Latest CVE Feed
-
6.6
CVSS31CVE-2025-47550
Unrestricted Upload of File with Dangerous Type vulnerability in Themefic Instantio allows Upload a Web Shell to a Web Server. This issue affects Instantio: from n/a through 3.3.16.... Read more
Affected Products :- Published: May. 07, 2025
- Modified: May. 08, 2025
-
7.6
CVSS31CVE-2025-47587
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in YayCommerce YaySMTP allows Blind SQL Injection. This issue affects YaySMTP: from n/a through 2.6.4.... Read more
Affected Products : yaysmtp- Published: May. 07, 2025
- Modified: May. 08, 2025
-
5.9
CVSS31CVE-2025-47605
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in AppJetty WP jQuery DataTable allows Stored XSS. This issue affects WP jQuery DataTable: from n/a through 4.1.0.... Read more
Affected Products :- Published: May. 07, 2025
- Modified: May. 08, 2025
-
6.5
CVSS31CVE-2025-47616
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Tushar Imran aBlocks allows Stored XSS. This issue affects aBlocks: from n/a through 1.9.1.... Read more
Affected Products :- Published: May. 07, 2025
- Modified: May. 08, 2025
-
6.5
CVSS31CVE-2025-47630
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Darren Cooney Ajax Load More allows Stored XSS. This issue affects Ajax Load More: from n/a through 7.3.1.... Read more
Affected Products : ajax_load_more- Published: May. 07, 2025
- Modified: May. 08, 2025
-
5.5
CVSS31CVE-2025-47635
Server-Side Request Forgery (SSRF) vulnerability in WPWebinarSystem WebinarPress allows Server Side Request Forgery. This issue affects WebinarPress: from n/a through 1.33.27.... Read more
Affected Products : webinarpress- Published: May. 07, 2025
- Modified: May. 08, 2025
-
4.7
CVSS31CVE-2025-47644
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in formsintegrations Integrations of Zoho CRM with Elementor form allows Phishing. This issue affects Integrations of Zoho CRM with Elementor form: from n/a through 1.0.7.... Read more
Affected Products :- Published: May. 07, 2025
- Modified: May. 08, 2025
-
4.3
CVSS31CVE-2025-47647
Cross-Site Request Forgery (CSRF) vulnerability in OTWthemes Sidebar Manager Light allows Cross Site Request Forgery. This issue affects Sidebar Manager Light: from n/a through 1.18.... Read more
Affected Products :- Published: May. 07, 2025
- Modified: May. 08, 2025
-
7.1
CVSS31CVE-2025-47648
Cross-Site Request Forgery (CSRF) vulnerability in axima Pays – WooCommerce Payment Gateway allows Stored XSS. This issue affects Pays – WooCommerce Payment Gateway: from n/a through 2.6.... Read more
Affected Products :- Published: May. 07, 2025
- Modified: May. 08, 2025
-
8.8
CVSS31CVE-2025-47649
Path Traversal vulnerability in ilmosys Open Close WooCommerce Store allows PHP Local File Inclusion. This issue affects Open Close WooCommerce Store: from n/a through 4.9.5.... Read more
Affected Products :- Published: May. 07, 2025
- Modified: May. 08, 2025
-
7.1
CVSS31CVE-2025-47655
Cross-Site Request Forgery (CSRF) vulnerability in themarketer2023 theMarketer allows Stored XSS. This issue affects theMarketer: from n/a through 1.4.7.... Read more
Affected Products :- Published: May. 07, 2025
- Modified: May. 08, 2025
-
6.5
CVSS31CVE-2025-47656
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in spiraclethemes Spiraclethemes Site Library allows Stored XSS. This issue affects Spiraclethemes Site Library: from n/a through 1.4.0.... Read more
Affected Products :- Published: May. 07, 2025
- Modified: May. 08, 2025
-
5.4
CVSS31CVE-2025-47661
Cross-Site Request Forgery (CSRF) vulnerability in codemstory 워드프레스 결제 심플페이 allows Cross Site Request Forgery. This issue affects 워드프레스 결제 심플페이: from n/a through 5.2.11.... Read more
Affected Products :- Published: May. 07, 2025
- Modified: May. 08, 2025
-
4.4
CVSS31CVE-2025-47664
Server-Side Request Forgery (SSRF) vulnerability in ThimPress WP Pipes allows Server Side Request Forgery. This issue affects WP Pipes: from n/a through 1.4.2.... Read more
Affected Products : wp_pipes- Published: May. 07, 2025
- Modified: May. 08, 2025
-
5.4
CVSS31CVE-2025-47667
Cross-Site Request Forgery (CSRF) vulnerability in qusupport LiveAgent allows Cross Site Request Forgery. This issue affects LiveAgent: from n/a through 4.4.7.... Read more
Affected Products :- Published: May. 07, 2025
- Modified: May. 08, 2025
-
4.3
CVSS31CVE-2025-47674
Cross-Site Request Forgery (CSRF) vulnerability in Credova Financial Credova_Financial allows Cross Site Request Forgery. This issue affects Credova_Financial: from n/a through 2.5.0.... Read more
Affected Products : financial- Published: May. 07, 2025
- Modified: May. 08, 2025
-
6.5
CVSS31CVE-2025-47686
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in DELUCKS DELUCKS SEO allows Stored XSS. This issue affects DELUCKS SEO: from n/a through 2.5.9.... Read more
Affected Products : delucks_seo- Published: May. 07, 2025
- Modified: May. 08, 2025
-
5.3
CVSS31CVE-2025-47688
Missing Authorization vulnerability in Saad Iqbal Advanced File Manager allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Advanced File Manager: from n/a through 5.3.1.... Read more
Affected Products : advanced_file_manager- Published: May. 07, 2025
- Modified: May. 08, 2025
-
8.0
CVSS31CVE-2025-46827
Graylog is a free and open log management platform. Prior to versions 6.0.14, 6.1.10, and 6.2.0, it is possible to obtain user session cookies by submitting an HTML form as part of an Event Definition Remediation Step field. For this attack to succeed, th... Read more
Affected Products : graylog- Published: May. 07, 2025
- Modified: May. 08, 2025
-
0.0
NONECVE-2025-46551
JRuby-OpenSSL is an add-on gem for JRuby that emulates the Ruby OpenSSL native library. Starting in JRuby-OpenSSL version 0.12.1 and prior to version 0.15.4 (corresponding to JRuby versions starting in 9.3.4.0 prior to 9.4.12.1 and 10.0.0.0 prior to 10.0.... Read more
Affected Products : jruby-openssl- Published: May. 07, 2025
- Modified: May. 08, 2025