Latest CVE Feed
-
7.1
HIGHCVE-2025-30913
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in podpirate Access Areas allows Reflected XSS. This issue affects Access Areas: from n/a through 1.5.19.... Read more
Affected Products :- Published: Apr. 01, 2025
- Modified: Apr. 02, 2025
- Vuln Type: Cross-Site Scripting
-
7.1
HIGHCVE-2025-30906
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Coffee Code Tech Plugin Oficial – Getnet para WooCommerce allows Reflected XSS. This issue affects Plugin Oficial – Getnet para WooCommerce: from n/a thr... Read more
Affected Products :- Published: Apr. 01, 2025
- Modified: Apr. 02, 2025
- Vuln Type: Cross-Site Scripting
-
7.1
HIGHCVE-2025-30905
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ays Pro Secure Copy Content Protection and Content Locking allows Stored XSS. This issue affects Secure Copy Content Protection and Content Locking: from... Read more
Affected Products : secure_copy_content_protection_and_content_locking- Published: Apr. 01, 2025
- Modified: Apr. 02, 2025
- Vuln Type: Cross-Site Scripting
-
8.8
HIGHCVE-2025-30892
Deserialization of Untrusted Data vulnerability in magepeopleteam WpTravelly allows Object Injection. This issue affects WpTravelly: from n/a through 1.8.7.... Read more
Affected Products :- Published: Apr. 01, 2025
- Modified: Apr. 02, 2025
- Vuln Type: Injection
-
5.4
MEDIUMCVE-2025-30853
Missing Authorization vulnerability in ShortPixel ShortPixel Adaptive Images allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects ShortPixel Adaptive Images: from n/a through 3.10.0.... Read more
Affected Products : shortpixel_adaptive_images- Published: Apr. 01, 2025
- Modified: Apr. 02, 2025
- Vuln Type: Authorization
-
7.1
HIGHCVE-2025-30852
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in emotionalonlinestorytelling Oracle Cards Lite allows Reflected XSS. This issue affects Oracle Cards Lite: from n/a through 1.2.1.... Read more
Affected Products :- Published: Apr. 01, 2025
- Modified: Apr. 02, 2025
- Vuln Type: Cross-Site Scripting
-
7.1
HIGHCVE-2025-30844
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Bob Watu Quiz allows Reflected XSS. This issue affects Watu Quiz: from n/a through 3.4.2.... Read more
Affected Products : watu_quiz- Published: Apr. 01, 2025
- Modified: Jul. 17, 2025
- Vuln Type: Cross-Site Scripting
-
9.9
CRITICALCVE-2025-30841
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in adamskaat Countdown & Clock allows Remote Code Inclusion. This issue affects Countdown & Clock: from n/a through 2.8.8.... Read more
Affected Products : countdown_builder- Published: Apr. 01, 2025
- Modified: Apr. 02, 2025
- Vuln Type: Path Traversal
-
8.8
HIGHCVE-2025-30825
Missing Authorization vulnerability in WPClever WPC Smart Linked Products - Upsells & Cross-sells for WooCommerce allows Privilege Escalation. This issue affects WPC Smart Linked Products - Upsells & Cross-sells for WooCommerce: from n/a through 1.3.5.... Read more
Affected Products :- Published: Apr. 01, 2025
- Modified: Apr. 02, 2025
- Vuln Type: Authorization
-
9.3
CRITICALCVE-2025-30807
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Martin Nguyen Next-Cart Store to WooCommerce Migration allows SQL Injection. This issue affects Next-Cart Store to WooCommerce Migration: from n/a throug... Read more
Affected Products :- Published: Apr. 01, 2025
- Modified: Apr. 02, 2025
- Vuln Type: Injection
-
7.1
HIGHCVE-2025-30778
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Vikas Ratudi VForm allows Reflected XSS. This issue affects VForm: from n/a through 3.1.9.... Read more
Affected Products : lifetime_free_drag_\&_drop_contact_form_builder- Published: Apr. 01, 2025
- Modified: Apr. 02, 2025
- Vuln Type: Cross-Site Scripting
-
10.0
CRITICALCVE-2025-30580
Improper Control of Generation of Code ('Code Injection') vulnerability in NotFound DigiWidgets Image Editor allows Remote Code Inclusion. This issue affects DigiWidgets Image Editor: from n/a through 1.10.... Read more
Affected Products :- Published: Apr. 01, 2025
- Modified: Apr. 02, 2025
- Vuln Type: Injection
-
7.1
HIGHCVE-2025-30554
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Frizzly allows Reflected XSS. This issue affects Frizzly: from n/a through 1.1.0.... Read more
Affected Products :- Published: Apr. 01, 2025
- Modified: Apr. 02, 2025
- Vuln Type: Cross-Site Scripting
-
7.5
HIGHCVE-2025-29070
A heap buffer overflow vulnerability has been identified in thesmooth2() in cmsgamma.c in lcms2-2.16 which allows a remote attacker to cause a denial of service. NOTE: the Supplier disputes this because "this is not exploitable as this function is never c... Read more
Affected Products :- Published: Apr. 01, 2025
- Modified: Apr. 04, 2025
- Vuln Type: Denial of Service
-
6.3
MEDIUMCVE-2025-29049
Cross Site Scripting vulnerability in arnog MathLive Versions v0.103.0 and before (fixed in 0.104.0) allows an attacker to execute arbitrary code via the MathLive function.... Read more
Affected Products :- Published: Apr. 01, 2025
- Modified: Apr. 02, 2025
- Vuln Type: Cross-Site Scripting
-
5.9
MEDIUMCVE-2025-29036
An issue in hackathon-starter v.8.1.0 allows a remote attacker to escalate privileges via the user.js component.... Read more
Affected Products :- Published: Apr. 01, 2025
- Modified: Apr. 04, 2025
- Vuln Type: Authentication
-
7.3
HIGHCVE-2025-29033
An issue in BambooHR Build v.25.0210.170831-83b08dd allows a remote attacker to escalate privileges via the /saml/index.php?r=" HTTP GET parameter.... Read more
Affected Products :- Published: Apr. 01, 2025
- Modified: Apr. 04, 2025
- Vuln Type: Authorization
-
5.3
MEDIUMCVE-2024-13941
A vulnerability was found in ouch-org ouch up to 0.3.1. It has been classified as critical. This affects the function ouch::archive::zip::convert_zip_date_time of the file zip.rs. The manipulation of the argument month leads to memory corruption. The atta... Read more
Affected Products :- Published: Apr. 01, 2025
- Modified: Apr. 02, 2025
- Vuln Type: Memory Corruption
-
5.6
MEDIUMCVE-2003-20001
An issue was discovered on Mitel ICP VoIP 3100 devices. When a remote user attempts to log in via TELNET during the login wait time and an external call comes in, the system incorrectly divulges information about the call and any SMDR records generated by... Read more
Affected Products :- Published: Apr. 01, 2025
- Modified: Apr. 04, 2025
- Vuln Type: Information Disclosure
-
7.3
HIGHCVE-2025-29069
A heap buffer overflow vulnerability has been identified in the lcms2-2.16. The vulnerability exists in the UnrollChunkyBytes function in cmspack.c, which is responsible for handling color space transformations. NOTE: this is disputed by the Supplier beca... Read more
Affected Products :- Published: Apr. 01, 2025
- Modified: Apr. 04, 2025
- Vuln Type: Memory Corruption