Latest CVE Feed
-
9.8
CRITICALCVE-2025-3969
A vulnerability was found in codeprojects News Publishing Site Dashboard 1.0. It has been rated as critical. This issue affects some unknown processing of the file /edit-category.php of the component Edit Category Page. The manipulation of the argument ca... Read more
Affected Products : news_publishing_site_dashboard- Published: Apr. 27, 2025
- Modified: Apr. 30, 2025
-
3.5
LOWCVE-2025-0627
The WordPress Tag, Category, and Taxonomy Manager WordPress plugin before 3.30.0 does not sanitise and escape some of its Widgets settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the ... Read more
Affected Products : taxopress- Published: Apr. 28, 2025
- Modified: Apr. 30, 2025
-
9.8
CRITICALCVE-2025-4020
A vulnerability was found in PHPGurukul Old Age Home Management System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /contact.php. The manipulation of the argument fname leads to sql injection. The attack... Read more
Affected Products : old_age_home_management_system- Published: Apr. 28, 2025
- Modified: Apr. 30, 2025
-
7.8
HIGHCVE-2023-21358
In UWB Google, there is a possible way for a malicious app to masquerade as system app com.android.uwb.resources due to improperly used crypto. This could lead to local escalation of privilege with no additional execution privileges needed. User interacti... Read more
Affected Products : android- EPSS Score: %0.01
- Published: Oct. 30, 2023
- Modified: Apr. 30, 2025
-
7.5
HIGHCVE-2022-45391
Jenkins NS-ND Integration Performance Publisher Plugin 4.8.0.143 and earlier globally and unconditionally disables SSL/TLS certificate and hostname validation for the entire Jenkins controller JVM.... Read more
Affected Products : ns-nd_integration_performance_publisher- EPSS Score: %0.03
- Published: Nov. 15, 2022
- Modified: Apr. 30, 2025
-
4.3
MEDIUMCVE-2022-45390
A missing permission check in Jenkins loader.io Plugin 1.0.1 and earlier allows attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.... Read more
Affected Products : loader.io- EPSS Score: %0.09
- Published: Nov. 15, 2022
- Modified: Apr. 30, 2025
-
5.3
MEDIUMCVE-2022-45389
A missing permission check in Jenkins XP-Dev Plugin 1.0 and earlier allows unauthenticated attackers to trigger builds of jobs corresponding to an attacker-specified repository.... Read more
Affected Products : xp-dev- EPSS Score: %0.11
- Published: Nov. 15, 2022
- Modified: Apr. 30, 2025
-
7.5
HIGHCVE-2022-45388
Jenkins Config Rotator Plugin 2.0.1 and earlier does not restrict a file name query parameter in an HTTP endpoint, allowing unauthenticated attackers to read arbitrary files with '.xml' extension on the Jenkins controller file system.... Read more
Affected Products : config_rotator- EPSS Score: %0.18
- Published: Nov. 15, 2022
- Modified: Apr. 30, 2025
-
5.4
MEDIUMCVE-2022-45387
Jenkins BART Plugin 1.0.3 and earlier does not escape the parsed content of build logs before rendering it on the Jenkins UI, resulting in a stored cross-site scripting (XSS) vulnerability.... Read more
Affected Products : bart- EPSS Score: %6.94
- Published: Nov. 15, 2022
- Modified: Apr. 30, 2025
-
5.5
MEDIUMCVE-2022-45386
Jenkins Violations Plugin 0.7.11 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.... Read more
Affected Products : violations- EPSS Score: %0.08
- Published: Nov. 15, 2022
- Modified: Apr. 30, 2025
-
7.5
HIGHCVE-2022-45385
