Latest CVE Feed
-
6.5
MEDIUMCVE-2025-5387
A vulnerability classified as critical has been found in JeeWMS up to 20250504. Affected is the function dogenerate of the file /generateController.do?dogenerate of the component File Handler. The manipulation leads to improper access controls. It is poss... Read more
Affected Products :- Published: May. 31, 2025
- Modified: Jun. 02, 2025
- Vuln Type: Authorization
-
10.0
HIGHCVE-2025-5408
A vulnerability was found in WAVLINK QUANTUM D2G, QUANTUM D3G, WL-WN530G3A, WL-WN530HG3, WL-WN532A3 and WL-WN576K1 up to V1410_240222 and classified as critical. Affected by this issue is the function sys_login of the file /cgi-bin/login.cgi of the compon... Read more
Affected Products :- Published: Jun. 01, 2025
- Modified: Jun. 02, 2025
- Vuln Type: Memory Corruption
-
9.4
CRITICALCVE-2025-0324
The VAPIX Device Configuration framework allowed a privilege escalation, enabling a lower-privileged user to gain administrator privileges.... Read more
Affected Products : axis_os- Published: Jun. 02, 2025
- Modified: Jun. 02, 2025
- Vuln Type: Authorization
-
8.6
HIGHCVE-2025-48990
NeKernal is a free and open-source operating system stack. Version 0.0.2 has a 1-byte heap overflow in `rt_copy_memory`, which unconditionally wrote a null terminator at `dst[len]`. When `len` equals the size of the destination buffer (256 bytes), that ex... Read more
Affected Products :- Published: Jun. 02, 2025
- Modified: Jun. 02, 2025
- Vuln Type: Memory Corruption
-
6.5
MEDIUMCVE-2025-5406
A vulnerability, which was classified as critical, was found in chaitak-gorai Blogbook up to 92f5cf90f8a7e6566b576fe0952e14e1c6736513. Affected is an unknown function of the file /admin/posts.php?source=add_post. The manipulation of the argument image lea... Read more
Affected Products :- Published: Jun. 01, 2025
- Modified: Jun. 02, 2025
- Vuln Type: Authentication
-
6.4
MEDIUMCVE-2025-5292
The Element Pack Addons for Elementor – Best Elementor addons with Ready Templates, Blocks, Widgets and WooCommerce Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'marker_content’ parameter in all versions up to, and inc... Read more
Affected Products : element_pack- Published: May. 31, 2025
- Modified: Jun. 02, 2025
- Vuln Type: Cross-Site Scripting
-
5.0
MEDIUMCVE-2025-3454
This vulnerability in Grafana's datasource proxy API allows authorization checks to be bypassed by adding an extra slash character in the URL path. Users with minimal permissions could gain unauthorized read access to GET endpoints in Alertmanager and Pr... Read more
Affected Products : grafana- Published: Jun. 02, 2025
- Modified: Jun. 02, 2025
- Vuln Type: Authorization
-
6.9
MEDIUMCVE-2025-5437
A vulnerability classified as critical has been found in Multilaser Sirius RE016 MLT1.0. Affected is an unknown function of the file /cgi-bin/cstecgi.cgi of the component Password Change Handler. The manipulation leads to improper authentication. It is po... Read more
Affected Products :- Published: Jun. 02, 2025
- Modified: Jun. 02, 2025
- Vuln Type: Authentication
-
8.5
HIGHCVE-2025-2501
An untrusted search path vulnerability was reported in Lenovo PC Manager that could allow a local attacker to elevate privileges.... Read more
Affected Products : pc_manager- Published: May. 30, 2025
- Modified: Jun. 02, 2025
- Vuln Type: Path Traversal
-
5.3
MEDIUMCVE-2025-5378
A vulnerability classified as problematic has been found in Astun Technology iShare Maps 5.4.0. This affects an unknown part of the file mycouncil2.aspx. The manipulation of the argument atTxtStreet leads to cross site scripting. It is possible to initiat... Read more
Affected Products :- Published: May. 31, 2025
- Modified: Jun. 02, 2025
- Vuln Type: Cross-Site Scripting
-
4.8
MEDIUMCVE-2025-5407
