Latest CVE Feed
-
8.8
HIGHCVE-2015-10140
The Ajax Load More plugin before 2.8.1.2 does not have authorisation in some of its AJAX actions, allowing any authenticated users, such as subscriber, to upload and delete arbitrary files.... Read more
Affected Products : ajax_load_more- Published: Jul. 22, 2025
- Modified: Jul. 25, 2025
- Vuln Type: Authorization
-
9.3
CRITICALCVE-2025-34143
An authentication bypass vulnerability exists in ETQ Reliance on the CG (legacy) platform. The application allowed login as the privileged internal SYSTEM user by manipulating the username field. The SYSTEM account does not require a password, enabling at... Read more
Affected Products :- Published: Jul. 22, 2025
- Modified: Jul. 25, 2025
- Vuln Type: Authentication
-
6.9
MEDIUMCVE-2025-34142
An XML External Entity (XXE) injection vulnerability exists in ETQ Reliance on the CG (legacy) platform within the `/resources/sessions/sso` endpoint. The SAML authentication handler processes XML input without disabling external entity resolution, allowi... Read more
Affected Products :- Published: Jul. 22, 2025
- Modified: Jul. 25, 2025
- Vuln Type: XML External Entity
-
5.1
MEDIUMCVE-2025-34141
A reflected cross-site scripting (XSS) vulnerability exists in ETQ Reliance CG (legacy) platform within the `SQLConverterServlet` component. This vulnerability requires user interaction, such as clicking a crafted link, and may result in execution of unau... Read more
Affected Products :- Published: Jul. 22, 2025
- Modified: Jul. 25, 2025
- Vuln Type: Cross-Site Scripting
-
8.7
HIGHCVE-2025-34140
An authorization bypass vulnerability exists in ETQ Reliance (legacy CG and NXG SaaS platforms). By appending a specific URI suffix to certain API endpoints, an unauthenticated attacker can bypass access control checks and retrieve limited sensitive resou... Read more
Affected Products :- Published: Jul. 22, 2025
- Modified: Jul. 25, 2025
- Vuln Type: Authorization
-
8.6
HIGHCVE-2025-7705
: Active Debug Code vulnerability in ABB Switch Actuator 4 DU-83330, ABB Switch actuator, door/light 4 DU -83330-500.This issue affects Switch Actuator 4 DU-83330: All Versions; Switch actuator, door/light 4 DU -83330-500: All Versions.... Read more
Affected Products :- Published: Jul. 22, 2025
- Modified: Jul. 22, 2025
- Vuln Type: Misconfiguration
-
10.0
CRITICALCVE-2025-4285
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Rolantis Information Technologies Agentis allows SQL Injection.This issue affects Agentis: before 4.32.... Read more
Affected Products :- Published: Jul. 22, 2025
- Modified: Jul. 22, 2025
- Vuln Type: Injection
-
6.1
MEDIUMCVE-2025-4284
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Rolantis Information Technologies Agentis allows Reflected XSS, DOM-Based XSS.This issue affects Agentis: before 4.32.... Read more
Affected Products :- Published: Jul. 22, 2025
- Modified: Jul. 22, 2025
- Vuln Type: Cross-Site Scripting
-
5.3
MEDIUMCVE-2025-7900
The femanager extension for TYPO3 allows Insecure Direct Object Reference resulting in unauthorized modification of userdata. This issue affects femanager version 6.4.1 and below, 7.0.0 to 7.5.2 and 8.0.0 to 8.3.0... Read more
Affected Products : femanager- Published: Jul. 22, 2025
- Modified: Jul. 22, 2025
- Vuln Type: Authorization
-
6.0
MEDIUMCVE-2025-7899
The powermail extension for TYPO3 allows Insecure Direct Object Reference resulting in download of arbitrary files from the webserver. This issue affects powermail version 12.0.0 up to 12.5.2 and version 13.0.0... Read more
Affected Products : powermail- Published: Jul. 22, 2025
- Modified: Jul. 22, 2025
- Vuln Type: Authorization
