Latest CVE Feed
-
8.8
HIGHCVE-2025-24456
In JetBrains Hub before 2024.3.55417 privilege escalation was possible via LDAP authentication mapping... Read more
Affected Products : hub- Published: Jan. 21, 2025
- Modified: Jan. 30, 2025
-
6.1
MEDIUMCVE-2025-24020
WeGIA is a Web manager for charitable institutions. An Open Redirect vulnerability was identified in the `control.php` endpoint of versions up to and including 3.2.10 of the WeGIA application. The vulnerability allows the `nextPage` parameter to be manipu... Read more
Affected Products : wegia- Published: Jan. 21, 2025
- Modified: Feb. 13, 2025
-
7.1
HIGHCVE-2025-24019
YesWiki is a wiki system written in PHP. In versions up to and including 4.4.5, it is possible for any authenticated user, through the use of the filemanager to delete any file owned by the user running the FastCGI Process Manager (FPM) on the host withou... Read more
Affected Products : yeswiki- Published: Jan. 21, 2025
- Modified: May. 09, 2025
-
4.3
MEDIUMCVE-2025-23996
Cross-Site Request Forgery (CSRF) vulnerability in anyroad.com AnyRoad allows Cross Site Request Forgery. This issue affects AnyRoad: from n/a through 1.3.2.... Read more
Affected Products :- Published: Jan. 21, 2025
- Modified: Jan. 21, 2025
-
7.1
HIGHCVE-2025-23994
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Estatebud Estatebud – Properties & Listings allows Stored XSS. This issue affects Estatebud – Properties & Listings: from n/a through 5.5.0.... Read more
Affected Products :- Published: Jan. 21, 2025
- Modified: Jan. 21, 2025
-
7.1
HIGHCVE-2025-23580
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Matthew Garvin BizLibrary allows Reflected XSS. This issue affects BizLibrary: from n/a through 1.1.... Read more
Affected Products : bizlibrary- Published: Jan. 21, 2025
- Modified: Jan. 21, 2025
-
7.1
HIGHCVE-2025-23551
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in P. Razvan SexBundle allows Reflected XSS. This issue affects SexBundle: from n/a through 1.4.... Read more
Affected Products :- Published: Jan. 21, 2025
- Modified: Jan. 21, 2025
-
7.1
HIGHCVE-2025-23489
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Brian Messenlehner of WebDevStudios WP-Announcements allows Reflected XSS. This issue affects WP-Announcements: from n/a through 1.8.... Read more
Affected Products :- Published: Jan. 21, 2025
- Modified: Jan. 21, 2025
-
8.2
HIGHCVE-2025-23477
Missing Authorization vulnerability in Realty Workstation Realty Workstation allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Realty Workstation: from n/a through 1.0.45.... Read more
Affected Products : realty_workstation- Published: Jan. 21, 2025
- Modified: Jan. 21, 2025
-
7.1
HIGHCVE-2025-23461
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Andrea Dotta, Jacopo Campani, di xkoll.com Social2Blog allows Reflected XSS. This issue affects Social2Blog: from n/a through 0.2.990.... Read more
Affected Products :- Published: Jan. 21, 2025
- Modified: Jan. 21, 2025
-
7.1
HIGHCVE-2025-23454
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in flashmaniac Nature FlipBook allows Reflected XSS. This issue affects Nature FlipBook: from n/a through 1.7.... Read more
Affected Products :- Published: Jan. 21, 2025
- Modified: Jan. 21, 2025
-
4.3
MEDIUMCVE-2025-22722
Missing Authorization vulnerability in Widget Options Team Widget Options allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Widget Options: from n/a through 4.0.8.... Read more
Affected Products :- Published: Jan. 21, 2025
- Modified: Jan. 21, 2025
-
4.3
MEDIUMCVE-2025-22721
Missing Authorization vulnerability in Farhan Noor ApplyOnline – Application Form Builder and Manager allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects ApplyOnline – Application Form Builder and Manager: from n/a ... Read more
Affected Products : applyonline_-_application_form_builder_and_manager- Published: Jan. 21, 2025
- Modified: Jan. 21, 2025
-
6.5
MEDIUMCVE-2025-22661
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in vcita.com Online Payments – Get Paid with PayPal, Square & Stripe allows Stored XSS. This issue affects Online Payments – Get Paid with PayPal, Square & ... Read more
Affected Products : online_payments_-_get_paid_with_paypal\,_square_\&_stripe- Published: Jan. 21, 2025
- Modified: Jan. 21, 2025
-
5.9
MEDIUMCVE-2025-22276
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Enguerran Weiss Related Post Shortcode allows Stored XSS. This issue affects Related Post Shortcode: from n/a through 1.2.... Read more
Affected Products :- Published: Jan. 21, 2025
- Modified: Jan. 21, 2025
-
6.5
MEDIUMCVE-2025-22267
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Bruce Wampler Weaver Themes Shortcode Compatibility allows Stored XSS. This issue affects Weaver Themes Shortcode Compatibility: from n/a through 1.0.4.... Read more
Affected Products :- Published: Jan. 21, 2025
- Modified: Jan. 21, 2025
-
6.8
MEDIUMCVE-2025-22150
Undici is an HTTP/1.1 client. Starting in version 4.5.0 and prior to versions 5.28.5, 6.21.1, and 7.2.3, undici uses `Math.random()` to choose the boundary for a multipart/form-data request. It is known that the output of `Math.random()` can be predicted ... Read more
Affected Products : undici- Published: Jan. 21, 2025
- Modified: Jan. 21, 2025
-
5.4
MEDIUMCVE-2024-54795
SpagoBI v3.5.1 contains multiple Stored Cross-Site Scripting (XSS) vulnerabilities in the create/edit forms of the worksheet designer function.... Read more
Affected Products : spagobi- Published: Jan. 21, 2025
- Modified: Jul. 03, 2025
-
9.1
CRITICALCVE-2024-54794
The script input feature of SpagoBI 3.5.1 allows arbitrary code execution.... Read more
Affected Products : spagobi- Published: Jan. 21, 2025
- Modified: Jul. 03, 2025
-
6.1
MEDIUMCVE-2024-54792
A Cross-Site Request Forgery (CSRF) vulnerability has been found in SpagoBI v3.5.1 in the user administration panel. An authenticated user can lead another user into executing unwanted actions inside the application they are logged in, like adding, editin... Read more
Affected Products : spagobi- Published: Jan. 21, 2025
- Modified: Jul. 03, 2025