CVE Feed

    Dashboard / CVE

    4.3
    Medium

    CVE-2025-39472

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in wpweb WooCommerce Social Login woo-social-login allows Cross Site Request Forgery.This issue affects WooCommerce Social Login: from n/a through < 2.8.3.

    Published: 16 Apr 2025
    6.5
    Medium

    CVE-2025-22872

    Last Modified: 15 Apr 2026

    The tokenizer incorrectly interprets tags with unquoted attribute values that end with a solidus character (/) as self-closing. When directly using Tokenizer, this can result in such tags incorrectly being marked as self-closing, and when using the Parse functions, this can result in content following such tags as being placed in the wrong scope during DOM construction, but only when tags are in foreign content (e.g. <math>, <svg>, etc contexts).

    Published: 16 Apr 2025
    5.9
    Medium

    CVE-2025-3739

    Last Modified: 18 Jun 2025

    Vulnerability in Drupal Drupal 8 Google Optimize Hide Page.This issue affects Drupal 8 Google Optimize Hide Page: *.*.

    Published: 16 Apr 2025
    5.9
    Medium

    CVE-2025-3738

    Last Modified: 2 Sept 2025

    Vulnerability in Drupal Google Optimize.This issue affects Google Optimize: *.*.

    Published: 16 Apr 2025
    5.9
    Medium

    CVE-2025-3737

    Last Modified: 2 Sept 2025

    Vulnerability in Drupal Google Maps: Store Locator.This issue affects Google Maps: Store Locator: *.*.

    Published: 16 Apr 2025
    5.9
    Medium

    CVE-2025-3736

    Last Modified: 2 Sept 2025

    Vulnerability in Drupal Simple GTM.This issue affects Simple GTM: *.*.

    Published: 16 Apr 2025
    5.9
    Medium

    CVE-2025-3735

    Last Modified: 2 Sept 2025

    Vulnerability in Drupal Panelizer (obsolete).This issue affects Panelizer (obsolete): *.*.

    Published: 16 Apr 2025
    5.9
    Medium

    CVE-2025-3734

    Last Modified: 2 Sept 2025

    Allocation of Resources Without Limits or Throttling vulnerability in Drupal Stage File Proxy allows Flooding.This issue affects Stage File Proxy: from 0.0.0 before 3.1.5.

    Published: 16 Apr 2025
    6.5
    Medium

    CVE-2025-3733

    Last Modified: 2 Sept 2025

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal baguetteBox.Js allows Cross-Site Scripting (XSS).This issue affects baguetteBox.Js: from 0.0.0 before 2.0.4, from 3.0.0 before 3.0.1.

    Published: 16 Apr 2025
    5.9
    Medium

    CVE-2024-22314

    Last Modified: 28 Aug 2025

    IBM Storage Defender - Resiliency Service 2.0.0 through 2.0.12 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information.

    Published: 16 Apr 2025
    8.8
    High

    CVE-2025-20236

    Last Modified: 26 Feb 2026

    A vulnerability in the custom URL parser of Cisco Webex App could allow an unauthenticated, remote attacker to persuade a user to download arbitrary files, which could allow the attacker to execute arbitrary commands on the host of the targeted user. This vulnerability is due to insufficient input validation when Cisco Webex App processes a meeting invite link. An attacker could exploit this vulnerability by persuading a user to click a crafted meeting invite link and download arbitrary files. A successful exploit could allow the attacker to execute arbitrary commands with the privileges of the targeted user.

    Published: 16 Apr 2025
    4.3
    Medium

    CVE-2025-2564

    Last Modified: 29 Sept 2025

    Mattermost versions 10.5.x <= 10.5.1, 10.4.x <= 10.4.3, 9.11.x <= 9.11.9 fail to properly enforce the 'Allow users to view/update archived channels' System Console setting, which allows authenticated users to view members and member information of archived channels even when this setting is disabled.

    Published: 16 Apr 2025
    5.3
    Medium

    CVE-2025-20150

    Last Modified: 7 Aug 2025

    A vulnerability in Cisco Nexus Dashboard could allow an unauthenticated, remote attacker to enumerate LDAP user accounts. This vulnerability is due to the improper handling of LDAP authentication requests. An attacker could exploit this vulnerability by sending authentication requests to an affected system. A successful exploit could allow an attacker to determine which usernames are valid LDAP user accounts.

    Published: 16 Apr 2025
    6
    Medium

    CVE-2025-20178

    Last Modified: 26 Feb 2026

    A vulnerability in the web-based management interface of Cisco Secure Network Analytics could allow an authenticated, remote attacker with valid administrative credentials to execute arbitrary commands as root on the underlying operating system. This vulnerability is due to insufficient integrity checks within device backup files. An attacker with valid administrative credentials could exploit this vulnerability by crafting a malicious backup file and restoring it to an affected device. A successful exploit could allow the attacker to obtain shell access on the underlying operating system with the privileges of root.

