Latest CVE Feed
-
7.8
HIGHCVE-2025-23294
NVIDIA WebDataset for all platforms contains a vulnerability where an attacker could execute arbitrary code with elevated permissions. A successful exploit of this vulnerability might lead to escalation of privileges, data tampering, information disclosur... Read more
Affected Products :- Published: Aug. 13, 2025
- Modified: Aug. 14, 2025
-
7.8
HIGHCVE-2025-23295
NVIDIA Apex for all platforms contains a vulnerability in a Python component where an attacker could cause a code injection issue by providing a malicious file. A successful exploit of this vulnerability might lead to code execution, escalation of privile... Read more
Affected Products :- Published: Aug. 13, 2025
- Modified: Aug. 14, 2025
-
7.3
HIGHCVE-2024-5477
A potential security vulnerability has been identified in the System BIOS for some HP PC products which may allow escalation of privilege, arbitrary code execution, denial of service, or information disclosure via a physical attack that requires specializ... Read more
Affected Products :- Published: Aug. 13, 2025
- Modified: Aug. 14, 2025
-
7.8
HIGHCVE-2025-23305
NVIDIA Megatron-LM for all platforms contains a vulnerability in the tools component, where an attacker may exploit a code injection issue. A successful exploit of this vulnerability may lead to code execution, escalation of privileges, information disclo... Read more
Affected Products : megatron-lm- Published: Aug. 13, 2025
- Modified: Aug. 14, 2025
-
7.8
HIGHCVE-2025-23296
NVIDIA Isaac-GR00T for all platforms contains a vulnerability in a Python component where an attacker could cause a code injection issue. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, information disclo... Read more
Affected Products :- Published: Aug. 13, 2025
- Modified: Aug. 14, 2025
-
7.8
HIGHCVE-2025-23306
NVIDIA Megatron-LM for all platforms contains a vulnerability in the megatron/training/ arguments.py component where an attacker could cause a code injection issue by providing a malicious input. A successful exploit of this vulnerability may lead to code... Read more
Affected Products : megatron-lm- Published: Aug. 13, 2025
- Modified: Aug. 14, 2025
-
6.5
MEDIUMCVE-2025-50946
OS Command Injection in Olivetin 2025.4.22 Custom Themes via the ParseRequestURI function in service/internal/executor/arguments.go.... Read more
Affected Products :- Published: Aug. 13, 2025
- Modified: Aug. 14, 2025
-
4.3
MEDIUMCVE-2025-54703
Cross-Site Request Forgery (CSRF) vulnerability in Prince Integrate Google Drive allows Cross Site Request Forgery. This issue affects Integrate Google Drive: from n/a through 1.5.2.... Read more
Affected Products :- Published: Aug. 14, 2025
- Modified: Aug. 14, 2025
-
9.3
CRITICALCVE-2025-54707
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in RealMag777 MDTF allows SQL Injection. This issue affects MDTF: from n/a through 1.3.3.7.... Read more
Affected Products : wordpress_meta_data_and_taxonomies_filter- Published: Aug. 14, 2025
- Modified: Aug. 14, 2025
-
5.3
MEDIUMCVE-2025-54691
Authorization Bypass Through User-Controlled Key vulnerability in Stylemix Motors allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Motors: from n/a through 1.4.80.... Read more
Affected Products : motors_-_car_dealer\,_classifieds_\&_listing- Published: Aug. 14, 2025
- Modified: Aug. 14, 2025
-
4.7
MEDIUMCVE-2025-54681
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in CRM Perks Connector for Gravity Forms and Google Sheets allows Phishing. This issue affects Connector for Gravity Forms and Google Sheets: from n/a through 1.2.4.... Read more
Affected Products :- Published: Aug. 14, 2025
- Modified: Aug. 14, 2025
-
4.3
MEDIUMCVE-2025-54702
Cross-Site Request Forgery (CSRF) vulnerability in motov.net Ebook Store allows Cross Site Request Forgery. This issue affects Ebook Store: from n/a through 5.8013.... Read more
Affected Products : ebook_store- Published: Aug. 14, 2025
- Modified: Aug. 14, 2025
-
6.5
MEDIUMCVE-2025-54699
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in masteriyo Masteriyo - LMS allows Stored XSS. This issue affects Masteriyo - LMS: from n/a through 1.18.3.... Read more
Affected Products : masteriyo- Published: Aug. 14, 2025
- Modified: Aug. 14, 2025
-
8.5
HIGHCVE-2025-52820
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in infosoftplugin WooCommerce Point Of Sale (POS) allows SQL Injection. This issue affects WooCommerce Point Of Sale (POS): from n/a through 1.4.... Read more
Affected Products :- Published: Aug. 14, 2025
- Modified: Aug. 14, 2025
-
6.5
MEDIUMCVE-2025-54688
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock JetEngine allows Stored XSS. This issue affects JetEngine: from n/a through 3.7.1.2.... Read more
Affected Products : jetengine_for_elementor- Published: Aug. 14, 2025
- Modified: Aug. 14, 2025
-
6.5
MEDIUMCVE-2025-54680
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Sparkle Themes Blogger Buzz allows Stored XSS. This issue affects Blogger Buzz: from n/a through 1.2.6.... Read more
Affected Products :- Published: Aug. 14, 2025
- Modified: Aug. 14, 2025
-
4.3
MEDIUMCVE-2025-54673
Cross-Site Request Forgery (CSRF) vulnerability in Ays Pro Chartify allows Cross Site Request Forgery. This issue affects Chartify: from n/a through 3.5.3.... Read more
Affected Products :- Published: Aug. 14, 2025
- Modified: Aug. 14, 2025
-
7.5
HIGHCVE-2025-52716
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Acato WP REST Cache allows PHP Local File Inclusion. This issue affects WP REST Cache: from n/a through 2025.1.0.... Read more
Affected Products :- Published: Aug. 14, 2025
- Modified: Aug. 14, 2025
-
7.1
HIGHCVE-2025-52775
Missing Authorization vulnerability in Ronik@UnlimitedWP Project Cost Calculator allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Project Cost Calculator: from n/a through 1.0.0.... Read more
Affected Products :- Published: Aug. 14, 2025
- Modified: Aug. 14, 2025
-
7.5
HIGHCVE-2025-52728
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in WebCodingPlace Responsive Posts Carousel WordPress Plugin allows PHP Local File Inclusion. This issue affects Responsive Posts Carouse... Read more
Affected Products :- Published: Aug. 14, 2025
- Modified: Aug. 14, 2025