CVE Feed

    Dashboard / CVE

    8.3
    High

    CVE-2025-3776

    Last Modified: 21 Apr 2026

    The Verification SMS with TargetSMS plugin for WordPress is vulnerable to limited Remote Code Execution in all versions up to, and including, 1.5 via the 'targetvr_ajax_handler' function. This is due to a lack of validation on the type of function that can be called. This makes it possible for unauthenticated attackers to execute any callable function on the site, such as phpinfo().

    Published: 24 Apr 2025
    4.2
    Medium

    CVE-2025-3793

    Last Modified: 20 Apr 2026

    The Buddypress Force Password Change plugin for WordPress is vulnerable to authenticated account takeover due to the plugin not properly validating a user's identity prior to updating their password through the 'bp_force_password_ajax' function in all versions up to, and including, 0.1. This makes it possible for authenticated attackers, with subscriber-level access and above and under certain prerequisites, to change arbitrary user's passwords, including administrators, and leverage that to gain access to their accounts.

    Published: 24 Apr 2025
    6.5
    Medium

    CVE-2025-3280

    Last Modified: 20 Apr 2026

    The ELEX WooCommerce Advanced Bulk Edit Products, Prices & Attributes plugin for WordPress is vulnerable to SQL Injection via the 'attribute_value_filter' parameter in all versions up to, and including, 1.4.9 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with Subscriber-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

    Published: 24 Apr 2025
    5.3
    Medium

    CVE-2024-13307

    Last Modified: 15 Apr 2026

    The Reales WP - Real Estate WordPress Theme theme for WordPress is vulnerable to unauthorized modification and loss of data due to a missing capability check on the 'reales_delete_file', 'reales_delete_file_plans', 'reales_add_to_favourites', and 'reales_remove_from_favourites' functions in all versions up to, and including, 2.1.2. This makes it possible for unauthenticated attackers to delete arbitrary attachments, and add or remove favorite property listings for any user.

    Published: 24 Apr 2025
    7.2
    High

    CVE-2025-3300

    Last Modified: 20 Apr 2026

    The WPMasterToolKit (WPMTK) – All in one plugin plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.5.2. This makes it possible for authenticated attackers, with Administrator-level access and above, to read and modify the contents of arbitrary files on the server, which can contain sensitive information.

    Published: 24 Apr 2025
    6.4
    Medium

    CVE-2025-3832

    Last Modified: 20 Apr 2026

    The FuseDesk plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘successredirect’ parameter in all versions up to, and including, 6.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 24 Apr 2025
    6.4
    Medium

    CVE-2025-2579

    Last Modified: 21 Apr 2026

    The Lottie Player plugin for WordPress is vulnerable to Stored Cross-Site Scripting via File uploads in all versions up to, and including, 1.1.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses the uploaded file.

    Published: 24 Apr 2025
    8.8
    High

    CVE-2025-3607

    Last Modified: 20 Apr 2026

    The Frontend Login and Registration Blocks plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 1.0.8. This is due to the plugin not properly validating a user's identity prior to updating a password. This makes it possible for authenticated attackers, with Subscriber-level access and above, to change arbitrary user's passwords, including administrators, and leverage that to gain access to their account.

    Published: 24 Apr 2025
    9.8
    Critical

    CVE-2025-3604

    Last Modified: 22 Apr 2026

    The Flynax Bridge plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 2.2.0. This is due to the plugin not properly validating a user's identity prior to updating their details like email. This makes it possible for unauthenticated attackers to change arbitrary user's email addresses, including administrators, and leverage that to reset the user's password and gain access to their account.

    Published: 24 Apr 2025
    6.4
    Medium

    CVE-2025-2543

    Last Modified: 22 Apr 2026

    The Advanced Accordion Gutenberg Block plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 5.0.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses the SVG file.

    Published: 24 Apr 2025
    4.3
    Medium

    CVE-2025-1284

    Last Modified: 21 Apr 2026

    The Woocommerce Automatic Order Printing | ( Formerly WooCommerce Google Cloud Print) plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 4.1 via the xc_woo_printer_preview AJAX action due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with Subscriber-level access and above, to view other user's invoices and orders which can contain sensitive information.

