Latest CVE Feed
-
5.1
MEDIUMCVE-2025-44039
CP-XR-DE21-S -4G Router Firmware version 1.031.022 was discovered to contain insecure protections for its UART console. This vulnerability allows local attackers to connect to the UART port via a serial connection, read all boot sequence, and revealing in... Read more
- Published: May. 13, 2025
- Modified: Jul. 11, 2025
- Vuln Type: Misconfiguration
-
4.9
MEDIUMCVE-2025-27695
Dell Wyse Management Suite, versions prior to WMS 5.1 contain an Authentication Bypass by Spoofing vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Information Disclosure.... Read more
Affected Products : wyse_management_suite- Published: May. 08, 2025
- Modified: Jul. 11, 2025
- Vuln Type: Authentication
-
7.8
HIGHCVE-2025-2762
CarlinKit CPC200-CCPA Missing Root of Trust Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of CarlinKit CPC200-CCPA devices. An attacker must first obtain the ability to... Read more
- Published: Apr. 23, 2025
- Modified: Jul. 11, 2025
- Vuln Type: Authentication
-
8.8
HIGHCVE-2025-2073
Out-of-Bounds Read in netfilter/ipset in Linux Kernel ChromeOS [6.1, 5.15, 5.10, 5.4, 4.19] allows a local attacker with low privileges to trigger an out-of-bounds read, potentially leading to information disclosure... Read more
- Published: Apr. 16, 2025
- Modified: Jul. 11, 2025
- Vuln Type: Information Disclosure
-
6.8
MEDIUMCVE-2025-2763
CarlinKit CPC200-CCPA Improper Verification of Cryptographic Signature Code Execution Vulnerability. This vulnerability allows physically present attackers to execute arbitrary code on affected installations of CarlinKit CPC200-CCPA devices. Authenticatio... Read more
- Published: Apr. 23, 2025
- Modified: Jul. 11, 2025
- Vuln Type: Cryptography
-
8.0
HIGHCVE-2025-2764
CarlinKit CPC200-CCPA update.cgi Improper Verification of Cryptographic Signature Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of CarlinKit CPC200-CCPA devices. Alth... Read more
- Published: Apr. 23, 2025
- Modified: Jul. 11, 2025
- Vuln Type: Authentication
-
8.8
HIGHCVE-2025-2765
CarlinKit CPC200-CCPA Wireless Hotspot Hard-Coded Credentials Authentication Bypass Vulnerability. This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of CarlinKit CPC200-CCPA devices. Authentication is ... Read more
- Published: Apr. 23, 2025
- Modified: Jul. 11, 2025
- Vuln Type: Authentication
-
6.5
MEDIUMCVE-2024-6479
The SIP Reviews Shortcode for WooCommerce plugin for WordPress is vulnerable to SQL Injection via the 'no_of_reviews' attribute in the woocommerce_reviews shortcode in all versions up to, and including, 1.2.3 due to insufficient escaping on the user suppl... Read more
Affected Products : sip_reviews_shortcode_for_woocommerce- Published: Oct. 31, 2024
- Modified: Jul. 11, 2025
-
6.4
MEDIUMCVE-2024-6480
The SIP Reviews Shortcode for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'no_of_reviews' attribute in the woocommerce_reviews shortcode in all versions up to, and including, 1.2.3 due to insufficient input saniti... Read more
Affected Products : sip_reviews_shortcode_for_woocommerce- Published: Oct. 31, 2024
- Modified: Jul. 11, 2025
-
9.1
CRITICALCVE-2024-28265
IBOS v4.5.5 has an arbitrary file deletion vulnerability via \system\modules\dashboard\controllers\LoginController.php.... Read more
Affected Products : ibos- Published: Nov. 01, 2024
- Modified: Jul. 11, 2025
-
6.1
MEDIUMCVE-2024-48059
gaizhenbiao/chuanhuchatgpt project, version <=20240802 is vulnerable to stored Cross-Site Scripting (XSS) in WebSocket session transmission. An attacker can inject malicious content into a WebSocket message. When a victim accesses this session, the malici... Read more
- Published: Nov. 04, 2024
- Modified: Jul. 11, 2025
-
4.3
MEDIUMCVE-2024-10084
The Contact Form 7 – Dynamic Text Extension plugin for WordPress is vulnerable to Basic Information Disclosure in all versions up to, and including, 4.5 via the CF7_get_post_var shortcode. This makes it possible for authenticated attackers, with Contribut... Read more
- Published: Nov. 05, 2024
- Modified: Jul. 11, 2025
-
7.7
HIGHCVE-2024-40715
A vulnerability in Veeam Backup & Replication Enterprise Manager has been identified, which allows attackers to perform authentication bypass. Attackers must be able to perform Man-in-the-Middle (MITM) attack to exploit this vulnerability.... Read more
- Published: Nov. 07, 2024
- Modified: Jul. 11, 2025
-
6.1
MEDIUMCVE-2024-10683
The Contact Form 7 – PayPal & Stripe Add-on plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg & remove_query_arg without appropriate escaping on the URL in all versions up to, and including, 2.3.1. This m... Read more
Affected Products : paypal_\&_stripe_add-on- Published: Nov. 09, 2024
- Modified: Jul. 11, 2025
-
8.1
HIGHCVE-2025-1290
A race condition Use-After-Free vulnerability exists in the virtio_transport_space_update function within the Kernel 5.4 on ChromeOS. Concurrent allocation and freeing of the virtio_vsock_sock structure during an AF_VSOCK connect syscall can occur before... Read more
- Published: Apr. 17, 2025
- Modified: Jul. 11, 2025
- Vuln Type: Race Condition
-
6.5
MEDIUMCVE-2024-10717
The Styler for Ninja Forms plugin for WordPress is vulnerable to unauthorized modification of data that can lead to a denial of service due to a missing capability check on the deactivate_license function in all versions up to, and including, 3.3.4. This ... Read more
Affected Products : styler_for_ninja_forms- Published: Nov. 13, 2024
- Modified: Jul. 11, 2025
-
9.1
CRITICALCVE-2024-39710
Argument injection in Ivanti Connect Secure before version 22.7R2.1 and 9.1R18.7 and Ivanti Policy Secure before version 22.7R1.1 allows a remote authenticated attacker with admin privileges to achieve remote code execution.... Read more
- Published: Nov. 13, 2024
- Modified: Jul. 11, 2025
-
9.1
CRITICALCVE-2024-39711
Argument injection in Ivanti Connect Secure before version 22.7R2.1 and 9.1R18.7 and Ivanti Policy Secure before version 22.7R1.1 allows a remote authenticated attacker with admin privileges to achieve remote code execution.... Read more
- Published: Nov. 13, 2024
- Modified: Jul. 11, 2025
-
9.1
CRITICALCVE-2024-39712
Argument injection in Ivanti Connect Secure before version 22.7R2.1 and 9.1R18.7 and Ivanti Policy Secure before version 22.7R1.1 allows a remote authenticated attacker with admin privileges to achieve remote code execution.... Read more
- Published: Nov. 13, 2024
- Modified: Jul. 11, 2025
-
6.1
MEDIUMCVE-2024-9614
The Constant Contact Forms by MailMunch plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 2.1.2. This makes it possible for un... Read more
Affected Products : constant_contact_forms- Published: Nov. 13, 2024
- Modified: Jul. 11, 2025