Latest CVE Feed
-
6.5
MEDIUMCVE-2024-53814
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Analytify.This issue affects Analytify: from n/a through 5.4.3.... Read more
Affected Products : analytify_-_google_analytics_dashboard- Published: Dec. 09, 2024
- Modified: Jun. 09, 2025
-
5.3
MEDIUMCVE-2023-41953
Missing Authorization vulnerability in ProfilePress Membership Team ProfilePress.This issue affects ProfilePress: from n/a through 4.13.1.... Read more
Affected Products : profilepress- Published: Dec. 09, 2024
- Modified: Jun. 09, 2025
-
5.3
MEDIUMCVE-2023-50882
Missing Authorization vulnerability in ProfilePress Membership Team ProfilePress allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects ProfilePress: from n/a through 4.13.2.... Read more
Affected Products : profilepress- Published: Dec. 09, 2024
- Modified: Jun. 09, 2025
-
4.3
MEDIUMCVE-2023-49835
Missing Authorization vulnerability in Metaphor Creations Post Duplicator allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Post Duplicator: from n/a through 2.31.... Read more
Affected Products : post_duplicator- Published: Dec. 09, 2024
- Modified: Jun. 09, 2025
-
5.4
MEDIUMCVE-2023-48774
Missing Authorization vulnerability in Martin Gibson IdeaPush allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects IdeaPush: from n/a through n/a.... Read more
Affected Products : ideapush- Published: Dec. 09, 2024
- Modified: Jun. 09, 2025
-
4.3
MEDIUMCVE-2025-32238
Generation of Error Message Containing Sensitive Information vulnerability in vcita Online Booking & Scheduling Calendar for WordPress by vcita allows Retrieve Embedded Sensitive Data. This issue affects Online Booking & Scheduling Calendar for WordPress ... Read more
Affected Products : online_booking_\&_scheduling_calendar_for_wordpress_by_vcita- Published: Apr. 04, 2025
- Modified: Jun. 09, 2025
- Vuln Type: Information Disclosure
-
4.3
MEDIUMCVE-2025-30897
Missing Authorization vulnerability in Adnan Analytify allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Analytify: from n/a through 5.5.1.... Read more
Affected Products : analytify_-_google_analytics_dashboard- Published: Mar. 27, 2025
- Modified: Jun. 09, 2025
- Vuln Type: Authorization
-
6.5
MEDIUMCVE-2025-30873
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpsoul Greenshift allows Stored XSS. This issue affects Greenshift: from n/a through 11.0.2.... Read more
- Published: Mar. 27, 2025
- Modified: Jun. 09, 2025
- Vuln Type: Cross-Site Scripting
-
9.1
CRITICALCVE-2025-3461
The Quantenna Wi-Fi chips ship with an unauthenticated telnet interface by default. This is an instance of CWE-306, "Missing Authentication for Critical Function," and is estimated as a CVSS 9.1 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N). This issue a... Read more
Affected Products :- Published: Jun. 08, 2025
- Modified: Jun. 09, 2025
- Vuln Type: Authentication
-
7.7
HIGHCVE-2025-3460
The Quantenna Wi-Fi chipset ships with a local control script, set_tx_pow, that is vulnerable to command injection. This is an instance of CWE-88, "Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')," and is estimated as a ... Read more
Affected Products :- Published: Jun. 08, 2025
- Modified: Jun. 09, 2025
- Vuln Type: Injection
-
7.7
HIGHCVE-2025-3459
The Quantenna Wi-Fi chipset ships with a local control script, transmit_file, that is vulnerable to command injection. This is an instance of CWE-88, "Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')," and is estimated as... Read more
Affected Products :- Published: Jun. 08, 2025
- Modified: Jun. 09, 2025
- Vuln Type: Injection
-
7.7
HIGHCVE-2025-32459
The Quantenna Wi-Fi chipset ships with a local control script, router_command.sh (in the sync_time argument), that is vulnerable to command injection. This is an instance of CWE-88, "Improper Neutralization of Argument Delimiters in a Command ('Argument I... Read more
Affected Products :- Published: Jun. 08, 2025
- Modified: Jun. 09, 2025
- Vuln Type: Injection
-
7.7
HIGHCVE-2025-32458
The Quantenna Wi-Fi chipset ships with a local control script, router_command.sh (in the get_syslog_from_qtn argument), that is vulnerable to command injection. This is an instance of CWE-88, "Improper Neutralization of Argument Delimiters in a Command ('... Read more
Affected Products :- Published: Jun. 08, 2025
- Modified: Jun. 09, 2025
- Vuln Type: Injection
-
7.7
HIGHCVE-2025-32457
The Quantenna Wi-Fi chipset ships with a local control script, router_command.sh (in the get_file_from_qtn argument), that is vulnerable to command injection. This is an instance of CWE-88, "Improper Neutralization of Argument Delimiters in a Command ('Ar... Read more
Affected Products :- Published: Jun. 08, 2025
- Modified: Jun. 09, 2025
- Vuln Type: Injection
-
7.7
HIGHCVE-2025-32456
The Quantenna Wi-Fi chipset ships with a local control script, router_command.sh (in the put_file_to_qtn argument), that is vulnerable to command injection. This is an instance of CWE-88, "Improper Neutralization of Argument Delimiters in a Command ('Argu... Read more
Affected Products :- Published: Jun. 08, 2025
- Modified: Jun. 09, 2025
- Vuln Type: Injection
-
7.7
HIGHCVE-2025-32455
The Quantenna Wi-Fi chipset ships with a local control script, router_command.sh (in the run_cmd argument), that is vulnerable to command injection. This is an instance of CWE-88, "Improper Neutralization of Argument Delimiters in a Command ('Argument Inj... Read more
Affected Products :- Published: Jun. 08, 2025
- Modified: Jun. 09, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2024-24330
TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the port or enable parameter in the setRemoteCfg function.... Read more
- Published: Jan. 30, 2024
- Modified: Jun. 09, 2025
-
5.4
MEDIUMCVE-2024-0589
Cross-site scripting (XSS) vulnerability in the entry overview tab in Devolutions Remote Desktop Manager 2023.3.36 and earlier on Windows allows an attacker with access to a data source to inject a malicious script via a specially crafted input in an entr... Read more
- Published: Jan. 31, 2024
- Modified: Jun. 09, 2025
-
9.8
CRITICALCVE-2023-51210
SQL injection vulnerability in Webkul Bundle Product 6.0.1 allows a remote attacker to execute arbitrary code via the id_product parameters in the UpdateProductQuantity function.... Read more
Affected Products : bundle_product- Published: Jan. 23, 2024
- Modified: Jun. 09, 2025
-
9.0
HIGHCVE-2025-5787
A vulnerability was found in TOTOLINK X15 1.0.0-B20230714.1105. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /boafrm/formWsc of the component HTTP POST Request Handler. The manipulation of the ar... Read more
- Published: Jun. 06, 2025
- Modified: Jun. 09, 2025
- Vuln Type: Memory Corruption