    Published: 24 Apr 2025
    8.8
    High

    CVE-2025-3101

    Last Modified: 22 Apr 2026

    The Configurator Theme Core plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.4.7. This is due to the plugin not properly validating user meta fields prior to updating them in the database. This makes it possible for authenticated attackers, with Subscriber-level access and above, to change escalate their privileges to Administrator.

    Published: 24 Apr 2025
    8.8
    High

    CVE-2025-3058

    Last Modified: 22 Apr 2026

    The Xelion Webchat plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on the xwc_save_settings() function in all versions up to, and including, 9.1.0. This makes it possible for authenticated attackers, with Subscriber-level access and above, to update arbitrary options on the WordPress site. This can be leveraged to update the default role for registration to administrator and enable user registration for attackers to gain administrative user access to a vulnerable site.

    Published: 24 Apr 2025
    9.1
    Critical

    CVE-2025-3065

    Last Modified: 22 Apr 2026

    The Database Toolset plugin is vulnerable to arbitrary file deletion due to insufficient file path validation in a function in all versions up to, and including, 1.8.4. This makes it possible for unauthenticated attackers to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such as wp-config.php).

    Published: 24 Apr 2025
    6.5
    Medium

    CVE-2025-0639

    Last Modified: 8 Aug 2025

    An issue has been discovered affecting service availability via issue preview in GitLab CE/EE affecting all versions from 16.7 before 17.9.7, 17.10 before 17.10.5, and 17.11 before 17.11.1.

    Published: 24 Apr 2025
    7.7
    High

    CVE-2025-1908

    Last Modified: 8 Aug 2025

    An issue has been discovered in GitLab EE/CE that could allow an attacker to track users' browsing activities, potentially leading to full account take-over, affecting all versions from 16.6 before 17.9.7, 17.10 before 17.10.5, and 17.11 before 17.11.1.

    Published: 24 Apr 2025
    8.8
    High

    CVE-2025-3761

    Last Modified: 22 Apr 2026

    The My Tickets – Accessible Event Ticketing plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.0.16. This is due to the mt_save_profile() function not appropriately restricting access to unauthorized users to update roles. This makes it possible for authenticated attackers, with Subscriber-level access and above, to update their role to that of an administrator.

    Published: 24 Apr 2025
    3.1
    Low

    CVE-2025-41423

    Last Modified: 29 Sept 2025

    Mattermost versions 10.4.x <= 10.4.2, 10.5.x <= 10.5.0, 9.11.x <= 9.11.10 fail to properly validate permissions for the API endpoint /plugins/playbooks/api/v0/signal/keywords/ignore-thread, allowing any user or attacker to delete posts containing actions created by the Playbooks bot, even without channel access or appropriate permissions.

    Published: 24 Apr 2025
    6.5
    Medium

    CVE-2025-35965

    Last Modified: 29 Sept 2025

    Mattermost versions 10.4.x <= 10.4.2, 10.5.x <= 10.5.0, 9.11.x <= 9.11.10 fail to validate the uniqueness and quantity of task actions within the UpdateRunTaskActions GraphQL operation, which allows an attacker to create task items containing an excessive number of actions triggered by specific posts, overloading the server and leading to a denial-of-service (DoS) condition.

    Published: 24 Apr 2025
    6.5
    Medium

    CVE-2025-41395

    Last Modified: 1 Oct 2025

    Mattermost versions 10.4.x <= 10.4.2, 10.5.x <= 10.5.0, 9.11.x <= 9.11.10 fail to properly validate the props used by the RetrospectivePost custom post type in the Playbooks plugin, which allows an attacker to create a specially crafted post with maliciously crafted props and cause a denial of service (DoS) of the web app for all users.

    Published: 24 Apr 2025
    6.8
    Medium

    CVE-2025-32730

    Last Modified: 15 Apr 2026

    Use of hard-coded cryptographic key vulnerability in i-PRO Configuration Tool affects the network system for i-PRO Co., Ltd. surveillance cameras and recorders. This vulnerability allows a local authenticated attacker to use the authentication information from the last connected surveillance cameras and recorders.

