Latest CVE Feed
-
3.5
LOWCVE-2025-1524
The Ultimate Dashboard WordPress plugin before 3.8.6 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disall... Read more
- Published: Apr. 17, 2025
- Modified: Apr. 30, 2025
- Vuln Type: Cross-Site Scripting
-
3.5
LOWCVE-2025-1523
The Ultimate Dashboard WordPress plugin before 3.8.6 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disall... Read more
- Published: Apr. 17, 2025
- Modified: Apr. 29, 2025
- Vuln Type: Cross-Site Scripting
-
7.5
HIGHCVE-2024-13925
The Klarna Checkout for WooCommerce WordPress plugin before 2.13.5 exposes an unauthenticated WooCommerce Ajax endpoint that allows an attacker to flood the log files with data at the maximum size allowed for a POST parameter per request. This can result ... Read more
Affected Products : klarna_checkout_for_woocommerce- Published: Apr. 17, 2025
- Modified: Apr. 29, 2025
- Vuln Type: Denial of Service
-
3.5
LOWCVE-2024-11924
The Icegram Express formerly known as Email Subscribers WordPress plugin before 5.7.52 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the un... Read more
Affected Products : icegram_express- Published: Apr. 17, 2025
- Modified: Apr. 29, 2025
- Vuln Type: Cross-Site Scripting
-
5.4
MEDIUMCVE-2025-43717
In PEAR HTTP_Request2 before 2.7.0, multiple files in the tests directory, notably tests/_network/getparameters.php and tests/_network/postparameters.php, reflect any GET or POST parameters, leading to XSS.... Read more
Affected Products : pear- Published: Apr. 17, 2025
- Modified: Apr. 17, 2025
- Vuln Type: Cross-Site Scripting
-
8.1
HIGHCVE-2025-43715
Nullsoft Scriptable Install System (NSIS) before 3.11 on Windows allows local users to escalate privileges to SYSTEM during an installation, because the temporary plugins directory is created under %WINDIR%\temp and unprivileged users can place a crafted ... Read more
Affected Products : nullsoft_scriptable_install_system- Published: Apr. 17, 2025
- Modified: Apr. 17, 2025
- Vuln Type: Race Condition
-
9.9
CRITICALCVE-2025-31340
A improper control of filename for include/require statement in PHP program vulnerability in the retrieve course Information function of Wisdom Master Pro versions 5.0 through 5.2 allows remote attackers to perform arbitrary system commands by running a m... Read more
Affected Products :- Published: Apr. 17, 2025
- Modified: Apr. 17, 2025
- Vuln Type: Path Traversal
-
5.3
MEDIUMCVE-2025-31339
An unrestricted upload of file with dangerous type vulnerability in the course management function of Wisdom Master Pro versions 5.0 through 5.2 allows remote authenticated users to craft a malicious file.... Read more
Affected Products :- Published: Apr. 17, 2025
- Modified: Apr. 17, 2025
- Vuln Type: Authentication
-
6.9
MEDIUMCVE-2025-31338
A missing authorization vulnerability in the retrieve teacher Information function of Wisdom Master Pro versions 5.0 through 5.2 allows remote attackers to obtain partial user data by accessing the API functionality.... Read more
Affected Products :- Published: Apr. 17, 2025
- Modified: Apr. 17, 2025
- Vuln Type: Authorization
-
3.3
LOWCVE-2025-43708
VisiCut 2.1 allows stack consumption via an XML document with nested set elements, as demonstrated by a java.util.HashMap StackOverflowError when reference='../../../set/set[2]' is used, aka an "insecure deserialization" issue.... Read more
Affected Products :- Published: Apr. 17, 2025
- Modified: Apr. 17, 2025
- Vuln Type: XML External Entity
-
8.1
HIGHCVE-2025-1290
A race condition Use-After-Free vulnerability exists in the virtio_transport_space_update function within the Kernel 5.4 on ChromeOS. Concurrent allocation and freeing of the virtio_vsock_sock structure during an AF_VSOCK connect syscall can occur before... Read more
- Published: Apr. 17, 2025
- Modified: Jul. 11, 2025
- Vuln Type: Race Condition
-
4.7
MEDIUMCVE-2025-43704
Arctera/Veritas Data Insight before 7.1.2 can send cleartext credentials when configured to use HTTP Basic Authentication to a Dell Isilon OneFS server.... Read more
Affected Products : data_insight- Published: Apr. 16, 2025
- Modified: Apr. 17, 2025
- Vuln Type: Authentication
-
8.8
HIGHCVE-2025-2073
Out-of-Bounds Read in netfilter/ipset in Linux Kernel ChromeOS [6.1, 5.15, 5.10, 5.4, 4.19] allows a local attacker with low privileges to trigger an out-of-bounds read, potentially leading to information disclosure... Read more
- Published: Apr. 16, 2025
- Modified: Jul. 11, 2025
- Vuln Type: Information Disclosure
-
4.9
MEDIUMCVE-2025-24911
Overview XML documents optionally contain a Document Type Definition (DTD), which, among other features, enables the definition of XML entities. It is possible to define an entity by providing a substitution string in the form of a URI. Once the ... Read more
Affected Products : pentaho_business_analytics_server- Published: Apr. 16, 2025
- Modified: Apr. 17, 2025
- Vuln Type: XML External Entity
-
4.9
MEDIUMCVE-2025-24910
Overview XML documents optionally contain a Document Type Definition (DTD), which, among other features, enables the definition of XML entities. It is possible to define an entity by providing a substitution string in the form of a URI. Once the ... Read more
Affected Products : pentaho_business_analytics_server- Published: Apr. 16, 2025
- Modified: Apr. 17, 2025
- Vuln Type: XML External Entity
-
4.4
MEDIUMCVE-2025-24909
Overview The software does not neutralize or incorrectly neutralize user-controllable input before it is placed in output that is used as a web page that is served to other users. (CWE-79) Description Hitachi Vantara Pentaho Bus... Read more
Affected Products : pentaho_business_analytics_server- Published: Apr. 16, 2025
- Modified: Apr. 17, 2025
- Vuln Type: Cross-Site Scripting
-
6.8
MEDIUMCVE-2025-24908
Overview The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize '.../...//' (doubled triple dot slash) sequences that can resolve to a location that is outside of ... Read more
Affected Products :- Published: Apr. 16, 2025
- Modified: Apr. 17, 2025
- Vuln Type: Path Traversal
-
6.8
MEDIUMCVE-2025-24907
Overview The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize '.../...//' (doubled triple dot slash) sequences that can resolve to a location that is outside of ... Read more
Affected Products :- Published: Apr. 16, 2025
- Modified: Apr. 17, 2025
- Vuln Type: Path Traversal
-
6.5
MEDIUMCVE-2025-1704
ComponentInstaller Modification in ComponentInstaller in Google ChromeOS 15823.23.0 on Chromebooks allows enrolled users with local access to unenroll devices and intercept device management requests via loading components from the unencrypted stateful p... Read more
Affected Products : chrome_os- Published: Apr. 16, 2025
- Modified: Jul. 11, 2025
- Vuln Type: Misconfiguration
-
8.8
HIGHCVE-2025-1568
Access Control Vulnerability in Gerrit chromiumos project configuration in Google ChromeOS 16063.87.0 allows an attacker with a registered Gerrit account to inject malicious code into ChromeOS projects and potentially achieve Remote Code Execution and Den... Read more
Affected Products : chrome_os- Published: Apr. 16, 2025
- Modified: Jul. 08, 2025
- Vuln Type: Misconfiguration