CVE Feed

    Dashboard / CVE

    5.3
    Medium

    CVE-2025-55675

    Last Modified: 4 Nov 2025

    Apache Superset contains an improper access control vulnerability in its /explore endpoint. A missing authorization check allows an authenticated user to discover metadata about datasources they do not have permission to access. By iterating through the datasource_id in the URL, an attacker can enumerate and confirm the existence and names of protected datasources, leading to sensitive information disclosure. This issue affects Apache Superset: before 5.0.0. Users are recommended to upgrade to version 5.0.0, which fixes the issue.

    Published: 14 Aug 2025
    5.3
    Medium

    CVE-2025-55674

    Last Modified: 4 Nov 2025

    A bypass of the DISALLOWED_SQL_FUNCTIONS security feature in Apache Superset allows for the execution of blocked SQL functions. An attacker can use a special inline block to circumvent the denylist. This allows a user with SQL Lab access to execute functions that were intended to be disabled, leading to the disclosure of sensitive database information like the software version. This issue affects Apache Superset: before 5.0.0. Users are recommended to upgrade to version 5.0.0, which fixes the issue.

    Published: 14 Aug 2025
    5.3
    Medium

    CVE-2025-55672

    Last Modified: 4 Nov 2025

    A stored Cross-Site Scripting (XSS) vulnerability exists in Apache Superset's chart visualization. An authenticated user with permissions to edit charts can inject a malicious payload into a column's label. The payload is not properly sanitized and gets executed in the victim's browser when they hover over the chart, potentially leading to session hijacking or the execution of arbitrary commands on behalf of the user. This issue affects Apache Superset: before 5.0.0. Users are recommended to upgrade to version 5.0.0, which fixes the issue.

    Published: 14 Aug 2025
    5.3
    Medium

    CVE-2025-55673

    Last Modified: 4 Nov 2025

    When a guest user accesses a chart in Apache Superset, the API response from the /chart/data endpoint includes a query field in its payload. This field contains the underlying query, which improperly discloses database schema information, such as table names, to the low-privileged guest user. This issue affects Apache Superset: before 4.1.3. Users are recommended to upgrade to version 4.1.3, which fixes the issue.

    Published: 14 Aug 2025
    4.1
    Medium

    CVE-2023-5342

    Last Modified: 15 Apr 2026

    The Fedora Secure Boot CA certificate shipped with shim in Fedora was expired which could lead to old or invalid signed boot components being loaded.

    Published: 14 Aug 2025
    5.3
    Medium

    CVE-2025-8963

    Last Modified: 17 Oct 2025

    A vulnerability was determined in jeecgboot JimuReport up to 2.1.1. Affected by this issue is some unknown functionality of the file /drag/onlDragDataSource/testConnection of the component Data Large Screen Template. The manipulation leads to deserialization. The attack may be launched remotely. The vendor response to the GitHub issue report is: "Modified, next version updated".

    Published: 14 Aug 2025
    8.8
    High

    CVE-2025-8715

    Last Modified: 15 Apr 2026

    Improper neutralization of newlines in pg_dump in PostgreSQL allows a user of the origin server to inject arbitrary code for restore-time execution as the client operating system account running psql to restore the dump, via psql meta-commands inside a purpose-crafted object name. The same attacks can achieve SQL injection as a superuser of the restore target server. pg_dumpall, pg_restore, and pg_upgrade are also affected. Versions before PostgreSQL 17.6, 16.10, 15.14, 14.19, and 13.22 are affected. Versions before 11.20 are unaffected. CVE-2012-0868 had fixed this class of problem, but version 11.20 reintroduced it.

    Published: 14 Aug 2025
    8.8
    High

    CVE-2025-8714

    Last Modified: 15 Apr 2026

    Untrusted data inclusion in pg_dump in PostgreSQL allows a malicious superuser of the origin server to inject arbitrary code for restore-time execution as the client operating system account running psql to restore the dump, via psql meta-commands. pg_dumpall is also affected. pg_restore is affected when used to generate a plain-format dump. This is similar to MySQL CVE-2024-21096. Versions before PostgreSQL 17.6, 16.10, 15.14, 14.19, and 13.22 are affected.

    Published: 14 Aug 2025
    3.1
    Low

    CVE-2025-8713

    Last Modified: 15 Apr 2026

    PostgreSQL optimizer statistics allow a user to read sampled data within a view that the user cannot access. Separately, statistics allow a user to read sampled data that a row security policy intended to hide. PostgreSQL maintains statistics for tables by sampling data available in columns; this data is consulted during the query planning process. Prior to this release, a user could craft a leaky operator that bypassed view access control lists (ACLs) and bypassed row security policies in partitioning or table inheritance hierarchies. Reachable statistics data notably included histograms and most-common-values lists. CVE-2017-7484 and CVE-2019-10130 intended to close this class of vulnerability, but this gap remained. Versions before PostgreSQL 17.6, 16.10, 15.14, 14.19, and 13.22 are affected.

