Latest CVE Feed
-
5.4
MEDIUMCVE-2025-24860
Incorrect Authorization vulnerability in Apache Cassandra allowing users to access a datacenter or IP/CIDR groups they should not be able to when using CassandraNetworkAuthorizer or CassandraCIDRAuthorizer. Users with restricted data center access can up... Read more
Affected Products : cassandra- Published: Feb. 04, 2025
- Modified: Jun. 09, 2025
-
9.8
CRITICALCVE-2025-0890
**UNSUPPORTED WHEN ASSIGNED** Insecure default credentials for the Telnet function in the legacy DSL CPE Zyxel VMG4325-B10A firmware version 1.00(AAFR.4)C0_20170615 could allow an attacker to log in to the management interface if the administrators have t... Read more
Affected Products : vmg4325-b10a_firmware- Published: Feb. 04, 2025
- Modified: Feb. 04, 2025
-
5.3
MEDIUMCVE-2024-27137
In Apache Cassandra it is possible for a local attacker without access to the Apache Cassandra process or configuration files to manipulate the RMI registry to perform a man-in-the-middle attack and capture user names and passwords used to access the J... Read more
Affected Products : cassandra- Published: Feb. 04, 2025
- Modified: Jul. 14, 2025
- Vuln Type: Authentication
-
8.8
HIGHCVE-2025-23015
Privilege Defined With Unsafe Actions vulnerability in Apache Cassandra. An user with MODIFY permission ON ALL KEYSPACES can escalate privileges to superuser within a targeted Cassandra cluster via unsafe actions to a system resource. Operators granting d... Read more
Affected Products : cassandra- Published: Feb. 04, 2025
- Modified: Jul. 14, 2025
-
8.8
HIGHCVE-2024-40891
**UNSUPPORTED WHEN ASSIGNED** A post-authentication command injection vulnerability in the management commands of the legacy DSL CPE Zyxel VMG4325-B10A firmware version 1.00(AAFR.4)C0_20170615 could allow an authenticated attacker to execute operating sys... Read more
Affected Products : vmg1312-b10a_firmware vmg4380-b10a_firmware vmg8324-b10a_firmware vmg8924-b10a_firmware sbg3300-n000_firmware sbg3300-nb00_firmware sbg3500-n000_firmware vmg8324-b10a vmg1312-b10a vmg4380-b10a +17 more products- Actively Exploited
- Published: Feb. 04, 2025
- Modified: Feb. 12, 2025
- Vuln Type: Injection
-
8.8
HIGHCVE-2024-40890
**UNSUPPORTED WHEN ASSIGNED** A post-authentication command injection vulnerability in the CGI program of the legacy DSL CPE Zyxel VMG4325-B10A firmware version 1.00(AAFR.4)C0_20170615 could allow an authenticated attacker to execute operating system (OS)... Read more
Affected Products : vmg1312-b10a_firmware vmg4380-b10a_firmware vmg8324-b10a_firmware vmg8924-b10a_firmware sbg3300-n000_firmware sbg3300-nb00_firmware sbg3500-n000_firmware vmg8324-b10a vmg1312-b10a vmg4380-b10a +17 more products- Actively Exploited
- Published: Feb. 04, 2025
- Modified: Feb. 12, 2025
- Vuln Type: Injection
-
6.4
MEDIUMCVE-2024-13733
The SKT Blocks – Gutenberg based Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's skt-blocks/post-carousel block in all versions up to, and including, 1.7 due to insufficient input sanitization and output esc... Read more
Affected Products : skt_blocks- Published: Feb. 04, 2025
- Modified: May. 23, 2025
- Vuln Type: Cross-Site Scripting
-
6.5
MEDIUMCVE-2024-13529
The SocialV - Social Network and Community BuddyPress Theme theme for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'socialv_send_download_file' function in all versions up to, and including, 2.0.15. This ... Read more
Affected Products :- Published: Feb. 04, 2025
- Modified: Feb. 04, 2025
- Vuln Type: Authorization
-
6.1
