Latest CVE Feed
-
2.3
LOWCVE-2024-49709
Internet Starter, one of SoftCOM iKSORIS system modules, allows for setting an arbitrary session cookie value. An attacker with an access to user's browser might set such a cookie, wait until the user logs in and then use the same cookie to take over the ... Read more
Affected Products :- Published: Apr. 14, 2025
- Modified: Apr. 15, 2025
- Vuln Type: Authentication
-
5.1
MEDIUMCVE-2024-49708
Internet Starter, one of SoftCOM iKSORIS system modules, is vulnerable to Stored XSS (Cross-site Scripting) attacks. An attacker might trick a user into filling a form designed for setting delivery address with a malicious script, what causes the script t... Read more
Affected Products :- Published: Apr. 14, 2025
- Modified: Apr. 15, 2025
- Vuln Type: Cross-Site Scripting
-
5.1
MEDIUMCVE-2024-49707
Internet Starter, one of SoftCOM iKSORIS system modules, is vulnerable to Reflected XSS (Cross-site Scripting) attacks. An attacker might trick a user into filling a form designed for resetting user's password with a malicious script, what causes the scri... Read more
Affected Products :- Published: Apr. 14, 2025
- Modified: Apr. 15, 2025
- Vuln Type: Cross-Site Scripting
-
5.1
MEDIUMCVE-2024-49706
Internet Starter, one of SoftCOM iKSORIS system modules, is vulnerable to Open Redirect attacks by including base64 encoded URLs in the target parameter sent in a POST request to one of the endpoints. This vulnerability has been patched in version 79.0... Read more
Affected Products :- Published: Apr. 14, 2025
- Modified: Apr. 15, 2025
- Vuln Type: Misconfiguration
-
5.3
MEDIUMCVE-2024-49705
Internet Starter, one of SoftCOM iKSORIS system modules, is vulnerable to client-side Denial of Servise (DoS) attacks. An attacker might trick a user into using an URL with a d parameter set to an unhandled value. All the subsequent requests will not be a... Read more
Affected Products :- Published: Apr. 14, 2025
- Modified: Apr. 15, 2025
- Vuln Type: Denial of Service
-
5.1
MEDIUMCVE-2024-13598
Internet Starter, one of SoftCOM iKSORIS system modules, is vulnerable to Reflected XSS (Cross-site Scripting) attacks. Using a functionality of creating new form fields one creates new parameters vulnerable to XSS attacks. A user tricked into filling su... Read more
Affected Products :- Published: Apr. 14, 2025
- Modified: Apr. 15, 2025
- Vuln Type: Cross-Site Scripting
-
5.1
MEDIUMCVE-2024-13597
Internet Starter, one of SoftCOM iKSORIS system modules, is vulnerable to Reflected XSS (Cross-site Scripting) attacks. An attacker might trick a user into filling a form sent to login panel at /softcom/ with a malicious script, what causes the script to ... Read more
Affected Products :- Published: Apr. 14, 2025
- Modified: Apr. 15, 2025
- Vuln Type: Cross-Site Scripting
-
5.1
MEDIUMCVE-2024-10090
Internet Starter, one of SoftCOM iKSORIS system modules, is vulnerable to Reflected XSS (Cross-site Scripting) attacks. An attacker might trick a user into filling a form designed for adding users with a malicious script, what causes the script to run in ... Read more
Affected Products :- Published: Apr. 14, 2025
- Modified: Apr. 15, 2025
- Vuln Type: Cross-Site Scripting
-
5.1
MEDIUMCVE-2024-10089
Internet Starter, one of SoftCOM iKSORIS system modules, is vulnerable to Stored XSS (Cross-site Scripting) attacks. An attacker might trick a user into filling a form designed for changing user's data with a malicious script, what causes the script to ru... Read more
Affected Products :- Published: Apr. 14, 2025
- Modified: Apr. 15, 2025
- Vuln Type: Cross-Site Scripting
-
5.1
MEDIUMCVE-2024-10088
Internet Starter, one of SoftCOM iKSORIS system modules, is vulnerable to Reflected XSS (Cross-site Scripting) attacks. An attacker might trick a user into filling a login form with a malicious script, what causes the script to run in user's context. Thi... Read more
Affected Products :- Published: Apr. 14, 2025
- Modified: Apr. 15, 2025
