Latest CVE Feed
-
8.8
HIGHCVE-2025-3417
The Embedder plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on the ajax_set_global_option() function in versions 1.3 to 1.3.5. This makes it possible for auth... Read more
Affected Products :- Published: Apr. 10, 2025
- Modified: Apr. 11, 2025
- Vuln Type: Authorization
-
7.3
HIGHCVE-2025-2809
The azurecurve Shortcodes in Comments plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 2.0.2. This is due to the software allowing users to execute an action that does not properly validate a value ... Read more
Affected Products :- Published: Apr. 10, 2025
- Modified: Apr. 11, 2025
- Vuln Type: Authentication
-
7.3
HIGHCVE-2025-2805
The ORDER POST plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 2.0.2. This is due to the software allowing users to execute an action that does not properly validate a value before running do_short... Read more
Affected Products :- Published: Apr. 10, 2025
- Modified: Apr. 11, 2025
- Vuln Type: Authentication
-
6.5
MEDIUMCVE-2025-2719
The Swatchly – WooCommerce Variation Swatches for Products (product attributes: Image swatch, Color swatches, Label swatches) plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the ajax_dismiss fun... Read more
Affected Products : swatchly- Published: Apr. 10, 2025
- Modified: Apr. 11, 2025
- Vuln Type: Authorization
-
4.9
MEDIUMCVE-2024-13909
The Accredible Certificates & Open Badges plugin for WordPress is vulnerable to time-based SQL Injection via the ‘orderby’ parameter in all versions up to, and including, 1.4.9 due to insufficient escaping on the user supplied parameter and lack of suffic... Read more
Affected Products : accredible_certificates_\&_open_badges- Published: Apr. 10, 2025
- Modified: Apr. 11, 2025
- Vuln Type: Injection
-
6.5
MEDIUMCVE-2024-13896
The WP-GeSHi-Highlight — rock-solid syntax highlighting for 259 languages WordPress plugin through 1.4.3 processes user-supplied input as a regular expression via the wp_geshi_filter_replace_code() function, which could lead to Regular Expression Denial o... Read more
Affected Products : wp-geshi-highlight- Published: Apr. 10, 2025
- Modified: May. 15, 2025
- Vuln Type: Denial of Service
-
7.1
HIGHCVE-2024-13874
The Feedify WordPress plugin before 2.4.6 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin... Read more
Affected Products : web_push_notifications- Published: Apr. 10, 2025
- Modified: Apr. 30, 2025
- Vuln Type: Cross-Site Scripting
-
6.4
MEDIUMCVE-2024-10894
The Payment Forms for Paystack plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes like 'datepicker', 'textarea', and 'text' in all versions up to, and including, 4.0.2 due to insufficient input sanitization and o... Read more
Affected Products : payment_forms_for_paystack- Published: Apr. 10, 2025
- Modified: Apr. 11, 2025
- Vuln Type: Cross-Site Scripting
-
8.8
HIGHCVE-2025-0539
In affected Microsoft Windows versions of Octopus Deploy, the server can be coerced into sending server-side requests that contain authentication material allowing a suitably positioned attacker to compromise the account running Octopus Server and potenti... Read more
- Published: Apr. 10, 2025
- Modified: Jul. 02, 2025
- Vuln Type: Server-Side Request Forgery
-
8.1
HIGHCVE-2025-3102
The SureTriggers: All-in-One Automation Platform plugin for WordPress is vulnerable to an authentication bypass leading to administrative account creation due to a missing empty value check on the 'secret_key' value in the 'autheticate_user' function in a... Read more
Affected Products :- Published: Apr. 10, 2025
- Modified: Apr. 11, 2025
- Vuln Type: Authentication
-
6.1
MEDIUMCVE-2025-3489
A vulnerability was found in Nababur Simple-User-Management-System 1.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /register.php. The manipulation of the argument name/username leads to cross site sc... Read more
Affected Products : simple-user-management-system- Published: Apr. 10, 2025
- Modified: Apr. 29, 2025
- Vuln Type: Cross-Site Scripting
-
9.8
CRITICALCVE-2025-27690
Dell PowerScale OneFS, versions 9.5.0.0 through 9.10.1.0, contains a use of default password vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to the takeover of a high privileged user acco... Read more
- Published: Apr. 10, 2025
- Modified: Jul. 11, 2025
- Vuln Type: Authentication
-
7.5
HIGHCVE-2025-26480
Dell PowerScale OneFS, versions 9.5.0.0 through 9.10.0.0, contains an uncontrolled resource consumption vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to denial of service.... Read more
- Published: Apr. 10, 2025
- Modified: Jul. 11, 2025
- Vuln Type: Denial of Service
-
3.1
LOWCVE-2025-26479
Dell PowerScale OneFS, versions 9.4.0.0 through 9.10.0.0, contains an out-of-bounds write vulnerability. An attacker could potentially exploit this vulnerability in NFS workflows, leading to data integrity issues.... Read more
- Published: Apr. 10, 2025
- Modified: Jul. 15, 2025
- Vuln Type: Memory Corruption
-
7.0
HIGHCVE-2025-26330
Dell PowerScale OneFS, versions 9.4.0.0 through 9.10.0.1, contains an incorrect authorization vulnerability. An unauthenticated attacker with local access could potentially exploit this vulnerability to access the cluster with previous privileges of a dis... Read more
- Published: Apr. 10, 2025
- Modified: Jul. 15, 2025
- Vuln Type: Authorization
-
3.3
LOWCVE-2025-23378
Dell PowerScale OneFS, versions 9.4.0.0 through 9.10.0.0, contains an exposure of information through directory listing vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to information disclos... Read more
- Published: Apr. 10, 2025
- Modified: Jul. 15, 2025
- Vuln Type: Information Disclosure
-
6.5
MEDIUMCVE-2025-22471
Dell PowerScale OneFS, versions 9.4.0.0 through 9.10.0.1, contains an integer overflow or wraparound vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to denial of service.... Read more
- Published: Apr. 10, 2025
- Modified: Jul. 15, 2025
- Vuln Type: Denial of Service
-
9.8
CRITICALCVE-2024-58136
Yii 2 before 2.0.52 mishandles the attaching of behavior that is defined by an __class array key, a CVE-2024-4990 regression, as exploited in the wild in February through April 2025.... Read more
Affected Products : yii- Actively Exploited
- Published: Apr. 10, 2025
- Modified: Jul. 30, 2025
- Vuln Type: Misconfiguration
-
4.3
MEDIUMCVE-2025-32728
In sshd in OpenSSH before 10.0, the DisableForwarding directive does not adhere to the documentation stating that it disables X11 and agent forwarding.... Read more
- Published: Apr. 10, 2025
- Modified: May. 22, 2025
- Vuln Type: Misconfiguration
-
4.4
MEDIUMCVE-2025-29989
Dell Client Platform BIOS contains a Security Version Number Mutable to Older Versions vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to BIOS upgrade denial.... Read more
- Published: Apr. 10, 2025
- Modified: Aug. 18, 2025
- Vuln Type: Denial of Service