Latest CVE Feed
-
7.5
HIGHCVE-2025-39364
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in PluginEver Product Category Slider for WooCommerce allows PHP Local File Inclusion.This issue affects Product Category Slider for WooC... Read more
Affected Products :- Published: May. 19, 2025
- Modified: May. 21, 2025
- Vuln Type: Path Traversal
-
5.3
MEDIUMCVE-2025-39353
Missing Authorization vulnerability in ThemeGoods Grand Restaurant WordPress allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Grand Restaurant WordPress: from n/a through 7.0.... Read more
Affected Products : grand_restaurant- Published: May. 19, 2025
- Modified: May. 21, 2025
- Vuln Type: Authorization
-
4.3
MEDIUMCVE-2025-39351
Cross-Site Request Forgery (CSRF) vulnerability in ThemeGoods Grand Restaurant WordPress allows Cross Site Request Forgery.This issue affects Grand Restaurant WordPress: from n/a through 7.0.... Read more
Affected Products : grand_restaurant- Published: May. 19, 2025
- Modified: May. 21, 2025
- Vuln Type: Cross-Site Request Forgery
-
5.4
MEDIUMCVE-2025-26920
Missing Authorization vulnerability in PressMaximum Customify allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Customify: from n/a through 0.4.8.... Read more
Affected Products :- Published: May. 19, 2025
- Modified: May. 21, 2025
- Vuln Type: Authorization
-
5.3
MEDIUMCVE-2025-26867
Missing Authorization vulnerability in Themes4WP Bulk allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Bulk: from n/a through 1.0.11.... Read more
Affected Products :- Published: May. 19, 2025
- Modified: May. 21, 2025
- Vuln Type: Authorization
-
7.5
HIGHCVE-2025-4948
A flaw was found in the soup_multipart_new_from_message() function of the libsoup HTTP library, which is commonly used by GNOME and other applications to handle web communications. The issue occurs when the library processes specially crafted multipart me... Read more
- Published: May. 19, 2025
- Modified: Jul. 30, 2025
- Vuln Type: Denial of Service
-
6.1
MEDIUMCVE-2025-4939
A vulnerability classified as problematic was found in PHPGurukul Credit Card Application Management System 1.0. This vulnerability affects unknown code of the file /admin/new-ccapplication.php. The manipulation leads to cross site scripting. The attack c... Read more
Affected Products : credit_card_application_management_system- Published: May. 19, 2025
- Modified: May. 28, 2025
- Vuln Type: Cross-Site Scripting
-
9.8
CRITICALCVE-2025-4938
A vulnerability was found in PHPGurukul Employee Record Management System 1.3. It has been rated as critical. Affected by this issue is some unknown functionality of the file /registererms.php. The manipulation of the argument Email leads to sql injection... Read more
Affected Products : employee_record_management_system- Published: May. 19, 2025
- Modified: May. 28, 2025
- Vuln Type: Injection
-
6.0
MEDIUMCVE-2025-4876
ConnectWise-Password-Encryption-Utility.exe in ConnectWise Risk Assessment allows an attacker to extract a hardcoded AES decryption key via reverse engineering. This key is embedded in plaintext within the binary and used in cryptographic operations witho... Read more
Affected Products : risk_assessment- Published: May. 19, 2025
- Modified: Sep. 03, 2025
- Vuln Type: Cryptography
-
6.5
MEDIUMCVE-2025-32920
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in TemplateInvaders TI WooCommerce Wishlist allows Stored XSS.This issue affects TI WooCommerce Wishlist: from n/a through 2.10.0.... Read more
Affected Products : ti_woocommerce_wishlist- Published: May. 19, 2025
- Modified: Jun. 17, 2025
- Vuln Type: Cross-Site Scripting
-
5.5
MEDIUMCVE-2025-31262
A permissions issue was addressed with additional restrictions. This issue is fixed in visionOS 2.3, iOS 18.3 and iPadOS 18.3, macOS Sequoia 15.3, watchOS 11.3, tvOS 18.3. An app may be able to modify protected parts of the file system.... Read more
- Published: May. 19, 2025
- Modified: May. 28, 2025
- Vuln Type: Authorization
-
3.3
LOWCVE-2025-31185
A logic issue was addressed with improved checks. This issue is fixed in iOS 18.3 and iPadOS 18.3. Photos in the Hidden Photos Album may be viewed without authentication.... Read more
- Published: May. 19, 2025
- Modified: May. 28, 2025
- Vuln Type: Authentication
-
7.6
HIGHCVE-2025-26621
OpenCTI is an open source platform for managing cyber threat intelligence knowledge and observables. Prior to version 6.5.2, any user with the capability manage customizations can edit webhook that will execute javascript code. This can be abused to cause... Read more
Affected Products : opencti- Published: May. 19, 2025
- Modified: Aug. 06, 2025
-
8.8
HIGHCVE-2025-24189
The issue was addressed with improved checks. This issue is fixed in Safari 18.3, visionOS 2.3, iOS 18.3 and iPadOS 18.3, macOS Sequoia 15.3, watchOS 11.3, tvOS 18.3. Processing maliciously crafted web content may lead to memory corruption.... Read more
- Published: May. 19, 2025
- Modified: May. 28, 2025
- Vuln Type: Memory Corruption
-
5.5
MEDIUMCVE-2025-24184
The issue was addressed with improved memory handling. This issue is fixed in visionOS 2.3, iOS 18.3 and iPadOS 18.3, iPadOS 17.7.4, macOS Sequoia 15.3, watchOS 11.3, tvOS 18.3. An app may be able to cause unexpected system termination.... Read more
- Published: May. 19, 2025
- Modified: May. 28, 2025
- Vuln Type: Memory Corruption
-
5.5
MEDIUMCVE-2025-24183
The issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.7.3, macOS Sequoia 15.3, macOS Sonoma 14.7.3. A local user may be able to modify protected parts of the file system.... Read more
Affected Products : macos- Published: May. 19, 2025
- Modified: May. 28, 2025
- Vuln Type: Misconfiguration
-
7.1
HIGHCVE-2025-23988
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Bruno Cavalcante Ghostwriter allows Reflected XSS.This issue affects Ghostwriter: from n/a through 1.4.... Read more
Affected Products :- Published: May. 19, 2025
- Modified: May. 21, 2025
- Vuln Type: Cross-Site Scripting
-
7.1
HIGHCVE-2025-23986
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in fyrewurks Tiki Time allows Reflected XSS.This issue affects Tiki Time: from n/a through 1.3.... Read more
Affected Products :- Published: May. 19, 2025
- Modified: May. 21, 2025
- Vuln Type: Cross-Site Scripting
-
7.1
HIGHCVE-2025-23983
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Tijaji allows Reflected XSS.This issue affects Tijaji: from n/a through 1.43.... Read more
Affected Products : tijaji- Published: May. 19, 2025
- Modified: May. 21, 2025
- Vuln Type: Cross-Site Scripting
-
7.1
HIGHCVE-2025-23981
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Takimi Themes CarZine allows Reflected XSS.This issue affects CarZine: from n/a through 1.4.6.... Read more
Affected Products :- Published: May. 19, 2025
- Modified: May. 21, 2025
- Vuln Type: Cross-Site Scripting