Latest CVE Feed
-
4.1
MEDIUMCVE-2023-50786
Dradis through 4.16.0 allows referencing external images (resources) over HTTPS, instead of forcing the use of embedded (uploaded) images. This can be leveraged by an authorized author to attempt to steal the Net-NTLM hashes of other authors on a Windows ... Read more
Affected Products : dradis- Published: Jul. 05, 2025
- Modified: Jul. 08, 2025
- Vuln Type: Information Disclosure
-
0.0
NACVE-2025-38234
In the Linux kernel, the following vulnerability has been resolved: sched/rt: Fix race in push_rt_task Overview ======== When a CPU chooses to call push_rt_task and picks a task to push to another CPU's runqueue then it will call find_lock_lowest_rq met... Read more
Affected Products : linux_kernel- Published: Jul. 04, 2025
- Modified: Jul. 08, 2025
- Vuln Type: Race Condition
-
8.1
HIGHCVE-2025-43711
Tunnelblick 3.5beta06 before 7.0, when incompletely uninstalled, allows attackers to execute arbitrary code as root (upon the next boot) by dragging a crafted Tunnelblick.app file into /Applications.... Read more
Affected Products :- Published: Jul. 05, 2025
- Modified: Jul. 08, 2025
- Vuln Type: Authentication
-
9.3
CRITICALCVE-2025-26850
The agent in Quest KACE Systems Management Appliance (SMA) before 14.0.97 and 14.1.x before 14.1.19 potentially allows privilege escalation on managed systems.... Read more
Affected Products : kace_systems_management_appliance- Published: Jul. 05, 2025
- Modified: Jul. 08, 2025
- Vuln Type: Authorization
-
5.3
MEDIUMCVE-2025-53602
Zipkin through 3.5.1 has a /heapdump endpoint (associated with the use of Spring Boot Actuator), a similar issue to CVE-2025-48927.... Read more
Affected Products :- Published: Jul. 04, 2025
- Modified: Jul. 08, 2025
- Vuln Type: Information Disclosure
-
7.9
HIGHCVE-2025-46733
OP-TEE is a Trusted Execution Environment (TEE) designed as companion to a non-secure Linux kernel running on Arm; Cortex-A cores using the TrustZone technology. In version 4.5.0, using a specially crafted tee-supplicant binary running in REE userspace, a... Read more
Affected Products : op-tee_os- Published: Jul. 04, 2025
- Modified: Jul. 08, 2025
- Vuln Type: Denial of Service
-
6.9
MEDIUMCVE-2025-6056
Timing difference in password reset in Ergon Informatik AG's Airlock IAM 7.7.9, 8.0.8, 8.1.7, 8.2.4 and 8.3.1 allows unauthenticated attackers to enumerate usernames.... Read more
Affected Products :- Published: Jul. 04, 2025
- Modified: Jul. 08, 2025
- Vuln Type: Information Disclosure
-
9.3
CRITICALCVE-2025-52833
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in designthemes LMS allows SQL Injection. This issue affects LMS: from n/a through 9.1.... Read more
Affected Products :- Published: Jul. 04, 2025
- Modified: Jul. 08, 2025
- Vuln Type: Injection
-
9.3
CRITICALCVE-2025-52831
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in thanhtungtnt Video List Manager allows SQL Injection. This issue affects Video List Manager: from n/a through 1.7.... Read more
Affected Products : video_list_manager- Published: Jul. 04, 2025
- Modified: Jul. 08, 2025
- Vuln Type: Injection
-
8.1
HIGHCVE-2025-52813
Missing Authorization vulnerability in pietro MobiLoud allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects MobiLoud: from n/a through 4.6.5.... Read more
Affected Products :- Published: Jul. 04, 2025
- Modified: Jul. 08, 2025
- Vuln Type: Authorization
-
8.1
HIGHCVE-2025-52807
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ApusWP Kossy - Minimalist eCommerce WordPress Theme allows PHP Local File Inclusion. This issue affects Kossy - Minimalist eCommerce W... Read more
Affected Products :- Published: Jul. 04, 2025
- Modified: Jul. 08, 2025
- Vuln Type: Path Traversal
-
7.1
HIGHCVE-2025-52776
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in thanhtungtnt Video List Manager allows Stored XSS. This issue affects Video List Manager: from n/a through 1.7.... Read more
Affected Products : video_list_manager- Published: Jul. 04, 2025
- Modified: Jul. 08, 2025
- Vuln Type: Cross-Site Scripting
-
7.2
HIGHCVE-2025-52718
Improper Control of Generation of Code ('Code Injection') vulnerability in Bearsthemes Alone allows Remote Code Inclusion. This issue affects Alone: from n/a through 7.8.2.... Read more
Affected Products :- Published: Jul. 04, 2025
- Modified: Jul. 08, 2025
- Vuln Type: Injection
-
6.5
MEDIUMCVE-2025-50039
Missing Authorization vulnerability in vgwort VG WORT METIS allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects VG WORT METIS: from n/a through 2.0.0.... Read more
Affected Products :- Published: Jul. 04, 2025
- Modified: Jul. 08, 2025
- Vuln Type: Authorization
-
6.5
MEDIUMCVE-2025-50032
Missing Authorization vulnerability in Paytiko - Payment Orchestration Platform Paytiko for WooCommerce allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Paytiko for WooCommerce: from n/a through 1.3.14.... Read more
Affected Products :- Published: Jul. 04, 2025
- Modified: Jul. 08, 2025
- Vuln Type: Authorization
-
7.5
HIGHCVE-2025-49870
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Cozmoslabs Paid Member Subscriptions allows SQL Injection. This issue affects Paid Member Subscriptions: from n/a through 2.15.1.... Read more
Affected Products : paid_membership_subscriptions- Published: Jul. 04, 2025
- Modified: Jul. 08, 2025
- Vuln Type: Injection
-
7.1
HIGHCVE-2025-49866
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Nikel Beautiful Cookie Consent Banner allows Reflected XSS. This issue affects Beautiful Cookie Consent Banner: from n/a through 4.6.1.... Read more
Affected Products : beautiful_cookie_consent_banner- Published: Jul. 04, 2025
- Modified: Jul. 08, 2025
- Vuln Type: Cross-Site Scripting
-
6.5
MEDIUMCVE-2025-49431
Missing Authorization vulnerability in Gnuget MF Plus WPML allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects MF Plus WPML: from n/a through 1.1.... Read more
Affected Products :- Published: Jul. 04, 2025
- Modified: Jul. 08, 2025
- Vuln Type: Authorization
-
9.8
CRITICALCVE-2025-49417
Deserialization of Untrusted Data vulnerability in BestWpDeveloper WooCommerce Product Multi-Action allows Object Injection. This issue affects WooCommerce Product Multi-Action: from n/a through 1.3.... Read more
Affected Products :- Published: Jul. 04, 2025
- Modified: Jul. 08, 2025
- Vuln Type: Injection
-
10.0
CRITICALCVE-2025-49414
Unrestricted Upload of File with Dangerous Type vulnerability in Fastw3b LLC FW Gallery allows Using Malicious Files. This issue affects FW Gallery: from n/a through 8.0.0.... Read more
Affected Products :- Published: Jul. 04, 2025
- Modified: Jul. 08, 2025
- Vuln Type: Misconfiguration