CVE Feed

    Dashboard / CVE

    6.4
    Medium

    CVE-2024-13757

    Last Modified: 8 Apr 2026

    The Master Slider – Responsive Touch Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's ms_layer shortcode in all versions up to, and including, 3.10.6 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 5 Mar 2025
    8.1
    High

    CVE-2024-13777

    Last Modified: 8 Apr 2026

    The ZoomSounds - WordPress Wave Audio Player with Playlist plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 6.91 via deserialization of untrusted input from the 'margs' parameter. This makes it possible for unauthenticated attackers to inject a PHP Object. No known POP chain is present in the vulnerable software, which means this vulnerability has no impact unless another plugin or theme containing a POP chain is installed on the site. If a POP chain is present via an additional plugin or theme installed on the target system, it may allow the attacker to perform actions like delete arbitrary files, retrieve sensitive data, or execute code depending on the POP chain present.

    Published: 5 Mar 2025
    6.1
    Medium

    CVE-2024-13779

    Last Modified: 15 Apr 2026

    The Hero Mega Menu - Responsive WordPress Menu Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'index' parameter in all versions up to, and including, 1.16.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

    Published: 5 Mar 2025
    6.5
    Medium

    CVE-2024-13780

    Last Modified: 15 Apr 2026

    The Hero Mega Menu - Responsive WordPress Menu Plugin plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the hmenu_delete_menu() function in all versions up to, and including, 1.16.5. This makes it possible for unauthenticated attackers to delete arbitrary directories on the server.

    Published: 5 Mar 2025
    8.1
    High

    CVE-2025-0956

    Last Modified: 15 Apr 2026

    The WooCommerce Recover Abandoned Cart plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 24.4.0 via deserialization of untrusted input from the 'raccookie_guest_email' cookie. This makes it possible for unauthenticated attackers to inject a PHP Object. No known POP chain is present in the vulnerable software, which means this vulnerability has no impact unless another plugin or theme containing a POP chain is installed on the site. If a POP chain is present via an additional plugin or theme installed on the target system, it may allow the attacker to perform actions like delete arbitrary files, retrieve sensitive data, or execute code depending on the POP chain present.

    Published: 5 Mar 2025
    5.6
    Medium

    CVE-2025-22493

    Last Modified: 15 Apr 2026

    Secure flag not set and SameSIte was set to Lax in the Foreseer Reporting Software (FRS). Absence of this secure flag could lead into the session cookie being transmitted over unencrypted HTTP connections. This security issue has been resolved in the latest version of FRS v1.5.100.

    Published: 5 Mar 2025
    6.4
    Medium

    CVE-2024-13866

    Last Modified: 15 Apr 2026

    The Simple Notification plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 1.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.

    Published: 5 Mar 2025
    6.4
    Medium

    CVE-2025-1008

    Last Modified: 21 Apr 2026

    The Recently Purchased Products For Woo plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘view’ parameter in all versions up to, and including, 1.1.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 5 Mar 2025
    6.1
    Medium

    CVE-2024-13827

    Last Modified: 15 Apr 2026

    The Razorpay Subscription Button Elementor Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg() and remove_query_arg() functions without appropriate escaping on the URL in all versions up to, and including, 1.0.3. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

    Published: 5 Mar 2025
    6.4
    Medium

    CVE-2024-13350

    Last Modified: 8 Apr 2026

    The SearchIQ – The Search Solution plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'siq_searchbox' shortcode in all versions up to, and including, 4.7 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 5 Mar 2025
    5.3
    Medium

    CVE-2024-8682

    Last Modified: 15 Apr 2026

    The JNews - WordPress Newspaper Magazine Blog AMP Theme theme for WordPress is vulnerable to unauthorized user registration in all versions up to, and including, 11.6.6. This is due to the plugin not properly validate if the user can register option is enabled prior to creating a user though the register_handler() function. This makes it possible for unauthenticated attackers to register as a user even when user registration is disabled.

    Published: 5 Mar 2025
    4.3
    Medium

    CVE-2025-0990

    Last Modified: 22 Apr 2026

    The I Am Gloria plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1.4. This is due to missing or incorrect nonce validation on the iamgloria23_gloria_settings_page function. This makes it possible for unauthenticated attackers to reset the tenant ID via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

    Published: 5 Mar 2025
    6.3
    Medium

    CVE-2025-1435

    Last Modified: 22 Apr 2026

    The bbPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.6.11. This is due to missing or incorrect nonce validation on the bbp_user_add_role_on_register() function. This makes it possible for unauthenticated attackers to elevate their privileges to that of a bbPress Keymaster via a forged request granted they can trick a site administrator into performing an action such as clicking on a link. Rather than implementing a nonce check to provide protection against this vulnerability, which would break functionality, the plugin no longer makes it possible to select a role during registration.

    Published: 5 Mar 2025
    9.8
    Critical

    CVE-2025-1393

    Last Modified: 15 Apr 2026

    An unauthenticated remote attacker can use hard-coded credentials to gain full administration privileges on the affected product.

