Latest CVE Feed
-
8.8
HIGHCVE-2025-1687
The Cardealer theme for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.6.4. This is due to missing nonce validation on the 'update_user_profile' function. This makes it possible for unauthenticated attackers to u... Read more
Affected Products : car_dealer_automotive- Published: Feb. 28, 2025
- Modified: Feb. 28, 2025
- Vuln Type: Cross-Site Request Forgery
-
8.8
HIGHCVE-2025-1682
The Cardealer theme for WordPress is vulnerable to privilege escalation in versions up to, and including, 1.6.4 due to missing capability check on the 'save_settings' function. This makes it possible for authenticated attackers, with subscriber-level acce... Read more
Affected Products : car_dealer_automotive- Published: Feb. 28, 2025
- Modified: Feb. 28, 2025
- Vuln Type: Authorization
-
5.4
MEDIUMCVE-2025-1681
The Cardealer theme for WordPress is vulnerable to unauthorized modification of data and loss of data due to a missing capability check and missing filename sanitization on the demo theme scheme AJAX functions in versions up to, and including, 1.6.4. This... Read more
Affected Products : car_dealer_automotive- Published: Feb. 28, 2025
- Modified: Feb. 28, 2025
- Vuln Type: Authorization
-
8.8
HIGHCVE-2024-12811
The Traveler theme for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.1.8 via the 'hotel_alone_slider' shortcode 'style' attribute. This makes it possible for authenticated attackers, with contributor-level and abo... Read more
Affected Products : traveler- Published: Feb. 28, 2025
- Modified: Feb. 28, 2025
- Vuln Type: Path Traversal
-
5.5
MEDIUMCVE-2025-24832
Arbitrary file overwrite during home directory recovery due to improper symbolic link handling. The following products are affected: Acronis Backup plugin for cPanel & WHM (Linux) before build 1.8.4.866, Acronis Backup plugin for cPanel & WHM (Linux) befo... Read more
Affected Products :- Published: Feb. 27, 2025
- Modified: Feb. 27, 2025
- Vuln Type: Path Traversal
-
9.1
CRITICALCVE-2024-37567
Infoblox NIOS through 8.6.4 has Improper Access Control for Grids.... Read more
Affected Products : nios- Published: Feb. 27, 2025
- Modified: Apr. 10, 2025
- Vuln Type: Authorization
-
9.8
CRITICALCVE-2024-37566
Infoblox NIOS through 8.6.4 has Improper Authentication for Grids.... Read more
Affected Products : nios- Published: Feb. 27, 2025
- Modified: Apr. 10, 2025
- Vuln Type: Authentication
-
9.8
CRITICALCVE-2024-36047
Infoblox NIOS through 8.6.4 and 9.x through 9.0.3 has Improper Input Validation.... Read more
Affected Products : nios- Published: Feb. 27, 2025
- Modified: Apr. 10, 2025
-
9.8
CRITICALCVE-2024-36046
Infoblox NIOS through 8.6.4 executes with more privileges than required.... Read more
Affected Products : nios- Published: Feb. 27, 2025
- Modified: Apr. 10, 2025
- Vuln Type: Authorization
-
9.8
CRITICALCVE-2025-26325
ShopXO 6.4.0 is vulnerable to File Upload in ThemeDataService.php.... Read more
Affected Products : shopxo- Published: Feb. 27, 2025
- Modified: Apr. 10, 2025
-
8.8
HIGHCVE-2025-26264
GeoVision GV-ASWeb with the version 6.1.2.0 or less (fixed in 6.2.0), contains a Remote Code Execution (RCE) vulnerability within its Notification Settings feature. An authenticated attacker with "System Settings" privileges in ASWeb can exploit this flaw... Read more
Affected Products :- Published: Feb. 27, 2025
- Modified: Mar. 19, 2025
- Vuln Type: Authentication
-
4.6
MEDIUMCVE-2025-25730
