Latest CVE Feed
-
9.8
CRITICALCVE-2025-3380
A vulnerability, which was classified as critical, has been found in PCMan FTP Server 2.0.7. Affected by this issue is some unknown functionality of the component FEAT Command Handler. The manipulation leads to buffer overflow. The attack may be launched ... Read more
- Published: Apr. 07, 2025
- Modified: Apr. 23, 2025
- Vuln Type: Memory Corruption
-
5.4
MEDIUMCVE-2024-46494
A cross-site scripting (XSS) vulnerability in Typecho v1.2.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into Name parameter under a comment for an Article.... Read more
Affected Products : typecho- Published: Apr. 07, 2025
- Modified: Apr. 23, 2025
- Vuln Type: Cross-Site Scripting
-
5.4
MEDIUMCVE-2024-29392
Silverpeas Core 6.3 is vulnerable to Cross Site Scripting (XSS) via ClipboardSessionController.... Read more
Affected Products : silverpeas- Published: May. 22, 2024
- Modified: Apr. 23, 2025
-
9.1
CRITICALCVE-2023-40492
LG Simple Editor deleteCheckSession Directory Traversal Arbitrary File Deletion Vulnerability. This vulnerability allows remote attackers to delete arbitrary files on affected installations of LG Simple Editor. Authentication is not required to exploit th... Read more
Affected Products : simple_editor- Published: May. 03, 2024
- Modified: Apr. 23, 2025
-
6.4
MEDIUMCVE-2024-2345
The FileBird – WordPress Media Library Folders & File Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the folder name parameter in all versions up to, and including, 5.6.3 due to insufficient input sanitization and output esc... Read more
Affected Products : filebird- Published: May. 02, 2024
- Modified: Apr. 23, 2025
-
5.4
MEDIUMCVE-2024-33102
A stored cross-site scripting (XSS) vulnerability in the component /pubs/counter.php of ThinkSAAS v3.7.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the code parameter.... Read more
Affected Products : thinksaas- Published: Apr. 30, 2024
- Modified: Apr. 23, 2025
-
6.1
MEDIUMCVE-2024-33101
A stored cross-site scripting (XSS) vulnerability in the component /action/anti.php of ThinkSAAS v3.7.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the word parameter.... Read more
Affected Products : thinksaas- Published: Apr. 30, 2024
- Modified: Apr. 23, 2025
-
7.3
HIGHCVE-2024-33338
Cross Site Scripting vulnerability in jizhicms v.2.5.4 allows a remote attacker to obtain sensitive information via a crafted article publication request.... Read more
Affected Products : jizhicms- Published: Apr. 29, 2024
- Modified: Apr. 23, 2025
-
6.1
MEDIUMCVE-2023-51254
Cross Site Scripting vulnerability in Jfinalcms v.5.0.0 allows a remote attacker to execute arbitrary code via a crafted script to the friendship link component.... Read more
Affected Products : jfinalcms- Published: Apr. 29, 2024
- Modified: Apr. 23, 2025
-
4.8
MEDIUMCVE-2024-46410
PublicCMS V4.0.202406.d was discovered to contain a cross-site scripting (XSS) vulnerability via a crafted script to the Category Managment feature... Read more
Affected Products : publiccms- Published: Oct. 08, 2024
- Modified: Apr. 23, 2025
-
4.8
MEDIUMCVE-2024-8488
The Survey Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Survey fields in all versions up to, and including, 4.9.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers... Read more
Affected Products : survey_maker- Published: Oct. 08, 2024
- Modified: Apr. 23, 2025
-
4.9
MEDIUMCVE-2024-45894
BlueCMS 1.6 suffers from Arbitrary File Deletion via the file_name parameter in an /admin/database.php?act=del request.... Read more
- Published: Oct. 07, 2024
- Modified: Apr. 23, 2025
-
7.5
HIGHCVE-2024-46078
itsourcecode Sports Management System Project 1.0 is vulnerable to SQL Injection in the function delete_category of the file sports_scheduling/player.php via the argument id.... Read more
- Published: Oct. 04, 2024
- Modified: Apr. 23, 2025
-
8.1
HIGHCVE-2024-41290
FlatPress CMS v1.3.1 1.3 was discovered to use insecure methods to store authentication data via the cookie's component.... Read more
Affected Products : flatpress- Published: Oct. 02, 2024
- Modified: Apr. 23, 2025
-
7.2
HIGHCVE-2024-48454
An issue in SourceCodester Purchase Order Management System v1.0 allows a remote attacker to execute arbitrary code via the /admin?page=user component... Read more
- Published: Oct. 24, 2024
- Modified: Apr. 23, 2025
-
7.5
HIGHCVE-2022-30354
OvalEdge 5.2.8.0 and earlier is affected by a Sensitive Data Exposure vulnerability via a GET request to /user/getUserWithTeam. Authentication is required. The information disclosed is associated with all registered user ID numbers.... Read more
Affected Products : ovaledge- Published: Oct. 25, 2024
- Modified: Apr. 23, 2025
-
8.1
HIGHCVE-2025-29394
An insecure permissions vulnerability in verydows v2.0 allows a remote attacker to execute arbitrary code by uploading a file type.... Read more
Affected Products :- Published: Apr. 09, 2025
- Modified: Apr. 22, 2025
- Vuln Type: Misconfiguration
-
3.3
LOWCVE-2022-4123
A flaw was found in Buildah. The local path and the lowest subdirectory may be disclosed due to incorrect absolute path traversal, resulting in an impact to confidentiality.... Read more
- Published: Dec. 08, 2022
- Modified: Apr. 22, 2025
-
5.3
MEDIUMCVE-2022-4122
A vulnerability was found in buildah. Incorrect following of symlinks while reading .containerignore and .dockerignore results in information disclosure.... Read more
- Published: Dec. 08, 2022
- Modified: Apr. 22, 2025
-
8.8
HIGHCVE-2022-45968
Alist v3.4.0 is vulnerable to File Upload. A user with only file upload permission can upload any file to any folder (even a password protected one).... Read more
Affected Products : alist- Published: Dec. 12, 2022
- Modified: Apr. 22, 2025