Latest CVE Feed
-
9.8
CRITICALCVE-2022-3600
The Easy Digital Downloads WordPress plugin before 3.1.0.2 does not validate data when its output in a CSV file, which could lead to CSV injection.... Read more
- EPSS Score: %0.54
- Published: Nov. 21, 2022
- Modified: Apr. 30, 2025
-
4.3
MEDIUMCVE-2022-3336
The Event Monster WordPress plugin before 1.2.0 does not have CSRF check when deleting visitors, which could allow attackers to make logged in admin delete arbitrary visitors via a CSRF attack... Read more
Affected Products : event_monster- EPSS Score: %0.17
- Published: Nov. 21, 2022
- Modified: Apr. 30, 2025
-
7.5
HIGHCVE-2022-38871
In Free5gc v3.0.5, the AMF breaks due to malformed NAS messages.... Read more
Affected Products : free5gc- EPSS Score: %0.08
- Published: Nov. 18, 2022
- Modified: Apr. 30, 2025
-
6.7
MEDIUMCVE-2022-20427
In (TBD) of (TBD), there is a possible way to corrupt memory due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersio... Read more
Affected Products : android- EPSS Score: %0.01
- Published: Nov. 17, 2022
- Modified: Apr. 30, 2025
-
9.8
CRITICALCVE-2021-24649
The WP User Frontend WordPress plugin before 3.5.29 uses a user supplied argument called urhidden in its registration form, which contains the role for the account to be created with, encrypted via wpuf_encryption(). This could allow an attacker having ac... Read more
Affected Products : wp_user_frontend- EPSS Score: %0.27
- Published: Nov. 21, 2022
- Modified: Apr. 30, 2025
-
5.8
MEDIUMCVE-2024-20291
A vulnerability in the access control list (ACL) programming for port channel subinterfaces of Cisco Nexus 3000 and 9000 Series Switches in standalone NX-OS mode could allow an unauthenticated, remote attacker to send traffic that should be blocked throug... Read more
Affected Products : nx-os nexus_3048 nexus_31108pc-v nexus_31108tc-v nexus_31128pq nexus_3132c-z nexus_3132q-v nexus_3132q-xl nexus_3164q nexus_3172pq +71 more products- Published: Feb. 29, 2024
- Modified: Apr. 30, 2025
-
6.4
MEDIUMCVE-2025-3457
The Ocean Extra plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'oceanwp_icon' shortcode in all versions up to, and including, 2.4.6 due to insufficient input sanitization and output escaping on user supplied attributes.... Read more
Affected Products : ocean_extra- Published: Apr. 22, 2025
- Modified: Apr. 30, 2025
-
7.2
HIGHCVE-2024-21682
This High severity Injection vulnerability was introduced in Assets Discovery 1.0 - 6.2.0 (all versions). Assets Discovery, which can be downloaded via Atlassian Marketplace, is a network scanning tool that can be used with or without an agent with Jira... Read more
Affected Products : assets_discovery_data_center- Published: Feb. 20, 2024
- Modified: Apr. 30, 2025
-
6.4
MEDIUMCVE-2025-3458
The Ocean Extra plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'ocean_gallery_id’ parameter in all versions up to, and including, 2.4.6 due to insufficient input sanitization and output escaping. This makes it possible for authe... Read more
Affected Products : ocean_extra- Published: Apr. 22, 2025
- Modified: Apr. 30, 2025
-
9.8
CRITICALCVE-2025-3472
The Ocean Extra plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 2.4.6. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shor... Read more
Affected Products : ocean_extra- Published: Apr. 22, 2025
- Modified: Apr. 30, 2025
-
4.8
MEDIUMCVE-2025-25431
Trendnet TEW-929DRU 1.0.0.10 contains a Stored Cross-site Scripting (XSS) vulnerability via the The ssid key of wifi_data parameter on the /captive_portal.htm page.... Read more
- Published: Feb. 28, 2025
- Modified: Apr. 30, 2025
-
6.5
MEDIUMCVE-2025-29743
D-Link DIR-816 A2V1.1.0B05 was found to contain a command injection in /goform/delRouting.... Read more
- Published: Apr. 22, 2025
- Modified: Apr. 30, 2025
-
9.8
CRITICALCVE-2025-45427
In Tenda AC9 v1.0 with firmware V15.03.05.14_multi, the security parameter of /goform/WifiBasicSet has a stack overflow vulnerability, which can lead to remote arbitrary code execution.... Read more
- Published: Apr. 23, 2025
- Modified: Apr. 30, 2025
-
9.8
CRITICALCVE-2025-3341
A vulnerability, which was classified as critical, was found in codeprojects Online Restaurant Management System 1.0. This affects an unknown part of the file /admin/reservation_view.php. The manipulation of the argument ID leads to sql injection. It is p... Read more
- Published: Apr. 07, 2025
- Modified: Apr. 30, 2025
-
9.8
CRITICALCVE-2025-3342
A vulnerability has been found in codeprojects Online Restaurant Management System 1.0 and classified as critical. This vulnerability affects unknown code of the file /admin/payment_save.php. The manipulation of the argument ID leads to sql injection. The... Read more
- Published: Apr. 07, 2025
- Modified: Apr. 30, 2025
-
9.8
CRITICALCVE-2025-3343
A vulnerability was found in codeprojects Online Restaurant Management System 1.0 and classified as critical. This issue affects some unknown processing of the file /admin/reservation_update.php. The manipulation of the argument ID leads to sql injection.... Read more
- Published: Apr. 07, 2025
- Modified: Apr. 30, 2025
-
9.8
CRITICALCVE-2025-3344
A vulnerability was found in codeprojects Online Restaurant Management System 1.0. It has been classified as critical. Affected is an unknown function of the file /admin/assign_save.php. The manipulation of the argument ID leads to sql injection. It is po... Read more
- Published: Apr. 07, 2025
- Modified: Apr. 30, 2025
-
9.8
CRITICALCVE-2025-3345
A vulnerability was found in codeprojects Online Restaurant Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /admin/combo.php. The manipulation of the argument del leads to sql... Read more
- Published: Apr. 07, 2025
- Modified: Apr. 30, 2025
-
7.5
HIGHCVE-2025-29087
In SQLite 3.44.0 through 3.49.0 before 3.49.1, the concat_ws() SQL function can cause memory to be written beyond the end of a malloc-allocated buffer. If the separator argument is attacker-controlled and has a large string (e.g., 2MB or more), an integer... Read more
Affected Products : sqlite- Published: Apr. 07, 2025
- Modified: Apr. 30, 2025
-
7.5
HIGHCVE-2024-27570
LBT T300-T390 v2.2.1.8 were discovered to contain a stack overflow via the ApCliSsid parameter in the generate_conf_router function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.... Read more
Affected Products : lbt-t300_firmware lbt-t300 lbt-t390_firmware lbt-t390 lbt-t300-t390_firmware lbt-t300-t390- Published: Mar. 01, 2024
- Modified: Apr. 30, 2025