Latest CVE Feed
- 
                                
                                8.8HIGHCVE-2025-62422DataEase is an open source data visualization and analytics platform. In versions 2.10.13 and earlier, the /de2api/datasetData/tableField interface is vulnerable to SQL injection. An attacker can construct a malicious tableName parameter to execute arbitr... Read more Affected Products : dataease- Published: Oct. 17, 2025
- Modified: Oct. 24, 2025
- Vuln Type: Injection
 
- 
                                
                                5.5MEDIUMCVE-2025-62421DataEase is a data visualization and analytics platform. In DataEase versions through 2.10.13, a stored cross-site scripting vulnerability exists due to improper file upload validation and authentication bypass. The StaticResourceApi interface defines a r... Read more Affected Products : dataease- Published: Oct. 17, 2025
- Modified: Oct. 24, 2025
- Vuln Type: Cross-Site Scripting
 
- 
                                
                                9.9CRITICALCVE-2025-10020Zohocorp ManageEngine ADManager Plus version before 8024 are vulnerable to authenticated command injection vulnerability in the Custom Script component.... Read more Affected Products : manageengine_admanager_plus- Published: Oct. 21, 2025
- Modified: Oct. 24, 2025
- Vuln Type: Injection
 
- 
                                
                                6.5MEDIUMCVE-2025-6239Zohocorp ManageEngine Applications Manager versions 176800 and below are vulnerable to information disclosure in File/Directory monitor.... Read more Affected Products : manageengine_applications_manager- Published: Oct. 21, 2025
- Modified: Oct. 24, 2025
- Vuln Type: Information Disclosure
 
- 
                                
                                4.3MEDIUMCVE-2025-5605An authentication bypass vulnerability exists in the Management Console of multiple WSO2 products. A malicious actor with access to the console can manipulate the request URI to bypass authentication and access certain restricted resources, resulting in p... Read more - Published: Oct. 24, 2025
- Modified: Oct. 24, 2025
- Vuln Type: Authentication
 
- 
                                
                                0.0NACVE-2025-40019In the Linux kernel, the following vulnerability has been resolved: crypto: essiv - Check ssize for decryption and in-place encryption Move the ssize check to the start in essiv_aead_crypt so that it's also checked for decryption and in-place encryption... Read more Affected Products : linux_kernel- Published: Oct. 24, 2025
- Modified: Oct. 24, 2025
- Vuln Type: Cryptography
 
- 
                                
                                0.0NACVE-2025-40018In the Linux kernel, the following vulnerability has been resolved: ipvs: Defer ip_vs_ftp unregister during netns cleanup On the netns cleanup path, __ip_vs_ftp_exit() may unregister ip_vs_ftp before connections with valid cp->app pointers are flushed, ... Read more Affected Products : linux_kernel- Published: Oct. 24, 2025
- Modified: Oct. 24, 2025
- Vuln Type: Memory Corruption
 
- 
                                
                                7.5HIGHCVE-2025-10861The Popup builder with Gamification, Multi-Step Popups, Page-Level Targeting, and WooCommerce Triggers plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 2.1.4. This is due to insufficient validation on... Read more Affected Products :- Published: Oct. 24, 2025
- Modified: Oct. 24, 2025
- Vuln Type: Server-Side Request Forgery
 
- 
                                
                                0.0NACVE-2023-53733In the Linux kernel, the following vulnerability has been resolved: net: sched: cls_u32: Undo tcf_bind_filter if u32_replace_hw_knode When u32_replace_hw_knode fails, we need to undo the tcf_bind_filter operation done at u32_set_parms.... Read more Affected Products : linux_kernel- Published: Oct. 24, 2025
- Modified: Oct. 24, 2025
- Vuln Type: Misconfiguration
 
- 
                                
                                10.0CRITICALCVE-2025-9574Missing Authentication for Critical Function vulnerability in ABB ALS-mini-s4 IP, ABB ALS-mini-s8 IP.This issue affects . All firmware versions with the Serial Number from 2000 to 5166... Read more Affected Products :- Published: Oct. 20, 2025
- Modified: Oct. 24, 2025
- Vuln Type: Authentication
 
