Latest CVE Feed
-
4.3
MEDIUMCVE-2025-5846
An issue has been discovered in GitLab EE affecting all versions from 16.10 before 17.11.5, 18.0 before 18.0.3, and 18.1 before 18.1.1 that could have allowed authenticated users to assign unrelated compliance frameworks to projects by sending crafted Gra... Read more
Affected Products : gitlab- Published: Jun. 26, 2025
- Modified: Aug. 12, 2025
- Vuln Type: Authorization
-
4.3
MEDIUMCVE-2025-5315
An issue has been discovered in GitLab CE/EE affecting all versions from 17.2 before 17.11.5, 18.0 before 18.0.3, and 18.1 before 18.1.1 that could have allowed authenticated users with Guest role permissions to add child items to incident work items by s... Read more
Affected Products : gitlab- Published: Jun. 26, 2025
- Modified: Aug. 12, 2025
- Vuln Type: Authorization
-
5.1
MEDIUMCVE-2025-48497
Cross-site request forgery vulnerability exists in iroha Board versions v0.10.12 and earlier. If a user accesses a specially crafted URL while being logged in to the affected product, arbitrary learning histories may be registered.... Read more
Affected Products :- Published: Jun. 26, 2025
- Modified: Jun. 26, 2025
- Vuln Type: Cross-Site Request Forgery
-
5.3
MEDIUMCVE-2025-41404
Direct request ('Forced Browsing') issue exists in iroha Board versions v0.10.12 and earlier. If this vulnerability is exploited, non-public contents may be viewed by an attacker who can log in to the affected product.... Read more
Affected Products :- Published: Jun. 26, 2025
- Modified: Jun. 26, 2025
- Vuln Type: Authorization
-
6.5
MEDIUMCVE-2025-3279
An issue has been discovered in GitLab CE/EE affecting all versions from 10.7 before 17.11.5, 18.0 before 18.0.3, and 18.1 before 18.1.1 that could have allowed authenticated attackers to create a DoS condition by sending crafted GraphQL requests.... Read more
Affected Products : gitlab- Published: Jun. 26, 2025
- Modified: Aug. 12, 2025
- Vuln Type: Denial of Service
-
8.7
HIGHCVE-2025-37101
A potential security vulnerability has been identified in HPE OneView for VMware vCenter (OV4VC). This vulnerability could be exploited allowing an attacker with read only privilege to cause Vertical Privilege Escalation (operator can perform admin action... Read more
Affected Products :- Published: Jun. 26, 2025
- Modified: Jun. 26, 2025
- Vuln Type: Authorization
-
8.8
HIGHCVE-2025-2938
An issue has been discovered in GitLab CE/EE affecting all versions from 17.3 before 17.11.5, 18.0 before 18.0.3, and 18.1 before 18.1.1 that could have allowed authenticated users to gain elevated project privileges by requesting access to projects where... Read more
Affected Products : gitlab- Published: Jun. 26, 2025
- Modified: Aug. 12, 2025
- Vuln Type: Authorization
-
5.3
MEDIUMCVE-2025-1754
An issue has been discovered in GitLab CE/EE affecting all versions from 17.2 before 17.11.5, 18.0 before 18.0.3, and 18.1 before 18.1.1 that could have allowed unauthenticated attackers to upload arbitrary files to public projects by sending crafted API ... Read more
Affected Products : gitlab- Published: Jun. 26, 2025
- Modified: Aug. 12, 2025
- Vuln Type: Authentication
-
7.2
HIGHCVE-2025-6624
Versions of the package snyk before 1.1297.3 are vulnerable to Insertion of Sensitive Information into Log File through local Snyk CLI debug logs. Container Registry credentials provided via environment variables or command line arguments can be exposed w... Read more
Affected Products : snyk_cli- Published: Jun. 26, 2025
- Modified: Jul. 09, 2025
- Vuln Type: Information Disclosure
-
6.4
MEDIUMCVE-2025-6546
The Drive Folder Embedder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘tablecssclass’ parameter in all versions up to, and including, 1.1.0 due to insufficient input sanitization and output escaping. This makes it possible fo... Read more
