Latest CVE Feed
-
8.8
HIGHCVE-2025-48142
Incorrect Privilege Assignment vulnerability in Saad Iqbal Bookify allows Privilege Escalation. This issue affects Bookify: from n/a through 1.0.9.... Read more
Affected Products :- Published: Aug. 20, 2025
- Modified: Aug. 20, 2025
- Vuln Type: Authorization
-
8.6
HIGHCVE-2025-48158
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Alex Githatu BuddyPress XProfile Custom Image Field allows Path Traversal. This issue affects BuddyPress XProfile Custom Image Field: from n/a through 3.0.1.... Read more
Affected Products :- Published: Aug. 20, 2025
- Modified: Aug. 20, 2025
- Vuln Type: Path Traversal
-
6.6
MEDIUMCVE-2025-54053
Deserialization of Untrusted Data vulnerability in Adrian Tobey Groundhogg allows Object Injection. This issue affects Groundhogg: from n/a through 4.2.2.... Read more
Affected Products : groundhogg- Published: Aug. 20, 2025
- Modified: Aug. 20, 2025
- Vuln Type: Injection
-
7.2
HIGHCVE-2025-54012
Deserialization of Untrusted Data vulnerability in nanbu Welcart e-Commerce allows Object Injection. This issue affects Welcart e-Commerce: from n/a through 2.11.16.... Read more
Affected Products : welcart_e-commerce- Published: Aug. 20, 2025
- Modified: Aug. 20, 2025
- Vuln Type: Injection
-
6.5
MEDIUMCVE-2025-53992
Insertion of Sensitive Information Into Sent Data vulnerability in Crocoblock JetTricks allows Retrieve Embedded Sensitive Data. This issue affects JetTricks: from n/a through 1.5.4.1.... Read more
Affected Products :- Published: Aug. 20, 2025
- Modified: Aug. 20, 2025
- Vuln Type: Information Disclosure
-
6.5
MEDIUMCVE-2025-54040
Missing Authorization vulnerability in Webba Appointment Booking Webba Booking allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Webba Booking: from n/a through 5.1.20.... Read more
Affected Products : webba_booking- Published: Aug. 20, 2025
- Modified: Aug. 20, 2025
- Vuln Type: Authorization
-
6.5
MEDIUMCVE-2025-54025
Missing Authorization vulnerability in Elliot Sowersby / RelyWP Coupon Affiliates allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Coupon Affiliates: from n/a through 6.4.0.... Read more
Affected Products : coupon_affiliates- Published: Aug. 20, 2025
- Modified: Aug. 20, 2025
- Vuln Type: Authorization
-
10.0
CRITICALCVE-2025-53577
Improper Control of Generation of Code ('Code Injection') vulnerability in thehp Global DNS allows Remote Code Inclusion. This issue affects Global DNS: from n/a through 3.1.0.... Read more
Affected Products :- Published: Aug. 20, 2025
- Modified: Aug. 20, 2025
-
5.9
MEDIUMCVE-2025-49890
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jorge Garcia de Bustos AWStats Script allows Stored XSS. This issue affects AWStats Script: from n/a through 0.3.... Read more
Affected Products :- Published: Aug. 20, 2025
- Modified: Aug. 20, 2025
- Vuln Type: Cross-Site Scripting
-
9.9
CRITICALCVE-2025-54049
Incorrect Privilege Assignment vulnerability in miniOrange Custom API for WP allows Privilege Escalation. This issue affects Custom API for WP: from n/a through 4.2.2.... Read more
Affected Products :- Published: Aug. 20, 2025
- Modified: Aug. 20, 2025
- Vuln Type: Authorization
-
6.5
MEDIUMCVE-2025-9173
A weakness has been identified in Emlog Pro up to 2.5.18. This issue affects some unknown processing of the file /admin/media.php?action=upload&sid=0. Executing manipulation of the argument File can lead to unrestricted upload. The attack may be launched ... Read more
Affected Products : emlog- Published: Aug. 20, 2025
- Modified: Aug. 20, 2025
- Vuln Type: Misconfiguration
-
5.3
MEDIUMCVE-2025-9229
Information disclosure vulnerability in error handling in MiR software prior to version 3.0.0 allows unauthenticated attackers to view detailed error information, such as file paths and other data, via access to verbose error pages.... Read more
Affected Products :- Published: Aug. 20, 2025
- Modified: Aug. 20, 2025
- Vuln Type: Information Disclosure
-
7.5
HIGHCVE-2025-54925
CWE-918: Server-Side Request Forgery (SSRF) vulnerability exists that could cause unauthorized access to sensitive data when an attacker configures the application to access a malicious url.... Read more
Affected Products : ecostruxure_power_monitoring_expert- Published: Aug. 20, 2025
- Modified: Aug. 20, 2025
- Vuln Type: Server-Side Request Forgery
-
7.2
HIGHCVE-2025-54926
CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists that could cause remote code execution when an authenticated attacker with admin privileges uploads a malicious file over HTTP which then gets exec... Read more
Affected Products : ecostruxure_power_monitoring_expert- Published: Aug. 20, 2025
- Modified: Aug. 20, 2025
- Vuln Type: Path Traversal
-
9.3
CRITICALCVE-2025-54726
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Miguel Useche JS Archive List allows SQL Injection. This issue affects JS Archive List: from n/a through n/a.... Read more
Affected Products :- Published: Aug. 20, 2025
- Modified: Aug. 20, 2025
- Vuln Type: Injection
-
4.9
MEDIUMCVE-2025-54927
CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists that could cause unauthorized access to sensitive files when an authenticated attackers uses a crafted path input that is processed by the system.... Read more
Affected Products : ecostruxure_power_monitoring_expert- Published: Aug. 20, 2025
- Modified: Aug. 20, 2025
- Vuln Type: Path Traversal
-
9.1
CRITICALCVE-2025-54677
Unrestricted Upload of File with Dangerous Type vulnerability in vcita Online Booking & Scheduling Calendar for WordPress by vcita allows Using Malicious Files. This issue affects Online Booking & Scheduling Calendar for WordPress by vcita: from n/a throu... Read more
Affected Products : online_booking_\&_scheduling_calendar_for_wordpress_by_vcita- Published: Aug. 20, 2025
- Modified: Aug. 20, 2025
- Vuln Type: Misconfiguration
-
8.1
HIGHCVE-2025-54031
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Schiocco Support Board allows PHP Local File Inclusion. This issue affects Support Board: from n/a through 3.8.0.... Read more
Affected Products : support_board- Published: Aug. 20, 2025
- Modified: Aug. 20, 2025
- Vuln Type: Path Traversal
-
7.5
HIGHCVE-2025-54017
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Cozmoslabs Paid Member Subscriptions allows PHP Local File Inclusion. This issue affects Paid Member Subscriptions: from n/a through 2... Read more
Affected Products : paid_membership_subscriptions- Published: Aug. 20, 2025
- Modified: Aug. 20, 2025
- Vuln Type: Path Traversal
-
7.5
HIGHCVE-2025-54052
Cross-Site Request Forgery (CSRF) vulnerability in Realtyna Realtyna Organic IDX plugin allows PHP Local File Inclusion. This issue affects Realtyna Organic IDX plugin: from n/a through 5.0.0.... Read more
Affected Products :- Published: Aug. 20, 2025
- Modified: Aug. 20, 2025
- Vuln Type: Cross-Site Request Forgery