Latest CVE Feed
-
7.1
HIGHCVE-2025-48151
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CreativeMindsSolutions CM Map Locations allows Reflected XSS. This issue affects CM Map Locations: from n/a through 2.1.6.... Read more
Affected Products :- Published: Aug. 20, 2025
- Modified: Aug. 20, 2025
-
8.6
HIGHCVE-2025-48158
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Alex Githatu BuddyPress XProfile Custom Image Field allows Path Traversal. This issue affects BuddyPress XProfile Custom Image Field: from n/a through 3.0.1.... Read more
Affected Products :- Published: Aug. 20, 2025
- Modified: Aug. 20, 2025
-
7.1
HIGHCVE-2025-48152
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in dimafreund Rentsyst allows Reflected XSS. This issue affects Rentsyst: from n/a through 2.0.100.... Read more
Affected Products :- Published: Aug. 20, 2025
- Modified: Aug. 20, 2025
-
8.8
HIGHCVE-2025-48142
Incorrect Privilege Assignment vulnerability in Saad Iqbal Bookify allows Privilege Escalation. This issue affects Bookify: from n/a through 1.0.9.... Read more
Affected Products :- Published: Aug. 20, 2025
- Modified: Aug. 20, 2025
-
8.1
HIGHCVE-2025-48149
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in dedalx Cook&Meal allows PHP Local File Inclusion. This issue affects Cook&Meal: from n/a through 1.2.3.... Read more
Affected Products :- Published: Aug. 20, 2025
- Modified: Aug. 20, 2025
-
5.9
MEDIUMCVE-2025-49892
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in badasswp Pending Order Bot allows Stored XSS. This issue affects Pending Order Bot: from n/a through 1.0.2.... Read more
Affected Products :- Published: Aug. 20, 2025
- Modified: Aug. 20, 2025
-
8.8
HIGHCVE-2025-50503
A vulnerability in the password reset workflow of the Touch Lebanon Mobile App 2.20.2 allows an attacker to bypass the OTP reset password mechanism. By manipulating the reset process, an unauthorized user may be able to reset the password and gain access ... Read more
Affected Products :- Published: Aug. 20, 2025
- Modified: Aug. 20, 2025
-
7.1
HIGHCVE-2025-54056
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LambertGroup Responsive HTML5 Audio Player PRO With Playlist allows Reflected XSS. This issue affects Responsive HTML5 Audio Player PRO With Playlist: fr... Read more
Affected Products :- Published: Aug. 20, 2025
- Modified: Aug. 20, 2025
-
4.3
MEDIUMCVE-2025-49896
Cross-Site Request Forgery (CSRF) vulnerability in wptasker WP Discord Post Plus – Supports Unlimited Channels allows Cross Site Request Forgery. This issue affects WP Discord Post Plus – Supports Unlimited Channels: from n/a through 1.0.2.... Read more
Affected Products :- Published: Aug. 20, 2025
- Modified: Aug. 20, 2025
-
9.8
CRITICALCVE-2025-53580
Incorrect Privilege Assignment vulnerability in quantumcloud Simple Business Directory Pro allows Privilege Escalation. This issue affects Simple Business Directory Pro: from n/a through n/a.... Read more
Affected Products :- Published: Aug. 20, 2025
- Modified: Aug. 20, 2025
-
6.5
MEDIUMCVE-2025-53988
Insertion of Sensitive Information Into Sent Data vulnerability in Crocoblock JetBlocks For Elementor allows Retrieve Embedded Sensitive Data. This issue affects JetBlocks For Elementor: from n/a through 1.3.18.... Read more
Affected Products : jetblocks_for_elementor- Published: Aug. 20, 2025
- Modified: Aug. 20, 2025
-
7.5
HIGHCVE-2025-48302
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Roxnor FundEngine allows PHP Local File Inclusion. This issue affects FundEngine: from n/a through 1.7.4.... Read more
Affected Products :- Published: Aug. 20, 2025
- Modified: Aug. 20, 2025
-
7.1
HIGHCVE-2025-48162
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in quantumcloud Simple Business Directory Pro allows Reflected XSS. This issue affects Simple Business Directory Pro: from n/a through 15.5.1.... Read more
Affected Products :- Published: Aug. 20, 2025
- Modified: Aug. 20, 2025
-
8.1
HIGHCVE-2025-48160
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in CocoBasic Caliris allows PHP Local File Inclusion. This issue affects Caliris: from n/a through 1.5.... Read more
Affected Products :- Published: Aug. 20, 2025
- Modified: Aug. 20, 2025
-
7.2
HIGHCVE-2025-24364
vaultwarden is an unofficial Bitwarden compatible server written in Rust, formerly known as bitwarden_rs. Attacker with authenticated access to the vaultwarden admin panel can execute arbitrary code in the system. The attacker could then change some setti... Read more
Affected Products : vaultwarden- Published: Jan. 27, 2025
- Modified: Aug. 20, 2025
-
8.1
HIGHCVE-2025-24365
vaultwarden is an unofficial Bitwarden compatible server written in Rust, formerly known as bitwarden_rs. Attacker can obtain owner rights of other organization. Hacker should know the ID of victim organization (in real case the user can be a part of the ... Read more
Affected Products : vaultwarden- Published: Jan. 27, 2025
- Modified: Aug. 20, 2025
-
9.3
HIGH- EPSS Score: %5.51
- Published: Mar. 11, 2021
- Modified: Aug. 20, 2025
-
9.3
HIGHCVE-2020-1481
A remote code execution vulnerability exists in the ESLint extension for Visual Studio Code when it validates source code after opening a project, aka 'Visual Studio Code ESLint Extention Remote Code Execution Vulnerability'.... Read more
- EPSS Score: %40.50
- Published: Jul. 14, 2020
- Modified: Aug. 20, 2025
-
4.3
MEDIUMCVE-2013-5714
Multiple cross-site scripting (XSS) vulnerabilities in ls/htmlchat.php in the VideoWhisper Live Streaming Integration plugin 4.25.3 and possibly earlier for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) name or (2) me... Read more
Affected Products : wordpress videowhisper_live_streaming_integration live_streaming_integration_plugin- EPSS Score: %0.41
- Published: Sep. 09, 2013
- Modified: Aug. 20, 2025
-
4.3
MEDIUMCVE-2014-1906
Multiple cross-site scripting (XSS) vulnerabilities in the VideoWhisper Live Streaming Integration plugin before 4.29.5 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) m parameter to lb_status.php; (2) msg parameter... Read more
- EPSS Score: %1.43
- Published: Mar. 06, 2014
- Modified: Aug. 20, 2025