Latest CVE Feed
-
4.6
MEDIUMCVE-2024-13126
The Download Manager WordPress plugin before 3.3.07 doesn't prevent directory listing on web servers that don't use htaccess, allowing unauthorized access of files.... Read more
- Published: Mar. 16, 2025
- Modified: Apr. 09, 2025
- Vuln Type: Information Disclosure
-
4.2
MEDIUMCVE-2025-24856
An issue was discovered in the oidc (aka OpenID Connect Authentication) extension before 4.0.0 for TYPO3. The account linking logic allows a pre-hijacking attack, leading to Account Takeover. The attack can only be exploited if the following requirements ... Read more
Affected Products :- Published: Mar. 16, 2025
- Modified: Mar. 16, 2025
- Vuln Type: Authentication
-
5.8
MEDIUMCVE-2024-58103
Square Wire before 5.2.0 does not enforce a recursion limit on nested groups in ByteArrayProtoReader32.kt and ProtoReader.kt.... Read more
Affected Products :- Published: Mar. 16, 2025
- Modified: Mar. 16, 2025
- Vuln Type: Denial of Service
-
6.2
MEDIUMCVE-2025-30077
Open Networking Foundation SD-RAN ONOS onos-lib-go 0.10.28 allows an index out-of-range panic in asn1/aper GetBitString via a zero value of numBits.... Read more
Affected Products :- Published: Mar. 16, 2025
- Modified: Mar. 17, 2025
- Vuln Type: Denial of Service
-
7.7
HIGHCVE-2025-30076
Koha before 24.11.02 allows admins to execute arbitrary commands via shell metacharacters in the tools/scheduler.pl report parameter.... Read more
Affected Products : koha- Published: Mar. 16, 2025
- Modified: Mar. 17, 2025
- Vuln Type: Injection
-
7.8
HIGHCVE-2025-30074
Alludo Parallels Desktop before 19.4.2 and 20.x before 20.2.2 for macOS on Intel platforms allows privilege escalation to root via the VM creation routine.... Read more
Affected Products : parallels_desktop- Published: Mar. 16, 2025
- Modified: Mar. 16, 2025
- Vuln Type: Authorization
-
5.1
MEDIUMCVE-2025-2335
A vulnerability classified as problematic was found in Drivin Soluções up to 20250226. This vulnerability affects unknown code of the file /api/school/registerSchool of the component API Handler. The manipulation of the argument message leads to cross sit... Read more
Affected Products :- Published: Mar. 16, 2025
- Modified: Mar. 16, 2025
- Vuln Type: Cross-Site Scripting
-
7.7
HIGHCVE-2022-49737
In X.Org X server 20.11 through 21.1.16, when a client application uses easystroke for mouse gestures, the main thread modifies various data structures used by the input thread without acquiring a lock, aka a race condition. In particular, AttachDevice in... Read more
Affected Products : x_server- Published: Mar. 16, 2025
- Modified: Mar. 17, 2025
- Vuln Type: Race Condition
-
5.5
MEDIUMCVE-2025-2334
A vulnerability classified as problematic has been found in 274056675 springboot-openai-chatgpt e84f6f5. This affects the function deleteChat of the file /api/mjkj-chat/chat/ai/delete/chat of the component Chat History Handler. The manipulation of the arg... Read more
Affected Products :- Published: Mar. 15, 2025
- Modified: Mar. 17, 2025
- Vuln Type: Authorization
-
8.5
HIGHCVE-2025-27281
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in cookforweb All In Menu allows Blind SQL Injection. This issue affects All In Menu: from n/a through 1.1.5.... Read more
Affected Products :- Published: Mar. 15, 2025
- Modified: Mar. 15, 2025
- Vuln Type: Injection
-
8.5
HIGHCVE-2025-26978
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in NotFound FS Poster. This issue affects FS Poster: from n/a through 6.5.8.... Read more
Affected Products :- Published: Mar. 15, 2025
- Modified: Mar. 15, 2025
- Vuln Type: Injection
-
8.5
HIGHCVE-2025-26976
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Aldo Latino PrivateContent. This issue affects PrivateContent: from n/a through 8.11.4.... Read more
Affected Products : privatecontent- Published: Mar. 15, 2025
- Modified: Mar. 15, 2025
- Vuln Type: Injection
-
7.1
HIGHCVE-2025-26972
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound PrivateContent. This issue affects PrivateContent: from n/a through 8.11.5.... Read more
Affected Products : privatecontent- Published: Mar. 15, 2025
- Modified: Mar. 15, 2025
- Vuln Type: Cross-Site Scripting
-
8.3
HIGHCVE-2025-26969
Missing Authorization vulnerability in Aldo Latino PrivateContent. This issue affects PrivateContent: from n/a through 8.11.5.... Read more
Affected Products : privatecontent- Published: Mar. 15, 2025
- Modified: Mar. 15, 2025
- Vuln Type: Authorization
-
8.6
HIGHCVE-2025-26961
Missing Authorization vulnerability in NotFound Fresh Framework allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Fresh Framework: from n/a through 1.70.0.... Read more
Affected Products :- Published: Mar. 15, 2025
- Modified: Mar. 15, 2025
- Vuln Type: Authorization
-
6.3
MEDIUMCVE-2025-26940
Path Traversal vulnerability in NotFound Pie Register Premium. This issue affects Pie Register Premium: from n/a through 3.8.3.2.... Read more
Affected Products :- Published: Mar. 15, 2025
- Modified: Mar. 15, 2025
- Vuln Type: Path Traversal
-
6.5
MEDIUMCVE-2025-26924
Improper Control of Generation of Code ('Code Injection') vulnerability in NotFound Ohio Extra allows Code Injection. This issue affects Ohio Extra: from n/a through 3.4.7.... Read more
Affected Products :- Published: Mar. 15, 2025
- Modified: Mar. 15, 2025
- Vuln Type: Injection
-
8.8
HIGHCVE-2025-26921
Deserialization of Untrusted Data vulnerability in magepeopleteam Booking and Rental Manager allows Object Injection. This issue affects Booking and Rental Manager: from n/a through 2.2.6.... Read more
Affected Products : booking_\&_rental_manager- Published: Mar. 15, 2025
- Modified: Mar. 15, 2025
- Vuln Type: Injection
-
6.5
MEDIUMCVE-2025-26899
Cross-Site Request Forgery (CSRF) vulnerability in Recapture Cart Recovery and Email Marketing Recapture for WooCommerce allows Cross Site Request Forgery. This issue affects Recapture for WooCommerce: from n/a through 1.0.43.... Read more
Affected Products :- Published: Mar. 15, 2025
- Modified: Mar. 15, 2025
-
6.5
MEDIUMCVE-2025-26895
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in maennchen1.de m1.DownloadList allows DOM-Based XSS. This issue affects m1.DownloadList: from n/a through 0.19.... Read more
Affected Products :- Published: Mar. 15, 2025
- Modified: Mar. 15, 2025
- Vuln Type: Cross-Site Scripting