Latest CVE Feed
-
5.3
MEDIUMCVE-2024-45659
IBM Security Verify Access Appliance and Container 10.0.0 through 10.0.8 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned. This information could be used in further attacks against the syste... Read more
- Published: Feb. 04, 2025
- Modified: Aug. 05, 2025
- Vuln Type: Information Disclosure
-
9.9
CRITICALCVE-2025-24677
Improper Control of Generation of Code ('Code Injection') vulnerability in WPSpins Post/Page Copying Tool allows Remote Code Inclusion. This issue affects Post/Page Copying Tool: from n/a through 2.0.3.... Read more
Affected Products :- Published: Feb. 04, 2025
- Modified: Feb. 04, 2025
- Vuln Type: Injection
-
7.5
HIGHCVE-2025-24648
Incorrect Privilege Assignment vulnerability in wpase.com Admin and Site Enhancements (ASE) allows Privilege Escalation. This issue affects Admin and Site Enhancements (ASE): from n/a through 7.6.2.1.... Read more
Affected Products :- Published: Feb. 04, 2025
- Modified: Feb. 04, 2025
-
7.1
HIGHCVE-2025-24602
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP24 WP24 Domain Check allows Reflected XSS. This issue affects WP24 Domain Check: from n/a through 1.10.14.... Read more
Affected Products :- Published: Feb. 04, 2025
- Modified: Feb. 04, 2025
- Vuln Type: Cross-Site Scripting
-
7.1
HIGHCVE-2025-24599
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Tribulant Newsletters allows Reflected XSS. This issue affects Newsletters: from n/a through 4.9.9.6.... Read more
Affected Products : newsletters- Published: Feb. 04, 2025
- Modified: Feb. 04, 2025
-
7.1
HIGHCVE-2025-24598
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in brandtoss WP Mailster allows Reflected XSS. This issue affects WP Mailster: from n/a through 1.8.17.0.... Read more
Affected Products : wp_mailster- Published: Feb. 04, 2025
- Modified: Feb. 11, 2025
-
7.1
HIGHCVE-2025-23645
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Optimize Worldwide Find Content IDs allows Reflected XSS. This issue affects Find Content IDs: from n/a through 1.0.... Read more
Affected Products :- Published: Feb. 04, 2025
- Modified: Feb. 04, 2025
- Vuln Type: Cross-Site Scripting
-
7.1
HIGHCVE-2025-22794
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Landoweb Programador World Cup Predictor allows Reflected XSS. This issue affects World Cup Predictor: from n/a through 1.9.6.... Read more
Affected Products :- Published: Feb. 04, 2025
- Modified: Feb. 18, 2025
- Vuln Type: Cross-Site Scripting
-
6.5
MEDIUMCVE-2025-22730
Missing Authorization vulnerability in Ksher Ksher allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Ksher: from n/a through 1.1.2.... Read more
Affected Products :- Published: Feb. 04, 2025
- Modified: Feb. 18, 2025
- Vuln Type: Authorization
-
8.5
HIGHCVE-2025-22700
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in NotFound Traveler Code. This issue affects Traveler Code: from n/a through 3.1.0.... Read more
Affected Products :- Published: Feb. 04, 2025
- Modified: Feb. 04, 2025
- Vuln Type: Injection
-
9.0
CRITICALCVE-2025-22699
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in NotFound Traveler Code. This issue affects Traveler Code: from n/a through 3.1.0.... Read more
Affected Products :- Published: Feb. 04, 2025
- Modified: Feb. 18, 2025
- Vuln Type: Injection
-
6.5
MEDIUMCVE-2025-22697
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CyberChimps Responsive Blocks allows Reflected XSS. This issue affects Responsive Blocks: from n/a through 1.9.9.... Read more
Affected Products : responsive_blocks- Published: Feb. 04, 2025
- Modified: Feb. 25, 2025
- Vuln Type: Cross-Site Scripting
-
5.4
MEDIUMCVE-2025-22696
Missing Authorization vulnerability in EmbedPress Document Block – Upload & Embed Docs. This issue affects Document Block – Upload & Embed Docs: from n/a through 1.1.0.... Read more
Affected Products :- Published: Feb. 04, 2025
- Modified: Feb. 04, 2025
- Vuln Type: Authorization
-
6.5
MEDIUMCVE-2025-22675
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in bPlugins Alert Box Block – Display notice/alerts in the front end allows Stored XSS. This issue affects Alert Box Block – Display notice/alerts in the fr... Read more
Affected Products :- Published: Feb. 04, 2025
- Modified: Feb. 18, 2025
- Vuln Type: Cross-Site Scripting
-
6.5
MEDIUMCVE-2025-22674
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Get Bowtied Product Blocks for WooCommerce allows Stored XSS. This issue affects Product Blocks for WooCommerce: from n/a through 1.9.1.... Read more
Affected Products :- Published: Feb. 04, 2025
- Modified: Feb. 18, 2025
- Vuln Type: Cross-Site Scripting
-
5.9
MEDIUMCVE-2025-22664
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Survey Maker team Survey Maker allows Stored XSS. This issue affects Survey Maker: from n/a through 5.1.3.5.... Read more
Affected Products : survey_maker- Published: Feb. 04, 2025
- Modified: Apr. 18, 2025
- Vuln Type: Cross-Site Scripting
-
6.5
MEDIUMCVE-2025-22662
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in SendPulse SendPulse Email Marketing Newsletter allows Stored XSS. This issue affects SendPulse Email Marketing Newsletter: from n/a through 2.1.5.... Read more
Affected Products : sendpulse_email_marketing_newsletter- Published: Feb. 04, 2025
- Modified: Feb. 18, 2025
- Vuln Type: Cross-Site Scripting
-
6.5
MEDIUMCVE-2025-22653
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in templaza Music Press Pro allows Stored XSS. This issue affects Music Press Pro: from n/a through 1.4.6.... Read more
Affected Products :- Published: Feb. 04, 2025
- Modified: Feb. 18, 2025
- Vuln Type: Cross-Site Scripting
-
4.3
MEDIUMCVE-2025-22643
Missing Authorization vulnerability in FameThemes OnePress allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects OnePress: from n/a through 2.3.11.... Read more
Affected Products :- Published: Feb. 04, 2025
- Modified: Feb. 18, 2025
- Vuln Type: Authorization
-
6.5
MEDIUMCVE-2025-22642
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in RTO GmbH Dynamic Conditions allows Stored XSS. This issue affects Dynamic Conditions: from n/a through 1.7.4.... Read more
Affected Products :- Published: Feb. 04, 2025
- Modified: Feb. 18, 2025
- Vuln Type: Cross-Site Scripting