Affected Products : drive_folder_embedder- Published: Jun. 26, 2025
- Modified: Jul. 08, 2025
- Vuln Type: Cross-Site Scripting
-
6.4
MEDIUMCVE-2025-6540
The web-cam plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘slug’ parameter in all versions up to, and including, 1.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers... Read more
Affected Products : web-cam- Published: Jun. 26, 2025
- Modified: Jul. 07, 2025
- Vuln Type: Cross-Site Scripting
-
6.4
MEDIUMCVE-2025-6537
The Namasha By Mdesign plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘playicon_title’ parameter in all versions up to, and including, 1.2.00 due to insufficient input sanitization and output escaping. This makes it possible for... Read more
Affected Products : namasha- Published: Jun. 26, 2025
- Modified: Jul. 08, 2025
- Vuln Type: Cross-Site Scripting
-
4.3
MEDIUMCVE-2025-5932
The Homerunner plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.29. This is due to missing or incorrect nonce validation on the main_settings() function. This makes it possible for unauthenticated ... Read more
Affected Products : homerunner- Published: Jun. 26, 2025
- Modified: Jul. 07, 2025
- Vuln Type: Cross-Site Request Forgery
-
6.4
MEDIUMCVE-2025-5929
The The Countdown plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘clientId’ parameter in all versions up to, and including, 2.0.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticat... Read more
Affected Products : the_countdown- Published: Jun. 26, 2025
- Modified: Jul. 08, 2025
- Vuln Type: Cross-Site Scripting
-
5.3
MEDIUMCVE-2025-5813
The Amazon Products to WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the wcta2w_get_amazon_product_callback() function in all versions up to, and including, 1.2.7. This makes it po... Read more
Affected Products : amazon_products_to_woocommerce- Published: Jun. 26, 2025
- Modified: Jul. 07, 2025
- Vuln Type: Authorization
-
4.4
MEDIUMCVE-2025-5275
The Charitable – Donation Plugin for WordPress – Fundraising with Recurring Donations & More plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the privacy settings fields in all versions up to, and including, 1.8.6.1 due to insufficien... Read more
- Published: Jun. 26, 2025
- Modified: Jul. 08, 2025
- Vuln Type: Cross-Site Scripting
-
6.4
MEDIUMCVE-2025-6538
The Post Rating and Review plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘class’ parameter in all versions up to, and including, 1.3.4 due to insufficient input sanitization and output escaping. This makes it possible for authe... Read more
Affected Products : post_rating_and_review- Published: Jun. 26, 2025
- Modified: Jul. 07, 2025
- Vuln Type: Cross-Site Scripting
-
6.4
MEDIUMCVE-2025-6383
The WP-PhotoNav plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's photonav shortcode in all versions up to, and including, 1.2.2 due to insufficient input sanitization and output escaping on user supplied attributes. This ... Read more
Affected Products : wp-photonav- Published: Jun. 26, 2025
- Modified: Jul. 08, 2025
- Vuln Type: Cross-Site Scripting
-
6.4
MEDIUMCVE-2025-6378
The Responsive Food and Drink Menu plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's display_pdf_menus shortcode in all versions up to, and including, 2.3 due to insufficient input sanitization and output escaping on user ... Read more
Affected Products : responsive_food_and_drink_menu- Published: Jun. 26, 2025
- Modified: Jul. 07, 2025
- Vuln Type: Cross-Site Scripting
-
6.4
MEDIUMCVE-2025-6290
The Tournament Bracket Generator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'bracket' shortcode in all versions up to, and including, 1.0.0 due to insufficient input sanitization and output escaping on user supplied... Read more
Affected Products : tournament_bracket_generator- Published: Jun. 26, 2025
- Modified: Jul. 08, 2025
- Vuln Type: Cross-Site Scripting