CVE-2025-3532

4 روز قبل 4 روز قبل 0
A vulnerability classified as problematic was found in YouDianCMS 9.5.21. This vulnerability affects unknown code of the file /App/Tpl/Member/Default/Order/index.html.Attackers. The manipulation of th ...

CVE-2025-3531

4 روز قبل 4 روز قبل 0
A vulnerability classified as problematic has been found in YouDianCMS 9.5.21. This affects an unknown part of the file /App/Tpl/Admin/Default/Log/index.html. The manipulation of the argument UserName ...

CVE-2025-2814

5 روز قبل 5 روز قبل 0
Crypt::CBC versions between 1.21 and 3.04 for Perl may use the rand() function as the default source of entropy, which is not cryptographically secure, for cryptographic functions. This issue affects ...

CVE-2025-1456

5 روز قبل 5 روز قبل 0
The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `widgetGrid`, `widgetCountDown`, and `widgetInstagramFeed` methods in all versions up ...

CVE-2025-1455

5 روز قبل 5 روز قبل 0
The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Woo Grid widget in all versions up to, and including, 1.7.1012 due to insufficient in ...

CVE-2025-3418

5 روز قبل 5 روز قبل 0
The WPC Admin Columns plugin for WordPress is vulnerable to privilege escalation in versions 2.0.6 to 2.1.0. This is due to the plugin not properly restricting user meta values that can be updated thr ...

CVE-2025-3292

5 روز قبل 5 روز قبل 0
The User Registration & Membership – Custom Registration Form, Login Form, and User Profile plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, ...

CVE-2025-3282

5 روز قبل 5 روز قبل 0
The User Registration & Membership – Custom Registration Form, Login Form, and User Profile plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, ...

CVE-2025-3276

5 روز قبل 5 روز قبل 0
The SKT Blocks – Gutenberg based Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Post Carousel block in all versions up to, and including, 1.9 due to insufficien ...

CVE-2024-13338

5 روز قبل 5 روز قبل 0
The Clearfy Cache – WordPress optimization plugin, Minify HTML, CSS & JS, Defer plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.3.1. This is du ...

CVE-2024-13337

5 روز قبل 5 روز قبل 0
The Clearfy Cache – WordPress optimization plugin, Minify HTML, CSS & JS, Defer plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.3.2. This is du ...

CVE-2025-2871

5 روز قبل 5 روز قبل 0
The WordPress Mega Menu – QuadMenu plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.2.0. This is due to missing or incorrect nonce validation on ...

CVE-2025-2881

6 روز قبل 6 روز قبل 0
The Developer Toolbar plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.0.3 through the publicly accessible phpinfo.php script. This makes it ...

CVE-2025-2841

6 روز قبل 6 روز قبل 0
The Cart66 Cloud plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.3.7 through the publicly accessible phpinfo.php script. This makes it poss ...

CVE-2025-32726

6 روز قبل 6 روز قبل 0
Improper access control in Visual Studio Code allows an authorized attacker to elevate privileges locally.

CVE-2025-29834

6 روز قبل 6 روز قبل 0
Out-of-bounds read in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

CVE-2025-29803

6 روز قبل 6 روز قبل 0
Uncontrolled search path element in Visual Studio Tools for Applications and SQL Server Management Studio allows an authorized attacker to elevate privileges locally.

CVE-2025-2269

6 روز قبل 6 روز قبل 0
The Photo Gallery by 10Web – Mobile-Friendly Image Gallery plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘image_id’ parameter in all versions up to, and including, 1.8.3 ...

CVE-2025-0129

6 روز قبل 6 روز قبل 0
Prisma Access Browser: Inappropriate control behavior in Prisma Access Browser

CVE-2024-11679

6 روز قبل 6 روز قبل 0
An input validation weakness was reported in the TpmSetup module for some legacy System x server products that could allow a local attacker with elevated privileges to read the contents of memory.

5 ماه قبل 5 ماه قبل 33
SOPlanning 1.52.01 (Simple Online Planning Tool) - Remote Code Execution (RCE) (Authenticated)

6 ماه قبل 6 ماه قبل 22
reNgine 2.2.0 - Command Injection (Authenticated)

6 ماه قبل 6 ماه قبل 23
openSIS 9.1 - SQLi (Authenticated)

6 ماه قبل 6 ماه قبل 22
dizqueTV 1.5.3 - Remote Code Execution (RCE)

7 ماه قبل 7 ماه قبل 24
NoteMark < 0.13.0 - Stored XSS

7 ماه قبل 7 ماه قبل 22
Gitea 1.22.0 - Stored XSS

7 ماه قبل 7 ماه قبل 21
Invesalius3 - Remote Code Execution

7 ماه قبل 7 ماه قبل 34
Windows TCP/IP - RCE Checker and Denial of Service

7 ماه قبل 7 ماه قبل 25
Aurba 501 - Authenticated RCE

7 ماه قبل 7 ماه قبل 23
HughesNet HT2000W Satellite Modem - Password Reset

7 ماه قبل 7 ماه قبل 24
Elber Wayber Analog/Digital Audio STL 4.00 - Device Config Disclosure

7 ماه قبل 7 ماه قبل 24
Elber Wayber Analog/Digital Audio STL 4.00 - Authentication Bypass

7 ماه قبل 7 ماه قبل 23
Elber ESE DVB-S/S2 Satellite Receiver 1.5.x - Device Config

7 ماه قبل 7 ماه قبل 26
Elber ESE DVB-S/S2 Satellite Receiver 1.5.x - Authentication Bypass

7 ماه قبل 7 ماه قبل 21
Helpdeskz v2.0.2 - Stored XSS

7 ماه قبل 7 ماه قبل 21
Calibre-web 0.6.21 - Stored XSS

8 ماه قبل 8 ماه قبل 24
Devika v1 - Path Traversal via 'snapshot_path'

8 ماه قبل 8 ماه قبل 20
Genexus Protection Server 9.7.2.10 - 'protsrvservice' Unquoted Service Path

8 ماه قبل 8 ماه قبل 24
SolarWinds Kiwi Syslog Server 9.6.7.1 - Unquoted Service Path

8 ماه قبل 8 ماه قبل 21
Oracle Database 12c Release 1 - Unquoted Service Path