- Vuln Type: Cross-Site Scripting
-
5.3
MEDIUMCVE-2024-10087
Internet Starter, one of SoftCOM iKSORIS system modules, is vulnerable to Reflected XSS (Cross-site Scripting) attacks. An attacker might craft a link containing a malicious script, which then gets directly embedded in references to other resources, what ... Read more
Affected Products :- Published: Apr. 14, 2025
- Modified: Apr. 15, 2025
- Vuln Type: Cross-Site Scripting
-
7.2
HIGHCVE-2025-3563
A vulnerability was found in WuzhiCMS 4.1. It has been rated as critical. Affected by this issue is the function Set of the file /index.php?m=attachment&f=index&_su=wuzhicms&v=set&submit=1 of the component Setting Handler. The manipulation of the argument... Read more
Affected Products : wuzhicms- Published: Apr. 14, 2025
- Modified: Apr. 29, 2025
- Vuln Type: Injection
-
5.3
MEDIUMCVE-2025-3562
A vulnerability was found in Yonyou YonBIP MA2.7. It has been declared as problematic. Affected by this vulnerability is the function FileInputStream of the file /mobsm/common/userfile. The manipulation of the argument path leads to path traversal. The at... Read more
Affected Products : yonbip- Published: Apr. 14, 2025
- Modified: Apr. 15, 2025
- Vuln Type: Path Traversal
-
7.1
HIGHCVE-2025-27009
Cross-Site Request Forgery (CSRF) vulnerability in wphocus My auctions allegro allows Stored XSS.This issue affects My auctions allegro: from n/a through 3.6.20.... Read more
Affected Products :- Published: Apr. 14, 2025
- Modified: Apr. 15, 2025
- Vuln Type: Cross-Site Request Forgery
-
5.3
MEDIUMCVE-2025-3561
A vulnerability was found in ghostxbh uzy-ssm-mall 1.0.0. It has been classified as problematic. Affected is an unknown function. The manipulation leads to cross-site request forgery. It is possible to launch the attack remotely. The exploit has been disc... Read more
Affected Products :- Published: Apr. 14, 2025
- Modified: Apr. 15, 2025
- Vuln Type: Cross-Site Request Forgery
-
5.1
MEDIUMCVE-2025-3560
A vulnerability was found in ghostxbh uzy-ssm-mall 1.0.0 and classified as problematic. This issue affects some unknown processing of the file /product. The manipulation of the argument product_name leads to cross site scripting. The attack may be initiat... Read more
Affected Products :- Published: Apr. 14, 2025
- Modified: Apr. 15, 2025
- Vuln Type: Cross-Site Scripting
-
6.5
MEDIUMCVE-2025-3559
A vulnerability has been found in ghostxbh uzy-ssm-mall 1.0.0 and classified as critical. This vulnerability affects the function ForeProductListController of the file /mall/product/0/20. The manipulation of the argument orderBy leads to sql injection. Th... Read more
Affected Products :- Published: Apr. 14, 2025
- Modified: Apr. 15, 2025
- Vuln Type: Injection
-
6.5
MEDIUMCVE-2025-3558
A vulnerability, which was classified as critical, was found in ghostxbh uzy-ssm-mall 1.0.0. This affects an unknown part of the file /mall/user/uploadUserHeadImage. The manipulation of the argument File leads to unrestricted upload. It is possible to ini... Read more
Affected Products :- Published: Apr. 14, 2025
- Modified: Apr. 15, 2025
- Vuln Type: Misconfiguration
-
8.8
HIGHCVE-2025-24859
A session management vulnerability exists in Apache Roller before version 6.1.5 where active user sessions are not properly invalidated after password changes. When a user's password is changed, either by the user themselves or by an administrator, existi... Read more
Affected Products : roller- Published: Apr. 14, 2025
- Modified: Jun. 03, 2025
- Vuln Type: Authentication
-
5.3
MEDIUMCVE-2025-3557
A vulnerability, which was classified as problematic, has been found in ScriptAndTools eCommerce-website-in-PHP 3.0. Affected by this issue is some unknown functionality. The manipulation leads to cross-site request forgery. The attack may be launched rem... Read more
Affected Products : ecommerce-website-in-php- Published: Apr. 14, 2025
- Modified: Jul. 17, 2025
- Vuln Type: Cross-Site Request Forgery