Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 9.8

    CRITICAL
    CVE-2025-6843

    A vulnerability was found in code-projects Simple Photo Gallery 1.0. It has been classified as critical. Affected is an unknown function of the file /upload-photo.php. The manipulation of the argument file_img leads to unrestricted upload. It is possible ... Read more

    • Published: Jun. 29, 2025
    • Modified: Jul. 10, 2025
    • Vuln Type: Misconfiguration
  • 6.4

    MEDIUM
    CVE-2025-5123

    The Contact Us Page – Contact People plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘style’ parameter in all versions up to, and including, 3.7.4 due to insufficient input sanitization and output escaping. This makes it possible... Read more

    Affected Products : contact_us_page_-_contact_people
    • Published: Jun. 13, 2025
    • Modified: Jul. 10, 2025
    • Vuln Type: Cross-Site Scripting
  • 5.3

    MEDIUM
    CVE-2025-5938

    The Digital Marketing and Agency Templates Addons for Elementor plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1.1. This is due to missing or incorrect nonce validation on the import_templates() fu... Read more

    • Published: Jun. 13, 2025
    • Modified: Jul. 10, 2025
    • Vuln Type: Cross-Site Request Forgery
  • 6.4

    MEDIUM
    CVE-2025-5950

    The IndieBlocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘kind’ parameter in all versions up to, and including, 0.13.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated at... Read more

    Affected Products : indieblocks
    • Published: Jun. 13, 2025
    • Modified: Jul. 10, 2025
    • Vuln Type: Cross-Site Scripting
  • 7.5

    HIGH
    CVE-2025-5282

    The WP Travel Engine – Tour Booking Plugin – Tour Operator Software plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the delete_package() function in all versions up to, and including, 6.5.1. This makes ... Read more

    Affected Products : wp_travel_engine
    • Published: Jun. 13, 2025
    • Modified: Jul. 10, 2025
    • Vuln Type: Authorization
  • 9.6

    CRITICAL
    CVE-2024-38824

    Directory traversal vulnerability in recv_file method allows arbitrary files to be written to the master cache directory.... Read more

    Affected Products : salt
    • Published: Jun. 13, 2025
    • Modified: Jul. 10, 2025
    • Vuln Type: Path Traversal
  • 8.8

    HIGH
    CVE-2025-4315

    The CubeWP – All-in-One Dynamic Content Framework plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.1.23. This is due to the plugin allowing a user to update arbitrary user meta through the update_user_meta... Read more

    Affected Products : cubewp
    • Published: Jun. 11, 2025
    • Modified: Jul. 10, 2025
    • Vuln Type: Authorization
  • 6.4

    MEDIUM
    CVE-2025-5144

    The The Events Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘data-date-*’ parameters in all versions up to, and including, 6.13.2 due to insufficient input sanitization and output escaping. This makes it possible for ... Read more

    Affected Products : the_events_calendar
    • Published: Jun. 11, 2025
    • Modified: Jul. 10, 2025
    • Vuln Type: Cross-Site Scripting
  • 9.8

    CRITICAL
    CVE-2025-4973

    The Workreap plugin for WordPress, used by the Workreap - Freelance Marketplace WordPress Theme, is vulnerable to authentication bypass in all versions up to, and including, 3.3.1. This is due to the plugin not properly verifying a user's identity prior t... Read more

    Affected Products : workreap
    • Published: Jun. 12, 2025
    • Modified: Jul. 10, 2025
    • Vuln Type: Authentication
  • 8.8

    HIGH
    CVE-2025-5012

    The Workreap plugin for WordPress, used by the Workreap - Freelance Marketplace WordPress Theme, is vulnerable to arbitrary file uploads due to missing file type validation in the 'workreap_temp_upload_to_media' function in all versions up to, and includi... Read more

    Affected Products : workreap
    • Published: Jun. 12, 2025
    • Modified: Jul. 10, 2025
    • Vuln Type: Authentication
  • 6.4

    MEDIUM
    CVE-2025-4479

    The ElementsKit Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin image comparison widget's before/after labels in all versions up to, and including, 3.5.2 due to insufficient input sanitizatio... Read more

