Latest CVE Feed
-
7.8
HIGHCVE-2022-39093
In power management service, there is a missing permission check. This could lead to set up power management service with no additional execution privileges needed.... Read more
- Published: Dec. 06, 2022
- Modified: Apr. 23, 2025
-
7.8
HIGHCVE-2022-39092
In power management service, there is a missing permission check. This could lead to set up power management service with no additional execution privileges needed.... Read more
- Published: Dec. 06, 2022
- Modified: Apr. 23, 2025
-
7.8
HIGHCVE-2022-39091
In power management service, there is a missing permission check. This could lead to set up power management service with no additional execution privileges needed.... Read more
- Published: Dec. 06, 2022
- Modified: Apr. 23, 2025
-
7.8
HIGHCVE-2022-39090
In power management service, there is a missing permission check. This could lead to set up power management service with no additional execution privileges needed.... Read more
- Published: Dec. 06, 2022
- Modified: Apr. 23, 2025
-
5.4
MEDIUMCVE-2022-25630
An authenticated user can embed malicious content with XSS into the admin group policy page.... Read more
Affected Products : messaging_gateway- Published: Dec. 09, 2022
- Modified: Apr. 23, 2025
-
5.4
MEDIUMCVE-2022-25629
An authenticated user who has the privilege to add/edit annotations on the Content tab, can craft a malicious annotation that can be executed on the annotations page (Annotation Text Column).... Read more
Affected Products : messaging_gateway- Published: Dec. 09, 2022
- Modified: Apr. 23, 2025
-
7.2
HIGHCVE-2022-1540
The PostmagThemes Demo Import WordPress plugin through 1.0.7 does not validate the imported file, allowing high-privilege users such as admin to upload arbitrary files (such as PHP) leading to RCE.... Read more
Affected Products : postmagthemes_demo_import- Published: Dec. 05, 2022
- Modified: Apr. 23, 2025
-
9.8
CRITICALCVE-2020-6627
The web-management application on Seagate Central NAS STCG2000300, STCG3000300, and STCG4000300 devices allows OS command injection via mv_backend_launch in cirrus/application/helpers/mv_backend_helper.php by leveraging the "start" state and sending a che... Read more
Affected Products : stcg2000300_firmware stcg3000300_firmware stcg4000300_firmware stcg2000300 stcg3000300 stcg4000300- Published: Dec. 06, 2022
- Modified: Apr. 23, 2025
-
9.1
CRITICALCVE-2024-35049
SurveyKing v1.3.1 was discovered to keep users' sessions active after logout. Related to an incomplete fix for CVE-2022-25590.... Read more
Affected Products : surveyking- Published: May. 14, 2024
- Modified: Apr. 23, 2025
-
8.8
HIGHCVE-2024-35050
An issue in SurveyKing v1.3.1 allows attackers to escalate privileges via re-using the session ID of a user that was deleted by an Admin.... Read more
Affected Products : surveyking- Published: May. 14, 2024
- Modified: Apr. 23, 2025
-
9.8
CRITICALCVE-2025-3174
A vulnerability has been found in Project Worlds Online Lawyer Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /searchLawyer.php. The manipulation of the argument experience leads to... Read more
- Published: Apr. 03, 2025
- Modified: Apr. 23, 2025
- Vuln Type: Injection
-
8.8
HIGHCVE-2024-44817
SQL Injection vulnerability in ZZCMS v.2023 and before allows a remote attacker to obtain sensitive information via the id parameter in the adv2.php component.... Read more
Affected Products : zzcms- Published: Sep. 04, 2024
- Modified: Apr. 23, 2025
-
5.4
MEDIUMCVE-2024-44818
Cross Site Scripting vulnerability in ZZCMS v.2023 and before allows a remote attacker to obtain sensitive information via the HTTP_Referer header of the caina.php component.... Read more
Affected Products : zzcms- Published: Sep. 04, 2024
- Modified: Apr. 23, 2025
-
5.3
MEDIUMCVE-2024-44821
ZZCMS 2023 contains a vulnerability in the captcha reuse logic located in /inc/function.php. The checkyzm function does not properly refresh the captcha value after a failed validation attempt. As a result, an attacker can exploit this flaw by repeatedly ... Read more
Affected Products : zzcms- Published: Sep. 04, 2024
- Modified: Apr. 23, 2025
-
7.2
HIGHCVE-2024-11242
A vulnerability was found in ZZCMS 2023. It has been rated as critical. Affected by this issue is some unknown functionality of the file /admin/ad_list.php?action=pass of the component Keyword Filtering. The manipulation of the argument keyword leads to s... Read more
Affected Products : zzcms- Published: Nov. 15, 2024
- Modified: Apr. 23, 2025
-
6.1
MEDIUMCVE-2025-1949
A vulnerability, which was classified as problematic, has been found in ZZCMS 2025. This issue affects some unknown processing of the file /3/ucenter_api/code/register_nodb.php of the component URL Handler. The manipulation of the argument $_SERVER['PHP_S... Read more
Affected Products : zzcms- Published: Mar. 04, 2025
- Modified: Apr. 23, 2025
- Vuln Type: Cross-Site Scripting
-
7.5
HIGHCVE-2024-47213
An issue was discovered affecting Enrich 5.1.0 and below. It involves sending a maliciously crafted Snowplow event to the pipeline. Upon receiving this event and trying to validate it, Enrich crashes and attempts to restart indefinitely. As a result, even... Read more
Affected Products : enrich- Published: Apr. 03, 2025
- Modified: Apr. 23, 2025
- Vuln Type: Denial of Service
-
7.5
HIGHCVE-2024-47215
An issue was discovered in Snowbridge setups sending data to Google Tag Manager Server Side. It involves attaching an invalid GTM SS preview header to events, causing them to be retried indefinitely. As a result, the performance of forwarding events to GT... Read more
Affected Products : snowbridge- Published: Apr. 03, 2025
- Modified: Apr. 23, 2025
- Vuln Type: Misconfiguration
-
9.8
CRITICALCVE-2025-3245
A vulnerability was found in itsourcecode Library Management System 1.0. It has been rated as critical. Affected by this issue is the function Search of the file library_management/src/Library_Management/Forgot.java. The manipulation of the argument txtun... Read more
Affected Products : library_management_system- Published: Apr. 04, 2025
- Modified: Apr. 23, 2025
- Vuln Type: Injection
-
6.1
MEDIUMCVE-2025-3252
A vulnerability has been found in xujiangfei admintwo 1.0 and classified as problematic. This vulnerability affects unknown code of the file /resource/add. The manipulation of the argument Name leads to cross site scripting. The attack can be initiated re... Read more
Affected Products : admintwo- Published: Apr. 04, 2025
- Modified: Apr. 23, 2025
- Vuln Type: Cross-Site Scripting