Latest CVE Feed
-
8.5
HIGHCVE-2025-32245
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in LambertGroup Apollo allows SQL Injection. This issue affects Apollo: from n/a through 3.6.3.... Read more
Affected Products : apollo- Published: May. 16, 2025
- Modified: May. 19, 2025
- Vuln Type: Injection
-
4.3
MEDIUMCVE-2025-32180
Missing Authorization vulnerability in QuanticaLabs CSS3 Tooltips for WordPress allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects CSS3 Tooltips for WordPress: from n/a through 1.8.... Read more
Affected Products :- Published: May. 16, 2025
- Modified: May. 19, 2025
- Vuln Type: Authorization
-
8.5
HIGHCVE-2025-31928
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in LambertGroup Multimedia Responsive Carousel with Image Video Audio Support allows SQL Injection. This issue affects Multimedia Responsive Carousel with I... Read more
Affected Products :- Published: May. 16, 2025
- Modified: May. 19, 2025
- Vuln Type: Injection
-
8.5
HIGHCVE-2025-31926
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in LambertGroup Sticky Radio Player allows SQL Injection. This issue affects Sticky Radio Player: from n/a through 3.4.... Read more
Affected Products :- Published: May. 16, 2025
- Modified: May. 19, 2025
- Vuln Type: Injection
-
5.4
MEDIUMCVE-2025-31923
Missing Authorization vulnerability in QuanticaLabs CSS3 Accordions for WordPress allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects CSS3 Accordions for WordPress: from n/a through 3.0.... Read more
Affected Products :- Published: May. 16, 2025
- Modified: May. 19, 2025
- Vuln Type: Authorization
-
7.1
HIGHCVE-2025-31922
Cross-Site Request Forgery (CSRF) vulnerability in QuanticaLabs CSS3 Accordions for WordPress allows Stored XSS. This issue affects CSS3 Accordions for WordPress: from n/a through 3.0.... Read more
Affected Products :- Published: May. 16, 2025
- Modified: May. 19, 2025
- Vuln Type: Cross-Site Request Forgery
-
4.3
MEDIUMCVE-2025-31921
Cross-Site Request Forgery (CSRF) vulnerability in loopus WP Ultimate Tours Builder allows Cross Site Request Forgery. This issue affects WP Ultimate Tours Builder: from n/a through 1.055.... Read more
Affected Products :- Published: May. 16, 2025
- Modified: May. 19, 2025
- Vuln Type: Cross-Site Request Forgery
-
5.4
MEDIUMCVE-2025-31915
Cross-Site Request Forgery (CSRF) vulnerability in kamleshyadav Pixel WordPress Form BuilderPlugin & Autoresponder allows Cross Site Request Forgery. This issue affects Pixel WordPress Form BuilderPlugin & Autoresponder: from n/a through 1.0.2.... Read more
Affected Products :- Published: May. 16, 2025
- Modified: May. 19, 2025
- Vuln Type: Cross-Site Request Forgery
-
8.5
HIGHCVE-2025-31641
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in LambertGroup UberSlider allows SQL Injection. This issue affects UberSlider: from n/a through 2.3.... Read more
Affected Products :- Published: May. 16, 2025
- Modified: May. 19, 2025
- Vuln Type: Injection
-
8.5
HIGHCVE-2025-31640
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in LambertGroup Magic Responsive Slider and Carousel WordPress allows SQL Injection. This issue affects Magic Responsive Slider and Carousel WordPress: from... Read more
Affected Products :- Published: May. 16, 2025
- Modified: May. 19, 2025
- Vuln Type: Injection
-
4.3
MEDIUMCVE-2025-31639
Cross-Site Request Forgery (CSRF) vulnerability in themeton Spare allows Cross Site Request Forgery. This issue affects Spare: from n/a through 1.7.... Read more
Affected Products :- Published: May. 16, 2025
- Modified: May. 19, 2025
- Vuln Type: Cross-Site Request Forgery
-
8.5
HIGHCVE-2025-31637
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in LambertGroup SHOUT allows SQL Injection. This issue affects SHOUT: from n/a through 3.5.3.... Read more
Affected Products : shout- Published: May. 16, 2025
- Modified: May. 19, 2025
- Vuln Type: Injection
-
5.3
MEDIUMCVE-2025-31630
Missing Authorization vulnerability in themeton The Business allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects The Business: from n/a through 1.6.1.... Read more
Affected Products :- Published: May. 16, 2025
- Modified: May. 19, 2025
- Vuln Type: Authorization
-
5.3
MEDIUMCVE-2025-31071
Missing Authorization vulnerability in themeton HotStar – Multi-Purpose Business Theme allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects HotStar – Multi-Purpose Business Theme: from n/a through 1.4.... Read more
Affected Products :- Published: May. 16, 2025
- Modified: May. 19, 2025
- Vuln Type: Authorization
-
4.3
MEDIUMCVE-2025-31068
Cross-Site Request Forgery (CSRF) vulnerability in themeton Seven Stars allows Cross Site Request Forgery. This issue affects Seven Stars: from n/a through 1.4.4.... Read more
Affected Products :- Published: May. 16, 2025
- Modified: May. 19, 2025
- Vuln Type: Cross-Site Request Forgery
-
5.3
MEDIUMCVE-2025-31066
Missing Authorization vulnerability in themeton Acerola allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Acerola: from n/a through 1.6.5.... Read more
Affected Products :- Published: May. 16, 2025
- Modified: May. 19, 2025
- Vuln Type: Authorization
-
5.3
MEDIUMCVE-2025-31065
Missing Authorization vulnerability in themeton Rozario allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Rozario: from n/a through 1.4.... Read more
Affected Products :- Published: May. 16, 2025
- Modified: May. 19, 2025
- Vuln Type: Authorization
-
4.3
MEDIUMCVE-2025-31063
Missing Authorization vulnerability in redqteam Wishlist allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Wishlist: from n/a through 2.1.0.... Read more
Affected Products :- Published: May. 16, 2025
- Modified: May. 19, 2025
- Vuln Type: Authorization
-
4.3
MEDIUMCVE-2025-31062
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in redqteam Wishlist allows Retrieve Embedded Sensitive Data. This issue affects Wishlist: from n/a through 2.1.0.... Read more
Affected Products :- Published: May. 16, 2025
- Modified: May. 19, 2025
- Vuln Type: Information Disclosure
-
9.8
CRITICALCVE-2025-4785
A vulnerability was found in PHPGurukul Daily Expense Tracker System 1.1. It has been rated as critical. Affected by this issue is some unknown functionality of the file /user-profile.php. The manipulation of the argument fullname/contactnumber leads to s... Read more
Affected Products : daily_expense_tracker_system- Published: May. 16, 2025
- Modified: May. 21, 2025
- Vuln Type: Injection