Latest CVE Feed
-
7.5
HIGHCVE-2025-26760
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Wow-Company Calculator Builder allows PHP Local File Inclusion. This issue affects Calculator Builder: from n/a through 1.6.2.... Read more
Affected Products : calculator-builder- Published: Feb. 22, 2025
- Modified: Feb. 22, 2025
- Vuln Type: Path Traversal
-
7.5
HIGHCVE-2025-26757
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in FULL SERVICES FULL Customer allows PHP Local File Inclusion. This issue affects FULL Customer: from n/a through 3.1.26.... Read more
Affected Products : full_-_customer- Published: Feb. 22, 2025
- Modified: Feb. 22, 2025
- Vuln Type: Path Traversal
-
7.1
HIGHCVE-2025-26756
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in grimdonkey Magic the Gathering Card Tooltips allows Stored XSS. This issue affects Magic the Gathering Card Tooltips: from n/a through 3.5.0.... Read more
Affected Products :- Published: Feb. 22, 2025
- Modified: Feb. 22, 2025
- Vuln Type: Cross-Site Scripting
-
6.5
MEDIUMCVE-2025-26750
Missing Authorization vulnerability in appsbd Vitepos allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Vitepos: from n/a through 3.1.3.... Read more
Affected Products :- Published: Feb. 22, 2025
- Modified: Feb. 22, 2025
- Vuln Type: Authorization
-
7.8
HIGHCVE-2024-52939
Kernel software installed and running inside a Guest VM may post improper commands to the GPU Firmware to trigger a write data outside the Guest's virtualised GPU memory.... Read more
Affected Products : ddk- Published: Feb. 22, 2025
- Modified: Feb. 24, 2025
- Vuln Type: Memory Corruption
-
3.3
LOWCVE-2024-47896
Kernel software installed and running inside a Guest VM may exploit memory shared with the GPU Firmware to write data outside the Guest's virtualised GPU memory.... Read more
Affected Products : ddk- Published: Feb. 22, 2025
- Modified: Mar. 05, 2025
- Vuln Type: Memory Corruption
-
7.9
HIGHCVE-2024-46975
Kernel software installed and running inside a Guest VM may exploit memory shared with the GPU Firmware to write data into another Guest's virtualised GPU memory.... Read more
Affected Products : ddk- Published: Feb. 22, 2025
- Modified: Feb. 24, 2025
- Vuln Type: Memory Corruption
-
7.3
HIGHCVE-2024-12577
Kernel software installed and running inside a Guest VM may exploit memory shared with the GPU Firmware to write data outside the Guest's virtualised GPU memory.... Read more
Affected Products : ddk- Published: Feb. 22, 2025
- Modified: Mar. 18, 2025
- Vuln Type: Memory Corruption
-
7.2
HIGHCVE-2025-0957
The SMTP for Amazon SES – YaySMTP plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.7.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to... Read more
Affected Products :- Published: Feb. 22, 2025
- Modified: Feb. 22, 2025
- Vuln Type: Cross-Site Scripting
-
5.3
MEDIUMCVE-2025-1557
A vulnerability, which was classified as problematic, was found in OFCMS 1.1.3. Affected is an unknown function. The manipulation leads to cross-site request forgery. It is possible to launch the attack remotely. The exploit has been disclosed to the publ... Read more
Affected Products : ofcms- Published: Feb. 22, 2025
- Modified: Jun. 04, 2025
- Vuln Type: Cross-Site Request Forgery
-
5.8
MEDIUMCVE-2025-1556
A vulnerability, which was classified as problematic, has been found in westboy CicadasCMS 1.0. This issue affects some unknown processing of the file /system of the component Template Management. The manipulation leads to deserialization. The attack may ... Read more
Affected Products : cicadascms- Published: Feb. 22, 2025
- Modified: Feb. 22, 2025
- Vuln Type: Authentication
-
7.2
HIGHCVE-2025-0953
The SMTP for Sendinblue – YaySMTP plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.1.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to... Read more
Affected Products : yaysmtp- Published: Feb. 22, 2025
- Modified: Mar. 05, 2025
- Vuln Type: Cross-Site Scripting
-
7.2
HIGHCVE-2025-0918
The SMTP for SendGrid – YaySMTP plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.3.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to i... Read more
Affected Products : yaysmtp- Published: Feb. 22, 2025
- Modified: Mar. 05, 2025
- Vuln Type: Cross-Site Scripting
-
7.2
HIGHCVE-2024-13869
The Migration, Backup, Staging – WPvivid Backup & Migration plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'upload_files' function in all versions up to, and including, 0.9.112. This makes it possib... Read more
- Published: Feb. 22, 2025
- Modified: Mar. 05, 2025
- Vuln Type: Authentication
-
0.0
NACVE-2025-21704
In the Linux kernel, the following vulnerability has been resolved: usb: cdc-acm: Check control transfer buffer size before access If the first fragment is shorter than struct usb_cdc_notification, we can't calculate an expected_size. Log an error and d... Read more
Affected Products : linux_kernel- Published: Feb. 22, 2025
- Modified: Mar. 25, 2025
- Vuln Type: Memory Corruption
-
5.1
MEDIUMCVE-2025-1553
A vulnerability was found in pankajindevops scale up to 3633544a00245d3df88b6d13d9b3dd0f411be7f6. It has been classified as problematic. Affected is an unknown function of the file /scale/project. The manipulation of the argument goal leads to cross site ... Read more
Affected Products :- Published: Feb. 22, 2025
- Modified: Feb. 24, 2025
- Vuln Type: Cross-Site Scripting
-
7.5
HIGHCVE-2025-1361
The IP2Location Country Blocker plugin for WordPress is vulnerable to Regular Information Exposure in all versions up to, and including, 2.38.8 due to missing capability checks on the admin_init() function. This makes it possible for unauthenticated attac... Read more
Affected Products : country_blocker- Published: Feb. 22, 2025
- Modified: Feb. 22, 2025
- Vuln Type: Information Disclosure
-
6.4
MEDIUMCVE-2024-13564
The Rife Elementor Extensions & Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Writing Effect Headline shortcode in all versions up to, and including, 1.2.5 due to insufficient input sanitization and output es... Read more
- Published: Feb. 22, 2025
- Modified: Mar. 18, 2025
- Vuln Type: Cross-Site Scripting
-
5.3
MEDIUMCVE-2024-13798
The Post Grid and Gutenberg Blocks – ComboBlocks plugin for WordPress is vulnerable to unauthorized order creation in all versions up to, and including, 2.3.5. This is due to insufficient verification on form fields. This makes it possible for unauthentic... Read more
Affected Products : comboblocks- Published: Feb. 22, 2025
- Modified: Feb. 22, 2025
- Vuln Type: Authentication
-
7.5
HIGHCVE-2024-13474
The LTL Freight Quotes – Purolator Edition plugin for WordPress is vulnerable to SQL Injection via the 'dropship_edit_id' and 'edit_id' parameters in all versions up to, and including, 2.2.3 due to insufficient escaping on the user supplied parameter and ... Read more
Affected Products :- Published: Feb. 22, 2025
- Modified: Feb. 22, 2025
- Vuln Type: Injection