Latest CVE Feed
-
6.4
MEDIUMCVE-2024-13427
The Page Builder: Pagelayer – Drag and Drop website builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Button widget in all versions up to, and including, 2.0.0 due to insufficient input sanitization and output esca... Read more
Affected Products : pagelayer- Published: May. 24, 2025
- Modified: May. 28, 2025
- Vuln Type: Cross-Site Scripting
-
9.8
CRITICALCVE-2025-5119
A vulnerability has been found in Emlog Pro 2.5.11 and classified as critical. This vulnerability affects unknown code of the file /include/controller/api_controller.php. The manipulation of the argument tag leads to sql injection. The attack can be initi... Read more
Affected Products : emlog- Published: May. 23, 2025
- Modified: Jun. 10, 2025
- Vuln Type: Injection
-
6.8
MEDIUMCVE-2025-48741
A Broken Access Control vulnerability in StrangeBee TheHive 5.2.0 before 5.2.16, 5.3.0 before 5.3.11, and 5.4.0 before 5.4.10 allows remote, authenticated, and unprivileged users to retrieve alerts, cases, logs, observables, or tasks, regardless of the us... Read more
Affected Products : thehive- Published: May. 23, 2025
- Modified: May. 28, 2025
- Vuln Type: Authorization
-
5.9
MEDIUMCVE-2025-48740
A Cross-Site Request Forgery (CSRF) vulnerability in StrangeBee TheHive 5.2.0 before 5.2.16, 5.3.0 before 5.3.11, 5.4.0 before 5.4.10, and 5.5.0 before 5.5.1 allows a remote attacker to trigger requests on their victim's behalf, if the attacker lures a pr... Read more
Affected Products : thehive- Published: May. 23, 2025
- Modified: May. 28, 2025
- Vuln Type: Cross-Site Request Forgery
-
4.6
MEDIUMCVE-2025-48739
A Server-Side Request Forgery (SSRF) vulnerability in StrangeBee TheHive 5.2.0 before 5.2.16, 5.3.0 before 5.3.11, 5.4.0 before 5.4.10, and 5.5.0 before 5.5.1 allows remote authenticated attackers with admin permissions (allowing them to access specific A... Read more
Affected Products : thehive- Published: May. 23, 2025
- Modified: May. 28, 2025
- Vuln Type: Server-Side Request Forgery
-
6.9
MEDIUMCVE-2025-48738
An e-mail flooding vulnerability in StrangeBee TheHive 5.2.0 before 5.2.16, 5.3.0 before 5.3.11, 5.4.0 before 5.4.10, and 5.5.0 before 5.5.1 allows unauthenticated remote attackers to use the password reset feature without limits. This can lead to several... Read more
Affected Products : thehive- Published: May. 23, 2025
- Modified: May. 28, 2025
- Vuln Type: Denial of Service
-
4.3
MEDIUMCVE-2025-48735
A SQL Injection issue in the request body processing in BOS IPCs with firmware 21.45.8.2.2_220219 before 21.45.8.2.3_230220 allows remote attackers to obtain sensitive information from the database via crafted input in the request body.... Read more
Affected Products :- Published: May. 23, 2025
- Modified: May. 28, 2025
- Vuln Type: Injection
-
6.5
MEDIUMCVE-2025-46176
Hardcoded credentials in the Telnet service in D-Link DIR-605L v2.13B01 and DIR-816L v2.06B01 allow attackers to remotely execute arbitrary commands via firmware analysis.... Read more
- Published: May. 23, 2025
- Modified: Jun. 03, 2025
- Vuln Type: Authentication
-
6.1
MEDIUMCVE-2025-44998
A stored cross-site scripting (XSS) vulnerability in the component /tinyfilemanager.php of TinyFileManager v2.4.7 allows attackers to execute arbitrary JavaScript or HTML via injecting a crafted payload into the js-theme-3 parameter.... Read more
Affected Products : tinyfilemanager- Published: May. 23, 2025
- Modified: Jul. 11, 2025
- Vuln Type: Cross-Site Scripting
-
4.4
MEDIUMCVE-2024-51102
PHPGURUKUL Student Management System using PHP and MySQL v1 was discovered to contain multiple SQL injection vulnerabilities at /studentrecordms/login.php via the username and password parameters.... Read more
Affected Products : student_management_system- Published: May. 23, 2025
