Latest CVE Feed
-
5.3
MEDIUMCVE-2025-48473
FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.179, when creating a conversation from a message in another conversation, there is no check to ensure that the user has the ability to view this message. Thus, the user can... Read more
Affected Products : freescout- Published: May. 29, 2025
- Modified: Jul. 11, 2025
- Vuln Type: Authorization
-
8.6
HIGHCVE-2025-48390
FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.178, FreeScout is vulnerable to code injection due to insufficient validation of user input in the php_path parameter. The backticks characters are not removed, as well as ... Read more
Affected Products : freescout- Published: May. 29, 2025
- Modified: Jul. 11, 2025
- Vuln Type: Injection
-
8.6
HIGHCVE-2025-48389
FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.178, FreeScout is vulnerable to deserialization of untrusted data due to insufficient validation. Through the set function, a string with a serialized object can be passed,... Read more
Affected Products : freescout- Published: May. 29, 2025
- Modified: Jul. 11, 2025
- Vuln Type: Misconfiguration
-
6.8
MEDIUMCVE-2025-36578
Dell Wyse Management Suite, versions prior to WMS 5.2, contain an Incorrect Authorization vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Unauthorized access.... Read more
Affected Products : wyse_management_suite- Published: Jun. 10, 2025
- Modified: Jul. 11, 2025
- Vuln Type: Authorization
-
6.1
MEDIUMCVE-2025-36577
Dell Wyse Management Suite, versions prior to WMS 5.2, contain an Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerabilit... Read more
Affected Products : wyse_management_suite- Published: Jun. 10, 2025
- Modified: Jul. 11, 2025
- Vuln Type: Cross-Site Scripting
-
2.7
LOWCVE-2025-36576
Dell Wyse Management Suite, versions prior to WMS 5.2, contain a Cross-Site Request Forgery (CSRF) vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Server-side request forgery.... Read more
Affected Products : wyse_management_suite- Published: Jun. 10, 2025
- Modified: Jul. 11, 2025
- Vuln Type: Cross-Site Request Forgery
-
7.5
HIGHCVE-2025-36575
Dell Wyse Management Suite, versions prior to WMS 5.2, contain an Exposure of Sensitive Information Through Data Queries vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Information dis... Read more
Affected Products : wyse_management_suite- Published: Jun. 10, 2025
- Modified: Jul. 11, 2025
- Vuln Type: Information Disclosure
-
8.2
HIGHCVE-2025-36574
Dell Wyse Management Suite, versions prior to WMS 5.2, contain an Absolute Path Traversal vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Information disclosure and Unauthorized access... Read more
Affected Products : wyse_management_suite- Published: Jun. 10, 2025
- Modified: Jul. 11, 2025
- Vuln Type: Path Traversal
-
4.3
MEDIUMCVE-2023-6980
The WP SMS – Messaging & SMS Notification for WordPress, WooCommerce, GravityForms, etc plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 6.5. This is due to missing or incorrect nonce validation on the... Read more
Affected Products : wp_sms- EPSS Score: %0.09
- Published: Jan. 03, 2024
- Modified: Jul. 11, 2025
-
7.0
HIGHCVE-2025-48388
FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.178, the application performs insufficient validation of user-supplied data, which is used as arguments to string formatting functions. As a result, an attacker can pass a ... Read more
Affected Products : freescout- Published: May. 29, 2025
- Modified: Jul. 11, 2025
- Vuln Type: Injection
-
8.6
HIGHCVE-2025-20152
A vulnerability in the RADIUS message processing feature of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper h... Read more
Affected Products : identity_services_engine- Published: May. 21, 2025
- Modified: Jul. 11, 2025
- Vuln Type: Denial of Service
-
9.1
CRITICALCVE-2025-20242
A vulnerability in the Cloud Connect component of Cisco Unified Contact Center Enterprise (CCE) could allow an unauthenticated, remote attacker to read and modify data on an affected device. This vulnerability is due to a lack of proper authentication ... Read more
Affected Products : unified_contact_center_enterprise- Published: May. 21, 2025
- Modified: Jul. 11, 2025
- Vuln Type: Authentication
-
5.4
MEDIUMCVE-2024-12120
The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Countdown widget display_message_text parameter in all versions up to, and including, 1.7.1017 due to insufficient input sanitization and ou... Read more
Affected Products : royal_elementor_addons- Published: May. 07, 2025
- Modified: Jul. 11, 2025
- Vuln Type: Cross-Site Scripting
-
6.5
MEDIUMCVE-2025-39361
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WProyal Royal Elementor Addons allows Stored XSS.This issue affects Royal Elementor Addons: from n/a through 1.7.1017.... Read more
Affected Products : royal_elementor_addons- Published: May. 07, 2025
- Modified: Jul. 11, 2025
- Vuln Type: Cross-Site Scripting
-
9.8
CRITICALCVE-2025-4456
A vulnerability classified as critical has been found in Project Worlds Car Rental Project 1.0. Affected is an unknown function of the file /signup.php. The manipulation of the argument fname leads to sql injection. It is possible to launch the attack rem... Read more
Affected Products : car_rental_project- Published: May. 09, 2025
- Modified: Jul. 11, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-4457
A vulnerability classified as critical was found in Project Worlds Car Rental Project 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/approve.php. The manipulation of the argument ID leads to sql injection. The attack ca... Read more
Affected Products : car_rental_project- Published: May. 09, 2025
- Modified: Jul. 11, 2025
- Vuln Type: Injection
-
8.6
HIGHCVE-2025-20162
A vulnerability in the DHCP snooping security feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a full interface queue wedge, which could result in a denial of service (DoS) condition. This vulnerability is due t... Read more
Affected Products : ios_xe- Published: May. 07, 2025
- Modified: Jul. 11, 2025
- Vuln Type: Denial of Service
-
8.8
HIGHCVE-2025-20186
A vulnerability in the web-based management interface of the Wireless LAN Controller feature of Cisco IOS XE Software could allow an authenticated, remote attacker with a lobby ambassador user account to perform a command injection attack against an affec... Read more
Affected Products : ios_xe- Published: May. 07, 2025
- Modified: Jul. 11, 2025
- Vuln Type: Injection
-
6.5
MEDIUMCVE-2025-20193
A vulnerability in the web-based management interface of Cisco IOS XE Software could allow an authenticated, low-privileged, remote attacker to perform an injection attack against an affected device.r This vulnerability is due to insufficient input vali... Read more
Affected Products : ios_xe- Published: May. 07, 2025
- Modified: Jul. 11, 2025
- Vuln Type: Injection
-
5.4
MEDIUMCVE-2025-20194
A vulnerability in the web-based management interface of Cisco IOS XE Software could allow an authenticated, low-privileged, remote attacker to perform an injection attack against an affected device. This vulnerability is due to insufficient input val... Read more
Affected Products : ios_xe- Published: May. 07, 2025
- Modified: Jul. 11, 2025
- Vuln Type: Injection