Latest CVE Feed
-
4.3
MEDIUMCVE-2025-12847
The All in One SEO – Powerful SEO Plugin to Boost SEO Rankings & Increase Traffic plugin for WordPress is vulnerable to unauthorized arbitrary media attachment deletion due to a missing authorization check in all versions up to, and including, 4.8.9. This... Read more
Affected Products : all_in_one_seo- Published: Nov. 15, 2025
- Modified: Nov. 18, 2025
- Vuln Type: Authorization
-
6.5
MEDIUMCVE-2025-13208
A security flaw has been discovered in FantasticLBP Hotels Server up to 67b44df162fab26df209bd5d5d542875fcbec1d0. The impacted element is an unknown function of the file controller/api/hotelList.php. The manipulation of the argument subjectId/cityName res... Read more
Affected Products :- Published: Nov. 15, 2025
- Modified: Nov. 18, 2025
- Vuln Type: Injection
-
7.5
HIGHCVE-2025-13033
A vulnerability was identified in the email parsing library due to improper handling of specially formatted recipient email addresses. An attacker can exploit this flaw by crafting a recipient address that embeds an external address within quotes. This ca... Read more
Affected Products : nodemailer- Published: Nov. 14, 2025
- Modified: Nov. 18, 2025
- Vuln Type: Information Disclosure
-
8.7
HIGHCVE-2025-62765
General Industrial Controls Lynx+ Gateway is vulnerable to a cleartext transmission vulnerability that could allow an attacker to observe network traffic to obtain sensitive information, including plaintext credentials.... Read more
Affected Products :- Published: Nov. 15, 2025
- Modified: Nov. 18, 2025
- Vuln Type: Information Disclosure
-
6.5
MEDIUMCVE-2025-54348
A Stored Cross Site Scripting (XSS) vulnerability was found in the Application Server of Desktop Alert PingAlert version 6.1.0.11 to 6.1.1.2 which allows an attacker to hijack user’s browser, capturing sensitive information.... Read more
Affected Products :- Published: Nov. 14, 2025
- Modified: Nov. 18, 2025
- Vuln Type: Cross-Site Scripting
-
7.3
HIGHCVE-2025-13204
npm package `expr-eval` is vulnerable to Prototype Pollution. An attacker with access to express eval interface can use JavaScript prototype-based inheritance model to achieve arbitrary code execution. The npm expr-eval-fork package resolves this issue.... Read more
Affected Products :- Published: Nov. 14, 2025
- Modified: Nov. 18, 2025
- Vuln Type: Misconfiguration
-
5.3
MEDIUMCVE-2025-6171
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13.2 before 18.3.6, 18.4 before 18.4.4, and 18.5 before 18.5.2 that could have allowed an authenticated attacker with reporter access to view branch names and pipeline details by a... Read more
Affected Products : gitlab- Published: Nov. 15, 2025
- Modified: Nov. 18, 2025
- Vuln Type: Authorization
-
4.3
MEDIUMCVE-2025-54562
A vulnerability was found in the Application Server of Desktop Alert PingAlert version 6.1.0.11 to 6.1.1.2 which allows Technical Information to be Disclosed through stack trace.... Read more
Affected Products :- Published: Nov. 14, 2025
- Modified: Nov. 18, 2025
- Vuln Type: Information Disclosure
-
4.3
MEDIUMCVE-2025-12494
The Image Gallery – Photo Grid & Video Gallery plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the ajax_import_file function in all versions up to, and including, 2.12.28. This makes it possible fo... Read more
Affected Products :- Published: Nov. 15, 2025
- Modified: Nov. 18, 2025
- Vuln Type: Path Traversal
-
5.3
MEDIUMCVE-2025-13179
A vulnerability has been found in Bdtask/CodeCanyon Wholesale Inventory Control and Inventory Management System up to 20250320. This issue affects some unknown processing. Such manipulation leads to cross-site request forgery. The attack may be performed ... Read more
Affected Products :- Published: Nov. 14, 2025
- Modified: Nov. 18, 2025
- Vuln Type: Cross-Site Request Forgery
