Latest CVE Feed
-
4.8
MEDIUMCVE-2023-6783
The WolfNet IDX for WordPress plugin through 1.19.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallow... Read more
Affected Products : wolfnet_idx_for_wordpress- Published: May. 15, 2025
- Modified: Jun. 11, 2025
- Vuln Type: Cross-Site Scripting
-
6.1
MEDIUMCVE-2023-6541
The Allow SVG WordPress plugin before 1.2.0 does not sanitize uploaded SVG files, which could allow users with a role as low as Author to upload a malicious SVG containing XSS payloads.... Read more
Affected Products : allow_svg- Published: May. 15, 2025
- Modified: Jun. 11, 2025
- Vuln Type: Cross-Site Scripting
-
5.4
MEDIUMCVE-2023-6030
The LogDash Activity Log WordPress plugin before 1.1.4 hooks the wp_login_failed function (from src/Hooks/Users.php) in order to log failed login attempts to the database but it doesn't escape the username when it perform some SQL request leading to a SQL... Read more
Affected Products : logdash_activity_log- Published: May. 15, 2025
- Modified: Jun. 11, 2025
- Vuln Type: Injection
-
7.3
HIGHCVE-2023-5934
The Travelpayouts: All Travel Brands in One Place WordPress plugin before 1.1.13 does not have CSRF check in place when importing settings from the v1, which could allow attackers to make a logged in admin update some settings via a CSRF attack... Read more
Affected Products : travelpayouts- Published: May. 15, 2025
- Modified: Jun. 04, 2025
- Vuln Type: Cross-Site Request Forgery
-
4.8
MEDIUMCVE-2023-5932
The Travelpayouts: All Travel Brands in One Place WordPress plugin before 1.1.14 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users s... Read more
Affected Products : travelpayouts- Published: May. 15, 2025
- Modified: Jun. 04, 2025
- Vuln Type: Cross-Site Scripting
-
4.8
MEDIUMCVE-2023-5529
The Advanced Page Visit Counter WordPress plugin before 8.0.6 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability ... Read more
Affected Products : advanced_page_visit_counter- Published: May. 15, 2025
- Modified: Jun. 04, 2025
- Vuln Type: Cross-Site Scripting
-
5.4
MEDIUMCVE-2023-2334
The edd-google-sheet-connector-pro WordPress plugin before 1.4, Easy Digital Downloads Google Sheet Connector WordPress plugin before 1.6.6 does not have CSRF check when updating its Access Code, which could allow attackers to make logged in admin change ... Read more
- Published: May. 15, 2025
- Modified: Jun. 11, 2025
- Vuln Type: Cross-Site Request Forgery
-
9.8
CRITICALCVE-2025-4714
A vulnerability was found in Campcodes Sales and Inventory System 1.0. It has been classified as critical. Affected is an unknown function of the file /pages/reprint.php. The manipulation of the argument sid leads to sql injection. It is possible to launc... Read more
Affected Products : sales_and_inventory_system- Published: May. 15, 2025
- Modified: May. 27, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-4713
A vulnerability was found in Campcodes Sales and Inventory System 1.0 and classified as critical. This issue affects some unknown processing of the file /pages/print.php. The manipulation of the argument sid leads to sql injection. The attack may be initi... Read more
Affected Products : sales_and_inventory_system- Published: May. 15, 2025
- Modified: May. 27, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-4712
A vulnerability has been found in Campcodes Sales and Inventory System 1.0 and classified as critical. This vulnerability affects unknown code of the file /pages/account_summary.php. The manipulation of the argument cid leads to sql injection. The attack ... Read more
Affected Products : sales_and_inventory_system- Published: May. 15, 2025
- Modified: May. 27, 2025
- Vuln Type: Injection
-
7.1
HIGHCVE-2025-32922
Cross-Site Request Forgery (CSRF) vulnerability in Tobias WP2LEADS allows Stored XSS.This issue affects WP2LEADS: from n/a through 3.5.0.... Read more
Affected Products :- Published: May. 15, 2025
- Modified: May. 16, 2025
- Vuln Type: Cross-Site Request Forgery
-
5.3
MEDIUMCVE-2025-30476
Dell PowerScale InsightIQ, version 5.2, contains an uncontrolled resource consumption vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to denial of service.... Read more
Affected Products : insightiq- Published: May. 15, 2025
- Modified: May. 16, 2025
- Vuln Type: Denial of Service
-
8.1
HIGHCVE-2025-30475
Dell PowerScale InsightIQ, versions 5.0 through 5.2, contains an improper privilege management vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to elevation of privileges.... Read more
Affected Products : insightiq- Published: May. 15, 2025
- Modified: May. 16, 2025
- Vuln Type: Authorization
-
7.5
HIGHCVE-2025-26481
Dell PowerScale OneFS, versions 9.4.0.0 through 9.9.0.0, contains an uncontrolled resource consumption vulnerability. A remote unprivileged attacker could potentially exploit this vulnerability, leading to denial of service.... Read more
- Published: May. 15, 2025
- Modified: Jul. 11, 2025
- Vuln Type: Denial of Service
-
5.3
MEDIUMCVE-2024-56006
Missing Authorization vulnerability in Automattic Jetpack Debug Tools.This issue affects Jetpack Debug Tools: from n/a before 2.0.1.... Read more
Affected Products :- Published: May. 15, 2025
- Modified: May. 16, 2025
- Vuln Type: Authorization
-
4.3
MEDIUMCVE-2024-51666
Missing Authorization vulnerability in Automattic Tours.This issue affects Tours: from n/a through 1.0.0.... Read more
Affected Products :- Published: May. 15, 2025
- Modified: May. 16, 2025
- Vuln Type: Authorization
-
9.8
CRITICALCVE-2025-4711
A vulnerability, which was classified as critical, was found in Campcodes Sales and Inventory System 1.0. This affects an unknown part of the file /pages/stockin_add.php. The manipulation of the argument prod_name leads to sql injection. It is possible to... Read more
Affected Products : sales_and_inventory_system- Published: May. 15, 2025
- Modified: May. 27, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-4710
A vulnerability, which was classified as critical, has been found in Campcodes Sales and Inventory System 1.0. Affected by this issue is some unknown functionality of the file /pages/transaction.php. The manipulation of the argument cid leads to sql injec... Read more
Affected Products : sales_and_inventory_system- Published: May. 15, 2025
- Modified: May. 28, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-4709
A vulnerability classified as critical was found in Campcodes Sales and Inventory System 1.0. Affected by this vulnerability is an unknown functionality of the file /pages/transaction_del.php. The manipulation of the argument ID leads to sql injection. Th... Read more
Affected Products : sales_and_inventory_system- Published: May. 15, 2025
- Modified: May. 28, 2025
- Vuln Type: Injection
-
2.9
LOWCVE-2025-47774
Vyper is the Pythonic Programming Language for the Ethereum Virtual Machine. In versions up to and including 0.4.2rc1, the `slice()` builtin can elide side effects when the output length is 0, and the source bytestring is a builtin (`msg.data` or `<addres... Read more
Affected Products : vyper- Published: May. 15, 2025
- Modified: May. 16, 2025
- Vuln Type: Denial of Service