Latest CVE Feed
-
4.3
MEDIUMCVE-2025-58599
Missing Authorization vulnerability in tychesoftwares Order Delivery Date for WooCommerce allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Order Delivery Date for WooCommerce: from n/a through 4.1.0.... Read more
Affected Products :- Published: Sep. 03, 2025
- Modified: Sep. 03, 2025
- Vuln Type: Authorization
-
6.6
MEDIUMCVE-2025-58598
Insertion of Sensitive Information Into Debugging Code vulnerability in Klarna Klarna Order Management for WooCommerce allows Retrieve Embedded Sensitive Data. This issue affects Klarna Order Management for WooCommerce: from n/a through 1.9.8.... Read more
Affected Products :- Published: Sep. 03, 2025
- Modified: Sep. 03, 2025
- Vuln Type: Information Disclosure
-
4.3
MEDIUMCVE-2025-58597
Authorization Bypass Through User-Controlled Key vulnerability in Tomdever wpForo Forum allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects wpForo Forum: from n/a through 2.4.6.... Read more
Affected Products :- Published: Sep. 03, 2025
- Modified: Sep. 03, 2025
- Vuln Type: Authorization
-
5.9
MEDIUMCVE-2025-58596
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in properfraction MailOptin allows Stored XSS. This issue affects MailOptin: from n/a through 1.2.75.0.... Read more
Affected Products :- Published: Sep. 03, 2025
- Modified: Sep. 03, 2025
- Vuln Type: Cross-Site Scripting
-
4.3
MEDIUMCVE-2025-58594
Missing Authorization vulnerability in themefusecom Brizy allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Brizy: from n/a through 2.7.12.... Read more
Affected Products :- Published: Sep. 03, 2025
- Modified: Sep. 03, 2025
- Vuln Type: Authorization
-
6.5
MEDIUMCVE-2025-58593
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themeisle Orbit Fox by ThemeIsle allows Stored XSS. This issue affects Orbit Fox by ThemeIsle: from n/a through 3.0.0.... Read more
Affected Products :- Published: Sep. 03, 2025
- Modified: Sep. 03, 2025
- Vuln Type: Cross-Site Scripting
-
8.8
HIGHCVE-2025-57151
phpgurukul Complaint Management System 2.0 is vulnerable to Cross Site Scripting (XSS) in admin/userprofile.php via the fullname parameter.... Read more
Affected Products :- Published: Sep. 03, 2025
- Modified: Sep. 03, 2025
- Vuln Type: Cross-Site Scripting
-
7.2
HIGHCVE-2025-57150
phpgurukul Complaint Management System in PHP 2.0 is vulnerable to Cross Site Scripting (XSS) in admin/subcategory.php via the categoryName parameter.... Read more
Affected Products :- Published: Sep. 03, 2025
- Modified: Sep. 03, 2025
- Vuln Type: Cross-Site Scripting
-
6.5
MEDIUMCVE-2025-57149
phpgurukul Complaint Management System 2.0 is vulnerable to SQL Injection in /complaint-details.php via the cid parameter.... Read more
Affected Products :- Published: Sep. 03, 2025
- Modified: Sep. 03, 2025
- Vuln Type: Injection
-
0.0
NACVE-2025-57148
phpgurukul Online Shopping Portal 2.0 is vulnerable to Arbitrary File Upload in /admin/insert-product.php, due to the lack of extension validation.... Read more
Affected Products :- Published: Sep. 03, 2025
- Modified: Sep. 03, 2025
- Vuln Type: Misconfiguration
-
0.0
NACVE-2025-57147
A SQL Injection vulnerability was found in phpgurukul Complaint Management System 2.0. The vulnerability is due to lack of input validation of multiple parameters including fullname, email, and contactno in user/registration.php.... Read more
Affected Products :- Published: Sep. 03, 2025
- Modified: Sep. 03, 2025
- Vuln Type: Injection
-
0.0
NACVE-2025-57146
phpgurukul Complaint Management System in PHP 2.0 is vulnerable to SQL Injection in user/reset-password.php via the mobileno parameter.... Read more
Affected Products :- Published: Sep. 03, 2025
- Modified: Sep. 03, 2025
- Vuln Type: Injection
-
0.0
NACVE-2025-57052
cJSON 1.5.0 through 1.7.18 allows out-of-bounds access via the decode_array_index_from_pointer function in cJSON_Utils.c, allowing remote attackers to bypass array bounds checking and access restricted data via malformed JSON pointer strings containing al... Read more
Affected Products :- Published: Sep. 03, 2025
- Modified: Sep. 03, 2025
- Vuln Type: Misconfiguration
-
0.0
NACVE-2025-56608
The SourceCodester Android application "Corona Virus Tracker App India" 1.0 uses MD5 for digest authentication in `OkHttpClientWrapper.java`. The `handleDigest()` function employs `MessageDigest.getInstance("MD5")` to hash credentials. MD5 is a broken cry... Read more
Affected Products :- Published: Sep. 03, 2025
- Modified: Sep. 03, 2025
- Vuln Type: Cryptography
-
8.7
HIGHCVE-2025-52478
n8n is a workflow automation platform. From 1.77.0 to before 1.98.2, a stored Cross-Site Scripting (XSS) vulnerability was identified in n8n, specifically in the Form Trigger node's HTML form element. An authenticated attacker can inject malicious HTML vi... Read more
Affected Products : n8n- Published: Aug. 19, 2025
- Modified: Sep. 03, 2025
- Vuln Type: Cross-Site Scripting
-
6.5
MEDIUMCVE-2025-57749
n8n is a workflow automation platform. Before 1.106.0, a symlink traversal vulnerability was discovered in the Read/Write File node in n8n. While the node attempts to restrict access to sensitive directories and files, it does not properly account for sym... Read more
Affected Products : n8n- Published: Aug. 20, 2025
- Modified: Sep. 03, 2025
- Vuln Type: Path Traversal
-
6.6
MEDIUMCVE-2024-13297
Deserialization of Untrusted Data vulnerability in Drupal Eloqua allows Object Injection.This issue affects Eloqua: from 7.X-* before 7.X-1.15.... Read more
Affected Products : eloqua- Published: Jan. 09, 2025
- Modified: Sep. 03, 2025
- Vuln Type: Injection
-
6.6
MEDIUMCVE-2024-13296
Deserialization of Untrusted Data vulnerability in Drupal Mailjet allows Object Injection.This issue affects Mailjet: from 0.0.0 before 4.0.1.... Read more
Affected Products : mailjet- Published: Jan. 09, 2025
- Modified: Sep. 03, 2025
- Vuln Type: Injection
-
9.0
HIGHCVE-2025-9297
A vulnerability was detected in Tenda i22 1.0.0.3(4687). This impacts the function formWeixinAuthInfoGet of the file /goform/wxportalauth. Performing manipulation of the argument Type results in stack-based buffer overflow. The attack can be initiated rem... Read more
- Published: Aug. 21, 2025
- Modified: Sep. 03, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2025-4846
A vulnerability, which was classified as critical, was found in FreeFloat FTP Server 1.0. This affects an unknown part of the component MPUT Command Handler. The manipulation leads to buffer overflow. It is possible to initiate the attack remotely. The ex... Read more
- Published: May. 18, 2025
- Modified: Sep. 03, 2025
- Vuln Type: Memory Corruption