    Affected Products : elementskit_elementor_addons
    • Published: Jun. 19, 2025
    • Modified: Jul. 10, 2025
    • Vuln Type: Cross-Site Scripting
  • 5.4

    MEDIUM
    CVE-2025-4571

    The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to unauthorized view and modification of data due to an insufficient capability check on the permissionsCheck functions in all versions up to, and including, 4.3.0. T... Read more

    Affected Products : givewp
    • Published: Jun. 19, 2025
    • Modified: Jul. 10, 2025
    • Vuln Type: Authorization
  • 6.4

    MEDIUM
    CVE-2025-4965

    The WPBakery Page Builder for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Grid Builder feature in all versions up to, and including, 8.4.1 due to insufficient input sanitization and output escaping on user ... Read more

    Affected Products : page_builder
    • Published: Jun. 19, 2025
    • Modified: Jul. 10, 2025
    • Vuln Type: Cross-Site Scripting
  • 9.8

    CRITICAL
    CVE-2025-6280

    A vulnerability, which was classified as critical, was found in TransformerOptimus SuperAGI up to 0.0.14. Affected is the function download_attachment of the file SuperAGI/superagi/helper/read_email.py of the component EmailToolKit. The manipulation of th... Read more

    Affected Products : superagi
    • Published: Jun. 19, 2025
    • Modified: Jul. 09, 2025
    • Vuln Type: Path Traversal
  • 9.4

    CRITICAL
    CVE-2025-49596

    The MCP inspector is a developer tool for testing and debugging MCP servers. Versions of MCP Inspector below 0.14.1 are vulnerable to remote code execution due to lack of authentication between the Inspector client and proxy, allowing unauthenticated requ... Read more

    Affected Products :
    • Published: Jun. 13, 2025
    • Modified: Jul. 09, 2025
    • Vuln Type: Authentication
  • 4.9

    MEDIUM
    CVE-2025-3295

    The WP Editor plugin for WordPress is vulnerable to arbitrary file read in all versions up to, and including, 1.2.9.1. This makes it possible for authenticated attackers, with Administrator-level access and above, to read arbitrary files on the affected s... Read more

    Affected Products : wp_editor
    • Published: Apr. 17, 2025
    • Modified: Jul. 09, 2025
    • Vuln Type: Information Disclosure
  • 7.2

    HIGH
    CVE-2025-3294

    The WP Editor plugin for WordPress is vulnerable to arbitrary file update due to missing file path validation in all versions up to, and including, 1.2.9.1. This makes it possible for authenticated attackers, with Administrator-level access and above, to ... Read more

    Affected Products : wp_editor
    • Published: Apr. 17, 2025
    • Modified: Jul. 09, 2025
    • Vuln Type: Path Traversal
  • 9.9

    CRITICAL
    CVE-2024-3025

    mintplex-labs/anything-llm is vulnerable to path traversal attacks due to insufficient validation of user-supplied input in the logo filename functionality. Attackers can exploit this vulnerability by manipulating the logo filename to reference files outs... Read more

    Affected Products : anythingllm
    • Published: Apr. 10, 2024
    • Modified: Jul. 09, 2025
  • 7.2

    HIGH
    CVE-2024-3101

    In mintplex-labs/anything-llm, an improper input validation vulnerability allows attackers to escalate privileges by deactivating 'Multi-User Mode'. By sending a specially crafted curl request with the 'multi_user_mode' parameter set to false, an attacker... Read more

    Affected Products : anythingllm
    • Published: Apr. 10, 2024
    • Modified: Jul. 09, 2025
  • 7.2

    HIGH
    CVE-2024-3283

    A vulnerability in mintplex-labs/anything-llm allows users with manager roles to escalate their privileges to admin roles through a mass assignment issue. The '/admin/system-preferences' API endpoint improperly authorizes manager-level users to modify the... Read more

    Affected Products : anythingllm
    • Published: Apr. 10, 2024
    • Modified: Jul. 09, 2025
Showing 20 of 291794 Results