CVE Feed

    Dashboard / CVE

    5.4
    Medium

    CVE-2025-0958

    Last Modified: 21 Apr 2026

    The Ultimate WordPress Auction Plugin plugin for WordPress is vulnerable to unauthorized access to functionality in all versions up to, and including, 4.2.9. This makes it possible for authenticated attackers, with Contributor-level access and above, to delete arbitrary auctions, posts as well as pages and allows them to execute other actions related to auction handling.

    Published: 4 Mar 2025
    6.4
    Medium

    CVE-2025-0433

    Last Modified: 21 Apr 2026

    The Master Addons – Elementor Addons with White Label, Free Widgets, Hover Effects, Conditions, & Animations plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘id’ parameter in all versions up to, and including, 2.0.7.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 4 Mar 2025
    4.3
    Medium

    CVE-2024-13724

    Last Modified: 8 Apr 2026

    The Wallet System for WooCommerce – Wallet, Wallet Cashback, Refunds, Partial Payment, Wallet Restriction plugin for WordPress is vulnerable to unauthorized access to functionality in all versions up to, and including, 2.6.2. This makes it possible for unauthenticated attackers to increase their own wallet balance, transfer balances between arbitrary users and initiate transfer requests from other users' wallets.

    Published: 4 Mar 2025
    6.4
    Medium

    CVE-2024-9618

    Last Modified: 8 Apr 2026

    The Master Addons – Elementor Addons with White Label, Free Widgets, Hover Effects, Conditions, & Animations plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple widgets in all versions up to, and including, 2.0.7.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 4 Mar 2025
    6.4
    Medium

    CVE-2025-0512

    Last Modified: 22 Apr 2026

    The Structured Content (JSON-LD) #wpsc plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's sc_fs_local_business shortcode in all versions up to, and including, 6.4.5 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 4 Mar 2025
    4.3
    Medium

    CVE-2024-13682

    Last Modified: 8 Apr 2026

    The Wallet System for WooCommerce – Wallet, Wallet Cashback, Refunds, Partial Payment, Wallet Restriction plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.6.2. This is due to missing or incorrect nonce validation in class-wallet-user-table.php. This makes it possible for unauthenticated attackers to modify wallet balances via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

    Published: 4 Mar 2025
    6.2
    Medium

    CVE-2024-58050

    Last Modified: 26 Sept 2025

    Vulnerability of improper access permission in the HDC module Impact: Successful exploitation of this vulnerability may affect service confidentiality.

    Published: 4 Mar 2025
    5
    Medium

    CVE-2024-58049

    Last Modified: 4 Mar 2025

    Permission verification vulnerability in the media library module Impact: Successful exploitation of this vulnerability may affect service confidentiality.

    Published: 4 Mar 2025
    6.7
    Medium

    CVE-2024-58048

    Last Modified: 4 Mar 2025

    Multi-thread problem vulnerability in the package management module Impact: Successful exploitation of this vulnerability may affect availability.

    Published: 4 Mar 2025
    5
    Medium

    CVE-2024-58047

    Last Modified: 4 Mar 2025

    Permission verification vulnerability in the media library module Impact: Successful exploitation of this vulnerability may affect service confidentiality.

    Published: 4 Mar 2025
    6.2
    Medium

    CVE-2024-58046

    Last Modified: 26 Sept 2025

    Permission management vulnerability in the lock screen module Impact: Successful exploitation of this vulnerability may affect service confidentiality.

    Published: 4 Mar 2025
    8.6
    High

    CVE-2024-58045

    Last Modified: 12 Jul 2025

    Multi-concurrency vulnerability in the media digital copyright protection module Impact: Successful exploitation of this vulnerability may affect availability.

    Published: 4 Mar 2025
    6.8
    Medium

    CVE-2025-27521

    Last Modified: 26 Sept 2025

    Vulnerability of improper access permission in the process management module Impact: Successful exploitation of this vulnerability may affect service confidentiality.

    Published: 4 Mar 2025
    8.4
    High

    CVE-2024-58044

    Last Modified: 4 Mar 2025

    Permission verification bypass vulnerability in the notification module Impact: Successful exploitation of this vulnerability may affect availability.

    Published: 4 Mar 2025
    7.3
    High

    CVE-2024-58043

    Last Modified: 4 Mar 2025

    Permission bypass vulnerability in the window module Impact: Successful exploitation of this vulnerability may affect service confidentiality.

    Published: 4 Mar 2025
    7.8
    High

    CVE-2025-0360

    Last Modified: 22 Jan 2026

    During an annual penetration test conducted on behalf of Axis Communication, Truesec discovered a flaw in the VAPIX Device Configuration framework that could lead to an incorrect user privilege level in the VAPIX service account D-Bus API.

