Latest CVE Feed
-
9.8
CRITICALCVE-2024-36526
ZKTeco ZKBio CVSecurity v6.1.1 was discovered to contain a hardcoded cryptographic key.... Read more
Affected Products : zkbio_cvsecurity- Published: Jul. 09, 2024
- Modified: Jun. 17, 2025
-
6.1
MEDIUMCVE-2025-28380
A cross-site scripting (XSS) vulnerability in OpenC3 COSMOS v6.0.0 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the URL parameter.... Read more
Affected Products : cosmos- Published: Jun. 13, 2025
- Modified: Jun. 17, 2025
- Vuln Type: Cross-Site Scripting
-
5.4
MEDIUMCVE-2024-5475
The Responsive video embed WordPress plugin before 0.5.1 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to ... Read more
Affected Products : responsive_video_embed- Published: Jun. 20, 2024
- Modified: Jun. 17, 2025
-
8.3
HIGHCVE-2024-4749
The wp-eMember WordPress plugin before 10.3.9 does not sanitize and escape the "fieldId" parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting.... Read more
Affected Products : wp_emember- Published: Jun. 04, 2024
- Modified: Jun. 17, 2025
-
2.5
LOWCVE-2025-5648
A vulnerability was found in Radare2 5.9.9. It has been classified as problematic. Affected is the function r_cons_pal_init in the library /libr/cons/pal.c of the component radiff2. The manipulation of the argument -T leads to memory corruption. An attack... Read more
Affected Products : radare2- Published: Jun. 05, 2025
- Modified: Jun. 17, 2025
- Vuln Type: Memory Corruption
-
6.5
MEDIUMCVE-2024-1076
The SSL Zen WordPress plugin before 4.6.0 does not properly prevent directory listing of the private keys folder, as it only relies on the use of .htaccess to prevent visitors from accessing the site's generated private keys, which allows an attacker to ... Read more
Affected Products : ssl_zen- Published: May. 08, 2024
- Modified: Jun. 17, 2025
-
6.5
MEDIUMCVE-2024-28294
Limbas up to v5.2.14 was discovered to contain a SQL injection vulnerability via the ftid parameter.... Read more
Affected Products : limbas- Published: Apr. 29, 2024
- Modified: Jun. 17, 2025
-
5.3
MEDIUMCVE-2024-0868
The coreActivity: Activity Logging plugin for WordPress plugin before 2.1 retrieved IP addresses of requests via headers such X-FORWARDED to log them, allowing users to spoof them by providing an arbitrary value... Read more
Affected Products : coreactivity- Published: Apr. 17, 2024
- Modified: Jun. 17, 2025
-
6.1
MEDIUMCVE-2023-4826
The SocialDriver WordPress theme before version 2024 has a prototype pollution vulnerability that could allow an attacker to inject arbitrary properties resulting in a cross-site scripting (XSS) attack.... Read more
Affected Products : socialdriver- Published: Feb. 23, 2024
- Modified: Jun. 17, 2025
-
7.5
HIGHCVE-2025-27956
Directory Traversal vulnerability in WebLaudos 24.2 (04) allows a remote attacker to obtain sensitive information via the id parameter.... Read more
Affected Products : weblaudos- Published: Jun. 02, 2025
- Modified: Jun. 17, 2025
- Vuln Type: Path Traversal
-
6.1
MEDIUMCVE-2024-50599
A reflected Cross-Site Scripting (XSS) vulnerability has been identified in Zimbra Collaboration Suite (ZCS) 8.8.15, affecting one of the webmail calendar endpoints. This arises from improper handling of user-supplied input, allowing an attacker to inject... Read more
Affected Products : zimbra_collaboration_suite- Published: Nov. 07, 2024
- Modified: Jun. 17, 2025
-
8.8
HIGHCVE-2025-5431
A vulnerability, which was classified as critical, was found in AssamLook CMS 1.0. Affected is an unknown function of the file /department-profile.php. The manipulation of the argument ID leads to sql injection. It is possible to launch the attack remotel... Read more
Affected Products : assamlook_cms- Published: Jun. 02, 2025
- Modified: Jun. 17, 2025
- Vuln Type: Injection
-
9.1
CRITICALCVE-2024-31815
In TOTOLINK EX200 V4.0.3c.7314_B20191204, an attacker can obtain the configuration file without authorization through /cgi-bin/ExportSettings.sh... Read more
- Published: Apr. 08, 2024
- Modified: Jun. 17, 2025
-
8.8
HIGHCVE-2024-24279
An issue in secdiskapp 1.5.1 (management program for NewQ Fingerprint Encryption Super Speed Flash Disk) allows attackers to gain escalated privileges via vsVerifyPassword and vsSetFingerPrintPower functions.... Read more
Affected Products : secdiskapp- Published: Apr. 08, 2024
- Modified: Jun. 17, 2025
-
6.5
MEDIUMCVE-2024-21507
Versions of the package mysql2 before 3.9.3 are vulnerable to Improper Input Validation through the keyFromFields function, resulting in cache poisoning. An attacker can inject a colon (:) character within a value of the attacker-crafted key.... Read more
Affected Products : mysql2- Published: Apr. 10, 2024
- Modified: Jun. 17, 2025
-
7.2
HIGHCVE-2025-39240
Some Hikvision Wireless Access Point are vulnerable to authenticated remote command execution due to insufficient input validation. Attackers with valid credentials can exploit this flaw by sending crafted packets containing malicious commands to affected... Read more
Affected Products :- Published: Jun. 13, 2025
- Modified: Jun. 17, 2025
- Vuln Type: Authentication
-
5.6
MEDIUMCVE-2025-22242
Worker process denial of service through file read operation. .A vulnerability exists in the Master's “pub_ret” method which is exposed to all minions. The un-sanitized input value “jid” is used to construct a path which is then opened for reading. An att... Read more
Affected Products : salt- Published: Jun. 13, 2025
- Modified: Jun. 17, 2025
- Vuln Type: Denial of Service
-
5.6
MEDIUMCVE-2025-22241
File contents overwrite the VirtKey class is called when “on-demand pillar” data is requested and uses un-validated input to create paths to the “pki directory”. The functionality is used to auto-accept Minion authentication keys based on a pre-placed “au... Read more
Affected Products : salt- Published: Jun. 13, 2025
- Modified: Jun. 17, 2025
- Vuln Type: Path Traversal
-
5.9
MEDIUMCVE-2024-13772
The Civi - Job Board & Freelance Marketplace WordPress Theme plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 2.1.6.1. This is due to a lack of password randomization and user validation through the fb_ajax... Read more
- Published: Mar. 14, 2025
- Modified: Jun. 17, 2025
- Vuln Type: Authentication
-
7.5
HIGHCVE-2023-52285
ExamSys 9150244 allows SQL Injection via the /Support/action/Pages.php s_score2 parameter.... Read more
Affected Products : examsys- Published: Jan. 17, 2024
- Modified: Jun. 17, 2025