Latest CVE Feed
-
6.5
CVSS31CVE-2025-47443
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpdevart Widget Countdown allows Stored XSS. This issue affects Widget Countdown: from n/a through 2.7.4.... Read more
Affected Products :- Published: May. 07, 2025
- Modified: May. 08, 2025
-
9.3
CVSS31CVE-2025-2775
SysAid On-Prem versions <= 23.3.40 are vulnerable to an unauthenticated XML External Entity (XXE) vulnerability in the Checkin processing functionality, allowing for administrator account takeover and file read primitives.... Read more
Affected Products :- Published: May. 07, 2025
- Modified: May. 08, 2025
-
7.5
CVSS31CVE-2025-47496
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in PublishPress PublishPress Authors allows PHP Local File Inclusion. This issue affects PublishPress Authors: from n/a through 4.7.5.... Read more
Affected Products :- Published: May. 07, 2025
- Modified: May. 08, 2025
-
7.5
CVSS31CVE-2025-47439
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in WP Chill Download Monitor allows PHP Local File Inclusion. This issue affects Download Monitor: from n/a through 5.0.22.... Read more
Affected Products :- Published: May. 07, 2025
- Modified: May. 08, 2025
-
4.3
CVSS31CVE-2025-47447
Cross-Site Request Forgery (CSRF) vulnerability in Hossni Mubarak Cool Author Box allows Cross Site Request Forgery. This issue affects Cool Author Box: from n/a through 3.0.0.... Read more
Affected Products :- Published: May. 07, 2025
- Modified: May. 08, 2025
-
0.0
NONECVE-2020-36791
In the Linux kernel, the following vulnerability has been resolved: net_sched: keep alloc_hash updated after hash allocation In commit 599be01ee567 ("net_sched: fix an OOB access in cls_tcindex") I moved cp->hash calculation before the first tcindex_all... Read more
Affected Products : linux_kernel- Published: May. 07, 2025
- Modified: May. 08, 2025
-
5.4
CVSS31CVE-2025-29153
SQL Injection vulnerability in lemeconsultoria HCM galera.app v.4.58.0 allows an attacker to execute arbitrary code via the Data export, filters functions.... Read more
Affected Products :- Published: May. 07, 2025
- Modified: May. 08, 2025
-
9.3
CVSS31CVE-2025-2776
SysAid On-Prem versions <= 23.3.40 are vulnerable to an unauthenticated XML External Entity (XXE) vulnerability in the Server URL processing functionality, allowing for administrator account takeover and file read primitives.... Read more
Affected Products :- Published: May. 07, 2025
- Modified: May. 08, 2025
-
6.5
CVSS31CVE-2025-47441
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Chris Reynolds Progress Bar allows Stored XSS. This issue affects Progress Bar: from n/a through 2.2.3.... Read more
Affected Products : progress_bar- Published: May. 07, 2025
- Modified: May. 08, 2025
-
4.3
CVSS31CVE-2025-47448
Cross-Site Request Forgery (CSRF) vulnerability in ThimPress WP Hotel Booking allows Cross Site Request Forgery. This issue affects WP Hotel Booking: from n/a through 2.1.9.... Read more
Affected Products : wp_hotel_booking- Published: May. 07, 2025
- Modified: May. 08, 2025
-
4.3
CVSS31CVE-2025-47451
Cross-Site Request Forgery (CSRF) vulnerability in silverplugins217 Product Quantity Dropdown For Woocommerce allows Cross Site Request Forgery. This issue affects Product Quantity Dropdown For Woocommerce: from n/a through 1.2.... Read more
Affected Products :- Published: May. 07, 2025
- Modified: May. 08, 2025
-
7.6
CVSS31CVE-2025-47460
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in TrackShip TrackShip for WooCommerce allows SQL Injection. This issue affects TrackShip for WooCommerce: from n/a through 1.9.1.... Read more
Affected Products :- Published: May. 07, 2025
- Modified: May. 08, 2025
-
5.4
CVSS31CVE-2025-47466
Cross-Site Request Forgery (CSRF) vulnerability in Rustaurius Ultimate WP Mail allows Cross Site Request Forgery. This issue affects Ultimate WP Mail: from n/a through 1.3.4.... Read more
Affected Products :- Published: May. 07, 2025
- Modified: May. 08, 2025
-
4.3
CVSS31CVE-2025-47468
Cross-Site Request Forgery (CSRF) vulnerability in hashthemes Hash Form allows Cross Site Request Forgery. This issue affects Hash Form: from n/a through 1.2.8.... Read more
Affected Products : hash_form- Published: May. 07, 2025
- Modified: May. 08, 2025
-
5.4
CVSS31CVE-2025-47472
Missing Authorization vulnerability in codepeople Music Player for WooCommerce allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Music Player for WooCommerce: from n/a through 1.5.1.... Read more
Affected Products :- Published: May. 07, 2025
- Modified: May. 08, 2025
-
4.9
CVSS31CVE-2025-47483
Server-Side Request Forgery (SSRF) vulnerability in Iulia Cazan Easy Replace Image allows Server Side Request Forgery. This issue affects Easy Replace Image: from n/a through 3.5.0.... Read more
Affected Products :- Published: May. 07, 2025
- Modified: May. 08, 2025
-
8.5
CVSS31CVE-2025-47490
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Rustaurius Ultimate WP Mail allows SQL Injection. This issue affects Ultimate WP Mail: from n/a through 1.3.4.... Read more
Affected Products :- Published: May. 07, 2025
- Modified: May. 08, 2025
-
7.4
CVSS31CVE-2025-47491
Cross-Site Request Forgery (CSRF) vulnerability in A WP Life Contact Form Widget allows Cross Site Request Forgery. This issue affects Contact Form Widget: from n/a through 1.4.6.... Read more
Affected Products : contact_form_widget- Published: May. 07, 2025
- Modified: May. 08, 2025
-
6.5
CVSS31CVE-2025-47547
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in SendPulse SendPulse Email Marketing Newsletter allows Stored XSS. This issue affects SendPulse Email Marketing Newsletter: from n/a through 2.1.6.... Read more
Affected Products :- Published: May. 07, 2025
- Modified: May. 08, 2025
-
7.6
CVSS31CVE-2025-47544
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in acowebs Dynamic Pricing With Discount Rules for WooCommerce allows Blind SQL Injection. This issue affects Dynamic Pricing With Discount Rules for WooCom... Read more
Affected Products :- Published: May. 07, 2025
- Modified: May. 08, 2025