Latest CVE Feed
-
6.7
MEDIUMCVE-2024-45780
A flaw was found in grub2. When reading tar files, grub2 allocates an internal buffer for the file name. However, it fails to properly verify the allocation against possible integer overflows. It's possible to cause the allocation length to overflow with ... Read more
Affected Products : grub2- Published: Mar. 03, 2025
- Modified: Mar. 05, 2025
- Vuln Type: Memory Corruption
-
6.0
MEDIUMCVE-2024-45779
An integer overflow flaw was found in the BFS file system driver in grub2. When reading a file with an indirect extent map, grub2 fails to validate the number of extent entries to be read. A crafted or corrupted BFS filesystem may cause an integer overflo... Read more
Affected Products : grub2- Published: Mar. 03, 2025
- Modified: Mar. 25, 2025
- Vuln Type: Memory Corruption
-
7.1
HIGHCVE-2025-27279
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Flashfader allows Reflected XSS. This issue affects Flashfader: from n/a through 1.1.1.... Read more
Affected Products :- Published: Mar. 03, 2025
- Modified: Mar. 03, 2025
- Vuln Type: Cross-Site Scripting
-
7.1
HIGHCVE-2025-27278
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound AcuGIS Leaflet Maps allows Reflected XSS. This issue affects AcuGIS Leaflet Maps: from n/a through 5.1.1.0.... Read more
Affected Products :- Published: Mar. 03, 2025
- Modified: Mar. 03, 2025
- Vuln Type: Cross-Site Scripting
-
7.1
HIGHCVE-2025-27275
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in andrew_fisher WOO Codice Fiscale allows Reflected XSS. This issue affects WOO Codice Fiscale: from n/a through 1.6.3.... Read more
Affected Products :- Published: Mar. 03, 2025
- Modified: Mar. 03, 2025
- Vuln Type: Cross-Site Scripting
-
4.9
MEDIUMCVE-2025-27274
Path Traversal vulnerability in NotFound GPX Viewer allows Path Traversal. This issue affects GPX Viewer: from n/a through 2.2.11.... Read more
Affected Products : gpx_viewer- Published: Mar. 03, 2025
- Modified: Mar. 03, 2025
- Vuln Type: Path Traversal
-
5.8
MEDIUMCVE-2025-27273
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in winking Affiliate Links Manager allows Reflected XSS. This issue affects Affiliate Links Manager: from n/a through 1.0.... Read more
Affected Products :- Published: Mar. 03, 2025
- Modified: Mar. 03, 2025
- Vuln Type: Cross-Site Scripting
-
7.1
HIGHCVE-2025-27271
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound DB Tables Import/Export allows Reflected XSS. This issue affects DB Tables Import/Export: from n/a through 1.0.1.... Read more
Affected Products :- Published: Mar. 03, 2025
- Modified: Mar. 03, 2025
- Vuln Type: Cross-Site Scripting
-
9.8
CRITICALCVE-2025-27270
Missing Authorization vulnerability in NotFound Residential Address Detection allows Privilege Escalation. This issue affects Residential Address Detection: from n/a through 2.5.4.... Read more
Affected Products :- Published: Mar. 03, 2025
- Modified: Mar. 03, 2025
- Vuln Type: Authorization
-
7.1
HIGHCVE-2025-27269
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound .htaccess Login block allows Reflected XSS. This issue affects .htaccess Login block: from n/a through 0.9a.... Read more
Affected Products :- Published: Mar. 03, 2025
- Modified: Mar. 03, 2025
- Vuln Type: Cross-Site Scripting
-
9.3
CRITICALCVE-2025-27268
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in enituretechnology Small Package Quotes – Worldwide Express Edition allows SQL Injection. This issue affects Small Package Quotes – Worldwide Express Edit... Read more
Affected Products : small_package_quotes- Published: Mar. 03, 2025
- Modified: Mar. 03, 2025
- Vuln Type: Injection
-
7.5
HIGHCVE-2025-27264
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in NotFound Doctor Appointment Booking allows PHP Local File Inclusion. This issue affects Doctor Appointment Booking: from n/a through 1... Read more
Affected Products :- Published: Mar. 03, 2025
- Modified: Mar. 03, 2025
- Vuln Type: Path Traversal
-
8.5
HIGHCVE-2025-27263
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in NotFound Doctor Appointment Booking allows SQL Injection. This issue affects Doctor Appointment Booking: from n/a through 1.0.0.... Read more
Affected Products :- Published: Mar. 03, 2025
- Modified: Mar. 03, 2025
- Vuln Type: Injection
-
8.8
HIGHCVE-2025-26999
Deserialization of Untrusted Data vulnerability in Metagauss ProfileGrid allows Object Injection. This issue affects ProfileGrid : from n/a through 5.9.4.3.... Read more
Affected Products : profilegrid- Published: Mar. 03, 2025
- Modified: Mar. 03, 2025
- Vuln Type: Injection
-
7.1
HIGHCVE-2025-26994
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in softdiscover Zigaform – Price Calculator & Cost Estimation Form Builder Lite allows Stored XSS. This issue affects Zigaform – Price Calculator & Cost Est... Read more
Affected Products : zigaform- Published: Mar. 03, 2025
- Modified: Mar. 03, 2025
- Vuln Type: Cross-Site Scripting
-
7.1
HIGHCVE-2025-26989
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in softdiscover Zigaform – Form Builder Lite allows Stored XSS. This issue affects Zigaform – Form Builder Lite: from n/a through 7.4.2.... Read more
Affected Products : zigaform- Published: Mar. 03, 2025
- Modified: Mar. 03, 2025
- Vuln Type: Cross-Site Scripting
-
9.3
CRITICALCVE-2025-26988
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Cozy Vision SMS Alert Order Notifications – WooCommerce allows SQL Injection. This issue affects SMS Alert Order Notifications – WooCommerce: from n/a th... Read more
Affected Products : sms_alert_order_notifications- Published: Mar. 03, 2025
- Modified: Mar. 03, 2025
- Vuln Type: Injection
-
7.1
HIGHCVE-2025-26984
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Cozy Vision SMS Alert Order Notifications – WooCommerce allows Reflected XSS. This issue affects SMS Alert Order Notifications – WooCommerce: from n/a th... Read more
Affected Products : sms_alert_order_notifications- Published: Mar. 03, 2025
- Modified: Mar. 03, 2025
- Vuln Type: Cross-Site Scripting
-
10.0
CRITICALCVE-2025-26970
Improper Control of Generation of Code ('Code Injection') vulnerability in NotFound Ark Theme Core ark-core allows Code Injection.This issue affects Ark Theme Core: from n/a before 1.71.0.... Read more
Affected Products : the_ark- Published: Mar. 03, 2025
- Modified: Apr. 14, 2025
- Vuln Type: Injection
-
8.8
HIGHCVE-2025-26967
Deserialization of Untrusted Data vulnerability in Stiofan Events Calendar for GeoDirectory allows Object Injection. This issue affects Events Calendar for GeoDirectory: from n/a through 2.3.14.... Read more
Affected Products : events_calendar*- Published: Mar. 03, 2025
- Modified: Mar. 03, 2025
- Vuln Type: Injection