Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 0.0

    NONE
    CVE-2025-48489

    FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.180, the application is vulnerable to Cross-Site Scripting (XSS) attacks due to insufficient data validation and sanitization during data reception. This issue has been pat... Read more

    Affected Products :
    • Published: May. 30, 2025
    • Modified: May. 30, 2025
  • 9.1

    CVSS31
    CVE-2025-48865

    Fabio is an HTTP(S) and TCP router for deploying applications managed by consul. Prior to version 1.6.6, Fabio allows clients to remove X-Forwarded headers (except X-Forwarded-For) due to a vulnerability in how it processes hop-by-hop headers. Fabio adds ... Read more

    Affected Products :
    • Published: May. 30, 2025
    • Modified: May. 30, 2025
  • 8.1

    CVSS31
    CVE-2025-48936

    Zitadel is open-source identity infrastructure software. Prior to versions 2.70.12, 2.71.10, and 3.2.2, a potential vulnerability exists in the password reset mechanism. ZITADEL utilizes the Forwarded or X-Forwarded-Host header from incoming requests to c... Read more

    Affected Products : zitadel
    • Published: May. 30, 2025
    • Modified: May. 30, 2025
  • 6.4

    CVSS31
    CVE-2025-4943

    The LA-Studio Element Kit for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘data-lakit-element-link’ parameter in all versions up to, and including, 1.5.2 due to insufficient input sanitization and output escaping. T... Read more

    Affected Products : element_kit_for_elementor
    • Published: May. 30, 2025
    • Modified: May. 30, 2025
  • 6.4

    CVSS31
    CVE-2025-5236

    The NinjaTeam Chat for Telegram plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘username’ parameter in all versions up to, and including, 1.1 due to insufficient input sanitization and output escaping. This makes it possible for... Read more

    Affected Products :
    • Published: May. 30, 2025
    • Modified: May. 30, 2025
  • 6.5

    CVSS31
    CVE-2025-48334

    Missing Authorization vulnerability in BinaryCarpenter Woo Slider Pro allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Woo Slider Pro: from n/a through 1.12. Affected action "woo_slide_pro_delete_slider".... Read more

    Affected Products :
    • Published: May. 30, 2025
    • Modified: May. 30, 2025
  • 6.5

    CVSS31
    CVE-2025-5142

    The Simple Page Access Restriction plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.31. This is due to missing nonce validation and capability checks in the settings save handler in the settings.ph... Read more

    Affected Products : simple_page_access_restriction
    • Published: May. 30, 2025
    • Modified: May. 30, 2025
  • 6.4

    CVSS31
    CVE-2025-5235

    The OpenSheetMusicDisplay plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘className’ parameter in all versions up to, and including, 1.4.0 due to insufficient input sanitization and output escaping. This makes it possible for au... Read more

    Affected Products :
    • Published: May. 30, 2025
    • Modified: May. 30, 2025
  • 6.5

    CVSS31
    CVE-2025-4597

    The Woo Slider Pro – Drag Drop Slider Builder For WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the woo_slide_pro_delete_draft_preview AJAX action in all versions up to, and includ... Read more

    Affected Products :
    • Published: May. 30, 2025
    • Modified: May. 30, 2025
  • 6.4

    CVSS31
    CVE-2025-4944

    The LA-Studio Element Kit for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Image Compare and Google Maps widgets in all versions up to, and including, 1.5.2 due to insufficient input sanitization and output ... Read more

    Affected Products : element_kit_for_elementor
    • Published: May. 30, 2025
    • Modified: May. 30, 2025
  • 8.8

    CVSS31
    CVE-2025-5190

    The Browse As plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 0.2. This is due to incorrect authentication checking in the 'IS_BA_Browse_As::notice' function with the 'is_ba_original_user_COOKIEHASH' cookie va... Read more

    Affected Products :
    • Published: May. 30, 2025
    • Modified: May. 30, 2025
  • 6.5

    CVSS31
    CVE-2025-1484

    A vulnerability exists in the media upload component of the Asset Suite versions listed below. If successfully exploited an attacker could impact the confidentiality or integrity of the system. An attacker can use this vulnerability to construct a reque... Read more

    Affected Products :
    • Published: May. 30, 2025
    • Modified: May. 30, 2025
  • 7.5

    CVSS31
    CVE-2025-48331

    Insertion of Sensitive Information Into Sent Data vulnerability in Vanquish WooCommerce Orders & Customers Exporter allows Retrieve Embedded Sensitive Data.This issue affects WooCommerce Orders & Customers Exporter: from n/a through 5.0.... Read more

    Affected Products :
    • Published: May. 30, 2025
    • Modified: May. 30, 2025
  • 4.2

    CVSS31
    CVE-2025-2571

    Mattermost versions 10.7.x <= 10.7.0, 10.6.x <= 10.6.2, 10.5.x <= 10.5.3, 9.11.x <= 9.11.12 fail to clear Google OAuth credentials when converting user accounts to bot accounts, allowing attackers to gain unauthorized access to bot accounts via the Google... Read more

    Affected Products : mattermost_server
    • Published: May. 30, 2025
    • Modified: May. 30, 2025
  • 8.7

    CVSS31
    CVE-2025-4983

    A stored Cross-site Scripting (XSS) vulnerability affecting City Referential in City Referential Manager on Release 3DEXPERIENCE R2025x allows an attacker to execute arbitrary script code in user's browser session.... Read more

    Affected Products :
    • Published: May. 30, 2025
    • Modified: May. 30, 2025
  • 8.7

    CVSS31
    CVE-2025-4989

    A stored Cross-site Scripting (XSS) vulnerability affecting Requirements in Product Manager from Release 3DEXPERIENCE R2022x through Release 3DEXPERIENCE R2025x allows an attacker to execute arbitrary script code in user's browser session.... Read more

    Affected Products :
    • Published: May. 30, 2025
    • Modified: May. 30, 2025
  • 8.7

    CVSS31
    CVE-2025-4990

    A stored Cross-site Scripting (XSS) vulnerability affecting Change Governance in Product Manager from Release 3DEXPERIENCE R2022x through Release 3DEXPERIENCE R2025x allows an attacker to execute arbitrary script code in user's browser session.... Read more

    Affected Products :
    • Published: May. 30, 2025
    • Modified: May. 30, 2025
  • 8.7

    CVSS31
    CVE-2025-4991

    A stored Cross-site Scripting (XSS) vulnerability affecting 3D Markup in Collaborative Industry Innovator from Release 3DEXPERIENCE R2022x through Release 3DEXPERIENCE R2025x allows an attacker to execute arbitrary script code in user's browser session.... Read more

    Affected Products :
    • Published: May. 30, 2025
    • Modified: May. 30, 2025
  • 8.7

    CVSS31
    CVE-2025-4992

    A stored Cross-site Scripting (XSS) vulnerability affecting Service Items Management in Service Process Engineer from Release 3DEXPERIENCE R2024x through Release 3DEXPERIENCE R2025x allows an attacker to execute arbitrary script code in user's browser ses... Read more

    Affected Products :
    • Published: May. 30, 2025
    • Modified: May. 30, 2025
  • 0.0

    NONE
    CVE-2024-13915

    Android based smartphones from vendors such as Ulefone and Krüger&Matz contain "com.pri.factorytest" application preloaded onto devices during manufacturing process. The application "com.pri.factorytest" (version name: 1.0, version code: 1) exposes a ”com... Read more

    Affected Products :
    • Published: May. 30, 2025
    • Modified: May. 30, 2025
Showing 20 of 192 Results
© cvefeed.io
Latest DB Update: May. 31, 2025 3:56