Latest CVE Feed
-
10.0
CRITICALCVE-2025-26776
Unrestricted Upload of File with Dangerous Type vulnerability in NotFound Chaty Pro allows Upload a Web Shell to a Web Server. This issue affects Chaty Pro: from n/a through 3.3.3.... Read more
Affected Products :- Published: Feb. 22, 2025
- Modified: Feb. 22, 2025
- Vuln Type: Misconfiguration
-
7.1
HIGHCVE-2025-26774
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Rock Solid Responsive Modal Builder for High Conversion – Easy Popups allows Reflected XSS. This issue affects Responsive Modal Builder for High Conversi... Read more
Affected Products :- Published: Feb. 22, 2025
- Modified: Feb. 22, 2025
- Vuln Type: Cross-Site Scripting
-
6.5
MEDIUMCVE-2025-26764
Missing Authorization vulnerability in enituretechnology Distance Based Shipping Calculator allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Distance Based Shipping Calculator: from n/a through 2.0.22.... Read more
Affected Products :- Published: Feb. 22, 2025
- Modified: Feb. 22, 2025
- Vuln Type: Authorization
-
9.8
CRITICALCVE-2025-26763
Deserialization of Untrusted Data vulnerability in MetaSlider Responsive Slider by MetaSlider allows Object Injection. This issue affects Responsive Slider by MetaSlider: from n/a through 3.94.0.... Read more
Affected Products : slider\,_gallery\,_and_carousel- Published: Feb. 22, 2025
- Modified: Feb. 22, 2025
- Vuln Type: Injection
-
7.5
HIGHCVE-2025-26760
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Wow-Company Calculator Builder allows PHP Local File Inclusion. This issue affects Calculator Builder: from n/a through 1.6.2.... Read more
Affected Products : calculator-builder- Published: Feb. 22, 2025
- Modified: Feb. 22, 2025
- Vuln Type: Path Traversal
-
7.5
HIGHCVE-2025-26757
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in FULL SERVICES FULL Customer allows PHP Local File Inclusion. This issue affects FULL Customer: from n/a through 3.1.26.... Read more
Affected Products : full_-_customer- Published: Feb. 22, 2025
- Modified: Feb. 22, 2025
- Vuln Type: Path Traversal
-
7.1
HIGHCVE-2025-26756
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in grimdonkey Magic the Gathering Card Tooltips allows Stored XSS. This issue affects Magic the Gathering Card Tooltips: from n/a through 3.5.0.... Read more
Affected Products :- Published: Feb. 22, 2025
- Modified: Feb. 22, 2025
- Vuln Type: Cross-Site Scripting
-
6.5
MEDIUMCVE-2025-26750
Missing Authorization vulnerability in appsbd Vitepos allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Vitepos: from n/a through 3.1.3.... Read more
Affected Products :- Published: Feb. 22, 2025
- Modified: Feb. 22, 2025
- Vuln Type: Authorization
-
7.8
HIGHCVE-2024-52939
Kernel software installed and running inside a Guest VM may post improper commands to the GPU Firmware to trigger a write data outside the Guest's virtualised GPU memory.... Read more
Affected Products : ddk- Published: Feb. 22, 2025
- Modified: Feb. 24, 2025
- Vuln Type: Memory Corruption
-
3.3
LOWCVE-2024-47896
Kernel software installed and running inside a Guest VM may exploit memory shared with the GPU Firmware to write data outside the Guest's virtualised GPU memory.... Read more
Affected Products : ddk- Published: Feb. 22, 2025
- Modified: Mar. 05, 2025
- Vuln Type: Memory Corruption
-
7.9
HIGHCVE-2024-46975
Kernel software installed and running inside a Guest VM may exploit memory shared with the GPU Firmware to write data into another Guest's virtualised GPU memory.... Read more
Affected Products : ddk- Published: Feb. 22, 2025
- Modified: Feb. 24, 2025
- Vuln Type: Memory Corruption
-
7.3
HIGHCVE-2024-12577
Kernel software installed and running inside a Guest VM may exploit memory shared with the GPU Firmware to write data outside the Guest's virtualised GPU memory.... Read more
Affected Products : ddk- Published: Feb. 22, 2025
- Modified: Mar. 18, 2025
- Vuln Type: Memory Corruption
-
7.2
HIGHCVE-2025-0957
The SMTP for Amazon SES – YaySMTP plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.7.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to... Read more
Affected Products :- Published: Feb. 22, 2025
- Modified: Feb. 22, 2025
- Vuln Type: Cross-Site Scripting
-
5.3
MEDIUMCVE-2025-1557
A vulnerability, which was classified as problematic, was found in OFCMS 1.1.3. Affected is an unknown function. The manipulation leads to cross-site request forgery. It is possible to launch the attack remotely. The exploit has been disclosed to the publ... Read more
Affected Products : ofcms- Published: Feb. 22, 2025
- Modified: Jun. 04, 2025
- Vuln Type: Cross-Site Request Forgery
-
5.8
MEDIUMCVE-2025-1556
A vulnerability, which was classified as problematic, has been found in westboy CicadasCMS 1.0. This issue affects some unknown processing of the file /system of the component Template Management. The manipulation leads to deserialization. The attack may ... Read more
Affected Products : cicadascms- Published: Feb. 22, 2025
- Modified: Feb. 22, 2025
- Vuln Type: Authentication
-
7.2
HIGHCVE-2025-0953
The SMTP for Sendinblue – YaySMTP plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.1.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to... Read more
Affected Products : yaysmtp- Published: Feb. 22, 2025
- Modified: Mar. 05, 2025
- Vuln Type: Cross-Site Scripting
-
7.2
HIGHCVE-2025-0918
The SMTP for SendGrid – YaySMTP plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.3.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to i... Read more
Affected Products : yaysmtp- Published: Feb. 22, 2025
- Modified: Mar. 05, 2025
- Vuln Type: Cross-Site Scripting
-
7.2
HIGHCVE-2024-13869
The Migration, Backup, Staging – WPvivid Backup & Migration plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'upload_files' function in all versions up to, and including, 0.9.112. This makes it possib... Read more
- Published: Feb. 22, 2025
- Modified: Mar. 05, 2025
- Vuln Type: Authentication
-
0.0
NACVE-2025-21704
In the Linux kernel, the following vulnerability has been resolved: usb: cdc-acm: Check control transfer buffer size before access If the first fragment is shorter than struct usb_cdc_notification, we can't calculate an expected_size. Log an error and d... Read more
Affected Products : linux_kernel- Published: Feb. 22, 2025
- Modified: Mar. 25, 2025
- Vuln Type: Memory Corruption
-
5.1
MEDIUMCVE-2025-1553
A vulnerability was found in pankajindevops scale up to 3633544a00245d3df88b6d13d9b3dd0f411be7f6. It has been classified as problematic. Affected is an unknown function of the file /scale/project. The manipulation of the argument goal leads to cross site ... Read more
Affected Products :- Published: Feb. 22, 2025
- Modified: Feb. 24, 2025
- Vuln Type: Cross-Site Scripting