- Modified: Jun. 03, 2025
- Vuln Type: Injection
-
8.7
HIGHCVE-2023-34873
On MOBOTIX P3 cameras before MX-V4.7.2.18 and Mx6 cameras before MX-V5.2.0.61, the tcpdump feature does not properly validate input, which allows authenticated users to execute code.... Read more
Affected Products :- Published: May. 23, 2025
- Modified: May. 28, 2025
- Vuln Type: Authentication
-
6.1
MEDIUMCVE-2025-48378
DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to version 9.13.9, uploaded SVG files could contain scripts and if rendered inline those scripts could run allowing XSS attacks. Version 9.... Read more
Affected Products : dotnetnuke- Published: May. 23, 2025
- Modified: Aug. 26, 2025
- Vuln Type: Cross-Site Scripting
-
6.0
MEDIUMCVE-2025-48377
DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to version 9.13.9, a specially crafted URL may be constructed which can inject an XSS payload that is triggered by using some module action... Read more
Affected Products : dotnetnuke- Published: May. 23, 2025
- Modified: Aug. 26, 2025
- Vuln Type: Cross-Site Scripting
-
3.5
LOWCVE-2025-48376
DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to version 9.13.9, a malicious SuperUser (Host) could craft a request to use an external url for a site export to then be imported. Version... Read more
Affected Products : dotnetnuke- Published: May. 23, 2025
- Modified: Aug. 26, 2025
- Vuln Type: Authorization
-
6.6
MEDIUMCVE-2025-48375
Schule is open-source school management system software. Prior to version 1.0.1, the file forgot_password.php (or equivalent endpoint responsible for email-based OTP generation) lacks proper rate limiting controls, allowing attackers to abuse the OTP requ... Read more
Affected Products :- Published: May. 23, 2025
- Modified: May. 28, 2025
- Vuln Type: Denial of Service
-
7.6
HIGHCVE-2025-43860
OpenEMR is a free and open source electronic health records and medical practice management application. A stored cross-site scripting (XSS) vulnerability in versions prior to 7.0.3.4 allows any authenticated user with patient creation and editing privile... Read more
Affected Products : openemr- Published: May. 23, 2025
- Modified: Jul. 02, 2025
- Vuln Type: Cross-Site Scripting
-
5.4
MEDIUMCVE-2025-32967
OpenEMR is a free and open source electronic health records and medical practice management application. A logging oversight in versions prior to 7.0.3.4 allows password change events to go unrecorded on the client-side log viewer, preventing administrato... Read more
Affected Products : openemr- Published: May. 23, 2025
- Modified: Jul. 02, 2025
- Vuln Type: Information Disclosure
-
7.6
HIGHCVE-2025-32794
OpenEMR is a free and open source electronic health records and medical practice management application. A stored cross-site scripting (XSS) vulnerability in versions prior to 7.0.3.4 allows any authenticated user with patient creation privileges to injec... Read more
Affected Products : openemr- Published: May. 23, 2025
- Modified: Jul. 02, 2025
- Vuln Type: Cross-Site Scripting
-
7.8
HIGHCVE-2025-24917
In Tenable Network Monitor versions prior to 6.5.1 on a Windows host, it was found that a non-administrative user could stage files in a local directory to run arbitrary code with SYSTEM privileges, potentially leading to local privilege escalation.... Read more
Affected Products :- Published: May. 23, 2025
- Modified: May. 28, 2025
- Vuln Type: Authorization
-
7.0
HIGHCVE-2025-24916
When installing Tenable Network Monitor to a non-default location on a Windows host, Tenable Network Monitor versions prior to 6.5.1 did not enforce secure permissions for sub-directories. This could allow for local privilege escalation if users had not s... Read more
Affected Products :- Published: May. 23, 2025
- Modified: May. 28, 2025
- Vuln Type: Misconfiguration