Latest CVE Feed
-
5.5
MEDIUMCVE-2025-8755
A vulnerability was found in macrozheng mall up to 1.0.3 and classified as problematic. This issue affects the function detail of the file UmsMemberController.java of the component com.macro.mall.portal.controller. The manipulation of the argument orderId... Read more
Affected Products :- Published: Aug. 09, 2025
- Modified: Aug. 12, 2025
-
5.5
MEDIUMCVE-2025-8753
A vulnerability, which was classified as critical, has been found in linlinjava litemall up to 1.8.0. Affected by this issue is the function delete of the file /admin/storage/delete of the component File Handler. The manipulation of the argument key leads... Read more
Affected Products : litemall- Published: Aug. 09, 2025
- Modified: Aug. 12, 2025
-
5.5
MEDIUMCVE-2025-29821
Improper input validation in Dynamics Business Central allows an authorized attacker to disclose information locally.... Read more
- Published: Apr. 08, 2025
- Modified: Aug. 12, 2025
-
9.8
CRITICALCVE-2024-11350
The AdForest theme for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 5.1.6. This is due to the plugin not properly validating a user's identity prior to updating their password through the adfor... Read more
Affected Products : adforest- Published: Jan. 08, 2025
- Modified: Aug. 12, 2025
-
5.4
MEDIUMCVE-2024-12855
The AdForest theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on several AJAX actions like 'sb_remove_ad' in all versions up to, and including, 5.1.7. This makes it possible for authenticated attacke... Read more
Affected Products : adforest- Published: Jan. 08, 2025
- Modified: Aug. 12, 2025
-
6.4
MEDIUMCVE-2024-13323
The WP Booking Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'booking' shortcode in all versions up to, and including, 10.9.2 due to insufficient input sanitization and output escaping on user supplied attribu... Read more
Affected Products : wp_booking_calendar- Published: Jan. 14, 2025
- Modified: Aug. 12, 2025
-
6.4
MEDIUMCVE-2024-12240
The Page Builder by SiteOrigin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the row label parameter in all versions up to, and including, 2.31.0 due to insufficient input sanitization and output escaping. This makes it possible fo... Read more
Affected Products : page_builder- Published: Jan. 14, 2025
- Modified: Aug. 12, 2025
-
7.2
HIGHCVE-2024-13158
An unbounded resource search path in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote authenticated attacker with admin privileges to achieve remote code execution.... Read more
Affected Products : endpoint_manager- Published: Jan. 14, 2025
- Modified: Aug. 12, 2025
-
8.8
HIGHCVE-2023-38120
Adtran SR400ac ping Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Adtran SR400ac routers. Although authentication is required to exploit this vulner... Read more
- Published: May. 03, 2024
- Modified: Aug. 12, 2025
-
8.8
HIGHCVE-2023-38125
Softing edgeAggregator Permissive Cross-domain Policy with Untrusted Domains Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Softing edgeAggregator. Authentication is r... Read more
- Published: May. 03, 2024
- Modified: Aug. 12, 2025
-
8.8
HIGHCVE-2023-39471
TP-Link TL-WR841N ated_tp Command Injection Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of TP-Link TL-WR841N routers. Authentication is not required to explo... Read more
- Published: May. 03, 2024
- Modified: Aug. 12, 2025
-
7.1
HIGHCVE-2025-46341
FreshRSS is a self-hosted RSS feed aggregator. Prior to version 1.26.2, when the server is using HTTP auth via reverse proxy, it's possible to impersonate any user either via the `Remote-User` header or the `X-WebAuth-User` header by making specially craf... Read more
Affected Products : freshrss- Published: Jun. 04, 2025
- Modified: Aug. 12, 2025
-
4.3
MEDIUMCVE-2025-46339
FreshRSS is a self-hosted RSS feed aggregator. Prior to version 1.26.2, it's possible to poison feed favicons by adding a given URL as a feed with the proxy set to an attacker-controlled one and disabled SSL verifying. The favicon hash is computed by hash... Read more
Affected Products : freshrss- Published: Jun. 04, 2025
- Modified: Aug. 12, 2025
-
6.7
MEDIUMCVE-2025-32015
FreshRSS is a self-hosted RSS feed aggregator. Prior to version 1.26.2, HTML is sanitized improperly inside the `<iframe srcdoc>` attribute, which leads to cross-site scripting (XSS) by loading an attacker's UserJS inside `<script src>`. In order to execu... Read more
Affected Products : freshrss- Published: Jun. 04, 2025
- Modified: Aug. 12, 2025
-
4.3
MEDIUMCVE-2025-31482
FreshRSS is a self-hosted RSS feed aggregator. A vulnerability in versions prior to 1.26.2 causes a user to be repeatedly logged out after fetching a malicious feed entry, effectively causing that user to suffer denial of service. Version 1.26.2 contains ... Read more
Affected Products : freshrss- Published: Jun. 04, 2025
- Modified: Aug. 12, 2025
-
8.8
HIGHCVE-2025-8320
Tesla Wall Connector Content-Length Header Improper Input Validation Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Tesla Wall Connector devices. Authenticat... Read more
- Published: Jul. 30, 2025
- Modified: Aug. 12, 2025
-
6.8
MEDIUMCVE-2025-8321
Tesla Wall Connector Firmware Downgrade Vulnerability. This vulnerability allows physically present attackers to execute arbitrary code on affected installations of Tesla Wall Connector devices. Authentication is not required to exploit this vulnerability... Read more
- Published: Jul. 30, 2025
- Modified: Aug. 12, 2025
-
7.8
HIGHCVE-2024-6031
Tesla Model S oFono AT Command Heap-based Buffer Overflow Code Execution Vulnerability. This vulnerability allows local attackers to execute arbitrary code on affected Tesla Model S vehicles. An attacker must first obtain the ability to execute code on th... Read more
- Published: Apr. 30, 2025
- Modified: Aug. 12, 2025
-
7.0
HIGHCVE-2024-6030
Tesla Model S oFono Unnecessary Privileges Sandbox Escape Vulnerability. This vulnerability allows local attackers to escape the sandbox on affected Tesla Model S vehicles. An attacker must first obtain the ability to execute code within the sandbox on th... Read more
- Published: Apr. 30, 2025
- Modified: Aug. 12, 2025
-
6.5
MEDIUMCVE-2025-8828
A vulnerability was determined in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 up to 20250801. Affected is the function ipv6cmd of the file /goform/setIpv6. The manipulation of the argument Ipv6PriDns/Ipv6SecDns/Ipv6StaticGateway/LanIpv6Addr/... Read more
Affected Products : re6500_firmware re6300_firmware re9000_firmware re6250_firmware re6350_firmware re7000_firmware- Published: Aug. 11, 2025
- Modified: Aug. 12, 2025