Latest CVE Feed
-
5.4
MEDIUMCVE-2024-1440
An open redirection vulnerability exists in multiple WSO2 products due to improper validation of the multi-option URL in the authentication endpoint when multi-option authentication is enabled. A malicious actor can craft a valid link that redirects users... Read more
Affected Products :- Published: Jun. 02, 2025
- Modified: Jun. 02, 2025
- Vuln Type: Misconfiguration
-
8.4
HIGHCVE-2024-12168
Yandex Telemost for Desktop before 2.7.0 has a DLL Hijacking Vulnerability because an untrusted search path is used.... Read more
Affected Products :- Published: Jun. 02, 2025
- Modified: Jun. 02, 2025
- Vuln Type: Misconfiguration
-
5.3
MEDIUMCVE-2025-5404
A vulnerability classified as problematic was found in chaitak-gorai Blogbook up to 92f5cf90f8a7e6566b576fe0952e14e1c6736513. This vulnerability affects unknown code of the file /search.php of the component GET Parameter Handler. The manipulation of the a... Read more
Affected Products :- Published: Jun. 01, 2025
- Modified: Jun. 02, 2025
- Vuln Type: Denial of Service
-
7.5
HIGHCVE-2025-5435
A vulnerability was found in Marwal Infotech CMS 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /page.php. The manipulation of the argument ID leads to sql injection. The attack can be initiated remotely. The ex... Read more
Affected Products :- Published: Jun. 02, 2025
- Modified: Jun. 02, 2025
- Vuln Type: Injection
-
2.6
LOWCVE-2025-48938
go-gh is a collection of Go modules to make authoring GitHub CLI extensions easier. A security vulnerability has been identified in versions prior to 2.12.1 where an attacker-controlled GitHub Enterprise Server could result in executing arbitrary commands... Read more
Affected Products :- Published: May. 30, 2025
- Modified: Jun. 02, 2025
- Vuln Type: Path Traversal
-
6.4
MEDIUMCVE-2025-4595
The FastSpring plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'fastspring/block-fastspringblocks-complete-product-catalog' block in all versions up to, and including, 3.0.1 due to insufficient input sanitization and out... Read more
Affected Products :- Published: May. 31, 2025
- Modified: Jun. 02, 2025
- Vuln Type: Cross-Site Scripting
-
9.8
CRITICALCVE-2025-4607
The PSW Front-end Login & Registration plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.12 via the customer_registration() function. This is due to the use of a weak, low-entropy OTP mechanism in the forge... Read more
Affected Products :- Published: May. 31, 2025
- Modified: Jun. 02, 2025
- Vuln Type: Authentication
-
9.8
CRITICALCVE-2025-4631
The Profitori plugin for WordPress is vulnerable to Privilege Escalation due to a missing capability check on the stocktend_object endpoint in versions 2.0.6.0 to 2.1.1.3. This makes it possible to trigger the save_object_as_user() function for objects wh... Read more
Affected Products :- Published: May. 31, 2025
- Modified: Jun. 02, 2025
- Vuln Type: Authentication
-
6.4
MEDIUMCVE-2025-5290
The Borderless – Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘title’ parameter in all versions up to, and including, 1.7.1 due to insufficient input sanitization and output escaping. This makes ... Read more
Affected Products :- Published: May. 31, 2025
- Modified: Jun. 02, 2025
- Vuln Type: Cross-Site Scripting
-
5.3
MEDIUMCVE-2025-5379
A vulnerability classified as critical was found in NuCom NC-WR744G 8.5.5 Build 20200530.307. This vulnerability affects unknown code of the component Console Application. The manipulation of the argument CMCCAdmin/useradmin/CUAdmin leads to hard-coded cr... Read more
Affected Products :- Published: May. 31, 2025
- Modified: Jun. 02, 2025
- Vuln Type: Authentication
-
6.5
MEDIUMCVE-2025-5386
