CVE Feed

    Dashboard / CVE

    4.9
    Medium

    CVE-2025-47465

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in creativethemeshq Blocksy blocksy allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Blocksy: from n/a through <= 2.0.97.

    Published: 7 May 2025
    4.9
    Medium

    CVE-2025-47464

    Last Modified: 23 Apr 2026

    Server-Side Request Forgery (SSRF) vulnerability in solacewp Solace Extra solace-extra allows Server Side Request Forgery.This issue affects Solace Extra: from n/a through <= 1.3.1.

    Published: 7 May 2025
    8.8
    High

    CVE-2025-47462

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in WebAppick Challan webappick-pdf-invoice-for-woocommerce allows Privilege Escalation.This issue affects Challan: from n/a through <= 3.7.58.

    Published: 7 May 2025
    7.6
    High

    CVE-2025-47460

    Last Modified: 23 Apr 2026

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in TrackShip TrackShip for WooCommerce trackship-for-woocommerce allows SQL Injection.This issue affects TrackShip for WooCommerce: from n/a through <= 1.9.1.

    Published: 7 May 2025
    4.3
    Medium

    CVE-2025-47459

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Roxnor FundEngine wp-fundraising-donation allows Cross Site Request Forgery.This issue affects FundEngine: from n/a through <= 1.7.3.

    Published: 7 May 2025
    5.3
    Medium

    CVE-2025-47457

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in dgamoni LocateAndFilter locateandfilter allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects LocateAndFilter: from n/a through <= 1.6.16.

    Published: 7 May 2025
    4.7
    Medium

    CVE-2025-47456

    Last Modified: 23 Apr 2026

    URL Redirection to Untrusted Site ('Open Redirect') vulnerability in CRM Perks WP Gravity Forms Zendesk gf-zendesk allows Phishing.This issue affects WP Gravity Forms Zendesk: from n/a through <= 1.1.2.

    Published: 7 May 2025
    4.7
    Medium

    CVE-2025-47455

    Last Modified: 23 Apr 2026

    URL Redirection to Untrusted Site ('Open Redirect') vulnerability in CRM Perks Integration for WooCommerce and Salesforce woo-salesforce-plugin-crm-perks allows Phishing.This issue affects Integration for WooCommerce and Salesforce: from n/a through <= 1.7.5.

    Published: 7 May 2025
    4.7
    Medium

    CVE-2025-47454

    Last Modified: 23 Apr 2026

    URL Redirection to Untrusted Site ('Open Redirect') vulnerability in CRM Perks WP Gravity Forms Dynamics CRM gf-dynamics-crm allows Phishing.This issue affects WP Gravity Forms Dynamics CRM: from n/a through <= 1.1.4.

    Published: 7 May 2025
    4.3
    Medium

    CVE-2025-47451

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in silverplugins217 Product Quantity Dropdown For Woocommerce product-quantity-dropdown-for-woocommerce allows Cross Site Request Forgery.This issue affects Product Quantity Dropdown For Woocommerce: from n/a through <= 1.2.

    Published: 7 May 2025
    5.3
    Medium

    CVE-2025-47450

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in Mitchell Bennis Simple File List simple-file-list allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Simple File List: from n/a through <= 6.1.13.

    Published: 7 May 2025
    5.9
    Medium

    CVE-2025-47449

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jordy Meow Meow Gallery meow-gallery allows Stored XSS.This issue affects Meow Gallery: from n/a through <= 5.2.7.

    Published: 7 May 2025
    4.3
    Medium

    CVE-2025-47448

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in ThimPress WP Hotel Booking wp-hotel-booking allows Cross Site Request Forgery.This issue affects WP Hotel Booking: from n/a through <= 2.1.9.

    Published: 7 May 2025
    4.3
    Medium

    CVE-2025-47447

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Hossni Mubarak Cool Author Box hm-cool-author-box-widget allows Cross Site Request Forgery.This issue affects Cool Author Box: from n/a through <= 3.0.0.

    Published: 7 May 2025
    4.3
    Medium

    CVE-2025-47446

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in listamester Listamester listamester allows Cross Site Request Forgery.This issue affects Listamester: from n/a through <= 2.3.6.

    Published: 7 May 2025
    6.5
    Medium

    CVE-2025-47443

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpdevart Widget Countdown widget-countdown allows Stored XSS.This issue affects Widget Countdown: from n/a through <= 2.7.4.

    Published: 7 May 2025
    6.5
    Medium

    CVE-2025-47442

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CC CC BMI Calculator cc-bmi-calculator allows Stored XSS.This issue affects CC BMI Calculator: from n/a through <= 2.1.0.

    Published: 7 May 2025
    6.5
    Medium

    CVE-2025-47441

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Chris Reynolds Progress Bar progress-bar allows Stored XSS.This issue affects Progress Bar: from n/a through <= 2.2.3.

