Latest CVE Feed
-
7.5
HIGHCVE-2025-25729
An information disclosure vulnerability in Bosscomm IF740 Firmware versions:11001.7078 & v11001.0000 and System versions: 6.25 & 6.00 allows attackers to obtain hardcoded cleartext credentials via the update or boot process.... Read more
Affected Products :- Published: Feb. 28, 2025
- Modified: Feb. 28, 2025
- Vuln Type: Information Disclosure
-
6.5
MEDIUMCVE-2025-25728
Bosscomm IF740 Firmware versions:11001.7078 & v11001.0000 and System versions: 6.25 & 6.00 were discovered to send communications to the update API in plaintext, allowing attackers to access sensitive information via a man-in-the-middle attack.... Read more
Affected Products :- Published: Feb. 28, 2025
- Modified: Mar. 19, 2025
- Vuln Type: Cryptography
-
6.2
MEDIUMCVE-2025-25727
Bosscomm IF740 Firmware versions:11001.7078 & v11001.0000 and System versions: 6.25 & 6.00 were discovered to store passwords in cleartext.... Read more
Affected Products :- Published: Feb. 28, 2025
- Modified: Mar. 19, 2025
- Vuln Type: Information Disclosure
-
8.1
HIGHCVE-2025-25477
A host header injection vulnerability in SysPass 3.2x allows an attacker to load malicious JS files from an arbitrary domain which would be executed in the victim's browser.... Read more
Affected Products : syspass- Published: Feb. 28, 2025
- Modified: Jul. 09, 2025
- Vuln Type: Misconfiguration
-
8.8
HIGHCVE-2025-1687
The Cardealer theme for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.6.4. This is due to missing nonce validation on the 'update_user_profile' function. This makes it possible for unauthenticated attackers to u... Read more
Affected Products : car_dealer_automotive- Published: Feb. 28, 2025
- Modified: Feb. 28, 2025
- Vuln Type: Cross-Site Request Forgery
-
8.8
HIGHCVE-2025-1682
The Cardealer theme for WordPress is vulnerable to privilege escalation in versions up to, and including, 1.6.4 due to missing capability check on the 'save_settings' function. This makes it possible for authenticated attackers, with subscriber-level acce... Read more
Affected Products : car_dealer_automotive- Published: Feb. 28, 2025
- Modified: Feb. 28, 2025
- Vuln Type: Authorization
-
5.4
MEDIUMCVE-2025-1681
The Cardealer theme for WordPress is vulnerable to unauthorized modification of data and loss of data due to a missing capability check and missing filename sanitization on the demo theme scheme AJAX functions in versions up to, and including, 1.6.4. This... Read more
Affected Products : car_dealer_automotive- Published: Feb. 28, 2025
- Modified: Feb. 28, 2025
- Vuln Type: Authorization
-
8.8
HIGHCVE-2024-12811
The Traveler theme for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.1.8 via the 'hotel_alone_slider' shortcode 'style' attribute. This makes it possible for authenticated attackers, with contributor-level and abo... Read more
Affected Products : traveler- Published: Feb. 28, 2025
- Modified: Feb. 28, 2025
- Vuln Type: Path Traversal
-
5.5
MEDIUMCVE-2025-24832
Arbitrary file overwrite during home directory recovery due to improper symbolic link handling. The following products are affected: Acronis Backup plugin for cPanel & WHM (Linux) before build 1.8.4.866, Acronis Backup plugin for cPanel & WHM (Linux) befo... Read more
Affected Products :- Published: Feb. 27, 2025
- Modified: Feb. 27, 2025
- Vuln Type: Path Traversal
-
9.1
CRITICALCVE-2024-37567
Infoblox NIOS through 8.6.4 has Improper Access Control for Grids.... Read more
Affected Products : nios- Published: Feb. 27, 2025
- Modified: Apr. 10, 2025
- Vuln Type: Authorization
-
9.8
CRITICALCVE-2024-37566
Infoblox NIOS through 8.6.4 has Improper Authentication for Grids.... Read more
Affected Products : nios- Published: Feb. 27, 2025
- Modified: Apr. 10, 2025
- Vuln Type: Authentication
-
9.8
CRITICALCVE-2024-36047
Infoblox NIOS through 8.6.4 and 9.x through 9.0.3 has Improper Input Validation.... Read more
Affected Products : nios- Published: Feb. 27, 2025
- Modified: Apr. 10, 2025
-
9.8
CRITICALCVE-2024-36046
Infoblox NIOS through 8.6.4 executes with more privileges than required.... Read more
Affected Products : nios- Published: Feb. 27, 2025
- Modified: Apr. 10, 2025
- Vuln Type: Authorization
-
9.8
CRITICALCVE-2025-26325
ShopXO 6.4.0 is vulnerable to File Upload in ThemeDataService.php.... Read more
Affected Products : shopxo- Published: Feb. 27, 2025
- Modified: Apr. 10, 2025
-
8.8
HIGHCVE-2025-26264
GeoVision GV-ASWeb with the version 6.1.2.0 or less (fixed in 6.2.0), contains a Remote Code Execution (RCE) vulnerability within its Notification Settings feature. An authenticated attacker with "System Settings" privileges in ASWeb can exploit this flaw... Read more
Affected Products :- Published: Feb. 27, 2025
- Modified: Mar. 19, 2025
- Vuln Type: Authentication
-
4.6
MEDIUMCVE-2025-25730
An issue in Motorola Mobility Droid Razr HD (Model XT926) System Version: 9.18.94.XT926.Verizon.en.US allows physically proximate unauthorized attackers to access USB debugging, leading to control of the host device itself.... Read more
Affected Products :- Published: Feb. 27, 2025
- Modified: Feb. 28, 2025
- Vuln Type: Misconfiguration
-
9.8
CRITICALCVE-2025-25570
Vue Vben Admin 2.10.1 allows unauthorized login to the backend due to an issue with hardcoded credentials.... Read more
Affected Products :- Published: Feb. 27, 2025
- Modified: Feb. 28, 2025
- Vuln Type: Authentication
-
9.8
CRITICALCVE-2024-38292
In Extreme Networks XIQ-SE before 24.2.11, due to a missing access control check, a path traversal is possible, which may lead to privilege escalation.... Read more
Affected Products : xiq-se- Published: Feb. 27, 2025
- Modified: Jul. 11, 2025
- Vuln Type: Path Traversal
-
8.8
HIGHCVE-2024-38291
In XIQ-SE before 24.2.11, a low-privileged user may be able to access admin passwords, which could lead to privilege escalation.... Read more
Affected Products : xiq-se- Published: Feb. 27, 2025
- Modified: Jul. 11, 2025
- Vuln Type: Authorization
-
5.3
MEDIUMCVE-2024-38290
In XIQ-SE before 24.2.11, a server misconfiguration may allow user enumeration when specific conditions are met.... Read more
Affected Products : xiq-se- Published: Feb. 27, 2025
- Modified: Jul. 11, 2025
- Vuln Type: Misconfiguration