    Published: 4 Mar 2025
    8.5
    High

    CVE-2025-0359

    Last Modified: 22 Jan 2026

    During an annual penetration test conducted on behalf of Axis Communication, Truesec discovered a flaw in the ACAP Application framework that allowed applications to access restricted D-Bus methods within the framework. Axis has released patched AXIS OS versions for the highlighted flaw. Please refer to the Axis security advisory for more information and solution.

    Published: 4 Mar 2025
    5.3
    Medium

    CVE-2024-47262

    Last Modified: 15 Apr 2026

    Dzmitry Lukyanenka, member of the AXIS OS Bug Bounty Program, has found that the VAPIX API param.cgi was vulnerable to a race condition attack allowing for an attacker to block access to the web interface of the Axis device. Other API endpoints or services not making use of param.cgi are not affected. Axis has released patched AXIS OS versions for the highlighted flaw. Please refer to the Axis security advisory for more information and solution.

    Published: 4 Mar 2025
    6.5
    Medium

    CVE-2024-47260

    Last Modified: 15 Apr 2026

    51l3nc3, member of the AXIS OS Bug Bounty Program, has found that the VAPIX API mediaclip.cgi did not have a sufficient input validation allowing for uploading more audio clips then designed resulting in the Axis device running out of memory.  Axis has released patched AXIS OS versions for the highlighted flaw. Please refer to the Axis security advisory for more information and solution.

    Published: 4 Mar 2025
    3.5
    Low

    CVE-2024-47259

    Last Modified: 22 Jan 2026

    Girishunawane, member of the AXIS OS Bug Bounty Program, has found that the VAPIX API dynamicoverlay.cgi did not have a sufficient input validation allowing for a possible command injection leading to being able to transfer files to the Axis device with the purpose to exhaust system resources. Axis has released patched AXIS OS versions for the highlighted flaw. Please refer to the Axis security advisory for more information and solution.

    Published: 4 Mar 2025
    5.1
    Medium

    CVE-2025-1906

    Last Modified: 12 Jul 2025

    A vulnerability has been found in PHPGurukul Restaurant Table Booking System 1.0 and classified as critical. This vulnerability affects unknown code of the file /admin/profile.php. The manipulation of the argument mobilenumber leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. Other parameters might be affected as well.

    Published: 4 Mar 2025
    5.1
    Medium

    CVE-2025-1905

    Last Modified: 6 Mar 2025

    A vulnerability, which was classified as problematic, was found in SourceCodester Employee Management System 1.0. This affects an unknown part of the file employee.php. The manipulation of the argument Full Name leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. Other parameters might be affected as well.

    Published: 4 Mar 2025
    5.1
    Medium

    CVE-2025-1904

    Last Modified: 6 Mar 2025

    A vulnerability, which was classified as problematic, has been found in code-projects Blood Bank System 1.0. Affected by this issue is some unknown functionality of the file /Blood/A+.php. The manipulation of the argument Availibility leads to cross site scripting. The attack may be launched remotely.

    Published: 4 Mar 2025
    9.8
    Critical

    CVE-2025-1307

    Last Modified: 22 Apr 2026

    The Newscrunch theme for WordPress is vulnerable to arbitrary file uploads due to a missing capability check in the newscrunch_install_and_activate_plugin() function in all versions up to, and including, 1.8.4.1. This makes it possible for authenticated attackers, with Subscriber-level access and above, to upload arbitrary files on the affected site's server which may make remote code execution possible.

    Published: 4 Mar 2025
    8.8
    High

    CVE-2025-1306

    Last Modified: 22 Apr 2026

    The Newscrunch theme for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.8.4. This is due to missing or incorrect nonce validation on the newscrunch_install_and_activate_plugin() function. This makes it possible for unauthenticated attackers to upload arbitrary files via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

    Published: 4 Mar 2025
    6.9
    Medium

    CVE-2025-1903

    Last Modified: 6 Mar 2025

    A vulnerability was found in Codezips Online Shopping Website 1.0. It has been rated as critical. This issue affects some unknown processing of the file /cart_add.php. The manipulation of the argument id leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

    Published: 4 Mar 2025
    6.9
    Medium

    CVE-2025-1902

    Last Modified: 6 Mar 2025

    A vulnerability was found in PHPGurukul Student Record System 3.2. It has been declared as critical. This vulnerability affects unknown code of the file /password-recovery.php. The manipulation of the argument emailid leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

    Published: 4 Mar 2025
    3.8
    Low

    CVE-2025-24309

    Last Modified: 11 Mar 2025

    in OpenHarmony v5.0.2 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through out-of-bounds write. This vulnerability can be exploited only in restricted scenarios.

    Published: 4 Mar 2025
    3.8
    Low

    CVE-2025-24301

    Last Modified: 11 Mar 2025

    in OpenHarmony v5.0.2 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through use after free. This vulnerability can be exploited only in restricted scenarios.

    Published: 4 Mar 2025
    3.8
    Low

    CVE-2025-23420

    Last Modified: 11 Mar 2025

    in OpenHarmony v5.0.2 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through out-of-bounds write. This vulnerability can be exploited only in restricted scenarios.