    Published: 16 Apr 2025
    6.5
    Medium

    CVE-2024-56736

    Last Modified: 23 Apr 2025

    Server-Side Request Forgery (SSRF) vulnerability in Apache HertzBeat. This issue affects Apache HertzBeat (incubating): before 1.7.0. Users are recommended to upgrade to version 1.7.0, which fixes the issue.

    Published: 16 Apr 2025
    5.3
    Medium

    CVE-2025-3697

    Last Modified: 14 May 2025

    A vulnerability, which was classified as critical, has been found in SourceCodester Web-based Pharmacy Product Management System 1.0. This issue affects some unknown processing of the file /edit-product.php. The manipulation of the argument ID leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

    Published: 16 Apr 2025
    5.3
    Medium

    CVE-2025-3696

    Last Modified: 14 May 2025

    A vulnerability classified as critical was found in SourceCodester Web-based Pharmacy Product Management System 1.0. This vulnerability affects unknown code of the file /search/search_stock. php. The manipulation of the argument Name leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

    Published: 16 Apr 2025
    6.9
    Medium

    CVE-2025-3694

    Last Modified: 14 May 2025

    A vulnerability classified as critical has been found in SourceCodester Web-based Pharmacy Product Management System 1.0. This affects an unknown part of the component Login Handler. The manipulation of the argument login_email leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

    Published: 16 Apr 2025
    8.7
    High

    CVE-2025-3693

    Last Modified: 16 Jul 2025

    A vulnerability was found in Tenda W12 3.0.0.5. It has been rated as critical. Affected by this issue is the function cgiWifiRadioSet of the file /bin/httpd. The manipulation leads to stack-based buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

    Published: 16 Apr 2025
    4.8
    Medium

    CVE-2025-3692

    Last Modified: 29 Apr 2025

    A vulnerability was found in SourceCodester Online Eyewear Shop 1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /oews/classes/Master.php?f=save_product. The manipulation leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

    Published: 16 Apr 2025
    5.1
    Medium

    CVE-2025-3691

    Last Modified: 24 Apr 2025

    A vulnerability was found in mirweiye Seven Bears Library CMS 2023. It has been classified as problematic. Affected is an unknown function of the component Add Link Handler. The manipulation leads to server-side request forgery. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

    Published: 16 Apr 2025
    6.9
    Medium

    CVE-2025-3690

    Last Modified: 24 Apr 2025

    A vulnerability was found in PHPGurukul Men Salon Management System 1.0 and classified as critical. This issue affects some unknown processing of the file /admin/edit-services.php. The manipulation of the argument cost leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

    Published: 16 Apr 2025
    4.3
    Medium

    CVE-2025-39512

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Yuya Hoshino Bulk Term Editor bulk-term-editor allows Cross Site Request Forgery.This issue affects Bulk Term Editor: from n/a through <= 1.1.4.

    Published: 16 Apr 2025
    5.3
    Medium

    CVE-2025-39513

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in ActiveDEMAND Online Agency Marketing Automation ActiveDEMAND activedemand allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects ActiveDEMAND: from n/a through <= 0.2.46.

    Published: 16 Apr 2025
    6.5
    Medium

    CVE-2025-39514

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Asgaros Asgaros Forum asgaros-forum allows Stored XSS.This issue affects Asgaros Forum: from n/a through <= 3.2.1.

    Published: 16 Apr 2025
    6.5
    Medium

    CVE-2025-39515

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in tnomi Attendance Manager attendance-manager allows Stored XSS.This issue affects Attendance Manager: from n/a through <= 0.6.2.

    Published: 16 Apr 2025
    6.5
    Medium

    CVE-2025-39516

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Alan Petersen Author WIP Progress Bar author-work-in-progress-bar allows DOM-Based XSS.This issue affects Author WIP Progress Bar: from n/a through <= 1.0.

    Published: 16 Apr 2025
    4.3
    Medium

    CVE-2025-39517

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in WP Map Plugins Basic Interactive World Map basic-interactive-world-map allows Cross Site Request Forgery.This issue affects Basic Interactive World Map: from n/a through <= 2.7.

    Published: 16 Apr 2025
    7.6
    High

    CVE-2025-39518

    Last Modified: 23 Apr 2026

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in RedefiningTheWeb BMA Lite bma-lite-appointment-booking-and-scheduling allows SQL Injection.This issue affects BMA Lite: from n/a through <= 1.4.2.

    Published: 16 Apr 2025
    6.5
    Medium

    CVE-2025-39520

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Wham Checkout Files Upload for WooCommerce checkout-files-upload-woocommerce allows Stored XSS.This issue affects Checkout Files Upload for WooCommerce: from n/a through <= 2.2.0.

    Published: 16 Apr 2025
    5.4
    Medium

    CVE-2025-39522

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in Service2Client LLC Dynamic Post dynamic-post allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Dynamic Post: from n/a through <= 5.03.

