Latest CVE Feed
-
7.1
HIGHCVE-2025-25825
A cross-site scripting (XSS) vulnerability in Emlog Pro v2.5.4 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Titile in the article category section.... Read more
Affected Products : emlog- Published: Feb. 26, 2025
- Modified: Apr. 07, 2025
- Vuln Type: Cross-Site Scripting
-
7.3
HIGHCVE-2025-25823
A cross-site scripting (XSS) vulnerability in Emlog Pro v2.5.4 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the article header at /admin/article.php.... Read more
Affected Products : emlog- Published: Feb. 26, 2025
- Modified: Apr. 07, 2025
- Vuln Type: Cross-Site Scripting
-
5.1
MEDIUMCVE-2025-25818
A cross-site scripting (XSS) vulnerability in Emlog Pro v2.5.4 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the postStrVar function at article_save.php.... Read more
Affected Products : emlog- Published: Feb. 26, 2025
- Modified: Apr. 07, 2025
- Vuln Type: Cross-Site Scripting
-
5.1
MEDIUMCVE-2025-25813
SeaCMS v13.3 was discovered to contain a remote code execution (RCE) vulnerability via the component admin_files.php.... Read more
Affected Products : seacms- Published: Feb. 26, 2025
- Modified: Mar. 28, 2025
-
5.1
MEDIUMCVE-2025-25802
SeaCMS v13.3 was discovered to contain a remote code execution (RCE) vulnerability via the component admin_ip.php.... Read more
Affected Products : seacms- Published: Feb. 26, 2025
- Modified: Mar. 28, 2025
-
5.3
MEDIUMCVE-2025-25800
SeaCMS 13.3 was discovered to contain an arbitrary file read vulnerability in the file_get_contents function at admin_safe_file.php.... Read more
Affected Products : seacms- Published: Feb. 26, 2025
- Modified: Mar. 28, 2025
- Vuln Type: Information Disclosure
-
6.0
MEDIUMCVE-2025-25799
SeaCMS 13.3 was discovered to contain an arbitrary file read vulnerability in the file_get_contents function at admin_safe.php.... Read more
Affected Products : seacms- Published: Feb. 26, 2025
- Modified: Mar. 28, 2025
- Vuln Type: Information Disclosure
-
5.1
MEDIUMCVE-2025-25797
SeaCMS v13.3 was discovered to contain a remote code execution (RCE) vulnerability via the component admin_smtp.php.... Read more
Affected Products : seacms- Published: Feb. 26, 2025
- Modified: Mar. 28, 2025
-
5.1
MEDIUMCVE-2025-25796
SeaCMS v13.3 was discovered to contain a remote code execution (RCE) vulnerability via the component admin_template.php.... Read more
Affected Products : seacms- Published: Feb. 26, 2025
- Modified: Mar. 28, 2025
-
5.1
MEDIUMCVE-2025-25794
SeaCMS v13.3 was discovered to contain a remote code execution (RCE) vulnerability via the component admin_ping.php.... Read more
Affected Products : seacms- Published: Feb. 26, 2025
- Modified: Mar. 28, 2025
-
5.1
MEDIUMCVE-2025-25793
SeaCMS v13.3 was discovered to contain a remote code execution (RCE) vulnerability via the component admin_notify.php.... Read more
Affected Products : seacms- Published: Feb. 26, 2025
- Modified: Mar. 28, 2025
- Vuln Type: Authentication
-
4.4
MEDIUMCVE-2025-25792
SeaCMS v13.3 was discovered to contain a remote code execution (RCE) vulnerability via the isopen parameter at admin_weixin.php.... Read more
Affected Products : seacms- Published: Feb. 26, 2025
- Modified: Mar. 28, 2025
- Vuln Type: Authentication
-
4.4
MEDIUMCVE-2025-25791
An arbitrary file upload vulnerability in the plugin installation feature of YZNCMS v2.0.1 allows attackers to execute arbitrary code via uploading a crafted Zip file.... Read more
Affected Products : yzncms- Published: Feb. 26, 2025
- Modified: Apr. 07, 2025
- Vuln Type: Misconfiguration
-
9.8
CRITICALCVE-2025-25790
An arbitrary file upload vulnerability in the component \controller\LocalTemplate.php of FoxCMS v1.2.5 allows attackers to execute arbitrary code via uploading a crafted Zip file.... Read more
Affected Products : foxcms- Published: Feb. 26, 2025
- Modified: Apr. 09, 2025
- Vuln Type: Authentication
-
9.8
CRITICALCVE-2025-25789
FoxCMS v1.2.5 was discovered to contain a remote code execution (RCE) vulnerability via the index() method at \controller\Sitemap.php.... Read more
Affected Products : foxcms- Published: Feb. 26, 2025
- Modified: Apr. 09, 2025
- Vuln Type: Misconfiguration
-
9.1
CRITICALCVE-2025-25785
JizhiCMS v2.5.4 was discovered to contain a Server-Side Request Forgery (SSRF) via the component \c\PluginsController.php. This vulnerability allows attackers to perform an intranet scan via a crafted request.... Read more
Affected Products : jizhicms- Published: Feb. 26, 2025
- Modified: Apr. 10, 2025
- Vuln Type: Server-Side Request Forgery
-
9.8
CRITICALCVE-2025-25784
An arbitrary file upload vulnerability in the component \c\TemplateController.php of Jizhicms v2.5.4 allows attackers to execute arbitrary code via uploading a crafted Zip file.... Read more
Affected Products : jizhicms- Published: Feb. 26, 2025
- Modified: Apr. 10, 2025
- Vuln Type: Authentication
-
9.8
CRITICALCVE-2025-25783
An arbitrary file upload vulnerability in the component admin\plugin.php of Emlog Pro v2.5.3 allows attackers to execute arbitrary code via uploading a crafted Zip file.... Read more
Affected Products : emlog- Published: Feb. 26, 2025
- Modified: Apr. 07, 2025
- Vuln Type: Misconfiguration
-
5.3
MEDIUMCVE-2025-1716
picklescan before 0.0.21 does not treat 'pip' as an unsafe global. An attacker could craft a malicious model that uses Pickle to pull in a malicious PyPI package (hosted, for example, on pypi.org or GitHub) via `pip.main()`. Because pip is not a restricte... Read more
Affected Products : picklescan- Published: Feb. 26, 2025
- Modified: Mar. 03, 2025
- Vuln Type: Supply Chain
-
5.3
MEDIUMCVE-2025-1249
Missing Authorization vulnerability in Pixelite Events Manager allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Events Manager: from n/a through 6.6.4.1.... Read more
Affected Products : events_manager- Published: Feb. 26, 2025
- Modified: Feb. 26, 2025
- Vuln Type: Authorization