Latest CVE Feed
-
5.3
MEDIUMCVE-2024-8682
The JNews - WordPress Newspaper Magazine Blog AMP Theme theme for WordPress is vulnerable to unauthorized user registration in all versions up to, and including, 11.6.6. This is due to the plugin not properly validate if the user can register option is en... Read more
Affected Products :- Published: Mar. 05, 2025
- Modified: Mar. 05, 2025
- Vuln Type: Authentication
-
6.4
MEDIUMCVE-2024-13866
The Simple Notification plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 1.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with admini... Read more
Affected Products :- Published: Mar. 05, 2025
- Modified: Mar. 05, 2025
- Vuln Type: Cross-Site Scripting
-
6.1
MEDIUMCVE-2024-13827
The Razorpay Subscription Button Elementor Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg() and remove_query_arg() functions without appropriate escaping on the URL in all versions up to, and in... Read more
Affected Products :- Published: Mar. 05, 2025
- Modified: Mar. 05, 2025
- Vuln Type: Cross-Site Scripting
-
6.4
MEDIUMCVE-2024-13350
The SearchIQ – The Search Solution plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'siq_searchbox' shortcode in all versions up to, and including, 4.7 due to insufficient input sanitization and output escaping on user su... Read more
Affected Products : searchiq- Published: Mar. 05, 2025
- Modified: May. 26, 2025
- Vuln Type: Cross-Site Scripting
-
9.8
CRITICALCVE-2025-1393
An unauthenticated remote attacker can use hard-coded credentials to gain full administration privileges on the affected product.... Read more
Affected Products :- Published: Mar. 05, 2025
- Modified: Mar. 05, 2025
- Vuln Type: Authentication
-
7.5
HIGHCVE-2025-27685
Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 1.0.735 Application 20.0.1330 allows Configuration File Contains CA & Private Key V-2022-001.... Read more
- Published: Mar. 05, 2025
- Modified: Apr. 15, 2025
- Vuln Type: Misconfiguration
-
7.5
HIGHCVE-2025-27684
Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 1.0.735 Application 20.0.1330 allows Debug Bundle Contains Sensitive Data V-2022-003.... Read more
- Published: Mar. 05, 2025
- Modified: Apr. 15, 2025
- Vuln Type: Information Disclosure
-
8.8
HIGHCVE-2025-27683
Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 1.0.735 Application 20.0.1330 allows Driver Unrestricted Upload of File with Dangerous Type V-2022-006.... Read more
- Published: Mar. 05, 2025
- Modified: Apr. 15, 2025
- Vuln Type: Misconfiguration
-
9.8
CRITICALCVE-2025-27682
Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 1.0.735 Application 20.0.1330 allows Insecure Log Permissions V-2022-005.... Read more
- Published: Mar. 05, 2025
- Modified: Apr. 15, 2025
- Vuln Type: Misconfiguration
-
9.8
CRITICALCVE-2025-27681
Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 1.0.735 Application 20.0.1330 mishandles Client Inter-process Security V-2022-004.... Read more
- Published: Mar. 05, 2025
- Modified: Apr. 15, 2025
-
9.1
CRITICALCVE-2025-27680
Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 1.0.750 Application 20.0.1442 allows Insecure Firmware Image with Insufficient Verification of Data Authenticity V-2024-004.... Read more
- Published: Mar. 05, 2025
- Modified: Apr. 15, 2025
-
6.1
MEDIUMCVE-2025-27679
Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.843 Application 20.0.1923 allows Cross-Site Scripting in Badge Registration V-2023-005.... Read more
- Published: Mar. 05, 2025
- Modified: Apr. 15, 2025
- Vuln Type: Cross-Site Scripting
-
9.8
CRITICALCVE-2025-27678
Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.843 Application 20.0.1923 allows Client Remote Code Execution V-2023-001.... Read more
- Published: Mar. 05, 2025
- Modified: Apr. 15, 2025
-
9.8
CRITICALCVE-2025-27677
Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.843 Application 20.0.1923 allows Symbolic Links For Unprivileged File Interaction V-2022-002.... Read more
- Published: Mar. 05, 2025
- Modified: Apr. 15, 2025
- Vuln Type: Misconfiguration
-
6.1
MEDIUMCVE-2025-27676
Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.843 Application 20.0.1923 allows Cross-Site Scripting in Reports V-2023-002.... Read more
- Published: Mar. 05, 2025
- Modified: Apr. 23, 2025
- Vuln Type: Cross-Site Scripting
-
9.8
CRITICALCVE-2025-27675
Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.843 Application 20.0.1923 allows Vulnerable OpenID Implementation V-2023-004.... Read more
- Published: Mar. 05, 2025
- Modified: Apr. 15, 2025
-
9.8
CRITICALCVE-2025-27674
Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.843 Application 20.0.1923 allows Hardcoded IdP Key V-2023-006.... Read more
- Published: Mar. 05, 2025
- Modified: Apr. 15, 2025
- Vuln Type: Misconfiguration
-
9.1
CRITICALCVE-2025-27673
Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.843 Application 20.0.1923 allows Cookie Returned in Response Body OVE-20230524-0017.... Read more
- Published: Mar. 05, 2025
- Modified: Apr. 01, 2025
- Vuln Type: Information Disclosure
-
9.8
CRITICALCVE-2025-27672
Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.843 Application 20.0.1923 allows OAUTH Security Bypass OVE-20230524-0016.... Read more
- Published: Mar. 05, 2025
- Modified: Apr. 01, 2025
- Vuln Type: Authentication
-
9.8
CRITICALCVE-2025-27671
Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.843 Application 20.0.1923 allows Device Impersonation OVE-20230524-0015.... Read more
- Published: Mar. 05, 2025
- Modified: Apr. 01, 2025