Latest CVE Feed
-
1.0
LOWCVE-2025-49842
conda-forge-webservices is the web app deployed to run conda-forge admin commands and linting. Prior to version 2025.3.24, the conda_forge_webservice Docker container executes commands without specifying a user. By default, Docker containers run as the ro... Read more
Affected Products :- Published: Jun. 17, 2025
- Modified: Jun. 17, 2025
- Vuln Type: Misconfiguration
-
7.1
HIGHCVE-2025-49312
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CodeRevolution Echo RSS Feed Post Generator Plugin for WordPress allows Reflected XSS. This issue affects Echo RSS Feed Post Generator Plugin for WordPre... Read more
Affected Products :- Published: Jun. 17, 2025
- Modified: Jun. 17, 2025
- Vuln Type: Cross-Site Scripting
-
7.2
HIGHCVE-2025-49331
Deserialization of Untrusted Data vulnerability in impleCode eCommerce Product Catalog allows Object Injection. This issue affects eCommerce Product Catalog: from n/a through 3.4.3.... Read more
Affected Products : ecommerce_product_catalog- Published: Jun. 17, 2025
- Modified: Jun. 17, 2025
- Vuln Type: Injection
-
8.1
HIGHCVE-2025-49251
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in thembay Fana allows PHP Local File Inclusion. This issue affects Fana: from n/a through 1.1.28.... Read more
Affected Products :- Published: Jun. 17, 2025
- Modified: Jun. 17, 2025
- Vuln Type: Path Traversal
-
10.0
CRITICALCVE-2025-49447
Unrestricted Upload of File with Dangerous Type vulnerability in Fastw3b LLC FW Food Menu allows Using Malicious Files. This issue affects FW Food Menu : from n/a through 6.0.0.... Read more
Affected Products :- Published: Jun. 17, 2025
- Modified: Jun. 17, 2025
- Vuln Type: Misconfiguration
-
8.7
HIGHCVE-2025-49154
An insecure access control vulnerability in Trend Micro Apex One and Trend Micro Worry-Free Business Security could allow a local attacker to overwrite key memory-mapped files which could then have severe consequences for the security and stability of aff... Read more
- Published: Jun. 17, 2025
- Modified: Jun. 17, 2025
- Vuln Type: Authorization
-
8.1
HIGHCVE-2025-49257
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in thembay Zota allows PHP Local File Inclusion. This issue affects Zota: from n/a through 1.3.8.... Read more
Affected Products :- Published: Jun. 17, 2025
- Modified: Jun. 17, 2025
- Vuln Type: Path Traversal
-
7.1
HIGHCVE-2025-49316
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Saleswonder Team Tobias WP2LEADS allows Reflected XSS. This issue affects WP2LEADS: from n/a through 3.5.0.... Read more
Affected Products :- Published: Jun. 17, 2025
- Modified: Jun. 17, 2025
- Vuln Type: Cross-Site Scripting
-
7.1
HIGHCVE-2025-48145
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Michal Jaworski Track, Analyze & Optimize by WP Tao allows Reflected XSS. This issue affects Track, Analyze & Optimize by WP Tao: from n/a throug... Read more
Affected Products :- Published: Jun. 17, 2025
- Modified: Jun. 17, 2025
- Vuln Type: Cross-Site Scripting
-
8.5
HIGHCVE-2025-48118
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WpExperts Hub Woocommerce Partial Shipment allows SQL Injection. This issue affects Woocommerce Partial Shipment: from n/a through 3.2.... Read more
Affected Products :- Published: Jun. 17, 2025
- Modified: Jun. 17, 2025
- Vuln Type: Injection
-
9.9
CRITICALCVE-2025-47559
Unrestricted Upload of File with Dangerous Type vulnerability in RomanCode MapSVG allows Upload a Web Shell to a Web Server. This issue affects MapSVG: from n/a through 8.5.32.... Read more
Affected Products : mapsvg- Published: Jun. 17, 2025
- Modified: Jun. 17, 2025
- Vuln Type: Misconfiguration
-
7.2
HIGHCVE-2025-3774
The Wise Chat plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the X-Forwarded-For header in all versions up to, and including, 3.3.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticat... Read more
Affected Products : wise_chat- Published: Jun. 17, 2025
- Modified: Jun. 17, 2025
- Vuln Type: Cross-Site Scripting
-
8.6
HIGHCVE-2025-3594
Path traversal vulnerability with the downloading and installation of Xuggler in Liferay Portal 7.0.0 through 7.4.3.4, and Liferay DXP 7.4 GA, 7.3 GA through update 34, and older unsupported versions allows remote attackers to (1) add files to arbitrary l... Read more
- Published: Jun. 16, 2025
- Modified: Jun. 17, 2025
- Vuln Type: Path Traversal
-
8.7
HIGHCVE-2025-3526
SessionClicks in Liferay Portal 7.0.0 through 7.4.3.21, and Liferay DXP 7.4 GA through update 9, 7.3 GA through update 25, and older unsupported versions does not restrict the saving of request parameters in the HTTP session, which allows remote attackers... Read more
- Published: Jun. 16, 2025
- Modified: Jun. 17, 2025
- Vuln Type: Denial of Service
-
8.7
HIGHCVE-2025-3602
Liferay Portal 7.4.0 through 7.4.3.97, and Liferay DXP 2023.Q3.1 through 2023.Q3.2, 7.4 GA through update 92, 7.3 GA through update 35, and 7.2 fix pack 8 through fix pack 20 does not limit the depth of a GraphQL queries, which allows remote attackers to ... Read more
- Published: Jun. 16, 2025
- Modified: Jun. 17, 2025
- Vuln Type: Denial of Service
-
9.3
CRITICALCVE-2025-39479
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in smartiolabs Smart Notification allows Blind SQL Injection. This issue affects Smart Notification: from n/a through 10.3.... Read more
Affected Products :- Published: Jun. 17, 2025
- Modified: Jun. 17, 2025
- Vuln Type: Injection
-
7.8
HIGHCVE-2025-36632
In Tenable Agent versions prior to 10.8.5 on a Windows host, it was found that a non-administrative user could execute code with SYSTEM privilege.... Read more
Affected Products :- Published: Jun. 16, 2025
- Modified: Jun. 17, 2025
- Vuln Type: Authorization
-
6.3
MEDIUMCVE-2025-34508
A path traversal vulnerability exists in the file dropoff functionality of ZendTo versions 6.15-7 and prior. This could allow a remote, authenticated attacker to retrieve the files of other ZendTo users, retrieve files on the host system, or cause a den... Read more
Affected Products :- Published: Jun. 17, 2025
- Modified: Jun. 17, 2025
- Vuln Type: Path Traversal
-
7.1
HIGHCVE-2025-30988
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in _CreativeMedia_ Elite Video Player allows Stored XSS. This issue affects Elite Video Player: from n/a through 10.0.5.... Read more
Affected Products :- Published: Jun. 17, 2025
- Modified: Jun. 17, 2025
- Vuln Type: Cross-Site Scripting
-
9.8
CRITICALCVE-2025-30618
Deserialization of Untrusted Data vulnerability in yuliaz Rapyd Payment Extension for WooCommerce allows Object Injection. This issue affects Rapyd Payment Extension for WooCommerce: from n/a through 1.2.0.... Read more
Affected Products :- Published: Jun. 17, 2025
- Modified: Jun. 17, 2025
- Vuln Type: Injection