Latest CVE Feed
-
10.0
CRITICALCVE-2025-49414
Unrestricted Upload of File with Dangerous Type vulnerability in Fastw3b LLC FW Gallery allows Using Malicious Files. This issue affects FW Gallery: from n/a through 8.0.0.... Read more
Affected Products :- Published: Jul. 04, 2025
- Modified: Jul. 08, 2025
-
6.8
MEDIUMCVE-2025-49303
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Shabti Kaplan Frontend Admin by DynamiApps allows Path Traversal. This issue affects Frontend Admin by DynamiApps: from n/a through 3.28.7.... Read more
Affected Products : frontend_admin- Published: Jul. 04, 2025
- Modified: Jul. 08, 2025
-
10.0
CRITICALCVE-2025-49302
Improper Control of Generation of Code ('Code Injection') vulnerability in Scott Paterson Easy Stripe allows Remote Code Inclusion. This issue affects Easy Stripe: from n/a through 1.1.... Read more
Affected Products :- Published: Jul. 04, 2025
- Modified: Jul. 08, 2025
-
7.1
HIGHCVE-2025-49274
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in awplife Neom Blog allows Reflected XSS. This issue affects Neom Blog: from n/a through 0.0.9.... Read more
Affected Products :- Published: Jul. 04, 2025
- Modified: Jul. 08, 2025
-
7.1
HIGHCVE-2025-49247
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in cmoreira Team Showcase allows DOM-Based XSS. This issue affects Team Showcase: from n/a through n/a.... Read more
Affected Products :- Published: Jul. 04, 2025
- Modified: Jul. 08, 2025
-
7.1
HIGHCVE-2025-49245
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in cmoreira Testimonials Showcase allows Reflected XSS. This issue affects Testimonials Showcase: from n/a through 1.9.16.... Read more
Affected Products :- Published: Jul. 04, 2025
- Modified: Jul. 08, 2025
-
7.5
HIGHCVE-2025-49070
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in NasaTheme Elessi allows PHP Local File Inclusion. This issue affects Elessi: from n/a through n/a.... Read more
Affected Products :- Published: Jul. 04, 2025
- Modified: Jul. 08, 2025
-
6.5
MEDIUMCVE-2025-48231
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in codepeople Booking Calendar Contact Form allows Stored XSS. This issue affects Booking Calendar Contact Form: from n/a through 1.2.58.... Read more
Affected Products : booking_calendar- Published: Jul. 04, 2025
- Modified: Jul. 08, 2025
-
6.5
MEDIUMCVE-2025-47634
Missing Authorization vulnerability in Keylor Mendoza WC Pickup Store allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects WC Pickup Store: from n/a through 1.8.9.... Read more
Affected Products :- Published: Jul. 04, 2025
- Modified: Jul. 08, 2025
-
7.5
HIGHCVE-2025-47627
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in LCweb PrivateContent - Mail Actions allows PHP Local File Inclusion. This issue affects PrivateContent - Mail Actions: from n/a throug... Read more
Affected Products :- Published: Jul. 04, 2025
- Modified: Jul. 08, 2025
-
6.3
MEDIUMCVE-2025-47565
Missing Authorization vulnerability in ashanjay EventON allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects EventON: from n/a through 4.9.9.... Read more
Affected Products : eventon-lite- Published: Jul. 04, 2025
- Modified: Jul. 08, 2025
-
9.8
CRITICALCVE-2025-47479
Weak Authentication vulnerability in AresIT WP Compress allows Authentication Abuse. This issue affects WP Compress: from n/a through 6.30.30.... Read more
Affected Products : wp_compress- Published: Jul. 04, 2025
- Modified: Aug. 14, 2025
-
7.1
HIGHCVE-2025-39487
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ValvePress Rankie allows Reflected XSS. This issue affects Rankie: from n/a through 1.8.2.... Read more
Affected Products : rankie- Published: Jul. 04, 2025
- Modified: Jul. 08, 2025
-
7.1
HIGHCVE-2025-32311
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in QuanticaLabs Pressroom - News Magazine WordPress Theme allows Reflected XSS. This issue affects Pressroom - News Magazine WordPress Theme: from n/a throu... Read more
Affected Products :- Published: Jul. 04, 2025
- Modified: Jul. 08, 2025
-
8.5
HIGHCVE-2025-32297
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in quantumcloud Simple Link Directory allows SQL Injection. This issue affects Simple Link Directory: from n/a through 14.7.3.... Read more
Affected Products : simple_link_directory- Published: Jul. 04, 2025
- Modified: Jul. 08, 2025
-
7.1
HIGHCVE-2025-31037
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in favethemes Homey allows Reflected XSS. This issue affects Homey: from n/a through 2.4.5.... Read more
Affected Products : homey- Published: Jul. 04, 2025
- Modified: Jul. 08, 2025
-
10.0
CRITICALCVE-2025-30933
Unrestricted Upload of File with Dangerous Type vulnerability in LiquidThemes LogisticsHub allows Upload a Web Shell to a Web Server. This issue affects LogisticsHub: from n/a through 1.1.6.... Read more
Affected Products :- Published: Jul. 04, 2025
- Modified: Jul. 08, 2025
-
9.8
CRITICALCVE-2025-28983
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ClickandPledge Click & Pledge Connect allows Privilege Escalation. This issue affects Click & Pledge Connect: from 25.04010101 through WP6.8.... Read more
Affected Products :- Published: Jul. 04, 2025
- Modified: Jul. 08, 2025
-
7.7
HIGHCVE-2025-28980
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in machouinard Aviation Weather from NOAA allows Path Traversal. This issue affects Aviation Weather from NOAA: from n/a through 0.7.2.... Read more
Affected Products :- Published: Jul. 04, 2025
- Modified: Jul. 08, 2025
-
7.1
HIGHCVE-2025-28978
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Hung Trang Si SB Breadcrumbs allows Reflected XSS. This issue affects SB Breadcrumbs: from n/a through 1.0.... Read more
Affected Products :- Published: Jul. 04, 2025
- Modified: Jul. 08, 2025