Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 6.5

    MEDIUM
    CVE-2025-0200

    A vulnerability has been found in code-projects Point of Sales and Inventory Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /user/search_num.php. The manipulation of the argument se... Read more

    • Published: Jan. 04, 2025
    • Modified: Feb. 25, 2025
    • Vuln Type: Injection
  • 7.5

    HIGH
    CVE-2025-22390

    An issue was discovered in Optimizely EPiServer.CMS.Core before 12.32.0. A medium-severity vulnerability exists in the CMS due to insufficient enforcement of password complexity requirements. The application permits users to set passwords with a minimum l... Read more

    Affected Products : optimizely_cms
    • Published: Jan. 04, 2025
    • Modified: May. 20, 2025
    • Vuln Type: Authentication
  • 8.0

    HIGH
    CVE-2025-22389

    An issue was discovered in Optimizely EPiServer.CMS.Core before 12.32.0. A medium-severity vulnerability exists in the CMS, where the application does not properly validate uploaded files. This allows the upload of potentially malicious file types, includ... Read more

    Affected Products : optimizely_cms
    • Published: Jan. 04, 2025
    • Modified: May. 20, 2025
    • Vuln Type: Misconfiguration
  • 5.7

    MEDIUM
    CVE-2025-22388

    An issue was discovered in Optimizely EPiServer.CMS.Core before 12.22.0. A high-severity Stored Cross-Site Scripting (XSS) vulnerability exists in the CMS, allowing malicious actors to inject and execute arbitrary JavaScript code, potentially compromising... Read more

    Affected Products : optimizely_cms
    • Published: Jan. 04, 2025
    • Modified: May. 20, 2025
    • Vuln Type: Cross-Site Scripting
  • 7.5

    HIGH
    CVE-2025-22387

    An issue was discovered in Optimizely Configured Commerce before 5.2.2408. A medium-severity issue exists in requests for resources where the session token is submitted as a URL parameter. This exposes information about the authenticated session, which ca... Read more

    Affected Products : configured_commerce
    • Published: Jan. 04, 2025
    • Modified: May. 21, 2025
    • Vuln Type: Information Disclosure
  • 7.3

    HIGH
    CVE-2025-22386

    An issue was discovered in Optimizely Configured Commerce before 5.2.2408. A medium-severity session issue exists in the Commerce B2B application, affecting the longevity of active sessions in the storefront. This allows session tokens tied to logged-out ... Read more

    Affected Products : configured_commerce
    • Published: Jan. 04, 2025
    • Modified: May. 20, 2025
    • Vuln Type: Authentication
  • 5.9

    MEDIUM
    CVE-2025-22385

    An issue was discovered in Optimizely Configured Commerce before 5.2.2408. For newly created accounts, the Commerce B2B application does not require email confirmation. This medium-severity issue allows the mass creation of accounts. This could affect dat... Read more

    Affected Products : configured_commerce
    • Published: Jan. 04, 2025
    • Modified: May. 20, 2025
    • Vuln Type: Authentication
  • 7.5

    HIGH
    CVE-2025-22384

    An issue was discovered in Optimizely Configured Commerce before 5.2.2408. A medium-severity issue concerning business logic exists in the Commerce B2B application, which allows storefront visitors to purchase discontinued products in specific scenarios w... Read more

    Affected Products : configured_commerce
    • Published: Jan. 04, 2025
    • Modified: May. 20, 2025
    • Vuln Type: Authorization
  • 4.6

    MEDIUM
    CVE-2025-22383

    An issue was discovered in Optimizely Configured Commerce before 5.2.2408. A medium-severity input validation issue exists in the Commerce B2B application, affecting the Contact Us functionality. This allows visitors to send e-mail messages that could con... Read more

    Affected Products : configured_commerce
    • Published: Jan. 04, 2025
    • Modified: May. 20, 2025
    • Vuln Type: Information Disclosure
  • 6.5

    MEDIUM
    CVE-2025-0199

    A vulnerability, which was classified as critical, was found in code-projects Point of Sales and Inventory Management System 1.0. Affected is an unknown function of the file /user/minus_cart.php. The manipulation of the argument id leads to sql injection.... Read more