A vulnerability has been found in chaitak-gorai Blogbook up to 92f5cf90f8a7e6566b576fe0952e14e1c6736513 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /register_script.php. The manipulation of the arg... Read more
Affected Products :- Published: Jun. 01, 2025
- Modified: Jun. 02, 2025
- Vuln Type: Cross-Site Scripting
-
7.5
HIGHCVE-2025-5400
A vulnerability was found in chaitak-gorai Blogbook up to 92f5cf90f8a7e6566b576fe0952e14e1c6736513. It has been classified as critical. Affected is an unknown function of the file /user.php of the component GET Parameter Handler. The manipulation of the a... Read more
Affected Products :- Published: Jun. 01, 2025
- Modified: Jun. 02, 2025
- Vuln Type: Injection
-
6.5
MEDIUMCVE-2025-5403
A vulnerability classified as critical has been found in chaitak-gorai Blogbook up to 92f5cf90f8a7e6566b576fe0952e14e1c6736513. This affects an unknown part of the file /admin/view_all_posts.php of the component GET Parameter Handler. The manipulation of ... Read more
Affected Products :- Published: Jun. 01, 2025
- Modified: Jun. 02, 2025
- Vuln Type: Injection
-
6.5
MEDIUMCVE-2025-5385
A vulnerability was found in JeeWMS up to 20250504. It has been declared as critical. This vulnerability affects the function doAdd of the file /cgformTemplateController.do?doAdd. The manipulation leads to path traversal. The attack can be initiated remot... Read more
Affected Products :- Published: May. 31, 2025
- Modified: Jun. 02, 2025
- Vuln Type: Path Traversal
-
6.5
MEDIUMCVE-2025-5388
A vulnerability classified as critical was found in JeeWMS up to 20250504. Affected by this vulnerability is the function dogenerate of the file /generateController.do?dogenerate. The manipulation leads to sql injection. The attack can be launched remotel... Read more
Affected Products :- Published: May. 31, 2025
- Modified: Jun. 02, 2025
- Vuln Type: Injection
-
6.4
MEDIUMCVE-2025-5285
The Product Subtitle for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘htmlTag’ parameter in all versions up to, and including, 1.3.9 due to insufficient input sanitization and output escaping. This makes it possib... Read more
Affected Products :- Published: May. 31, 2025
- Modified: Jun. 02, 2025
- Vuln Type: Cross-Site Scripting
-
5.1
MEDIUMCVE-2025-5411
A vulnerability was found in Mist Community Edition up to 4.7.1. It has been rated as problematic. This issue affects the function tag_resources of the file src/mist/api/tag/views.py. The manipulation of the argument tag leads to cross site scripting. The... Read more
Affected Products :- Published: Jun. 01, 2025
- Modified: Jun. 02, 2025
- Vuln Type: Cross-Site Scripting
-
6.5
MEDIUMCVE-2025-5384
A vulnerability was found in JeeWMS up to 20250504. It has been classified as critical. This affects the function CgAutoListController of the file /cgAutoListController.do?datagrid. The manipulation leads to sql injection. It is possible to initiate the a... Read more
Affected Products :- Published: May. 31, 2025
- Modified: Jun. 02, 2025
- Vuln Type: Injection
-
7.5
HIGHCVE-2025-5434
A vulnerability was found in Aem Solutions CMS up to 1.0. It has been classified as critical. This affects an unknown part of the file /page.php. The manipulation of the argument ID leads to sql injection. It is possible to initiate the attack remotely. T... Read more
Affected Products :- Published: Jun. 02, 2025
- Modified: Jun. 02, 2025
- Vuln Type: Injection
-
4.7
MEDIUMCVE-2025-5016
The Relevanssi – A Better Search plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Excerpt Highlights in all versions up to, and including, 4.24.5 (Free) and 2.27.6 (Premium) due to insufficient input sanitization and output escapi... Read more
Affected Products : relevanssi- Published: May. 31, 2025
- Modified: Jun. 02, 2025
- Vuln Type: Cross-Site Scripting