MEDIUMCVE-2024-13510
The ShopSite plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.5.10. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to update ... Read more
Affected Products : shopsite- Published: Feb. 04, 2025
- Modified: Feb. 04, 2025
- Vuln Type: Cross-Site Request Forgery
-
6.5
MEDIUMCVE-2024-13356
The DSGVO All in one for WP plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.6. This is due to missing or incorrect nonce validation in the user_remove_form.php file. This makes it possible for unaut... Read more
Affected Products : dsgvo_all_in_one_for_wp- Published: Feb. 04, 2025
- Modified: May. 23, 2025
- Vuln Type: Cross-Site Request Forgery
-
6.4
MEDIUMCVE-2024-13403
The WPForms – Easy Form Builder for WordPress – Contact Forms, Payment Forms, Surveys, & More plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘fieldHTML’ parameter in all versions up to, and including, 1.9.3.1 due to insufficient... Read more
Affected Products : wpforms- Published: Feb. 04, 2025
- Modified: Aug. 12, 2025
- Vuln Type: Cross-Site Scripting
-
7.5
HIGHCVE-2025-22205
Improper handling of input variables lead to multiple path traversal vulnerabilities in the Admiror Gallery extension for Joomla in version branch 4.x.... Read more
Affected Products : admiror_gallery- Published: Feb. 04, 2025
- Modified: Jun. 04, 2025
- Vuln Type: Path Traversal
-
9.8
CRITICALCVE-2025-22204
Improper control of generation of code in the sourcerer extension for Joomla in versions before 11.0.0 lead to a remote code execution vulnerability.... Read more
Affected Products : sourcerer- Published: Feb. 04, 2025
- Modified: Jun. 04, 2025
-
6.0
MEDIUMCVE-2025-20907
Improper privilege management in Samsung Find prior to SMR Feb-2025 Release 1 allows local privileged attackers to disable Samsung Find.... Read more
- Published: Feb. 04, 2025
- Modified: Feb. 12, 2025
- Vuln Type: Authorization
-
5.5
MEDIUMCVE-2025-20906
Improper Export of Android Application Components in Settings prior to SMR Feb-2025 Release 1 allows local attackers to enable ADB.... Read more
Affected Products : android- Published: Feb. 04, 2025
- Modified: Feb. 04, 2025
- Vuln Type: Misconfiguration
-
6.7
MEDIUMCVE-2025-20905
Out-of-bounds read and write in mPOS TUI trustlet prior to SMR Feb-2025 Release 1 allows local privileged attackers to read and write out-of-bounds memory.... Read more
- Published: Feb. 04, 2025
- Modified: Feb. 12, 2025
-
6.7
MEDIUMCVE-2025-20904
Out-of-bounds write in mPOS TUI trustlet prior to SMR Feb-2025 Release 1 allows local privileged attackers to cause memory corruption.... Read more
- Published: Feb. 04, 2025
- Modified: Feb. 12, 2025
- Vuln Type: Memory Corruption
-
5.1
MEDIUMCVE-2025-20902
Improper access control in Media Controller prior to version 1.0.24.5282 allows local attacker to launch activities in MediaController's privilege.... Read more
Affected Products :- Published: Feb. 04, 2025
- Modified: Feb. 04, 2025
-
4.4
MEDIUMCVE-2025-20901
Out-of-bounds read in Blockchain Keystore prior to version 1.3.16.5 allows local privileged attackers to read out-of-bounds memory.... Read more
Affected Products : blockchain_keystore- Published: Feb. 04, 2025
- Modified: Jul. 17, 2025
- Vuln Type: Memory Corruption
-
6.3
MEDIUMCVE-2025-20900
Out-of-bounds write in Blockchain Keystore prior to version 1.3.16.5 allows local privileged attackers to write out-of-bounds memory.... Read more
Affected Products : blockchain_keystore- Published: Feb. 04, 2025
- Modified: Jul. 17, 2025
- Vuln Type: Memory Corruption