    Published: 7 May 2025
    7.5
    High

    CVE-2025-47440

    Last Modified: 23 Apr 2026

    Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Greg Winiarski WPAdverts wpadverts allows PHP Local File Inclusion.This issue affects WPAdverts: from n/a through <= 2.2.2.

    Published: 7 May 2025
    7.5
    High

    CVE-2025-47439

    Last Modified: 23 Apr 2026

    Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in WP Chill Download Monitor download-monitor allows PHP Local File Inclusion.This issue affects Download Monitor: from n/a through <= 5.0.22.

    Published: 7 May 2025
    Unknown

    CVE-2025-35980

    Last Modified: 29 Oct 2025

    ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2025. Notes: none.

    Published: 7 May 2025
    7.5
    High

    CVE-2025-33093

    Last Modified: 13 Nov 2025

    IBM Sterling Partner Engagement Manager 6.1.0, 6.2.0, 6.2.2 JWT secret is stored in public Helm Charts and is not stored as a Kubernetes secret.

    Published: 7 May 2025
    9.8
    Critical

    CVE-2025-4104

    Last Modified: 15 Apr 2026

    The Frontend Dashboard plugin for WordPress is vulnerable to Privilege Escalation due to a missing capability check on the fed_wp_ajax_fed_login_form_post() function in versions 1.0 to 2.2.6. This makes it possible for unauthenticated attackers to reset the administrator’s email and password, and elevate their privileges to that of an administrator.

    Published: 7 May 2025
    6.5
    Medium

    CVE-2025-39361

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Royal Royal Elementor Addons royal-elementor-addons allows Stored XSS.This issue affects Royal Elementor Addons: from n/a through <= 1.7.1017.

    Published: 7 May 2025
    6.9
    Medium

    CVE-2025-27533

    Last Modified: 3 Nov 2025

    Memory Allocation with Excessive Size Value vulnerability in Apache ActiveMQ. During unmarshalling of OpenWire commands the size value of buffers was not properly validated which could lead to excessive memory allocation and be exploited to cause a denial of service (DoS) by depleting process memory, thereby affecting applications and services that rely on the availability of the ActiveMQ broker when not using mutual TLS connections. This issue affects Apache ActiveMQ: from 6.0.0 before 6.1.6, from 5.18.0 before 5.18.7, from 5.17.0 before 5.17.7, before 5.16.8. ActiveMQ 5.19.0 is not affected. Users are recommended to upgrade to version 6.1.6+, 5.19.0+, 5.18.7+, 5.17.7, or 5.16.8 or which fixes the issue. Existing users may implement mutual TLS to mitigate the risk on affected brokers.

    Published: 7 May 2025
    4
    Medium

    CVE-2025-20980

    Last Modified: 2 Oct 2025

    Out-of-bounds write in libsavscmn prior to Android 15 allows local attackers to cause memory corruption.

    Published: 7 May 2025
    8.4
    High

    CVE-2025-20979

    Last Modified: 26 Feb 2026

    Out-of-bounds write in libsavscmn prior to Android 15 allows local attackers to execute arbitrary code.

    Published: 7 May 2025
    6.2
    Medium

    CVE-2025-20978

    Last Modified: 15 Apr 2026

    Improper access control in PENUP prior to version 3.9.19.32 allows local attackers to access files with PENUP privilege.

    Published: 7 May 2025
    3.3
    Low

    CVE-2025-20977

    Last Modified: 16 Jul 2025

    Use of implicit intent for sensitive communication in translation in Samsung Notes prior to version 4.4.29.23 allows local attackers to get sensitive information. User interaction is required for triggering this vulnerability.

    Published: 7 May 2025
    5.5
    Medium

    CVE-2025-20976

    Last Modified: 17 Jul 2025

    Out-of-bounds read in applying binary of text content in Samsung Notes prior to version 4.4.29.23 allows attackers to read out-of-bounds memory.

    Published: 7 May 2025
    5.5
    Medium

    CVE-2025-20975

    Last Modified: 15 Apr 2026

    Improper Export of Android Application Components in AODService prior to version 8.8.28.12 allows local attackers to launch arbitrary activity with systemui privilege.

    Published: 7 May 2025
    6.1
    Medium

    CVE-2025-20974

    Last Modified: 15 Apr 2026

    Improper handling of insufficient permission in PackageInstallerCN prior to version 15.0.11.0 allows local attacker to bypass user interaction for requested installation.

    Published: 7 May 2025
    5.4
    Medium

    CVE-2025-20973

    Last Modified: 15 Apr 2026

    Improper authentication in Secure Folder prior to version 1.8.12.0 in Android 13, and 1.9.21.00 in Android 14 allows physical attackers to reset the lock type of Secure Folder.