    Published: 16 Apr 2025
    6.5
    Medium

    CVE-2025-39524

    Last Modified: 23 Apr 2026

    Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in bPlugins Html5 Audio Player html5-audio-player allows Stored XSS.This issue affects Html5 Audio Player: from n/a through <= 2.2.28.

    Published: 16 Apr 2025
    6.5
    Medium

    CVE-2025-39525

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpWax Logo Carousel Slider logo-carousel-slider allows Stored XSS.This issue affects Logo Carousel Slider: from n/a through <= 2.1.3.

    Published: 16 Apr 2025
    6.5
    Medium

    CVE-2025-39528

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Rescue Themes Rescue Shortcodes rescue-shortcodes allows Stored XSS.This issue affects Rescue Shortcodes: from n/a through <= 3.1.

    Published: 16 Apr 2025
    6.5
    Medium

    CVE-2025-39529

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Robin Cornett Scriptless Social Sharing scriptless-social-sharing allows Stored XSS.This issue affects Scriptless Social Sharing: from n/a through <= 3.3.0.

    Published: 16 Apr 2025
    7.1
    High

    CVE-2025-39530

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in dsky Site Search 360 site-search-360 allows Stored XSS.This issue affects Site Search 360: from n/a through <= 2.1.8.

    Published: 16 Apr 2025
    5.3
    Medium

    CVE-2025-39531

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in slazzercom Slazzer Background Changer slazzer-background-changer allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Slazzer Background Changer: from n/a through <= 3.14.

    Published: 16 Apr 2025
    6.6
    Medium

    CVE-2025-39538

    Last Modified: 23 Apr 2026

    Unrestricted Upload of File with Dangerous Type vulnerability in Mathieu Chartier WP-Advanced-Search wp-advanced-search allows Upload a Web Shell to a Web Server.This issue affects WP-Advanced-Search: from n/a through <= 3.3.9.4.

    Published: 16 Apr 2025
    6.5
    Medium

    CVE-2025-39540

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Rhys Wynne WP Flipclock wp-flipclock allows DOM-Based XSS.This issue affects WP Flipclock: from n/a through <= 1.9.1.

    Published: 16 Apr 2025
    6.5
    Medium

    CVE-2025-39543

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Royal Royal Elementor Addons royal-elementor-addons allows Stored XSS.This issue affects Royal Elementor Addons: from n/a through <= 1.3.977.

    Published: 16 Apr 2025
    7.4
    High

    CVE-2025-39544

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in sminozzi WP Tools wptools allows Path Traversal.This issue affects WP Tools: from n/a through <= 5.18.

    Published: 16 Apr 2025
    5.4
    Medium

    CVE-2025-39545

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in miniOrange WordPress REST API Authentication wp-rest-api-authentication allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WordPress REST API Authentication: from n/a through <= 3.6.3.

    Published: 16 Apr 2025
    4.3
    Medium

    CVE-2025-39546

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in quomodosoft ElementsReady Addons for Elementor element-ready-lite allows Cross Site Request Forgery.This issue affects ElementsReady Addons for Elementor: from n/a through <= 6.6.2.

    Published: 16 Apr 2025
    7.1
    High

    CVE-2025-39547

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Toast Plugins Internal Link Optimiser internal-link-finder allows Stored XSS.This issue affects Internal Link Optimiser: from n/a through <= 5.1.3.

    Published: 16 Apr 2025
    7.1
    High

    CVE-2025-39548

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in A WP Life Right Click Disable OR Ban right-click-disable-or-ban allows Stored XSS.This issue affects Right Click Disable OR Ban: from n/a through <= 1.1.17.

    Published: 16 Apr 2025
    6.5
    Medium

    CVE-2025-39549

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in whiletrue Most And Least Read Posts Widget most-and-least-read-posts-widget allows Stored XSS.This issue affects Most And Least Read Posts Widget: from n/a through <= 2.5.20.

    Published: 16 Apr 2025
    5.4
    Medium

    CVE-2025-39552

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in Dylan James Zephyr Project Manager zephyr-project-manager allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Zephyr Project Manager: from n/a through <= 3.3.200.

    Published: 16 Apr 2025
    6.5
    Medium

    CVE-2025-39555

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in andy_moyle Church Admin church-admin allows Stored XSS.This issue affects Church Admin: from n/a through <= 5.0.23.

    Published: 16 Apr 2025
    5.3
    Medium

    CVE-2025-39556

    Last Modified: 23 Apr 2026

    Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in mediavine Mediavine Control Panel mediavine-control-panel allows Retrieve Embedded Sensitive Data.This issue affects Mediavine Control Panel: from n/a through <= 2.10.6.

    Published: 16 Apr 2025
    9.1
    Critical

    CVE-2025-39557

    Last Modified: 23 Apr 2026

    Unrestricted Upload of File with Dangerous Type vulnerability in StellarWP Kadence WooCommerce Email Designer kadence-woocommerce-email-designer allows Upload a Web Shell to a Web Server.This issue affects Kadence WooCommerce Email Designer: from n/a through <= 1.5.14.

    Published: 16 Apr 2025