Latest CVE Feed
-
5.4
MEDIUMCVE-2025-1577
A vulnerability, which was classified as problematic, has been found in code-projects Blood Bank System 1.0. Affected by this issue is some unknown functionality of the file /prostatus.php. The manipulation of the argument message leads to cross site scri... Read more
- Published: Feb. 23, 2025
- Modified: Mar. 03, 2025
- Vuln Type: Cross-Site Scripting
-
6.1
MEDIUMCVE-2024-13728
The Accept Donations with PayPal & Stripe plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the rf parameter in all versions up to, and including, 1.4.4 due to insufficient input sanitization and output escaping. This makes it possi... Read more
Affected Products : accept_donations_with_paypal- Published: Feb. 23, 2025
- Modified: Feb. 23, 2025
- Vuln Type: Cross-Site Scripting
-
9.8
CRITICALCVE-2025-1576
A vulnerability classified as critical was found in code-projects Real Estate Property Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /ajax_state.php. The manipulation of the argument StateName as part of Str... Read more
- Published: Feb. 23, 2025
- Modified: Mar. 03, 2025
- Vuln Type: Injection
-
5.3
MEDIUMCVE-2025-1575
A vulnerability classified as problematic has been found in Harpia DiagSystem 12. Affected is an unknown function of the file /diagsystem/PACS/atualatendimento_jpeg.php. The manipulation of the argument cod/codexame leads to improper control of resource i... Read more
Affected Products :- Published: Feb. 23, 2025
- Modified: Feb. 23, 2025
- Vuln Type: Path Traversal
-
7.8
HIGHCVE-2022-28339
Trend Micro HouseCall for Home Networks version 5.3.1302 and below contains an uncontrolled search patch element vulnerability that could allow an attacker with low user privileges to create a malicious DLL that could lead to escalated privileges.... Read more
- Published: Feb. 22, 2025
- Modified: Jul. 29, 2025
- Vuln Type: Misconfiguration
-
8.8
HIGHCVE-2025-27012
Cross-Site Request Forgery (CSRF) vulnerability in a1post A1POST.BG Shipping for Woo allows Privilege Escalation. This issue affects A1POST.BG Shipping for Woo: from n/a through 1.5.1.... Read more
Affected Products :- Published: Feb. 22, 2025
- Modified: Feb. 22, 2025
- Vuln Type: Cross-Site Request Forgery
-
6.5
MEDIUMCVE-2025-26973
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WarfarePlugins Social Warfare allows DOM-Based XSS. This issue affects Social Warfare: from n/a through 4.5.4.... Read more
Affected Products : social_warfare- Published: Feb. 22, 2025
- Modified: Feb. 22, 2025
- Vuln Type: Cross-Site Scripting
-
10.0
CRITICALCVE-2025-26776
Unrestricted Upload of File with Dangerous Type vulnerability in NotFound Chaty Pro allows Upload a Web Shell to a Web Server. This issue affects Chaty Pro: from n/a through 3.3.3.... Read more
Affected Products :- Published: Feb. 22, 2025
- Modified: Feb. 22, 2025
- Vuln Type: Misconfiguration
-
7.1
HIGHCVE-2025-26774
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Rock Solid Responsive Modal Builder for High Conversion – Easy Popups allows Reflected XSS. This issue affects Responsive Modal Builder for High Conversi... Read more
Affected Products :- Published: Feb. 22, 2025
- Modified: Feb. 22, 2025
- Vuln Type: Cross-Site Scripting
-
6.5
MEDIUMCVE-2025-26764
Missing Authorization vulnerability in enituretechnology Distance Based Shipping Calculator allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Distance Based Shipping Calculator: from n/a through 2.0.22.... Read more
Affected Products :- Published: Feb. 22, 2025
- Modified: Feb. 22, 2025
- Vuln Type: Authorization
-
9.8
CRITICALCVE-2025-26763
Deserialization of Untrusted Data vulnerability in MetaSlider Responsive Slider by MetaSlider allows Object Injection. This issue affects Responsive Slider by MetaSlider: from n/a through 3.94.0.... Read more
Affected Products : slider\,_gallery\,_and_carousel- Published: Feb. 22, 2025
- Modified: Feb. 22, 2025
- Vuln Type: Injection
-
7.5
HIGHCVE-2025-26760
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Wow-Company Calculator Builder allows PHP Local File Inclusion. This issue affects Calculator Builder: from n/a through 1.6.2.... Read more
Affected Products : calculator-builder- Published: Feb. 22, 2025
- Modified: Feb. 22, 2025
- Vuln Type: Path Traversal
-
7.5
HIGHCVE-2025-26757
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in FULL SERVICES FULL Customer allows PHP Local File Inclusion. This issue affects FULL Customer: from n/a through 3.1.26.... Read more
Affected Products : full_-_customer- Published: Feb. 22, 2025
- Modified: Feb. 22, 2025
- Vuln Type: Path Traversal
-
7.1
HIGHCVE-2025-26756
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in grimdonkey Magic the Gathering Card Tooltips allows Stored XSS. This issue affects Magic the Gathering Card Tooltips: from n/a through 3.5.0.... Read more
Affected Products :- Published: Feb. 22, 2025
- Modified: Feb. 22, 2025
- Vuln Type: Cross-Site Scripting
-
6.5
MEDIUMCVE-2025-26750
Missing Authorization vulnerability in appsbd Vitepos allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Vitepos: from n/a through 3.1.3.... Read more
Affected Products :- Published: Feb. 22, 2025
- Modified: Feb. 22, 2025
- Vuln Type: Authorization
-
7.8
HIGHCVE-2024-52939
Kernel software installed and running inside a Guest VM may post improper commands to the GPU Firmware to trigger a write data outside the Guest's virtualised GPU memory.... Read more
Affected Products : ddk- Published: Feb. 22, 2025
- Modified: Feb. 24, 2025
- Vuln Type: Memory Corruption
-
3.3
LOWCVE-2024-47896
Kernel software installed and running inside a Guest VM may exploit memory shared with the GPU Firmware to write data outside the Guest's virtualised GPU memory.... Read more
Affected Products : ddk- Published: Feb. 22, 2025
- Modified: Mar. 05, 2025
- Vuln Type: Memory Corruption
-
7.9
HIGHCVE-2024-46975
Kernel software installed and running inside a Guest VM may exploit memory shared with the GPU Firmware to write data into another Guest's virtualised GPU memory.... Read more
Affected Products : ddk- Published: Feb. 22, 2025
- Modified: Feb. 24, 2025
- Vuln Type: Memory Corruption
-
7.3
HIGHCVE-2024-12577
Kernel software installed and running inside a Guest VM may exploit memory shared with the GPU Firmware to write data outside the Guest's virtualised GPU memory.... Read more
Affected Products : ddk- Published: Feb. 22, 2025
- Modified: Mar. 18, 2025
- Vuln Type: Memory Corruption
-
7.2
HIGHCVE-2025-0957
The SMTP for Amazon SES – YaySMTP plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.7.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to... Read more
Affected Products :- Published: Feb. 22, 2025
- Modified: Feb. 22, 2025
- Vuln Type: Cross-Site Scripting