    Published: 5 Mar 2025
    4.3
    Medium

    CVE-2025-1923

    Last Modified: 1 Apr 2025

    Inappropriate implementation in Permission Prompts in Google Chrome prior to 134.0.6998.35 allowed an attacker who convinced a user to install a malicious extension to perform UI spoofing via a crafted Chrome Extension. (Chromium security severity: Low)

    Published: 5 Mar 2025
    4.3
    Medium

    CVE-2025-1922

    Last Modified: 1 Apr 2025

    Inappropriate implementation in Selection in Google Chrome on Android prior to 134.0.6998.35 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)

    Published: 5 Mar 2025
    6.5
    Medium

    CVE-2025-1921

    Last Modified: 1 Apr 2025

    Inappropriate implementation in Media Stream in Google Chrome prior to 134.0.6998.35 allowed a remote attacker to obtain information about a peripheral via a crafted HTML page. (Chromium security severity: Medium)

    Published: 5 Mar 2025
    8.8
    High

    CVE-2025-1919

    Last Modified: 26 Feb 2026

    Out of bounds read in Media in Google Chrome prior to 134.0.6998.35 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page. (Chromium security severity: Medium)

    Published: 5 Mar 2025
    8.8
    High

    CVE-2025-1918

    Last Modified: 26 Feb 2026

    Out of bounds read in PDFium in Google Chrome prior to 134.0.6998.35 allowed a remote attacker to potentially perform out of bounds memory access via a crafted PDF file. (Chromium security severity: Medium)

    Published: 5 Mar 2025
    4.3
    Medium

    CVE-2025-1917

    Last Modified: 1 Apr 2025

    Inappropriate implementation in Browser UI in Google Chrome on Android prior to 134.0.6998.35 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)

    Published: 5 Mar 2025
    8.8
    High

    CVE-2025-1916

    Last Modified: 26 Feb 2026

    Use after free in Profiles in Google Chrome prior to 134.0.6998.35 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)

    Published: 5 Mar 2025
    8.1
    High

    CVE-2025-1915

    Last Modified: 26 Feb 2026

    Improper Limitation of a Pathname to a Restricted Directory in DevTools in Google Chrome on Windows prior to 134.0.6998.35 allowed an attacker who convinced a user to install a malicious extension to bypass file access restrictions via a crafted Chrome Extension. (Chromium security severity: Medium)

    Published: 5 Mar 2025
    8.8
    High

    CVE-2025-1914

    Last Modified: 26 Feb 2026

    Out of bounds read in V8 in Google Chrome prior to 134.0.6998.35 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High)

    Published: 5 Mar 2025
    5.1
    Medium

    CVE-2025-1967

    Last Modified: 3 Apr 2025

    A vulnerability, which was classified as problematic, has been found in code-projects Blood Bank Management System 1.0. Affected by this issue is some unknown functionality of the file /user_dashboard/donor.php. The manipulation of the argument name leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

    Published: 5 Mar 2025
    8.1
    High

    CVE-2024-0114

    Last Modified: 15 Apr 2026

    NVIDIA Hopper HGX for 8-GPU contains a vulnerability in the HGX Management Controller (HMC) that may allow a malicious actor with administrative access on the BMC to access the HMC as an administrator. A successful exploit of this vulnerability may lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.

    Published: 5 Mar 2025
    6.8
    Medium

    CVE-2024-0141

    Last Modified: 15 Apr 2026

    NVIDIA Hopper HGX for 8-GPU contains a vulnerability in the GPU vBIOS that may allow a malicious actor with tenant level GPU access to write to an unsupported registry causing a bad state. A successful exploit of this vulnerability may lead to denial of service.

    Published: 5 Mar 2025
    6.9
    Medium

    CVE-2025-1966

    Last Modified: 2 Apr 2025

    A vulnerability classified as critical was found in PHPGurukul Pre-School Enrollment System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/index.php. The manipulation of the argument username leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

    Published: 5 Mar 2025
    6.9
    Medium

    CVE-2025-1965

    Last Modified: 2 Apr 2025

    A vulnerability classified as critical has been found in projectworlds Online Hotel Booking 1.0. Affected is an unknown function of the file /admin/login.php. The manipulation of the argument emailusername leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

    Published: 5 Mar 2025
    6.9
    Medium

    CVE-2025-1964

    Last Modified: 15 May 2025

    A vulnerability was found in projectworlds Online Hotel Booking 1.0. It has been rated as critical. This issue affects some unknown processing of the file /booknow.php?roomname=Duplex. The manipulation of the argument checkin leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. Other parameters might be affected as well.

