Latest CVE Feed
-
4.8
MEDIUMCVE-2025-2205
The GDPR Cookie Compliance – Cookie Banner, Cookie Consent, Cookie Notice – CCPA, DSGVO, RGPD plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 4.15.6 due to insufficient input sanit... Read more
Affected Products : gdpr_cookie_compliance- Published: Mar. 12, 2025
- Modified: Jul. 08, 2025
- Vuln Type: Cross-Site Scripting
-
8.1
HIGHCVE-2025-1785
The Download Manager plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 3.3.08 via the 'wpdm_newfile' action. This makes it possible for authenticated attackers, with Author-level access and above, to overwrite... Read more
- Published: Mar. 13, 2025
- Modified: Jul. 08, 2025
- Vuln Type: Path Traversal
-
7.8
HIGHCVE-2023-50192
Trimble SketchUp Viewer SKP File Parsing Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Trimble SketchUp Viewer. User interaction is required to exploit... Read more
- Published: May. 03, 2024
- Modified: Jul. 08, 2025
-
7.8
HIGHCVE-2023-50191
Trimble SketchUp Viewer SKP File Parsing Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Trimble SketchUp Viewer. User interaction is required to exploit... Read more
- Published: May. 03, 2024
- Modified: Jul. 08, 2025
-
7.5
HIGHCVE-2024-11283
The WP JobHunt plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 7.1. This is due to wp_ajax_google_api_login_callback function not properly verifying a user's identity prior to authenticating them. This mak... Read more
Affected Products : jobcareer- Published: Mar. 14, 2025
- Modified: Jul. 08, 2025
- Vuln Type: Authentication
-
9.8
CRITICALCVE-2024-11284
The WP JobHunt plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 6.9. This is due to the plugin not properly validating a user's identity prior to updating their password through the acco... Read more
Affected Products : jobcareer- Published: Mar. 14, 2025
- Modified: Jul. 08, 2025
- Vuln Type: Authentication
-
9.8
CRITICALCVE-2024-11285
The WP JobHunt plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 7.1. This is due to the plugin not properly validating a user's identity prior to updating their details like email via th... Read more
Affected Products : jobcareer- Published: Mar. 14, 2025
- Modified: Jul. 08, 2025
- Vuln Type: Authentication
-
9.8
CRITICALCVE-2024-11286
The WP JobHunt plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 7.1. This is due to the plugin not properly verifying a user's identity prior to authenticating them through the cs_parse_request() function. ... Read more
Affected Products : jobcareer- Published: Mar. 14, 2025
- Modified: Jul. 08, 2025
-
7.8
HIGHCVE-2023-50196
Trimble SketchUp Viewer SKP File Parsing Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Trimble SketchUp Viewer. User interaction is required to exploit... Read more
- Published: May. 03, 2024
- Modified: Jul. 08, 2025
-
8.1
HIGHCVE-2025-33070
Use of uninitialized resource in Windows Netlogon allows an unauthorized attacker to elevate privileges over a network.... Read more
Affected Products : windows_server_2008 windows_server_2012 windows_server_2016 windows_server_2019 windows_10_1607 windows_10_1809 windows_10_21h2 windows_10_22h2 windows_server_2022 windows_11_22h2 +8 more products- Published: Jun. 10, 2025
- Modified: Jul. 08, 2025
- Vuln Type: Authentication
-
8.1
HIGHCVE-2025-33071
Use after free in Windows KDC Proxy Service (KPSSVC) allows an unauthorized attacker to execute code over a network.... Read more
- Published: Jun. 10, 2025
- Modified: Jul. 08, 2025
- Vuln Type: Memory Corruption
-
7.6
HIGHCVE-2025-0966
IBM InfoSphere Information Server 11.7 vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify, or delete information in the back-end database.... Read more
- Published: Jun. 25, 2025
- Modified: Jul. 08, 2025
- Vuln Type: Injection
-
6.4
MEDIUMCVE-2025-5585
The SiteOrigin Widgets Bundle plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `data-url` DOM Element Attribute in all versions up to, and including, 1.68.4 due to insufficient input sanitization and output escaping. This makes it... Read more
Affected Products : siteorigin_widgets_bundle- Published: Jun. 25, 2025
- Modified: Jul. 08, 2025
- Vuln Type: Cross-Site Scripting
-
7.5
HIGHCVE-2025-5927
The Everest Forms (Pro) plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the delete_entry_files() function in all versions up to, and including, 1.9.4. This makes it possible for unauthenticated att... Read more
Affected Products : everest_forms- Published: Jun. 25, 2025
- Modified: Jul. 08, 2025
- Vuln Type: Authorization
-
6.4
MEDIUMCVE-2025-20264
A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to bypass the authorization mechanisms for specific administrative functions. This vulnerability is due to insuf... Read more
Affected Products : identity_services_engine- Published: Jun. 25, 2025
- Modified: Jul. 08, 2025
- Vuln Type: Authorization
-
8.8
HIGHCVE-2025-6915
A vulnerability, which was classified as critical, has been found in PHPGurukul Student Record System 3.2. Affected by this issue is some unknown functionality of the file /register.php. The manipulation of the argument session leads to sql injection. The... Read more
Affected Products : student_record_system- Published: Jun. 30, 2025
- Modified: Jul. 08, 2025
- Vuln Type: Injection
-
6.8
MEDIUMCVE-2025-5832
Pioneer DMH-WT7600NEX Software Update Signing Insufficient Verification of Data Authenticity Vulnerability. This vulnerability allows physically present attackers to execute arbitrary code on affected installations of Pioneer DMH-WT7600NEX devices. Authen... Read more
- Published: Jun. 25, 2025
- Modified: Jul. 08, 2025
- Vuln Type: Authentication
-
6.8
MEDIUMCVE-2025-5833
Pioneer DMH-WT7600NEX Root Filesystem Insufficient Verification of Data Authenticity Vulnerability. This vulnerability allows physically present attackers to bypass authentication on affected installations of Pioneer DMH-WT7600NEX devices. Authentication ... Read more
- Published: Jun. 25, 2025
- Modified: Jul. 08, 2025
- Vuln Type: Authentication
-
7.8
HIGHCVE-2025-5834
Pioneer DMH-WT7600NEX Missing Immutable Root of Trust in Hardware Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to bypass authentication on affected installations of Pioneer DMH-WT7600NEX devices. Although authenticat... Read more
- Published: Jun. 25, 2025
- Modified: Jul. 08, 2025
- Vuln Type: Authentication
-
6.4
MEDIUMCVE-2025-6689
The FL3R Accessibility Suite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's fl3raccessibilitysuite shortcode in all versions up to, and including, 1.4 due to insufficient input sanitization and output escaping on user s... Read more
Affected Products : fl3r_accessibility_suite- Published: Jun. 27, 2025
- Modified: Jul. 08, 2025
- Vuln Type: Cross-Site Scripting