Latest CVE Feed
-
9.8
CRITICALCVE-2025-29411
An arbitrary file upload vulnerability in the Client Profile Update section of Mart Developers iBanking v2.0.0 allows attackers to execute arbitrary code via uploading a crafted PHP file.... Read more
Affected Products : ibanking- Published: Mar. 20, 2025
- Modified: Mar. 28, 2025
- Vuln Type: Authentication
-
6.1
MEDIUMCVE-2024-48591
Inflectra SpiraTeam 7.2.00 is vulnerable to Cross Site Scripting (XSS). A specially crafted SVG file can be uploaded that will render and execute JavaScript upon direct viewing.... Read more
Affected Products : spirateam- Published: Mar. 20, 2025
- Modified: Apr. 01, 2025
- Vuln Type: Cross-Site Scripting
-
4.8
MEDIUMCVE-2025-29412
A cross-site scripting (XSS) vulnerability in the Client Profile Update section of Mart Developers iBanking v2.0.0 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Name parameter.... Read more
Affected Products : ibanking- Published: Mar. 20, 2025
- Modified: Apr. 01, 2025
- Vuln Type: Cross-Site Scripting
-
6.1
MEDIUMCVE-2025-29410
A cross-site scripting (XSS) vulnerability in the component /contact.php of Hospital Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the txtEmail parameter.... Read more
Affected Products : hospital_management_system- Published: Mar. 20, 2025
- Modified: Apr. 01, 2025
- Vuln Type: Cross-Site Scripting
-
6.5
MEDIUMCVE-2025-1496
Improper Restriction of Excessive Authentication Attempts vulnerability in BG-TEK Coslat Hotspot allows Password Brute Forcing, Authentication Abuse.This issue affects Coslat Hotspot: before 6.26.0.R.20250227.... Read more
Affected Products :- Published: Mar. 20, 2025
- Modified: Mar. 20, 2025
- Vuln Type: Authentication
-
5.9
MEDIUMCVE-2025-0254
HCL Digital Experience components Ring API and dxclient may be vulnerable to man-in-the-middle (MitM) attacks prior to 9.5 CF226. An attacker could intercept and potentially alter communication between two parties.... Read more
Affected Products : digital_experience- Published: Mar. 20, 2025
- Modified: Mar. 20, 2025
- Vuln Type: Cryptography
-
9.8
CRITICALCVE-2024-48590
Inflectra SpiraTeam 7.2.00 is vulnerable to Server-Side Request Forgery (SSRF) via the NewsReaderService. This allows an attacker to escalate privileges and obtain sensitive information.... Read more
Affected Products : spirateam- Published: Mar. 20, 2025
- Modified: Apr. 01, 2025
- Vuln Type: Server-Side Request Forgery
-
7.5
HIGHCVE-2025-29101
Tenda AC8V4.0 V16.03.34.06 was discovered to contain a stack overflow via the deviceid parameter in the get_parentControl_list_Info function.... Read more
- Published: Mar. 20, 2025
- Modified: Mar. 25, 2025
- Vuln Type: Memory Corruption
-
7.5
HIGHCVE-2025-2539
The File Away plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the ajax() function in all versions up to, and including, 3.9.9.0.1. This makes it possible for unauthenticated attackers, leveraging the ... Read more
Affected Products : file_away- Published: Mar. 20, 2025
- Modified: Aug. 11, 2025
- Vuln Type: Authorization
-
9.0
CRITICALCVE-2025-2311
Incorrect Use of Privileged APIs, Cleartext Transmission of Sensitive Information, Insufficiently Protected Credentials vulnerability in Sechard Information Technologies SecHard allows Authentication Bypass, Interface Manipulation, Authentication Abuse, H... Read more
Affected Products :- Published: Mar. 20, 2025
- Modified: Mar. 21, 2025
- Vuln Type: Authentication
-
5.8
MEDIUMCVE-2025-27888
Severity: medium (5.8) / important Server-Side Request Forgery (SSRF), Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting'), URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Apache Druid. This issue af... Read more
Affected Products : druid- Published: Mar. 20, 2025
- Modified: Jul. 14, 2025
- Vuln Type: Server-Side Request Forgery
-
6.4
MEDIUMCVE-2025-1802
The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘marker_title’, 'notification_content', and 'stt_button_text' parameters in all versions up to, and including, 2.8.3 due to insufficient ... Read more
Affected Products : ht_mega- Published: Mar. 20, 2025
- Modified: Mar. 26, 2025
- Vuln Type: Cross-Site Scripting
-
7.6
HIGHCVE-2024-13923
The Order Export & Order Import for WooCommerce plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 2.6.0 via the validate_file() function. This makes it possible for authenticated attackers, with Admini... Read more
Affected Products : order_export_\&_order_import_for_woocommerce- Published: Mar. 20, 2025
- Modified: Mar. 26, 2025
- Vuln Type: Server-Side Request Forgery
-
6.5
MEDIUMCVE-2024-13922
The Order Export & Order Import for WooCommerce plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the admin_log_page() function in all versions up to, and including, 2.6.0. This makes it possible for... Read more
Affected Products : order_export_\&_order_import_for_woocommerce- Published: Mar. 20, 2025
- Modified: Mar. 26, 2025
- Vuln Type: Path Traversal
-
7.2
HIGHCVE-2024-13921
The Order Export & Order Import for WooCommerce plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.6.0 via deserialization of untrusted input from the 'form_data' parameter. This makes it possible for authen... Read more
Affected Products : order_export_\&_order_import_for_woocommerce- Published: Mar. 20, 2025
- Modified: Mar. 26, 2025
- Vuln Type: Authentication
-
4.9
MEDIUMCVE-2024-13920
The Order Export & Order Import for WooCommerce plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.6.0 via the download_file() function. This makes it possible for authenticated attackers, with Administrator-... Read more
Affected Products : order_export_\&_order_import_for_woocommerce- Published: Mar. 20, 2025
- Modified: Mar. 27, 2025
- Vuln Type: Path Traversal
-
7.5
HIGHCVE-2024-13558
The NP Quote Request for WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.9.179 due to missing validation on a user controlled key. This makes it possible for unauthenticated attack... Read more
Affected Products : np_quote_request_for_woocommerce- Published: Mar. 20, 2025
- Modified: Mar. 27, 2025
- Vuln Type: Authorization
-
8.8
HIGHCVE-2025-1796
A vulnerability in langgenius/dify v0.10.1 allows an attacker to take over any account, including administrator accounts, by exploiting a weak pseudo-random number generator (PRNG) used for generating password reset codes. The application uses `random.ran... Read more
- Published: Mar. 20, 2025
- Modified: Jul. 16, 2025
- Vuln Type: Authentication
-
5.5
MEDIUMCVE-2025-1474
In mlflow/mlflow version 2.18, an admin is able to create a new user account without setting a password. This vulnerability could lead to security risks, as accounts without passwords may be susceptible to unauthorized access. Additionally, this issue vio... Read more
Affected Products : mlflow- Published: Mar. 20, 2025
- Modified: Mar. 27, 2025
- Vuln Type: Authentication
-
7.1
HIGHCVE-2025-1473
A Cross-Site Request Forgery (CSRF) vulnerability exists in the Signup feature of mlflow/mlflow versions 2.17.0 to 2.20.1. This vulnerability allows an attacker to create a new account, which may be used to perform unauthorized actions on behalf of the ma... Read more
Affected Products : mlflow- Published: Mar. 20, 2025
- Modified: Aug. 05, 2025
- Vuln Type: Cross-Site Request Forgery