Latest CVE Feed
-
4.3
MEDIUMCVE-2025-2197
Browser is affected by type confusion vulnerability, successful exploitation of this vulnerability may affect service availability.... Read more
Affected Products : baidu- Published: Apr. 17, 2025
- Modified: Jul. 11, 2025
- Vuln Type: Denial of Service
-
7.1
HIGHCVE-2025-32526
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Dylan James Zephyr Project Manager allows Reflected XSS. This issue affects Zephyr Project Manager: from n/a through 3.3.101.... Read more
- Published: Apr. 17, 2025
- Modified: Jul. 11, 2025
- Vuln Type: Cross-Site Scripting
-
7.2
HIGHCVE-2025-4102
The Beaver Builder Plugin (Starter Version) plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'save_enabled_icons' function in all versions up to, and including, 2.9.1. This makes it possible for authe... Read more
Affected Products : beaver_builder- Published: Jun. 20, 2025
- Modified: Jul. 11, 2025
- Vuln Type: Authentication
-
9.8
CRITICALCVE-2024-53298
Dell PowerScale OneFS, versions 9.5.0.0 through 9.10.0.1, contains a missing authorization vulnerability in the NFS export. An unauthenticated attacker with remote access could potentially exploit this vulnerability leading to unauthorized filesystem acce... Read more
- Published: Jun. 20, 2025
- Modified: Jul. 11, 2025
- Vuln Type: Authorization
-
7.8
HIGHCVE-2025-32753
Dell PowerScale OneFS, versions 9.5.0.0 through 9.10.0.1, contains an improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerabil... Read more
- Published: Jun. 20, 2025
- Modified: Jul. 11, 2025
- Vuln Type: Injection
-
5.4
MEDIUMCVE-2025-6347
A vulnerability was found in code-projects Responsive Blog 1.0/1.12.4/3.3.4. It has been declared as problematic. This vulnerability affects unknown code of the file /responsive/resblog/blogadmin/admin/pageViewMembers.php. The manipulation leads to cross ... Read more
Affected Products : responsive_blog_site- Published: Jun. 20, 2025
- Modified: Jul. 11, 2025
- Vuln Type: Cross-Site Scripting
-
5.4
MEDIUMCVE-2025-6353
A vulnerability classified as problematic was found in code-projects Responsive Blog 1.0. Affected by this vulnerability is an unknown functionality of the file /search.php. The manipulation of the argument keyword leads to cross site scripting. The attac... Read more
Affected Products : responsive_blog_site- Published: Jun. 20, 2025
- Modified: Jul. 11, 2025
- Vuln Type: Cross-Site Scripting
-
9.8
CRITICALCVE-2025-6446
A vulnerability, which was classified as critical, has been found in code-projects Client Details System 1.0. This issue affects some unknown processing of the file /clientdetails/admin/index.php. The manipulation of the argument Username leads to sql inj... Read more
Affected Products : client_details_system- Published: Jun. 21, 2025
- Modified: Jul. 11, 2025
- Vuln Type: Injection
-
7.2
HIGHCVE-2025-6484
A vulnerability was found in code-projects Online Shopping Store 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /action.php. The manipulation of the argument cat_id/brand_id/keyword/proId/pid leads to sql ... Read more
Affected Products : online_shopping_store- Published: Jun. 22, 2025
- Modified: Jul. 11, 2025
- Vuln Type: Injection
-
6.5
MEDIUMCVE-2025-5145
A vulnerability, which was classified as critical, was found in Netcore NBR1005GPEV2, B6V2, COVER5, NAP830, NAP930, NBR100V2, NBR200V2 and POWER13 up to 20250508. This affects an unknown part of the file /www/cgi-bin/ of the component Query String Handler... Read more
Affected Products :- Published: May. 25, 2025
- Modified: Jul. 11, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-22952
elestio memos v0.23.0 is vulnerable to Server-Side Request Forgery (SSRF) due to insufficient validation of user-supplied URLs, which can be exploited to perform SSRF attacks.... Read more
Affected Products : memos- Published: Feb. 27, 2025
- Modified: Jul. 10, 2025
- Vuln Type: Server-Side Request Forgery
-
5.4
MEDIUMCVE-2024-57240
A Cross-Site Scripting (XSS) vulnerability in the Rendering Engine component in Apryse WebViewer v11.1 and earlier allows attackers to execute arbitrary code via a crafted PDF file.... Read more
Affected Products : webviewer- Published: Mar. 03, 2025
- Modified: Jul. 10, 2025
- Vuln Type: Cross-Site Scripting
-
8.8
HIGHCVE-2024-37479
Local File Inclusion vulnerability in LA-Studio LA-Studio Element Kit for Elementor via "LaStudioKit Progress Bar" widget in New Post, specifically in the "progress_type" attribute.This issue affects LA-Studio Element Kit for Elementor: from n/a through 1... Read more
Affected Products : element_kit_for_elementor- Published: Jul. 02, 2024
- Modified: Jul. 10, 2025
-
7.5
HIGHCVE-2024-53450
RAGFlow 0.13.0 suffers from improper access control in document-hooks.ts, allowing unauthorized access to user documents.... Read more
Affected Products : ragflow- Published: Dec. 09, 2024
- Modified: Jul. 10, 2025
-
9.1
CRITICALCVE-2024-5926
A path traversal vulnerability in the get-project-files functionality of stitionai/devika allows attackers to read arbitrary files from the filesystem and cause a Denial of Service (DoS). This issue is present in all versions of the application. The vulne... Read more
Affected Products : devika- Published: Jun. 30, 2024
- Modified: Jul. 10, 2025
-
9.8
CRITICALCVE-2024-38993
rjrodger jsonic-next v2.12.1 was discovered to contain a prototype pollution via the function empty. This vulnerability allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via injecting arbitrary properties.... Read more
Affected Products : jsonic- Published: Jul. 01, 2024
- Modified: Jul. 10, 2025
-
6.5
MEDIUMCVE-2024-39853
adolph_dudu ratio-swiper 0.0.2 was discovered to contain a prototype pollution via the function parse. This vulnerability allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via injecting arbitrary properties.... Read more
Affected Products : swiper- Published: Jul. 01, 2024
- Modified: Jul. 10, 2025
-
5.4
MEDIUMCVE-2024-39929
Exim through 4.97.1 misparses a multiline RFC 2231 header filename, and thus remote attackers can bypass a $mime_filename extension-blocking protection mechanism, and potentially deliver executable attachments to the mailboxes of end users.... Read more
Affected Products : exim- Published: Jul. 04, 2024
- Modified: Jul. 10, 2025
-
5.4
MEDIUMCVE-2024-36387
Serving WebSocket protocol upgrades over a HTTP/2 connection could result in a Null Pointer dereference, leading to a crash of the server process, degrading performance.... Read more
- Published: Jul. 01, 2024
- Modified: Jul. 10, 2025
-
8.8
HIGHCVE-2024-6353
The Wallet for WooCommerce plugin for WordPress is vulnerable to SQL Injection via the 'search[value]' parameter in all versions up to, and including, 1.5.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on ... Read more
Affected Products : terawallet- Published: Jul. 12, 2024
- Modified: Jul. 10, 2025