Latest CVE Feed
-
6.1
MEDIUMCVE-2024-34831
cross-site scripting (XSS) vulnerability in Gibbon Core v26.0.00 allows an attacker to execute arbitrary code via the imageLink parameter in the library_manage_catalog_editProcess.php component.... Read more
Affected Products : gibbon- Published: Sep. 10, 2024
- Modified: Jul. 17, 2025
-
7.8
HIGHCVE-2024-31890
IBM i 7.3, 7.4, and 7.5 product IBM TCP/IP Connectivity Utilities for i contains a local privilege escalation vulnerability. A malicious actor with command line access to the host operating system can elevate privileges to gain root access to the host ope... Read more
- Published: Jun. 21, 2024
- Modified: Jul. 17, 2025
-
7.5
HIGHCVE-2024-3403
imartinez/privategpt version 0.2.0 is vulnerable to a local file inclusion vulnerability that allows attackers to read arbitrary files from the filesystem. By manipulating file upload functionality to ingest arbitrary local files, attackers can exploit th... Read more
- Published: May. 16, 2024
- Modified: Jul. 17, 2025
-
5.5
MEDIUMCVE-2024-20870
Improper verification of intent by broadcast receiver vulnerability in Galaxy Store prior to version 4.5.71.8 allows local attackers to write arbitrary files with the privilege of Galaxy Store.... Read more
Affected Products : galaxy_store- Published: May. 07, 2024
- Modified: Jul. 17, 2025
-
5.5
MEDIUMCVE-2024-20869
Improper privilege management vulnerability in Samsung Internet prior to version 25.0.0.41 allows local attackers to bypass protection for cookies.... Read more
Affected Products : internet- Published: May. 07, 2024
- Modified: Jul. 17, 2025
-
6.4
MEDIUMCVE-2024-12504
The Broadcast Live Video – Live Streaming : HTML5, WebRTC, HLS, RTSP, RTMP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'videowhisper_hls' shortcode in all versions up to, and including, 6.1.9 due to insufficient inpu... Read more
- Published: Jan. 23, 2025
- Modified: Jul. 17, 2025
- Vuln Type: Cross-Site Scripting
-
8.8
HIGHCVE-2025-48255
Cross-Site Request Forgery (CSRF) vulnerability in videowhisper Broadcast Live Video – Live Streaming : WebRTC, HLS, RTSP, RTMP allows Cross Site Request Forgery. This issue affects Broadcast Live Video – Live Streaming : WebRTC, HLS, RTSP, RTMP: from n/a... Read more
- Published: May. 19, 2025
- Modified: Jul. 17, 2025
- Vuln Type: Cross-Site Request Forgery
-
8.1
HIGHCVE-2025-3555
A vulnerability classified as problematic has been found in ScriptAndTools eCommerce-website-in-PHP 3.0. Affected is an unknown function of the file /login.php. The manipulation leads to improper restriction of excessive authentication attempts. It is pos... Read more
Affected Products : ecommerce-website-in-php- Published: Apr. 14, 2025
- Modified: Jul. 17, 2025
- Vuln Type: Authentication
-
8.1
HIGHCVE-2025-3556
A vulnerability classified as problematic was found in ScriptAndTools eCommerce-website-in-PHP 3.0. Affected by this vulnerability is an unknown functionality of the file /admin/login.php. The manipulation leads to improper restriction of excessive authen... Read more
Affected Products : ecommerce-website-in-php- Published: Apr. 14, 2025
- Modified: Jul. 17, 2025
- Vuln Type: Authentication
-
6.5
MEDIUMCVE-2025-48253
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPFactory Free Shipping Bar: Amount Left for Free Shipping for WooCommerce allows Stored XSS. This issue affects Free Shipping Bar: Amount Left for Free ... Read more
- Published: May. 19, 2025
- Modified: Jul. 17, 2025
- Vuln Type: Cross-Site Scripting
-
5.3
MEDIUMCVE-2025-3557
A vulnerability, which was classified as problematic, has been found in ScriptAndTools eCommerce-website-in-PHP 3.0. Affected by this issue is some unknown functionality. The manipulation leads to cross-site request forgery. The attack may be launched rem... Read more
Affected Products : ecommerce-website-in-php- Published: Apr. 14, 2025
- Modified: Jul. 17, 2025
- Vuln Type: Cross-Site Request Forgery
-
5.4
MEDIUMCVE-2022-43847
IBM Aspera Console 3.4.0 through 3.4.4 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers. This could allow an attacker to conduct various attacks against the vulnerable system, including cross-site script... Read more
- Published: Apr. 14, 2025
- Modified: Jul. 17, 2025
- Vuln Type: Misconfiguration
-
5.4
MEDIUMCVE-2022-43850
IBM Aspera Console 3.4.0 through 3.4.4 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a... Read more
- Published: Apr. 14, 2025
- Modified: Jul. 17, 2025
- Vuln Type: Cross-Site Scripting
-
7.5
HIGHCVE-2022-43851
IBM Aspera Console 3.4.0 through 3.4.4 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information.... Read more
- Published: Apr. 14, 2025
- Modified: Jul. 17, 2025
- Vuln Type: Cryptography
-
5.3
MEDIUMCVE-2022-43852
IBM Aspera Console 3.4.0 through 3.4.4 could disclose sensitive information in HTTP headers that could be used in further attacks against the system.... Read more
- Published: Apr. 14, 2025
- Modified: Jul. 17, 2025
- Vuln Type: Information Disclosure
-
8.8
HIGHCVE-2023-27272
IBM Aspera Console 3.4.0 through 3.4.4 allows passwords to be reused when a new user logs into the system.... Read more
- Published: Apr. 14, 2025
- Modified: Jul. 17, 2025
- Vuln Type: Authentication
-
7.2
HIGHCVE-2025-39565
Deserialization of Untrusted Data vulnerability in Melapress MelaPress Login Security allows Object Injection. This issue affects MelaPress Login Security: from n/a through 2.1.0.... Read more
Affected Products : melapress_login_security- Published: Apr. 16, 2025
- Modified: Jul. 17, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-2947
IBM i 7.6 contains a privilege escalation vulnerability due to incorrect profile swapping in an OS command. A malicious actor can use the command to elevate privileges to gain root access to the host operating system.... Read more
- Published: Apr. 17, 2025
- Modified: Jul. 17, 2025
- Vuln Type: Authorization
-
7.1
HIGHCVE-2025-30844
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Bob Watu Quiz allows Reflected XSS. This issue affects Watu Quiz: from n/a through 3.4.2.... Read more
Affected Products : watu_quiz- Published: Apr. 01, 2025
- Modified: Jul. 17, 2025
- Vuln Type: Cross-Site Scripting
-
8.8
HIGHCVE-2025-22923
An issue in OS4ED openSIS v8.0 through v9.1 allows attackers to execute a directory traversal and delete files by sending a crafted POST request to /Modules.php?modname=users/Staff.php&removefile.... Read more
Affected Products : opensis- Published: Apr. 02, 2025
- Modified: Jul. 17, 2025
- Vuln Type: Path Traversal