Latest CVE Feed
-
6.5
MEDIUMCVE-2025-46482
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in MyThemeShop WP Quiz allows Stored XSS.This issue affects WP Quiz: from n/a through 2.0.10.... Read more
Affected Products :- Published: Apr. 25, 2025
- Modified: Apr. 29, 2025
- Vuln Type: Cross-Site Scripting
-
7.2
HIGHCVE-2025-46617
Quantum StorNext Web GUI API before 7.2.4 grants access to internal StorNext configuration and unauthorized modification of some software configuration parameters via undocumented user credentials. This affects StorNext RYO before 7.2.4, StorNext Xcellis ... Read more
Affected Products :- Published: Apr. 25, 2025
- Modified: Apr. 29, 2025
- Vuln Type: Authentication
-
9.9
CRITICALCVE-2025-46616
Quantum StorNext Web GUI API before 7.2.4 allows potential Arbitrary Remote Code Execution (RCE) via upload of a file. This affects StorNext RYO before 7.2.4, StorNext Xcellis Workflow Director before 7.2.4, and ActiveScale Cold Storage.... Read more
Affected Products :- Published: Apr. 25, 2025
- Modified: Apr. 29, 2025
- Vuln Type: Authentication
-
6.1
MEDIUMCVE-2025-3868
The Custom Admin-Bar Favorites plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'menuObject' parameter in all versions up to, and including, 0.1 due to insufficient input sanitization and output escaping. This makes it possible... Read more
Affected Products :- Published: Apr. 25, 2025
- Modified: Apr. 29, 2025
- Vuln Type: Cross-Site Scripting
-
6.1
MEDIUMCVE-2025-3867
The Ajax Comment Form CST plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.2. This is due to missing or incorrect nonce validation via the 'acform_cst_settings' page. This makes it possible for unaut... Read more
Affected Products :- Published: Apr. 25, 2025
- Modified: Apr. 29, 2025
- Vuln Type: Cross-Site Request Forgery
-
6.1
MEDIUMCVE-2025-3866
The Add Google +1 (Plus one) social share Button plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.0. This is due to missing or incorrect nonce validation on the google-plus-one-share-button page. T... Read more
Affected Products :- Published: Apr. 25, 2025
- Modified: Apr. 29, 2025
- Vuln Type: Cross-Site Request Forgery
-
5.3
MEDIUMCVE-2025-3743
The Upsell Funnel Builder for WooCommerce plugin for WordPress is vulnerable to order manipulation in all versions up to, and including, 3.0.0. This is due to the plugin allowing the additional product ID and discount field to be manipulated prior to proc... Read more
Affected Products :- Published: Apr. 25, 2025
- Modified: Apr. 29, 2025
- Vuln Type: Authentication
-
8.8
HIGHCVE-2025-2238
The Vikinger theme for WordPress is vulnerable to privilege in all versions up to, and including, 1.9.30. This is due to insufficient user_meta restrictions in the 'vikinger_user_meta_update_ajax' function. This makes it possible for authenticated attacke... Read more
Affected Products :- Published: Apr. 25, 2025
- Modified: Apr. 29, 2025
- Vuln Type: Authorization
-
7.5
HIGHCVE-2025-46613
OpenPLC 3 through 64f9c11 has server.cpp Memory Corruption because a thread may access handleConnections arguments after the parent stack frame becomes unavailable.... Read more
Affected Products : openplc- Published: Apr. 25, 2025
- Modified: Apr. 29, 2025
- Vuln Type: Memory Corruption
-
5.3
MEDIUMCVE-2025-3923
The Prevent Direct Access – Protect WordPress Files plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.8.8 via the 'generate_unique_string' due to insufficient randomness of the generated file name... Read more
Affected Products :- Published: Apr. 25, 2025
- Modified: Apr. 29, 2025
- Vuln Type: Information Disclosure
-
5.4
MEDIUMCVE-2025-3861