    • Published: Jan. 03, 2025
    • Modified: Feb. 25, 2025
    • Vuln Type: Injection
  • 4.3

    MEDIUM
    CVE-2024-55897

    IBM PowerHA SystemMirror for i 7.4 and 7.5 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user goes ... Read more

    Affected Products : i i powerha_system_mirror
    • Published: Jan. 03, 2025
    • Modified: Jun. 20, 2025
    • Vuln Type: Misconfiguration
  • 5.4

    MEDIUM
    CVE-2024-55896

    IBM PowerHA SystemMirror for i 7.4 and 7.5 contains improper restrictions when rendering content via iFrames.  This vulnerability could allow an attacker to gain improper access and perform unauthorized actions on the system.... Read more

    Affected Products : i i
    • Published: Jan. 03, 2025
    • Modified: Aug. 19, 2025
    • Vuln Type: Authorization
  • 4.3

    MEDIUM
    CVE-2024-12237

    The Photo Gallery Slideshow & Masonry Tiled Gallery plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.0.15 via the rjg_get_youtube_info_justified_gallery_callback function. This makes it possible for... Read more

    • Published: Jan. 03, 2025
    • Modified: Jan. 03, 2025
    • Vuln Type: Server-Side Request Forgery
  • 7.3

    HIGH
    CVE-2024-11733

    The The WordPress Popular Posts plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 7.1.0. This is due to the software allowing users to execute an action that does not properly validate a value before... Read more

    Affected Products : wordpress_popular_posts
    • Published: Jan. 03, 2025
    • Modified: Jan. 03, 2025
    • Vuln Type: Authentication
  • 5.3

    MEDIUM
    CVE-2025-22376

    In Net::OAuth::Client in the Net::OAuth package before 0.29 for Perl, the default nonce is a 32-bit integer generated from the built-in rand() function, which is not cryptographically strong.... Read more

    Affected Products :
    • Published: Jan. 03, 2025
    • Modified: Jan. 21, 2025
    • Vuln Type: Cryptography
  • 9.0

    HIGH
    CVE-2024-13129

    A vulnerability was found in Roxy-WI up to 8.1.3. It has been declared as critical. Affected by this vulnerability is the function action_service of the file app/modules/roxywi/roxy.py. The manipulation of the argument action/service leads to os command i... Read more

    Affected Products :
    • Published: Jan. 03, 2025
    • Modified: Aug. 26, 2025
    • Vuln Type: Injection
  • 6.5

    MEDIUM
    CVE-2025-0198

    A vulnerability, which was classified as critical, has been found in code-projects Point of Sales and Inventory Management System 1.0. This issue affects some unknown processing of the file /user/search_result.php. The manipulation of the argument id lead... Read more

    • Published: Jan. 03, 2025
    • Modified: Feb. 25, 2025
    • Vuln Type: Injection
  • 5.3

    MEDIUM
    CVE-2024-56332

    Next.js is a React framework for building full-stack web applications. Starting in version 13.0.0 and prior to versions 13.5.8, 14.2.21, and 15.1.2, Next.js is vulnerable to a Denial of Service (DoS) attack that allows attackers to construct requests that... Read more

    Affected Products : next.js
    • Published: Jan. 03, 2025
    • Modified: Sep. 10, 2025
    • Vuln Type: Denial of Service
  • 6.5

    MEDIUM
    CVE-2025-0197

    A vulnerability classified as critical was found in code-projects Point of Sales and Inventory Management System 1.0. This vulnerability affects unknown code of the file /user/search.php. The manipulation of the argument name leads to sql injection. The a... Read more

    • Published: Jan. 03, 2025
    • Modified: Feb. 25, 2025
    • Vuln Type: Injection
  • 6.5

    MEDIUM
    CVE-2025-0196

    A vulnerability classified as critical has been found in code-projects Point of Sales and Inventory Management System 1.0. This affects an unknown part of the file /user/plist.php. The manipulation of the argument cat leads to sql injection. It is possibl... Read more

    • Published: Jan. 03, 2025
    • Modified: Feb. 25, 2025
    • Vuln Type: Injection
Showing 20 of 293592 Results