Latest CVE Feed
-
6.1
MEDIUMCVE-2024-25807
Cross Site Scripting (XSS) vulnerability in Lychee 3.1.6, allows remote attackers to execute arbitrary code and obtain sensitive information via the title parameter when creating an album.... Read more
Affected Products : lychee- Published: Mar. 22, 2024
- Modified: May. 28, 2025
-
5.4
MEDIUMCVE-2024-26557
Codiad v2.8.4 allows reflected XSS via the components/market/dialog.php type parameter.... Read more
Affected Products : codiad- Published: Mar. 22, 2024
- Modified: May. 28, 2025
-
8.3
HIGHCVE-2024-25808
Cross-site Request Forgery (CSRF) vulnerability in Lychee version 3.1.6, allows remote attackers to execute arbitrary code via the create new album function.... Read more
Affected Products : lychee- Published: Mar. 22, 2024
- Modified: May. 28, 2025
-
6.1
MEDIUMCVE-2024-29271
Reflected Cross-Site Scripting (XSS) vulnerability in VvvebJs before version 1.7.7, allows remote attackers to execute arbitrary code and obtain sensitive information via the action parameter in save.php.... Read more
Affected Products : vvvebjs- Published: Mar. 22, 2024
- Modified: May. 28, 2025
-
5.3
MEDIUMCVE-2024-3601
The Poll Maker – Best WordPress Poll Plugin plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the ays_poll_create_author function in all versions up to, and including, 5.1.8. This makes it possible for ... Read more
Affected Products : poll_maker- Published: May. 02, 2024
- Modified: May. 28, 2025
-
5.5
MEDIUMCVE-2024-9462
The Poll Maker – Versus Polls, Anonymous Polls, Image Polls plugin for WordPress is vulnerable to Stored Cross-Site Scripting via poll settings in all versions up to, and including, 5.4.6 due to insufficient input sanitization and output escaping. This ma... Read more
Affected Products : poll_maker- Published: Oct. 26, 2024
- Modified: May. 28, 2025
-
7.2
HIGHCVE-2024-9475
The Poll Maker – Versus Polls, Anonymous Polls, Image Polls plugin for WordPress is vulnerable to generic SQL Injection via the order_by parameter in all versions up to, and including, 5.4.6 due to insufficient escaping on the user-supplied parameter and... Read more
Affected Products : poll_maker- Published: Oct. 26, 2024
- Modified: May. 28, 2025
-
4.3
MEDIUMCVE-2024-12115
The Poll Maker – Versus Polls, Anonymous Polls, Image Polls plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 5.5.4. This is due to missing or incorrect nonce validation on the duplicate_poll() function... Read more
Affected Products : poll_maker- Published: Dec. 07, 2024
- Modified: May. 28, 2025
-
7.2
HIGHCVE-2024-3600
The Poll Maker – Best WordPress Poll Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting due to a missing capability check on the ays_poll_maker_quick_start AJAX action in addition to insufficient escaping and sanitization in all vers... Read more
Affected Products : poll_maker- Published: Apr. 19, 2024
- Modified: May. 28, 2025
-
6.1
MEDIUMCVE-2023-49453
Reflected cross-site scripting (XSS) vulnerability in Racktables v0.22.0 and before, allows local attackers to execute arbitrary code and obtain sensitive information via the search component in index.php.... Read more
- Published: Mar. 12, 2024
- Modified: May. 28, 2025
-
8.8
HIGHCVE-2023-41504
SQL Injection vulnerability in Student Enrollment In PHP 1.0 allows attackers to run arbitrary code via the Student Search function.... Read more
Affected Products : student_enrollment- Published: Mar. 13, 2024
- Modified: May. 28, 2025
-
9.8
CRITICALCVE-2023-41505
An arbitrary file upload vulnerability in the Add Student's Profile Picture function of Student Enrollment In PHP v1.0 allows attackers to execute arbitrary code via uploading a crafted PHP file.... Read more
Affected Products : student_enrollment- Published: Mar. 13, 2024
- Modified: May. 28, 2025
-
8.8
HIGHCVE-2025-2847
A vulnerability, which was classified as critical, has been found in Codezips Gym Management System 1.0. This issue affects some unknown processing of the file /dashboard/admin/over_month.php. The manipulation of the argument mm leads to sql injection. Th... Read more
Affected Products : gym_management_system- Published: Mar. 27, 2025
- Modified: May. 28, 2025
- Vuln Type: Injection
-
8.8
HIGHCVE-2025-2151
A vulnerability classified as critical was found in Open Asset Import Library Assimp 5.4.3. This vulnerability affects the function Assimp::GetNextLine in the library ParsingUtils.h of the component File Handler. The manipulation leads to stack-based buff... Read more
Affected Products : assimp- Published: Mar. 10, 2025
- Modified: May. 28, 2025
- Vuln Type: Memory Corruption
-
8.4
HIGHCVE-2025-3395
Incorrect Permission Assignment for Critical Resource, Cleartext Storage of Sensitive Information vulnerability in ABB Automation Builder.This issue affects Automation Builder: through 2.8.0.... Read more
Affected Products : automation_builder- Published: Apr. 30, 2025
- Modified: May. 28, 2025
- Vuln Type: Misconfiguration
-
8.5
HIGHCVE-2025-3394
Incorrect Permission Assignment for Critical Resource vulnerability in ABB Automation Builder.This issue affects Automation Builder: through 2.8.0.... Read more
Affected Products : automation_builder- Published: Apr. 30, 2025
- Modified: May. 28, 2025
- Vuln Type: Authorization
-
7.3
HIGHCVE-2024-51319
A local file include vulnerability in the /servlet/Report of Zucchetti Ad Hoc Infinity 2.4 allows an authenticated attacker to achieve Remote Code Execution by uploading a jsp web/reverse shell through /jsp/zimg_upload.jsp.... Read more
Affected Products : ad_hoc_infinity- Published: Mar. 11, 2025
- Modified: May. 28, 2025
- Vuln Type: Path Traversal
-
8.8
HIGHCVE-2025-5186
A vulnerability was found in thinkgem JeeSite up to 5.11.1. It has been rated as critical. Affected by this issue is the function ResourceLoader.getResource of the file /cms/fileTemplate/form of the component URI Scheme Handler. The manipulation of the ar... Read more
Affected Products : jeesite- Published: May. 26, 2025
- Modified: May. 28, 2025
- Vuln Type: Server-Side Request Forgery
-
9.2
CRITICALCVE-2025-5124
A vulnerability classified as critical has been found in Sony SNC-M1, SNC-M3, SNC-RZ25N, SNC-RZ30N, SNC-DS10, SNC-CS3N and SNC-RX570N up to 1.30. This affects an unknown part of the component Administrative Interface. The manipulation leads to use of defa... Read more
Affected Products :- Published: May. 24, 2025
- Modified: May. 28, 2025
- Vuln Type: Authentication
-
9.8
CRITICALCVE-2022-37265
Prototype pollution vulnerability in stealjs steal 2.2.4 via the alias variable in babel.js.... Read more
Affected Products : steal- Published: Sep. 20, 2022
- Modified: May. 28, 2025