Latest CVE Feed
-
7.1
HIGHCVE-2025-46589
Vulnerability of unauthorized access in the app lock module Impact: Successful exploitation of this vulnerability will affect integrity and confidentiality.... Read more
Affected Products : harmonyos- Published: May. 06, 2025
- Modified: May. 09, 2025
- Vuln Type: Authorization
-
7.7
HIGHCVE-2025-46588
Vulnerability of unauthorized access in the app lock module Impact: Successful exploitation of this vulnerability will affect integrity and confidentiality.... Read more
Affected Products : harmonyos- Published: May. 06, 2025
- Modified: May. 09, 2025
- Vuln Type: Authentication
-
6.2
MEDIUMCVE-2025-46587
Permission control vulnerability in the media library module Impact: Successful exploitation of this vulnerability may affect service confidentiality.... Read more
Affected Products : harmonyos- Published: May. 06, 2025
- Modified: May. 09, 2025
- Vuln Type: Authorization
-
5.3
MEDIUMCVE-2025-3281
The User Registration & Membership – Custom Registration Form, Login Form, and User Profile plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 4.2.1 via the create_stripe_subscription() function, d... Read more
- Published: May. 06, 2025
- Modified: May. 07, 2025
- Vuln Type: Authorization
-
5.4
MEDIUMCVE-2025-3020
An low privileged remote Attacker can execute arbitrary web scripts or HTML via a crafted payload injected into several fields of the configuration webpage with limited impact.... Read more
Affected Products :- Published: May. 06, 2025
- Modified: May. 07, 2025
- Vuln Type: Cross-Site Scripting
-
6.2
MEDIUMCVE-2024-58252
Vulnerability of insufficient information protection in the media library module Impact: Successful exploitation of this vulnerability may affect service confidentiality.... Read more
Affected Products : harmonyos- Published: May. 06, 2025
- Modified: May. 09, 2025
- Vuln Type: Information Disclosure
-
5.3
MEDIUMCVE-2025-4329
A vulnerability was found in 74CMS up to 3.33.0. It has been rated as problematic. Affected by this issue is the function index of the file /index.php/index/download/index. The manipulation of the argument url leads to path traversal. The attack may be la... Read more
Affected Products : 74cms- Published: May. 06, 2025
- Modified: Jun. 12, 2025
- Vuln Type: Path Traversal
-
5.1
MEDIUMCVE-2025-4328
A vulnerability was found in fp2952 spring-cloud-base up to 7f050dc6db9afab82c5ce1d41cd74ed255ec9bfa. It has been declared as problematic. Affected by this vulnerability is the function sendBack of the file /spring-cloud-base-master/auth-center/auth-cente... Read more
Affected Products :- Published: May. 06, 2025
- Modified: May. 07, 2025
- Vuln Type: Misconfiguration
-
5.3
MEDIUMCVE-2025-4327
A vulnerability was found in MRCMS 3.1.2. It has been classified as problematic. Affected is an unknown function. The manipulation leads to cross-site request forgery. It is possible to launch the attack remotely. The exploit has been disclosed to the pub... Read more
Affected Products : mrcms- Published: May. 06, 2025
- Modified: Jun. 12, 2025
- Vuln Type: Cross-Site Request Forgery
-
5.5
MEDIUMCVE-2025-46586
Permission control vulnerability in the contacts module Impact: Successful exploitation of this vulnerability may affect availability.... Read more
Affected Products : harmonyos- Published: May. 06, 2025
- Modified: May. 09, 2025
- Vuln Type: Authorization
-
7.5
HIGHCVE-2025-46585
Out-of-bounds array read/write vulnerability in the kernel module Impact: Successful exploitation of this vulnerability may affect availability.... Read more
Affected Products : harmonyos- Published: May. 06, 2025
- Modified: May. 09, 2025
- Vuln Type: Memory Corruption
-
7.8
HIGHCVE-2025-46584
Vulnerability of improper authentication logic implementation in the file system module Impact: Successful exploitation of this vulnerability may affect service confidentiality.... Read more
Affected Products : harmonyos- Published: May. 06, 2025
- Modified: May. 09, 2025
- Vuln Type: Authentication
-
5.4
MEDIUMCVE-2025-4326
A vulnerability was found in MRCMS 3.1.2 and classified as problematic. This issue affects some unknown processing of the file /admin/chip/add.do of the component Add Fragment Page. The manipulation leads to cross site scripting. The attack may be initiat... Read more
Affected Products : mrcms- Published: May. 06, 2025
- Modified: Jun. 17, 2025
- Vuln Type: Cross-Site Scripting
-
4.8
MEDIUMCVE-2025-4325
A vulnerability has been found in MRCMS 3.1.2 and classified as problematic. This vulnerability affects unknown code of the file /admin/category/add.do of the component Category Management Page. The manipulation of the argument Name leads to cross site sc... Read more
Affected Products : mrcms- Published: May. 06, 2025
- Modified: Jun. 17, 2025
- Vuln Type: Cross-Site Scripting
-
5.4
MEDIUMCVE-2025-4324
A vulnerability, which was classified as problematic, was found in MRCMS 3.1.2. This affects an unknown part of the file /admin/link/edit.do of the component External Link Management Page. The manipulation leads to cross site scripting. It is possible to ... Read more
Affected Products : mrcms- Published: May. 06, 2025
- Modified: Jun. 17, 2025
- Vuln Type: Cross-Site Scripting
-
4.3
MEDIUMCVE-2025-4337
The AHAthat Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.6. This is due to missing or incorrect nonce validation on the aha_plugin_page() function. This makes it possible for unauthenticat... Read more
Affected Products : ahathat- Published: May. 06, 2025
- Modified: May. 07, 2025
- Vuln Type: Cross-Site Request Forgery
-
5.4
MEDIUMCVE-2025-4323
A vulnerability, which was classified as problematic, has been found in MRCMS 3.1.2. Affected by this issue is some unknown functionality of the component Edit Article Page. The manipulation of the argument Title leads to cross site scripting. The attack ... Read more
Affected Products : mrcms- Published: May. 06, 2025
- Modified: Jun. 17, 2025
- Vuln Type: Cross-Site Scripting
-
9.8
CRITICALCVE-2025-4314
A vulnerability has been found in SourceCodester Advanced Web Store 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /admin/index.php. The manipulation of the argument txtLogin leads to sql injection. ... Read more
Affected Products : advanced_web_store- Published: May. 06, 2025
- Modified: May. 14, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-4313
A vulnerability, which was classified as critical, was found in SourceCodester Advanced Web Store 1.0. Affected is an unknown function of the file /admin/admin_addnew_product.php. The manipulation of the argument txtProdId leads to sql injection. It is po... Read more
Affected Products : advanced_web_store- Published: May. 06, 2025
- Modified: May. 14, 2025
- Vuln Type: Injection
-
7.3
HIGHCVE-2025-2802
The LayoutBoxx plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 0.3.1. This is due to the software allowing users to execute an action that does not properly validate a value before running do_short... Read more
Affected Products :- Published: May. 06, 2025
- Modified: May. 07, 2025
- Vuln Type: Authentication