Latest CVE Feed
-
6.6
MEDIUMCVE-2025-0293
CLRF injection in Ivanti Connect Secure before version 22.7R2.8 and Ivanti Policy Secure before version 22.7R1.5 allows a remote authenticated attacker with admin rights to write to a protected configuration file on disk.... Read more
- Published: Jul. 08, 2025
- Modified: Jul. 10, 2025
- Vuln Type: Injection
-
7.5
HIGHCVE-2024-39134
A Stack Buffer Overflow vulnerability in zziplibv 0.13.77 allows attackers to cause a denial of service via the __zzip_fetch_disk_trailer() function at /zzip/zip.c.... Read more
Affected Products : zziplib- Published: Jun. 27, 2024
- Modified: Jul. 10, 2025
-
9.1
CRITICALCVE-2024-27905
** UNSUPPORTED WHEN ASSIGNED ** Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Aurora. An endpoint exposing internals to unauthenticated users can be used as a "padding oracle" allowing an anonymous attacker to constru... Read more
Affected Products : aurora- Published: Feb. 27, 2024
- Modified: Jul. 10, 2025
-
6.5
MEDIUMCVE-2025-48916
Missing Authorization vulnerability in Drupal Bookable Calendar allows Forceful Browsing.This issue affects Bookable Calendar: from 0.0.0 before 2.2.13.... Read more
Affected Products : bookable_calendar- Published: Jun. 13, 2025
- Modified: Jul. 10, 2025
- Vuln Type: Authorization
-
9.8
CRITICALCVE-2025-45988
Blink routers BL-WR9000 V2.4.9 , BL-AC2100_AZ3 V1.0.4, BL-X10_AC8 v1.0.5 , BL-LTE300 v1.2.3, BL-F1200_AT1 v1.0.0, BL-X26_AC8 v1.2.8, BLAC450M_AE4 v4.0.0 and BL-X26_DA3 v1.2.7 were discovered to contain multiple command injection vulnerabilities via the cm... Read more
Affected Products : bl-wr9000_firmware bl-wr9000 bl-ac1900_firmware bl-ac1900 bl-ac2100_az3_firmware bl-ac2100_az3 bl-x10_ac8_firmware bl-x10_ac8 bl-lte300_firmware bl-lte300 +8 more products- Published: Jun. 13, 2025
- Modified: Jul. 10, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-45987
Blink routers BL-WR9000 V2.4.9 , BL-AC2100_AZ3 V1.0.4, BL-X10_AC8 v1.0.5 , BL-LTE300 v1.2.3, BL-F1200_AT1 v1.0.0, BL-X26_AC8 v1.2.8, BLAC450M_AE4 v4.0.0 and BL-X26_DA3 v1.2.7 were discovered to contain multiple command injection vulnerabilities via the dn... Read more
Affected Products : bl-wr9000_firmware bl-wr9000 bl-ac2100_az3_firmware bl-ac2100_az3 bl-lte300_firmware bl-lte300 bl-f1200_at1_firmware bl-f1200_at1 bl-x26_ac8_firmware bl-x26_ac8 +4 more products- Published: Jun. 13, 2025
- Modified: Jul. 10, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-45985
Blink routers BL-WR9000 V2.4.9 , BL-AC2100_AZ3 V1.0.4, BL-X10_AC8 v1.0.5 , BL-LTE300 v1.2.3, BL-F1200_AT1 v1.0.0, BL-X26_AC8 v1.2.8, BLAC450M_AE4 v4.0.0 and BL-X26_DA3 v1.2.7 were discovered to contain a command injection vulnerability via the bs_SetSSIDH... Read more
Affected Products : bl-wr9000_firmware bl-wr9000 bl-ac2100_az3_firmware bl-ac2100_az3 bl-x10_ac8_firmware bl-x10_ac8 bl-lte300_firmware bl-lte300 bl-f1200_at1_firmware bl-f1200_at1 +6 more products- Published: Jun. 13, 2025
- Modified: Jul. 10, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-45984
Blink routers BL-WR9000 V2.4.9, BL-AC1900 V1.0.2, BL-AC2100_AZ3 V1.0.4, BL-X10_AC8 V1.0.5, BL-LTE300 V1.2.3, BL-F1200_AT1 V1.0.0, BL-X26_AC8 V1.2.8, BLAC450M_AE4 V4.0.0 and BL-X26_DA3 V1.2.7 were discovered to contain a command injection vulnerability via... Read more
Affected Products : bl-wr9000_firmware bl-wr9000 bl-ac1900_firmware bl-ac1900 bl-ac2100_az3_firmware bl-ac2100_az3 bl-x10_ac8_firmware bl-x10_ac8 bl-lte300_firmware bl-lte300 +8 more products- Published: Jun. 13, 2025
- Modified: Jul. 10, 2025
-
4.8
MEDIUMCVE-2024-6344
A vulnerability, which was classified as problematic, was found in ZKTeco ZKBio CVSecurity V5000 4.1.0. This affects an unknown part of the component Push Configuration Section. The manipulation of the argument Configuration Name leads to cross site scrip... Read more
Affected Products : zkbiosecurity_v5000- Published: Jun. 26, 2024
- Modified: Jul. 10, 2025
-
5.5
MEDIUMCVE-2025-52900