    Published: 14 Aug 2025
    Unknown

    CVE-2025-55721

    Last Modified: 15 Aug 2025

    Not used

    Published: 14 Aug 2025
    Unknown

    CVE-2025-55722

    Last Modified: 15 Aug 2025

    Not used

    Published: 14 Aug 2025
    Unknown

    CVE-2025-55723

    Last Modified: 15 Aug 2025

    Not used

    Published: 14 Aug 2025
    Unknown

    CVE-2025-55724

    Last Modified: 15 Aug 2025

    Not used

    Published: 14 Aug 2025
    Unknown

    CVE-2025-55725

    Last Modified: 15 Aug 2025

    Not used

    Published: 14 Aug 2025
    Unknown

    CVE-2025-55726

    Last Modified: 15 Aug 2025

    Not used

    Published: 14 Aug 2025
    Unknown

    CVE-2025-55718

    Last Modified: 15 Aug 2025

    Not used

    Published: 14 Aug 2025
    Unknown

    CVE-2025-55719

    Last Modified: 15 Aug 2025

    Not used

    Published: 14 Aug 2025
    Unknown

    CVE-2025-55720

    Last Modified: 15 Aug 2025

    Not used

    Published: 14 Aug 2025
    1.9
    Low

    CVE-2025-8961

    Last Modified: 11 Sept 2025

    A weakness has been identified in LibTIFF 4.7.0. This affects the function main of the file tiffcrop.c of the component tiffcrop. Executing manipulation can lead to memory corruption. The attack can only be executed locally. The exploit has been made available to the public and could be exploited.

    Published: 14 Aug 2025
    5.5
    Medium

    CVE-2025-8960

    Last Modified: 14 Aug 2025

    A vulnerability has been found in Campcodes Online Flight Booking Management System 1.0. Affected by this issue is some unknown functionality of the file /admin/save_airlines.php. The manipulation of the argument ID leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

    Published: 14 Aug 2025
    7.4
    High

    CVE-2025-8958

    Last Modified: 21 Oct 2025

    A vulnerability was identified in Tenda TX3 16.03.13.11_multi_TDE01. Affected by this vulnerability is an unknown functionality of the file /goform/fast_setting_wifi_set. The manipulation of the argument ssid leads to stack-based buffer overflow. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

    Published: 14 Aug 2025
    9.3
    Critical

    CVE-2025-54707

    Last Modified: 23 Apr 2026

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in RealMag777 MDTF wp-meta-data-filter-and-taxonomy-filter allows SQL Injection.This issue affects MDTF: from n/a through <= 1.3.3.7.

    Published: 14 Aug 2025
    6.5
    Medium

    CVE-2025-54706

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Noor Alam Magical Posts Display magical-posts-display allows DOM-Based XSS.This issue affects Magical Posts Display: from n/a through <= 1.2.52.

    Published: 14 Aug 2025
    4.3
    Medium

    CVE-2025-54705

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in magepeopleteam WpEvently mage-eventpress allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WpEvently: from n/a through <= 4.4.6.

    Published: 14 Aug 2025
    6.5
    Medium

    CVE-2025-54704

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in hashthemes Easy Elementor Addons easy-elementor-addons allows DOM-Based XSS.This issue affects Easy Elementor Addons: from n/a through <= 2.2.6.

    Published: 14 Aug 2025
    4.3
    Medium

    CVE-2025-54703

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in princeahmed Integrate Google Drive integrate-google-drive allows Cross Site Request Forgery.This issue affects Integrate Google Drive: from n/a through <= 1.5.2.

    Published: 14 Aug 2025
    4.3
    Medium

    CVE-2025-54702

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in motov.net Ebook Store ebook-store allows Cross Site Request Forgery.This issue affects Ebook Store: from n/a through <= 5.8013.

    Published: 14 Aug 2025
    8.1
    High

    CVE-2025-54701

    Last Modified: 23 Apr 2026

    Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeMove Unicamp unicamp allows PHP Local File Inclusion.This issue affects Unicamp: from n/a through <= 2.6.3.

    Published: 14 Aug 2025
    8.1
    High

    CVE-2025-54700

    Last Modified: 23 Apr 2026

    Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeMove Makeaholic makeaholic allows PHP Local File Inclusion.This issue affects Makeaholic: from n/a through <= 1.8.4.

    Published: 14 Aug 2025
    6.5
    Medium

    CVE-2025-54699

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in masteriyo Masteriyo - LMS learning-management-system allows Stored XSS.This issue affects Masteriyo - LMS: from n/a through <= 1.18.3.

    Published: 14 Aug 2025
    5.4
    Medium

    CVE-2025-54698

    Last Modified: 23 Apr 2026

    Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in RadiusTheme Classified Listing classified-listing allows Code Injection.This issue affects Classified Listing: from n/a through <= 5.0.0.

    Published: 14 Aug 2025
    7.2
    High

    CVE-2025-54697

    Last Modified: 23 Apr 2026

    Incorrect Privilege Assignment vulnerability in StellarWP Kadence WooCommerce Email Designer kadence-woocommerce-email-designer allows Privilege Escalation.This issue affects Kadence WooCommerce Email Designer: from n/a through <= 1.5.16.

