CVE Feed

    Dashboard / CVE

    7.1
    High

    CVE-2025-30558

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in EnzoCostantini55 ANAC XML Render anac-xml-render allows Stored XSS.This issue affects ANAC XML Render: from n/a through <= 1.5.7.

    Published: 24 Mar 2025
    4.3
    Medium

    CVE-2025-30557

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in odihost Easy 301 Redirects odihost-easy-redirect-301 allows Cross Site Request Forgery.This issue affects Easy 301 Redirects: from n/a through <= 1.33.

    Published: 24 Mar 2025
    4.3
    Medium

    CVE-2025-30556

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in flyaga Fix Rss Feeds fix-rss-feed allows Cross Site Request Forgery.This issue affects Fix Rss Feeds: from n/a through <= 3.1.

    Published: 24 Mar 2025
    7.1
    High

    CVE-2025-30555

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in iiiryan WordPres 同步微博 wp2wb allows Stored XSS.This issue affects WordPres 同步微博: from n/a through <= 1.1.0.

    Published: 24 Mar 2025
    6.5
    Medium

    CVE-2025-30553

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Z.com byGMO GMO Font Agent gmo-font-agent allows Stored XSS.This issue affects GMO Font Agent: from n/a through <= 1.6.

    Published: 24 Mar 2025
    7.1
    High

    CVE-2025-30552

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Donald Gilbert WordPress Admin Bar Improved wordpress-admin-bar-improved allows Stored XSS.This issue affects WordPress Admin Bar Improved: from n/a through <= 3.3.5.

    Published: 24 Mar 2025
    6.5
    Medium

    CVE-2025-30551

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in smartredfox Pretty file links pretty-file-links allows Stored XSS.This issue affects Pretty file links: from n/a through <= 0.9.

    Published: 24 Mar 2025
    7.1
    High

    CVE-2025-30550

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in WPShop.ru CallPhone'r callphoner allows Stored XSS.This issue affects CallPhone'r: from n/a through <= 1.1.1.

    Published: 24 Mar 2025
    4.3
    Medium

    CVE-2025-30549

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Yummly Yummly Rich Recipes yummly-rich-recipes allows Cross Site Request Forgery.This issue affects Yummly Rich Recipes: from n/a through <= 4.2.

    Published: 24 Mar 2025
    4.3
    Medium

    CVE-2025-30546

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in boroV Cackle cackle allows Cross Site Request Forgery.This issue affects Cackle: from n/a through <= 4.33.

    Published: 24 Mar 2025
    5.9
    Medium

    CVE-2025-30545

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in pixeline issuuPress issuupress allows Stored XSS.This issue affects issuuPress: from n/a through <= 1.3.2.

    Published: 24 Mar 2025
    4.3
    Medium

    CVE-2025-30543

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in swayam.tejwani Menu Duplicator copy-menu allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Menu Duplicator: from n/a through <= 1.0.

    Published: 24 Mar 2025
    4.3
    Medium

    CVE-2025-30542

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in wpsolutions SoundCloud Ultimate soundcloud-ultimate allows Cross Site Request Forgery.This issue affects SoundCloud Ultimate: from n/a through <= 1.5.

    Published: 24 Mar 2025
    4.3
    Medium

    CVE-2025-30541

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in OTWthemes Info Boxes Shortcode and Widget info-boxes-shortcode-and-widget allows Cross Site Request Forgery.This issue affects Info Boxes Shortcode and Widget: from n/a through <= 1.15.

    Published: 24 Mar 2025
    5.9
    Medium

    CVE-2025-30540

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in avaibook AvaiBook avaibook allows Stored XSS.This issue affects AvaiBook: from n/a through <= 1.2.

    Published: 24 Mar 2025
    5.9
    Medium

    CVE-2025-30539

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Benedikt Mo BMo Expo bmo-expo allows Stored XSS.This issue affects BMo Expo: from n/a through <= 1.0.15.

    Published: 24 Mar 2025
    4.3
    Medium

    CVE-2025-30538

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in ChrisHurst Simple Optimizer simple-optimizer allows Cross Site Request Forgery.This issue affects Simple Optimizer: from n/a through <= 1.2.7.

    Published: 24 Mar 2025
    5.9
    Medium

    CVE-2025-30537

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Cristian Sarov Upload Quota per User upload-quota-per-user allows Stored XSS.This issue affects Upload Quota per User: from n/a through <= 1.3.

    Published: 24 Mar 2025
    5.9
    Medium

    CVE-2025-30536

    Last Modified: 28 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in zeitwesentech Beautiful Link Preview beautiful-link-preview allows Stored XSS.This issue affects Beautiful Link Preview: from n/a through <= 1.5.0.

