Latest CVE Feed
-
9.1
CRITICALCVE-2025-3895
Token used for resetting passwords in MegaBIP software are generated using a small space of random values combined with a queryable value. It allows an unauthenticated attacker who know user login names to brute force these tokens and change account pass... Read more
Affected Products : megabip- Published: May. 23, 2025
- Modified: May. 23, 2025
- Vuln Type: Authentication
-
8.2
HIGHCVE-2025-39536
Missing Authorization vulnerability in Chimpstudio JobHunt Job Alerts allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects JobHunt Job Alerts: from n/a through 3.6.... Read more
Affected Products :- Published: May. 23, 2025
- Modified: May. 23, 2025
- Vuln Type: Authorization
-
7.1
HIGHCVE-2025-39502
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in GoodLayers Goodlayers Hostel allows Reflected XSS. This issue affects Goodlayers Hostel: from n/a through 3.1.2.... Read more
Affected Products :- Published: May. 23, 2025
- Modified: May. 23, 2025
- Vuln Type: Cross-Site Scripting
-
9.8
CRITICALCVE-2025-39495
Deserialization of Untrusted Data vulnerability in BoldThemes Avantage allows Object Injection. This issue affects Avantage: from n/a through 2.4.6.... Read more
Affected Products :- Published: May. 23, 2025
- Modified: May. 23, 2025
- Vuln Type: Injection
-
8.1
HIGHCVE-2025-32286
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ApusTheme Butcher allows PHP Local File Inclusion. This issue affects Butcher: from n/a through 2.40.... Read more
Affected Products :- Published: May. 23, 2025
- Modified: May. 23, 2025
- Vuln Type: Path Traversal
-
8.1
HIGHCVE-2025-32302
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in gavias Winnex allows PHP Local File Inclusion. This issue affects Winnex: from n/a through 1.3.2.... Read more
Affected Products :- Published: May. 23, 2025
- Modified: May. 23, 2025
- Vuln Type: Path Traversal
-
8.1
HIGHCVE-2025-31913
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ApusTheme Ogami allows PHP Local File Inclusion. This issue affects Ogami: from n/a through 1.53.... Read more
Affected Products :- Published: May. 23, 2025
- Modified: May. 23, 2025
- Vuln Type: Path Traversal
-
9.0
CRITICALCVE-2025-31916
Unrestricted Upload of File with Dangerous Type vulnerability in joy2012bd JP Students Result Management System Premium allows Upload a Web Shell to a Web Server. This issue affects JP Students Result Management System Premium: from 1.1.7 through n/a.... Read more
Affected Products :- Published: May. 23, 2025
- Modified: May. 23, 2025
- Vuln Type: Authentication
-
9.3
CRITICALCVE-2025-31914
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in kamleshyadav Pixel WordPress Form BuilderPlugin & Autoresponder allows Blind SQL Injection. This issue affects Pixel WordPress Form BuilderPlugin & Autor... Read more
Affected Products :- Published: May. 23, 2025
- Modified: May. 23, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-31631
Deserialization of Untrusted Data vulnerability in AncoraThemes Fish House allows Object Injection. This issue affects Fish House: from n/a through 1.2.7.... Read more
Affected Products :- Published: May. 23, 2025
- Modified: May. 23, 2025
- Vuln Type: Injection
-
7.1
HIGHCVE-2025-31636
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in SaurabhSharma WP Post Modules for Elementor allows Reflected XSS. This issue affects WP Post Modules for Elementor: from n/a through 2.5.0.... Read more
Affected Products :- Published: May. 23, 2025
- Modified: May. 23, 2025
- Vuln Type: Cross-Site Scripting
-
8.1
HIGHCVE-2025-31633
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in gavias Kiamo - Responsive Business Service WordPress Theme allows PHP Local File Inclusion. This issue affects Kiamo - Responsive Busi... Read more
Affected Products :- Published: May. 23, 2025
- Modified: May. 23, 2025
- Vuln Type: Path Traversal
-
8.1
HIGHCVE-2025-31064
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in gavias Vizeon - Business Consulting allows PHP Local File Inclusion. This issue affects Vizeon - Business Consulting: from n/a through... Read more
Affected Products :- Published: May. 23, 2025
- Modified: May. 23, 2025
- Vuln Type: Path Traversal
-
4.7
MEDIUMCVE-2025-2394
Ecovacs Home Android and iOS Mobile Applications up to version 3.3.0 contained embedded access keys and secrets for Alibaba Object Storage Service (OSS), leading to sensitive data disclosure.... Read more
Affected Products :- Published: May. 23, 2025
- Modified: May. 23, 2025
- Vuln Type: Information Disclosure
-
7.2
HIGHCVE-2025-1123
The Solid Mail – SMTP email and logging made by SolidWP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via email Name, Subject, and Body in all versions up to, and including, 2.1.5 due to insufficient input sanitization and output escap... Read more
Affected Products :- Published: May. 23, 2025
- Modified: May. 23, 2025
- Vuln Type: Cross-Site Scripting
-
6.1
MEDIUMCVE-2024-5962
A reflected cross-site scripting (XSS) vulnerability exists in the authentication endpoint of multiple WSO2 products due to missing output encoding of user-supplied input. A malicious actor can exploit this vulnerability to inject arbitrary JavaScript int... Read more
Affected Products :- Published: May. 22, 2025
- Modified: May. 23, 2025
- Vuln Type: Cross-Site Scripting
-
7.0
HIGHCVE-2024-51553
Predictable filename vulnerabilities in ASPECT may expose sensitive information to a potential attacker if administrator credentials become compromisedThis issue affects ASPECT-Enterprise: through 3.*; NEXUS Series: through 3.*; MATRIX Series: through 3.*... Read more
Affected Products :- Published: May. 22, 2025
- Modified: May. 23, 2025
- Vuln Type: Information Disclosure
-
7.1
HIGHCVE-2024-51552
Weak password storage vulnerabilities exist in ASPECT if administrator credentials become compromisedThis issue affects ASPECT-Enterprise: through 3.*; NEXUS Series: through 3.*; MATRIX Series: through 3.*.... Read more
Affected Products :- Published: May. 22, 2025
- Modified: May. 23, 2025
- Vuln Type: Authentication
-
7.0
HIGHCVE-2024-48848
Large content vulnerabilities are present in ASPECT exposing a device to disk overutilization on a system if administrator credentials become compromisedThis issue affects ASPECT-Enterprise: through 3.*; NEXUS Series: through 3.*; MATRIX Series: through 3... Read more
Affected Products :- Published: May. 22, 2025
- Modified: May. 23, 2025
- Vuln Type: Misconfiguration
-
8.8
HIGHCVE-2024-13956
SSL Verification Bypass vulnerabilities exist in ASPECT if administrator credentials become compromisedThis issue affects ASPECT-Enterprise: through 3.*; NEXUS Series: through 3.*; MATRIX Series: through 3.*.... Read more
Affected Products :- Published: May. 22, 2025
- Modified: May. 23, 2025
- Vuln Type: Misconfiguration