    Published: 14 Aug 2025
    6.5
    Medium

    CVE-2025-54696

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPFunnels WPFunnels wpfunnels allows Stored XSS.This issue affects WPFunnels: from n/a through <= 3.5.26.

    Published: 14 Aug 2025
    5.4
    Medium

    CVE-2025-54695

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in DevItems HT Mega ht-mega-for-elementor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects HT Mega: from n/a through <= 2.9.0.

    Published: 14 Aug 2025
    4.3
    Medium

    CVE-2025-54694

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in bPlugins Button Block button-block allows Cross Site Request Forgery.This issue affects Button Block: from n/a through <= 1.2.0.

    Published: 14 Aug 2025
    9
    Critical

    CVE-2025-54693

    Last Modified: 23 Apr 2026

    Unrestricted Upload of File with Dangerous Type vulnerability in epiphyt Form Block form-block allows Upload a Web Shell to a Web Server.This issue affects Form Block: from n/a through <= 1.5.5.

    Published: 14 Aug 2025
    7.5
    High

    CVE-2025-54692

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in WP Swings Membership For WooCommerce membership-for-woocommerce allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Membership For WooCommerce: from n/a through <= 2.9.0.

    Published: 14 Aug 2025
    5.3
    Medium

    CVE-2025-54691

    Last Modified: 23 Apr 2026

    Authorization Bypass Through User-Controlled Key vulnerability in Stylemix Motors motors-car-dealership-classified-listings allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Motors: from n/a through <= 1.4.80.

    Published: 14 Aug 2025
    8.1
    High

    CVE-2025-54690

    Last Modified: 23 Apr 2026

    Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in themeStek Xinterio xinterio allows PHP Local File Inclusion.This issue affects Xinterio: from n/a through <= 4.2.

    Published: 14 Aug 2025
    8.1
    High

    CVE-2025-54689

    Last Modified: 23 Apr 2026

    Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in thembay Urna urna allows PHP Local File Inclusion.This issue affects Urna: from n/a through <= 2.5.7.

    Published: 14 Aug 2025
    6.5
    Medium

    CVE-2025-54688

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock JetEngine jet-engine allows Stored XSS.This issue affects JetEngine: from n/a through <= 3.7.1.2.

    Published: 14 Aug 2025
    6.5
    Medium

    CVE-2025-54687

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock JetTabs jet-tabs allows DOM-Based XSS.This issue affects JetTabs: from n/a through <= 2.2.9.1.

    Published: 14 Aug 2025
    9.8
    Critical

    CVE-2025-54686

    Last Modified: 23 Apr 2026

    Deserialization of Untrusted Data vulnerability in scriptsbundle Exertio exertio allows Object Injection.This issue affects Exertio: from n/a through <= 1.3.2.

    Published: 14 Aug 2025
    6.5
    Medium

    CVE-2025-54685

    Last Modified: 23 Apr 2026

    Insertion of Sensitive Information Into Sent Data vulnerability in Brainstorm Force SureDash suredash allows Retrieve Embedded Sensitive Data.This issue affects SureDash: from n/a through <= 1.1.0.

    Published: 14 Aug 2025
    5.9
    Medium

    CVE-2025-54684

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CRM Perks Integration for Contact Form 7 and Constant Contact cf7-constant-contact allows Stored XSS.This issue affects Integration for Contact Form 7 and Constant Contact: from n/a through <= 1.1.7.

    Published: 14 Aug 2025
    5.9
    Medium

    CVE-2025-54683

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Astoundify WP Modal Popup with Cookie Integration wp-modal-popup-with-cookie-integration allows Reflected XSS.This issue affects WP Modal Popup with Cookie Integration: from n/a through <= 2.4.

    Published: 14 Aug 2025
    5.4
    Medium

    CVE-2025-54682

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in CRM Perks Connector for Gravity Forms and Google Sheets wp-gravity-forms-spreadsheets allows Cross Site Request Forgery.This issue affects Connector for Gravity Forms and Google Sheets: from n/a through <= 1.2.4.

    Published: 14 Aug 2025
    4.7
    Medium

    CVE-2025-54681

    Last Modified: 23 Apr 2026

    URL Redirection to Untrusted Site ('Open Redirect') vulnerability in CRM Perks Connector for Gravity Forms and Google Sheets wp-gravity-forms-spreadsheets allows Phishing.This issue affects Connector for Gravity Forms and Google Sheets: from n/a through <= 1.2.4.

    Published: 14 Aug 2025
    6.5
    Medium

    CVE-2025-54680

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in sparklewpthemes Blogger Buzz blogger-buzz allows Stored XSS.This issue affects Blogger Buzz: from n/a through <= 1.2.6.

    Published: 14 Aug 2025
    7.5
    High

    CVE-2025-54679

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in vertim Neon Channel Product Customizer Free neon-channel-product-customizer-free allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Neon Channel Product Customizer Free: from n/a through <= 2.0.

    Published: 14 Aug 2025