CVE Database

Comprehensive vulnerability intelligence with advanced analytics

5.3

The Chained Quiz plugin for WordPress is vulnerable to Insecure Direct Object Reference in version 1.3.4 and below via the quiz submission and completion mechanisms due to missing validation on a user controlled key. This makes it possible for unauthenticated attackers to hijack and modify other users' quiz attempts by…

Published: Sep 18, 2025
Modified: Sep 18, 2025
EPSS: 2.43%
View Details
5.9

The Quiz Maker plugin for WordPress is vulnerable to SQL Injection via spoofed IP headers in all versions up to, and including, 6.7.0.56 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to…

Published: Sep 17, 2025
Modified: Dec 19, 2025
EPSS: 0.19%
View Details
4.9

The ELEX WooCommerce Google Shopping (Google Product Feed) plugin for WordPress is vulnerable to SQL Injection via the 'file_to_delete' parameter in all versions up to, and including, 1.4.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it…

Published: Sep 06, 2025
Modified: Sep 08, 2025
EPSS: 0.14%
View Details
9.8

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In versions 9.4-rc-1 through 16.10.5 and 17.0.0-rc-1 through 17.2.2, it's possible for anyone to inject SQL using the parameter sort of the getdeleteddocuments.vm. It's injected as is as an ORDER BY value. This…

Published: Jul 24, 2025
Modified: Sep 03, 2025
Product: xwiki xwiki
EPSS: 29.58%
View Details

An incomplete fix has been identified for CVE-2025-23084 in Node.js, specifically affecting Windows device names like CON, PRN, and AUX. This vulnerability affects Windows users of `path.join` API.

Published: Jul 18, 2025
Modified: Nov 04, 2025
EPSS: 2.17%
View Details
7.2

SugarCRM before 13.0.4 and 14.x before 14.0.1 allows SSRF in the API module because a limited type of code injection can occur.

Published: Jul 13, 2025
Modified: Nov 03, 2025
EPSS: 1.17%
View Details
9.8

The Simple-File-List Plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 4.2.2 via the rename function which can be used to rename uploaded PHP code with a png extension to use a php extension. This allows unauthenticated attackers to execute code on the server.

Published: Jul 12, 2025
Modified: Jul 29, 2025
Product: simplefilelist simple_file_list
EPSS: 86.14%
View Details

An authentication bypass vulnerability exists in the WordPress Pie Register plugin ≤ 3.7.1.4 that allows unauthenticated attackers to impersonate arbitrary users by submitting a crafted POST request to the login endpoint. By setting social_site=true and manipulating the user_id_social_site parameter, an attacker can generate a valid WordPress session cookie for any…

Published: Jul 09, 2025
Modified: Jul 10, 2025
EPSS: 71.21%
View Details
2.8

Sudo before 1.9.17p1, when used with a sudoers file that specifies a host that is neither the current host nor ALL, allows listed users to execute commands on unintended machines.

Published: Jun 30, 2025
Modified: Nov 03, 2025
Product: sudo_project sudo
EPSS: 13.62%
View Details
5.7

An issue in OneTrust SDK v.6.33.0 allows a local attacker to cause a denial of service via the Object.setPrototypeOf, __proto__, and Object.assign components. NOTE: this is disputed by the Supplier who does not agree it is a prototype pollution vulnerability.

Published: Jun 25, 2025
Modified: Jul 25, 2025
EPSS: 0.21%
View Details
4.8

An Insufficient Session Expiration vulnerability [CWE-613] in FortiOS SSL-VPN version 7.6.0, version 7.4.6 and below, version 7.2.10 and below, 7.0 all versions, 6.4 all versions may allow an attacker in possession of a cookie used to log in the SSL-VPN portal to log in again, although the session has expired…

Published: Jun 10, 2025
Modified: Jul 25, 2025
Product: fortinet fortios
EPSS: 0.25%
View Details
9.9

Roundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 allows remote code execution by authenticated users because the _from parameter in a URL is not validated in program/actions/settings/upload.php, leading to PHP Object Deserialization.

Published: Jun 02, 2025
Modified: Dec 22, 2025
Product: roundcube webmail
EPSS: 91.84%
View Details
6.8

DLL's are not digitally signed when loaded in ASPECT's configuration toolset exposing the application to binary planting during device commissioning.This issue affects ASPECT-Enterprise: through 3.*; NEXUS Series: through 3.*; MATRIX Series: through 3.*.

