Latest CVE Feed
-
5.7
MEDIUMCVE-2024-42012
GRAU DATA Blocky before 3.1 stores passwords encrypted rather than hashed. At the login screen, the user's password is compared to the user's decrypted cleartext password. An attacker with Windows admin or debugging rights can therefore steal the user's B... Read more
Affected Products :- Published: Jan. 22, 2025
- Modified: Feb. 04, 2025
- Vuln Type: Cryptography
-
8.8
HIGHCVE-2024-31903
IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.1.2.5 and 6.2.0.0 through 6.2.0.2 allow an attacker on the local network to execute arbitrary code on the system, caused by the deserialization of untrusted data.... Read more
Affected Products : sterling_b2b_integrator- Published: Jan. 22, 2025
- Modified: Mar. 05, 2025
- Vuln Type: Authentication
-
8.6
HIGHCVE-2024-24429
A reachable assertion in the nas_eps_send_emm_to_esm function of Open5GS <= 2.6.4 allows attackers to cause a Denial of Service (DoS) via a crafted NGAP packet.... Read more
Affected Products : open5gs- Published: Jan. 22, 2025
- Modified: Apr. 22, 2025
- Vuln Type: Denial of Service
-
5.1
MEDIUMCVE-2024-10929
In certain circumstances, an issue in Arm Cortex-A57, Cortex-A72 (revisions before r1p0), Cortex-A73 and Cortex-A75 may allow an adversary to gain a weak form of control over the victim's branch history.... Read more
Affected Products :- Published: Jan. 22, 2025
- Modified: Jul. 22, 2025
- Vuln Type: Misconfiguration
-
9.8
CRITICALCVE-2023-37777
A SQL injection vulnerability exists in Synnefo Internet Management Software (IMS) version 2023 and earlier. This vulnerability occurs due to improper input validation in a specific API endpoint parameter allowing an attacker to manipulate SQL queries via... Read more
Affected Products :- Published: Jan. 22, 2025
- Modified: Jan. 31, 2025
- Vuln Type: Injection
-
6.2
MEDIUMCVE-2025-24027
ps_contactinfo, a PrestaShop module for displaying store contact information, has a cross-site scripting (XSS) vulnerability in versions up to and including 3.3.2. This can not be exploited in a fresh install of PrestaShop, only shops made vulnerable by t... Read more
Affected Products : prestashop- Published: Jan. 22, 2025
- Modified: Jan. 22, 2025
- Vuln Type: Cross-Site Scripting
-
7.1
HIGHCVE-2025-23966
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in AlaFalaki a Gateway for Pasargad Bank on WooCommerce allows Reflected XSS. This issue affects a Gateway for Pasargad Bank on WooCommerce: from n/a throug... Read more
Affected Products :- Published: Jan. 22, 2025
- Modified: Jan. 22, 2025
- Vuln Type: Cross-Site Scripting
-
7.1
HIGHCVE-2025-23959
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Linus Lundahl Good Old Gallery allows Reflected XSS. This issue affects Good Old Gallery: from n/a through 2.1.2.... Read more
Affected Products :- Published: Jan. 22, 2025
- Modified: Jan. 22, 2025
- Vuln Type: Cross-Site Scripting
-
10.0
CRITICALCVE-2025-23953
Unrestricted Upload of File with Dangerous Type vulnerability in Innovative Solutions user files allows Upload a Web Shell to a Web Server. This issue affects user files: from n/a through 2.4.2.... Read more
Affected Products :- Published: Jan. 22, 2025
- Modified: Jan. 22, 2025
- Vuln Type: Misconfiguration
-
8.1
HIGHCVE-2025-23949
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Mihajlovic Nenad Improved Sale Badges – Free Version allows PHP Local File Inclusion. This issue affects Improved Sale Badges – Free V... Read more
Affected Products :- Published: Jan. 22, 2025
- Modified: Jan. 22, 2025
- Vuln Type: Path Traversal
-
8.1
HIGHCVE-2025-23948
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in WebArea Background animation blocks allows PHP Local File Inclusion. This issue affects Background animation blocks: from n/a through ... Read more
Affected Products :- Published: Jan. 22, 2025
- Modified: Jan. 22, 2025
- Vuln Type: Path Traversal
-
8.8
HIGHCVE-2025-23944
Deserialization of Untrusted Data vulnerability in WOOEXIM.COM WOOEXIM allows Object Injection. This issue affects WOOEXIM: from n/a through 5.0.0.... Read more
Affected Products : wooexim- Published: Jan. 22, 2025
- Modified: Jan. 22, 2025
- Vuln Type: Injection
-
9.1
CRITICALCVE-2025-23942
Unrestricted Upload of File with Dangerous Type vulnerability in NgocCode WP Load Gallery allows Upload a Web Shell to a Web Server. This issue affects WP Load Gallery: from n/a through 2.1.6.... Read more
Affected Products :- Published: Jan. 22, 2025
- Modified: Jan. 22, 2025
- Vuln Type: Misconfiguration
-
7.5
HIGHCVE-2025-23938
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in NotFound Image Gallery Box by CRUDLab allows PHP Local File Inclusion. This issue affects Image Gallery Box by CRUDLab: from n/a throu... Read more
Affected Products :- Published: Jan. 22, 2025
- Modified: Jan. 22, 2025
- Vuln Type: Path Traversal
-
9.8
CRITICALCVE-2025-23932
Deserialization of Untrusted Data vulnerability in NotFound Quick Count allows Object Injection. This issue affects Quick Count: from n/a through 3.00.... Read more
Affected Products :- Published: Jan. 22, 2025
- Modified: Jan. 22, 2025
- Vuln Type: Injection
-
9.3
CRITICALCVE-2025-23931
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in NotFound WordPress Local SEO allows Blind SQL Injection. This issue affects WordPress Local SEO: from n/a through 2.3.... Read more
Affected Products :- Published: Jan. 22, 2025
- Modified: Jan. 22, 2025
- Vuln Type: Injection
-
9.0
CRITICALCVE-2025-23921
Unrestricted Upload of File with Dangerous Type vulnerability in NotFound Multi Uploader for Gravity Forms allows Upload a Web Shell to a Web Server. This issue affects Multi Uploader for Gravity Forms: from n/a through 1.1.3.... Read more
Affected Products :- Published: Jan. 22, 2025
- Modified: Jan. 22, 2025
- Vuln Type: Misconfiguration
-
9.9
CRITICALCVE-2025-23918
Unrestricted Upload of File with Dangerous Type vulnerability in NotFound Smallerik File Browser allows Upload a Web Shell to a Web Server. This issue affects Smallerik File Browser: from n/a through 1.1.... Read more
Affected Products :- Published: Jan. 22, 2025
- Modified: Jan. 22, 2025
- Vuln Type: Misconfiguration
-
8.5
HIGHCVE-2025-23910
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in NotFound Menus Plus+ allows SQL Injection. This issue affects Menus Plus+: from n/a through 1.9.6.... Read more
Affected Products :- Published: Jan. 22, 2025
- Modified: Jan. 22, 2025
- Vuln Type: Injection
-
7.1
HIGHCVE-2025-23882
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound WP Download Codes allows Reflected XSS. This issue affects WP Download Codes: from n/a through 2.5.4.... Read more
Affected Products :- Published: Jan. 22, 2025
- Modified: Jan. 22, 2025
- Vuln Type: Cross-Site Scripting