    Published: 24 Mar 2025
    4.3
    Medium

    CVE-2025-30535

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in muro External image replace external-image-replace allows Cross Site Request Forgery.This issue affects External image replace: from n/a through <= 1.0.8.

    Published: 24 Mar 2025
    4.3
    Medium

    CVE-2025-30534

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in captcha.soft Image Captcha image-captcha allows Cross Site Request Forgery.This issue affects Image Captcha: from n/a through <= 1.2.

    Published: 24 Mar 2025
    5.9
    Medium

    CVE-2025-30533

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in gopiplus Message ticker message-ticker allows Stored XSS.This issue affects Message ticker: from n/a through <= 9.3.

    Published: 24 Mar 2025
    5.9
    Medium

    CVE-2025-30532

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in MorganF Weather Layer weather-layer allows Stored XSS.This issue affects Weather Layer: from n/a through <= 4.2.1.

    Published: 24 Mar 2025
    4.3
    Medium

    CVE-2025-30531

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in GBS Developer WP Ride Booking wp-ride-booking allows Cross Site Request Forgery.This issue affects WP Ride Booking: from n/a through <= 2.4.

    Published: 24 Mar 2025
    5.9
    Medium

    CVE-2025-30530

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Atikul AI Preloader ai-preloader allows Stored XSS.This issue affects AI Preloader: from n/a through <= 1.0.2.

    Published: 24 Mar 2025
    4.3
    Medium

    CVE-2025-30529

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Sébastien Dumont Auto Load Next Post auto-load-next-post allows Cross Site Request Forgery.This issue affects Auto Load Next Post: from n/a through <= 1.5.14.

    Published: 24 Mar 2025
    9.3
    Critical

    CVE-2025-30528

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in wpshopee Awesome Logos awesome-logos allows SQL Injection.This issue affects Awesome Logos: from n/a through <= 1.2.

    Published: 24 Mar 2025
    5.9
    Medium

    CVE-2025-30527

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in codetoolbox My Bootstrap Menu my-bootstrap-menu allows Stored XSS.This issue affects My Bootstrap Menu: from n/a through <= 1.2.1.

    Published: 24 Mar 2025
    4.3
    Medium

    CVE-2025-30526

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in lucksy Typekit plugin for WordPress typekit allows Cross Site Request Forgery.This issue affects Typekit plugin for WordPress: from n/a through <= 1.2.3.

    Published: 24 Mar 2025
    7.6
    High

    CVE-2025-30525

    Last Modified: 23 Apr 2026

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ProfitShare.ro WP Profitshare wp-profitshare allows SQL Injection.This issue affects WP Profitshare: from n/a through <= 1.4.9.

    Published: 24 Mar 2025
    7.6
    High

    CVE-2025-30523

    Last Modified: 23 Apr 2026

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Marcel-NL Super Simple Subscriptions super-simple-subscriptions allows SQL Injection.This issue affects Super Simple Subscriptions: from n/a through <= 1.1.0.

    Published: 24 Mar 2025
    7.1
    High

    CVE-2025-30522

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Damian Orzol Contact Form 7 Material Design cf7-material-design allows Stored XSS.This issue affects Contact Form 7 Material Design: from n/a through <= 1.0.0.

    Published: 24 Mar 2025
    4.3
    Medium

    CVE-2025-30521

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in giangmd93 GP Back To Top gp-back-to-top allows Cross Site Request Forgery.This issue affects GP Back To Top: from n/a through <= 3.0.

    Published: 24 Mar 2025
    7.7
    High

    CVE-2024-8774

    Last Modified: 15 Apr 2026

    The SIMPLE.ERP client stores superuser password in a recoverable format, allowing any authenticated SIMPLE.ERP user to escalate privileges to a database administrator. This issue affect SIMPLE.ERP from 6.20 through 6.30. Only the 6.30 version received a patch [email protected], which removed the vulnerability. Versions 6.20 and 6.25 remain unpatched.

    Published: 24 Mar 2025
    8.3
    High

    CVE-2024-8773

    Last Modified: 15 Apr 2026

    SIMPLE.ERP client is vulnerable to MS SQL protocol downgrade request from a server side, what could lead to an unencrypted communication vulnerable to data interception and modification. This issue affect SIMPLE.ERP from 6.20 to 6.30. Only the 6.30 version received a patch [email protected], which make it possible for an administrator to enforce encrypted communication. Versions 6.20 and 6.25 remain unpatched.

    Published: 24 Mar 2025
    —
    Unknown

    CVE-2025-2718

    Last Modified: 5 Jul 2025

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

    Published: 24 Mar 2025
    7.8
    High

    CVE-2025-0835

    Last Modified: 15 Apr 2026

    Software installed and run as a non-privileged user may conduct improper GPU system calls to corrupt kernel heap memory.

