Latest CVE Feed
-
5.3
MEDIUMCVE-2025-32972
XWiki is a generic wiki platform. In versions starting from 6.1-milestone-1 to before 15.10.12, from 16.0.0-rc-1 to before 16.4.3, and from 16.5.0-rc-1 to before 16.8.0-rc-1, the script API of the LESS compiler in XWiki is incorrectly checking for rights ... Read more
Affected Products : xwiki- Published: Apr. 30, 2025
- Modified: May. 13, 2025
- Vuln Type: Authorization
-
5.4
MEDIUMCVE-2024-26450
An issue exists within Piwigo before v.14.2.0 allowing a malicious user to take over the application. This exploit involves chaining a Cross Site Request Forgery vulnerability to issue a Stored Cross Site Scripting payload stored within an Admin user's da... Read more
Affected Products : piwigo- Published: Feb. 28, 2024
- Modified: May. 13, 2025
-
9.0
CRITICALCVE-2025-32973
XWiki is a generic wiki platform. In versions starting from 15.9-rc-1 to before 15.10.12, from 16.0.0-rc-1 to before 16.4.3, and from 16.5.0-rc-1 to before 16.8.0-rc-1, when a user with programming rights edits a document in XWiki that was last edited by ... Read more
Affected Products : xwiki- Published: Apr. 30, 2025
- Modified: May. 13, 2025
- Vuln Type: Authorization
-
7.1
HIGHCVE-2024-25859
A path traversal vulnerability in the /path/to/uploads/ directory of Blesta before v5.9.2 allows attackers to takeover user accounts and execute arbitrary code.... Read more
Affected Products : blesta- Published: Feb. 28, 2024
- Modified: May. 13, 2025
-
9.0
CRITICALCVE-2025-32974
XWiki is a generic wiki platform. In versions starting from 15.9-rc-1 to before 15.10.8 and from 16.0.0-rc-1 to before 16.2.0, the required rights analysis doesn't consider TextAreas with default content type. When editing a page, XWiki warns since versio... Read more
Affected Products : xwiki- Published: Apr. 30, 2025
- Modified: May. 13, 2025
- Vuln Type: Cross-Site Scripting
-
7.6
HIGHCVE-2023-45859
In Hazelcast through 4.1.10, 4.2 through 4.2.8, 5.0 through 5.0.5, 5.1 through 5.1.7, 5.2 through 5.2.4, and 5.3 through 5.3.2, some client operations don't check permissions properly, allowing authenticated users to access data stored in the cluster.... Read more
Affected Products : hazelcast- Published: Feb. 28, 2024
- Modified: May. 13, 2025
-
9.8
CRITICALCVE-2024-25180
An issue discovered in pdfmake 0.2.9 allows remote attackers to run arbitrary code via crafted POST request to the /pdf endpoint. NOTE: this is disputed because the behavior of the /pdf endpoint is intentional. The /pdf endpoint is only available after in... Read more
Affected Products : pdfmake- Published: Feb. 29, 2024
- Modified: May. 13, 2025
-
6.5
MEDIUMCVE-2024-22532
Buffer Overflow vulnerability in XNSoft NConvert 7.163 (for Windows x86) allows attackers to cause a denial of service via crafted xwd file.... Read more
Affected Products : nconvert- Published: Feb. 28, 2024
- Modified: May. 13, 2025
-
6.1
MEDIUMCVE-2022-45847
Cross-Site Request Forgery (CSRF) vulnerability in WPAssist.Me WordPress Countdown Widget allows Cross-Site Scripting (XSS).This issue affects WordPress Countdown Widget: from n/a through 3.1.9.1. ... Read more
Affected Products : countdown_widget- Published: Mar. 27, 2024
- Modified: May. 13, 2025
-
3.5
LOWCVE-2024-26476
An issue in open-emr before v.7.0.2 allows a remote attacker to escalate privileges via a crafted script to the formid parameter in the ereq_form.php component.... Read more
- Published: Feb. 28, 2024
- Modified: May. 13, 2025
-
6.1
MEDIUMCVE-2023-34020
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Uncanny Owl Uncanny Toolkit for LearnDash.This issue affects Uncanny Toolkit for LearnDash: from n/a through 3.6.4.3. ... Read more
Affected Products : uncanny_toolkit_for_learndash- Published: Mar. 27, 2024
- Modified: May. 13, 2025
-
9.3
CRITICALCVE-2024-25293
mjml-app versions 3.0.4 and 3.1.0-beta were discovered to contain a remote code execution (RCE) via the href attribute.... Read more
- Published: Mar. 01, 2024
- Modified: May. 13, 2025
-
8.8
HIGHCVE-2023-39311
Cross-Site Request Forgery (CSRF) vulnerability in ThemeFusion Fusion Builder.This issue affects Fusion Builder: from n/a through 3.11.1. ... Read more
- Published: Mar. 27, 2024
- Modified: May. 13, 2025
-
9.8
CRITICALCVE-2024-22891
Nteract v.0.28.0 was discovered to contain a remote code execution (RCE) vulnerability via the Markdown link.... Read more
Affected Products : nteract- Published: Mar. 01, 2024
- Modified: May. 13, 2025
-
9.8
CRITICALCVE-2024-26548
An issue in vivotek Network Camera v.FD8166A-VVTK-0204j allows a remote attacker to execute arbitrary code via a crafted payload to the upload_file.cgi component.... Read more
- Published: Feb. 29, 2024
- Modified: May. 13, 2025
-
6.1
MEDIUMCVE-2024-24035
Cross Site Scripting (XSS) vulnerability in Setor Informatica SIL 3.1 allows attackers to run arbitrary code via the hmessage parameter.... Read more
Affected Products : s.i.l.- Published: Mar. 07, 2024
- Modified: May. 13, 2025
-
8.8
HIGHCVE-2024-23510
Cross-Site Request Forgery (CSRF) vulnerability in Martyn Chamberlin Don't Muck My Markup.This issue affects Don't Muck My Markup: from n/a through 1.8. ... Read more
Affected Products : dont_muck_my_markup- Published: Mar. 27, 2024
- Modified: May. 13, 2025
-
6.1
MEDIUMCVE-2020-36845
The KnowBe4 Security Awareness Training application before 2020-01-10 contains a redirect function that does not validate the destination URL before redirecting. The response has a SCRIPT element that sets window.location.href to an arbitrary https URL.... Read more
Affected Products : security_awareness_training- Published: Apr. 20, 2025
- Modified: May. 13, 2025
- Vuln Type: Information Disclosure
-
6.1
MEDIUMCVE-2020-36844
The KnowBe4 Security Awareness Training application before 2020-01-10 allows reflected XSS. The response has a SCRIPT element that sets window.location.href to a JavaScript URL.... Read more
Affected Products : security_awareness_training- Published: Apr. 20, 2025
- Modified: May. 13, 2025
- Vuln Type: Cross-Site Scripting
-
9.8
CRITICALCVE-2025-43955
TwsCachedXPathAPI in Convertigo through 8.3.4 does not restrict the use of commons-jxpath APIs.... Read more
Affected Products : convertigo- Published: Apr. 20, 2025
- Modified: May. 13, 2025
- Vuln Type: Misconfiguration