    Published: 24 Apr 2025
    8.6
    High

    CVE-2025-2558

    Last Modified: 23 Jun 2025

    The-wound WordPress theme through 0.0.1 does not validate some parameters before using them to generate paths passed to include function/s, allowing unauthenticated users to perform LFI attacks and download arbitrary file from the server

    Published: 24 Apr 2025
    4.8
    Medium

    CVE-2025-1453

    Last Modified: 7 May 2025

    The Category Posts Widget WordPress plugin before 4.9.20 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

    Published: 24 Apr 2025
    4.3
    Medium

    CVE-2024-12244

    Last Modified: 8 Aug 2025

    An issue has been discovered in access controls could allow users to view certain restricted project information even when related features are disabled in GitLab EE, affecting all versions from 17.7 prior to 17.9.7, 17.10 prior to 17.10.5, and 17.11 prior to 17.11.1.

    Published: 24 Apr 2025
    4.4
    Medium

    CVE-2025-3435

    Last Modified: 21 Apr 2026

    The Mang Board WP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the board_header and board_footer parameters in all versions up to, and including, 1.8.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.

    Published: 24 Apr 2025
    8.6
    High

    CVE-2025-1976

    Last Modified: 26 Feb 2026

    Brocade Fabric OS versions starting with 9.1.0 have root access removed, however, a local user with admin privilege can potentially execute arbitrary code with full root privileges on Fabric OS versions 9.1.0 through 9.1.1d6.

    Published: 24 Apr 2025
    6.8
    Medium

    CVE-2025-46421

    Last Modified: 30 Jun 2026

    A flaw was found in libsoup. When libsoup clients encounter an HTTP redirect, they mistakenly send the HTTP Authorization header to the new host that the redirection points to. This allows the new host to impersonate the user to the original host that issued the redirect.

    Published: 24 Apr 2025
    6.5
    Medium

    CVE-2025-46420

    Last Modified: 30 Jun 2026

    A flaw was found in libsoup. It is vulnerable to memory leaks in the soup_header_parse_quality_list() function when parsing a quality list that contains elements with all zeroes.

    Published: 24 Apr 2025
    8
    High

    CVE-2025-25777

    Last Modified: 28 May 2025

    Insecure Direct Object Reference (IDOR) in Codeastro Bus Ticket Booking System v1.0 allows unauthorized access to user profiles. By manipulating the user ID in the URL, an attacker can access another user's profile without proper authentication or authorization checks.

    Published: 24 Apr 2025
    6.5
    Medium

    CVE-2025-29529

    Last Modified: 15 Apr 2026

    ITC Systems Multiplan/Matrix OneCard platform v3.7.4.1002 was discovered to contain a SQL injection vulnerability via the component Forgotpassword.aspx.

    Published: 24 Apr 2025
    4.8
    Medium

    CVE-2025-29568

    Last Modified: 14 May 2025

    A vulnerability has been discovered in the code-projects Online Class and Exam Scheduling System 1.0. The issue affects some unknown features in the file /Scheduling/pages/class_sched.php. Manipulating the class parameter can lead to cross-site scripting (XSS).

    Published: 24 Apr 2025
    6.5
    Medium

    CVE-2025-44134

    Last Modified: 14 May 2025

    A vulnerability was found in Code-Projects Online Class and Exam Scheduling System 1.0 in the file /Scheduling/pages/class_save.php. Manipulation of parameter class will lead to SQL injection attacks.

    Published: 24 Apr 2025
    6.5
    Medium

    CVE-2025-44135

    Last Modified: 14 May 2025

    A vulnerability was found in code-projects Online Class and Exam Scheduling System 1.0 in /Scheduling/pages/profile_update.php. Manipulating the parameter username will cause SQL injection attacks.

    Published: 24 Apr 2025
    6.8
    Medium

    CVE-2025-46417

    Last Modified: 1 Oct 2025

    The unsafe globals in Picklescan before 0.0.25 do not include ssl. Consequently, ssl.get_server_certificate can exfiltrate data via DNS after deserialization.

    Published: 24 Apr 2025
    5.9
    Medium

    CVE-2025-46419

    Last Modified: 15 Apr 2026

    Westermo WeOS 5 through 5.23.0 allows a reboot via a malformed ESP packet.