-
8.1
HIGHCVE-2025-7692
The Orion Login with SMS plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 1.0.5. This is due to the olws_handle_verify_phone() function not utilizing a strong enough OTP value, exposing the hash needed to g... Read more
Affected Products :- Published: Jul. 22, 2025
- Modified: Jul. 22, 2025
- Vuln Type: Authentication
-
6.1
MEDIUMCVE-2025-7687
The Latest Post Accordian Slider plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.3. This is due to missing or incorrect nonce validation on the 'lpaccordian' page. This makes it possible for unauthe... Read more
Affected Products :- Published: Jul. 22, 2025
- Modified: Jul. 22, 2025
- Vuln Type: Cross-Site Request Forgery
-
6.1
MEDIUMCVE-2025-7685
The Like & Share My Site plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 0.2. This is due to missing or incorrect nonce validation on the 'lsms_admin' page. This makes it possible for unauthenticated ... Read more
Affected Products :- Published: Jul. 22, 2025
- Modified: Jul. 22, 2025
- Vuln Type: Cross-Site Request Forgery
-
5.9
MEDIUMCVE-2025-7427
Uncontrolled Search Path Element in Arm Development Studio before 2025 may allow an attacker to perform a DLL hijacking attack. Successful exploitation could lead to local arbitrary code execution in the context of the user running Arm Development Studio.... Read more
Affected Products :- Published: Jul. 22, 2025
- Modified: Jul. 23, 2025
- Vuln Type: Misconfiguration
-
7.2
HIGHCVE-2025-6213
The Nginx Cache Purge Preload plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.1.1 via the 'nppp_preload_cache_on_update' function. This is due to insufficient sanitization of the $_SERVER['HTTP_REFERERER... Read more
Affected Products :- Published: Jul. 22, 2025
- Modified: Aug. 01, 2025
- Vuln Type: Authentication
-
9.8
CRITICALCVE-2025-6187
The bSecure plugin for WordPress is vulnerable to Privilege Escalation due to missing authorization within its order_info REST endpoint in versions 1.3.7 through 1.7.9. The plugin registers the /webhook/v2/order_info/ route with a permission_callback that... Read more
Affected Products :- Published: Jul. 22, 2025
- Modified: Jul. 22, 2025
- Vuln Type: Authorization
-
5.3
MEDIUMCVE-2025-6082
The Birth Chart Compatibility plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 2.0. This is due to insufficient protection against directly accessing the plugin's index.php file, which causes an error exposi... Read more
Affected Products :- Published: Jul. 22, 2025
- Modified: Jul. 22, 2025
- Vuln Type: Information Disclosure
-
8.6
HIGHCVE-2025-53472
WRC-BE36QS-B and WRC-W701-B contain an improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability in WebGUI. If exploited, an arbitrary OS command may be executed by a remote attacker who can log in to WebGUI.... Read more
Affected Products :- Published: Jul. 22, 2025
- Modified: Jul. 22, 2025
- Vuln Type: Injection
-
6.9
MEDIUMCVE-2025-46267
Hidden functionality issue exists in WRC-BE36QS-B and WRC-W701-B. If exploited, the product's hidden debug function may be enabled by a remote attacker who can log in to WebGUI.... Read more
Affected Products :- Published: Jul. 22, 2025
- Modified: Jul. 22, 2025
- Vuln Type: Authentication
-
0.0
NACVE-2025-38352
In the Linux kernel, the following vulnerability has been resolved: posix-cpu-timers: fix race between handle_posix_cpu_timers() and posix_cpu_timer_del() If an exiting non-autoreaping task has already passed exit_notify() and calls handle_posix_cpu_tim... Read more
Affected Products : linux_kernel- Published: Jul. 22, 2025
- Modified: Jul. 22, 2025
- Vuln Type: Race Condition