Latest CVE Feed
-
0.0
NONECVE-2025-48489
FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.180, the application is vulnerable to Cross-Site Scripting (XSS) attacks due to insufficient data validation and sanitization during data reception. This issue has been pat... Read more
Affected Products :- Published: May. 30, 2025
- Modified: May. 30, 2025
-
9.1
CVSS31CVE-2025-48865
Fabio is an HTTP(S) and TCP router for deploying applications managed by consul. Prior to version 1.6.6, Fabio allows clients to remove X-Forwarded headers (except X-Forwarded-For) due to a vulnerability in how it processes hop-by-hop headers. Fabio adds ... Read more
Affected Products :- Published: May. 30, 2025
- Modified: May. 30, 2025
-
8.1
CVSS31CVE-2025-48936
Zitadel is open-source identity infrastructure software. Prior to versions 2.70.12, 2.71.10, and 3.2.2, a potential vulnerability exists in the password reset mechanism. ZITADEL utilizes the Forwarded or X-Forwarded-Host header from incoming requests to c... Read more
Affected Products : zitadel- Published: May. 30, 2025
- Modified: May. 30, 2025
-
6.4
CVSS31CVE-2025-4943
The LA-Studio Element Kit for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘data-lakit-element-link’ parameter in all versions up to, and including, 1.5.2 due to insufficient input sanitization and output escaping. T... Read more
Affected Products : element_kit_for_elementor- Published: May. 30, 2025
- Modified: May. 30, 2025
-
6.4
CVSS31CVE-2025-5236
The NinjaTeam Chat for Telegram plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘username’ parameter in all versions up to, and including, 1.1 due to insufficient input sanitization and output escaping. This makes it possible for... Read more
Affected Products :- Published: May. 30, 2025
- Modified: May. 30, 2025
-
6.5
CVSS31CVE-2025-48334
Missing Authorization vulnerability in BinaryCarpenter Woo Slider Pro allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Woo Slider Pro: from n/a through 1.12. Affected action "woo_slide_pro_delete_slider".... Read more
Affected Products :- Published: May. 30, 2025
- Modified: May. 30, 2025
-
6.5
CVSS31CVE-2025-5142
The Simple Page Access Restriction plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.31. This is due to missing nonce validation and capability checks in the settings save handler in the settings.ph... Read more
Affected Products : simple_page_access_restriction- Published: May. 30, 2025
- Modified: May. 30, 2025
-
6.4
CVSS31CVE-2025-5235
The OpenSheetMusicDisplay plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘className’ parameter in all versions up to, and including, 1.4.0 due to insufficient input sanitization and output escaping. This makes it possible for au... Read more
Affected Products :- Published: May. 30, 2025
- Modified: May. 30, 2025
-
6.5
CVSS31CVE-2025-4597
The Woo Slider Pro – Drag Drop Slider Builder For WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the woo_slide_pro_delete_draft_preview AJAX action in all versions up to, and includ... Read more
Affected Products :- Published: May. 30, 2025
- Modified: May. 30, 2025
-
6.4
CVSS31CVE-2025-4944
The LA-Studio Element Kit for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Image Compare and Google Maps widgets in all versions up to, and including, 1.5.2 due to insufficient input sanitization and output ... Read more
Affected Products : element_kit_for_elementor- Published: May. 30, 2025
- Modified: May. 30, 2025
-
8.8
CVSS31CVE-2025-5190
The Browse As plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 0.2. This is due to incorrect authentication checking in the 'IS_BA_Browse_As::notice' function with the 'is_ba_original_user_COOKIEHASH' cookie va... Read more
Affected Products :- Published: May. 30, 2025
- Modified: May. 30, 2025
-
6.5
CVSS31CVE-2025-1484
A vulnerability exists in the media upload component of the Asset Suite versions listed below. If successfully exploited an attacker could impact the confidentiality or integrity of the system. An attacker can use this vulnerability to construct a reque... Read more
Affected Products :- Published: May. 30, 2025
- Modified: May. 30, 2025
-
7.5
CVSS31CVE-2025-48331
Insertion of Sensitive Information Into Sent Data vulnerability in Vanquish WooCommerce Orders & Customers Exporter allows Retrieve Embedded Sensitive Data.This issue affects WooCommerce Orders & Customers Exporter: from n/a through 5.0.... Read more
Affected Products :- Published: May. 30, 2025
- Modified: May. 30, 2025
-
4.2
CVSS31CVE-2025-2571
Mattermost versions 10.7.x <= 10.7.0, 10.6.x <= 10.6.2, 10.5.x <= 10.5.3, 9.11.x <= 9.11.12 fail to clear Google OAuth credentials when converting user accounts to bot accounts, allowing attackers to gain unauthorized access to bot accounts via the Google... Read more
Affected Products : mattermost_server- Published: May. 30, 2025
- Modified: May. 30, 2025
-
8.7
CVSS31CVE-2025-4983
A stored Cross-site Scripting (XSS) vulnerability affecting City Referential in City Referential Manager on Release 3DEXPERIENCE R2025x allows an attacker to execute arbitrary script code in user's browser session.... Read more
Affected Products :- Published: May. 30, 2025
- Modified: May. 30, 2025
-
8.7
CVSS31CVE-2025-4989
A stored Cross-site Scripting (XSS) vulnerability affecting Requirements in Product Manager from Release 3DEXPERIENCE R2022x through Release 3DEXPERIENCE R2025x allows an attacker to execute arbitrary script code in user's browser session.... Read more
Affected Products :- Published: May. 30, 2025
- Modified: May. 30, 2025
-
8.7
CVSS31CVE-2025-4990
A stored Cross-site Scripting (XSS) vulnerability affecting Change Governance in Product Manager from Release 3DEXPERIENCE R2022x through Release 3DEXPERIENCE R2025x allows an attacker to execute arbitrary script code in user's browser session.... Read more
Affected Products :- Published: May. 30, 2025
- Modified: May. 30, 2025
-
8.7
CVSS31CVE-2025-4991
A stored Cross-site Scripting (XSS) vulnerability affecting 3D Markup in Collaborative Industry Innovator from Release 3DEXPERIENCE R2022x through Release 3DEXPERIENCE R2025x allows an attacker to execute arbitrary script code in user's browser session.... Read more
Affected Products :- Published: May. 30, 2025
- Modified: May. 30, 2025
-
8.7
CVSS31CVE-2025-4992
A stored Cross-site Scripting (XSS) vulnerability affecting Service Items Management in Service Process Engineer from Release 3DEXPERIENCE R2024x through Release 3DEXPERIENCE R2025x allows an attacker to execute arbitrary script code in user's browser ses... Read more
Affected Products :- Published: May. 30, 2025
- Modified: May. 30, 2025
-
0.0
NONECVE-2024-13915
Android based smartphones from vendors such as Ulefone and Krüger&Matz contain "com.pri.factorytest" application preloaded onto devices during manufacturing process. The application "com.pri.factorytest" (version name: 1.0, version code: 1) exposes a ”com... Read more
Affected Products :- Published: May. 30, 2025
- Modified: May. 30, 2025