Latest CVE Feed
-
6.5
MEDIUMCVE-2025-28874
Authorization Bypass Through User-Controlled Key vulnerability in shanebp BP Email Assign Templates allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects BP Email Assign Templates: from n/a through 1.6.... Read more
Affected Products : bp_email_assign_templates- Published: Mar. 11, 2025
- Modified: Apr. 09, 2025
- Vuln Type: Authorization
-
9.8
CRITICALCVE-2025-28872
Missing Authorization vulnerability in jwpegram Block Spam By Math Reloaded allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Block Spam By Math Reloaded: from n/a through 2.2.4.... Read more
Affected Products : block_spam_by_math_reloaded- Published: Mar. 11, 2025
- Modified: Apr. 09, 2025
- Vuln Type: Authorization
-
5.9
MEDIUMCVE-2025-28871
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in jwpegram Block Spam By Math Reloaded allows Stored XSS. This issue affects Block Spam By Math Reloaded: from n/a through 2.2.4.... Read more
Affected Products : block_spam_by_math_reloaded- Published: Mar. 11, 2025
- Modified: Mar. 17, 2025
- Vuln Type: Cross-Site Scripting
-
6.5
MEDIUMCVE-2025-28870
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in amocrm amoCRM WebForm allows DOM-Based XSS. This issue affects amoCRM WebForm: from n/a through 1.1.... Read more
Affected Products : amocrm- Published: Mar. 11, 2025
- Modified: Mar. 18, 2025
- Vuln Type: Cross-Site Scripting
-
8.8
HIGHCVE-2025-28868
Cross-Site Request Forgery (CSRF) vulnerability in ZipList ZipList Recipe allows Cross Site Request Forgery. This issue affects ZipList Recipe: from n/a through 3.1.... Read more
- Published: Mar. 11, 2025
- Modified: Mar. 19, 2025
- Vuln Type: Cross-Site Request Forgery
-
8.8
HIGHCVE-2025-28867
Cross-Site Request Forgery (CSRF) vulnerability in stesvis Frontpage category filter allows Cross Site Request Forgery. This issue affects Frontpage category filter: from n/a through 1.0.2.... Read more
Affected Products : frontpage_category_filter- Published: Mar. 11, 2025
- Modified: Mar. 18, 2025
- Vuln Type: Cross-Site Request Forgery
-
8.8
HIGHCVE-2025-28866
Cross-Site Request Forgery (CSRF) vulnerability in smerriman Login Logger allows Cross Site Request Forgery. This issue affects Login Logger: from n/a through 1.2.1.... Read more
Affected Products : login_logger- Published: Mar. 11, 2025
- Modified: Mar. 19, 2025
- Vuln Type: Cross-Site Request Forgery
-
8.8
HIGHCVE-2025-28864
Cross-Site Request Forgery (CSRF) vulnerability in Planet Studio Builder for Contact Form 7 by Webconstruct allows Cross Site Request Forgery. This issue affects Builder for Contact Form 7 by Webconstruct: from n/a through 1.2.2.... Read more
Affected Products : builder_for_contact_form_7- Published: Mar. 11, 2025
- Modified: Mar. 19, 2025
- Vuln Type: Cross-Site Request Forgery
-
8.8
HIGHCVE-2025-28863
Cross-Site Request Forgery (CSRF) vulnerability in Carlos Minatti Delete Original Image allows Cross Site Request Forgery. This issue affects Delete Original Image: from n/a through 0.4.... Read more
Affected Products : delete_original_image- Published: Mar. 11, 2025
- Modified: Mar. 19, 2025
- Vuln Type: Cross-Site Request Forgery
-
8.8
HIGHCVE-2025-28862
Cross-Site Request Forgery (CSRF) vulnerability in Venugopal Comment Date and Gravatar remover allows Cross Site Request Forgery. This issue affects Comment Date and Gravatar remover: from n/a through 1.0.... Read more
Affected Products : comment_date_and_gravatar_remover- Published: Mar. 11, 2025
- Modified: Mar. 19, 2025
- Vuln Type: Cross-Site Request Forgery
-
7.1
HIGHCVE-2025-28861
Cross-Site Request Forgery (CSRF) vulnerability in bhzad WP jQuery Persian Datepicker allows Stored XSS. This issue affects WP jQuery Persian Datepicker: from n/a through 0.1.0.... Read more
Affected Products : wp_jquery_persian_datepicker- Published: Mar. 11, 2025
- Modified: Mar. 19, 2025
- Vuln Type: Cross-Site Request Forgery
-
7.1
HIGHCVE-2025-28860
Cross-Site Request Forgery (CSRF) vulnerability in PPDPurveyor Google News Editors Picks Feed Generator allows Stored XSS. This issue affects Google News Editors Picks Feed Generator: from n/a through 2.1.... Read more
Affected Products : google_news_editors_picks_feed_generator- Published: Mar. 11, 2025
- Modified: Mar. 19, 2025
-
8.8
HIGHCVE-2025-28859
Cross-Site Request Forgery (CSRF) vulnerability in CodeVibrant Maintenance Notice allows Cross Site Request Forgery. This issue affects Maintenance Notice: from n/a through 1.0.5.... Read more
Affected Products : maintenance_notice- Published: Mar. 11, 2025
- Modified: Mar. 19, 2025
- Vuln Type: Cross-Site Request Forgery
-
7.1
HIGHCVE-2025-28857
Cross-Site Request Forgery (CSRF) vulnerability in rankchecker Rankchecker.io Integration allows Stored XSS. This issue affects Rankchecker.io Integration: from n/a through 1.0.9.... Read more
Affected Products : rankchecker- Published: Mar. 11, 2025
- Modified: Mar. 19, 2025
- Vuln Type: Cross-Site Request Forgery
-
8.8
HIGHCVE-2025-28856
Cross-Site Request Forgery (CSRF) vulnerability in dangrossman W3Counter Free Real-Time Web Stats allows Cross Site Request Forgery. This issue affects W3Counter Free Real-Time Web Stats: from n/a through 4.1.... Read more
Affected Products : w3counter- Published: Mar. 11, 2025
- Modified: Apr. 09, 2025
- Vuln Type: Cross-Site Request Forgery
-
7.8
HIGHCVE-2025-27181
Substance3D - Modeler versions 1.15.0 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must o... Read more
Affected Products : substance_3d_modeler- Published: Mar. 11, 2025
- Modified: Apr. 18, 2025
- Vuln Type: Memory Corruption
-
5.5
MEDIUMCVE-2025-27180
Substance3D - Modeler versions 1.15.0 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this... Read more
Affected Products : substance_3d_modeler- Published: Mar. 11, 2025
- Modified: Apr. 18, 2025
- Vuln Type: Information Disclosure
-
7.8
HIGHCVE-2025-27173
Substance3D - Modeler versions 1.15.0 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a v... Read more
Affected Products : substance_3d_modeler- Published: Mar. 11, 2025
- Modified: Apr. 18, 2025
- Vuln Type: Memory Corruption
-
5.5
MEDIUMCVE-2025-21170
Substance3D - Modeler versions 1.15.0 and earlier are affected by a NULL Pointer Dereference vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading to a denial-of... Read more
Affected Products : substance_3d_modeler- Published: Mar. 11, 2025
- Modified: Apr. 14, 2025
- Vuln Type: Denial of Service
-
3.3
LOWCVE-2025-0900
PDF-XChange Editor PDF File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of PDF-XChange Editor. User interaction is required to expl... Read more
- Published: Mar. 11, 2025
- Modified: Jul. 07, 2025
- Vuln Type: Information Disclosure