Latest CVE Feed
-
6.2
MEDIUMCVE-2025-25727
Bosscomm IF740 Firmware versions:11001.7078 & v11001.0000 and System versions: 6.25 & 6.00 were discovered to store passwords in cleartext.... Read more
Affected Products :- Published: Feb. 28, 2025
- Modified: Mar. 19, 2025
- Vuln Type: Information Disclosure
-
8.1
HIGHCVE-2025-25477
A host header injection vulnerability in SysPass 3.2x allows an attacker to load malicious JS files from an arbitrary domain which would be executed in the victim's browser.... Read more
Affected Products : syspass- Published: Feb. 28, 2025
- Modified: Jul. 09, 2025
- Vuln Type: Misconfiguration
-
8.8
HIGHCVE-2025-1687
The Cardealer theme for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.6.4. This is due to missing nonce validation on the 'update_user_profile' function. This makes it possible for unauthenticated attackers to u... Read more
Affected Products : car_dealer_automotive- Published: Feb. 28, 2025
- Modified: Feb. 28, 2025
- Vuln Type: Cross-Site Request Forgery
-
8.8
HIGHCVE-2025-1682
The Cardealer theme for WordPress is vulnerable to privilege escalation in versions up to, and including, 1.6.4 due to missing capability check on the 'save_settings' function. This makes it possible for authenticated attackers, with subscriber-level acce... Read more
Affected Products : car_dealer_automotive- Published: Feb. 28, 2025
- Modified: Feb. 28, 2025
- Vuln Type: Authorization
-
5.4
MEDIUMCVE-2025-1681
The Cardealer theme for WordPress is vulnerable to unauthorized modification of data and loss of data due to a missing capability check and missing filename sanitization on the demo theme scheme AJAX functions in versions up to, and including, 1.6.4. This... Read more
Affected Products : car_dealer_automotive- Published: Feb. 28, 2025
- Modified: Feb. 28, 2025
- Vuln Type: Authorization
-
8.8
HIGHCVE-2024-12811
The Traveler theme for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.1.8 via the 'hotel_alone_slider' shortcode 'style' attribute. This makes it possible for authenticated attackers, with contributor-level and abo... Read more
Affected Products : traveler- Published: Feb. 28, 2025
- Modified: Feb. 28, 2025
- Vuln Type: Path Traversal
-
5.5
MEDIUMCVE-2025-24832
Arbitrary file overwrite during home directory recovery due to improper symbolic link handling. The following products are affected: Acronis Backup plugin for cPanel & WHM (Linux) before build 1.8.4.866, Acronis Backup plugin for cPanel & WHM (Linux) befo... Read more
Affected Products :- Published: Feb. 27, 2025
- Modified: Feb. 27, 2025
- Vuln Type: Path Traversal
-
9.1
CRITICALCVE-2024-37567
Infoblox NIOS through 8.6.4 has Improper Access Control for Grids.... Read more
Affected Products : nios- Published: Feb. 27, 2025
- Modified: Apr. 10, 2025
- Vuln Type: Authorization
-
9.8
CRITICALCVE-2024-37566
Infoblox NIOS through 8.6.4 has Improper Authentication for Grids.... Read more
Affected Products : nios- Published: Feb. 27, 2025
- Modified: Apr. 10, 2025
- Vuln Type: Authentication
-
9.8
CRITICALCVE-2024-36047
Infoblox NIOS through 8.6.4 and 9.x through 9.0.3 has Improper Input Validation.... Read more
Affected Products : nios- Published: Feb. 27, 2025
- Modified: Apr. 10, 2025
-
9.8
CRITICALCVE-2024-36046
Infoblox NIOS through 8.6.4 executes with more privileges than required.... Read more
Affected Products : nios- Published: Feb. 27, 2025
- Modified: Apr. 10, 2025
- Vuln Type: Authorization
-
9.8
CRITICALCVE-2025-26325
ShopXO 6.4.0 is vulnerable to File Upload in ThemeDataService.php.... Read more
Affected Products : shopxo- Published: Feb. 27, 2025
- Modified: Apr. 10, 2025
-
8.8
HIGHCVE-2025-26264
GeoVision GV-ASWeb with the version 6.1.2.0 or less (fixed in 6.2.0), contains a Remote Code Execution (RCE) vulnerability within its Notification Settings feature. An authenticated attacker with "System Settings" privileges in ASWeb can exploit this flaw... Read more
Affected Products :- Published: Feb. 27, 2025
- Modified: Mar. 19, 2025
- Vuln Type: Authentication
-
4.6
MEDIUMCVE-2025-25730
An issue in Motorola Mobility Droid Razr HD (Model XT926) System Version: 9.18.94.XT926.Verizon.en.US allows physically proximate unauthorized attackers to access USB debugging, leading to control of the host device itself.... Read more
Affected Products :- Published: Feb. 27, 2025
- Modified: Feb. 28, 2025
- Vuln Type: Misconfiguration
-
9.8
CRITICALCVE-2025-25570
Vue Vben Admin 2.10.1 allows unauthorized login to the backend due to an issue with hardcoded credentials.... Read more
Affected Products :- Published: Feb. 27, 2025
- Modified: Feb. 28, 2025
- Vuln Type: Authentication
-
9.8
CRITICALCVE-2024-38292
In Extreme Networks XIQ-SE before 24.2.11, due to a missing access control check, a path traversal is possible, which may lead to privilege escalation.... Read more
Affected Products : xiq-se- Published: Feb. 27, 2025
- Modified: Jul. 11, 2025
- Vuln Type: Path Traversal
-
8.8
HIGHCVE-2024-38291
In XIQ-SE before 24.2.11, a low-privileged user may be able to access admin passwords, which could lead to privilege escalation.... Read more
Affected Products : xiq-se- Published: Feb. 27, 2025
- Modified: Jul. 11, 2025
- Vuln Type: Authorization
-
5.3
MEDIUMCVE-2024-38290
In XIQ-SE before 24.2.11, a server misconfiguration may allow user enumeration when specific conditions are met.... Read more
Affected Products : xiq-se- Published: Feb. 27, 2025
- Modified: Jul. 11, 2025
- Vuln Type: Misconfiguration
-
9.8
CRITICALCVE-2024-55160
GFast between v2 to v3.2 was discovered to contain a SQL injection vulnerability via the OrderBy parameter at /system/operLog/list.... Read more
Affected Products : gfast- Published: Feb. 27, 2025
- Modified: Jul. 07, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2024-51139
Buffer Overflow vulnerability in Vigor2620/LTE200 3.9.8.9 and earlier and Vigor2860/2925 3.9.8 and earlier and Vigor2862/2926 3.9.9.5 and earlier and Vigor2133/2762/2832 3.9.9 and earlier and Vigor165/166 4.2.7 and earlier and Vigor2135/2765/2766 4.4.5.1 ... Read more
Affected Products : vigor2860_firmware vigor2832_firmware vigor2766_firmware vigor2765_firmware vigor2763_firmware vigor2762_firmware vigor2135_firmware vigor2133_firmware vigor2620_firmware vigor2925_firmware +36 more products- Published: Feb. 27, 2025
- Modified: May. 28, 2025
- Vuln Type: Memory Corruption