Latest CVE Feed
-
5.1
MEDIUMCVE-2024-10929
In certain circumstances, an issue in Arm Cortex-A57, Cortex-A72 (revisions before r1p0), Cortex-A73 and Cortex-A75 may allow an adversary to gain a weak form of control over the victim's branch history.... Read more
Affected Products :- Published: Jan. 22, 2025
- Modified: Jul. 22, 2025
- Vuln Type: Misconfiguration
-
9.8
CRITICALCVE-2023-37777
A SQL injection vulnerability exists in Synnefo Internet Management Software (IMS) version 2023 and earlier. This vulnerability occurs due to improper input validation in a specific API endpoint parameter allowing an attacker to manipulate SQL queries via... Read more
Affected Products :- Published: Jan. 22, 2025
- Modified: Jan. 31, 2025
- Vuln Type: Injection
-
6.2
MEDIUMCVE-2025-24027
ps_contactinfo, a PrestaShop module for displaying store contact information, has a cross-site scripting (XSS) vulnerability in versions up to and including 3.3.2. This can not be exploited in a fresh install of PrestaShop, only shops made vulnerable by t... Read more
Affected Products : prestashop- Published: Jan. 22, 2025
- Modified: Jan. 22, 2025
- Vuln Type: Cross-Site Scripting
-
7.1
HIGHCVE-2025-23966
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in AlaFalaki a Gateway for Pasargad Bank on WooCommerce allows Reflected XSS. This issue affects a Gateway for Pasargad Bank on WooCommerce: from n/a throug... Read more
Affected Products :- Published: Jan. 22, 2025
- Modified: Jan. 22, 2025
- Vuln Type: Cross-Site Scripting
-
7.1
HIGHCVE-2025-23959
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Linus Lundahl Good Old Gallery allows Reflected XSS. This issue affects Good Old Gallery: from n/a through 2.1.2.... Read more
Affected Products :- Published: Jan. 22, 2025
- Modified: Jan. 22, 2025
- Vuln Type: Cross-Site Scripting
-
10.0
CRITICALCVE-2025-23953
Unrestricted Upload of File with Dangerous Type vulnerability in Innovative Solutions user files allows Upload a Web Shell to a Web Server. This issue affects user files: from n/a through 2.4.2.... Read more
Affected Products :- Published: Jan. 22, 2025
- Modified: Jan. 22, 2025
- Vuln Type: Misconfiguration
-
8.1
HIGHCVE-2025-23949
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Mihajlovic Nenad Improved Sale Badges – Free Version allows PHP Local File Inclusion. This issue affects Improved Sale Badges – Free V... Read more
Affected Products :- Published: Jan. 22, 2025
- Modified: Jan. 22, 2025
- Vuln Type: Path Traversal
-
8.1
HIGHCVE-2025-23948
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in WebArea Background animation blocks allows PHP Local File Inclusion. This issue affects Background animation blocks: from n/a through ... Read more
Affected Products :- Published: Jan. 22, 2025
- Modified: Jan. 22, 2025
- Vuln Type: Path Traversal
-
8.8
HIGHCVE-2025-23944
Deserialization of Untrusted Data vulnerability in WOOEXIM.COM WOOEXIM allows Object Injection. This issue affects WOOEXIM: from n/a through 5.0.0.... Read more
Affected Products : wooexim- Published: Jan. 22, 2025
- Modified: Jan. 22, 2025
- Vuln Type: Injection
-
9.1
CRITICALCVE-2025-23942
Unrestricted Upload of File with Dangerous Type vulnerability in NgocCode WP Load Gallery allows Upload a Web Shell to a Web Server. This issue affects WP Load Gallery: from n/a through 2.1.6.... Read more
Affected Products :- Published: Jan. 22, 2025
- Modified: Jan. 22, 2025
- Vuln Type: Misconfiguration
-
7.5
HIGHCVE-2025-23938
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in NotFound Image Gallery Box by CRUDLab allows PHP Local File Inclusion. This issue affects Image Gallery Box by CRUDLab: from n/a throu... Read more
Affected Products :- Published: Jan. 22, 2025
- Modified: Jan. 22, 2025
- Vuln Type: Path Traversal
-
9.8
CRITICALCVE-2025-23932
Deserialization of Untrusted Data vulnerability in NotFound Quick Count allows Object Injection. This issue affects Quick Count: from n/a through 3.00.... Read more
Affected Products :- Published: Jan. 22, 2025
- Modified: Jan. 22, 2025
- Vuln Type: Injection
-
9.3
CRITICALCVE-2025-23931
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in NotFound WordPress Local SEO allows Blind SQL Injection. This issue affects WordPress Local SEO: from n/a through 2.3.... Read more
Affected Products :- Published: Jan. 22, 2025
- Modified: Jan. 22, 2025
- Vuln Type: Injection
-
9.0
CRITICALCVE-2025-23921
Unrestricted Upload of File with Dangerous Type vulnerability in NotFound Multi Uploader for Gravity Forms allows Upload a Web Shell to a Web Server. This issue affects Multi Uploader for Gravity Forms: from n/a through 1.1.3.... Read more
Affected Products :- Published: Jan. 22, 2025
- Modified: Jan. 22, 2025
- Vuln Type: Misconfiguration
-
9.9
CRITICALCVE-2025-23918
Unrestricted Upload of File with Dangerous Type vulnerability in NotFound Smallerik File Browser allows Upload a Web Shell to a Web Server. This issue affects Smallerik File Browser: from n/a through 1.1.... Read more
Affected Products :- Published: Jan. 22, 2025
- Modified: Jan. 22, 2025
- Vuln Type: Misconfiguration
-
8.5
HIGHCVE-2025-23910
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in NotFound Menus Plus+ allows SQL Injection. This issue affects Menus Plus+: from n/a through 1.9.6.... Read more
Affected Products :- Published: Jan. 22, 2025
- Modified: Jan. 22, 2025
- Vuln Type: Injection
-
7.1
HIGHCVE-2025-23882
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound WP Download Codes allows Reflected XSS. This issue affects WP Download Codes: from n/a through 2.5.4.... Read more
Affected Products :- Published: Jan. 22, 2025
- Modified: Jan. 22, 2025
- Vuln Type: Cross-Site Scripting
-
7.1
HIGHCVE-2025-23874
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound WP Block Pack allows Reflected XSS. This issue affects WP Block Pack: from n/a through 1.1.6.... Read more
Affected Products :- Published: Jan. 22, 2025
- Modified: Jan. 22, 2025
- Vuln Type: Cross-Site Scripting
-
7.1
HIGHCVE-2025-23867
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound WordPress File Search allows Reflected XSS. This issue affects WordPress File Search: from n/a through 1.2.... Read more
Affected Products :- Published: Jan. 22, 2025
- Modified: Jan. 22, 2025
- Vuln Type: Cross-Site Scripting
-
7.1
HIGHCVE-2025-23866
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound EU DSGVO Helper allows Reflected XSS. This issue affects EU DSGVO Helper: from n/a through 1.0.6.1.... Read more
Affected Products :- Published: Jan. 22, 2025
- Modified: Jan. 22, 2025
- Vuln Type: Cross-Site Scripting