Latest CVE Feed
-
0.0
NACVE-2025-38176
In the Linux kernel, the following vulnerability has been resolved: binder: fix use-after-free in binderfs_evict_inode() Running 'stress-ng --binderfs 16 --timeout 300' under KASAN-enabled kernel, I've noticed the following: BUG: KASAN: slab-use-after-... Read more
Affected Products : linux_kernel- Published: Jul. 04, 2025
- Modified: Jul. 08, 2025
- Vuln Type: Memory Corruption
-
0.0
NACVE-2025-38175
In the Linux kernel, the following vulnerability has been resolved: binder: fix yet another UAF in binder_devices Commit e77aff5528a18 ("binderfs: fix use-after-free in binder_devices") addressed a use-after-free where devices could be released without ... Read more
Affected Products : linux_kernel- Published: Jul. 04, 2025
- Modified: Jul. 08, 2025
- Vuln Type: Memory Corruption
-
0.0
NACVE-2025-38174
In the Linux kernel, the following vulnerability has been resolved: thunderbolt: Do not double dequeue a configuration request Some of our devices crash in tb_cfg_request_dequeue(): general protection fault, probably for non-canonical address 0xdead00... Read more
Affected Products : linux_kernel- Published: Jul. 04, 2025
- Modified: Jul. 08, 2025
- Vuln Type: Memory Corruption
-
7.5
HIGHCVE-2025-5920
The Sharable Password Protected Posts before version 1.1.1 allows access to password protected posts by providing a secret key in a GET parameter. However, the key is exposed by the REST API.... Read more
Affected Products :- Published: Jul. 04, 2025
- Modified: Jul. 08, 2025
- Vuln Type: Information Disclosure
-
6.5
MEDIUMCVE-2025-5351
A flaw was found in the key export functionality of libssh. The issue occurs in the internal function responsible for converting cryptographic keys into serialized formats. During error handling, a memory structure is freed but not cleared, leading to a p... Read more
- Published: Jul. 04, 2025
- Modified: Aug. 22, 2025
- Vuln Type: Memory Corruption
-
4.3
MEDIUMCVE-2025-53569
Cross-Site Request Forgery (CSRF) vulnerability in Trust Payments Trust Payments Gateway for WooCommerce (JavaScript Library) allows Cross Site Request Forgery. This issue affects Trust Payments Gateway for WooCommerce (JavaScript Library): from n/a throu... Read more
Affected Products :- Published: Jul. 04, 2025
- Modified: Jul. 08, 2025
- Vuln Type: Cross-Site Request Forgery
-
4.3
MEDIUMCVE-2025-53568
Cross-Site Request Forgery (CSRF) vulnerability in Tony Zeoli Radio Station allows Cross Site Request Forgery. This issue affects Radio Station: from n/a through 2.5.12.... Read more
Affected Products : radio_station- Published: Jul. 04, 2025
- Modified: Jul. 08, 2025
- Vuln Type: Cross-Site Request Forgery
-
6.5
MEDIUMCVE-2025-53566
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in osama.esh WP Visitor Statistics (Real Time Traffic) allows Stored XSS. This issue affects WP Visitor Statistics (Real Time Traffic): from n/a through 7.8... Read more
Affected Products :- Published: Jul. 04, 2025
- Modified: Jul. 08, 2025
- Vuln Type: Cross-Site Scripting
-
6.5
MEDIUMCVE-2025-30983
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in gopiplus Card flip image slideshow allows DOM-Based XSS. This issue affects Card flip image slideshow: from n/a through 1.5.... Read more
Affected Products :- Published: Jul. 04, 2025
- Modified: Jul. 08, 2025
- Vuln Type: Cross-Site Scripting
-
8.5
HIGHCVE-2025-30979
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in gopiplus Pixelating image slideshow gallery allows SQL Injection. This issue affects Pixelating image slideshow gallery: from n/a through 8.0.... Read more
Affected Products :- Published: Jul. 04, 2025
- Modified: Jul. 08, 2025
- Vuln Type: Injection
-
8.5
HIGHCVE-2025-30969
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in gopiplus iFrame Images Gallery allows SQL Injection. This issue affects iFrame Images Gallery: from n/a through 9.0.... Read more
Affected Products :- Published: Jul. 04, 2025
- Modified: Jul. 08, 2025
- Vuln Type: Injection
-
8.5
HIGHCVE-2025-30947
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in gopiplus Cool fade popup allows Blind SQL Injection. This issue affects Cool fade popup: from n/a through 10.1.... Read more
Affected Products :- Published: Jul. 04, 2025
- Modified: Jul. 08, 2025
- Vuln Type: Injection
-
6.5
MEDIUMCVE-2025-30943
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Aakif Kadiwala Posts Slider Shortcode allows DOM-Based XSS. This issue affects Posts Slider Shortcode: from n/a through 1.0.... Read more
Affected Products :- Published: Jul. 04, 2025
- Modified: Jul. 08, 2025
- Vuln Type: Cross-Site Scripting
-
5.3
MEDIUMCVE-2025-30929
Missing Authorization vulnerability in amazewp fluXtore allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects fluXtore: from n/a through 1.6.0.... Read more
Affected Products :- Published: Jul. 04, 2025
- Modified: Jul. 08, 2025
- Vuln Type: Authorization
-
5.3
MEDIUMCVE-2025-29012
Missing Authorization vulnerability in kamleshyadav CF7 7 Mailchimp Add-on allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects CF7 7 Mailchimp Add-on: from n/a through 2.2.... Read more
Affected Products :- Published: Jul. 04, 2025
- Modified: Jul. 08, 2025
- Vuln Type: Authorization
-
4.3
MEDIUMCVE-2025-29007
Missing Authorization vulnerability in LMSACE LMSACE Connect allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects LMSACE Connect: from n/a through 3.4.... Read more
Affected Products :- Published: Jul. 04, 2025
- Modified: Jul. 08, 2025
- Vuln Type: Authorization
-
4.3
MEDIUMCVE-2025-29001
Missing Authorization vulnerability in ZoomIt WooCommerce Shop Page Builder allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects WooCommerce Shop Page Builder: from n/a through 2.27.7.... Read more
Affected Products :- Published: Jul. 04, 2025
- Modified: Jul. 08, 2025
- Vuln Type: Authorization
-
5.9
MEDIUMCVE-2025-28971
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CWD Web Designer Easy Elements Hider allows Stored XSS. This issue affects Easy Elements Hider: from n/a through 2.0.... Read more
Affected Products :- Published: Jul. 04, 2025
- Modified: Jul. 08, 2025
- Vuln Type: Cross-Site Scripting
-
8.5
HIGHCVE-2025-28969
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in cybio Gallery Widget allows SQL Injection. This issue affects Gallery Widget: from n/a through 1.2.1.... Read more
Affected Products :- Published: Jul. 04, 2025
- Modified: Jul. 08, 2025
- Vuln Type: Injection
-
8.5
HIGHCVE-2025-28967
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Steve Truman Contact Us page - Contact people LITE allows SQL Injection. This issue affects Contact Us page - Contact people LITE: from n/a through 3.7.4... Read more
Affected Products : contact_us_page_-_contact_people- Published: Jul. 04, 2025
- Modified: Jul. 08, 2025
- Vuln Type: Injection