Latest CVE Feed
-
7.8
HIGHCVE-2024-45331
A incorrect privilege assignment in Fortinet FortiAnalyzer versions 7.4.0 through 7.4.3, 7.2.0 through 7.2.5, 7.0.0 through 7.0.13, 6.4.0 through 6.4.15, FortiManager versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.5, 7.0.0 through 7.0.13, 6.4.0 through 6... Read more
- Published: Jan. 16, 2025
- Modified: Feb. 03, 2025
- Vuln Type: Authorization
-
6.5
MEDIUMCVE-2024-12226
In affected versions of the Octopus Kubernetes worker or agent, sensitive variables could be written to the Kubernetes script pod log in clear-text. This was identified in Version 2 however it was determined that this could also be achieved in Version 1 a... Read more
Affected Products :- Published: Jan. 16, 2025
- Modified: Jan. 16, 2025
- Vuln Type: Information Disclosure
-
6.4
MEDIUMCVE-2024-11452
The Chamber Dashboard Business Directory plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'business_categories' shortcode in all versions up to, and including, 3.3.8 due to insufficient input sanitization and output escap... Read more
Affected Products :- Published: Jan. 16, 2025
- Modified: Jan. 16, 2025
- Vuln Type: Cross-Site Scripting
-
4.3
MEDIUMCVE-2024-10789
The WP User Profile Avatar plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.5. This is due to missing or incorrect nonce validation on the wpupa_user_admin() function. This makes it possible for un... Read more
Affected Products :- Published: Jan. 16, 2025
- Modified: Jan. 16, 2025
- Vuln Type: Cross-Site Request Forgery
-
9.8
CRITICALCVE-2025-22916
RE11S v1.11 was discovered to contain a stack overflow via the pppUserName parameter in the formPPPoESetup function.... Read more
- Published: Jan. 16, 2025
- Modified: Apr. 09, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2025-22913
RE11S v1.11 was discovered to contain a stack overflow via the rootAPmac parameter in the formStaDrvSetup function.... Read more
- Published: Jan. 16, 2025
- Modified: Apr. 09, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2025-22912
RE11S v1.11 was discovered to contain a command injection vulnerability via the component /goform/formAccept.... Read more
- Published: Jan. 16, 2025
- Modified: Apr. 09, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-22907
RE11S v1.11 was discovered to contain a stack overflow via the selSSID parameter in the formWlSiteSurvey function.... Read more
- Published: Jan. 16, 2025
- Modified: Apr. 09, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2025-22906
RE11S v1.11 was discovered to contain a command injection vulnerability via the L2TPUserName parameter at /goform/setWAN.... Read more
- Published: Jan. 16, 2025
- Modified: Apr. 09, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-22905
RE11S v1.11 was discovered to contain a command injection vulnerability via the command parameter at /goform/mp.... Read more
- Published: Jan. 16, 2025
- Modified: Apr. 09, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-22904
RE11S v1.11 was discovered to contain a stack overflow via the pptpUserName parameter in the setWAN function.... Read more
- Published: Jan. 16, 2025
- Modified: Apr. 09, 2025
- Vuln Type: Memory Corruption
-
8.8
HIGHCVE-2025-0457
The airPASS from NetVision Information has an OS Command Injection vulnerability, allowing remote attackers with regular privileges to inject and execute arbitrary OS commands.... Read more
Affected Products : airpass- Published: Jan. 16, 2025
- Modified: Jan. 16, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-0456
The airPASS from NetVision Information has a Missing Authentication vulnerability, allowing unauthenticated remote attackers to access the specific administrative functionality to retrieve * all accounts and passwords.... Read more
Affected Products : airpass- Published: Jan. 16, 2025
- Modified: Jan. 16, 2025
- Vuln Type: Authentication
-
9.8
CRITICALCVE-2025-0455
The airPASS from NetVision Information has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary SQL commands to read, modify, and delete database contents.... Read more
Affected Products : airpass- Published: Jan. 16, 2025
- Modified: Jan. 16, 2025
- Vuln Type: Injection
-
6.1
MEDIUMCVE-2025-0170
The DWT - Directory & Listing WordPress Theme is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 3.3.3 due to insufficient input sanitization and output escaping on the 'sort_by' and 'token' parameters. This makes it possibl... Read more
Affected Products : dwt_listing- Published: Jan. 16, 2025
- Modified: Jan. 16, 2025
- Vuln Type: Cross-Site Scripting
-
5.4
MEDIUMCVE-2024-10970
The The Motors – Car Dealer, Classifieds & Listing plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 1.4.43. This is due to the software allowing users to execute an action that does not properly val... Read more
Affected Products : motors_-_car_dealer\,_classifieds_\&_listing- Published: Jan. 16, 2025
- Modified: Aug. 08, 2025
- Vuln Type: Misconfiguration
-
4.3
MEDIUMCVE-2025-0476
Mattermost Mobile Apps versions <=2.22.0 fail to properly handle specially crafted attachment names, which allows an attacker to crash the mobile app for any user who opened a channel containing the specially crafted attachment... Read more
- Published: Jan. 16, 2025
- Modified: Jan. 16, 2025
- Vuln Type: Denial of Service
-
7.1
HIGHCVE-2025-22976
SQL Injection vulnerability in dingfanzuCMS v.1.0 allows a local attacker to execute arbitrary code via not filtering the content correctly at the "checkOrder.php" shopId module.... Read more
Affected Products :- Published: Jan. 15, 2025
- Modified: Feb. 03, 2025
- Vuln Type: Injection
-
8.1
HIGHCVE-2025-22964
DDSN Interactive cm3 Acora CMS version 10.1.1 has an unauthenticated time-based blind SQL Injection vulnerability caused by insufficient input sanitization and validation in the "table" parameter. This flaw allows attackers to inject malicious SQL queries... Read more
Affected Products :- Published: Jan. 15, 2025
- Modified: Feb. 03, 2025
- Vuln Type: Injection
-
6.1
MEDIUMCVE-2025-0215
The UpdraftPlus: WP Backup & Migration Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the showdata and initiate_restore parameters in all versions up to, and including, 1.24.12 due to insufficient input sanitization and ou... Read more
Affected Products :- Published: Jan. 15, 2025
- Modified: Jan. 15, 2025
- Vuln Type: Cross-Site Scripting