Latest CVE Feed
-
4.8
MEDIUMCVE-2025-8542
A vulnerability was found in Portabilis i-Educar 2.10. It has been rated as problematic. This issue affects some unknown processing of the file /intranet/empresas_cad.php. The manipulation of the argument fantasia/razao_social leads to cross site scriptin... Read more
Affected Products : i-educar- Published: Aug. 05, 2025
- Modified: Aug. 12, 2025
- Vuln Type: Cross-Site Scripting
-
4.8
MEDIUMCVE-2025-8543
A vulnerability classified as problematic has been found in Portabilis i-Educar 2.10. Affected is an unknown function of the file /intranet/educar_raca_cad.php. The manipulation of the argument nm_raca leads to cross site scripting. It is possible to laun... Read more
Affected Products : i-educar- Published: Aug. 05, 2025
- Modified: Aug. 12, 2025
- Vuln Type: Cross-Site Scripting
-
4.8
MEDIUMCVE-2025-8544
A vulnerability classified as problematic was found in Portabilis i-Educar 2.10. Affected by this vulnerability is an unknown functionality of the file /module/RegraAvaliacao/edit. The manipulation of the argument nome leads to cross site scripting. The a... Read more
Affected Products : i-educar- Published: Aug. 05, 2025
- Modified: Aug. 12, 2025
- Vuln Type: Cross-Site Scripting
-
9.8
CRITICALCVE-2025-3604
The Flynax Bridge plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 2.2.0. This is due to the plugin not properly validating a user's identity prior to updating their details like email. ... Read more
Affected Products : flynax_bridge- Published: Apr. 24, 2025
- Modified: Aug. 12, 2025
- Vuln Type: Authentication
-
4.8
MEDIUMCVE-2025-8545
A vulnerability, which was classified as problematic, has been found in Portabilis i-Educar 2.10. Affected by this issue is some unknown functionality of the file /intranet/educar_motivo_afastamento_cad.php. The manipulation of the argument nm_motivo lead... Read more
Affected Products : i-educar- Published: Aug. 05, 2025
- Modified: Aug. 12, 2025
- Vuln Type: Cross-Site Scripting
-
9.9
CRITICALCVE-2024-29241
Missing authorization vulnerability in System webapi component in Synology Surveillance Station before 9.2.0-9289 and 9.2.0-11289 allows remote authenticated users to obtain non-sensitive information, write sensitive configurations in DSM, and reboot or s... Read more
- Published: Mar. 28, 2024
- Modified: Aug. 12, 2025
-
8.8
HIGHCVE-2025-2328
The Drag and Drop Multiple File Upload for Contact Form 7 plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the 'dnd_remove_uploaded_files' function in all versions up to, and including, 1.3.8.7. Thi... Read more
Affected Products : drag_and_drop_multiple_file_upload_-_contact_form_7- Published: Mar. 28, 2025
- Modified: Aug. 12, 2025
- Vuln Type: Path Traversal
-
8.1
HIGHCVE-2019-4702
IBM Security Guardium Data Encryption (GDE) 3.0.0.2 specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors.... Read more
- EPSS Score: %0.06
- Published: Jan. 13, 2021
- Modified: Aug. 12, 2025
-
7.5
HIGHCVE-2019-4160
IBM Security Guardium Data Encryption (GDE) 3.0.0.2 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 158577.... Read more
- EPSS Score: %0.05
- Published: Jan. 13, 2021
- Modified: Aug. 12, 2025
-
5.3
MEDIUMCVE-2019-4687
IBM Security Guardium Data Encryption (GDE) 3.0.0.2 stores sensitive information in URL parameters. This may lead to information disclosure if unauthorized parties have access to the URLs via server logs, referrer header or browser history. IBM X-Force ID... Read more
- EPSS Score: %0.04
- Published: Jan. 13, 2021
- Modified: Aug. 12, 2025
-
9.8
CRITICALCVE-2019-7401
NGINX Unit before 1.7.1 might allow an attacker to cause a heap-based buffer overflow in the router process with a specially crafted request. This may result in a denial of service (router process crash) or possibly have unspecified other impact.... Read more
- EPSS Score: %3.42
- Published: Feb. 08, 2019
- Modified: Aug. 12, 2025
-
8.8
HIGHCVE-2025-2485
The Drag and Drop Multiple File Upload for Contact Form 7 plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.3.8.7 via deserialization of untrusted input from the 'dnd_upload_cf7_upload' function. This mak... Read more
Affected Products : drag_and_drop_multiple_file_upload_-_contact_form_7- Published: Mar. 28, 2025
- Modified: Aug. 12, 2025
- Vuln Type: Authentication
-
9.8
CRITICALCVE-2025-2005
The Front End Users plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the file uploads field of the registration form in all versions up to, and including, 3.2.32. This makes it possible for unauthenticate... Read more
Affected Products : front_end_users- Published: Apr. 02, 2025
- Modified: Aug. 12, 2025
- Vuln Type: Misconfiguration
-
4.9
MEDIUMCVE-2024-12410
The Front End Users plugin for WordPress is vulnerable to SQL Injection via the 'UserSearchField' parameter in all versions up to, and including, 3.2.32 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the ... Read more
Affected Products : front_end_users- Published: Apr. 02, 2025
- Modified: Aug. 12, 2025
- Vuln Type: Injection
-
4.3
MEDIUMCVE-2024-13518
The Simple:Press Forum plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 6.10.11. This is due to missing or incorrect nonce validation on the 'sp_save_edited_post' function. This makes it possible for u... Read more
- Published: Mar. 01, 2025
- Modified: Aug. 12, 2025
- Vuln Type: Cross-Site Request Forgery
-
6.4
MEDIUMCVE-2025-1459
The Page Builder by SiteOrigin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Embedded Video(PB) widget in all versions up to, and including, 2.31.4 due to insufficient input sanitization and output escaping. This makes it possi... Read more
Affected Products : page_builder- Published: Mar. 01, 2025
- Modified: Aug. 12, 2025
- Vuln Type: Cross-Site Scripting
-
4.3
MEDIUMCVE-2024-13526
The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability checks on the export_submittion_attendees function in all versions up to, and including, 4.0.7.3. This mak... Read more
Affected Products : eventprime- Published: Mar. 07, 2025
- Modified: Aug. 12, 2025
- Vuln Type: Authorization
-
6.1
MEDIUMCVE-2024-12409
The Simple:Press Forum plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 's' parameter in all versions up to, and including, 6.10.11 due to insufficient input sanitization and output escaping. This makes it possible for unauthen... Read more
- Published: Jan. 30, 2025
- Modified: Aug. 12, 2025
- Vuln Type: Cross-Site Scripting
-
7.8
HIGHCVE-2023-38114
Foxit PDF Reader AcroForm Doc Object Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulne... Read more
- Published: May. 03, 2024
- Modified: Aug. 12, 2025
-
7.5
HIGHCVE-2025-23333
NVIDIA Triton Inference Server for Windows and Linux contains a vulnerability in the Python backend, where an attacker could cause an out-of-bounds read by manipulating shared memory data. A successful exploit of this vulnerability might lead to informati... Read more
- Published: Aug. 06, 2025
- Modified: Aug. 12, 2025
- Vuln Type: Information Disclosure