    Published: 7 May 2025
    6.2
    Medium

    CVE-2025-20972

    Last Modified: 16 Jul 2025

    Improper verification of intent by broadcast receiver in Samsung Flow prior to version 4.9.17.6 allows local attackers to modify Samsung Flow configuration.

    Published: 7 May 2025
    5.5
    Medium

    CVE-2025-20971

    Last Modified: 16 Jul 2025

    Improper input validation in Samsung Flow prior to version 4.9.17.6 allows local attackers to access data within Samsung Flow.

    Published: 7 May 2025
    6.2
    Medium

    CVE-2025-20970

    Last Modified: 15 Apr 2026

    Improper access control in Bixby Vision prior to version 3.8.1 in Android 13, 3.8.3 in Android 14, 3.8.21 in Android 15 allows local attackers to access image files with Bixby Vision privilege.

    Published: 7 May 2025
    5.5
    Medium

    CVE-2025-20969

    Last Modified: 30 Jan 2026

    Improper input validation in Samsung Gallery prior to version 14.5.10.3 in Global Android 13, 14.5.09.3 in China Android 13, and 15.5.04.5 in Android 14 allows local attackers to access data within Samsung Gallery.

    Published: 7 May 2025
    7.2
    High

    CVE-2025-20968

    Last Modified: 30 Jan 2026

    Improper access control in Samsung Gallery prior to version 14.5.10.3 in Global Android 13, 14.5.09.3 in China Android 13, and 15.5.04.5 in Android 14 allows remote attackers to access data and perform internal operations within Samsung Gallery.

    Published: 7 May 2025
    5.1
    Medium

    CVE-2025-20967

    Last Modified: 30 Jan 2026

    Improper access control in Samsung Gallery prior to version 14.5.10.3 in Global Android 13, 14.5.09.3 in China Android 13, and 15.5.04.5 in Android 14 allows attackers to read and write arbitrary file with the privilege of Samsung Gallery.

    Published: 7 May 2025
    4.6
    Medium

    CVE-2025-20966

    Last Modified: 30 Jan 2026

    Improper access control in Samsung Gallery prior to version 14.5.10.3 in Global Android 13, 14.5.09.3 in China Android 13, and 15.5.04.5 in Android 14 allows physical attackers to access data across multiple user profiles.

    Published: 7 May 2025
    6.2
    Medium

    CVE-2025-20965

    Last Modified: 18 Jul 2025

    Improper handling of insufficient permission in Bixby wakeup prior to version 2.3.74.8 allows local attackers to access sensitive data.

    Published: 7 May 2025
    6.6
    Medium

    CVE-2025-20964

    Last Modified: 21 May 2025

    Out-of-bounds write in parsing media files in libsavsvc.so prior to SMR May-2025 Release 1 allows local attackers to write out-of-bounds memory.

    Published: 7 May 2025
    6.6
    Medium

    CVE-2025-20963

    Last Modified: 21 May 2025

    Out-of-bounds write in memory initialization in libsavsvc.so prior to SMR May-2025 Release 1 allows local attackers to write out-of-bounds memory.

    Published: 7 May 2025
    4
    Medium

    CVE-2025-20962

    Last Modified: 21 May 2025

    Improper handling of insufficient permission in SpenGesture service prior to SMR May-2025 Release 1 allows local attackers to track the S Pen position.

    Published: 7 May 2025
    5.5
    Medium

    CVE-2025-20961

    Last Modified: 21 May 2025

    Improper handling of insufficient permission or privileges in sepunion service prior to SMR May-2025 Release 1 allows local privileged attackers to access files with system privilege.

    Published: 7 May 2025
    4
    Medium

    CVE-2025-20960

    Last Modified: 21 May 2025

    Improper handling of insufficient permission in CocktailBarService prior to SMR May-2025 Release 1 allows local attackers to use the privileged api.

    Published: 7 May 2025
    5.1
    Medium

    CVE-2025-20959

    Last Modified: 21 May 2025

    Use of implicit intent for sensitive communication in Wi-Fi P2P service prior to SMR May-2025 Release 1 allows local attackers to access sensitive information.

    Published: 7 May 2025
    4.4
    Medium

    CVE-2025-20958

    Last Modified: 21 May 2025

    Improper verification of intent by broadcast receiver in UnifiedWFC prior to SMR May-2025 Release 1 allows local attackers to manipulate VoWiFi related behaviors.

    Published: 7 May 2025
    7.3
    High

    CVE-2025-20957

    Last Modified: 21 May 2025

    Improper access control in SmartManagerCN prior to SMR May-2025 Release 1 allows local attackers to launch arbitrary activities with SmartManagerCN privilege.

    Published: 7 May 2025
    4.3
    Medium

    CVE-2025-20956

    Last Modified: 15 Jan 2026

    Improper export of android application components in Settings in Galaxy Watch prior to SMR May-2025 Release 1 allows physical attackers to access developer settings.

    Published: 7 May 2025