Latest CVE Feed
-
7.1
HIGHCVE-2025-30158
NamelessMC is a free, easy to use & powerful website software for Minecraft servers. In version 2.1.4 and prior, the forum allows users to post iframe elements inside forum topics/comments/feed with no restriction on the iframe's width and height attribut... Read more
Affected Products : nameless- Published: Apr. 18, 2025
- Modified: May. 13, 2025
- Vuln Type: Denial of Service
-
7.3
HIGHCVE-2025-30357
NamelessMC is a free, easy to use & powerful website software for Minecraft servers. In version 2.1.4 and prior, if a malicious user is leaving spam comments on many topics then an administrator, unable to manually remove each spam comment, may delete the... Read more
Affected Products : nameless- Published: Apr. 18, 2025
- Modified: May. 13, 2025
-
5.4
MEDIUMCVE-2024-6938
A vulnerability has been found in SiYuan 3.1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file PDF.js of the component PDF Handler. The manipulation leads to cross site scripting. The attack can be lau... Read more
Affected Products : siyuan- Published: Jul. 21, 2024
- Modified: May. 13, 2025
-
7.1
HIGHCVE-2025-31118
NamelessMC is a free, easy to use & powerful website software for Minecraft servers. In version 2.1.4 and prior, forum quick reply feature (view_topic.php) does not implement any spam prevention mechanism. This allows authenticated users to continuously p... Read more
Affected Products : nameless- Published: Apr. 18, 2025
- Modified: May. 13, 2025
- Vuln Type: Denial of Service
-
7.8
HIGHCVE-2024-24245
An issue in Canimaan Software LTD ClamXAV v3.1.2 through v3.6.1 and fixed in v.3.6.2 allows a local attacker to escalate privileges via the ClamXAV helper tool component.... Read more
Affected Products : clamxav- Published: Apr. 09, 2024
- Modified: May. 13, 2025
-
5.3
MEDIUMCVE-2025-31120
NamelessMC is a free, easy to use & powerful website software for Minecraft servers. In version 2.1.4 and prior, an insecure view count mechanism in the forum page allows an unauthenticated attacker to artificially increase the view count. The application... Read more
Affected Products : nameless- Published: Apr. 18, 2025
- Modified: May. 13, 2025
- Vuln Type: Misconfiguration
-
8.6
HIGHCVE-2025-32389
NamelessMC is a free, easy to use & powerful website software for Minecraft servers. Prior to version 2.1.4, NamelessMC is vulnerable to SQL injection by providing an unexpected square bracket GET parameter syntax. Square bracket GET parameter syntax refe... Read more
Affected Products : nameless- Published: Apr. 18, 2025
- Modified: May. 13, 2025
- Vuln Type: Injection
-
6.3
MEDIUMCVE-2025-22142
NamelessMC is a free, easy to use & powerful website software for Minecraft servers. In affected versions an admin can add the ability to have users fill out an additional field and users can inject javascript code into it that would be activated once a s... Read more
Affected Products : nameless- Published: Jan. 13, 2025
- Modified: May. 13, 2025
- Vuln Type: Cross-Site Scripting
-
7.5
HIGHCVE-2024-8418
A flaw was found in Aardvark-dns, which is vulnerable to a Denial of Service attack due to the serial processing of TCP DNS queries. An attacker can exploit this flaw by keeping a TCP connection open indefinitely, causing the server to become unresponsive... Read more
- Published: Sep. 04, 2024
- Modified: May. 13, 2025
-
9.8
CRITICALCVE-2024-12442
EnerSys AMPA versions 24.04 through 24.16, inclusive, are vulnerable to command injection leading to privileged remote shell access.... Read more
Affected Products :- Published: May. 09, 2025
- Modified: May. 13, 2025
- Vuln Type: Injection
-
7.5
HIGHCVE-2023-6064
The PayHere Payment Gateway WordPress plugin before 2.2.12 automatically creates publicly-accessible log files containing sensitive information when transactions occur.... Read more
Affected Products : payhere_payment_gateway- EPSS Score: %0.39
- Published: Jan. 01, 2024
- Modified: May. 13, 2025
-
7.2
HIGHCVE-2022-42218
Open Source SACCO Management System v1.0 vulnerable to SQL Injection via /sacco_shield/manage_loan.php.... Read more
Affected Products : open_source_sacco_management_system- EPSS Score: %0.09
- Published: Oct. 18, 2022
- Modified: May. 13, 2025
-
6.1
MEDIUMCVE-2022-42202
TP-Link TL-WR841N 8.0 4.17.16 Build 120201 Rel.54750n is vulnerable to Cross Site Scripting (XSS).... Read more
- EPSS Score: %0.11
- Published: Oct. 18, 2022
- Modified: May. 13, 2025
-
7.5
HIGHCVE-2022-42188
In Lavalite 9.0.0, the XSRF-TOKEN cookie is vulnerable to path traversal attacks, enabling read access to arbitrary files on the server.... Read more
Affected Products : lavalite- EPSS Score: %0.15
- Published: Oct. 18, 2022
- Modified: May. 13, 2025
-
9.8
CRITICALCVE-2022-42165
Tenda AC10 V15.03.06.23 contains a Stack overflow vulnerability via /goform/formSetDeviceName.... Read more
- EPSS Score: %0.17
- Published: Oct. 17, 2022
- Modified: May. 13, 2025
-
6.1
MEDIUMCVE-2022-42116
A Cross-site scripting (XSS) vulnerability in the Frontend Editor module's integration with CKEditor in Liferay Portal 7.3.2 through 7.4.3.14, and Liferay DXP 7.3 before update 6, and 7.4 before update 15 allows remote attackers to inject arbitrary web sc... Read more
- EPSS Score: %0.18
- Published: Oct. 18, 2022
- Modified: May. 13, 2025
-
5.4
MEDIUMCVE-2022-42115
Cross-site scripting (XSS) vulnerability in the Object module's edit object details page in Liferay Portal 7.4.3.4 through 7.4.3.36 allows remote attackers to inject arbitrary web script or HTML via a crafted payload injected into the object field's `Labe... Read more
Affected Products : liferay_portal- EPSS Score: %0.19
- Published: Oct. 18, 2022
- Modified: May. 13, 2025
-
9.8
CRITICALCVE-2022-40889
Phpok 6.1 has a deserialization vulnerability via framework/phpok_call.php.... Read more
Affected Products : phpok- EPSS Score: %0.11
- Published: Oct. 18, 2022
- Modified: May. 13, 2025
-
7.8
HIGHCVE-2022-3569
Due to an issue with incorrect sudo permissions, Zimbra Collaboration Suite (ZCS) suffers from a local privilege escalation issue in versions 9.0.0 and prior, where the 'zimbra' user can effectively coerce postfix into running arbitrary commands as 'root'... Read more
Affected Products : zimbra_collaboration_suite- EPSS Score: %2.48
- Published: Oct. 17, 2022
- Modified: May. 13, 2025
-
9.8
CRITICALCVE-2022-39198
A deserialization vulnerability existed in dubbo hessian-lite 3.2.12 and its earlier versions, which could lead to malicious code execution. This issue affects Apache Dubbo 2.7.x version 2.7.17 and prior versions; Apache Dubbo 3.0.x version 3.0.11 and pri... Read more
Affected Products : dubbo- EPSS Score: %7.55
- Published: Oct. 18, 2022
- Modified: May. 13, 2025