Latest CVE Feed
-
6.2
MEDIUMCVE-2025-33013
IBM MQ Operator LTS 2.0.0 through 2.0.29, MQ Operator CD 3.0.0, 3.0.1, 3.1.0 through 3.1.3, 3.3.0, 3.4.0, 3.4.1, 3.5.0, 3.5.1, 3.6.0, and MQ Operator SC2 3.2.0 through 3.2.13 Container could disclose sensitive information to a local user due to improper c... Read more
- Published: Jul. 24, 2025
- Modified: Aug. 22, 2025
- Vuln Type: Information Disclosure
-
9.8
CRITICALCVE-2025-4784
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Moderec Tourtella allows SQL Injection.This issue affects Tourtella: before 26.05.2025.... Read more
Affected Products : tourtella- Published: Jul. 24, 2025
- Modified: Jul. 28, 2025
- Vuln Type: Injection
-
6.5
MEDIUMCVE-2025-45731
A group deletion race condition in 2FAuth v5.5.0 causes data inconsistencies and orphaned accounts when a group is deleted while other operations are pending.... Read more
Affected Products : 2fauth- Published: Jul. 24, 2025
- Modified: Jul. 28, 2025
- Vuln Type: Race Condition
-
10.0
CRITICALCVE-2025-5243
Unrestricted Upload of File with Dangerous Type, Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in SMG Software Information Portal allows Code Injection, Upload a Web Shell to a Web Server, Code In... Read more
Affected Products :- Published: Jul. 24, 2025
- Modified: Jul. 25, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-4822
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Bayraktar Solar Energies ScadaWatt Otopilot allows SQL Injection.This issue affects ScadaWatt Otopilot: before 27.05.2025.... Read more
Affected Products :- Published: Jul. 24, 2025
- Modified: Jul. 25, 2025
- Vuln Type: Injection
-
6.9
MEDIUMCVE-2025-40680
Lack of sensitive data encryption in CapillaryScope v2.5.0 of Capillary io, which stores both the proxy credentials and the JWT session token in plain text within different registry keys on the Windows operating system. Any authenticated local user with r... Read more
Affected Products :- Published: Jul. 24, 2025
- Modified: Jul. 25, 2025
- Vuln Type: Cryptography
-
6.4
MEDIUMCVE-2025-8071
Mine CloudVod plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘audio’ parameter in all versions up to, and including, 2.1.10 due to insufficient input sanitization and output escaping. This makes it possible for authenticated att... Read more
Affected Products :- Published: Jul. 24, 2025
- Modified: Jul. 25, 2025
- Vuln Type: Cross-Site Scripting
-
6.4
MEDIUMCVE-2025-7966
The Get Youtube Subs plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘channel', 'layout', and 'subs_count’ parameters in all versions up to, and including, 3.5 due to insufficient input sanitization and output escaping. This make... Read more
Affected Products :- Published: Jul. 24, 2025
- Modified: Jul. 25, 2025
- Vuln Type: Cross-Site Scripting
-
6.4
MEDIUMCVE-2025-7959
The Station Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘width' and 'height’ parameter in all versions up to, and including, 2.4.2 due to insufficient input sanitization and output escaping. This makes it possible for aut... Read more
Affected Products :- Published: Jul. 24, 2025
- Modified: Jul. 25, 2025
- Vuln Type: Cross-Site Scripting
-
4.3
MEDIUMCVE-2025-7835
The iThoughts Advanced Code Editor plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.2.10. This is due to missing or incorrect nonce validation on the 'ithoughts_ace_update_options' AJAX action. This ... Read more
Affected Products :- Published: Jul. 24, 2025
- Modified: Jul. 25, 2025
- Vuln Type: Cross-Site Request Forgery
-
4.3
MEDIUMCVE-2025-7822
The WP Wallcreeper plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the admin_notices hook in all versions up to, and including, 1.6.1. This makes it possible for authenticated attackers, with Su... Read more
Affected Products :- Published: Jul. 24, 2025
- Modified: Jul. 25, 2025
- Vuln Type: Authorization
-
6.5
MEDIUMCVE-2025-7780
The AI Engine plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.9.4. The simpleTranscribeAudio endpoint fails to restrict URL schemes before calling get_audio(). This makes it possible for authent... Read more
- Published: Jul. 24, 2025
- Modified: Jul. 25, 2025
- Vuln Type: Information Disclosure
-
8.8
HIGHCVE-2025-7695
The Dataverse Integration plugin for WordPress is vulnerable to Privilege Escalation due to missing authorization checks within its reset_password_link REST endpoint in versions 2.77 through 2.81. The endpoint’s handler accepts a client-supplied id, email... Read more
Affected Products :- Published: Jul. 24, 2025
- Modified: Jul. 25, 2025
- Vuln Type: Authorization
-
6.1
MEDIUMCVE-2025-7690
The Affiliate Plus plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.3.2. This is due to missing or incorrect nonce validation on the 'affiplus_settings' page. This makes it possible for unauthenticat... Read more
Affected Products :- Published: Jul. 24, 2025
- Modified: Jul. 25, 2025
- Vuln Type: Cross-Site Request Forgery
-
8.1
HIGHCVE-2025-7640
The hiWeb Export Posts plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 0.9.0.0. This is due to missing or incorrect nonce validation on the tool-dashboard-history.php file. This makes it possible for ... Read more
Affected Products :- Published: Jul. 24, 2025
- Modified: Jul. 25, 2025
- Vuln Type: Cross-Site Request Forgery
-
6.1
MEDIUMCVE-2025-6588
The FunnelCockpit plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘error’ parameter in all versions up to, and including, 1.4.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthentic... Read more
Affected Products :- Published: Jul. 24, 2025
- Modified: Jul. 25, 2025
- Vuln Type: Cross-Site Scripting
-
6.4
MEDIUMCVE-2025-6539
The Voltax Video Player plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘id’ parameter in all versions up to, and including, 1.6.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticat... Read more
Affected Products :- Published: Jul. 24, 2025
- Modified: Jul. 25, 2025
- Vuln Type: Cross-Site Scripting
-
9.8
CRITICALCVE-2025-6441
The Webinar Solution: Create live/evergreen/automated/instant webinars, stream & Zoom Meetings | WebinarIgnition plugin for WordPress is vulnerable to unauthenticated login token generation due to a missing capability check on the `webinarignition_sign_in... Read more
Affected Products : webinarignition- Published: Jul. 24, 2025
- Modified: Jul. 25, 2025
- Vuln Type: Authentication
-
6.4
MEDIUMCVE-2025-6387
The WP Get The Table plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘url’ parameter in all versions up to, and including, 1.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated a... Read more
Affected Products :- Published: Jul. 24, 2025
- Modified: Jul. 25, 2025
- Vuln Type: Cross-Site Scripting
-
6.4
MEDIUMCVE-2025-6385
The WP Applink plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘title’ parameter in all versions up to, and including, 0.4.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated att... Read more
Affected Products :- Published: Jul. 24, 2025
- Modified: Jul. 25, 2025
- Vuln Type: Cross-Site Scripting