Latest CVE Feed
-
6.9
MEDIUMCVE-2025-31654
An attacker can get information about the groups of the smart home devices for arbitrary users (i.e., "rooms").... Read more
Affected Products :- Published: Apr. 15, 2025
- Modified: Apr. 16, 2025
- Vuln Type: Information Disclosure
-
6.9
MEDIUMCVE-2025-31360
Unauthenticated attackers can trigger device actions associated with specific "scenes" of arbitrary users.... Read more
Affected Products :- Published: Apr. 15, 2025
- Modified: Apr. 16, 2025
- Vuln Type: Authorization
-
6.9
MEDIUMCVE-2025-31147
Unauthenticated attackers can query information about total energy consumed by EV chargers of arbitrary users.... Read more
Affected Products :- Published: Apr. 15, 2025
- Modified: Apr. 16, 2025
- Vuln Type: Authentication
-
7.1
HIGHCVE-2025-30984
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound SEO Tools allows Reflected XSS. This issue affects SEO Tools: from n/a through 4.0.7.... Read more
Affected Products : seo_tools- Published: Apr. 15, 2025
- Modified: Apr. 16, 2025
- Vuln Type: Cross-Site Scripting
-
6.5
MEDIUMCVE-2025-30982
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in zookatron MyBookProgress by Stormhill Media allows Stored XSS. This issue affects MyBookProgress by Stormhill Media: from n/a through 1.0.8.... Read more
Affected Products :- Published: Apr. 15, 2025
- Modified: Apr. 16, 2025
- Vuln Type: Cross-Site Scripting
-
7.1
HIGHCVE-2025-30970
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Easy Contact allows Reflected XSS. This issue affects Easy Contact: from n/a through 0.1.2.... Read more
Affected Products :- Published: Apr. 15, 2025
- Modified: Apr. 16, 2025
- Vuln Type: Cross-Site Scripting
-
9.6
CRITICALCVE-2025-30967
Cross-Site Request Forgery (CSRF) vulnerability in NotFound WPJobBoard allows Upload a Web Shell to a Web Server. This issue affects WPJobBoard: from n/a through n/a.... Read more
Affected Products :- Published: Apr. 15, 2025
- Modified: Apr. 16, 2025
- Vuln Type: Cross-Site Request Forgery
-
5.4
MEDIUMCVE-2025-30966
Path Traversal vulnerability in NotFound WPJobBoard allows Path Traversal. This issue affects WPJobBoard: from n/a through n/a.... Read more
Affected Products :- Published: Apr. 15, 2025
- Modified: Apr. 16, 2025
- Vuln Type: Path Traversal
-
6.9
MEDIUMCVE-2025-30512
Unauthenticated attackers can send configuration settings to device and possible perform physical actions remotely (e.g., on/off).... Read more
Affected Products :- Published: Apr. 15, 2025
- Modified: Apr. 16, 2025
- Vuln Type: Authentication
-
9.8
CRITICALCVE-2025-30510
An attacker can upload an arbitrary file instead of a plant image.... Read more
Affected Products :- Published: Apr. 15, 2025
- Modified: Apr. 16, 2025
- Vuln Type: Misconfiguration
-
6.9
MEDIUMCVE-2025-30257
Unauthenticated attackers can retrieve serial number of smart meters associated to a specific user account.... Read more
Affected Products :- Published: Apr. 15, 2025
- Modified: Apr. 16, 2025
- Vuln Type: Information Disclosure
-
8.3
HIGHCVE-2025-29471
Cross Site Scripting vulnerability in Nagios Log Server v.2024R1.3.1 allows a remote attacker to execute arbitrary code via a payload into the Email field.... Read more
Affected Products : log_server- Published: Apr. 15, 2025
- Modified: Apr. 23, 2025
- Vuln Type: Cross-Site Scripting
-
6.9
MEDIUMCVE-2025-27929
Unauthenticated attackers can retrieve full list of users associated with arbitrary accounts.... Read more
Affected Products :- Published: Apr. 15, 2025
- Modified: Apr. 16, 2025
- Vuln Type: Information Disclosure
-
6.9
MEDIUMCVE-2025-27927
An unauthenticated attackers can obtain a list of smart devices by knowing a valid username through an unprotected API.... Read more
Affected Products :- Published: Apr. 15, 2025
- Modified: Apr. 16, 2025
- Vuln Type: Information Disclosure
-
6.8
MEDIUMCVE-2025-27892
Shopware prior to version 6.5.8.13 is affected by a SQL injection vulnerability in the /api/search/order endpoint. NOTE: this issue exists because of a CVE-2024-22406 and CVE-2024-42357 regression.... Read more
Affected Products : shopware- Published: Apr. 15, 2025
- Modified: Apr. 23, 2025
- Vuln Type: Injection
-
6.9
MEDIUMCVE-2025-27719
Unauthenticated attackers can query an API endpoint and get device details.... Read more
Affected Products :- Published: Apr. 15, 2025
- Modified: Apr. 16, 2025
- Vuln Type: Authentication
-
6.9
MEDIUMCVE-2025-27575
An unauthenticated attacker can obtain EV charger version and firmware upgrading history by knowing the charger ID.... Read more
Affected Products :- Published: Apr. 15, 2025
- Modified: Apr. 16, 2025
- Vuln Type: Information Disclosure
-
6.9
MEDIUMCVE-2025-27565
An unauthenticated attacker can delete any user's "rooms" by knowing the user's and room IDs.... Read more
Affected Products :- Published: Apr. 15, 2025
- Modified: Apr. 16, 2025
- Vuln Type: Authorization
-
6.9
MEDIUMCVE-2025-27561
Unauthenticated attackers can rename "rooms" of arbitrary users.... Read more
Affected Products :- Published: Apr. 15, 2025
- Modified: Apr. 16, 2025
- Vuln Type: Authentication
-
7.5
HIGHCVE-2025-27011
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in magepeopleteam Booking and Rental Manager allows PHP Local File Inclusion. This issue affects Booking and Rental Manager: from n/a thr... Read more
Affected Products : booking_\&_rental_manager- Published: Apr. 15, 2025
- Modified: Apr. 16, 2025
- Vuln Type: Path Traversal