Latest CVE Feed
-
2.1
LOWCVE-2025-47929
DumbDrop, a file upload application that provides an interface for dragging and dropping files, has a DOM cross-site scripting vulnerability in the upload functionality prior to commit db27b25372eb9071e63583d8faed2111a2b79f1b. A user could be tricked into... Read more
Affected Products :- Published: May. 15, 2025
- Modified: May. 16, 2025
- Vuln Type: Cross-Site Scripting
-
4.3
MEDIUMCVE-2025-1138
IBM InfoSphere Information Server 11.7 could disclose sensitive information to an authenticated user that could aid in further attacks against the system through a directory listing.... Read more
- Published: May. 15, 2025
- Modified: Jun. 04, 2025
- Vuln Type: Information Disclosure
-
9.8
CRITICALCVE-2025-4717
A vulnerability, which was classified as critical, was found in PHPGurukul Company Visitor Management System 2.0. Affected is an unknown function of the file /visitors-form.php. The manipulation of the argument fullname leads to sql injection. It is possi... Read more
Affected Products : company_visitor_management_system- Published: May. 15, 2025
- Modified: May. 27, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-4716
A vulnerability was found in Campcodes Sales and Inventory System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /pages/credit_transaction_add.php. The manipulation of the argument prod_name leads to s... Read more
Affected Products : sales_and_inventory_system- Published: May. 15, 2025
- Modified: May. 27, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-4715
A vulnerability was found in Campcodes Sales and Inventory System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /pages/view_application.php. The manipulation of the argument cid leads to sql ... Read more
Affected Products : sales_and_inventory_system- Published: May. 15, 2025
- Modified: May. 27, 2025
- Vuln Type: Injection
-
9.1
CRITICALCVE-2025-47928
Spotipy is a Python library for the Spotify Web API. As of commit 4f5759dbfb4506c7b6280572a4db1aabc1ac778d, using `pull_request_target` on `.github/workflows/integration_tests.yml` followed by the checking out the head.sha of a forked PR can be exploited ... Read more
Affected Products : spotipy- Published: May. 15, 2025
- Modified: May. 16, 2025
- Vuln Type: Misconfiguration
-
6.1
MEDIUMCVE-2025-47789
Horilla is a free and open source Human Resource Management System (HRMS). In versions up to and including 1.3, an attacker can craft a Horilla URL that refers to an external domain. Upon clicking and logging in, the user is redirected to an external doma... Read more
Affected Products :- Published: May. 15, 2025
- Modified: May. 16, 2025
- Vuln Type: Authentication
-
9.4
CRITICALCVE-2025-47788
Atheos is a self-hosted browser-based cloud IDE. Prior to v602, similar to GHSA-rgjm-6p59-537v/CVE-2025-22152, the `$target` parameter in `/controller.php` was not properly validated, which could allow an attacker to execute arbitrary files on the server ... Read more
Affected Products :- Published: May. 15, 2025
- Modified: May. 19, 2025
- Vuln Type: Path Traversal
-
9.8
CRITICALCVE-2025-47787
Emlog is an open source website building system. Emlog Pro prior to version 2.5.10 contains a file upload vulnerability. The store.php component contains a critical security flaw where it fails to properly validate the contents of remotely downloaded ZIP ... Read more
Affected Products : emlog- Published: May. 15, 2025
- Modified: Jul. 01, 2025
- Vuln Type: Authentication
-
4.8
MEDIUMCVE-2025-47786
Emlog is an open source website building system. Version 2.5.13 has a stored cross-site scripting vulnerability that allows any registered user to construct malicious JavaScript, inducing all website users to click. In `/admin/comment.php`, the parameter ... Read more
Affected Products : emlog- Published: May. 15, 2025
- Modified: Jun. 12, 2025
- Vuln Type: Cross-Site Scripting
-
8.8
HIGHCVE-2025-47785
Emlog is an open source website building system. In versions up to and including 2.5.9, SQL injection occurs because the $origContent parameter in admin/article_save.php is not strictly filtered. Since admin/article_save.php can be accessed by ordinary re... Read more
Affected Products : emlog- Published: May. 15, 2025
- Modified: Jun. 12, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-47784
Emlog is an open source website building system. Versions 2.5.13 and prior have a deserialization vulnerability. A user who creates a carefully crafted nickname can cause `str_replace` to replace the value of `name_orig` with empty, causing deserializatio... Read more
Affected Products : emlog- Published: May. 15, 2025
- Modified: Jul. 18, 2025
- Vuln Type: Misconfiguration
-
7.8
HIGHCVE-2025-47161
Improper access control in Microsoft Defender for Endpoint allows an authorized attacker to elevate privileges locally.... Read more
Affected Products : defender_for_endpoint- Published: May. 15, 2025
- Modified: Jul. 08, 2025
- Vuln Type: Authorization
-
6.6
MEDIUMCVE-2025-46834
Alchemy's Modular Account is a smart contract account that is compatible with ERC-4337 and ERC-6900. In versions on the 2.x branch prior to commit 5e6f540d249afcaeaf76ab95517d0359fde883b0, owners of Modular Accounts can grant session keys (scoped external... Read more
Affected Products :- Published: May. 15, 2025
- Modified: May. 16, 2025
- Vuln Type: Authorization
-
5.4
MEDIUMCVE-2025-2248
The WP-PManager WordPress plugin through 1.2 does not sanitize and escape a parameter before using it in a SQL statement, allowing admins to perform SQL injection attacks... Read more
Affected Products : wp-pmanager- Published: May. 15, 2025
- Modified: Jun. 04, 2025
- Vuln Type: Injection
-
5.4
MEDIUMCVE-2025-2247
The WP-PManager WordPress plugin through 1.2 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack... Read more
Affected Products : wp-pmanager- Published: May. 15, 2025
- Modified: Jun. 04, 2025
- Vuln Type: Cross-Site Request Forgery
-
6.1
MEDIUMCVE-2025-2203
The FunnelKit WordPress plugin before 3.10.2 does not sanitize and escape a parameter before using it in a SQL statement, allowing admins to perform SQL injection attacks... Read more
Affected Products : funnel_builder- Published: May. 15, 2025
- Modified: Jun. 12, 2025
- Vuln Type: Injection
-
5.4
MEDIUMCVE-2025-1454
The Ninja Pages WordPress plugin through 1.4.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (f... Read more
Affected Products : ninja_pages- Published: May. 15, 2025
- Modified: Jun. 12, 2025
- Vuln Type: Cross-Site Scripting
-
6.1
MEDIUMCVE-2025-1303
The Plugin Oficial WordPress plugin through 1.7.3 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against only unauthenticated users.... Read more
- Published: May. 15, 2025
- Modified: Aug. 01, 2025
- Vuln Type: Cross-Site Scripting
-
4.8
MEDIUMCVE-2025-1289
The Plugin Oficial WordPress plugin through 1.7.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowe... Read more
- Published: May. 15, 2025
- Modified: Aug. 01, 2025
- Vuln Type: Cross-Site Scripting