Latest CVE Feed
-
3.1
LOWCVE-2025-46720
Keystone is a content management system for Node.js. Prior to version 6.5.0, `{field}.isFilterable` access control can be bypassed in `update` and `delete` mutations by adding additional unique filters. These filters can be used as an oracle to probe the ... Read more
Affected Products : keystone- Published: May. 05, 2025
- Modified: May. 05, 2025
- Vuln Type: Authorization
-
7.5
HIGHCVE-2025-4210
A vulnerability classified as critical was found in Casdoor up to 1.811.0. This vulnerability affects the function HandleScim of the file controllers/scim.go of the component SCIM User Creation Endpoint. The manipulation leads to authorization bypass. The... Read more
Affected Products : casdoor- Published: May. 02, 2025
- Modified: May. 05, 2025
- Vuln Type: Authorization
-
7.3
HIGHCVE-2024-13738
The The Motors - Car Dealer, Rental & Listing WordPress theme theme for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 5.6.65. This is due to the software allowing users to execute an action that does not pr... Read more
Affected Products :- Published: May. 03, 2025
- Modified: May. 05, 2025
-
6.1
MEDIUMCVE-2025-4199
The Abundatrade Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.8.02. This is due to missing or incorrect nonce validation on the 'abundatrade' page. This makes it possible for unauthenticate... Read more
Affected Products :- Published: May. 03, 2025
- Modified: May. 05, 2025
- Vuln Type: Cross-Site Request Forgery
-
5.3
MEDIUMCVE-2025-4260
A vulnerability was found in zhangyanbo2007 youkefu up to 4.2.0 and classified as problematic. Affected by this issue is the function impsave of the file m\web\handler\admin\system\TemplateController.java. The manipulation of the argument dataFile leads t... Read more
Affected Products :- Published: May. 05, 2025
- Modified: May. 05, 2025
- Vuln Type: Authentication
-
5.3
MEDIUMCVE-2025-4261
A vulnerability was found in GAIR-NLP factool up to 3f3914bc090b644be044b7e0005113c135d8b20f. It has been classified as critical. This affects the function run_single of the file factool/factool/math/tool.py. The manipulation leads to code injection. The ... Read more
Affected Products :- Published: May. 05, 2025
- Modified: May. 05, 2025
- Vuln Type: Injection
-
6.4
MEDIUMCVE-2025-46734
league/commonmark is a PHP Markdown parser. A cross-site scripting (XSS) vulnerability in the Attributes extension of the league/commonmark library (versions 1.5.0 through 2.6.x) allows remote attackers to insert malicious JavaScript calls into HTML. The ... Read more
Affected Products : commonmark- Published: May. 05, 2025
- Modified: May. 05, 2025
- Vuln Type: Cross-Site Scripting
-
6.4
MEDIUMCVE-2025-3815
The SurveyJS plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘id’ parameter in all versions up to, and including, 1.12.32 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attack... Read more
Affected Products :- Published: May. 03, 2025
- Modified: May. 05, 2025
- Vuln Type: Cross-Site Scripting
-
6.5
MEDIUMCVE-2025-4258
A vulnerability, which was classified as critical, was found in zhangyanbo2007 youkefu up to 4.2.0. Affected is the function Upload of the file \youkefu-master\src\main\java\com\ukefu\webim\web\handler\resource\MediaController.java. The manipulation of th... Read more
Affected Products :- Published: May. 05, 2025
- Modified: May. 05, 2025
- Vuln Type: Misconfiguration
-
7.3
HIGHCVE-2025-47244
Inedo ProGet through 2024.22 allows remote attackers to reach restricted functionality through the C# reflection layer, as demonstrated by causing a denial of service (when an attacker executes a loop calling RestartWeb) or obtaining potentially sensitive... Read more
Affected Products : proget- Published: May. 03, 2025