    Published: 24 Apr 2025
    3.7
    Low

    CVE-2025-25046

    Last Modified: 28 Aug 2025

    IBM InfoSphere Information Server 11.7 DataStage Flow Designer  transmits sensitive information via URL or query parameters that could be exposed to an unauthorized actor using man in the middle techniques.

    Published: 23 Apr 2025
    4.3
    Medium

    CVE-2025-25045

    Last Modified: 28 Aug 2025

    IBM InfoSphere Information 11.7 Server authenticated user to obtain sensitive information when a detailed technical error message is returned in a request. This information could be used in further attacks against the system.

    Published: 23 Apr 2025
    6.3
    Medium

    CVE-2024-22351

    Last Modified: 1 Sept 2025

    IBM InfoSphere Information 11.7 Server does not invalidate session after logout which could allow an authenticated user to impersonate another user on the system.

    Published: 23 Apr 2025
    5.5
    Medium

    CVE-2025-46400

    Last Modified: 30 Jun 2026

    In xfig diagramming tool, a segmentation fault while running fig2dev allows an attacker to availability via local input manipulation via read_arcobject function.

    Published: 23 Apr 2025
    5.5
    Medium

    CVE-2025-46399

    Last Modified: 30 Jun 2026

    A flaw was found in fig2dev. This vulnerability allows availability via local input manipulation via genge_itp_spline function.

    Published: 23 Apr 2025
    5.5
    Medium

    CVE-2025-46398

    Last Modified: 30 Jun 2026

    In xfig diagramming tool, a stack-overflow while running fig2dev allows memory corruption via local input manipulation via read_objects function.

    Published: 23 Apr 2025
    7.8
    High

    CVE-2025-46397

    Last Modified: 30 Jun 2026

    A flaw was found in xfig. This vulnerability allows possible code execution via local input manipulation via bezier_spline function.

    Published: 23 Apr 2025
    7.5
    High

    CVE-2025-32818

    Last Modified: 15 Apr 2026

    A Null Pointer Dereference vulnerability in the SonicOS SSLVPN Virtual office interface allows a remote, unauthenticated attacker to crash the firewall, potentially leading to a Denial-of-Service (DoS) condition.

    Published: 23 Apr 2025
    4.3
    Medium

    CVE-2025-3907

    Last Modified: 2 Sept 2025

    Cross-Site Request Forgery (CSRF) vulnerability in Drupal Search API Solr allows Cross Site Request Forgery.This issue affects Search API Solr: from 0.0.0 before 4.3.9.

    Published: 23 Apr 2025
    7.3
    High

    CVE-2025-3904

    Last Modified: 2 Sept 2025

    Vulnerability in Drupal Sportsleague.This issue affects Sportsleague: *.*.

    Published: 23 Apr 2025
    7.3
    High

    CVE-2025-3903

    Last Modified: 2 Sept 2025

    Vulnerability in Drupal UEditor - 百度编辑器.This issue affects UEditor - 百度编辑器: *.*.

    Published: 23 Apr 2025
    6.1
    Medium

    CVE-2025-3902

    Last Modified: 17 Jun 2025

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Block Class allows Cross-Site Scripting (XSS).This issue affects Block Class: from 4.0.0 before 4.0.1.

    Published: 23 Apr 2025
    6.1
    Medium

    CVE-2025-3901

    Last Modified: 18 Jun 2025

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Bootstrap Site Alert allows Cross-Site Scripting (XSS).This issue affects Bootstrap Site Alert: from 0.0.0 before 1.13.0, from 3.0.0 before 3.0.4.

    Published: 23 Apr 2025
    6.1
    Medium

    CVE-2025-3900

    Last Modified: 20 Jun 2025

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Colorbox allows Cross-Site Scripting (XSS).This issue affects Colorbox: from 0.0.0 before 2.1.3.

    Published: 23 Apr 2025
    7.2
    High

    CVE-2025-2773

    Last Modified: 21 Aug 2025

    BEC Technologies Multiple Routers sys ping Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of BEC Technologies Multiple Routers. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within the management interface, which listens on TCP port 22 by default. The issue results from the lack of proper validation of a user-supplied string before using it to execute a system call. An attacker can leverage this vulnerability to execute code in the context of the device. Was ZDI-CAN-25903.

    Published: 23 Apr 2025