Latest CVE Feed
-
7.5
HIGHCVE-2025-22963
Teedy through 1.11 allows CSRF for account takeover via POST /api/user/admin.... Read more
Affected Products : teedy- Published: Jan. 13, 2025
- Modified: Aug. 08, 2025
- Vuln Type: Cross-Site Request Forgery
-
8.4
HIGHCVE-2024-52333
An improper array index validation vulnerability exists in the determineMinMax functionality of OFFIS DCMTK 3.6.8. A specially crafted DICOM file can lead to an out-of-bounds write. An attacker can provide a malicious file to trigger this vulnerability.... Read more
Affected Products : dcmtk- Published: Jan. 13, 2025
- Modified: Jun. 24, 2025
- Vuln Type: Memory Corruption
-
8.4
HIGHCVE-2024-47796
An improper array index validation vulnerability exists in the nowindow functionality of OFFIS DCMTK 3.6.8. A specially crafted DICOM file can lead to an out-of-bounds write. An attacker can provide a malicious file to trigger this vulnerability.... Read more
Affected Products : dcmtk- Published: Jan. 13, 2025
- Modified: Jun. 24, 2025
- Vuln Type: Memory Corruption
-
8.8
HIGHCVE-2025-22800
Missing Authorization vulnerability in Post SMTP Post SMTP allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Post SMTP: from n/a through 2.9.11.... Read more
Affected Products : post_smtp- Published: Jan. 13, 2025
- Modified: Jun. 04, 2025
- Vuln Type: Authorization
-
9.8
CRITICALCVE-2025-22777
Deserialization of Untrusted Data vulnerability in GiveWP GiveWP allows Object Injection.This issue affects GiveWP: from n/a through 3.19.3.... Read more
Affected Products : givewp- Published: Jan. 13, 2025
- Modified: Jun. 04, 2025
- Vuln Type: Injection
-
7.1
HIGHCVE-2025-22588
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Scanventory.net Scanventory allows Reflected XSS.This issue affects Scanventory: from n/a through 1.1.3.... Read more
Affected Products :- Published: Jan. 13, 2025
- Modified: Jan. 13, 2025
-
7.1
HIGHCVE-2025-22586
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Detlef Stöver WPEX Replace DB Urls allows Reflected XSS.This issue affects WPEX Replace DB Urls: from n/a through 0.4.0.... Read more
Affected Products :- Published: Jan. 13, 2025
- Modified: Jan. 13, 2025
- Vuln Type: Cross-Site Scripting
-
7.1
HIGHCVE-2025-22583
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Anshul Sojatia Scan External Links allows Reflected XSS.This issue affects Scan External Links: from n/a through 1.0.... Read more
Affected Products :- Published: Jan. 13, 2025
- Modified: Jan. 13, 2025
- Vuln Type: Cross-Site Scripting
-
7.1
HIGHCVE-2025-22576
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Marcus Downing Site PIN allows Reflected XSS.This issue affects Site PIN: from n/a through 1.3.... Read more
Affected Products :- Published: Jan. 13, 2025
- Modified: Jan. 13, 2025
-
7.1
HIGHCVE-2025-22570
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Miloš Đekić Inline Tweets allows Stored XSS.This issue affects Inline Tweets: from n/a through 2.0.... Read more
Affected Products :- Published: Jan. 13, 2025
- Modified: Jan. 13, 2025
- Vuln Type: Cross-Site Scripting
-
7.1
HIGHCVE-2025-22569
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in grandslambert Featured Page Widget allows Reflected XSS.This issue affects Featured Page Widget: from n/a through 2.2.... Read more
Affected Products :- Published: Jan. 13, 2025
- Modified: Jan. 13, 2025
- Vuln Type: Cross-Site Scripting
-
7.1
HIGHCVE-2025-22568
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Paramveer Singh for Arete IT Private Limited Post And Page Reactions allows Reflected XSS.This issue affects Post And Page Reactions: from n/a through 1.... Read more
Affected Products :- Published: Jan. 13, 2025
- Modified: Jan. 13, 2025
- Vuln Type: Cross-Site Scripting
-
7.1
HIGHCVE-2025-22567
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in trustist TRUSTist REVIEWer allows Reflected XSS.This issue affects TRUSTist REVIEWer: from n/a through 2.0.... Read more
Affected Products :- Published: Jan. 13, 2025
- Modified: Jan. 13, 2025
- Vuln Type: Cross-Site Scripting
-
7.1
HIGHCVE-2025-22514
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Yamna Tatheer KNR Author List Widget allows Reflected XSS.This issue affects KNR Author List Widget: from n/a through 3.1.1.... Read more
Affected Products :- Published: Jan. 13, 2025
- Modified: Jan. 13, 2025
- Vuln Type: Cross-Site Scripting
-
7.1
HIGHCVE-2025-22506
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in SmartAgenda Smart Agenda allows Stored XSS.This issue affects Smart Agenda: from n/a through 4.7.... Read more
Affected Products :- Published: Jan. 13, 2025
- Modified: Jan. 13, 2025
- Vuln Type: Cross-Site Scripting
-
7.1
HIGHCVE-2025-22499
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in FAKTOR VIER F4 Post Tree allows Reflected XSS.This issue affects F4 Post Tree: from n/a through 1.1.18.... Read more
Affected Products :- Published: Jan. 13, 2025
- Modified: Jan. 13, 2025
- Vuln Type: Cross-Site Scripting
-
7.1
HIGHCVE-2025-22498
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in New Normal LLC LucidLMS allows Reflected XSS.This issue affects LucidLMS: from n/a through 1.0.5.... Read more
Affected Products :- Published: Jan. 13, 2025
- Modified: Jan. 13, 2025
- Vuln Type: Cross-Site Scripting
-
7.1
HIGHCVE-2025-22344
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Convoy Media Category Library allows Reflected XSS.This issue affects Media Category Library: from n/a through 2.7.... Read more
Affected Products :- Published: Jan. 13, 2025
- Modified: Jan. 13, 2025
- Vuln Type: Cross-Site Scripting
-
7.1
HIGHCVE-2025-22337
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Infosoft Consultant Order Audit Log for WooCommerce allows Reflected XSS.This issue affects Order Audit Log for WooCommerce: from n/a through 2.0.... Read more
Affected Products :- Published: Jan. 13, 2025
- Modified: Jan. 13, 2025
- Vuln Type: Cross-Site Scripting
-
7.1
HIGHCVE-2025-22314
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Scripts Food Store – Online Food Delivery & Pickup allows Reflected XSS.This issue affects Food Store – Online Food Delivery & Pickup: from n/a throug... Read more
Affected Products :- Published: Jan. 13, 2025
- Modified: Jan. 13, 2025
- Vuln Type: Cross-Site Scripting