Latest CVE Feed
-
5.5
MEDIUMCVE-2025-31242
A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in iPadOS 17.7.7, macOS Ventura 13.7.6, macOS Sequoia 15.5, macOS Sonoma 14.7.6. An app may be able to access sensitive user data.... Read more
- Published: May. 12, 2025
- Modified: May. 27, 2025
- Vuln Type: Information Disclosure
-
8.8
HIGHCVE-2025-31244
A file quarantine bypass was addressed with additional checks. This issue is fixed in macOS Sequoia 15.5. An app may be able to break out of its sandbox.... Read more
Affected Products : macos- Published: May. 12, 2025
- Modified: May. 27, 2025
- Vuln Type: Authorization
-
5.5
MEDIUMCVE-2025-31245
The issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14.7.6, tvOS 18.5, iPadOS 17.7.7, iOS 18.5 and iPadOS 18.5, macOS Sequoia 15.5, visionOS 2.5, macOS Ventura 13.7.6. An app may be able to cause unexpected system termination... Read more
- Published: May. 12, 2025
- Modified: May. 27, 2025
- Vuln Type: Denial of Service
-
8.8
HIGHCVE-2025-31246
The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.5, macOS Sonoma 14.7.6. Connecting to a malicious AFP server may corrupt kernel memory.... Read more
Affected Products : macos- Published: May. 12, 2025
- Modified: May. 27, 2025
- Vuln Type: Memory Corruption
-
7.5
HIGHCVE-2025-31247
A logic issue was addressed with improved state management. This issue is fixed in macOS Ventura 13.7.6, macOS Sequoia 15.5, macOS Sonoma 14.7.6. An attacker may gain access to protected parts of the file system.... Read more
Affected Products : macos- Published: May. 12, 2025
- Modified: May. 27, 2025
- Vuln Type: Authorization
-
5.4
MEDIUMCVE-2024-6884
The Gutenberg Blocks with AI by Kadence WP WordPress plugin before 3.2.39 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and ab... Read more
Affected Products : gutenberg_blocks_with_ai- Published: Aug. 08, 2024
- Modified: May. 27, 2025
-
9.0
CRITICALCVE-2022-32174
In Gogs, versions v0.6.5 through v0.12.10 are vulnerable to Stored Cross-Site Scripting (XSS) that leads to an account takeover.... Read more
Affected Products : gogs- Published: Oct. 11, 2022
- Modified: May. 27, 2025
-
6.2
MEDIUMCVE-2022-31022
Bleve is a text indexing library for go. Bleve includes HTTP utilities under bleve/http package, that are used by its sample application. These HTTP methods pave way for exploitation of a node’s filesystem where the bleve index resides, if the user has us... Read more
Affected Products : bleve- Published: Jun. 01, 2022
- Modified: May. 27, 2025
-
9.0
CRITICALCVE-2021-21353
Pug is an npm package which is a high-performance template engine. In pug before version 3.0.1, if a remote attacker was able to control the `pretty` option of the pug compiler, e.g. if you spread a user provided object such as the query parameters of a ... Read more
- Published: Mar. 03, 2021
- Modified: May. 27, 2025
-
9.0
CRITICALCVE-2022-32176
In "Gin-Vue-Admin", versions v2.5.1 through v2.5.3b are vulnerable to Unrestricted File Upload that leads to execution of javascript code, through the "Compress Upload" functionality to the Media Library. When an admin user views the uploaded file, a low ... Read more
Affected Products : gin-vue-admin- Published: Oct. 17, 2022
- Modified: May. 27, 2025
-
4.8
MEDIUMCVE-2024-6158
The Category Posts Widget WordPress plugin before 4.9.17, term-and-category-based-posts-widget WordPress plugin before 4.9.13 does not validate and escape some of its "Category Posts" widget settings before outputting them back in a page/post where the Wi... Read more
- Published: Aug. 12, 2024
- Modified: May. 27, 2025
-
9.8
CRITICALCVE-2024-6330
The GEO my WP WordPress plugin before 4.5.0.2 does not prevent unauthenticated attackers from including arbitrary files in PHP's execution context, which leads to Remote Code Execution.... Read more
Affected Products : geo_my_wordpress- Published: Aug. 19, 2024
- Modified: May. 27, 2025
-
9.8
CRITICALCVE-2021-4226
RSFirewall tries to identify the original IP address by looking at different HTTP headers. A bypass is possible due to the way it is implemented.... Read more
Affected Products : rsfirewall\!- Published: Dec. 15, 2022
- Modified: May. 27, 2025
-
7.2
HIGHCVE-2024-6451
AI Engine < 2.4.3 is susceptible to remote-code-execution (RCE) via Log Poisoning. The AI Engine WordPress plugin before 2.5.1 fails to validate the file extension of "logs_path", allowing Administrators to change log filetypes from .log to .php.... Read more
Affected Products : ai_engine- Published: Aug. 19, 2024
- Modified: May. 27, 2025
-
6.1
MEDIUMCVE-2024-6843
The Chatbot with ChatGPT WordPress plugin before 2.4.5 does not sanitise and escape user inputs, which could allow unauthenticated users to perform Stored Cross-Site Scripting attacks against admins... Read more
- Published: Aug. 19, 2024
- Modified: May. 27, 2025
-
9.8
CRITICALCVE-2024-6847
The Chatbot with ChatGPT WordPress plugin before 2.4.5 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by unauthenticated users when submitting messages to the chatbot.... Read more
- Published: Aug. 20, 2024
- Modified: May. 27, 2025
-
8.8
HIGHCVE-2024-48655
An issue in Total.js CMS v.1.0 allows a remote attacker to execute arbitrary code via the func.js file.... Read more
- Published: Oct. 25, 2024
- Modified: May. 27, 2025
-
6.3
MEDIUMCVE-2024-48191
dingfanzu CMS 1.0 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/doAdminAction.php?act=delAdmin&id=17... Read more
- Published: Oct. 28, 2024
- Modified: May. 27, 2025
-
6.3
MEDIUMCVE-2024-48291
dingfanzu CMS 1.0 was discovered to contain a Cross-Site Request Forgery (CSRF) via /admin/doAdminAction.php?act=editAdmin&id=17... Read more
- Published: Oct. 28, 2024
- Modified: May. 27, 2025
-
9.8
CRITICALCVE-2024-42835
langflow v1.0.12 was discovered to contain a remote code execution (RCE) vulnerability via the PythonCodeTool component.... Read more
Affected Products : langflow- Published: Oct. 31, 2024
- Modified: May. 27, 2025