Latest CVE Feed
-
7.8
HIGHCVE-2025-30310
Dreamweaver Desktop versions 21.4 and earlier are affected by an Access of Resource Using Incompatible Type ('Type Confusion') vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requi... Read more
- Published: May. 13, 2025
- Modified: May. 14, 2025
- Vuln Type: Memory Corruption
-
6.1
MEDIUMCVE-2024-11849
The Pods WordPress plugin before 3.2.8.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for ex... Read more
Affected Products : pods- Published: Jan. 06, 2025
- Modified: May. 14, 2025
- Vuln Type: Cross-Site Scripting
-
7.1
HIGHCVE-2025-24645
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Rob Scott Eazy Under Construction allows Reflected XSS. This issue affects Eazy Under Construction: from n/a through 1.0.... Read more
Affected Products :- Published: Apr. 17, 2025
- Modified: May. 14, 2025
- Vuln Type: Cross-Site Scripting
-
3.4
LOWCVE-2022-41603
The phones have the heap overflow, out-of-bounds read, and null pointer vulnerabilities in the fingerprint trusted application (TA).Successful exploitation of this vulnerability may affect the fingerprint service.... Read more
- EPSS Score: %0.01
- Published: Oct. 14, 2022
- Modified: May. 14, 2025
-
7.8
HIGHCVE-2022-41305
A maliciously crafted PKT file when consumed through SubassemblyComposer.exe application could lead to memory corruption vulnerability by write access violation. This vulnerability in conjunction with other vulnerabilities could lead to code execution in ... Read more
Affected Products : subassembly_composer- EPSS Score: %0.04
- Published: Oct. 14, 2022
- Modified: May. 14, 2025
-
7.3
HIGHCVE-2022-2865
A cross-site scripting issue has been discovered in GitLab CE/EE affecting all versions before 15.1.6, 15.2 to 15.2.4 and 15.3 prior to 15.3.2. It was possible to exploit a vulnerability in setting the labels colour feature which could lead to a stored XS... Read more
Affected Products : gitlab- EPSS Score: %0.13
- Published: Oct. 17, 2022
- Modified: May. 14, 2025
-
6.1
MEDIUMCVE-2024-12302
The Icegram Engage WordPress plugin before 3.1.32 does not sanitise and escape some of its Campaign settings, which could allow authors and above to perform Stored Cross-Site Scripting attacks... Read more
Affected Products : icegram_engage- Published: Jan. 06, 2025
- Modified: May. 14, 2025
- Vuln Type: Cross-Site Scripting
-
6.5
MEDIUMCVE-2024-12311
The Email Subscribers by Icegram Express WordPress plugin before 5.7.44 does not sanitize and escape a parameter before using it in a SQL statement, allowing admins to perform SQL injection attacks... Read more
Affected Products : email_subscribers_\&_newsletters- Published: Jan. 06, 2025
- Modified: May. 14, 2025
- Vuln Type: Injection
-
2.7
LOWCVE-2024-10102
The Photo Gallery, Images, Slider in Rbs Image Gallery WordPress plugin before 3.2.22 does not sanitise and escape some of its Gallery settings, which could allow high privilege users such as contributor to perform Stored Cross-Site Scripting attacks... Read more
- Published: Jan. 07, 2025
- Modified: May. 14, 2025
- Vuln Type: Cross-Site Scripting
-
7.0
HIGHCVE-2025-30378
Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code locally.... Read more
- Published: May. 13, 2025
- Modified: May. 14, 2025
- Vuln Type: Authentication
-
9.8
CRITICALCVE-2024-8855
The WordPress Auction Plugin WordPress plugin through 3.7 does not sanitize and escape a parameter before using it in a SQL statement, allowing editors and above to perform SQL injection attacks... Read more
Affected Products : wordpress_auction- Published: Jan. 07, 2025
- Modified: May. 14, 2025
- Vuln Type: Injection
-
4.8
MEDIUMCVE-2024-8857
The WordPress Auction Plugin WordPress plugin through 3.7 does not sanitise and escape some of its settings, which could allow high privilege users such as editors to perform Stored Cross-Site Scripting attacks.... Read more
Affected Products : wordpress_auction- Published: Jan. 07, 2025
- Modified: May. 14, 2025
- Vuln Type: Cross-Site Scripting
-
9.8
CRITICALCVE-2025-3819
A vulnerability has been found in PHPGurukul Men Salon Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /admin/search-appointment.php. The manipulation of the argument searchdata lead... Read more
Affected Products : men_salon_management_system- Published: Apr. 19, 2025
- Modified: May. 14, 2025
- Vuln Type: Injection
-
5.9
MEDIUMCVE-2025-39444
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Maxfoundry MaxButtons allows Stored XSS.This issue affects MaxButtons: from n/a through 9.8.3.... Read more
Affected Products : maxbuttons- Published: Apr. 17, 2025
- Modified: May. 14, 2025
- Vuln Type: Cross-Site Scripting
-
9.8
CRITICALCVE-2023-43958
An arbitrary file upload vulnerability in the component /jquery-file-upload/server/php/index.php of Hospital Management System v4.0 allows an unauthenticated attacker to upload any file to the server and execute arbitrary code.... Read more
Affected Products : hospital_management_system- Published: Apr. 22, 2025
- Modified: May. 14, 2025
- Vuln Type: Authentication
-
4.9
MEDIUMCVE-2025-47729
The TeleMessage archiving backend through 2025-05-05 holds cleartext copies of messages from TM SGNL (aka Archive Signal) app users, which is different functionality than described in the TeleMessage "End-to-End encryption from the mobile phone through to... Read more
Affected Products : text_message_archiver- Actively Exploited
- Published: May. 08, 2025
- Modified: May. 14, 2025
- Vuln Type: Cryptography
-
4.8
MEDIUMCVE-2025-29568
A vulnerability has been discovered in the code-projects Online Class and Exam Scheduling System 1.0. The issue affects some unknown features in the file /Scheduling/pages/class_sched.php. Manipulating the class parameter can lead to cross-site scripting ... Read more
Affected Products : online_class_and_exam_scheduling_system- Published: Apr. 24, 2025
- Modified: May. 14, 2025
- Vuln Type: Cross-Site Scripting
-
6.5
MEDIUMCVE-2025-44134
A vulnerability was found in Code-Projects Online Class and Exam Scheduling System 1.0 in the file /Scheduling/pages/class_save.php. Manipulation of parameter class will lead to SQL injection attacks.... Read more
Affected Products : online_class_and_exam_scheduling_system- Published: Apr. 24, 2025
- Modified: May. 14, 2025
- Vuln Type: Injection
-
6.5
MEDIUMCVE-2025-44135
A vulnerability was found in code-projects Online Class and Exam Scheduling System 1.0 in /Scheduling/pages/profile_update.php. Manipulating the parameter username will cause SQL injection attacks.... Read more
Affected Products : online_class_and_exam_scheduling_system- Published: Apr. 24, 2025
- Modified: May. 14, 2025
- Vuln Type: Injection
-
5.5
MEDIUMCVE-2024-0340
A vulnerability was found in vhost_new_msg in drivers/vhost/vhost.c in the Linux kernel, which does not properly initialize memory in messages passed between virtual guests and the host operating system in the vhost/vhost.c:vhost_new_msg() function. This ... Read more
- EPSS Score: %0.01
- Published: Jan. 09, 2024
- Modified: May. 14, 2025