Latest CVE Feed
-
7.8
HIGHCVE-2025-6020
A flaw was found in linux-pam. The module pam_namespace may use access user-controlled paths without proper protection, allowing local users to elevate their privileges to root via multiple symlink attacks and race conditions.... Read more
- Published: Jun. 17, 2025
- Modified: Aug. 26, 2025
- Vuln Type: Path Traversal
-
9.3
CRITICALCVE-2025-5777
Insufficient input validation leading to memory overread when the NetScaler is configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) OR AAA virtual server... Read more
- Actively Exploited
- Published: Jun. 17, 2025
- Modified: Aug. 14, 2025
- Vuln Type: Memory Corruption
-
8.8
HIGHCVE-2025-5349
Improper access control on the NetScaler Management Interface in NetScaler ADC and NetScaler Gateway... Read more
- Published: Jun. 17, 2025
- Modified: Aug. 06, 2025
- Vuln Type: Authentication
-
7.5
HIGH- Published: Jun. 17, 2025
- Modified: Aug. 06, 2025
- Vuln Type: Information Disclosure
-
6.4
MEDIUMCVE-2025-5700
The Simple Logo Carousel plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘id’ parameter in all versions up to, and including, 1.9.3 due to insufficient input sanitization and output escaping. This makes it possible for authentica... Read more
Affected Products :- Published: Jun. 17, 2025
- Modified: Jun. 17, 2025
- Vuln Type: Cross-Site Scripting
-
6.4
MEDIUMCVE-2025-5291
The Master Slider – Responsive Touch Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's masterslider_pb and ms_slide shortcodes in all versions up to, and including, 3.10.8 due to insufficient input sanitization and ... Read more
Affected Products : master_slider- Published: Jun. 17, 2025
- Modified: Jul. 02, 2025
- Vuln Type: Cross-Site Scripting
-
4.3
MEDIUMCVE-2025-3880
The Poll, Survey & Quiz Maker Plugin by Opinion Stage plugin for WordPress is vulnerable to unauthorized modification of data due to a misconfigured capability check on several functions in all versions up to, and including, 19.9.0. This makes it possible... Read more
Affected Products : poll\,_survey_\&_quiz_maker- Published: Jun. 17, 2025
- Modified: Jul. 09, 2025
- Vuln Type: Authorization
-
4.8
MEDIUMCVE-2025-6050
Mezzanine CMS, in versions prior to 6.1.1, contains a Stored Cross-Site Scripting (XSS) vulnerability in the admin interface. The vulnerability exists in the "displayable_links_js" function, which fails to properly sanitize blog post titles before includi... Read more
Affected Products : mezzanine- Published: Jun. 17, 2025
- Modified: Jul. 30, 2025
- Vuln Type: Cross-Site Scripting
-
9.8
CRITICALCVE-2025-3515
The Drag and Drop Multiple File Upload for Contact Form 7 plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in all versions up to, and including, 1.3.8.9. This makes it possible for unauthenticated attac... Read more
Affected Products : drag_and_drop_multiple_file_upload_-_contact_form_7- Published: Jun. 17, 2025
- Modified: Aug. 11, 2025
- Vuln Type: Authentication
-
5.1
MEDIUMCVE-2025-40674
Reflected Cross-Site Scripting (XSS) in osCommerce v4. This vulnerability allows an attacker to execute JavaScript code in the victim's browser by sending the victim a malicious URL using the name of any parameter in /watch/en/about-us. This vulnerability... Read more
Affected Products : oscommerce- Published: Jun. 17, 2025
- Modified: Jun. 17, 2025
- Vuln Type: Cross-Site Scripting
-
7.2
HIGHCVE-2025-6173
A vulnerability classified as critical was found in Webkul QloApps 1.6.1. Affected by this vulnerability is an unknown functionality of the file /admin/ajax_products_list.php. The manipulation of the argument packItself leads to sql injection. The attack ... Read more
Affected Products : qloapps- Published: Jun. 17, 2025
- Modified: Jun. 26, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-6167
A vulnerability classified as critical has been found in themanojdesai python-a2a up to 0.5.5. Affected is the function create_workflow of the file python_a2a/agent_flow/server/api.py. The manipulation leads to path traversal. Upgrading to version 0.5.6 i... Read more
Affected Products : python_a2a- Published: Jun. 17, 2025
- Modified: Jul. 02, 2025
- Vuln Type: Path Traversal
-
5.1
MEDIUMCVE-2025-6166
A vulnerability was found in frdel Agent-Zero up to 0.8.4. It has been rated as problematic. This issue affects the function image_get of the file /python/api/image_get.py. The manipulation of the argument path leads to path traversal. Upgrading to versio... Read more
Affected Products :- Published: Jun. 17, 2025
- Modified: Jun. 17, 2025
- Vuln Type: Path Traversal
-
9.0
HIGHCVE-2025-6165
A vulnerability was found in TOTOLINK X15 1.0.0-B20230714.1105. It has been declared as critical. This vulnerability affects unknown code of the file /boafrm/formTmultiAP of the component HTTP POST Request Handler. The manipulation of the argument submit-... Read more
- Published: Jun. 17, 2025
- Modified: Jun. 23, 2025
- Vuln Type: Memory Corruption
-
9.0
HIGHCVE-2025-6164
A vulnerability was found in TOTOLINK A3002R 4.0.0-B20230531.1404. It has been classified as critical. This affects an unknown part of the file /boafrm/formMultiAP of the component HTTP POST Request Handler. The manipulation of the argument submit-url lea... Read more
- Published: Jun. 17, 2025
- Modified: Jun. 23, 2025
- Vuln Type: Memory Corruption
-
4.8
MEDIUMCVE-2025-5209
The Ivory Search WordPress plugin before 5.5.10 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed... Read more
Affected Products : ivory_search- Published: Jun. 17, 2025
- Modified: Jun. 26, 2025
- Vuln Type: Cross-Site Scripting
-
9.0
HIGHCVE-2025-6163
A vulnerability was found in TOTOLINK A3002RU 3.0.0-B20230809.1615 and classified as critical. Affected by this issue is some unknown functionality of the file /boafrm/formMultiAP of the component HTTP POST Request Handler. The manipulation of the argumen... Read more
- Published: Jun. 17, 2025
- Modified: Jun. 23, 2025
- Vuln Type: Memory Corruption
-
9.0
HIGHCVE-2025-6162
A vulnerability has been found in TOTOLINK EX1200T 4.1.2cu.5232_B20210713 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /boafrm/formMultiAP of the component HTTP POST Request Handler. The manipulation o... Read more
- Published: Jun. 17, 2025
- Modified: Jun. 23, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2025-6161
A vulnerability, which was classified as critical, was found in SourceCodester Simple Food Ordering System 1.0. Affected is an unknown function of the file /editproduct.php. The manipulation of the argument photo leads to unrestricted upload. It is possib... Read more
Affected Products : simple_food_ordering_system simple_food_ordering_system simple_food_ordering_system- Published: Jun. 17, 2025
- Modified: Jul. 07, 2025
- Vuln Type: Authentication
-
9.8
CRITICALCVE-2025-6160
A vulnerability, which was classified as critical, has been found in SourceCodester Client Database Management System 1.0. This issue affects some unknown processing of the file /user_customer_create_order.php. The manipulation of the argument user_id lea... Read more
- Published: Jun. 17, 2025
- Modified: Jun. 26, 2025
- Vuln Type: Injection