Latest CVE Feed
-
9.8
CRITICALCVE-2025-1475
The WPCOM Member plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 1.7.5. This is due to insufficient verification on the 'user_phone' parameter when logging in. This makes it possible for unauthenticated at... Read more
Affected Products : wpcom_member- Published: Mar. 07, 2025
- Modified: Mar. 07, 2025
- Vuln Type: Authentication
-
8.1
HIGHCVE-2024-13655
The Flex Mag - Responsive WordPress News Theme theme for WordPress is vulnerable to unauthorized modification of data that can lead to a denial of service due to a missing capability check on the propanel_of_ajax_callback() function in all versions up to,... Read more
Affected Products :- Published: Mar. 07, 2025
- Modified: Mar. 07, 2025
- Vuln Type: Authorization
-
7.5
HIGHCVE-2024-13320
The CURCY - WooCommerce Multi Currency - Currency Switcher plugin for WordPress is vulnerable to SQL Injection via the 'wc_filter_price_meta[where]' parameter in all versions up to, and including, 2.3.6 due to insufficient escaping on the user supplied pa... Read more
Affected Products :- Published: Mar. 07, 2025
- Modified: Mar. 07, 2025
- Vuln Type: Injection
-
6.4
MEDIUMCVE-2024-12809
The Wishlist plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wishlist_button' shortcode in all versions up to, and including, 1.0.43 due to insufficient input sanitization and output escaping on user supplied attributes... Read more
Affected Products :- Published: Mar. 07, 2025
- Modified: Mar. 07, 2025
- Vuln Type: Cross-Site Scripting
-
4.5
MEDIUMCVE-2025-27796
ReadWPGImage in WPG in GraphicsMagick before 1.3.46 mishandles palette buffer allocation, resulting in out-of-bounds access to heap memory in ReadBlob.... Read more
Affected Products : graphicsmagick- Published: Mar. 07, 2025
- Modified: Mar. 07, 2025
- Vuln Type: Memory Corruption
-
4.3
MEDIUMCVE-2025-27795
ReadJXLImage in JXL in GraphicsMagick before 1.3.46 lacks image dimension resource limits.... Read more
Affected Products : graphicsmagick- Published: Mar. 07, 2025
- Modified: Mar. 07, 2025
- Vuln Type: Denial of Service
-
9.8
CRITICALCVE-2025-2067
A vulnerability was found in projectworlds Life Insurance Management System 1.0 and classified as critical. This issue affects some unknown processing of the file /search.php. The manipulation of the argument key leads to sql injection. The attack may be ... Read more
Affected Products : life_insurance_management_system- Published: Mar. 07, 2025
- Modified: May. 14, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-2066
A vulnerability has been found in projectworlds Life Insurance Management System 1.0 and classified as critical. This vulnerability affects unknown code of the file /updateAgent.php. The manipulation of the argument agent_id leads to sql injection. The at... Read more
Affected Products : life_insurance_management_system- Published: Mar. 07, 2025
- Modified: May. 14, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-2065
A vulnerability, which was classified as critical, was found in projectworlds Life Insurance Management System 1.0. This affects an unknown part of the file /editAgent.php. The manipulation of the argument agent_id leads to sql injection. It is possible t... Read more
Affected Products : life_insurance_management_system- Published: Mar. 07, 2025
- Modified: May. 14, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-2064
A vulnerability, which was classified as critical, has been found in projectworlds Life Insurance Management System 1.0. Affected by this issue is some unknown functionality of the file /deletePayment.php. The manipulation of the argument recipt_no leads ... Read more
Affected Products : life_insurance_management_system- Published: Mar. 07, 2025
- Modified: May. 14, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-2063
A vulnerability classified as critical was found in projectworlds Life Insurance Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /deleteNominee.php. The manipulation of the argument nominee_id leads to sql inj... Read more
Affected Products : life_insurance_management_system- Published: Mar. 07, 2025
- Modified: May. 14, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-2062
A vulnerability classified as critical has been found in projectworlds Life Insurance Management System 1.0. Affected is an unknown function of the file /clientStatus.php. The manipulation of the argument client_id leads to sql injection. It is possible t... Read more
Affected Products : life_insurance_management_system- Published: Mar. 07, 2025
- Modified: May. 14, 2025
- Vuln Type: Injection
-
6.1
MEDIUMCVE-2025-2061
A vulnerability was found in code-projects Online Ticket Reservation System 1.0. It has been declared as problematic. This vulnerability affects unknown code of the file /passenger.php. The manipulation of the argument name leads to cross site scripting. ... Read more
Affected Products : online_ticket_reservation_system- Published: Mar. 07, 2025
- Modified: May. 28, 2025
- Vuln Type: Cross-Site Scripting
-
9.8
CRITICALCVE-2025-2060
A vulnerability was found in PHPGurukul Emergency Ambulance Hiring Portal 1.0. It has been classified as critical. This affects an unknown part of the file /admin/admin-profile.php. The manipulation of the argument contactnumber leads to sql injection. It... Read more
Affected Products : emergency_ambulance_hiring_portal- Published: Mar. 07, 2025
- Modified: May. 21, 2025
- Vuln Type: Injection
-
4.2
MEDIUMCVE-2025-26708
There is a configuration defect vulnerability in ZTELink 5.4.9 for iOS. This vulnerability is caused by a flaw in the WiFi parameter configuration of the ZTELink. An attacker can obtain unauthorized access to the WiFi service.... Read more
Affected Products :- Published: Mar. 07, 2025
- Modified: Mar. 07, 2025
- Vuln Type: Misconfiguration
-
9.8
CRITICALCVE-2025-2059
A vulnerability was found in PHPGurukul Emergency Ambulance Hiring Portal 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /admin/booking-details.php. The manipulation of the argument ambulanceregnum leads t... Read more
Affected Products : emergency_ambulance_hiring_portal- Published: Mar. 07, 2025
- Modified: May. 21, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-2058
A vulnerability has been found in PHPGurukul Emergency Ambulance Hiring Portal 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /admin/search.php. The manipulation of the argument searchdata leads to s... Read more
Affected Products : emergency_ambulance_hiring_portal- Published: Mar. 07, 2025
- Modified: May. 08, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-2057
A vulnerability, which was classified as critical, was found in PHPGurukul Emergency Ambulance Hiring Portal 1.0. Affected is an unknown function of the file /admin/about-us.php. The manipulation of the argument pagedes leads to sql injection. It is possi... Read more
Affected Products : emergency_ambulance_hiring_portal- Published: Mar. 07, 2025
- Modified: May. 08, 2025
- Vuln Type: Injection
-
7.2
HIGHCVE-2025-2054
A vulnerability was found in code-projects Blood Bank Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /admin/edit_state.php. The manipulation of the argument state_id leads to... Read more
- Published: Mar. 07, 2025
- Modified: May. 21, 2025
- Vuln Type: Injection
-
8.1
HIGHCVE-2025-0749
The Homey theme for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.4.3. This is due to the 'verification_id' value being set to empty, and the not empty check is missing in the dashboard user profile page. This makes ... Read more
Affected Products : homey- Published: Mar. 07, 2025
- Modified: Mar. 07, 2025
- Vuln Type: Authentication