Latest CVE Feed
-
8.8
HIGHCVE-2025-6535
A vulnerability has been found in xxyopen/201206030 novel-plus up to 5.1.3 and classified as critical. This vulnerability affects the function list of the file novel-admin/src/main/resources/mybatis/system/UserMapper.xml of the component User Management M... Read more
Affected Products : novel-plus- Published: Jun. 24, 2025
- Modified: Jul. 09, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2021-41691
A SQL injection vulnerability exists in OS4Ed Open Source Information System Community v8.0 via the "student_id" and "TRANSFER{SCHOOL]" parameters in POST request sent to /TransferredOutModal.php.... Read more
Affected Products : opensis- Published: Jun. 24, 2025
- Modified: Jul. 09, 2025
- Vuln Type: Injection
-
7.5
HIGHCVE-2025-44531
An issue in Realtek RTL8762EKF-EVB RTL8762E SDK v1.4.0 allows attackers to cause a Denial of Service (DoS) via sending a crafted before a pairing public key is received during a Bluetooth connection attempt.... Read more
- Published: Jun. 24, 2025
- Modified: Jul. 09, 2025
- Vuln Type: Denial of Service
-
9.8
CRITICALCVE-2024-37743
An issue in mmzdev KnowledgeGPT V.0.0.5 allows a remote attacker to execute arbitrary code via the Document Display Component.... Read more
Affected Products : knowledgegpt- Published: Jun. 24, 2025
- Modified: Jul. 09, 2025
- Vuln Type: Authentication
-
7.5
HIGHCVE-2025-45332
vkoskiv c-ray 1.1 contains a Null Pointer Dereference (NPD) vulnerability in the parse_mtllib function of its data processing module, leading to unpredictable program behavior, causing segmentation faults, and program crashes.... Read more
Affected Products : c-ray- Published: Jun. 25, 2025
- Modified: Jul. 09, 2025
- Vuln Type: Memory Corruption
-
7.5
HIGHCVE-2025-45333
berkeley-abc abc 1.1 contains a Null Pointer Dereference (NPD) vulnerability in the Abc_NtkCecFraigPart function of its data processing module, leading to unpredictable program behavior, causing segmentation faults, and program crashes.... Read more
Affected Products : abc- Published: Jun. 25, 2025
- Modified: Jul. 09, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2023-51574
Voltronic Power ViewPower updateManagerPassword Exposed Dangerous Method Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authentication on affected installations of Voltronic Power ViewPower. Authentication is not... Read more
Affected Products : viewpower- Published: May. 03, 2024
- Modified: Jul. 09, 2025
-
4.9
MEDIUMCVE-2025-4798
The WP-DownloadManager plugin for WordPress is vulnerable to arbitrary file read in all versions up to, and including, 1.68.10. This is due to a lack of restriction on the directory an administrator can select for storing downloads. This makes it possible... Read more
Affected Products : wp-downloadmanager- Published: Jun. 11, 2025
- Modified: Jul. 09, 2025
- Vuln Type: Path Traversal
-
6.4
MEDIUMCVE-2025-5143
The TableOn – WordPress Posts Table Filterable plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's tableon_popup_iframe_button shortcode in all versions up to, and including, 1.0.4.1 due to insufficient input sanitization an... Read more
Affected Products : tableon_-_wordpress_posts_table_filterable- Published: Jun. 21, 2025
- Modified: Jul. 09, 2025
- Vuln Type: Cross-Site Scripting
-
6.4
MEDIUMCVE-2025-4367
The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wpdm_user_dashboard shortcode in all versions up to, and including, 3.3.18 due to insufficient input sanitization and output escaping on user supplied ... Read more
Affected Products : download_manager- Published: Jun. 19, 2025
- Modified: Jul. 09, 2025
- Vuln Type: Cross-Site Scripting
-
6.1
MEDIUMCVE-2025-48923
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Toc.Js allows Cross-Site Scripting (XSS).This issue affects Toc.Js: from 0.0.0 before 3.2.1.... Read more
Affected Products : toc.js- Published: Jun. 26, 2025
- Modified: Jul. 09, 2025
- Vuln Type: Cross-Site Scripting
-
9.8
CRITICALCVE-2025-1562
The Recover WooCommerce Cart Abandonment, Newsletter, Email Marketing, Marketing Automation By FunnelKit plugin for WordPress is vulnerable to unauthorized arbitrary plugin installation due to a missing capability check on the install_or_activate_addon_pl... Read more
Affected Products : funnelkit_automations- Published: Jun. 18, 2025
- Modified: Jul. 09, 2025
- Vuln Type: Authorization
-
9.8
CRITICALCVE-2024-8856
The Backup and Staging by WP Time Capsule plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the the UploadHandler.php file and no direct file access prevention in all versions up to, and including, 1.22.21... Read more
Affected Products : backup_and_staging_by_wp_time_capsule- Published: Nov. 16, 2024
- Modified: Jul. 09, 2025
-
7.2
HIGHCVE-2025-6220
The Ultra Addons for Contact Form 7 plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'save_options' function in all versions up to, and including, 3.5.12. This makes it possible for authenticated atta... Read more
Affected Products : ultimate_addons_for_contact_form_7- Published: Jun. 18, 2025
- Modified: Jul. 09, 2025
- Vuln Type: Authentication
-
8.8
HIGHCVE-2024-10728
The Post Grid Gutenberg Blocks and WordPress Blog Plugin – PostX plugin for WordPress is vulnerable to unauthorized plugin installation/activation due to a missing capability check on the 'install_required_plugin_callback' function in all versions up to, ... Read more
Affected Products : postx- Published: Nov. 16, 2024
- Modified: Jul. 09, 2025
-
6.1
MEDIUMCVE-2024-10878
The Sugar Calendar – Simple Event Management plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg & remove_query_arg without appropriate escaping on the URL in all versions up to, and including, 3.3.0. This ... Read more
Affected Products : sugar_calendar- Published: Nov. 26, 2024
- Modified: Jul. 09, 2025
-
6.3
MEDIUMCVE-2024-11002
The The InPost Gallery plugin for WordPress is vulnerable to arbitrary shortcode execution via the inpost_gallery_get_shortcode_template AJAX action in all versions up to, and including, 2.1.4.2. This is due to the software allowing users to execute an ac... Read more
Affected Products : inpost_gallery- Published: Nov. 26, 2024
- Modified: Jul. 09, 2025
-
9.8
CRITICALCVE-2025-49003
DataEase is an open source business intelligence and data visualization tool. Prior to version 2.10.11, a threat actor may take advantage of a feature in Java in which the character "ı" becomes "I" when converted to uppercase, and the character "ſ" become... Read more
Affected Products : dataease- Published: Jun. 26, 2025
- Modified: Jul. 09, 2025
- Vuln Type: Information Disclosure
-
6.5
MEDIUMCVE-2024-10857
The Product Input Fields for WooCommerce plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.9 via the handle_downloads() function due to insufficient file path validation/sanitization. This makes it possible ... Read more
Affected Products : product_input_fields_for_woocommerce- Published: Nov. 26, 2024
- Modified: Jul. 09, 2025
-
4.3
MEDIUMCVE-2024-10778
The BuddyPress Builder for Elementor – BuddyBuilder plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.7.4 via the 'elementor-template' shortcode due to insufficient restrictions on which posts can be includ... Read more
Affected Products : buddybuilder- Published: Nov. 13, 2024
- Modified: Jul. 09, 2025