    Published: 24 Mar 2025
    7.8
    High

    CVE-2025-0478

    Last Modified: 15 Apr 2026

    Software installed and run as a non-privileged user may conduct improper GPU system calls to issue reads and writes to arbitrary physical memory pages. Under certain circumstances this exploit could be used to corrupt data pages not allocated by the GPU driver but memory pages in use by the kernel and drivers running on the platform, altering their behaviour.

    Published: 24 Mar 2025
    5.3
    Medium

    CVE-2025-2702

    Last Modified: 15 Apr 2026

    A vulnerability, which was classified as critical, has been found in Softwin WMX3 3.1. This issue affects the function ImageAdd of the file /ImageAdd.ashx. The manipulation of the argument File leads to unrestricted upload. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 24 Mar 2025
    5.3
    Medium

    CVE-2025-2701

    Last Modified: 17 Oct 2025

    A vulnerability classified as critical was found in AMTT Hotel Broadband Operation System 1.0. This vulnerability affects the function popen of the file /manager/network/port_setup.php. The manipulation of the argument SwitchVersion/SwitchWrite/SwitchIP/SwitchIndex/SwitchState leads to os command injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 24 Mar 2025
    5.1
    Medium

    CVE-2025-2700

    Last Modified: 1 Apr 2025

    A vulnerability classified as problematic has been found in michelson Dante Editor up to 0.4.4. This affects an unknown part of the component Insert Link Handler. The manipulation leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 24 Mar 2025
    5.1
    Medium

    CVE-2025-2699

    Last Modified: 22 Jul 2025

    A vulnerability was found in GetmeUK ContentTools up to 1.6.16. It has been rated as problematic. Affected by this issue is some unknown functionality of the component Image Handler. The manipulation of the argument onload leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 24 Mar 2025
    5.3
    Medium

    CVE-2025-2690

    Last Modified: 24 Mar 2025

    A vulnerability, which was classified as critical, was found in yiisoft Yii2 up to 2.0.39. This affects the function Generate of the file phpunit\src\Framework\MockObject\MockClass.php. The manipulation leads to deserialization. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

    Published: 24 Mar 2025
    5.3
    Medium

    CVE-2025-2689

    Last Modified: 24 Mar 2025

    A vulnerability, which was classified as critical, has been found in yiisoft Yii2 up to 2.0.45. Affected by this issue is the function getIterator of the file symfony\finder\Iterator\SortableIterator.php. The manipulation leads to deserialization. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

    Published: 24 Mar 2025
    5.3
    Medium

    CVE-2025-2688

    Last Modified: 2 Jul 2025

    A vulnerability classified as problematic was found in TOTOLINK A3000RU up to 5.9c.5185. Affected by this vulnerability is an unknown functionality of the file /cgi-bin/ExportSyslog.sh of the component Syslog Configuration File Handler. The manipulation leads to improper access controls. The attack needs to be done within the local network. The exploit has been disclosed to the public and may be used.

    Published: 24 Mar 2025
    5.3
    Medium

    CVE-2025-2687

    Last Modified: 27 Mar 2025

    A vulnerability classified as critical has been found in PHPGurukul eLearning System 1.0. Affected is an unknown function of the file /user/index.php of the component Image Handler. The manipulation leads to unrestricted upload. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

    Published: 24 Mar 2025
    3.5
    Low

    CVE-2025-1203

    Last Modified: 8 Apr 2025

    The Slider, Gallery, and Carousel by MetaSlider WordPress plugin before 3.95.0 does not sanitise and escape some of its settings, which could allow high privilege users such as editor to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

    Published: 24 Mar 2025
    3.5
    Low

    CVE-2025-1062

    Last Modified: 8 Apr 2025

    The Slider, Gallery, and Carousel by MetaSlider WordPress plugin before 3.95.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

    Published: 24 Mar 2025
    6.9
    Medium

    CVE-2025-2686

    Last Modified: 15 Apr 2026

    A vulnerability has been found in mingyuefusu 明月复苏 tushuguanlixitong 图书管理系统 up to d4836f6b49cd0ac79a4021b15ce99ff7229d4694 and classified as critical. Affected by this vulnerability is the function doFilter of the file /admin/ of the component Backend. The manipulation of the argument Request leads to improper access controls. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

    Published: 24 Mar 2025
    6.9
    Medium

    CVE-2025-2684

    Last Modified: 24 Mar 2025

    A vulnerability, which was classified as critical, has been found in PHPGurukul Bank Locker Management System 1.0. This issue affects some unknown processing of the file /search-report-details.php. The manipulation of the argument searchinput leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

    Published: 24 Mar 2025