Latest CVE Feed
-
8.4
HIGHCVE-2025-5964
A path traversal issue in the API endpoint in M-Files Server before version 25.6.14925.0 allows an authenticated user to read files in the server.... Read more
Affected Products : m-files_server- Published: Jun. 15, 2025
- Modified: Jun. 16, 2025
- Vuln Type: Path Traversal
-
5.3
MEDIUMCVE-2025-6092
A vulnerability was found in comfyanonymous comfyui up to 0.3.39. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /upload/image of the component Incomplete Fix CVE-2024-10099. The manipulation of... Read more
Affected Products :- Published: Jun. 15, 2025
- Modified: Jun. 16, 2025
- Vuln Type: Cross-Site Scripting
-
7.6
HIGHCVE-2025-5990
An input neutralization vulnerability in the Server Name form and API Key form components of Crafty Controller allows a remote, authenticated attacker to perform stored XSS via malicious form input.... Read more
Affected Products : crafty_controller- Published: Jun. 15, 2025
- Modified: Aug. 11, 2025
- Vuln Type: Cross-Site Scripting
-
9.0
HIGHCVE-2025-6091
A vulnerability was found in H3C GR-3000AX V100R007L50. It has been classified as critical. Affected is the function UpdateWanParamsMulti/UpdateIpv6Params of the file /routing/goform/aspForm. The manipulation of the argument param leads to buffer overflow... Read more
Affected Products :- Published: Jun. 15, 2025
- Modified: Jun. 16, 2025
- Vuln Type: Memory Corruption
-
6.9
MEDIUMCVE-2024-25573
Unsanitized user-supplied data saved in the PingFederate Administrative Console could trigger the execution of JavaScript code in subsequent user processing.... Read more
Affected Products : pingfederate- Published: Jun. 15, 2025
- Modified: Jun. 16, 2025
- Vuln Type: Cross-Site Scripting
-
9.0
HIGHCVE-2025-6090
A vulnerability was found in H3C GR-5400AX V100R009L50 and classified as critical. This issue affects the function UpdateWanparamsMulti/UpdateIpv6params of the file /routing/goform/aspForm. The manipulation of the argument param leads to buffer overflow. ... Read more
Affected Products : gr-5400ax_firmware- Published: Jun. 15, 2025
- Modified: Jun. 16, 2025
- Vuln Type: Memory Corruption
-
6.9
MEDIUMCVE-2025-22854
Improper handling of non-200 http responses in the PingFederate Google Adapter leads to thread exhaustion under normal usage conditions.... Read more
Affected Products : pingfederate- Published: Jun. 15, 2025
- Modified: Jun. 16, 2025
- Vuln Type: Denial of Service
-
2.1
LOWCVE-2025-21085
PingFederate OAuth2 grant duplication in PostgreSQL persistent storage allows OAuth2 requests to use excessive memory utilization.... Read more
Affected Products : pingfederate- Published: Jun. 15, 2025
- Modified: Jun. 16, 2025
- Vuln Type: Denial of Service
-
5.3
MEDIUMCVE-2025-6089
A vulnerability has been found in Astun Technology iShare Maps 5.4.0 and classified as problematic. This vulnerability affects unknown code of the file atCheckJS.aspx. The manipulation of the argument ref leads to open redirect. The attack can be initiate... Read more
Affected Products :- Published: Jun. 15, 2025
- Modified: Jun. 16, 2025
- Vuln Type: Misconfiguration
-
9.8
CRITICALCVE-2025-36041
IBM MQ Operator LTS 2.0.0 through 2.0.29, MQ Operator CD 3.0.0, 3.0.1, 3.1.0 through 3.1.3, 3.3.0, 3.4.0, 3.4.1, 3.5.0, 3.5.1 through 3.5.3, and MQ Operator SC2 3.2.0 through 3.2.12 Native HA CRR could be configured with a private key and chain other than... Read more
- Published: Jun. 15, 2025
- Modified: Aug. 22, 2025
- Vuln Type: Misconfiguration
-
7.8
HIGHCVE-2025-1411
IBM Security Verify Directory Container 10.0.0.0 through 10.0.3.1 could allow a local user to execute commands as root due to execution with unnecessary privileges.... Read more
Affected Products : security_verify_directory- Published: Jun. 15, 2025
- Modified: Aug. 11, 2025
- Vuln Type: Authorization
-
6.4
MEDIUMCVE-2025-5337
The Slider, Gallery, and Carousel by MetaSlider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘aria-label’ parameter in all versions up to, and including, 3.98.0 due to insufficient input sanitization and output escaping. This ... Read more
Affected Products : slider\,_gallery\,_and_carousel- Published: Jun. 14, 2025
- Modified: Jul. 09, 2025
- Vuln Type: Cross-Site Scripting
-
6.4
MEDIUMCVE-2025-5238
The YITH WooCommerce Wishlist plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘id’ parameter in all versions up to, and including, 4.5.0 due to insufficient input sanitization and output escaping. This makes it possible for authe... Read more
Affected Products : yith_woocommerce_wishlist- Published: Jun. 14, 2025
- Modified: Jun. 16, 2025
- Vuln Type: Cross-Site Scripting
-
6.4
MEDIUMCVE-2025-4667
The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's ssa_admin_upcoming_appointments, ssa_admin_upcoming_appointments, and ssa_past_appointments s... Read more
Affected Products : simply_schedule_appointments- Published: Jun. 14, 2025
- Modified: Jun. 16, 2025
- Vuln Type: Cross-Site Scripting
-
6.5
MEDIUMCVE-2025-6070
The Restrict File Access plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.1.2 via the output() function. This makes it possible for authenticated attackers, with Subscriber-level access and above, to read t... Read more
Affected Products :- Published: Jun. 14, 2025
- Modified: Jun. 16, 2025
- Vuln Type: Path Traversal
-
9.1
CRITICALCVE-2025-6065
The Image Resizer On The Fly plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the 'delete' task in all versions up to, and including, 1.1. This makes it possible for unauthenticated attackers to del... Read more
Affected Products :- Published: Jun. 14, 2025
- Modified: Jun. 16, 2025
- Vuln Type: Path Traversal
-
6.1
MEDIUMCVE-2025-6064
The WP URL Shortener plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.2. This is due to missing or incorrect nonce validation on the 'url_shortener_settings' page. This makes it possible for unauthen... Read more
Affected Products :- Published: Jun. 14, 2025
- Modified: Jun. 16, 2025
- Vuln Type: Cross-Site Request Forgery
-
6.1
MEDIUMCVE-2025-6063
The XiSearch bar plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.6. This is due to missing or incorrect nonce validation on the 'xisearch-key-config' page. This makes it possible for unauthenticated... Read more
Affected Products :- Published: Jun. 14, 2025
- Modified: Jun. 16, 2025
- Vuln Type: Cross-Site Request Forgery
-
4.3
MEDIUMCVE-2025-6062
The Yougler Blogger Profile Page plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, v1.01. This is due to missing or incorrect nonce validation on the 'yougler-plugin.php' page. This makes it possible fo... Read more
Affected Products :- Published: Jun. 14, 2025
- Modified: Jun. 16, 2025
- Vuln Type: Cross-Site Request Forgery
-
6.4
MEDIUMCVE-2025-6061
The kk Youtube Video plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'kkytv' shortcode in all versions up to, and including, 0.2 due to insufficient input sanitization and output escaping on user supplied attributes. Thi... Read more
Affected Products :- Published: Jun. 14, 2025
- Modified: Jun. 16, 2025
- Vuln Type: Cross-Site Scripting