An issue in Motorola Mobility Droid Razr HD (Model XT926) System Version: 9.18.94.XT926.Verizon.en.US allows physically proximate unauthorized attackers to access USB debugging, leading to control of the host device itself.... Read more
Affected Products :- Published: Feb. 27, 2025
- Modified: Feb. 28, 2025
- Vuln Type: Misconfiguration
-
9.8
CRITICALCVE-2025-25570
Vue Vben Admin 2.10.1 allows unauthorized login to the backend due to an issue with hardcoded credentials.... Read more
Affected Products :- Published: Feb. 27, 2025
- Modified: Feb. 28, 2025
- Vuln Type: Authentication
-
9.8
CRITICALCVE-2024-38292
In Extreme Networks XIQ-SE before 24.2.11, due to a missing access control check, a path traversal is possible, which may lead to privilege escalation.... Read more
Affected Products : xiq-se- Published: Feb. 27, 2025
- Modified: Jul. 11, 2025
- Vuln Type: Path Traversal
-
8.8
HIGHCVE-2024-38291
In XIQ-SE before 24.2.11, a low-privileged user may be able to access admin passwords, which could lead to privilege escalation.... Read more
Affected Products : xiq-se- Published: Feb. 27, 2025
- Modified: Jul. 11, 2025
- Vuln Type: Authorization
-
5.3
MEDIUMCVE-2024-38290
In XIQ-SE before 24.2.11, a server misconfiguration may allow user enumeration when specific conditions are met.... Read more
Affected Products : xiq-se- Published: Feb. 27, 2025
- Modified: Jul. 11, 2025
- Vuln Type: Misconfiguration
-
9.8
CRITICALCVE-2024-55160
GFast between v2 to v3.2 was discovered to contain a SQL injection vulnerability via the OrderBy parameter at /system/operLog/list.... Read more
Affected Products : gfast- Published: Feb. 27, 2025
- Modified: Jul. 07, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2024-51139
Buffer Overflow vulnerability in Vigor2620/LTE200 3.9.8.9 and earlier and Vigor2860/2925 3.9.8 and earlier and Vigor2862/2926 3.9.9.5 and earlier and Vigor2133/2762/2832 3.9.9 and earlier and Vigor165/166 4.2.7 and earlier and Vigor2135/2765/2766 4.4.5.1 ... Read more
Affected Products : vigor2860_firmware vigor2832_firmware vigor2766_firmware vigor2765_firmware vigor2763_firmware vigor2762_firmware vigor2135_firmware vigor2133_firmware vigor2620_firmware vigor2925_firmware +36 more products- Published: Feb. 27, 2025
- Modified: May. 28, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2024-51138
Vigor165/166 4.2.7 and earlier; Vigor2620/LTE200 3.9.8.9 and earlier; Vigor2860/2925 3.9.8 and earlier; Vigor2862/2926 3.9.9.5 and earlier; Vigor2133/2762/2832 3.9.9 and earlier; Vigor2135/2765/2766 4.4.5. and earlier; Vigor2865/2866/2927 4.4.5.3 and earl... Read more
Affected Products : vigor2860_firmware vigor2832_firmware vigor2766_firmware vigor2765_firmware vigor2763_firmware vigor2762_firmware vigor2135_firmware vigor2133_firmware vigor2620_firmware vigor2925_firmware +36 more products- Published: Feb. 27, 2025
- Modified: May. 28, 2025
- Vuln Type: Memory Corruption
-
8.4
HIGHCVE-2024-41340
An issue in Draytek devices Vigor 165/166 prior to v4.2.6 , Vigor 2620/LTE200 prior to v3.9.8.8, Vigor 2860/2925 prior to v3.9.7, Vigor 2862/2926 prior to v3.9.9.4, Vigor 2133/2762/2832 prior to v3.9.8, Vigor 2135/2765/2766 prior to v4.4.5.1, Vigor 2865/2... Read more
Affected Products : vigor2860_firmware vigor2832_firmware vigor2766_firmware vigor2765_firmware vigor2762_firmware vigor2135_firmware vigor2133_firmware vigor166_firmware vigor165_firmware vigor2620_firmware +30 more products- Published: Feb. 27, 2025
- Modified: Jun. 03, 2025
- Vuln Type: Misconfiguration