Published: May 22, 2025
Modified: May 23, 2025
EPSS: 0.48%
View Details
7.8

In the Linux kernel, the following vulnerability has been resolved: dm-bufio: don't schedule in atomic context A BUG was reported as below when CONFIG_DEBUG_ATOMIC_SLEEP and try_verify_in_tasklet are enabled. [ 129.444685][ T934] BUG: sleeping function called from invalid context at drivers/md/dm-bufio.c:2421 [ 129.444723][ T934] in_atomic(): 1, irqs_disabled(): 0, non_block: 0, pid:…

Published: May 20, 2025
Modified: Nov 10, 2025
Product: linux linux_kernel
EPSS: 0.26%
View Details
9.8

The Frontend Login and Registration Blocks plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 1.0.7. This is due to the plugin not properly validating a user's identity prior to updating their details like email via the flr_blocks_user_settings_handle_ajax_callback() function. This makes…

Published: May 09, 2025
Modified: May 12, 2025
EPSS: 19.55%
View Details
7.5

Memory Allocation with Excessive Size Value vulnerability in Apache ActiveMQ. During unmarshalling of OpenWire commands the size value of buffers was not properly validated which could lead to excessive memory allocation and be exploited to cause a denial of service (DoS) by depleting process memory, thereby affecting applications and services…

Published: May 07, 2025
Modified: Nov 03, 2025
Product: apache activemq
EPSS: 0.64%
View Details
7.5

The Slider & Popup Builder by Depicter plugin for WordPress is vulnerable to generic SQL Injection via the ‘s' parameter in all versions up to, and including, 3.6.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it…

Published: May 06, 2025
Modified: May 07, 2025
EPSS: 50.36%
View Details
8.1

A Cross-Site Request Forgery (CSRF) vulnerability was discovered in ERPNEXT 14.82.1 and 14.74.3. The vulnerability allows an attacker to perform unauthorized actions such as user deletion, password resets, and privilege escalation due to missing CSRF protections.

Published: May 05, 2025
Modified: Jun 17, 2025
Product: frappe erpnext
EPSS: 0.13%
View Details
9.8

Incorrect Privilege Assignment vulnerability in Brainstorm Force SureTriggers allows Privilege Escalation.This issue affects SureTriggers: from n/a through 1.0.82.

Published: May 01, 2025
Modified: May 05, 2025
EPSS: 73.51%
View Details
7.5

Improper Input Validation vulnerability in Apache Tomcat. Incorrect error handling for some invalid HTTP priority headers resulted in incomplete clean-up of the failed request which created a memory leak. A large number of such requests could trigger an OutOfMemoryException resulting in a denial of service. This issue affects Apache Tomcat:…

Published: Apr 28, 2025
Modified: Nov 03, 2025
Product: apache tomcat
EPSS: 8.12%
View Details
8.1

The User Registration & Membership WordPress plugin before 4.1.3 does not properly validate data in an AJAX action when the Membership Addon is enabled, allowing attackers to authenticate as any user, including administrators, by simply using the target account's user ID.

Published: Apr 22, 2025
Modified: Sep 30, 2025
Product: wpeverest user_registration_\&_membership
EPSS: 4.81%
View Details
7.8

An incorrect permission assignment vulnerability in the PostgreSQL commands of the Zyxel USG FLEX H series uOS firmware versions from V1.20 through V1.31 could allow an authenticated local attacker with low privileges to gain access to the Linux shell and escalate their privileges by crafting malicious scripts or modifying system…

Published: Apr 22, 2025
Modified: Oct 30, 2025
Product: zyxel uos
EPSS: 0.08%
View Details
6.1

code-projects Online Exam Mastering System 1.0 is vulnerable to Cross Site Scripting (XSS) in feedback.php via the "q" parameter allowing remote attackers to execute arbitrary code.

Published: Apr 21, 2025
Modified: Apr 24, 2025
Product: code-projects online_exam_mastering_system
EPSS: 0.44%
View Details
8.3

Cross Site Scripting vulnerability in Nagios Log Server v.2024R1.3.1 allows a remote attacker to execute arbitrary code via a payload into the Email field.

Published: Apr 15, 2025
Modified: Apr 23, 2025
Product: nagios log_server
EPSS: 10.79%
View Details
Page 1 Next