Latest CVE Feed
-
5.5
MEDIUMCVE-2024-48241
An issue in radare2 v5.8.0 through v5.9.4 allows a local attacker to cause a denial of service via the __bf_div function.... Read more
Affected Products : radare2- Published: Oct. 30, 2024
- Modified: Jun. 13, 2025
-
6.5
MEDIUMCVE-2024-48052
In gradio <=4.42.0, the gr.DownloadButton function has a hidden server-side request forgery (SSRF) vulnerability. The reason is that within the save_url_to_cache function, there are no restrictions on the URL, which allows access to local target resources... Read more
Affected Products : gradio- Published: Nov. 04, 2024
- Modified: Jun. 13, 2025
-
5.4
MEDIUMCVE-2024-6766
The shortcodes-ultimate-pro WordPress plugin before 7.2.1 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to... Read more
Affected Products : shortcodes_ultimate- Published: Aug. 06, 2024
- Modified: Jun. 13, 2025
-
9.8
CRITICALCVE-2021-20588
Improper Handling of Length Parameter Inconsistency vulnerability in Mitsubishi Electric FA Engineering Software (CPU Module Logging Configuration Tool versions 1.112R and prior, CW Configurator versions 1.011M and prior, Data Transfer versions 3.44W and ... Read more
Affected Products : gx_works3 gt_designer3 gt_softgot2000 cpu_module_logging_configuration_tool cw_configurator gx_logviewer gx_works2 m_commdtm-hart m_commdtm-io-link melfa-works +35 more products- Published: Feb. 19, 2021
- Modified: Jun. 13, 2025
-
9.8
CRITICALCVE-2021-20587
Heap-based buffer overflow vulnerability in Mitsubishi Electric FA Engineering Software (CPU Module Logging Configuration Tool versions 1.112R and prior, CW Configurator versions 1.011M and prior, Data Transfer versions 3.44W and prior, EZSocket versions ... Read more
Affected Products : gx_works3 gt_designer3 gt_softgot2000 cpu_module_logging_configuration_tool cw_configurator gx_logviewer gx_works2 m_commdtm-hart m_commdtm-io-link melfa-works +35 more products- Published: Feb. 19, 2021
- Modified: Jun. 13, 2025
-
7.3
HIGHCVE-2024-40560
Tmall_demo before v2024.07.03 was discovered to contain a SQL injection vulnerability.... Read more
Affected Products : tmall_demo- Published: Jul. 15, 2024
- Modified: Jun. 13, 2025
-
5.3
MEDIUMCVE-2024-40555
Tmall_demo v2024.07.03 was discovered to contain an arbitrary file upload vulnerability.... Read more
Affected Products : tmall_demo- Published: Jul. 15, 2024
- Modified: Jun. 13, 2025
-
6.8
MEDIUMCVE-2024-4977
The Index WP MySQL For Speed WordPress plugin before 1.4.18 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin... Read more
- Published: Jul. 13, 2024
- Modified: Jun. 13, 2025
-
4.4
MEDIUMCVE-2024-30799
An issue in PX4 Autopilot v1.14 and before allows a remote attacker to execute arbitrary code and cause a denial of service via the Breach Return Point function.... Read more
Affected Products : px4_drone_autopilot- Published: Apr. 22, 2024
- Modified: Jun. 12, 2025
-
6.6
MEDIUMCVE-2024-29460
An issue in PX4 Autopilot v.1.14.0 allows an attacker to manipulate the flight path allowing for crashes of the drone via the home point location of the mission_block.cpp component.... Read more
Affected Products : px4_drone_autopilot- Published: Apr. 10, 2024
- Modified: Jun. 12, 2025
-
4.2
MEDIUMCVE-2024-2260
A session fixation vulnerability exists in the zenml-io/zenml application, where JWT tokens used for user authentication are not invalidated upon logout. This flaw allows an attacker to bypass authentication mechanisms by reusing a victim's JWT token.... Read more
Affected Products : zenml- Published: Apr. 16, 2024
- Modified: Jun. 12, 2025
-
8.8
HIGHCVE-2024-31759
An issue in sanluan PublicCMS v.4.0.202302.e allows an attacker to escalate privileges via the change password function.... Read more
Affected Products : publiccms- Published: Apr. 16, 2024
- Modified: Jun. 12, 2025
-
4.8
MEDIUMCVE-2024-2996
A vulnerability was found in Bdtask Multi-Store Inventory Management System up to 20240320. It has been classified as problematic. Affected is an unknown function of the component Page Title Handler. The manipulation leads to cross site scripting. It is p... Read more
- Published: Mar. 27, 2024
- Modified: Jun. 12, 2025
-
5.4
MEDIUMCVE-2024-2997
A vulnerability was found in Bdtask Multi-Store Inventory Management System up to 20240320. It has been declared as problematic. Affected by this vulnerability is an unknown functionality. The manipulation of the argument Category Name/Model Name/Brand Na... Read more
- Published: Mar. 27, 2024
- Modified: Jun. 12, 2025
-
5.4
MEDIUMCVE-2024-2998
A vulnerability was found in Bdtask Multi-Store Inventory Management System up to 20240320. It has been rated as problematic. Affected by this issue is some unknown functionality of the component Store Update Page. The manipulation of the argument Store N... Read more
- Published: Mar. 27, 2024
- Modified: Jun. 12, 2025
-
8.8
HIGHCVE-2024-3013
A vulnerability was found in FLIR AX8 up to 1.46.16. It has been rated as critical. This issue affects some unknown processing of the file /tools/test_login.php?action=register of the component User Registration. The manipulation leads to improper authori... Read more
- Published: Mar. 28, 2024
- Modified: Jun. 12, 2025
-
6.9
MEDIUMCVE-2025-31128
gifplayer is a customizable jquery plugin to play and stop animated gifs. gifplayer contains a cross-site scripting (XSS) vulnerability. This vulnerability is fixed in 0.3.7.... Read more
Affected Products :- Published: Mar. 31, 2025
- Modified: Jun. 12, 2025
- Vuln Type: Cross-Site Scripting
-
7.2
HIGHCVE-2025-25426
yshopmall <=v1.9.0 is vulnerable to SQL Injection in the image listing interface.... Read more
Affected Products : yshopmall- Published: Mar. 04, 2025
- Modified: Jun. 12, 2025
- Vuln Type: Injection
-
6.5
MEDIUMCVE-2025-1799
A vulnerability, which was classified as critical, was found in Zorlan SkyCaiji 2.9. This affects the function previewAction of the file vendor/skycaiji/app/admin/controller/Tool.php. The manipulation of the argument data leads to server-side request forg... Read more
Affected Products : skycaiji- Published: Mar. 01, 2025
- Modified: Jun. 12, 2025
- Vuln Type: Server-Side Request Forgery
-
5.4
MEDIUMCVE-2025-46853
Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be e... Read more
- Published: Jun. 10, 2025
- Modified: Jun. 12, 2025
- Vuln Type: Cross-Site Scripting