File Browser provides a file managing interface within a specified directory and it can be used to upload, delete, preview, rename and edit files. The file access permissions for files uploaded to or created from File Browser are never explicitly set by t... Read more
Affected Products : filebrowser- Published: Jun. 26, 2025
- Modified: Jul. 10, 2025
- Vuln Type: Misconfiguration
-
7.6
HIGHCVE-2025-52902
File Browser provides a file managing interface within a specified directory and it can be used to upload, delete, preview, rename and edit files. The Markdown preview function of File Browser prior to v2.33.7 is vulnerable to Stored Cross-Site-Scripting ... Read more
Affected Products : filebrowser- Published: Jun. 26, 2025
- Modified: Jul. 10, 2025
- Vuln Type: Cross-Site Scripting
-
6.1
MEDIUMCVE-2025-6701
A vulnerability, which was classified as problematic, has been found in Xuxueli xxl-sso 1.1.0. This issue affects some unknown processing of the file /xxl-sso-server/doLogin. The manipulation of the argument redirect_url leads to open redirect. The attack... Read more
Affected Products : xxl-sso- Published: Jun. 26, 2025
- Modified: Jul. 10, 2025
- Vuln Type: Misconfiguration
-
5.3
MEDIUMCVE-2025-6702
A vulnerability, which was classified as problematic, was found in linlinjava litemall 1.8.0. Affected is an unknown function of the file /wx/comment/post. The manipulation of the argument adminComment leads to improper authorization. It is possible to la... Read more
Affected Products : litemall- Published: Jun. 26, 2025
- Modified: Jul. 10, 2025
- Vuln Type: Authorization
-
9.6
CRITICALCVE-2024-52928
Arc before 1.26.1 on Windows has a bypass issue in the site settings that allows websites (with previously granted permissions) to add new permissions when the user clicks anywhere on the website.... Read more
- Published: Jun. 26, 2025
- Modified: Jul. 10, 2025
- Vuln Type: Authorization
-
9.8
CRITICALCVE-2025-6843
A vulnerability was found in code-projects Simple Photo Gallery 1.0. It has been classified as critical. Affected is an unknown function of the file /upload-photo.php. The manipulation of the argument file_img leads to unrestricted upload. It is possible ... Read more
- Published: Jun. 29, 2025
- Modified: Jul. 10, 2025
- Vuln Type: Misconfiguration
-
6.4
MEDIUMCVE-2025-5123
The Contact Us Page – Contact People plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘style’ parameter in all versions up to, and including, 3.7.4 due to insufficient input sanitization and output escaping. This makes it possible... Read more
Affected Products : contact_us_page_-_contact_people- Published: Jun. 13, 2025
- Modified: Jul. 10, 2025
- Vuln Type: Cross-Site Scripting
-
5.3
MEDIUMCVE-2025-5938
The Digital Marketing and Agency Templates Addons for Elementor plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1.1. This is due to missing or incorrect nonce validation on the import_templates() fu... Read more
Affected Products : digital_marketing_and_agency_templates_addons_for_elementor- Published: Jun. 13, 2025
- Modified: Jul. 10, 2025
- Vuln Type: Cross-Site Request Forgery
-
6.4
MEDIUMCVE-2025-5950
The IndieBlocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘kind’ parameter in all versions up to, and including, 0.13.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated at... Read more
Affected Products : indieblocks- Published: Jun. 13, 2025
- Modified: Jul. 10, 2025
- Vuln Type: Cross-Site Scripting
-
7.5
HIGHCVE-2025-5282
The WP Travel Engine – Tour Booking Plugin – Tour Operator Software plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the delete_package() function in all versions up to, and including, 6.5.1. This makes ... Read more
Affected Products : wp_travel_engine- Published: Jun. 13, 2025
- Modified: Jul. 10, 2025
- Vuln Type: Authorization
-
9.6
CRITICALCVE-2024-38824
Directory traversal vulnerability in recv_file method allows arbitrary files to be written to the master cache directory.... Read more
Affected Products : salt- Published: Jun. 13, 2025
- Modified: Jul. 10, 2025
- Vuln Type: Path Traversal