Latest CVE Feed
-
0.0
NACVE-2025-38499
In the Linux kernel, the following vulnerability has been resolved: clone_private_mnt(): make sure that caller has CAP_SYS_ADMIN in the right userns What we want is to verify there is that clone won't expose something hidden by a mount we wouldn't be ab... Read more
Affected Products : linux_kernel- Published: Aug. 11, 2025
- Modified: Aug. 11, 2025
-
0.0
NACVE-2022-50233
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: eir: Fix using strlen with hdev->{dev_name,short_name} Both dev_name and short_name are not guaranteed to be NULL terminated so this instead use strnlen and then attempt to d... Read more
Affected Products : linux_kernel- Published: Aug. 09, 2025
- Modified: Aug. 11, 2025
-
6.5
MEDIUMCVE-2025-8839
A vulnerability was found in jshERP up to 3.5. This issue affects some unknown processing of the file /jshERP-boot/user/addUser of the component Endpoint. The manipulation leads to improper authorization. The attack may be initiated remotely. The exploit ... Read more
Affected Products : jsherp- Published: Aug. 11, 2025
- Modified: Aug. 11, 2025
-
7.5
HIGHCVE-2025-8752
A vulnerability was found in wangzhixuan spring-shiro-training up to 94812c1fd8f7fe796c931f4984ff1aa0671ab562. It has been declared as critical. This vulnerability affects unknown code of the file /role/add. The manipulation leads to command injection. Th... Read more
Affected Products :- Published: Aug. 09, 2025
- Modified: Aug. 11, 2025
-
6.3
MEDIUMCVE-2025-8763
A vulnerability was found in Ruijie EG306MG 3.0(1)B11P309. It has been rated as problematic. This issue affects some unknown processing of the file /etc/strongswan.conf of the component strongSwan. The manipulation of the argument i_dont_care_about_securi... Read more
Affected Products :- Published: Aug. 09, 2025
- Modified: Aug. 11, 2025
-
6.4
MEDIUMCVE-2025-7726
The The7 theme for WordPress is vulnerable to Stored Cross-Site Scripting via its lightbox rendering code in all versions up to, and including, 12.6.0 due to insufficient input sanitization and output escaping. The theme’s JavaScript reads user-supplied '... Read more
Affected Products :- Published: Aug. 09, 2025
- Modified: Aug. 11, 2025
-
6.8
MEDIUMCVE-2025-8864
Shared Access Signature token is not masked in the backup configuration response and is also exposed in the yb_backup logs... Read more
Affected Products :- Published: Aug. 11, 2025
- Modified: Aug. 11, 2025
-
7.5
HIGHCVE-2025-20234
A vulnerability in Universal Disk Format (UDF) processing of ClamAV could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to a memory overread during UDF file scann... Read more
- Published: Jun. 18, 2025
- Modified: Aug. 11, 2025
-
9.1
CRITICALCVE-2025-49591
CryptPad is a collaboration suite. Prior to version 2025.3.0, enforcement of Two-Factor Authentication (2FA) in CryptPad can be trivially bypassed, due to weak implementation of access controls. An attacker that compromises a user's credentials can gain a... Read more
Affected Products : cryptpad- Published: Jun. 18, 2025
- Modified: Aug. 11, 2025
-
9.8
CRITICALCVE-2025-20260
A vulnerability in the PDF scanning processes of ClamAV could allow an unauthenticated, remote attacker to cause a buffer overflow condition, cause a denial of service (DoS) condition, or execute arbitrary code on an affected device. This vulnerability... Read more
Affected Products : clamav- Published: Jun. 18, 2025
- Modified: Aug. 11, 2025
-
6.1
MEDIUMCVE-2025-49590
CryptPad is a collaboration suite. Prior to version 2025.3.0, the "Link Bouncer" functionality attempts to filter javascript URIs to prevent Cross-Site Scripting (XSS), however this can be bypassed. There is an "early allow" code path that happens before ... Read more
Affected Products : cryptpad- Published: Jun. 18, 2025
- Modified: Aug. 11, 2025
-
2.0
LOWCVE-2025-8573
Concrete CMS versions 9 through 9.4.2 are vulnerable to Stored XSS from Home Folder on Members Dashboard page. Version 8 was not affected. A rogue admin could set up a malicious folder containing XSS to which users could be directed upon login. The Concr... Read more
- Published: Aug. 05, 2025
- Modified: Aug. 11, 2025
-
8.8
HIGHCVE-2025-5071
The AI Engine plugin for WordPress is vulnerable to unauthorized modification of data and loss of data due to a missing capability check on the 'Meow_MWAI_Labs_MCP::can_access_mcp' function in versions 2.8.0 to 2.8.3. This makes it possible for authentica... Read more
- Published: Jun. 19, 2025
- Modified: Aug. 11, 2025
-
5.3
MEDIUMCVE-2025-1766
The Event Manager, Events Calendar, Tickets, Registrations – Eventin plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'payment_complete' function in all versions up to, and including, 4.0.24.... Read more
Affected Products : eventin- Published: Mar. 20, 2025
- Modified: Aug. 11, 2025
-
5.8
MEDIUMCVE-2025-2109
The WP Compress – Instant Performance & Speed Optimization plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 6.30.15 via the init() function. This makes it possible for unauthenticated attackers to mak... Read more
Affected Products : wp_compress- Published: Mar. 25, 2025
- Modified: Aug. 11, 2025
-
8.8
HIGHCVE-2025-2110
The WP Compress – Instant Performance & Speed Optimization plugin for WordPress is vulnerable to unauthorized access, modification, and loss of data due to missing capability checks on its on its AJAX functions in all versions up to, and including, 6.30.1... Read more
Affected Products : wp_compress- Published: Mar. 26, 2025
- Modified: Aug. 11, 2025
-
8.8
HIGHCVE-2025-26964
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Themewinter Eventin allows PHP Local File Inclusion. This issue affects Eventin: from n/a through 4.0.20.... Read more
Affected Products : eventin- Published: Feb. 25, 2025
- Modified: Aug. 11, 2025
-
6.5
MEDIUMCVE-2024-37507
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Themewinter Eventin allows Stored XSS.This issue affects Eventin: from n/a through 3.3.57.... Read more
Affected Products : eventin- Published: Jul. 21, 2024
- Modified: Aug. 11, 2025
-
5.9
MEDIUMCVE-2024-39648
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Themewinter Eventin allows Stored XSS.This issue affects Eventin: from n/a through 4.0.5.... Read more
Affected Products : eventin- Published: Aug. 01, 2024
- Modified: Aug. 11, 2025
-
6.1
MEDIUMCVE-2022-20634
A vulnerability in the web-based management interface of Cisco ECE could allow an unauthenticated, remote attacker to redirect a user to an undesired web page. This vulnerability is due to improper input validation of the URL parameters in an HTTP r... Read more
Affected Products : enterprise_chat_and_email- Published: Nov. 15, 2024
- Modified: Aug. 11, 2025