Latest CVE Feed
-
6.0
MEDIUMCVE-2024-45598
Cacti is an open source performance and fault management framework. Prior to 1.2.29, an administrator can change the `Poller Standard Error Log Path` parameter in either Installation Step 5 or in Configuration->Settings->Paths tab to a local file inside t... Read more
Affected Products : cacti- Published: Jan. 27, 2025
- Modified: Jan. 27, 2025
-
5.9
MEDIUMCVE-2024-38325
IBM Storage Defender 2.0.0 through 2.0.7 on-prem defender-sensor-cmd CLI could allow a remote attacker to obtain sensitive information, caused by sending network requests over an insecure channel. An attacker could exploit this vulnerability to obtain s... Read more
- Published: Jan. 27, 2025
- Modified: Aug. 14, 2025
-
7.5
HIGHCVE-2024-38320
IBM Storage Protect for Virtual Environments: Data Protection for VMware and Storage Protect Backup-Archive Client 8.1.0.0 through 8.1.23.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive informa... Read more
- Published: Jan. 27, 2025
- Modified: Aug. 18, 2025
-
5.4
MEDIUMCVE-2024-37527
IBM OpenPages with Watson 8.3 and 9.0 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials discl... Read more
- Published: Jan. 27, 2025
- Modified: Mar. 11, 2025
-
4.3
MEDIUMCVE-2024-22316
IBM Sterling File Gateway 6.0.0.0 through 6.1.2.5 and 6.2.0.0 through 6.2.0.1 could allow an authenticated user to perform unauthorized actions to another user's data due to improper access controls.... Read more
Affected Products : sterling_file_gateway- Published: Jan. 27, 2025
- Modified: Jan. 27, 2025
-
6.4
MEDIUMCVE-2023-52292
IBM Sterling File Gateway 6.0.0.0 through 6.1.2.5 and 6.2.0.0 through 6.2.0.3 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potential... Read more
Affected Products : sterling_file_gateway- Published: Jan. 27, 2025
- Modified: Jan. 27, 2025
-
4.3
MEDIUMCVE-2023-47159
IBM Sterling File Gateway 6.0.0.0 through 6.1.2.5 and 6.2.0.0 through 6.2.0.1 could allow an authenticated user to enumerate usernames due to an observable discrepancy in request responses.... Read more
Affected Products : sterling_file_gateway- Published: Jan. 27, 2025
- Modified: Jan. 27, 2025
-
7.5
HIGHCVE-2025-24783
** UNSUPPORTED WHEN ASSIGNED ** Incorrect Usage of Seeds in Pseudo-Random Number Generator (PRNG) vulnerability in Apache Cocoon. This issue affects Apache Cocoon: all versions. When a continuation is created, it gets a random identifier. Because the ra... Read more
Affected Products : cocoon- Published: Jan. 27, 2025
- Modified: Jul. 15, 2025
-
8.8
HIGHCVE-2025-24782
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in wpWax Post Grid, Slider & Carousel Ultimate allows PHP Local File Inclusion. This issue affects Post Grid, Slider & Carousel Ultimate:... Read more
Affected Products : post_grid\,_slider_\&_carousel_ultimate- Published: Jan. 27, 2025
- Modified: Jan. 27, 2025
-
5.3
MEDIUMCVE-2025-24747
Missing Authorization vulnerability in Houzez.co Houzez. This issue affects Houzez: from n/a through 3.4.0.... Read more
Affected Products :- Published: Jan. 27, 2025
- Modified: Jan. 27, 2025
-
4.3
MEDIUMCVE-2025-24744
Missing Authorization vulnerability in NotFound Bridge Core. This issue affects Bridge Core: from n/a through 3.3.... Read more
Affected Products : bridge_core- Published: Jan. 27, 2025
- Modified: Jan. 27, 2025
-
4.3
MEDIUMCVE-2025-24743
Missing Authorization vulnerability in Rometheme RomethemeKit For Elementor. This issue affects RomethemeKit For Elementor: from n/a through 1.5.2.... Read more
Affected Products : romethemekit_for_elementor- Published: Jan. 27, 2025
- Modified: Jan. 27, 2025
-
8.8
HIGHCVE-2025-24742
Cross-Site Request Forgery (CSRF) vulnerability in WP Go Maps (formerly WP Google Maps) WP Go Maps. This issue affects WP Go Maps: from n/a through 9.0.40.... Read more
Affected Products : wp_go_maps- Published: Jan. 27, 2025
- Modified: Feb. 11, 2025
-
6.1
MEDIUMCVE-2025-24741
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in KB Support KB Support. This issue affects KB Support: from n/a through 1.6.7.... Read more
- Published: Jan. 27, 2025
- Modified: Feb. 10, 2025
-
4.7
MEDIUMCVE-2025-24740
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in ThimPress LearnPress. This issue affects LearnPress: from n/a through 4.2.7.1.... Read more
Affected Products : learnpress- Published: Jan. 27, 2025
- Modified: Jan. 27, 2025
-
8.8
HIGHCVE-2025-24734
Missing Authorization vulnerability in CodeSolz Better Find and Replace allows Privilege Escalation. This issue affects Better Find and Replace: from n/a through 1.6.7.... Read more
Affected Products : better_find_and_replace- Published: Jan. 27, 2025
- Modified: Jan. 27, 2025
-
7.1
HIGHCVE-2025-24708
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CRM Perks WP Dynamics CRM for Contact Form 7, WPForms, Elementor, Formidable and Ninja Forms allows Reflected XSS. This issue affects WP Dynamics CRM for... Read more
Affected Products :- Published: Jan. 27, 2025
- Modified: Jan. 27, 2025
-
5.9
MEDIUMCVE-2025-24689
Insertion of Sensitive Information into Externally-Accessible File or Directory vulnerability in codection Import and export users and customers allows Retrieve Embedded Sensitive Data. This issue affects Import and export users and customers: from n/a th... Read more
Affected Products : import_and_export_users_and_customers- Published: Jan. 27, 2025
- Modified: Jan. 27, 2025
-
7.1
HIGHCVE-2025-24680
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in WpMultiStoreLocator WP Multi Store Locator allows Reflected XSS. This issue affects WP Multi Store Locator: from n/a through 2.4.7.... Read more
Affected Products : wp_multi_store_locator- Published: Jan. 27, 2025
- Modified: Feb. 25, 2025
-
9.8
CRITICALCVE-2025-24671
Deserialization of Untrusted Data vulnerability in Pdfcrowd Save as PDF plugin by Pdfcrowd allows Object Injection. This issue affects Save as PDF plugin by Pdfcrowd: from n/a through 4.4.0.... Read more
Affected Products : save_as_pdf- Published: Jan. 27, 2025
- Modified: Jan. 27, 2025