A vulnerability was found in JeeWMS up to 20250504. It has been rated as critical. This issue affects the function transEditor of the file /cgformTransController.do?transEditor. The manipulation leads to sql injection. The attack may be initiated remotely... Read more
Affected Products :- Published: May. 31, 2025
- Modified: Jun. 02, 2025
- Vuln Type: Injection
-
6.5
MEDIUMCVE-2025-5389
A vulnerability, which was classified as critical, has been found in JeeWMS up to 20250504. Affected by this issue is the function dogenerateOne2Many of the file /generateController.do?dogenerateOne2Many of the component File Handler. The manipulation lea... Read more
Affected Products :- Published: May. 31, 2025
- Modified: Jun. 02, 2025
- Vuln Type: Authorization
-
7.5
HIGHCVE-2025-5401
A vulnerability was found in chaitak-gorai Blogbook up to 92f5cf90f8a7e6566b576fe0952e14e1c6736513. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /post.php of the component GET Parameter Handler. ... Read more
Affected Products :- Published: Jun. 01, 2025
- Modified: Jun. 02, 2025
- Vuln Type: Injection
-
7.5
HIGHCVE-2025-5402
A vulnerability was found in chaitak-gorai Blogbook up to 92f5cf90f8a7e6566b576fe0952e14e1c6736513. It has been rated as critical. Affected by this issue is some unknown functionality of the file /admin/includes/edit_post.php of the component GET Paramete... Read more
Affected Products :- Published: Jun. 01, 2025
- Modified: Jun. 02, 2025
- Vuln Type: Injection
-
7.5
HIGHCVE-2025-5409
A vulnerability was found in Mist Community Edition up to 4.7.1. It has been classified as critical. This affects the function create_token of the file src/mist/api/auth/views.py of the component API Token Handler. The manipulation leads to improper acces... Read more
Affected Products :- Published: Jun. 01, 2025
- Modified: Jun. 02, 2025
- Vuln Type: Authorization
-
5.3
MEDIUMCVE-2025-5410
A vulnerability was found in Mist Community Edition up to 4.7.1. It has been declared as problematic. This vulnerability affects the function session_start_response of the file src/mist/api/auth/middleware.py. The manipulation leads to cross-site request ... Read more
Affected Products :- Published: Jun. 01, 2025
- Modified: Jun. 02, 2025
- Vuln Type: Cross-Site Request Forgery
-
8.5
HIGHCVE-2024-11857
Bluetooth HCI Adaptor from Realtek has a Link Following vulnerability. Local attackers with regular privileges can create a symbolic link with the same name as a specific file, causing the product to delete arbitrary files pointed to by the link. Subseque... Read more
Affected Products :- Published: Jun. 02, 2025
- Modified: Jun. 02, 2025
- Vuln Type: Path Traversal
-
4.3
MEDIUMCVE-2025-1235
A low privileged attacker can set the date of the devices to the 19th of January 2038 an therefore exceed the 32-Bit time limit. This causes the date of the switch to be set back to January 1st, 1970.... Read more
Affected Products :- Published: Jun. 02, 2025
- Modified: Jun. 02, 2025
- Vuln Type: Misconfiguration
-
8.6
HIGHCVE-2025-4010
The Netcom NTC 6200 and NWL 222 series expose a web interface to be configured and set up by operators. Multiple endpoints of the web interface are vulnerable to arbitrary command injection and use insecure hardcoded passwords. Remote authenticated attack... Read more
Affected Products :- Published: Jun. 02, 2025
- Modified: Jun. 02, 2025
- Vuln Type: Injection
-
8.8
HIGHCVE-2025-0358
During an annual penetration test conducted on behalf of Axis Communication, Truesec discovered a flaw in the VAPIX Device Configuration framework that allowed a privilege escalation, enabling a lower-privileged user to gain administrator privileges.... Read more
Affected Products : axis_os- Published: Jun. 02, 2025
- Modified: Jun. 02, 2025
- Vuln Type: Authorization