- Modified: May. 05, 2025
-
5.1
MEDIUMCVE-2025-4257
A vulnerability, which was classified as problematic, has been found in SeaCMS 13.2. This issue affects some unknown processing of the file /admin_pay.php. The manipulation of the argument cstatus leads to cross site scripting. The attack may be initiated... Read more
Affected Products : seacms- Published: May. 05, 2025
- Modified: May. 05, 2025
- Vuln Type: Cross-Site Scripting
-
0.0
NACVE-2023-53115
In the Linux kernel, the following vulnerability has been resolved: scsi: mpi3mr: Fix memory leaks in mpi3mr_init_ioc() Don't allocate memory again when IOC is being reinitialized.... Read more
Affected Products : linux_kernel- Published: May. 02, 2025
- Modified: May. 05, 2025
-
7.8
HIGHCVE-2025-46723
OpenVM is a performant and modular zkVM framework built for customization and extensibility. In version 1.0.0, OpenVM is vulnerable to overflow through byte decomposition of pc in AUIPC chip. A typo results in the highest limb of pc being range checked to... Read more
Affected Products :- Published: May. 02, 2025
- Modified: May. 05, 2025
- Vuln Type: Memory Corruption
-
4.8
MEDIUMCVE-2025-4287
A vulnerability was found in PyTorch 2.6.0+cu124. It has been rated as problematic. Affected by this issue is the function torch.cuda.nccl.reduce of the file torch/cuda/nccl.py. The manipulation leads to denial of service. It is possible to launch the att... Read more
Affected Products : pytorch- Published: May. 05, 2025
- Modified: May. 05, 2025
- Vuln Type: Denial of Service
-
5.3
MEDIUMCVE-2025-4281
A vulnerability, which was classified as problematic, was found in Shenzhen Sixun Software Sixun Shanghui Group Business Management System 7. This affects an unknown part of the file /api/GylOperator/LoadData. The manipulation leads to information disclos... Read more
Affected Products :- Published: May. 05, 2025
- Modified: May. 05, 2025
- Vuln Type: Information Disclosure
-
8.8
HIGHCVE-2025-4279
The External image replace plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'external_image_replace_get_posts::replace_post' function in all versions up to, and including, 1.0.8. This makes it possibl... Read more
Affected Products :- Published: May. 05, 2025
- Modified: May. 05, 2025
- Vuln Type: Authentication
-
6.4
MEDIUMCVE-2025-4170
The Xavin's Review Ratings plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'xrr' shortcode in all versions up to, and including, 1.4.0 due to insufficient input sanitization and output escaping on user supplied attr... Read more
Affected Products :- Published: May. 03, 2025
- Modified: May. 05, 2025
- Vuln Type: Cross-Site Scripting
-
7.3
HIGHCVE-2025-4272
A vulnerability was found in Mechrevo Control Console 1.0.2.70. It has been rated as critical. Affected by this issue is some unknown functionality in the library C:\Program Files\OEM\MECHREVO Control Center\UniwillService\MyControlCenter\csCAPI.dll of th... Read more
Affected Products :- Published: May. 05, 2025
- Modified: May. 05, 2025
- Vuln Type: Misconfiguration
-
4.0
MEDIUMCVE-2025-47241
In browser-use (aka Browser Use) before 0.1.45, URL parsing of allowed_domains is mishandled because userinfo can be placed in the authority component.... Read more
Affected Products :- Published: May. 03, 2025
- Modified: May. 05, 2025
- Vuln Type: Misconfiguration
-
7.5
HIGHCVE-2025-46813
Discourse is an open-source community platform. A data leak vulnerability affects sites deployed between commits 10df7fdee060d44accdee7679d66d778d1136510 and 82d84af6b0efbd9fa2aeec3e91ce7be1a768511b. On login-required sites, the leak meant that some conte... Read more
Affected Products : discourse- Published: May. 05, 2025
- Modified: May. 05, 2025
- Vuln Type: Information Disclosure