Latest CVE Feed
-
8.8
HIGHCVE-2025-32310
Cross-Site Request Forgery (CSRF) vulnerability in ThemeMove QuickCal allows Privilege Escalation. This issue affects QuickCal: from n/a through 1.0.13.... Read more
Affected Products :- Published: May. 16, 2025
- Modified: May. 19, 2025
- Vuln Type: Cross-Site Request Forgery
-
4.3
MEDIUMCVE-2025-39511
Missing Authorization vulnerability in ValvePress Pinterest Automatic Pin allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Pinterest Automatic Pin: from n/a through 4.18.2.... Read more
Affected Products : pinterest_automatic_pin- Published: May. 16, 2025
- Modified: May. 19, 2025
- Vuln Type: Authorization
-
5.4
MEDIUMCVE-2025-47556
Missing Authorization vulnerability in QuanticaLabs CSS3 Compare Pricing Tables for WordPress allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects CSS3 Compare Pricing Tables for WordPress: from n/a through 11.5.... Read more
Affected Products :- Published: May. 16, 2025
- Modified: May. 19, 2025
- Vuln Type: Authorization
-
4.3
MEDIUMCVE-2025-47791
Nextcloud Server is a self hosted personal cloud system. In Nextcloud Server prior to 28.0.13, 29.0.10, and 30.0.3 and Nextcloud Enterprise Server prior to 28.0.13, 29.0.10, and 30.0.3, a currently unused endpoint to verify a share recipient was not prote... Read more
Affected Products : notes- Published: May. 16, 2025
- Modified: May. 19, 2025
- Vuln Type: Server-Side Request Forgery
-
5.3
MEDIUMCVE-2025-47563
Missing Authorization vulnerability in villatheme CURCY allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects CURCY: from n/a through 2.3.7.... Read more
Affected Products : curcy- Published: May. 16, 2025
- Modified: May. 19, 2025
- Vuln Type: Authorization
-
4.3
MEDIUMCVE-2025-31062
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in redqteam Wishlist allows Retrieve Embedded Sensitive Data. This issue affects Wishlist: from n/a through 2.1.0.... Read more
Affected Products :- Published: May. 16, 2025
- Modified: May. 19, 2025
- Vuln Type: Information Disclosure
-
8.5
HIGHCVE-2025-32307
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in LambertGroup Chameleon HTML5 Audio Player With/Without Playlist allows SQL Injection. This issue affects Chameleon HTML5 Audio Player With/Without Playli... Read more
Affected Products :- Published: May. 16, 2025
- Modified: May. 19, 2025
- Vuln Type: Injection
-
4.3
MEDIUMCVE-2025-32295
Missing Authorization vulnerability in wordpresschef Salon Booking Pro allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Salon Booking Pro: from n/a through 10.10.2.... Read more
Affected Products :- Published: May. 16, 2025
- Modified: May. 19, 2025
- Vuln Type: Authorization
-
4.3
MEDIUMCVE-2025-31639
Cross-Site Request Forgery (CSRF) vulnerability in themeton Spare allows Cross Site Request Forgery. This issue affects Spare: from n/a through 1.7.... Read more
Affected Products :- Published: May. 16, 2025
- Modified: May. 19, 2025
- Vuln Type: Cross-Site Request Forgery
-
8.5
HIGHCVE-2025-31640
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in LambertGroup Magic Responsive Slider and Carousel WordPress allows SQL Injection. This issue affects Magic Responsive Slider and Carousel WordPress: from... Read more
Affected Products :- Published: May. 16, 2025
- Modified: May. 19, 2025
- Vuln Type: Injection
-
7.1
HIGHCVE-2025-31922
Cross-Site Request Forgery (CSRF) vulnerability in QuanticaLabs CSS3 Accordions for WordPress allows Stored XSS. This issue affects CSS3 Accordions for WordPress: from n/a through 3.0.... Read more
Affected Products :- Published: May. 16, 2025
- Modified: May. 19, 2025
- Vuln Type: Cross-Site Request Forgery
-
5.0
MEDIUMCVE-2025-47792
Nextcloud Desktop is the desktop sync client for Nextcloud. In versions of Nextcloud Desktop prior to 3.15, 3rdparty applications already installed on a user machine can create link shares for almost all data via the socket API. These shares can then be e... Read more
Affected Products : notes- Published: May. 16, 2025
- Modified: May. 19, 2025
- Vuln Type: Authorization
-
4.3
MEDIUMCVE-2025-47793
Nextcloud Server is a self hosted personal cloud system, and the Nextcloud Groupfolders app provides admin-configured folders shared by everyone in a group or team. In Nextcloud Server prior to 30.0.2, 29.0.9, and 28.0.1, Nextcloud Enterprise Server prior... Read more
Affected Products : notes- Published: May. 16, 2025
- Modified: May. 19, 2025
- Vuln Type: Authorization
-
2.6
LOWCVE-2025-47794
Nextcloud Server is a self hosted personal cloud system. In Nextcloud Server prior to 29.0.13, 30.0.7, and 31.0.1 and Nextcloud Enterprise Server prior to 26.0.13.13, 27.1.11.13, 28.0.14.4, 29.0.13, 30.0.7, and 31.0.1, an attacker on a multi-user system m... Read more
Affected Products : notes- Published: May. 16, 2025
- Modified: May. 19, 2025
- Vuln Type: Information Disclosure
-
5.3
MEDIUMCVE-2025-31066
Missing Authorization vulnerability in themeton Acerola allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Acerola: from n/a through 1.6.5.... Read more
Affected Products :- Published: May. 16, 2025
- Modified: May. 19, 2025
- Vuln Type: Authorization
-
4.3
MEDIUMCVE-2025-31068
Cross-Site Request Forgery (CSRF) vulnerability in themeton Seven Stars allows Cross Site Request Forgery. This issue affects Seven Stars: from n/a through 1.4.4.... Read more
Affected Products :- Published: May. 16, 2025
- Modified: May. 19, 2025
- Vuln Type: Cross-Site Request Forgery
-
5.3
MEDIUMCVE-2025-31071
Missing Authorization vulnerability in themeton HotStar – Multi-Purpose Business Theme allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects HotStar – Multi-Purpose Business Theme: from n/a through 1.4.... Read more
Affected Products :- Published: May. 16, 2025
- Modified: May. 19, 2025
- Vuln Type: Authorization
-
5.3
MEDIUMCVE-2025-31630
Missing Authorization vulnerability in themeton The Business allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects The Business: from n/a through 1.6.1.... Read more
Affected Products :- Published: May. 16, 2025
- Modified: May. 19, 2025
- Vuln Type: Authorization
-
8.5
HIGHCVE-2025-31641
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in LambertGroup UberSlider allows SQL Injection. This issue affects UberSlider: from n/a through 2.3.... Read more
Affected Products :- Published: May. 16, 2025
- Modified: May. 19, 2025
- Vuln Type: Injection
-
5.4
MEDIUMCVE-2025-31915
Cross-Site Request Forgery (CSRF) vulnerability in kamleshyadav Pixel WordPress Form BuilderPlugin & Autoresponder allows Cross Site Request Forgery. This issue affects Pixel WordPress Form BuilderPlugin & Autoresponder: from n/a through 1.0.2.... Read more
Affected Products :- Published: May. 16, 2025
- Modified: May. 19, 2025
- Vuln Type: Cross-Site Request Forgery