Latest CVE Feed
-
5.3
MEDIUMCVE-2024-12610
The School Management System for Wordpress plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the 'mj_smgt_remove_feetype' and 'mj_smgt_remove_category_new' AJAX actions in all versions up to, and includin... Read more
Affected Products : school_management_system- Published: Mar. 07, 2025
- Modified: Jul. 07, 2025
- Vuln Type: Authorization
-
6.5
MEDIUMCVE-2024-12609
The School Management System for Wordpress plugin for WordPress is vulnerable to SQL Injection via the 'view-attendance' page in all versions up to, and including, 92.0.0 due to insufficient escaping on the user supplied parameter and lack of sufficient p... Read more
Affected Products : school_management_system- Published: Mar. 07, 2025
- Modified: Jul. 07, 2025
- Vuln Type: Injection
-
6.5
MEDIUMCVE-2024-12607
The School Management System for Wordpress plugin for WordPress is vulnerable to SQL Injection via the 'id' parameter of the 'mj_smgt_show_event_task' AJAX action in all versions up to, and including, 92.0.0 due to insufficient escaping on the user suppli... Read more
Affected Products : school_management_system- Published: Mar. 07, 2025
- Modified: Jul. 07, 2025
- Vuln Type: Injection
-
7.5
HIGHCVE-2024-12036
The CS Framework plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 6.9 via the get_widget_settings_json() function. This makes it possible for authenticated attackers, with subscriber-level access and above, t... Read more
Affected Products :- Published: Mar. 07, 2025
- Modified: Mar. 07, 2025
- Vuln Type: Information Disclosure
-
8.8
HIGHCVE-2024-12035
The CS Framework plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the cs_widget_file_delete() function in all versions up to, and including, 6.9. This makes it possible for authenticated attackers, ... Read more
Affected Products :- Published: Mar. 07, 2025
- Modified: Mar. 07, 2025
- Vuln Type: Path Traversal
-
7.5
HIGHCVE-2024-10804
The Ultimate Video Player WordPress & WooCommerce Plugin plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 10.0 via the content/downloader.php file. This makes it possible for unauthenticated attackers to read... Read more
Affected Products :- Published: Mar. 07, 2025
- Modified: Mar. 07, 2025
- Vuln Type: Path Traversal
-
9.8
CRITICALCVE-2025-27816
A vulnerability was discovered in the Arctera InfoScale 7.0 through 8.0.2 where a .NET remoting endpoint can be exploited due to the insecure deserialization of potentially untrusted messages. The vulnerability is present in the Windows Plugin_Host servic... Read more
Affected Products :- Published: Mar. 07, 2025
- Modified: Mar. 07, 2025
- Vuln Type: Misconfiguration
-
7.8
HIGHCVE-2025-26331
Dell ThinOS 2411 and prior, contains an Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to arbitrary code ... Read more
- Published: Mar. 07, 2025
- Modified: Jul. 01, 2025
- Vuln Type: Injection
-
8.8
HIGHCVE-2025-1309
The UiPress lite | Effortless custom dashboards, admin themes and pages plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on the uip_save_form_as_option() functi... Read more
Affected Products : uipress_lite- Published: Mar. 07, 2025
- Modified: Mar. 07, 2025
- Vuln Type: Authorization
-
6.4
MEDIUMCVE-2025-0863
The Flexmls® IDX Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'idx_frame' shortcode in all versions up to, and including, 3.14.27 due to insufficient input sanitization and output escaping on user supplied attr... Read more
Affected Products :- Published: Mar. 07, 2025
- Modified: Mar. 07, 2025
- Vuln Type: Cross-Site Scripting
-
7.2
HIGHCVE-2024-13906
The Gallery by BestWebSoft – Customizable Image and Photo Galleries for WordPress plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 4.7.3 via deserialization of untrusted input in the 'import_gallery_from_csv... Read more
Affected Products : gallery- Published: Mar. 07, 2025
- Modified: Mar. 07, 2025
- Vuln Type: Injection
-
7.8
HIGHCVE-2024-12837
Software installed and run as a non-privileged user may conduct improper GPU system calls to corrupt kernel heap memory.... Read more
Affected Products : ddk- Published: Mar. 07, 2025
- Modified: Mar. 07, 2025
- Vuln Type: Memory Corruption
-
5.5
MEDIUMCVE-2024-12576
Software installed and run as a non-privileged user may conduct improper GPU system calls to trigger a crash of the FW running on the GPU freezing graphics output.... Read more
Affected Products : ddk- Published: Mar. 07, 2025
- Modified: Mar. 07, 2025
- Vuln Type: Denial of Service
-
9.8
CRITICALCVE-2025-1475
The WPCOM Member plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 1.7.5. This is due to insufficient verification on the 'user_phone' parameter when logging in. This makes it possible for unauthenticated at... Read more
Affected Products : wpcom_member- Published: Mar. 07, 2025
- Modified: Mar. 07, 2025
- Vuln Type: Authentication
-
8.1
HIGHCVE-2024-13655
The Flex Mag - Responsive WordPress News Theme theme for WordPress is vulnerable to unauthorized modification of data that can lead to a denial of service due to a missing capability check on the propanel_of_ajax_callback() function in all versions up to,... Read more
Affected Products :- Published: Mar. 07, 2025
- Modified: Mar. 07, 2025
- Vuln Type: Authorization
-
7.5
HIGHCVE-2024-13320
The CURCY - WooCommerce Multi Currency - Currency Switcher plugin for WordPress is vulnerable to SQL Injection via the 'wc_filter_price_meta[where]' parameter in all versions up to, and including, 2.3.6 due to insufficient escaping on the user supplied pa... Read more
Affected Products :- Published: Mar. 07, 2025
- Modified: Mar. 07, 2025
- Vuln Type: Injection
-
6.4
MEDIUMCVE-2024-12809
The Wishlist plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wishlist_button' shortcode in all versions up to, and including, 1.0.43 due to insufficient input sanitization and output escaping on user supplied attributes... Read more
Affected Products :- Published: Mar. 07, 2025
- Modified: Mar. 07, 2025
- Vuln Type: Cross-Site Scripting
-
4.5
MEDIUMCVE-2025-27796
ReadWPGImage in WPG in GraphicsMagick before 1.3.46 mishandles palette buffer allocation, resulting in out-of-bounds access to heap memory in ReadBlob.... Read more
Affected Products : graphicsmagick- Published: Mar. 07, 2025
- Modified: Mar. 07, 2025
- Vuln Type: Memory Corruption
-
4.3
MEDIUMCVE-2025-27795
ReadJXLImage in JXL in GraphicsMagick before 1.3.46 lacks image dimension resource limits.... Read more
Affected Products : graphicsmagick- Published: Mar. 07, 2025
- Modified: Mar. 07, 2025
- Vuln Type: Denial of Service
-
9.8
CRITICALCVE-2025-2067
A vulnerability was found in projectworlds Life Insurance Management System 1.0 and classified as critical. This issue affects some unknown processing of the file /search.php. The manipulation of the argument key leads to sql injection. The attack may be ... Read more
Affected Products : life_insurance_management_system- Published: Mar. 07, 2025
- Modified: May. 14, 2025
- Vuln Type: Injection