Latest CVE Feed
-
7.1
HIGHCVE-2025-30970
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Easy Contact allows Reflected XSS. This issue affects Easy Contact: from n/a through 0.1.2.... Read more
Affected Products :- Published: Apr. 15, 2025
- Modified: Apr. 16, 2025
- Vuln Type: Cross-Site Scripting
-
9.6
CRITICALCVE-2025-30967
Cross-Site Request Forgery (CSRF) vulnerability in NotFound WPJobBoard allows Upload a Web Shell to a Web Server. This issue affects WPJobBoard: from n/a through n/a.... Read more
Affected Products :- Published: Apr. 15, 2025
- Modified: Apr. 16, 2025
- Vuln Type: Cross-Site Request Forgery
-
5.4
MEDIUMCVE-2025-30966
Path Traversal vulnerability in NotFound WPJobBoard allows Path Traversal. This issue affects WPJobBoard: from n/a through n/a.... Read more
Affected Products :- Published: Apr. 15, 2025
- Modified: Apr. 16, 2025
- Vuln Type: Path Traversal
-
6.9
MEDIUMCVE-2025-30512
Unauthenticated attackers can send configuration settings to device and possible perform physical actions remotely (e.g., on/off).... Read more
Affected Products :- Published: Apr. 15, 2025
- Modified: Apr. 16, 2025
- Vuln Type: Authentication
-
9.8
CRITICALCVE-2025-30510
An attacker can upload an arbitrary file instead of a plant image.... Read more
Affected Products :- Published: Apr. 15, 2025
- Modified: Apr. 16, 2025
- Vuln Type: Misconfiguration
-
6.9
MEDIUMCVE-2025-30257
Unauthenticated attackers can retrieve serial number of smart meters associated to a specific user account.... Read more
Affected Products :- Published: Apr. 15, 2025
- Modified: Apr. 16, 2025
- Vuln Type: Information Disclosure
-
8.3
HIGHCVE-2025-29471
Cross Site Scripting vulnerability in Nagios Log Server v.2024R1.3.1 allows a remote attacker to execute arbitrary code via a payload into the Email field.... Read more
Affected Products : log_server- Published: Apr. 15, 2025
- Modified: Apr. 23, 2025
- Vuln Type: Cross-Site Scripting
-
6.9
MEDIUMCVE-2025-27929
Unauthenticated attackers can retrieve full list of users associated with arbitrary accounts.... Read more
Affected Products :- Published: Apr. 15, 2025
- Modified: Apr. 16, 2025
- Vuln Type: Information Disclosure
-
6.9
MEDIUMCVE-2025-27927
An unauthenticated attackers can obtain a list of smart devices by knowing a valid username through an unprotected API.... Read more
Affected Products :- Published: Apr. 15, 2025
- Modified: Apr. 16, 2025
- Vuln Type: Information Disclosure
-
6.8
MEDIUMCVE-2025-27892
Shopware prior to version 6.5.8.13 is affected by a SQL injection vulnerability in the /api/search/order endpoint. NOTE: this issue exists because of a CVE-2024-22406 and CVE-2024-42357 regression.... Read more
Affected Products : shopware- Published: Apr. 15, 2025
- Modified: Apr. 23, 2025
- Vuln Type: Injection
-
6.9
MEDIUMCVE-2025-27719
Unauthenticated attackers can query an API endpoint and get device details.... Read more
Affected Products :- Published: Apr. 15, 2025
- Modified: Apr. 16, 2025
- Vuln Type: Authentication
-
6.9
MEDIUMCVE-2025-27575
An unauthenticated attacker can obtain EV charger version and firmware upgrading history by knowing the charger ID.... Read more
Affected Products :- Published: Apr. 15, 2025
- Modified: Apr. 16, 2025
- Vuln Type: Information Disclosure
-
6.9
MEDIUMCVE-2025-27565
An unauthenticated attacker can delete any user's "rooms" by knowing the user's and room IDs.... Read more
Affected Products :- Published: Apr. 15, 2025
- Modified: Apr. 16, 2025
- Vuln Type: Authorization
-
6.9
MEDIUMCVE-2025-27561
Unauthenticated attackers can rename "rooms" of arbitrary users.... Read more
Affected Products :- Published: Apr. 15, 2025
- Modified: Apr. 16, 2025
- Vuln Type: Authentication
-
7.5
HIGHCVE-2025-27011
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in magepeopleteam Booking and Rental Manager allows PHP Local File Inclusion. This issue affects Booking and Rental Manager: from n/a thr... Read more
Affected Products : booking_\&_rental_manager- Published: Apr. 15, 2025
- Modified: Apr. 16, 2025
- Vuln Type: Path Traversal
-
7.5
HIGHCVE-2025-27008
Missing Authorization vulnerability in NotFound Unlimited Timeline allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Unlimited Timeline: from n/a through n/a.... Read more
Affected Products :- Published: Apr. 15, 2025
- Modified: Apr. 16, 2025
- Vuln Type: Authorization
-
6.5
MEDIUMCVE-2025-26998
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in sonalsinha21 SKT Blocks – Gutenberg based Page Builder allows Stored XSS. This issue affects SKT Blocks – Gutenberg based Page Builder: from n/a through ... Read more
Affected Products : skt_blocks- Published: Apr. 15, 2025
- Modified: May. 21, 2025
- Vuln Type: Cross-Site Scripting
-
6.5
MEDIUMCVE-2025-26996
Improper Control of Generation of Code ('Code Injection') vulnerability in Fetch Designs Sign-up Sheets allows Code Injection. This issue affects Sign-up Sheets: from n/a through 2.3.0.1.... Read more
Affected Products : sign-up_sheets- Published: Apr. 15, 2025
- Modified: Apr. 16, 2025
- Vuln Type: Injection
-
7.5
HIGHCVE-2025-26953
Missing Authorization vulnerability in NotFound JetMenu allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects JetMenu: from n/a through 2.4.9.... Read more
Affected Products :- Published: Apr. 15, 2025
- Modified: Apr. 16, 2025
- Vuln Type: Authorization
-
6.5
MEDIUMCVE-2025-26951
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in covertnine C9 Blocks allows DOM-Based XSS. This issue affects C9 Blocks: from n/a through 1.7.7.... Read more
Affected Products :- Published: Apr. 15, 2025
- Modified: Apr. 16, 2025
- Vuln Type: Cross-Site Scripting