 2025
-
6.1
MEDIUMCVE-2024-26467
A DOM based cross-site scripting (XSS) vulnerability in the component generator.html of tabatkins/railroad-diagrams before commit ea9a123 allows attackers to execute arbitrary Javascript via sending a crafted URL.... Read more
Affected Products : railroad-diagram_generator- Published: Feb. 26, 2024
- Modified: Jun. 02, 2025
-
7.5
HIGHCVE-2022-37620
A Regular Expression Denial of Service (ReDoS) flaw was found in kangax html-minifier 4.0.0 because of the reCustomIgnore regular expression.... Read more
- EPSS Score: %0.09
- Published: Oct. 31, 2022
- Modified: Jun. 01, 2025
-
5.6
MEDIUMCVE-2025-1647
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Bootstrap allows Cross-Site Scripting (XSS).This issue affects Bootstrap: from 3.4.1 before 4.0.0.... Read more
Affected Products : bootstrap- Published: May. 15, 2025
- Modified: Jun. 01, 2025
- Vuln Type: Cross-Site Scripting
-
7.8
HIGHCVE-2022-41322
In Kitty before 0.26.2, insufficient validation in the desktop notification escape sequence can lead to arbitrary code execution. The user must display attacker-controlled content in the terminal, then click on a notification popup.... Read more
- EPSS Score: %0.87
- Published: Sep. 23, 2022
- Modified: Jun. 01, 2025
-
6.5
MEDIUMCVE-2025-5321
A vulnerability classified as critical was found in aimhubio aim up to 3.29.1. This vulnerability affects the function RestrictedPythonQuery of the file /aim/storage/query.py of the component run_view Object Handler. The manipulation of the argument Abfra... Read more
Affected Products : aim- Published: May. 29, 2025
- Modified: Jun. 01, 2025
- Vuln Type: Authorization
-
6.3
MEDIUMCVE-2025-5320
A vulnerability classified as problematic has been found in gradio-app gradio up to 5.29.1. This affects the function is_valid_origin of the component CORS Handler. The manipulation of the argument localhost_aliases leads to erweiterte Rechte. It is possi... Read more
Affected Products : gradio- Published: May. 29, 2025
- Modified: Jun. 01, 2025
- Vuln Type: Authorization
-
5.4
MEDIUMCVE-2025-5283
Use after free in libvpx in Google Chrome prior to 137.0.7151.55 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)... Read more
- Published: May. 27, 2025
- Modified: May. 31, 2025
- Vuln Type: Memory Corruption
-
6.6
MEDIUMCVE-2025-46836
net-tools is a collection of programs that form the base set of the NET-3 networking distribution for the Linux operating system. Inn versions up to and including 2.10, the Linux network utilities (like ifconfig) from the net-tools package do not properly... Read more
Affected Products : net-tools- Published: May. 14, 2025
- Modified: May. 31, 2025
- Vuln Type: Memory Corruption
-
8.1
HIGHCVE-2025-23368
A flaw was found in Wildfly Elytron integration. The component does not implement sufficient measures to prevent multiple failed authentication attempts within a short time frame, making it more susceptible to brute force attacks via CLI.... Read more
Affected Products :- Published: Mar. 04, 2025
- Modified: May. 31, 2025