Latest CVE Feed
- 
                                
                                
6.9
MEDIUMCVE-2025-62275
Blogs in Liferay Portal 7.4.0 through 7.4.3.111, and older unsupported versions, and Liferay DXP 2023.Q4.0 through 2023.Q4.10, 2023.Q3.1 through 2023.Q3.10, 7.4 GA through update 92, and older unsupported versions does not check permission of images in a ... Read more
- Published: Nov. 01, 2025
 - Modified: Nov. 01, 2025
 - Vuln Type: Authorization
 
 - 
                                
                                
6.4
MEDIUMCVE-2025-11922
The Inactive Logout plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'ina_redirect_page_individual_user' parameter in all versions up to, and including, 3.5.5 due to insufficient input sanitization and output escaping. This makes ... Read more
Affected Products :- Published: Nov. 01, 2025
 - Modified: Nov. 01, 2025
 - Vuln Type: Cross-Site Scripting
 
 - 
                                
                                
8.8
HIGHCVE-2025-11920
The WPCOM Member plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.7.14 via the action parameter in one of its shortcodes. This makes it possible for authenticated attackers, with Contributor-level access a... Read more
Affected Products : wpcom_member- Published: Nov. 01, 2025
 - Modified: Nov. 01, 2025
 - Vuln Type: Path Traversal
 
 - 
                                
                                
5.3
MEDIUMCVE-2025-11816
The Privacy Policy Generator, Terms & Conditions Generator WordPress Plugin : WP Legal Pages plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the disconnect_account_request() function in all vers... Read more
Affected Products :- Published: Nov. 01, 2025
 - Modified: Nov. 01, 2025
 - Vuln Type: Authorization
 
 - 
                                
                                
5.3
MEDIUMCVE-2025-11174
The Document Library Lite plugin for WordPress is vulnerable to Improper Authorization in all versions up to, and including, 1.1.6. This is due to the plugin exposing an unauthenticated AJAX action dll_load_posts which returns a JSON table of document dat... Read more
Affected Products :- Published: Nov. 01, 2025
 - Modified: Nov. 01, 2025
 - Vuln Type: Authorization
 
 - 
                                
                                
4.6
MEDIUMCVE-2025-62276
The Document Library and the Adaptive Media modules in Liferay Portal 7.4.0 through 7.4.3.111, and older unsupported versions, and Liferay DXP 2023.Q4.0 through 2023.Q4.10, 2023.Q3.1 through 2023.Q3.10, 7.4 GA through update 92, and older unsupported vers... Read more
- Published: Nov. 01, 2025
 - Modified: Nov. 01, 2025
 - Vuln Type: Misconfiguration
 
 - 
                                
                                
6.2
MEDIUMCVE-2025-12464
A stack-based buffer overflow was found in the QEMU e1000 network device. The code for padding short frames was dropped from individual network devices and moved to the net core code. The issue stems from the device's receive code still being able to proc... Read more
Affected Products :- Published: Oct. 31, 2025
 - Modified: Oct. 31, 2025
 - Vuln Type: Memory Corruption
 
 - 
                                
                                
6.1
MEDIUMCVE-2025-12334
A vulnerability was found in code-projects E-Commerce Website 1.0. Affected is an unknown function of the file /pages/product_add.php. The manipulation of the argument prod_name/prod_desc/prod_cost results in cross site scripting. It is possible to launch... Read more
Affected Products : e-commerce_website- Published: Oct. 27, 2025
 - Modified: Oct. 31, 2025
 - Vuln Type: Cross-Site Scripting
 
 - 
                                
                                
4.8
MEDIUMCVE-2025-12332
A flaw has been found in SourceCodester Student Grades Management System 1.0. This affects the function delete_user of the file /admin.php. Executing manipulation can lead to cross site scripting. The attack may be performed from remote. The exploit has b... Read more
Affected Products : student_grades_management_system- Published: Oct. 28, 2025
 - Modified: Oct. 31, 2025
 - Vuln Type: Cross-Site Scripting
 
 - 
                                
                                
6.1
MEDIUMCVE-2025-12335
A vulnerability was determined in code-projects E-Commerce Website 1.0. Affected by this vulnerability is an unknown functionality of the file /pages/supplier_update.php. This manipulation of the argument supp_name/supp_address causes cross site scripting... Read more
Affected Products : e-commerce_website- Published: Oct. 28, 2025
 - Modified: Oct. 31, 2025
 - Vuln Type: Cross-Site Scripting
 