The Prevent Direct Access – Protect WordPress Files plugin for WordPress is vulnerable to unauthorized access and modification of data| due to a misconfigured capability check on the 'pda_lite_custom_permission_check' function in versions 2.8.6 to 2.8.8.2... Read more
Affected Products :- Published: Apr. 25, 2025
- Modified: Apr. 29, 2025
- Vuln Type: Authorization
-
5.9
MEDIUMCVE-2025-3511
Improper Validation of Specified Quantity in Input vulnerability in Mitsubishi Electric Corporation CC-Link IE TSN Remote I/O module, CC-Link IE TSN Analog-Digital Converter module, CC-Link IE TSN Digital-Analog Converter module, CC-Link IE TSN FPGA modul... Read more
Affected Products :- Published: Apr. 25, 2025
- Modified: Apr. 29, 2025
- Vuln Type: Denial of Service
-
4.9
MEDIUMCVE-2025-2580
The Contact Form by Bit Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 2.18.3 due to insufficient input sanitization and output escaping. This makes it possible for authent... Read more
Affected Products : contact_form_builder- Published: Apr. 25, 2025
- Modified: Apr. 29, 2025
- Vuln Type: Cross-Site Scripting
-
6.1
MEDIUMCVE-2025-0671
The Icegram Express WordPress plugin before 5.7.50 does not sanitise and escape some of its Template settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is... Read more
- Published: Apr. 25, 2025
- Modified: Apr. 29, 2025
- Vuln Type: Cross-Site Scripting
-
6.8
MEDIUMCVE-2025-46599
CNCF K3s 1.32 before 1.32.4-rc1+k3s1 has a Kubernetes kubelet configuration change with the unintended consequence that, in some situations, ReadOnlyPort is set to 10255. For example, the default behavior of a K3s online installation might allow unauthent... Read more
Affected Products : k3s- Published: Apr. 25, 2025
- Modified: Apr. 29, 2025
- Vuln Type: Authentication
-
6.5
MEDIUMCVE-2025-3775
The ShopLentor – WooCommerce Builder for Elementor & Gutenberg +20 Modules – All in One Solution (formerly WooLentor) plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 3.1.2 via the woolentor_template_... Read more
Affected Products : shoplentor- Published: Apr. 25, 2025
- Modified: Apr. 29, 2025
- Vuln Type: Server-Side Request Forgery
-
6.4
MEDIUMCVE-2025-3752
The Able Player, accessible HTML5 media player plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘preload’ parameter in all versions up to, and including, 1.2.1 due to insufficient input sanitization and output escaping. This makes... Read more
Affected Products :- Published: Apr. 25, 2025
- Modified: Apr. 29, 2025
- Vuln Type: Cross-Site Scripting
-
6.4
MEDIUMCVE-2025-46595
An XSS issue was discovered in the Flag module before 1.x-3.6.2 for Backdrop CMS. Flag is a module that allows flags to be added to nodes, comments, users, and any other type of entity. It doesn't verify flag links before performing the flag action, or ve... Read more
Affected Products :- Published: Apr. 25, 2025
- Modified: Apr. 29, 2025
- Vuln Type: Cross-Site Scripting
-
5.4
MEDIUMCVE-2025-46547
In Sherpa Orchestrator 141851, the web application lacks protection against CSRF attacks, with resultant effects of an attacker conducting XSS attacks, adding a new user or role, or exploiting a SQL injection issue.... Read more
Affected Products :- Published: Apr. 25, 2025
- Modified: Apr. 29, 2025
- Vuln Type: Cross-Site Request Forgery
-
3.5
LOWCVE-2025-46546
In Sherpa Orchestrator 141851, multiple time-based blind SQL injections can be performed by an authenticated user. This affects api/gui/asset/list, /api/gui/files/export/csv/, /api/gui/files/list, /api/gui/process/export/csv, /api/gui/process/export/xlsx,... Read more
Affected Products :- Published: Apr. 25, 2025
- Modified: Apr. 29, 2025
- Vuln Type: Injection