A missing permission check in Jenkins CloudBees Docker Hub/Registry Notification Plugin 2.6.2 and earlier allows unauthenticated attackers to trigger builds of jobs corresponding to the attacker-specified repository.... Read more
Affected Products : cloudbees_docker_hub\/registry_notification- EPSS Score: %0.11
- Published: Nov. 15, 2022
- Modified: Apr. 30, 2025
-
6.5
MEDIUMCVE-2022-45384
Jenkins Reverse Proxy Auth Plugin 1.7.3 and earlier stores the LDAP manager password unencrypted in the global config.xml file on the Jenkins controller where it can be viewed by attackers with access to the Jenkins controller file system.... Read more
Affected Products : reverse_proxy_auth- EPSS Score: %0.08
- Published: Nov. 15, 2022
- Modified: Apr. 30, 2025
-
6.1
MEDIUMCVE-2022-43119
A cross-site scripting (XSS) vulnerability in Clansphere CMS v2011.4 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Username parameter.... Read more
Affected Products : clansphere- EPSS Score: %0.26
- Published: Nov. 09, 2022
- Modified: Apr. 30, 2025
-
5.5
MEDIUMCVE-2022-43071
A stack overflow in the Catalog::readPageLabelTree2(Object*) function of XPDF v4.04 allows attackers to cause a Denial of Service (DoS) via a crafted PDF file.... Read more
Affected Products : xpdf- EPSS Score: %0.06
- Published: Nov. 15, 2022
- Modified: Apr. 30, 2025
-
7.5
HIGHCVE-2022-42978
In the Netic User Export add-on before 1.3.5 for Atlassian Confluence, authorization is mishandled. An unauthenticated attacker could access files on the remote system.... Read more
Affected Products : confluence_data_center- EPSS Score: %0.61
- Published: Nov. 15, 2022
- Modified: Apr. 30, 2025
-
6.1
MEDIUMCVE-2021-25926
In SiCKRAGE, versions 9.3.54.dev1 to 10.0.11.dev1 are vulnerable to Reflected Cross-Site-Scripting (XSS) due to user input not being validated properly in the `quicksearch` feature. Therefore, an attacker can steal a user's sessionID to masquerade as a vi... Read more
Affected Products : sickrage- EPSS Score: %0.33
- Published: Apr. 12, 2021
- Modified: Apr. 30, 2025
-
5.4
MEDIUMCVE-2021-25925
in SiCKRAGE, versions 4.2.0 to 10.0.11.dev1 are vulnerable to Stored Cross-Site-Scripting (XSS) due to user input not being validated properly when processed by the server. Therefore, an attacker can inject arbitrary JavaScript code inside the application... Read more
Affected Products : sickrage- EPSS Score: %0.18
- Published: Apr. 12, 2021
- Modified: Apr. 30, 2025
-
5.4
MEDIUMCVE-2021-25921
In OpenEMR, versions 2.7.3-rc1 to 6.0.0 are vulnerable to Stored Cross-Site-Scripting (XSS) due to user input not being validated properly in the `Allergies` section. An attacker could lure an admin to enter a malicious payload and by that initiate the ex... Read more
Affected Products : openemr- EPSS Score: %57.07
- Published: Mar. 22, 2021
- Modified: Apr. 30, 2025
-
6.5
MEDIUMCVE-2021-25920
In OpenEMR, versions v2.7.2-rc1 to 6.0.0 are vulnerable to Improper Access Control when creating a new user, which leads to a malicious user able to read and send sensitive messages on behalf of the victim user.... Read more
Affected Products : openemr- EPSS Score: %0.22
- Published: Mar. 22, 2021
- Modified: Apr. 30, 2025
-
4.8
MEDIUMCVE-2021-25919
In OpenEMR, versions 5.0.2 to 6.0.0 are vulnerable to Stored Cross-Site-Scripting (XSS) due to user input not being validated properly. A highly privileged attacker could inject arbitrary code into input fields when creating a new user.... Read more
Affected Products : openemr- EPSS Score: %58.97
- Published: Mar. 22, 2021
- Modified: Apr. 30, 2025