    Published: 4 Mar 2025
    3.3
    Low

    CVE-2025-23418

    Last Modified: 11 Mar 2025

    in OpenHarmony v5.0.2 and prior versions allow a local attacker cause DOS through out-of-bounds read.

    Published: 4 Mar 2025
    3.8
    Low

    CVE-2025-23414

    Last Modified: 11 Mar 2025

    in OpenHarmony v5.0.2 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through use after free. This vulnerability can be exploited only in restricted scenarios.

    Published: 4 Mar 2025
    3.8
    Low

    CVE-2025-23409

    Last Modified: 12 Jul 2025

    in OpenHarmony v5.0.2 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through use after free. This vulnerability can be exploited only in restricted scenarios.

    Published: 4 Mar 2025
    3.8
    Low

    CVE-2025-23240

    Last Modified: 12 Jul 2025

    in OpenHarmony v5.0.2 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through out-of-bounds write. This vulnerability can be exploited only in restricted scenarios.

    Published: 4 Mar 2025
    3.3
    Low

    CVE-2025-23234

    Last Modified: 13 Jul 2025

    in OpenHarmony v5.0.2 and prior versions allow a local attacker cause DOS through buffer overflow.

    Published: 4 Mar 2025
    3.3
    Low

    CVE-2025-22897

    Last Modified: 12 Jul 2025

    in OpenHarmony v5.0.2 and prior versions allow a local attacker cause DOS through buffer overflow.

    Published: 4 Mar 2025
    3.3
    Low

    CVE-2025-22847

    Last Modified: 13 Jul 2025

    in OpenHarmony v5.0.2 and prior versions allow a local attacker cause DOS through out-of-bounds read.

    Published: 4 Mar 2025
    3.3
    Low

    CVE-2025-22841

    Last Modified: 12 Jul 2025

    in OpenHarmony v5.0.2 and prior versions allow a local attacker cause DOS through out-of-bounds read.

    Published: 4 Mar 2025
    3.3
    Low

    CVE-2025-22837

    Last Modified: 12 Jul 2025

    in OpenHarmony v5.0.2 and prior versions allow a local attacker cause DOS through NULL pointer dereference.

    Published: 4 Mar 2025
    3.8
    Low

    CVE-2025-22835

    Last Modified: 11 Mar 2025

    in OpenHarmony v5.0.2 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through out-of-bounds write. This vulnerability can be exploited only in restricted scenarios.

    Published: 4 Mar 2025
    3.3
    Low

    CVE-2025-22443

    Last Modified: 12 Jul 2025

    in OpenHarmony v5.0.2 and prior versions allow a local attacker cause DOS through out-of-bounds read.

    Published: 4 Mar 2025
    5.5
    Medium

    CVE-2025-21098

    Last Modified: 13 Jul 2025

    in OpenHarmony v5.0.2 and prior versions allow a local attacker cause information leak through out-of-bounds read bypass permission check.

    Published: 4 Mar 2025
    3.3
    Low

    CVE-2025-21097

    Last Modified: 4 Mar 2025

    in OpenHarmony v5.0.2 and prior versions allow a local attacker cause DOS through NULL pointer dereference.

    Published: 4 Mar 2025
    3.3
    Low

    CVE-2025-21089

    Last Modified: 12 Jul 2025

    in OpenHarmony v5.0.2 and prior versions allow a local attacker cause DOS through out-of-bounds read.

    Published: 4 Mar 2025
    3.8
    Low

    CVE-2025-21084

    Last Modified: 4 Mar 2025

    in OpenHarmony v5.0.2 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through through NULL pointer dereference.. This vulnerability can be exploited only in restricted scenarios.

    Published: 4 Mar 2025
    3.8
    Low

    CVE-2025-20626

    Last Modified: 13 Jul 2025

    in OpenHarmony v5.0.2 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through use after free. This vulnerability can be exploited only in restricted scenarios.

    Published: 4 Mar 2025
    3.8
    Low

    CVE-2025-20091

    Last Modified: 12 Jul 2025

    in OpenHarmony v5.0.2 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through use after free. This vulnerability can be exploited only in restricted scenarios.

    Published: 4 Mar 2025
    3.8
    Low

    CVE-2025-20081

    Last Modified: 4 Mar 2025

    in OpenHarmony v5.0.2 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through use after free. This vulnerability can be exploited only in restricted scenarios.

    Published: 4 Mar 2025
    5.5
    Medium

    CVE-2025-20042

    Last Modified: 4 Mar 2025

    in OpenHarmony v5.0.2 and prior versions allow a local attacker cause information leak through out-of-bounds read.

    Published: 4 Mar 2025
    3.8
    Low

    CVE-2025-20024

    Last Modified: 4 Mar 2025

    in OpenHarmony v5.0.2 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through integer overflow. This vulnerability can be exploited only in restricted scenarios.

    Published: 4 Mar 2025