Latest CVE Feed
-
9.8
CRITICALCVE-2024-55210
An issue in TOTVS Framework (Linha Protheus) 12.1.2310 allows attackers to bypass multi-factor authentication (MFA) via a crafted websocket message.... Read more
Affected Products : framework_\(linha_protheus\)- Published: Apr. 09, 2025
- Modified: Apr. 30, 2025
- Vuln Type: Authentication
-
7.8
HIGHCVE-2025-2630
There is a DLL hijacking vulnerability due to an uncontrolled search path that exists in NI LabVIEW. This vulnerability may result in arbitrary code execution. Successful exploitation requires an attacker to insert a malicious DLL into the uncontrolled ... Read more
Affected Products : labview- Published: Apr. 09, 2025
- Modified: Aug. 18, 2025
- Vuln Type: Misconfiguration
-
7.8
HIGHCVE-2025-2629
There is a DLL hijacking vulnerability due to an uncontrolled search path that exists in NI LabVIEW when loading NI Error Reporting. This vulnerability may result in arbitrary code execution. Successful exploitation requires an attacker to insert a mali... Read more
Affected Products : labview- Published: Apr. 09, 2025
- Modified: Aug. 18, 2025
- Vuln Type: Misconfiguration
-
6.5
MEDIUMCVE-2025-3475
Allocation of Resources Without Limits or Throttling, Incorrect Authorization vulnerability in Drupal WEB-T allows Excessive Allocation, Content Spoofing.This issue affects WEB-T: from 0.0.0 before 1.1.0.... Read more
- Published: Apr. 09, 2025
- Modified: Jun. 02, 2025
- Vuln Type: Authorization
-
6.5
MEDIUMCVE-2025-3474
Missing Authentication for Critical Function vulnerability in Drupal Panels allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Panels: from 0.0.0 before 4.9.0.... Read more
Affected Products : panels- Published: Apr. 09, 2025
- Modified: May. 01, 2025
- Vuln Type: Authentication
-
5.4
MEDIUMCVE-2025-3131
Cross-Site Request Forgery (CSRF) vulnerability in Drupal ECA: Event - Condition - Action allows Cross Site Request Forgery.This issue affects ECA: Event - Condition - Action: from 0.0.0 before 1.1.12, from 2.0.0 before 2.0.16, from 2.1.0 before 2.1.7, fr... Read more
Affected Products : eca\- Published: Apr. 09, 2025
- Modified: Apr. 22, 2025
- Vuln Type: Cross-Site Request Forgery
-
9.8
CRITICALCVE-2025-3115
Injection Vulnerabilities: Attackers can inject malicious code, potentially gaining control over the system executing these functions. Additionally, insufficient validation of filenames during file uploads can enable attackers to upload and execute malici... Read more
- Published: Apr. 09, 2025
- Modified: Apr. 22, 2025
- Vuln Type: Injection
-
9.4
CRITICALCVE-2025-3114
Code Execution via Malicious Files: Attackers can create specially crafted files with embedded code that may execute without adequate security validation, potentially leading to system compromise. Sandbox Bypass Vulnerability: A flaw in the TERR security... Read more
Affected Products :- Published: Apr. 09, 2025
- Modified: Apr. 15, 2025
- Vuln Type: Misconfiguration
-
9.8
CRITICALCVE-2025-32695
Incorrect Privilege Assignment vulnerability in Mestres do WP Checkout Mestres WP allows Privilege Escalation. This issue affects Checkout Mestres WP: from n/a through 8.7.5.... Read more
Affected Products : checkout_mestres_wp- Published: Apr. 09, 2025
- Modified: Apr. 09, 2025
- Vuln Type: Authorization
-
4.7
MEDIUMCVE-2025-32694
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Rustaurius Ultimate WP Mail allows Phishing. This issue affects Ultimate WP Mail: from n/a through 1.3.2.... Read more
Affected Products : ultimate_wp_mail- Published: Apr. 09, 2025
- Modified: Apr. 09, 2025
- Vuln Type: Misconfiguration
-
4.7
MEDIUMCVE-2025-32693
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in WPWebinarSystem WebinarPress allows Phishing. This issue affects WebinarPress: from n/a through 1.33.27.... Read more
Affected Products : webinarpress- Published: Apr. 09, 2025
- Modified: Apr. 09, 2025
- Vuln Type: Misconfiguration
-
7.5
HIGHCVE-2025-32692
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in WP Shuffle WP Subscription Forms allows PHP Local File Inclusion. This issue affects WP Subscription Forms: from n/a through 1.2.4.... Read more
Affected Products :- Published: Apr. 09, 2025
- Modified: Apr. 09, 2025
- Vuln Type: Path Traversal
-
4.9
MEDIUMCVE-2025-32691
Server-Side Request Forgery (SSRF) vulnerability in Angelo Mandato PowerPress Podcasting allows Server Side Request Forgery. This issue affects PowerPress Podcasting: from n/a through 11.12.4.... Read more
Affected Products : powerpress- Published: Apr. 09, 2025
- Modified: Apr. 09, 2025
- Vuln Type: Server-Side Request Forgery
-
6.5
MEDIUMCVE-2025-32690
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Angelo Mandato PowerPress Podcasting allows DOM-Based XSS.This issue affects PowerPress Podcasting: from n/a through 11.12.5.... Read more
Affected Products : powerpress- Published: Apr. 09, 2025
- Modified: May. 05, 2025
- Vuln Type: Cross-Site Scripting
-
7.6
HIGHCVE-2025-32685
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Aristo Rinjuang WP Inquiries allows SQL Injection. This issue affects WP Inquiries: from n/a through 0.2.1.... Read more
Affected Products :- Published: Apr. 09, 2025
- Modified: Apr. 09, 2025
- Vuln Type: Injection
-
5.0
MEDIUMCVE-2025-32684
Missing Authorization vulnerability in RomanCode MapSVG Lite allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects MapSVG Lite: from n/a through 8.5.32.... Read more
Affected Products : mapsvg_lite- Published: Apr. 09, 2025
- Modified: Apr. 09, 2025
- Vuln Type: Authorization
-
6.5
MEDIUMCVE-2025-32683
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in RomanCode MapSVG Lite allows DOM-Based XSS. This issue affects MapSVG Lite: from n/a through 8.5.32.... Read more
Affected Products : mapsvg_lite- Published: Apr. 09, 2025
- Modified: Apr. 09, 2025
- Vuln Type: Cross-Site Scripting
-
5.9
MEDIUMCVE-2025-32680
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Grade Us, Inc. Review Stream allows Stored XSS. This issue affects Review Stream: from n/a through 1.6.7.... Read more
Affected Products : review_stream- Published: Apr. 09, 2025
- Modified: Apr. 09, 2025
- Vuln Type: Cross-Site Scripting
-
5.4
MEDIUMCVE-2025-32679
Cross-Site Request Forgery (CSRF) vulnerability in ZealousWeb User Registration Using Contact Form 7 allows Cross Site Request Forgery. This issue affects User Registration Using Contact Form 7: from n/a through 2.2.... Read more
Affected Products :- Published: Apr. 09, 2025
- Modified: Apr. 09, 2025
- Vuln Type: Cross-Site Request Forgery
-
4.3
MEDIUMCVE-2025-32678
Cross-Site Request Forgery (CSRF) vulnerability in Ashish Ajani WP Show Stats allows Cross Site Request Forgery. This issue affects WP Show Stats: from n/a through 1.5.... Read more
Affected Products :- Published: Apr. 09, 2025
- Modified: Apr. 09, 2025
- Vuln Type: Cross-Site Request Forgery