 - 
                                
                                
7.5
HIGHCVE-2025-27223
TRUfusion Enterprise through 7.10.4.0 exposes the encrypted COOKIEID as an authentication mechanism for some endpoints such as /trufusionPortal/getProjectList. However, the application uses a static key to create the encrypted cookie, ultimately allowing ... Read more
Affected Products : trufusion_enterprise- Published: Oct. 27, 2025
 - Modified: Oct. 31, 2025
 - Vuln Type: Authentication
 
 - 
                                
                                
9.8
CRITICALCVE-2025-27224
TRUfusion Enterprise through 7.10.4.0 uses the /trufusionPortal/fileupload endpoint to upload files. However, the application doesn't properly sanitize the input to this endpoint, ultimately allowing path traversal sequences to be included. This can be us... Read more
Affected Products : trufusion_enterprise- Published: Oct. 27, 2025
 - Modified: Oct. 31, 2025
 - Vuln Type: Path Traversal
 
 - 
                                
                                
7.5
HIGHCVE-2025-27225
TRUfusion Enterprise through 7.10.4.0 exposes the /trufusionPortal/jsp/internal_admin_contact_login.jsp endpoint to unauthenticated users. This endpoint discloses sensitive internal information including PII to unauthenticated attackers.... Read more
Affected Products : trufusion_enterprise- Published: Oct. 27, 2025
 - Modified: Oct. 31, 2025
 - Vuln Type: Information Disclosure
 
 - 
                                
                                
6.5
MEDIUMCVE-2025-54967
An issue was discovered in BAE SOCET GXP before 4.6.0.3. It permits external entities in certain XML-based files. An attacker who is able to social engineer a SOCET GXP user into opening a malicious file can trigger a variety of outbound requests, potenti... Read more
Affected Products : socet_gxp- Published: Oct. 27, 2025
 - Modified: Oct. 31, 2025
 - Vuln Type: XML External Entity
 
 - 
                                
                                
8.8
HIGHCVE-2025-54968
An issue was discovered in BAE SOCET GXP before 4.6.0.2. The SOCET GXP Job Service does not require authentication. In some configurations, this may allow remote users to submit jobs, or local users to submit jobs that will execute with the permissions of... Read more
Affected Products : socet_gxp- Published: Oct. 27, 2025
 - Modified: Oct. 31, 2025
 - Vuln Type: Authentication
 
 - 
                                
                                
6.1
MEDIUMCVE-2025-54969
An issue was discovered in BAE SOCET GXP before 4.6.0.2. The SOCET GXP Job Status Service does not implement CSRF protections. An attacker who social engineers a valid user into clicking a malicious link or visiting a malicious website may be able to subm... Read more
Affected Products : socet_gxp- Published: Oct. 27, 2025
 - Modified: Oct. 31, 2025
 - Vuln Type: Cross-Site Request Forgery
 
 - 
                                
                                
6.5
MEDIUMCVE-2025-54970
An issue was discovered in BAE SOCET GXP before 4.6.0.2. The SOCET GXP Job Status Service fails to authenticate requests. In some configurations, this may allow remote or local users to abort jobs or read information without the permissions of the job own... Read more
Affected Products : socet_gxp- Published: Oct. 27, 2025
 - Modified: Oct. 31, 2025
 - Vuln Type: Authentication
 
 - 
                                
                                
9.8
CRITICALCVE-2025-12268
A vulnerability has been found in LearnHouse up to 98dfad76aad70711a8113f6c1fdabfccf10509ca. Impacted is an unknown function of the file /api/v1/courses/ of the component Course Thumbnail Handler. The manipulation of the argument thumbnail leads to unrest... Read more
Affected Products : learnhouse- Published: Oct. 27, 2025
 - Modified: Oct. 31, 2025
 - Vuln Type: Misconfiguration
 
 - 
                                
                                
5.4
MEDIUMCVE-2025-12269
A vulnerability was found in LearnHouse up to 98dfad76aad70711a8113f6c1fdabfccf10509ca. The affected element is an unknown function of the file /dash/org/settings/previews of the component Account Setting Page. The manipulation results in cross site scrip... Read more
Affected Products : learnhouse- Published: Oct. 27, 2025
 - Modified: Oct. 31, 2025
 - Vuln Type: Cross-Site Scripting
 
 - 
                                
                                
7.5
HIGHCVE-2025-12270
A vulnerability was determined in LearnHouse up to 98dfad76aad70711a8113f6c1fdabfccf10509ca. The impacted element is an unknown function of the file /api/v1/assignments/{assignment_id}/tasks/{task_id}/sub_file of the component Student Assignment Submissio... Read more
Affected Products : learnhouse- Published: Oct. 27, 2025
 - Modified: Oct. 31, 2025
 - Vuln Type: Path Traversal