-
3.7
LOWCVE-2025-54559
An issue was found in the Application Server of Desktop Alert PingAlert version 6.1.0.11 to 6.1.1.2 which allows remote Path Traversal for loading arbitrary external content.... Read more
Affected Products :- Published: Nov. 14, 2025
- Modified: Nov. 18, 2025
- Vuln Type: Path Traversal
-
8.8
HIGHCVE-2025-55034
General Industrial Controls Lynx+ Gateway is vulnerable to a weak password requirement vulnerability, which may allow an attacker to execute a brute-force attack resulting in unauthorized access and login.... Read more
Affected Products :- Published: Nov. 15, 2025
- Modified: Nov. 18, 2025
- Vuln Type: Authentication
-
6.5
MEDIUMCVE-2025-13209
A weakness has been identified in bestfeng oa_git_free up to 9.5. This affects the function updateWriteBack of the file yimioa-oa9.5\server\c-flow\src\main\java\com\cloudweb\oa\controller\WorkflowPredefineController.java. This manipulation of the argument... Read more
Affected Products :- Published: Nov. 15, 2025
- Modified: Nov. 18, 2025
- Vuln Type: XML External Entity
-
6.5
MEDIUMCVE-2025-13174
A weakness has been identified in rachelos WeRSS we-mp-rss up to 1.4.7. Affected by this vulnerability is the function do_job of the file /rachelos/we-mp-rss/blob/main/jobs/mps.py of the component Webhook Module. Executing manipulation of the argument web... Read more
Affected Products :- Published: Nov. 14, 2025
- Modified: Nov. 18, 2025
- Vuln Type: Server-Side Request Forgery
-
7.5
HIGHCVE-2025-12482
The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to SQL Injection via the ‘search’ parameter in all versions up to, and including, 1.2.35 due to insufficient escaping on the user supplied parameter and lack of s... Read more
Affected Products : amelia- Published: Nov. 16, 2025
- Modified: Nov. 18, 2025
- Vuln Type: Injection
-
8.7
HIGHCVE-2021-4466
IPCop versions up to and including 2.1.9 contain an authenticated remote code execution vulnerability within the web-based administration interface. The email configuration component inserts user-controlled values, including the EMAIL_PW parameter, direct... Read more
Affected Products : ipcop- Published: Nov. 14, 2025
- Modified: Nov. 18, 2025
- Vuln Type: Injection
-
10.0
HIGHCVE-2025-13188
A vulnerability was detected in D-Link DIR-816L 2_06_b09_beta. Affected by this vulnerability is the function authenticationcgi_main of the file /authentication.cgi. Performing manipulation of the argument Password results in stack-based buffer overflow. ... Read more
Affected Products : dir-816l_firmware- Published: Nov. 14, 2025
- Modified: Nov. 18, 2025
- Vuln Type: Memory Corruption
-
5.8
MEDIUMCVE-2025-13185
A security flaw has been discovered in Bdtask/CodeCanyon News365 up to 7.0.3. This affects an unknown function of the file /admin/dashboard/profile. The manipulation of the argument profile_image/banner_image results in unrestricted upload. The attack can... Read more
Affected Products :- Published: Nov. 14, 2025
- Modified: Nov. 18, 2025
- Vuln Type: Misconfiguration
-
4.3
MEDIUMCVE-2025-12182
The Qi Blocks plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the `resize_image_callback()` function in all versions up to, and including, 1.4.3. This is due to the plugin not properly verifying that a user h... Read more
Affected Products : qi_blocks- Published: Nov. 15, 2025
- Modified: Nov. 18, 2025
- Vuln Type: Authorization
-
6.5
MEDIUMCVE-2025-63291
When processing API requests, the Alteryx server 2022.1.1.42654 and 2024.1 used MongoDB object IDs to uniquely identify the data being requested by the caller. The Alteryx server did not check whether the authenticated user had permission to access the sp... Read more
Affected Products :- Published: Nov. 14, 2025
- Modified: Nov. 18, 2025
- Vuln Type: Authorization