Latest CVE Feed
-
7.1
HIGHCVE-2025-23571
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Internal Links Generator allows Reflected XSS. This issue affects Internal Links Generator: from n/a through 3.51.... Read more
Affected Products :- Published: Feb. 14, 2025
- Modified: Feb. 14, 2025
- Vuln Type: Cross-Site Scripting
-
7.1
HIGHCVE-2025-23568
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in fredsted WP Login Attempt Log allows Reflected XSS. This issue affects WP Login Attempt Log: from n/a through 1.3.... Read more
Affected Products :- Published: Feb. 14, 2025
- Modified: Feb. 14, 2025
- Vuln Type: Cross-Site Scripting
-
6.5
MEDIUMCVE-2025-23534
Missing Authorization vulnerability in Mark Winiarski WPLingo allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects WPLingo: from n/a through 1.1.2.... Read more
Affected Products :- Published: Feb. 14, 2025
- Modified: Feb. 14, 2025
- Vuln Type: Authorization
-
7.1
HIGHCVE-2025-23525
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in kvvaradha Kv Compose Email From Dashboard allows Reflected XSS. This issue affects Kv Compose Email From Dashboard: from n/a through 1.1.... Read more
Affected Products :- Published: Feb. 14, 2025
- Modified: Feb. 14, 2025
- Vuln Type: Cross-Site Scripting
-
7.1
HIGHCVE-2025-23523
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in hoststreamsell HSS Embed Streaming Video allows Reflected XSS. This issue affects HSS Embed Streaming Video: from n/a through 3.23.... Read more
Affected Products :- Published: Feb. 14, 2025
- Modified: Feb. 14, 2025
- Vuln Type: Cross-Site Scripting
-
7.1
HIGHCVE-2025-23492
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CantonBolo WordPress 淘宝客插件 allows Reflected XSS. This issue affects WordPress 淘宝客插件: from n/a through 1.1.2.... Read more
Affected Products :- Published: Feb. 14, 2025
- Modified: Feb. 14, 2025
- Vuln Type: Cross-Site Scripting
-
7.1
HIGHCVE-2025-23474
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Mike Martel Live Dashboard allows Reflected XSS. This issue affects Live Dashboard: from n/a through 0.3.3.... Read more
Affected Products :- Published: Feb. 14, 2025
- Modified: Feb. 14, 2025
- Vuln Type: Cross-Site Scripting
-
7.1
HIGHCVE-2025-23431
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Envato Affiliater allows Reflected XSS. This issue affects Envato Affiliater: from n/a through 1.2.4.... Read more
Affected Products :- Published: Feb. 14, 2025
- Modified: Feb. 14, 2025
- Vuln Type: Cross-Site Scripting
-
7.1
HIGHCVE-2025-23428
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound QMean – WordPress Did You Mean allows Reflected XSS. This issue affects QMean – WordPress Did You Mean: from n/a through 2.0.... Read more
Affected Products :- Published: Feb. 14, 2025
- Modified: Feb. 14, 2025
- Vuln Type: Cross-Site Scripting
-
7.1
HIGHCVE-2025-22705
Cross-Site Request Forgery (CSRF) vulnerability in godthor Disqus Popular Posts allows Reflected XSS. This issue affects Disqus Popular Posts: from n/a through 2.1.1.... Read more
Affected Products :- Published: Feb. 14, 2025
- Modified: Feb. 14, 2025
- Vuln Type: Cross-Site Request Forgery
-
6.3
MEDIUMCVE-2025-22702
Missing Authorization vulnerability in EPC Photography. This issue affects Photography: from n/a through 7.5.2.... Read more
Affected Products :- Published: Feb. 14, 2025
- Modified: Feb. 14, 2025
- Vuln Type: Authorization
-
6.3
MEDIUMCVE-2025-22698
Missing Authorization vulnerability in Ability, Inc Accessibility Suite by Online ADA allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Accessibility Suite by Online ADA: from n/a through 4.16.... Read more
Affected Products : accessibility_suite_by_online_ada- Published: Feb. 14, 2025
- Modified: Feb. 14, 2025
- Vuln Type: Authorization
-
9.9
CRITICALCVE-2025-0867
The standard user uses the run as function to start the MEAC applications with administrative privileges. To ensure that the system can startup on its own, the credentials of the administrator were stored. Consequently, the EPC2 user can execute any comma... Read more
Affected Products :- Published: Feb. 14, 2025
- Modified: Feb. 14, 2025
- Vuln Type: Authorization
-
7.2
HIGHCVE-2024-52500
Missing Authorization vulnerability in monetagwp Monetag Official Plugin allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Monetag Official Plugin: from n/a through 1.1.3.... Read more
Affected Products :- Published: Feb. 14, 2025
- Modified: Feb. 14, 2025
- Vuln Type: Authorization
-
10.0
CRITICALCVE-2024-13152
Authorization Bypass Through User-Controlled SQL Primary Key vulnerability in BSS Software Mobuy Online Machinery Monitoring Panel allows SQL Injection.This issue affects Mobuy Online Machinery Monitoring Panel: before 2.0.... Read more
Affected Products :- Published: Feb. 14, 2025
- Modified: Feb. 14, 2025
- Vuln Type: Authorization
-
5.1
MEDIUMCVE-2025-26524
This vulnerability exists in RupeeWeb trading platform due to missing rate limiting on OTP requests in certain API endpoints. An authenticated remote attacker could exploit this vulnerability by sending multiple OTP request through vulnerable API endpoint... Read more
Affected Products :- Published: Feb. 14, 2025
- Modified: Feb. 14, 2025
- Vuln Type: Authentication
-
7.4
HIGHCVE-2025-26523
This vulnerability exists in RupeeWeb trading platform due to insufficient authorization controls on certain API endpoints handling addition and deletion operations. Successful exploitation of this vulnerability could allow an authenticated remote attacke... Read more
Affected Products :- Published: Feb. 14, 2025
- Modified: Feb. 14, 2025
- Vuln Type: Authorization
-
7.5
HIGHCVE-2025-26522
This vulnerability exists in RupeeWeb trading platform due to improper implementation of OTP validation mechanism in certain API endpoints. A remote attacker with valid credentials could exploit this vulnerability by manipulating API responses. Success... Read more
Affected Products :- Published: Feb. 14, 2025
- Modified: Feb. 14, 2025
- Vuln Type: Authentication
-
6.5
MEDIUMCVE-2025-0821
Bit Assist plugin for WordPress is vulnerable to time-based SQL Injection via the ‘id’ parameter in all versions up to, and including, 1.5.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL... Read more
Affected Products : bit_assist- Published: Feb. 14, 2025
- Modified: Feb. 25, 2025
- Vuln Type: Injection
-
4.9
MEDIUMCVE-2024-13791
Bit Assist plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.5.2 via the downloadResponseFile() function. This makes it possible for authenticated attackers, with Administrator-level access and above, to read the... Read more
Affected Products : bit_assist- Published: Feb. 14, 2025
- Modified: Feb. 25, 2025
- Vuln Type: Path Traversal