- 
                                
                                5.9MEDIUMCVE-2025-5350SSRF and Reflected XSS Vulnerabilities exist in multiple WSO2 products within the deprecated Try-It feature, which was accessible only to administrative users. This feature accepted user-supplied URLs without proper validation, leading to server-side requ... Read more - Published: Oct. 24, 2025
- Modified: Oct. 24, 2025
- Vuln Type: Server-Side Request Forgery
 
- 
                                
                                6.8MEDIUMCVE-2025-12136The Real Cookie Banner: GDPR & ePrivacy Cookie Consent plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 5.2.4. This is due to insufficient validation on the user-supplied URL in the '/scanner/scan-wit... Read more Affected Products :- Published: Oct. 24, 2025
- Modified: Oct. 24, 2025
- Vuln Type: Server-Side Request Forgery
 
- 
                                
                                5.3MEDIUMCVE-2025-12134The ZoloBlocks – Gutenberg Block Editor Plugin with Advanced Blocks, Dynamic Content, Templates & Patterns plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the update_popup_status() function in a... Read more Affected Products :- Published: Oct. 24, 2025
- Modified: Oct. 24, 2025
- Vuln Type: Authorization
 
- 
                                
                                6.4MEDIUMCVE-2025-12096The Simple Excel Pricelist for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'pricelist' shortcode in all versions up to, and including, 1.13 due to insufficient input sanitization and output escaping on user suppli... Read more Affected Products :- Published: Oct. 24, 2025
- Modified: Oct. 24, 2025
- Vuln Type: Cross-Site Scripting
 
- 
                                
                                4.3MEDIUMCVE-2025-12072The Disable Content Editor For Specific Template plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.0. This is due to missing nonce validation on template configuration updates. This makes it possible ... Read more Affected Products :- Published: Oct. 24, 2025
- Modified: Oct. 24, 2025
- Vuln Type: Cross-Site Request Forgery
 
- 
                                
                                8.8HIGHCVE-2025-12028The IndieAuth plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.5.4. This is due to missing nonce verification on the `login_form_indieauth()` function and the authorization endpoint at wp-login.php?a... Read more Affected Products :- Published: Oct. 24, 2025
- Modified: Oct. 24, 2025
- Vuln Type: Cross-Site Request Forgery
 
- 
                                
                                6.1MEDIUMCVE-2025-12017The VNPAY Payment gateway plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'message' parameter in all versions up to, and including, 1.0.0 due to insufficient input sanitization and output escaping. This makes it possible for u... Read more Affected Products :- Published: Oct. 24, 2025
- Modified: Oct. 24, 2025
- Vuln Type: Cross-Site Scripting
 
- 
                                
                                4.4MEDIUMCVE-2025-12016The qnotsquiz plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'qnotsquiz_custom_start_text' parameter in all versions up to, and including, 1.0.0 due to insufficient input sanitization and output escaping. This makes it possible ... Read more Affected Products :- Published: Oct. 24, 2025
- Modified: Oct. 24, 2025
- Vuln Type: Cross-Site Scripting
 
- 
                                
                                4.3MEDIUMCVE-2025-12014The NGINX Cache Optimizer plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'nginxcacheoptimizer-blacklist-update' AJAX action in all versions up to, and including, 1.1. This makes it possible... Read more Affected Products :- Published: Oct. 24, 2025
- Modified: Oct. 24, 2025
- Vuln Type: Authorization
 
- 
                                
                                6.1MEDIUMCVE-2025-11992The Multi Item Responsive Slider plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0. This is due to missing or incorrect nonce validation on the 'mioptions.php' page. This makes it possible for unaut... Read more Affected Products :- Published: Oct. 24, 2025
- Modified: Oct. 24, 2025
- Vuln Type: Cross-Site Request Forgery
 
 
                         
                         
                         
                                             
                                            