Latest CVE Feed
-
8.8
HIGHCVE-2025-48136
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Estatik Mortgage Calculator Estatik allows PHP Local File Inclusion. This issue affects Mortgage Calculator Estatik: from n/a through ... Read more
- Published: May. 16, 2025
- Modified: May. 30, 2025
- Vuln Type: Path Traversal
-
8.5
HIGHCVE-2025-48137
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in proxymis Interview allows SQL Injection. This issue affects Interview: from n/a through 1.01.... Read more
Affected Products : interview- Published: May. 16, 2025
- Modified: May. 30, 2025
- Vuln Type: Injection
-
6.5
MEDIUMCVE-2025-48135
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in aptivadadev Aptivada for WP allows DOM-Based XSS. This issue affects Aptivada for WP: from n/a through 2.0.0.... Read more
Affected Products : aptivada_for_wp- Published: May. 16, 2025
- Modified: May. 30, 2025
- Vuln Type: Cross-Site Scripting
-
7.2
HIGHCVE-2025-48134
Deserialization of Untrusted Data vulnerability in ShapedPlugin LLC WP Tabs allows Object Injection. This issue affects WP Tabs: from n/a through 2.2.11.... Read more
Affected Products : wp_tabs- Published: May. 16, 2025
- Modified: May. 30, 2025
- Vuln Type: Injection
-
6.5
MEDIUMCVE-2025-48132
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in pencilwp X Addons for Elementor allows Stored XSS. This issue affects X Addons for Elementor: from n/a through 1.0.14.... Read more
Affected Products : x_addons_for_elementor- Published: May. 16, 2025
- Modified: May. 30, 2025
- Vuln Type: Cross-Site Scripting
-
6.1
MEDIUMCVE-2023-30394
The MoveIt framework 1.1.11 for ROS allows cross-site scripting (XSS) via the API authentication function. NOTE: this issue is disputed by the original reporter because it has "no impact."... Read more
Affected Products : moveit- Published: May. 11, 2023
- Modified: May. 30, 2025
-
8.8
HIGHCVE-2024-35388
TOTOLINK NR1800X v9.1.0u.6681_B20230703 was discovered to contain a stack overflow via the password parameter in the function urldecode... Read more
- Published: May. 24, 2024
- Modified: May. 30, 2025
-
8.1
HIGHCVE-2024-33377
LB-LINK BL-W1210M v2.0 was discovered to contain a clickjacking vulnerability via the Administrator login page. Attackers can cause victim users to perform arbitrary operations via interaction with crafted elements on the web page.... Read more
- Published: Jun. 14, 2024
- Modified: May. 30, 2025
-
9.8
CRITICALCVE-2024-33375
LB-LINK BL-W1210M v2.0 was discovered to store user credentials in plaintext within the router's firmware.... Read more
- Published: Jun. 14, 2024
- Modified: May. 30, 2025
-
8.8
HIGHCVE-2024-3767
A vulnerability classified as critical was found in PHPGurukul News Portal 4.1. This vulnerability affects unknown code of the file /admin/edit-post.php. The manipulation of the argument posttitle/category leads to sql injection. The attack can be initiat... Read more
- Published: Apr. 15, 2024
- Modified: May. 30, 2025
-
9.8
CRITICALCVE-2025-4226
A vulnerability classified as critical has been found in PHPGurukul/Campcodes Cyber Cafe Management System 1.0. This affects an unknown part of the file /add-computer.php. The manipulation of the argument compname/comploc leads to sql injection. It is pos... Read more
Affected Products : cyber_cafe_management_system- Published: May. 03, 2025
- Modified: May. 30, 2025
- Vuln Type: Injection
-
8.8
HIGHCVE-2025-4695
A vulnerability was found in PHPGurukul/Campcodes Cyber Cafe Management System 1.0. It has been classified as critical. Affected is an unknown function of the file /add-users.php. The manipulation of the argument uadd leads to sql injection. It is possibl... Read more
Affected Products : cyber_cafe_management_system- Published: May. 15, 2025
- Modified: May. 30, 2025
- Vuln Type: Injection
-
8.1
HIGHCVE-2024-42514
A vulnerability in the legacy chat component of Mitel MiContact Center Business through 10.1.0.4 could allow an unauthenticated attacker to conduct an unauthorized access attack due to inadequate access control checks. A successful exploit requires user i... Read more
Affected Products : micontact_center_business- Published: Oct. 01, 2024
- Modified: May. 30, 2025
-
9.8
CRITICALCVE-2025-44881
A command injection vulnerability in the component /cgi-bin/qos.cgi of Wavlink WL-WN579A3 v1.0 allows attackers to execute arbitrary commands via a crafted input.... Read more
- Published: May. 20, 2025
- Modified: May. 30, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-44880
A command injection vulnerability in the component /cgi-bin/adm.cgi of Wavlink WL-WN579A3 v1.0 allows attackers to execute arbitrary commands via a crafted input.... Read more
- Published: May. 20, 2025
- Modified: May. 30, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-44882
A command injection vulnerability in the component /cgi-bin/firewall.cgi of Wavlink WL-WN579A3 v1.0 allows attackers to execute arbitrary commands via a crafted input.... Read more
- Published: May. 20, 2025
- Modified: May. 30, 2025
- Vuln Type: Injection
-
8.8
HIGHCVE-2025-33136
IBM Aspera Faspex 5.0.0 through 5.0.12 could allow an authenticated user to obtain sensitive information or perform unauthorized actions on behalf of another user due to improper protection of assumed immutable data.... Read more
- Published: May. 22, 2025
- Modified: May. 30, 2025
- Vuln Type: Authorization
-
8.8
HIGHCVE-2025-33137
IBM Aspera Faspex 5.0.0 through 5.0.12 could allow an authenticated user to obtain sensitive information or perform unauthorized actions on behalf of another user due to client-side enforcement of server-side security.... Read more
- Published: May. 22, 2025
- Modified: May. 30, 2025
- Vuln Type: Authentication
-
6.1
MEDIUMCVE-2025-33138
IBM Aspera Faspex 5.0.0 through 5.0.12 is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the victim's Web browser within the security context of the hosting site.... Read more
- Published: May. 22, 2025
- Modified: May. 30, 2025
- Vuln Type: Cross-Site Scripting
-
8.8
HIGHCVE-2024-52874
In Infoblox NETMRI before 7.6.1, authenticated users can perform SQL injection attacks.... Read more
Affected Products : netmri- Published: May. 22, 2025
- Modified: May. 30, 2025
- Vuln Type: Injection