Latest CVE Feed
-
7.8
HIGHCVE-2025-27198
Photoshop Desktop versions 25.12.1, 26.4.1 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in tha... Read more
- Published: Apr. 08, 2025
- Modified: May. 05, 2025
- Vuln Type: Memory Corruption
-
8.8
HIGHCVE-2024-0779
The Enjoy Social Feed plugin for WordPress website WordPress plugin through 6.2.2 does not have authorisation and CSRF in various function hooked to admin_init, allowing unauthenticated users to call them and unlink arbitrary users Instagram Account for e... Read more
Affected Products : enjoy_social_feed- Published: Mar. 18, 2024
- Modified: May. 05, 2025
-
8.8
HIGHCVE-2024-0858
The Innovs HR WordPress plugin through 1.0.3.4 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions via CSRF attacks such as adding them as employees.... Read more
Affected Products : innovs_hr- Published: Mar. 18, 2024
- Modified: May. 05, 2025
-
6.1
MEDIUMCVE-2024-0973
The Widget for Social Page Feeds WordPress plugin before 6.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is... Read more
Affected Products : widget_for_social_page_feeds- Published: Mar. 18, 2024
- Modified: May. 05, 2025
-
4.8
MEDIUMCVE-2024-1401
The Profile Box Shortcode And Widget WordPress plugin before 1.2.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capabil... Read more
Affected Products : profile_box_shortcode_and_widget- Published: Mar. 19, 2024
- Modified: May. 05, 2025
-
5.4
MEDIUMCVE-2023-7246
The System Dashboard WordPress plugin before 2.8.10 does not sanitize and escape some parameters, which could allow administrators in multisite WordPress configurations to perform Cross-Site Scripting attacks... Read more
Affected Products : system_dashboard- Published: Mar. 20, 2024
- Modified: May. 05, 2025
-
6.1
MEDIUMCVE-2024-0337
The Travelpayouts: All Travel Brands in One Place WordPress plugin through 1.1.15 is vulnerable to Open Redirect due to insufficient validation on the travelpayouts_redirect variable. This makes it possible for unauthenticated attackers to redirect users ... Read more
Affected Products : travelpayouts- Published: Mar. 20, 2024
- Modified: May. 05, 2025
-
8.8
HIGHCVE-2024-0856
The Appointment Booking Calendar WordPress plugin before 1.3.83 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions via CSRF attacks such as adding a booking to the calendar without paying... Read more
Affected Products : appointment_booking_calendar- Published: Mar. 20, 2024
- Modified: May. 05, 2025
-
7.1
HIGHCVE-2024-1983
The Simple Ajax Chat WordPress plugin before 20240223 does not prevent visitors from using malicious Names when using the chat, which will be reflected unsanitized to other users.... Read more
Affected Products : simple_ajax_chat- Published: Mar. 20, 2024
- Modified: May. 05, 2025
-
6.2
MEDIUMCVE-2025-29316
An issue in DataPatrol Screenshot watermark, printing watermark agent v.3.5.2.0 allows a physically proximate attacker to obtain sensitive information. NOTE: the Supplier disputes the Print Job Watermark Bypass claim because the watermark is added by hook... Read more
Affected Products :- Published: Apr. 17, 2025
- Modified: May. 05, 2025
- Vuln Type: Information Disclosure
-
6.5
MEDIUMCVE-2022-43351
Sanitization Management System v1.0 was discovered to contain an arbitrary file deletion vulnerability via the component /classes/Master.php?f=delete_img.... Read more
Affected Products : sanitization_management_system- EPSS Score: %0.10
- Published: Nov. 07, 2022
- Modified: May. 05, 2025
-
7.2
HIGHCVE-2022-43350
Sanitization Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /php-sms/classes/Master.php?f=delete_inquiry.... Read more
Affected Products : sanitization_management_system- EPSS Score: %0.09
- Published: Nov. 07, 2022
- Modified: May. 05, 2025
-
7.5
HIGHCVE-2022-43319
An information disclosure vulnerability in the component vcs/downloadFiles.php?download=./search.php of Simple E-Learning System v1.0 allows attackers to read arbitrary files.... Read more
Affected Products : simple_e-learning_system- EPSS Score: %0.12
- Published: Nov. 07, 2022
- Modified: May. 05, 2025
-
8.8
HIGHCVE-2022-43306
The d8s-timer for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. A potential code execution backdoor inserted by third parties is the democritus-dates package. The affected version of d8s-htm is 0.1... Read more
Affected Products : d8s-timer- EPSS Score: %0.12
- Published: Nov. 07, 2022
- Modified: May. 05, 2025
-
9.8
CRITICALCVE-2022-43305
The d8s-python for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. A potential code execution backdoor inserted by third parties is the democritus-algorithms package. The affected version of d8s-htm ... Read more
Affected Products : d8s-python- EPSS Score: %0.12
- Published: Nov. 07, 2022
- Modified: May. 05, 2025
-
9.8
CRITICALCVE-2022-43304
The d8s-timer for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. A potential code execution backdoor inserted by third parties is the democritus-uuids package. The affected version of d8s-htm is 0.1... Read more
Affected Products : d8s-timer- EPSS Score: %0.12
- Published: Nov. 07, 2022
- Modified: May. 05, 2025
-
9.8
CRITICALCVE-2022-43303
The d8s-strings for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. A potential code execution backdoor inserted by third parties is the democritus-uuids package. The affected version of d8s-htm is 0... Read more
Affected Products : d8s-strings- EPSS Score: %0.12
- Published: Nov. 07, 2022
- Modified: May. 05, 2025
-
7.2
HIGHCVE-2022-43052
Online Diagnostic Lab Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /odlms/classes/Users.php?f=delete.... Read more
Affected Products : online_diagnostic_lab_management_system- EPSS Score: %0.09
- Published: Nov. 07, 2022
- Modified: May. 05, 2025
-
7.2
HIGHCVE-2022-43051
Online Diagnostic Lab Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /odlms/classes/Users.php?f=delete_test.... Read more
Affected Products : online_diagnostic_lab_management_system- EPSS Score: %0.09
- Published: Nov. 07, 2022
- Modified: May. 05, 2025
-
7.2
HIGHCVE-2022-43050
Online Tours & Travels Management System v1.0 was discovered to contain an arbitrary file upload vulnerability in the component update_profile.php. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file.... Read more
Affected Products : online_tours_and_travels_management_system- EPSS Score: %0.12
- Published: Nov. 07, 2022
- Modified: May. 05, 2025