Latest CVE Feed
-
6.5
MEDIUMCVE-2025-32209
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in totalprocessing Total processing card payments for WooCommerce allows Path Traversal. This issue affects Total processing card payments for WooCommerce: from n... Read more
Affected Products :- Published: Apr. 10, 2025
- Modified: Apr. 11, 2025
- Vuln Type: Path Traversal
-
6.5
MEDIUMCVE-2025-32208
Missing Authorization vulnerability in Hive Support Hive Support allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Hive Support: from n/a through 1.2.2.... Read more
Affected Products :- Published: Apr. 10, 2025
- Modified: Apr. 11, 2025
- Vuln Type: Authorization
-
9.1
CRITICALCVE-2025-32206
Unrestricted Upload of File with Dangerous Type vulnerability in LABCAT Processing Projects allows Upload a Web Shell to a Web Server. This issue affects Processing Projects: from n/a through 1.0.2.... Read more
Affected Products :- Published: Apr. 10, 2025
- Modified: Apr. 11, 2025
- Vuln Type: Misconfiguration
-
2.7
LOWCVE-2025-32205
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in piotnetdotcom Piotnet Forms. This issue affects Piotnet Forms: from n/a through 1.0.30.... Read more
Affected Products : piotnet_forms- Published: Apr. 10, 2025
- Modified: Apr. 11, 2025
- Vuln Type: Path Traversal
-
9.1
CRITICALCVE-2025-32202
Unrestricted Upload of File with Dangerous Type vulnerability in Brian Batt - elearningfreak.com Insert or Embed Articulate Content into WordPress allows Upload a Web Shell to a Web Server. This issue affects Insert or Embed Articulate Content into WordPr... Read more
Affected Products : insert_or_embed_articulate_content- Published: Apr. 10, 2025
- Modified: Apr. 11, 2025
- Vuln Type: Misconfiguration
-
6.5
MEDIUMCVE-2025-32199
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in eyale-vc Contact Form Builder by vcita. This issue affects Contact Form Builder by vcita: from n/a through 4.10.2.... Read more
Affected Products : contact_form_and_calls_to_action_by_vcita- Published: Apr. 10, 2025
- Modified: Apr. 11, 2025
- Vuln Type: Cross-Site Scripting
-
6.5
MEDIUMCVE-2025-32198
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in themefusecom Brizy. This issue affects Brizy: from n/a through 2.6.14.... Read more
Affected Products : brizy- Published: Apr. 10, 2025
- Modified: Aug. 07, 2025
- Vuln Type: Cross-Site Scripting
-
7.5
HIGHCVE-2025-32160
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Ashan Perera EventON. This issue affects EventON: from n/a through 2.3.2.... Read more
Affected Products :- Published: Apr. 10, 2025
- Modified: Apr. 11, 2025
- Vuln Type: Path Traversal
-
8.8
HIGHCVE-2025-32158
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in aThemes aThemes Addons for Elementor. This issue affects aThemes Addons for Elementor: from n/a through 1.0.15.... Read more
Affected Products : athemes_addons_for_elementor- Published: Apr. 10, 2025
- Modified: May. 29, 2025
- Vuln Type: Path Traversal
-
8.8
HIGHCVE-2025-32145
Deserialization of Untrusted Data vulnerability in magepeopleteam WpEvently allows Object Injection. This issue affects WpEvently: from n/a through 4.3.5.... Read more
Affected Products : event_manager_and_tickets_selling_for_woocommerce- Published: Apr. 10, 2025
- Modified: Apr. 11, 2025
- Vuln Type: Injection
-
9.9
CRITICALCVE-2025-32140
Unrestricted Upload of File with Dangerous Type vulnerability in Nirmal Kumar Ram WP Remote Thumbnail allows Upload a Web Shell to a Web Server. This issue affects WP Remote Thumbnail: from n/a through 1.3.1.... Read more
Affected Products :- Published: Apr. 10, 2025
- Modified: Apr. 11, 2025
- Vuln Type: Misconfiguration
-
5.9
MEDIUMCVE-2025-32139
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in bradvin FooBox Image Lightbox . This issue affects FooBox Image Lightbox : from n/a through 2.7.33.... Read more
Affected Products :- Published: Apr. 10, 2025
- Modified: Apr. 11, 2025
- Vuln Type: Cross-Site Scripting
-
7.6
HIGHCVE-2025-32128
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in aaronfrey Nearby Locations allows SQL Injection. This issue affects Nearby Locations: from n/a through 1.1.1.... Read more
Affected Products :- Published: Apr. 10, 2025
- Modified: Apr. 11, 2025
- Vuln Type: Injection
-
8.2
HIGHCVE-2025-32119
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in CardGate CardGate Payments for WooCommerce allows Blind SQL Injection. This issue affects CardGate Payments for WooCommerce: from n/a through 3.2.1.... Read more
Affected Products :- Published: Apr. 10, 2025
- Modified: Apr. 11, 2025
- Vuln Type: Injection
-
7.1
HIGHCVE-2025-32116
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Studi7 QR Master allows Reflected XSS. This issue affects QR Master: from n/a through 1.0.5.... Read more
Affected Products :- Published: Apr. 10, 2025
- Modified: Apr. 11, 2025
- Vuln Type: Cross-Site Scripting
-
7.1
HIGHCVE-2025-32115
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in OTWthemes Popping Content Light allows Reflected XSS. This issue affects Popping Content Light: from n/a through 2.4.... Read more
Affected Products :- Published: Apr. 10, 2025
- Modified: Apr. 11, 2025
- Vuln Type: Cross-Site Scripting
-
7.1
HIGHCVE-2025-32114
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in 5sterrenspecialist 5sterrenspecialist allows Reflected XSS. This issue affects 5sterrenspecialist: from n/a through 1.3.... Read more
Affected Products :- Published: Apr. 10, 2025
- Modified: Apr. 11, 2025
- Vuln Type: Cross-Site Scripting
-
8.8
HIGHCVE-2025-31524
Incorrect Privilege Assignment vulnerability in NotFound WP User Profiles allows Privilege Escalation. This issue affects WP User Profiles: from n/a through 2.6.2.... Read more
Affected Products :- Published: Apr. 10, 2025
- Modified: Apr. 11, 2025
- Vuln Type: Authorization
-
8.1
HIGHCVE-2025-30582
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in aytechnet DyaPress ERP/CRM allows PHP Local File Inclusion. This issue affects DyaPress ERP/CRM: from n/a through 18.0.2.0.... Read more
Affected Products :- Published: Apr. 10, 2025
- Modified: Apr. 11, 2025
- Vuln Type: Path Traversal
-
8.8
HIGHCVE-2024-38865
Improper neutralization of livestatus command delimiters in a specific endpoint within RestAPI of Checkmk prior to 2.2.0p39, 2.3.0p25, and 2.1.0p51 (EOL) allows arbitrary livestatus command execution. Exploitation requires the attacker to have a contact g... Read more
- Published: Apr. 10, 2025
- Modified: Aug. 21, 2025
- Vuln Type: Injection