    Published: 5 Mar 2025
    6.9
    Medium

    CVE-2025-20002

    Last Modified: 15 Apr 2026

    After attempting to upload a file that does not meet prerequisites, GMOD Apollo will respond with local path information disclosure

    Published: 5 Mar 2025
    9.3
    Critical

    CVE-2025-24924

    Last Modified: 15 Apr 2026

    Certain functionality within GMOD Apollo does not require authentication when passed with an administrative username

    Published: 5 Mar 2025
    6.9
    Medium

    CVE-2025-1963

    Last Modified: 2 Apr 2025

    A vulnerability was found in projectworlds Online Hotel Booking 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /reservation.php. The manipulation of the argument checkin leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

    Published: 5 Mar 2025
    6.4
    Medium

    CVE-2024-36347

    Last Modified: 15 Apr 2026

    Improper signature verification in AMD CPU ROM microcode patch loader may allow an attacker with local administrator privilege to load malicious microcode, potentially resulting in loss of integrity of x86 instruction execution, loss of confidentiality and integrity of data in x86 CPU privileged context and compromise of SMM execution environment.

    Published: 5 Mar 2025
    7.5
    High

    CVE-2025-27684

    Last Modified: 3 Nov 2025

    Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 1.0.735 Application 20.0.1330 allows Debug Bundle Contains Sensitive Data V-2022-003.

    Published: 5 Mar 2025
    9.8
    Critical

    CVE-2025-27682

    Last Modified: 3 Nov 2025

    Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 1.0.735 Application 20.0.1330 allows Insecure Log Permissions V-2022-005.

    Published: 5 Mar 2025
    9.1
    Critical

    CVE-2025-27680

    Last Modified: 3 Nov 2025

    Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 1.0.750 Application 20.0.1442 allows Insecure Firmware Image with Insufficient Verification of Data Authenticity V-2024-004.

    Published: 5 Mar 2025
    9.8
    Critical

    CVE-2025-27678

    Last Modified: 3 Nov 2025

    Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.843 Application 20.0.1923 allows Client Remote Code Execution V-2023-001.

    Published: 5 Mar 2025
    6.5
    Medium

    CVE-2025-25634

    Last Modified: 10 Apr 2025

    A vulnerability has been found in Tenda AC15 15.03.05.19 in the function GetParentControlInfo of the file /goform/GetParentControlInfo. The manipulation of the argument src leads to stack-based buffer overflow.

    Published: 5 Mar 2025
    9.8
    Critical

    CVE-2025-27643

    Last Modified: 3 Nov 2025

    Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.933 Application 20.0.2368 allows Hardcoded AWS API Key V-2024-006.

    Published: 5 Mar 2025
    9.8
    Critical

    CVE-2025-27645

    Last Modified: 3 Nov 2025

    Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.933 Application 20.0.2368 allows Insecure Extension Installation by Trusting HTTP Permission Methods on the Server Side V-2024-005.

    Published: 5 Mar 2025
    9.8
    Critical

    CVE-2025-27662

    Last Modified: 1 Apr 2025

    Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.843 Application 20.0.1923 allows Password in URL OVE-20230524-0005.

    Published: 5 Mar 2025
    7.5
    High

    CVE-2025-27669

    Last Modified: 1 Apr 2025

    Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.843 Application 20.0.1923 allows Remote Network Scanning (XSPA)/DoS OVE-20230524-0013.

    Published: 5 Mar 2025
    6.1
    Medium

    CVE-2025-27637

    Last Modified: 3 Nov 2025

    Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.1002 Application 20.0.2614 allows Cross-Site Scripting V-2024-016.

    Published: 5 Mar 2025
    9.8
    Critical

    CVE-2025-27642

    Last Modified: 3 Nov 2025

    Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.933 Application 20.0.2368 allows Unauthenticated Driver Package Editing V-2024-008.

    Published: 5 Mar 2025
    9.8
    Critical

    CVE-2025-27648

    Last Modified: 3 Nov 2025

    Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.913 Application 20.0.2253 allows Cross Tenant Password Exposure V-2024-003.

    Published: 5 Mar 2025
    9.8
    Critical

    CVE-2025-27651

    Last Modified: 3 Nov 2025

    Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.862 Application 20.0.2014 allows Server-Side Request Forgery: Elatec V-2023-014.

    Published: 5 Mar 2025
    6.1
    Medium

    CVE-2025-27654

    Last Modified: 3 Nov 2025

    Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.862 Application 20.0.2014 allows Cross Site Scripting (XSS) V-2023-017.

    Published: 5 Mar 2025
    9.8
    Critical

    CVE-2025-27656

    Last Modified: 3 Nov 2025

    Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.862 Application 20.0.2014 allows Password Stored in Process List V-2023-011.

    Published: 5 Mar 2025
    9.8
    Critical

    CVE-2025-27675

    Last Modified: 3 Nov 2025

    Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.843 Application 20.0.1923 allows Vulnerable OpenID Implementation V-2023-004.

    Published: 5 Mar 2025
    6.1
    Medium

    CVE-2025-27679

    Last Modified: 3 Nov 2025

    Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.843 Application 20.0.1923 allows Cross-Site Scripting in Badge Registration V-2023-005.

    Published: 5 Mar 2025