Latest CVE Feed
-
9.8
CRITICALCVE-2025-1093
The AIHub theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the generate_image function in all versions up to, and including, 1.3.7. This makes it possible for unauthenticated attackers to upload arbitrary ... Read more
Affected Products :- Published: Apr. 19, 2025
- Modified: Apr. 21, 2025
- Vuln Type: Authentication
-
4.3
MEDIUMCVE-2025-3284
The User Registration & Membership – Custom Registration Form, Login Form, and User Profile plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 5.1.3. This is due to missing or incorrect nonce validation ... Read more
Affected Products :- Published: Apr. 19, 2025
- Modified: Apr. 21, 2025
- Vuln Type: Cross-Site Request Forgery
-
9.8
CRITICALCVE-2025-3278
The UrbanGo Membership plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 1.0.4. This is due to the plugin allowing users who are registering new accounts to set their own role or by supplying 'user_register_role'... Read more
Affected Products :- Published: Apr. 19, 2025
- Modified: Apr. 21, 2025
- Vuln Type: Authentication
-
7.5
HIGHCVE-2025-2010
The JobWP – Job Board, Job Listing, Career Page and Recruitment Plugin plugin for WordPress is vulnerable to SQL Injection via the 'jobwp_upload_resume' parameter in all versions up to, and including, 2.3.9 due to insufficient escaping on the user supplie... Read more
Affected Products :- Published: Apr. 19, 2025
- Modified: Apr. 21, 2025
- Vuln Type: Injection
-
4.3
MEDIUMCVE-2025-43903
NSSCryptoSignBackend.cc in Poppler before 25.04.0 does not verify the adbe.pkcs7.sha1 signatures on documents, resulting in potential signature forgeries.... Read more
Affected Products : poppler- Published: Apr. 18, 2025
- Modified: Apr. 21, 2025
- Vuln Type: Cryptography
-
8.8
HIGHCVE-2025-3796
A vulnerability classified as critical has been found in PHPGurukul Men Salon Management System 1.0. This affects an unknown part of the file /admin/contact-us.php. The manipulation of the argument pagetitle/pagedes/email/mobnumber/timing leads to sql inj... Read more
Affected Products : men_salon_management_system- Published: Apr. 18, 2025
- Modified: May. 28, 2025
- Vuln Type: Injection
-
8.7
HIGHCVE-2025-32953
z80pack is a mature emulator of multiple platforms with 8080 and Z80 CPU. In version 1.38 and prior, the `makefile-ubuntu.yml` workflow file uses `actions/upload-artifact@v4` to upload the `z80pack-ubuntu` artifact. This artifact is a zip of the current d... Read more
Affected Products :- Published: Apr. 18, 2025
- Modified: Apr. 21, 2025
- Vuln Type: Misconfiguration
-
9.8
CRITICALCVE-2025-29058
An issue in Qimou CMS v.3.34.0 allows a remote attacker to execute arbitrary code via the upgrade.php component.... Read more
Affected Products : qimou_cms- Published: Apr. 18, 2025
- Modified: Jun. 19, 2025
- Vuln Type: Authentication
-
9.8
CRITICALCVE-2024-53591
An issue in the login page of Seclore v3.27.5.0 allows attackers to bypass authentication via a brute force attack.... Read more
Affected Products : seclore- Published: Apr. 18, 2025
- Modified: Jun. 23, 2025
- Vuln Type: Authentication
-
4.8
MEDIUMCVE-2025-3795
A vulnerability was found in DaiCuo 1.3.13. It has been rated as problematic. Affected by this issue is some unknown functionality of the component SEO Optimization Settings Section. The manipulation leads to cross site scripting. The attack may be launch... Read more
Affected Products : daicuo- Published: Apr. 18, 2025
- Modified: Jun. 23, 2025
- Vuln Type: Cross-Site Scripting
-
4.3
MEDIUMCVE-2025-36625
In Nessus versions prior to 10.8.4, a non-authenticated attacker could alter Nessus logging entries by manipulating http requests to the application.... Read more
Affected Products : nessus- Published: Apr. 18, 2025
- Modified: Apr. 21, 2025
- Vuln Type: Authentication
-
6.5
MEDIUMCVE-2025-32377
Rasa Pro is a framework for building scalable, dynamic conversational AI assistants that integrate large language models (LLMs). A vulnerability has been identified in Rasa Pro where voice connectors in Rasa Pro do not properly implement authentication ev... Read more
Affected Products :- Published: Apr. 18, 2025
- Modified: Apr. 21, 2025
- Vuln Type: Authentication
-
9.1
CRITICALCVE-2025-28197
Crawl4AI <=0.4.247 is vulnerable to SSRF in /crawl4ai/async_dispatcher.py.... Read more
Affected Products : crawl4ai- Published: Apr. 18, 2025
- Modified: Jun. 23, 2025
- Vuln Type: Server-Side Request Forgery
-
2.6
LOWCVE-2025-25985
An issue in Macro-video Technologies Co.,Ltd V380E6_C1 IP camera (Hw_HsAKPIQp_WF_XHR) 1020302 allows a physically proximate attacker to execute arbitrary code via the /mnt/mtd/mvconf/wifi.ini and /mnt/mtd/mvconf/user_info.ini components.... Read more
- Published: Apr. 18, 2025
- Modified: Jun. 25, 2025
- Vuln Type: Authentication
-
6.8
MEDIUMCVE-2025-25984
An issue in Macro-video Technologies Co.,Ltd V380E6_C1 IP camera (Hw_HsAKPIQp_WF_XHR) 1020302 allows a physically proximate attacker to execute arbitrary code via UART component.... Read more
- Published: Apr. 18, 2025
- Modified: Jun. 25, 2025
- Vuln Type: Memory Corruption
-
3.4
LOWCVE-2025-25983
An issue in Macro-video Technologies Co.,Ltd V380 Pro android application 2.1.44 and V380 Pro android application 2.1.64 allows an attacker to obtain sensitive information via the QE code based sharing component.... Read more
Affected Products : v380_pro- Published: Apr. 18, 2025
- Modified: Jun. 25, 2025
- Vuln Type: Information Disclosure
-
5.5
MEDIUMCVE-2024-57493
An issue in redoxOS relibc before commit 98aa4ea5 allows a local attacker to cause a denial of service via the setsockopt function.... Read more
Affected Products : redox- Published: Apr. 18, 2025
- Modified: Jun. 25, 2025
- Vuln Type: Denial of Service
-
4.7
MEDIUMCVE-2025-28355
Volmarg Personal Management System 1.4.65 is vulnerable to Cross Site Request Forgery (CSRF) allowing attackers to execute arbitrary code and obtain sensitive information via the SameSite cookie attribute defaults value set to none... Read more
Affected Products : personal_management_system- Published: Apr. 18, 2025
- Modified: Jun. 20, 2025
- Vuln Type: Cross-Site Request Forgery
-
7.8
HIGHCVE-2025-24914
When installing Nessus to a non-default location on a Windows host, Nessus versions prior to 10.8.4 did not enforce secure permissions for sub-directories. This could allow for local privilege escalation if users had not secured the directories in the non... Read more
Affected Products : nessus- Published: Apr. 18, 2025
- Modified: Apr. 21, 2025
- Vuln Type: Misconfiguration
-
6.1
MEDIUMCVE-2025-29513
Cross-Site Scripting (XSS) vulnerability in NodeBB v4.0.4 and before allows remote attackers to store arbitrary code in the admin API Access token generator.... Read more
Affected Products : nodebb- Published: Apr. 18, 2025
- Modified: Apr. 23, 2025
- Vuln Type: Cross-Site Scripting