Latest CVE Feed
-
7.1
HIGHCVE-2024-12400
The tourmaster WordPress plugin before 5.3.5 does not escape generated URLs before outputting them in attributes, leading to Reflected Cross-Site Scripting.... Read more
Affected Products : tour_master- Published: Jan. 30, 2025
- Modified: Jun. 09, 2025
- Vuln Type: Cross-Site Scripting
-
6.5
MEDIUMCVE-2024-12163
The goodlayers-core WordPress plugin before 2.1.3 allows users with a subscriber role and above to upload SVGs containing malicious payloads.... Read more
Affected Products : goodlayers_core- Published: Jan. 30, 2025
- Modified: Jun. 09, 2025
- Vuln Type: Authentication
-
4.8
MEDIUMCVE-2024-10510
The adBuddy+ (AdBlocker Detection) by NetfunkDesign WordPress plugin through 1.1.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfilte... Read more
Affected Products : adbuddy\+_\(adblocker_detection\)- Published: Nov. 28, 2024
- Modified: Jun. 09, 2025
-
6.5
MEDIUMCVE-2025-46011
Listmonk v4.1.0 (fixed in v5.0.0) is vulnerable to SQL Injection in the QuerySubscribers function which allows attackers to escalate privileges.... Read more
Affected Products :- Published: Jun. 04, 2025
- Modified: Jun. 09, 2025
- Vuln Type: Injection
-
8.8
HIGHCVE-2024-22818
FlyCms v1.0 contains a Cross-Site Request Forgery (CSRF) vulnerbility via /system/site/filterKeyword_save... Read more
Affected Products : flycms- Published: Jan. 18, 2024
- Modified: Jun. 09, 2025
-
4.8
MEDIUMCVE-2023-6163
The WP Crowdfunding WordPress plugin before 2.1.10 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowe... Read more
Affected Products : wp_crowdfunding- Published: Jan. 15, 2024
- Modified: Jun. 09, 2025
-
4.8
MEDIUMCVE-2023-5956
The Wp-Adv-Quiz WordPress plugin through 1.0.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (f... Read more
Affected Products : wp-adv-quiz- Published: Jan. 29, 2024
- Modified: Jun. 09, 2025
-
7.1
HIGHCVE-2023-42876
The issue was addressed with improved bounds checks. This issue is fixed in macOS Sonoma 14. Processing a file may lead to a denial-of-service or potentially disclose memory contents.... Read more
Affected Products : macos- Published: Jan. 10, 2024
- Modified: Jun. 09, 2025
-
6.5
MEDIUMCVE-2024-30180
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Easy Social Feed allows Stored XSS.This issue affects Easy Social Feed: from n/a through 6.5.3. ... Read more
Affected Products : easy_social_feed- Published: Mar. 27, 2024
- Modified: Jun. 09, 2025
-
5.9
MEDIUMCVE-2024-29818
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Poll Maker & Voting Plugin Team (InfoTheme) WP Poll Maker allows Stored XSS.This issue affects WP Poll Maker: from n/a through 3.1. ... Read more
Affected Products : wp_poll_maker- Published: Mar. 27, 2024
- Modified: Jun. 09, 2025
-
5.3
MEDIUMCVE-2024-32823
Authorization Bypass Through User-Controlled Key vulnerability in FeedbackWP Rate my Post – WP Rating System.This issue affects Rate my Post – WP Rating System: from n/a through 3.4.4. ... Read more
Affected Products : rate_my_post- Published: Apr. 24, 2024
- Modified: Jun. 09, 2025
-
9.1
CRITICALCVE-2024-32948
Missing Authorization vulnerability in Repute Infosystems ARMember.This issue affects ARMember: from n/a through 4.0.28. ... Read more
Affected Products : armember- Published: Apr. 24, 2024
- Modified: Jun. 09, 2025
-
9.9
CRITICALCVE-2024-32514
Unrestricted Upload of File with Dangerous Type vulnerability in Poll Maker & Voting Plugin Team (InfoTheme) WP Poll Maker.This issue affects WP Poll Maker: from n/a through 3.4. ... Read more
Affected Products : wp_poll_maker- Published: Apr. 17, 2024
- Modified: Jun. 09, 2025
-
4.3
MEDIUMCVE-2024-30526
Cross-Site Request Forgery (CSRF) vulnerability in Easy Social Feed.This issue affects Easy Social Feed: from n/a through 6.5.6. ... Read more
Affected Products : easy_social_feed- Published: Mar. 31, 2024
- Modified: Jun. 09, 2025
-
6.5
MEDIUMCVE-2024-29803
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Mehanoid.Pro FlatPM allows Stored XSS.This issue affects FlatPM: from n/a before 3.1.05. ... Read more
- Published: Mar. 27, 2024
- Modified: Jun. 09, 2025
-
6.8
MEDIUMCVE-2025-31200
A memory corruption issue was addressed with improved bounds checking. This issue is fixed in tvOS 18.4.1, visionOS 2.4.1, iOS iOS 18.4.1 and iPadOS 18.4.1, macOS Sequoia 15.4.1. Processing an audio stream in a maliciously crafted media file may result in... Read more
- Actively Exploited
- Published: Apr. 16, 2025
- Modified: Jun. 09, 2025
- Vuln Type: Memory Corruption
-
7.5
HIGHCVE-2025-31201
This issue was addressed by removing the vulnerable code. This issue is fixed in tvOS 18.4.1, visionOS 2.4.1, iOS iOS 18.4.1 and iPadOS 18.4.1, macOS Sequoia 15.4.1. An attacker with arbitrary read and write capability may be able to bypass Pointer Authen... Read more
- Actively Exploited
- Published: Apr. 16, 2025
- Modified: Jun. 09, 2025
- Vuln Type: Authorization
-
8.4
HIGHCVE-2018-8639
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka "Win32k Elevation of Privilege Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Serv... Read more
Affected Products : windows_10 windows_7 windows_8.1 windows_rt_8.1 windows_server_2008 windows_server_2012 windows_server_2016 windows_server_2019 windows_10_1607 windows_10_1809 +6 more products- Actively Exploited
- Published: Dec. 12, 2018
- Modified: Jun. 09, 2025
-
9.1
CRITICALCVE-2024-57727
SimpleHelp remote support software v5.5.7 and before is vulnerable to multiple path traversal vulnerabilities that enable unauthenticated remote attackers to download arbitrary files from the SimpleHelp host via crafted HTTP requests. These files include ... Read more
Affected Products : simplehelp- Actively Exploited
- Published: Jan. 15, 2025
- Modified: Jun. 09, 2025
- Vuln Type: Path Traversal
-
7.5
HIGHCVE-2024-24869
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in BoldGrid Total Upkeep allows Relative Path Traversal.This issue affects Total Upkeep: from n/a through 1.15.8.... Read more
Affected Products : total_upkeep- Published: May. 17, 2024
- Modified: Jun. 09, 2025