Latest CVE Feed
-
5.4
MEDIUMCVE-2025-4470
A vulnerability classified as problematic was found in SourceCodester Online Student Clearance System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/add-student.php. The manipulation of the argument Fullname leads to cr... Read more
Affected Products : online_student_clearance_system- Published: May. 09, 2025
- Modified: May. 14, 2025
- Vuln Type: Cross-Site Scripting
-
9.8
CRITICALCVE-2025-4468
A vulnerability was found in SourceCodester Online Student Clearance System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /edit-photo.php. The manipulation of the argument userImage leads to unrestricted upload... Read more
Affected Products : online_student_clearance_system- Published: May. 09, 2025
- Modified: May. 14, 2025
- Vuln Type: Misconfiguration
-
4.8
MEDIUMCVE-2024-13493
The Sensly Online Presence WordPress plugin through 0.6 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disa... Read more
Affected Products : sensly_online_presence- Published: Feb. 14, 2025
- Modified: May. 14, 2025
- Vuln Type: Cross-Site Scripting
-
4.8
MEDIUMCVE-2024-7052
The Forminator Forms WordPress plugin before 1.38.3 does not sanitise and escape some of its settings, which could allow high privilege users such as Admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallo... Read more
Affected Products : forminator_forms- Published: Feb. 14, 2025
- Modified: May. 14, 2025
- Vuln Type: Cross-Site Scripting
-
4.3
MEDIUMCVE-2024-13208
The Maps Plugin using Google Maps for WordPress WordPress plugin before 1.9.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_... Read more
Affected Products : wp_google_map- Published: Feb. 15, 2025
- Modified: May. 14, 2025
- Vuln Type: Cross-Site Scripting
-
4.3
MEDIUMCVE-2024-13306
The Maps Plugin using Google Maps for WordPress WordPress plugin before 1.9.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_... Read more
Affected Products : wp_google_map- Published: Feb. 15, 2025
- Modified: May. 14, 2025
- Vuln Type: Cross-Site Scripting
-
6.1
MEDIUMCVE-2024-13603
The Wise Forms WordPress plugin through 1.2.0 does not sanitise and escape some of its settings, which could allow unauthenticated users to perform Stored Cross-Site Scripting attacks via malicious form submissions.... Read more
Affected Products : wise_forms- Published: Feb. 17, 2025
- Modified: May. 14, 2025
- Vuln Type: Cross-Site Scripting
-
4.7
MEDIUMCVE-2024-13608
The Track Logins WordPress plugin through 1.0 does not sanitize and escape a parameter before using it in a SQL statement, allowing admins to perform SQL injection attacks... Read more
Affected Products : track_logins- Published: Feb. 17, 2025
- Modified: May. 14, 2025
- Vuln Type: Injection
-
7.1
HIGHCVE-2024-13625
The Tube Video Ads Lite WordPress plugin through 1.5.7 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.... Read more
Affected Products : tube_video_ads_lite- Published: Feb. 17, 2025
- Modified: May. 14, 2025
- Vuln Type: Cross-Site Scripting
-
4.8
MEDIUMCVE-2024-10939
The Image Widget WordPress plugin before 4.4.11 does not sanitise and escape some of its Image Widget settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is... Read more
Affected Products : image_widget- Published: Dec. 13, 2024
- Modified: May. 14, 2025
-
5.3
MEDIUMCVE-2024-5333
The Events Calendar WordPress plugin before 6.8.2.1 is missing access checks in the REST API, allowing for unauthenticated users to access information about password protected events.... Read more
Affected Products : the_events_calendar- Published: Dec. 16, 2024
- Modified: May. 14, 2025
-
9.8
CRITICALCVE-2023-52030
TOTOlink A3700R v9.1.2u.5822_B20200513 was discovered to contain a remote command execution (RCE) vulnerability via the setOpModeCfg function.... Read more
- EPSS Score: %14.82
- Published: Jan. 11, 2024
- Modified: May. 14, 2025
-
8.3
HIGHCVE-2023-50930
An issue was discovered in savignano S/Notify before 4.0.2 for Jira. While an administrative user is logged on, the configuration settings of S/Notify can be modified via a CSRF attack. The injection could be initiated by the administrator clicking a mali... Read more
Affected Products : s-notify- EPSS Score: %0.05
- Published: Jan. 09, 2024
- Modified: May. 14, 2025
-
6.5
MEDIUMCVE-2023-47996
An integer overflow vulnerability in Exif.cpp::jpeg_read_exif_dir in FreeImage 3.18.0 allows attackers to obtain information and cause a denial of service.... Read more
Affected Products : freeimage- EPSS Score: %0.10
- Published: Jan. 09, 2024
- Modified: May. 14, 2025
-
5.3
MEDIUMCVE-2022-41587
Uncaptured exceptions in the home screen module. Successful exploitation of this vulnerability may affect stability.... Read more
Affected Products : emui- EPSS Score: %0.06
- Published: Oct. 14, 2022
- Modified: May. 14, 2025
-
5.4
MEDIUMCVE-2024-10892
The Cost Calculator Builder WordPress plugin before 3.2.43 does not have CSRF checks in some AJAX actions, which could allow attackers to make logged in users perform unwanted actions via CSRF attacks.... Read more
Affected Products : cost_calculator_builder- Published: Dec. 18, 2024
- Modified: May. 14, 2025
-
7.8
HIGHCVE-2025-4077
A vulnerability classified as critical was found in code-projects School Billing System 1.0. This vulnerability affects the function searchrec. The manipulation of the argument Name leads to stack-based buffer overflow. It is possible to launch the attack... Read more
Affected Products : school_billing_system- Published: Apr. 29, 2025
- Modified: May. 14, 2025
- Vuln Type: Memory Corruption
-
8.8
HIGHCVE-2025-4080
A vulnerability has been found in PHPGurukul Online Nurse Hiring System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /admin/view-request.php. The manipulation of the argument viewid leads to sql in... Read more
Affected Products : online_nurse_hiring_system- Published: Apr. 29, 2025
- Modified: May. 14, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2019-10173
It was found that xstream API version 1.4.10 before 1.4.11 introduced a regression for a previous deserialization flaw. If the security framework has not been initialized, it may allow a remote attacker to run arbitrary shell commands when unmarshalling X... Read more
Affected Products : retail_xstore_point_of_service webcenter_portal xstream banking_platform communications_diameter_signaling_router communications_unified_inventory_management utilities_framework endeca_information_discovery_studio communications_billing_and_revenue_management_elastic_charging_engine business_activity_monitoring +2 more products- EPSS Score: %91.87
- Published: Jul. 23, 2019
- Modified: May. 14, 2025
-
7.5
HIGHCVE-2025-30202
vLLM is a high-throughput and memory-efficient inference and serving engine for LLMs. Versions starting from 0.5.2 and prior to 0.8.5 are vulnerable to denial of service and data exposure via ZeroMQ on multi-node vLLM deployment. In a multi-node vLLM depl... Read more
Affected Products : vllm- Published: Apr. 30, 2025
- Modified: May. 14, 2025
- Vuln Type: Denial of Service